All practice questions
2232 questions
A security engineer is establishing hardware hardening controls for smart grid embedded devices deployed in physically accessible remote locations. Which of the following hardware-level controls will protect device integrity and prevent unauthorized boot-level tampering? (Select TWO.)
Select all that apply
During an incident triage session, security analysts isolate four distinct technical telemetry artifacts collected from host and network sensors. Match each observed technical indicator on the left with its primary malware classification on the right.
Click a left item, then click its matching right item
Items
Matches
An enterprise cloud security architect is evaluating isolation boundaries for a multi-tenant microservices platform. The platform currently runs multiple containerized services sharing a single host Linux kernel. During a risk assessment, the team identifies a risk where a kernel-level privilege escalation or vulnerability exploitation within one container could allow an attacker to escape to the host host OS and compromise adjacent tenant workloads. Which of the following deployment strategies provides the strongest architectural isolation boundary to mitigate host kernel sharing risks?
A enterprise storage architect is designing a secure storage architecture for an off-site media storage facility and cloud synchronization gateway that processes large volumes of sensitive customer transactional data. The solution must ensure bulk encryption of data at rest with minimal CPU overhead, enforce hardware-isolated key protection to prevent key extraction, and prevent unauthorized exfiltration of unencrypted sensitive data across network egress interfaces. Which of the following technological controls should the architect incorporate into the architecture design to meet these requirements? (Select TWO.)
Select all that apply
A security team is conducting a technical audit of an organization's network and application infrastructure. Match each identified cryptographic or security control weakness on the left with the precise risk or impact it presents on the right.
Click a left item, then click its matching right item
Items
Matches
A game development studio migrates its multiplayer matchmaking microservices to a managed Platform as a Service (PaaS) environment hosted by a public cloud provider. As part of defining the organization's cloud security baseline, the architecture team evaluates operational governance duties. Which of the following security responsibilities remains strictly with the game development studio under this cloud service model?
Match each specialized enterprise network architectural scenario with the network segmentation control or isolation mechanism that best satisfies its security and operational constraints.
Click a left item, then click its matching right item
Items
Matches
A threat hunting team performs memory analysis on a suspected workstation and discovers active network sockets associated with hidden execution threads. Lower-level operating system call tables have been intercepted to filter out these specific process IDs from standard administrative monitoring tools. Which of the following malware types is MOST likely operating on the system?
A security analyst conducts incident triage on an enterprise server and uncovers two distinct anomalous indicators:
1. The standard administrative utility binary on disk was replaced with a compromised version that allows unauthorized access using a hardcoded master key.
2. A loadable kernel module is actively intercepting system calls to modify process listings, effectively hiding malicious processes and network sockets from diagnostic commands.
Which of the following malware classifications or mechanisms are directly demonstrated by these forensic findings? (Select TWO)
Select all that apply
A biomedical equipment manufacturer is designing an embedded patient monitoring device intended for hospital environments where physical access to the device cannot be fully restricted. To meet strict regulatory standards, the architecture must guarantee that the initial bootloader execution sequence is validated using one-time programmable, non-volatile hardware fuses burned into the system-on-chip during manufacturing, preventing any subsequent firmware update or physical attacker from altering the initial trust anchor. Which hardware security component best establishes this immutable, non-modifiable foundation for the secure boot process?
During an incident response investigation, a security analyst reviews an Endpoint Detection and Response (EDR) alert on a enterprise workstation. Telemetry logs show that a user opened a weaponized document that invoked PowerShell. The script executed directly within system memory, injected shellcode into a legitimate system process, established an encrypted reverse shell, and modified registry run keys for persistence without creating executable binary files on the local disk. Which of the following malware classifications best describes this threat?
A security analyst reviews a vulnerability scan report for an internal web application server. The scan output displays the following finding:
text
Host: 192.168.10.45:443
Plugin Name: TLS/SSL Server Supports Weak Cipher Suites / Legacy Protocols
Risk Factor: High
Description: The remote service accepts TLS 1.0 and SSL 3.0 protocol negotiations using CBC-mode ciphers.
Which of the following host and infrastructure vulnerabilities is directly identified by this report?
An incident response team at a critical defense manufacturing contractor is investigating a prolonged network intrusion. Analysis reveals that the attacker leveraged undisclosed zero-day exploits across third-party supply chain software, executed custom fileless malware directly in memory, and maintained persistent command-and-control communications over eight months using domain fronting techniques. The threat group operated during standard business hours of a foreign timezone, conducted targeted reconnaissance without exfiltrating immediate commercial value data or deploying extortion malware, and focused exclusively on long-term technological blueprint espionage. Which threat actor type and attribute profile best categorizes this adversary?
A security analyst is inspecting a critical legacy host after an automated vulnerability assessment flagged multiple high-severity findings. The scanner provided the following port audit report and service banner details:
PORT STATE SERVICE VERSION / NOTES
21/tcp OPEN ftp vsftpd 2.3.4 (CVE-2011-2523 confirmed exploitable)
23/tcp OPEN telnet Linux telnetd (Plaintext authentication enabled)
80/tcp OPEN http Apache httpd 2.2.15 ((CentOS) OS end-of-life)
443/tcp CLOSED https No TLS listener configured
Which of the following identifies the primary host and architecture root cause vulnerability exposing this server to immediate remote privilege escalation and credential compromise?
A security team is selecting security testing methods and assessment techniques for different operational scenarios. Match each security assessment method on the left with its corresponding operational description on the right.
Click a left item, then click its matching right item
Items
Matches
During a comprehensive security audit for a healthcare enterprise, a security analyst identifies several distinct threat profiles and attack vectors. Match each threat actor type or vector on the left with its defining operational attribute or scenario on the right.
Click a left item, then click its matching right item
Items
Matches
During a routine security audit, a security analyst discovers that several Linux web servers hosted in an Infrastructure as a Service (IaaS) environment have diverged from the enterprise's hardened configuration baseline after manual hotfixes were applied by system administrators. Which of the following implementation strategies best provides automated drift detection and continuously enforces the designated configuration baseline across the server fleet?
An enterprise security team is addressing risks associated with a critical legacy operational technology (OT) monitoring console that cannot be updated or patched without voiding vendor support compliance. To manage this liability, the organization purchases a third-party cybersecurity insurance policy covering unauthorized access incidents and deploys an isolated, read-only out-of-band network monitoring tap to detect suspicious network traffic without interrupting operations. Which of the following risk response strategies are demonstrated in this scenario? (Select TWO.)
Select all that apply
A newly hired security manager at a healthcare technology company is organizing the documentation repository to distinguish between mandatory compliance directives and discretionary guidance. Which of the following documents constitute mandatory elements of an enterprise security governance framework? (Select TWO.)
Select all that apply
Match each business continuity concept on the left with the operational description on the right that best defines its role in disaster recovery planning.
Click a left item, then click its matching right item
Items
Matches