All practice questions
2232 questions
A security analyst is defining standard testing procedures for an enterprise vulnerability management program. Match each security assessment method to its corresponding operational description.
Click a left item, then click its matching right item
Items
Matches
During a post-incident analysis of an unexpected enterprise database outage, incident responders discover dormant malicious SQL routines embedded within a core payroll application stored procedure. Telemetry reveals that the script continuously queries the human resources database to verify whether a specific administrator account remains marked as active. The code contains logic specifying that if the account status changes to inactive, or if a designated calendar date passes, the routine automatically executes commands to purge database logs and overwrite primary table records. Which of the following malware types is described in this scenario?
A system administrator captures network traffic between an application host and a centralized authentication server on an internal network segment:
text
14:22:05.819201 IP 172.16.40.12.51234 > 172.16.40.50.389: Flags [P.], length 88: LDAP
bindRequest(1) "cn=svc_auth,ou=services,dc=internal,dc=net" simple
Which of the following is the BEST mitigation strategy to resolve the infrastructure vulnerability demonstrated in this log snippet?
During an infrastructure security review of a high-frequency financial transaction processing service, security operations observed that active credentialed vulnerability scanning triggered service account lockouts and unacceptable latency spikes on production database nodes. The engineering team requires an assessment approach that identifies software security flaws and system configuration weaknesses without initiating active network probes, modifying authentication states, or disrupting live operations. Which security testing methodology best addresses these operational constraints?
During an emergency response to a critical zero-day remote code execution vulnerability on an enterprise edge gateway, an administrator bypassed standard Change Advisory Board (CAB) review and applied an emergency patch directly to production systems. Within minutes of application, critical external API endpoints began returning persistent HTTP 500 errors, causing high-priority business service outages. To handle this ongoing operational disruption while adhering to formal change management frameworks, which of the following actions should the security operations team take FIRST?
A security analyst reviews a network packet capture taken from an internal segment connecting an administrative system to an embedded host management interface. The packet capture reveals the following HTTP request:
GET /api/v1/system/status?session_token=9f8e7d6c5b4a3210 HTTP/1.1
Host: 10.20.30.50:8080
User-Agent: EnterpriseAdminConsole/3.4
Accept: */*
A subsequent vulnerability assessment confirms that the embedded host management server lacks Transport Layer Security (TLS) support and processes cleartext HTTP requests. Which of the following represents the primary host and network vulnerability exposed in this scenario?
An organization is conducting a baseline security audit of its internal servers and infrastructure. Match each identified host or architecture vulnerability on the left with its corresponding primary risk on the right.
Click a left item, then click its matching right item
Items
Matches
Match each threat actor category with its defining attribute or primary motivation.
Click a left item, then click its matching right item
Items
Matches
Match each malware classification to its primary characteristic or technical indicator.
Click a left item, then click its matching right item
Items
Matches
A security operations team is implementing an active defense strategy across a enterprise network to detect lateral movement and credential theft. Match each deception technology implementation on the left with its corresponding active defense classification on the right.
Click a left item, then click its matching right item
Items
Matches
A enterprise security operation center (SOC) analyst is categorizing threat actors and attack vectors identified during a comprehensive threat landscape assessment. Match each threat actor type or attack vector on the left with its primary operational attribute or delivery mechanism on the right.
Click a left item, then click its matching right item
Items
Matches
Match each organizational security management requirement to the cloud service model where the customer retains primary operational responsibility for implementing that control.
Click a left item, then click its matching right item
Items
Matches
An incident response team investigating a breach at a regional cloud healthcare provider discovers that infrastructure automation scripts were modified to disable TLS verification across internal microservices. Forensic analysis shows the modification was performed using an active API token originally issued to a former system Administrator who recently left the organization on poor terms. Although the connection originated from an anonymized VPN node commonly associated with political hacktivist campaigns, no external software vulnerabilities or social engineering attacks were involved. Which threat actor type and attack vector combination primary characterizes this incident?
A security analyst investigates an alert on an infected corporate workstation. Endpoint telemetry shows that a user executed a file disguised as a legitimate printer driver update. Immediately after execution, the process initiated automated network probes on port 445 (SMB) to spread to adjacent unpatched systems without further user intervention. Which of the following malware classifications or behaviors are demonstrated in this scenario? (Select TWO.)
Select all that apply
A security technician is planning a vulnerability assessment for an enterprise segment that includes legacy operational technology (OT) devices highly sensitive to unexpected network traffic. The technician decides to implement passive vulnerability scanning rather than active scanning. Which TWO of the following statements correctly describe the primary characteristics of passive vulnerability scanning? (Select TWO)
Select all that apply
An IT technician is auditing an organization's legacy infrastructure to identify host and network vulnerabilities. Which TWO of the following technical conditions represent significant network or host architecture vulnerabilities that could allow unauthorized access or credential exposure? (Select TWO.)
Select all that apply
A security analyst evaluates an operational technology (OT) network segment and captures the following service enumeration and vulnerability assessment report for an embedded field controller:
Nmap scan report for 192.168.50.14 (HVAC Controller)
PORT STATE SERVICE VERSION
161/udp open snmp SNMPv1 (public community string enabled)
22/tcp open ssh OpenSSH 4.3 (Linux kernel 2.6.18 - vendor status: End-of-Life)
Host Assessment Alert: Kernel memory corruption vulnerability identified (No vendor patch available).
Based on the report, which of the following specific host and network vulnerabilities are directly present on this controller? (Select TWO.)
Select all that apply
A cybersecurity team is establishing security testing procedures across various stages of an enterprise application lifecycle and infrastructure deployment. Match each security testing method on the left with its corresponding operational characteristic or execution scenario on the right.
Click a left item, then click its matching right item
Items
Matches
System telemetry and forensic logs from four compromised endpoints within an enterprise environment reveal distinct technical indicators of compromise (IoCs). Match each observed technical indicator on the left with its correct malware classification on the right.
Click a left item, then click its matching right item
Items
Matches
A security analyst is performing host and network triage following a security incident. Match each technical indicator of compromise (IoC) artifact to the correct malware classification.
Click a left item, then click its matching right item
Items
Matches