All practice questions
2232 questions
During a threat hunting exercise, a security analyst reviews network logs from a Kubernetes host node running enterprise microservices. The log entries indicate that a compromised container instance successfully issued a request to extract infrastructure credentials:
[2026-07-20 09:14:02 UTC] TCP 10.244.1.45:49152 -> 169.254.169.254:80 GET /latest/meta-data/iam/security-credentials/node-role HTTP/1.1
[2026-07-20 09:14:02 UTC] HTTP 200 OK (Content-Length: 1248, IAM Role: NodeInstanceRole)
[2026-07-20 09:14:15 UTC] AWS STS API call initiated directly from container IP 10.244.1.45 using retrieved token
Which host and architecture vulnerability is the root cause of this credential exposure?
A system administrator at a retail organization notices automated scans targeting the company's public web server using off-the-shelf, publicly available exploit toolkits. The activity demonstrates minimal technical expertise and relies entirely on well-known vulnerabilities without using custom tools or zero-day exploits. Which threat actor type is most likely responsible for this activity?
A security analyst at a healthcare technology firm is investigating a network intrusion. Analysis reveals that an external group gained access through a zero-day vulnerability in an edge device, established undetected long-term persistence for over nine months, and specifically targeted proprietary medical diagnostic algorithms. The adversary did not deploy ransomware, make extortion demands, or disrupt operations. Which threat actor type and attribute profile is most likely responsible for this attack?
A security technician reviews a vulnerability scanner report for an unpatchable host operating critical legacy services:
`[WARN] Host 10.0.4.15 (Legacy_SCADA_GW): Outdated SSLv3 enabled on port 443`
`[WARN] Host 10.0.4.15 (Legacy_SCADA_GW): Active unencrypted Telnet service detected on port 23`
`[INFO] Host 10.0.4.15 shares a flat Layer 2 broadcast domain with 150 user workstations.`
Because replacing or patching the legacy system would interrupt critical operations, which of the following is the MOST effective architectural control to mitigate network-based exploitation of these host vulnerabilities?
A security analyst inspecting web application access logs discovers the following HTTP POST request payload targeting an enterprise search endpoint:
`POST /api/v1/products/search HTTP/1.1`
`Host: portal.example.com`
`Content-Type: application/x-www-form-urlencoded`
`Payload: item_query=gadget' UNION SELECT credit_card_num, CVV FROM customer_payment_data WHERE '1'='1`
Which of the following vulnerabilities is being exploited in this scenario, and what is the primary application-level mitigation control required to prevent it?
A forensic analyst investigating an unexpected data wipe on a critical financial server discovers an obfuscated script embedded within a routine system backup routine. The script performs no malicious activity during normal execution; however, it regularly queries the enterprise LDAP directory. Inspection reveals that if a specific senior database administrator's account status transitions to 'Inactive' or 'Disabled', the script triggers an automated payload that executes a multi-pass overwrite of disk sectors and purges transaction logs. Which of the following malware classifications best describes this threat based on its operational behavior?
A defense contractor's incident response team discovers that several senior propulsion engineers' workstations were compromised by specialized remote access trojans (RATs). Forensic analysis indicates that none of the engineers received malicious emails, text messages, or direct phone calls. Instead, the threat actors compromised a reputable, third-party industry standards forum frequently visited by propulsion engineers and modified its server code to dynamically serve malicious drive-by exploits only to visitors originating from the contractor's specific public IP range. Which social engineering attack vector was primarily utilized in this scenario?
A network security engineer investigates an incident where internal users on VLAN 20 report unexpected SSL/TLS certificate warnings when accessing enterprise web resources. Analysis of packet captures and wireless sensor logs reveals anomalous network frames and suspicious radio frequency traffic around the perimeter. Which of the following technical indicators collectively confirm the simultaneous presence of an ARP poisoning on-path attack and a rogue wireless access point attempt? (Select TWO.)
Select all that apply
An enterprise organization is migrating its internal customer portal to a cloud environment utilizing a Platform as a Service (PaaS) deployment model. Under the cloud Shared Responsibility Model, which of the following security tasks remains the primary responsibility of the enterprise organization?
An organization is deploying a serverless Function-as-a-Service (FaaS) application in a public cloud environment to process customer images. According to the cloud Shared Responsibility Model, which TWO of the following tasks remain the responsibility of the customer? (Select TWO)
Select all that apply
During a post-incident review following an enterprise security evaluation, a security operations team discovers that an automated vulnerability scan failed to identify a critical unpatched remote code execution vulnerability on an internal database server. Simultaneously, the scan report flagged numerous high-severity vulnerabilities on an edge API gateway that manual verification confirmed were false positives. System logs reveal that the scanner performed service banner grabbing, port identification, and basic packet probing across subnets without host-level credentials or local management agents. Which assessment methodology limitation best explains why the scanner failed to detect the internal database flaw while producing false positives on the gateway?
An organization is deploying a custom web application to a cloud environment where the cloud service provider manages the underlying hardware, operating system, and web server runtime environment. The organization's development team is responsible only for deploying their application code and managing the application data. Which cloud service model is being utilized in this scenario?
A security analyst reviews a active network service list and vulnerability report for an internal host managing legacy industrial control equipment:
tcp 0 0 0.0.0.0:21 0.0.0.0:* LISTEN 1042/ftpd
tcp 0 0 0.0.0.0:23 0.0.0.0:* LISTEN 1108/telnetd
The report confirms that administrative management sessions and file uploads to this server transmit credentials in plaintext without restricted network access control lists (ACLs). Which TWO of the following architectural weaknesses or vulnerabilities are directly demonstrated in this scenario? (Select TWO.)
Select all that apply
A logistics firm is updating its threat intelligence matrix to help security staff recognize different adversary profiles. The team needs to document the primary characteristics associated specifically with nation-state threat actors (Advanced Persistent Threats). Which TWO of the following attributes best describe nation-state threat actors?
Select all that apply
A senior Security Operations Center (SOC) analyst is designing an automated threat intelligence sharing pipeline between an enterprise SIEM and a regional Information Sharing and Analysis Center (ISAC). The requirement dictates establishing an automated, machine-readable mechanism capable of transporting standardized indicators of compromise (IoCs) and threat actor context over HTTPS. Which combination of technical standards and protocols best fulfills this architectural requirement?
A security analyst is planning a vulnerability assessment for a web application deployment. The team wants to ensure both dynamic, runtime testing and passive monitoring are utilized during the security evaluation. Which of the following methods should the analyst select to accomplish these goals? (Select TWO).
Select all that apply
A security analyst reviews packet capture logs from a corporate wireless network following reports of sudden connectivity drops. The capture reveals a high volume of unencrypted IEEE 802.11 management frames containing Reason Code 7 (Class 3 frame received from nonassociated STA) broadcast from an unverified MAC address. Immediately following these frames, several client stations transmit EAPOL-Key 4-way handshake messages toward a secondary access point that is broadcasting an identical SSID on the same channel but exhibiting a significantly higher RSSI and a different BSSID. Which of the following best diagnoses the ongoing attack vector and its primary operational objective?
An organization's security team identifies that several software developers received personalized email messages appearing to originate from their version control platform administrator. The messages claimed that due to a critical security compliance violation, their repository access would be suspended within 90 minutes unless they logged into a specified web portal to verify their identity. The link provided led to a counterfeit authentication portal hosted on a visually similar, typo-registered domain designed to harvest credentials. Which of the following social engineering attack vectors and influence principles were directly employed in this campaign? (Select TWO).
Select all that apply
A security technician running an infrastructure discovery scan receives the following report for an internal management host:
[+] Host 192.168.10.45:161/UDP - Active
[+] Protocol: SNMPv2c
[+] Community String: public
[+] Extracted Info: SysName: HV-NODE01, OS: Linux 4.19, Interfaces: eth0 (192.168.10.45), eth1 (10.50.0.1 - Storage SAN)
Which of the following represents the primary host and network architecture vulnerability demonstrated in this scan output?
During a security investigation on a compromised server, an administrator suspects a rootkit has been installed to maintain stealthy persistence. Which TWO of the following indicators of compromise specifically signal the presence of a rootkit?
Select all that apply