All practice questions
2232 questions
A network security administrator examining packet captures from an enterprise core switch notices several anomalous frames originating from an untrusted workstation segment. The captured frame header displays an outer 802.1Q tag corresponding to VLAN 1 (the native VLAN) and an inner 802.1Q tag designated for VLAN 50 (the secure database subnet). Which of the following network attack indicators is demonstrated in this scenario?
A system administrator is reviewing web application event logs and discovers multiple database syntax errors generated by user input containing payload strings such as `' OR '1'='1`. Which of the following application vulnerabilities is the attacker attempting to exploit?
A DevSecOps engineer is configuring automated security testing methods within a continuous integration/continuous deployment (CI/CD) pipeline for a microservices application. Security directives require identifying code flaws before deployment and assessing application security at runtime in a non-production staging environment without attempting intrusive exploitation. Which TWO of the following security testing methods should be integrated to meet these requirements? (Select TWO.)
Select all that apply
A network administrator needs to isolate legacy industrial control devices that cannot accept software patches from the primary corporate network to prevent unauthorized lateral movement. Which of the following network design techniques best fulfills this security requirement?
A wireless intrusion prevention system (WIPS) generates a high-severity alert for a mobile workstation located on an enterprise campus. The event log records that an unauthorized device is transmitting targeted unicast 802.11 Probe Response frames matching multiple distinct entries from the workstation's Preferred Network List (PNL). Immediately following the probe responses, the unauthorized device initiates an EAP-TTLS handshake and requests legacy authentication credentials. Which of the following attack mechanisms is most accurately represented by these indicators?
A global manufacturing corporation is deploying a multi-cloud security architecture to support collaborative supply chain partner integration, internal software engineering teams, and cloud governance monitoring. Match each cloud architecture model or security control placement on the left with its corresponding responsibility boundary or functional description on the right.
Click a left item, then click its matching right item
Items
Matches
Match each cloud deployment model to its defining security architecture characteristic.
Click a left item, then click its matching right item
Items
Matches
An organization plans to deploy a database solution in the cloud. The company requires the Cloud Service Provider (CSP) to manage hardware provisioning, operating system installation, and database engine maintenance, while the internal IT team retains control over database tables and user permissions. Which cloud service model should the organization select to meet these requirements?
A security architect is developing a cloud security matrix to clarify operational responsibilities across multi-cloud environments. Match each security operational task to the corresponding cloud service model where the customer is primarily responsible for performing that specific task.
Click a left item, then click its matching right item
Items
Matches
An incident response team at a critical infrastructure firm is investigating several concurrent security incidents involving social engineering vectors. Match each observed incident scenario to the attack vector that best describes the adversary's delivery method.
Click a left item, then click its matching right item
Items
Matches
A security architect is updating the enterprise security baseline for several subnets and workload environments. Match each network design requirement to the most appropriate architecture technique or isolation mechanism.
Click a left item, then click its matching right item
Items
Matches
A chief information security officer (CISO) observes that system administrators are frequently targeted with sophisticated social engineering tactics tailored specifically to technical environments. Which training approach is most effective for addressing this human risk?
A security analyst investigates an incident where an adversary registered a domain visually similar to an enterprise's external vendor portal (payro1l-service.com). The adversary hosted a trojanized software patch on the site and sent personalized emails directly to three payroll specialists, claiming an urgent compliance update was required to prevent processing delays. Which of the following social engineering attack vectors best describes the primary delivery tactic used against the payroll specialists?
A security engineering team is conducting a vulnerability assessment of an internal payment API gateway. The assessment reveals that client TLS connections are configured to accept cipher suites utilizing the RC4 stream cipher for data encryption and static RSA key exchange for session negotiation. Which of the following security risks or weaknesses are directly introduced by this cryptographic configuration? (Select TWO.)
Select all that apply
A security architect is designing a multi-tier web application network layout for a corporate enterprise. The design requires that public Internet users can access the front-end web servers, but direct connectivity from the Internet to the backend database servers holding sensitive payment data must be strictly prohibited. Furthermore, administrative access to the database tier must be tightly restricted and audited, with lateral East-West movement between unauthorized server segments blocked. Which of the following network architecture designs best achieves this security objective?
A lead security analyst at a online retail enterprise is evaluating threat intelligence options to proactively detect compromised corporate credentials being offered for sale on subterranean marketplaces. The organization requires actionable, curated threat feeds with tailored risk scoring and automated API integration to ingest indicators of compromise (IOCs) without dedicating internal staff to manually monitor dark web forums. Which threat intelligence source type should the analyst recommend to meet these requirements?
A global pharmaceutical firm connects several remote research facilities to its central datacenters using legacy IPsec VPN site-to-site tunnels. A cryptographic assessment of the gateway configurations reveals that Phase 1 IKE negotiations utilize Diffie-Hellman (DH) Group 2 (1024-bit) with 3DES-CBC payload encryption, while Phase 2 uses MD5 for message integrity verification. Security analysts report elevated risks of session key recovery, collision vulnerabilities, and performance degradation. Which of the following primary mitigation strategies comprehensively addresses these cryptographic control weaknesses?
A web application developer wants to remediate software vulnerabilities that allow attacker-controlled inputs to execute malicious scripts in user browsers or alter database commands. Which of the following secure coding practices should the developer implement to address these application vulnerabilities? (Select TWO.)
Select all that apply
A network security team is establishing security zones and access control mechanisms for an enterprise environment. Match each network segmentation strategy on the left to its primary application scenario on the right.
Click a left item, then click its matching right item
Items
Matches
Match each threat intelligence source type to its primary characteristic or operational scope.
Click a left item, then click its matching right item
Items
Matches