All practice questions
2232 questions
An enterprise infrastructure security team is implementing system hardening practices to remediate recent penetration test findings. Match each specific technical hardening control to the primary vulnerability mechanism or attack vector it directly suppresses.
Click a left item, then click its matching right item
Items
Matches
During a routine wireless site survey, a technician discovers a rogue wireless access point broadcasting the exact same Service Set Identifier (SSID) as the corporate network, but transmitting with a different basic service set identifier (BSSID) and higher signal strength to intercept client authentication traffic. Which of the following attack types is indicated by these symptoms?
A security operations analyst is categorizing threat intelligence sources to build a tiered threat data pipeline. Match each threat intelligence source classification on the left with its primary operational characteristic on the right.
Click a left item, then click its matching right item
Items
Matches
An enterprise organization is migrating a mission-critical web service to a public cloud Infrastructure as a Service (IaaS) environment utilizing customer-managed virtual machines behind a cloud provider's network load balancer. Under the cloud Shared Responsibility Model, which of the following security functions remain the explicit responsibility of the enterprise security team? (Select TWO.)
Select all that apply
During a security review at a healthcare facility, security logs reveal that multiple remote clinical staff members received short message service (SMS) communications claiming to originate from the organization's IT department. The text messages asserted that an urgent system update required recipients to immediately click an enclosed link and re-authenticate to prevent loss of Electronic Health Record (EHR) system access. Which social engineering attack vector was executed, and which technical control provides the most robust protection against credential compromise resulting from this attack?
A junior security analyst is tasked with setting up an automated, machine-readable threat intelligence feed to deliver standardized cyber threat indicators directly into the organization's Security Information and Event Management (SIEM) system over HTTPS. Which of the following standards and transport protocols should the analyst implement to achieve this? (Select TWO.)
Select all that apply
A biomedical research organization is implementing an event-driven serverless (Function-as-a-Service) workflow to process sensitive genomic datasets. The solution operates within a community cloud model shared among research partners and integrates with an on-premises data repository via a secure hybrid connection. The security architecture team must define strict operational responsibilities in accordance with the cloud shared responsibility model. Which of the following security management tasks remain the direct responsibility of the biomedical research organization? (Select TWO.)
Select all that apply
A security specialist is reviewing code and application layer security controls for a public web portal. Which of the following vulnerabilities occur directly due to insufficient input validation and sanitization of user-supplied data? (Select TWO).
Select all that apply
A network technician notices that several workstations on a local subnet are experiencing intermittent network connectivity issues. Upon checking the IP configurations of affected client devices, the technician discovers unexpected network settings. Which TWO of the following indicators specifically point to the presence of an active rogue DHCP server on the network?
Select all that apply
A healthcare technology enterprise deploys an event-driven application using cloud-managed API gateways, serverless execution functions (FaaS), and a managed NoSQL database service to ingest patient telemetry data. The chief information security officer (CISO) requires a security matrix mapping operational duties under the cloud service provider's shared responsibility model for serverless workloads. Which of the following tasks is exclusively the responsibility of the customer organization?
During a security architecture audit of a hybrid enterprise environment, analysts discover that system administrators regularly use PowerShell Remoting (WinRM) over TLS to manage internal domain controllers directly from unmanaged endpoints connected via a split-tunnel VPN. If an unmanaged endpoint is compromised, attackers could execute arbitrary administrative commands across the internal infrastructure. Which of the following enterprise hardening strategies MOST effectively mitigates this administrative exposure while preserving required remote management capabilities?
A network security technician is configuring access controls for a healthcare portal. The technician establishes a system that continuously authenticates user identity, validates device compliance, and evaluates permissions for every resource request, even when traffic originates from within the internal corporate network. Which core principle of Zero Trust Architecture is directly demonstrated by this implementation?
An IT security team is establishing baseline endpoint hardening configurations for newly deployed employee workstations. Which TWO of the following technical measures directly reduce the local host attack surface?
Select all that apply
A security analyst at a specialized aerospace firmware developer is investigating a high-profile intrusion into the company's build systems. The threat group gained initial access using a custom zero-day exploit targeting a perimeter firewall, maintained silent persistence for eight months without disrupting service operations, and exfiltrated proprietary satellite navigation algorithms. Investigation reveals the group utilized custom memory-only payloads and a multi-hop proxy network spans multiple foreign jurisdictions. Which of the following threat actor categories and attribute profiles best characterizes this threat entity?
Match each observed log signature or network artifact on the left with its corresponding attack classification on the right.
Click a left item, then click its matching right item
Items
Matches
A security operations team at a commercial satellite communications provider is evaluating two separate security incidents to classify the underlying threat actors and their attack vectors based on observed operational attributes.
• Incident 1: A prolonged, highly sophisticated intrusion into ground station controller firmware utilizing zero-day exploits and custom memory-resident malware, sustained over nine months with no apparent financial extortion attempt.
• Incident 2: A sudden web defacement of the public customer portal paired with a high-volume volumetric DDoS attack, accompanied by public statements demanding the cancellation of aerospace defense contracts.
Based on these attributes and operational indicators, which of the following threat actor classifications and profile assessments are correct? (Select TWO.)
Select all that apply
A network administrator receives multiple user tickets regarding frequent, transient disconnections on an enterprise wireless network using WPA3-Enterprise. A wireless packet capture collected near the affected access points reveals an abnormally high frequency of IEEE 802.11 Type 0 (Management) Subtype 12 frames sent with the BSSID spoofed as the legitimate AP address targeting client MAC addresses, causing immediate client state reset. Further configuration inspection indicates that Management Frame Protection (802.11w / PMF) was set to 'Optional' across all access points. Which of the following wireless attack types is directly indicated by these packet capture artifacts?
A security operations team is reviewing credentialed vulnerability scan reports for an enterprise hybrid cloud architecture. The report reveals missing operating system kernel security patches on high-availability backend database servers and unvalidated input parameters on public-facing web API endpoints. To address these findings effectively while preventing service interruption and maintaining security integrity, which of the following actions should the team implement? (Select TWO.)
Select all that apply
Three weeks after a system administrator resigns from an organization, a database server executing a scheduled midnight payroll job unexpectedly wipes all stored tables. Forensic review of the application's source code identifies an unauthorized script configured to monitor Active Directory for the former administrator's account status. Upon detecting that the account was flagged as disabled, the script automatically triggered the destructive payload. Which of the following malware types best describes this malicious code?
An enterprise security team must perform routine vulnerability assessments across 5,000 corporate workstations distributed over low-bandwidth branch network links. The assessment must accurately detect missing operating system patches and local registry misconfigurations while minimizing network traffic and preventing false positives caused by endpoint firewalls. Which of the following vulnerability assessment methods should the security team implement?