All practice questions
2232 questions
A senior threat intelligence analyst at a global financial services firm is architecting an automated threat feed ingestion pipeline. The system must standardize machine-readable cyber threat indicators and automatically transport them directly into the enterprise Security Information and Event Management (SIEM) platform for real-time correlation without requiring manual analyst intervention. Which of the following standards or protocol frameworks are specifically designed to meet these requirements? (Select TWO.)
Select all that apply
A logistics company migrates its core inventory database to a public cloud Infrastructure as a Service (IaaS) environment using custom virtual machine instances. Under the cloud shared responsibility model, which of the following tasks is the sole operational security responsibility of the customer enterprise?
A security analyst reviews a vulnerability assessment report for an internal Network Attached Storage (NAS) appliance deployed on a dedicated storage management subnet. The audit report identifies two critical host and infrastructure vulnerabilities:
1. The storage management web console accepts cleartext HTTP traffic over TCP port 80 and retains factory default administrator credentials.
2. An unencrypted Telnet service is active on TCP port 23 for command-line access.
Which of the following hardening measures should the security team implement to remediate these specific vulnerabilities? (Select TWO.)
Select all that apply
An IT technician is tasked with applying baseline security hardening controls to enterprise endpoints. Match each system hardening technique on the left with its corresponding security mitigation goal on the right.
Click a left item, then click its matching right item
Items
Matches
A security architect is designing the network architecture for a manufacturing facility. The site contains a legacy Industrial Control System (ICS) operating sensitive Programmable Logic Controllers (PLCs), alongside an automated telemetry module that needs to push real-time performance metrics to a cloud analytics provider. Enterprise security policy mandates that external cloud systems and corporate IT networks must be strictly prevented from sending incoming traffic back into the ICS network segment. Which of the following network architecture designs best fulfills these security requirements?
A security engineering lead at a global telecommunications provider is building an automated workflow to ingest threat indicators into an enterprise SIEM. The threat intelligence vendor supplies standardized, machine-readable data structures representing threat actor TTPs, attack vectors, and observable indicators. To enable automated client-server polling and pushing of these structured data packages over HTTPS, which protocol must be deployed at the application transport layer?
A cybersecurity team at a commercial bank wants to collaborate with peer organizations to exchange industry-specific threat alerts, emerging attack vectors, and operational insights tailored specifically to the financial sector. Which of the following resources best satisfies this requirement?
A network security architect is implementing defense-in-depth segmentation to secure access from external users to an isolated internal backend database. Arrange the network transit points and security control boundaries in the correct sequence through which inbound traffic must flow from the untrusted Internet to the database server.
Drag items to arrange them in the correct order
A security analyst inspects an HTTP request sent to an enterprise document service along with the corresponding server response:
http
GET /documents/download?file=..%2F..%2F..%2Fetc%2Fpasswd HTTP/1.1
Host: portal.example.com
The web server responds with an HTTP 200 OK status code containing the root filesystem account details. Additionally, when a user submits a non-existent path parameter, the application returns a detailed Java stack trace displaying internal file system paths, framework versions, and database connection strings.
Based on these findings, which of the following application vulnerabilities are present? (Select TWO.)
Select all that apply
A healthcare organization deploys a microservice backend utilizing a serverless Function-as-a-Service (FaaS) architecture on a public cloud platform to ingest patient telemetry. Under the cloud shared responsibility model, which TWO of the following security tasks remain the responsibility of the organization rather than the cloud service provider?
Select all that apply
An enterprise security team discovers that a bare-metal server's Baseboard Management Controller (BMC) interface running IPMI v2.0 on UDP port 623 is reachable directly from standard workstation VLANs. The IPMI service is configured with Cipher Suite 0, allowing session establishment without authentication and transmitting management traffic in cleartext. Although edge firewalls restrict external internet access to UDP port 623, no internal network segmentation or host-level access control lists exist to restrict internal traffic. Which of the following mitigation strategies BEST addresses the host, protocol, and architectural vulnerabilities described in this scenario?
A security administrator needs to prevent smart building environmental sensors from communicating directly with internal servers holding confidential employee files on the company network. Which of the following secure network design techniques provides the most effective logical isolation for these sensors?
A network administrator is designing a wireless architecture for a company branch office. The goal is to provide visitors with internet access while preventing them from accessing sensitive internal servers and local network resources. Which of the following controls should the administrator implement to achieve secure network segmentation? (Select TWO.)
Select all that apply
A multinational technology company is migrating its customer analytics workloads to a managed Platform as a Service (PaaS) cloud architecture. Under this service model, the Cloud Service Provider (CSP) manages the physical hardware, hypervisors, database engine software, and underlying operating system runtime environments. The company's security engineering team must establish appropriate security architecture controls for the hosted applications and sensitive data. Under the cloud shared responsibility model, which of the following tasks remains the sole responsibility of the customer organization?
An organization's security operations team observes that unauthorized software scripts are frequently executing from temporary user directories on endpoint workstations. To restrict hosts so that only explicitly authorized executables and scripts are permitted to run, which of the following technical mitigation controls should be implemented?
During a post-breach investigation at a software development firm, incident responders trace an initial access event to a multi-stage campaign. The threat actor scattered USB drives branded with the firm's logo and labeled 'Confidential Executive Salaries' across the employee parking area. Concurrently, the actor compromised a popular third-party technical documentation site frequented by the firm's DevOps engineering team, injecting a malicious script that prompted visitors to download a forged browser extension update. Which of the following social engineering techniques and attack vectors were directly executed in this campaign? (Select TWO.)
Select all that apply
An enterprise financial institution is establishing a multi-tenant Community Cloud deployment model shared exclusively among partner credit unions to host a real-time collaborative fraud detection platform. The platform is constructed using managed Platform as a Service (PaaS) microservices that process customer transactions. The enterprise security architect must define control boundaries according to the cloud shared responsibility model and Zero Trust principles. Which of the following security responsibilities rests exclusively with the participating organization's security team?
A cybersecurity specialist at a hospital wants to receive sector-specific threat intelligence and exchange real-time attack indicators with peer healthcare entities. Which of the following sources best fulfills this requirement?
A security analyst is conducting forensic triage on several compromised endpoints following an enterprise network incident. Match each observed technical Indicator of Compromise (IoC) with its corresponding malware classification.
Click a left item, then click its matching right item
Items
Matches
An e-commerce retailer is conducting a quantitative risk assessment for its primary inventory management database, which has an Asset Value () of . Security analysts estimate that a ransomware outbreak would impact of the system (). Based on threat intelligence, such an attack is expected to occur once every years (). What is the Annual Loss Expectancy () associated with this risk?