All practice questions
173 questions
A security operations team is configuring a Security Information and Event Management (SIEM) data pipeline to handle heterogeneous syslog and event streams from enterprise endpoints, firewalls, and application servers. Place the following SIEM processing stages in the correct chronological order from initial data intake to analyst notification.
Drag items to arrange them in the correct order
A digital forensics analyst must collect evidence from a powered-on virtual machine host following an active intrusion. In what sequence should the analyst capture the following evidence sources, starting from the most volatile to the least volatile?
Drag items to arrange them in the correct order
A security architect is designing a jump box administrative access path for a high-security internal database zone. Arrange the sequence of network traffic flows and security enforcement controls in the correct order, starting from the administrator's initial remote connection attempt and ending at the destination database server.
Drag items to arrange them in the correct order
A cybersecurity responder is acquiring digital evidence from a running Linux enterprise server suspected of executing an in-memory malware payload. Adhering strictly to the Order of Volatility (RFC 3227), in what order should the responder capture the following evidence components from most volatile to least volatile?
Drag items to arrange them in the correct order
A security analyst is executing an incident response playbook following the detection of an unauthorized rogue wireless access point connected to an enterprise network switch. According to the NIST Incident Response Framework (NIST SP 800-61 Rev. 2), in what chronological order should the analyst perform the response actions below?
Drag items to arrange them in the correct order
Place the core phases of the NIST SP 800-61 Incident Response Lifecycle in the correct sequential order from first to last.
Drag items to arrange them in the correct order
In Security Information and Event Management (SIEM) workflow, log data undergoes several processing stages from initial ingestion to analyst notification. Which sequence correctly places the stages of SIEM log processing in chronological order from first to last?
Drag items to arrange them in the correct order
An incident response investigator is tasked with preserving forensic evidence from a live high-frequency trading server that was compromised during an active cyber intrusion. The server is currently powered on and running critical processes in memory. To ensure that digital evidence is collected without destroying highly transient artifact state in compliance with RFC 3227 guidelines, in what sequence should the investigator acquire the artifacts from most volatile to least volatile?
Drag items to arrange them in the correct order
Following the detection and initial triage of an active web shell exploit on an enterprise web server, a Security Operations Center (SOC) analyst must execute the incident response playbook. Arrange the following operational response procedures in the correct chronological sequence according to standard NIST incident response lifecycle guidelines, from the earliest action to the final action.
Drag items to arrange them in the correct order
A digital forensics responder is preparing to collect evidence from a powered-on target workstation. Place the following memory and storage components in the correct sequence according to the standard Order of Volatility, starting from the MOST volatile to the LEAST volatile.
Drag items to arrange them in the correct order
During a multi-vector attack on a hybrid enterprise infrastructure, a security operations team identifies active data exfiltration using a compromised cloud service account API key, alongside automated ransomware scripts terminating database processes on internal servers. To effectively mitigate damage and recover services according to standard incident response frameworks, what is the correct chronological sequence of steps the response team must execute?
Drag items to arrange them in the correct order
A security team is defining an automated containment and investigation workflow for suspicious host behavior flagged by an Endpoint Detection and Response (EDR) agent. Order the steps in the correct chronological sequence from initial detection through remediation.
Drag items to arrange them in the correct order
An analyst is defining an automated incident response playbook within an Endpoint Detection and Response (EDR) system to handle high-severity malware execution alerts on enterprise workstations. Place the following steps of the automated containment, analysis, and recovery workflow in the correct chronological order from first to last.
Drag items to arrange them in the correct order
Place the following steps of an Endpoint Detection and Response (EDR) automated containment and incident investigation workflow in the correct sequential order from initial event detection to host restoration.
Drag items to arrange them in the correct order
A Security Operations Center (SOC) engineering team is designing an enterprise SIEM processing architecture to handle unstructured log streams from hybrid cloud applications, perimeter firewalls, and endpoint agents. In what order should the log processing pipeline execute these stages from initial log retrieval to automated response handling?
Drag items to arrange them in the correct order
During operational monitoring, a Security Operations Center (SOC) analyst identifies unusual Windows Management Instrumentation (WMI) execution on a core Domain Controller, indicating potential credential harvesting. Following the standard NIST SP 800-61 Incident Response Framework, in which chronological sequence should the security team perform the following response procedures?
Drag items to arrange them in the correct order
A security administrator is establishing an automated failover sequence for an active-passive high-availability firewall pair to ensure continuous uptime during a node failure while preserving connection state tables. Place the operational failover steps in the correct chronological order from first to last.
Drag items to arrange them in the correct order
A cybersecurity forensic analyst has just completed a bit-stream disk acquisition of a target drive seized during an insider threat investigation. The analyst must now process and secure the physical drive and digital image to ensure legal admissibility in court. Place the following evidence handling and chain of custody steps in the correct chronological order from first to last.
Drag items to arrange them in the correct order
An incident responder arrives at a compromised live workstation suspected of running volatile in-memory malware. To preserve digital evidence without destroying transient data, the responder must extract system artifacts in strict adherence to the forensic Order of Volatility (RFC 3227). In what sequence should the analyst collect the following evidence items, starting with the MOST volatile artifact (collected first) and ending with the LEAST volatile artifact (collected last)?
Drag items to arrange them in the correct order
A security engineer is configuring an enterprise Security Information and Event Management (SIEM) pipeline to process raw web application traffic logs and detect potential SQL injection attacks. Arrange the following log processing and analysis stages in the correct sequential order from initial log generation to SOC notification.
Drag items to arrange them in the correct order