All practice questions
2232 questions
During an internal security audit, an administrator identifies two host vulnerabilities on an enterprise web server: an unauthenticated REST API endpoint susceptible to directory traversal, and legacy SMB services accepting anonymous NULL session connections. Which TWO of the following remediation measures should the administrator implement to directly resolve these host and architecture vulnerabilities?
Select all that apply
An enterprise security team deploys an automated vulnerability scanner to conduct network-based discovery across a newly created subnet housing microservices. Although monitoring tools verify that the microservices are online and actively serving traffic, the scanner's report indicates zero active hosts were discovered on the target subnet. Which of the following best explains why the vulnerability scanner failed to identify the active hosts?
A security engineer is designing network controls for a cloud-hosted e-commerce application processing payment transactions. The architecture requires granular security controls to prevent lateral movement (east-west traffic) between individual cloud workload instances within the cardholder data environment. Which network design strategy best provides granular isolation and controls east-west traffic between individual cloud workloads?
Match each observed network or wireless attack indicator on the left with its corresponding attack classification on the right.
Click a left item, then click its matching right item
Items
Matches
During a routine post-incident investigation at a commercial financial auditing firm, security engineers discover an intrusion originating from a compromised third-party software build pipeline. The attack exhibited high technical sophistication, stealthy persistence across multiple network segments, and extensive resource backing, with an operational focus on long-term corporate intelligence gathering rather than immediate financial extortion. Which threat actor profile best aligns with the operational attributes and attack vector observed in this scenario?
A network administrator inspecting wireless event logs discovers that multiple client devices are repeatedly and abruptly losing connectivity to the enterprise access point. The logs reveal a flood of unencrypted 802.11 management packets sent with the MAC address of the access point, instructing the clients to immediately terminate their session. Which of the following wireless attack types is indicated by these log entries?
A financial services organization operates a microservices-based payment engine within a container orchestration cluster. Public API proxies, payment verification services, and sensitive database connectors execute across shared worker nodes. To mitigate lateral movement risks between workloads running on identical physical hosts while satisfying strict audit compliance, which of the following network architecture controls should the security team implement?
A network administrator needs to establish a remote management session to perform critical database maintenance from an untrusted external network. Arrange the following network boundary transit steps and control points in the correct order, starting from the external connection initiation to the final session establishment on the internal database server.
Drag items to arrange them in the correct order
An organization is updating its enterprise security strategy to align with Zero Trust Architecture (ZTA) principles. Which of the following implementations best demonstrates the core Zero Trust tenet of "assume breach"?
A system administrator is updating an enterprise security policy to align with core Zero Trust Architecture (ZTA) principles. Which of the following practices represent core tenets of Zero Trust? (Select TWO.)
Select all that apply
An application security engineer analyzes transaction execution traces and thread dumps from a multi-threaded microservice responsible for handling account withdrawals. The application verifies an account's available funds prior to deducting the balance and completing the transfer. During high-concurrency peak load testing, automated monitoring detects instances where account balances drop below zero despite validation checks executing successfully without failure. Code analysis confirms that the check and the update operations are executed as non-atomic statements across separate database connections. Which of the following vulnerabilities is demonstrated in this scenario?
During a post-incident investigation of a cloud-native microservices environment, a security analyst determines that an attacker exploited a kernel vulnerability within an application container to break out of the container runtime environment and execute code directly on the host operating system. The application was running as a standard non-root service within an OCI-compliant container ecosystem. Which of the following root causes best explains why containerization failed to isolate the workload compared to a traditional hardware-enforced virtual machine architecture?
A network security administrator is setting up access rules for an enterprise environment to ensure strict isolation between public web servers and internal databases, while also maintaining secure remote administrative access. Which TWO network architecture and segmentation practices should the administrator implement to meet these requirements?
Select all that apply
A security analyst is reviewing the security architecture for a hybrid cloud deployment containing both virtual machines and containerized applications. Match each security mechanism on the left with its primary isolation property on the right.
Click a left item, then click its matching right item
Items
Matches
Match each observed security incident technical indicator on the left with its corresponding malware classification on the right.
Click a left item, then click its matching right item
Items
Matches
An organization is transitioning several legacy applications to a containerized deployment. A security administrator is explaining to the development team why container security boundaries differ from traditional virtual machine (VM) security boundaries. Which of the following statements accurately describes a fundamental isolation difference between containers and VMs?
A global retail organization is transitioning its legacy transaction processing platform to a hybrid cloud deployment model. The architecture uses Infrastructure as a Service (IaaS) to host legacy relational database instances and Platform as a Service (PaaS) to host modern containerized web frontends. During a cloud architecture security review, the lead security engineer must define operational boundaries under the Shared Responsibility Model for both service types. Which of the following security management tasks remain the exclusive responsibility of the organization across BOTH the IaaS database instances and PaaS web frontends? (Select TWO.)
Select all that apply
An enterprise financial organization is redesigning its Storage Area Network (SAN) security architecture to comply with data-at-rest encryption requirements for bulk database backups. The design must eliminate host server CPU overhead during cryptographic operations and safeguard encryption keys against physical tampering or theft from the data center. Which of the following storage security solutions best meets these requirements?
A DevOps team is deploying microservices within a containerized environment on Linux host servers. The system administrator needs to enforce hard limits on CPU usage and memory consumption for individual containers to prevent a single compromised or misconfigured container from exhausting shared host system resources. Which Linux kernel mechanism should be configured to directly enforce these resource limits?
An enterprise security architect is refining the workload protection matrix for a multi-tenant cloud environment hosting both legacy virtualized infrastructure and microservice containers. Match each virtualization or containerization security control on the left to its corresponding isolation property or policy enforcement mechanism on the right.
Click a left item, then click its matching right item
Items
Matches