All practice questions
2232 questions
During an incident investigation on an enterprise wired subnet, a security analyst reviews endpoint logs and network traffic captures. The log entries reveal that the MAC address bound to the default gateway IP address () is rapidly oscillating between the legitimate router physical address () and an unknown physical address (). This address flipping is accompanied by a continuous flood of unsolicited Gratuitous ARP reply packets broadcast across the local segment. Which of the following network attacks is currently taking place?
A fleet logistics company transitions its core routing engine to an Infrastructure as a Service (IaaS) environment provided by a public cloud vendor. The IT team deploys multiple virtual machines to host the application software. Which of the following operational security responsibilities remains exclusively with the logistics company?
Match each storage security mechanism or state to its corresponding enterprise data protection objective.
Click a left item, then click its matching right item
Items
Matches
During a security audit, system administrators discover an unapproved executable file residing on a database server. Technical analysis reveals that the executable monitors system performance and remains inactive until the database reaches exactly records, at which point it automatically executes a script to purge system audit logs. Which of the following malware classifications best describes this threat?
A security architect is reviewing the access control path for remote administrators connecting from an untrusted management subnet to a high-security internal database zone holding regulated financial records. To enforce defense-in-depth and zero-trust principles, traffic must traverse multiple inspection boundaries and transit controls in a precise order. Sequence the security controls and transit points in the correct order that administrative network traffic must navigate from the originating management workstation to the target database server.
Drag items to arrange them in the correct order
An enterprise facility contains legacy operational technology (OT) devices that cannot receive security updates or support modern encryption protocols. Which network design approach provides the most complete protection by physically isolating these critical devices from all untrusted and corporate network traffic?
A healthcare organization must connect legacy diagnostic imaging equipment running unsupported operating systems to the enterprise network. The architecture must allow authorized workstations to retrieve image files while preventing lateral movement if an imaging system is compromised, and restricting administrative access to authenticated technicians. Which of the following network design strategies best fulfills these security requirements?
An enterprise systems administrator is performing a security posture review of host operating systems, network services, and infrastructure hardware. Match each host, network, or architecture vulnerability to its corresponding primary risk or operational impact.
Click a left item, then click its matching right item
Items
Matches
To enforce defense-in-depth across a multi-tenant cloud infrastructure hosting both virtual machines and container workloads, a platform security engineer must align security mechanisms with their specific operational boundaries. Match each virtualization or containerization technology on the left with its primary isolation boundary or resource control capability on the right.
Click a left item, then click its matching right item
Items
Matches
A financial institution requires a storage security architecture for its high-performance database cluster. The design must protect data at rest against physical drive theft from the data center without incurring host operating system processor overhead, while centralizing cryptographic key management inside a dedicated tamper-resistant hardware appliance. Which of the following solutions best satisfies these security and architectural requirements?
An autonomous manufacturing enterprise is transitioning its edge-compute microservices and industrial IoT telemetry pipeline to a Zero Trust Architecture (ZTA). A security architect must define control plane and data plane operational requirements to enforce core Zero Trust tenets across all component communications.
Which of the following architectural requirements MUST be implemented to strictly align with Zero Trust Architecture principles? (Select TWO.)
Select all that apply
A security administrator is configuring host-level hardening for an application running in a Linux container environment. Which of the following security mechanisms directly restrict container resource usage and limit accessible host kernel system calls? (Select TWO.)
Select all that apply
A security administrator is configuring runtime security settings for a container execution host that processes untrusted third-party workloads. Which TWO of the following security controls should be implemented to reduce the kernel attack surface and prevent persistent host filesystem modifications during container execution?
Select all that apply
A financial services company hosts multi-tenant microservices handling sensitive transaction processing. Following a penetration test, security assessors demonstrated that a compromised container could exploit a host Linux kernel vulnerability to gain root privileges on the underlying host OS, compromising adjacent containers. To mitigate this specific attack vector while preserving container deployment automation, which of the following controls should the security team implement?
An organization is updating its internal web application architecture to prevent eavesdropping and data tampering across internal subnets. A network team member suggests omitting TLS encryption for internal microservice communications, arguing that existing perimeter firewalls and isolated VLANs make the internal network inherently safe from interception. Which security control weakness is demonstrated by this proposed architecture?
Match each observed technical indicator from packet captures and system logs to its corresponding network or wireless attack classification.
Click a left item, then click its matching right item
Items
Matches
An endpoint detection and response telemetry report identifies an unapproved background process establishing persistence via a scheduled task named SystemHealthCheck. Memory inspection confirms the payload performs API hooking into explorer.exe to capture user credentials typed into web browsers and collect window titles, while establishing encrypted outbound connections to an external command-and-control server. Which of the following technical characteristics and malware classifications directly align with this observed incident? (Select TWO.)
Select all that apply
Match each storage security and data protection mechanism to its primary enterprise operational control function.
Click a left item, then click its matching right item
Items
Matches
A security technician is setting up a Security Information and Event Management (SIEM) log processing pipeline. Match each SIEM log management phase to its corresponding core function.
Click a left item, then click its matching right item
Items
Matches
An industrial manufacturing plant operates a Safety Instrumented System (SIS) to control physical emergency shutdown valves. The security architecture team must forward real-time operational telemetry from the SIS domain to a cloud-based enterprise monitoring platform. However, regulatory standards mandate that no network path can exist that allows incoming commands or external traffic to reach the safety controllers under any circumstances. Which of the following network segmentation controls best satisfies this requirement?