All practice questions
2232 questions
A enterprise network security architect is reviewing the organization's network segmentation model across physical, virtual, and industrial environments. Match each network segmentation approach to the business and architectural requirement it best addresses.
Click a left item, then click its matching right item
Items
Matches
An enterprise airport operations authority is redesigning its security architecture across operational technology (OT), cloud management, tenant infrastructure, and administrative networks. Match each network isolation and control mechanism on the left to its corresponding architectural requirement on the right.
Click a left item, then click its matching right item
Items
Matches
A logistics enterprise is migrating its fleet tracking telemetry infrastructure to a Zero Trust Architecture (ZTA). The security team is defining architecture baseline policies for API communication between edge gateway devices and core analytical microservices. Which of the following technical requirements directly align with core Zero Trust Architecture principles? (Select TWO).
Select all that apply
An IT administrator needs to ensure that all data written to enterprise storage drives is automatically encrypted at the hardware level without placing an operational processing burden on the host operating system. Which of the following storage security solutions best fulfills this requirement?
A security manager at a retail organization is establishing a threat research and information-sharing strategy. Management wants to receive timely early warnings regarding cyber threats specifically targeting the retail sector and securely exchange anonymized threat telemetry with industry peers. Which of the following sources or mechanisms best fulfills these organizational requirements?
An industrial IoT device manufacturer is designing a field-deployed microcontroller unit that operates in physically untrusted locations. Security engineers need to prevent attackers from executing anti-rollback (firmware downgrade) attacks—where an adversary physically unsolders external flash memory and writes a cryptographically valid, but older and vulnerable, firmware image. Which of the following hardware security controls best mitigates this physical firmware downgrade vector?
Match each Identity and Access Management (IAM) protocol to its primary architectural use case.
Click a left item, then click its matching right item
Items
Matches
A system administrator is auditing isolation and runtime protection controls across a enterprise infrastructure hosting both virtual machines and containerized microservices. Match each security control on the left with the specific operational threat or attack vector it directly mitigates on the right.
Click a left item, then click its matching right item
Items
Matches
A software development firm hosts its multi-tenant build infrastructure on a high-performance Storage Area Network (SAN). During a security assessment, auditors identified two main storage architecture vulnerabilities: block-level data traffic traversing the storage fabric between compute hypervisors and storage arrays is unencrypted and subject to packet sniffing, and logical unit numbers (LUNs) can potentially be accessed by unauthorized host adapters attached to the same fabric switches. Which set of storage architecture controls most effectively mitigates both identified vulnerabilities?
A security engineer is hardening a shared Linux host operating system that runs containerized financial processing microservices. To minimize the risk of a container escape and kernel compromise, which TWO security mechanisms should the engineer implement to restrict container privileges and limit interaction with the host kernel?
Select all that apply
Match each storage security technology to its primary operational function.
Click a left item, then click its matching right item
Items
Matches
A fintech enterprise is restructuring its cloud-native microservices architecture to mitigate risks associated with lateral movement after a compromised service credential allowed unauthorized database queries. The security engineering team must align service-to-service communication with core Zero Trust Architecture (ZTA) principles. Which implementation strategy best enforces the Zero Trust principles of explicit verification and dynamic access control for every transaction request?
A security analyst is investigating an automated SIEM threshold alert triggered by unusual outbound network activity from an internal host (192.168.10.114). The analyst reviews the following DNS query log entries within the SIEM dashboard:
text
27-Jul-2026 14:15:01.123 queries: info: client 192.168.10.114#49152 (a1g4z9x8q.exfil.attacker-domain.com): query: a1g4z9x8q.exfil.attacker-domain.com IN TXT +
27-Jul-2026 14:15:01.450 queries: info: client 192.168.10.114#49152 (b9k2m8p3w.exfil.attacker-domain.com): query: b9k2m8p3w.exfil.attacker-domain.com IN TXT +
27-Jul-2026 14:15:01.890 queries: info: client 192.168.10.114#49152 (c3r7v1q5n.exfil.attacker-domain.com): query: c3r7v1q5n.exfil.attacker-domain.com IN TXT +
27-Jul-2026 14:15:02.210 queries: info: client 192.168.10.114#49152 (d4m9p2k7x.exfil.attacker-domain.com): query: d4m9p2k7x.exfil.attacker-domain.com IN TXT +
Based on the log data, which of the following security events is MOST likely taking place?
A system administrator is hardening container instances operating on a shared host. Which TWO of the following mechanisms directly enforce kernel-level isolation and resource boundaries for container processes?
Select all that apply
A security operations team at a financial technology firm discovers that an external adversary maintained undetected access inside their cloud development pipeline for over eight months. The adversary utilized custom zero-day exploits, digitally signed binary payloads, and target-tailored command-and-control channels to exfiltrate proprietary trading algorithms without demanding ransom or disrupting services. Which of the following threat actor attributes and attack vectors are demonstrated in this scenario? (Select TWO.)
Select all that apply
A security operations analyst is evaluating several network monitoring alerts and packet captures from an enterprise environment. Match each observed technical indicator on the left with its corresponding attack classification on the right.
Click a left item, then click its matching right item
Items
Matches
A biopharmaceutical research enterprise is refactoring its data protection and storage security architecture across a hybrid deployment containing high-throughput NVMe Storage Area Network (SAN) arrays and off-site cloud object storage. The design must ensure zero-trust data protection for proprietary genomic data at rest and during transit, enforce cryptographically isolated key management, maintain ultra-low latency bulk encryption, and prevent sensitive data exfiltration from endpoint storage interfaces. Which of the following architectural controls should the security architect select to satisfy these enterprise security objectives? (Select THREE.)
Select all that apply
A smart utility metering company is migrating its real-time telemetry processing pipeline to a public cloud environment. The architecture utilizes cloud-hosted virtual machines (IaaS) for running custom protocol ingestion agents and a fully managed database service (PaaS) for long-term data warehousing. Which TWO of the following operational security tasks remain the direct responsibility of the utility company's security team across both service models?
Select all that apply
A logistics enterprise hosting financial transaction archives on an enterprise Storage Area Network (SAN) must ensure bulk data at rest remains cryptographically protected if physical drives are stolen or improperly decommissioned. The security architecture team mandates that encryption and decryption operations execute directly on the storage controller hardware without host server performance overhead, while key generation and key lifecycle management must remain strictly isolated inside a dedicated FIPS 140-3 validated key management appliance. Which of the following storage security solutions best meets these requirements?
A network security analyst investigating connectivity issues on a corporate subnet captures traffic from an interface receiving anomalous activity. Packet inspection reveals thousands of broadcast DHCPDISCOVER requests sent within a 10-second window, each specifying a unique, randomized client hardware MAC address. As a result, legitimate clients on the network are receiving IP address APIPA configurations due to scope exhaustion. Which of the following attack indicators is described in this scenario?