All practice questions
173 questions
An incident response team is conducting live digital forensics on a powered-up enterprise database server experiencing active kernel-level malware execution and network exfiltration. To prevent the loss of critical evidence during acquisition, in what exact sequence should the investigator collect the following digital evidence sources, starting with the MOST volatile source and ending with the LEAST volatile source?
Drag items to arrange them in the correct order
A security architect is configuring a zero-trust network ingress path for an administrator connecting remotely to a sensitive database in an isolated zone. Arrange the operational steps for establishing this administrative session in the correct chronological sequence, from initial external initiation to final host authorization.
Drag items to arrange them in the correct order
An enterprise Incident Response Team (IRT) detects unauthorized DNS redirection caused by ARP cache poisoning on a critical core network segment. According to standard NIST SP 800-61 incident response frameworks, in what order should the incident response team execute the following operational response steps?
Drag items to arrange them in the correct order
A Security Operations Center (SOC) team is configuring an automated Endpoint Detection and Response (EDR) incident response workflow to handle host-based malicious script execution. In what sequence should the EDR platform execute the containment, mitigation, and post-incident investigation actions?
Drag items to arrange them in the correct order
Following an EDR telemetry alert indicating an active credential-harvesting attempt on a Windows domain controller, a SOC analyst must execute an incident response procedure. In what sequence should the analyst execute the following actions to effectively contain the threat, preserve evidence, and remediate the endpoint?
Drag items to arrange them in the correct order
An incident responder is preparing to collect digital evidence from a powered-on corporate workstation suspected of compromise. According to standard forensic evidence collection guidelines (Order of Volatility), in what sequence should the responder capture the following components, from MOST volatile to LEAST volatile?
Drag items to arrange them in the correct order
An enterprise Security Operations Center (SOC) detects abnormal outbound DNS traffic indicating potential data exfiltration via DNS tunneling from an internal host. Place the incident response actions in the correct chronological order according to standard NIST incident handling guidelines, starting from the initial response through completion.
Drag items to arrange them in the correct order
An incident response team is conducting live digital evidence acquisition on a compromised enterprise gateway server suspected of hosting an active in-memory exploit. Based on the RFC 3227 standard Order of Volatility, in what sequence should the forensic investigator capture the following digital evidence components, starting from the most volatile to the least volatile?
Drag items to arrange them in the correct order
An incident response team is performing live digital evidence acquisition on a compromised enterprise application server following a detected in-memory code injection attack. To ensure dynamic evidence is captured before it is lost or modified, the forensic investigator must collect data strictly according to the standard Order of Volatility. Place the following digital evidence sources in the correct order of acquisition, from MOST volatile (acquired first) to LEAST volatile (acquired last).
Drag items to arrange them in the correct order
A security analyst receives a high-severity EDR alert indicating a fileless process injection attack targeting a critical server. To mitigate lateral movement, preserve evidence, and remediate the incident, the analyst must follow a structured EDR incident response workflow. In what order should the analyst perform the following response actions?
Drag items to arrange them in the correct order
An incident response team is performing live evidence collection on an enterprise web application server following a detected code injection attack. To preserve forensic integrity, in what sequence should the analyst collect the following data sources, ordered from most volatile to least volatile?
Drag items to arrange them in the correct order
An Endpoint Detection and Response (EDR) agent detects an active ransomware process attempting to encrypt files on a enterprise workstation. Place the following incident response workflow steps in the correct chronological order from first action to last action.
Drag items to arrange them in the correct order
An enterprise Security Information and Event Management (SIEM) pipeline is being configured to ingest, analyze, and respond to authentication anomalies across a hybrid environment. Place the following stages of the SIEM log processing pipeline in the correct sequential order from initial endpoint activity to final incident response.
Drag items to arrange them in the correct order
An organization discovers that an exposed API key associated with a cloud storage container was leaked on a public repository, allowing unauthorized external downloading of sensitive customer backups. Place the following incident response workflow steps in the correct chronological order according to standard incident handling frameworks.
Drag items to arrange them in the correct order
A security administrator is establishing a SIEM log handling pipeline for enterprise endpoint and network telemetry. Place the following stages of SIEM log processing in the correct sequential order, starting from the initial arrival of raw security telemetry to final analyst notification.
Drag items to arrange them in the correct order
A security analyst is establishing the standard administrative workflow for user onboarding and offboarding within an enterprise Identity and Access Management (IAM) system. Place the following identity lifecycle steps in the correct chronological order from first to last.
Drag items to arrange them in the correct order
A Security Operations Center (SOC) analyst receives an active EDR telemetry alert indicating that a Windows workstation is executing malicious code via a Living-off-the-Land (LotL) binary. Place the following Endpoint Detection and Response (EDR) containment and incident handling actions in the correct chronological order from first step to last step.
Drag items to arrange them in the correct order
A security operations team is implementing Just-In-Time (JIT) access controls within a Privileged Access Management (PAM) framework to reduce standing administrative privileges. Place the operational steps of a JIT privileged access session lifecycle in the correct sequential order from start to finish.
Drag items to arrange them in the correct order
A Security Operations Center (SOC) analyst detects an unauthorized third-party integration added to an enterprise cloud tenant, followed by bulk exfiltration of sensitive email records via an exposed OAuth 2.0 token. According to standard incident response frameworks, in what sequence should the IR team execute the following response and recovery steps?
Drag items to arrange them in the correct order
During a security event, an Endpoint Detection and Response (EDR) agent deployed on a critical file server detects suspicious rapid file modification patterns consistent with ransomware activity. Arrange the following EDR incident containment and response steps in the correct sequential order from first to last.
Drag items to arrange them in the correct order