All practice questions
2232 questions
An enterprise organization is designing a disaster recovery strategy for its critical e-commerce platform. To ensure continuous business operations, the organization requires an off-site recovery facility that is fully configured with active servers, network infrastructure, and real-time data synchronization, allowing it to immediately assume operational duties if the primary site fails. Which of the following recovery site types best satisfies these requirements?
An enterprise security team is implementing enterprise hardening practices for out-of-band management interfaces on network switches to reduce the risk of unauthorized lateral movement. Which TWO of the following technical controls should the team implement? (Select TWO.)
Select all that apply
A logistics enterprise is integrating automated freight crane telemetry sensors with its centralized monitoring dashboard. The crane control systems run legacy industrial software that cannot be patched, whereas the monitoring dashboard resides on the corporate administrative network. Which network design control best mitigates the risk of lateral threat movement from the corporate network to the crane controllers while continuing to permit automated telemetry collection?
A security team is implementing an access control model that evaluates contextual variables—such as user location, device security compliance, time of request, and resource sensitivity—before granting access. Which access control architecture model natively uses these dynamic characteristics to make authorization decisions?
An organization is deploying a multi-tenant cloud platform where microservices processing sensitive financial records will run alongside third-party analytics services on the same physical host node. The software engineering team proposes relying solely on standard Linux container runtime features, claiming that container namespaces provide security boundary isolation identical to dedicated virtual machines on a Type-1 hypervisor. Which of the following statements best describes the primary security risk associated with this deployment architecture?
A security analyst is conducting a vulnerability assessment on a company's web portal source code and server logs. The audit identifies that input from a search field is concatenated directly into a backend database statement without input sanitization. Additionally, users can view arbitrary account records by modifying the user ID parameter in the HTTP GET request line because server-side authorization validation is absent. Which of the following application vulnerabilities are present in this scenario? (Select TWO.)
Select all that apply
A security handler confirms that a cloud administrator host is actively exporting database backups to an unapproved external storage endpoint using hijacked API credentials. Following standard incident response procedures, which of the following actions should the security handler take FIRST?
Match each storage security technology on the left with its primary enterprise implementation role on the right.
Click a left item, then click its matching right item
Items
Matches
A security analyst is investigating a high-fidelity SIEM alert generated from cloud infrastructure audit logs. The analyst retrieves the following sequential log events originating from external IP address 198.51.100.4:
text
2026-06-14T09:12:01Z cloudtrail: User="j.smith" Event="ConsoleLogin" Status="Failure" SourceIP="198.51.100.4"
2026-06-14T09:12:03Z cloudtrail: User="m.davis" Event="ConsoleLogin" Status="Failure" SourceIP="198.51.100.4"
2026-06-14T09:12:05Z cloudtrail: User="a.wilson" Event="ConsoleLogin" Status="Failure" SourceIP="198.51.100.4"
2026-06-14T09:12:10Z cloudtrail: User="r.taylor" Event="ConsoleLogin" Status="Success" SourceIP="198.51.100.4"
2026-06-14T09:12:18Z cloudtrail: User="r.taylor" Event="CreateAccessKey" Status="Success" SourceIP="198.51.100.4"
Based on these log entries, which of the following security events has occurred?
A security analyst is evaluating packet captures and log entries following a network intrusion alert. Match each observed technical indicator to its corresponding network or wireless attack classification.
Click a left item, then click its matching right item
Items
Matches
A security operations team responds to an active breach involving a malicious third-party OAuth application that gained consent to access executive mailboxes in a cloud SaaS environment. The application is actively exporting sensitive financial emails via automated API calls. According to standard incident response playbooks for cloud containment, which TWO of the following actions should the team perform immediately? (Select TWO.)
Select all that apply
A healthcare organization is deploying a patient engagement application using virtual machine instances hosted on an Infrastructure as a Service (IaaS) cloud platform. The security architect is defining the operational security responsibilities between the organization and the cloud service provider (CSP). According to the cloud shared responsibility model, which of the following tasks is the sole responsibility of the customer?
A systems administrator is configuring a critical database server to eliminate single points of failure at both the power source and internal storage levels. Which of the following hardware and physical redundancy solutions directly satisfy these resilience requirements? (Select TWO.)
Select all that apply
Place the core stages of the Security Information and Event Management (SIEM) log processing pipeline in the correct sequential order from initial intake to analyst notification.
Drag items to arrange them in the correct order
During a routine traffic audit of an enterprise perimeter router, a security team examines the following network telemetry log generated by a passive Network Security Monitoring (NSM) sensor inspecting outbound UDP traffic:
Timestamp: 2026-07-27T14:22:01Z
Sensor_ID: NSM-PERIMETER-02
Src_IP: 10.4.18.99 (Internal Workstation)
Dst_IP: 198.51.100.45 (External Name Server)
Proto/Port: UDP/53
Query_Type: TXT
Query_String: a1b2c3d4e5f67890abcdef1234567890.sub.exfil-domain.example
Packet_Count: 14,250 queries/5 min
Avg_Payload_Size: 480 bytes
Which of the following is the most accurate assessment of the threat indicated by this alert and the security operational classification of the sensor mechanism?
An incident response team is executing a playbook following the detection of an active unauthorized remote access Trojan on an enterprise workstation. Which of the following actions represent appropriate steps to take specifically during the containment phase of the incident response lifecycle? (Select TWO.)
Select all that apply
An organization is updating its enterprise security architecture to streamline user access across external cloud applications. The security team needs to implement standards that support federated single sign-on (SSO) and automated account lifecycle management between the corporate identity provider and SaaS platforms. Which TWO of the following open standards should the team integrate into the IAM architecture to fulfill these specific requirements?
Select all that apply
A security architect is establishing high availability and resilience specifications for a mission-critical infrastructure deployment. Match each resiliency requirement or architectural challenge on the left with its corresponding technical mechanism or metric on the right.
Click a left item, then click its matching right item
Items
Matches
A security analyst investigating a cloud-hosted infrastructure detects that an OAuth 2.0 refresh token assigned to an automated microservice was compromised. Real-time monitoring confirms an unauthorized external entity is actively exploiting this token to execute bulk queries and exfiltrate sensitive financial records from a database endpoint. According to standard incident response lifecycle frameworks, which of the following represents the IMMEDIATE next step the incident response team should take?
An enterprise security architect is evaluating modern Identity and Access Management (IAM) controls to enforce Zero Trust principles and streamline federated access across a multi-cloud enterprise. Match each identity architecture protocol or mechanism on the left to its corresponding architectural implementation on the right.
Click a left item, then click its matching right item
Items
Matches