All practice questions
2232 questions
A network architect is designing a high-availability edge network infrastructure for a regional operational facility. The architecture must ensure continuous default gateway availability for local internal hosts and dynamic, redundant routing across two independent upstream Internet Service Providers (ISPs). Which of the following resilience mechanisms should the architect deploy to fulfill these requirements? (Select TWO.)
Select all that apply
A network administrator receives alerts regarding unauthorized network configuration changes on several enterprise workstations. Inspection of client packet captures reveals that the affected systems received IP configuration leases containing an unexpected primary DNS server address () and default gateway, originating from an unrecognized device sending unauthorized DHCPACK messages on the local subnet. Which of the following attacks is indicated by these symptoms?
During an security incident, an incident response team has successfully isolated an infected enterprise application server from the internal network. According to standard incident response lifecycle frameworks, which of the following actions represents the primary goal of the eradication phase?
A security administrator wants to collect continuous host-level telemetry, such as process creation events, registry modifications, and network connections, to detect fileless malware and zero-day threats in real time across corporate workstations. Which of the following security solutions best fulfills this requirement?
During a security posture review of a enterprise cloud infrastructure, an audit reveals that newly provisioned virtual machine instances frequently drift from established secure configuration baselines over time due to manual administrator modifications and unapproved emergency changes. Which enterprise hardening practice provides the MOST effective mechanism to continuously prevent and remediate host baseline configuration drift across all deployed instances?
During an ongoing security breach, an Incident Response Team (IRT) identifies that an attacker has gained access to internal endpoints using harvested domain administrator credentials and is actively attempting lateral movement across enterprise network segments via pass-the-ticket techniques. Which of the following containment actions should the IRT execute IMMEDIATELY to stop ongoing lateral movement while preserving evidence integrity? (Select TWO.)
Select all that apply
An enterprise security architecture team is categorizing identity standards and protocols for a multi-cloud infrastructure deployment. Match each Identity and Access Management (IAM) protocol or standard on the left to its corresponding architectural use case on the right.
Click a left item, then click its matching right item
Items
Matches
An incident response team is preparing to collect evidence from a physical storage drive recovered during an investigation. To ensure that the drive's contents cannot be altered or modified by the operating system while creating a forensic bit-stream image, which of the following tools should the technician use to connect the drive to the workstation?
During a physical security audit at a remote branch office, a security analyst discovers an unauthorized rogue wireless access point connected directly to a network switch port. The rogue device is broadcasting an unencrypted SSID and bridging external wireless traffic directly into the internal corporate network segment. According to standard incident response frameworks, which of the following actions should the analyst perform FIRST?
An application developer is reviewing security logs following an incident where a backend microservice was compromised. The investigation reveals that an external attacker submitted a base64-encoded serialized object within an HTTP header, triggering execution of arbitrary system commands on the hosting server. Which of the following vulnerabilities was exploited, and what is the most effective code-level remediation to prevent future occurrences?
Match each vulnerability scanning concept on the left with its corresponding operational description on the right.
Click a left item, then click its matching right item
Items
Matches
An enterprise Security Operations Center (SOC) detects abnormal outbound DNS traffic indicating potential data exfiltration via DNS tunneling from an internal host. Place the incident response actions in the correct chronological order according to standard NIST incident handling guidelines, starting from the initial response through completion.
Drag items to arrange them in the correct order
A software enterprise is redesigning access controls for its third-party developer API integration portal. Currently, after external developers authenticate through a legacy VPN connection, their sessions are implicitly trusted across internal staging systems. The enterprise wants to modernize this architecture to align with Zero Trust Architecture (ZTA) principles. Which of the following strategies best implements Zero Trust for these third-party developer connections?
An incident response team is conducting live digital evidence acquisition on a compromised enterprise gateway server suspected of hosting an active in-memory exploit. Based on the RFC 3227 standard Order of Volatility, in what sequence should the forensic investigator capture the following digital evidence components, starting from the most volatile to the least volatile?
Drag items to arrange them in the correct order
A digital forensics analyst receives a seized external hard drive transported from a field office via a secure courier. Upon intake, the analyst notices that the tamper-evident transport bag was torn and the accompanying paper tracking form lacks the courier's transfer signature. Before connecting the drive to a hardware write-blocker for imaging, which of the following actions MUST the analyst perform first to maintain evidentiary standards?
A security analyst is investigating network and wireless security alerts recorded in an enterprise environment. Match each observed technical attack indicator on the left with its corresponding attack classification on the right.
Click a left item, then click its matching right item
Items
Matches
A security administrator is evaluating Endpoint Detection and Response (EDR) software to upgrade workstation security across an enterprise environment. Which of the following capabilities are primary features provided by EDR solutions? (Select TWO.)
Select all that apply
An incident response team is performing live digital evidence acquisition on a compromised enterprise application server following a detected in-memory code injection attack. To ensure dynamic evidence is captured before it is lost or modified, the forensic investigator must collect data strictly according to the standard Order of Volatility. Place the following digital evidence sources in the correct order of acquisition, from MOST volatile (acquired first) to LEAST volatile (acquired last).
Drag items to arrange them in the correct order
During a routine audit, a Security Operations Center (SOC) analyst detects an unauthorized rogue wireless access point bridged directly into an isolated network segment containing sensitive customer databases. Forensic monitoring confirms that an external threat actor is actively exfiltrating live database traffic across this rogue wireless link. According to standard incident response lifecycle frameworks, which of the following actions should the incident response team perform FIRST?
A cybersecurity analyst is investigating an active fileless malware infection on a host machine operating multiple virtualized enterprise services. The analyst must capture digital evidence in strict compliance with the Order of Volatility while maintaining chain of custody standards for legal admissibility. Which of the following procedures should the analyst execute FIRST?