All practice questions
2232 questions
A security analyst receives a high-fidelity Endpoint Detection and Response (EDR) alert indicating that a web service process on a critical Linux server is executing unauthorized shell commands and attempting outbound command-and-control communications. The analyst must contain the threat immediately to prevent lateral movement while preserving volatile memory and maintaining an administrative management channel to the host. Which of the following is the most appropriate action to take using the EDR console?
During a security review of a cloud-hosted feedback portal, an analyst discovers that user comments submitted to the support forum are stored in the application database without sanitization. When an administrator views the support dashboard, script tags embedded inside user comments execute within the administrator's browser session, attempting to transmit session tokens to an external host.
Which of the following correctly identifies the vulnerability type demonstrated in this incident and the most effective code-level remediation?
A security analyst is hardening an enterprise domain environment after an internal audit revealed two critical weaknesses: unauthenticated network hosts can execute anonymous directory queries to enumerate domain user accounts, and internal authentication traffic is susceptible to credential relay attacks. Which of the following mitigation strategies should the analyst implement to address these specific vulnerabilities? (Select TWO.)
Select all that apply
A healthcare organization is updating its enterprise Identity and Access Management (IAM) architecture to support dynamic, fine-grained access control across decoupled microservices. The security team requires a centralized component that evaluates contextual attributes—such as user role, device posture, time of day, and resource sensitivity—against security policies to issue an authorization decision for each access request. Which architectural component directly performs this policy evaluation to determine whether access should be granted?
A digital forensics investigator is preparing to capture a bit-stream copy of a seized hard drive recovered from an employee's computer during an insider threat investigation. To ensure that the physical drive's original data remains unmodified and that the acquired evidence is legally admissible, which of the following procedures must the investigator implement prior to starting the imaging process?
A Security Operations Center (SOC) team receives an automated alert generated by their Security Information and Event Management (SIEM) system regarding suspicious outbound traffic from host IP 10.10.4.15. The team pulls the following correlated telemetry logs:
[Sysmon Event ID 22 - DNS Query]
ProcessImage: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
QueryName: aW50ZXJuYWwtZGF0YS0wMQ.exfil.attacker-domain.com
QueryStatus: 0 (SUCCESS)
[Perimeter Firewall Egress Log]
SrcIP: 10.10.4.15 | DstIP: 198.51.100.45 | DstPort: 53 | Protocol: UDP | Action: ALLOWED | BytesSent: 1420
[SIEM Correlation Engine Alert]
Rule_ID: RULE_DNS_HIGH_ENTROPY_SUBDOMAINS
Condition: Count(DNS_Query) > 500 per 60 seconds targeting unique high-entropy subdomains of a single domain.
Based on the log telemetry and correlation rule output, which of the following best identifies the active attack vector and the underlying operational reason it bypassed initial perimeter controls?
A logistics company is deploying telemetry edge devices on freight vehicles. To protect against unauthorized firmware tampering, the systems engineer must guarantee that the microcontroller only executes cryptographically signed boot code during power-on. Which hardware security control serves as the immutable foundation to perform this initial integrity verification?
Match each core Zero Trust Architecture (ZTA) functional component to its primary operational responsibility within an enterprise security infrastructure.
Click a left item, then click its matching right item
Items
Matches
During an ongoing incident investigation, a security analyst detects that an unauthorized rogue laptop is actively transmitting encrypted data across an internal enterprise network. According to standard incident response frameworks, which of the following actions should the analyst perform FIRST?
A cloud security architect is evaluating a high-availability strategy for a critical online payment application. The application requires near-zero Recovery Time Objective (RTO) and real-time transaction consistency across two distinct cloud regions. A system administrator proposes using asynchronous database replication paired with automated failover via DNS routing, but without implementing a third-site witness or quorum node. Which of the following risks is MOST likely to occur if a network partition isolates the primary region while servers in both regions remain fully operational?
A security engineer is conducting vulnerability scans across an enterprise hybrid cloud environment. During network-based authenticated scans of Linux server instances, the scanner continuously reports multiple critical vulnerabilities for outdated software packages. However, system administrators confirm that vendor-specific security patches were already installed via package management backporting, which updates internal code without changing upstream major version strings. Furthermore, the network scans consistently fail to capture vulnerabilities on ephemeral, short-lived container instances deployed during peak auto-scaling events. Which of the following vulnerability assessment approaches should the security engineer implement to eliminate these false positives and ensure continuous visibility into short-lived instances?
A security analyst notices suspicious process execution on a financial department workstation during an active malware outbreak. To immediately block the workstation's network communication with other internal systems while preserving the security team's remote telemetry and control channel, which of the following is the most appropriate action to take?
A Security Operations Center (SOC) analyst is reviewing raw telemetry in a SIEM console containing the following event logs from an internal DNS resolver and perimeter firewall:
2026-07-27T14:10:02Z dns-resolver named[2104]: query: 61646d696e2d70617373776f7264.exfil.external-badactor.net IN TXT + (10.0.4.15)
2026-07-27T14:10:05Z dns-resolver named[2104]: query: 636f6e666964656e7469616c3132.exfil.external-badactor.net IN TXT + (10.0.4.15)
2026-07-27T14:10:08Z perimeter-fw kernel: [DENY] SRC=10.0.4.15 DST=203.0.113.50 PROTO=TCP SPT=49210 DPT=443 SIG=DIRECT_OUTBOUND_RESTRICTED
Based on these correlated log entries, which of the following security findings are accurate? (Select TWO.)
Select all that apply
A security analyst reviews network traffic captures following reports of credential leakage on an internal subnet. The analyst observes frequent UDP port 5355 multicast traffic where an unauthenticated endpoint rapidly responds to failed host name resolution requests from legitimate clients, prompting those clients to attempt NTLMv2 authentication against the endpoint. Which of the following attack types is most directly indicated by this activity?
A security analyst receives a high-severity EDR alert indicating a fileless process injection attack targeting a critical server. To mitigate lateral movement, preserve evidence, and remediate the incident, the analyst must follow a structured EDR incident response workflow. In what order should the analyst perform the following response actions?
Drag items to arrange them in the correct order
An incident response team is performing live evidence collection on an enterprise web application server following a detected code injection attack. To preserve forensic integrity, in what sequence should the analyst collect the following data sources, ordered from most volatile to least volatile?
Drag items to arrange them in the correct order
A security analyst monitoring session logs observes multiple concurrent active sessions originating from different geographic regions for a single administrative account on an enterprise cloud portal, indicating active session hijacking. According to standard incident response playbooks, which of the following actions should the team perform immediately as part of the containment phase? (Select TWO.)
Select all that apply
A security analyst detects suspicious fileless PowerShell execution on an enterprise workstation. The analyst needs to use Endpoint Detection and Response (EDR) capabilities to respond to the incident effectively while maintaining investigation capability. Which of the following response actions are primary capabilities provided directly by an EDR platform in this scenario? (Select TWO.)
Select all that apply
An Endpoint Detection and Response (EDR) agent detects an active ransomware process attempting to encrypt files on a enterprise workstation. Place the following incident response workflow steps in the correct chronological order from first action to last action.
Drag items to arrange them in the correct order
A systems engineer is hardening enterprise endpoints, embedded controllers, and server infrastructure. Match each hardware security feature on the left with its primary operational function on the right.
Click a left item, then click its matching right item
Items
Matches