All practice questions
173 questions
An enterprise organization operating an immutable containerized infrastructure discovers a critical zero-day vulnerability in its base operating system image across multiple microservices. What is the correct chronological sequence of steps the security operations team must perform to remediate this vulnerability while maintaining configuration integrity and change control compliance?
Drag items to arrange them in the correct order
A security administrator is establishing a high-availability disaster recovery plan for a mission-critical web application. During an unrecoverable primary data center outage, administrative staff must execute a site failover to the secondary site. Place the following failover operational steps in the correct chronological sequence from first to last.
Drag items to arrange them in the correct order
A security administrator needs to apply a critical security update to enterprise web servers. What is the correct sequence of steps the administrator should follow to complete the patch management workflow?
Drag items to arrange them in the correct order
A security analyst is configuring a Security Orchestration, Automation, and Response (SOAR) playbook to automatically handle alerts triggered when a cloud IAM access key is exposed in a public repository. Arrange the automated response workflow steps into the correct chronological sequence from first step to final step.
Drag items to arrange them in the correct order
An incident response team is responding to a confirmed security incident involving unauthorized API key usage and data exfiltration from an enterprise cloud storage bucket. Place the following incident response actions in the correct sequential order from first step to last step according to standard incident response playbooks.
Drag items to arrange them in the correct order
A Security Operations Center (SOC) analyst receives an Endpoint Detection and Response (EDR) telemetry alert indicating a malicious DLL side-loading attempt on an enterprise domain controller. Arrange the standard EDR incident response steps in the correct chronological order from first to last.
Drag items to arrange them in the correct order
An enterprise security team is configuring a Just-In-Time (JIT) Privileged Access Management (PAM) workflow with short-lived ephemeral credentials for database administrators. Place the operational lifecycle steps in the correct chronological order from the initial access request through session termination.
Drag items to arrange them in the correct order
A digital forensics examiner is performing evidence collection on a powered-on enterprise server following a suspected breach. To ensure maximum preservation of transient evidence, the examiner must adhere strictly to the forensic Order of Volatility. Sequence the following evidence sources from most volatile (highest priority for acquisition) to least volatile (lowest priority for acquisition).
Drag items to arrange them in the correct order
A security engineer is configuring a SIEM collector to process raw syslog feeds from perimeter devices. Place the stages of SIEM log processing in the correct order from initial ingestion to analyst notification.
Drag items to arrange them in the correct order
A Security Operations Center (SOC) analyst receives an automated alert from a network intrusion detection system (NIDS) flagging potential command-and-control (C2) beaconing activity from an internal workstation. Place the following incident triage and response steps in the correct chronological order from first to last.
Drag items to arrange them in the correct order
A Security Operations Center (SOC) team is deploying an automated Security Orchestration, Automation, and Response (SOAR) playbook to address high-risk suspicious email reports. To prevent accidental disruption to critical business communications while ensuring rapid response, the automated response workflow must follow strict SOC governance standards spanning ingest, threat intelligence enrichment, analyst review, containment, and post-incident cleanup. In what sequence should the SOAR playbook execute these operational steps?
Drag items to arrange them in the correct order
A Security Operations Center (SOC) analyst receives an automated high-severity SIEM alert indicating suspicious outbound traffic from an internal database server containing sensitive customer records to an unknown external IP address over port 443. The analyst must follow network security monitoring and initial incident response procedures. In what chronological sequence should the analyst execute the following triage and containment actions?
Drag items to arrange them in the correct order
A security operations team is deploying a enterprise cloud application integrated with an internal Identity Provider (IdP) using SAML 2.0. Arrange the operational steps of a Service Provider-initiated (SP-initiated) Single Sign-On (SSO) authentication sequence in the correct chronological order from first to last.
Drag items to arrange them in the correct order
A security technician is documenting the standard patch deployment workflow for enterprise operating systems. Place the following stages of the patch management lifecycle in the correct order from first to last.
Drag items to arrange them in the correct order
An enterprise Endpoint Detection and Response (EDR) agent detects an unauthorized process attempting to read sensitive memory structures from the Local Security Authority Subsystem Service (LSASS) on a finance system host. In what sequence should the automated EDR response workflow process this security event from initial containment to post-incident analysis?
Drag items to arrange them in the correct order
An enterprise Security Operations Center (SOC) detects unauthorized execution of encryption software across several internal host systems. Place the following incident response playbook actions in the correct chronological order according to NIST SP 800-61 guidelines, starting from initial detection.
Drag items to arrange them in the correct order
A Security Operations Center (SOC) team is configuring an automated Security Orchestration, Automation, and Response (SOAR) playbook to handle suspicious email attachments reported by end users. Place the following playbook execution steps in the correct operational sequence from initial alert ingestion to final incident closure.
Drag items to arrange them in the correct order
A incident response analyst is performing evidence collection on a live enterprise server following an intrusion alert. According to the Order of Volatility standard, in what sequence should the analyst acquire the evidence sources, ordered from most volatile to least volatile?
Drag items to arrange them in the correct order
A security analyst is implementing an out-of-band security patch for a critical database cluster following the discovery of an actively exploited zero-day vulnerability. Arrange the following steps of the emergency patch management process in the correct sequential order from first to last.
Drag items to arrange them in the correct order
An enterprise systems administrator is troubleshooting a Kerberos authentication issue in an Active Directory environment. Place the steps of the Kerberos ticket exchange process in the correct order from initial user login to final resource access.
Drag items to arrange them in the correct order