All practice questions
2232 questions
A security analyst is conducting a routine audit of Identity and Access Management (IAM) operational logs following an employee offboarding procedure. The log analysis reveals that an offboarded engineer's primary user account was disabled in Active Directory immediately upon termination. However, three days later, successful interactive logins were recorded on several internal servers using a secondary administrative account assigned to the same individual. Which of the following identity management operational failures is the MOST likely root cause of this security gap?
Match each enterprise identity and access management (IAM) architectural component on the left to its primary functional responsibility on the right.
Click a left item, then click its matching right item
Items
Matches
An enterprise security team is configuring a Just-In-Time (JIT) Privileged Access Management (PAM) workflow with short-lived ephemeral credentials for database administrators. Place the operational lifecycle steps in the correct chronological order from the initial access request through session termination.
Drag items to arrange them in the correct order
A digital forensics examiner is performing evidence collection on a powered-on enterprise server following a suspected breach. To ensure maximum preservation of transient evidence, the examiner must adhere strictly to the forensic Order of Volatility. Sequence the following evidence sources from most volatile (highest priority for acquisition) to least volatile (lowest priority for acquisition).
Drag items to arrange them in the correct order
A security operations team discovers that critical production servers frequently experience configuration drift due to uncoordinated hotfixes applied by system administrators during emergency outage incidents. Although automated configuration auditing tools successfully flag these non-compliant system states during nightly scans, security engineers cannot readily distinguish between unauthorized vulnerabilities and approved emergency hotfixes. Which of the following solutions should the security team implement to effectively manage configuration drift while maintaining audit compliance for emergency changes?
A chief information security officer (CISO) is evaluating a proposed security safeguard for an enterprise web application valued at . Threat intelligence and audit history indicate an Annual Rate of Occurrence () of for major security breach attempts, with a current Exposure Factor () of . The proposed security control requires an annual subscription and maintenance cost of and is projected to reduce the Exposure Factor () to , while the remains unchanged. What is the net annual financial benefit of implementing this safeguard?
A security engineer is refining the vulnerability assessment strategy for an enterprise data center hosting high-availability web applications and legacy backend databases. To ensure deep asset visibility while mitigating the risk of service disruption and unauthorized network impact, which of the following operational practices should the engineer implement? (Select TWO.)
Select all that apply
A security engineer is configuring a SIEM collector to process raw syslog feeds from perimeter devices. Place the stages of SIEM log processing in the correct order from initial ingestion to analyst notification.
Drag items to arrange them in the correct order
An enterprise incident response team is evaluating a newly deployed Security Orchestration, Automation, and Response (SOAR) playbook intended to contain compromised systems. The playbook automatically executes a script that isolates host network interfaces upon receiving high-severity endpoint alerts. Security engineers are concerned that automated execution against critical infrastructure, such as domain controllers or primary database hosts, could cause severe business disruptions in the event of a false positive. Which of the following workflow modifications best mitigates this risk while preserving automated containment capabilities for standard endpoints?
An enterprise security policy requires that any unauthorized changes to server system configurations are automatically detected and restored to a pre-approved security state. Which of the following operational controls best meets this requirement?
An e-commerce enterprise hosts a customer transaction database valued at $500,000. Security metrics indicate that a successful SQL injection attack has an Exposure Factor (EF) of 0.15, and threat intelligence data estimates the Annualized Rate of Occurrence (ARO) for this threat vector to be 0.40. What is the Annualized Loss Expectancy (ALE) in dollars for this database asset?
A security administrator is reviewing high-availability cluster resilience and failover mechanisms for mission-critical enterprise services. Match each clustering component or condition on the left with its corresponding operational definition or control mechanism on the right.
Click a left item, then click its matching right item
Items
Matches
A security administrator is establishing standard operating procedures for system maintenance across enterprise servers. Which of the following actions should be performed prior to deploying software patches to live production servers? (Select TWO)
Select all that apply
An organization evaluates the risk of a critical power surge affecting an off-site infrastructure facility housing archival data servers valued at EF = 0.40 ARO = 0.25$). What is the Annual Loss Expectancy (ALE) for this server infrastructure?
A security operations team is configuring an automated Security Orchestration, Automation, and Response (SOAR) workflow to handle initial triage and containment for incoming high-severity suspicious email alerts. Which of the following tasks represent safe, effective automated steps to include in the initial playbook execution prior to analyst review? (Select TWO.)
Select all that apply
Match each security governance document type on the left with its corresponding characteristic on the right.
Click a left item, then click its matching right item
Items
Matches
Following a third-party compliance audit that highlighted inconsistent multi-cloud storage configurations, an enterprise Chief Information Security Officer (CISO) publishes a high-level organizational mandate requiring all data at rest containing non-public personal information (NPI) to be protected with strong cryptographic controls. To translate this high-level directive into mandatory, non-negotiable operational requirements for deployment pipelines across all engineering units, the security governance committee drafts a document specifying exact encryption algorithms (AES-256), mandatory key rotation schedules (every 90 days), and rigid access control lists. Which document type in the security governance hierarchy is the committee publishing to establish these mandatory technical specifications?
An enterprise security manager issues a document detailing the specific, mandatory step-by-step technical instructions that system administrators must execute when hardening a newly deployed Linux web server. Which type of security governance document has the manager published?
A systems administrator deploys a lightweight host-based agent across a fleet of Linux web servers to perform continuous vulnerability assessment. During an audit, the agent flags several critical local kernel vulnerabilities requiring remediation. However, a subsequent uncredentialed network-based vulnerability scan targeting the public IP addresses of these same web servers fails to detect any of the reported kernel flaws. Which of the following best explains why the network vulnerability scan missed these kernel vulnerabilities?
A Security Operations Center (SOC) analyst is reviewing alerts generated by a SIEM correlation rule designed to flag potential credential harvesting activity. Within a five-minute window, a standard domain user workstation generated multiple instances of the following Windows Security Event log entry:
Event ID: 4769
Task Category: Kerberos Service Ticket Operations
TargetUserName: [email protected]
Service Name: MSSQLSvc/db01.contoso.com:1433
Ticket Options: 0x40810000
Ticket Encryption Type: 0x17
Failure Code: 0x0
Client Address: ::ffff:192.168.10.115
Based on this log telemetry, which of the following security events is occurring?