All practice questions
2232 questions
An enterprise security organization is restructuring its internal governance documentation to align with ISO/IEC 27001 and NIST SP 800-53 standards. Match each formal security governance document type to the specific operational characteristic and enforcement authority that defines its role in the security program.
Click a left item, then click its matching right item
Items
Matches
A Security Operations Center (SOC) analyst receives an automated alert from a network intrusion detection system (NIDS) flagging potential command-and-control (C2) beaconing activity from an internal workstation. Place the following incident triage and response steps in the correct chronological order from first to last.
Drag items to arrange them in the correct order
During security monitoring of an enterprise cloud environment, an automated alert flags an unauthorized microservice container actively establishing encrypted outbound connections to an external command-and-control (C2) server. Security analysts verify that the container is compromised and holds active database connection tokens. According to standard incident response frameworks, which of the following actions should the security team perform FIRST?
An enterprise system administrator identifies suspicious administrative tool execution on a human resources endpoint. EDR telemetry reports that an unauthorized process is actively attempting lateral movement across internal subnets using compromised domain credentials. Which of the following actions should the security engineer take FIRST using the EDR platform to stop the attack while maintaining investigation capabilities?
A security analyst is conducting live evidence acquisition on a compromised application server following a suspected data exfiltration attempt. The analyst needs to preserve network statistics, system RAM, swap space, and non-volatile storage while minimizing data alteration. According to the standard order of volatility, which of the following evidence types should the analyst acquire FIRST?
A security engineer analyzing packet telemetry from an inline Network Intrusion Prevention System (NIPS) notices a high-priority alert triggered by inbound traffic directed at a public-facing web server. The alert details contain the following HTTP payload snippet:
`GET /catalog.php?item_id=105%27%20UNION%20SELECT%20null,username,password_hash%20FROM%20user_credentials--%20HTTP/1.1`
`Host: portal.example.com`
The engineer must select a targeted mitigation control that specifically blocks this attack payload while preserving uninterrupted HTTP/HTTPS access for legitimate users. Which of the following actions should the engineer take?
An organization discovers that an old standalone web server running a critical legacy service contains severe unpatchable vulnerabilities. To eliminate the threat of an external remote compromise entirely, the security team decides to shut down and permanently decommission the server without replacing its function. Which risk response strategy has the organization applied?
A Security Operations Center (SOC) team is deploying an automated Security Orchestration, Automation, and Response (SOAR) playbook to address high-risk suspicious email reports. To prevent accidental disruption to critical business communications while ensuring rapid response, the automated response workflow must follow strict SOC governance standards spanning ingest, threat intelligence enrichment, analyst review, containment, and post-incident cleanup. In what sequence should the SOAR playbook execute these operational steps?
Drag items to arrange them in the correct order
A Security Operations Center (SOC) analyst receives an automated high-severity SIEM alert indicating suspicious outbound traffic from an internal database server containing sensitive customer records to an unknown external IP address over port 443. The analyst must follow network security monitoring and initial incident response procedures. In what chronological sequence should the analyst execute the following triage and containment actions?
Drag items to arrange them in the correct order
A security architect is designing an authentication and authorization framework for a newly developed microservices-based web application. The architectural design requires a lightweight, stateless mechanism to securely transport identity claims and delegated authorization scopes between independent API endpoints without maintaining server-side session state or performing repeated directory database lookups for each call. Which of the following IAM standards should the architect implement?
A security operations team is deploying a enterprise cloud application integrated with an internal Identity Provider (IdP) using SAML 2.0. Arrange the operational steps of a Service Provider-initiated (SP-initiated) Single Sign-On (SSO) authentication sequence in the correct chronological order from first to last.
Drag items to arrange them in the correct order
A cloud-native enterprise operates a core microservices infrastructure valued at . Threat intelligence data indicates that a catastrophic ransomware compromise occurs once every years (), resulting in a operational loss per incident (). The Chief Information Security Officer (CISO) is evaluating an automated endpoint detection and response (EDR) platform costing annually. If deployed, the EDR solution will mitigate the incident impact, reducing the Exposure Factor to () while the occurrence rate remains unchanged. Based on quantitative risk assessment principles, what is the net annual financial benefit of implementing the proposed EDR platform?
A Security Operations Center (SOC) analyst receives a high-severity alert from an enterprise Endpoint Detection and Response (EDR) platform. Telemetry indicates an unprivileged user account initiated a obfuscated command execution that attempted process injection into `lsass.exe` and established an encrypted outbound connection to an untrusted external IP address. Which TWO of the following actions represent capabilities native to an EDR solution that the analyst should execute to contain the threat and facilitate analysis?
Select all that apply
A security technician is deploying monitoring sensors across an enterprise network. Which of the following statements correctly describe the features and operational behavior of a passive Network Intrusion Detection System (NIDS)? (Select TWO.)
Select all that apply
A security technician is documenting the standard patch deployment workflow for enterprise operating systems. Place the following stages of the patch management lifecycle in the correct order from first to last.
Drag items to arrange them in the correct order
A security analyst reviews a network security monitoring alert generated by a Network Intrusion Detection System (NIDS). The alert log highlights the following HTTP GET parameter string:
`GET /login.php?username=admin'%20OR%20'1'='1'-- HTTP/1.1`
Which of the following best identifies the type of malicious activity captured in this alert?
During an on-site physical security review of a remote branch office, a security analyst discovers an unauthorized rogue wireless access point plugged into an active wall jack. The rogue device is actively broadcasting a duplicate corporate SSID to intercept wireless client credentials. Following standard incident response playbooks, which of the following immediate containment actions should the incident response team perform? (Select TWO.)
Select all that apply
An organization relies on an Operational Technology (OT) supervisory control and data acquisition (SCADA) system valued at . Historical threat assessments indicate that an unmitigated industrial ransomware attack has an Exposure Factor (EF) of () and an Annualized Rate of Occurrence (ARO) of ( event every years).
To mitigate this risk, the security team proposes deploying an immutable network air-gap and anomaly monitoring safeguard with an annual operating cost of . With this safeguard active, the EF is reduced to () and the ARO is reduced to ( event every years).
What is the net annual cost savings (in USD) achieved by implementing this safeguard?
Security telemetry on a corporate workstation detects a suspicious living-off-the-land binary attempting to dump process memory and establish outbound command-and-control communication. Which feature of an Endpoint Detection and Response (EDR) agent should be executed FIRST to prevent potential lateral movement while preserving remote investigation capabilities?
An enterprise security manager is reviewing the risk register for an unpatchable legacy portal hosting sensitive customer records. To address the vulnerability, the organization decides to decommission the portal entirely and transition users to an enterprise platform. Additionally, to mitigate residual financial risk during the data migration phase, the organization purchases a cybersecurity liability policy. Which of the following risk response strategies are being directly implemented in this scenario? (Select TWO.)
Select all that apply