All practice questions
2232 questions
An enterprise Security Operations Center (SOC) detects unauthorized execution of encryption software across several internal host systems. Place the following incident response playbook actions in the correct chronological order according to NIST SP 800-61 guidelines, starting from initial detection.
Drag items to arrange them in the correct order
A security administrator needs to ensure that all newly deployed enterprise servers strictly adhere to a standardized, hardened set of initial operational settings prior to production release. Which of the following should the administrator implement to establish these standardized settings?
A network security analyst is reviewing real-time alert logs from a Network Intrusion Detection System (NIDS). The analyst spots an alert flagging an HTTP GET request containing the following parameter string: GET /products.php?id=1%20UNION%20SELECT%20username,%20password%20FROM%20users--. Which of the following attack types has been detected by this monitoring alert?
A Security Operations Center (SOC) team is configuring an automated Security Orchestration, Automation, and Response (SOAR) playbook to handle suspicious email attachments reported by end users. Place the following playbook execution steps in the correct operational sequence from initial alert ingestion to final incident closure.
Drag items to arrange them in the correct order
During a security evaluation of a segmented payment processing environment, an analyst runs an automated vulnerability assessment against a cluster of Linux servers holding cardholder data. The final report lists open network ports and service banners, but fails to identify installed software patch levels or local kernel flaws. Further inspection reveals that administrative SSH credentials were properly entered into the scanner configuration, but network access control lists blocked SSH protocol traffic while permitting HTTPS traffic between the scanner and targets. Which of the following best accounts for the missing host-level vulnerability data in the final report?
A healthcare organization is conducting a quantitative risk assessment for its primary electronic health record (EHR) database cluster, valued at . Threat intelligence data indicates that a major ransomware breach has an Annual Rate of Occurrence (ARO) of with an Exposure Factor (EF) of . To mitigate this risk, the organization evaluates an automated air-gapped immutable backup vault with an annual operating cost of . This safeguard will reduce the system's Exposure Factor to while keeping the ARO unchanged. Based on a quantitative risk analysis, what is the net annual financial benefit of implementing this safeguard?
A security analyst is reviewing correlated events in a SIEM console generated from cloud audit logs:
text
[2026-07-27T10:14:22Z] AWS CloudTrail: eventName=ConsoleLogin, userIdentity=arn:aws:iam::123456789012:user/jdoe, sourceIPAddress=198.51.100.45, responseElements={ConsoleLogin=Success}, additionalEventData={MFAUsed=No}
[2026-07-27T10:14:25Z] AWS CloudTrail: eventName=CreateAccessKey, userIdentity=arn:aws:iam::123456789012:user/jdoe, sourceIPAddress=198.51.100.45, responseElements={accessKey={accessKeyId=AKIAIOSFODNN7EXAMPLE}}
[2026-07-27T10:15:01Z] AWS CloudTrail: eventName=DescribeInstances, userIdentity=arn:aws:iam::123456789012:user/jdoe, sourceIPAddress=203.0.113.88, userAgent=aws-cli/2.11.0
Based on the log sequence provided, which of the following conclusions and immediate mitigation steps are correct? (Select TWO.)
Select all that apply
An organization is establishing a direct, dedicated network connection between its data center and a business partner's network to exchange sensitive data continuously. Which of the following agreements specifically documents the technical security requirements, encryption controls, and interface parameters for this direct connection?
An enterprise security architect is designing an Identity and Access Management (IAM) architecture for a hybrid enterprise environment. To align with modern Zero Trust principles, the system must evaluate real-time context—such as user risk score, device compliance state, and access location—before granting access to sensitive cloud databases, rather than trusting users based on network location. Which architectural component in this framework is directly responsible for evaluating these dynamic context attributes against enterprise security policies to render an access decision?
Match each security governance document type to its corresponding operational characteristic within an enterprise governance framework.
Click a left item, then click its matching right item
Items
Matches
An analyst is configuring an automated Security Orchestration, Automation, and Response (SOAR) playbook to respond to API token abuse detected by a SIEM. The playbook must automatically mitigate active malicious access while minimizing operational disruption to critical cloud workloads. Which of the following automated actions should be incorporated into the playbook containment workflow? (Select TWO.)
Select all that apply
A healthcare organization is conducting a quantitative risk assessment on an unencrypted portable diagnostic platform. The total asset value (), including sensitive data asset valuation and regulatory non-compliance exposure, is estimated at . Security metrics indicate that a single breach incident would impact of the asset's total value (). Historical threat intelligence indicates that this specific type of breach occurs once every years ().
What is the Annual Loss Expectancy () in dollars associated with this security risk?
A incident response analyst is performing evidence collection on a live enterprise server following an intrusion alert. According to the Order of Volatility standard, in what sequence should the analyst acquire the evidence sources, ordered from most volatile to least volatile?
Drag items to arrange them in the correct order
An IT manager wants to issue recommendations and practical advice to help remote employees secure their home Wi-Fi networks. The document provides optional best practices rather than mandatory operational requirements. Which type of security governance document should the IT manager publish?
A security analyst is implementing an out-of-band security patch for a critical database cluster following the discovery of an actively exploited zero-day vulnerability. Arrange the following steps of the emergency patch management process in the correct sequential order from first to last.
Drag items to arrange them in the correct order
An enterprise cloud security engineering team is updating its operational documentation following a compliance review. Executive leadership has already established an overarching Information Security Policy mandating baseline security hygiene and risk minimization across all enterprise workloads. To operationalize this directive for system deployments, the team needs to publish a document detailing the mandatory minimum security configuration parameters—such as specific SSH cipher suites, disabled unneeded services, and firewall rule defaults—that every Linux virtual machine must satisfy before launch. Which of the following governance document types should the team publish to establish these minimum configuration requirements?
An enterprise organization is conducting a third-party risk assessment of a key managed service provider (MSP). The security evaluation reveals that the MSP routes sensitive telemetry data over a dedicated, persistent network connection to a secondary facility operated by a fourth-party subcontractor. The enterprise security manager requires the technical security controls, data encryption rules, and interface boundaries for this specific direct network connection to be formally documented and enforced. Which of the following agreements should be established between the MSP and the fourth-party provider to meet this requirement?
An organization is preparing to onboard a new software-as-a-service (SaaS) vendor to process sensitive financial records. Which of the following activities are essential steps in performing third-party risk management and supply chain oversight during vendor assessment? (Select TWO).
Select all that apply
During routine operational monitoring of a Linux web application server hosting a customer portal, a security analyst identifies an unauthorized web shell script placed in the web root. Log entries confirm an external attacker is currently executing remote commands through the web shell to perform local privilege escalation. According to standard incident response procedures, which of the following actions should the security analyst take FIRST?
An organization is evaluating a security safeguard for a facility control system valued at ARO = 0.20 EF 7,000, which will reduce the post-control Exposure Factor to 5% while keeping the ARO unchanged. What is the net annual financial savings realized by implementing this security control?