All practice questions
2232 questions
A Chief Information Security Officer (CISO) is conducting a quantitative risk assessment for a legacy customer database server with an estimated Asset Value () of . Threat metrics indicate an Annual Rate of Occurrence () of for unauthorized data extraction attacks. Without additional security controls, the Exposure Factor () for a successful compromise is .
To mitigate this risk, the organization evaluates deploying an Endpoint Detection and Response (EDR) solution combined with network microsegmentation. This countermeasure costs annually to license and manage, and it reduces the Exposure Factor () to while leaving the unchanged.
What is the net annual cost benefit of implementing this countermeasure?
An enterprise risk manager is evaluating the updated organizational risk register following a infrastructure modernizing initiative. During this initiative, the cybersecurity team decommissioned several legacy database servers that contained unpatchable vulnerabilities, purchased a comprehensive cyber insurance policy to cover data breach notifications and regulatory fines, and migrated customer analytics workloads to a public Cloud Service Provider (CSP) under an Infrastructure as a Service (IaaS) arrangement. Based on this risk management scenario, which of the following statements correctly evaluate the risk response strategies and governance responsibilities? (Select TWO.)
Select all that apply
An enterprise security governance team is reviewing its information security documentation hierarchy to resolve audit findings regarding governance ambiguity. Match each governance document type on the left with its corresponding organizational characteristic and legal/enforcement property on the right.
Click a left item, then click its matching right item
Items
Matches
A Security Operations Center (SOC) analyst is inspecting SIEM alerts originating from an internal web server hosting an enterprise customer portal. The SIEM correlated the following sequential Sysmon process creation events:
text
EventID: 1 (Process Create)
UtcTime: 2026-07-27 11:04:12.102
Image: C:\Windows\System32\inetsrv\w3wp.exe
CommandLine: w3wp.exe -ap "CustomerPortalPool"
User: NT AUTHORITY\NETWORK SERVICE
EventID: 1 (Process Create)
UtcTime: 2026-07-27 11:04:15.884
ParentImage: C:\Windows\System32\inetsrv\w3wp.exe
Image: C:\Windows\System32\cmd.exe
CommandLine: cmd.exe /c powershell.exe -nop -w hidden -EncodedCommand aW52b2tlLXdlYnJlcXVlc3Q...
User: NT AUTHORITY\NETWORK SERVICE
Based on the log evidence provided, which of the following best describes the security incident taking place?
A logistics organization is performing a quantitative risk assessment for its automated warehouse management system, which has an Asset Value () of . Without additional security controls, a critical cyber attack is estimated to occur once every 2 years () with an Exposure Factor () of . The cybersecurity team plans to deploy an endpoint detection and response (EDR) platform alongside network microsegmentation controls, which is expected to reduce the to and the to . The total annual cost for subscription licensing and maintenance of these controls is .
What is the net annual financial value (net benefit in USD) of implementing these security controls?
Following a phishing simulation report, a security analyst reviews telemetry to identify systems where an unauthorized script executed via a native administrative tool without creating new executable files on disk. Traditional signature-based antivirus on the endpoints flagged no alerts. Which of the following Endpoint Detection and Response (EDR) capabilities allows the analyst to identify this activity?
A system administrator is preparing to roll out a critical operating system patch across enterprise workstations. Which of the following tasks should be completed prior to deploying the patch into the broad production environment? (Select TWO.)
Select all that apply
Following an automated alert indicating potential fileless malware activity on an operational database server, a security analyst must collect volatile digital evidence prior to server isolation. Adhering strictly to the standard order of volatility, which of the following data sources should the analyst acquire FIRST?
A logistics company evaluates the risk of server downtime at a remote warehouse facility. The database server cluster has an Asset Value () of . An assessment indicates that a severe localized network outage would result in an Exposure Factor () of (). The Annual Rate of Occurrence () for this type of outage is estimated to be (occurring once every two years). What is the Annualized Loss Expectancy () in USD for this threat?
An enterprise systems administrator is troubleshooting a Kerberos authentication issue in an Active Directory environment. Place the steps of the Kerberos ticket exchange process in the correct order from initial user login to final resource access.
Drag items to arrange them in the correct order
An organization is updating its security governance hierarchy to resolve operational ambiguities discovered during a regulatory audit. Match each governance document type on the left with its corresponding organizational scope and enforceability characteristic on the right.
Click a left item, then click its matching right item
Items
Matches
An enterprise security team manages a geographically distributed fleet of edge servers running containerized microservices. Following an emergency zero-day patch deployment, several edge nodes experience configuration drift, causing unauthorized modifications to local system baselines and security settings. Which TWO of the following technical controls should the security team implement to remediate this configuration drift and prevent future baseline deviations?
Select all that apply
Following an executive directive mandating strict software supply chain security, an enterprise security architect publishes a technical document for application development teams. The document establishes mandatory technical criteria, including requiring all container images to be cryptographically signed and prohibiting deployment if any unresolved critical vulnerabilities are detected. While the document does not outline tool-specific step-by-step workflow actions, adherence to these quantitative rules is strictly compulsory across all engineering teams. Which of the following security governance document types is represented by this technical specification?
A security operations analyst is investigating an automated alert from a enterprise Identity Provider (IdP). An administrator attempted to access a critical production Kubernetes management console, generating the following log excerpt:
text
[TIMESTAMP: 2026-07-27T14:20:11Z] EVENT: Auth_Request | User: admin_ops | Source_IP: 10.240.12.88 | Protocol: SAML_2.0 | Auth_Result: SUCCESS (MFA Verified)
[TIMESTAMP: 2026-07-27T14:20:15Z] EVENT: Resource_Access | User: admin_ops | Target: Prod_K8s_Console | Action: EVAL_POLICY | Result: DENIED | Reason: Missing_Privileged_Role_Claim
[TIMESTAMP: 2026-07-27T14:20:18Z] EVENT: Privileged_Elevate | User: admin_ops | Request_ID: 99412 | Action: ASSUME_ROLE | Result: FAILED | Reason: No_Active_PAM_Approval_Ticket
Which of the following security operational concepts best explains why access was blocked after successful identity verification?
A security engineering team is refining the vulnerability assessment strategy for a hybrid cloud environment. The team wants to obtain detailed patch and configuration status from cloud virtual machines while minimizing network bandwidth overhead and avoiding the transmission of privileged domain credentials across the network. Which TWO of the following configurations or approaches should the team implement? (Select TWO.)
Select all that apply
An enterprise organization is enhancing its vendor onboarding process for commercial off-the-shelf (COTS) software applications. To evaluate software supply chain risks and ensure the integrity of vendor-supplied code before deployment, which TWO of the following controls or artifacts should the security team require from software vendors? (Select TWO)
Select all that apply
A network security analyst receives a high-severity Network Intrusion Detection System (NIDS) alert signaling anomalous outbound data transfers from a internal web server to an unknown external IP address. Which of the following sequences represents the correct chronological order of network security monitoring and incident triage steps the analyst should follow from initial alert validation through enterprise protection?
Drag items to arrange them in the correct order
Match each third-party risk management artifact or supply chain control on the left with its corresponding oversight function on the right.
Click a left item, then click its matching right item
Items
Matches
A healthcare provider contracts a third-party software vendor to maintain its remote patient monitoring platform. During a compliance audit, the security team discovers that the vendor transferred customer data backups to an unvetted sub-processor to reduce hosting expenses. The existing contract includes non-disclosure obligations, minimum uptime guarantees, and annual on-site audit privileges, but lacks restrictions regarding sub-tier service providers. Which of the following contractual provisions should the security team mandate in future procurement agreements to directly restrict unauthorized downstream vendor engagements?
An enterprise organization is outsourcing its customer data analytics platform to a cloud service provider that will process sensitive financial records. To establish continuous risk oversight and maintain regulatory compliance throughout the contractual relationship, which of the following mechanisms should the organization require? (Select TWO.)
Select all that apply