All practice questions
2232 questions
An enterprise Security Operations Center (SOC) identifies anomalous database queries originating from an authenticated SSL/TLS VPN remote user session outside of normal business hours. Place the following incident response actions in the correct chronological order from first step to last step according to the standard NIST Incident Response Lifecycle.
Drag items to arrange them in the correct order
A security engineer is configuring a Service Provider-initiated SAML 2.0 Single Sign-On (SSO) integration between an enterprise SaaS application (Service Provider) and an external cloud Identity Provider (IdP) with mandatory MFA. In what order should the steps occur to complete a secure authentication and access flow?
Drag items to arrange them in the correct order
An enterprise web application experienced an unrecoverable infrastructure failure at its primary facility. The incident response team must execute the disaster recovery plan to activate the secondary warm site and minimize service disruption. In what chronological order should the administrator execute the following steps to complete the failover securely while preserving data integrity?
Drag items to arrange them in the correct order
During an ongoing incident investigation, a Security Operations Center (SOC) team detects that an automated Continuous Integration/Continuous Deployment (CI/CD) build server has been compromised. An attacker modified build scripts to exfiltrate enterprise API credentials to an external host while continuing to compile production software images. Which TWO of the following containment actions should the incident response team perform immediately to mitigate the incident while preserving evidence?
Select all that apply
An organization is establishing hardware security specifications for edge computing appliances deployed in remote, physically untrusted locations. The security architect must ensure cryptographic keys stored on hardware cannot be extracted via physical chip probing, and device identities cannot be duplicated onto unauthorized hardware. Which of the following hardware security controls should be implemented to meet these specific requirements? (Select TWO.)
Select all that apply
A security technician needs to conduct a vulnerability scan on an internal application server to accurately identify missing software patches and internal misconfigurations without disrupting active services. Which of the following scanning approaches best satisfies these requirements?
During a network security monitoring review of a cloud environment, a security analyst examines the following NIDS alert log associated with an internal application gateway:
Timestamp: 2026-07-27T14:22:01Z
Src_IP: 192.168.10.45:49152 -> Dst_IP: 10.0.4.12:80
Signature: HTTP_Req_Pattern_Match
Payload Snippet: POST /search.php HTTP/1.1\r
Host: store.internal\r
User-Agent: Mozilla/5.0\r
Content-Type: application/x-www-form-urlencoded\r
Content-Length: 68\r
\r
item=1+UNION+SELECT+null,username,password_hash+FROM+users--
Following this initial request, outbound firewall logs capture sustained 15-minute periodic TCP connections from 10.0.4.12 to an external IP address over port 443. Based on the log evidence, which of the following represents the most accurate diagnosis of the activity and the appropriate immediate analyst action?
An IAM administrator at an online payment processor is reviewing identity operational logs after an audit revealed that a terminated contractor retained administrative access to production API gateways 48 hours after offboarding:
| Timestamp (UTC) | Event ID | Identity / Subject | System Component | Details / Status |
|---|---|---|---|---|
| 2026-07-25 09:00:00 | EVT-801 | [email protected] | IdP Directory | User account status set to Disabled |
| 2026-07-25 09:00:05 | EVT-802 | [email protected] | SCIM Engine | Provisioning push failed: Integration token expired |
| 2026-07-25 09:05:00 | EVT-803 | [email protected] | API Gateway | Refresh token exchange succeeded (New access token issued) |
| 2026-07-27 08:30:00 | EVT-804 | [email protected] | API Gateway | Administrative configuration change executed |
Based on the log analysis, which of the following identifies the primary technical cause of the persistent access and the most effective operational fix?
An enterprise security team needs to publish a document that specifies the mandatory minimum technical security settings required for all newly deployed cloud virtual machines. Which type of security governance document should the team create to define these mandatory minimum configurations?
An enterprise logistics provider is conducting a quantitative risk assessment for a mission-critical database cluster valued at 30,000 annually, which is expected to lower the ARO to 0.1 without altering the EF. What is the net annual financial benefit (safeguard value) of implementing this security control?
A security operations team must implement appropriate vulnerability assessment methodologies across four distinct IT and operational environments. Which vulnerability scanning approach best matches each enterprise operational requirement?
Click a left item, then click its matching right item
Items
Matches
Following an enterprise-wide cloud transformation, an organization's Chief Information Security Officer (CISO) establishes a multi-tiered governance structure to enforce security controls across diverse engineering teams. The framework includes high-level security objectives, mandatory technical requirements for microservices, discretionary coding recommendations, and platform-specific step-by-step configuration steps. During an internal compliance review, a software development team is flagged for utilizing AES-128 encryption across microservices instead of the mandatory enterprise cipher specification. The team lead asserts that technical rules specified outside the overarching executive policy document are non-binding recommendations. Which governance document type did the CISO issue to enforce mandatory technical requirements across the enterprise, and what is its role within the governance hierarchy?
During a routine security review of cloud identity operations, a security analyst discovers that an automated data synchronization process uses a legacy service account configured with a long-lived static API key. The key was inadvertently committed to an internal repository, allowing an unauthorized external entity to request access tokens and enumerate cloud resources. Which of the following operational controls should the security team implement to remediate this vulnerability and secure the service identity lifecycle? (Select TWO.)
Select all that apply
A security engineer is configuring a newly deployed Security Information and Event Management (SIEM) system to ingest and analyze multi-source telemetry across the enterprise network. Arrange the core stages of the SIEM log processing pipeline in the correct sequential order from initial intake to operational notice.
Drag items to arrange them in the correct order
An enterprise security architect is designing an updated Identity and Access Management (IAM) architecture to support dynamic, fine-grained authorization across microservices while automating user account lifecycles across cloud services. Which of the following components or standards should be incorporated into the architecture to fulfill these requirements? (Select TWO.)
Select all that apply
A security analyst is auditing access logs following an unauthorized privilege escalation incident on a network perimeter gateway. The organization utilizes a centralized RADIUS server integrated with Directory Services for network access control. The authentication and authorization logs display the following consecutive events:
[TIMESTAMP: 2026-07-27T14:22:01Z] RADIUS-Auth: User 'j_doe' successfully authenticated via MS-CHAPv2.
[TIMESTAMP: 2026-07-27T14:22:02Z] RADIUS-Authz: Vendor-Specific Attribute (VSA) 'Cisco-AVPair = shell:priv-lvl=15' rejected due to policy schema syntax mismatch.
[TIMESTAMP: 2026-07-27T14:22:03Z] Gateway-Daemon: Fallback default authorization rule applied; assigned administrative profile (privilege level 15) to session 'j_doe'.
Which of the following operational vulnerabilities is the primary root cause of the unauthorized privilege escalation?
A digital forensics analyst has completed the imaging of a seized storage volume from an enterprise database server involved in a security incident. The analyst is preparing to transfer the physical evidence to an external forensic laboratory for detailed examination. Which of the following actions must the analyst take to maintain a valid chain of custody during this transfer? (Select TWO.)
Select all that apply
A Security Operations Center (SOC) analyst receives a high-priority alert indicating that an enterprise Voice over IP (VoIP) management server has established unauthorized outbound secure shell (SSH) sessions to an unknown external IP address and is attempting horizontal scanning across internal server subnets. The analyst inspects network logs and confirms that an active remote code execution exploit took place through the server's web administration panel. According to standard incident response playbooks, which of the following actions should the analyst perform FIRST?
A tier 2 incident responder analyzing endpoint telemetry observes an active fileless attack on an enterprise financial server, where an injected process is issuing unauthorized API calls to extract credentials and establish an outbound encrypted beacon. To effectively contain the active compromise and preserve critical evidence for incident triage without losing agent telemetry, which of the following response actions should the responder perform using EDR agent capabilities? (Select TWO.)
Select all that apply
A systems administrator is configuring a secure remote management channel for server administration over an untrusted network. The security policy mandates perfect forward secrecy so that compromising the server's long-term private key in the future will not allow an attacker to decrypt previously recorded session traffic. Which cryptographic key exchange mechanism should the administrator implement to satisfy this requirement?