All practice questions
2232 questions
An organization deploys a centralized Privileged Access Management (PAM) solution to govern administrator access to production databases. When a database administrator requests a session, the PAM system first verifies their identity using a hardware token and PIN. Next, the PAM system evaluates an access policy matrix to determine if the session occurs within an approved maintenance window and applies a restricted read-only role for that specific database instance. Finally, the proxy engine writes a cryptographic audit log of all executed SQL queries. Which pillar of the Security AAA framework is being implemented when the PAM system evaluates the policy matrix to grant the restricted read-only role?
A security manager is updating an enterprise third-party risk management framework to enhance vendor oversight and supply chain resilience. Match each third-party governance control or evaluation artifact to its primary operational purpose.
Click a left item, then click its matching right item
Items
Matches
An enterprise organization is updating its security governance framework following a comprehensive compliance audit. The Governance, Risk, and Compliance (GRC) team must establish clear operational boundaries between mandatory requirements and discretionary guidance across all departments. Which of the following governance components represent MANDATORY requirements that personnel or technical implementations must strictly adhere to? (Select TWO.)
Select all that apply
To align with newly enacted data privacy regulations, a financial institution's executive leadership issues an overarching directive declaring that all customer-facing applications must enforce data protection measures. The document establishes high-level business goals, defines organizational scope, and applies mandatorily to all employees, but deliberately omits technical algorithm choices, key lengths, and step-by-step administrative procedures. Which governance document tier does this directive represent?
Match each cryptographic primitive or mechanism to its primary operational security function in an enterprise environment.
Click a left item, then click its matching right item
Items
Matches
A security operations center analyst receives a high-severity alert from a network security monitoring system watching a dedicated deception host (honeypot) located inside a monitored subnet segment. The alert logs multiple inbound connection attempts on TCP port 22 originating from an external IP address. The analyst immediately submits an emergency change request to reconfigure the honeypot host's local firewall to block port 22 incoming traffic to mitigate the risk of compromise. Which of the following best evaluates the analyst's action?
A financial institution is evaluating the risk profile of its online identity verification service, which has an estimated Asset Value () of . A threat modeling report indicates that an unmitigated credential stuffing vulnerability has an Exposure Factor () of per security incident. Threat intelligence metrics project an Annual Rate of Occurrence () of for this specific attack vector. Based on quantitative risk analysis principles, what is the Annual Loss Expectancy () associated with this risk?
An enterprise organization is procuring custom network appliances from a third-party manufacturer. To mitigate the risk of hardware supply chain tampering and unauthorized firmware modification during transit, the security team must establish a verification mechanism to validate device authenticity prior to deployment. Which of the following controls provides the MOST effective verification of hardware and firmware integrity upon receipt?
A United States healthcare provider operates a web portal that allows patients to view medical records and pay out-of-pocket expenses using credit cards. Which of the following regulatory compliance frameworks must the organization adhere to in order to protect patient health records and credit card transactions? (Select TWO.)
Select all that apply
A fintech enterprise is assessing security controls for an e-commerce API gateway with an Asset Value (AV) of . Threat intelligence indicates an Annual Rate of Occurrence (ARO) of for a major distributed denial-of-service (DDoS) attack. The Chief Risk Officer (CRO) sets a maximum acceptable Annual Loss Expectancy (ALE) threshold of for DDoS-related risks. Which of the following represents the maximum Exposure Factor () that an implemented Web Application Firewall must achieve to keep residual risk within this threshold?
A financial enterprise is migrating its transaction processing infrastructure to a cloud-native container environment. The Chief Information Security Officer (CISO) mandates that every production container host and image must enforce an identical set of mandatory minimum security configurations, including root access restrictions, disabled unused daemons, and read-only root filesystems. Which of the following security governance documents should the security architecture team publish to define these compulsory minimum configuration settings across all host platforms?
An e-commerce enterprise is performing a quantitative risk assessment for its core order processing cluster, which has an estimated Asset Value () of . Security metrics indicate that a ransomware incident affecting this cluster has an Annualized Rate of Occurrence () of and an Exposure Factor () of . To mitigate this risk, the enterprise plans to deploy an Endpoint Detection and Response (EDR) control costing annually. This safeguard will reduce the to without affecting the . What is the net annual financial benefit, in dollars, of implementing this security safeguard?
A financial enterprise operates a high-frequency trading platform with continuous uptime requirements. A vendor releases a critical security patch addressing an unauthenticated remote code execution flaw in the underlying operating system. The security team must address this threat across all host instances while ensuring system stability and compliance with strict service level agreement (SLA) commitments. Which of the following patch management strategies best balances rapid threat mitigation with continuous operational availability?
During a physical security assessment, security auditors observe an unauthorized individual entering a secured facility by following closely behind a credentialed staff member through a badge-access door. Once inside the facility, the individual secretly records an administrator entering sensitive credentials onto a workstation keyboard from a nearby seating area. Which of the following social engineering vectors were executed during this physical security breach? (Select TWO)
Select all that apply
A Chief Information Security Officer (CISO) is restructuring the enterprise security documentation hierarchy to streamline compliance and operational governance across cloud and on-premises environments. Match each security governance document type to its corresponding operational characteristic.
Click a left item, then click its matching right item
Items
Matches
Following an unannounced infrastructure outage, a financial services company executes its business continuity plan for a core payment gateway. The organization's Business Impact Analysis (BIA) specifies a Maximum Tolerable Downtime (MTD) of and a Recovery Point Objective (RPO) of . Technical recovery teams successfully restore the primary database from an automated snapshot generated prior to the incident, completing baseline platform recovery in . However, post-restoration data integrity verification, transaction reconciliation, and security testing require an additional before operational sign-off is granted and production traffic is resumed. Which of the following conclusions best evaluates the organization's business continuity performance against its established metrics?
An enterprise security engineer is auditing identity lifecycle management and access control workflows across the organization. Match each operational access activity on the left with its corresponding identity management or AAA (Authentication, Authorization, and Accounting) component on the right.
Click a left item, then click its matching right item
Items
Matches
A security engineer is designing an authentication microservice for an enterprise web application. The security policy requires storing user credentials in a manner that mitigates offline brute-force and precomputed rainbow table attacks if the credential database is compromised. Which of the following cryptographic techniques should the engineer implement to satisfy this requirement?
An IT security team is defining operational metric parameters during a Business Impact Analysis (BIA) for an enterprise enterprise resource planning (ERP) environment. Which TWO of the following statements correctly distinguish Recovery Time Objective (RTO) from Recovery Point Objective (RPO)?
Select all that apply
An enterprise security analyst discovers that recent vulnerability scan reports flag several Linux production servers as critical due to missing OS security updates. However, the system administration team provides logs showing that the vendor patches were installed two weeks ago. Further investigation reveals the scanner performed an unauthenticated remote scan relying solely on service banners exposed over open network ports. Which of the following actions should the analyst take to ensure the vulnerability scan accurately reflects the true patch status of the servers?