All practice questions
2232 questions
A financial technology SaaS provider headquartered in Canada expands its operations to process real-time payment transactions and consumer credit metrics for financial institutions operating in both the European Union and the United States. During a legal compliance audit, the enterprise risk management team evaluates the organization's regulatory obligations regarding stored cardholder data, non-public personal information (NPI), and financial telemetry. Which of the following requirements MUST the organization implement to achieve compliance with PCI DSS and GDPR mandates? (Select TWO.)
Select all that apply
An organization is updating its third-party risk management policies and vendor contract templates. Match each agreement or documentation type to its primary purpose in vendor oversight.
Click a left item, then click its matching right item
Items
Matches
A security analyst is investigating a breach where an adversary captured encrypted TLS traffic traversing an enterprise network. Months later, the adversary obtained the web server's private key and successfully decrypted all historical session data. Which of the following cryptographic mechanisms should be implemented to ensure that a future compromise of the server's private key does not expose previously recorded encrypted session communications?
A network security engineer is auditing the AAA implementation for an enterprise 802.1X wireless network backed by a central RADIUS server. Which of the following statements correctly describe how authentication, authorization, or accounting functions operate in this deployment? (Select TWO.)
Select all that apply
A publicly traded company in the United States must establish internal security controls to ensure the accuracy, transparency, and integrity of its corporate financial reports and auditing processes. Which of the following regulatory frameworks specifically mandates these financial data governance and reporting control requirements?
A security engineer is updating the cryptographic specifications for an enterprise file ingest service. The system baseline requires high-throughput data confidentiality for large batch data uploads, alongside digital non-repudiation and origin verification for administrative policy manifests submitted with each batch. Which TWO cryptographic algorithms or mechanisms should the security engineer implement to satisfy these specific operational requirements?
Select all that apply
An organization must conduct scheduled external vulnerability assessments of its public-facing web applications to satisfy regulatory compliance. During previous unauthenticated scans, the perimeter web application firewall (WAF) repeatedly blocked the scanner's IP address, resulting in incomplete scan reports and false positives. Which scanning strategy should the security analyst implement to obtain comprehensive assessment results without disabling perimeter defenses for external traffic?
A security operations team is implementing an automated system for endpoint security baseline auditing and patch management across a hybrid enterprise environment. Which of the following operational practices should the security team deploy to maintain system stability while enforcing secure configuration baselines? (Select TWO.)
Select all that apply
During a malware investigation, an incident responder discovers that several engineers in an organization had their workstations infected after visiting an authentic, third-party software development forum that they frequently use for work. The attacker had previously breached the forum and injected a malicious drive-by download script targeting visitors originating from the organization's corporate IP range. Which of the following social engineering attack vectors was executed by the threat actor?
During a Business Impact Analysis (BIA), an enterprise security team defines a target timeframe of two hours to fully restore a critical application and its services after an unexpected server failure. Which of the following metrics best describes this targeted restoration timeframe?
A financial services enterprise relies on a critical SaaS provider for processing customer transactions. To strengthen its third-party risk governance, the security team needs to establish continuous oversight to detect security posture changes between annual audit cycles without violating tenant boundaries. Which of the following technical and operational controls should the security team implement? (Select TWO.)
Select all that apply
A university research facility hosts a specialized data repository with an estimated Asset Value () of . Threat analysis indicates an Exposure Factor () of from potential unauthorized network intrusions, with an Annual Rate of Occurrence () of . The security team proposes implementing an intrusion prevention system (IPS) that would reduce the to and the to . What is the expected annual financial loss reduction achieved by deploying the IPS control?
An organization is preparing its annual compliance roadmap and needs to explain the purpose of external third-party security audits to executive leadership. Which of the following statements correctly describe key characteristics of an external third-party security audit? (Select TWO.)
Select all that apply
An enterprise financial institution relies on a custom, proprietary fraud detection application supplied by a niche third-party software vendor. During an annual supply chain risk assessment, the security team identifies a major operational risk: if the software vendor unexpectedly faces insolvency, goes out of business, or fails to maintain the application, the institution will lose the ability to update or fix critical bugs in the software. Which of the following risk mitigation provisions should the security team implement in the vendor agreement to directly resolve this continuity risk?
A regional healthcare provider is performing a quantitative risk assessment for its web-based patient telemetry portal. The asset value () of the portal infrastructure is estimated at . A threat assessment projects that a web application breach occurs once every two years (), with an estimated Exposure Factor () of per incident. To mitigate this risk, the organization evaluates a Web Application Firewall (WAF) service costing annually, which is expected to reduce the Exposure Factor to . Based on quantitative risk analysis principles, what is the net annual financial benefit of implementing this security safeguard?
A mid-sized financial technology firm is preparing for an upcoming regulatory inspection. To evaluate how effectively its security controls withstand a targeted cyberattack, executive leadership hires an independent third-party team to perform an assessment. The team is given zero prior knowledge of the company's internal infrastructure and is authorized to actively exploit discovered vulnerabilities to determine potential intrusion depth. Which of the following security evaluations is the organization conducting?
A system administrator configures a central Linux bastion host that allows external contractors to connect via SSH using public key cryptography. Access control policies successfully restrict contractors from accessing unapproved file directories or running root-level processes. However, during a post-incident review, security auditors discover that while login timestamps and initial connection attempts were recorded, there are no log records detailing the specific commands executed or configuration files modified by contractors during their active sessions. Which pillar of the AAA framework is deficient in this configuration?
A security engineer is updating enterprise cryptographic standards across various operational systems. Match each cryptographic algorithm or mechanism on the left to its primary operational security capability on the right.
Click a left item, then click its matching right item
Items
Matches
A newly established fintech firm is defining its formal security governance architecture to ensure consistent risk oversight across cloud services. Match each governance document type on the left with its corresponding operational characteristic on the right.
Click a left item, then click its matching right item
Items
Matches
A security analyst investigates a SIEM alert triggered by a Network Traffic Analysis (NTA) sensor monitoring an internal enterprise workstation subnet. The flow log snippet displays the following sequential network events:
Timestamp: 2026-07-27T14:02:11Z | SrcIP: 10.0.4.15 | DstIP: 192.168.1.50 | DstPort: 445 | Protocol: TCP | Flags: SYN
Timestamp: 2026-07-27T14:02:11Z | SrcIP: 10.0.4.15 | DstIP: 192.168.1.51 | DstPort: 445 | Protocol: TCP | Flags: SYN
Timestamp: 2026-07-27T14:02:11Z | SrcIP: 10.0.4.15 | DstIP: 192.168.1.52 | DstPort: 445 | Protocol: TCP | Flags: SYN
Timestamp: 2026-07-27T14:02:12Z | SrcIP: 10.0.4.15 | DstIP: 192.168.1.53 | DstPort: 445 | Protocol: TCP | Flags: SYN
Based on the network security monitoring logs, which of the following actions should the analyst take first to address this threat?