All practice questions
173 questions
A security analyst is setting up a Security Information and Event Management (SIEM) pipeline to process incoming telemetry from enterprise web application firewalls. Arrange the stages of the SIEM log processing workflow in the correct operational sequence, from initial data receipt to incident notification.
Drag items to arrange them in the correct order
A Security Operations Center (SOC) analyst detects an active exfiltration attempt where an unauthorized external IP address is utilizing a compromised cloud API key to download sensitive data. Place the following incident response playbook actions in the correct sequential order from FIRST to LAST.
Drag items to arrange them in the correct order
A security analyst receives a high-priority alert from a perimeter Network Intrusion Detection System (NIDS) indicating anomalous, high-frequency outbound HTTPS connections from an internal host to an unrated external IP address. Place the operational monitoring and initial response steps in the correct chronological order from alert reception to formal escalation.
Drag items to arrange them in the correct order
An enterprise security team plans to modify central authentication controls to enforce hardware-based multi-factor authentication across production subnets. To ensure operational continuity and minimize security risks, the team must follow the organization's formal change management process. Place the following change management steps in the correct chronological order from first to last.
Drag items to arrange them in the correct order
A network security analyst receives a SIEM alert indicating suspicious encrypted outbound traffic from an internal host to an untrusted external IP address. Place the following incident triage and network monitoring response actions in the correct chronological order, from initial alert confirmation to threat containment.
Drag items to arrange them in the correct order
A security operations center (SOC) team is deploying a Security Orchestration, Automation, and Response (SOAR) playbook to handle automated containment when secret-scanning tools detect exposed API keys in public code repositories. In what sequence should the SOAR engine execute the following playbook steps?
Drag items to arrange them in the correct order
A network security monitoring (NSM) system triggers an automated alert indicating anomalous outbound TLS traffic from an enterprise host to an unrated external IP address. In what sequence should a network analyst execute the technical triage and mitigation workflow?
Drag items to arrange them in the correct order
An organization relies on end-user reporting to reduce human risk and mitigate phishing attacks. Place the following steps in the correct sequential order from initial end-user reporting to security awareness program escalation.
Drag items to arrange them in the correct order
A network security administrator is commissioning a new internal web application server that requires a trusted SSL/TLS certificate signed by the enterprise internal Certificate Authority (CA). Which of the following sequences represents the correct chronological order of steps the administrator must perform to obtain and deploy this certificate?
Drag items to arrange them in the correct order
A network security analyst receives a high-severity alert from a Network Traffic Analysis (NTA) system regarding anomalous outbound encrypted communications originating from an internal workstation. Place the following incident triage and response steps in the correct sequential order from initial alert verification to containment.
Drag items to arrange them in the correct order
A DevOps engineer is setting up a secure internal web endpoint for a microservice and needs to enroll it into the organization's Public Key Infrastructure (PKI). Which of the following represents the correct sequential order of operational steps required to successfully obtain and deploy an X.509 certificate, from initial key creation to final service binding?
Drag items to arrange them in the correct order
An organization's security manager is implementing a human risk management campaign to address a high frequency of unattended, unlocked workstations observed during an internal audit. In what chronological order should the security manager execute the following phases of the campaign, from initial risk assessment to program evaluation?
Drag items to arrange them in the correct order
An organization is updating its incident response playbooks to better integrate end-user security awareness reporting with human risk management oversight. Place the following operational steps in the correct chronological sequence from initial detection by an employee to the continuous improvement of the security awareness program.
Drag items to arrange them in the correct order