Security Operations
627 questions
During an ongoing incident investigation involving an enterprise network gateway suspected of active data exfiltration, an incident responder is tasked with collecting digital evidence from the running target system to support potential legal prosecution. Which of the following procedures must the responder perform to maintain evidence integrity and adhere to forensic collection standards? (Select TWO.)
Select all that apply
During off-hours monitoring, a Security Operations Center (SOC) analyst receives a high-severity alert indicating that an unauthorized IAM access key associated with a developer account is actively making API calls to export enterprise database snapshots to an unapproved external cloud storage location. The analyst verifies that data exfiltration is currently taking place in real time. Following standard NIST SP 800-61 incident response lifecycle guidelines, which of the following actions should the analyst take FIRST?
A security operations team observes significant network degradation and inconsistent scan results during scheduled vulnerability assessments of an enterprise auto-scaling container cluster. The current scanning infrastructure relies on a centralized network scanner initiating remote, credentialed SSH/WinRM connections across dynamically assigned pod IP addresses, frequently failing when transient instances terminate mid-scan. Which architectural modification best resolves these operational scanning challenges while minimizing privileged credential transmission across the internal network?
A security analyst is establishing the standard administrative workflow for user onboarding and offboarding within an enterprise Identity and Access Management (IAM) system. Place the following identity lifecycle steps in the correct chronological order from first to last.
Drag items to arrange them in the correct order
An enterprise security team needs to deploy a security capability to corporate laptops that provides continuous behavioral telemetry, process execution monitoring, and the ability to perform remote network host isolation during an incident. Which of the following technologies best meets these operational requirements?
A security administrator needs to perform a routine vulnerability scan on a critical production database server during business hours. The administrator must maximize detection accuracy for missing operating system patches while ensuring database availability is not impacted. Which of the following scanning practices should the administrator select? (Select TWO.)
Select all that apply
A Security Operations Center (SOC) analyst receives an active EDR telemetry alert indicating that a Windows workstation is executing malicious code via a Living-off-the-Land (LotL) binary. Place the following Endpoint Detection and Response (EDR) containment and incident handling actions in the correct chronological order from first step to last step.
Drag items to arrange them in the correct order
A forensic investigator arrives at an enterprise branch office to analyze a powered-on physical server suspected of hosting an active in-memory keylogger that exfiltrates proprietary records. To preserve evidence for legal proceedings while strictly following forensic acquisition standards, which of the following actions must the investigator take before acquiring non-volatile disk media?
During an incident response investigation, a Security Operations Center (SOC) team detects an active web shell on a public-facing web server cluster. Log telemetry confirms that the threat actor is abusing harvested service account credentials to attempt lateral movement toward the enterprise database tier. According to standard incident response lifecycle frameworks, which of the following containment actions should the Incident Response Team (IRT) execute immediately? (Select TWO.)
Select all that apply
A security operations team is implementing Just-In-Time (JIT) access controls within a Privileged Access Management (PAM) framework to reduce standing administrative privileges. Place the operational steps of a JIT privileged access session lifecycle in the correct sequential order from start to finish.
Drag items to arrange them in the correct order
An enterprise security architecture team is updating its vulnerability assessment strategy across a diverse hybrid infrastructure. The environment comprises internal database servers, virtualized cloud workloads, and legacy operational technology (OT) controlling industrial processes. The team must maximize vulnerability discovery accuracy while adhering to strict operational availability constraints. Which of the following scanning strategies should the security team implement to satisfy these requirements? (Select TWO.)
Select all that apply
During security monitoring, an analyst detects unauthorized data exfiltration via DNS tunneling originating from an internal web application server. The incident response team validates the threat and confirms the incident response playbook needs to be executed immediately. According to standard incident response lifecycle frameworks, which of the following actions should the responder take FIRST during the containment phase?
During a threat hunting operation on a dual-homed critical enterprise jump server running Windows Server, a SOC analyst identifies suspicious memory-only reflective DLL injection into a legitimate system process. Telemetry shows the process initiating beaconing over an encrypted channel to an unknown external IP address while simultaneously maintaining active RPC session handles to adjacent internal database servers. Which of the following containment actions should the security analyst perform using the Endpoint Detection and Response (EDR) agent to stop lateral movement without losing volatile memory evidence or breaking analyst access?
A senior systems engineer is evaluating centralized administrative access controls for an organization's network infrastructure devices, including core switches and routers. Operational security requirements specify that the solution must encrypt the entire packet payload during transit, strictly separate authentication and authorization processes, and support per-command authorization auditing for administrative sessions. Which of the following protocols should the engineer implement to satisfy these operational requirements?
A security analyst is reviewing authentication and session logs from an enterprise Identity Provider (IdP) following a suspected compromise of a cloud-hosted infrastructure management console. The investigation reveals the following log snippet:
[2026-07-27T14:02:11Z] AUTH_SUCCESS [email protected] AuthMethod=FIDO2_HardwareKey SourceIP=192.168.10.45 Location=Corp_HQ_HQ1
[2026-07-27T14:02:14Z] SESSION_ISSUED [email protected] OAuthTokenID=tk-998231 Scope=CloudAdmin_FullAccess
[2026-07-27T14:02:40Z] API_CALL [email protected] OAuthTokenID=tk-998231 SourceIP=198.51.100.77 Location=External_Unknown Endpoint=/api/v1/iam/roles/delete
[2026-07-27T14:02:45Z] API_CALL [email protected] OAuthTokenID=tk-998231 SourceIP=198.51.100.77 Location=External_Unknown Endpoint=/api/v1/storage/exportAll
Further physical access logs confirm User j.doe was continuously present at Corporate HQ during this timeframe. Which of the following identity operational vulnerabilities MOST likely enabled this unauthorized access? (Select TWO.)
Select all that apply
During an active security incident on an enterprise application server, logs indicate an unauthorized process attempting to extract LSASS memory contents. The incident response team must immediately stop potential lateral movement across the internal domain while keeping an active channel open to capture volatile RAM and run diagnostic commands. Which capability of an Endpoint Detection and Response (EDR) platform best meets these requirements?
A digital forensics specialist receives a sealed evidence bag containing a seized hard drive from a field investigator for intake into the forensic laboratory. Which of the following actions should the specialist perform first to maintain the chain of custody?
An enterprise administrator requires short-term elevated permissions to perform maintenance on a critical domain controller. Rather than assigning a permanent administrative account, the security operations team uses a Privileged Access Management (PAM) solution that temporarily grants rights and automatically revokes them when the maintenance window expires. Which of the following identity and access management operational concepts is best demonstrated in this scenario?
A security analyst is investigating an authentication alert involving an enterprise user account. Log analysis indicates that the account completed a successful multi-factor authentication (MFA) login from a corporate desktop in Chicago. Less than ten minutes later, authentication logs show successful access to cloud resources using the same account credentials via legacy POP3/IMAP protocols from an unmanaged external IP address, bypassing MFA prompts. Which of the following operational actions should the analyst take to contain the immediate risk and prevent future occurrences of this issue? (Select TWO.)
Select all that apply
During a security audit, a vulnerability analyst configures an authenticated network-based vulnerability scanner to audit a subnet of Linux application servers using an SSH service account. The resulting report indicates zero critical or high vulnerabilities across all hosts. However, a concurrent local agent-based scan on the same servers flags several high-severity vulnerabilities associated with missing kernel patches and outdated system libraries. Which of the following best explains why the authenticated network scan failed to detect these vulnerabilities?