Security Operations
627 questions
During a vulnerability assessment of an enterprise infrastructure, a scanner flags a critical unpatched remote code execution vulnerability on a core database server. The system administrator requests to mark the finding as risk-accepted without patching, citing that an inline Network Intrusion Prevention System (NIPS) is active on the network segment. Which of the following best describes the primary operational risk of relying on this compensating control instead of applying the vendor patch?
An enterprise security analyst is configuring an automated vulnerability scanner to conduct routine compliance assessments across internal production database servers. To ensure accurate vulnerability identification while preventing system downtime or account lockouts, which of the following configuration options should the analyst implement? (Select TWO.)
Select all that apply
An organization's security operations center observes that newly provisioned virtual servers in a public cloud environment consistently lack mandatory security monitoring agents and feature non-standard firewall configurations. An investigation reveals that system administrators are manually launching instances from legacy local image templates instead of using approved central images. Which of the following operational practices should the organization implement to MOST effectively prevent future configuration drift?
A Security Operations Center (SOC) analyst is reviewing network security monitoring alerts generated by a Network Traffic Analysis (NTA) sensor inspecting perimeter egress traffic. The sensor triggers a high-severity alert for an outbound TCP session originating from an internal host () to an external server ():
src_ip: 10.2.14.50
src_port: 51024
dest_ip: 198.51.100.89
dest_port: 443
transport: tcp
detected_protocol: ssh
expected_protocol: tls
alert_type: Protocol Mismatch / Evasion
Based on the log snippet provided, which of the following is the most accurate interpretation of this network security monitoring alert?
A network security analyst receives a high-severity alert from a Network Traffic Analysis (NTA) system regarding anomalous outbound encrypted communications originating from an internal workstation. Place the following incident triage and response steps in the correct sequential order from initial alert verification to containment.
Drag items to arrange them in the correct order
A security analyst reviewing Network Intrusion Detection System (NIDS) alerts for an enterprise web server identifies multiple HTTP POST requests containing payload strings such as `<script>document.cookie</script>` submitted through an unauthenticated feedback form. Which of the following correctly identifies the type of attack detected by network monitoring?
A Security Operations Center (SOC) analyst reviewing network security monitoring (NSM) alerts identifies sustained IP protocol 47 (Generic Routing Encapsulation - GRE) traffic originating from an internal DMZ web server toward an unknown external IP address. NetFlow records confirm a high volume of asymmetric outbound data transfer. Which TWO of the following actions should the analyst take to address this network security incident?
Select all that apply