Threats, Vulnerabilities, and Mitigations
490 questions
An enterprise security analyst is investigating an incident where several finance department employees received unexpected phone calls from an individual claiming to be a senior IT support engineer. The caller stated that an emergency payroll system update required immediate phone-based password confirmation to avoid halting monthly salary disbursements. Which TWO of the following social engineering attack vectors or principles of influence were directly utilized in this scenario?
Select all that apply
A corporate employee receives a customized USB flash drive in the mail labeled 'Confidential: Executive Salary Adjustments Q3' that appears to originate from the human resources department. Driven by curiosity, the employee connects the drive to a company workstation, which immediately triggers malicious code execution. Which social engineering attack vector did the attacker utilize in this scenario?
Match each social engineering attack vector or technique on the left with the enterprise incident scenario on the right that best demonstrates its execution.
Click a left item, then click its matching right item
Items
Matches
Software developers at an enterprise regularly visit a well-known third-party technical documentation website to view API specifications. A threat actor compromises this external website and injects malicious code designed to execute a drive-by download targeting visitors connecting from the enterprise's public IP block. Which of the following social engineering attack vectors is described in this scenario?
A corporate finance officer receives an urgent SMS message on their personal mobile phone claiming that a critical vendor invoice is past due and requiring immediate review via a provided shortened link. Upon clicking the link, the officer is directed to a login page and receives a follow-up call from an individual claiming to be a senior IT auditor. The caller uses authoritative technical terms and pressures the officer to disclose their multi-factor authentication (MFA) verification code to resolve an apparent account lock. Which of the following social engineering attack vectors and principles of influence were directly employed in this scenario? (Select TWO.)
Select all that apply
A lead security analyst is designing a vulnerability assessment strategy for an operational technology segment that hosts legacy embedded web services. Previous active credentialed vulnerability scans caused several legacy daemons to crash, resulting in unexpected system downtime. The analyst must establish continuous monitoring to identify unpatched vulnerabilities and service misconfigurations across this segment without transmitting synthetic packets that could disrupt host stability. Which of the following security assessment methods best fulfills these operational requirements?
A lead security analyst is evaluating security testing methods for a critical financial application hosted in an enterprise cloud environment. During a credentialed automated vulnerability scan, an unauthenticated web endpoint was flagged as potentially vulnerable to blind SQL injection; however, the scanner report notes a potential false positive due to non-standard HTTP response headers. The analyst must safely validate whether this security finding is a true positive without impacting production database performance or altering production data records. Which of the following is the most appropriate assessment methodology to accomplish this goal?
An enterprise risk assessment team is categorizing threat entities involved in recent cyber incidents across various critical sectors. Match each incident narrative detailing specific adversary attributes, resources, and attack vectors on the left to the corresponding threat actor classification on the right.
Click a left item, then click its matching right item
Items
Matches
An incident responder notices that a malicious program rapidly infected dozens of systems across an internal network by exploiting a known remote code execution vulnerability, operating completely independently without any user action. Which of the following malware types best describes this threat?
An incident response team is investigating multiple concurrent network and wireless security anomalies detected across enterprise infrastructure. Match each technical log entry or packet capture indicator to its correct attack classification.
Click a left item, then click its matching right item
Items
Matches
A high-precision semiconductor fabrication facility experiences intermittent disruptions across its automated silicon wafer etching equipment. Investigation reveals that custom-compiled bootkit firmware was stealthily flashed onto isolated industrial controllers. The attackers gained initial access six months prior by compromising an offshore vendor's network management software used for remote equipment maintenance, demonstrating long-term persistence, custom exploit development, and zero-day evasions without requesting ransom or leaving overt defacement signatures. Which TWO of the following threat actor attributes or attack vectors are demonstrated in this scenario? (Select TWO)
Select all that apply
A network administrator conducts a vulnerability assessment on a critical server and discovers that an unencrypted legacy service, Telnet (TCP port 23), is enabled for remote administrative access across the internal network. Which of the following primary vulnerabilities does this host configuration introduce?
A security systems administrator analyzes a performance anomaly on an enterprise administrative jump host. System telemetry reveals an unverified process running from `C:\ProgramData\VendorApp\Temp\` that attaches hooks to Windows messaging queues via `SetWindowsHookEx`. Process analysis indicates that the application quietly records active window titles and raw keyboard entry sequences into an encrypted local buffer before exfiltrating the collected logs to a remote server over port 443. The host shows no evidence of automated network scanning, lateral propagation, or unauthorized driver installation. Which of the following malware types has infected the jump host?
During a physical security assessment of an organization's remote branch offices, security auditors discover that unauthorized individuals could gain brief physical access to server hardware hosting edge compute workloads. The audit highlights a critical risk: an attacker with local physical access could reboot the system, modify kernel boot parameters, and force the operating system to load compromised drivers that disable host security software prior to OS initialization. Which of the following enterprise hardening strategies is the MOST effective technical mitigation to prevent this unauthorized pre-boot tampering?
An organization wants to analyze its newly deployed cloud microservices for runtime security flaws and improper error handling under live execution conditions. The assessment team has been provided with API specifications and functional documentation, but does not have access to the underlying application source code. Which security testing method should the organization perform to satisfy this requirement?
An application security analyst is evaluating a custom backend Java service that receives serialized object payloads over an unauthenticated network socket to restore user session state. Code review reveals that the application reinstantiates these binary payloads directly into memory without performing type verification or input validation. Which of the following security risks and mitigation strategies correctly apply to this scenario? (Select TWO.)
Select all that apply
Following an industry-wide software supply chain incident, an enterprise incident response director wants to enable real-time ingestion of machine-readable indicators of compromise from trusted peer organizations. The technical requirements specify establishing automated client-server polling over encrypted HTTPS connections to retrieve structured threat feeds directly into defensive gateway controls. Which standard provides the transport mechanism required to support this automated intelligence exchange?
A security analyst is reviewing audit findings for a Linux-based public web server operating within an enterprise DMZ. The audit report highlights that the web server daemon process currently runs under the root superuser account, exposing the entire host operating system to complete takeover if an application-level remote code execution vulnerability is exploited. Which of the following mitigation strategies represents the MOST effective host hardening control to resolve this security risk?
An enterprise security architect is updating host and network hardening standards across the organization to address findings from a recent security assessment. Match each enterprise security risk scenario on the left with the most effective enterprise hardening mitigation on the right.
Click a left item, then click its matching right item
Items
Matches
Match each social engineering attack vector on the left with its correct scenario description on the right.
Click a left item, then click its matching right item
Items
Matches