Threats, Vulnerabilities, and Mitigations
490 questions
A security consultant is evaluating vulnerability assessment strategies for an enterprise hybrid environment that contains both standard server infrastructure and sensitive legacy Operational Technology (OT) systems. The consultant must recommend assessment techniques that accurately identify missing patches and host misconfigurations while minimizing the risk of system instability or network interruption on sensitive legacy segments. Which of the following approaches should the consultant recommend? (Select TWO.)
Select all that apply
A university research laboratory discovers that confidential quantum computing project files were accessed by an unauthorized external party. The investigation reveals that a lead researcher had set up an unapproved personal cloud storage folder to easily share files with external colleagues, bypassing university security controls. The external party accessed the folder by running automated public scripts that guessed default administrative credentials on the storage service. Which of the following threat actor attributes and attack vectors are demonstrated in this scenario? (Select TWO.)
Select all that apply
A security team is designing a vulnerability assessment and testing strategy for an enterprise hybrid environment hosting critical financial microservices. The team must satisfy two core requirements: first, obtain granular, host-level visibility into operating system patch levels and local security misconfigurations; second, continuously analyze external runtime exposure without injecting active scan traffic that could disrupt live user transactions or impact service availability. Which of the following security assessment methods should the team implement to meet these operational goals? (Select TWO.)
Select all that apply
A security engineering team is designing a vulnerability assessment and security testing strategy for a cloud-native microservices application processing sensitive payment data. To comply with enterprise governance, the testing pipeline must evaluate software components early in the development lifecycle without causing service instability, and inspect containerized workloads for known software vulnerabilities before deployment. Which of the following security assessment methods and testing controls should the team implement to fulfill these requirements? (Select TWO)
Select all that apply
An Endpoint Detection and Response (EDR) agent alerts security personnel that files across a shared network drive are rapidly being encrypted and appended with a custom `.locked` file extension. In addition, a text file demanding payment in exchange for a decryption key has been placed in each affected directory. Which of the following malware types is most likely responsible for this activity?
A system administrator needs to perform a vulnerability assessment on a public web server to determine what exposed services and flaws can be discovered by an unauthenticated external attacker without administrative privileges. Which of the following assessment methods should the administrator execute?
During a routine incident investigation, a security analyst reviews web application gateway logs for a custom automated reporting microservice. The logs contain consecutive HTTP POST requests targeting the endpoint `/api/v1/generate-report` with the body payload `template_header={{7*7}}`, which returned a `200 OK` status with `49` rendered in the response preview. Subsequent log entries show the payload modified to `template_header={{self.__init__.__globals__['__builtins__']['__import__']('os').popen('id').read()}}`, which returned operating system user identity context. Which of the following vulnerabilities is present in the application, and what is the primary mitigation strategy to prevent exploitation?
During an incident response investigation, a SOC analyst examines endpoint detection telemetry from a workstation alerting on suspected fileless malware execution involving process injection. Which of the following technical indicators of compromise (IoCs) specifically indicate that memory-only process injection using legitimate system binaries has occurred? (Select TWO.)
Select all that apply
A security analyst investigates an Endpoint Detection and Response (EDR) alert on an enterprise application server. Volatile memory triage reveals DLL function pointer hooking in system memory without corresponding binary files on disk, alongside a WMI event subscription executing an obfuscated PowerShell payload. Which of the following malware behaviors and indicators of compromise are characteristic of this specific incident? (Select TWO.)
Select all that apply
A cybersecurity analyst is conducting a threat model assessment for a renewable energy infrastructure firm. The analyst needs to accurately map different threat actor categories to their characteristic attributes, motivations, and attack vectors. Which of the following statements correctly align a threat actor category with its defining attributes and attack vectors? (Select TWO).
Select all that apply
During an incident response triage, a SOC analyst reviews EDR telemetry and network logs from an endpoint suspected of compromise. The logs indicate that a compromised account spawned a PowerShell process executing base64-encoded commands directly in host RAM without writing any binary payload to the local file system. Simultaneously, the endpoint initiated a high volume of outbound DNS TXT requests containing high-entropy subdomains to an unknown external domain. Which of the following technical indicators of compromise (IoCs) specifically characterize this fileless malware attack operating via Living-off-the-Land (LotL) techniques? (Select TWO.)
Select all that apply
An IT administrator at a manufacturing company discovers that an employee installed an unauthorized third-party cloud storage application on a corporate desktop to transfer large file packages, bypassing corporate security policy. Which threat vector or security risk category best describes this situation?
A security analyst is establishing a vulnerability management process for an enterprise network containing multiple isolated cloud VPCs and container worker nodes. The primary requirement is to continuously audit host operating system patch levels and missing security updates without generating network probe traffic or managing remote SSH/WinRM authentication credentials across network boundaries. Which of the following vulnerability assessment techniques best fulfills these requirements?
During a baseline security audit of an enterprise network infrastructure, a systems administrator discovers an operational network switch that is still functioning with factory-assigned administrative username and password credentials. Which of the following best classifies this host and infrastructure security weakness?
During a comprehensive enterprise security architecture assessment of a cloud-native platform, an auditor identified several critical cryptographic and security control deficiencies across different operational subsystems. Match each identified security deficiency on the left with its corresponding root cause vulnerability or architectural flaw on the right.
Click a left item, then click its matching right item
Items
Matches
An enterprise hires a third-party security firm to audit its internal payment processing system. To maximize vulnerability discovery within a short two-week assessment window, the organization provides the auditors with complete network topology maps, source code repositories, and system configuration files prior to initiating testing. Which security testing methodology is being employed in this scenario?
During a post-incident security review of a critical enterprise server, system logs indicate that disk-based malware scanners and host integrity checks reported zero altered binaries or suspicious files on the file system. However, memory analysis reveals unauthorized code executing during early system initialization, hijacking the Volume Boot Record (VBR) execution path before the core operating system kernel load and security controls initialize. Which malware classification is directly indicated by this persistence and execution behavior?
During a threat analysis following an intrusion at an international maritime logistics company, security analysts discover that an adversary gained stealthy, persistent access to port scheduling control systems using custom zero-day exploits. Forensic evidence indicates the campaign was conducted over several months without causing immediate operational disruption, backed by extensive financial resources and targeted toward strategic intelligence gathering. Which threat actor type and attribute profile is most likely responsible for this attack?
An enterprise facility relies on a legacy industrial control host running an End-of-Life (EoL) operating system that cannot receive vendor software patches. A vulnerability assessment reveals that this host communicates via unauthenticated embedded management protocols and resides on the same broad broadcast domain as employee workstations. Which of the following architectural strategies is the BEST mitigation to reduce threat exposure while ensuring continued operational functionality?
An organization's security operations center (SOC) detects an ongoing multi-vector attack targeting executive administrative assistants. The adversary uses spoofed Voice over IP (VoIP) calls to impersonate the Chief Financial Officer (CFO), claiming an urgent regulatory filing requires immediate authorization. Simultaneously, target personnel receive SMS messages containing links to a look-alike domain designed to clone the organization's single sign-on (SSO) authentication portal. Which of the following social engineering attack vectors and associated principles of influence are demonstrated in this campaign? (Select TWO).
Select all that apply