Threats, Vulnerabilities, and Mitigations
490 questions
A defense contractor's incident response team discovers that several senior propulsion engineers' workstations were compromised by specialized remote access trojans (RATs). Forensic analysis indicates that none of the engineers received malicious emails, text messages, or direct phone calls. Instead, the threat actors compromised a reputable, third-party industry standards forum frequently visited by propulsion engineers and modified its server code to dynamically serve malicious drive-by exploits only to visitors originating from the contractor's specific public IP range. Which social engineering attack vector was primarily utilized in this scenario?
A network security engineer investigates an incident where internal users on VLAN 20 report unexpected SSL/TLS certificate warnings when accessing enterprise web resources. Analysis of packet captures and wireless sensor logs reveals anomalous network frames and suspicious radio frequency traffic around the perimeter. Which of the following technical indicators collectively confirm the simultaneous presence of an ARP poisoning on-path attack and a rogue wireless access point attempt? (Select TWO.)
Select all that apply
During a post-incident review following an enterprise security evaluation, a security operations team discovers that an automated vulnerability scan failed to identify a critical unpatched remote code execution vulnerability on an internal database server. Simultaneously, the scan report flagged numerous high-severity vulnerabilities on an edge API gateway that manual verification confirmed were false positives. System logs reveal that the scanner performed service banner grabbing, port identification, and basic packet probing across subnets without host-level credentials or local management agents. Which assessment methodology limitation best explains why the scanner failed to detect the internal database flaw while producing false positives on the gateway?
A security analyst reviews a active network service list and vulnerability report for an internal host managing legacy industrial control equipment:
tcp 0 0 0.0.0.0:21 0.0.0.0:* LISTEN 1042/ftpd
tcp 0 0 0.0.0.0:23 0.0.0.0:* LISTEN 1108/telnetd
The report confirms that administrative management sessions and file uploads to this server transmit credentials in plaintext without restricted network access control lists (ACLs). Which TWO of the following architectural weaknesses or vulnerabilities are directly demonstrated in this scenario? (Select TWO.)
Select all that apply
A logistics firm is updating its threat intelligence matrix to help security staff recognize different adversary profiles. The team needs to document the primary characteristics associated specifically with nation-state threat actors (Advanced Persistent Threats). Which TWO of the following attributes best describe nation-state threat actors?
Select all that apply
A senior Security Operations Center (SOC) analyst is designing an automated threat intelligence sharing pipeline between an enterprise SIEM and a regional Information Sharing and Analysis Center (ISAC). The requirement dictates establishing an automated, machine-readable mechanism capable of transporting standardized indicators of compromise (IoCs) and threat actor context over HTTPS. Which combination of technical standards and protocols best fulfills this architectural requirement?
A security analyst is planning a vulnerability assessment for a web application deployment. The team wants to ensure both dynamic, runtime testing and passive monitoring are utilized during the security evaluation. Which of the following methods should the analyst select to accomplish these goals? (Select TWO).
Select all that apply
A security analyst reviews packet capture logs from a corporate wireless network following reports of sudden connectivity drops. The capture reveals a high volume of unencrypted IEEE 802.11 management frames containing Reason Code 7 (Class 3 frame received from nonassociated STA) broadcast from an unverified MAC address. Immediately following these frames, several client stations transmit EAPOL-Key 4-way handshake messages toward a secondary access point that is broadcasting an identical SSID on the same channel but exhibiting a significantly higher RSSI and a different BSSID. Which of the following best diagnoses the ongoing attack vector and its primary operational objective?
An organization's security team identifies that several software developers received personalized email messages appearing to originate from their version control platform administrator. The messages claimed that due to a critical security compliance violation, their repository access would be suspended within 90 minutes unless they logged into a specified web portal to verify their identity. The link provided led to a counterfeit authentication portal hosted on a visually similar, typo-registered domain designed to harvest credentials. Which of the following social engineering attack vectors and influence principles were directly employed in this campaign? (Select TWO).
Select all that apply
A security technician running an infrastructure discovery scan receives the following report for an internal management host:
[+] Host 192.168.10.45:161/UDP - Active
[+] Protocol: SNMPv2c
[+] Community String: public
[+] Extracted Info: SysName: HV-NODE01, OS: Linux 4.19, Interfaces: eth0 (192.168.10.45), eth1 (10.50.0.1 - Storage SAN)
Which of the following represents the primary host and network architecture vulnerability demonstrated in this scan output?
During a security investigation on a compromised server, an administrator suspects a rootkit has been installed to maintain stealthy persistence. Which TWO of the following indicators of compromise specifically signal the presence of a rootkit?
Select all that apply
A security team is evaluating testing methodologies to identify vulnerabilities within a newly deployed web application. To satisfy compliance standards, the team must implement security testing techniques that analyze the application while it is actively executing in a target runtime environment. Which of the following assessment methods fulfill this requirement? (Select TWO)
Select all that apply
A system administrator downloaded a third-party system maintenance utility disguised as a performance optimizer. Upon execution, the application created a persistent registry entry under `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`, established an encrypted outbound connection to an external IP address, and injected code into system processes to monitor keyboard inputs. Which of the following technical characteristics and indicators of compromise (IoCs) distinguish this threat as a Trojan with spyware capabilities rather than a self-propagating network worm? (Select TWO.)
Select all that apply
A healthcare enterprise recently integrated a third-party remote patient monitoring service that communicates via HTTPS with an internal API gateway. During an incident investigation, security analysts discovered that an attacker who obtained a compromised, revoked private key from a former partner company successfully established a man-in-the-middle (MitM) session and exfiltrated sensitive patient records. The API gateway validated that the presented certificate was issued by a trusted Certificate Authority (CA) and had not reached its expiration date, but failed to inspect current revocation data. Which cryptographic control weakness directly allowed this unauthorized session to be established?
A regional water treatment utility discovers an advanced network intrusion. Forensic investigators determine that the threat group maintained undetected persistence within the operational technology (OT) network for over nine months. Rather than deploying ransomware or causing immediate service disruption, the group focused exclusively on collecting SCADA configuration files and mapping control system logic. Which TWO of the following threat actor attributes and vector profiles most accurately describe this incident? (Select TWO)
Select all that apply
During an incident investigation at a biotechnology research facility, forensic analysts discover that an adversary gained initial network access through a compromised third-party software supply chain, utilized unpublished zero-day vulnerabilities targeting the underlying virtualization hypervisors, and established covert, out-of-band command-and-control channels to exfiltrate proprietary genomic sequencing intellectual property. The intruder maintained stealthy persistence for over ten months without altering system integrity, deploying ransomware, or publishing defacement material. Which threat actor profile MOST accurately aligns with the observed attributes, capabilities, and attack vector?
A human resources administrator receives an unexpected phone call from an individual claiming to be a senior IT compliance auditor. The caller asserts that an emergency vulnerability audit of the enterprise payroll database is currently underway and demands immediate provision of temporary administrative credentials to avoid a severe regulatory non-compliance fine. To establish credibility, the caller references specific internal department codes obtained from an employee's public professional profile. Which social engineering technique and combination of influence principles is the attacker primarily utilizing in this attack scenario?
A security technician investigating an isolated endpoint alert reviews host telemetry and memory capture files. The triage report indicates that a persistent process executing from `%APPDATA%` invokes the system API `SetWindowsHookEx` to intercept keystrokes, while simultaneously establishing an encrypted reverse shell back-connect over TCP port 443 to a remote host. The process modifies system registry run keys for boot persistence, but shows no network scanning or self-replication capabilities across local SMB shares. Which of the following malware classifications and technical indicators accurately describe this malicious activity? (Select TWO.)
Select all that apply
A user downloads a free utility program from an unverified website. After executing the installer, the utility operates as advertised, but it secretly opens a backdoor to establish unauthorized remote access for an attacker. Which malware classification best describes this malicious software?
A system administrator is reviewing a web application's legacy configuration and discovers that user passwords are saved in the database using the MD5 hashing algorithm without any salt. Which cryptographic weakness does this implementation exhibit?