Tüm alıştırma soruları
2232 soru
A multinational logistics enterprise is restructuring its security operations to satisfy data governance requirements. During an internal security management review, the audit team observes that database administrators (DBAs) are currently determining data sensitivity labels, authorizing access permissions, and establishing data retention schedules for supply chain relational databases. Executive leadership mandates that operational technical management must be separated from business data accountability. Which of the following structural adjustments best aligns with standard data governance role definitions?
An enterprise security manager is defining an updated data governance and privacy enforcement framework to ensure compliance with global regulations. Match each data governance role or privacy mechanism on the left to its corresponding operational responsibility or functional objective on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A financial technology enterprise is integrating a third-party analytical platform to evaluate customer payment trends. Legal and privacy compliance requirements state that Primary Account Numbers (PANs) transmitted to the external vendor must be replaced with random surrogate values that maintain no mathematical relationship to the underlying data. Additionally, internal billing microservices must maintain the ability to resolve these surrogate values back to the original PANs using an isolated, highly secure lookup database hosted on-premises. Which of the following privacy-enhancing controls best fulfills these requirements?
An enterprise organization is updating its data governance framework prior to launching a global customer analytics project. The Chief Risk Officer must formally segregate duties between executive business leads and technical operations staff. Which of the following duties are primary responsibilities of the Data Owner rather than the Data Custodian? (Select TWO.)
Geçerli olan tümünü seçin
An international financial services company is preparing to share historical transaction records with an external research consortium. The privacy officer mandates that the dataset must be modified so that individual data subjects can no longer be identified by any direct or indirect means, even if the records are combined with outside data sources. Once applied, this technical transformation must render the dataset completely exempt from privacy regulation requirements (such as GDPR), permitting long-term retention for analytical study. Which of the following data protection controls should the security team implement to satisfy this mandate?
A regional hospital network is deploying an automated Data Loss Prevention (DLP) system across its Electronic Health Record (EHR) databases. The database administration team has configured technical access controls, automated encrypted backups, and database audit logs. However, during a compliance audit, the team discovers that data sensitivity levels and user authorization baselines for custom health datasets were never formally defined or authorized. Which of the following responsibilities must be assigned to the Data Owner to resolve this compliance deficiency?
An automotive software enterprise is establishing privacy and governance controls for its connected vehicle telematics platform, which collects driver location history and telemetry data. The Chief Information Security Officer (CISO) designates the Fleet Analytics Product Manager as the Data Owner and the Lead Database Administrator as the Data Custodian. Which of the following operational tasks are the primary responsibility of the Data Custodian? (Select TWO.)
Geçerli olan tümünü seçin
An e-commerce enterprise is updating its security governance framework to ensure compliance with international data protection regulations. During an internal audit, the security manager discovers that database administrators (DBAs) are currently responsible for setting data sensitivity classification tags, defining retention periods, and approving access permissions for customer profile databases. Which of the following actions should the organization take to align with data governance best practices?
A security analyst is categorizing corporate IT procedures according to the core components of the AAA framework. Match each operational scenario to the AAA component it primarily demonstrates.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A system administrator is configuring access control for an enterprise network. Before a user is granted permissions to access sensitive network shares, the system must first verify who the user claims to be using a username and password. Which pillar of the Authentication, Authorization, and Accounting (AAA) framework is being performed during this initial identity verification step?
A security architect for a regional energy utility is reviewing security mechanisms implemented across the smart grid infrastructure. Match each technical security control scenario on the left with the primary CIA Triad pillar or Non-Repudiation objective it satisfies on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A cloud operations team configures an automated logging mechanism to record high-privilege configuration changes across production servers. The system computes a Hash-based Message Authentication Code (HMAC) for each log entry using a single symmetric key shared among all system administrators. Following an unauthorized system modification, an administrator denies executing the change, claiming that any user with access to the shared key could have forged the log entry. Which of the following security goals failed to be established by this logging design?
An enterprise security architect is mapping operational security controls to primary security principles within a multi-tier datacenter deployment. Match each operational control on the left with the corresponding core CIA Triad or Non-Repudiation goal on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An energy distribution company is upgrading its remote terminal unit (RTU) fleet across regional sub-stations. The security engineering team must implement a mechanism for over-the-air (OTA) control command execution. The system must guarantee that once a lead control engineer issues a high-voltage switching instruction, the engineer cannot later deny having authorized the command, and the RTUs can verify both origin authenticity and data integrity. Which of the following technical controls best satisfies this security requirement?
During a security audit of an enterprise infrastructure, a analyst discovers that network administrators authenticate via a central RADIUS server using multi-factor authentication (MFA). However, once authenticated, any administrator gains full privileged access across all routers and switches, and individual command executions are not recorded in audit logs. The CISO mandates an updated architecture that enforces granular, role-based command execution limits and records every individual command invoked during administrator sessions. Which protocol migration and AAA pillar focus directly fulfills the CISO's mandate?
A cloud compliance team is configuring an automated log aggregation vault to collect audit trails from independent third-party SaaS vendors. The organization mandates two primary security requirements for all ingested logs: first, the vault must be able to prove that a log file was not modified after creation; second, the log file must provide non-repudiation, ensuring that an untrusted vault administrator who possesses read access cannot forge a valid log entry on behalf of any vendor. Which of the following cryptographic techniques should each vendor apply to the log files prior to transmission to meet all audit requirements?
An IT security administrator is implementing the Authentication, Authorization, and Accounting (AAA) framework for remote access connections. Which of the following tasks directly represent the Accounting component of AAA? (Select TWO.)
Geçerli olan tümünü seçin
An enterprise security engineer is auditing a network management infrastructure after migrating remote administrator access to a centralized access control server. Network switches correctly validate administrator credentials against Active Directory and log the total session connection time and byte counts. However, security audits reveal that individual privilege-escalation commands (such as entering configuration modes) executed during active switch sessions are neither restricted based on administrator roles nor recorded in detailed command audit logs. Which of the following best explains why session-level authentication and accounting succeed while command-level authorization and accounting fail?
A financial organization is implementing a centralized enterprise API gateway to handle high-value B2B fund transfers with external corporate partners. The security team must ensure that once a corporate partner transmits a payment request, they cannot plausibly claim the request was forged or sent by an unauthorized party. Which of the following technical controls directly support non-repudiation for these payment requests? (Select TWO.)
Geçerli olan tümünü seçin
An organization installs a new physical access control system at the entrance of its data center. When an employee presents a smart card and enters a personal identification number (PIN), the system checks these credentials against the central directory to verify who the employee is before unlocking the door. Which component of the Authentication, Authorization, and Accounting (AAA) framework is being directly performed during credential verification?