Tüm alıştırma soruları
2232 soru
An enterprise web portal requires remote employees to enter a username and a dynamic one-time password (OTP) generated by an authenticator application to prove who they are before entering the network. Which pillar of the AAA framework is directly performed during this credential verification step?
An organization is transitioning from a traditional boundary firewall model to a Zero Trust Architecture (ZTA). An administrator is configuring access rules for internal workstations connected directly to the corporate office local area network. Which of the following statements best reflects a fundamental Zero Trust principle that should guide this configuration?
A security administrator is categorizing system events and operational functions into the core pillars of the Authentication, Authorization, and Accounting (AAA) framework. Match each operational scenario on the left to the corresponding AAA pillar on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
Match each core Zero Trust Architecture (ZTA) principle to its corresponding operational description.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A security architect is reviewing an organization's microservice API gateway architecture. The gateway successfully validates JSON Web Tokens (JWTs) issued by a central Identity Provider to confirm user identity upon initial request. However, once validated, the gateway forwards all traffic to backend microservices using a shared system service account with unrestricted permissions, and backend service logs only record the gateway's IP address. Which of the following correctly identifies the AAA pillars that are currently deficient in the backend microservice architecture and the necessary control implementation?
A hospital network requires attending physicians to electronically sign controlled substance prescriptions. The security engineering team mandates the use of asymmetric key digital signatures on hardware security tokens rather than hash-based message authentication codes (HMACs) utilizing a shared key between the hospital system and the pharmacy portal. Which of the following primary security concepts explains why asymmetric digital signatures are required for this deployment?
Match each enterprise identity and access management scenario on the left with the corresponding core AAA phase or concept on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A security engineering team is establishing baseline controls for a cloud-native software delivery pipeline. Match each security implementation on the left with the primary security objective (CIA Triad pillar or Non-Repudiation) it provides on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A system administrator is reviewing log retention policies and system auditing controls to ensure compliance with AAA principles. Which of the following tasks specifically perform the Accounting function of AAA? (Select TWO.)
Geçerli olan tümünü seçin
A financial services firm is implementing Zero Trust Architecture (ZTA) principles to govern remote employee access to cloud-hosted databases and web services. A security engineer is establishing authorization policies at the gateway level. To align with the core Zero Trust tenets of continuous verification and explicit validation, which of the following mechanisms should the engineer enforce?
An enterprise organization is updating security policies for employees accessing corporate SaaS applications. To align with Zero Trust Architecture principles, the security engineering team configures the identity provider to re-evaluate user identity, device health posture, and geolocation context for every single access request, rather than granting trusted access for the duration of the session after initial login. Which core Zero Trust Architecture principle is directly implemented by this configuration?
A pharmaceutical research organization operates a platform where external laboratories submit clinical trial data files. To meet regulatory requirements, the security team must implement a mechanism ensuring that a submitting laboratory cannot later deny having submitted a specific file. Which of the following mechanisms best provides this non-repudiation capability?
An enterprise security team is implementing NIST SP 800-207 Zero Trust Architecture (ZTA) principles across their hybrid cloud infrastructure. Match each core Zero Trust operational requirement to its corresponding technical implementation.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An enterprise security team deploys a centralized RADIUS server for remote VPN access. During a post-deployment audit, a security analyst reviews the access workflow: users validate their identity via multi-factor authentication, the RADIUS server returns Vendor-Specific Attributes (VSAs) specifying restricted network segments to the VPN gateway, and the gateway transmits session durations to a central SIEM. The analyst discovers that while identity validation succeeds, the RADIUS policy engine fails to evaluate user group memberships properly and instead attaches default attributes granting unrestricted network access across all enterprise subnets. Which pillar of the AAA framework is failing to function as intended?
A security administrator needs to ensure that sensitive company data stored on enterprise laptops remains confidential if a laptop is lost or stolen, and must also verify that system configuration files have not been modified. Which of the following cryptographic techniques should the administrator implement to fulfill these requirements? (Select TWO.)
Geçerli olan tümünü seçin
A network security gateway generates logs that record the start time, end time, and total volume of data transmitted during a user's remote connection session. Which pillar of the Authentication, Authorization, and Accounting (AAA) framework is directly provided by recording these metrics?
An enterprise legal technology organization is upgrading its electronic contract processing platform. The platform must implement controls to guarantee non-repudiation so that signers cannot plausibly deny their participation in executing an agreement. Which of the following technical mechanisms directly satisfy the requirement for non-repudiation? (Select TWO.)
Geçerli olan tümünü seçin
During a post-incident review at a logistics company, security analysts discovered that an administrator modified system event logs and disputed making any changes. The logging infrastructure maintained file integrity using standalone SHA-256 hashes stored alongside the logs, but because multiple staff members had write permissions to update those hash files, individual accountability could not be established. Which of the following solutions should the organization implement to achieve non-repudiation for log updates?
An enterprise security engineer is auditing the AAA implementation of a newly deployed hybrid cloud access portal. The engineer needs to ensure that access governance controls are strictly categorized according to core AAA principles. Which of the following technical controls specifically perform the Authorization function within this framework? (Select TWO).
Geçerli olan tümünü seçin
A systems analyst is selecting an encryption method to protect large volumes of static data archived on enterprise storage arrays. The primary requirement is high-speed performance and minimal processing overhead during bulk encryption and decryption operations. Which of the following cryptographic approaches should the analyst implement?