Tüm alıştırma soruları
2232 soru
A Chief Information Security Officer (CISO) is evaluating two mutually exclusive risk response proposals for an enterprise cloud platform with an estimated Asset Value () of . Threat intelligence and historical logs establish an baseline Annual Rate of Occurrence () of and an Exposure Factor () of .
- Proposal 1 (Risk Mitigation): Deploy automated microsegmentation and advanced web application defense controls costing annually. This control reduces the to and decreases the to .
- Proposal 2 (Risk Transference): Procure a cybersecurity insurance policy costing annually with a deductible per incident. The policy covers all loss exceeding the deductible per event, effectively capping the Single Loss Expectancy () at , while leaving the at .
Based on quantitative risk analysis, which proposal delivers the maximum net annual financial benefit (gross annual risk reduction minus implementation cost), and what is that net financial benefit value?
During off-hours monitoring, a security operations analyst identifies an active, unauthorized bulk exfiltration of sensitive personnel records from an internal HR database server to an external IP address via a compromised service account. The analyst has confirmed that the exfiltration is actively taking place. According to standard incident response lifecycle guidelines, which of the following actions should the analyst take FIRST?
A security engineer is updating the firmware verification process for remote, low-power industrial sensor gateways. The firmware update image must be digitally signed by the vendor to verify its origin and integrity before installation. Due to severe memory and processing constraints on the gateway hardware, the solution must provide strong asymmetric security while minimizing key size and computational overhead. Which cryptographic algorithm combination should the engineer select?
A logistics enterprise operates an automated fleet dispatch server with an Asset Value () of . Historical security data indicates that severe malware incidents impact this server once every four years (), resulting in an Exposure Factor () of . To mitigate this risk, the organization plans to deploy an Endpoint Detection and Response (EDR) control that will reduce the Exposure Factor () to , while the remains unchanged. The total annual cost to license and maintain the EDR solution is . What is the net annual financial benefit (in USD) of implementing the EDR safeguard?
In an enterprise information security program, governance documentation is structured into distinct tiers based on enforceability, scope, and technical specificity. Match each governance document type on the left with its corresponding operational characteristic on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A security analyst at a maritime logistics firm is performing a quantitative risk assessment for an automated port crane control system with an estimated asset value of 100,000. A proposed security control consisting of network isolation and endpoint protection costs $15,000 annually to maintain and would reduce the ARO to 0.05. What is the net annual financial benefit of implementing this security safeguard?
Match each Business Impact Analysis (BIA) and Business Continuity Management (BCM) metric on the left with its accurate operational definition on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An organization has officially terminated its contract with a third-party software development vendor. To minimize third-party security risk immediately following the end of the contractual relationship, which of the following operational tasks should the security administrator complete first?
Match each third-party risk management document or agreement to its primary organizational security purpose.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A security engineer is auditing an automated provisioning pipeline for a fleet of internal microservice gateways. The deployment script generates a single public/private key pair and Certificate Signing Request (CSR) on a central management server, submits the CSR to the internal Certificate Authority (CA), and then copies the issued certificate and private key over SSH to all target gateway nodes. Which of the following best describes the primary security flaw in this PKI workflow?
An enterprise is contracting with a cloud service provider to host its business-critical applications. The security team needs to establish clear operational requirements regarding system uptime response expectations, scheduled maintenance windows, and financial remedies if performance targets are missed. Which of the following agreements should be implemented to define these specific requirements?
Match each vulnerability scanning methodology with its most appropriate enterprise operational scenario.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A software development firm is enhancing its software supply chain risk management following a security incident where a tampered third-party open-source library introduced malicious code into the build pipeline. Which TWO of the following technical controls should the security team implement to verify third-party component integrity and maintain ongoing visibility into software supply chain vulnerabilities? (Select TWO.)
Geçerli olan tümünü seçin
A network security monitoring (NSM) system triggers an automated alert indicating anomalous outbound TLS traffic from an enterprise host to an unrated external IP address. In what sequence should a network analyst execute the technical triage and mitigation workflow?
Öğeleri doğru sıraya koymak için sürükleyin
An enterprise security architect is formalizing the organization's third-party risk management framework and supply chain security controls. Match each vendor risk oversight scenario to the most appropriate verification mechanism or audit artifact required to validate the control.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An enterprise security team is refining its third-party risk management framework to evaluate complex software supply chains and downstream vendor dependencies. Match each third-party oversight mechanism to its primary risk management or governance objective.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A security enterprise architect is formalizing Business Impact Analysis (BIA) and Business Continuity Management (BCM) metrics for a multi-region cloud deployment. Match each continuity metric on the left with the operational description on the right that best defines its role in disaster recovery planning.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An organization's security team detects an unauthorized login to a corporate account. Incident analysis reveals that the compromised employee received an SMS notification on their mobile device claiming to be from the IT helpdesk, warning that their account access would be revoked unless verified immediately via a provided URL. The link directed the user to a fraudulent authentication portal where their credentials were captured. Which social engineering attack vector initiated this security incident?
An organization's DevSecOps team is implementing a supply chain security framework to validate third-party software packages and open-source dependencies incorporated into its CI/CD pipeline. The security posture mandates continuous visibility into nested software components and verification that compiled binaries match their declared source code repositories. Which of the following solutions should the security team implement to achieve this objective?
Match each regulatory framework or legal mandate to its corresponding compliance and scope requirement.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler