Tüm alıştırma soruları
2232 soru
An enterprise financial organization is conducting a quantitative risk analysis for its core transaction processing database. The asset has an estimated Asset Value () of . Historical threat intelligence indicates an Exposure Factor () of () from ransomware incidents, with an Annual Rate of Occurrence () of (once every two years).
To address this exposure, the Chief Information Security Officer (CISO) evaluates a dual-layer risk management proposal:
1. Deploying an automated air-gapped immutable backup architecture costing annually, which reduces the to ().
2. Purchasing a specialized cybersecurity liability insurance policy costing annually that provides coverage up to per incident.
Based on quantitative risk assessment principles and risk response definitions, which of the following statements correctly classify the risk response strategies and numerical metrics for this organization? (Select TWO.)
Geçerli olan tümünü seçin
Match each organizational compliance scenario to the specific regulatory mandate or statutory framework that governs its security and privacy controls.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
During a vulnerability assessment of an enterprise infrastructure, a scanner flags a critical unpatched remote code execution vulnerability on a core database server. The system administrator requests to mark the finding as risk-accepted without patching, citing that an inline Network Intrusion Prevention System (NIPS) is active on the network segment. Which of the following best describes the primary operational risk of relying on this compensating control instead of applying the vendor patch?
An organization recently launched simulated phishing exercises to evaluate its human risk management program. Rather than relying solely on training completion rates, the security team wants to assess active employee engagement during a simulated attack. Which of the following metrics best indicates a positive security awareness outcome?
An organization relies on end-user reporting to reduce human risk and mitigate phishing attacks. Place the following steps in the correct sequential order from initial end-user reporting to security awareness program escalation.
Öğeleri doğru sıraya koymak için sürükleyin
A security operations team configures an isolated decoy server populated with simulated confidential files on an internal subnet. The server is designed to attract unauthorized intruders who have breached the perimeter, allowing analysts to log their activities and gather telemetry on their attack techniques without exposing production data. Which of the following security control classifications correctly identifies both the category and functional type of this deployment?
A multinational logistics enterprise headquartered in the United States processes payment card transactions for international shipments, manages personal data of European Union residents, and reports internal audit controls as a publicly traded company. The chief information security officer (CISO) is updating the enterprise regulatory compliance matrix following a cloud migration. Which of the following operational obligations directly apply to this organization? (Select TWO.)
Geçerli olan tümünü seçin
An enterprise security analyst is configuring an automated vulnerability scanner to conduct routine compliance assessments across internal production database servers. To ensure accurate vulnerability identification while preventing system downtime or account lockouts, which of the following configuration options should the analyst implement? (Select TWO.)
Geçerli olan tümünü seçin
A field technician working at a remote facility discovers several corporate-branded USB flash drives left on tables in the facility's cafeteria. Each drive is labeled with the text "Q3 Executive Compensation & Bonus Allocations - Confidential." Driven by curiosity, the technician plugs one of the drives into a corporate network workstation to view the contents, triggering an automatic payload execution that harvests local account credentials. Which type of social engineering attack vector did the threat actor utilize in this scenario?
An aerospace communications operator is updating its cybersecurity governance framework to ensure clear alignment across strategic leadership, system administrators, and third-party operational contractors. Match each governance document type on the left with its corresponding organizational scope and operational requirement on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An organization's security operations center observes that newly provisioned virtual servers in a public cloud environment consistently lack mandatory security monitoring agents and feature non-standard firewall configurations. An investigation reveals that system administrators are manually launching instances from legacy local image templates instead of using approved central images. Which of the following operational practices should the organization implement to MOST effectively prevent future configuration drift?
A financial firm is onboarding a cloud-based Software-as-a-Service (SaaS) provider to process confidential customer transactions. To maintain governance, the security team needs to contractually enforce defined operational uptime thresholds and mandate strict compliance with data handling responsibilities. Which TWO of the following agreements or contractual components should the firm execute to achieve these specific objectives?
Geçerli olan tümünü seçin
A publicly traded digital media enterprise experiences an unauthenticated API breach exposing non-sensitive server telemetry logs. During incident containment, security analysts discover that the threat actor attempted lateral movement toward backend financial databases, causing a temporary three-hour outage of the core subscription billing microservice before being isolated. The incident response team confirms no customer PII or financial data was exfiltrated. The corporate legal and compliance committee is evaluating reporting requirements under Securities and Exchange Commission (SEC) cyber disclosure mandates. Which of the following factors primary determines whether the enterprise must report this incident on Form 8-K within the required four-business-day timeframe?
A healthcare organization is reviewing third-party compliance documentation for a cloud-based medical billing platform. The compliance team specifically requires independent verification that the vendor's internal controls over financial reporting (ICFR) operating within the platform are effectively designed and operating as intended over time. Which of the following audit reports should the organization request to satisfy this requirement?
An enterprise organization is enhancing its supply chain security and vendor governance program to address risks associated with third-party software, hardware, and service providers. Match each vendor oversight mechanism or contractual control on the left to its corresponding supply chain risk management purpose on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A security administrator is refining the Public Key Infrastructure (PKI) deployment for an enterprise RADIUS server supporting 802.1X EAP-TLS authentication. Mobile clients connecting over high-latency cellular links experience frequent authentication timeouts caused by real-time Certificate Revocation List (CRL) downloads. To optimize client authentication performance and ensure secure server identity verification, which of the following mechanisms or configurations should the administrator implement? (Select TWO).
Geçerli olan tümünü seçin
A financial technology firm's executive board issues a high-level directive requiring all employee remote access connections to utilize multi-factor authentication. To implement this directive across the organization, the security operations team must publish a mandatory document that defines the specific technical controls and required configuration rules for all remote access gateways. Which governance document type should the team publish to establish these mandatory requirements?
A security analyst is classifying enterprise defense mechanisms according to CompTIA Security+ implementation categories (Technical, Managerial, Operational, Physical) and functional control types (Preventive, Deterrent, Detective, Corrective, Compensating, Directive). Match each security scenario on the left with its primary dual-axis security control classification on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A manufacturing enterprise is performing a quantitative risk assessment on its automated build pipeline server fleet. The fleet has an Asset Value () of . A risk analysis team determines that a supply chain compromise would yield an Exposure Factor () of . Threat intelligence estimates the Annualized Rate of Occurrence () for such an attack to be (occurring once every two years).
What is the Annual Loss Expectancy () in dollars for this asset?
A satellite communications provider is formalizing its enterprise security oversight framework following a regulatory audit. Security analysts must properly categorize governance artifacts to establish clear organizational hierarchy. Match each security governance document type on the left with its defining operational characteristic on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler