Tüm alıştırma soruları
2232 soru
A network security administrator is commissioning a new internal web application server that requires a trusted SSL/TLS certificate signed by the enterprise internal Certificate Authority (CA). Which of the following sequences represents the correct chronological order of steps the administrator must perform to obtain and deploy this certificate?
Öğeleri doğru sıraya koymak için sürükleyin
A financial services firm operating in the United States is updating its security governance controls to maintain compliance with Sarbanes-Oxley Act (SOX) Section 404 requirements. The security manager must implement controls that verify the integrity and accuracy of internal financial reporting data stored within enterprise systems. Which of the following actions best fulfills this specific regulatory requirement?
During a Business Impact Analysis (BIA) for a commercial bank's real-time fraud detection engine, the risk management team establishes two key operational constraints: transaction data loss must not exceed 15 minutes of activity, and the service must be fully operational within 2 hours following a disaster to avoid severe regulatory penalties. Which of the following metric assignments correctly aligns with these BIA findings?
A receptionist at an enterprise regional office receives a phone call from an individual claiming to be a technician from the building management company. The caller states that an urgent HVAC emergency requires immediate physical access to the server room key box and asks the receptionist to read the emergency access PIN code over the phone. The caller provides fake ticket numbers and references real facility manager names to build credibility. Which of the following social engineering techniques did the attacker primarily execute in this scenario?
During a physical security audit, an analyst notes multiple instances of unauthorized visitors entering secure facility zones by closely following badged employees through access doors. Which of the following security awareness initiatives is the most effective administrative control to directly reduce employee susceptibility to this risk?
An organization deploys a new RADIUS server to support 802.1X EAP-TLS authentication across corporate laptops. During testing, client devices fail to authenticate, reporting that the RADIUS server's identity cannot be verified. Analysis indicates that while client devices trust the organization's offline Root CA, the RADIUS server is transmitting only its leaf certificate, and clients cannot validate the intermediate issuing CA that signed it. Which of the following configuration changes on the server will resolve the authentication failure?
A Security Operations Center (SOC) analyst is reviewing network security monitoring alerts generated by a Network Traffic Analysis (NTA) sensor inspecting perimeter egress traffic. The sensor triggers a high-severity alert for an outbound TCP session originating from an internal host () to an external server ():
src_ip: 10.2.14.50
src_port: 51024
dest_ip: 198.51.100.89
dest_port: 443
transport: tcp
detected_protocol: ssh
expected_protocol: tls
alert_type: Protocol Mismatch / Evasion
Based on the log snippet provided, which of the following is the most accurate interpretation of this network security monitoring alert?
A newly appointed Chief Information Security Officer (CISO) at a global renewable energy management corporation is restructuring the organization's security documentation hierarchy. Match each security governance document type on the left with its corresponding operational characteristic on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A United States-based Software-as-a-Service (SaaS) provider stores customer analytics records on cloud servers located exclusively in North America. A European Union-based multinational enterprise plans to subscribe to the platform but requires a legally recognized mechanism to ensure that cross-border transfers of personal data outside the European Economic Area (EEA) maintain compliance with data privacy regulations. Which of the following mechanisms directly satisfies this regulatory compliance requirement under the General Data Protection Regulation (GDPR)?
A security analyst is reviewing business continuity and resilience planning metrics following a Business Impact Analysis (BIA) for a critical enterprise application. Match each business continuity metric on the left with its corresponding operational definition on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
Match each social engineering attack vector or influence principle on the left with the enterprise incident scenario on the right that best demonstrates its execution.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
Following an increase in security events involving remote employees working from public locations, an organization updates its security awareness program to focus on human risk management for mobile workers. Which of the following administrative and operational security awareness controls should the security team implement to directly address these human-centric risks? (Select TWO.)
Geçerli olan tümünü seçin
A systems engineer is implementing security controls for a enterprise API gateway that requires mutual TLS authentication. To optimize client connection speeds, the engineer wants to eliminate third-party real-time lookup latency during certificate revocation verification. Additionally, the engineer must request a new web server certificate following strict Public Key Infrastructure (PKI) enrollment best practices. Which of the following steps should the security engineer take to meet these requirements?
Geçerli olan tümünü seçin
An enterprise healthcare provider establishes an executive directive mandating that all sensitive patient data must be encrypted both in transit and at rest across all internal systems. To operationalize this executive mandate, the IT security team creates a mandatory compliance document that details the specific required cryptographic algorithms, minimum key lengths, and approved cipher suites that system administrators must configure on all database nodes without exception. Which component of the security governance hierarchy does this technical configuration document represent?
A network security analyst receives a high-severity alert from a Network Traffic Analysis (NTA) system regarding anomalous outbound encrypted communications originating from an internal workstation. Place the following incident triage and response steps in the correct sequential order from initial alert verification to containment.
Öğeleri doğru sıraya koymak için sürükleyin
A pharmaceutical research organization completes a Business Impact Analysis (BIA) for its clinical trial data management system. The BIA determines that during an unplanned system outage, the organization can tolerate losing a maximum of 15 minutes of uncommitted trial records, while the system itself must be restored to functional operation within 6 hours. Which of the following metrics represents the 15-minute maximum data loss threshold?
An e-commerce corporation is auditing its security program to ensure proper alignment between executive directives, technical requirements, and operational advice across software development teams. The Chief Information Security Officer (CISO) publishes an updated organizational framework document. Which of the following governance elements represent mandatory requirements that organizational members and technical systems must strictly comply with? (Select TWO.)
Geçerli olan tümünü seçin
An organization recently transitioned from mandatory annual security awareness video training to monthly role-based microlearning simulations tailored to high-risk personnel. The Chief Information Security Officer (CISO) wants to evaluate whether this new program effectively mitigates human risk rather than just satisfying compliance requirements. Which of the following metrics provides the most direct evidence of behavioral risk reduction among staff?
An enterprise security administrator is deploying a high-traffic public web application server using TLS encryption. To minimize TLS handshake latency and prevent third-party tracking of user browsing habits caused by real-time client queries to an external Certificate Authority (CA), the administrator wants the web server to fetch and cache signed revocation status responses from the CA to append during the TLS handshake. Which of the following solutions should the administrator implement?
An accounts payable specialist receives an urgent email that appears to originate from the organization's Chief Financial Officer (CFO). The message references an undisclosed legal settlement and directs the specialist to immediately wire $45,000 to an external account, explicitly instructing them to bypass normal dual-authorization procedures to meet a strict deadline. Investigation reveals the message originated from an external domain registered to mimic the enterprise domain by substituting the letter 'o' with the number '0'. Which of the following attack types is best described in this scenario?