Tüm alıştırma soruları
2232 soru
A security architect is designing an Identity and Access Management (IAM) architecture for a microservices-based application deployed across multiple cloud environments. To align with Zero Trust principles, the architecture must issue short-lived, cryptographically verifiable identities to service workloads and decouple fine-grained authorization enforcement from application code. Which of the following protocols or architectural components should the architect integrate to satisfy these requirements? (Select TWO.)
Geçerli olan tümünü seçin
A security analyst is evaluating code remediation requirements following an assessment of an enterprise web portal. The evaluation identified two primary software flaws: database queries constructed by concatenating unsanitized user inputs, and user-submitted data reflected directly into rendered HTML responses without escaping. Which of the following mitigation strategies must developers implement to address these specific application vulnerabilities? (Select TWO).
Geçerli olan tümünü seçin
A defense technology organization is implementing Zero Trust Architecture (ZTA) for field operations. Mobile tactical command units must access centralized intelligence databases across untrusted wireless channels. To strictly adhere to Zero Trust principles, the architecture must decouple control plane policy evaluation from data plane enforcement. Which of the following implementations correctly demonstrates this architectural separation?
During a forensic investigation of a compromise on a critical database host, an incident handler needs to collect evidence while the system remains powered on. To minimize data loss, which of the following evidence acquisition steps should be executed FIRST according to the order of volatility?
A Security Operations Center (SOC) analyst receives a high-severity Endpoint Detection and Response (EDR) alert indicating an active living-off-the-land attack where a compromised workstation is attempting lateral movement via WMI and fileless memory injection. Arrange the following incident response containment and forensic actions in the correct sequential order from first step to last step.
Öğeleri doğru sıraya koymak için sürükleyin
A security analyst evaluates an enterprise environment where legacy monitoring agents running on internal host servers transmit host telemetry data using unencrypted broadcast traffic across a flat management subnet. Additionally, internal host-to-host administrative communication is automatically permitted based strictly on subnetwork IP address origin without requiring continuous session verification or microsegmentation.
Which of the following vulnerabilities are present in this architectural deployment? (Select TWO.)
Geçerli olan tümünü seçin
A telecommunications enterprise security team detects covert data staging on an internal jump host. The activity was conducted during off-peak hours using valid domain administrative credentials, bypassing perimeter firewalls without triggering external traffic alerts. The entity utilized native system administration tools to clear system logs and pivot into restricted intellectual property repositories. Which TWO of the following threat actor attributes or capabilities are most characteristic of this adversary profile? (Select TWO)
Geçerli olan tümünü seçin
A security analyst conducts an internal infrastructure assessment of an enterprise application environment. The assessment reveals two critical architectural findings:
1. Web application microservices communicate with back-end database servers across an unsegmented internal subnet using standard unencrypted HTTP endpoints.
2. No host-based firewalls or network access control lists (ACLs) are configured to restrict traffic between adjacent application servers on the same subnet.
Which of the following host, network, or architecture vulnerabilities are directly present in this environment? (Select TWO.)
Geçerli olan tümünü seçin
A financial organization is migrating an existing legacy internal application to a public Infrastructure as a Service (IaaS) environment. Under the cloud shared responsibility model, which of the following security management tasks are the direct responsibility of the organization? (Select TWO.)
Geçerli olan tümünü seçin
A threat hunting team analyzes workstation artifacts following reports of compromised privileged account credentials. Network telemetry and host activity reveal an unauthorized background program that captures input typed into authentication forms and periodically exfiltrates this data to an external server over port 443. The software was installed after an employee executed a third-party utility download, does not attempt to scan or self-replicate across local subnet subnets, and does not modify kernel-level system routines. Which of the following malware classifications best describes this threat?
A security technician conducts an assessment of an embedded building control device connected to an enterprise network. A vulnerability scan produces the following finding:
Host: 192.168.4.12
Port: 8080/tcp (HTTP)
Finding: Embedded Web Interface Hardcoded Credentials
Risk Level: High
Description: The device firmware contains fixed administrative credentials transmitted in cleartext over HTTP. No vendor security patches are available.
The legacy device must remain operational for business operations. Which of the following architecture-level mitigations is the BEST solution to protect the enterprise from this host vulnerability?
A cybersecurity analyst needs to assess internal enterprise servers for missing software security patches and configuration flaws without sending intrusive exploit payloads or generating heavy network traffic across the subnet. Which of the following vulnerability assessment methods should the analyst perform?
A security operations team is designing a vulnerability assessment strategy for a legacy operational technology (OT) network housing fragile programmable logic controllers (PLCs). Prior active network vulnerability scans against these devices caused unexpected buffer overflows, triggering critical system resets and operational downtime. Which of the following approaches should the analyst implement to safely identify known software vulnerabilities on these OT assets without risking system instability?
A smart manufacturing facility is updating its industrial control network to align with Zero Trust Architecture (ZTA) principles. Currently, field sensor nodes and automated robotic assembly controllers communicate freely within an internal operational technology (OT) network segment once inside the network perimeter. Which of the following architectural modifications best implements the core Zero Trust principle of continuous explicit verification for these device communications?
Match each vulnerability assessment scan approach with its corresponding operational description.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An enterprise Security Operations Center (SOC) team is configuring an automated playbook within their Endpoint Detection and Response (EDR) solution to respond to an active ransomware outbreak involving credential dumping and process injection. Place the incident response steps in the correct operational order from initial containment through complete host restoration.
Öğeleri doğru sıraya koymak için sürükleyin
An enterprise Endpoint Detection and Response (EDR) system alerts a security analyst to an active malicious code injection on a user workstation. Sequence the standard EDR response steps from initial detection to host restoration.
Öğeleri doğru sıraya koymak için sürükleyin
An organization plans to deprecate legacy cryptographic protocols across all internal application gateways during a scheduled maintenance window. Following the change execution, several mission-critical legacy internal applications lose connection to the centralized authentication service, causing widespread business disruption. Investigation reveals that while the protocol deprecation was approved by the Change Advisory Board (CAB), the technical change request did not evaluate application-level dependency on legacy protocol suites. Which of the following change management practices was omitted prior to submission?
A system administrator notifies the incident response team after discovering that a critical internal database server containing confidential customer records is actively opening outbound connections to an unknown remote IP address. Endpoint monitoring confirms an unauthorized background process executing with administrative privileges and sending encrypted data packages outside the enterprise network boundary. According to standard incident response frameworks, which of the following actions should the team take FIRST?
A security analyst is reviewing the risk register for an organization's legacy operational technology (OT) environment. Due to vendor constraints, the OT systems cannot be updated with recent security patches, leaving them vulnerable to remote code execution exploits. To address this risk without disrupting active business operations or decommissioning the equipment, which of the following response strategies and control implementations should the analyst recommend? (Select TWO.)
Geçerli olan tümünü seçin