Tüm alıştırma soruları
2232 soru
A security team at a regional retail corporation is investigating a security incident involving unauthorized access to internal file servers. The attacker gained access using valid employee credentials purchased from an online broker, deployed commercially available ransomware within two hours of access, and left a ransom note demanding an immediate cryptocurrency payment. The investigation confirmed that no sensitive intellectual property was exfiltrated and no attempts were made to establish long-term persistence. Which threat actor category and attribute profile are most consistent with this attack?
A security operations team is organizing its threat intelligence pipeline to improve context, automation, and threat response capabilities across different enterprise monitoring tools. Match each threat intelligence source type on the left to its corresponding operational characteristic or operational capability on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A systems administrator observes that unauthenticated, network-based vulnerability scans are failing to detect internal software patch status and host misconfigurations due to strict host-based firewall rules blocking network probes on corporate endpoints. The administrator needs to collect detailed vulnerability data across all endpoints without altering network firewall policies or exposing administrative credentials across network subnets. Which of the following vulnerability assessment methods should the administrator implement?
During a routine internal audit of an enterprise infrastructure, a security analyst reviews a vulnerability scan report for an Active Directory server host. The scan highlights that a custom system service executable path is configured as C:\Program Files\Enterprise Apps\Service Manager\service.exe without quotation marks, and the directory C:\Program Files\Enterprise Apps has write permissions granted to unprivileged users. Which of the following host vulnerabilities does this specific configuration represent?
A Incident Response Team is responding to an ongoing breach where an adversary compromised an automated CI/CD pipeline build runner service account. The attacker injected malicious code into build scripts and is actively exfiltrating deployment credentials over an encrypted tunnel. Playbook analysis indicates the attack payload includes an automated anti-forensic wiper script that triggers upon service account termination or system reboot. Which TWO of the following immediate actions should the incident response handler perform to isolate the threat and preserve volatile evidence? (Select TWO.)
Geçerli olan tümünü seçin
An enterprise security audit reveals that workstations in a software development subnet can establish direct, unmonitored SSH and remote execution sessions to production database servers without passing through a centralized management gateway. Which of the following mitigation strategies should the security team implement FIRST to enforce strict administrative boundary isolation and prevent unauthorized lateral movement?
A security analyst reviews device logs following reports of abnormal wireless activity on an executive's smartphone during an off-site conference. The logs indicate that the smartphone first accepted an unsolicited vCard contact file over an unauthenticated Bluetooth Object Exchange (OBEX) connection. Immediately after, an unauthorized background process queried and exfiltrated the device's internal calendar entries and contact lists over Bluetooth without requesting user pairing approval. Based on these technical indicators, which of the following wireless attacks occurred? (Select TWO).
Geçerli olan tümünü seçin
A security engineer at a utility organization oversees a fleet of distributed industrial edge gateways. Following a vendor firmware patch rollout, a security audit reveals that multiple gateways experienced configuration drift, automatically re-enabling legacy, unencrypted management protocols that violate organizational hardening standards. The engineer must implement a solution that continuously detects non-compliant settings and automatically restores all gateways to their authorized security baseline without manual intervention. Which of the following is the BEST solution to meet these requirements?
A security administrator at a financial institution is auditing Privileged Access Management (PAM) logs following an automated night-shift batch job failure. The log analysis reveals that a dedicated service account was locked out because a recently updated global security baseline enforced interactive multi-factor authentication (MFA) and a 30-day password expiration policy across all privileged identities. Which of the following is the MOST appropriate operational remedy to ensure unattended batch processing succeeds without compromising privileged security controls?
A security analyst is configuring an internal vulnerability assessment for a enterprise web platform located behind a reverse proxy. The platform includes legacy application services that are highly sensitive to traffic spikes. The analyst needs to obtain precise host vulnerability data while preventing service outages on legacy components. Which of the following scanner configurations and techniques should the analyst implement? (Select TWO.)
Geçerli olan tümünü seçin
During a security incident investigation on an enterprise server host, security analysts discover that an attacker exploited a vulnerability within a containerized application process to inject a malicious kernel module. This kernel module allowed the attacker to escape the application environment, gain full root control over the underlying host operating system, and access data across all neighboring tenant applications on that physical node. Which of the following fundamental architectural weaknesses enabled this cross-tenant host compromise, and what control provides the required isolation boundary?
A security analyst at a municipal emergency dispatch center is investigating a targeted network breach. The adversary gained initial access through compromised supply chain vendor credentials, utilized custom zero-day exploits to maintain persistent access across system reboots, and subtly modified dispatch routing tables without demanding a ransom or exfiltrating data. Threat intelligence reports indicate the threat group operates with state-sponsored backing, high technical sophistication, and extensive financial resources aimed at critical infrastructure disruption. Which of the following threat actor categories best describes the adversary behind this attack?
A security analyst reviews a vulnerability assessment report for an internal application server host. The report contains the following network service scan snippet:
Host: 192.168.4.15
Port: 1099/TCP
Service: Java JMX RMI
Finding: Remote JMX agent accepting unauthenticated connections. Anonymous users can register MBeans and execute arbitrary code with host system privileges.
Which of the following represents the BEST remediation strategy to address this host vulnerability?
A network security architect is designing an ingress traffic transit flow for an enterprise application processing sensitive financial data. External client traffic must traverse multiple physical and logical security zones to interact with the backend database while enforcing strict North-South and East-West control boundaries. Arrange the following network security architecture traversal steps in the correct sequential order from the initial external inbound packet arrival to the final payload processing at the database host.
Öğeleri doğru sıraya koymak için sürükleyin
An organization notices that several corporate laptops used by remote employees have failed to apply a critical operating system security patch dispatched by the patch management server. Investigation reveals that the employees continuously opted to defer the required system restart, causing their devices to fall out of compliance with the enterprise security configuration baseline. Which of the following technical controls would most effectively enforce compliance and ensure the required patch installation before granting endpoints access to internal network resources?
A security analyst reviewing a Security Information and Event Management (SIEM) log aggregator observes the following consecutive Kerberos event entries generated by internal endpoint `10.0.12.88` within a 90-second time window:
text 2026-07-27T11:02:14Z | EventID: 4769 | TargetUser: [email protected] | ServiceName: MSSQLSvc/sql01.corp.local:1433 | TicketEncryption: 0x17 (RC4-HMAC) | Status: 0x0 2026-07-27T11:02:41Z | EventID: 4769 | TargetUser: [email protected] | ServiceName: BackupSvc/storage01.corp.local | TicketEncryption: 0x17 (RC4-HMAC) | Status: 0x0 2026-07-27T11:03:12Z | EventID: 4769 | TargetUser: [email protected] | ServiceName: HTTP/webserver01.corp.local | TicketEncryption: 0x17 (RC4-HMAC) | Status: 0x0
Based on the log output, which attack technique is taking place, and what correlation rule condition should the analyst configure in the SIEM to detect this activity?
A enterprise healthcare provider relies on a software-as-a-service (SaaS) vendor for managing patient scheduling. The vendor provided a SOC 2 Type II attestation report covering the twelve-month period ending September 30. However, the healthcare provider's annual compliance audit occurs on December 31, resulting in a three-month gap between the vendor's audit end date and the healthcare provider's fiscal year end. Which of the following documents should the vendor provide to confirm that no material changes affected the control environment during this gap period?
A financial technology platform operating in North America provides automated payroll processing software to publicly traded enterprise clients. During an internal audit, security team members discover that system administrators can directly modify system logs and executive compensation reporting data without triggering an independent approval workflow or producing an immutable audit record. Which legal or regulatory requirement mandates the implementation of strict internal controls to guarantee the integrity, oversight, and auditability of these financial records?
An enterprise software company is updating its data governance program following an internal compliance assessment. A senior database administrator has been tasked with configuring database permissions, executing automated daily backups, and applying technical data loss prevention tags. The product management team requests that a key customer telemetry dataset be reclassified from Restricted to Confidential to enable easier integration with an external analytics vendor. Which of the following best describes the correct operational procedure for handling this request?
An enterprise organization recently deployed a critical application database server equipped with redundant hot-swappable power supplies and a RAID 5 disk array to fulfill a high-availability SLA. Following a malicious script execution, essential database tables were logically corrupted and encrypted. The network administrator confirmed that all hard drives and hardware components remained fully operational with active green status indicators, yet data restoration from the local array was impossible. Which of the following best explains why this high-availability configuration failed to preserve data access, and what control should be implemented?