Tüm alıştırma soruları
2232 soru
A security engineer is configuring an automated failover workflow for an active-passive high-availability database cluster to prevent split-brain conditions and ensure data integrity during an ungraceful primary node failure. Arrange the operational steps in the correct chronological order from initial failure detection to full service restoration on the standby node.
Öğeleri doğru sıraya koymak için sürükleyin
An enterprise financial platform maintains an active-passive database cluster across two data centers using synchronous storage replication to satisfy a Recovery Point Objective (RPO) of zero. During a security architecture review, an auditor notes that while synchronous replication protects against site-level hardware failure, a ransomware infection or database corruption on the primary node will instantly mirror to the secondary node, destroying operational integrity across both sites. Which of the following technical solutions best maintains high availability while ensuring recovery capability against logical data corruption?
A cloud-native software provider operates a microservices workload where internal APIs communicate across multiple environments. A threat actor successfully steals active bearer tokens from a developer workstation located on the internal office LAN. When the attacker uses these stolen tokens to invoke downstream financial data microservices from inside the corporate network, access is denied due to an anomalous device posture score and unverified request velocity. Which core Zero Trust Architecture principle directly prevented this lateral movement despite the presentation of valid authentication credentials from an internal source?
Match each Zero Trust Architecture (ZTA) logical component defined in NIST SP 800-207 to its primary operational responsibility.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An enterprise DevOps team implements a security policy requiring all software developers to digitally sign Git commits using their individual GPG private keys prior to merging code into the production repository. The central repository server automatically validates each signature against the developer's registered public key. Which of the following security objectives are directly achieved by enforcing this digital signature mechanism? (Select TWO.)
Geçerli olan tümünü seçin
An enterprise health system is updating its clinical application platform to align with Zero Trust Architecture (ZTA) principles. During an architectural review, an engineer proposes that once a medical professional completes multi-factor authentication (MFA) at the central identity provider (IdP) and receives a session token, all subsequent API requests sent to internal microservices during their 8-hour shift should be implicitly trusted without re-assessing device posture or access policies. Which core Zero Trust Architecture principle does this proposed design fail to uphold?
Match each core security goal on the left with its primary operational objective on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A healthcare analytics platform receives automated diagnostic telemetry from remote clinics. To comply with regulatory standards, the platform must verify that incoming data is unaltered during transit and ensure that sending clinics cannot deny originating a record. An engineer proposes applying a keyed-Hash Message Authentication Code (HMAC) using a symmetric key shared exclusively between each clinic and the platform. Which of the following security goals is compromised under this implementation when presenting log evidence to an independent third-party auditor?
An enterprise e-commerce organization requires external suppliers to digitally approve updated procurement contracts. During an audit, a supplier claims that an internal administrator forged an approval entry and that the supplier never authorized the agreement. Which security objective and technical implementation best prevents the supplier from successfully denying their action?
An organization is updating its network access controls to align with Zero Trust Architecture (ZTA) principles. Which of the following fundamental principles should the security team implement as part of this design? (Select TWO)
Geçerli olan tümünü seçin
A security administrator needs to conduct a vulnerability assessment on internal workstations to identify missing operating system patches and software misconfigurations with high accuracy and a minimal false-positive rate. Which of the following testing methods should the administrator perform?
A system administrator receives an alert that several host files on a workstation have been encrypted unexpectedly, and a pop-up window on the desktop demands a cryptocurrency payment to obtain the decryption key. Which of the following malware types is described in this scenario?
A cybersecurity analyst is investigating an intrusion into a enterprise network belonging to a major financial institution. The attack demonstrated high sophistication, utilized custom zero-day vulnerabilities, maintained persistent covert access over several months, and required extensive financial funding and technical resources. Which of the following threat actor types is most likely responsible for this attack?
A SOC analyst responds to an alert regarding anomalous outbound network connections from a critical enterprise server. During incident triage, the analyst gathers the following telemetry artifacts:
- Volatile memory inspection shows shellcode executing directly within the allocated memory space of a legitimate `lsass.exe` process via reflective DLL injection.
- System logs indicate persistence was achieved via a non-standard WMI event consumer executing an encoded script payload.
- Comprehensive storage forensics confirm no new binary files, modified system executables, or untrusted drivers exist on disk.
Which of the following malware classifications best describes this attack vector?
An enterprise is migrating its customer database to a Platform as a Service (PaaS) cloud environment. During the architectural design phase, the security team must document operational duties in accordance with the cloud shared responsibility model. Which of the following responsibilities remains strictly with the customer organization in a PaaS deployment?
During an incident response investigation, a Security Operations Center (SOC) analyst isolates an endpoint after Endpoint Detection and Response (EDR) telemetry alerts on anomalous process behavior. Further forensic analysis reveals that malicious payload execution occurred directly within system memory (RAM) via process injection into `explorer.exe` using encoded PowerShell commands, leaving zero binary artifacts on the local disk. Which of the following malware classifications best describes this attack?
A security analyst conducts an internal infrastructure vulnerability assessment on an enterprise network segment containing legacy servers. The assessment scan report reveals the following open ports and vulnerability indicators:
PORT STATE SERVICE VERSION
21/tcp open ftp vsftpd 2.3.4 (Anonymous login permitted)
23/tcp open telnet Legacy router management service
445/tcp open smb Windows Server 2008 R2 (SMBv1 enabled / CVE-2017-0144 detected)
The security operations team must immediately address the threat of unauthenticated remote code execution (RCE) exploitation traversing the internal network while long-term migration plans are finalized. Which of the following mitigations is the MOST effective immediate action to eliminate this specific vulnerability vector?
An investigation at a defense industrial base organization reveals a sophisticated, long-term intrusion targeting unreleased satellite telemetry software designs. Forensic analysis indicates the attackers breached the network by leveraging a zero-day exploit against a third-party supply chain management vendor, maintained persistent memory-only access for over eight months, and systematically exfiltrated specific intellectual property without altering operational data or attempting financial extortion. Which threat actor type and attribute profile is most likely responsible for this attack vector and operational methodology?
Match each cloud service model to its primary operational responsibility boundary.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
Match each technical host telemetry artifact and indicator of compromise with its corresponding malware classification.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler