Tüm alıştırma soruları
2232 soru
A healthcare enterprise is architecting a storage and data security solution for its electronic health record (EHR) database environment. The design must ensure bulk data at rest remains cryptographically secured without causing significant performance overhead on database queries, while also preventing unauthorized exfiltration of sensitive patient records across endpoint storage interfaces and removable media. Which of the following security controls should the architect integrate to satisfy these requirements? (Select TWO.)
Geçerli olan tümünü seçin
A security engineering team is implementing an automated threat intelligence platform to exchange structured cyber threat data with an industry ISAC and ingest machine-readable indicators into internal security tools. Which of the following components specifically define the standardized language for expressing threat data and the automated transport protocol for exchanging it? (Select TWO.)
Geçerli olan tümünü seçin
An organization determines that the Single Loss Expectancy (SLE) for a critical server data breach is $40,000. Historical security assessment data indicates an Annual Rate of Occurrence (ARO) of 0.25 for this event. What is the Annual Loss Expectancy (ALE) associated with this risk?
A security analyst reviews the following log entry from an internal web proxy gateway:
`2026-07-27T14:22:05Z proxy01 squid[4812]: 10.10.4.15 TCP_DENIED/403 3512 GET http://known-malicious-domain.org/updater.exe - HIER_NONE/- text/html`
Which of the following conclusions can be directly drawn from this log entry? (Select TWO.)
Geçerli olan tümünü seçin
Match each threat intelligence source type to its primary operational use case or intelligence characteristic in an enterprise security framework.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A security analyst investigating a high-priority SIEM alert reviews the following audit log snippet generated sequentially across cloud control plane services within a 15-second window:
[
{
"eventTime": "2026-07-27T14:22:05Z",
"eventName": "AssumeRole",
"userIdentity": { "type": "AWSAccount", "principalId": "AROA3X921EXAMPLE:session1" },
"sourceIPAddress": "198.51.100.45",
"requestParameters": { "roleArn": "arn:aws:iam::123456789012:role/DevOps-Admin-Role" }
},
{
"eventTime": "2026-07-27T14:22:12Z",
"eventName": "GetSecretValue",
"userIdentity": { "type": "AssumedRole", "principalId": "AROA3X921EXAMPLE:DevOps-Admin-Role" },
"sourceIPAddress": "198.51.100.45",
"requestParameters": { "secretId": "prod/db/credentials" }
},
{
"eventTime": "2026-07-27T14:22:18Z",
"eventName": "CreateAccessKey",
"userIdentity": { "type": "AssumedRole", "principalId": "AROA3X921EXAMPLE:DevOps-Admin-Role" },
"sourceIPAddress": "198.51.100.45",
"requestParameters": { "userName": "backup-svc" }
}
]
Based on these log entries, which of the following best assesses the threat activity and identifies the appropriate SIEM correlation rule tuning strategy?
A healthcare organization is refactoring its data architecture to secure sensitive patient diagnostic records stored on a Network Attached Storage (NAS) array. The security requirements dictate that data must be encrypted at rest, key lifecycle operations must be centrally managed and audited, and storage administrators must not have direct access to root cryptographic keys or store them on the local NAS hardware. Which of the following data protection solutions best fulfills these architectural requirements?
A global healthcare organization requires a federated access solution allowing external medical specialists from partner hospitals to query patient diagnostic APIs hosted in its cloud environment. The architecture must ensure partner organizations maintain control over their own user credentials, support identity assertion, enable fine-grained attribute-based access decisions at the API gateway without exposing internal directory services, and avoid establishing persistent network-level perimeter trust. Which architectural combination of identity and authorization frameworks best satisfies these security requirements?
A financial enterprise is deploying a third-party reporting server into a virtualized datacenter. The reporting server requires outbound internet access to fetch external market data, but corporate security policy dictates that it must be strictly prevented from initiating lateral connections to any other internal virtual machines, even those within the same subnet. Which of the following network architecture design solutions best satisfies this requirement?
A storage administrator is configuring security mechanisms for sensitive database volumes hosted on an enterprise Storage Area Network (SAN). The administrator needs to protect data at rest with hardware-accelerated bulk encryption and ensure that top-level encryption keys are managed in a tamper-resistant environment. Which of the following technologies should the administrator deploy? (Select TWO.)
Geçerli olan tümünü seçin
A financial enterprise is decommissioning a multi-tenant cloud storage array containing sensitive personally identifiable information (PII) stored across encrypted block volumes. The architecture relies on envelope encryption where unique Data Encryption Keys (DEKs) are wrapped by Key Encryption Keys (KEKs) managed inside a Key Management Interoperability Protocol (KMIP)-compliant Hardware Security Module (HSM). The compliance team mandates immediate, verifiable data sanitization before the physical storage media is recycled by the provider, but traditional multi-pass disk overwriting would exceed bandwidth limits and disrupt SAN performance. Which of the following storage security architectural approaches best satisfies these operational and compliance constraints?
A security administrator is documenting high-availability and business continuity metrics for an organization's core infrastructure. Match each availability metric on the left with its corresponding description on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A biomedical engineering department at a regional hospital plans to integrate networked smart infusion pumps into the facility's network. To minimize the threat of malware spreading laterally from compromised medical devices to critical electronic health record (EHR) databases while still allowing automated telemetry collection by central servers, which network architecture control should the security team implement?
A enterprise security architect is configuring an automated cross-region database failover workflow between two active-passive data centers to maintain zero Recovery Point Objective (RPO) and minimal Recovery Time Objective (RTO) during an ungraceful outage. Arrange the operational steps of the automated failover sequence in the correct chronological order from first step executed to final step completed.
Öğeleri doğru sıraya koymak için sürükleyin
An enterprise organization operates two data centers connected via a low-latency dark fiber link. The business continuity requirement mandates a strict Recovery Point Objective of zero () for transactional database records during a primary site outage, while simultaneously preventing split-brain conditions during automated failover. Which of the following high-availability storage configurations best satisfies these requirements?
An aerospace security architecture team is designing a satellite communications (SATCOM) avionics gateway for autonomous aircraft. The gateway will operate in environments susceptible to physical interception, probe attacks, and firmware tampering. To meet stringent safety standards, the hardware must establish an immutable boot verification chain and prevent physical extraction of secret keys stored in memory. Which TWO of the following hardware security controls should the team implement to satisfy these architecture requirements? (Select TWO)
Geçerli olan tümünü seçin
An enterprise security team is upgrading its data protection and storage security architecture to protect sensitive databases and block storage volumes across on-premises SAN and cloud environments. The architect needs to implement controls that ensure centralized key governance for encrypted storage, isolate storage network traffic to authorized hosts, and prevent unauthorized exfiltration of sensitive files from endpoints. Which of the following technical controls should the architect implement to meet these storage security requirements? (Select THREE)
Geçerli olan tümünü seçin
A security technician analyzing network packet captures following a reported credential compromise notes that multiple workstations are issuing UDP port 5355 multicast requests after failing standard DNS name resolution for local resources. Immediately following each multicast query, an unauthorized host on the local subnet returns spoofed name resolution responses, directing the victim workstations to initiate SMB authentication over TCP port 445 to the attacker's machine. Which of the following technical indicators specifically confirm the presence of this attack? Select TWO.
Geçerli olan tümünü seçin
An enterprise security architecture team is evaluating cloud deployment and service models for a multi-cloud initiative. Match each operational requirement on the left with the most appropriate cloud architecture or service model on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An aerospace engineering organization has implemented Zero Trust Architecture (ZTA) controls for engineers accessing proprietary CAD schematics stored in a hybrid cloud repository. During an active remote session from a corporate laptop, the security monitoring system detects that the local endpoint protection agent was disabled and the asset's dynamic risk score surged. Although the engineer successfully completed multi-factor authentication (MFA) at session initiation, access to the repository is revoked instantly. Which Zero Trust Architecture core principle is directly demonstrated by this access enforcement action?