Tüm alıştırma soruları
2232 soru
A security operations team is configuring an enterprise Security Information and Event Management (SIEM) data pipeline to process heterogeneous log sources across cloud and on-premises environments. In what sequential order does the SIEM pipeline process incoming event data from initial receipt to alert generation?
Öğeleri doğru sıraya koymak için sürükleyin
A chief information security officer (CISO) at a regional healthcare network wants to establish a secure, bidirectional threat intelligence sharing channel to exchange sector-specific cyber threat indicators and attacker tactics directly with peer healthcare organizations. Which threat intelligence source or framework is best suited to fulfill this requirement?
An organization is modernizing its deployment architecture by hosting multiple containerized microservices on a shared host operating system. During a technical audit, a security analyst discovers that microservices run with standard system privileges, exposing the host operating system kernel to potential privilege escalation via unauthorized system calls if a container is compromised. Which of the following controls should the security team implement on the container host to restrict the specific system calls available to container processes?
A security architect is designing an identity and access management (IAM) infrastructure for an enterprise microservices environment. The organization requires that OAuth 2.0 access tokens issued to client applications are sender-constrained, ensuring that if a token is intercepted in transit, it cannot be replayed by an unauthorized third party to access downstream APIs. Which of the following architectural solutions best satisfies this security requirement?
During a late-night monitoring shift, a security analyst identifies an active outbound socket connection transferring encrypted data from a CI/CD build node to an unrecognized external IP address. Initial investigation confirms that an unauthorized process is exfiltrating proprietary code repositories. According to standard incident response lifecycle frameworks, which of the following actions should the analyst perform FIRST?
A security analyst is investigating network security logs following user complaints of sudden, repeated disconnections from the corporate Wi-Fi network. Shortly after being disconnected, several user devices automatically reconnected to an unauthorized access point broadcasting the corporate ESSID. Which TWO of the following wireless network indicators specifically point to an active disassociation and Evil Twin attack sequence?
Geçerli olan tümünü seçin
During a threat hunting exercise on an enterprise SCADA network, a SOC analyst identifies an unauthorized background service executing on a primary operational jump server. The rogue process is actively establishing covert encrypted DNS tunnels to external command-and-control (C2) servers to exfiltrate system telemetry. The incident response playbook mandates immediate threat containment while strictly maintaining volatile RAM evidence for subsequent forensics. Which of the following operational steps should the security team perform FIRST to adhere to the containment phase protocols?
A Security Operations Center (SOC) team is investigating a multi-stage enterprise breach. A SIEM correlation engine collected logs across web application firewalls, endpoint detection agents, and Windows Domain Controllers. Based on log signatures and attack techniques, arrange the following log events in the correct chronological order of the attacker's progression through the cyber kill chain (from initial access to persistence).
Öğeleri doğru sıraya koymak için sürükleyin
A cloud security architect is designing a resilient infrastructure for a critical financial transaction service deployed across two geographically distant cloud regions. To satisfy business requirements, the architecture must achieve a Recovery Point Objective (RPO) of zero (zero data loss) and a Recovery Time Objective (RTO) of near-zero in the event of an entire regional failure. Which TWO of the following architectural mechanisms must be deployed together to meet these strict availability and resilience targets?
Geçerli olan tümünü seçin
A maritime shipping container logistics terminal is modernizing its operational technology (OT) network and port management systems. The security architecture team is adopting Zero Trust Architecture (ZTA) principles to prevent unauthorized access between automated gantry crane control systems, IoT tracking sensors, and cloud management consoles. Which of the following architectural requirements represent core tenets of Zero Trust Architecture that must be implemented in this design? (Select TWO.)
Geçerli olan tümünü seçin
A security analyst is examining raw log snippets collected by a SIEM system from various network resources. Match each log entry pattern on the left to the corresponding security event or attack type on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A security operations center (SOC) analyst confirms an active Golden Ticket attack originating from a compromised Active Directory Domain Controller within an enterprise network. Arrange the following incident response procedures in the correct chronological order according to standard NIST incident response lifecycle guidelines, starting with the earliest step.
Öğeleri doğru sıraya koymak için sürükleyin
A pharmaceutical research organization is updating its storage architecture to host confidential genomic sequencing datasets. The security architect must satisfy two primary requirements: guarantee bulk data encryption at rest on storage area network (SAN) arrays without degrading host processing performance, and prevent research data from being copied to unauthorized physical media or unapproved endpoints. Which of the following technical security solutions should the architect select to meet these requirements? (Select TWO)
Geçerli olan tümünü seçin
A system administrator reviews the following web server access log entries associated with an internal audit endpoint:
192.168.1.45 - - [27/Jul/2026:14:22:01 +0000] "POST /api/v1/query HTTP/1.1" 200 4520 "id=101+UNION+SELECT+username,password_hash+FROM+users--" "Mozilla/5.0"
192.168.1.45 - - [27/Jul/2026:14:22:05 +0000] "POST /api/v1/query HTTP/1.1" 200 5120 "id=101' OR '1'='1" "Mozilla/5.0"
Which type of attack vector do these log entries demonstrate, and what is the most effective application-level mitigation?
An organization is updating its cybersecurity incident response plan according to the standard NIST SP 800-61 framework. In what sequential order should the core phases of the incident response lifecycle be performed from first to last?
Öğeleri doğru sıraya koymak için sürükleyin
A Security Operations Center (SOC) analyst is standardizing correlation rules in an enterprise Security Information and Event Management (SIEM) system. Match each log entry pattern on the left to its corresponding security event or attack vector on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
Match each Identity and Access Management (IAM) protocol to its primary architectural function in enterprise security environments.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A pharmaceutical enterprise has implemented a Zero Trust Architecture (ZTA) to secure access to proprietary clinical research data. During an active database session initiated via multi-factor authentication, the remote endpoint's client security agent reports that host firewall services were unexpectedly disabled. Which of the following actions best reflects the core tenets of Zero Trust in this scenario?
A security engineering team is automating its enterprise threat intelligence workflow to improve SIEM alert enrichment. The solution requires a standardized data format for expressing structured cyber threat information alongside an automated protocol for machine-to-machine transport over HTTPS. Which of the following standards should the team implement to satisfy these requirements? (Select TWO.)
Geçerli olan tümünü seçin
A security architect for an enterprise organization is designing network isolation controls across various operational environments. Match each security design requirement on the left to the network segmentation mechanism on the right that best satisfies it.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler