Tüm alıştırma soruları
2232 soru
A DevSecOps engineer is configuring a shared Linux compute host that executes untrusted CI/CD pipeline container images. To minimize the risk of a container process exploiting kernel vulnerabilities or escalating privileges on the underlying host operating system, which of the following controls should be implemented? (Select TWO.)
Geçerli olan tümünü seçin
A international maritime logistics enterprise operates edge storage appliances at remote port facilities to handle offline container manifest data. The security architecture team must ensure that if storage drives are physically stolen from an unattended facility, the data at rest cannot be extracted. Additionally, key lifecycle management must be centralized without relying on local site administrators to manually unlock storage volumes after a system reboot. Which of the following storage security architectures best meets these requirements?
A security analyst receives a critical Endpoint Detection and Response (EDR) alert showing an unauthorized process attempting to dump LSASS memory on a key workstation in the finance department. The alert confirms that the malicious process is actively attempting to establish command-and-control (C2) communications. According to standard NIST SP 800-61 incident response guidelines, what is the immediate next action the analyst should take?
A cloud security engineering team is designing an Identity and Access Management (IAM) architecture for microservices operating across multi-cloud Kubernetes environments. The architecture must enforce Zero Trust principles by replacing static API keys and long-lived service account tokens with short-lived X.509 certificates issued automatically through platform attestation rather than user credentials. Which of the following identity architecture solutions best satisfies these requirements?
A security analyst identifies an active incident where a web server is communicating with an unauthorized external command-and-control (C2) server. According to standard incident response playbooks, which of the following initial actions should the incident response team perform during the containment phase? (Select TWO.)
Geçerli olan tümünü seçin
During cloud infrastructure monitoring, a SOC analyst detects suspicious automated API calls using a developer service account key to copy sensitive object storage buckets to an unapproved external destination. The security team must immediately initiate containment procedures according to the incident response playbook. Which of the following containment actions should the incident response team execute immediately? (Select TWO.)
Geçerli olan tümünü seçin
Match each enterprise security risk scenario on the left with the most effective enterprise hardening mitigation on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An enterprise wants to allow its employees to securely sign in to multiple external cloud-based vendor applications using their central corporate identity provider, ensuring that user passwords are never transmitted to or stored by the external vendors. Which Identity and Access Management (IAM) architectural solution best fulfills this requirement?
A Security Operations Center (SOC) analyst is reviewing SIEM log correlation logic designed to detect unauthorized administrative lateral movement. The SIEM rule requires three conditions to trigger a high-severity alert:
1. A Windows Event ID 4624 (Logon Type 3 - Network) for a service account.
2. A Windows Event ID 4672 (Special privileges assigned) for the same account occurring within of the logon event.
3. A Sysmon Event ID 1 (Process Creation) where `ParentImage` is `services.exe` occurring within of privilege assignment.
The analyst extracts the following log sequence from a compromised server:
text
[2026-07-27T14:10:02Z] Host=SRV-FIN01 EventID=4624 LogonType=3 TargetUserName=svc_backup WorkstationName=WKSTN-77
[2026-07-27T14:11:05Z] Host=SRV-FIN01 EventID=4672 TargetUserName=svc_backup PrivilegeList=SeDebugPrivilege
[2026-07-27T14:11:15Z] Host=SRV-FIN01 EventID=1 Image=C:\Windows\System32\cmd.exe ParentImage=C:\Windows\System32\services.exe
Despite malicious process execution occurring, no SIEM alert was generated. Which of the following best explains why the correlation rule failed to trigger?
During a security investigation following alerts from an enterprise Network Intrusion Detection System (NIDS), a security analyst inspects captured traffic headers from a user workstation. The network logs reveal that outbound TCP port 443 connections destined for an internal authentication portal are systematically terminated via forged TCP Reset (RST) packets, while concurrent HTTP 302 response headers redirect the user's browser to submit credentials in cleartext over port 80. Which of the following network attacks is best demonstrated by these observed technical indicators?
A security technician is reviewing Wireless Intrusion Prevention System (WIPS) alerts after several wireless industrial sensors lost connectivity simultaneously. The WIPS telemetry reveals a sudden, sustained rise in the physical RF noise floor to across all channels in the spectrum, resulting in a severely degraded Signal-to-Noise Ratio (SNR) and a high rate of corrupted frame retransmissions. Which of the following wireless attacks is indicated by these metrics?
A security analyst in a Security Operations Center (SOC) receives a high-confidence alert that a finance department workstation is infected with worm-like malware actively attempting to spread to adjacent hosts on the local subnet. According to standard incident response playbooks, which of the following actions should the analyst perform first?
A security analyst discovers that an operational AWS IAM access key belonging to a production microservice repository was inadvertently committed to a public version control repository. Following standard incident response playbook procedures for credential exposure, place the following response actions in the correct sequential order from first to last.
Öğeleri doğru sıraya koymak için sürükleyin
A security operations team is configuring a Security Information and Event Management (SIEM) data pipeline to handle heterogeneous syslog and event streams from enterprise endpoints, firewalls, and application servers. Place the following SIEM processing stages in the correct chronological order from initial data intake to analyst notification.
Öğeleri doğru sıraya koymak için sürükleyin
A Security Operations Center (SOC) team validates an active alert showing that a core database server hosting sensitive human resources data is performing covert DNS tunneling to transmit data to an external command-and-control (C2) IP address. The incident has been confirmed and analyzed. According to the NIST SP 800-61 incident response lifecycle, which of the following actions should the incident response team perform FIRST?
A forensic analyst receives a bit-stream disk image of a compromised virtual domain controller from an external incident response team. Prior to initiating analysis, the analyst calculates a SHA-256 hash of the evidence file and discovers that it does not match the SHA-256 hash value documented on the accompanying chain of custody form. Which of the following describes the most appropriate immediate course of action for the analyst to take?
A security specialist investigates an automated alert triggered in a Security Information and Event Management (SIEM) dashboard. The alert aggregates logs from the web application firewall (WAF) and the database audit logger as shown below:
[2026-07-27T14:02:11Z] WAF_LOG: Src=203.0.113.84 URI="/search.php?item=1%27%20OR%201=1--" Action=ALLOWED HTTP_Status=200
[2026-07-27T14:02:15Z] DB_AUDIT: User=app_web Query="SELECT * FROM items WHERE item_id = '1' OR 1=1--" Execution_Status=SUCCESS RowsReturned=84200
[2026-07-27T14:02:18Z] SIEM_CORRELATION: RuleID=RL-4092 Trigger="High Volume Data Read Post WAF Anomaly"
Based on these correlated log entries, which of the following security events is actively occurring?
A telemedicine organization is updating its infrastructure to align with Zero Trust Architecture (ZTA) principles for remote radiologists querying patient imaging databases hosted across hybrid cloud environments. The lead security architect mandates that access decisions must continuously evaluate user identity, device compliance, and real-time risk context, while separate proxy gateways enforce those authorization decisions at the resource boundary. Which of the following architectural implementations best satisfies this requirement?
A lead security analyst at a financial enterprise is optimizing the organization's security operations center (SOC) workflows. The analyst requires an external threat intelligence source that provides professionally verified, machine-readable technical Indicators of Compromise (IoCs)—such as malicious IP addresses, domain names, and file hashes—updated in real time for direct automated ingestion into their SIEM. Which of the following threat intelligence sources best satisfies these requirements?
A security analyst is investigating a high-priority correlation alert in a Security Information and Event Management (SIEM) dashboard. The analyst reviews the following sequential event logs collected from a Web Application Firewall (WAF), an Nginx web server, and a Linux host kernel audit subsystem (auditd):
text
[2026-07-27T14:22:01.104Z] WAF-ALERT rule_id=942100 severity=CRITICAL client_ip=198.51.100.44 uri="/api/v1/export?format=pdf&cmd=id" action=DETECTED_ONLY
[2026-07-27T14:22:01.108Z] HTTP-ACCESS client_ip=198.51.100.44 status=200 method=GET uri="/api/v1/export?format=pdf&cmd=%3B%20cat%20%2Fetc%2Fpasswd" bytes=4096
[2026-07-27T14:22:01.112Z] AUDITD type=EXECVE pid=88412 ppid=1420 (www-data) comm="sh" args="sh -c cat /etc/passwd"
Based on the provided log telemetry, which of the following conclusions and remediation requirements are correct? (Select TWO.)
Geçerli olan tümünü seçin