Tüm alıştırma soruları

2232 soru

Soru 1021Soru

A security administrator is establishing an automated failover sequence for an active-passive high-availability firewall pair to ensure continuous uptime during a node failure while preserving connection state tables. Place the operational failover steps in the correct chronological order from first to last.

Öğeleri doğru sıraya koymak için sürükleyin

Cevabı ve açıklamayı göster

Cevap

The correct sequence begins with the standby node detecting missed heartbeat probes, followed by the standby node transitioning to active and broadcasting a GARP message, then assuming the Virtual IP and activating synchronized state tables, and concluding with network traffic routing through the secondary appliance without disruption.
In stateful high availability failover, the process begins when health monitoring detects loss of heartbeat probes from the primary appliance. Next, the standby appliance promotes itself to active status and transmits a Gratuitous ARP (GARP) frame to update switch forwarding tables for the shared virtual IP (VIP). The new active appliance then assumes the VIP and applies the synchronized connection state table. Finally, network traffic transitions through the secondary firewall seamlessly.

Adım Adım Çözüm

1
Identify the event that triggers the failover routine.
Failure of primary node heartbeat probes alerts the standby firewall.
Redundant clusters require continuous health checks to detect primary node degradation before executing role promotion.
2
Determine how network switching infrastructure is alerted to the topology change.
The standby node promotes itself to active and issues Gratuitous ARP (GARP) broadcasts.
GARP messages instantly update the Layer 2 MAC address tables on upstream switches, pointing the virtual IP interface to the new physical port.
3
Apply high availability session state controls to maintain connection persistence.
The newly active node binds the VIP and loads synchronized connection state data.
Stateful failover relies on continuously replicated state tables so existing TCP sessions do not require renegotiation.
4
Verify traffic flow restoration.
Production network traffic successfully flows through the newly active node without user disruption.
Once routing and MAC tables converge, live production connections proceed through the failover target seamlessly.

Anahtar Kavram

Active-Passive Stateful High Availability Failover Sequence
Soru 1022Soru

A security analyst is initiating a digital forensics investigation on a compromised live application server. Which of the following actions should the analyst perform to adhere to proper evidence preservation and chain of custody procedures? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Capture the active system RAM before shutting down or rebooting the server.; Calculate and record SHA-256 cryptographic hashes for all disk images immediately upon acquisition.

Cevap

The analyst should capture active system RAM before shutting down the server and calculate SHA-256 cryptographic hashes for disk images immediately upon acquisition.
Capturing active RAM prior to system shutdown preserves highly volatile evidence according to the order of volatility. Calculating and recording cryptographic hashes immediately upon image acquisition ensures evidence integrity and supports chain of custody proof in legal proceedings.

Adım Adım Çözüm

1
Identify the most volatile evidence components.
System RAM is identified as highly volatile and must be captured while the server remains powered on.
Shutting down the server clears RAM contents, resulting in permanent loss of volatile evidence.
2
Establish evidence integrity baseline upon collection.
Cryptographic hashes (e.g., SHA-256) are generated immediately after image acquisition.
Hashes provide proof that the forensic image was not modified during handling or analysis.

Anahtar Kavram

Digital Forensics Order of Volatility and Chain of Custody Integrity
Soru 1023Soru

A cybersecurity forensic analyst has just completed a bit-stream disk acquisition of a target drive seized during an insider threat investigation. The analyst must now process and secure the physical drive and digital image to ensure legal admissibility in court. Place the following evidence handling and chain of custody steps in the correct chronological order from first to last.

Öğeleri doğru sıraya koymak için sürükleyin

Cevabı ve açıklamayı göster

Cevap

The correct chronological order for preserving forensic disk evidence is: (1) Generate and document a baseline cryptographic hash of the acquired forensic image, (2) Complete the initial chain of custody log entry with item details, timestamps, collector identity, and baseline hash value, (3) Place the original drive into an antistatic tamper-evident bag and apply a signed tamper-proof seal, and (4) Deposit the sealed evidence package into a secure evidence vault and log the storage location transfer.
Digital forensic integrity relies on immediate verification followed by meticulous documentation and physical security. First, generating a baseline cryptographic hash immediately after bit-stream acquisition verifies that the copy is exact and unaltered. Second, recording this hash alongside collector details, serial numbers, and timestamps on the chain of custody form creates an official legal record. Third, physically enclosing the drive in a sealed tamper-evident bag ensures protection against tampering and static. Finally, transferring the sealed item to a secure evidence locker and logging the location transfer maintains an unbroken chain of custody.

Adım Adım Çözüm

1
Verify baseline data integrity
Generating a SHA-256 hash immediately after image capture creates a mathematical signature of the evidence state.
Cryptographic hashes prove non-repudiation and verify that the evidence has not been tampered with or corrupted during acquisition.
2
Record chain of custody documentation
The collector logs essential metadata including collector name, date, time, serial number, and baseline hash.
Detailed documentation establishes accountability and legal defensibility before the evidence is packaged.
3
Package and seal physical evidence
The physical media is secured inside a anti-static tamper-evident bag with a signed security seal across the opening.
Physical sealing ensures protection against electrostatic discharge and detects any physical compromise.
4
Secure evidence and log custodial transfer
The sealed bag is transferred to an access-controlled evidence vault, and the transfer of custody log is updated.
Maintaining continuous custody tracking prevents claims of evidence contamination or unrecorded access.

Anahtar Kavram

Chain of Custody and Evidence Integrity Preservation Workflow
Soru 1024Soru

An organization is deploying an Endpoint Detection and Response (EDR) agent across all enterprise hosts. Which of the following core capabilities differentiate EDR solutions from traditional signature-based antivirus software? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Continuous real-time collection and analysis of endpoint behavioral telemetry; Remote network isolation of compromised hosts while preserving management access

Cevap

The features that distinguish EDR solutions from legacy antivirus are continuous real-time collection of endpoint behavioral telemetry and remote network isolation of compromised hosts.
Endpoint Detection and Response (EDR) solutions extend beyond traditional antivirus by continuously recording host behavioral telemetry (such as process trees, file modifications, and local network connections) and enabling rapid containment actions like network isolation of compromised endpoints.

Adım Adım Çözüm

1
Identify key EDR features.
EDR emphasizes continuous host telemetry collection and active containment options such as network isolation.
Legacy antivirus relies primarily on static file signatures, whereas EDR continuously analyzes behavior and provides direct incident response capabilities.
2
Evaluate wrong options.
IP reputation filtering is a network firewall control, and assuming internal host trustworthiness relies on perimeter trust rather than endpoint monitoring.
These distractor options represent perimeter control functions or flawed security assumptions rather than host EDR features.

Anahtar Kavram

Endpoint Detection and Response (EDR) Core Functions
Tahmini Süre:1m 0s
Soru 1025Soru

An autonomous electric vehicle (EV) charging network operator is updating its management plane and edge gateway infrastructure to comply with NIST SP 800-207 Zero Trust Architecture (ZTA) principles. Match each Zero Trust logical component to its core operational responsibility within the enterprise architecture.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Policy Engine (PE)
Policy Administrator (PA)
Policy Enforcement Point (PEP)
Continuous Diagnostics and Mitigation (CDM) System

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Policy Engine (PE) matches with evaluating access requests against policies and risk algorithms. Policy Administrator (PA) matches with translating decisions into control plane commands and session keys. Policy Enforcement Point (PEP) matches with operating in the data plane to intercept, inspect, enable, and terminate active connection sessions. Continuous Diagnostics and Mitigation (CDM) System matches with monitoring endpoint posture and vulnerability state for real-time contextual intelligence.
NIST SP 800-207 divides Zero Trust Architecture into distinct logical components across the control plane and data plane. The Policy Engine evaluates policy and telemetry to make access decisions. The Policy Administrator receives those decisions and commands Policy Enforcement Points to open, monitor, or close sessions. The Policy Enforcement Point acts as the inline barrier in the data plane to manage connection traffic. Continuous Diagnostics and Mitigation systems gather device state telemetry to provide the ongoing context necessary for dynamic trust evaluation.

Adım Adım Çözüm

1
Differentiate between the Control Plane components (Policy Engine and Policy Administrator) and the Data Plane component (Policy Enforcement Point).
Identified the Policy Engine as the decision maker, the Policy Administrator as the control signal manager, and the Policy Enforcement Point as the inline data traffic gatekeeper.
Zero Trust Architecture enforces a strict functional separation between access decision logic and data path enforcement.
2
Identify the contextual support role of telemetry systems such as Continuous Diagnostics and Mitigation (CDM).
Mapped CDM to endpoint health state, vulnerability metrics, and continuous compliance monitoring.
Zero Trust dynamic access evaluations require real-time posture context rather than static perimeter trust assumptions.
3
Map each component to its exact functional description as specified in NIST SP 800-207.
Verified accurate component-to-responsibility pairings.
Ensures standard alignment with standard Zero Trust Architecture control plane and data plane models.

Anahtar Kavram

Zero Trust Architecture Control Plane vs. Data Plane Component Responsibilities
Tahmini Süre:1m 30s
Soru 1026Soru

A security analyst is investigating a stealthy compromise on an enterprise server where an attacker executed an obfuscated script directly in host memory using native tools, avoiding writing any malicious files to the disk. Standard signature-based antivirus software and perimeter firewalls failed to detect the activity. Which capability of Endpoint Detection and Response (EDR) provides the visibility required to identify and trace this fileless execution?

Cevabı ve açıklamayı göster

Cevap: Continuous behavioral monitoring and process parent-child lineage tracking

Cevap

Continuous behavioral monitoring and process parent-child lineage tracking
The correct answer highlights EDR's ability to monitor ongoing endpoint behavior and process trees in real time. Because fileless attacks execute directly in volatile memory using native system binaries (Living off the Land), traditional static file checks fail. EDR solves this by recording runtime telemetry, including parent-child process chains and command-line parameters.

Adım Adım Çözüm

1
Analyze the attack vector described in the scenario
The attack uses fileless execution techniques, relying on memory-resident script execution via native binaries without dropping files to disk.
Understanding that no file was created eliminates static inspection methods that depend on file system artifacts.
2
Evaluate the capabilities of security monitoring technologies against fileless execution
EDR agents maintain continuous telemetry on process creation, memory activity, and execution arguments on host endpoints.
Process lineage tracking enables visibility into abnormal execution flows, such as a legitimate system utility spawning an unexpected command shell.
3
Select the option that specifically addresses host process and memory execution tracking
Continuous behavioral monitoring and process lineage tracking is the core EDR function designed for fileless threat detection.
It captures real-time endpoint behavioral anomalies regardless of file signature presence.

Anahtar Kavram

EDR Behavioral Telemetry & Fileless Threat Detection
Soru 1027Soru

A storage administrator at a financial enterprise is tasked with securing sensitive transaction logs stored on a high-throughput Storage Area Network (SAN). The solution must protect data at rest against physical drive theft from the data center without introducing computational overhead on the host servers or latency into bulk disk operations. Which of the following storage security controls best satisfies these requirements?

Cevabı ve açıklamayı göster

Cevap: Deploying Self-Encrypting Drives (SEDs) utilizing dedicated hardware controllers and symmetric AES block encryption

Cevap

Deploying Self-Encrypting Drives (SEDs) utilizing dedicated hardware controllers and symmetric AES block encryption.
Self-Encrypting Drives (SEDs) incorporate dedicated cryptographic hardware directly onto the drive controller. They utilize fast symmetric algorithms (such as AES) to perform transparent encryption and decryption at media speed, ensuring zero processing burden on host CPU resources while protecting data at rest if physical drives are stolen.

Adım Adım Çözüm

1
Analyze the scenario constraints and security objectives.
The requirement calls for data-at-rest protection against physical theft, zero host CPU overhead, and minimal latency for high-throughput SAN storage.
Host-based cryptographic processing reduces available server computing resources for applications.
2
Evaluate hardware-based versus software-based storage encryption mechanisms.
Hardware-based encryption handled directly at the drive media layer (SEDs) offloads cryptographic processing from host systems while enforcing transparent bulk data protection.
SED controllers encrypt data seamlessly as it is written to media using fast symmetric block ciphers.
3
Select the correct storage control matching all enterprise criteria.
Self-Encrypting Drives (SEDs) with symmetric encryption satisfy the performance, host load, and confidentiality requirements.
Hardware SED implementation satisfies all constraint parameters efficiently.

Anahtar Kavram

Hardware-based Storage Encryption & Data at Rest Protection
Soru 1028Soru

An incident responder arrives at a compromised live workstation suspected of running volatile in-memory malware. To preserve digital evidence without destroying transient data, the responder must extract system artifacts in strict adherence to the forensic Order of Volatility (RFC 3227). In what sequence should the analyst collect the following evidence items, starting with the MOST volatile artifact (collected first) and ending with the LEAST volatile artifact (collected last)?

Öğeleri doğru sıraya koymak için sürükleyin

Cevabı ve açıklamayı göster

Cevap

The correct order of collection from most volatile to least volatile is: CPU registers and cache contents, System RAM and active network socket tables, Swap file and pagefile contents on the local drive, Bit-stream image of the local secondary storage drive, and Off-site archival backup tapes.
Digital forensics standards (RFC 3227) mandate collecting evidence in order of lifetime volatility: CPU cache and registers change constantly (nanoseconds), System RAM and active network connections are cleared upon power-down (seconds to minutes), temporary swap/pagefiles retain paged data on disk, non-volatile local disk partitions persist across power cycles, and offline archival backup tapes remain stable over long periods.

Adım Adım Çözüm

1
Identify the most transient artifacts that change within nanoseconds.
CPU registers and cache contents must be acquired first because any processor instruction or context switch instantly overwrites this state.
Top tier of volatility per RFC 3227.
2
Capture main memory and running kernel state before rebooting or modifying system state.
System RAM and active network socket tables are extracted using live acquisition tools before any changes to operating system processes occur.
Volatile system memory loses all data upon host shutdown.
3
Extract temporary memory paging files stored on disk.
Swap files and pagefiles are collected next, as they contain remnants of volatile RAM swapped to disk during system operations.
Transient storage bridges the gap between dynamic RAM and static disk contents.
4
Perform bit-stream disk acquisition of non-volatile local drives.
A forensic duplicate of the secondary storage drive is imaged using a hardware write-blocker.
Non-volatile storage persists through power cycles and is captured after all live volatile memory artifacts.
5
Identify persistent offline and long-term archival evidence.
Off-site archival backup tapes are cataloged and secured last.
Offline backup media is highly static and has the lowest risk of immediate volatility or decay.

Anahtar Kavram

Order of Volatility (RFC 3227)
Soru 1029Soru

A security engineer is configuring an enterprise Security Information and Event Management (SIEM) pipeline to process raw web application traffic logs and detect potential SQL injection attacks. Arrange the following log processing and analysis stages in the correct sequential order from initial log generation to SOC notification.

Öğeleri doğru sıraya koymak için sürükleyin

Cevabı ve açıklamayı göster

Cevap

The correct operational sequence is: (1) Raw web server log generation, (2) Field parsing via regular expressions, (3) Data normalization into a common schema, (4) Contextual telemetry enrichment, (5) Correlation rule evaluation across time windows, and (6) SIEM alert generation and SOC escalation.
The SIEM pipeline strictly processes events in sequential stages: raw log creation at the host is followed by parsing string text into discrete key-value fields. Once parsed, fields are normalized to a common enterprise schema so correlation logic remains vendor-agnostic. Enriched telemetry (such as threat intelligence reputational scores) is added next. The correlation engine then compares the normalized, enriched events against time-window thresholds. Finally, matching correlation conditions trigger an automated alert and escalation in the SOC dashboard.

Adım Adım Çözüm

1
Identify the event origination point.
The web server creates raw log text locally upon receiving an HTTP request.
Log data must first exist at the source endpoint before it can be collected and processed by SIEM infrastructure.
2
Structure the raw data payload.
SIEM ingestion regex splits string data into discrete key-value pairs.
Unstructured text cannot be efficiently queried or correlated until field boundaries are extracted.
3
Standardize variable names.
Parsed fields map to standard enterprise schema tags.
Normalization ensures correlation logic written for one device type applies across all vendor formats.
4
Augment event data with security context.
Event record receives threat intelligence risk scores and geographic metadata.
Enrichment allows correlation engines to weigh contextual risk (e.g., suspicious IP reputation) during rule evaluation.
5
Analyze multi-event patterns.
Stateful correlation engine detects threshold breaches for malicious patterns within a specified timeframe.
Correlation links individual enriched events together to detect broader attack behaviors.
6
Trigger security response.
An actionable alert is pushed to the SOC queue.
Alert generation notifies analysts after correlation logic confirms a high-confidence security event.

Anahtar Kavram

SIEM Log Processing Pipeline Lifecycle
Soru 1030Soru

Following an security alert indicating active LSASS memory injection on a Windows Domain Controller, an incident investigator needs to collect digital evidence from the running system. To strictly adhere to the order of volatility and maintain evidence integrity, which of the following actions should the investigator perform FIRST?

Cevabı ve açıklamayı göster

Cevap: Dump physical RAM to an external destination and immediately generate a cryptographic hash of the captured memory file

Cevap

The investigator should dump physical RAM to an external destination and immediately generate a cryptographic hash of the captured memory file.
In digital forensics, evidence must be collected in sequence from most volatile to least volatile (Order of Volatility: CPU registers/cache -> RAM -> network state -> disk -> archival media). Physical RAM contains transient evidence of active attacks such as LSASS memory injection. Capturing RAM while the system is running and calculating an immediate cryptographic hash ensures evidence preservation and verifies chain of custody integrity.

Adım Adım Çözüm

1
Identify the volatility level of evidence sources on the target system.
Physical RAM (live memory) is higher on the order of volatility than disk swap files, system disk images, or static logs.
According to the Order of Volatility (RFC 3227), most volatile evidence must be collected first before it is lost due to power changes or system activity.
2
Acquire the live physical memory without altering system power state.
Live injection payloads and credentials stored in RAM are successfully captured.
Shutting down or rebooting the server would instantly erase RAM contents.
3
Compute a cryptographic hash (e.g., SHA-256) of the acquired memory image file.
A baseline hash is established for the chain of custody log.
Cryptographic hashing proves evidence integrity and ensures that collected data remains unaltered throughout legal and forensic proceedings.

Anahtar Kavram

Order of Volatility and Chain of Custody Integrity Verification
Soru 1031Soru

A cybersecurity analyst is establishing an automated intelligence pipeline to ingest threat indicators from external industry peers. The analyst needs a standardized language format to represent attack patterns, indicators of compromise, and threat actor tactics in a structured, machine-readable format, independent of how the data is transmitted across the network. Which of the following standards should the analyst implement for data representation?

Cevabı ve açıklamayı göster

Cevap: STIX (Structured Threat Information Expression)

Cevap

STIX (Structured Threat Information Expression) is the correct standard because it provides a structured, machine-readable language format for specifying cyber threat intelligence.
STIX (Structured Threat Information Expression) is an open-standardized language designed specifically for describing cyber threat information in a structured, machine-readable JSON format. It allows organizations to share threat context, including indicators of compromise, threat actors, campaigns, and attack patterns, independently of the underlying network protocol used for transport.

Adım Adım Çözüm

1
Identify the core requirement of the scenario.
The requirement calls for a standardized data representation format for threat intelligence content, separate from transport protocols.
Threat intelligence frameworks separate the data serialization schema from the network delivery mechanisms.
2
Differentiate between data format standards and transport protocols.
STIX defines the data model schema (indicators, actors, TTPs), whereas TAXII defines the transport mechanism over HTTPS.
Understanding the separation of concerns between STIX and TAXII ensures proper architectural implementation.
3
Select the option corresponding to the data representation schema.
STIX (Structured Threat Information Expression) satisfies the requirement.
STIX is the industry standard format for representing structured cyber threat data.

Anahtar Kavram

STIX vs TAXII Standards in Cyber Threat Intelligence
Soru 1032Soru

During network traffic monitoring, a security administrator observes high volumes of unicast traffic being unexpectedly flooded to every physical port on a managed Layer 2 Ethernet switch. Packet analysis reveals that a single connected workstation is transmitting thousands of Ethernet frames per second, each using a unique, randomized source MAC address. As a result, the switch's Content Addressable Memory (CAM) table has become completely full, forcing the switch to broadcast incoming traffic across all ports in the broadcast domain. Which of the following network attacks is indicated by these observed behaviors?

Cevabı ve açıklamayı göster

Cevap: MAC table overflow

Cevap

The attack indicated by these indicators is a MAC table overflow attack.
The correct answer is MAC table overflow. Switches maintain a Content Addressable Memory (CAM) table to map MAC addresses to physical ports. When an attacker floods the network with frames containing randomized source MAC addresses, the CAM table quickly fills up. Once full, the switch can no longer learn new MAC mappings and enters a fail-open state, broadcasting incoming unicast frames out of all ports within the VLAN (acting like a hub), allowing an attacker to intercept traffic.

Adım Adım Çözüm

1
Analyze the observed technical indicators from the scenario log.
Identified high-volume Ethernet frame transmission from a single host containing randomized source MAC addresses causing CAM memory exhaustion.
Managed switches store MAC address to port mappings in a fixed-capacity CAM table.
2
Determine the impact on switch behavior when CAM table capacity is exceeded.
The switch fails open and behaves like a network hub, flooding unicast frames out of all ports within the VLAN.
When a destination MAC address is unknown because new entries cannot be learned in a full CAM table, the switch must flood frames to ensure delivery.
3
Map the technical indicators and outcome to the correct network attack classification.
Matched MAC table overflow (MAC flooding) as the specific attack technique.
Attacker tools (such as macof) flood fake MAC addresses specifically to capture traffic across the broadcast domain once the switch fails open.

Anahtar Kavram

MAC Table Overflow (MAC Flooding) Indicators
Soru 1033Soru

An enterprise infrastructure team is deploying an online transaction application that requires continuous availability and dynamic distribution of user traffic across multiple web servers. The application relies on in-memory user sessions that must remain mapped to the same backend host throughout an active session. If an application node becomes unresponsive, incoming connections must automatically be rerouted to healthy nodes without manual intervention. Which of the following high-availability solutions should the architect implement to meet these requirements?

Cevabı ve açıklamayı göster

Cevap: A Layer 7 load balancer configured with session affinity and automated health probes

Cevap

A Layer 7 load balancer configured with session affinity and automated health probes
Implementing a Layer 7 load balancer with session affinity (sticky sessions) and health probes meets all requirements. Layer 7 load balancing inspects HTTP/HTTPS requests to maintain user affinity to a specific backend server for in-memory session persistence. Simultaneously, active health probes continuously monitor node responsiveness, instantly removing failed servers from the active pool and rerouting incoming connections to ensure high availability and seamless uptime.

Adım Adım Çözüm

1
Analyze the operational requirements from the scenario
Identified key requirements: dynamic traffic distribution across multiple nodes, preservation of in-memory user session state, and automated health monitoring with continuous availability during node failure.
High-availability designs must evaluate both traffic routing capacity and application-level state constraints.
2
Evaluate application-layer (Layer 7) load balancing functionality
Determined that Layer 7 load balancers can read application data (such as HTTP cookies) to implement session affinity (sticky sessions) while performing active health checks to remove failed nodes from the pool.
Session affinity ensures users maintain connection state to their specific host, and health probes allow immediate automatic rerouting when a host fails.
3
Differentiate service high availability from storage fault tolerance and disaster recovery
Eliminated storage redundancy (RAID), unmonitored DNS distribution, and cold disaster recovery options as ineffective for real-time traffic balancing and session tracking.
Only application-aware load balancing fulfills both the resilience (failover) and state persistence requirements simultaneously.

Anahtar Kavram

Application Load Balancing, Session Affinity, and Active Health Monitoring
Tahmini Süre:1m 30s
Soru 1034Soru

A security technician has isolated a physical hard drive containing forensic evidence from a workstation involved in an internal investigation. The technician must transport the drive to a secure off-site facility for forensic imaging. Which of the following actions is most critical to preserve the legal admissibility of the physical evidence during transport?

Cevabı ve açıklamayı göster

Cevap: Maintaining a chain of custody document that records every physical transfer, including dates, times, and signatures of handlers.

Cevap

Maintaining a chain of custody document that records every physical transfer, including dates, times, and signatures of handlers.
Maintaining a comprehensive chain of custody form ensures that every transfer of physical control is logged with exact dates, times, purpose, and signatures of all handlers. This documentation establishes evidence provenance and proves that the evidence was continuously safeguarded against unauthorized access or modification.

Adım Adım Çözüm

1
Identify the primary requirement for legal evidence admissibility during physical transport.
Recognize that proof of continuous control and documentation of handler custody is mandatory.
Forensic evidence must be accounted for at all times to prevent allegations of evidence tampering or loss of integrity.
2
Evaluate operational procedures against digital forensics standards.
Logging each transfer with exact timestamps, handler identities, and signatures establishes a unbroken chain of custody.
Chain of custody forms provide verifiable proof of evidence provenance in judicial proceedings.

Anahtar Kavram

Chain of Custody and Evidence Provenance
Soru 1035Soru

A digital forensics investigator receives an external solid-state drive (SSD) delivered by a courier as part of an ongoing insider threat investigation. The drive is stored in an anti-static evidence bag with a tamper-evident seal and is accompanied by a chain of custody log detailing its initial acquisition and cryptographic hash. Which of the following steps should the investigator perform first upon receiving the physical evidence?

Cevabı ve açıklamayı göster

Cevap: Inspect the tamper-evident seal, sign the chain of custody form to document the transfer of possession, and attach the drive to a hardware write-blocker before taking verification hashes.

Cevap

Inspect the tamper-evident seal, sign the chain of custody form to document the transfer of possession, and attach the drive to a hardware write-blocker before taking verification hashes.
The correct answer emphasizes verifying physical evidence seals, immediately logging the transfer of control on the chain of custody form, and utilizing hardware write-blocking controls prior to mounting or hashing the evidence. This ensures evidence remains untampered and legal chain of custody is strictly preserved.

Adım Adım Çözüm

1
Verify physical evidence package integrity
Ensure the tamper-evident seal is undamaged and matches the seal ID listed on the accompanying documentation.
Physical integrity verification proves evidence was not modified or tampered with in transit.
2
Log custody transfer
Sign and date the chain of custody log indicating formal receipt of the storage drive from the courier.
Maintaining an unbroken chain of custody is mandatory for evidence admissibility.
3
Prepare for evidence acquisition
Connect the drive to a hardware write-blocking device prior to plugging it into the forensic workstation.
Write-blockers prevent the host operating system from writing data or updating access timestamps on the original evidence drive.

Anahtar Kavram

Chain of Custody and Forensic Evidence Intake
Tahmini Süre:1m 30s
Soru 1036Soru

During security monitoring, a Security Operations Center (SOC) analyst verifies that a database server hosting critical business records has executed an unauthorized executable from a temporary directory and opened an active outbound connection to a suspicious external endpoint. The threat analyst confirms the host is compromised. According to standard incident response process frameworks, which of the following actions should the analyst perform FIRST?

Cevabı ve açıklamayı göster

Cevap: Isolate the compromised database server from the network while maintaining host power to preserve volatile memory evidence.

Cevap

Isolate the compromised database server from the network while maintaining host power to preserve volatile memory evidence.
In standard incident response frameworks (such as NIST SP 800-61), once an incident is verified, the immediate priority is containment. Isolating the server from the network prevents the adversary from exfiltrating data or moving laterally to other enterprise resources. Keeping the machine powered on ensures volatile memory (RAM) is preserved for forensic analysis.

Adım Adım Çözüm

1
Identify the current incident response phase based on the scenario state.
The compromise is confirmed, placing the current activity at the transition between Detection/Analysis and Containment.
Once an active breach is verified, preventing lateral movement and further data exfiltration is mandatory prior to remediation.
2
Select the immediate containment step that preserves forensic artifacts.
Isolating the system at the network level stops adversary communication while preserving RAM volatile data.
NIST SP 800-61 Rev. 2 guidelines mandate limiting incident impact (containment) as the immediate next step after detection.

Anahtar Kavram

Incident Response Lifecycle - Containment Phase Execution
Soru 1037Soru

A Security Operations Center (SOC) analyst is investigating a cross-environment security alert in a SIEM console. The alert correlates web application server logs with cloud audit logs across a 5-minute timeframe:

Log Snippet 1 (Nginx Web Server Access Log):
`192.0.2.45 - - [27/Jul/2026:14:22:10 +0000] "GET /api/v1/fetch?url=http://169.254.169.254/latest/meta-data/iam/security-credentials/AppRole HTTP/1.1" 200 1423 "-" "Mozilla/5.0"`

Log Snippet 2 (CloudTrail Security Audit Log):
`{"eventTime": "2026-07-27T14:25:04Z", "eventName": "ListBuckets", "userARN": "arn:aws:iam::123456789012:role/AppRole", "sourceIPAddress": "198.51.100.89", "userAgent": "aws-sdk-python/1.26.0"}`

Based on the correlated log telemetry, which of the following best describes the attack vector executed and the log indicator confirming successful exploitation?

Cevabı ve açıklamayı göster

Cevap: A Server-Side Request Forgery (SSRF) attack exfiltrated IAM temporary role credentials from the instance metadata service (IMDS), confirmed by CloudTrail logging API requests issued from an external IP address (198.51.100.89) using the compromised role.

Cevap

A Server-Side Request Forgery (SSRF) attack exfiltrated IAM temporary role credentials from the instance metadata service (IMDS), confirmed by CloudTrail logging API requests issued from an external IP address (198.51.100.89) using the compromised role.
The correct answer accurately identifies Server-Side Request Forgery (SSRF) aimed at the internal cloud metadata address (169.254.169.254). The Nginx log demonstrates an attacker abusing a URL parameter to fetch temporary access tokens for the AppRole. The corresponding CloudTrail log confirms that the stolen temporary credentials were subsequently used by an external IP address (198.51.100.89) to execute the ListBuckets API call.

Adım Adım Çözüm

1
Analyze Nginx access log snippet for web application vector
Identified a GET request to `/api/v1/fetch?url=http://169.254.169.254/latest/meta-data/iam/security-credentials/AppRole` returning HTTP 200. This is a classic SSRF pattern targeting the cloud Instance Metadata Service (IMDS) to retrieve temporary security credentials.
The `url=` query parameter indicates the application fetches arbitrary external/internal URLs provided by user input without proper sanitization.
2
Analyze CloudTrail audit log snippet for credential usage
Event `ListBuckets` was called using `arn:aws:iam::123456789012:role/AppRole` from external source IP `198.51.100.89` via Python SDK (`aws-sdk-python`).
Instance roles are intended to be used directly by the EC2 instance host. Originating API calls from an unexpected external public IP indicates an attacker obtained the secret key/token from IMDS and configured local AWS CLI/SDK tools.
3
Correlate telemetry timeline and synthesize root cause
The web log entry at 14:22:10 UTC exfiltrated credentials, which were then used at 14:25:04 UTC by the attacker's workstation (198.51.100.89) to enumerate S3 buckets.
SIEM event correlation rules trigger on sequential events linking web application SSRF telemetry with anomalous external API calls using host-assigned IAM roles.

Anahtar Kavram

Log Correlation for Server-Side Request Forgery (SSRF) and Cloud Credential Theft
Soru 1038Soru

An enterprise security team detects that an automated build server within their CI/CD pipeline has been compromised by an attacker executing unauthorized external network sweeps and downloading secondary payloads. The incident response plan has entered the containment phase. Which of the following actions should the incident response team perform during this phase? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Isolate the compromised build server from the internal network by modifying its virtual security group or network interface settings.; Capture a complete volatile memory (RAM) snapshot of the compromised server prior to taking the host offline or rebooting.

Cevap

The incident response team should isolate the compromised build server from the network and capture a volatile memory (RAM) snapshot before powering down or re-imaging the host.
During the containment phase, the priority is to stop the incident from spreading while preserving evidence. Modifying network security settings to isolate the host prevents further lateral movement and C2 communications. Capturing volatile memory before rebooting or disconnecting ensures that live process states, active network connections, and unencrypted keys are captured following the order of volatility.

Adım Adım Çözüm

1
Identify the primary objectives of the Containment phase in NIST SP 800-61 / ISO 27035 IR frameworks.
The immediate goals are preventing further damage/lateral movement and preserving volatile evidence.
Containment limits the scope of an incident without destroying volatile forensic evidence necessary for root-cause analysis.
2
Evaluate containment options against evidence preservation rules.
Isolating the system via network controls stops network egress/sprouting while keeping memory intact. Capturing RAM preserves volatile state before memory is lost.
Taking volatile captures prior to host shutdown adheres to the order of volatility.
3
Differentiate containment actions from eradication, recovery, and post-incident activities.
System re-imaging belongs to Eradication/Recovery, while updating policies belongs to Post-Incident Activity (Lessons Learned).
Performing remediation or policy update steps out of order disrupts the incident response process and compromises forensic investigations.

Anahtar Kavram

Incident Response Lifecycle Phases and Containment Strategies
Tahmini Süre:1m 30s
Soru 1039Soru

An incident response team is conducting live digital forensics on a powered-up enterprise database server experiencing active kernel-level malware execution and network exfiltration. To prevent the loss of critical evidence during acquisition, in what exact sequence should the investigator collect the following digital evidence sources, starting with the MOST volatile source and ending with the LEAST volatile source?

Öğeleri doğru sıraya koymak için sürükleyin

Cevabı ve açıklamayı göster

Cevap

The correct sequence from most volatile to least volatile is: CPU registers and cache memory → System RAM and active network/kernel tables → Temporary file systems and swap space → Local non-volatile NVMe/SSD storage → Off-site archived backup media.
In digital forensics, evidence acquisition follows RFC 3227 Order of Volatility guidelines to ensure ephemeral data is captured before it evaporates or gets overwritten. CPU registers and L1/L2/L3 cache represent the most volatile tier because data shifts within nanoseconds. Physical RAM, active network sockets, ARP tables, and running process tables form the second tier because they rely on continuous system power. Pagefiles and swap space form the third tier; while located on disk, their contents change rapidly during OS memory swapping. Local persistent storage (SSDs/NVMe) is non-volatile and forms the fourth tier. Off-site archival media and cold backups are static long-term records, placing them in the final, least volatile tier.

Adım Adım Çözüm

1
Apply the RFC 3227 Order of Volatility guidelines for digital evidence collection.
Standard hierarchy established: Registers/Cache > System RAM/Kernel Tables > Swap/Temp Files > Local Disk Storage > Remote/Archival Media.
Volatile evidence collection must prioritize storage components with the shortest lifespan to prevent automated memory decay or overwriting.
2
Identify CPU hardware state data as position 1.
Item 1 (CPU registers, L1/L2/L3 cache) is placed first.
Processor registers and cache levels change continuously with every clock instruction cycle, making them extremely transient.
3
Identify system volatile RAM and live kernel structures as position 2.
Item 2 (System RAM, ARP cache, kernel tables) is placed second.
Random access memory depends on constant electrical charge and active power, losing all context immediately upon shutdown or power failure.
4
Identify virtual memory paging and swap structures as position 3.
Item 3 (Swap space, pagefile.sys, temporary file systems) is placed third.
Paging files reside on physical disk sectors but undergo rapid dynamic updates during memory swapping operations.
5
Identify local persistent drive storage as position 4.
Item 4 (Local non-volatile storage, NVMe, SSD) is placed fourth.
Local solid-state or magnetic drives are non-volatile and maintain stored data without electrical power.
6
Identify off-site long-term backups as position 5.
Item 5 (Off-site archived backup tapes, cold cloud snapshots) is placed fifth.
Archival storage backups are static, stored offline or in write-once repositories, and present zero risk of immediate volatile alteration.

Anahtar Kavram

Order of Volatility (RFC 3227)
Tahmini Süre:2m 30s
Soru 1040Soru

An organization is deploying an Endpoint Detection and Response (EDR) agent across its fleet of enterprise workstations to enhance host-level threat detection and incident containment capabilities. Which of the following represent core operational features provided by an EDR solution? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Continuous host telemetry collection and behavioral monitoring of active processes, registry changes, and memory executions; Automated host network isolation to stop lateral movement upon high-confidence threat detection

Cevap

The correct answers are the continuous host telemetry collection and behavioral monitoring of active processes, registry changes, and memory executions, along with automated host network isolation to stop lateral movement upon high-confidence threat detection.
Endpoint Detection and Response (EDR) agents provide continuous visibility into host activity by recording behavioral telemetry (process creation, file writes, network sockets, memory allocation) and support active response mechanisms like automated endpoint isolation to mitigate malicious lateral movement.

Adım Adım Çözüm

1
Identify the primary scope of Endpoint Detection and Response (EDR) technology.
EDR focuses specifically on host-level security observability, behavioral telemetry, continuous recording of system events, and proactive containment.
Understanding the boundary between endpoint monitoring and network/perimeter controls helps isolate valid EDR features.
2
Evaluate options offering continuous monitoring and automated containment.
Real-time process telemetry logging and automated network isolation of compromised host devices are standard EDR functions.
EDR replaces legacy signature-only scanning with continuous monitoring and automated playbooks for incident containment.
3
Differentiate EDR from network perimeter controls and legacy signature-based antivirus.
Edge traffic inspection belongs to network firewalls/IPS, while signature-based batch disk scanning characterizes legacy antivirus.
EDR operates on the endpoint itself using behavioral monitoring rather than relying on perimeter filtering or static signatures.

Anahtar Kavram

Core capabilities of Endpoint Detection and Response (EDR)
ÖncekiSayfa 52 / 112Sonraki
Tüm alıştırma soruları — CompTIA Security+ | Examkin