Tüm alıştırma soruları
2232 soru
A security administrator is establishing an automated failover sequence for an active-passive high-availability firewall pair to ensure continuous uptime during a node failure while preserving connection state tables. Place the operational failover steps in the correct chronological order from first to last.
Öğeleri doğru sıraya koymak için sürükleyin
A security analyst is initiating a digital forensics investigation on a compromised live application server. Which of the following actions should the analyst perform to adhere to proper evidence preservation and chain of custody procedures? (Select TWO.)
Geçerli olan tümünü seçin
A cybersecurity forensic analyst has just completed a bit-stream disk acquisition of a target drive seized during an insider threat investigation. The analyst must now process and secure the physical drive and digital image to ensure legal admissibility in court. Place the following evidence handling and chain of custody steps in the correct chronological order from first to last.
Öğeleri doğru sıraya koymak için sürükleyin
An organization is deploying an Endpoint Detection and Response (EDR) agent across all enterprise hosts. Which of the following core capabilities differentiate EDR solutions from traditional signature-based antivirus software? (Select TWO.)
Geçerli olan tümünü seçin
An autonomous electric vehicle (EV) charging network operator is updating its management plane and edge gateway infrastructure to comply with NIST SP 800-207 Zero Trust Architecture (ZTA) principles. Match each Zero Trust logical component to its core operational responsibility within the enterprise architecture.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A security analyst is investigating a stealthy compromise on an enterprise server where an attacker executed an obfuscated script directly in host memory using native tools, avoiding writing any malicious files to the disk. Standard signature-based antivirus software and perimeter firewalls failed to detect the activity. Which capability of Endpoint Detection and Response (EDR) provides the visibility required to identify and trace this fileless execution?
A storage administrator at a financial enterprise is tasked with securing sensitive transaction logs stored on a high-throughput Storage Area Network (SAN). The solution must protect data at rest against physical drive theft from the data center without introducing computational overhead on the host servers or latency into bulk disk operations. Which of the following storage security controls best satisfies these requirements?
An incident responder arrives at a compromised live workstation suspected of running volatile in-memory malware. To preserve digital evidence without destroying transient data, the responder must extract system artifacts in strict adherence to the forensic Order of Volatility (RFC 3227). In what sequence should the analyst collect the following evidence items, starting with the MOST volatile artifact (collected first) and ending with the LEAST volatile artifact (collected last)?
Öğeleri doğru sıraya koymak için sürükleyin
A security engineer is configuring an enterprise Security Information and Event Management (SIEM) pipeline to process raw web application traffic logs and detect potential SQL injection attacks. Arrange the following log processing and analysis stages in the correct sequential order from initial log generation to SOC notification.
Öğeleri doğru sıraya koymak için sürükleyin
Following an security alert indicating active LSASS memory injection on a Windows Domain Controller, an incident investigator needs to collect digital evidence from the running system. To strictly adhere to the order of volatility and maintain evidence integrity, which of the following actions should the investigator perform FIRST?
A cybersecurity analyst is establishing an automated intelligence pipeline to ingest threat indicators from external industry peers. The analyst needs a standardized language format to represent attack patterns, indicators of compromise, and threat actor tactics in a structured, machine-readable format, independent of how the data is transmitted across the network. Which of the following standards should the analyst implement for data representation?
During network traffic monitoring, a security administrator observes high volumes of unicast traffic being unexpectedly flooded to every physical port on a managed Layer 2 Ethernet switch. Packet analysis reveals that a single connected workstation is transmitting thousands of Ethernet frames per second, each using a unique, randomized source MAC address. As a result, the switch's Content Addressable Memory (CAM) table has become completely full, forcing the switch to broadcast incoming traffic across all ports in the broadcast domain. Which of the following network attacks is indicated by these observed behaviors?
An enterprise infrastructure team is deploying an online transaction application that requires continuous availability and dynamic distribution of user traffic across multiple web servers. The application relies on in-memory user sessions that must remain mapped to the same backend host throughout an active session. If an application node becomes unresponsive, incoming connections must automatically be rerouted to healthy nodes without manual intervention. Which of the following high-availability solutions should the architect implement to meet these requirements?
A security technician has isolated a physical hard drive containing forensic evidence from a workstation involved in an internal investigation. The technician must transport the drive to a secure off-site facility for forensic imaging. Which of the following actions is most critical to preserve the legal admissibility of the physical evidence during transport?
A digital forensics investigator receives an external solid-state drive (SSD) delivered by a courier as part of an ongoing insider threat investigation. The drive is stored in an anti-static evidence bag with a tamper-evident seal and is accompanied by a chain of custody log detailing its initial acquisition and cryptographic hash. Which of the following steps should the investigator perform first upon receiving the physical evidence?
During security monitoring, a Security Operations Center (SOC) analyst verifies that a database server hosting critical business records has executed an unauthorized executable from a temporary directory and opened an active outbound connection to a suspicious external endpoint. The threat analyst confirms the host is compromised. According to standard incident response process frameworks, which of the following actions should the analyst perform FIRST?
A Security Operations Center (SOC) analyst is investigating a cross-environment security alert in a SIEM console. The alert correlates web application server logs with cloud audit logs across a 5-minute timeframe:
Log Snippet 1 (Nginx Web Server Access Log):
`192.0.2.45 - - [27/Jul/2026:14:22:10 +0000] "GET /api/v1/fetch?url=http://169.254.169.254/latest/meta-data/iam/security-credentials/AppRole HTTP/1.1" 200 1423 "-" "Mozilla/5.0"`
Log Snippet 2 (CloudTrail Security Audit Log):
`{"eventTime": "2026-07-27T14:25:04Z", "eventName": "ListBuckets", "userARN": "arn:aws:iam::123456789012:role/AppRole", "sourceIPAddress": "198.51.100.89", "userAgent": "aws-sdk-python/1.26.0"}`
Based on the correlated log telemetry, which of the following best describes the attack vector executed and the log indicator confirming successful exploitation?
An enterprise security team detects that an automated build server within their CI/CD pipeline has been compromised by an attacker executing unauthorized external network sweeps and downloading secondary payloads. The incident response plan has entered the containment phase. Which of the following actions should the incident response team perform during this phase? (Select TWO.)
Geçerli olan tümünü seçin
An incident response team is conducting live digital forensics on a powered-up enterprise database server experiencing active kernel-level malware execution and network exfiltration. To prevent the loss of critical evidence during acquisition, in what exact sequence should the investigator collect the following digital evidence sources, starting with the MOST volatile source and ending with the LEAST volatile source?
Öğeleri doğru sıraya koymak için sürükleyin
An organization is deploying an Endpoint Detection and Response (EDR) agent across its fleet of enterprise workstations to enhance host-level threat detection and incident containment capabilities. Which of the following represent core operational features provided by an EDR solution? (Select TWO.)
Geçerli olan tümünü seçin