Tüm alıştırma soruları
2232 soru
A security analyst is investigating a compromised cloud-hosted Linux virtual machine suspected of participating in an ongoing data exfiltration attack. To ensure proper digital forensics and maintain legal defensibility, which of the following actions should the analyst perform during initial evidence acquisition? (Select TWO).
Geçerli olan tümünü seçin
A security analyst investigates anomalous wireless activity at a corporate branch office. Users report being prompted to re-enter their domain credentials on an unfamiliar web page while connected to the corporate Wi-Fi, and a Wireless Intrusion Prevention System (WIPS) flags abnormal access point behaviors. Which of the following technical indicators specifically point to an active Evil Twin attack performing credential harvesting? Select TWO.
Geçerli olan tümünü seçin
A Security Operations Center (SOC) analyst is reviewing raw log telemetry streams collected from web servers, authentication systems, and perimeter firewalls inside a SIEM environment. Match each log snippet pattern on the left with its corresponding attack vector or security event classification on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A Security Operations Center (SOC) analyst receives a high-severity alert indicating that a powershell process on an internal endpoint is performing process injection into system memory. The analyst needs to immediately contain the active threat and prevent potential lateral movement across the internal network while maintaining remote administrative management to investigate the endpoint. Which of the following actions performed via an Endpoint Detection and Response (EDR) agent best achieves this goal?
A security analyst discovers that a developer's API key was publicly exposed in a code repository and is actively being used by an unauthorized external entity to read data from a cloud storage bucket. According to standard incident response playbooks, which of the following immediate CONTAINMENT steps should the analyst take? (Select TWO.)
Geçerli olan tümünü seçin
Match each enterprise system hardening practice to the specific security risk or operational vulnerability it is primarily designed to mitigate.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A multinational financial services enterprise is transitioning its legacy core banking infrastructure to align with Zero Trust Architecture (ZTA) principles to prevent lateral movement following network breaches. Which of the following architectural strategies MUST be implemented to adhere to Zero Trust principles? (Select TWO.)
Geçerli olan tümünü seçin
An organization experiences an unexpected municipal power grid failure at its primary data center. Although the rack-mounted Uninterruptible Power Supply (UPS) units immediately supplied emergency battery power to critical servers, all systems abruptly shut down 15 minutes later when the batteries depleted. An investigation revealed that the facility's backup diesel generator successfully started, but utility power was never switched over to generator power. Which of the following components should the security architect install to automate switching between primary utility power and secondary generator power?
A digital forensics investigator takes possession of a storage drive seized during an internal security investigation. What is the primary purpose of completing a chain of custody document for this evidence?
During a threat hunting exercise on an enterprise Linux application server hosting a mission-critical web service, a security analyst analyzes host telemetry. While network perimeter security controls inspect traffic as encrypted HTTPS over TCP port 443, the Endpoint Detection and Response (EDR) agent captures a process creation event where the primary web service daemon spawned an unauthorized bash shell, which subsequently loaded an obfuscated binary payload into volatile shared memory (`/dev/shm`). The analyst must halt the active command-and-control (C2) session and eradicate the malicious code execution immediately without causing downtime for legitimate external application users. Which of the following capabilities provided by the EDR platform should the analyst utilize to accomplish this objective?
A security analyst reviews a vulnerability assessment report for an enterprise web application that processes uploaded XML documents. The report indicates that the application parser evaluates Document Type Definitions (DTDs) containing external system references and subsequently passes unvalidated XML node content into backend database calls. Which of the following statements accurately identify the security risks present and their appropriate application-level remediations? (Select TWO.)
Geçerli olan tümünü seçin
A security analyst is designing an enterprise vulnerability assessment strategy for a network that includes legacy operational technology (OT) control systems, web applications, and sensitive database servers. The analyst must achieve maximum vulnerability visibility while minimizing the risk of unexpected service disruptions or system crashes. Which of the following technical scanning approaches should the security team implement to meet these requirements? (Select TWO.)
Geçerli olan tümünü seçin
A Security Operations Center (SOC) analyst detects an active, verified security incident where an adversary is utilizing a compromised internal jump server to maintain an unauthorized encrypted SSH tunnel to an external command-and-control IP address. The analyst has confirmed that sensitive data is actively being transferred across this channel. According to standard incident response lifecycle frameworks, which of the following actions should the analyst take FIRST?
Match each security log entry or SIEM telemetry event to the attack vector or operational activity it most accurately demonstrates.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A cloud incident handler detects active unauthorized API activity within a production cloud tenant. Investigation reveals that a developer accidentally committed an administrative API key to a public code repository, allowing an external threat actor to deploy unauthorized compute instances and initiate unauthorized data export jobs. The handler has verified the malicious activity in the cloud provider's audit logs. According to standard incident response lifecycle guidelines, which of the following actions should the handler take FIRST to contain the threat?
During an active incident response investigation involving an enterprise server suspected of executing malware in memory, a technician is instructed to power down the server immediately and pull the primary storage drive to generate a bit-stream disk image prior to capturing any system RAM or running processes. Which digital forensics principle is directly violated by executing this instruction?
A security engineer is reviewing correlated telemetry in a SIEM console containing the following web application firewall (WAF) and database audit events:
text
2026-07-27T14:15:02Z waf01 http_request client_ip=198.51.100.44 uri="/api/v1/catalog" status=200 payload="' UNION SELECT username, password_hash FROM accounts--"
2026-07-27T14:15:02Z db01 query_exec db_user="app_service" query="SELECT * FROM products WHERE category = '' UNION SELECT username, password_hash FROM accounts--'" rows_returned=1420
Which of the following attack vectors was successfully executed against the application based on these log entries?
During an active ransomware campaign impacting healthcare infrastructure, a security analyst at a regional hospital network needs to obtain verified indicators of compromise (IOCs) and threat actor tactics specifically targeting medical equipment. The analyst requires a trust-based, sector-focused intelligence pool that facilitates sanitized peer-to-peer telemetry exchange without exposing internal infrastructure details to commercial third parties. Which intelligence resource is best suited for this operational requirement?
A security analyst takes possession of a physical hard drive seized during a breach investigation. Which of the following actions must the analyst take to maintain a valid chain of custody and preserve evidence integrity? (Select TWO.)
Geçerli olan tümünü seçin
A security architect is designing hardware-level protections for unattended retail payment kiosks deployed in public environments. To protect payment encryption keys against physical memory extraction and ensure that only authenticated firmware executes during startup, which of the following hardware security controls should be implemented? (Select TWO.)
Geçerli olan tümünü seçin