Tüm alıştırma soruları
2232 soru
A network security administrator is investigating reports of intermittent network interception on a local subnet. Upon inspecting the ARP table of a target workstation, the administrator records the following entry state:
| IP Address | MAC Address | Binding Type |
|---|---|---|
| 192.168.1.1 | 00-11-22-AA-BB-CC | Dynamic |
| 192.168.1.105 | 00-11-22-AA-BB-CC | Dynamic |
Where 192.168.1.1 is the default gateway and 192.168.1.105 belongs to an unauthorized host on the network. Which of the following attack types is indicated by these findings?
Match each enterprise security assessment objective on the left with the scanning configuration or methodology best suited to satisfy it on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
During security operations monitoring, incident responders confirm an active data exfiltration event where an internal database server is sending bulk sensitive records via covert DNS port 53 queries to an untrusted external domain. According to standard incident response lifecycle frameworks, which of the following actions represents the immediate next step the incident response team should perform?
A manufacturing company relies on legacy operational technology (OT) workstations to manage assembly line machinery. Because these systems run specialized software on an outdated operating system that cannot receive vendor security updates, the security team must harden the workstations without disrupting continuous operations. The primary requirement is to block unauthorized executable files and unapproved dynamic-link libraries (DLLs) from running on the systems. Which of the following host hardening strategies is MOST effective for this requirement?
An Endpoint Detection and Response (EDR) agent on a critical enterprise macOS host generates a high-priority alert indicating that an unprivileged process is attempting direct system calls to read sensitive memory structures, bypassing user-mode security hooks. Which of the following actions performed via the EDR administration console is the most appropriate immediate step to contain the incident while preserving volatile forensic evidence?
A cybersecurity analyst is setting up a scheduled vulnerability assessment for production servers. The main requirement is to identify missing patches and misconfigurations without risking system crashes or service outages. Which scanning method should the analyst use?
A Security Operations Center (SOC) analyst detects an unauthorized third-party integration added to an enterprise cloud tenant, followed by bulk exfiltration of sensitive email records via an exposed OAuth 2.0 token. According to standard incident response frameworks, in what sequence should the IR team execute the following response and recovery steps?
Öğeleri doğru sıraya koymak için sürükleyin
A security analyst confirms that an active remote access Trojan (RAT) is running on an internal finance server and establishing outbound connections to an external command-and-control server. According to standard incident response lifecycle frameworks, which of the following actions should the analyst perform NEXT?
A security analyst is reviewing correlated alerts in a Security Information and Event Management (SIEM) dashboard following an automated high-severity trigger. The SIEM correlated the following two sequential event log entries captured from an internal workstation within a 5-second interval:
text EventID: 4624 Source: Microsoft-Windows-Security-Auditing Time: 2026-07-27T14:22:05Z Logon Type: 3 (Network) Account Name: admin_corp Workstation Name: WS-FINANCE-04 Source Network Address: 10.0.4.112 Elevated Token: Yes EventID: 7045 Source: Service Control Manager Time: 2026-07-27T14:22:10Z User: NT AUTHORITY\SYSTEM Service Name: PSEXESVC Service File Name: %SystemRoot%\PSEXESVC.exe Image Path: C:\Windows\PSEXESVC.exe Start Type: demand start
Which of the following attack vectors is most directly indicated by this log sequence?
A security analyst is investigating a suspected threat actor moving laterally within an enterprise network. The edge firewall recorded no unauthorized inbound traffic, and the legacy signature-based antivirus on host endpoints reported zero malicious file detections. However, the Endpoint Detection and Response (EDR) agent flagged an active alert when a natively trusted system utility, `wmic.exe`, was executed by a parent process to delete volume shadow copies. Which of the following capabilities of EDR enabled the identification of this malicious activity?
A security analyst reviews an alert from a Network Intrusion Detection System (NIDS). The alert log captures an incoming HTTP request containing the payload: `http://example.com/login?user=admin' OR '1'='1'--`. Which of the following statements correctly identify the type of attack detected and an effective mitigation? (Select TWO.)
Geçerli olan tümünü seçin
During a financial audit of a modern web application, security engineers discover that concurrent asynchronous POST requests to the payment endpoint allow users to apply a single-use promotional credit code multiple times simultaneously before the database updates the credit balance to zero. Which of the following application vulnerabilities is being exploited in this scenario?
A digital forensic examiner receives a powered-off workstation hard drive confiscated during an insider threat investigation. The examiner needs to duplicate the physical drive onto a forensic storage unit for analysis while ensuring evidence admissibility in court. Which of the following actions should the examiner take FIRST?
A system architect is designing high-availability storage connectivity for a mission-critical database server connected to a Storage Area Network (SAN). The design must ensure continuous data access even if a host bus adapter (HBA), interconnect cable, or SAN switch fails, while also balancing traffic across active pathways. Which of the following architectural controls should the security architect implement to fulfill this requirement?
A security engineer is designing an embedded industrial sensor node deployed in untrusted physical locations. The design requires that the system only executes cryptographically signed boot code during power-on to prevent unauthorized firmware modifications. Which of the following hardware security controls should the engineer implement to fulfill this requirement?
A network administrator is configuring centralized AAA for enterprise network hardware. During testing, administrative authentication to an edge switch succeeds via TACACS+, but the user is placed into unprivileged user EXEC mode rather than privileged EXEC mode. The TACACS+ server logs confirm that primary user authentication was successful. Which of the following identity and access management operations issues is the MOST likely cause of this behavior?
A security analyst reviews alert logs from a Wireless Intrusion Detection System (WIDS) deployed at a corporate headquarters. The WIDS flagged an anomaly where a single access point MAC address is sending immediate 802.11 Probe Response frames to every nearby device broadcasting Probe Requests, automatically matching whatever Service Set Identifier (SSID) the client requests—including 'Airport_Free_WiFi', 'Hotel_Guest', and 'Home_Network'. Which of the following attack types is indicated by this wireless behavior?
A security administrator is preparing to perform a credentialed vulnerability scan on internal application servers. Which of the following represent primary advantages of using a credentialed vulnerability scan instead of an unauthenticated scan? (Select TWO.)
Geçerli olan tümünü seçin
A financial technology organization is refactoring its internal microservices communication architecture to align with Zero Trust Architecture (ZTA) principles. An application security architect specifies that internal services must no longer trust incoming network traffic based on IP subnets or internal network placement. Instead, every request must be dynamically evaluated against contextual security policies and session health attributes before access is granted. Which logical component within the Zero Trust framework is directly responsible for evaluating these access policies and rendering the authorization decision?
An enterprise security team deployed agent-based vulnerability scanners across a hybrid environment comprising bare-metal host servers, containerized application workloads on managed Kubernetes nodes, and high-transaction database instances. During the initial operational assessment, the security team identifies two critical issues:
1. The installed host agents successfully inventory host OS packages but fail to detect software vulnerabilities existing inside running container filesystem layers.
2. Standard network-based vulnerability scans triggered against the database servers caused severe query latency and session timeouts.
Which of the following architectural modifications or scanning strategies should the security team implement to resolve both operational issues? (Select TWO.)
Geçerli olan tümünü seçin