Tüm alıştırma soruları
2232 soru
A security administrator is auditing an organization's identity lifecycle procedures to ensure clear operational separation between authentication and authorization controls. Which of the following operational activities specifically perform authentication? (Select TWO.)
Geçerli olan tümünü seçin
During network telemetry monitoring, a security technician observes an alert generated when an internal workstation attempts an unauthorized connection to a non-production server that contains simulated sensitive files and no real enterprise services. Which of the following network security monitoring concepts is actively being utilized in this scenario?
A security architect is evaluating hardware security controls for enterprise hardware and embedded system deployments. Match each hardware security component on the left to its corresponding security capability on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A security technician needs to assess an internal enterprise server to accurately identify missing operating system patches and local software misconfigurations while minimizing network bandwidth usage. Which of the following scan methods should the technician execute?
A security analyst reviews packet capture metrics following reports of intermittent traffic manipulation on a corporate wireless network. The packet capture reveals unexpected network protocol behavior during client IP address assignment. Which TWO of the following indicators specifically point to a rogue DHCP server attack on the network? (Select TWO.)
Geçerli olan tümünü seçin
A municipal water utility is re-architecting remote operational telemetry monitoring access for field maintenance engineers. The security architect must enforce Zero Trust Architecture (ZTA) principles to prevent unauthorized lateral movement across operational technology (OT) networks. Which of the following access control implementations best demonstrates the core Zero Trust tenets of explicit verification and least privilege?
Match each resilience and redundancy mechanism on the left with the corresponding operational requirement or architecture scenario on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A logistics enterprise is deploying thousands of handheld mobile terminals to remote distribution staff. The devices operate in physically untrusted environments and store sensitive customer authentication data. The security engineering team mandates that each device must validate system integrity from power-on through operating system initialization using hardware-bound cryptographic measurements, while securely storing full-disk encryption keys on a dedicated cryptoprocessor integrated into the endpoint's motherboard. Which of the following hardware security controls BEST meets this requirement?
A security administrator is planning a routine security evaluation of internal server infrastructure. Which of the following are distinct operational advantages of conducting a credentialed vulnerability scan rather than a non-credentialed network scan? (Select TWO.)
Geçerli olan tümünü seçin
A security administrator is troubleshooting a critical network storage appliance in a data center. The appliance features dual internal power supply units (PSUs) to ensure hardware fault tolerance. However, during a recent scheduled power maintenance event on a single electrical circuit, the appliance unexpectedly lost power and shut down. Investigation reveals that both PSUs were plugged into the same rack Power Distribution Unit (PDU). Which of the following infrastructure modifications should the administrator implement to prevent single-circuit power outages from taking the appliance offline?
Following an influx of fileless malware alerts detected by an Endpoint Detection and Response (EDR) solution, a Security Operations Center (SOC) team is refining an automated Security Orchestration, Automation, and Response (SOAR) playbook. During initial testing, a high-severity alert triggered the playbook to automatically isolate a primary Domain Controller, causing a critical network outage. Which playbook design modification BEST balances rapid threat containment with enterprise operational resilience to prevent future accidental outages?
A security operations analyst at a financial institution is investigating an unauthorized change alert on a core network device. The organization relies on a central TACACS+ server integrated with an LDAP directory for network device administration. The analyst reviews the following TACACS+ audit log entries:
text
[2026-07-27 14:15:02 UTC] AUTHEN PASS: user="net_admin1" port="tty1" rem_addr="10.1.5.22"
[2026-07-27 14:15:10 UTC] AUTHOR PASS: user="net_admin1" cmd="show running-config"
[2026-07-27 14:16:05 UTC] AUTHOR FAIL: user="net_admin1" cmd="configure terminal" reason="Privilege level insufficient"
[2026-07-27 14:16:12 UTC] AUTHEN PASS: user="svc_monitor" port="tty2" rem_addr="10.1.5.50"
[2026-07-27 14:16:30 UTC] AUTHOR PASS: user="svc_monitor" cmd="configure terminal" matched_rule="rule_group_ops_override"
Further inspection confirms that `svc_monitor` is a low-privilege automated monitoring account with read-only rights in the LDAP directory. Which of the following operational misconfigurations best explains why `svc_monitor` was permitted to run the restricted command while `net_admin1` was denied?
A security analyst inspecting telemetry from an Endpoint Detection and Response (EDR) system observes an unapproved administrative utility downloading an encoded payload from an external domain, followed by an immediate attempt to modify host boot configurations. Which of the following is the MOST effective immediate action the analyst should take using the EDR platform to contain the incident?
A security administrator notices during a routine audit that an employee who transferred to a new department retains active access permissions from their previous job role. Which identity and access management procedure should be executed to address this issue?
A Security Operations Center (SOC) analyst is inspecting web server access logs ingested into a SIEM platform. An automated correlation rule generated a low-priority informational alert after detecting directory path indicators in incoming HTTP requests. The SIEM displays the following sequential log entries:
192.168.1.45 - - [27/Jul/2026:14:22:01 +0000] "GET /api/v1/download?file=../../../../etc/passwd HTTP/1.1" 200 4096
192.168.1.45 - - [27/Jul/2026:14:22:05 +0000] "GET /api/v1/download?file=..%2f..%2f..%2f..%2fetc%2fshadow HTTP/1.1" 403 280
Based on these log entries, which of the following conclusions accurately identifies the security incident status and the required SIEM management action?
A security operations team is investigating an incident where an attacker maintained active access to enterprise cloud applications following the revocation of a compromised user's directory credentials. The centralized Identity Provider (IdP) successfully initiated password resets and disabled the directory account in response to a SIEM alert, yet the attacker continued performing privileged actions in single sign-on (SSO) web applications for several hours. Which of the following operational root causes directly contributed to this continuous unauthorized access and failure of immediate session termination? (Select TWO.)
Geçerli olan tümünü seçin
An IT security operations team wants to streamline incident triage by automatically connecting threat intelligence feeds with security monitoring tools and executing pre-defined response actions across different platforms. Which technology should the team implement to achieve this orchestration and automation?
During an internal fraud investigation, a security analyst seizes a desktop computer and generates a forensic image of the primary storage drive. Months later, during a legal proceeding, opposing counsel moves to suppress the forensic disk image evidence. Which of the following circumstances would serve as the strongest basis for suppressing the evidence due to a breakdown in the chain of custody?
A security technician is configuring network security monitoring rules to detect active compromises and data exfiltration. Which of the following observations represent valid network-level threat indicators that should trigger an immediate security alert? (Select TWO.)
Geçerli olan tümünü seçin
A Security Operations Center (SOC) team deploys an automated Security Orchestration, Automation, and Response (SOAR) playbook designed to mitigate rapid ransomware propagation. The playbook triggers automatically upon receiving high-severity Endpoint Detection and Response (EDR) telemetry, querying external threat intelligence APIs to verify file hashes before calling a Network Access Control (NAC) API to isolate the host network interface. During a red-team simulation, synthetic high-volume alert telemetry from an active primary domain controller causes the playbook to execute auto-isolation on the server, resulting in an immediate domain-wide operational outage. Which modification to the SOAR playbook logic or execution configuration best mitigates the operational risk of automated service disruption while maintaining rapid containment capabilities for verified threats?