Tüm alıştırma soruları
2232 soru
An enterprise security architect is designing a hybrid Identity and Access Management (IAM) solution to enable Single Sign-On (SSO) for employees accessing both legacy on-premises systems and cloud-hosted web applications. The legacy systems rely on internal Active Directory Domain Services (AD DS) and Kerberos tickets, whereas the cloud applications require SAML 2.0 security assertions. Which of the following architectural controls and components must be deployed to support this hybrid authentication design? (Select TWO.)
Geçerli olan tümünü seçin
Security telemetry indicates that an administrative workstation has executed an unauthorized script attempting to establish a reverse shell to an external command-and-control (C2) server and extract system credentials. Which of the following response actions should an analyst perform directly using the Endpoint Detection and Response (EDR) agent to contain the threat while preserving forensic evidence? (Select TWO.)
Geçerli olan tümünü seçin
A security administrator is reviewing identity and access management protocol configurations for network infrastructure management. When evaluating TACACS+ against RADIUS for central administrative access control, which of the following operational characteristics are specific to TACACS+? (Select TWO.)
Geçerli olan tümünü seçin
A software security engineer is reviewing static code analysis findings for a legacy file rendering service. The report identifies two vulnerabilities: one where unvalidated user input is directly concatenated into a shell command string, allowing arbitrary system execution, and another where arithmetic calculations for buffer allocation fail to validate integer limits, leading to potential heap buffer overflows. Which of the following remediation techniques should the team implement to directly fix these code-level software vulnerabilities? (Select TWO).
Geçerli olan tümünü seçin
A security analyst is tasked with acquiring digital evidence from a detached persistent cloud storage volume associated with a compromised virtual machine. To ensure the collected storage volume data remains legally admissible and mathematically verifiable throughout the forensic investigation, which of the following procedures must the analyst perform? (Select TWO.)
Geçerli olan tümünü seçin
A security architect is designing a high-availability solution for a critical authentication service distributed across two geographically separated cloud availability zones. The solution must support dynamic redirection of client traffic during an outage and ensure zero data loss for active user sessions during a database failover. Which of the following technical controls should be included in the design to meet these resilience requirements? (Select TWO.)
Geçerli olan tümünü seçin
Match each hardware security mechanism on the left to its corresponding primary functional capability on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A Security Operations Center (SOC) team is responding to a high-severity Endpoint Detection and Response (EDR) alert on a Linux server hosting critical API microservices. Telemetry indicates an adversary attempted to load an unsigned rootkit kernel module via the `init_module` system call while disabling the local `auditd` daemon. Which of the following initial containment and forensic actions should be executed to halt potential threat activity while preserving crucial digital evidence? (Select TWO.)
Geçerli olan tümünü seçin
An enterprise security engineer is configuring vulnerability assessment approaches across specialized network segments and target environments. Match each operational scenario on the left with the scanning methodology or configuration best suited to satisfy its operational requirements on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A security analyst is monitoring network alerts and observes repeated connection attempts targeting an isolated server in the DMZ. The server contains no actual production data or legitimate services and is specifically set up to decoy potential attackers. Which type of security tool is generating alerts for this monitored activity?
A financial services organization is designing a modern Identity and Access Management (IAM) architecture. The organization needs to grant a third-party analytics application permission to read transaction history from its internal API on behalf of authenticated end users. Company security policy mandates that end-user credentials must never be exposed to or stored by the third-party application, and access rights must be scoped specifically for API data delegation without transferring identity authentication assertions. Which of the following identity and access management frameworks should the security architect select to meet these requirements?
During an active threat triage, telemetry from a critical workstation's Endpoint Detection and Response (EDR) agent alerts to suspicious memory modifications. An unprivileged process performed memory injection into a legitimate system binary using direct Native API system calls, bypassing user-mode API hooks. The rogue process has created an unbacked memory region executing stealthy code, but no outbound command-and-control (C2) network sockets have been established yet. Which action should the security analyst take FIRST via the EDR platform to mitigate risk without destroying essential volatile forensic evidence?
A security analyst at a healthcare organization is auditing authentication logs following a security alert. The logs reveal that an offboarded remote employee successfully accessed internal resources using legacy RADIUS credentials. Although the central identity provider (IdP) had disabled the employee's primary directory account, the RADIUS server accepted local fallback credentials because it failed to synchronize account deprovisioning status. Which of the following identity management operational practices would have MOST effectively prevented this unauthorized access?
An organization is conducting a quantitative risk assessment for an operational technology (OT) historian database with an Asset Value () of . Historical telemetry indicates an Annual Rate of Occurrence () of for ransomware incidents targeting this segment, with an estimated Exposure Factor () of . The security team proposes installing an air-gapped data diode and automated offline snapshot vault, which carries an annual maintenance and licensing cost of . This safeguard is expected to reduce the to , though heightened network scanning associated with the diode's monitoring system increases the overall slightly to . What is the net annual monetary benefit (safeguard value) of implementing this countermeasure?
A manufacturing enterprise is conducting a quantitative risk analysis on a critical industrial control system (ICS) server. The server has an estimated Asset Value () of . A specific malware outbreak is projected to result in an Exposure Factor () of . Historical threat intelligence indicates that the Annualized Rate of Occurrence () for this type of attack is . What is the baseline Annualized Loss Expectancy () in dollars for this asset prior to implementing additional countermeasures?
An enterprise financial institution is preparing to integrate a third-party payment processing API into its core banking platform. During the vendor risk assessment, the security team notes that while the primary vendor adheres to strong internal security standards, the API relies on multiple embedded open-source components and downstream software dependencies. To continuously track, evaluate, and respond to vulnerabilities originating within these embedded components across the software deployment lifecycle, which of the following mechanisms should the security team require from the vendor?
A Security Operations Center (SOC) analyst is reviewing Identity and Access Management (IAM) event logs following an automated alert regarding an unauthorized privilege escalation attempt. The following log snippet was retrieved from the central SIEM:
[2026-07-27 10:02:11] IdP_AUTH SUCCESS user="j.smith" realm="corp.internal" src_ip="10.10.4.12" auth_method="MFA_TOTP"
[2026-07-27 10:02:14] PAM_ELEVATE_REQ user="j.smith" target_role="DomainAdmin" verified_group_membership=["Helpdesk_L1"]
[2026-07-27 10:02:15] PAM_POLICY_EVAL user="j.smith" rule="Trust_Internal_Subnet_AutoApprove" match=TRUE
[2026-07-27 10:02:16] PAM_SESSION_START user="j.smith" effective_role="DomainAdmin" status="GRANTED"
Based on the log data, which of the following operational root causes explains why `j.smith` was granted the `DomainAdmin` role?
A biotechnology enterprise is updating its network security posture to protect cloud-hosted genomic research databases accessed by remote scientists. The organization intends to implement Zero Trust Architecture (ZTA) principles to replace legacy perimeter defenses. Which of the following requirements must be implemented to align with core Zero Trust tenets? (Select TWO.)
Geçerli olan tümünü seçin
An enterprise risk manager is evaluating proposed risk responses for a legacy payment processing database with an Asset Value () of . A quantitative risk assessment established an Exposure Factor () of and an Annual Rate of Occurrence () of . To address the identified vulnerabilities, the leadership team executes two initiatives:
1. Decommissioning the legacy database completely and migrating its functionality to a managed SaaS platform to remove internal system exposure.
2. Executing a contract with an external service vendor that includes explicit financial indemnification clauses in the event of data breaches during transit.
Which TWO of the following statements accurately characterize these risk management responses and associated metrics?
Geçerli olan tümünü seçin
Match each organizational vulnerability assessment requirement to the most appropriate scan configuration method.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler