Tüm alıştırma soruları
2232 soru
A financial enterprise is evaluating several third-party software and service providers during a comprehensive supply chain risk review. Match each vendor security assessment artifact on the left with the operational compliance or risk verification requirement it satisfies on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An enterprise executive board is drafting a high-level document that defines the organization's overarching commitment to information security, establishes security roles, and outlines broad strategic goals for risk management. Which security governance document type is the board preparing?
An organization is conducting a quantitative risk assessment for a core fintech payment processing service with an estimated asset value () of . Historical security data indicates an Exposure Factor () of () for data corruption threats, with an Annual Rate of Occurrence () of (once every two years). The security team proposes implementing an automated real-time transaction validation safeguard that costs annually to maintain. This safeguard lowers the to (), but due to operational overhead, the revised increases slightly to . Based on quantitative risk analysis, what is the net annual financial benefit of implementing this risk mitigation safeguard?
An organization is upgrading its access control infrastructure to allow third-party contractors temporary access to cloud-hosted management portals and APIs. The security team mandates that credentials must not be statically stored on client devices, identity assertions must be centralized via modern web standards, and access decisions must not rely on internal network perimeter position. Which of the following security mechanisms should be incorporated into this Identity and Access Management (IAM) architecture? (Select TWO.)
Geçerli olan tümünü seçin
An organization purchases a commercial cyber insurance policy to cover potential monetary losses resulting from data breach liabilities. Which risk response strategy is the organization implementing?
During an ongoing incident investigation, a security analyst suspects that a compromised workstation is executing fileless commands in memory and attempting to persist across reboots. Which of the following capabilities and telemetry sources provided by an Endpoint Detection and Response (EDR) solution should the analyst utilize to contain the threat and investigate the attack? (Select TWO)
Geçerli olan tümünü seçin
A security technician is inspecting newly received enterprise network switches to ensure they were not modified or tampered with by an unauthorized party during transit from the manufacturer. Which of the following supply chain security practices should the technician perform?
An organization discovers that a third-party networking vendor's internal build pipeline was compromised, allowing an attacker to push malicious, validly signed firmware updates directly to customer appliances via automated update channels. Which of the following supply chain risk management practices would have MOST effectively prevented the execution of the tampered firmware package within the organization's environment?
Match each third-party risk management agreement type on the left with its corresponding primary purpose on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An organization is conducting a quantitative risk assessment on an internal document storage server. Security analysts determine that a severe malware infection on the server results in a Single Loss Expectancy (SLE) of $10,000. Historical threat metrics indicate an Annual Rate of Occurrence (ARO) of 0.5 (occurring approximately once every two years). What is the Annual Loss Expectancy (ALE) for this risk?
A security analyst is reviewing organizational risk management activities across several enterprise initiatives. Which of the following examples correctly align the stated risk response strategy or security control application with its operational description? (Select TWO.)
Geçerli olan tümünü seçin
A Security Operations Center (SOC) analyst detects suspicious internal SMB traffic and administrative share creation originating from an HR workstation after business hours. Further inspection reveals that the host is actively communicating with an external command-and-control (C2) server. According to standard incident response frameworks, which of the following actions should the incident response team perform during the Containment phase? (Select TWO.)
Geçerli olan tümünü seçin
An enterprise security manager is defining the organization's internal governance framework. Which of the following document types represent mandatory rules or directives within an enterprise security governance structure? (Select TWO).
Geçerli olan tümünü seçin
A financial technology enterprise evaluates a security countermeasure for its core transaction processing portal, which has an Asset Value () of . Prior to implementing the safeguard, quantitative risk assessment indicates an Exposure Factor () of and an Annualized Rate of Occurrence () of .
To mitigate potential impact, the security team deploys a high-availability cloud mitigation service costing annually. With this safeguard active, the Exposure Factor () drops to , but automated threat scanning raises the effective Annualized Rate of Occurrence () to .
What is the net annual cost benefit (net safeguard value in USD) realized by deploying this cloud mitigation service?
A lead security architect is structuring an enterprise third-party risk management (TPRM) framework to mitigate supply chain exposure and enforce regulatory compliance across downstream service providers. Match each third-party oversight mechanism on the left with its primary operational objective on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An organization is purchasing enterprise network hardware to deploy in a high-security facility. To mitigate the threat of hardware supply chain tampering and counterfeit component insertion during transit from the vendor, which of the following operational controls should the organization mandate upon equipment delivery?
During a post-incident review of a cloud VPC environment, a network security monitoring (NSM) analyst inspects the following log generated by a monitoring sensor attached to a Virtual Network TAP:
text
[ALERT] 2026-07-27T14:22:05.112482 [GID: 1] [SID: 2049110] [REV: 3]
[Classification: A Network Trojan was detected] [Priority: 1]
{TCP} 10.150.4.52:49812 -> 198.51.100.77:8443
[Payload Snippet]: 47 45 54 20 2f 61 70 69 2f 76 31 2f 63 6f 6d 6d 61 6e 64 73
[TLS SNI]: c2.external-domain.invalid | [JA3 Fingerprint]: e7d705a3286e19ea42f589255019d675
Although the Snort/Suricata rule applied to the sensor was configured with a `drop` action, packet telemetry reveals the outbound C2 session established successfully and transferred data. Which of the following best explains why the malicious traffic was not blocked?
During an enterprise audit of a recently deployed cloud-native microservices architecture, auditors discovered that while executive leadership has mandated data encryption at rest, individual development teams are implementing inconsistent cryptographic algorithms, key lengths, and key rotation schedules. To remediate this finding by establishing mandatory, uniform technical specifications across all microservices without detailing tactical, step-by-step operational workflows, which security governance document must the CISO publish?
A security engineer is designing an enterprise Security Information and Event Management (SIEM) log pipeline to ingest data from heterogeneous sources. Place the stages of the log processing life cycle in the correct chronological order from initial log intake to incident detection notification.
Öğeleri doğru sıraya koymak için sürükleyin
A security analyst monitoring a Linux web server notices an alert indicating an unauthorized process was spawned in memory following a web application exploit. The process is actively attempting to establish outbound command-and-control (C2) communication. To minimize impact, the security analyst must stop the adversary's lateral movement and communication immediately without powering down the host or losing volatile RAM evidence. Which of the following EDR features best fulfills this requirement?