Tüm alıştırma soruları
2232 soru
A healthcare organization is evaluating a Web Application Firewall (WAF) safeguard for its cloud-hosted Patient Portal API. The API system has an estimated Asset Value () of . Threat modeling indicates that an unmitigated API breach has an Exposure Factor () of and an Annual Rate of Occurrence () of . Deploying the WAF will cost annually and is projected to reduce the Exposure Factor to , while keeping the constant. What is the net annual financial benefit of implementing this security safeguard?
A financial enterprise is integrating a legacy on-premises web application—which natively authenticates internal users via Kerberos tickets—with a modern cloud-based Identity Provider (IdP) to support federated single sign-on (SSO) for remote workers. The architecture must enable remote users to authenticate against the cloud IdP while ensuring internal domain controllers and Kerberos Key Distribution Centers (KDCs) are not directly exposed to external network traffic. Which IAM architectural solution best meets these requirements?
A security analyst monitoring identity provider logs identifies anomalous administrative API activity originating from an untrusted external IP address. Investigation reveals that a high-privilege user's OAuth refresh token was stolen via a session hijacking attack. The unauthorized actor is actively using this token to query and exfiltrate sensitive cloud database backups. Which of the following actions should the incident response team take FIRST to contain the breach?
A security operations team is reviewing identity and access management controls after an internal audit revealed two major vulnerabilities: third-party contractor sessions remain active for 24 hours without re-validation, and administrative users are executing high-risk privilege escalations from non-standard locations without step-up authentication. Which of the following IAM operational solutions should the security team implement to remediate these specific findings? (Select TWO.)
Geçerli olan tümünü seçin
During a routine vulnerability assessment, a security analyst reviews scan results targeting an internal web server farm behind a reverse proxy. The report highlights several high-severity remote code execution vulnerabilities based on outdated software version headers. However, an authenticated system audit confirms that security patches were fully applied and the underlying software was patched out-of-band without updating the exposed service header strings. Which of the following best explains why the vulnerability scanner reported these vulnerabilities?
Following an external compliance audit that uncovered inconsistent multi-cloud storage configurations across divisions, a Chief Information Security Officer (CISO) restructures the organization's security documentation hierarchy. The objective is to establish clear operational boundaries by distinguishing strictly enforceable mandates from discretionary guidance. Which of the following governance document types represent mandatory elements within an enterprise governance framework? (Select TWO.)
Geçerli olan tümünü seçin
A security analyst is investigating configuration compliance reports across an operational technology (OT) environment managed by an automated deployment framework. Although the centralized dashboard reports full compliance with the organization's hardened baseline template, manual vulnerability audits reveal that several controllers have unapproved network services active and customized settings configured locally. Further inspection indicates that local system administrators made manual adjustments directly on the devices, leading to configuration drift that was not detected or overridden by the centralized management tool. Which of the following actions should the security analyst perform FIRST to permanently address the configuration drift and restore baseline integrity?
A Security Operations Center (SOC) analyst receives an Endpoint Detection and Response (EDR) alert indicating an unauthorized process injection attempt on a critical financial application server. What is the correct operational sequence of actions to take when responding to this incident, ordered from the initial containment step to the final system restoration?
Öğeleri doğru sıraya koymak için sürükleyin
An automated Security Orchestration, Automation, and Response (SOAR) workflow is triggered upon detecting malicious code execution on a workstation. In what order should the playbook execute the following response actions to ensure effective containment while preventing unauthorized operational disruption?
Öğeleri doğru sıraya koymak için sürükleyin
An internal audit of a web application server reveals the following entries within the web server access log file:
text
192.168.1.105 - - [27/Jul/2026:14:22:10 +0000] "GET /api/v1/users?id=101%20OR%201=1 HTTP/1.1" 200 4520
192.168.1.105 - - [27/Jul/2026:14:22:15 +0000] "GET /api/v1/users?id=101%20UNION%20SELECT%20username,password_hash%20FROM%20accounts HTTP/1.1" 200 8940
192.168.1.105 - - [27/Jul/2026:14:22:18 +0000] "POST /api/v1/users?id=101%20EXEC%20xp_cmdshell('whoami') HTTP/1.1" 500 230
Based on these log entries, which of the following attack types has occurred, and what SIEM correlation logic should be deployed to detect similar future attempts?
A healthcare organization is issuing new tablet devices to clinical staff. Before provisioning the devices, the information security team must define a mandatory document specifying the minimum security configuration requirements, such as enabling full-disk encryption, enforcing PIN complexity, and disabling unused radio interfaces. Which of the following governance document types should the security team publish to enforce these minimum requirements?
A security analyst is evaluating correlated SIEM telemetry generated by network security monitoring sensors for host 172.16.10.45:
NIDS Alert:
[ALERT] [1:1002941:2] WEB-ATTACK HTTP POST /api/v1/user?input=%3Cscript%3Ealert%281%29%3C%2Fscript%3E HTTP/1.1
NetFlow Log:
SrcIP: 172.16.10.45 | DstIP: 198.51.100.55 | DstPort: 53/UDP | Packets: 4 | Bytes: 216 | Interval: 30s (Recurring)
Based on the network security monitoring telemetry provided, which of the following conclusions are accurate? (Select TWO).
Geçerli olan tümünü seçin
An enterprise organization is establishing a comprehensive third-party risk governance program and must evaluate four distinct independent security audit and attestation deliverables submitted by vendor candidates. Match each audit or attestation deliverable on the left with its defining operational scope and objective on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A global logistics organization is establishing vendor risk requirements for a third-party managed database service provider that will store customer personal data. The organization's risk management policy mandates independent third-party attestation confirming that operational security, availability, and confidentiality controls were actively tested and proven effective over a minimum six-month observation window. Which of the following audit attestation reports should the security manager request to meet this requirement?
Following a six-month human risk management initiative, an enterprise CISO observes that while employee click-through rates on simulated phishing emails dropped from 24% to 3%, the Security Operations Center (SOC) still experiences severe delays in receiving user reports during live spear-phishing campaigns. An audit reveals that employees frequently delete suspicious emails without utilizing the organization's automated phishing report button because they perceive reporting as time-consuming and non-essential. Which of the following security awareness program enhancements would be MOST effective to incentivize active threat reporting and improve the organization's Mean Time to Detect (MTTD)?
A chief information security officer (CISO) is preparing an online retail company for an annual regulatory oversight evaluation. To satisfy compliance mandates, the CISO must obtain an independent auditor's report that evaluates whether security controls were properly designed and operated effectively throughout a continuous six-month observation period, specifically addressing security, availability, and confidentiality trust services criteria. Which of the following independent attestations best fulfills this requirement?
A financial technology enterprise recently identified that software developers frequently bypass secure code review protocols when under tight sprint deadlines. Rather than issuing standard mandatory annual awareness training, the Chief Information Security Officer (CISO) wants to implement a human risk management strategy specifically targeted at modifying developer behavior during their active workflow. Which of the following initiatives represents the most effective security awareness control for this scenario?
During an enterprise security audit following a corporate reorganization, a financial institution discovers that the database administration team has been independently creating access control lists and adjusting retention schedules for repositories containing customer financial records. When interviewed, the database administrators stated that because they manage the storage servers and backup scripts, they are responsible for determining who receives access and how long records are maintained. Which role should the organization enforce to ensure that business accountability for data classification and access authorization is properly separated from operational system maintenance?
During an enterprise security alignment following an international expansion, an organization must formalize its data governance framework. Match each data management role on the left with its corresponding primary operational responsibility on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An organization's security team is evaluating a microservices deployment where an API gateway receives requests containing OAuth 2.0 JSON Web Tokens (JWTs) issued by a central Identity Provider. The API gateway validates the cryptographic signature of incoming tokens to verify issuer authenticity, but it immediately forwards all requests to downstream microservices without checking if the token's granted scopes permit access to the requested endpoint URI. Which pillar of the Authentication, Authorization, and Accounting (AAA) framework is improperly implemented at the API gateway layer?