Tüm alıştırma soruları
2232 soru
During network monitoring, a security team identifies an unauthorized device acting as a rogue DHCP server on a corporate office VLAN, assigning malicious default gateway addresses to internal endpoints. The incident response team has confirmed the alert and identified the specific physical switch port connected to the rogue device. According to standard incident response procedures, which of the following actions should the team perform next?
A security operations analyst is reviewing access gateway logs following reports that remote workers cannot connect to an enterprise VPN. The authentication gateway delegates identity verification to a central SAML 2.0 Identity Provider (IdP) and passes authorization queries to a RADIUS policy server. The analyst inspects the following log entries from the RADIUS policy engine:
[2026-07-27 11:02:14] RADIUS-AUTH: SAML token validated successfully for '[email protected]'.
[2026-07-27 11:02:15] RADIUS-POL: Evaluating Network Policy 'VPN_Engineering_Access'.
[2026-07-27 11:02:15] RADIUS-POL-ERR: Group attribute 'CN=Contractors,OU=Groups' does not match required group 'CN=FullTime_Engineers'.
[2026-07-27 11:02:15] RADIUS-AAA: Sending ACCESS-REJECT for session candidate '[email protected]'.
Based on the log output, which of the following best describes the root cause of the access failure?
A security analyst is investigating an authentication and privileges alert in a hybrid enterprise environment. The log audit reveals that a non-interactive service account (`svc_vaultsync`) authenticated via LDAPS from a workstation IP address and successfully retrieved domain administrative credentials from a Privileged Access Management (PAM) vault outside scheduled maintenance hours. Which of the following operational controls or administrative practices should the security team implement to mitigate this incident and harden IAM operations against future abuse? (Select TWO.)
Geçerli olan tümünü seçin
During a scheduled vulnerability assessment of an enterprise network segment, an automated scanner causes several legacy network switches to become unresponsive due to resource exhaustion from high-frequency port probing and service discovery requests. Which of the following adjustments should the security engineer implement to maintain visibility into these network devices without causing service disruptions?
A security analyst is reviewing modern cryptographic primitives and key management practices for an enterprise application architecture. Match each cryptographic technique on the left with its primary security objective or operational implementation on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A security architect is mapping newly implemented security controls across an enterprise network against CompTIA Security+ control categories (Technical, Managerial, Operational, Physical) and functional control types (Preventive, Deterrent, Detective, Corrective, Compensating, Directive). Match each enterprise security measure on the left to its corresponding dual-axis classification on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
Following an alert indicating potential ransomware propagation via macro execution on an executive laptop, an incident responder requires immediate containment and detailed investigation tools operating directly on the host. Which TWO of the following capabilities represent primary features of an Endpoint Detection and Response (EDR) solution that address this situation?
Geçerli olan tümünü seçin
A security administrator must deploy a critical system patch and an updated security hardening baseline across a fleet of enterprise application servers. To minimize operational risk and maintain security compliance, the administrator must follow a structured configuration and patch management workflow. In what order should the administrator execute these operational steps from first to last?
Öğeleri doğru sıraya koymak için sürükleyin
An organization is updating its security governance framework to enforce consistent cryptographic controls across all network edge devices. The security team needs to publish a document that specifies mandatory technical configuration requirements, including exact encryption algorithms and key lengths that systems administrators must implement. Which of the following document types best fulfills this requirement?
A security analyst is conducting a awareness session regarding telecommunications-based threat vectors. Which of the following social engineering attacks specifically rely on voice phone calls or cellular text messages as their primary delivery vector? (Select TWO.)
Geçerli olan tümünü seçin
During a security incident, an organization's Security Operations Center (SOC) identifies a compromised containerized application actively scanning internal microservices for vulnerabilities. Place the following incident response actions in the correct sequential order from FIRST to LAST according to standard incident handling frameworks.
Öğeleri doğru sıraya koymak için sürükleyin
An enterprise security team is selecting appropriate vulnerability assessment methodologies for distinct operational requirements across the enterprise environment. Match each vulnerability assessment approach on the left with the operational use case on the right that best represents its application.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An organization configures an automated endpoint configuration management agent across its cloud instances. The agent continuously monitors system files for unapproved modifications, immediately sends an alert upon detecting a divergence, and automatically restores the altered files back to their authorized baseline state without human intervention. Which of the following best classifies this control by its category and functional type?
Match each security governance document type on the left with its corresponding operational characteristic on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A security analyst detects suspicious fileless activity on an enterprise endpoint, where a legitimate administrative process is spawned to run encoded PowerShell scripts that attempt lateral movement across the internal subnet. The analyst must halt all network communication to and from the compromised host to stop lateral movement, while maintaining active command-and-control connectivity between the endpoint agent and the EDR management console for live forensic investigation. Which of the following Endpoint Detection and Response (EDR) actions should the analyst take?
A web administrator is setting up a new internal server and needs to secure web traffic using HTTPS. The administrator generates a public-private key pair on the web server and packages the public key alongside organizational details into a request file to send to the enterprise Certificate Authority (CA). Which of the following is the administrator creating to submit to the CA?
A security analyst in a Security Operations Center (SOC) confirms that a workstation in the accounting department is infected with active ransomware. Network monitoring logs indicate the infected host is currently attempting to scan and encrypt remote file shares over SMB across the local subnet. Which of the following actions should the analyst perform FIRST according to standard incident response process playbooks?
A financial institution upgraded its treasury management software to require biometric verification prior to executing wire transfers, while enforcing role-based policies that constrain transfer limits according to employee job titles. During a post-transaction audit, security analysts confirmed that user identities were successfully verified and authorization boundaries were strictly enforced, but noted that no timestamped system logs were generated to record the specific destination account numbers or transfer amounts modified during sessions. Which pillar of the AAA framework is incomplete in this system design?
An organization's security team is publishing advisory recommendations and suggestions for employees working remotely. These document entries offer non-mandatory best practices to help staff maintain clean home workspaces, but they do not enforce strict operational compliance. Which of the following governance document types best describes these advisory recommendations?
A security administrator needs to obtain and deploy a new TLS server certificate signed by a public Certificate Authority (CA). What is the correct sequence of administrative steps to accomplish this task?
Öğeleri doğru sıraya koymak için sürükleyin