Tüm alıştırma soruları
2232 soru
An enterprise security architect is reviewing access control operations across different corporate infrastructure components. Match each operational scenario on the left with its corresponding Authentication, Authorization, or Accounting (AAA) functional role on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An enterprise security team needs to deploy an urgent software patch to core payment gateways to remediate an actively exploited remote code execution vulnerability. To balance immediate threat mitigation with enterprise governance and risk management requirements, which of the following actions should the team take FIRST according to formal change management principles?
A healthcare SaaS vendor maintains an electronic prescribing API valued at . A security assessment identifies an unmitigated software vulnerability with an Exposure Factor () of and an Annual Rate of Occurrence () of . To address this risk, the organization evaluates an inline security control with an annual recurring operating expense of . Implementing this control will reduce the to and the to . What is the net annual financial benefit of implementing this security control?
An enterprise security architect is establishing a two-tier internal Public Key Infrastructure (PKI) hierarchy. The Root CA will remain air-gapped to maintain security, while a new Intermediate CA will issue operational certificates to web servers. Place the administrative steps for provisioning and activating the Intermediate CA into the correct chronological order from first to last.
Öğeleri doğru sıraya koymak için sürükleyin
During an ongoing security investigation into an automated build system, a security analyst discovers that an attacker compromised a CI/CD service account's API token and created unauthorized secondary deployment keys to maintain persistent access. The incident response team is currently executing the Containment phase of the NIST incident response lifecycle. Which of the following technical actions should the team perform immediately as part of containment? (Select TWO.)
Geçerli olan tümünü seçin
A security administrator must deploy a critical security patch across enterprise production application servers following standard change control and patch management practices. Place the following operational lifecycle steps in the correct sequential order from first to last.
Öğeleri doğru sıraya koymak için sürükleyin
An IT infrastructure team plans to implement a centralized Privileged Access Management (PAM) solution to manage administrative access across corporate servers. To comply with formal change management policies and minimize operational and security risks, in which sequence should the team perform the following change control steps?
Öğeleri doğru sıraya koymak için sürükleyin
During operational threat hunting, a security analyst detects an internal workstation communicating with an unrecognized external IP address using DNS over HTTPS (DoH). Detailed inspection of the query logs reveals that sensitive file paths and directory metadata are being systematically encoded into subdomains and sent outside the enterprise network. According to standard incident response lifecycle guidelines (NIST SP 800-61), which of the following actions should the incident response team execute FIRST upon confirming this activity?
An enterprise executive committee issues a high-level mandate requiring all internal data transmissions containing sensitive customer information to be strongly encrypted. To implement this directive across the organization, the IT security team publishes a mandatory technical document establishing the exact approved cipher suites, minimum key lengths, and required protocol versions that all systems must comply with. Which of the following governance document types is represented by this mandatory technical document?
An organization specifies that its primary customer database must be fully restored and operational within four hours following an unexpected system outage to prevent severe financial impact. Which of the following business continuity metrics does this duration represent?
A security operations team is configuring an internal vulnerability assessment for a critical database cluster. During initial test runs, network-based scans produced incomplete results because inline Network Intrusion Prevention System (NIPS) appliances dropped scanning probes after flagging them as port scanning attacks. Which of the following approaches should the team implement to ensure comprehensive vulnerability visibility without triggering network traffic blocking? (Select TWO.)
Geçerli olan tümünü seçin
An organization is ending its contract with a third-party cloud service vendor that hosted proprietary customer datasets. To satisfy data privacy compliance mandates and prevent unauthorized data disclosure, the security team must verify that all organizational data, including backups and shadow copies stored on the vendor's storage infrastructure, has been permanently removed and sanitized. Which of the following artifacts should the organization require from the vendor to validate that this requirement was completed?
A security administrator is evaluating the AAA implementation for a new enterprise remote access gateway. During connection establishment, the gateway verifies user credentials against an Active Directory domain controller, applies dynamic firewall rules to restrict network access based on role attributes, enforces bandwidth throttling policies according to user subscription tiers, and writes start/stop session timestamps to a central syslog server.
Which of the following operational activities performed by the gateway represent the Authorization pillar of AAA? (Select TWO.)
Geçerli olan tümünü seçin
A chief information security officer (CISO) is reviewing the quantitative risk assessment report for an organization's legacy data center hosting critical data storage arrays. The assessment establishes an Asset Value () of , an Exposure Factor () of , and an Annual Rate of Occurrence () of . The risk management team is evaluating several potential risk handling options. Which of the following statements accurately describe the risk metrics and response strategies in this scenario? (Select TWO.)
Geçerli olan tümünü seçin
A security analyst investigating enterprise Network Security Monitoring (NSM) alerts receives a notification from a Network Traffic Analysis (NTA) sensor. The alert indicates an unusual volume of outbound encrypted SSH traffic on port 22 originating from an internal corporate workstation toward an unfamiliar external IP address during non-business hours. Which of the following actions should the analyst perform as initial investigation and containment steps? (Select TWO.)
Geçerli olan tümünü seçin
An enterprise financial service provider relies on a third-party software-as-a-service (SaaS) platform to process sensitive customer data. During a recent audit, the security team discovered that while the SaaS vendor maintains a clean SOC 2 Type II report, the vendor's software pipeline dynamically pulls unverified sub-dependencies from open-source repositories at build time, exposing the enterprise to potential downstream software supply chain compromises. Which of the following technical controls should the enterprise security team require from the vendor to continuously validate component integrity and mitigate this software supply chain risk?
A systems administrator is configuring bulk storage encryption for a enterprise cloud file server holding sensitive financial records. The organization requires a cryptographic mechanism that delivers high-speed symmetric data encryption while simultaneously calculating an authentication tag to ensure confidentiality and data integrity during high-throughput disk operations. Which of the following cryptographic algorithms and modes BEST fulfills these requirements?
A security engineer is establishing a secure mutual TLS (mTLS) framework between microservices operating within air-gapped container clusters. During deployment testing, client microservices fail TLS handshakes because they cannot reach external certificate revocation lists (CRLs) or online responders to check server certificate validity. Additionally, security compliance mandates that private keys must originate exclusively within the local trusted execution environment of each microservice during certificate enrollment. Which of the following solutions should the engineer implement to resolve the revocation validation failures and satisfy the key generation compliance requirement? (Select TWO.)
Geçerli olan tümünü seçin
An enterprise is preparing to onboard a third-party Software-as-a-Service (SaaS) provider to process customer payment data. To comply with regulatory requirements, the security team must verify not only that the vendor has implemented required security controls, but also that these controls operated effectively over a continuous six-month period. Which of the following vendor artifacts should the security team request to validate this operational effectiveness?
An organization's security team is conducting a Business Impact Analysis (BIA) for a cloud-hosted customer portal. The analysis indicates that the organization can tolerate a maximum of two hours of lost data during an unpredicted outage before experiencing critical business impact. Which of the following metrics defines this maximum acceptable data loss timeframe?