Tüm alıştırma soruları
2232 soru
A global logistics organization is evaluating a cloud-based warehouse management platform to manage critical supply chain operations. The security team requires verification that the vendor's security controls addressing system availability and data confidentiality are not only properly designed, but have also been evaluated for operational effectiveness over a six-month monitoring window. Which of the following audit reports or attestations should the organization request from the vendor?
A cloud development team integrates an automated scanner into a continuous integration and continuous deployment (CI/CD) pipeline to check Infrastructure-as-Code (IaC) templates for misconfigurations. When the scanner identifies high-risk security flaws, it automatically terminates the build job, stopping non-compliant infrastructure from being deployed into the live cloud environment. According to security control classifications, which category and functional type pair best describes this automated scanner gate?
A software firm utilizes a cloud database service to store business records. The firm's executive leadership designates an internal department manager to establish access permissions, assign classification sensitivity levels, and dictate data retention rules for these records. Which of the following data governance roles is this department manager performing?
A financial analytics firm is conducting a quantitative risk assessment on its real-time market data feed server. The server has an Asset Value () of . Historical security data indicates that a major data breach occurs once every five years (). If the calculated Annualized Loss Expectancy () for this threat vector is , what is the Exposure Factor () of a single security breach?
A enterprise healthcare organization is deploying an S/MIME solution for secure email communications. The compliance team mandates that encrypted emails must remain recoverable by security auditors if an employee leaves the company. However, the legal team requires that digitally signed emails strictly maintain legal non-repudiation. Which of the following public key infrastructure (PKI) key management configurations should the security team implement to satisfy both requirements?
A security analyst is evaluating enterprise security mechanisms to classify them according to CompTIA Security+ functional control types. Which of the following examples correctly pair a security control with its primary functional control type? (Select TWO).
Geçerli olan tümünü seçin
An attacker contacts a remote branch manager while posing as an executive auditor from corporate headquarters. The attacker presents a fabricated narrative regarding an urgent regulatory compliance audit and persuades the branch manager to bypass standard identity verification procedures to grant temporary network credentials. Which social engineering technique was primarily utilized by the attacker to manipulate the victim?
An enterprise organization is establishing data governance boundaries for its centralized cloud repository. Which of the following responsibilities belong specifically to the Data Owner rather than the Data Custodian? (Select TWO.)
Geçerli olan tümünü seçin
A security analyst is investigating a dual-vector social engineering campaign targeting a corporate facility. During the investigation, the analyst notes that employees received text messages prompting them to verify credentials on a spoofed portal, while physical USB flash drives labeled "Executive Salaries" were strategically dropped in the employee parking area. Which of the following social engineering attack vectors were executed during this campaign? (Select TWO.)
Geçerli olan tümünü seçin
A regional financial institution based in the United States is updating its cybersecurity policy framework to ensure full alignment with the updated Gramm-Leach-Bliley Act (GLBA) Safeguards Rule. Which of the following administrative or technical controls is explicitly mandated by this regulatory framework to protect customer nonpublic personal information (NPI)?
An enterprise cloud engineering team at an online learning platform is standardizing infrastructure deployments across multiple cloud environments. To prevent configuration drift, the team publishes a mandatory document defining the mandatory minimum technical security configuration settings—such as turning off root SSH access, enforcing minimum encryption protocol versions, and disabling unused network daemons—that every Linux virtual machine must satisfy before deployment. Which of the following governance document types best describes this mandatory configuration document?
Following a compliance audit, an enterprise identifies a legacy core mainframe application that cannot natively support multi-factor authentication (MFA) or modern encryption protocols. To address the vulnerability without replacing the application, the security team deploys an isolated jump host requiring hardware token MFA and places an inline proxy in front of the mainframe to encrypt all transient sessions. Which of the following functional control types is best demonstrated by this implementation?
A cloud-based SaaS organization is evaluating security management options to address vulnerabilities identified in a legacy customer authentication service. The Chief Information Security Officer (CISO) recommends deploying an inline Web Application Firewall (WAF) to filter malicious input and purchasing a cyber liability insurance policy to cover regulatory penalties and third-party losses in the event of a breach. Which of the following risk response strategies are being directly implemented through these combined actions? (Select TWO.)
Geçerli olan tümünü seçin
Network security monitoring logs report repeated periodic UDP bursts originating from an internal application server to an unfamiliar external IP address over port 123. System configuration audits confirm that standard Network Time Protocol (NTP) services are disabled on this host. Which of the following initial actions should the security team take to analyze and contain this anomalous network activity? (Select TWO.)
Geçerli olan tümünü seçin
A security analyst is reviewing results from a routine network vulnerability scan targeting internal application servers. The generated report lists open network ports and OS banners, but fails to identify missing operating system patches, misconfigured registry settings, or internal web application vulnerabilities. Which of the following adjustments should the analyst make to resolve these scanning visibility gaps? (Select TWO)
Geçerli olan tümünü seçin
A cybersecurity team at a pharmaceutical organization is revising its governance framework for cloud storage repositories housing sensitive clinical trial data. Which of the following governance document types represent mandatory rules that mandate compliance across the enterprise? (Select TWO.)
Geçerli olan tümünü seçin
A security operations team is configuring an enterprise vulnerability management program for remote branch office Linux workstations connected over low-bandwidth VPN links. During preliminary network-based scanning, central scanner traffic caused noticeable network congestion across the VPN tunnels, and local host firewalls on workstations dropped multiple probe packets, resulting in incomplete scan results. Which of the following solutions should the team deploy to perform comprehensive vulnerability assessments without saturating WAN bandwidth or altering workstation firewall policies?
A regional health authority is updating its overarching security governance framework following an infrastructure modernization project. The governance steering committee must clearly distinguish between mandatory governance mandates and non-binding operational material. Which of the following document types constitute mandatory compliance requirements within the enterprise security governance framework? (Select TWO).
Geçerli olan tümünü seçin
A security systems engineer is deploying mutual TLS (mTLS) for communication between internal microservices. During testing, client microservice instances fail to authenticate to target API gateways. Inspection of the certificate validation logs reveals that the client certificates were rejected because their Extended Key Usage (EKU) attribute is configured exclusively for "Server Authentication" (1.3.6.1.5.5.7.3.1) rather than "Client Authentication" (1.3.6.1.5.5.7.3.2). Which of the following actions should the security engineer take to resolve the authentication failures while adhering to PKI best practices?
A systems administrator at a financial firm is assigned to manage database server infrastructure, perform routine data backups, and configure technical access controls according to management policies. The administrator does not determine why the customer data is collected or define how long it should be legally retained. Which data governance role is this administrator fulfilling?