Tüm alıştırma soruları
2232 soru
A multinational e-commerce company headquartered in the United States is expanding its online retail services to consumers residing within the European Union. During payment checkout, the platform processes customer credit card numbers, primary account numbers (PAN), full legal names, billing addresses, and IP addresses. Which of the following regulatory compliance frameworks or mandates directly govern the protection and handling of this customer data? (Select TWO.)
Geçerli olan tümünü seçin
Following an enterprise-wide risk assessment, a multi-national cargo shipping organization dictates that all database servers housing customer payment data must enforce mandatory AES-256 encryption at rest across all operating environments. Which governance document type should the security governance team publish to officially enforce this specific mandatory technical requirement?
A healthcare software organization is establishing governance guidelines for its compliance team to differentiate formal third-party attestations from internal technical security assessments. The security manager must clarify how third-party attestation reports function within an enterprise risk management program. Which TWO of the following statements accurately describe the primary characteristics of third-party security attestations?
Geçerli olan tümünü seçin
A security analyst reviewing network security monitoring logs spots an alert triggered by an HTTP POST payload sent to an internal web application: `POST /api/search HTTP/1.1 Host: app.internal Payload: vendor_id=102 UNION SELECT username, password_hash FROM user_accounts--`. The analyst must identify the nature of the alert and determine the correct mitigation step without disabling HTTP services across the enterprise subnet. Which of the following correctly categorizes this attack vector and specifies the appropriate security control?
A hospital network contracts a third-party security firm to perform a systematic evaluation of its electronic health records (EHR) infrastructure. The assessors conduct staff interviews, review policy documentation, and inspect access log configurations against established regulatory safeguards to verify compliance. The assessment team does not execute exploit scripts or perform automated vulnerability scanning against live endpoints. Which of the following assessment types is being performed?
A financial technology company is establishing risk management controls for its public customer feedback portal. To manage risks associated with potential web application threats and security breaches, the CISO approves purchasing a specialized cyber insurance policy while also deploying multi-factor authentication (MFA) and API rate limiting on the portal. Which of the following risk response strategies are being directly implemented by the organization in this scenario? (Select TWO.)
Geçerli olan tümünü seçin
A security analyst is evaluating privacy-enhancing technologies for handling sensitive customer location records under regional data protection frameworks. Which of the following statements accurately describe key characteristics of pseudonymization? (Select TWO.)
Geçerli olan tümünü seçin
An attacker registers a domain name that closely resembles an enterprise's official login portal by altering a single character in the domain URL. The attacker uses this fraudulent domain to host a spoofed site that captures employee credentials when users accidentally mistype the legitimate web address. Which of the following social engineering attack vectors is best illustrated in this scenario?
A cloud-based human resources software-as-a-service (SaaS) provider located in the United States hosts employee performance records on behalf of its corporate enterprise clients operating within the European Union. The clients determine which employee data is collected and how long it should be retained. Under the General Data Protection Regulation (GDPR), which role and legal obligation best describes the SaaS provider's compliance status regarding this employee data?
An enterprise risk manager is performing a quantitative risk assessment on a database cluster hosting proprietary research data with an Asset Value () of . Initial threat modeling indicates an Exposure Factor () of per ransomware event, with an estimated Annual Rate of Occurrence () of . The Chief Information Security Officer (CISO) is evaluating an automated endpoint containment safeguard costing annually, which would reduce the to while leaving the unchanged. What is the net annual cost-benefit (annual loss reduction minus safeguard cost) of deploying this security control?
Following an internal audit that identified unauthorized workstation software modifications, an enterprise security team deploys an automated configuration management tool. This software continuously monitors workstation configuration files against an established baseline and automatically restores any modified settings back to their approved baseline state. Which of the following best classifies this security control according to CompTIA Security+ category and functional type definitions?
A cloud infrastructure engineer is tasked with configuring encryption settings, running routine database backup jobs, and enforcing access control lists on a cloud storage bucket per corporate policy mandates. Which data governance role best describes the engineer's operational responsibilities?
Match each enterprise security implementation to its primary CompTIA Security+ classification by category and functional type.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A defense technology enterprise is updating its security management framework to enforce minimum host configuration states across all endpoint devices. The cybersecurity team must publish a mandatory governance document that explicitly defines the compulsory security settings, patch levels, and feature configurations required for a system to be permitted on the network. Which of the following governance document types best satisfies this requirement?
An enterprise security administrator is establishing a Public Key Infrastructure (PKI) key lifecycle policy for employee S/MIME email certificates. The policy specifies that private keys associated with email encryption certificates must be backed up to a key escrow agent, whereas private keys associated with digital signature certificates are strictly prohibited from key escrow. Which of the following best explains the security rationale for prohibiting key escrow on digital signature private keys?
A security administrator is designing a vulnerability scanning strategy for an enterprise environment containing both standard authenticated servers and fragile legacy embedded systems. The primary goals are to obtain deep visibility into host patches and configuration flaws on the servers while minimizing network traffic overhead and preventing disruption to sensitive legacy devices. Which of the following technical scanning approaches should the administrator implement? (Select TWO.)
Geçerli olan tümünü seçin
A Security Operations Center (SOC) analyst receives a high-priority alert regarding anomalous network traffic detected by a NetFlow monitoring tool. The flow logs reveal continuous, high-volume ICMP Echo Request traffic originating from an internal server to an unknown external IP address, with each packet carrying an unusually large payload of 1,400 bytes. Which of the following statements accurately interpret this network activity and specify the appropriate initial containment steps? (Select TWO.)
Geçerli olan tümünü seçin
An enterprise security administrator is formalizing an operational workflow to handle human risk incidents, progressing from initial end-user detection of a spear-phishing attempt to enterprise-wide awareness training improvements. Place the following procedural steps in the correct chronological order from first to last.
Öğeleri doğru sıraya koymak için sürükleyin
A publicly traded healthcare technology firm in the United States is deploying an enterprise resource planning (ERP) system to process billing records and forecast quarterly corporate revenues. During an operational risk review, the audit committee emphasizes that the application must enforce strict separation of duties, tamper-evident audit logging, and verifiable internal controls specifically to prevent fraudulent reporting of financial statements. Which of the following regulatory frameworks or federal mandates primarily governs these financial data integrity requirements?
During a routine network security monitoring review, a security analyst analyzes DNS traffic logs from an internal database server and identifies repetitive query patterns requesting long, randomized subdomains under an external domain, accompanied by large TXT record responses containing base64-encoded payloads. Which of the following initial containment and mitigation actions should the analyst take? (Select TWO.)
Geçerli olan tümünü seçin