Tüm alıştırma soruları

2232 soru

Soru 1861Soru

Match each regulatory compliance framework or legal mandate on the left with its primary governing scope or regulatory requirement on the right.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Children's Online Privacy Protection Act (COPPA)
NYDFS Cybersecurity Regulation (23 NYCRR 500)
Federal Information Security Modernization Act (FISMA)
Digital Operational Resilience Act (DORA)

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

COPPA matches verifiable parental consent for children under 13; NYDFS Cybersecurity Regulation matches designating a qualified CISO and submitting annual compliance certification; FISMA matches federal agency security controls aligned with NIST frameworks; DORA matches European ICT risk management and operational resilience requirements.
Each regulatory framework is accurately paired with its legal scope. COPPA targets online services collecting data from children under 13; NYDFS Cybersecurity Regulation targets state-regulated financial entities by requiring a designated CISO and annual attestation; FISMA governs federal agency information systems via NIST standards; and DORA establishes European Union operational resilience and ICT incident reporting rules.

Adım Adım Çözüm

1
Identify the mandate of COPPA
COPPA protects children online by requiring verifiable parental consent before gathering personal data from anyone under 13.
The primary focus of COPPA is child privacy protection for commercial websites and online services.
2
Identify the mandate of the NYDFS Cybersecurity Regulation
NYDFS 23 NYCRR 500 mandates covered financial entities to designate a CISO and submit annual compliance attestations.
This state regulation sets explicit governance and reporting rules for financial services licensed in New York.
3
Identify the mandate of FISMA
FISMA mandates federal information system protection using NIST frameworks.
FISMA legally binds federal executive agencies and government contractors to maintain standardized security controls.
4
Identify the mandate of DORA
DORA enforces digital operational resilience and incident reporting for European financial entities and ICT providers.
DORA standardizes ICT risk management across financial sectors in the European Union.

Anahtar Kavram

Scope and technical obligations of international, federal, state, and sector-specific regulatory compliance frameworks.
Tahmini Süre:1m 30s
Soru 1862Soru

An enterprise security analyst is investigating an incident where several finance department employees received unexpected phone calls from an individual claiming to be a senior IT support engineer. The caller stated that an emergency payroll system update required immediate phone-based password confirmation to avoid halting monthly salary disbursements. Which TWO of the following social engineering attack vectors or principles of influence were directly utilized in this scenario?

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Vishing, by conducting voice-based telephone calls to coax targets into revealing sensitive credentials; Urgency, by threatening imminent disruption to salary disbursements if employees failed to act immediately

Cevap

The scenario demonstrates vishing (using voice calls over the telephone to gather credentials) and urgency (forcing quick compliance by threatening immediate financial process delays).
Vishing is correct because the social engineering attack was executed over the telephone using voice communications. Urgency is correct because the attacker exploited panic and pressure by fabricating a time-critical situation involving employee payroll delays to force immediate compliance.

Adım Adım Çözüm

1
Analyze the primary communication vector utilized in the attack.
The attacker contacted targets via direct telephone conversations to request corporate credentials.
Voice communications used for social engineering credential harvesting represent vishing (voice phishing).
2
Analyze the psychological mechanism applied to compel victim compliance.
The threat actor claimed that immediate action was mandatory to avoid delaying salary disbursements.
Creating a artificial sense of imminent crisis to bypass standard verification protocols exemplifies the principle of urgency.

Anahtar Kavram

Differentiating social engineering delivery vectors (vishing) and psychological principles of influence (urgency).
Soru 1863Soru

A network intrusion detection system (NIDS) generates an alert showing unexpected SMB connection attempts originating from an internal workstation (192.168.10.45) directed toward an unassigned internal IP address (10.0.99.50) hosting a decoy server. Security policy dictates that no operational systems should ever communicate with this target address. Which of the following conclusions correctly interprets this network security monitoring alert?

Cevabı ve açıklamayı göster

Cevap: The alert indicates unauthorized internal lateral movement or reconnaissance detected by a deception monitoring control.

Cevap

The alert indicates unauthorized internal lateral movement or reconnaissance detected by a deception monitoring control.
Because honeypots are decoy assets with no legitimate operational role, any network traffic directed toward them serves as a high-fidelity indicator of unauthorized reconnaissance or lateral movement from a compromised host.

Adım Adım Çözüm

1
Analyze the alert telemetry, identifying the source IP, destination IP, and target protocol.
Identified internal host 192.168.10.45 initiating SMB connections to target host 10.0.99.50.
Determining the flow and nature of traffic is necessary to evaluate the security context of the alert.
2
Evaluate the functional role of the target asset in network operations.
Recognized 10.0.99.50 as a decoy/honeypot asset with zero legitimate production traffic.
Because honeypots serve no active business purpose, any connection attempt represents high-fidelity evidence of scanning or unauthorized lateral movement.
3
Select the option that accurately reflects the alert significance and security control classification.
Concluded that the event captures internal threat activity via a detective deception control.
Honeypots serve a detective function rather than acting as inline traffic firewalls or automated remediation utilities.

Anahtar Kavram

Deception Technology and Network Incident Alerting
Soru 1864Soru

An enterprise security team is defining fundamental data governance and privacy requirements for a new corporate application. Match each data governance concept on the left with its corresponding operational description on the right.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Data Sovereignty
Data Minimization
Data Anonymization
Data Retention Policy

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Data Sovereignty pairs with subjecting data to local laws where stored; Data Minimization pairs with collecting only strictly necessary data; Data Anonymization pairs with irreversibly removing identifiable attributes; Data Retention Policy pairs with establishing storage timelines and disposal schedules.
Each concept directly aligns with its fundamental security requirement: Data Sovereignty relates to legal jurisdiction based on physical storage location; Data Minimization enforces collecting only what is strictly necessary; Data Anonymization irreversibly removes PII; and Data Retention Policies specify holding periods and secure destruction.

Adım Adım Çözüm

1
Identify the core objective of Data Sovereignty
Recognize that legal jurisdiction over data depends on geographic physical location.
Sovereignty relates directly to national boundaries and regional data privacy compliance laws.
2
Identify the core objective of Data Minimization
Recognize the constraint to restrict collection to minimal required fields.
Minimization reduces risk exposure by preventing superfluous collection of sensitive user information.
3
Identify the core objective of Data Anonymization
Recognize irreversible destruction of identity markers.
Unlike pseudonymization, true anonymization cannot be reversed to expose personal identities.
4
Identify the core objective of a Data Retention Policy
Recognize lifecycle rules governing how long data stays in storage and when it must be purged.
Retention policies balance compliance obligations with risk reduction through timely data destruction.

Anahtar Kavram

Data Governance, Classification, and Privacy Controls

Daha Fazla Pratik

Review how data pseudonymization differs from data anonymization under GDPR and modern privacy standards.
Tahmini Süre:1m 0s
Soru 1865Soru

An organization's security metrics reveal that high-risk departments, such as finance and human resources, continue to exhibit elevated click-through rates on sophisticated spear-phishing simulations despite completing the mandatory annual security awareness course. The CISO wants to update the awareness program to effectively reduce human risk in these departments while maintaining a supportive security culture. Which of the following strategies is the most effective approach to achieve this objective?

Cevabı ve açıklamayı göster

Cevap: Deliver tailored, role-based micro-learning and targeted phishing simulations designed specifically for high-risk job functions.

Cevap

Deliver tailored, role-based micro-learning and targeted phishing simulations designed specifically for high-risk job functions.
Role-based security awareness tailors educational content and simulated phishing scenarios to the specific threats, data access levels, and workflows of vulnerable job functions (such as financial wire transfers or HR credential targeting). Providing frequent micro-learning modules keeps threat awareness top of mind without causing training fatigue, fostering a constructive security culture.

Adım Adım Çözüm

1
Analyze the organizational problem
High-risk departments (Finance, HR) face specialized threats like business email compromise and spear phishing that general awareness courses do not adequately address.
Generic baseline training provides broad compliance coverage but lacks role-specific context.
2
Evaluate human risk management controls against organizational goals
Targeted, role-based micro-learning combined with relevant simulations directly addresses function-specific threat vectors while reinforcing behavioral change.
Training must fit the user's operational context and avoid punitive policies to encourage prompt incident reporting.

Anahtar Kavram

Role-Based Security Awareness and Human Risk Management
Soru 1866Soru

A security architect is deploying TLS certificates for three newly established internal microservices hosted on distinct domain structures: identity.corp.local, billing.corp.internal, and api.corp.com. To simplify management, the architect intends to issue a single digital certificate that will be trusted and valid across all three different fully qualified domain names. Which of the following configuration options should the security architect specify during certificate generation to achieve this goal?

Cevabı ve açıklamayı göster

Cevap: Subject Alternative Name (SAN) extension

Cevap

The Subject Alternative Name (SAN) extension should be specified in the certificate request.
The correct option is the Subject Alternative Name (SAN) extension. SAN is an X.509 extension that allows security professionals to specify multiple hostnames, IP addresses, or domain names (including different top-level domains) in a single SSL/TLS certificate.

Adım Adım Çözüm

1
Analyze the technical requirements of the scenario.
The requirement demands securing three distinct domain names (identity.corp.local, billing.corp.internal, and api.corp.com) using a single digital certificate.
Different domain names with varied top-level domains cannot be covered by standard single-domain certificates or wildcard certificates.
2
Evaluate PKI certificate extension options for multi-domain support.
The Subject Alternative Name (SAN) X.509 extension field explicitly allows multiple discrete hostnames and domain names to be embedded within a single certificate.
SAN extensions provide flexible identity binding across unrelated domain structures.

Anahtar Kavram

Subject Alternative Name (SAN) Certificates
Tahmini Süre:1m 15s
Soru 1867Soru

A Security Operations Center (SOC) analyst receives a high-priority alert from a Network Intrusion Detection System (NIDS) indicating anomalous outbound TCP traffic on port 443 with a mismatched Server Name Indication (SNI) header. In what order should the analyst execute the following triage and response steps to effectively investigate and mitigate the network threat?

Öğeleri doğru sıraya koymak için sürükleyin

Cevabı ve açıklamayı göster

Cevap

The correct sequence begins with examining the initial NIDS alert metadata, querying NetFlow data to measure session impact, correlating network events with host endpoint logs, and ending with executing containment and network block rules.
The analyst must follow standard network security monitoring procedure: start by reviewing NIDS metadata for baseline context, examine NetFlow records for session metrics, cross-reference endpoint logs to determine the initiating process, and finally enforce containment once malicious activity is confirmed.

Adım Adım Çözüm

1
Analyze NIDS alert metadata
Identified source internal host IP and remote destination IP address
Initial triage requires verifying basic alert properties before conducting deeper analysis.
2
Evaluate NetFlow telemetry
Quantified session duration and total byte counts sent over the network
Flow statistics help assess potential impact and determine if large data transfers occurred.
3
Correlate with host endpoint logs
Identified the specific process and user account creating the socket connection
Linking network alerts to endpoint activity isolates the root cause software or script.
4
Execute containment and mitigation controls
Blocked outbound connection attempt and isolated compromised system
Active containment is performed after identifying and verifying the threat vector to prevent further damage.

Anahtar Kavram

Network Security Monitoring Triage Workflow
Tahmini Süre:1m 30s
Soru 1868Soru

A corporate employee receives a customized USB flash drive in the mail labeled 'Confidential: Executive Salary Adjustments Q3' that appears to originate from the human resources department. Driven by curiosity, the employee connects the drive to a company workstation, which immediately triggers malicious code execution. Which social engineering attack vector did the attacker utilize in this scenario?

Cevabı ve açıklamayı göster

Cevap: Baiting

Cevap

Baiting is the social engineering technique used in this scenario.
Baiting is an attack vector in which an adversary promises or provides a physical medium (such as a USB drive) or a digital item enticed by curiosity or reward. When the target plugs the compromised device into an internal machine, malicious code executes.

Adım Adım Çözüm

1
Analyze the attack vector and medium described in the scenario
The attacker delivered a physical storage device (USB flash drive) enticingly labeled to exploit curiosity.
Identifying the medium (physical USB drive vs. digital email or phone call) narrows down the social engineering classification.
2
Evaluate the psychological trigger used by the attacker
The label 'Executive Salary Adjustments' relies on curiosity and greed to induce the victim to plug in the drive.
Baiting specifically relies on offering something enticing or intriguing (the bait) to entice the user into taking an unsafe physical action.
3
Match the observed tactic to standard social engineering definitions
Leaving or sending malware-laden physical hardware for a victim to connect is the textbook definition of baiting.
This differentiates the attack from purely digital vector mechanisms such as email phishing or web compromises.

Anahtar Kavram

Baiting Social Engineering Vector
Soru 1869Soru

A financial institution is performing a quantitative risk assessment on its central Hardware Security Module (HSM) cluster used for payment cryptographic operations. The HSM cluster has an estimated Asset Value (AVAV) of $1,200,000\$1,200,000. A risk analysis team determines that a major key exposure incident would have an Exposure Factor (EFEF) of 0.250.25. Threat intelligence models project an Annualized Rate of Occurrence (AROARO) of 0.150.15 for such an incident. What is the calculated Annualized Loss Expectancy (ALEALE) in US dollars for the HSM cluster?

Cevabı ve açıklamayı göster

Cevap: 45000

Cevap

The Annualized Loss Expectancy (ALEALE) is $45,000.
To calculate the Annualized Loss Expectancy (ALEALE), first determine the Single Loss Expectancy (SLE=AV×EFSLE = AV \times EF). With an Asset Value (AVAV) of $1,200,000\$1,200,000 and an Exposure Factor (EFEF) of 0.250.25, SLE=$1,200,000×0.25=$300,000SLE = \$1,200,000 \times 0.25 = \$300,000. Next, multiply SLESLE by the Annualized Rate of Occurrence (ARO=0.15ARO = 0.15) to arrive at ALE=$300,000×0.15=$45,000ALE = \$300,000 \times 0.15 = \$45,000.

Adım Adım Çözüm

1
Calculate the Single Loss Expectancy (SLE)
$300,000
Single Loss Expectancy (SLESLE) measures the monetary loss expected each time a threat occurs. It is computed as Asset Value (AVAV) multiplied by Exposure Factor (EFEF): $1,200,000×0.25=$300,000\$1,200,000 \times 0.25 = \$300,000.
2
Calculate the Annualized Loss Expectancy (ALE)
$45,000
Annualized Loss Expectancy (ALEALE) calculates the overall yearly expected loss from the threat. It is computed by multiplying Single Loss Expectancy (SLESLE) by the Annualized Rate of Occurrence (AROARO): $300,000×0.15=$45,000\$300,000 \times 0.15 = \$45,000.

Anahtar Kavram

Quantitative Risk Analysis (SLE and ALE Calculation)
Tahmini Süre:1m 30s
Soru 1870Soru

A financial technology company operating a cloud-native microservices platform requires all container host nodes processing sensitive transaction data to comply with a specific, mandatory set of minimum technical security settings, such as disabling root SSH logins and enabling kernel audit logging. Which of the following governance documents should the security architecture team publish to define these mandatory, platform-specific minimum configuration settings?

Cevabı ve açıklamayı göster

Cevap: Security baseline

Cevap

The security baseline is the correct document type because it specifies mandatory minimum technical configuration standards for targeted platforms or operating systems.
A security baseline specifies mandatory minimum configuration settings tailored to a particular operating system, cloud platform, or device role. System-level hardening parameters like kernel audit configurations and SSH restrictions represent platform-specific baseline settings.

Adım Adım Çözüm

1
Analyze the scenario requirements
The requirement calls for a mandatory, platform-specific set of low-level technical hardening rules (disabling root SSH, enabling kernel audit logging) across container host nodes.
Determining whether a governance document is mandatory vs discretionary and high-level vs system-specific identifies its position in the governance hierarchy.
2
Evaluate governance document types against the requirements
A security baseline translates broader policies and standards into a mandatory, reproducible minimum configuration state for specific hardware, software, or operating systems.
Baselines ensure consistent enforcement of minimum security settings across identical platform deployments.

Anahtar Kavram

Security Governance Hierarchy: Policies vs Standards vs Baselines vs Guidelines
Tahmini Süre:1m 0s
Soru 1871Soru

Following an incident where an attacker successfully impersonated an IT helpdesk technician over the phone to reset employee passwords, a security team is enhancing its human risk management program. The team seeks to implement targeted administrative controls and specialized training to prevent similar credential compromise incidents. Which of the following strategies represent appropriate human risk mitigation controls for this scenario? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Establish mandatory out-of-band verification protocols when employees receive unprompted requests for credential updates or identity confirmation.; Deliver role-based security awareness training focused on identifying voice phishing (vishing) tactics and phone-based social engineering.

Cevap

The correct controls are establishing mandatory out-of-band verification protocols for unprompted identity requests and delivering role-based security awareness training focused on voice phishing tactics.
Establishing out-of-band verification requires employees to authenticate phone requests using a secondary, independently verified communication channel (such as calling back an official internal extension). Combining this policy with role-based vishing awareness ensures personnel can recognize impersonation attempts and adhere to identity validation procedures.

Adım Adım Çözüm

1
Analyze the incident scenario to identify the primary threat vector and human risk component.
The attack vector involves phone-based impersonation (vishing) targeting employees to reset passwords.
Understanding the attack mechanism is essential for selecting controls tailored to the specific human vulnerability.
2
Evaluate proposed administrative and awareness controls for mitigating phone-based social engineering.
Mandatory out-of-band verification prevents unauthorized password resets by confirming identity through an independent channel. Role-based training equips staff with knowledge of vishing tactics.
Combining procedural verification controls with targeted awareness training mitigates human susceptibility to social engineering.
3
Verify control classification and technical feasibility of distractor options.
Host EDR tools operate on computer endpoints and cannot manage telephone traffic. Training programs are administrative/operational controls, not technical controls.
Distinction between technical, operational, and administrative control categories ensures proper defense implementation.

Anahtar Kavram

Security Awareness and Human Risk Management Controls
Soru 1872Soru

Match each social engineering attack vector or technique on the left with the enterprise incident scenario on the right that best demonstrates its execution.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Pharming
Quid Pro Quo
Hoax
Dumpster Diving

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Pharming matches the DNS/host file redirection scenario; Quid Pro Quo matches offering an IT upgrade service in exchange for credentials; Hoax matches the false virus alert instructing file deletion; Dumpster Diving matches searching physical waste bins for discarded documents.
Each attack vector is paired correctly according to its characteristic method: Pharming alters name resolution to redirect traffic, Quid Pro Quo exchanges a service for credentials, Hoax disseminates false alarms to provoke self-harming behavior, and Dumpster Diving physically recovers sensitive discarded items from trash bins.

Adım Adım Çözüm

1
Analyze the technical mechanics described in each scenario.
Identify technical redirection (Pharming), physical scavenging (Dumpster Diving), false threat warning (Hoax), and transactional incentive offering (Quid Pro Quo).
Social engineering vectors are distinguished by their primary delivery medium and psychological mechanism.
2
Pair each technique with its corresponding operational scenario.
Pharming links to DNS corruption, Quid Pro Quo links to service exchange for credentials, Hoax links to fake virus alert causing self-inflicted damage, and Dumpster Diving links to waste bin scavenging.
Matching requires evaluating key indicators such as DNS tampering, physical access to trash, service offers, and deceitful warnings.

Anahtar Kavram

Social engineering attack vectors and operational techniques
Tahmini Süre:1m 30s
Soru 1873Soru

An enterprise security analyst is performing a quantitative risk assessment on an internal source code repository server housing proprietary intellectual property. The repository server has an estimated Asset Value (AVAV) of $400,000\$400,000. Threat intelligence reports indicate that a major security breach would result in an Exposure Factor (EFEF) of 25%25\% (0.250.25). Based on historical incident data, such an exposure event is expected to occur once every two and a half years, establishing an Annual Rate of Occurrence (AROARO) of 0.400.40. What is the Annual Loss Expectancy (ALEALE) for this repository server?

Cevabı ve açıklamayı göster

Cevap: $40,000\$40,000

Cevap

The Annual Loss Expectancy (ALEALE) for the source code repository server is $40,000\$40,000.
The correct calculation for Annual Loss Expectancy (ALEALE) requires first finding the Single Loss Expectancy (SLE=AV×EF=$400,000×0.25=$100,000SLE = AV \times EF = \$400,000 \times 0.25 = \$100,000) and then multiplying by the Annual Rate of Occurrence (ALE=SLE×ARO=$100,000×0.40=$40,000ALE = SLE \times ARO = \$100,000 \times 0.40 = \$40,000).

Adım Adım Çözüm

1
Calculate the Single Loss Expectancy (SLESLE)
SLE=AV×EF=$400,000×0.25=$100,000SLE = AV \times EF = \$400,000 \times 0.25 = \$100,000
Single Loss Expectancy determines the financial impact of a single risk event by multiplying the total asset value by the loss impact percentage.
2
Calculate the Annual Loss Expectancy (ALEALE)
ALE=SLE×ARO=$100,000×0.40=$40,000ALE = SLE \times ARO = \$100,000 \times 0.40 = \$40,000
Annual Loss Expectancy projects the annualized loss by taking the financial loss of a single event and multiplying it by the yearly frequency of occurrence.

Anahtar Kavram

Quantitative Risk Analysis formulas: SLE=AV×EFSLE = AV \times EF and ALE=SLE×AROALE = SLE \times ARO
Tahmini Süre:1m 30s
Soru 1874Soru

Following an evaluation of an enterprise security awareness program, a security analyst notes that while annual training completion rates reach 98%, employees rarely notify the security team when encountering suspicious messages. To improve human risk detection, the organization wants to establish a key performance indicator (KPI) that specifically measures proactive employee engagement in threat detection during phishing simulations. Which of the following metrics best evaluates this proactive reporting behavior?

Cevabı ve açıklamayı göster

Cevap: The phishing reporting rate, measured by the percentage of simulated phishing emails reported by employees using an automated reporting tool

Cevap

The phishing reporting rate, measured by the percentage of simulated phishing emails reported by employees using an automated reporting tool
Tracking the phishing reporting rate using an automated reporting tool measures active user behavior and practical threat detection skills during simulated campaigns. It provides empirical data on how effectively employees act as a human defense layer by identifying and escalating suspected social engineering attacks.

Adım Adım Çözüm

1
Analyze the goal of the organization
The organization needs a metric that evaluates active employee engagement and threat detection rather than passive course completion.
Effective human risk management relies on employees actively identifying and reporting suspicious activities.
2
Evaluate candidate metrics against human risk detection capabilities
Tracking the percentage of simulated phishing emails reported by users demonstrates behavioral intent and capability to defend against social engineering.
High reporting rates indicate an active defense culture where employees act as effective sensors for the security team.

Anahtar Kavram

Security Awareness Program Metrics and Reporting Behavior
Tahmini Süre:1m 15s
Soru 1875Soru

Software developers at an enterprise regularly visit a well-known third-party technical documentation website to view API specifications. A threat actor compromises this external website and injects malicious code designed to execute a drive-by download targeting visitors connecting from the enterprise's public IP block. Which of the following social engineering attack vectors is described in this scenario?

Cevabı ve açıklamayı göster

Cevap: Watering hole attack

Cevap

Watering hole attack
A watering hole attack occurs when a threat actor identifies and compromises a legitimate third-party website frequently visited by members of a targeted organization. When users visit the compromised site, malicious code silently executes to compromise their systems.

Adım Adım Çözüm

1
Analyze the target group and victim behavior in the scenario
The target group consists of enterprise software developers accessing a legitimate third-party documentation website.
Identifying the target audience and their trusted web resources clarifies the attack vector.
2
Examine the attacker's method of compromise
The attacker compromised the trusted third-party website and embedded malicious code to infect visitors from the target organization's IP address range.
Compromising a site where targets naturally congregate to deliver malware defines a watering hole strategy.
3
Match the observed technique to standard social engineering attack definitions
The technique matches a watering hole attack.
Watering hole attacks leverage implicit trust in a frequently visited third-party resource without sending direct malicious messages to the targets.

Anahtar Kavram

Watering Hole Attack
Soru 1876Soru

A regional telemedicine network is defining business continuity metrics for its real-time video consultation platform. The business impact analysis (BIA) mandates that patient interaction records must not experience more than 15 minutes of data loss, and the platform must resume full operations within 4 hours of an unplanned outage. Which of the following statements accurately align these operational targets with business continuity metrics? (Select TWO)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Establishing a Recovery Point Objective (RPO) of 15 minutes ensures that data loss does not exceed the maximum acceptable 15-minute timeframe.; Establishing a Recovery Time Objective (RTO) of 4 hours targets the maximum acceptable duration of service downtime following a disruption.

Cevap

The correct statements are that setting a Recovery Point Objective (RPO) of 15 minutes bounds maximum acceptable data loss, and setting a Recovery Time Objective (RTO) of 4 hours defines maximum allowable service downtime.
Recovery Point Objective (RPO) measures the maximum acceptable timeframe of unrecoverable data loss during an outage, matching the 15-minute consultation log target. Recovery Time Objective (RTO) measures the targeted duration required to restore operational capabilities, matching the 4-hour downtime limit.

Adım Adım Çözüm

1
Analyze data loss requirement
Maximum acceptable data loss is 15 minutes, which corresponds directly to Recovery Point Objective (RPO).
RPO dictates how far back in time data recovery points must reach.
2
Analyze downtime/restoration requirement
Maximum acceptable downtime is 4 hours, which corresponds directly to Recovery Time Objective (RTO).
RTO defines the target time required to restore the business process or system following an incident.

Anahtar Kavram

Distinguishing RTO and RPO in Business Impact Analysis
Soru 1877Soru

A corporate finance officer receives an urgent SMS message on their personal mobile phone claiming that a critical vendor invoice is past due and requiring immediate review via a provided shortened link. Upon clicking the link, the officer is directed to a login page and receives a follow-up call from an individual claiming to be a senior IT auditor. The caller uses authoritative technical terms and pressures the officer to disclose their multi-factor authentication (MFA) verification code to resolve an apparent account lock. Which of the following social engineering attack vectors and principles of influence were directly employed in this scenario? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Smishing; Pretexting

Cevap

The attack involved Smishing (using SMS to deliver a phishing link) and Pretexting (fabricating an IT auditor identity to manipulate the employee into sharing MFA credentials).
Smishing is used because the initial social engineering attack vector was delivered via text message (SMS). Pretexting is present because the attacker created a fabricated persona and scenario (a senior IT auditor resolving an account lock) to trick the target into revealing sensitive MFA credentials over the phone.

Adım Adım Çözüm

1
Analyze the initial delivery mechanism described in the scenario
The message was delivered via SMS text message requesting urgent action, which defines smishing.
Identifying the medium (SMS) categorizes the specific phishing variant.
2
Analyze the secondary voice communication and psychological tactic
The caller created a fake scenario as an authoritative IT auditor to obtain credentials, which defines pretexting.
Pretexting involves building a believable backstory and role to establish trust or convey authority to trick the target.

Anahtar Kavram

Social Engineering Attack Vectors and Influence Tactics
Tahmini Süre:1m 30s
Soru 1878Soru

An enterprise security administrator is formalizing a human risk management initiative to reduce departmental vulnerability to targeted social engineering attacks. In what order should the administrator execute the stages of this security awareness lifecycle from start to finish?

Öğeleri doğru sıraya koymak için sürükleyin

Cevabı ve açıklamayı göster

Cevap

The correct sequence begins with conducting a baseline human risk assessment, followed by developing tailored role-based training modules, delivering the targeted training to key personnel, executing unannounced simulations to measure behavioral changes, and concluding with reporting risk reduction metrics to leadership to refine governance policy.
The correct sequence follows the standard security program lifecycle: first assess baseline risks to identify vulnerable roles, second develop tailored role-based learning content, third deliver training to targeted personnel, fourth evaluate behavioral change using unannounced simulations, and fifth present outcome metrics to leadership to update overall program governance.

Adım Adım Çözüm

1
Conduct a baseline risk assessment across departments.
Identifies specific threat vectors and vulnerable job roles.
Security awareness programs must be data-driven and targeted toward actual risk profiles.
2
Develop role-based microlearning modules.
Creates targeted educational content tailored to specific job responsibilities.
Tailored training addresses unique attack surfaces more effectively than generic, one-size-fits-all awareness modules.
3
Roll out training and monitor completion metrics.
Ensures targeted personnel acquire necessary threat identification skills.
Formal training must precede practical evaluation so employees know how to recognize and report threats.
4
Launch unannounced simulated attack scenarios.
Gathers empirical data on click-through rates and threat reporting performance.
Simulations test whether educational concepts successfully translate into practical behavioral defense in real-world scenarios.
5
Aggregate metrics for executive reporting and policy refinement.
Demonstrates program effectiveness and informs ongoing security governance updates.
Continuous security program management requires leadership visibility and continuous policy alignment based on measured metrics.

Anahtar Kavram

Role-Based Security Awareness Program Lifecycle
Soru 1879Soru

An enterprise security manager is mapping organizational compliance requirements across various jurisdictions and industry domains. Match each regulatory framework or legal mandate on the left with its primary governing scope or regulatory requirement on the right.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Gramm-Leach-Bliley Act (GLBA) Safeguards Rule
Health Insurance Portability and Accountability Act (HIPAA) Security Rule
EU Network and Information Security (NIS 2) Directive
Federal Information Security Modernization Act (FISMA)

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

GLBA Safeguards Rule matches with protecting nonpublic personal information (NPI) at financial institutions; HIPAA Security Rule matches with protecting electronic protected health information (ePHI); EU NIS 2 Directive matches with cybersecurity standards for essential entities in critical infrastructure across the EU; and FISMA matches with federal agency information security program mandates.
Each regulation serves a specific domain: GLBA protects consumer financial data (NPI), HIPAA governs healthcare information (ePHI), NIS 2 enforces EU-wide critical infrastructure cybersecurity, and FISMA mandates security programs for U.S. federal government agencies.

Adım Adım Çözüm

1
Identify the primary sector and target entity type for each legal framework.
GLBA targets financial entities, HIPAA targets healthcare/covered entities, NIS 2 targets European critical infrastructure, and FISMA targets U.S. federal government agencies.
Compliance frameworks are defined primarily by jurisdiction, industry domain, and covered entity types.
2
Map data classification types and operational scopes to the corresponding regulations.
Customer NPI correlates to GLBA, ePHI correlates to HIPAA Security Rule, EU essential entity resilience correlates to NIS 2, and U.S. agency information system protection correlates to FISMA.
Matching specific regulatory data categories (NPI vs ePHI) and statutory jurisdictions ensures accurate compliance alignment.

Anahtar Kavram

Regulatory Scopes and Legal Compliance Frameworks
Soru 1880Soru

A multinational fintech company processes both Payment Card Industry Data Security Standard (PCI DSS) regulated payment card data and user personally identifiable information (PII). The security team is updating its regulatory compliance posture. Which of the following actions represent mandatory compliance practices for managing these regulatory requirements? (Select TWO).

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Segmenting the network to isolate the Cardholder Data Environment (CDE) from systems that process general enterprise PII; Rendering primary account numbers (PAN) unreadable anywhere they are stored using strong cryptographic algorithms and proper key management

Cevap

The correct practices are isolating the Cardholder Data Environment (CDE) through network segmentation to limit audit scope, and rendering stored primary account numbers (PAN) unreadable using strong cryptography and key management.
Isolating the Cardholder Data Environment (CDE) via network segmentation reduces the audit boundary, and cryptographically protecting primary account numbers (PAN) ensures compliance with PCI DSS data protection rules.

Adım Adım Çözüm

1
Analyze PCI DSS scope reduction strategies
Network segmentation isolates cardholder data processing systems, reducing the overall audit and compliance boundary.
Without segmentation, the entire enterprise network falls under PCI DSS compliance scope.
2
Evaluate data protection controls for cardholder data storage
Primary account numbers (PAN) must be protected using strong encryption, truncation, or tokenization.
PCI DSS mandates cryptographic protection for PAN to prevent unauthorized exposure.
3
Evaluate cloud governance and liability limitations
Cloud service agreements cannot transfer legal compliance obligations away from the data controller or organization.
The shared responsibility model assigns data governance and regulatory compliance responsibilities to the customer.

Anahtar Kavram

PCI DSS Compliance and Scope Management
ÖncekiSayfa 94 / 112Sonraki
Tüm alıştırma soruları — CompTIA Security+ | Examkin