Tüm alıştırma soruları
2232 soru
Match each regulatory compliance framework or legal mandate on the left with its primary governing scope or regulatory requirement on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An enterprise security analyst is investigating an incident where several finance department employees received unexpected phone calls from an individual claiming to be a senior IT support engineer. The caller stated that an emergency payroll system update required immediate phone-based password confirmation to avoid halting monthly salary disbursements. Which TWO of the following social engineering attack vectors or principles of influence were directly utilized in this scenario?
Geçerli olan tümünü seçin
A network intrusion detection system (NIDS) generates an alert showing unexpected SMB connection attempts originating from an internal workstation (192.168.10.45) directed toward an unassigned internal IP address (10.0.99.50) hosting a decoy server. Security policy dictates that no operational systems should ever communicate with this target address. Which of the following conclusions correctly interprets this network security monitoring alert?
An enterprise security team is defining fundamental data governance and privacy requirements for a new corporate application. Match each data governance concept on the left with its corresponding operational description on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An organization's security metrics reveal that high-risk departments, such as finance and human resources, continue to exhibit elevated click-through rates on sophisticated spear-phishing simulations despite completing the mandatory annual security awareness course. The CISO wants to update the awareness program to effectively reduce human risk in these departments while maintaining a supportive security culture. Which of the following strategies is the most effective approach to achieve this objective?
A security architect is deploying TLS certificates for three newly established internal microservices hosted on distinct domain structures: identity.corp.local, billing.corp.internal, and api.corp.com. To simplify management, the architect intends to issue a single digital certificate that will be trusted and valid across all three different fully qualified domain names. Which of the following configuration options should the security architect specify during certificate generation to achieve this goal?
A Security Operations Center (SOC) analyst receives a high-priority alert from a Network Intrusion Detection System (NIDS) indicating anomalous outbound TCP traffic on port 443 with a mismatched Server Name Indication (SNI) header. In what order should the analyst execute the following triage and response steps to effectively investigate and mitigate the network threat?
Öğeleri doğru sıraya koymak için sürükleyin
A corporate employee receives a customized USB flash drive in the mail labeled 'Confidential: Executive Salary Adjustments Q3' that appears to originate from the human resources department. Driven by curiosity, the employee connects the drive to a company workstation, which immediately triggers malicious code execution. Which social engineering attack vector did the attacker utilize in this scenario?
A financial institution is performing a quantitative risk assessment on its central Hardware Security Module (HSM) cluster used for payment cryptographic operations. The HSM cluster has an estimated Asset Value () of . A risk analysis team determines that a major key exposure incident would have an Exposure Factor () of . Threat intelligence models project an Annualized Rate of Occurrence () of for such an incident. What is the calculated Annualized Loss Expectancy () in US dollars for the HSM cluster?
A financial technology company operating a cloud-native microservices platform requires all container host nodes processing sensitive transaction data to comply with a specific, mandatory set of minimum technical security settings, such as disabling root SSH logins and enabling kernel audit logging. Which of the following governance documents should the security architecture team publish to define these mandatory, platform-specific minimum configuration settings?
Following an incident where an attacker successfully impersonated an IT helpdesk technician over the phone to reset employee passwords, a security team is enhancing its human risk management program. The team seeks to implement targeted administrative controls and specialized training to prevent similar credential compromise incidents. Which of the following strategies represent appropriate human risk mitigation controls for this scenario? (Select TWO.)
Geçerli olan tümünü seçin
Match each social engineering attack vector or technique on the left with the enterprise incident scenario on the right that best demonstrates its execution.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An enterprise security analyst is performing a quantitative risk assessment on an internal source code repository server housing proprietary intellectual property. The repository server has an estimated Asset Value () of . Threat intelligence reports indicate that a major security breach would result in an Exposure Factor () of (). Based on historical incident data, such an exposure event is expected to occur once every two and a half years, establishing an Annual Rate of Occurrence () of . What is the Annual Loss Expectancy () for this repository server?
Following an evaluation of an enterprise security awareness program, a security analyst notes that while annual training completion rates reach 98%, employees rarely notify the security team when encountering suspicious messages. To improve human risk detection, the organization wants to establish a key performance indicator (KPI) that specifically measures proactive employee engagement in threat detection during phishing simulations. Which of the following metrics best evaluates this proactive reporting behavior?
Software developers at an enterprise regularly visit a well-known third-party technical documentation website to view API specifications. A threat actor compromises this external website and injects malicious code designed to execute a drive-by download targeting visitors connecting from the enterprise's public IP block. Which of the following social engineering attack vectors is described in this scenario?
A regional telemedicine network is defining business continuity metrics for its real-time video consultation platform. The business impact analysis (BIA) mandates that patient interaction records must not experience more than 15 minutes of data loss, and the platform must resume full operations within 4 hours of an unplanned outage. Which of the following statements accurately align these operational targets with business continuity metrics? (Select TWO)
Geçerli olan tümünü seçin
A corporate finance officer receives an urgent SMS message on their personal mobile phone claiming that a critical vendor invoice is past due and requiring immediate review via a provided shortened link. Upon clicking the link, the officer is directed to a login page and receives a follow-up call from an individual claiming to be a senior IT auditor. The caller uses authoritative technical terms and pressures the officer to disclose their multi-factor authentication (MFA) verification code to resolve an apparent account lock. Which of the following social engineering attack vectors and principles of influence were directly employed in this scenario? (Select TWO.)
Geçerli olan tümünü seçin
An enterprise security administrator is formalizing a human risk management initiative to reduce departmental vulnerability to targeted social engineering attacks. In what order should the administrator execute the stages of this security awareness lifecycle from start to finish?
Öğeleri doğru sıraya koymak için sürükleyin
An enterprise security manager is mapping organizational compliance requirements across various jurisdictions and industry domains. Match each regulatory framework or legal mandate on the left with its primary governing scope or regulatory requirement on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A multinational fintech company processes both Payment Card Industry Data Security Standard (PCI DSS) regulated payment card data and user personally identifiable information (PII). The security team is updating its regulatory compliance posture. Which of the following actions represent mandatory compliance practices for managing these regulatory requirements? (Select TWO).
Geçerli olan tümünü seçin