Tüm alıştırma soruları
2232 soru
An enterprise cloud engineering team is establishing baseline security controls for a newly migrated production environment. Match each technical implementation on the left with the primary security pillar or objective it satisfies on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A security analyst configures an automated reporting tool to sign all generated financial reports using an asymmetric private key. Which of the following core security objectives are directly provided by using digital signatures in this scenario? (Select TWO.)
Geçerli olan tümünü seçin
A security analyst deploys an intentionally vulnerable decoy server on an isolated network segment. The server contains simulated sensitive files and fake credentials designed to attract threat actors, observe their tactics, and generate alerts upon any interaction. Which of the following deception technologies has the analyst implemented?
A healthcare provider is deploying a tele-radiology platform where remote radiologists submit diagnostic reports to hospital electronic health record (EHR) systems. Security policy dictates that the platform must guarantee two key objectives: (1) hospitals must be able to prove which specific radiologist authored a report such that the radiologist cannot later claim they did not send it, and (2) any alteration to report contents during transit or storage must be immediately detectable. Which of the following technical controls must be implemented to fulfill these security requirements? (Select TWO.)
Geçerli olan tümünü seçin
A security architect is establishing control and data plane boundaries for a microsegmented enterprise network undergoing transition to a Zero Trust Architecture (ZTA). Match each logical Zero Trust component with its corresponding operational role during access evaluations.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A security analyst is reviewing access policies during an initiative to adopt a Zero Trust Architecture (ZTA). The analyst needs to ensure that access decisions are never granted solely based on a device's physical or network location. Which core Zero Trust principle directly addresses this requirement?
An enterprise security manager needs to ensure that high-priority system change requests sent via email cannot be denied by the author after submission. Which of the following security concepts specifically addresses this requirement?
Match each deception technology term on the left with its corresponding operational description on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An organization is migrating its customer relationship management operations to a Software as a Service (SaaS) cloud solution. Under the cloud shared responsibility model, which of the following tasks remains the primary responsibility of the organization?
A network administrator conducts a vulnerability assessment on a critical server and discovers that an unencrypted legacy service, Telnet (TCP port 23), is enabled for remote administrative access across the internal network. Which of the following primary vulnerabilities does this host configuration introduce?
A security systems administrator analyzes a performance anomaly on an enterprise administrative jump host. System telemetry reveals an unverified process running from `C:\ProgramData\VendorApp\Temp\` that attaches hooks to Windows messaging queues via `SetWindowsHookEx`. Process analysis indicates that the application quietly records active window titles and raw keyboard entry sequences into an encrypted local buffer before exfiltrating the collected logs to a remote server over port 443. The host shows no evidence of automated network scanning, lateral propagation, or unauthorized driver installation. Which of the following malware types has infected the jump host?
A global logistics organization migrates its freight tracking platform to a cloud provider's managed container orchestration service (PaaS). Under the contract, the cloud service provider maintains the physical host infrastructure, hypervisor layer, and control plane nodes. To maintain regulatory compliance, the organization's security architect must establish the operational control boundaries for the deployment. Which of the following security responsibilities rests exclusively with the organization in this managed cloud model?
During a physical security assessment of an organization's remote branch offices, security auditors discover that unauthorized individuals could gain brief physical access to server hardware hosting edge compute workloads. The audit highlights a critical risk: an attacker with local physical access could reboot the system, modify kernel boot parameters, and force the operating system to load compromised drivers that disable host security software prior to OS initialization. Which of the following enterprise hardening strategies is the MOST effective technical mitigation to prevent this unauthorized pre-boot tampering?
An organization wants to analyze its newly deployed cloud microservices for runtime security flaws and improper error handling under live execution conditions. The assessment team has been provided with API specifications and functional documentation, but does not have access to the underlying application source code. Which security testing method should the organization perform to satisfy this requirement?
An enterprise financial organization is redesigning its network architecture for a cloud-hosted payment gateway platform. While perimeter Next-Generation Firewalls (NGFW) currently inspect all North-South ingress traffic from external clients, recent audit logs revealed that compromised web application nodes in the public presentation subnet attempted unauthorized lateral movement (East-West traffic) to internal database clusters within the same virtual private network. The security team requires a design that enforces granular, application-centric access controls between internal workloads without requiring major subnet re-addressing or causing latency bottlenecks associated with hairpinning internal traffic through a central hardware appliance. Which of the following architectural strategies best satisfies these requirements?
A system administrator needs to configure a mission-critical web server to ensure continuous operation even if a single network interface card (NIC) or power circuit fails. Which of the following hardware resilience controls should the administrator implement to eliminate these specific single points of failure? (Select TWO.)
Geçerli olan tümünü seçin
A digital media broadcasting corporation stores petabytes of high-definition video archives within an enterprise object storage platform. To fulfill compliance mandates from content licensors, the security team must implement a data protection solution that enforces hardware-rooted key protection, strict audit logging of key access requests, and annual key rotation. Crucially, the key rotation process must not require re-encrypting the underlying multi-terabyte static data objects. Which of the following storage security architectures best meets these combined requirements?
An application security analyst is evaluating a custom backend Java service that receives serialized object payloads over an unauthenticated network socket to restore user session state. Code review reveals that the application reinstantiates these binary payloads directly into memory without performing type verification or input validation. Which of the following security risks and mitigation strategies correctly apply to this scenario? (Select TWO.)
Geçerli olan tümünü seçin
A Security Operations Center (SOC) analyst receives a high-severity SIEM alert and extracts the following raw Active Directory Kerberos ticket request log entry from a central domain controller:
text
Event ID: 4769
Status: 0x0
TargetUserName: [email protected]
Service Name: MSSQLSvc/sql-prod01.finance.local:1433
Service ID: S-1-5-21-3829102-1204918-948102-5102
Ticket Options: 0x40810000
Ticket Encryption Type: 0x17
Client Address: ::ffff:10.12.84.45
Client Port: 53218
Based on the log snippet provided, which threat activity is occurring, and how should the SIEM correlation rule be configured to detect future instances of this attack while minimizing false positives?
An enterprise financial services organization is redesigning its hybrid cloud infrastructure to transition from a legacy perimeter security model to a Zero Trust Architecture (ZTA). The security architecture team must define mandatory implementation standards that adhere strictly to NIST SP 800-207 Zero Trust tenets. Which of the following architectural requirements must be enforced to align with Zero Trust principles? (Select TWO.)
Geçerli olan tümünü seçin