Tüm alıştırma soruları
2232 soru
Following an industry-wide software supply chain incident, an enterprise incident response director wants to enable real-time ingestion of machine-readable indicators of compromise from trusted peer organizations. The technical requirements specify establishing automated client-server polling over encrypted HTTPS connections to retrieve structured threat feeds directly into defensive gateway controls. Which standard provides the transport mechanism required to support this automated intelligence exchange?
A security analyst is reviewing audit findings for a Linux-based public web server operating within an enterprise DMZ. The audit report highlights that the web server daemon process currently runs under the root superuser account, exposing the entire host operating system to complete takeover if an application-level remote code execution vulnerability is exploited. Which of the following mitigation strategies represents the MOST effective host hardening control to resolve this security risk?
An autonomous vehicle research firm stores large volumes of sensor telemetry and machine learning datasets on distributed block storage arrays. The security team needs to protect data at rest against physical drive theft from the data center while minimizing processor performance impact on host hypervisors. Which of the following storage security controls best satisfies this requirement?
Match each Identity and Access Management (IAM) architectural protocol component to its corresponding enterprise security implementation requirement.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An incident responder acquires a forensic bit-stream image of a compromised server's storage drive. To demonstrate in court that the collected evidence image remains untampered and identical to the original drive at the time of capture, which of the following actions should the responder perform?
An enterprise security architect is updating host and network hardening standards across the organization to address findings from a recent security assessment. Match each enterprise security risk scenario on the left with the most effective enterprise hardening mitigation on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A security engineer is documenting the automated failover process for an active-passive cluster of perimeter firewalls. When the primary node experiences an unrecoverable hardware failure, specific high-availability failover events must occur. Place the following operational steps in the correct chronological order from first to last.
Öğeleri doğru sıraya koymak için sürükleyin
A security analyst discovers that a workstation on the corporate network is actively communicating with a known malicious command-and-control server following a phishing incident. Which of the following actions should the analyst perform as part of the containment phase? (Select TWO).
Geçerli olan tümünü seçin
A systems administrator needs to assess internal enterprise servers for missing operating system patches and local security misconfigurations. To obtain accurate, detailed host inspection results while minimizing false positives and network noise, the administrator must avoid attempting any actual system exploitation. Which of the following scanning approaches best satisfies these requirements?
A Security Operations Center (SOC) analyst detects lateral movement across several workstation subnets. Further analysis reveals that an attacker is using compromised domain administrator credentials to remotely execute malicious scripts and establish persistent connections. The organization initiates its incident response playbook and moves into the containment phase. Which TWO of the following immediate actions should the incident response team execute during this phase?
Geçerli olan tümünü seçin
A Security Operations Center (SOC) analyst receives a high-severity Network Intrusion Prevention System (NIPS) alert indicating potential unauthorized data exfiltration from a core database host to an external IP address. Place the incident response steps in the correct operational sequence, starting from initial alert validation through threat intelligence integration.
Öğeleri doğru sıraya koymak için sürükleyin
An organization is migrating its enterprise authentication framework to a modern cloud Identity Provider (IdP) supporting OpenID Connect (OIDC). However, several legacy internal web applications only support HTTP header-based authentication and cannot natively process OIDC tokens. Which of the following architectural components should be deployed between the legacy applications and the cloud IdP to translate federated identity assertions into secure local application headers?
An enterprise security platform detects an exposed cloud service API key in a public code repository. Arrange the steps of an automated Security Orchestration, Automation, and Response (SOAR) playbook into the correct operational sequence from initial alert detection to incident ticket resolution.
Öğeleri doğru sıraya koymak için sürükleyin
During a incident response simulation, an automated Security Orchestration, Automation, and Response (SOAR) playbook triggered by a high-fidelity alert executed a host isolation script against a primary Domain Controller, causing an enterprise-wide network outage. Which modification to the playbook workflow best mitigates the operational risk to critical infrastructure while preserving automated response speed for standard endpoints?
During a routine vulnerability audit, a security analyst discovers that multiple cloud virtual machines provisioned via Infrastructure as Code (IaC) templates are running outdated OS software packages vulnerable to remote code execution. Manually logging into each running instance to apply software patches resolves the vulnerability temporarily, but subsequent automated orchestration runs overwrite the manual patches, reverting systems to the vulnerable state. Which of the following operational procedures should the analyst implement to permanently remediate the vulnerability without introducing configuration drift?
A Security Operations Center (SOC) team is designing an automated Security Orchestration, Automation, and Response (SOAR) playbook to handle high-fidelity ransomware alerts from Endpoint Detection and Response (EDR) agents. To prevent widespread encryption, the playbook is intended to isolate infected hosts immediately. However, leadership is concerned that automated isolation of critical domain controllers or database servers could cause severe business disruption. Which design modification should the SOC team implement in the SOAR playbook to balance rapid response with operational safety?
An enterprise security team is reviewing options for managing identified operational risks within their IT infrastructure. Which of the following represent recognized risk response strategies? (Select TWO.)
Geçerli olan tümünü seçin
A financial enterprise is conducting a quantitative risk assessment on an internal database cluster. The asset value () of the database cluster is estimated at . Threat intelligence estimates that a single ransomware incident would result in an exposure factor () of (). Historical occurrence data indicates that such an incident is likely to occur once every four years, giving an annual rate of occurrence () of . Which of the following is the estimated Annual Loss Expectancy () for this asset?
An enterprise organization is evaluating a cloud service provider during initial procurement screening. The organization requires verification that the provider's security controls operate effectively over a continuous period. However, the provider refuses to share confidential architectural blueprints or detailed technical test procedures prior to contract execution. Which of the following audit reports should the provider furnish to satisfy this request?
A company is finalizing a contract with a third-party software provider. To ensure operational reliability, the company wants clear metrics specifying system uptime guarantees and incident resolution response windows. Which type of document is specifically designed to enforce these technical performance standards?