General Security Concepts
268 soru
A cybersecurity team is deploying deception and disruption technologies within a cloud-native software development environment to detect early-stage credential access and lateral movement. Which of the following components and operational practices should the security team implement to achieve high-fidelity alerting without interfering with legitimate production workflows? (Select TWO.)
Geçerli olan tümünü seçin
An organization requires department managers to perform quarterly user access reviews by manually evaluating account permissions and verifying that assigned rights match current job responsibilities. Which of the following best classifies both the security control category and functional type of this process?
A systems administrator is configuring a newly deployed internal web portal to serve traffic over HTTPS using a certificate issued by the organization's Enterprise Certificate Authority (CA). Place the administrative steps in the correct chronological order required to successfully enroll and enable the TLS certificate on the web portal.
Öğeleri doğru sıraya koymak için sürükleyin
An enterprise network security team deploys a centralized RADIUS architecture to manage access to infrastructure devices. During a post-implementation audit, a security analyst notes the following behavior: when network administrators log in, the system successfully validates their multi-factor credentials. However, upon login, all authenticated administrators are granted identical, unrestricted administrative permissions across all switches and firewalls, regardless of their specific role or group membership in the directory service. Meanwhile, session start/end timestamps and data transfer metrics are accurately recorded in central logs. Which component of the AAA framework failed to be properly configured to restrict administrative privileges?
A network engineer notices that users connecting to the enterprise Wi-Fi are successfully validating their domain credentials against a centralized RADIUS server. However, after successful login, all users—including system administrators—are placed into a restricted guest VLAN instead of being assigned their appropriate department VLANs. Which aspect of the AAA framework is failing to execute correctly in this scenario?
An automated algorithmic trading platform logs high-frequency order requests to an external compliance vault. Following a significant financial anomaly, a senior trader asserts that a series of unauthorized trades attributed to their user account were forged by a malicious internal microservice rather than initiated from their terminal. To resolve the dispute, the security audit team must provide irrefutable proof of the trader's authorship as well as guarantee that the order data was not tampered with after creation. Which of the following security mechanisms best fulfills these requirements?
A network administrator configures a centralized syslog server to record user login timestamps, executed command histories, and session resource usage for auditing compliance. Which core component of the AAA framework is being implemented?
A network security administrator is evaluating access control mechanisms following an audit of an enterprise infrastructure. The current deployment utilizes RADIUS for network access control and TACACS+ for network device management. During the audit, management observed that while remote administrative login attempts are logged, the security team cannot verify which specific commands were executed by individual engineers on edge routers during maintenance sessions. Additionally, permission checks fail to evaluate individual command authorizations dynamically. Which TWO of the following architectural distinctions or protocol changes should the administrator implement to resolve these issues? (Select TWO.)
Geçerli olan tümünü seçin
A security analyst is investigating an incident where an attacker compromised a low-privileged service account's API key. The API gateway successfully verified the key's digital signature and validated the identity of the service account. However, due to a missing role-mapping rule on the API gateway, the request was granted access to an internal database management endpoint intended exclusively for domain administrators. Additionally, because the gateway was configured to log only initial connection handshakes rather than detailed endpoint requests, security teams cannot determine which database commands were executed. Which of the following correctly identifies the AAA pillar that failed to restrict endpoint access, and the AAA pillar whose configuration deficiency prevents auditing the executed actions?
A security operations team is deploying internal code-signing certificates generated through an enterprise two-tier PKI consisting of an offline root Certificate Authority (CA) and an online intermediate issuing CA. Developers submit Certificate Signing Requests (CSRs) for binary signing. During testing on isolated target systems that already have the offline root CA certificate installed in their trusted root store, verification fails because the operating system cannot build the certification path to validate the signature. Further inspection reveals that the intermediate CA certificate was neither bundled with the signature nor pre-installed on the target machines. Which of the following is the most appropriate action to resolve this certificate chain validation failure?
An organization is categorizing its security controls based on CompTIA Security+ implementation categories (Technical, Managerial, Operational, Physical) and functional types (Preventive, Deterrent, Detective, Corrective, Compensating, Directive). Match each implemented security control on the left with its correct dual-classification on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A network administrator is establishing PKI certificate management processes and automated revocation checks for a cluster of internal web applications. To ensure optimal security during certificate issuance and minimize handshake latency during revocation checking, which of the following implementation steps should the administrator select? (Select TWO).
Geçerli olan tümünü seçin
Match each core Zero Trust Architecture (ZTA) control plane component with its primary operational responsibility in accordance with NIST SP 800-207 standards.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A security operations team wants to identify unauthorized credential harvesting and post-exploitation lateral movement within a hybrid cloud enterprise network. To achieve this without altering production network routing or risking asset compromise, the team injects synthetic cloud API keys and decoy Kerberos ticket-granting service (TGS) requests into the LSASS memory space of critical endpoints. When an attacker attempts to extract these fake credentials and present them to a decoy authentication service, an alert is triggered immediately. Which of the following deception and disruption technologies did the organization deploy?
A systems administrator is configuring a secure remote management channel for server administration over an untrusted network. The security policy mandates perfect forward secrecy so that compromising the server's long-term private key in the future will not allow an attacker to decrypt previously recorded session traffic. Which cryptographic key exchange mechanism should the administrator implement to satisfy this requirement?
A security technician is troubleshooting a user access issue on a corporate document platform. The user successfully validates their password and multi-factor authentication prompt at login. However, when attempting to open shared department folders, the platform denies access with a 'Privilege Insufficient' error. System logs confirm that the identity provider successfully verified who the user is, but failed to evaluate or grant access permissions to the requested resources. Which component of the AAA framework is failing to execute as intended?
An organization plans to deprecate legacy cryptographic protocols across all internal application gateways during a scheduled maintenance window. Following the change execution, several mission-critical legacy internal applications lose connection to the centralized authentication service, causing widespread business disruption. Investigation reveals that while the protocol deprecation was approved by the Change Advisory Board (CAB), the technical change request did not evaluate application-level dependency on legacy protocol suites. Which of the following change management practices was omitted prior to submission?
A cloud-native software provider operates a microservices workload where internal APIs communicate across multiple environments. A threat actor successfully steals active bearer tokens from a developer workstation located on the internal office LAN. When the attacker uses these stolen tokens to invoke downstream financial data microservices from inside the corporate network, access is denied due to an anomalous device posture score and unverified request velocity. Which core Zero Trust Architecture principle directly prevented this lateral movement despite the presentation of valid authentication credentials from an internal source?
Match each Zero Trust Architecture (ZTA) logical component defined in NIST SP 800-207 to its primary operational responsibility.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An enterprise DevOps team implements a security policy requiring all software developers to digitally sign Git commits using their individual GPG private keys prior to merging code into the production repository. The central repository server automatically validates each signature against the developer's registered public key. Which of the following security objectives are directly achieved by enforcing this digital signature mechanism? (Select TWO.)
Geçerli olan tümünü seçin