General Security Concepts
268 soru
During a post-incident review at a logistics company, security analysts discovered that an administrator modified system event logs and disputed making any changes. The logging infrastructure maintained file integrity using standalone SHA-256 hashes stored alongside the logs, but because multiple staff members had write permissions to update those hash files, individual accountability could not be established. Which of the following solutions should the organization implement to achieve non-repudiation for log updates?
An enterprise security engineer is auditing the AAA implementation of a newly deployed hybrid cloud access portal. The engineer needs to ensure that access governance controls are strictly categorized according to core AAA principles. Which of the following technical controls specifically perform the Authorization function within this framework? (Select TWO).
Geçerli olan tümünü seçin
A systems analyst is selecting an encryption method to protect large volumes of static data archived on enterprise storage arrays. The primary requirement is high-speed performance and minimal processing overhead during bulk encryption and decryption operations. Which of the following cryptographic approaches should the analyst implement?
Match each network access control scenario on the left with the corresponding pillar of the Authentication, Authorization, and Accounting (AAA) framework (or Identification) on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A healthcare organization is replacing its legacy virtual private network (VPN) infrastructure with a Zero Trust Architecture (ZTA) to secure access to electronic health record (EHR) microservices hosted across hybrid cloud environments. Which of the following design decisions directly reflect core Zero Trust Architecture principles? (Select THREE.)
Geçerli olan tümünü seçin
An enterprise organization is establishing a micro-segmented hybrid environment based on Zero Trust Architecture (ZTA) control plane and data plane principles. Match each logical Zero Trust component on the left with its correct operational responsibility on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
Match each cryptographic concept or algorithm on the left with its corresponding operational security objective on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
Match each enterprise AAA protocol mechanism or access control payload on the left with its corresponding functional role and operational process on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A security engineer needs to ensure that software updates distributed to client workstations cannot be denied by the vendor and that their authenticity and integrity can be verified upon download. Which of the following cryptographic techniques directly provides non-repudiation?
A network administrator is reviewing access management logs on a remote access VPN gateway. The logs indicate that after a user successfully presents a valid username, password, and time-based one-time password (TOTP), the gateway queries an LDAP directory to check the user's assigned group memberships and determine which specific internal subnets the user is permitted to reach. Which pillar of the AAA framework is being executed during this group membership evaluation?
An organization installs highly visible warning signs along the perimeter fence of a secure facility stating that trespassers will be prosecuted. Which of the following security control types is best demonstrated by this measure?
An aerospace engineering firm hosts sensitive CAD schematics on an internal server. Previously, any workstation connected to the internal corporate LAN was implicitly trusted and allowed access to the repository after a single initial morning domain login. To align this environment with Zero Trust Architecture (ZTA) principles, which strategy should the security team implement?
A security infrastructure team is establishing proactive defense capabilities across an enterprise environment. Match each disruption or deception technology on the left with the scenario that best illustrates its primary operational objective on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
Match each operational enterprise security scenario on the left with the corresponding Authentication, Authorization, or Accounting (AAA) functional mechanism on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A financial services firm is modernizing its security architecture by transitioning from a traditional boundary defense model to a Zero Trust Architecture (ZTA). The security engineering team is defining foundational policy controls for both cloud workloads and remote workforce access. Which of the following architectural practices directly implement core Zero Trust Architecture principles? (Select THREE)
Geçerli olan tümünü seçin
A security architect is implementing NIST SP 800-207 Zero Trust Architecture (ZTA) logical components within an enterprise hybrid network. Match each Zero Trust logical component on the left with its correct operational responsibility on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A system administrator needs to update an operational system to resolve a software vulnerability. Which of the following actions should the administrator take FIRST as part of the formal change management process to evaluate potential security impacts?
A lead security analyst is reviewing the cryptographic design for an enterprise file storage service. The system must encrypt multi-gigabyte data archives efficiently while ensuring data confidentiality, integrity, and origin authenticity. The engineering team proposes encrypting each entire backup file directly using RSA-4096 asymmetric encryption to achieve confidentiality and non-repudiation in a single operation. Which of the following architectural modifications should the security analyst require to meet both performance and security objectives?
A security operations team configures an isolated network segment containing multiple fully functional decoy servers and simulated industrial control system (ICS) devices. The environment allows attackers to execute commands, run scripts, and interact extensively with system operating systems so analysts can capture advanced tactics, techniques, and procedures (TTPs). Which of the following deception technologies has been implemented?
A network administrator is configuring a secure transport session to protect financial telemetry transmitted across an untrusted enterprise network. The session configuration requires high-speed symmetric data confidentiality as well as a key exchange mechanism that guarantees Perfect Forward Secrecy (PFS). Which TWO of the following cryptographic mechanisms should the administrator select to meet these requirements?
Geçerli olan tümünü seçin