General Security Concepts
268 soru
A corporate employee working remotely authenticates successfully at the start of their shift using multi-factor authentication (MFA) from a compliant corporate laptop. Mid-day, a local policy check detects that the endpoint antivirus service was forcibly stopped and an unauthorized storage device was attached. Under Zero Trust Architecture (ZTA) principles, how should the access control system respond to this change in device posture?
An enterprise security administrator is auditing network infrastructure logs to verify full implementation of the Authentication, Authorization, and Accounting (AAA) framework. Which of the following technical controls directly perform Accounting functions? (Select TWO).
Geçerli olan tümünü seçin
Match each organizational security measure to its corresponding functional control type according to CompTIA Security+ standards.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A security technician needs to verify that a downloaded software installation package has not been modified or corrupted during transit. Which of the following cryptographic mechanisms should the technician use to check the file's integrity?
A security architect is auditing the access management architecture of a microservices-based enterprise platform. The platform relies on a central Identity Provider (IdP), an API Gateway, fine-grained access policies, and a SIEM system. Which of the following technical mechanisms specifically fulfill the Authorization pillar of the AAA framework? (Select TWO.)
Geçerli olan tümünü seçin
An enterprise financial institution relies on a legacy mainframe system to process batch payments. A security compliance audit reveals that the mainframe application cannot natively support TLS 1.3 network transport encryption due to legacy protocol stack limitations. To satisfy data-in-transit security requirements without taking the system offline, the security engineering team deploys an inline hardware cryptographic proxy that intercepts outbound mainframe communications and encapsulates them inside an encrypted IPsec tunnel across the internal network. Which of the following best classifies the deployment of the hardware cryptographic proxy?
A security team deploys automated log parsing software that continuously analyzes server event logs to identify and flag unauthorized login attempts as they occur. Which functional control type is best demonstrated by this measure?
Match each cryptographic mechanism to its primary operational security objective.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A DevOps security architect is establishing an automated firmware distribution pipeline for remote edge devices operating on untrusted networks. The security baseline mandates a mechanism that guarantees payload data integrity, authenticates the vendor build system as the source, and provides non-repudiation so the authoring system cannot deny issuing a specific release. Which of the following cryptographic controls should the architect implement?
An enterprise security architect is standardizing cryptographic controls across a zero-trust network infrastructure. Match each security design requirement on the left with the most appropriate cryptographic mechanism or algorithm on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A security engineer is configuring cryptographic primitives for a high-throughput financial microservice architecture. The system must establish session keys over untrusted networks ensuring Perfect Forward Secrecy (PFS), while also supporting high-speed authenticated bulk data encryption for payload storage. Which of the following cryptographic mechanisms should the engineer implement to satisfy BOTH requirements? (Select TWO.)
Geçerli olan tümünü seçin
An enterprise security architecture team discovers that a legacy mainframe application processing sensitive financial transactions cannot support native transport layer encryption due to application stack limitations. To mitigate the risk of unauthorized data exposure across internal network segments without modifying legacy software, the team deploys an encrypted IPSec tunnel overlay between dedicated network gateway appliances. Which of the following best classifies both the control category and the functional control type of this IPSec tunnel implementation?
A security administrator is evaluating enterprise security controls to classify them by control category. Which of the following security measures are classified as technical controls? (Select TWO.)
Geçerli olan tümünü seçin
A security administrator is configuring disk-level encryption for an enterprise storage network containing high-volume database files. The encryption solution must provide data confidentiality for bulk data while maintaining fast processing speeds and low performance overhead. Which of the following cryptographic approaches is best suited for this task?
An enterprise security administrator is deploying a high-volume public web service that requires TLS mutual authentication (mTLS) for client devices and automated certificate lifecycle management. The administrator must ensure that client certificate status checks are optimized for minimal latency without exposing the internal Certificate Authority (CA) to external query floods, while also establishing an automated, secure enrollment mechanism for enterprise endpoint certificates. Which of the following technical controls and configurations should the administrator implement to satisfy these requirements? (Select TWO.)
Geçerli olan tümünü seçin
An organization is evaluating its security architecture following a comprehensive risk assessment. Match each enterprise security measure to its correct dual-axis classification (Category and Functional Type) according to CompTIA Security+ standards.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An organization is modernizing its security controls by adopting Zero Trust Architecture (ZTA) principles across its enterprise environment. Match each core Zero Trust principle on the left with its corresponding operational description on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A network administrator is setting up a new secure web server and needs to obtain an X.509 digital certificate from an enterprise Certificate Authority (CA). Which of the following actions should the administrator perform first on the server?
A software development team is building an automated third-party API webhook receiver to process incoming transaction status updates. The security specification requires that the receiver must verify both the data integrity and origin authenticity of each incoming payload using a shared secret key, while avoiding the processing overhead associated with public key cryptography. Which cryptographic mechanism should the team implement to meet these requirements?
A senior security architect is updating an enterprise security standard to enforce modern cryptographic controls across cloud, archive, hardware, and transport systems. Match each operational cryptographic requirement on the left to the corresponding technical concept or mechanism on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler