General Security Concepts
268 soru
During an enterprise infrastructure hardening project, a security architect is tasked with selecting controls that are classified as technical controls and function specifically in a preventive capacity. Which of the following security measures meet both of these criteria? (Select TWO.)
Geçerli olan tümünü seçin
An enterprise cloud engineering team is migrating a legacy microservices architecture to align with NIST SP 800-207 Zero Trust Architecture (ZTA) principles. The modern architecture spans hybrid cloud environments and supports both remote and on-premise users. Which of the following technical design choices directly reflect core Zero Trust Architecture principles? (Select THREE)
Geçerli olan tümünü seçin
A security operations team wants to detect unauthorized lateral movement and Kerberoasting attacks within their Active Directory domain without modifying host configurations or deploying dedicated virtual servers. The team creates a fake domain account configured with a Service Principal Name (SPN) and monitors domain controller logs for any Ticket Granting Service (TGS) request targeting this account. Which of the following deception technologies has the team deployed?
A security administrator is reviewing identity management definitions for new security operations team members. Match each access control phase of the AAA framework on the left with its corresponding operational security scenario on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
Following a compliance audit, an enterprise security team identifies that a legacy industrial control server hosting critical operational technology cannot support endpoint detection and response (EDR) agents or full-disk encryption due to system resource constraints. To satisfy the security standard without taking the legacy system offline, the team installs a dedicated inline micro-segmentation appliance with access control lists restricted strictly to authorized jump boxes. Which of the following best classifies the security control category and functional type of this newly deployed appliance?
An enterprise security team plans to modify central authentication controls to enforce hardware-based multi-factor authentication across production subnets. To ensure operational continuity and minimize security risks, the team must follow the organization's formal change management process. Place the following change management steps in the correct chronological order from first to last.
Öğeleri doğru sıraya koymak için sürükleyin
A system administrator is preparing to obtain a new TLS certificate for an internal server from the enterprise Certificate Authority (CA). Which of the following tasks must be completed on the server during the initial certificate request workflow? (Select TWO.)
Geçerli olan tümünü seçin
A security analyst is hardening an internal web application's authentication module. An audit reveals two major vulnerabilities: session identifiers are predictable due to weak random seed generation, and user passwords stored in the database are susceptible to rapid offline dictionary and GPU-accelerated rainbow table attacks. Which of the following cryptographic techniques should the security analyst implement to mitigate both vulnerabilities? (Select TWO.)
Geçerli olan tümünü seçin
An organization's infrastructure team plans to enable HTTP/3 (QUIC) across all enterprise edge load balancers to reduce web application latency. Because HTTP/3 utilizes UDP port 443 instead of traditional TCP port 443, the team must perform a security impact analysis before presenting the proposal to the Change Advisory Board (CAB). Which of the following represents the primary security impact that must be evaluated during this change management step?
An enterprise network administrator is configuring centralized access management for core network hardware using a TACACS+ server. To align with the Authentication, Authorization, and Accounting (AAA) framework, which of the following configurations specifically satisfy the Authorization and Accounting pillars? (Select TWO.)
Geçerli olan tümünü seçin
A security administrator is tasked with updating the data protection mechanism for a customer relationship management (CRM) database storing high-volume customer records at rest. The enterprise security policy requires that all stored data be encrypted using a high-speed algorithm that provides confidentiality with low computational overhead. Which of the following cryptographic algorithms should the administrator implement to meet this requirement?
A software engineering team is preparing to deploy an updated microservice that modifies shared container network policies and ingress routing rules within a production Kubernetes cluster. Which of the following steps must be completed as part of the formal change management workflow to evaluate and mitigate security risks prior to implementation? (Select TWO.)
Geçerli olan tümünü seçin
A security analyst is designing a secure telemetry collection architecture for edge gateway devices transmitting environmental data to an enterprise cloud endpoint. The design mandates establishing keying material that ensures perfect forward secrecy and validating the authenticity and data integrity of each transmitted payload with minimal performance overhead. Which of the following cryptographic techniques should the analyst select to meet these requirements? (Select TWO.)
Geçerli olan tümünü seçin
A security analyst is investigating an automated alert from a cloud-hosted API gateway. A third-party developer successfully logged into the developer portal using single sign-on (SSO) credentials. However, when the developer attempted to issue a DELETE call against a production storage bucket, the API gateway returned a 403 Forbidden error because the developer's OAuth 2.0 access token lacked the required write/delete scope claims. Which pillar of the Authentication, Authorization, and Accounting (AAA) security framework directly enforced the decision to block the DELETE request?
A security engineer is troubleshooting intermittent connection timeouts and handshake failures reported by users accessing a high-security internal web application. Network logs indicate that client web browsers are attempting to query external Certificate Authority (CA) validation servers to verify the revocation status of the application's TLS certificate. However, client endpoints are on a strict zero-trust VLAN with no outbound internet access, causing the certificate status requests to block and eventually time out. Which of the following should the security engineer implement on the web server to resolve the validation failures while maintaining certificate status checking?
A security engineer is updating the firmware verification process for remote, low-power industrial sensor gateways. The firmware update image must be digitally signed by the vendor to verify its origin and integrity before installation. Due to severe memory and processing constraints on the gateway hardware, the solution must provide strong asymmetric security while minimizing key size and computational overhead. Which cryptographic algorithm combination should the engineer select?
A security engineer is auditing an automated provisioning pipeline for a fleet of internal microservice gateways. The deployment script generates a single public/private key pair and Certificate Signing Request (CSR) on a central management server, submits the CSR to the internal Certificate Authority (CA), and then copies the issued certificate and private key over SSH to all target gateway nodes. Which of the following best describes the primary security flaw in this PKI workflow?
A security operations team configures an isolated decoy server populated with simulated confidential files on an internal subnet. The server is designed to attract unauthorized intruders who have breached the perimeter, allowing analysts to log their activities and gather telemetry on their attack techniques without exposing production data. Which of the following security control classifications correctly identifies both the category and functional type of this deployment?
A security administrator is refining the Public Key Infrastructure (PKI) deployment for an enterprise RADIUS server supporting 802.1X EAP-TLS authentication. Mobile clients connecting over high-latency cellular links experience frequent authentication timeouts caused by real-time Certificate Revocation List (CRL) downloads. To optimize client authentication performance and ensure secure server identity verification, which of the following mechanisms or configurations should the administrator implement? (Select TWO).
Geçerli olan tümünü seçin
A security analyst is classifying enterprise defense mechanisms according to CompTIA Security+ implementation categories (Technical, Managerial, Operational, Physical) and functional control types (Preventive, Deterrent, Detective, Corrective, Compensating, Directive). Match each security scenario on the left with its primary dual-axis security control classification on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler