Security Operations
627 soru
During a active security incident, a enterprise Security Operations Center (SOC) team detects that an attacker has gained persistence on an internal domain-joined SQL database server containing highly sensitive PII. Forensics logs reveal the attacker established a reverse shell via a web application vulnerability and is currently conducting live internal network scanning and attempting lateral movement via Server Message Block (SMB). According to the NIST Incident Response Framework (SP 800-61 Rev. 2), which of the following actions should the incident response team perform IMMEDIATELY as part of the Containment phase? (Select TWO.)
Geçerli olan tümünü seçin
A security analyst is initiating a digital forensics investigation on a compromised live application server. Which of the following actions should the analyst perform to adhere to proper evidence preservation and chain of custody procedures? (Select TWO.)
Geçerli olan tümünü seçin
A cybersecurity forensic analyst has just completed a bit-stream disk acquisition of a target drive seized during an insider threat investigation. The analyst must now process and secure the physical drive and digital image to ensure legal admissibility in court. Place the following evidence handling and chain of custody steps in the correct chronological order from first to last.
Öğeleri doğru sıraya koymak için sürükleyin
An organization is deploying an Endpoint Detection and Response (EDR) agent across all enterprise hosts. Which of the following core capabilities differentiate EDR solutions from traditional signature-based antivirus software? (Select TWO.)
Geçerli olan tümünü seçin
A security analyst is investigating a stealthy compromise on an enterprise server where an attacker executed an obfuscated script directly in host memory using native tools, avoiding writing any malicious files to the disk. Standard signature-based antivirus software and perimeter firewalls failed to detect the activity. Which capability of Endpoint Detection and Response (EDR) provides the visibility required to identify and trace this fileless execution?
An incident responder arrives at a compromised live workstation suspected of running volatile in-memory malware. To preserve digital evidence without destroying transient data, the responder must extract system artifacts in strict adherence to the forensic Order of Volatility (RFC 3227). In what sequence should the analyst collect the following evidence items, starting with the MOST volatile artifact (collected first) and ending with the LEAST volatile artifact (collected last)?
Öğeleri doğru sıraya koymak için sürükleyin
A security engineer is configuring an enterprise Security Information and Event Management (SIEM) pipeline to process raw web application traffic logs and detect potential SQL injection attacks. Arrange the following log processing and analysis stages in the correct sequential order from initial log generation to SOC notification.
Öğeleri doğru sıraya koymak için sürükleyin
Following an security alert indicating active LSASS memory injection on a Windows Domain Controller, an incident investigator needs to collect digital evidence from the running system. To strictly adhere to the order of volatility and maintain evidence integrity, which of the following actions should the investigator perform FIRST?
A security technician has isolated a physical hard drive containing forensic evidence from a workstation involved in an internal investigation. The technician must transport the drive to a secure off-site facility for forensic imaging. Which of the following actions is most critical to preserve the legal admissibility of the physical evidence during transport?
A digital forensics investigator receives an external solid-state drive (SSD) delivered by a courier as part of an ongoing insider threat investigation. The drive is stored in an anti-static evidence bag with a tamper-evident seal and is accompanied by a chain of custody log detailing its initial acquisition and cryptographic hash. Which of the following steps should the investigator perform first upon receiving the physical evidence?
During security monitoring, a Security Operations Center (SOC) analyst verifies that a database server hosting critical business records has executed an unauthorized executable from a temporary directory and opened an active outbound connection to a suspicious external endpoint. The threat analyst confirms the host is compromised. According to standard incident response process frameworks, which of the following actions should the analyst perform FIRST?
A Security Operations Center (SOC) analyst is investigating a cross-environment security alert in a SIEM console. The alert correlates web application server logs with cloud audit logs across a 5-minute timeframe:
Log Snippet 1 (Nginx Web Server Access Log):
`192.0.2.45 - - [27/Jul/2026:14:22:10 +0000] "GET /api/v1/fetch?url=http://169.254.169.254/latest/meta-data/iam/security-credentials/AppRole HTTP/1.1" 200 1423 "-" "Mozilla/5.0"`
Log Snippet 2 (CloudTrail Security Audit Log):
`{"eventTime": "2026-07-27T14:25:04Z", "eventName": "ListBuckets", "userARN": "arn:aws:iam::123456789012:role/AppRole", "sourceIPAddress": "198.51.100.89", "userAgent": "aws-sdk-python/1.26.0"}`
Based on the correlated log telemetry, which of the following best describes the attack vector executed and the log indicator confirming successful exploitation?
An enterprise security team detects that an automated build server within their CI/CD pipeline has been compromised by an attacker executing unauthorized external network sweeps and downloading secondary payloads. The incident response plan has entered the containment phase. Which of the following actions should the incident response team perform during this phase? (Select TWO.)
Geçerli olan tümünü seçin
An incident response team is conducting live digital forensics on a powered-up enterprise database server experiencing active kernel-level malware execution and network exfiltration. To prevent the loss of critical evidence during acquisition, in what exact sequence should the investigator collect the following digital evidence sources, starting with the MOST volatile source and ending with the LEAST volatile source?
Öğeleri doğru sıraya koymak için sürükleyin
An organization is deploying an Endpoint Detection and Response (EDR) agent across its fleet of enterprise workstations to enhance host-level threat detection and incident containment capabilities. Which of the following represent core operational features provided by an EDR solution? (Select TWO.)
Geçerli olan tümünü seçin
A technician identifies an active malware infection on an enterprise desktop. To stop lateral movement without losing volatile memory evidence, the technician uses the Endpoint Detection and Response (EDR) console. Which of the following capabilities should the technician execute?
A forensic analyst is responding to an active security incident involving a bare-metal hypervisor suspected of hosting a sophisticated, memory-resident kernel rootkit that utilizes Direct Memory Access (DMA) to exfiltrate cryptographic keys. To preserve evidence for potential judicial proceedings while adhering strictly to forensic standards, which of the following actions should the analyst perform FIRST?
A security analyst confirms that an internal user workstation is infected with active malware that is attempting to communicate with an external command-and-control server. According to standard incident response lifecycle frameworks (such as NIST SP 800-61), which of the following actions should the analyst take immediately after confirming the incident?
During an incident response investigation involving suspected database exfiltration on a live cloud-hosted virtual server, a security analyst must preserve system evidence while maintaining strict chain of custody compliance for potential legal proceedings. Which of the following procedures should the analyst perform immediately following the acquisition of the system's volatile memory?
An enterprise Incident Response Team (IRT) detects unauthorized DNS redirection caused by ARP cache poisoning on a critical core network segment. According to standard NIST SP 800-61 incident response frameworks, in what order should the incident response team execute the following operational response steps?
Öğeleri doğru sıraya koymak için sürükleyin