Security Operations
627 soru
A security administrator wants to collect continuous host-level telemetry, such as process creation events, registry modifications, and network connections, to detect fileless malware and zero-day threats in real time across corporate workstations. Which of the following security solutions best fulfills this requirement?
During an ongoing security breach, an Incident Response Team (IRT) identifies that an attacker has gained access to internal endpoints using harvested domain administrator credentials and is actively attempting lateral movement across enterprise network segments via pass-the-ticket techniques. Which of the following containment actions should the IRT execute IMMEDIATELY to stop ongoing lateral movement while preserving evidence integrity? (Select TWO.)
Geçerli olan tümünü seçin
An incident response team is preparing to collect evidence from a physical storage drive recovered during an investigation. To ensure that the drive's contents cannot be altered or modified by the operating system while creating a forensic bit-stream image, which of the following tools should the technician use to connect the drive to the workstation?
During a physical security audit at a remote branch office, a security analyst discovers an unauthorized rogue wireless access point connected directly to a network switch port. The rogue device is broadcasting an unencrypted SSID and bridging external wireless traffic directly into the internal corporate network segment. According to standard incident response frameworks, which of the following actions should the analyst perform FIRST?
Match each vulnerability scanning concept on the left with its corresponding operational description on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An enterprise Security Operations Center (SOC) detects abnormal outbound DNS traffic indicating potential data exfiltration via DNS tunneling from an internal host. Place the incident response actions in the correct chronological order according to standard NIST incident handling guidelines, starting from the initial response through completion.
Öğeleri doğru sıraya koymak için sürükleyin
An incident response team is conducting live digital evidence acquisition on a compromised enterprise gateway server suspected of hosting an active in-memory exploit. Based on the RFC 3227 standard Order of Volatility, in what sequence should the forensic investigator capture the following digital evidence components, starting from the most volatile to the least volatile?
Öğeleri doğru sıraya koymak için sürükleyin
A digital forensics analyst receives a seized external hard drive transported from a field office via a secure courier. Upon intake, the analyst notices that the tamper-evident transport bag was torn and the accompanying paper tracking form lacks the courier's transfer signature. Before connecting the drive to a hardware write-blocker for imaging, which of the following actions MUST the analyst perform first to maintain evidentiary standards?
A security administrator is evaluating Endpoint Detection and Response (EDR) software to upgrade workstation security across an enterprise environment. Which of the following capabilities are primary features provided by EDR solutions? (Select TWO.)
Geçerli olan tümünü seçin
An incident response team is performing live digital evidence acquisition on a compromised enterprise application server following a detected in-memory code injection attack. To ensure dynamic evidence is captured before it is lost or modified, the forensic investigator must collect data strictly according to the standard Order of Volatility. Place the following digital evidence sources in the correct order of acquisition, from MOST volatile (acquired first) to LEAST volatile (acquired last).
Öğeleri doğru sıraya koymak için sürükleyin
During a routine audit, a Security Operations Center (SOC) analyst detects an unauthorized rogue wireless access point bridged directly into an isolated network segment containing sensitive customer databases. Forensic monitoring confirms that an external threat actor is actively exfiltrating live database traffic across this rogue wireless link. According to standard incident response lifecycle frameworks, which of the following actions should the incident response team perform FIRST?
A cybersecurity analyst is investigating an active fileless malware infection on a host machine operating multiple virtualized enterprise services. The analyst must capture digital evidence in strict compliance with the Order of Volatility while maintaining chain of custody standards for legal admissibility. Which of the following procedures should the analyst execute FIRST?
A security analyst receives a high-fidelity Endpoint Detection and Response (EDR) alert indicating that a web service process on a critical Linux server is executing unauthorized shell commands and attempting outbound command-and-control communications. The analyst must contain the threat immediately to prevent lateral movement while preserving volatile memory and maintaining an administrative management channel to the host. Which of the following is the most appropriate action to take using the EDR console?
A digital forensics investigator is preparing to capture a bit-stream copy of a seized hard drive recovered from an employee's computer during an insider threat investigation. To ensure that the physical drive's original data remains unmodified and that the acquired evidence is legally admissible, which of the following procedures must the investigator implement prior to starting the imaging process?
A Security Operations Center (SOC) team receives an automated alert generated by their Security Information and Event Management (SIEM) system regarding suspicious outbound traffic from host IP 10.10.4.15. The team pulls the following correlated telemetry logs:
[Sysmon Event ID 22 - DNS Query]
ProcessImage: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
QueryName: aW50ZXJuYWwtZGF0YS0wMQ.exfil.attacker-domain.com
QueryStatus: 0 (SUCCESS)
[Perimeter Firewall Egress Log]
SrcIP: 10.10.4.15 | DstIP: 198.51.100.45 | DstPort: 53 | Protocol: UDP | Action: ALLOWED | BytesSent: 1420
[SIEM Correlation Engine Alert]
Rule_ID: RULE_DNS_HIGH_ENTROPY_SUBDOMAINS
Condition: Count(DNS_Query) > 500 per 60 seconds targeting unique high-entropy subdomains of a single domain.
Based on the log telemetry and correlation rule output, which of the following best identifies the active attack vector and the underlying operational reason it bypassed initial perimeter controls?
During an ongoing incident investigation, a security analyst detects that an unauthorized rogue laptop is actively transmitting encrypted data across an internal enterprise network. According to standard incident response frameworks, which of the following actions should the analyst perform FIRST?
A security engineer is conducting vulnerability scans across an enterprise hybrid cloud environment. During network-based authenticated scans of Linux server instances, the scanner continuously reports multiple critical vulnerabilities for outdated software packages. However, system administrators confirm that vendor-specific security patches were already installed via package management backporting, which updates internal code without changing upstream major version strings. Furthermore, the network scans consistently fail to capture vulnerabilities on ephemeral, short-lived container instances deployed during peak auto-scaling events. Which of the following vulnerability assessment approaches should the security engineer implement to eliminate these false positives and ensure continuous visibility into short-lived instances?
A security analyst notices suspicious process execution on a financial department workstation during an active malware outbreak. To immediately block the workstation's network communication with other internal systems while preserving the security team's remote telemetry and control channel, which of the following is the most appropriate action to take?
A Security Operations Center (SOC) analyst is reviewing raw telemetry in a SIEM console containing the following event logs from an internal DNS resolver and perimeter firewall:
2026-07-27T14:10:02Z dns-resolver named[2104]: query: 61646d696e2d70617373776f7264.exfil.external-badactor.net IN TXT + (10.0.4.15)
2026-07-27T14:10:05Z dns-resolver named[2104]: query: 636f6e666964656e7469616c3132.exfil.external-badactor.net IN TXT + (10.0.4.15)
2026-07-27T14:10:08Z perimeter-fw kernel: [DENY] SRC=10.0.4.15 DST=203.0.113.50 PROTO=TCP SPT=49210 DPT=443 SIG=DIRECT_OUTBOUND_RESTRICTED
Based on these correlated log entries, which of the following security findings are accurate? (Select TWO.)
Geçerli olan tümünü seçin
A security analyst receives a high-severity EDR alert indicating a fileless process injection attack targeting a critical server. To mitigate lateral movement, preserve evidence, and remediate the incident, the analyst must follow a structured EDR incident response workflow. In what order should the analyst perform the following response actions?
Öğeleri doğru sıraya koymak için sürükleyin