Security Operations
627 soru
During network security monitoring of a segmented cloud environment, an analyst receives an automated Network Intrusion Detection System (NIDS) alert indicating that an internal deception host (honeypot) has initiated outbound network connections toward an unknown external address. A team member suggests modifying network routing policies to use this honeypot host as an inline security filter for all outbound enterprise traffic to block unauthorized connections. Which of the following best explains why this recommendation represents a fundamental misunderstanding of network monitoring and deception controls?
A cybersecurity analyst is configuring an automated incident response playbook within a Security Orchestration, Automation, and Response (SOAR) platform to process high-severity credential dumping alerts triggered by Endpoint Detection and Response (EDR) agents. To effectively contain potential lateral movement without introducing catastrophic operational downtime to enterprise operations, which of the following playbook logic designs should be implemented?
A security analyst is setting up an automated Security Orchestration, Automation, and Response (SOAR) playbook to streamline initial response tasks when a suspicious email attachment is reported. Which of the following tasks are most appropriate for full automation without requiring human-in-the-loop approval? (Select TWO.)
Geçerli olan tümünü seçin
An incident response team is responding to a confirmed security incident involving unauthorized API key usage and data exfiltration from an enterprise cloud storage bucket. Place the following incident response actions in the correct sequential order from first step to last step according to standard incident response playbooks.
Öğeleri doğru sıraya koymak için sürükleyin
A Security Operations Center (SOC) analyst receives an Endpoint Detection and Response (EDR) telemetry alert indicating a malicious DLL side-loading attempt on an enterprise domain controller. Arrange the standard EDR incident response steps in the correct chronological order from first to last.
Öğeleri doğru sıraya koymak için sürükleyin
A network administrator needs to monitor enterprise traffic volumes, protocol distributions, and IP communication pairs across internal routers without inspecting or storing packet payloads. Which of the following monitoring mechanisms should the administrator implement?
A security analyst is conducting a routine audit of Identity and Access Management (IAM) operational logs following an employee offboarding procedure. The log analysis reveals that an offboarded engineer's primary user account was disabled in Active Directory immediately upon termination. However, three days later, successful interactive logins were recorded on several internal servers using a secondary administrative account assigned to the same individual. Which of the following identity management operational failures is the MOST likely root cause of this security gap?
An enterprise security team is configuring a Just-In-Time (JIT) Privileged Access Management (PAM) workflow with short-lived ephemeral credentials for database administrators. Place the operational lifecycle steps in the correct chronological order from the initial access request through session termination.
Öğeleri doğru sıraya koymak için sürükleyin
A digital forensics examiner is performing evidence collection on a powered-on enterprise server following a suspected breach. To ensure maximum preservation of transient evidence, the examiner must adhere strictly to the forensic Order of Volatility. Sequence the following evidence sources from most volatile (highest priority for acquisition) to least volatile (lowest priority for acquisition).
Öğeleri doğru sıraya koymak için sürükleyin
A security operations team discovers that critical production servers frequently experience configuration drift due to uncoordinated hotfixes applied by system administrators during emergency outage incidents. Although automated configuration auditing tools successfully flag these non-compliant system states during nightly scans, security engineers cannot readily distinguish between unauthorized vulnerabilities and approved emergency hotfixes. Which of the following solutions should the security team implement to effectively manage configuration drift while maintaining audit compliance for emergency changes?
A security engineer is refining the vulnerability assessment strategy for an enterprise data center hosting high-availability web applications and legacy backend databases. To ensure deep asset visibility while mitigating the risk of service disruption and unauthorized network impact, which of the following operational practices should the engineer implement? (Select TWO.)
Geçerli olan tümünü seçin
A security engineer is configuring a SIEM collector to process raw syslog feeds from perimeter devices. Place the stages of SIEM log processing in the correct order from initial ingestion to analyst notification.
Öğeleri doğru sıraya koymak için sürükleyin
An enterprise incident response team is evaluating a newly deployed Security Orchestration, Automation, and Response (SOAR) playbook intended to contain compromised systems. The playbook automatically executes a script that isolates host network interfaces upon receiving high-severity endpoint alerts. Security engineers are concerned that automated execution against critical infrastructure, such as domain controllers or primary database hosts, could cause severe business disruptions in the event of a false positive. Which of the following workflow modifications best mitigates this risk while preserving automated containment capabilities for standard endpoints?
An enterprise security policy requires that any unauthorized changes to server system configurations are automatically detected and restored to a pre-approved security state. Which of the following operational controls best meets this requirement?
A security administrator is establishing standard operating procedures for system maintenance across enterprise servers. Which of the following actions should be performed prior to deploying software patches to live production servers? (Select TWO)
Geçerli olan tümünü seçin
A security operations team is configuring an automated Security Orchestration, Automation, and Response (SOAR) workflow to handle initial triage and containment for incoming high-severity suspicious email alerts. Which of the following tasks represent safe, effective automated steps to include in the initial playbook execution prior to analyst review? (Select TWO.)
Geçerli olan tümünü seçin
A systems administrator deploys a lightweight host-based agent across a fleet of Linux web servers to perform continuous vulnerability assessment. During an audit, the agent flags several critical local kernel vulnerabilities requiring remediation. However, a subsequent uncredentialed network-based vulnerability scan targeting the public IP addresses of these same web servers fails to detect any of the reported kernel flaws. Which of the following best explains why the network vulnerability scan missed these kernel vulnerabilities?
A Security Operations Center (SOC) analyst is reviewing alerts generated by a SIEM correlation rule designed to flag potential credential harvesting activity. Within a five-minute window, a standard domain user workstation generated multiple instances of the following Windows Security Event log entry:
Event ID: 4769
Task Category: Kerberos Service Ticket Operations
TargetUserName: [email protected]
Service Name: MSSQLSvc/db01.contoso.com:1433
Ticket Options: 0x40810000
Ticket Encryption Type: 0x17
Failure Code: 0x0
Client Address: ::ffff:192.168.10.115
Based on this log telemetry, which of the following security events is occurring?
A Security Operations Center (SOC) analyst receives an automated alert from a network intrusion detection system (NIDS) flagging potential command-and-control (C2) beaconing activity from an internal workstation. Place the following incident triage and response steps in the correct chronological order from first to last.
Öğeleri doğru sıraya koymak için sürükleyin
During security monitoring of an enterprise cloud environment, an automated alert flags an unauthorized microservice container actively establishing encrypted outbound connections to an external command-and-control (C2) server. Security analysts verify that the container is compromised and holds active database connection tokens. According to standard incident response frameworks, which of the following actions should the security team perform FIRST?