Security Operations
627 soru
A security analyst reviewing automated audit logs discovers that several cloud-hosted web servers have diverged from the organization's hardened baseline. Investigation reveals that system administrators manually modified SSL/TLS configuration files to troubleshoot a legacy integration, inadvertently re-enabling weak cipher suites that violate security policy. The central Infrastructure-as-Code (IaC) repository still contains the approved, secure configuration state. Which of the following is the BEST initial action to remediate the vulnerability and prevent future configuration drift?
A security analyst is reviewing correlated firewall and internal DNS query logs for an internal workstation (10.0.4.15):
[Firewall Log]
Timestamp: 2026-07-27T14:15:02Z Src_IP: 10.0.4.15 Dst_IP: 198.51.100.44 Dst_Port: 53 Protocol: UDP Bytes_Sent: 4520 Bytes_Rcvd: 312 Action: ALLOW
Timestamp: 2026-07-27T14:15:05Z Src_IP: 10.0.4.15 Dst_IP: 198.51.100.44 Dst_Port: 53 Protocol: UDP Bytes_Sent: 4890 Bytes_Rcvd: 298 Action: ALLOW
[DNS Query Log]
Timestamp: 2026-07-27T14:15:02Z Client: 10.0.4.15 Query: 58617a7964617461.exfil.badactor-domain.com Type: TXT RCODE: NOERROR
Timestamp: 2026-07-27T14:15:05Z Client: 10.0.4.15 Query: 6261636b75703031.exfil.badactor-domain.com Type: TXT RCODE: NOERROR
Based on this log telemetry, which of the following statements regarding the threat activity and appropriate mitigation steps are correct? (Select TWO.)
Geçerli olan tümünü seçin
During a routine operational review of corporate laptops, endpoint telemetry detects a malicious script executing directly in volatile memory and initiating unauthorized outbound traffic to a known adversary infrastructure. To stop lateral movement and data exfiltration immediately while retaining live memory context for incident investigation, which of the following EDR capabilities should be executed?
A security engineer inspects network security telemetry following a simulated penetration test. The red team successfully executed a known web application exploit payload over an HTTPS connection to an internal web server. Although the Network Intrusion Prevention System (NIPS) was deployed inline and possessed the latest vendor signature for the exploit, it neither generated an alert nor dropped the malicious connection. NetFlow records confirm the attack traffic passed directly through the NIPS interface. Which of the following best explains why the monitoring and alerting controls failed to detect this attack?
A security analyst receives a high-severity alert from an Endpoint Detection and Response (EDR) agent indicating that a malicious WMI event subscription has been registered on a critical enterprise server and is attempting to execute unauthorized PowerShell scripts. Place the containment and incident response steps in the correct sequential order from initial response to final remediation.
Öğeleri doğru sıraya koymak için sürükleyin
A network administrator at a logistics enterprise configures TACACS+ for centralized management of core routers. Network engineers can successfully authenticate to the router command-line interface using their domain credentials. However, when the engineers attempt to run restricted configuration commands, the router returns a permission error. The administrator verifies that credential validation against Active Directory is functioning properly. Which of the following describes the root cause of this operational issue?
A Security Operations Center (SOC) analyst identifies active data exfiltration from a user workstation caused by an unauthorized memory-resident process. The analyst must immediately stop the data egress and restrict lateral network communication while retaining remote console administrative access to collect RAM telemetry and run live response forensic commands. Which of the following capabilities should the analyst execute?
An enterprise mobile application authenticates users via a cloud-hosted Identity Provider (IdP) using the OAuth 2.0 Authorization Code Flow with Proof Key for Code Exchange (PKCE). Place the operational steps of this authentication sequence in the correct order, from initial client initialization to final token delivery.
Öğeleri doğru sıraya koymak için sürükleyin
During a routine automated compliance scan, a security operations team discovers a critical zero-day vulnerability in a core software dependency running on legacy Linux application hosts. Vendor testing reveals that applying the official patch breaks custom enterprise middleware dependencies, causing service instability during canary testing. Which of the following actions represents the MOST appropriate immediate strategy to maintain security posture without compromising service availability?
A security analyst is investigating a SIEM alert containing the URI parameter: `/inventory.php?item=10' UNION SELECT null, table_name FROM information_schema.tables--`. Moments later, network security monitoring sensors record outbound traffic originating from the targeted web server to an IP address within an isolated deception subnet (honeypot). Which of the following statements accurately identifies the attack technique observed and the operational purpose of the triggered deception control?
During network monitoring, a security team identifies an unauthorized device acting as a rogue DHCP server on a corporate office VLAN, assigning malicious default gateway addresses to internal endpoints. The incident response team has confirmed the alert and identified the specific physical switch port connected to the rogue device. According to standard incident response procedures, which of the following actions should the team perform next?
A security operations analyst is reviewing access gateway logs following reports that remote workers cannot connect to an enterprise VPN. The authentication gateway delegates identity verification to a central SAML 2.0 Identity Provider (IdP) and passes authorization queries to a RADIUS policy server. The analyst inspects the following log entries from the RADIUS policy engine:
[2026-07-27 11:02:14] RADIUS-AUTH: SAML token validated successfully for '[email protected]'.
[2026-07-27 11:02:15] RADIUS-POL: Evaluating Network Policy 'VPN_Engineering_Access'.
[2026-07-27 11:02:15] RADIUS-POL-ERR: Group attribute 'CN=Contractors,OU=Groups' does not match required group 'CN=FullTime_Engineers'.
[2026-07-27 11:02:15] RADIUS-AAA: Sending ACCESS-REJECT for session candidate '[email protected]'.
Based on the log output, which of the following best describes the root cause of the access failure?
A security analyst is investigating an authentication and privileges alert in a hybrid enterprise environment. The log audit reveals that a non-interactive service account (`svc_vaultsync`) authenticated via LDAPS from a workstation IP address and successfully retrieved domain administrative credentials from a Privileged Access Management (PAM) vault outside scheduled maintenance hours. Which of the following operational controls or administrative practices should the security team implement to mitigate this incident and harden IAM operations against future abuse? (Select TWO.)
Geçerli olan tümünü seçin
During a scheduled vulnerability assessment of an enterprise network segment, an automated scanner causes several legacy network switches to become unresponsive due to resource exhaustion from high-frequency port probing and service discovery requests. Which of the following adjustments should the security engineer implement to maintain visibility into these network devices without causing service disruptions?
Following an alert indicating potential ransomware propagation via macro execution on an executive laptop, an incident responder requires immediate containment and detailed investigation tools operating directly on the host. Which TWO of the following capabilities represent primary features of an Endpoint Detection and Response (EDR) solution that address this situation?
Geçerli olan tümünü seçin
A security administrator must deploy a critical system patch and an updated security hardening baseline across a fleet of enterprise application servers. To minimize operational risk and maintain security compliance, the administrator must follow a structured configuration and patch management workflow. In what order should the administrator execute these operational steps from first to last?
Öğeleri doğru sıraya koymak için sürükleyin
During a security incident, an organization's Security Operations Center (SOC) identifies a compromised containerized application actively scanning internal microservices for vulnerabilities. Place the following incident response actions in the correct sequential order from FIRST to LAST according to standard incident handling frameworks.
Öğeleri doğru sıraya koymak için sürükleyin
An enterprise security team is selecting appropriate vulnerability assessment methodologies for distinct operational requirements across the enterprise environment. Match each vulnerability assessment approach on the left with the operational use case on the right that best represents its application.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A security analyst detects suspicious fileless activity on an enterprise endpoint, where a legitimate administrative process is spawned to run encoded PowerShell scripts that attempt lateral movement across the internal subnet. The analyst must halt all network communication to and from the compromised host to stop lateral movement, while maintaining active command-and-control connectivity between the endpoint agent and the EDR management console for live forensic investigation. Which of the following Endpoint Detection and Response (EDR) actions should the analyst take?
A security analyst in a Security Operations Center (SOC) confirms that a workstation in the accounting department is infected with active ransomware. Network monitoring logs indicate the infected host is currently attempting to scan and encrypt remote file shares over SMB across the local subnet. Which of the following actions should the analyst perform FIRST according to standard incident response process playbooks?