Threats, Vulnerabilities, and Mitigations
490 soru
A security operations center (SOC) analyst is performing forensic triage on endpoints following an enterprise network intrusion. Analyze the host and network telemetry artifacts, and match each malware classification on the left with its corresponding technical indicator of compromise (IoC) artifact on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An enterprise security assessment reveals that unprivileged workforce endpoints allow employees to connect unauthorized USB flash drives and execute untrusted software binaries directly from external media. Which of the following host-hardening strategies provides the MOST effective technical control to enforce peripheral hardware restrictions and prevent unauthorized program execution?
Match each social engineering attack vector on the left with its corresponding attack scenario description on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An executive assistant receives a tailored email that appears to come directly from the company's Chief Executive Officer (CEO). The message insists on an urgent, confidential wire transfer to secure an enterprise acquisition before the end of the business day. Which of the following social engineering attack vectors best describes this incident?
An attacker leaves several USB flash drives labeled "Executive Compensation Q3" on tables in an enterprise cafeteria, relying on curious employees to pick one up and plug it into a corporate workstation. Which social engineering attack vector is being demonstrated in this scenario?
A security analyst is tasked with assessing a newly deployed web application hosted in a staging environment. The analyst needs to identify runtime vulnerabilities, such as parameter tampering and input validation flaws, operating from a black-box perspective without access to the underlying source code. Which of the following security testing methods is most appropriate for this assessment?
An enterprise system Administrator discovers that a malicious script unexpectedly executed on a server immediately after a terminated employee's user account was disabled. The script was configured to monitor user directory changes and wipe database backups once the account status changed. Which type of malware or malicious code relies on a predefined trigger condition or specific event to execute its payload?
A security operations team investigating an incident at a global maritime logistics enterprise discovers that an unauthorized external entity compromised an edge API endpoint used by a third-party tracking partner. The threat actor utilized legitimate, stolen developer API tokens to gain access. Over an eight-month period, the actor made subtle, highly targeted modifications to cargo manifest metadata to delay specific dual-use technology shipments across international borders. The actor avoided deploying malware, exfiltrating bulk data, or disrupting general operations to evade detection by automated security controls. Based on these observed tactics, techniques, and procedures (TTPs), which threat actor profile and attribute combination is MOST likely responsible for this attack?
An enterprise financial institution plans to automate the ingestion of machine-readable threat indicators specifically sourced from peer sector organizations while standardizing automated indicator transport into its Security Orchestration, Automation, and Response (SOAR) platform. Which of the following solutions should the cybersecurity team implement to achieve these specific objectives? (Select TWO.)
Geçerli olan tümünü seçin
A security operations team at an autonomous vehicle software vendor detects a long-term breach of their internal development environment. The investigation reveals that the adversary exploited an undisclosed zero-day vulnerability in a perimeter gateway, used custom memory-resident tools to avoid endpoint detection, and maintained persistence for over six months strictly to exfiltrate proprietary machine learning models without disrupting operations or making extortion demands. Which threat actor profile best aligns with the attributes and tactics observed in this scenario?
A security monitoring tool flags multiple enterprise endpoints executing command-line instructions to disable the Volume Shadow Copy Service (`vssadmin delete shadows /all /quiet`) while concurrently generating high-volume disk write events that append custom file extensions to local documents. Which of the following malware types is most likely responsible for this activity?
A lead security auditor is reviewing a security assessment proposal for a facility that manages sensitive operational technology (OT) and legacy SCADA devices. The assessment team initially proposes running high-intensity active vulnerability scans across all subnets to discover open ports, running services, and unpatched vulnerabilities. The lead auditor rejects this proposal due to the high risk of intrusive active probing crashing sensitive legacy controllers. Which security assessment method should the lead auditor recommend as the safest alternative to identify active hosts and services on the OT network without disrupting operational systems?
A financial institution's security team is investigating an incident where confidential transaction payloads transmitted over an encrypted TLS connection were intercepted and decrypted by an adversary positioned on the network path. Technical analysis reveals that the server accepted legacy TLS 1.2 connections configured with AES in Cipher Block Chaining (CBC) mode using predictable initialization vectors (IVs) and HMAC-SHA1. Which cryptographic weakness directly enabled the adversary to decrypt the payload without possessing the server's private key?
A security engineer conducts an architecture review of a hypervisor cluster hosting mission-critical enterprise workloads. The assessment reveals that the Out-of-Band (OOB) Baseboard Management Controller (BMC) interfaces of the physical host servers reside on the same IP subnet as the guest virtual machine data traffic. The organization relies exclusively on the enterprise perimeter firewall to restrict outside access, placing no internal firewall rules, microsegmentation, or access control lists (ACLs) between the guest networks and the BMC interfaces. Which of the following architectural vulnerabilities represents the MOST critical threat to the infrastructure?
Match each vulnerability assessment and security testing method on the left with its appropriate operational description on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A security analyst is reviewing incident reports to classify different types of malicious software based on their core behavior and primary indicators of compromise. Match each malware type on the left with its corresponding technical indicator or defining behavior on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
Match each threat actor type to its primary defining attribute or motivation in cybersecurity. Which pairings accurately reflect each threat actor profile?
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
Match each enterprise host, network, or architecture vulnerability scenario to its primary mitigation strategy.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A security analyst is selecting appropriate security assessment methodologies for an enterprise infrastructure audit. Match each vulnerability assessment and security testing method on the left to its corresponding operational characteristic on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A security analyst is investigating severe performance slowdowns on a server transferring large archive files across the network. The investigation reveals that the file transfer service uses RSA asymmetric encryption to encrypt the full content of every file being transmitted, rather than using it solely to negotiate a symmetric session key. Which of the following describes the fundamental cryptographic weakness causing this performance issue?