Threats, Vulnerabilities, and Mitigations
490 soru
Match each enterprise endpoint hardening practice to the primary security threat or vulnerability vector it mitigates.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A software developer discovers that a user feedback form concatenates untrusted input directly into a database query string, allowing arbitrary database command execution. Which of the following is the MOST effective coding practice to mitigate this vulnerability?
Match each network or wireless security threat on the left with its corresponding technical indicator or observed evidence on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A security analyst is reviewing a vulnerability scan report for a company web application. The report indicates that an attacker can access arbitrary files on the server's file system by inserting relative path sequences (such as `../../etc/passwd`) into a file request parameter. Which of the following application vulnerabilities is described in this scenario?
A security analyst is auditing an e-commerce platform's microservice that processes promotional discount codes. During testing, the analyst discovers that when a user sends multiple concurrent asynchronous API requests utilizing the same single-use discount voucher, the application processes several of the requests simultaneously before updating the voucher's status flag to used in the persistent database. Which of the following application vulnerabilities is present, and what is the most effective code-level mitigation strategy?
A security analyst is investigating a newly reported software vulnerability and needs to review its official description, standardized Common Vulnerability Scoring System (CVSS) metrics, and vendor patch links. Which threat intelligence source is specifically designed to provide this centralized repository of public vulnerability data?
A security operations manager at an electric vehicle charging station network provider is categorizing recent security incidents and threat activity profiles. Match each observed incident scenario on the left with the threat actor attribute or vector on the right that primarily defines it.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
During a security assessment of a web portal's user profile microservice, a security analyst reviews the API request handling logic. The microservice accepts a JSON payload for profile updates and automatically maps all incoming key-value pairs directly to the backend database user model without filtering. Furthermore, when users supply a web URL to import a profile avatar, the server issues an HTTP request to retrieve the image using service privileges without validating the target destination host or IP address. Which of the following application vulnerabilities are present in this scenario? (Select TWO.)
Geçerli olan tümünü seçin
A security analyst is evaluating different testing procedures to incorporate into an organization's vulnerability management policy. Match each security testing method on the left with its corresponding operational characteristic on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
Match each host and infrastructure vulnerability scenario to the underlying security weakness or misconfiguration it represents.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An enterprise infrastructure security team is implementing system hardening practices to remediate recent penetration test findings. Match each specific technical hardening control to the primary vulnerability mechanism or attack vector it directly suppresses.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
During a routine wireless site survey, a technician discovers a rogue wireless access point broadcasting the exact same Service Set Identifier (SSID) as the corporate network, but transmitting with a different basic service set identifier (BSSID) and higher signal strength to intercept client authentication traffic. Which of the following attack types is indicated by these symptoms?
A security operations analyst is categorizing threat intelligence sources to build a tiered threat data pipeline. Match each threat intelligence source classification on the left with its primary operational characteristic on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
During a security review at a healthcare facility, security logs reveal that multiple remote clinical staff members received short message service (SMS) communications claiming to originate from the organization's IT department. The text messages asserted that an urgent system update required recipients to immediately click an enclosed link and re-authenticate to prevent loss of Electronic Health Record (EHR) system access. Which social engineering attack vector was executed, and which technical control provides the most robust protection against credential compromise resulting from this attack?
A junior security analyst is tasked with setting up an automated, machine-readable threat intelligence feed to deliver standardized cyber threat indicators directly into the organization's Security Information and Event Management (SIEM) system over HTTPS. Which of the following standards and transport protocols should the analyst implement to achieve this? (Select TWO.)
Geçerli olan tümünü seçin
A security specialist is reviewing code and application layer security controls for a public web portal. Which of the following vulnerabilities occur directly due to insufficient input validation and sanitization of user-supplied data? (Select TWO).
Geçerli olan tümünü seçin
A network technician notices that several workstations on a local subnet are experiencing intermittent network connectivity issues. Upon checking the IP configurations of affected client devices, the technician discovers unexpected network settings. Which TWO of the following indicators specifically point to the presence of an active rogue DHCP server on the network?
Geçerli olan tümünü seçin
During a security architecture audit of a hybrid enterprise environment, analysts discover that system administrators regularly use PowerShell Remoting (WinRM) over TLS to manage internal domain controllers directly from unmanaged endpoints connected via a split-tunnel VPN. If an unmanaged endpoint is compromised, attackers could execute arbitrary administrative commands across the internal infrastructure. Which of the following enterprise hardening strategies MOST effectively mitigates this administrative exposure while preserving required remote management capabilities?
An IT security team is establishing baseline endpoint hardening configurations for newly deployed employee workstations. Which TWO of the following technical measures directly reduce the local host attack surface?
Geçerli olan tümünü seçin
A security analyst at a specialized aerospace firmware developer is investigating a high-profile intrusion into the company's build systems. The threat group gained initial access using a custom zero-day exploit targeting a perimeter firewall, maintained silent persistence for eight months without disrupting service operations, and exfiltrated proprietary satellite navigation algorithms. Investigation reveals the group utilized custom memory-only payloads and a multi-hop proxy network spans multiple foreign jurisdictions. Which of the following threat actor categories and attribute profiles best characterizes this threat entity?