Threats, Vulnerabilities, and Mitigations
490 soru
Match each observed log signature or network artifact on the left with its corresponding attack classification on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A security operations team at a commercial satellite communications provider is evaluating two separate security incidents to classify the underlying threat actors and their attack vectors based on observed operational attributes.
• Incident 1: A prolonged, highly sophisticated intrusion into ground station controller firmware utilizing zero-day exploits and custom memory-resident malware, sustained over nine months with no apparent financial extortion attempt.
• Incident 2: A sudden web defacement of the public customer portal paired with a high-volume volumetric DDoS attack, accompanied by public statements demanding the cancellation of aerospace defense contracts.
Based on these attributes and operational indicators, which of the following threat actor classifications and profile assessments are correct? (Select TWO.)
Geçerli olan tümünü seçin
A network administrator receives multiple user tickets regarding frequent, transient disconnections on an enterprise wireless network using WPA3-Enterprise. A wireless packet capture collected near the affected access points reveals an abnormally high frequency of IEEE 802.11 Type 0 (Management) Subtype 12 frames sent with the BSSID spoofed as the legitimate AP address targeting client MAC addresses, causing immediate client state reset. Further configuration inspection indicates that Management Frame Protection (802.11w / PMF) was set to 'Optional' across all access points. Which of the following wireless attack types is directly indicated by these packet capture artifacts?
Three weeks after a system administrator resigns from an organization, a database server executing a scheduled midnight payroll job unexpectedly wipes all stored tables. Forensic review of the application's source code identifies an unauthorized script configured to monitor Active Directory for the former administrator's account status. Upon detecting that the account was flagged as disabled, the script automatically triggered the destructive payload. Which of the following malware types best describes this malicious code?
An enterprise security team must perform routine vulnerability assessments across 5,000 corporate workstations distributed over low-bandwidth branch network links. The assessment must accurately detect missing operating system patches and local registry misconfigurations while minimizing network traffic and preventing false positives caused by endpoint firewalls. Which of the following vulnerability assessment methods should the security team implement?
A senior threat intelligence analyst at a global financial services firm is architecting an automated threat feed ingestion pipeline. The system must standardize machine-readable cyber threat indicators and automatically transport them directly into the enterprise Security Information and Event Management (SIEM) platform for real-time correlation without requiring manual analyst intervention. Which of the following standards or protocol frameworks are specifically designed to meet these requirements? (Select TWO.)
Geçerli olan tümünü seçin
A security analyst reviews a vulnerability assessment report for an internal Network Attached Storage (NAS) appliance deployed on a dedicated storage management subnet. The audit report identifies two critical host and infrastructure vulnerabilities:
1. The storage management web console accepts cleartext HTTP traffic over TCP port 80 and retains factory default administrator credentials.
2. An unencrypted Telnet service is active on TCP port 23 for command-line access.
Which of the following hardening measures should the security team implement to remediate these specific vulnerabilities? (Select TWO.)
Geçerli olan tümünü seçin
An IT technician is tasked with applying baseline security hardening controls to enterprise endpoints. Match each system hardening technique on the left with its corresponding security mitigation goal on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A security engineering lead at a global telecommunications provider is building an automated workflow to ingest threat indicators into an enterprise SIEM. The threat intelligence vendor supplies standardized, machine-readable data structures representing threat actor TTPs, attack vectors, and observable indicators. To enable automated client-server polling and pushing of these structured data packages over HTTPS, which protocol must be deployed at the application transport layer?
A cybersecurity team at a commercial bank wants to collaborate with peer organizations to exchange industry-specific threat alerts, emerging attack vectors, and operational insights tailored specifically to the financial sector. Which of the following resources best satisfies this requirement?
A security analyst inspects an HTTP request sent to an enterprise document service along with the corresponding server response:
http
GET /documents/download?file=..%2F..%2F..%2Fetc%2Fpasswd HTTP/1.1
Host: portal.example.com
The web server responds with an HTTP 200 OK status code containing the root filesystem account details. Additionally, when a user submits a non-existent path parameter, the application returns a detailed Java stack trace displaying internal file system paths, framework versions, and database connection strings.
Based on these findings, which of the following application vulnerabilities are present? (Select TWO.)
Geçerli olan tümünü seçin
An enterprise security team discovers that a bare-metal server's Baseboard Management Controller (BMC) interface running IPMI v2.0 on UDP port 623 is reachable directly from standard workstation VLANs. The IPMI service is configured with Cipher Suite 0, allowing session establishment without authentication and transmitting management traffic in cleartext. Although edge firewalls restrict external internet access to UDP port 623, no internal network segmentation or host-level access control lists exist to restrict internal traffic. Which of the following mitigation strategies BEST addresses the host, protocol, and architectural vulnerabilities described in this scenario?
An organization's security operations team observes that unauthorized software scripts are frequently executing from temporary user directories on endpoint workstations. To restrict hosts so that only explicitly authorized executables and scripts are permitted to run, which of the following technical mitigation controls should be implemented?
During a post-breach investigation at a software development firm, incident responders trace an initial access event to a multi-stage campaign. The threat actor scattered USB drives branded with the firm's logo and labeled 'Confidential Executive Salaries' across the employee parking area. Concurrently, the actor compromised a popular third-party technical documentation site frequented by the firm's DevOps engineering team, injecting a malicious script that prompted visitors to download a forged browser extension update. Which of the following social engineering techniques and attack vectors were directly executed in this campaign? (Select TWO.)
Geçerli olan tümünü seçin
A cybersecurity specialist at a hospital wants to receive sector-specific threat intelligence and exchange real-time attack indicators with peer healthcare entities. Which of the following sources best fulfills this requirement?
A security analyst is conducting forensic triage on several compromised endpoints following an enterprise network incident. Match each observed technical Indicator of Compromise (IoC) with its corresponding malware classification.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An application security specialist is investigating a recurring system crash in a legacy network daemon written in C. Log analysis reveals that an attacker sent a single network packet containing a 2,048-byte payload field into a fixed 512-byte destination memory buffer, causing a segmentation fault and corrupting the instruction pointer. Which of the following vulnerabilities was exploited, and what is the most effective code-level mitigation?
An enterprise security analyst investigates a workstation after an employee reports unexpected system sluggishness. Detailed inspection of system logs reveals a persistent background process hook intercepting API keystrokes and capturing authentication session cookies. Further analysis of network flow records demonstrates stealthy, recurring outbound connections over non-standard ports transferring the collected data to an external address, while no attempts to scan or infect adjacent hosts are detected. Which of the following malware types and indicators of compromise are demonstrated in this incident? (Select TWO.)
Geçerli olan tümünü seçin
A network technician inspecting local subnet traffic notices a high volume of unsolicited Address Resolution Protocol (ARP) reply packets mapping the legitimate default gateway's IP address to an unknown host's MAC address. Which of the following network attacks is directly indicated by this activity?
A security analyst is establishing a vulnerability testing framework for a web application hosted in a staging environment. The framework requires two specific testing techniques: one method that actively interacts with the executing web application to identify runtime vulnerabilities like cross-site scripting, and another method that passively observes network traffic without injecting traffic or modifying state to identify unencrypted cleartext protocols. Which of the following security assessment methods should the analyst select to fulfill these requirements? (Select TWO.)
Geçerli olan tümünü seçin