Threats, Vulnerabilities, and Mitigations
490 soru
An enterprise security architect is evaluating system hardening controls to address findings from a comprehensive technical vulnerability audit. Match each enterprise hardening practice on the left to its corresponding primary risk mitigation objective on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A security technician is tasked with implementing host-level hardening controls on enterprise web servers. Which of the following technical mitigation practices directly reduce the host's attack surface? (Select TWO.)
Geçerli olan tümünü seçin
An organization wants to immediately detect unauthorized modifications made to critical system configuration files on a server. Which of the following technical controls is MOST effective for this purpose?
An enterprise software vendor distributes signed firmware updates to industrial IoT controllers. A recent security audit reveals that while the vendor uses a 2048-bit RSA key for asymmetric signing, the update process relies on the SHA-1 hashing algorithm to compute message digests. Which of the following best describes the primary security risk created by using SHA-1 for digital signature generation?
A network security administrator is analyzing wireless performance logs after users report sudden network disconnection across an entire office floor. The administrator suspects a physical Radio Frequency (RF) jamming attack rather than an 802.11 deauthentication attack. Which of the following indicators specifically suggest an RF jamming attack is occurring? (Select TWO)
Geçerli olan tümünü seçin
A software developer is designing a web application search feature that queries a back-end database using user-supplied input. Which of the following software development practices is the most effective method to prevent SQL injection vulnerabilities in this application?
During a post-incident analysis of a compromised legacy industrial control jump server, security auditors discover that attackers leveraged an unquoted service path vulnerability combined with permissive folder write permissions to execute arbitrary code with SYSTEM privileges. The jump server cannot be immediately decommissioned or upgraded due to operational uptime dependencies. Which of the following mitigation strategies provides the MOST effective immediate technical control to prevent execution of unauthorized binaries in these writable paths while preserving host stability?
Network monitoring alerts show that a malicious binary on an infected host is actively scanning neighboring subnets over TCP port 445 and automatically exploiting a remote code execution vulnerability on adjacent systems. The malware spreads from machine to machine across the network without requiring any user action, social engineering, or credential theft, after which it encrypts local files and issues a ransom prompt. Which of the following malware classifications best describes this threat?
Match each enterprise host or infrastructure security scenario to the underlying vulnerability or architectural weakness it represents.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A security administrator must perform regular vulnerability assessments on production enterprise servers hosting critical database applications. The organization requires detailed visibility into missing OS security patches and host configuration compliance, but must avoid destabilizing active production services or triggering target account lockouts. Which vulnerability testing approach should the administrator implement to meet these requirements?
Match each observed wireless attack indicator on the left with its corresponding attack classification on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
During an infrastructure security review at an industrial design firm, security analysts discover that several senior hardware engineers were infected with malware after visiting a popular, highly niche third-party CAD community forum. Investigation reveals that threat actors compromised the forum server weeks earlier and modified its code to selectively deliver an exploit payload only to visitors originating from the design firm's corporate IP address range. Which social engineering vector did the threat actor primarily execute to target these specific employees?
During an application security assessment of an enterprise document ingestion pipeline, an analyst reviews crash logs and source code snippets from a C/C++ processing engine that parses uploaded XML metadata and binary graphics. The analysis reveals two distinct flaws:
1. Submitting a specially crafted payload containing `<!ENTITY xxe SYSTEM "file:///etc/passwd">` causes the engine to return confidential system files in the API response.
2. Submitting an image file with an inflated metadata length field causes the application to write incoming payload bytes past the allocated dynamic memory buffer, leading to process memory corruption and instability.
Which of the following software vulnerabilities are present in this ingestion pipeline? (Select TWO).
Geçerli olan tümünü seçin
A security administrator is reviewing findings from a static application security testing (SAST) tool scan on an enterprise web portal. The scan identified several software flaws caused by improper handling of user input. Which of the following software security practices directly mitigate input validation and injection vulnerabilities such as Cross-Site Scripting (XSS) and SQL Injection (SQLi)? (Select TWO.)
Geçerli olan tümünü seçin
An employee working in a public conference hall receives several unsolicited contact cards and pop-up text messages on their smartphone via Bluetooth. A subsequent investigation by an IT technician confirms that no files, credentials, or personal data were stolen or accessed from the device. Which of the following wireless attack indicators is described in this scenario?
A cybersecurity team at an automated pharmaceutical manufacturing plant is investigating a covert intrusion into their industrial control systems. The adversary maintained persistent access for eight months without detection, utilized proprietary zero-day exploits against specialized programmable logic controller (PLC) firmware, and subtly modified drug formulation parameters rather than attempting extortion or causing immediate system outages. Which TWO of the following threat actor attributes and attack vector characteristics are demonstrated in this scenario?
Geçerli olan tümünü seçin
A security analyst reviews host logs and process telemetry from an endpoint suspected of infection. The analyst notices unauthorized background screen captures being saved to a hidden directory and outbound HTTP POST requests transmitting encrypted archives to an unrated external IP address on port 443. Which of the following malware classifications and primary capabilities are indicated by these observed technical artifacts? (Select TWO.)
Geçerli olan tümünü seçin
A security analyst inspects a vulnerability scan report for an internal legacy application host. The report displays the following output:
Host: 10.12.8.44
Service: SMBv1 (Port 445/TCP)
Finding: Legacy file-sharing protocol active; vulnerable to remote code execution (MS17-010) and anonymous NULL session enumeration.
Risk Level: Critical
Which of the following actions represents the MOST effective host mitigation strategy to address this specific vulnerability?
A security analyst is investigating network monitoring alerts in a enterprise corporate office. Wireless packet captures and syslog entries show that client laptops are receiving spoofed 802.11 Deauthentication frames originating from a legitimate Access Point's BSSID. Immediately following disassociation, affected clients connect to a rogue access point broadcasting the corporate ESSID and prompting users for authentication via an insecure EAP-GTC protocol with an untrusted RADIUS server certificate. Which of the following statements correctly identify the attack mechanism and the most effective combination of technical controls to mitigate this threat? (Select TWO.)
Geçerli olan tümünü seçin
A security analyst is reviewing an audit report detailing cryptographic vulnerabilities identified across an enterprise network. Match each observed security incident or technical finding on the left with its underlying cryptographic weakness on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler