Threats, Vulnerabilities, and Mitigations
490 soru
A security analyst investigates an alert on an infected corporate workstation. Endpoint telemetry shows that a user executed a file disguised as a legitimate printer driver update. Immediately after execution, the process initiated automated network probes on port 445 (SMB) to spread to adjacent unpatched systems without further user intervention. Which of the following malware classifications or behaviors are demonstrated in this scenario? (Select TWO.)
Geçerli olan tümünü seçin
A security technician is planning a vulnerability assessment for an enterprise segment that includes legacy operational technology (OT) devices highly sensitive to unexpected network traffic. The technician decides to implement passive vulnerability scanning rather than active scanning. Which TWO of the following statements correctly describe the primary characteristics of passive vulnerability scanning? (Select TWO)
Geçerli olan tümünü seçin
An IT technician is auditing an organization's legacy infrastructure to identify host and network vulnerabilities. Which TWO of the following technical conditions represent significant network or host architecture vulnerabilities that could allow unauthorized access or credential exposure? (Select TWO.)
Geçerli olan tümünü seçin
A security analyst evaluates an operational technology (OT) network segment and captures the following service enumeration and vulnerability assessment report for an embedded field controller:
Nmap scan report for 192.168.50.14 (HVAC Controller)
PORT STATE SERVICE VERSION
161/udp open snmp SNMPv1 (public community string enabled)
22/tcp open ssh OpenSSH 4.3 (Linux kernel 2.6.18 - vendor status: End-of-Life)
Host Assessment Alert: Kernel memory corruption vulnerability identified (No vendor patch available).
Based on the report, which of the following specific host and network vulnerabilities are directly present on this controller? (Select TWO.)
Geçerli olan tümünü seçin
A cybersecurity team is establishing security testing procedures across various stages of an enterprise application lifecycle and infrastructure deployment. Match each security testing method on the left with its corresponding operational characteristic or execution scenario on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
System telemetry and forensic logs from four compromised endpoints within an enterprise environment reveal distinct technical indicators of compromise (IoCs). Match each observed technical indicator on the left with its correct malware classification on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A security analyst is performing host and network triage following a security incident. Match each technical indicator of compromise (IoC) artifact to the correct malware classification.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A security posture assessment identified several vulnerability findings across an enterprise environment. Match each vulnerability finding on the left to its corresponding infrastructure exposure category on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A senior security engineering team is formalizing an enterprise security assessment policy spanning corporate workstations, custom web microservices, software build pipelines, and sensitive industrial control network segments. Match each security testing methodology on the left to the operational execution characteristic on the right that correctly defines its technical application.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A security analyst is performing a comprehensive assessment across an enterprise environment. Match each host, network, or infrastructure vulnerability scenario observed during the assessment to its corresponding vulnerability category.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
Match each enterprise technical assessment finding to its primary host, network, or architecture vulnerability classification.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
During a comprehensive threat landscape assessment for a global logistics management enterprise, the security operations team identified four distinct threat threat actor profiles active against the organization's ecosystem. Match each threat actor incident profile on the left with its defining combination of attributes, intent, and primary attack vector on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An administrator needs to perform a vulnerability scan on internal servers to accurately detect missing software patches without installing host software agents. Which of the following scanning methods should the administrator use?
A system administrator discovers that a server in the data center is running an operating system version for which the vendor has permanently discontinued all technical support and security updates. Which of the following host vulnerabilities best describes this situation?
During a proactive security audit of a mission-critical database server, a security engineer compares user-mode system monitoring logs with low-level kernel telemetry. Standard operating system process enumeration APIs display 48 active processes, but a direct memory analysis of kernel structures reveals an additional executive process block (EPROCESS) decoupled from the ActiveProcessLinks doubly linked list. The unlisted process actively hooks system calls to subvert detection. Which of the following malware classifications best describes this threat?
A municipal public transit organization discovers that its public announcement website was defaced with political slogans during an election cycle. Incident responders determine that the attacker utilized pre-built exploit scripts downloaded from an open forum, without customizing code or attempting to establish long-term persistence. Which of the following threat actor types is most likely responsible for this incident?
A security analyst at an e-commerce firm discovers unauthorized administrative access on an internal transactional database. Investigation reveals that the intruder gained access by compromising an automated software update pipeline managed by an external service contractor trusted by the organization. Which of the following attack vectors was primarily exploited to achieve initial access?
A security engineer is designing a vulnerability assessment strategy for a legacy medical telemetry network containing sensitive embedded firmware devices that crash when receiving unexpected port probes or high packet volumes. The organization must identify known software vulnerabilities and unauthorized device configuration changes without causing operational downtime or system instability. Which of the following security assessment methods should the engineer implement to meet these requirements?
Forensic examination of an compromised enterprise host reveals anomalous system behavior where administrative utilities fail to display running processes and active network sockets that are visibly present in raw memory captures. Further inspection demonstrates that kernel-level System Service Descriptor Table (SSDT) function pointers have been redirected to execute code in unallocated memory addresses, effectively intercepting and filtering operating system API responses. Which of the following malware classifications is primarily indicated by these technical indicators of compromise?
A financial services organization discovers an unauthorized persistent presence within its internal software build pipeline infrastructure. Analysis shows that the attackers compromised stolen code-signing certificates to sign custom fileless payloads, established covert command-and-control communication using DNS tunneling, and conducted low-and-slow exfiltration of proprietary quantitative trading models over an eight-month period without causing service disruption or demanding a ransom. Which threat actor classification and attribute profile are most consistent with this activity?