Courseiva

CAS-005 · domain

scenario questions

Practise CompTIA SecurityX (CAS-005) scenario questions practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

968 questions234 easy437 medium297 hard

Focused practice

Practice scenario questions questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about scenario questions

scenario questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common scenario questions exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All scenario questions questions (968)

Click any question to see the full explanation, or start a practice session above.

1

An organization uses an EDR solution and wants to detect ransomware that encrypts files and then deletes volume shadow copies. Which EDR detection technique would be most effective for this behavior?

Hard
2

A security administrator is configuring IPsec VPN between two sites. The data transmitted includes sensitive financial records. The administrator wants to ensure both confidentiality and integrity of the data, and also wants to authenticate the source. Which IPsec protocol and mode should be used?

Medium
3

A security team is implementing deception technology to detect attackers inside the network. They plan to deploy fake systems that appear vulnerable and attract attackers. Which of the following is an example of a honeytoken?

Easy
4

A security manager is reviewing a set of documents: an organizational security policy, a standard for encryption, a guideline for remote access, and a procedure for incident response. Which document is at the highest level in the policy hierarchy?

Medium
5

A security architect is designing a hybrid cloud environment where a web application hosted in AWS needs to securely access an on-premises database. The architect wants to minimize exposure to the internet and ensure encryption in transit. Which TWO techniques should the architect consider? (Choose two.)

Medium
6

Which phase of the incident response lifecycle involves removing the threat from the environment and restoring systems to normal operations?

Easy
7

A penetration tester is planning a test against a web application. The rules of engagement specify that the tester must not disrupt production services. Which TWO reconnaissance techniques are considered passive and would be appropriate for initial information gathering without impacting the target? (Select TWO.)

Easy
8

Which of the following is the BEST definition of a risk register?

Easy
9

A security operations center (SOC) analyst receives an alert from the SIEM indicating a user has logged into the corporate VPN from an unusual geographic location at 3 AM, which is outside the user's normal working hours. The user has not previously exhibited this behavior. Which advanced SIEM capability is most likely responsible for generating this alert?

Medium
10

An architect is designing a multi-factor authentication (MFA) solution for remote access. Which of the following is the STRONGEST form of second factor?

Hard
11

An organization is implementing a Secure Access Service Edge (SASE) architecture to support remote workers. Which key capability does SASE provide that traditional VPNs lack?

Medium
12

An organization wants to share threat intelligence with industry peers using a standardized format. Which of the following formats is specifically designed for representing structured threat information in a machine-readable way?

Easy
13

A security assessor is reviewing a containerized application. Which three of the following practices help secure the container runtime environment? (Select the three best options.)

Hard
14

Which THREE of the following are required by the NIST Cybersecurity Framework (CSF) for the 'Protect' function?

Hard
15

During a ransomware incident, the organization discovers that all production backups have been encrypted by the attacker. What is the most effective recovery approach?

Hard
16

A company is deploying IoT sensors that require secure firmware updates over the air (OTA). To ensure integrity and authenticity of the firmware, which of the following should be implemented?

Medium
17

A financial institution is required to comply with PCI DSS. A low-severity vulnerability is found in the cardholder data environment that would cost significant downtime to patch. What is the BEST course of action?

Easy
18

A network administrator is troubleshooting connectivity issues. Based on the exhibit, which of the following is true about the iptables rules?

Hard
19

Which of the following best describes the primary security benefit of using immutable infrastructure in a containerized environment?

Easy
20

A security engineer is evaluating options for securing firmware updates on IoT devices. Which TWO methods provide integrity verification of the update?

Medium
21

Which risk treatment option involves reducing the likelihood or impact of a risk through controls?

Easy
22

Which security metric measures the average time it takes to detect a security incident after it has occurred?

Easy
23

A security analyst is analyzing a memory dump from a compromised host using Volatility. Which Volatility plugin would be most useful to identify a malicious process that is hidden from the standard process listing?

Medium
24

A security architect is designing a new authentication system for a high-security environment. The system must support passwordless authentication while providing strong protection against phishing attacks. Which of the following protocols best meets these requirements?

Medium
25

A threat hunter wants to identify potential lateral movement within the network. Which data source is LEAST useful for this purpose?

Medium
26

An organization is implementing a DevSecOps pipeline. Which of the following are essential security controls to include? (Select TWO.)

Medium
27

During a routine vulnerability scan, a security engineer discovers that a critical web application is running an outdated version of a third-party library with a known remote code execution (RCE) vulnerability. The application is in production and cannot be taken offline immediately. Which of the following is the BEST immediate action to reduce risk?

Medium
28

Which TWO of the following are considered secure design principles for cryptographic systems?

Medium
29

A security engineer is designing a secure hybrid cloud connection between an on-premises data center and AWS. Which service provides a dedicated, private network connection that bypasses the public internet?

Medium
30

A security architect is evaluating a new cloud-based application that will process sensitive customer data. The architect must ensure compliance with GDPR and PCI DSS. Which THREE of the following controls should be implemented? (Select THREE.)

Hard
31

A company is adopting container security best practices. Which TWO actions should be implemented to reduce the attack surface of container images? (Select TWO.)

Medium
32

A company is designing a new multi-tier web application. The security team recommends placing a web application firewall (WAF) in front of the web servers and a network firewall between the web and application tiers. Which security architecture principle does this represent?

Easy
33

A security architect is designing a data classification scheme. Which TWO of the following are commonly used classification levels? (Select TWO.)

Medium
34

A security analyst is using the MITRE ATT&CK framework to categorize adversary behavior observed in recent incidents. The analyst notes that the adversary used spearphishing with a malicious attachment to gain initial access, then executed a PowerShell script to download additional tools. Which ATT&CK tactic is the PowerShell execution associated with?

Medium
35

A security engineer is deploying a wireless network for a high-security facility. Which protocol should be used to provide the strongest authentication and encryption for client devices?

Medium
36

An organization is evaluating a third-party vendor that will have access to its customer database. The vendor provides a SOC 2 Type II report dated six months ago. Which of the following is the BEST next step?

Medium
37

A security architect is designing a cryptographic system for a government agency that must protect classified data for the next 30 years. The agency is concerned about the threat from quantum computers. Which NIST post-quantum cryptography algorithm is recommended for key encapsulation?

Medium
38

A company is designing a secure communication channel between two branch offices over the internet using IPsec. Which TWO statements are true regarding IPsec modes and protocols? (Select TWO.)

Medium
39

A security architect is reviewing the network security controls for a critical industrial control system (ICS) environment. The architect must select two controls that are most effective at preventing unauthorized access to the ICS network from the corporate IT network, while still allowing necessary monitoring traffic. Which TWO controls should be implemented? (Choose two.)

Hard
40

A security architect is evaluating web application firewall (WAF) features to protect against common attacks. Which TWO of the following attacks can a WAF most effectively prevent?

Medium
41

A security analyst is conducting a penetration test for a client. The rules of engagement specify that no social engineering is allowed. Which TWO of the following reconnaissance techniques are permitted under these rules?

Medium
42

An analyst needs to automate the extraction of indicators of compromise (IOCs) from log files generated by various systems. Which scripting language is most commonly used for cross-platform log parsing and automation due to its extensive library support?

Easy
43

An organization needs to ensure that evidence collected during a forensic investigation remains intact and admissible in court. Which process is most critical for maintaining the integrity of digital evidence?

Easy
44

A company is deploying a web application in a containerized environment. The security team wants to ensure that the application runs with the least privilege necessary. Which of the following is the BEST approach to achieve this?

Medium
45

During a digital forensics investigation of a compromised Linux server, the investigator needs to preserve the evidence in a forensically sound manner. The server is still running. Which of the following should the investigator do first?

Medium
46

Which two of the following are effective mitigations against XML External Entity (XXE) injection attacks? (Select the two best options.)

Medium
47

Refer to the exhibit. A security administrator finds this IAM policy attached to a Lambda execution role. What is the most critical security risk?

Easy
48

Match each authentication protocol or method to its characteristic.

Medium
49

A security team is implementing a threat intelligence program and wants to consume intelligence from various sources. Which TWO of the following are commonly used threat intelligence feeds or sharing mechanisms? (Select TWO.)

Medium
50

A security analyst is reviewing threat intelligence feeds and notices that a known Advanced Persistent Threat (APT) group has been using a specific technique to move laterally within networks. The analyst wants to map this technique to the MITRE ATT&CK framework. Which resource would the analyst use to find the corresponding ATT&CK technique ID?

Medium
51

A security analyst is investigating a phishing campaign targeting the organization. The threat intelligence team has provided indicators such as email subject lines, sender domains, and attachment hashes. However, the analyst notices that these IOCs change rapidly and are only effective for a short period. Which type of threat intelligence would provide more durable and actionable information for defending against this campaign?

Medium
52

A vulnerability scanner reports a critical vulnerability on a critical server with a CVSS v3.1 base score of 9.8. The server cannot be patched immediately due to vendor constraints. Which of the following should the security team implement as a compensating control?

Easy
53

A security architect is designing a public key infrastructure (PKI). Which component is responsible for issuing and revoking certificates?

Medium
54

A company is implementing a new cloud-based SaaS application and needs to ensure compliance with GDPR. The security team is tasked with updating the data protection impact assessment (DPIA). Which of the following should the team prioritize?

Easy
55

Which of the following is a secure method for storing secrets (e.g., API keys, passwords) in a cloud-native application?

Easy
56

An organization wants to implement a solution that ensures data cannot be read if a storage device is physically stolen. Which encryption approach BEST meets this requirement?

Easy
57

A large financial organization is migrating its on-premises authentication infrastructure to a cloud-based identity provider (IdP) to support a hybrid workforce. Currently, on-premises Active Directory is used with smart cards for authentication. The cloud IdP will support SAML 2.0 and OAuth 2.0. The security team requires that all authentication to cloud applications be protected by hardware-backed keys and that user credentials never leave the on-premises network. The solution must also support FIDO2 authentication for passwordless logins. During a pilot, users report that after authenticating to the cloud IdP using their smart cards, they are prompted again for credentials when accessing certain cloud applications. The logs show that the cloud IdP is issuing multiple authentication requests to the on-premises AD Federation Services (AD FS). The CISO is concerned about performance and security of repeated authentication. As a security architect, what is the best course of action?

Easy
58

A company uses an API gateway to manage their microservices. Which security control should the gateway enforce to prevent abuse from excessive API calls?

Medium
59

Which of the following is a key principle of the zero trust security model?

Easy
60

A financial institution is adopting a new vendor-managed SaaS platform for customer data processing. The CISO wants to ensure the vendor's security controls meet regulatory requirements before data is transferred. Which of the following should be completed FIRST?

Medium
61

A security analyst is reviewing a malware sample in a sandbox environment. The analyst notes that the malware attempts to check for the presence of a debugger and modifies its behavior if one is detected. Additionally, the malware uses encrypted strings and resolves API calls dynamically. Which THREE analysis techniques would be most effective for understanding this malware's capabilities? (Select THREE.)

Hard
62

A company is implementing continuous compliance monitoring for PCI DSS. Which TWO activities are most appropriate for this approach? (Select TWO.)

Medium
63

An organization is concerned about side-channel attacks on its embedded devices. Which of the following is the MOST effective countermeasure against power analysis attacks?

Medium
64

Which of the following risk treatment options involves transferring the financial impact of a risk to a third party, such as through insurance?

Easy
65

A security architect is designing a web application that handles sensitive user data. To protect against cross-site scripting (XSS) attacks, which of the following should be implemented?

Medium
66

A security team is preparing for a penetration test. Which document defines the scope, rules, and restrictions for the test?

Easy
67

A security architect is evaluating hardware security modules (HSMs) for a new PKI deployment. The HSM must be compliant with FIPS 140-2 Level 3. Which of the following is a requirement for Level 3 that distinguishes it from Level 2?

Hard
68

A security team is deploying deception technology to detect lateral movement within the network. They plan to use honeypots configured to mimic critical servers. Which TWO of the following are essential considerations for the honeypot deployment to be effective? (Choose TWO.)

Medium
69

An organization is planning to adopt quantum-resistant cryptography. According to NIST PQC standards, which algorithm is recommended for digital signatures?

Medium
70

A large enterprise has deployed a security information and event management (SIEM) system that ingests logs from all critical servers, network devices, and endpoints. The SIEM is configured to correlate events and generate alerts for suspicious activities. Recently, the SOC team has been overwhelmed by a high volume of false positive alerts, particularly from the web server farm. The false positives are mainly triggered by legitimate web crawling and scanning activities from partners and internal tools. The SOC manager wants to reduce false positives without missing real threats. As the security architect, you are asked to recommend a solution. Which of the following is the BEST course of action?

Hard
71

A security engineer is configuring IPsec VPN between two sites. The requirement is to encrypt the entire IP packet, including the original IP header. Which IPsec mode and protocol should be used?

Hard
72

A security engineer is deploying a Cloud Access Security Broker (CASB) to protect a SaaS application. Which deployment mode allows the CASB to inspect encrypted traffic without requiring client software?

Hard
73

During a penetration test, the tester has obtained a foothold on an internal server. The tester wants to identify other systems on the network and find potential targets for lateral movement. Which type of reconnaissance is MOST appropriate in this scenario?

Medium
74

A container orchestration platform uses secrets management. Which two methods are recommended for injecting secrets into containers? (Choose two.)

Hard
75

A security engineer is tasked with designing a cryptographic solution to protect data at rest in a multi-tenant cloud storage system. Each tenant's data must be encrypted with a unique key, and the system must support key rotation with minimal performance impact. Which of the following is the BEST approach?

Hard
76

Refer to the exhibit. A system administrator creates a systemd service to run a daily patching script. Which security concern is most prevalent?

Hard
77

During a compliance audit, an organization discovers that its backup data for a critical database is stored in an unencrypted format on a tape that is kept offsite. The organization's data protection policy requires encryption of all data at rest. Which of the following is the BEST remediation action?

Medium
78

A multinational corporation that processes personal data of EU residents is required to appoint a Data Protection Officer (DPO) and implement data protection impact assessments. Which regulation primarily drives these requirements?

Easy
79

A security analyst needs to ensure that only authorized containers run in a Kubernetes cluster. Which Kubernetes native security control should be configured?

Easy
80

A company is migrating its on-premises ERP system to a public cloud IaaS environment. The ERP system contains sensitive financial data. Which of the following architectural changes best maintains data security during and after migration?

Medium
81

During a digital forensics investigation, an analyst is examining a Windows system suspected of being compromised. Which THREE of the following artifacts would be most useful for determining the timeline of the attack?

Hard
82

An organization is implementing a Windows Hello for Business deployment to enable passwordless authentication. The solution uses TPM 2.0 for key storage. Which of the following TPM features ensures that the system has not been tampered with before the user authenticates?

Medium
83

A company wants to ensure that a third-party vendor allows them to perform an audit of the vendor's security controls. Which clause should be included in the contract?

Easy
84

A SOC team uses a SOAR platform to automate incident response. They want to ensure that playbooks run with minimal human intervention but still require approval for actions that could cause service disruption. Which approach should be used?

Hard
85

An organization is evaluating risk treatment options for a critical vulnerability with a CVSS score of 9.8. The cost to remediate is $500,000, and the potential loss if exploited is estimated at $2,000,000. Which risk response is most appropriate?

Medium
86

An organization is implementing a data classification scheme. Which data type should be given the highest protection and is typically restricted to a very small number of individuals?

Medium
87

A company is implementing a defense-in-depth strategy for its web application. Which THREE of the following are layers that should be included? (Select THREE.)

Easy
88

Which TWO of the following are secure coding practices to prevent SQL injection?

Medium
89

A company is conducting a vendor risk assessment and receives a SOC 2 Type II report from a cloud service provider. The report covers a 12-month period and includes an opinion on the effectiveness of controls. Which of the following is the primary benefit of using this report?

Hard
90

A security analyst is reviewing an AppArmor profile for an application. Based on the exhibit, which action would the application be denied?

Medium
91

When conducting a vendor risk assessment, which contractual clause is most important for ensuring ongoing visibility into the vendor's security posture?

Medium
92

A security architect is reviewing a Secure Access Service Edge (SASE) implementation. Which component of SASE provides security inspection for all traffic, regardless of location?

Medium
93

A security architect is designing a secure boot chain for an IoT device. Which THREE components are essential to ensure the integrity of the firmware update process? (Select THREE.)

Medium
94

A company is evaluating a vendor that will process sensitive customer data. The vendor's SOC 2 Type II report shows that controls were in place but had several exceptions noted. Which of the following is the BEST course of action?

Medium
95

A company wants to protect its intellectual property stored on a file server. The security architect proposes implementing rights management services (RMS) integrated with Active Directory. Which attack is this architecture primarily designed to mitigate?

Hard
96

A security architect is designing a data classification scheme. Which of the following is the highest level of sensitivity that would typically require the most stringent controls?

Medium
97

A network administrator needs to establish a secure VPN tunnel between two branch offices using IPsec. The requirement is to encrypt the entire IP packet, including the original IP header. Which IPsec mode should be used?

Easy
98

Given the exhibit, what is the effect of this S3 bucket policy on an object stored in 'bucket-name'?

Medium
99

A security architect is evaluating a new SIEM solution for a large enterprise. Which THREE of the following capabilities are CRITICAL for effective threat detection and response? (Choose three.)

Hard
100

An organization is implementing IPsec VPNs between sites. The security team wants to ensure data integrity and authentication but is less concerned about confidentiality for this particular link. Which IPsec protocol and mode should they use?

Medium
101

A security analyst notices repeated failed login attempts from a single IP address across multiple user accounts. Which of the following is the BEST immediate action to mitigate this attack?

Medium
102

A security engineer is analyzing a serverless application that uses AWS Lambda. Which of the following is the most critical security concern when the function processes external input?

Hard
103

A security engineer must select a cryptographic algorithm to ensure non-repudiation for digitally signed documents. Which algorithm is most appropriate?

Easy
104

During a business continuity planning meeting, the team identifies several critical systems. Which THREE of the following are key components of a Business Impact Analysis (BIA)? (Select THREE.)

Hard
105

An organization is migrating sensitive customer data to a public cloud. Which of the following actions best demonstrates due diligence for compliance with GDPR?

Medium
106

A security architect reviews the iptables firewall rules above. A new web server with IP 192.168.1.100 must be reachable from the internet on ports 80 and 443. Which of the following changes is necessary to allow inbound HTTPS while maintaining security?

Medium
107

A security analyst needs to write a script that detects changes to critical files across a fleet of Linux servers. Which approach is most efficient and secure?

Medium
108

An organization uses a hardware security module (HSM) to protect cryptographic keys. Which aspect of key management does an HSM primarily address?

Medium
109

Based on the iptables exhibit, a security analyst has received an alert that an external IP (203.0.113.5) is attempting to connect to TCP port 3389 on the server. Which of the following best describes the current rule set's treatment of this traffic?

Medium
110

A company is migrating its internal services to use SSH key-based authentication instead of passwords. The security policy requires using the strongest supported algorithms. The SSH server supports the following key exchange algorithms: diffie-hellman-group14-sha256, ecdh-sha2-nistp384, curve25519-sha256. Which algorithm should the administrator choose to meet the policy?

Medium
111

A security analyst is reviewing metrics for the security program. Which metric best measures the effectiveness of incident response processes?

Medium
112

A security architect is designing a network segmentation strategy for a multi-tenant cloud environment. Which of the following is the MOST effective technique to isolate tenant workloads while maintaining manageability?

Medium
113

A company uses a CI/CD pipeline with Jenkins to build and deploy containerized applications. Security scanning of container images is currently done manually after deployment, causing delays. Which of the following would be the most effective automation to improve security and efficiency?

Medium
114

A security engineer needs to implement a solution that provides both confidentiality and integrity for data at rest. Which cryptographic method BEST meets these requirements?

Easy
115

A company is evaluating its disaster recovery plan. Which metric indicates the maximum acceptable downtime?

Easy
116

A security engineer is reviewing firewall logs and finds multiple failed SSH attempts from an internal IP. Which control should be implemented to reduce this risk?

Easy
117

A security architect is designing a secure enclave for processing classified data. Which TWO of the following controls are essential for ensuring data confidentiality in such an enclave? (Select TWO.)

Medium
118

A company is deploying a wireless network for guests. Which security measure is most important to prevent unauthorized users from accessing internal resources?

Easy
119

Which of the following are accurate descriptions for the given container security concepts? (Select all that apply.)

Hard
120

A security operations center (SOC) analyst is investigating an alert from an EDR tool indicating that a workstation executed a suspicious PowerShell command that decoded a base64 string. The decoded string contained a command to download a file from an external IP address. Which stage of the cyber kill chain does this activity most likely represent?

Medium
121

A security architect is reviewing the network architecture of a financial trading system. The system uses a time-sensitive order matching engine that must process trades with minimal latency. The architect is concerned about the risk of a DDoS attack on the matching engine. Which of the following architectural changes would best mitigate DDoS risk while preserving low latency?

Hard
122

A company's risk assessment identifies that employees often use weak passwords. Which control directly addresses this risk?

Easy
123

A security analyst is reviewing a CI/CD pipeline configuration. The pipeline uses a containerized application and includes automated security scanning. Which TWO practices should be implemented to ensure container immutability and reduce the attack surface?

Easy
124

An organization is merging with another company and needs to ensure that the combined entity's security policies are aligned. Which document type should the security team prioritize to harmonize security expectations and responsibilities?

Medium
125

A company wants to ensure that its data handling practices align with the principle of 'privacy by design'. Which of the following actions best supports this principle?

Easy
126

A security architect is evaluating cloud security architectures. The company requires that all data at rest in a public cloud object storage bucket be encrypted with a key that is managed by the company's own hardware security module (HSM) on-premises. Which encryption approach should the architect recommend?

Easy
127

A security analyst observes anomalous outbound network traffic from a server that normally only performs internal functions. According to the incident response plan, what should the analyst do first?

Easy
128

A security analyst is reviewing threat intelligence feeds and notices indicators from a known APT group. Which threat intelligence sharing standard is most commonly used to structure and share such cyber threat information in a machine-readable format?

Easy
129

A security architect is evaluating cryptographic agility for a system that must be resistant to quantum computing attacks. Which TWO algorithms are part of the NIST PQC standards? (Select TWO.)

Medium
130

A security analyst is defining key risk indicators (KRIs) for the security program. Which TWO of the following are examples of KRIs? (Select TWO.)

Easy
131

A security engineer is evaluating the use of AES-256-GCM for encrypting sensitive data in transit. They note that the Additional Authenticated Data (AAD) field is empty. What is the security implication?

Medium
132

A company deploys a microservices architecture using container orchestration. The security team wants to enforce mutual TLS between services. Which technology should be used?

Hard
133

Which THREE of the following are common challenges when implementing a vendor risk management program? (Select THREE)

Medium
134

A security architect is designing a web application that handles sensitive customer data. The application must ensure that if one server is compromised, the attacker cannot access the private keys used for TLS termination. Which of the following approaches best meets this requirement?

Easy
135

Which automation security concept coordinates the deployment, scaling, and management of containers?

Hard
136

A security administrator is implementing TPM 2.0 for secure boot and measured boot on new laptops. Which TWO capabilities does TPM 2.0 provide that are directly related to ensuring the integrity of the boot process? (Select TWO.)

Medium
137

During an incident response, the team identifies that an attacker gained initial access via a phishing email containing a malicious macro. The macro downloaded a payload from a remote server. Which phase of the incident response lifecycle is currently being executed when the team identifies the phishing email as the attack vector?

Medium
138

A SOC analyst is tuning a SIEM correlation rule to detect lateral movement. The rule currently triggers on a single failed authentication followed by a successful authentication from a new IP address within 5 minutes. Which improvement would best reduce false positives while maintaining detection of pass-the-hash attacks?

Hard
139

An organization wants to implement a hardware security module (HSM) to protect cryptographic keys. Which of the following is a primary benefit of using an HSM?

Easy
140

A company needs to connect its on-premises data center to a public cloud provider with low latency and high bandwidth while avoiding the public internet. Which connectivity method should be used?

Medium
141

Which TWO of the following are key benefits of using a software-defined perimeter (SDP) in a zero trust architecture? (Select TWO.)

Easy
142

An organization is implementing a threat hunting program. The team plans to use the MITRE ATT&CK framework to structure their hunts. Which THREE of the following are core components of the ATT&CK framework? (Choose THREE.)

Easy
143

A multinational corporation is migrating its data centers to a hybrid cloud model. The security team must ensure that data sovereignty laws are respected. The company operates in the EU, US, and Asia. Which of the following is the BEST approach?

Medium
144

A security analyst is calculating the annualized loss expectancy (ALE) for a server that has an asset value of $50,000 and an exposure factor (EF) of 0.2. The annualized rate of occurrence (ARO) is estimated at 4. What is the ALE?

Easy
145

A security engineer is designing a secure communication channel between two internal systems over an untrusted network. Which protocol should be used to ensure both confidentiality and integrity of data in transit?

Easy
146

An organization wants to ensure that its employees understand their responsibilities regarding data protection. Which of the following is the MOST effective way to achieve this?

Easy
147

A security engineer is designing a secure wireless network for a corporate office. Which TWO configurations should be implemented to maximize security?

Medium
148

A security architect is designing a defense-in-depth strategy for a cloud-native application. Which TWO controls are most effective for protecting east-west traffic between microservices?

Medium
149

A security analyst is investigating a malware sample found on a workstation. The analyst wants to determine the malware's capabilities without executing it. Which type of malware analysis involves examining the binary's strings, headers, and structure?

Easy
150

A security architect is designing a supply chain security program. Which TWO of the following are essential components of a software bill of materials (SBOM) strategy? (Select TWO.)

Medium
151

Which TWO of the following are key components of a risk assessment methodology?

Medium
152

Which hashing algorithm is recommended for modern applications requiring high security and resistance to quantum computing threats, and offers improved performance over SHA-2?

Easy
153

Which THREE of the following are common vulnerabilities found in web applications according to the OWASP Top 10 2021? (Select THREE.)

Medium
154

Refer to the exhibit. A security engineer reviews the S3 bucket policy. Which of the following is the most concerning security issue?

Medium
155

An organization is architecting a hybrid cloud environment with AWS and on-premises resources. Which THREE considerations are essential for meeting data residency requirements? (Choose three.)

Hard
156

An organization is adopting a cloud-first strategy and needs to ensure compliance with SOC 2. Which cloud service model places the most responsibility on the customer for security?

Easy
157

A company is deploying IoT sensors in a remote area with limited connectivity. The sensors must be able to securely transmit data using minimal bandwidth. Which protocol should the engineer choose?

Medium
158

During a security review, it is discovered that a critical application uses hardcoded cryptographic keys. The development team refactors the code to retrieve keys from a centralized key management system (KMS) using role-based access control. Which additional practice should be implemented to minimize the risk of key compromise?

Hard
159

An organization implements a CI/CD pipeline that automatically builds and deploys containerized microservices. Which of the following is the most effective method to ensure that only signed, trusted container images are deployed to production?

Hard
160

An organization deploys a new web application that stores sensitive data in a backend database. During a penetration test, the tester discovers that the application is vulnerable to SQL injection via a search field. Which of the following design changes would best mitigate this vulnerability without significantly impacting functionality?

Hard
161

A multinational corporation is subject to GDPR and the California Consumer Privacy Act (CCPA). A security architect is designing a data governance solution to meet both regulations. Which TWO controls are most appropriate?

Hard
162

During a malware analysis, an analyst runs a suspicious binary in a sandbox and observes that it attempts to communicate with a known malicious IP address, modifies registry keys, and creates a service. The analyst then extracts strings from the binary and finds references to a specific C2 server. Which analysis phase does the extraction of strings represent?

Hard
163

A company's risk register shows a high-likelihood, high-impact risk related to ransomware. The cost to mitigate fully is $2M, while the expected annual loss is $500K. Which risk response is most appropriate?

Hard
164

An organization is unable to patch a critical vulnerability in a legacy application due to vendor limitations. The risk assessment indicates a high likelihood of exploitation. Which compensating control should the organization implement to reduce the risk?

Medium
165

A security administrator needs to secure remote access for employees using personal devices. The company requires that company data be encrypted and that the device be wiped if lost. Which solution best meets these requirements?

Easy
166

Based on the exhibit, which vulnerability is being exploited?

Easy
167

A company is migrating from a legacy three-tier architecture to a microservices architecture on Kubernetes. The security team wants to ensure that service-to-service communication is encrypted and mutually authenticated. Which approach best meets these requirements with minimal operational overhead?

Hard
168

A security architect is designing a secure software development pipeline. The organization wants to ensure that code is thoroughly analyzed before deployment. Which TWO of the following should be integrated into the pipeline to identify vulnerabilities early? (Select TWO.)

Medium
169

Under the GDPR, which of the following is a data subject right?

Easy
170

During a security incident, a forensic investigator needs to acquire volatile data from a compromised server. Which of the following is the correct order for collecting volatile data according to the standard digital forensics process?

Medium
171

A security analyst receives an alert indicating an internal host is sending outbound traffic on TCP port 25 to multiple external IP addresses. Which action should the analyst take first to investigate potential data exfiltration?

Easy
172

An organization is migrating to an immutable infrastructure model for its containerized applications. Which practice is essential to ensure the integrity of the immutable infrastructure?

Hard
173

A company is implementing MFA for remote access. Which TWO factors are considered possession factors?

Easy
174

An organization is deploying a new application that processes sensitive user data. The security team recommends using a dedicated cryptographic module. Which standard should the module comply with to ensure it is validated for security?

Easy
175

A penetration tester is performing an assessment of a web application. During reconnaissance, the tester discovers a publicly accessible Jenkins server with default credentials. The tester gains access and finds a build job that executes arbitrary commands. What is the most effective way for the tester to escalate privileges and move laterally within the network?

Hard
176

A security engineer is implementing container security controls. Which TWO practices are most effective in preventing privilege escalation within a container? (Choose two.)

Medium
177

A web server is configured to use TLS 1.3. Which of the following is a key security benefit of TLS 1.3 over earlier versions?

Easy
178

Which cryptographic best practice ensures that a private key remains protected even if the server it is stored on is compromised?

Easy
179

A company's incident response team is conducting a post-incident review. They identify that the intrusion was not detected for 72 hours due to insufficient logging on critical servers. Which phase of the incident response lifecycle should be improved to address this gap?

Medium
180

A DevOps team is automating the deployment of a containerized application to production. Which THREE practices are essential for maintaining security and reliability? (Select THREE.)

Medium
181

An organization is deploying hardware security modules (HSMs) to protect cryptographic keys used for digital signatures. Which attack vector is most effectively mitigated by using an HSM compared to storing keys in software?

Medium
182

A company's web application uses single sign-on (SSO) via SAML. Security analysts notice that attackers are able to forge SAML responses to impersonate users. Which misconfiguration is most likely causing this vulnerability?

Hard
183

A security engineer is selecting an asymmetric encryption algorithm for a system that must provide non-repudiation and long-term security (at least 20 years). The system has limited computational resources. Which of the following is the best choice?

Medium
184

A security team needs to implement a CI/CD pipeline that automatically scans container images for vulnerabilities before deployment. Which tool can be integrated into the pipeline for this purpose?

Medium
185

A company is migrating to AWS and needs to comply with SOC 2. Which cloud-native service would BEST help monitor and enforce security configurations across the AWS environment?

Medium
186

A multinational corporation is implementing a privacy program that must comply with both GDPR and CCPA. Which approach to privacy impact assessments (PIAs) is most appropriate?

Hard
187

A company is implementing a Privileged Access Management (PAM) solution to manage admin credentials. Which feature allows administrators to request temporary elevated access for a specific task?

Medium
188

A small business wants to achieve compliance with PCI DSS. Which approach should they take to minimize the scope of the assessment?

Easy
189

A SOC analyst is investigating a potential data exfiltration incident. The analyst suspects that an attacker used DNS tunneling to exfiltrate data. Which THREE network traffic indicators would support this hypothesis? (Select THREE.)

Medium
190

A company is implementing measured boot using TPM 2.0. What is the primary purpose of storing boot measurements in Platform Configuration Registers (PCRs)?

Medium
191

A company wants to ensure that a compromised root CA does not affect the validity of previously issued certificates. Which PKI control should be implemented?

Medium
192

A security analyst is reviewing a suspicious executable file. The analyst performs static analysis by examining the file's strings and imports. Which of the following findings would most strongly suggest the file is packed or obfuscated?

Medium
193

A multinational corporation must comply with both the EU's GDPR and the California Consumer Privacy Act (CCPA). Which of the following scenarios would cause a conflict between these regulations?

Hard
194

In a zero trust architecture, which concept ensures that an attacker who compromises one segment cannot move laterally to other segments?

Easy
195

Which of the following best describes the purpose of the STIX and TAXII standards in threat intelligence sharing?

Easy
196

A security analyst is prioritizing remediation of vulnerabilities. Which three of the following factors should be considered when determining the risk level of a vulnerability? (Choose three.)

Hard
197

A security architect is designing a Kubernetes cluster for a government agency that requires high security and compliance with FedRAMP. The cluster will host microservices processing sensitive data. Which TWO configurations are most critical for hardening the Kubernetes environment? (Choose TWO.)

Hard
198

A security engineer is reviewing a CI/CD pipeline that builds a Docker image. The engineer notices that the Dockerfile uses a base image from a public registry, installs packages via apt-get without version pinning, and copies a private SSH key into the image. Which of the following vulnerabilities is MOST directly introduced by this practice?

Hard
199

A healthcare organization has suffered a ransomware attack. The ransomware encrypted all files on file servers and workstations, and a ransom note demands payment in cryptocurrency. The backup systems were also encrypted because the backup service account had write access to the backup repository. The organization's cybersecurity team has activated the incident response plan. Which of the following is the BEST course of action?

Medium
200

An organization wants to implement a zero-trust architecture for remote access. Which of the following is the MOST important component?

Easy
201

A security engineer is configuring a SIEM and wants to reduce false positives while ensuring that real attacks are detected. Which of the following approaches would best achieve this balance?

Medium
202

A security architect is designing a new web application that must meet strict data confidentiality and integrity requirements. The application will run in a cloud environment and must support low-latency operations. The architect is considering cipher suites for TLS 1.3. Which combination of algorithms would best meet these requirements?

Medium
203

Which TWO of the following are key elements of a data classification policy?

Medium
204

Which TWO of the following are essential elements of an effective data governance framework?

Medium
205

You are the compliance officer for a financial institution that must adhere to the Payment Card Industry Data Security Standard (PCI DSS). During a quarterly vulnerability scan, you discover that several critical vulnerabilities in the cardholder data environment (CDE) were not remediated within the required 30-day window. Additionally, the most recent penetration test report shows that a segmentation control between the CDE and the corporate network is not functioning as intended. The next PCI DSS assessment is in two months. Which of the following remediation actions should be prioritized FIRST to maintain compliance?

Medium
206

An organization is migrating a legacy application to a containerized environment. The application requires root privileges to bind to a low port (80). What is the most secure approach to handle this requirement?

Medium
207

A SOC team is implementing a SOAR platform to automate responses to phishing emails. The team wants to create a playbook that, upon detection of a phishing email, automatically quarantines the email from all mailboxes and blocks the sender's domain. Which type of playbook action is being described?

Medium
208

A vulnerability management team is prioritizing patches for a large number of vulnerabilities discovered in a quarterly scan. A critical vulnerability in a widely used application has a CVSS base score of 9.8, but it is not currently being exploited in the wild and the application is not directly exposed to the internet. According to CVSS scoring principles, which factors should the team consider to adjust the priority?

Medium
209

A security administrator needs to automate the process of revoking access for terminated employees across multiple cloud services. Which scripting approach would best minimize the risk of errors and ensure consistent execution?

Easy
210

A company is implementing a zero trust architecture. Which of the following BEST describes the principle of micro-segmentation in this model?

Medium
211

An organization wants to implement passwordless authentication for its employees using FIDO2/WebAuthn. What is a primary security advantage of this approach over traditional password-based MFA?

Medium
212

A security engineer is hardening a container image. Which practice is MOST effective in reducing the attack surface?

Medium
213

A security team is hardening a Kubernetes cluster. Which resource should be used to define fine-grained rules for which pods can communicate with each other?

Medium
214

A security analyst reviews the above Windows security events from a domain controller. What is the most likely conclusion about the activity?

Hard
215

An organization is deploying a cloud workload protection platform (CWPP). Which TWO capabilities are essential for protecting workloads in a hybrid cloud?

Medium
216

A security architect is designing a segmentation strategy for a multi-tier web application. The public-facing web servers must communicate only with application servers, and application servers must communicate only with database servers. The architect wants to use a firewall that can inspect application-layer traffic to prevent SQL injection attacks. Which firewall type should be deployed between the application tier and the database tier?

Medium
217

The security engineer notices that SSH login attempts to 192.168.1.1 from the untrust zone are being blocked. Which policy misconfiguration is MOST likely causing this?

Medium
218

Based on the exhibit, what type of attack is most likely occurring?

Hard
219

During a security audit, it was discovered that an application uses RSA with 1024-bit keys for encrypting sensitive data. The organization's security policy mandates a minimum of 128-bit symmetric equivalent security. Which of the following should be recommended as a replacement?

Hard
220

An organization plans to establish a cross-forest trust between two Active Directory forests to enable resource access. The security architect is concerned about the risk of privilege escalation from a compromised domain in one forest. Which design choice best mitigates this risk?

Hard
221

An organization discovers that a third-party vendor has a subcontractor that processes its data. The organization did not have a contract with the subcontractor. This is an example of which type of risk?

Medium
222

A security team is selecting key risk indicators (KRIs) for the organization's cybersecurity program. Which of the following is an example of a KRI that provides a leading indicator of risk?

Medium
223

An organization is implementing a vulnerability management program and needs to prioritize patching based on risk. The team has identified multiple vulnerabilities with different CVSS scores. Which THREE factors should be considered when prioritizing patches according to CVSS environmental metrics? (Choose THREE.)

Easy
224

Which TWO of the following are best practices for securing a database server?

Easy
225

An organization has implemented a zero-trust architecture for its mobile workforce. Employees use company-managed smartphones to access internal applications through a reverse proxy. Recently, users report that they are frequently prompted to re-authenticate, causing workflow interruptions. The security team wants to maintain zero-trust principles while improving the user experience. Analysis shows that session tokens are being revoked after a short idle timeout. Which adjustment should the security team implement to balance security and usability?

Hard
226

A security operations center (SOC) is evaluating a new EDR solution. Which three capabilities are essential for effective endpoint detection and response? (Select THREE).

Hard
227

During an incident response, a team is prioritizing containment actions. Which THREE of the following actions should be taken to contain the incident effectively?

Hard
228

A cloud security team uses AWS and has configured a virtual private cloud (VPC) with a public subnet for a web application. The web servers in the public subnet have security groups that allow inbound HTTP/HTTPS from 0.0.0.0/0. The security team receives an alert that an EC2 instance in the public subnet is making outbound connections to an IP address that is listed on a threat intelligence feed as a known mining pool. The instance's security group allows all outbound traffic. The team suspects the instance is compromised and running cryptocurrency mining malware. Which of the following should be the FIRST action to take?

Medium
229

A security architect is designing a cloud security strategy for a company that uses multiple cloud providers. The architect needs a solution that provides visibility into cloud application usage, enforces security policies, and protects data. Which technology is most appropriate?

Medium
230

An organization is implementing a zero trust architecture and needs to enforce identity-centric access for all resources. Which THREE components are essential to this approach?

Hard
231

A small business is designing a defense-in-depth strategy for its e-commerce website. The web server is hosted in a cloud provider and handles credit card transactions. Which of the following additional controls best complements the existing firewall and IDS?

Easy
232

Drag and drop the steps to implement a DLP policy to prevent credit card data exfiltration via email into the correct order.

Medium
233

A security architect is designing a PKI for a large enterprise that issues certificates to thousands of users and devices. The architect wants to implement a mechanism to efficiently check certificate revocation status without requiring clients to download a full CRL. Which TWO technologies should be considered?

Medium
234

The exhibit shows results from a CIS Controls assessment. Based on the findings, which control deficiency poses the greatest risk to the organization and should be prioritized for remediation?

Hard
235

Refer to the exhibit. A security analyst is reviewing the firewall rule set for a corporate network. Which misconfiguration is present?

Easy
236

Drag and drop the steps to set up a SIEM alert for a failed login threshold into the correct order.

Medium
237

An organization is adopting a DevSecOps approach and wants to integrate security early in the development lifecycle. Which practice involves creating visual representations of threats and identifying potential attack vectors during the design phase?

Medium
238

A DevOps team integrates security into the CI/CD pipeline. They want to identify vulnerabilities in open-source libraries used by their application. Which tool or practice is specifically designed for this purpose?

Hard
239

A company is migrating critical workloads to AWS and must secure data at rest. They need to maintain control over the encryption keys. Which service should they use to meet this requirement?

Medium
240

During a penetration test, the tester has gained initial access to a web server and wants to move laterally to a database server. Which technique is most commonly used for lateral movement in a Windows environment?

Easy
241

An organization uses a PKI with a three-tier hierarchy: root CA, issuing CA, and registration authority. The root CA is kept offline. An intermediate CA certificate must be renewed. Which of the following is the correct process?

Medium
242

A financial institution must ensure that its data classification policy aligns with regulatory requirements for customer financial information. Which of the following actions best demonstrates governance in this context?

Easy
243

A security analyst is investigating a potential side-channel attack on an IoT device. The device's cryptographic operations show variable execution times based on the key and plaintext. Which mitigation is most effective against timing attacks?

Hard
244

A security manager is reviewing business continuity plans. Which element is MOST critical to test regularly?

Hard
245

A regional healthcare provider with 2,000 employees recently acquired a smaller clinic that uses a legacy electronic health record (EHR) system. The provider's security team performed a risk assessment and identified that the legacy system does not support encryption at rest, lacks role-based access controls (RBAC), and stores administrative credentials in plaintext. The system is scheduled to be decommissioned in 18 months, but it must remain operational to support patient care during the transition. The provider is subject to HIPAA and state breach notification laws. The CEO wants to avoid any disruption to patient services but also minimize regulatory risk. Which of the following is the BEST course of action?

Hard
246

An organization is deploying a just-in-time (JIT) privileged access management solution. What is a key benefit of JIT access compared to standing privileged accounts?

Medium
247

Which of the following is a benefit of using an immutable infrastructure approach?

Easy
248

A company is deploying a new IoT device that must perform secure boot and verify the integrity of firmware updates. The device has limited processing power. Which cryptographic algorithm combination is MOST appropriate for verifying firmware signatures efficiently?

Hard
249

An organization wants to implement a solution that automatically detects and blocks malicious traffic based on known signatures and behavioral anomalies. Which of the following should be deployed?

Easy
250

A company is adopting a defense-in-depth strategy. Which of the following is an example of a preventive control at the network layer?

Medium
251

Which of the following is the MOST effective way to detect unauthorized changes to critical files?

Medium
252

During a threat modeling exercise for a new web application, the team identifies a risk of API abuse due to lack of rate limiting. Which security control should be implemented at the API gateway to mitigate this risk?

Medium
253

A security operations team wants to improve their threat intelligence program. Which THREE of the following are most important for ensuring that threat intelligence is actionable and effectively integrated into security operations?

Hard
254

During a penetration test, the tester successfully gains access to a web server and wants to escalate privileges to domain administrator. The tester discovers that the web server has a service account that is a member of the local administrators group. Which technique would the tester most likely use to move laterally to a domain controller?

Medium
255

A security analyst discovers that a third-party vendor has been granted access to the company's production database for support purposes. The vendor's contract expires in two weeks. What is the BEST course of action to ensure compliance with the principle of least privilege and reduce risk?

Medium
256

A data loss prevention (DLP) solution is being implemented to prevent sensitive data from leaving the corporate network. Which of the following is the most effective approach for detecting structured data like credit card numbers in outbound traffic?

Medium
257

An organization is implementing network segmentation to limit lateral movement. It wants to isolate application tiers at the virtual network level in a cloud environment. Which technology enforces policies on east-west traffic between VMs in different subnets?

Hard
258

A security architect is designing a zero-trust architecture for a multi-cloud environment. Which principle is essential for enforcing identity-centric micro-segmentation?

Medium
259

An organization wants to enforce consistent security policies across multiple cloud providers (AWS, Azure, GCP). Which tool is designed to continuously monitor and remediate misconfigurations in cloud environments?

Medium
260

An organization is implementing a PKI and wants to ensure that clients can quickly check if a certificate has been revoked without downloading a large list. Which protocol should be used?

Easy
261

In the shared responsibility model for cloud security, which of the following is generally the responsibility of the cloud customer?

Easy
262

A company is deploying containers in a Kubernetes cluster and needs to enforce that containers run with reduced capabilities. Which Linux security feature should be configured to drop unnecessary capabilities?

Medium
263

During a vulnerability assessment, a security analyst discovers a critical vulnerability in a legacy application that cannot be patched due to vendor end-of-life. Which compensating control would best mitigate the risk?

Medium
264

A healthtech startup is developing a mobile app that collects PHI. They plan to use a third-party cloud provider for data storage. What is the most critical compliance requirement before signing the contract?

Hard
265

Which TWO of the following are examples of administrative controls? (Select TWO)

Easy
266

During a policy gap analysis, it is discovered that the organization has a policy stating that sensitive data must be encrypted, but there are no procedures for implementing encryption on mobile devices. This is an example of a gap between:

Medium
267

A developer needs to securely store user passwords in a database. Which hashing technique is recommended for password storage?

Easy
268

An administrator runs the above iptables command on a Linux server. The server is directly connected to the internet. Which of the following is the MOST significant security issue with this configuration?

Medium
269

You are the security architect for a global manufacturing company that has recently experienced a ransomware attack. The attack originated from a third-party vendor's compromised VPN account, which had been granted privileged access to the corporate network for remote maintenance. The vendor is a critical supplier of industrial control system (ICS) components. The incident severely disrupted production for three days. Post-incident analysis reveals that the vendor's security posture was not assessed prior to granting access, and the contract did not include specific security requirements or audit rights. The company now wants to implement a vendor risk management program to prevent future incidents. Which of the following is the MOST comprehensive and effective course of action to address the root cause?

Hard
270

A security team discovers a misconfiguration that exposes sensitive data. The operations team wants to wait until the next maintenance window. What is the BEST course of action?

Hard
271

During a security audit, it is discovered that a critical server uses SSH with password authentication and supports weak key exchange algorithms. Which of the following is the most effective hardening step to prevent brute-force attacks and ensure forward secrecy?

Hard
272

A company is deploying a new authentication system that leverages FIDO2/WebAuthn. Security architects want to ensure that the private key never leaves the authenticator device. Which attack vector is mitigated by this approach?

Hard
273

A security engineer needs to design a solution to detect and respond to insider threats involving unauthorized data exfiltration via USB devices. Which of the following is the MOST effective approach?

Hard
274

An organization wants to detect attackers who have already breached the network by deploying decoy credentials and data files. Which type of deception technology should they use?

Medium
275

An organization is implementing a privacy program based on privacy by design. Which principle requires that privacy controls be integrated into the system's default settings?

Hard
276

An organization wants to collect threat intelligence from multiple Information Sharing and Analysis Centers (ISACs) relevant to their industry. Which of the following is a primary benefit of participating in an ISAC?

Easy
277

An organization is implementing SSH hardening for server access. Which configuration change most effectively reduces the attack surface against brute-force and credential theft?

Medium
278

An organization uses a multi-cloud strategy with workloads on AWS, Azure, and GCP. They need a single tool to monitor and enforce security configurations across all cloud environments. Which cloud security solution is best suited for this requirement?

Medium
279

An organization is implementing a Secure Access Service Edge (SASE) architecture. Which of the following is a key component of SASE?

Medium
280

A company is merging with another organization and needs to integrate their identity management systems. The security team is concerned about maintaining least privilege and segregation of duties across the combined environment. Which of the following approaches BEST addresses these concerns?

Hard
281

A security operations team is developing a SOAR playbook to automate response to a detected ransomware outbreak. The team wants to ensure the playbook can contain the threat quickly while minimizing business disruption. Which TWO actions should the playbook include as automated responses? (Select TWO.)

Medium
282

A security engineer is configuring a web server to use TLS 1.3. Which feature of TLS 1.3 should be disabled to prevent replay attacks in 0-RTT mode?

Hard
283

A security manager is implementing a policy exception management process. Which TWO of the following are essential components of an effective exception management process?

Medium
284

During an API security review, an assessor finds that the API uses JSON Web Tokens (JWT) with a symmetric key shared among multiple services. Which of the following is the MOST significant security concern?

Hard
285

An enterprise is adopting a DevOps model and wants to integrate security into the CI/CD pipeline. The security architect recommends adding automated security testing. Which phase of the pipeline should static application security testing (SAST) be introduced to minimize rework?

Medium
286

An organization is implementing a privacy program to comply with GDPR. Which of the following BEST describes the concept of 'privacy by design' as it applies to a new customer relationship management (CRM) system?

Hard
287

A large healthcare organization has implemented a zero-trust network architecture (ZTNA) to secure access to its electronic health record (EHR) system. The architecture uses a software-defined perimeter (SDP) where all users must authenticate and be authorized before accessing the EHR. The EHR system is hosted in a private cloud and communicates with a legacy billing system that cannot support modern authentication protocols. The billing system is accessed by a small number of finance employees via a dedicated VPN. Recently, an auditor discovered that a finance employee's credentials were compromised, and the attacker used the VPN to access the billing system and exfiltrate patient billing data. The security architect must prevent such lateral movement while maintaining access for legitimate users. Which of the following is the BEST course of action?

Hard
288

During a threat hunting exercise, a security analyst hypothesizes that an adversary is using PowerShell to execute malicious scripts. Which approach is the analyst employing?

Medium
289

A security architect finds this IAM policy attached to an S3 bucket. Which of the following best describes a critical security flaw in this policy?

Hard
290

Which of the following is a primary function of a Cloud Access Security Broker (CASB)?

Easy
291

An organization is deploying a new IoT device that must securely update its firmware over the air (OTA). The device has limited processing power and memory. Which cryptographic solution would provide the BEST balance of security and performance for verifying firmware updates?

Easy
292

A large enterprise recently migrated its critical applications to a hybrid cloud environment. The security team is concerned about the risk of privileged account abuse. They have implemented a privileged access management (PAM) solution that rotates passwords for service accounts after each use. However, during a incident response drill, the team discovers that an attacker who compromised a jump server was able to access multiple administrative consoles without re-authentication. Investigation reveals that the PAM solution uses session recording but does not enforce session termination; instead, it relies on the lifecycle of the token issued during initial authentication. The attacker captured a valid token and reused it from a different machine. Which of the following is the most effective remediation?

Hard
293

Which of the following is a key feature of TLS 1.3 compared to earlier versions?

Medium
294

A small business uses an on-premises Active Directory for user authentication. They want to enable employees to use their corporate credentials to access a SaaS application that supports SAML 2.0. The security administrator needs to set up a federation between the on-premises AD and the SaaS provider. Which of the following components must be deployed on-premises to act as a bridge between AD and the SAML identity provider?

Easy
295

A healthcare organization is implementing a vendor risk management program. Which THREE of the following should be included in the vendor risk assessment process? (Select THREE.)

Hard
296

A company is required to comply with FedRAMP for its cloud deployment. Which of the following is a key requirement for FedRAMP compliance?

Medium
297

A vulnerability management team is prioritizing patches for a large enterprise. They have identified a critical vulnerability in a widely used software with a CVSS base score of 9.8. However, the exploit requires local access and authentication. Which CVSS metric should the team use to adjust the score to reflect the actual risk in their environment?

Medium
298

A security analyst reviews this output from an SSH session. What security control is in place on the remote server?

Medium
299

A security architect is designing a data classification scheme aligned with a new privacy regulation. Which THREE of the following are common data classification levels used in enterprise environments? (Select THREE.)

Hard
300

Based on the exhibit, what is the primary purpose of the condition in this IAM policy?

Medium
301

An organization is implementing a PKI hierarchy. The security team wants to ensure that if an issuing CA is compromised, the root CA remains unaffected and can revoke the issuing CA's certificate. Which of the following BEST describes the recommended architecture?

Medium
302

A security architect is designing a network segmentation strategy for a multi-tier web application. The web servers must be accessible from the internet, while the application and database servers must only be accessible from the web tier. Which architecture best meets these requirements?

Easy
303

A multinational corporation must comply with multiple data protection laws. What is the BEST strategy?

Hard
304

An organization's security team is reviewing security metrics to present to the board. Which THREE of the following are commonly used Key Performance Indicators (KPIs) for a security program? (Select THREE.)

Medium
305

A company is implementing a secure SDLC and wants to integrate application security testing early. Which THREE tools are most appropriate for shift-left security? (Select THREE.)

Hard
306

During a security assessment, a penetration tester discovers that a web application uses a custom encryption algorithm to protect session tokens. According to secure engineering principles, what is the primary concern?

Hard
307

A small business runs its critical line-of-business application on a single Windows server located in a local data center. The server is accessed by employees remotely via RDP over a VPN. Recently, the server has been experiencing slow performance, and the administrator notices high CPU usage from a process named 'svchost.exe'. The administrator suspects malware but is not sure. The business has no security tools beyond Windows Defender. Management wants to minimize downtime and ensure the server is back to full operation as soon as possible. Which of the following is the BEST course of action for the administrator to take first?

Medium
308

During an incident response engagement, the team has completed containment and eradication. What is the next phase in the incident response lifecycle according to NIST SP 800-61?

Easy
309

You are the security architect for a mid-sized e-commerce company that processes credit card payments. The company must comply with PCI DSS. Currently, the cardholder data environment (CDE) includes a web server, an application server, and a database server, all on the same flat network segment. The QSA has identified that the CDE is not properly segmented, and network access controls are insufficient. The company wants to minimize the scope of PCI compliance by reducing the number of systems that handle cardholder data. You propose implementing network segmentation to isolate the CDE. Which of the following is the most effective approach to reduce PCI scope while maintaining business functionality?

Hard
310

A company wants to implement certificate pinning for its mobile application to prevent man-in-the-middle attacks. Which of the following is the BEST practice when implementing certificate pinning?

Easy
311

During a forensic investigation, an analyst finds that a compromised system's memory dump shows signs of a kernel-mode rootkit. Which technique is MOST effective to detect the rootkit without relying on the compromised OS?

Hard
312

Which two practices are essential for securing a CI/CD pipeline? (Choose two.)

Easy
313

A security analyst is reviewing a web application's authentication mechanism. Which of the following are best practices to prevent session hijacking? (Select TWO.)

Medium
314

A security engineer is configuring a TLS 1.3 connection between a web server and client. Which feature is unique to TLS 1.3 and provides reduced latency for returning clients?

Easy
315

Which of the following is the primary purpose of input validation in application security?

Easy
316

An organization is adopting a cloud-first strategy and wants to ensure proper security responsibilities are understood. Which concept defines the division of security responsibilities between the cloud provider and the customer?

Easy
317

An organization is adopting the NIST Risk Management Framework (RMF). During which step would the security team select and implement security controls, and how does this map to the organization's governance structure?

Hard
318

A security team wants to implement a certificate pinning strategy for their mobile application to prevent man-in-the-middle attacks. Which of the following should be pinned in the application code?

Easy
319

Which THREE of the following are common vulnerabilities in IoT devices? (Select THREE.)

Hard
320

A security analyst at a financial institution is investigating a potential data exfiltration incident. The organization uses a zero-trust network architecture with micro-segmentation. The analyst notices that a database server with sensitive customer financial data has been communicating with an external IP address (198.51.100.45) over port 443 during non-business hours. The database server is not supposed to initiate outbound connections; all outbound traffic is logged and blocked by default except for specific allowlisted IPs and ports. The analyst reviews the firewall logs and finds that the outbound connection to 198.51.100.45 was allowed because the source port was 443, which is an allowed port for inbound HTTPS traffic. The database server is not a web server and does not run any HTTPS services. Which of the following is the best course of action for the analyst to take first?

Medium
321

A security analyst is reviewing web server logs and notices repeated requests to URLs containing sequences like '/../../../etc/shadow' and '/../../../etc/passwd'. Which TWO actions should the analyst take as part of the immediate incident response process?

Easy
322

When evaluating the security architecture of a containerized application, which THREE of the following practices should be implemented to minimize the attack surface? (Select THREE.)

Hard
323

A security analyst is analyzing a network capture and sees repeated TCP SYN packets to a host but no SYN-ACK responses. Which TWO conclusions are MOST likely? (Choose two.)

Medium
324

A security team is conducting a penetration test against a client's web application. During the reconnaissance phase, the tester discovers a subdomain that hosts a development version of the application with debug mode enabled. Which type of reconnaissance does this activity represent?

Medium
325

In a CI/CD pipeline, a container image is built from a Dockerfile that uses a base image from a public registry. To minimize the attack surface, which of the following actions should be automated in the pipeline?

Hard
326

A system administrator is configuring a Linux server to host a web application. Which file permission should be set for the private SSL key?

Easy
327

During a vendor risk assessment, a company receives a SOC 2 Type II report from a cloud service provider. What does this report primarily attest to?

Medium
328

A security assessor is evaluating an application that uses ChaCha20-Poly1305 for encryption. Which TWO of the following are true about this cryptographic algorithm?

Hard
329

A company uses a microservices architecture with Docker containers orchestrated by Kubernetes. Developers push code to a Git repository, which triggers a CI/CD pipeline using Jenkins. The pipeline builds Docker images and pushes them to a private registry (Harbor). Recently, a critical vulnerability (CVE-2024-XXXX) was discovered in the base image of several containers. The security team wants to ensure that only images that pass vulnerability scans are deployed to production. The pipeline currently builds and pushes images without any security check. Developers are responsible for updating base images, but this has been inconsistent. Which action should the security team take?

Medium
330

A company is deploying a cloud access security broker (CASB) to gain visibility into shadow IT. Which mode of operation would allow the CASB to inspect traffic without requiring proxy configuration on endpoints?

Medium
331

A security architect is selecting a cipher suite for TLS 1.3 to ensure forward secrecy and high performance. Which cipher suite should be recommended?

Easy
332

An organization has a critical vulnerability in a legacy application that cannot be patched due to vendor end-of-life. The application is required for business operations and is accessible only from the internal network. Which compensating control would best reduce the risk of exploitation while maintaining availability?

Hard
333

During a compliance audit, an organization's security team discovers that sensitive data in a legacy database is stored in plaintext. The database is critical for operations and cannot be taken offline for patching until the next maintenance window in three months. Which of the following is the BEST compensating control to reduce risk immediately?

Hard
334

A large enterprise is migrating its critical financial applications to a public cloud provider. The security architecture team has designed a multi-region deployment to ensure availability and disaster recovery. The applications use TLS for data in transit and rely on a key management service (KMS) for encryption keys. During a penetration test, it was discovered that the KMS master keys are stored in a single region, creating a single point of failure. Additionally, the load balancer configuration exposes internal application health check ports to the internet. The security architect must remediate these issues while minimizing latency and cost. Which of the following is the BEST course of action?

Hard
335

Under GDPR, which of the following is a data subject right that allows an individual to request that their personal data be erased?

Easy
336

A SOC team receives an alert from a SOAR platform indicating a potential phishing email. The SOAR playbook automatically quarantines the email, blocks the sender, and opens a ticket. This is an example of which SOAR capability?

Medium
337

An organization is deploying a containerized application on Kubernetes and must enforce that only approved container images are allowed to run, and that containers cannot escalate privileges. Which combination of controls should the architect implement?

Hard
338

A small business uses Puppet for configuration management on Linux servers. They are now migrating to containers and want to maintain security. The operations team is unfamiliar with containers. The security team insists on automated vulnerability scanning of container images before deployment. What should be the company's first step?

Easy
339

A security analyst is reviewing the following JSON Web Token (JWT) header: {"alg":"none","typ":"JWT"}. Which of the following vulnerabilities does this indicate?

Hard
340

An organization is implementing a hardware security module (HSM) to protect cryptographic keys used for code signing. The HSM is required to meet a government standard for physical security and tamper resistance. Which FIPS 140 security level must the HSM achieve to provide tamper-evident coatings and tamper response mechanisms?

Medium
341

Which of the following are secure scripting practices when automating administrative tasks? (Choose two.)

Medium
342

A security analyst is investigating a potential data breach. The logs show that an attacker used a compromised service account to access sensitive files on a file server. Which TWO actions should the analyst take FIRST to contain the incident? (Choose TWO.)

Medium
343

A security administrator is configuring SSH for a jump host used to access critical servers. Which of the following is the most secure configuration option to restrict authentication and reduce the attack surface?

Medium
344

A security architect is reviewing supply chain security for a software product. Which TWO artifacts are most important for verifying the integrity and provenance of third-party components?

Medium
345

Which THREE of the following are common techniques to mitigate side-channel attacks?

Hard
346

An organization is implementing a governance framework to ensure that security controls are aligned with business objectives. Which of the following frameworks is specifically designed for this purpose?

Medium
347

An organization is implementing a software-defined perimeter (SDP) for zero trust network access. Which THREE characteristics are typical of an SDP architecture? (Choose three.)

Hard
348

A security architect is designing a zero trust architecture for a corporate network. Which principle is fundamental to the zero trust model?

Easy
349

During a penetration test, the tester gains access to a web server and wants to escalate privileges to root. The tester discovers that the web application runs with a service account that has the SeImpersonatePrivilege enabled. Which attack is most likely to succeed for privilege escalation?

Hard
350

An organization uses AWS, Azure, and GCP for different workloads. They want a single tool to manage infrastructure consistently across all providers. Which approach is most appropriate?

Hard
351

Which of the following is a primary benefit of using a Web Application Firewall (WAF) in front of a web application?

Easy
352

A company wants to reduce the mean time to detect (MTTD) for security incidents. Which technology is most effective for this purpose?

Medium
353

A security architect is designing deception technologies to detect and delay attackers. Which TWO of the following are examples of deception technologies that can be deployed? Select TWO.

Medium
354

A company uses a SIEM with User Behavior Analytics (UBA). The UBA generates an alert when a user accesses sensitive data at unusual hours. Which type of correlation rule is being applied?

Medium
355

A network administrator is configuring a firewall rule set. The requirement is to allow inbound HTTPS traffic from the internet to a web server at 10.1.1.10, and to allow the web server to respond. All other inbound traffic should be blocked. Which rule set accomplishes this?

Medium
356

An organization is deploying a new PKI and wants to ensure certificate revocation is performed efficiently. Which THREE methods should be implemented? (Select THREE.)

Hard
357

A security engineer is hardening an SSH server. The policy requires disabling all legacy algorithms and using only modern, secure cryptography. Which THREE of the following configurations should the engineer apply?

Hard
358

A security engineer is reviewing the configuration of an AWS S3 bucket that stores customer data. Which of the following settings is most likely to cause a data breach?

Medium
359

Drag and drop the steps to perform a forensic acquisition of a hard drive using FTK Imager into the correct order.

Medium
360

A security analyst is reviewing the firewall rules. Which of the following best describes the rule set's effect?

Hard
361

Which key exchange algorithm provides perfect forward secrecy (PFS) and is recommended for use in TLS 1.3?

Easy
362

An organization's risk appetite is defined as 'low' for data privacy. Which of the following risk treatments is most aligned with this appetite?

Medium
363

A security engineer is hardening SSH server configuration. Which TWO options improve security? (Select TWO.)

Medium
364

An organization has recently migrated its on-premises data center to a public cloud. The security team notices that several virtual machines (VMs) in the same subnet are communicating with each other without any restrictions. The company policy requires that only specific application traffic (e.g., database queries from web servers) be allowed between VMs, and all other inter-VM traffic must be blocked to comply with a zero-trust model. The cloud provider offers native security group and network ACL features. The architect must design a solution that enforces the policy with minimal administrative overhead and supports future expansion. Which of the following is the BEST course of action?

Hard
365

A digital forensics investigator is called to the scene of a potential data breach. The investigator must collect evidence from a live Windows system. Which of the following represents the correct order of volatility when collecting volatile data?

Hard
366

A security engineer is writing a Python script to automate the revocation of compromised credentials across multiple cloud services. Which of the following is the most critical security consideration when implementing this script?

Medium
367

Based on the auth.log exhibit, what is the MOST appropriate immediate action to mitigate this attack?

Easy
368

Which key performance indicator (KPI) is most useful for measuring the effectiveness of an incident response process?

Easy
369

An organization wants to adopt a cybersecurity framework that provides a structured approach to managing cyber risks. Which framework is BEST suited?

Medium
370

A company is evaluating multi-factor authentication methods. Which TWO are considered phishing-resistant? (Select TWO.)

Medium
371

An organization is using the FAIR model to quantify risk. Which of the following is a primary component of the FAIR taxonomy?

Medium
372

A company is implementing a software-defined perimeter (SDP) architecture. Which TWO of the following are key characteristics of SDP? (Select TWO.)

Easy
373

A company is migrating its applications to a SaaS model. Which of the following should be included in the contract to ensure secure data handling?

Easy
374

A security architect is evaluating a hardware security module (HSM) for key management. Which of the following is a PRIMARY benefit of using an HSM over software-based key storage?

Medium
375

A security analyst discovers that a containerized application is running with root privileges. Which of the following is the best practice to reduce the attack surface?

Easy
376

A security engineer is hardening a Kubernetes cluster. They want to reduce the risk of container escape attacks. Which combination of settings is most effective at the pod security context level?

Hard
377

A mid-sized healthcare organization processes protected health information (PHI) and must comply with HIPAA and the GDPR for its EU patients. The organization uses a hybrid cloud environment with on-premises servers and AWS. Recently, an employee's laptop was stolen containing unencrypted PHI. The incident response team was activated. The security architect must determine the best course of action to address compliance obligations. The organization has a data classification policy, but it is not consistently enforced. A business continuity plan exists but has not been tested in two years. The CEO is concerned about reputational damage and legal liability. Which of the following should the security architect recommend FIRST?

Easy
378

A financial institution must comply with the Sarbanes-Oxley Act (SOX). Which of the following is a primary focus of SOX compliance?

Easy
379

A company is deploying a containerized application on Kubernetes. The security team requires that only signed images from a private registry be used and that containers run without privileged mode. Which Kubernetes admission controller should be configured to enforce both requirements?

Hard
380

A security architect is designing a PKI for an organization that requires high assurance certificates. The architect needs to protect the root CA private key. Which solution provides the highest level of security for the root CA key?

Medium
381

Which component of the MITRE ATT&CK framework categorizes the 'why' of an adversary's action, such as initial access or credential access?

Easy
382

An organization is migrating to a hybrid cloud model. The security policy mandates that all keys used for data encryption must be managed on-premises. Which key management solution should be used?

Hard
383

An incident responder is analyzing a malware sample obtained from an infected host. The responder wants to perform dynamic analysis to observe the malware's behavior in a safe environment. Which of the following is the best approach?

Hard
384

A security analyst is reviewing alerts from a SIEM and notices multiple failed login attempts from a single IP address to different user accounts over a 5-minute window. What should the analyst do FIRST?

Medium
385

A company is required to comply with PCI DSS. What is the primary purpose of conducting quarterly network vulnerability scans?

Medium
386

During a red team exercise, the team gains access to a workstation and needs to maintain persistence. They modify a registry run key to execute a payload. However, the organization uses EDR that monitors registry changes. Which technique could the red team use to avoid detection?

Hard
387

A risk manager is applying the FAIR model to quantify a risk. Which TWO of the following are primary components used in FAIR analysis? (Select TWO.)

Medium
388

An organization is implementing a vendor risk management program and is reviewing a contract that includes a right-to-audit clause. Which THREE of the following are common elements that should be verified during such an audit? (Select THREE.)

Hard
389

An auditor reviews this IAM policy attached to a user group. What is the primary compliance concern?

Hard
390

A security analyst calculates the annualized loss expectancy (ALE) for a server. The single loss expectancy (SLE) is $50,000, and the annualized rate of occurrence (ARO) is 0.2. What is the ALE?

Hard
391

An organization uses Kubernetes to orchestrate containers. Which practice enhances the security of pod-to-pod communication?

Easy
392

An organization wants to implement infrastructure as code (IaC) with immutable infrastructure. Which security benefit does immutable infrastructure provide?

Medium
393

A security analyst reviews logs from a web application firewall (WAF) and notices that an attacker is bypassing the WAF by encoding malicious payloads using base64 and then sending them in HTTP headers. Which WAF configuration change would BEST detect and block such attacks?

Hard
394

A security analyst is reviewing logs from a SIEM and notices that a user account has been successfully authenticated from two different geographic locations within a short time span, which is impossible. The SIEM uses user behavior analytics (UBA). What type of anomaly is this most likely to detect?

Hard
395

A SOC wants to improve detection of advanced persistent threats (APTs) that evade traditional signature-based tools. Which TWO approaches are most effective? (Select exactly 2.)

Medium
396

A company wants to protect sensitive data stored in a public cloud bucket. Which of the following is the MOST effective control to prevent accidental public exposure?

Easy
397

A security architect is designing a secure connectivity solution between an on-premises data center and a public cloud provider. The solution must provide low latency, high bandwidth, and avoid traversing the public internet. Which approach BEST meets these requirements?

Hard
398

An organization is implementing a threat hunting program. The team decides to use a hypothesis-driven approach. Which of the following best describes this methodology?

Medium
399

An organization must comply with FedRAMP requirements for a cloud service. Which aspect of cloud security is most directly assessed under FedRAMP?

Hard
400

A security architect is designing a system that requires hardware-enforced isolation for sensitive computations. Which technology provides the strongest isolation by running code in a protected environment within the CPU?

Hard
401

A security architect is designing a zero trust architecture for a financial services company. Which component is MOST critical to enforce identity-centric access control in a zero trust model?

Medium
402

A financial institution is required to comply with PCI DSS and uses a mix of legacy and modern applications. The security architect proposes to segment the network so that the cardholder data environment (CDE) is isolated. However, a legacy application in a non-CDE segment must send data to a database in the CDE. The legacy application cannot be modified and communicates via clear-text protocols. Which of the following is the most secure solution that maintains compliance?

Medium
403

An organization wants to implement a zero-trust architecture for remote access. Which component is most critical for enforcing least-privilege access to internal applications?

Hard
404

A security administrator is hardening SSH access to a jump host. The requirement is to allow only key-based authentication and restrict the use of weak cryptographic algorithms. Which of the following configurations accomplishes this?

Medium
405

An organization wants to implement a hardware root of trust for measuring system integrity at boot. Which technology should be used to store measurements in Platform Configuration Registers (PCRs) and support remote attestation?

Medium
406

A systems administrator must automate the patching of 200 Windows servers. The environment has strict security requirements and change management. Which scripting approach best balances automation and control?

Medium
407

A security analyst is reviewing a CVSS score for a vulnerability that affects a critical server. The base score is 7.5, but the analyst needs to adjust for the environment. Which TWO of the following are valid CVSS environmental metrics that can modify the score? (Choose two.)

Medium
408

A security architect is designing a zero trust network architecture and needs to implement micro-segmentation. Which TWO of the following techniques are commonly used to achieve micro-segmentation? (Select TWO).

Medium
409

An engineer reviews the TLS configuration for a web server, which includes the following line: ssl_verify_client optional; Which of the following is a security concern present in this configuration?

Easy
410

An organization's security policy defines that all sensitive data must be encrypted. However, a business unit has a legacy application that cannot support encryption without a major rewrite. The risk owner decides to accept the risk. This is an example of which risk treatment strategy?

Hard
411

During a compliance audit for PCI DSS, the auditor identifies that cardholder data is stored beyond the required retention period. The organization wants to implement proper data lifecycle management. Which THREE of the following should the organization include in its data retention policy? (Select THREE.)

Hard
412

A security team is evaluating the effectiveness of their patching program. Which metric would best indicate how quickly the organization applies critical patches?

Medium
413

An organization is adopting SASE to converge network and security functions. Which component of SASE provides secure web gateway (SWG) capabilities?

Medium
414

A financial institution is evaluating a cloud service provider for hosting customer data. During the due diligence process, which report would best help the institution assess the provider's control environment and compliance with SOC 2?

Medium
415

A cloud security engineer reviews the above S3 bucket policy. Which of the following is the most significant security concern?

Medium
416

A security architect is designing a secure remote access solution for employees using personal devices (BYOD). The company requires that corporate data is separated from personal data and can be wiped remotely without affecting personal data. Which solution best meets these requirements?

Easy
417

A security engineer is designing a secure enclave for processing sensitive personally identifiable information (PII). The enclave must protect data at rest and in use, and must support attestation to verify its integrity. Which THREE technologies should the engineer incorporate? (Choose three.)

Hard
418

An organization is reviewing its third-party risk management process. Which of the following clauses should be included in contracts with critical vendors to ensure ongoing visibility into their security posture?

Medium
419

A security analyst is performing a risk assessment for a critical application. Which TWO of the following are characteristics of a quantitative risk assessment methodology?

Medium
420

An organization is migrating to a zero trust model and wants to implement identity-centric security. Which THREE of the following are key principles of an identity-centric zero trust approach? (Select THREE.)

Hard
421

A penetration tester is conducting a black-box test on a web application. The tester wants to gather information about the target without directly interacting with the target systems. Which three techniques are considered passive reconnaissance? (Select THREE).

Medium
422

A company is deploying a just-in-time (JIT) privileged access management solution. Which of the following BEST describes a key security benefit of JIT access?

Hard
423

A company's incident response team is developing a playbook for ransomware incidents. The playbook should cover the preparation phase. Which THREE of the following are appropriate preparation activities? (Choose THREE.)

Medium
424

A security analyst receives an alert from the SIEM indicating a potential phishing email with a malicious attachment. The analyst wants to automatically isolate the affected endpoint and block the sender. Which technology should be used to automate this response?

Easy
425

A healthcare organization is implementing HIPAA Security Rule safeguards. Which TWO of the following are required administrative safeguards? (Choose TWO.)

Easy
426

A security architect is designing a microservices application that uses JWTs for authentication. Which of the following is the most critical security concern regarding JWT handling?

Medium
427

A company's data classification policy labels all financial data as 'Confidential.' An employee accidentally emails a spreadsheet containing customer payment information to an unauthorized external party. Which type of control failure occurred?

Medium
428

An IoT device manufacturer wants to ensure secure firmware updates. Which approach best protects against malicious firmware being installed on devices?

Medium
429

A security architect is designing a system for a healthcare provider that must comply with HIPAA. Which control is required for ePHI transmission?

Medium
430

An organization uses a SIEM to collect logs from multiple sources. The security team wants to identify users who are accessing resources outside of normal business hours and exhibiting unusual data transfer patterns. Which advanced SIEM capability would be most effective?

Hard
431

Which of the following is a primary advantage of using ChaCha20-Poly1305 over AES-256-GCM in certain environments?

Easy
432

A security operations center (SOC) is implementing User Behavior Analytics (UBA) to detect insider threats. Which TWO of the following data sources are most critical for establishing a baseline of normal user behavior?

Medium
433

Which THREE of the following are required components of a Business Continuity Plan (BCP) per ISO 22301?

Hard
434

A security architect is designing a hybrid cloud environment. The organization requires low-latency, private connectivity between on-premises and a public cloud provider, bypassing the public internet. Which solution best meets this requirement?

Medium
435

A security analyst is calculating the annualized loss expectancy (ALE) for a server that processes credit card data. The server has a $100,000 asset value, and the exposure factor for a security breach is 0.4. Historical data shows that such breaches occur twice per year. What is the ALE?

Medium
436

An organization requires a cryptographic algorithm that provides both encryption and authentication in a single pass. Which algorithm should be selected?

Medium
437

Drag and drop the steps to deploy a new certificate from an internal CA using Group Policy into the correct order.

Medium
438

A security auditor is reviewing the cryptographic controls of a financial application that processes transactions. The application uses digital signatures with RSA 4096 and SHA-256. The auditor recommends migrating to a stronger algorithm due to concerns about long-term security and quantum resistance. Which of the following would be the MOST appropriate replacement?

Hard
439

A security architect at a financial institution is designing a cloud-native application using AWS. The application processes sensitive customer data and must comply with PCI DSS. Which of the following security architecture decisions best supports both compliance and operational efficiency?

Hard
440

Which CVSS metric component is used to reflect the impact of a vulnerability based on the specific environment of an organization?

Medium
441

A security operations team is designing a threat hunting program. They want to use the MITRE ATT&CK framework to structure their hunts. Which TWO components of the ATT&CK framework should they focus on to develop hypothesis-driven hunts? (Select TWO.)

Medium
442

In the shared responsibility model for cloud security, which of the following is typically the responsibility of the customer when using an Infrastructure as a Service (IaaS) model?

Easy
443

A security analyst is investigating an API that uses JSON Web Tokens (JWT) for authentication. Which field in a JWT contains the token expiration time?

Easy
444

During a risk assessment, a residual risk is identified as high. What should be the NEXT step?

Hard
445

During a forensic investigation, an analyst needs to collect volatile data from a compromised Linux server. Which of the following orders of volatility is correct for collecting the listed data?

Medium
446

A global financial firm must comply with GDPR and SOX. The CISO wants to consolidate controls across frameworks using a single set of controls. Which approach best addresses this requirement?

Medium
447

Which TWO of the following are common compliance frameworks used in the healthcare industry?

Easy
448

A company is deploying a new web application that handles sensitive customer data. The application is built using a microservices architecture running in containers on a Kubernetes cluster. The security team wants to implement mutual TLS (mTLS) for service-to-service communication. However, they are concerned about the operational overhead of certificate management. Which approach minimizes management overhead while still ensuring strong authentication?

Medium
449

A company is considering adopting the NIST Risk Management Framework (RMF). Which of the following steps is unique to NIST RMF compared to ISO 27005?

Hard
450

A DevOps engineer is automating container orchestration using Kubernetes. Which of the following are security best practices to include in the automation? (Choose two.)

Hard
451

A development team is using Docker containers for microservices. The security team wants to scan containers for vulnerabilities during the CI/CD pipeline. Which approach is most effective?

Medium
452

During a secure SDLC, a security architect wants to identify design flaws early. Which activity is most appropriate for the design phase?

Medium
453

A security operations center (SOC) analyst is tuning a SIEM correlation rule to detect lateral movement using pass-the-hash attacks. The analyst wants to minimize false positives while ensuring detection of true positives. Which approach is most effective for reducing false positives in this scenario?

Hard
454

A security analyst is triaging a suspicious file. The analyst wants to perform static analysis to gather initial information. Which TWO of the following are static analysis techniques?

Medium
455

An organization is deploying containerized applications and needs to enforce security policies that restrict the system calls a container can make. Which Linux security module should be used?

Medium
456

A company is implementing a risk management framework to comply with PCI DSS. Which type of control is a firewall rule that blocks all inbound traffic except HTTP and HTTPS?

Easy
457

A security analyst is using Volatility to analyze a memory dump from a compromised Windows system. The analyst suspects that a rootkit is hiding processes. Which Volatility plugin should the analyst use to detect hidden processes?

Medium
458

During an incident response, a forensic analyst captures the memory of a compromised Windows system. Using Volatility, the analyst runs the 'pslist' command and sees a suspicious process 'svchost.exe' with a parent process 'explorer.exe'. Which Volatility plugin should the analyst use next to detect potential process hollowing?

Hard
459

A SOC analyst is investigating a potential lateral movement within the network. Which log source is most critical for detecting lateral movement using pass-the-hash or pass-the-ticket attacks?

Easy
460

A security analyst calculates the annual loss expectancy (ALE) for a critical asset. The single loss expectancy (SLE) is $50,000, and the annualized rate of occurrence (ARO) is 0.2. What is the annual loss expectancy?

Medium
461

An organization is migrating its on-premises monolithic application to a containerized microservices architecture on a Kubernetes cluster. The development team has created a set of Docker images that are stored in a private registry. The security team requires that all container images be scanned for vulnerabilities before deployment. The current CI/CD pipeline uses Jenkins to build images, push them to the registry, and then deploy to Kubernetes via kubectl. The scanning is performed by a tool that generates a report, but developers have been ignoring critical vulnerabilities and deploying anyway. The security team wants to enforce a policy that blocks deployment if the image has any critical or high-severity vulnerabilities. Additionally, the cluster must ensure that containers run with the least privilege and that secrets are not exposed in environment variables. The operations team is concerned about performance overhead from runtime security monitoring. Which of the following approaches best addresses these requirements while minimizing operational overhead?

Hard
462

A company's security policy requires that all remote access be conducted via VPN. An employee uses a personal device without VPN to access company email. Which type of policy violation is this?

Easy
463

Which THREE of the following are essential components of a secure software development lifecycle (SSDLC) to ensure security engineering? (Select exactly 3.)

Hard
464

You are a SOC analyst at a mid-sized company. The SIEM alerts on anomalous outbound traffic from a finance workstation to an external IP address never seen before. The workstation belongs to an employee in the accounts payable department. The alert shows that 500 MB of data was transferred via SMB over the internet, which is unusual because internal file shares are normally used. The employee is currently logged in and is in a meeting across the building. The initial triage confirms the workstation is not domain-joined and has been bypassing corporate firewall rules using a personal VPN. Which of the following actions should you take FIRST?

Easy
465

During a security assessment, it is discovered that an organization's DMZ hosts can initiate outbound connections to the internal network. Which architectural change would best mitigate the risk of a DMZ compromise spreading to the internal network?

Easy
466

A security architect is designing a PKI hierarchy for a large enterprise that issues certificates for internal users, devices, and code signing. Which of the following best practices should be implemented to minimize the impact of a CA compromise?

Medium
467

A security architect is designing a secure remote access solution for a global workforce. The company requires that all remote connections be authenticated using certificates issued by the company's internal PKI, and that the connection be encrypted and integrity-protected. Additionally, the solution must support IP-based network access control to restrict access to specific internal subnets based on the user's role. Which of the following should the architect recommend?

Medium
468

A financial company is expanding its hybrid cloud architecture. They have an AWS VPC connected to an on-premises network via an IPsec VPN using IKEv2. The on-premises firewall is a Cisco ASA. Recently, users report intermittent connectivity to cloud resources. The security team reviews logs and finds the following message on the ASA: 'no matching crypto map entry for traffic from on-prem to cloud'. The team also suspects potential data leakage due to occasional unencrypted traffic. The corporate policy requires all traffic between environments to be encrypted. The engineer has verified that the IKEv2 proposals match on both sides. The cloud side uses a virtual private gateway with a static route to the on-premises network. Which of the following should the engineer do FIRST to resolve the issue?

Hard
469

A developer is implementing input validation for a web application that accepts file uploads. Which of the following is the most secure method to prevent path traversal attacks?

Easy
470

A container security team wants to enforce that containers run with the least privileges possible. Which Linux security module can be used to restrict system calls available to a container?

Hard
471

A security manager is reviewing Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs) for the security program. Which of the following is an example of a KRI?

Medium
472

An organization is implementing a zero-trust architecture for remote access. Which component is essential for continuous authentication?

Hard
473

A security team is implementing a secure SDLC for a new application. Which THREE activities should be included as part of the development phase? (Choose three.)

Hard
474

Match each acronym to its definition.

Medium
475

During a third-party risk assessment, a security architect discovers that a vendor's data retention policy does not align with the organization's legal requirements. Which of the following is the BEST course of action?

Hard
476

An organization is planning to adopt quantum-resistant cryptography. According to NIST PQC standards, which THREE algorithms are currently selected for standardization? (Select THREE).

Hard
477

Drag and drop the steps to configure a host-based firewall (Windows Defender Firewall) to block all inbound traffic except RDP into the correct order.

Medium
478

A company is migrating to a public cloud and wants to ensure they understand their security responsibilities. According to the shared responsibility model, which of the following is typically the responsibility of the cloud customer?

Medium
479

Match each security tier or model to its description.

Medium
480

A virtualization administrator needs to ensure that virtual machines (VMs) from different customers cannot communicate with each other unless explicitly allowed. Which network security control should be implemented on the hypervisor?

Medium
481

An organization has identified a vulnerability in a legacy system that cannot be patched. The system is critical for operations, and the cost of mitigating the vulnerability exceeds the potential loss. Which risk treatment option is most appropriate?

Medium
482

A company is implementing a SIEM solution and needs to ensure that logs from network devices, servers, and endpoints are collected in a consistent format. Which protocol should be used to transport logs securely?

Easy
483

A company uses a CASB to monitor cloud application usage. Which primary function does a CASB provide for enforcing security policies between users and cloud services?

Medium
484

A security analyst is writing a Python script to parse network logs and automatically block IP addresses that exceed a threshold of failed login attempts. Which security consideration is most critical when implementing this automation?

Medium
485

A company that processes credit card transactions discovers that a third-party vendor with access to its network has suffered a data breach. The vendor's access was limited but included a connection to the cardholder data environment. The company must comply with PCI DSS. Which of the following is the FIRST action the company should take?

Hard
486

A SOC analyst is reviewing an alert about a suspicious process execution on a critical server. The alert shows that cmd.exe spawned from Microsoft Word. Which of the following is the BEST next step for the analyst?

Hard
487

A security analyst reviews this configuration and identifies a vulnerability. What is the MOST critical issue?

Easy
488

Drag and drop the steps to perform a vulnerability scan using Nessus into the correct order.

Medium
489

A company is adopting a secure software development lifecycle (SDLC). Which two practices are most effective for identifying vulnerabilities early in the development process? (Select TWO.)

Medium
490

A security architect is evaluating Cloud Security Posture Management (CSPM) tools. Which TWO capabilities are typically provided by CSPM? (Choose two.)

Medium
491

A system administrator needs to securely store cryptographic keys and perform signing operations in a tamper-resistant hardware device. Which solution should be used?

Easy
492

A security analyst is using the MITRE ATT&CK framework to map adversarial behaviors. Which THREE of the following are tactics defined by ATT&CK? (Select THREE.)

Hard
493

An organization is implementing a SOAR solution to automate responses to common incidents. They want to create a playbook for phishing email handling. Which of the following actions should be automated in the playbook after a user reports a suspicious email?

Medium
494

A multinational organization is subject to GDPR and local data protection laws. A data subject from country X requests deletion of personal data, but the data is also required for a legal hold under country Y's law. What is the BEST course of action?

Hard
495

A security engineer is configuring a new web server to support TLS 1.3. The server must provide forward secrecy and support clients that may not have updated certificates frequently. Which of the following is a feature of TLS 1.3 that addresses these requirements?

Medium
496

An organization is deploying a new wireless network for employees and guests. The security policy requires that all wireless traffic be encrypted using AES-CCMP, and that clients must authenticate using 802.1X with EAP-TLS. Which of the following wireless security standards should be implemented?

Easy
497

A threat intelligence analyst is profiling a threat actor that has been targeting the energy sector. Which THREE of the following attributes are most important to include in a threat actor profile? Select THREE.

Hard
498

During a red team exercise, an attacker exploits a vulnerability in a containerized web application to gain a shell. The container is running with a read-only root filesystem. What is the most likely persistence mechanism the attacker will use?

Hard
499

A security architect is reviewing the architecture of a critical web application that handles sensitive financial transactions. The application is deployed across three tiers: a web server, an application server, and a database server. The application is protected by a web application firewall (WAF) and a network-based intrusion detection system (IDS). Recent penetration testing identified a SQL injection vulnerability in the application's search feature. The architect needs to propose a remediation that minimizes performance impact and maintains defense in depth. The development team is slow to fix code due to legacy dependencies. What should the security architect recommend as the MOST effective immediate control?

Medium
500

A SOC analyst discovers unusual outbound traffic from a host in the production DMZ to an unknown IP address on the internet. The traffic consists of encrypted connections (HTTPS) to a domain that was registered three days ago. The host is a web server that has been fully patched and is configured with a default deny egress firewall policy, but this particular traffic is being allowed because a recently added rule permits outbound HTTPS to any destination for a specific application's updates. The security architect is called in to investigate and must determine the best course of action to identify the scope of the potential compromise and prevent further data exfiltration. The architect has access to network flow data, endpoint detection and response (EDR) telemetry, and firewall logs. What should the security architect do FIRST?

Hard
501

Which risk management framework is specifically designed for U.S. federal agencies and includes a six-step process: Categorize, Select, Implement, Assess, Authorize, and Monitor?

Easy
502

A company is migrating to immutable infrastructure for its production environment. The security architect needs to ensure that any changes to the infrastructure are made by replacing instances, not by modifying existing ones. Which security advantage does immutable infrastructure provide?

Hard
503

A security engineer is hardening a Linux web server. The team requires that the web server process cannot run with root privileges and that any file it writes must have minimal permissions. Which two controls should be implemented together? (Select TWO).

Hard
504

A security officer is reviewing continuous compliance monitoring tools. Which TWO of the following are primary benefits of implementing such tools? (Select TWO.)

Medium
505

A security analyst reviews a web application that accepts user-supplied data to generate PDF reports. The application uses a legacy library that directly inserts user input into SQL queries and also includes user input in the PDF generation without sanitization. Which is the most effective countermeasure?

Medium
506

A company wants to implement certificate pinning for its mobile app to prevent man-in-the-middle attacks. Which approach is most secure and maintainable?

Medium
507

A security analyst is calculating the annualized loss expectancy (ALE) for a server that has an asset value of $100,000, an exposure factor (EF) of 0.5, and an annualized rate of occurrence (ARO) of 2. What is the ALE?

Easy
508

During a security assessment, a penetration tester discovers that a web application fails to validate the size of user input, leading to a buffer overflow. Which application security control would have BEST prevented this vulnerability?

Hard
509

A SOC manager is considering implementing a SOAR platform. Which is the primary benefit of SOAR in day-to-day operations?

Medium
510

A financial services company uses a continuous integration/continuous delivery (CI/CD) pipeline to deploy microservices. The security team wants to ensure that no secrets (e.g., API keys, database passwords) are hard-coded in source code repositories. Which tool or practice is most appropriate for detecting secrets before they are committed?

Hard
511

An organization is deploying deception technology to detect lateral movement by attackers. Which of the following would be the most effective to detect an attacker who has gained access to the internal network and is attempting to move to a sensitive server?

Medium
512

A security architect is designing a deception-based detection system for a high-security environment. The goal is to detect lateral movement by attackers who have already breached the perimeter. Which of the following deception techniques would be most effective at identifying an attacker without alerting them to the deception?

Hard
513

A SOC analyst is investigating an alert from the EDR system indicating that a user's workstation made multiple failed login attempts to a sensitive server, followed by a successful login from an unusual IP address. The analyst suspects a brute force attack. Which type of threat hunting methodology is being used?

Medium
514

A healthcare provider is migrating patient records to a cloud EHR system. The security officer is concerned about data ownership and portability. Which contractual clause is MOST critical to include in the cloud service agreement?

Medium
515

A security analyst discovers that an employee has been using a personal USB drive to transfer sensitive customer data from a workstation to a home computer. This violates the company's data handling policy. According to the company's incident response plan, which of the following is the FIRST step the analyst should take?

Medium
516

Which of the following is the primary security benefit of using immutable infrastructure in automated deployments?

Easy
517

During a security incident, the incident response team has identified the root cause and removed the threat from all affected systems. Which phase of the incident response lifecycle involves returning systems to normal operation and monitoring for any signs of recurrence?

Easy
518

A security operations center (SOC) analyst is investigating a potential malware infection on a workstation. The analyst wants to perform static analysis on a suspicious executable. Which tool or technique is most appropriate for examining the executable without executing it?

Medium
519

A security administrator is evaluating ways to improve endpoint detection and response (EDR) capabilities. Which TWO of the following approaches would most effectively enhance the detection of fileless malware attacks?

Medium
520

A Kubernetes pod is defined with the above manifest. Which security concern is most critical?

Hard
521

A security analyst is tuning the SIEM and wants to create a correlation rule that detects potential lateral movement using pass-the-hash attacks. Which log sources are most essential for detecting this technique?

Medium
522

Which TWO of the following are valid techniques to mitigate the risk of side-channel attacks on cryptographic implementations? (Select exactly 2.)

Medium
523

A security architect is designing a PKI for a large enterprise. Which component is used to protect private keys and perform cryptographic operations in a tamper-resistant environment?

Medium
524

A company is migrating its legacy VPN to use IPsec with IKEv2. The security team wants to ensure the strongest possible security. Which THREE configuration options should be selected?

Hard
525

A SOC analyst is investigating a suspicious process that is making outbound connections to an unknown IP address. The analyst wants to examine the process memory for injected code. Which Volatility plugin is most appropriate for detecting code injection by listing all Virtual Address Descriptors (VADs) that are mapped as executable and writable?

Hard
526

Which of the following is the primary advantage of using STIX and TAXII for threat intelligence sharing?

Easy
527

A security architect is designing a just-in-time (JIT) privileged access management (PAM) solution. Which TWO of the following are key characteristics of JIT access?

Medium
528

An organization is migrating to a zero-trust architecture. Which of the following components is CRITICAL for enforcing policy decisions based on user identity, device health, and context?

Hard
529

A technology company suspects an insider threat is exfiltrating intellectual property. The security team has deployed user and entity behavior analytics (UEBA) and set up data loss prevention (DLP) rules. A UEBA alert flags a senior developer who is accessing the source code repository at 2 AM from a VPN connection that routes through a foreign country. The developer also recently downloaded a large quantity of source code—more than 10 times the normal volume. DLP policies are configured to block emails with attachments over 10 MB. Which of the following should the incident response team do FIRST?

Hard
530

A security architect is designing a data lifecycle management program. Which TWO of the following are phases of the data lifecycle? (Select TWO.)

Medium
531

Which THREE of the following are key components of a zero-trust security architecture? (Select THREE).

Hard
532

Which TWO of the following are key components of a governance framework? (Select TWO)

Medium
533

An IAM policy is applied to an AWS user. Which of the following actions is permitted?

Medium
534

Refer to the exhibit. The data classification policy defines levels and rules. During an audit, a database containing both PII and credit card numbers is found labeled as 'Internal'. Which of the following is the BEST first action?

Hard
535

A network administrator is configuring a firewall to block traffic from a specific IP address range. The firewall uses ACLs. Which ACL entry would deny traffic from 192.168.1.0/24?

Medium
536

A security analyst is performing a quantitative risk assessment for a server that processes payment card data. The server has an asset value of $50,000. Based on historical data, the exposure factor (EF) for a ransomware attack is 80%, and the annualized rate of occurrence (ARO) is 0.5. What is the annualized loss expectancy (ALE)?

Medium
537

A security team is evaluating an EDR solution. Which of the following capabilities is a primary differentiator between EDR and traditional antivirus?

Medium
538

An organization wants to deploy a technology that lures attackers into a controlled environment to observe their tactics, techniques, and procedures (TTPs). Which deception technology should the organization implement?

Easy
539

A developer is creating a REST API that handles sensitive data. Which HTTP method should be used for updates that are not idempotent?

Easy
540

A company uses Kubernetes for container orchestration. Which security control should be implemented to enforce that only specific images from a trusted registry can run in the cluster?

Medium
541

A security engineer is configuring SSH for a jump host used to access critical servers. The engineer wants to restrict the cryptographic algorithms to the most secure options. Which of the following should be DISABLED?

Medium
542

Match each encryption standard or algorithm to its type.

Medium
543

An organization's containerized application is deployed on Kubernetes. The security team wants to enforce that containers run with the least privilege and cannot access the host file system. Which Kubernetes security mechanism should be configured?

Hard
544

A security team is implementing controls to meet PCI DSS requirements for cardholder data. Which THREE controls are required?

Easy
545

A vulnerability scanner reports a critical vulnerability with a CVSS base score of 9.8 on a public-facing web server. However, the server has a compensating control: a Web Application Firewall (WAF) that blocks exploit attempts. How should the security team prioritize patching this vulnerability?

Medium
546

A security analyst is evaluating security metrics for the security program. Which TWO of the following are considered key performance indicators (KPIs) for measuring the effectiveness of a security program?

Easy
547

A company is developing a secure software development lifecycle (SDLC) and wants to integrate security testing early. Which THREE techniques should be used to find vulnerabilities in code during development? (Choose three.)

Hard
548

Which of the following is the primary benefit of using infrastructure as code (IaC) for automating security configurations?

Easy
549

A threat hunter is looking for signs of a ransomware attack that encrypts files and drops a ransom note. The hunter decides to search for processes that have modified many files in a short period. Which threat hunting methodology is being used?

Medium
550

Match each security tool to its purpose.

Medium
551

A penetration tester is performing a test against a web application. During active reconnaissance, the tester discovers that the application discloses version numbers in HTTP headers. Which phase of the penetration testing lifecycle does this activity belong to?

Medium
552

An organization is developing a security policy hierarchy. Which TWO of the following correctly represent the typical order from highest to lowest level in a policy framework? (Select TWO.)

Easy
553

Which of the following is the correct order of the security policy hierarchy from highest to lowest?

Easy
554

A security engineer is evaluating a new Hardware Security Module (HSM) for a financial application that requires FIPS 140-2 Level 3 compliance. Which TWO features are required for Level 3 validation? (Select TWO.)

Medium
555

A company processes personal data of EU citizens and wants to implement privacy by design. Which of the following is the BEST first step in this process?

Medium
556

A security architect is planning the migration of a legacy application to a containerized microservices architecture on Kubernetes. The architect must ensure that the architecture supports secrets management, service-to-service authentication, and encryption of data in transit between microservices. Which THREE components should the architect include in the design? (Choose three.)

Hard
557

A security analyst is reviewing a suspicious email reported by a user. The email contains an attachment named 'invoice.pdf.exe'. Which type of malware analysis technique should the analyst perform first to determine if the file is malicious?

Medium
558

A security engineer needs to implement a solution that will detect and block command-and-control (C2) traffic from malware on the internal network. The solution must be able to inspect encrypted traffic and operate at the network layer. Which of the following is the BEST choice?

Medium
559

A security engineer is reviewing the results of a penetration test. The tester successfully exploited a vulnerability in a web application and escalated privileges to domain admin. Which THREE of the following findings should be included in the technical report to provide actionable remediation steps? (Select THREE.)

Hard
560

A security architect is designing a secure enclave for a high-value application. Which of the following is the BEST approach to isolate the application from the rest of the network?

Easy
561

A security architect is designing a data classification scheme. Which of the following is the MOST effective way to ensure consistent labeling across the organization?

Medium
562

Which TWO of the following are key components of a successful incident response plan according to NIST SP 800-61?

Easy
563

Based on the exhibit, which security issue does this IAM policy represent?

Hard
564

An organization is implementing a privacy by design approach for a new customer-facing application. Which of the following actions best exemplifies this principle?

Hard
565

Which of the following is the PRIMARY purpose of a business impact analysis (BIA)?

Easy
566

An organization has implemented a risk treatment plan that includes purchasing cyber insurance for potential data breach costs. Which risk treatment option does this represent?

Hard
567

A security architect is implementing a zero trust architecture for a corporate network. Which TWO principles are fundamental to the zero trust approach? (Choose two.)

Medium
568

An organization is implementing a risk management framework and wants to align with a standard that emphasizes a continuous, iterative process for identifying, assessing, and responding to risk. Which framework is most appropriate?

Medium
569

A vulnerability management team is prioritizing patches for a set of critical vulnerabilities. Vulnerability A has a CVSS base score of 9.8, vulnerability B has a CVSS base score of 7.5, and vulnerability C has a CVSS base score of 8.2. However, vulnerability B is actively being exploited in the wild, while the others are not. Which vulnerability should be patched first according to best practices?

Medium
570

An analyst is examining a memory dump with Volatility and finds a suspicious process that has no parent process (parent PID 0). Which technique is the malware likely using to hide?

Hard
571

A DevOps team is implementing a CI/CD pipeline for a Java application. They want to ensure that all dependencies are scanned for known vulnerabilities before deployment. Which type of tool should they integrate into the pipeline?

Hard
572

A security analyst is reviewing cryptographic implementations for a new application. The application needs to support digital signatures that are quantum-resistant and provide high performance. Which TWO algorithms should the analyst consider? (Select TWO.)

Hard
573

During a security review, you find that a web application uses a Content Security Policy (CSP) header with the value: 'default-src 'self'; script-src 'self' 'unsafe-inline' https://cdn.example.com;'. Which attack is the application still vulnerable to?

Hard
574

A security team is hardening a Kubernetes cluster. Which control should be implemented to restrict a container's system calls to only those required by the application?

Hard
575

A web application generates an Ansible playbook from user input as shown. What is the primary security risk?

Easy
576

Which of the following is a key benefit of using an Extended Detection and Response (XDR) solution over traditional Endpoint Detection and Response (EDR)?

Easy
577

Drag and drop the steps to configure a RADIUS server for 802.1X authentication into the correct order.

Medium
578

In the shared responsibility model for cloud security, which of the following is typically the responsibility of the customer?

Easy
579

A DevSecOps team is integrating security into the CI/CD pipeline. Which THREE practices should be included to ensure supply chain security?

Hard
580

An organization's business continuity plan (BCP) includes a recovery time objective (RTO) of 4 hours for its critical ERP system. During a disaster, the system is restored in 5 hours. Which of the following is the MOST significant impact?

Hard
581

A security architect is designing a cloud security strategy for a healthcare organization that uses a hybrid cloud environment with AWS and Azure. The organization must comply with HIPAA and needs to protect sensitive patient data. Which THREE cloud security controls should be prioritized? (Choose THREE.)

Medium
582

Match each automation security concept (left) with its corresponding best practice (right).

Hard
583

A security architect is reviewing firewall rules for a new application tier. Which TWO of the following principles should be applied when designing the firewall policy? (Choose two.)

Easy
584

A company is preparing for post-quantum cryptography migration. According to NIST PQC standards, which algorithm is a candidate for key encapsulation?

Hard
585

Which of the following is the primary purpose of a honeypot in a security operations environment?

Easy
586

A security analyst receives an alert from the SIEM indicating multiple failed logon attempts from an external IP address followed by a successful logon for a domain admin account. Which phase of the incident response lifecycle is the analyst currently in?

Medium
587

A security analyst is reviewing a Kubernetes cluster's security configuration. Which component should be used to ensure that only authorized pods can communicate with each other?

Easy
588

A company must protect cryptographic keys used to sign financial transactions. The solution must be FIPS 140-2 Level 3 compliant and provide tamper-resistant hardware. Which technology should be deployed?

Hard
589

A security architect is evaluating an API security strategy for a SaaS application that supports OAuth 2.0. Which TWO controls should the architect recommend to protect against token interception and replay attacks?

Medium
590

During a security incident, a forensic investigator needs to capture the contents of volatile memory on a compromised server. Which of the following tools should the investigator use?

Easy
591

Refer to the exhibit. A security analyst notices that traffic from external clients to the web server at 10.0.0.10 port 80 is being blocked. Which of the following is the MOST likely cause?

Medium
592

A security engineer is reviewing a TLS 1.3 configuration. Which of the following is a key feature of TLS 1.3 that improves security compared to earlier versions?

Hard
593

A company is implementing API security for its web services. Which THREE of the following are considered best practices for securing APIs? (Select THREE).

Easy
594

During a digital forensics investigation, an analyst needs to acquire the contents of RAM from a compromised server. Which order of volatility should the analyst follow?

Medium
595

A company uses Terraform to deploy infrastructure on AWS. They have a compliance requirement that all containers running on Amazon ECS must have a read-only root filesystem and must not run as root. The security team needs an automated way to enforce this policy and provide an audit trail for any violations. Which solution best meets these requirements?

Hard
596

A development team wants to deploy a microservices application using containers. They need a solution to automate the deployment, scaling, and management of the containers across a cluster. Which technology is most suitable?

Easy
597

A PKI administrator is deploying certificates for code signing. Which certificate type should be used to ensure that the signed code can be verified by clients without requiring a full chain validation?

Medium
598

A forensic analyst needs to collect volatile data from a live Windows system. In which order should the analyst collect the following data? (Order of volatility)

Easy
599

A PKI administrator is concerned about the risk of a compromised issuing CA. Which certificate transparency feature helps detect unauthorized certificate issuance?

Medium
600

A Windows administrator needs to automate the retrieval of failed login events from the Security log. Which scripting language is most native and efficient for this task?

Easy
601

During a vendor risk assessment, a security analyst reviews a SOC 2 Type II report from a cloud provider. What is the primary value of this report?

Medium
602

An organization is hardening its Kubernetes cluster. Which THREE of the following are effective controls to limit the blast radius of a compromised container?

Medium
603

A SOC team is implementing a SOAR playbook to automate response to phishing emails reported by users. Which step should be included in the playbook to prevent other users from accessing the malicious link?

Medium
604

A company is developing a new mobile app that will process users' biometric data for authentication. The legal team is concerned about compliance with the GDPR's data protection by design. Which of the following is the MOST appropriate control to implement?

Easy
605

Which TWO of the following are advantages of using a hardware security module (HSM) over a software-based cryptographic module? (Select exactly 2.)

Medium
606

An organization is implementing a PKI to issue certificates for internal applications. The security team wants to minimize the risk of compromise to the root CA. Which of the following is the BEST practice to protect the root CA?

Easy
607

Which document in a security policy hierarchy provides specific step-by-step instructions for performing a task?

Easy
608

An organization uses a multi-cloud strategy with workloads in AWS and Azure. The security architect needs to implement a single identity provider for all cloud resources while maintaining on-premises Active Directory as the authoritative source. Which architecture minimizes latency and complexity?

Hard
609

A company is implementing a zero-trust network architecture. Which of the following components is essential for enforcing micro-segmentation?

Medium
610

A healthcare organization is required to comply with HIPAA. During an audit, the auditor requests evidence of access controls for electronic protected health information (ePHI). Which of the following would be the BEST evidence to provide?

Medium
611

During a security assessment, a penetration tester discovers that a web application's session tokens are predictable. The application uses a custom session management system. Which of the following is the MOST effective remediation to ensure secure session tokens?

Hard
612

A healthcare organization subject to HIPAA must ensure that patients can access their medical records. This requirement is an example of which data subject right under privacy regulations?

Medium
613

Which TWO of the following are valid methods for securing REST APIs? (Select TWO.)

Medium
614

Refer to the exhibit. Based on the data classification policy JSON, what action is MOST consistent with the policy?

Medium
615

During a security audit, it was discovered that an HSM used for code signing is FIPS 140-2 Level 3 certified. The auditor is concerned about the key ceremony process. Which of the following is a required element of a secure key ceremony for an HSM at this level?

Hard
616

An organization is designing a PKI for certificate lifecycle management. Which TWO practices are critical for maintaining the security of the certificate authority (CA)? (Select TWO.)

Medium
617

An organization is using the FAIR framework to quantify risk. The analyst estimates the probable loss event frequency (LEF) as 4 per year and the probable loss magnitude (LM) as $25,000 per event. What is the annualized loss expectancy (ALE) under FAIR?

Hard
618

An organization discovers a critical vulnerability in a legacy application that cannot be patched due to vendor end-of-life. Which of the following is the BEST compensating control to reduce risk?

Medium
619

A healthcare organization is planning to migrate patient data to a cloud provider. The risk assessment identifies that the provider's SOC 2 report does not cover HIPAA controls. What is the BEST course of action?

Hard
620

A security architect is designing a secure software development lifecycle (SSDLC). Which of the following practices are essential for integrating security into the development process? (Select TWO.)

Hard
621

A security architect is designing a zero trust architecture for a financial institution. Which principle is fundamental to the zero trust model?

Easy
622

Refer to the exhibit. A security analyst notices that the pod is running with a service account token mounted. Which security best practice should be implemented to reduce the risk of token theft in container environments?

Medium
623

A company is deploying a new cloud-based application that processes sensitive customer data. The security architect has proposed a zero-trust architecture to secure remote access. The architecture includes identity-aware proxies, microsegmentation, and continuous monitoring. During the transition, several remote users report being unable to access the application. The security architect verifies that the identity-aware proxy is correctly configured and that users are authenticated via SSO. However, access attempts are still failing. The architect suspects that the issue may be related to the microsegmentation rules. What should the security architect do FIRST to resolve the problem?

Easy
624

An organization is implementing continuous compliance monitoring. Which of the following metrics would best indicate whether the organization is maintaining compliance with PCI DSS Requirement 10 (log management)?

Hard
625

During a vendor risk assessment, a third-party vendor refuses to provide a SOC 2 report but offers a completed security questionnaire. The vendor handles sensitive customer data. Which of the following is the BEST course of action?

Medium
626

A company is implementing a privileged access management (PAM) solution to reduce the risk of standing privileges. Which feature allows users to request temporary elevated access for a specific task, which is automatically revoked after the task is completed?

Medium
627

An organization is designing a PKI to issue certificates to thousands of IoT devices. Which architectural decision will BEST support automated certificate lifecycle management?

Medium
628

A security analyst discovers that a web application is vulnerable to directory traversal. Which of the following is the MOST effective mitigation?

Medium
629

A security analyst is investigating a malware sample and wants to determine its capabilities without executing it. The analyst examines the binary's imports, strings, and structure. What type of analysis is being performed?

Hard
630

An enterprise is implementing a cloud security posture management (CSPM) solution. What is the primary function of CSPM?

Medium
631

A security architect is designing a secure coding standard for a web application. Which of the following should be prioritized to mitigate cross-site scripting (XSS) risks?

Medium
632

An organization needs to ensure compliance with GDPR regarding data subject access requests. What is the MOST important control to implement?

Easy
633

A security analyst is reviewing CVSS scores for vulnerability prioritization. Which TWO of the following are component metric groups in CVSS v3?

Easy
634

A security architect is designing an API security strategy for a microservices-based application. The architect needs to ensure that only authenticated and authorized clients can invoke APIs, and that rate limiting is enforced to prevent abuse. Which technology should be placed in front of the microservices?

Hard
635

A security administrator needs to ensure that only authorized devices can access the corporate network. Which technology would best enforce this requirement at the network access layer?

Easy
636

During a forensic investigation, the examiner discovers that the chain of custody documentation was not properly maintained for a critical hard drive. What is the most likely consequence?

Hard
637

During a penetration test, the tester has gained initial access to a web server and wants to move laterally to a database server. Which of the following techniques would be most effective for identifying valid credentials that could be reused on the database server?

Medium
638

Match each security feature to its description.

Medium
639

Which of the following is a key difference between a security guideline and a security procedure?

Easy
640

An organization wants to implement an immutable infrastructure for its containerized applications. Which security benefit is most directly achieved by immutability?

Hard
641

An incident response team discovers that an attacker was able to forge a certificate for a legitimate domain. Which TWO mechanisms should the team implement to detect and prevent such misissuance in the future? (Select TWO.)

Hard
642

Match each cloud service model to its scope.

Medium
643

A SOC analyst notices that a containerized application is making unexpected outbound connections. The container runs with minimal privileges. Which step should the analyst take first to investigate without compromising the environment?

Hard
644

An organization is implementing SASE to secure remote user access. Which component of SASE is responsible for enforcing identity-based access policies and inspecting traffic?

Medium
645

A company is implementing a new vendor risk management program. Which of the following is the BEST approach to assess third-party security controls?

Medium
646

A company uses a hybrid cloud model with workloads on AWS and on-premises. They need to ensure secure connectivity between the two environments with high bandwidth and low latency, bypassing the public internet. Which solution should they implement?

Medium
647

A security analyst is calculating the annualized loss expectancy (ALE) for a server. The single loss expectancy (SLE) is $5,000 and the annualized rate of occurrence (ARO) is 0.2. What is the ALE?

Easy
648

A security engineer is evaluating hardware security modules (HSMs) for key management. The HSM must support key generation, storage, and cryptographic operations without exposing private keys. Additionally, the solution must comply with FIPS 140-2 Level 3. Which THREE features are essential for this requirement? (Select THREE.)

Medium
649

An organization discovers that a vendor's data breach exposed customer PII. The contract with the vendor does not address breach notification. What is the BEST way to prevent this in the future?

Medium
650

A security architect is designing a zero-trust network architecture for a hybrid cloud environment. Which TWO principles should be implemented to enforce the "never trust, always verify" model?

Easy
651

A company is conducting a third-party risk assessment of a cloud service provider. Which TWO of the following are appropriate sources of evidence for evaluating the provider's security controls? (Select TWO.)

Medium
652

During a third-party risk assessment, an organization discovers that a cloud service provider (CSP) stores data in a jurisdiction with conflicting privacy laws. The organization's legal team advises that this could expose the organization to regulatory penalties. Which of the following contractual clauses would best address this compliance risk?

Hard
653

An organization uses a TPM 2.0 for measured boot and attestation. Which TPM feature ensures that the boot process has not been tampered with by measuring each component before it executes?

Medium
654

A security architect is implementing network segmentation in a hybrid cloud environment. Which TWO controls are most effective for reducing east-west traffic risks?

Medium
655

A company is adopting the NIST Risk Management Framework (RMF). Which step in the RMF involves selecting security controls based on the risk assessment?

Medium
656

Which two of the following are best practices for securing container orchestration platforms (e.g., Kubernetes)? (Select two.)

Medium
657

Which of the following is the primary purpose of implementing a public key infrastructure (PKI)?

Easy
658

An enterprise is deploying a multi-factor authentication (MFA) solution. The security team requires a factor that is resistant to phishing and does not rely on shared secrets. Which of the following MFA types BEST meets this requirement?

Easy
659

A company is migrating sensitive workloads to the cloud and must comply with FedRAMP requirements. Which of the following is the most appropriate cloud deployment model?

Medium
660

A financial organization's SOC analysts have observed repeated failed authentication attempts from a single external IP address against multiple user accounts, followed by a successful authentication from the same IP using one of those accounts. Which type of security monitoring rule would be most effective at detecting this attack pattern in real time?

Medium
661

A small business wants to protect endpoints from malware without incurring per-device licensing costs. Which approach is MOST cost-effective?

Easy
662

An organization is planning to deploy a new internal CA hierarchy. Which THREE considerations are critical for ensuring the security and manageability of the PKI?

Hard
663

A security manager is developing key risk indicators (KRIs) for the organization's cybersecurity program. Which THREE of the following are examples of KRIs? (Select THREE.)

Hard
664

Match each command-line tool to its primary function.

Medium
665

A security architect is implementing a zero trust model for a financial services company. The goal is to prevent lateral movement in the data center. Which approach best achieves this objective?

Medium
666

A SOC analyst is reviewing a large volume of failed login attempts across multiple user accounts from a single external IP address. The attempts use common usernames and passwords over SSH (port 22). Which security control would be most effective at preventing this type of attack?

Medium
667

Refer to the exhibit. A security analyst is reviewing the Nginx configuration. Which of the following is the most critical security flaw?

Hard
668

During a security incident, a forensic analyst needs to acquire a memory dump from a Linux server without altering the system state. Which tool is most appropriate for this task?

Hard
669

A large enterprise is implementing a SOAR platform to automate incident response. The security team wants to create a playbook for handling phishing emails reported by users. The playbook should: 1) validate the reported email by checking headers and attachments, 2) automatically block the sender's domain at the email gateway if malicious, 3) create a ticket, and 4) send an automated response to the user. Which of the following describes the best approach to design this playbook?

Hard
670

A network administrator is configuring a firewall to allow only necessary traffic to a web server. The server should be accessible from the internet on port 443 and from a management subnet on port 22. Which firewall rule ensures least privilege?

Easy
671

Using the FAIR model, which of the following best describes the factor that represents the probable frequency of a threat acting on a vulnerability?

Hard
672

A security analyst is reviewing a suspicious process that has been identified on an endpoint. The analyst wants to determine if the process has any network connections and what data it might be sending. Which tool is most appropriate for analyzing the memory of the affected system to identify network connections and potential data exfiltration?

Medium
673

Which THREE of the following are required for PCI DSS compliance regarding cardholder data?

Hard
674

A cloud security architect is designing a key management system for a multi-tenant SaaS application. Which TWO practices are essential for ensuring cryptographic key security? (Select TWO).

Easy
675

A small business has a single physical server running multiple virtual machines (VMs) using Type 2 hypervisor software on a Windows Server host. The host is not joined to a domain. The VMs include an Active Directory domain controller, a file server, and a web server. The company recently suffered a ransomware attack that encrypted all data on the file server VM. The IT administrator restored the file server from a backup, but the ransomware returned within hours. Analysis shows that the ransomware is now spreading to other VMs. The administrator suspects that the hypervisor host itself may be compromised. Which of the following is the MOST effective immediate action to contain the spread and secure the environment?

Easy
676

Refer to the exhibit. A security analyst reviews the following firewall rule on a border firewall. Which vulnerability is present?

Medium
677

A defense contractor is developing a new secure messaging application for classified communications. The application must ensure end-to-end encryption, perfect forward secrecy, and resistance to quantum computing attacks. The development team proposes using ECDH for key exchange and AES-256-GCM for message encryption. The security architect reviews the design and identifies a weakness: the current key exchange does not authenticate the public keys, making it vulnerable to man-in-the-middle attacks. The team suggests adding digital signatures using RSA-2048. However, the architect is concerned about quantum resistance. What should the architect recommend?

Medium
678

A security manager is selecting metrics to present to the board. Which two of the following are key risk indicators (KRIs) that would be most relevant for executive oversight? (Choose two.)

Medium
679

A mid-sized e-commerce company has recently experienced a data breach where customer payment card information was exfiltrated. The security team has identified that the breach originated from a compromised web server that was part of a PCI DSS compliant environment. The server was running outdated software and had several known vulnerabilities. Post-incident analysis reveals that the attacker exploited a SQL injection vulnerability in the order-tracking feature. The incident response team followed NIST SP 800-61 guidelines: they contained the threat, eradicated the malicious code, and restored the server from a known clean backup. However, two weeks after the restoration, the same server is again showing signs of similar malicious activity. The server is still in production and handling credit card transactions. Which of the following is the MOST effective course of action to prevent this recurring compromise?

Hard
680

A financial institution needs to ensure that transaction logs are tamper-proof after creation. Which solution should be implemented?

Medium
681

A security analyst is analyzing a memory dump using Volatility. The analyst wants to list all running processes and identify any hidden processes. Which Volatility plugin should be used?

Hard
682

A company is implementing a passwordless authentication solution using FIDO2/WebAuthn. What is the primary security advantage of this approach over traditional password-based authentication?

Easy
683

An organization is implementing a third-party risk management program. Which of the following is the FIRST step in the vendor risk assessment process?

Easy
684

After a risk assessment, a company identifies that the residual risk for a critical application is higher than the risk appetite. The risk owner proposes implementing additional controls to reduce the risk further. Which risk treatment option does this represent?

Hard
685

A security manager is reviewing the organization's security policy hierarchy. Which of the following correctly orders these documents from highest to lowest level of authority?

Medium
686

Drag and drop the steps to respond to a ransomware incident in the correct order.

Medium
687

A security architect is designing a VPN solution for remote employees. The company requires strong authentication and integrity protection but is less concerned about confidentiality for non-sensitive traffic. Which protocol is most appropriate?

Medium
688

A penetration tester is preparing for an engagement and must define the rules of engagement (ROE) with the client. Which TWO of the following should be included in the ROE? Select TWO.

Medium
689

A security team is auditing a Kubernetes cluster. They find a pod running with `securityContext`: `privileged: true` and `runAsUser: 0`. Which of the following is the most critical risk?

Hard
690

A company is migrating critical applications to a multi-cloud architecture using AWS and Google Cloud Platform (GCP). The security team must ensure secure connectivity between on-premises data centers and cloud environments while meeting data residency requirements in the EU. Which TWO solutions should the architect implement to address these requirements? (Choose TWO.)

Hard
691

A security analyst is performing incident response and needs to collect evidence from a live system. Which of the following should be collected first to preserve volatile data?

Easy
692

A security analyst is investigating a potential malware infection on a user's workstation. The analyst wants to examine the file system for any suspicious files without altering the original data. Which forensic principle is the analyst following?

Easy
693

A healthcare organization must comply with HIPAA. Which of the following is a key requirement for protecting electronic protected health information (ePHI)?

Medium
694

A security architect is evaluating a new cloud SaaS application that will handle sensitive customer data. The SaaS provider offers a shared responsibility model where the customer is responsible for data classification, access management, and encryption of data at rest using customer-managed keys. The architect must ensure that the organization retains the ability to revoke access to the data if the provider is compromised. Which key management strategy best meets this requirement?

Hard
695

A security architect is designing a network segmentation strategy for a data center to reduce the attack surface. Which TWO of the following are best practices for implementing effective network segmentation?

Medium
696

A company is implementing a microservices architecture and needs to ensure secure service-to-service communication. Which of the following BEST describes the recommended approach?

Easy
697

A security engineer is configuring a VPN between two sites and needs to ensure data confidentiality and integrity. Which IPsec mode and protocol combination should be used to encrypt the entire IP packet including the header?

Easy
698

An organization wants to implement continuous compliance monitoring for PCI DSS. Which of the following tools would be MOST effective for this purpose?

Easy
699

A company is migrating its monolithic application to a microservices architecture. The security team wants to implement controls to protect inter-service communication and ensure data integrity. Which THREE security controls should be implemented? (Select THREE.)

Medium
700

Which of the following is the BEST practice for securely storing secrets (e.g., database passwords) in a cloud-native application?

Easy
701

A security analyst observes that SSH connections to the server are failing, but HTTP and HTTPS traffic works. Based on the exhibit, what is the most likely cause?

Hard
702

A security architect is designing a zero-trust network architecture. Which of the following is a fundamental principle of zero trust?

Medium
703

A company is evaluating a new cloud service provider. The provider has a SOC 2 Type II report covering the previous year. Which additional assurance should the company request to verify the provider's current security controls?

Medium
704

A security architect is designing a secure connection between an on-premises data center and a cloud provider's virtual network. The connection must be private, low-latency, and not traverse the public internet. Which solution should they recommend?

Medium
705

A company's development team uses a CI/CD pipeline hosted in a public cloud. The pipeline builds container images, pushes them to a private registry, and deploys them to a Kubernetes cluster. A security engineer must ensure that only signed and vulnerability-scanned images are deployed. The engineer has configured the registry to require signatures and the CI/CD pipeline to scan images. However, deployments are still failing because unsigned images are being pulled. The engineer discovers that developers can push images directly to the registry bypassing the CI/CD pipeline and that Kubernetes nodes can pull images without signature verification. Which of the following should the engineer implement to enforce image signing and scanning?

Easy
706

An IoT device manufacturer wants to ensure the security of over-the-air (OTA) firmware updates. Which TWO measures are essential to protect the update process?

Easy
707

Refer to the exhibit. Which of the following best describes the security constraint imposed by this policy?

Medium
708

A security architect is designing a hybrid cloud environment with workloads in AWS and on-premises. The architect needs to ensure secure, low-latency connectivity between the two environments without traversing the internet. Which solution should be used?

Hard
709

A financial institution is implementing a privacy program based on GDPR principles. Which of the following best describes the concept of 'privacy by design'?

Hard
710

During a merger, two companies need to integrate their networks securely. Company A uses RFC 1918 addresses (10.0.0.0/8) and Company B also uses 10.0.0.0/8. Which architectural solution prevents routing conflicts and maintains security?

Medium
711

An organization is concerned about future quantum computer attacks on their public key infrastructure. Which NIST-standardized algorithm is designed for digital signatures and is resistant to quantum attacks?

Hard
712

A security engineer is writing a Python script to automate the revocation of compromised certificates using the ACME protocol. The script uses the `acme` library and requires secure credential storage. Which method is MOST appropriate for storing the ACME account private key used for authentication?

Hard
713

A security architect is designing a data classification scheme. Which classification level should be used for data that, if disclosed, could cause serious damage to the organization's reputation or financial standing?

Hard
714

A cloud security architect is designing a multi-region active-active application. The application must maintain high availability even if an entire AWS region fails. Which architecture BEST meets this requirement?

Hard
715

A company is implementing a zero-trust network architecture. Which THREE of the following are critical components of this approach?

Hard
716

A company is adopting a DevOps model and wants to integrate security into CI/CD pipelines. Which of the following is the MOST effective approach?

Medium
717

Refer to the exhibit. A cloud security engineer is reviewing an AWS S3 bucket policy. What security issue does the policy contain?

Hard
718

A security architect is designing a defense-in-depth strategy for a web application. Which combination of controls provides overlapping protection against SQL injection attacks?

Medium
719

A security analyst is investigating a potential advanced persistent threat (APT) that has evaded traditional signature-based defenses. The analyst hypothesizes that the attacker is using a specific technique from the MITRE ATT&CK framework: process injection. Which threat hunting methodology is most appropriate for this scenario?

Hard
720

A financial institution is implementing a secure software development lifecycle (SSDLC) for a new web application that will handle sensitive transactions. The security architect must ensure that application security testing is integrated into the development process. Which THREE testing techniques should be used to identify vulnerabilities early and throughout the lifecycle? (Choose THREE.)

Medium
721

During an incident response exercise, a company discovers that sensitive data was exfiltrated. The CIRT needs to determine the root cause and prevent recurrence. Which THREE of the following steps are part of the lessons learned process? (Choose THREE.)

Hard
722

An organization uses a CI/CD pipeline that builds Docker images and pushes them to a private registry. A security analyst discovers that some images contain environment variables with database credentials. Which of the following is the most effective way to prevent this in the future?

Hard
723

A company uses a multi-cloud strategy with workloads in AWS and Azure. They need a centralized solution to enforce consistent security policies across both cloud environments. Which type of tool should they deploy?

Medium
724

A company's security policy requires all sensitive data to be encrypted at rest. However, a business unit requests an exception to store certain data unencrypted due to performance constraints. Which document should govern the exception process?

Medium
725

A security analyst is using a SOAR platform to automate response to phishing emails reported by users. The playbook should perform the following actions in order: (1) extract indicators from the email, (2) query threat intelligence feeds for reputation, (3) if malicious, block the sender's domain at the email gateway and delete the email from all user inboxes. Which type of playbook step is most appropriate for step 3?

Hard
726

A security analyst is reviewing a third-party assessment report and notes that the vendor's encryption algorithms are outdated. The contract requires the vendor to follow industry best practices. Which of the following is the BEST response?

Hard
727

A small business is implementing a privacy impact assessment (PIA) for a new application that processes personal data of EU citizens. Which TWO of the following are required under GDPR?

Medium
728

A security team is analyzing a suspicious binary using static analysis. They run the strings command and observe references to 'CreateRemoteThread' and 'WriteProcessMemory'. Which technique is the binary likely employing?

Hard
729

A security architect is designing a VPN that requires both authentication and encryption. Which IPsec protocol provides both services in a single protocol?

Easy
730

A multinational corporation must comply with GDPR, CCPA, and LGPD. The CISO proposes a unified data classification policy. Which approach best minimizes compliance conflicts?

Medium
731

A security manager is reviewing the company's security policy hierarchy. Which of the following correctly orders these documents from highest to lowest authority?

Medium
732

A company is migrating to a zero trust architecture. Which of the following is a key principle of zero trust?

Hard
733

A security manager is evaluating two risk quantification approaches: Factor Analysis of Information Risk (FAIR) and a qualitative heat map. Which of the following is a key advantage of using FAIR over the qualitative heat map?

Hard
734

During a secure SDLC, a development team wants to identify vulnerabilities in running code. Which type of testing should be performed?

Easy
735

During a security assessment, an engineer discovers that a smartcard used for authentication is vulnerable to side-channel attacks. Which countermeasure would best mitigate power analysis attacks?

Hard
736

An organization is implementing a hybrid cloud architecture and must ensure secure connectivity between its on-premises network and a public cloud VPC. The traffic includes sensitive data that must not traverse the internet. The solution must provide high bandwidth and low latency. Which connectivity option should the architect choose?

Hard
737

Which THREE of the following are required for a valid Business Associate Agreement (BAA) under HIPAA? (Select THREE)

Hard
738

An organization is deploying a Kubernetes cluster and needs to harden security. Which THREE controls should be implemented? (Choose three.)

Medium
739

A penetration tester is planning a test for a client that has a critical web application. The rules of engagement specify that the tester must avoid causing a denial of service (DoS). Which THREE actions are appropriate for the tester to include in the scope? (Select THREE.)

Easy
740

A security architect is implementing defense-in-depth for a critical application. Which of the following is an example of a detective control?

Easy
741

Match each error code or HTTP status code to its meaning.

Medium
742

During a penetration test, an assessor successfully exploits a timing side-channel attack to extract an ECDSA private key from a secure enclave. Which TWO mitigations should the development team implement to prevent such attacks? (Select TWO.)

Hard
743

To protect against quantum computing attacks, a security architect is planning to transition to post-quantum cryptography. Which algorithm has been selected by NIST for general encryption (key encapsulation) in the PQC standard?

Hard
744

During a security assessment, a tester finds that a web application accepts user input and directly uses it in an LDAP query without sanitization. Which of the following attacks is most likely to be successful?

Hard
745

A DevOps engineer is automating the deployment of a web application using containers. Which of the following security practices should be implemented to reduce the attack surface of the containers? (Select TWO.)

Medium
746

An organization is implementing a CASB to secure their SaaS applications. Which CASB deployment mode is most appropriate for monitoring and controlling data in transit between users and cloud apps without modifying the user's device?

Hard
747

A security operations center (SOC) analyst is tuning a SIEM correlation rule to detect a known attack pattern that involves multiple failed logins followed by a successful login from a different IP address. Which approach best reduces false positives while maintaining detection effectiveness?

Hard
748

During an incident response, a security analyst identifies a previously unknown malware variant. Which type of threat intelligence feed would provide the most timely and structured information about this threat?

Medium
749

A small business wants to achieve compliance with the Payment Card Industry Data Security Standard (PCI DSS). Which of the following is an essential requirement they must implement?

Easy
750

A security engineer is implementing deception technology to detect lateral movement by adversaries. Which type of deception resource would be MOST effective for capturing adversary credential harvesting activities on a network segment that contains no real domain controllers?

Hard
751

A company has implemented a hardware security module (HSM) to manage cryptographic keys for a payment processing system. Which of the following best describes an advantage of using an HSM over software-based key storage?

Medium
752

A security architect is designing a risk mitigation strategy for a critical application. Which TWO of the following are examples of risk acceptance? (Select TWO.)

Medium
753

A security architect is evaluating a CSPM tool for a multi-cloud environment. Which TWO capabilities should the architect consider essential for the CSPM? (Choose two.)

Medium
754

An IoT device manufacturer wants to ensure that firmware updates are authentic and have not been tampered with. The device has limited computational resources. Which cryptographic primitive is most appropriate for verifying the integrity and authenticity of firmware images?

Medium
755

A company is implementing privileged access management (PAM) for its critical servers. Which THREE practices should be included to enhance security? (Select THREE.)

Medium
756

Which of the following is a core principle of the Zero Trust security model?

Easy
757

Which security issue is addressed by this configuration?

Easy
758

A global e-commerce company processes payment card data and is required to comply with PCI DSS. During a quarterly vulnerability scan, the security team discovers that a web application firewall (WAF) rule is blocking legitimate traffic, causing transaction failures. The WAF is a critical compensating control for a known vulnerability in the application that cannot be patched for 90 days. The compliance officer is concerned about maintaining PCI DSS compliance while ensuring business continuity. The security team proposes temporarily disabling the WAF to restore service while they fine-tune the rules. Which of the following is the BEST action?

Hard
759

An organization is implementing a zero trust architecture (ZTA). The security architect proposes using a software-defined perimeter (SDP) to replace the traditional VPN for remote access. Which of the following best describes the primary security benefit of SDP over VPN in a zero trust model?

Hard
760

Which TWO of the following are effective defenses against Server-Side Request Forgery (SSRF) attacks? (Select TWO.)

Hard
761

An organization is migrating critical workloads to the cloud and must comply with FedRAMP. Which cloud service model provides the most customer control over security configuration while still leveraging the provider's FedRAMP authorization?

Hard
762

After a security incident, the IR team identifies that the attacker used a spear-phishing email with an attached malicious macro. Which log source would be MOST crucial to determine the scope of the compromise?

Medium
763

An organization is concerned about quantum computer attacks on its current cryptographic infrastructure. Which of the following NIST-approved post-quantum cryptographic algorithms is designed for key encapsulation?

Medium
764

An organization is implementing a public key infrastructure (PKI). Which THREE of the following are essential components?

Easy
765

An organization needs to demonstrate compliance with the General Data Protection Regulation (GDPR) for processing personal data of EU citizens. Which of the following is a mandatory requirement under GDPR?

Easy
766

A CSIRT is developing a threat hunting hypothesis based on the MITRE ATT&CK framework. Which THREE of the following are techniques that threat hunters would commonly investigate for initial access? (Choose three.)

Hard
767

During a security incident, a SOC analyst identifies a process with a suspicious hash on several endpoints. The analyst wants to determine if this hash is known to be malicious by querying internal and external threat intelligence sources. Which standard should the analyst use to structure the threat intelligence data for automated sharing?

Medium
768

A security team is automating incident response using playbooks. Which two of the following are critical considerations when designing automated response actions? (Select two.)

Hard
769

A network architect is designing a DMZ for a web application. Which of the following is the MOST appropriate placement for a reverse proxy?

Easy
770

A financial services company is implementing a risk management framework. The security team has identified that the current encryption algorithm for customer data in transit is deprecated. According to NIST SP 800-53, which of the following is the MOST appropriate step to address this finding?

Medium
771

A DevOps team is automating server configuration using configuration management tools. Which THREE principles should be followed to ensure secure automation? (Choose three.)

Hard
772

Drag and drop the steps to perform a secure code review for a web application into the correct order.

Medium
773

You are a security consultant for a law firm that handles highly confidential client data. The firm wants to implement a data loss prevention (DLP) solution to prevent sensitive data from leaving the network via email. The firm's email system is Microsoft 365. The DLP policy must comply with the firm's data classification policy, which identifies 'Legal Strategy' as top secret and 'Client Contact Info' as confidential. The firm also wants to allow attorneys to send confidential information to clients with a business justification. Which of the following DLP rule configurations best meets these requirements?

Medium
774

A security analyst reviews the syslog messages from the company's ASA firewall. Based on the exhibit, which of the following is the MOST likely cause of the denied traffic?

Hard
775

A security architect is evaluating a SASE solution. Which capability is expected to be part of a SASE platform?

Medium
776

A company is designing a secure web application that processes credit card payments. The architect needs to ensure that the application is resilient against SQL injection attacks. Which of the following is the most effective defense?

Medium
777

A security engineer is reviewing the configuration of a web application firewall (WAF) that protects a critical e-commerce site. Which TWO settings should be enabled to defend against SQL injection attacks? (Select TWO.)

Medium
778

A security engineer is reviewing a PKI deployment where the root CA is kept offline. The issuing CA signs certificates for internal applications. Recently, a subordinate CA was compromised, and the engineer needs to revoke all certificates issued by that CA. Which of the following is the most efficient method to revoke these certificates?

Hard
779

A security analyst is reviewing a SIEM alert that indicates a user's credentials were used to log in from two different countries within a span of 10 minutes. This is likely an indicator of what type of attack?

Easy
780

During a security assessment, a penetration tester discovers that a smart card used for authentication is vulnerable to a timing attack. The card uses a cryptographic algorithm that has data-dependent timing variations. Which of the following algorithms is MOST likely being used on the smart card?

Hard
781

A security architect is reviewing API security for a financial services platform that uses OAuth 2.0 for authorization and JWTs for token exchange. The platform must protect against common API threats such as token theft and injection attacks. Which TWO controls should be implemented to mitigate these specific threats? (Choose TWO.)

Medium
782

A DevOps team uses Ansible to automate server configuration. They need to ensure that sensitive variables like passwords are not exposed in playbook logs or version control. What is the recommended approach?

Medium
783

A security team is measuring the effectiveness of its incident response process. Which of the following metrics would best indicate how quickly the team can contain an incident after it is detected?

Medium
784

What is the primary benefit of using infrastructure as code (IaC) tools like Terraform for cloud resource provisioning?

Easy
785

Refer to the exhibit. A security review is being conducted on the Python application configuration. Which of the following security issues is present?

Easy
786

An enterprise is securing a hybrid cloud environment with on-premises and AWS workloads. They need to ensure that on-premises systems can privately access VPC resources without traversing the public internet. Which AWS service should they use?

Hard
787

A threat hunter hypothesizes that a sophisticated attacker is using DNS tunneling for command and control. Which data source would most likely confirm this activity?

Medium
788

A security team needs to automate the enforcement of cloud security policies across multiple accounts in AWS. They want a solution that uses code to define policies and automatically remediate violations. Which approach best meets these requirements?

Hard
789

A company wants to automate the creation of IAM roles and policies in AWS using infrastructure as code. Which tool is specifically designed for provisioning cloud infrastructure across multiple providers?

Easy
790

A security analyst at a large enterprise notices that several servers have missing security patches that are critical. The patch management process requires approval from the change advisory board (CAB) which meets weekly. The next meeting is in three days, but the vulnerability is being actively exploited. What should the analyst do?

Medium
791

A vulnerability has a CVSS base score of 9.8. The vulnerability is present on a server that is not exposed to the internet but is accessible to internal users with valid credentials. Which CVSS metric should be adjusted to reflect the reduced risk?

Medium
792

A security architect is designing a zero-trust network architecture for a hybrid cloud environment. The company uses on-premises servers and AWS. Which of the following best implements the principle of least privilege for inter-component communication?

Medium
793

A SOC team is implementing a SOAR playbook to automate the response to phishing emails reported by users. The playbook should perform initial triage and, if the email is determined to be malicious, take containment actions. Which TWO of the following actions should be included in the playbook? (Choose TWO.)

Medium
794

A company wants to ensure that only authorized code runs on its point-of-sale (POS) terminals. Which technology should be implemented?

Easy
795

A security analyst is investigating a potential data exfiltration incident. The analyst needs to preserve evidence for legal proceedings. Which two actions must the analyst take to maintain the chain of custody? (Select TWO).

Medium
796

An incident responder notices that a compromised host is sending encrypted C2 traffic over TCP port 443. The existing firewall rule allows outbound HTTPS (443) to any destination. Which change to the security architecture would best detect this behavior while minimizing impact on legitimate traffic?

Medium
797

A large enterprise is designing a disaster recovery site that must support rapid failover with minimal data loss. The primary data center is 50 miles away. The RPO is 1 minute, and RTO is 15 minutes. Which replication strategy best meets these requirements?

Hard
798

During a security assessment, the engineer discovers that a network appliance's firmware updates are signed using a 1024-bit RSA key. The appliance was manufactured in 2015. What is the primary security concern?

Hard
799

A security architect is designing a new DMZ for an e-commerce platform. The DMZ must host a web server, an API gateway, and a database server. The architect needs to minimize the attack surface while ensuring the web server can communicate with the API gateway, and the API gateway can communicate with the database. Which network segmentation approach best meets these requirements?

Medium
800

A company is adopting a serverless architecture using AWS Lambda. Which of the following are security concerns specific to serverless functions? (Select TWO.)

Medium
801

The Docker container `myservice` has the mount configuration shown. What is the most significant security implication of this configuration?

Medium
802

An organization wants to reduce the attack surface of its web servers by ensuring only necessary modules are enabled. Which practice directly supports this goal?

Easy
803

A security architect is designing a PKI for a large organization. The architect wants to ensure that private keys are stored securely and that cryptographic operations are performed in a tamper-resistant environment. Which solution should be used?

Hard
804

A security architect is evaluating a web application that uses JSON Web Tokens (JWTs) for authentication. The application uses an RSA256 asymmetric signing algorithm. The architect discovers that the JWT library accepts tokens with the algorithm set to 'none' if the public key is not provided during verification. Which of the following attacks is most likely to succeed if the application does not enforce algorithm validation?

Hard
805

During a penetration test, a tester finds that an application uses server-side sessions with predictable session IDs. Which attack is this vulnerability most likely to facilitate?

Hard
806

An organization is developing a SOAR playbook to handle phishing emails reported by users. Which of the following actions is most appropriate to automate in the first step of the playbook?

Easy
807

An organization is adopting a SASE architecture to provide secure access to cloud applications. Which component is essential for enforcing security policies based on user identity and device posture?

Hard
808

After containing a confirmed security incident, the incident response team must plan for eradication. What must be done before eradication begins?

Hard
809

A security analyst is reviewing the results of a vulnerability scan and identifies a critical vulnerability in a legacy application that cannot be patched because it is no longer supported by the vendor. The application is critical for business operations. Which of the following risk treatment strategies should the organization implement?

Medium
810

A security engineer is hardening a Linux server. Which TWO of the following are best practices for preventing privilege escalation attacks?

Easy
811

An IoT device uses a Trusted Platform Module (TPM) 2.0 for secure boot and attestation. Which THREE of the following functions does the TPM provide to support these security features?

Medium
812

During a penetration test, the tester has gained initial access to a system and wants to escalate privileges. Which of the following techniques is most likely to be effective for privilege escalation on a Windows system?

Medium
813

Which of the following best describes the security benefit of using an API gateway in a microservices architecture?

Easy
814

A security architect is evaluating a SASE solution. Which component of SASE is primarily responsible for inspecting encrypted traffic for threats?

Medium
815

In a CI/CD pipeline, a security gate fails because a high-severity vulnerability is found in the base image of a container. The pipeline is configured to block deployment on such findings. What is the appropriate remediation step?

Medium
816

The engineer needs to prevent brute-force attacks while allowing legitimate access. Which security control is MOST effective?

Hard
817

A company is migrating its workloads to a public cloud and wants to ensure it understands the division of security responsibilities. Which model defines the demarcation of security controls between the cloud provider and the customer?

Medium
818

During a penetration test, the tester has gained initial access to a web server and wants to perform lateral movement to reach a database server. The tester enumerates the network and finds that the web server has two network interfaces: one connected to a DMZ and one to an internal network. The database server is on the internal network. Which TWO techniques could the tester use to pivot from the web server to the database server? (Choose TWO.)

Hard
819

A security architect is designing a new authentication system for a cloud-based application that requires strong multi-factor authentication. The solution must be resistant to phishing attacks and not rely on shared secrets. Which of the following is the BEST choice?

Medium
820

A security architect reviews this Cisco router ACL configuration. The web server at 192.168.1.100 is accessible from the internet. What additional security measure should be implemented to protect the internal network (10.0.0.0/24)?

Easy
821

Refer to the exhibit. A security engineer is reviewing an X.509 certificate used for TLS. Which security concern should the engineer identify?

Medium
822

An OpenVPN configuration file is shown. A security auditor recommends replacing the cipher and auth directives. Which of the following is the BEST replacement pair from a security engineering perspective?

Hard
823

A company's security team is reviewing the integration of a legacy application that only supports NTLM authentication. The infrastructure must be updated to meet modern security standards. Which of the following is the BEST approach to mitigate the risk of using NTLM?

Hard
824

Which TWO of the following are examples of compensating controls for a security control deficiency?

Easy
825

A company runs a containerized application in a Kubernetes cluster. After a penetration test, the security team found that several containers are running with root privileges and have unnecessary packages installed. To reduce the attack surface, the team wants to enforce least privilege and minimize the software footprint. Which action should be taken first to address these findings?

Medium
826

A security team is developing a data classification policy. Which TWO of the following elements should be included in the policy to ensure effective data governance?

Medium
827

A multinational corporation is implementing a data classification scheme. Which of the following data types should be classified as 'restricted'?

Hard
828

Which of the following is a cloud-native security control provided by a cloud service provider to manage user permissions and access to resources?

Easy
829

A security architect is designing a cloud-native application that must comply with GDPR data residency requirements. Which TWO of the following measures should the architect implement? (Choose two.)

Medium
830

A security analyst is reviewing CVSS scores for vulnerabilities in the environment. A vulnerability has a base score of 9.0, but the organization has a compensating control that reduces the likelihood of exploitation. The analyst adjusts the score to 6.0 for prioritization. Which CVSS metric group did the analyst modify?

Medium
831

Which of the following is a key difference between compliance and security?

Medium
832

A security analyst is investigating a potential advanced persistent threat (APT) that has been evading traditional detection. The analyst decides to use User and Entity Behavior Analytics (UEBA) to identify anomalous activity. Which TWO of the following activities would be most indicative of a potential compromise when analyzed through UEBA? (Choose TWO.)

Hard
833

A security architect is designing a secure wireless network for a government facility. Which TWO of the following measures should be implemented to ensure the highest level of security? (Select TWO.)

Medium
834

A company is deploying IoT sensors in a harsh environment. The sensors have limited processing power and memory. Which of the following cryptographic algorithms is most suitable for ensuring data confidentiality with minimal overhead?

Medium
835

A senior security architect is designing a detection strategy for advanced persistent threats (APTs) that employ living-off-the-land (LotL) techniques. Which THREE of the following approaches are most effective for detecting LotL activities? (Choose three.)

Hard
836

Which of the following certificate types is most appropriate for an organization that needs to validate the identity of individuals for email encryption and signing?

Easy
837

An organization is implementing a PKI with a three-tier hierarchy (root CA, intermediate CA, issuing CA). The security team wants to ensure that certificate revocation information is available quickly and efficiently. Which TWO mechanisms should they implement? (Select TWO.)

Hard
838

An organization wants to enforce that only signed container images are deployed in production. Which of the following should be implemented?

Easy
839

Based on the exhibit, what vulnerability is present in the firewall rule?

Medium
840

Based on the exhibit, which type of attack is most likely occurring?

Hard
841

Which TWO of the following are primary goals of security operations monitoring? (Choose two.)

Easy
842

A developer is writing a mobile app that stores sensitive user data locally on the device. Which is the best practice for protecting the data at rest?

Easy
843

A financial institution manages customer data through a web application built on a LAMP stack. The application uses a third-party library for PDF generation that was patched last year. Recently, the security team discovered that an attacker exploited an unpatched vulnerability in the library to execute arbitrary code on the server. The library vendor has released an update, but the development team is concerned that updating the library will break several custom features that rely on its internal API. The CIO wants to minimize risk while maintaining business continuity. The application is critical to daily operations, and any downtime would result in significant revenue loss. Which course of action should the security analyst recommend?

Hard
844

Refer to the exhibit. A security architect is reviewing this S3 bucket policy. Which of the following security concerns is MOST evident?

Easy
845

A SOC analyst receives an alert indicating that a workstation has been making outbound connections to a known command-and-control (C2) IP address. The analyst initiates the incident response process. Which of the following should be the FIRST action taken?

Easy
846

A financial institution is required to comply with SOX. Which of the following is a primary focus of this regulation?

Medium
847

A security auditor reviews this Kubernetes pod configuration. Which security vulnerability is most critical?

Hard
848

A security engineer is reviewing the configuration of a web application firewall (WAF) that protects a public-facing e-commerce site. The site has been experiencing intermittent false positives that block legitimate customers during checkout. The WAF is deployed in blocking mode with a rule set that includes SQL injection and cross-site scripting (XSS) signatures. The engineer notices that legitimate credit card numbers containing the string 'OR' are being blocked. The site uses HTTPS and input validation on the server side. Which of the following actions would BEST resolve the false positives while maintaining security?

Medium
849

Which THREE components are essential for a fully functional Security Operations Center (SOC)? (Select exactly 3.)

Easy
850

A security team is evaluating endpoint detection and response (EDR) solutions. They want a solution that can detect fileless malware and malicious PowerShell scripts. Which TWO capabilities should the team prioritize? (Choose TWO.)

Easy
851

An organization is evaluating its cloud service provider's security posture as part of third-party risk management. Which regulatory framework requires the organization to ensure that the provider has appropriate technical and organizational measures to protect personal data?

Hard
852

A security architect needs to protect sensitive data in use within a server's memory from other processes. Which technology should be implemented?

Easy
853

A security analyst is collecting evidence from a compromised workstation. Which of the following should be collected first to preserve volatile data?

Easy
854

During a PKI migration, the security team discovers that some internal clients do not support OCSP stapling but require online certificate status checking. Which alternative should be configured to minimize latency and ensure validity?

Hard
855

Refer to the exhibit. The security team has been asked to remediate the vulnerability before the next PCI DSS audit. Which of the following is the MOST appropriate action?

Easy
856

A security analyst is reviewing a Kubernetes cluster and wants to ensure that only authorized users can create or modify pods. Which Kubernetes object should be configured to enforce this?

Easy
857

A security engineer is writing a Python script to parse system logs and alert on suspicious patterns. What is the best practice to ensure the script remains secure when handling log data?

Medium
858

During a tabletop exercise, the CSIRT discovers that the organization lacks a clear chain of command for decision-making during incidents. Which document should be updated to address this gap?

Easy
859

An organization wants to detect and respond to advanced threats that may evade traditional endpoint security solutions. They deploy an EDR solution that provides real-time visibility into endpoint activities. However, the security team is overwhelmed by alerts. Which technology can be integrated with EDR to automate response actions and reduce alert fatigue?

Medium
860

A security engineer is designing a secure boot process for embedded devices. Which component is responsible for verifying the signature of the bootloader before execution?

Medium
861

A penetration tester is in the post-exploitation phase and wants to maintain access to a compromised system. Which of the following techniques is most effective for establishing persistent access while evading detection?

Medium
862

Refer to the exhibit. Which of the following best describes the effect of this ACL?

Medium
863

A security manager is selecting key risk indicators (KRIs) for the organization's risk management program. Which THREE of the following are examples of KRIs that can provide early warning of increasing risk?

Hard
864

A company is implementing a risk management framework and needs to prioritize remediation of vulnerabilities based on potential impact. Which of the following is the MOST appropriate approach?

Easy
865

During an incident response, the team must perform containment actions. Which TWO actions are considered proper containment? (Select exactly 2.)

Hard
866

An organization is planning to modernize its cryptographic infrastructure to protect sensitive data for the next 10 years. The security architect must consider future threats from quantum computing. Which TWO quantum-resistant algorithms should the architect prioritize for key encapsulation and digital signatures? (Choose TWO.)

Easy
867

An organization is setting up a PKI with a three-tier hierarchy (root CA, issuing CA, and registration authority). Which TWO of the following are best practices for securing the root CA?

Medium
868

An organization is developing a policy exception management process. Which three of the following are essential components of an effective exception process? (Choose three.)

Hard
869

A SOC analyst is investigating a potential data exfiltration incident. The analyst suspects that an insider is using encrypted tunnels to transfer data. Which TWO of the following network traffic analysis (NTA) indicators are most likely to suggest encrypted exfiltration? (Choose two.)

Medium
870

During a penetration test, the tester has gained initial access to a network and now aims to move laterally to a sensitive database server. Which phase of the penetration testing lifecycle does this activity represent?

Medium
871

During an audit, a compliance officer finds that the organization has not conducted a risk assessment in over two years. Which of the following is the MOST significant risk?

Hard
872

A security analyst is conducting a threat hunt based on the hypothesis that an adversary may have used PowerShell to execute malicious scripts. Which threat hunting methodology is being employed?

Medium
873

A security engineer is integrating API security for a RESTful service. Which mechanism is used to verify that the API request has not been tampered with and originates from a legitimate client?

Easy
874

A company is designing a hybrid cloud architecture with AWS and an on-premises data center. They need to ensure that all data transmitted between environments is encrypted and that the connection is resilient. Which design should the architect choose?

Hard
875

A security analyst is configuring a TPM 2.0 for a new fleet of laptops. The requirement is to ensure that only authorized operating systems can boot and that any tampering with the boot process is detected. Which TPM feature should be used?

Medium
876

A security engineer is reviewing an S3 bucket policy for a bucket named 'corporate-data'. The policy is shown. Which of the following describes a vulnerability in this configuration?

Hard
877

Refer to the exhibit. A security analyst reviews this pod specification. Which attack surface is most increased by the added capabilities?

Medium
878

A security engineer is configuring a web application firewall (WAF) for an e-commerce site. The application uses JSON APIs for all transactions. Which WAF mode provides the best protection against injection attacks while minimizing false positives?

Medium
879

During a penetration test, an engineer discovers that the application uses client-side JavaScript to validate input before submission. What is the MOST significant vulnerability?

Medium
880

Which TWO of the following are best practices for securing a cloud-based identity and access management (IAM) system? (Select exactly 2.)

Medium
881

Which TWO of the following are best practices for securing a database that stores personally identifiable information (PII)? (Select TWO.)

Easy
882

Refer to the exhibit. This clause is a requirement of which of the following?

Medium
883

Drag and drop the steps to configure a site-to-site IPsec VPN on a firewall into the correct order.

Medium
884

A security architect is designing a secure boot process for a new line of embedded devices. The boot ROM loads the bootloader, which then loads the OS kernel. To ensure that only signed code is executed, which mechanism should the bootloader use to verify the kernel?

Medium
885

An organization is required to comply with PCI DSS. Which of the following is a mandatory requirement for protecting cardholder data?

Medium
886

A company is evaluating a new cloud service provider. The provider offers a SOC 2 Type II report, a third-party penetration test summary, and a completed security questionnaire. However, the company's procurement team discovers that the provider uses a subcontractor for data storage. Which of the following is the BEST next step for the security team?

Medium
887

A company is deploying a RESTful API that handles sensitive financial data. Which of the following should be implemented to ensure data integrity during transmission?

Easy
888

An organization's vulnerability management team discovers a critical vulnerability in a legacy application that cannot be patched because the vendor no longer supports it. The application is essential for business operations. Which of the following compensating controls would best reduce the risk of exploitation while maintaining functionality?

Hard
889

A financial services company is implementing a zero-trust architecture. The security architect needs to ensure that all network traffic between application tiers is inspected and logged regardless of source location. Which of the following should be implemented?

Medium
890

Which TWO are required by PCI DSS for all merchants?

Hard
891

A security engineer is hardening a Kubernetes environment. Which THREE of the following are effective controls for securing the cluster? (Select THREE.)

Medium
892

An organization is moving to a passwordless authentication approach. They require a solution that supports hardware-based cryptographic authentication and is resistant to phishing. Which standard should they implement?

Medium
893

A company is deploying containerized applications on Kubernetes and needs to ensure that only authorized images are run in the cluster. Which Kubernetes resource should be used to enforce policies on what containers can run, including image source restrictions?

Hard
894

Which TWO of the following are essential characteristics of a hardware security module (HSM)? (Select TWO.)

Easy
895

A small business uses a single on-premise server running a custom application and a SQL database. The IT manager is concerned about data loss due to hardware failure. The company has a backup tape drive but often forgets to change tapes. The RTO is 24 hours and RPO is 4 hours. Which of the following is the BEST improvement to meet the RPO/RTO requirements?

Easy
896

A multinational corporation is adopting a zero trust architecture for its enterprise network. The security team is evaluating mechanisms to enforce granular access controls and segment workloads. Which TWO components are most critical for implementing a zero trust model? (Choose TWO.)

Medium
897

During a threat modeling exercise for a new web application, the team identifies that the application uses JWT for authentication. Which vulnerability is most likely if the server does not properly verify the JWT signature?

Hard
898

An organization deploys honeypots to detect attackers. Which type of deception technology is being used?

Easy
899

A security analyst is investigating a potential data exfiltration incident. The analyst has collected a memory dump from the affected server. Which Volatility command should the analyst use to extract the contents of the clipboard, which may contain copied sensitive data?

Hard
900

Which three options are best practices for writing secure scripts? (Choose three.)

Medium
901

During a security assessment, an analyst discovers that an HSM used for key generation is FIPS 140-2 Level 2 compliant. The organization requires a higher level of physical security to prevent tampering. Which upgrade would best address this requirement?

Hard
902

A penetration tester is performing reconnaissance against a target. Which TWO of the following are examples of active reconnaissance? (Select TWO.)

Medium
903

A company's internal audit found that employees often share passwords. Which policy change would BEST address this?

Easy
904

During an incident response, a forensic examiner is collecting evidence from a compromised Windows workstation. The examiner must follow proper order of volatility to preserve potential evidence. Which THREE of the following items should be collected first, before the others? (Choose THREE.)

Hard
905

Which three measures should be implemented to secure a RESTful API? (Select THREE.)

Hard
906

A company is deploying a SASE architecture. Which component is responsible for securing web traffic and enforcing acceptable use policies at the edge?

Medium
907

A security engineer is reviewing a Kubernetes deployment where the pod spec includes `securityContext: { privileged: true }`. What is the primary security concern of this configuration?

Hard
908

A security audit reveals that Docker containers are built with multiple unnecessary layers and utilities. Which practice reduces the attack surface of the container image?

Hard
909

During a threat hunting exercise, a security analyst hypothesizes that adversaries may be using PowerShell to execute commands in memory. Which threat hunting methodology is being employed?

Easy
910

A security manager is reviewing the company's vendor risk management program. Which of the following should be included as a mandatory step BEFORE entering into a contract with a new cloud service provider?

Easy
911

A multinational corporation is deploying a new application that will be accessed by employees, partners, and customers. The security architecture must support single sign-on (SSO) across different identity providers (IdPs) while maintaining strict access control based on user attributes such as role, location, and device posture. The company uses Active Directory for employees, a cloud IdP for partners, and self-registration for customers. The architect needs to design a centralized policy enforcement point that can evaluate access requests from multiple IdPs and enforce dynamic access policies before granting access to the application. Which of the following is the BEST architectural approach?

Medium
912

A company is merging with another company that has a different security posture. The CISO wants to integrate the two security programs quickly. Which of the following is the MOST critical first step?

Hard
913

An organization is planning to deploy digital certificates for various use cases. Which TWO of the following certificate types are typically used for email security?

Easy
914

Based on the exhibit, what type of attack is indicated?

Easy
915

A compliance officer is reviewing logs from a web application and finds multiple failed login attempts from a single IP address. Which type of control should be implemented to reduce the risk of brute-force attacks?

Easy
916

A security analyst is reviewing a suspicious file. Which static analysis technique would the analyst use to examine the file without executing it?

Easy
917

An organization is reviewing its supply chain risk management. Which TWO of the following are effective strategies to manage fourth-party risk?

Medium
918

An organization wants to ensure that its third-party vendors comply with the company's security policies. Which of the following is the MOST effective method?

Easy
919

Match each port number to its associated protocol.

Medium
920

Which technology is used to discover and control cloud applications, enforce security policies, and provide visibility into cloud usage?

Easy
921

An organization wants to protect cryptographic keys used for TLS termination. Which hardware solution should be deployed to prevent key extraction?

Medium
922

A security operations center (SOC) is implementing a SOAR platform to automate responses to phishing incidents. The playbook will include steps to automatically quarantine suspicious emails, delete them from user mailboxes, and block the sender's domain. Which element should the SOAR playbook incorporate to ensure the automated response does not cause unintended disruption?

Medium
923

In a cloud shared responsibility model, which of the following is typically the customer's responsibility for IaaS?

Easy
924

A company is implementing a defense-in-depth strategy for its web application. Which THREE security controls should be included in the architecture? (Choose three.)

Medium
925

A global company must comply with data residency regulations that require customer data to stay within specific geographic boundaries. The company uses a multi-cloud architecture. Which THREE strategies should the architect implement to ensure compliance?

Hard
926

Refer to the exhibit. Which security issue does this cloud storage bucket policy present?

Medium
927

An organization is automating cloud security group management across AWS, Azure, and GCP. Which TWO approaches provide centralized, auditable control? (Select TWO.)

Hard
928

A security operations team is implementing deception technology to detect lateral movement. Which TWO of the following are examples of deception technologies? (Select TWO.)

Medium
929

A compliance officer is preparing for an audit and needs to collect evidence. Which TWO of the following are considered acceptable forms of audit evidence? (Select TWO.)

Easy
930

A security administrator is reviewing a Python script used to automate compliance checks across cloud resources. The script uses environment variables for API tokens. Which of the following are secure coding practices that should be implemented in this script? (Select TWO.)

Hard
931

During a penetration test, the tester successfully gains initial access to a web server and wants to move laterally to a database server. The web server uses a service account that has local admin rights on the database server. What is the most effective technique for lateral movement in this scenario?

Hard
932

An organization wants to ensure that its supply chain vendors are compliant with its security policies. Which of the following is the MOST effective approach?

Medium
933

Which of the following is a primary purpose of using code signing for application deployment?

Easy
934

Given the exhibit, what is the MOST likely scenario?

Hard
935

A company requires a cryptographic hash function for integrity verification of large files. The solution must be resistant to length extension attacks and provide high performance. Which of the following is the best choice?

Easy
936

A company is conducting a third-party risk assessment for a SaaS provider. The provider has provided a SOC 2 Type II report, penetration test results, and a completed security questionnaire. Which of these provides the most independent and comprehensive view of the provider's control environment over time?

Medium
937

A security architect is designing a secure remote access solution for contractors who need temporary access to a few internal applications. Which THREE of the following are best practices for controlling contractor access? (Select THREE.)

Easy
938

A company is implementing a hardware security module (HSM) to protect cryptographic keys. The security architect must ensure the solution meets FIPS 140-2 Level 3 requirements. Which TWO of the following features are required for Level 3?

Hard
939

A multinational organization is adopting a zero trust architecture and needs to align its network segmentation with regulatory requirements. The compliance team has identified that certain data must be isolated to meet PCI DSS scope reduction. Which of the following design approaches BEST supports both zero trust and PCI DSS compliance?

Hard
940

An organization is implementing a secure software development lifecycle. Which of the following practices BEST ensures that security requirements are addressed early in the development process?

Hard
941

Refer to the exhibit. A security analyst notices that users from the internet can reach the web server at 10.0.1.100 on port 443, but they cannot reach it on port 8443. What is the most likely cause?

Medium
942

A security architect is implementing an API gateway to protect microservices. Which security capability is uniquely provided by an API gateway compared to a traditional web application firewall (WAF)?

Medium
943

An application uses a relational database and constructs SQL queries by concatenating user input. Which secure coding practice should be implemented to mitigate SQL injection?

Medium
944

An analyst wants to automate incident response tasks in a SOC environment. Which THREE scripting languages are commonly used for automation? (Choose three.)

Easy
945

A security architect is designing a secure OTA update mechanism for IoT devices. Which TWO features are essential to ensure the integrity and authenticity of firmware updates?

Medium
946

Refer to the exhibit. A web server is unable to connect to a local database socket. Which of the following actions would MOST likely resolve this issue?

Hard
947

During an incident response engagement, the security team identifies that a compromised host has been communicating with multiple external IP addresses using encrypted channels. The team needs to determine which processes initiated the connections. Which type of evidence collection should be performed first to preserve the most volatile data?

Medium
948

During a secure SDLC, a development team is reviewing code for security flaws early in the development process. Which type of testing is MOST appropriate for identifying vulnerabilities in source code before it is compiled?

Medium
949

A security engineer is implementing a solution to securely store and manage cryptographic keys for a fleet of IoT devices. The devices have limited processing power and cannot perform asymmetric operations. Which of the following is the BEST approach?

Medium
950

A security engineer is configuring a SIEM correlation rule to detect a potential data exfiltration attempt. The rule should trigger when a single internal host sends more than 10 MB of data to an external IP address that has never been communicated with before, within a 5-minute window. Additionally, the external IP should not be on any whitelist. Which correlation logic best implements this detection?

Hard
951

During a security review, a developer discovers that a containerized application runs with root privileges. Which of the following is the most secure approach to mitigate this risk while maintaining functionality?

Hard
952

An organization is deploying a new cloud-based application that processes personally identifiable information (PII). The security team must ensure data at rest is encrypted. Which THREE of the following controls should be implemented to protect the data? (Select THREE.)

Hard
953

A company is designing a new data center with high availability requirements. The network team proposes using virtualized network functions (VNFs) on commodity hardware to reduce costs. Which security consideration is MOST important when implementing this design?

Medium
954

A security analyst is writing a script to scan container images for known vulnerabilities before deployment. Which of the following best practices should the analyst implement to ensure the script runs securely?

Medium
955

During a threat hunting exercise, a hunter uses the MITRE ATT&CK framework to identify a series of behaviors: an attacker used PowerShell to download a payload, then created a scheduled task for persistence, and finally performed credential dumping via LSASS. Which ATT&CK tactic is associated with the credential dumping technique?

Hard
956

A security architect is evaluating a new identity management solution. The requirement is to allow users to authenticate using their existing social media accounts while maintaining corporate control over access policies. Which architecture best meets this requirement?

Easy
957

A security analyst is reviewing TLS 1.3 configuration for a web server. The analyst wants to ensure that the configuration provides forward secrecy and prevents the reuse of session keys. Which of the following is a characteristic of TLS 1.3 that supports these goals?

Medium
958

An organization needs to ensure consistent configuration across multiple Linux servers. They want to automate this process with a solution that requires minimal agent installation and uses push-based communication. Which approach is most appropriate?

Easy
959

A company is implementing single sign-on using SAML 2.0. A security architect is reviewing the authentication flow and notices that the identity provider (IdP) does not digitally sign the SAML assertions. Which of the following is the most significant security risk?

Hard
960

An incident responder is analyzing a compromised server. Which THREE indicators are MOST likely to confirm a successful attack?

Hard
961

A penetration tester is conducting a test against a web application. The client has defined rules of engagement that prohibit any denial of service attacks. The tester discovers an endpoint that is vulnerable to command injection. Which THREE of the following actions should the tester take to validate the vulnerability while staying within scope? (Choose THREE.)

Medium
962

Which THREE of the following are effective techniques for detecting advanced persistent threats (APTs) within a network? (Select exactly 3.)

Hard
963

An incident response team is handling a ransomware incident. The team has successfully contained the threat and is now in the eradication phase. Which THREE actions are appropriate for the eradication phase? (Select THREE.)

Hard
964

A security architect is reviewing the network segmentation of a healthcare organization that must comply with HIPAA. The current flat network allows all devices to communicate. Which segmentation approach provides the best balance of security and manageability?

Medium
965

A company wants to implement continuous compliance monitoring. Which of the following approaches BEST supports this goal?

Hard
966

A compliance officer is preparing for a GDPR audit. Which THREE of the following are key data subject rights under GDPR that the organization must be able to demonstrate?

Hard
967

A security architect is designing a system that must comply with FedRAMP Moderate controls. The system will use a cloud service provider (CSP) that is already FedRAMP Authorized. What is the primary benefit of using this CSP?

Hard
968

Which THREE of the following are essential components of a secure software development lifecycle (SSDLC)?

Hard

Frequently asked questions

What does the scenario questions domain cover on the CAS-005 exam?
scenario questions questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 968 scenario questions questions in the CAS-005 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only scenario questions questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.