/
AI Flashcards
Save to my account
Sign up
AI Flashcards
Security Operations and Attack Surface Reduction
Study
1
Question
What is the primary purpose of a 3DES hash from an installer file posted on a vendor's website in a security context?
Answer
To test the integrity of the file
2
Question
In incident response, what is the final step of the modem response process?
Answer
Lessons learned
3
Question
Which activity is included in the post-incident review phase?
Answer
Determining the root cause of the incident
4
Question
An administrator observes remote after-hours data exfiltration to a personal device. What best describes the user’s activity?
Answer
Insider threat
5
Question
What helps measure overall organizational risk when a new vulnerability is disclosed?
Answer
A full inventory of all hardware and software
6
Question
Which log type provides the most relevant data about an executable running on a corporate laptop?
Answer
Endpoint
7
Question
Which is a feature of a next-generation SIEM system?
Answer
Automated response actions
8
Question
To prevent attackers from accessing new network devices using publicly available information, which step is essential?
Answer
Change default passwords
9
Question
What is a tabletop exercise in security operations?
Answer
Tabletop exercise
10
Question
Why is Infrastructure as Code (IaC) favored in security architecture?
Answer
Configuration can be better managed and replicated
11
Question
What adds an extra layer of security by preventing unauthorized access to internal resources via an intermediary server?
Answer
Jump server
12
Question
Which data handling activities are paired with sanitization in data lifecycle management? (Select two)
Answer
Data retention; Classification
13
Question
Which technology best mitigates high-risk region attacks by returning traffic from trusted sources?
Answer
IP geolocation
14
Question
To block signature-based attacks with an IPS, which mode is appropriate?
Answer
Active
15
Question
If a file integrity monitoring tool flags a hash change on cmd.exe and patches weren’t applied, what is likely occurred?
Answer
A rootkit was deployed
16
Question
Which control best mitigates insecure web inputs that could lead to injection attacks?
Answer
Input sanitization
17
Question
If a security operations center deems some detected activity as normal, what practice explains ignoring it going forward?
Answer
Tuning
18
Question
Which agreement defines response time, escalation, and performance metrics?
Answer
SLA (Service Level Agreement)
19
Question
What ensures a device is inaccessible to the network while preserving forensic evidence on the host?
Answer
Host isolation
20
Question
What tool type helps identify attacker activity without impacting production servers?
Answer
Honey pot
21
Question
Which security tool fingerprinting specific files to prevent exfiltration is used to enforce data loss prevention?
Answer
DLP (Data Loss Prevention)
22
Question
Which solution distributes incoming traffic to multiple servers to improve performance and availability?
Answer
Load balancer
23
Question
What method secures credit card data in SQL databases by using a surrogate value rather than the real data?
Answer
Tokenization
24
Question
Which social engineering technique targets executives to commit fraud?
Answer
Whaling
25
Question
Which attack type involves brute-force attempts to guess credentials from a server?
Answer
Brute-force attack
26
Question
What is the most important element when defining effective security governance?
Answer
Assigning roles and responsibilities
27
Question
What does decommissioning two unused web servers currently exposed to the internet illustrate in terms of security practices?
Answer
Attack surface reduction
28
Question
Which activity involves closing 18 open and unused ports on production web servers?
Answer
Attack surface reduction
29
Question
Why is removing company email addresses from public domain records considered attack surface reduction?
Answer
Reduces publicly available information attackers can leverage
30
Question
What is the primary purpose of reducing attack surface in security operations?
Answer
Lower exposure to threats and entry points