Which of the following data states applies to data that is being actively processed by a database server?
Data in use refers to data actively being processed, such as by a database server.
A manager meets with various stakeholders involved with a recently resolved security incident. During the meeting, they discuss potential improvements to the environment in order to better respond to future incidents. Which of the following incident response activities does this describe?
The lessons learned phase involves gathering stakeholders to review what worked well and what gaps existed in handling an incident. This retrospective helps update policies and procedures to improve future response times and effectiveness.
A company wants to track modifications to the code that is used to build new virtual servers. Which of the following will the company most likely deploy?
A version control tool helps track changes to code and allows for rollback and collaboration in software development.
Which of the following is an effective method for detecting unauthorized devices attempting to connect to a corporate network?
A Network Intrusion Detection System (NIDS) monitors network traffic and identifies unauthorized devices attempting to access the network, helping to detect potential security threats.
Which of the following is the phase in the incident response process when a security analyst reviews roles and responsibilities?
The preparation phase of incident response involves planning and preparation for handling security incidents. This includes defining roles and responsibilities, establishing procedures, and setting up tools and resources to effectively respond to incidents.
During an assessment, an organization provides a penetration tester with a website URL and login credentials. However, the tester does not have access to the source code. Which of the following describes the type of test being performed?
A partially known, or gray-box, test gives the tester limited internal knowledge such as credentials but not full source code. This approach balances realistic threat scenarios with targeted testing.
The management team reports that employees are missing features on company-provided tablets, which is causing productivity issues. The management team directs the IT team to resolve the issue within 48 hours. Which of the following would be the best solution for the IT team to leverage in this scenario?
Mobile Device Management (MDM) allows IT to remotely push configuration updates and install missing applications on corporate tablets. It streamlines deployment and ensures uniform feature availability across devices.
A pentest report shows the tester pivoted internally using the same local credentials. Which would prevent this?
Centralized authentication enforces consistent password policies, rotation, and strong complexity rules across all systems. This prevents reuse of local credentials and reduces the risk of lateral movement during a compromise.
Which of the following can automate vulnerability management?
The Security Content Automation Protocol (SCAP) provides standardized formats and tools for automated vulnerability scanning, configuration assessment, and patch tracking. It enables seamless integration between scanners and management systems.
A security administrator receives alerts about employees transferring system files and information about sensitive projects to their personal email accounts outside of normal job duties. Which of the following enterprise security capabilities will the security team most likely deploy to detect that activity?
DLP (Data Loss Prevention) is designed to monitor, detect, and prevent unauthorized data transfers, such as sending sensitive files or information to personal email accounts. It is the most suitable solution for preventing and detecting activities like this.
After three contract revisions, HR needs to track changes. Which process should they follow?
Version control systems track each document revision, including who made the change and when. They provide history, enable comparison between versions, and allow rollback to prior drafts.
Which of the following activities should a systems administrator perform to quarantine a potentially infected system?
Quarantining a potentially infected system by placing it into an air-gapped environment physically disconnects it from the network. This prevents the spread of malware while maintaining the integrity of forensic evidence.
A company hired a security manager from outside the organization to lead security operations. Which of the following actions should the security manager perform first in this new role?
Reviewing existing security policies gives the new manager insight into current controls, gaps, and organizational expectations. This knowledge forms the foundation for establishing baselines and making improvements.
Which of the following activities is included in the post-incident review phase?
In the post-incident review phase, the root cause of the incident is determined to prevent similar incidents in the future.
Which of the following activities is included in the post-incident review phase?
The post-incident review focuses on understanding what happened, determining the root cause, and identifying improvements to prevent recurrence. Recovery tasks like restoring configurations occur earlier, not in the review stage.
Quiz Complete!
Domain 4: Security Operations