A threat hunter is looking for suspicious login activity across multiple different authentication systems and cloud providers. Today, the threat hunter has to query multiple different data sources with unique logic to gather basic information about authentication events.
What method provides a simple way to standardize data formats, and look for common activity across different sources?
Answer : D
A corporation chooses to engage in a Request for Information (RFI) / Request for Proposal (RFP) process.
What is a major advantage of this type of formal procurement process?
Answer : A
Buttercup Games needs to provide its SOC team access to a wide range of security data sources located across different regions and cloud providers.
Which architectural solution allows the SOC analysts to query these data sources as a single logical source without having to migrate or copy all the raw data?
Answer : D
An architect is consulting with an organization that requires data to be sent to various destination data stores based on a combination of criteria. This includes, but is not limited to, the presence of personally identifiable information (PII), specific key/value pairs in each event, and the required retention duration for specific data sources.
Which of the following types of technology would be most appropriate to address these requirements?
Answer : B
A U.S. based company has recently purchased a German company. The U.S. organization is planning to consolidate their customer rewards program globally and begin collecting purchasing information on the German customers to send back to their U.S. data center.
Which data privacy law would they violate if they did not update the German End User Agreement?
Answer : B
While working with the Security Automation team, an architect is reviewing a playbook that automates the handling of compromised credentials. The playbook contains the following stages:
Examine account to ensure that it is not a service or control account.
Access all identity platforms and lock the user account.
Revoke all current sessions (email, VPN, etc.).
The architect points out the potential for the compromised credentials to be used remotely again.
Which of the following actions need to be added to the playbook to alleviate this?
Answer : A
Danielle is a security architect at a multinational retail company. She is evaluating threat intelligence feeds to add to her company’s security monitoring program.
What is the primary benefit that threat intelligence data can provide?
Answer : C
Melinda’s team is responsible for maintaining detection content for a large organization. Her team consists of ten detection engineers, who need to log in to multiple SIEMs in order to make any changes to rules. Melinda wants to evaluate a “detection as code” methodology using the organization’s version control and continuous integration systems.
What benefits can detection as code provide her team? (Choose all that apply.)
Answer : ABD
Which of the following are key advantages of providing “paved road” security engineering templates? (Choose all that apply.)
Answer : ABD
A new vulnerability has been announced in a software library. Leadership would like to understand what exposure this has caused.
What can be used to determine which vendor provided executables use that library?
Answer : D
The internet facing WAF for a new customer facing application has been identified as a potential telemetry collection point.
Which of the following best describes this data prior to any tuning or curation efforts?
Answer : B
An organization has decided to implement a new endpoint security product. The CISO has concerns about the rollout due to the nature of the varied endpoint builds and installed applications.
After initial testing in lab has shown no issues, what next step should the architect perform to ensure the success of their rollout?
Answer : D
Which of the following describes CIS controls?
Answer : C
Kevin, a security architect, is planning a long-term retention strategy for security logs (e.g.7+ years) for compliance and forensic purposes.
Which storage solutions are cost-effective for this requirement and still allow future access? (Choose all that apply.)
Answer : AB
A critical legacy application server runs on an unsupported OS and IT cannot install a security agent or forward logs on this server. This application processes sensitive data.
What is the best strategy to continuously monitor the server’s activities?
Answer : A
Have any questions or issues ? Please dont hesitate to contact us