1. An organization is migrating its on-premises applications to a public cloud environment. The security team is concerned about ensuring that the cloud resources (virtual machines, databases, storage accounts) are configured securely according to industry best practices and compliance requirements before they are deployed. Which security program element is most relevant to this proactive approach?
Security Concepts
A.Vulnerability Management
B.Incident Response Planning
C.Security Architecture and Design
D.Security Operations Center (SOC)
Show answerAnswer
C. Security Architecture and Design
Security Architecture and Design is a proactive security program element that focuses on integrating security considerations into the initial planning, design, and implementation phases of systems and applications. Ensuring cloud resources are securely configured *before* deployment falls directly under this domain, aiming to build security in from the start.
2. A company is implementing a new data classification policy. Sensitive customer data, if compromised, would result in severe financial penalties and reputational damage. According to common security principles, which classification level should this data receive?
Security Concepts
A.Confidential
B.Internal
C.Public
D.Restricted
Show answerAnswer
D. Restricted
Data classified as 'Restricted' typically represents the highest level of sensitivity, where unauthorized disclosure would lead to severe consequences, such as legal penalties, significant financial loss, or severe reputational damage. Customer data with high impact fits this category.
3. A security team is implementing a vulnerability management program and needs to establish a systematic approach to identify and categorize vulnerabilities. They decide to use a publicly available, standardized system for naming and identifying vulnerabilities. Which system are they most likely to adopt?
Vulnerability Management
A.CVSS (Common Vulnerability Scoring System)
B.NIST SP 800-53
C.OWASP Top 10
D.CVE (Common Vulnerabilities and Exposures)
Show answerAnswer
D. CVE (Common Vulnerabilities and Exposures)
CVE (Common Vulnerabilities and Exposures) provides a standard naming system for publicly known cybersecurity vulnerabilities. It assigns a unique identifier (e.g., CVE-2023-XXXX) to each vulnerability, allowing security teams to consistently track and reference specific flaws across different tools and reports.
4. A security architect is designing a system that requires ensuring data not only remains confidential but also that its origin can be verified and that the sender cannot later deny having sent it. Which cryptographic primitive is essential for achieving both data origin authentication and non-repudiation?
Security Concepts
A.Hashing
B.Key Exchange
C.Digital Signatures
D.Symmetric Encryption
Show answerAnswer
C. Digital Signatures
Digital signatures use asymmetric cryptography to provide data integrity, data origin authentication, and non-repudiation. The sender uses their private key to sign a hash of the message, and the recipient uses the sender's public key to verify the signature, proving the sender's identity and that the message hasn't been altered.
5. A security analyst is performing a black-box penetration test against a client's external web application. During the reconnaissance phase, the analyst discovers several subdomains and public-facing IP addresses, but no direct access to source code or internal network diagrams. Which of the following best describes the perspective and information available to the analyst at this stage?
Vulnerability Management
A.They have an insider's view, similar to a malicious employee.
B.They have partial knowledge, similar to a privileged user.
C.They are operating with full system knowledge and access.
D.They are simulating an external, unauthenticated attacker.
Show answerAnswer
D. They are simulating an external, unauthenticated attacker.
A black-box penetration test explicitly simulates an external, unauthenticated attacker with no prior knowledge of the internal system. Discovering public-facing information like subdomains and IPs aligns with the reconnaissance phase of such a test.
6. A security analyst is reviewing system logs on a Linux server and notices repetitive failed login attempts for a root user account originating from various external IP addresses within a short timeframe. Which type of attack is most likely underway?
Security Monitoring
A.Brute-force Attack
B.Denial-of-Service (DoS)
C.Privilege Escalation
D.Cross-Site Scripting (XSS)
Show answerAnswer
A. Brute-force Attack
Repetitive failed login attempts for a specific account, especially from multiple external IPs, are a classic indicator of a brute-force attack where an attacker tries many password combinations to gain unauthorized access.
7. A large enterprise uses a centralized logging system to collect security events from all network devices and servers. A security analyst frequently reviews these logs to identify anomalies and potential threats. This practice is a core component of which security program element?
Security Concepts
A.Security Monitoring
B.Security Awareness Training
C.Vulnerability Management
D.Disaster Recovery Planning
Show answerAnswer
A. Security Monitoring
Security monitoring involves continuously observing and analyzing activity to detect security events, anomalies, and potential threats. Centralized logging and analyst review of logs are fundamental activities within a security monitoring program.
8. A security team is analyzing network traffic logs and observes a significant increase in connection attempts to a web server from a single source IP address, occurring rapidly over a short period. The connection attempts are incomplete, with the attacker sending only the initial SYN packet but never completing the three-way handshake. What type of Denial of Service (DoS) attack is this?
Security Concepts
A.UDP Flood
B.SYN Flood
C.HTTP Flood
D.ICMP Flood
Show answerAnswer
B. SYN Flood
A SYN flood is a type of DoS attack that exploits the TCP three-way handshake. The attacker sends a large number of SYN requests to a server but never completes the handshake by sending the final ACK. This leaves the server's connection tables full of half-open connections, exhausting resources and preventing legitimate users from connecting.
9. A security operations center (SOC) analyst is investigating an alert from an Intrusion Prevention System (IPS) indicating a potential buffer overflow attack. The IPS has successfully blocked the traffic. The analyst needs to determine if the attack attempt was indeed a buffer overflow and identify its source and target. What type of security monitoring concept is the IPS primarily demonstrating in this scenario?
Security Concepts
A.Network Intrusion Detection/Prevention
B.Log Management
C.Endpoint Detection and Response (EDR)
D.Security Information and Event Management (SIEM)
Show answerAnswer
A. Network Intrusion Detection/Prevention
An IPS (Intrusion Prevention System) actively monitors network traffic for malicious activity and can automatically block or prevent detected threats, such as a buffer overflow attack. This falls under the category of network intrusion detection and prevention, which focuses on analyzing network traffic for attacks.
10. A security analyst is investigating a series of alerts from a host-based intrusion detection system (HIDS) indicating 'Registry Key Modification: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'. The alerts show that a new entry has been added pointing to an executable in the C:\Users\Public\ directory. What is the most likely purpose of this registry modification?
Security Monitoring
A.To elevate user privileges
B.To disable system services
C.To establish persistence
D.To delete critical system files
Show answerAnswer
C. To establish persistence
The 'HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run' registry key is a well-known location where programs can register themselves to automatically start when Windows boots up or a user logs in. Adding an entry here is a common technique used by malware to ensure it restarts and maintains its presence on the system after a reboot, which is known as establishing persistence.
11. An organization is considering implementing a continuous vulnerability management program. Which of the following is a primary benefit of integrating threat intelligence feeds into their vulnerability management process?
Vulnerability Management
A.It automates the patching of all identified vulnerabilities.
B.It eliminates the need for regular vulnerability scanning.
C.It guarantees 100% protection against zero-day attacks.
D.It provides context on active exploits and attacker methodologies, aiding prioritization.
Show answerAnswer
D. It provides context on active exploits and attacker methodologies, aiding prioritization.
Threat intelligence provides crucial context by detailing current threats, active exploits, and attacker tactics, techniques, and procedures (TTPs). This information helps security teams prioritize which vulnerabilities to address first based on the actual likelihood and impact of exploitation.
12. A security engineer is configuring a new Intrusion Detection System (IDS) to monitor network traffic for malicious activity. The engineer decides to implement a rule that triggers an alert whenever a specific, known malicious payload signature is detected within any network packet. This approach is an example of which type of security monitoring concept?
Security Concepts
A.Behavioral-based detection
B.Anomaly-based detection
C.Signature-based detection
D.Heuristic-based detection
Show answerAnswer
C. Signature-based detection
Signature-based detection relies on a database of known attack patterns or 'signatures'. When the IDS detects traffic that matches one of these predefined signatures, it triggers an alert. The scenario explicitly mentions detecting a 'specific, known malicious payload signature', which is the hallmark of signature-based detection.
13. A security analyst is investigating a potential data exfiltration incident. Network traffic analysis reveals large volumes of encrypted data being sent from an internal server to an external IP address over an unusual port (TCP 53000). The internal server's legitimate function does not involve outbound connections of this nature. Which network intrusion analysis technique is most critical for determining the content of the exfiltrated data?
Security Monitoring
A.Packet capture and decryption (if possible) to inspect payload.
B.NetFlow analysis to identify source and destination IPs.
C.Firewall log review to confirm blocked connections.
D.DNS query analysis to detect command and control (C2) channels.
Show answerAnswer
A. Packet capture and decryption (if possible) to inspect payload.
To determine the *content* of exfiltrated data, direct inspection of the data itself is required. Since the data is encrypted, the most critical step is to obtain a packet capture and then attempt decryption using available keys or certificates. Other options identify traffic but don't reveal content.
14. A security analyst is investigating a suspicious process on a Linux server. The process is running as 'nobody' (a low-privilege user) but is observed making outbound connections to various external IP addresses on high-numbered, ephemeral ports. There is no legitimate application configured to run as 'nobody' with this network behavior. Which type of malware is most likely responsible?
Security Monitoring
A.Rootkit
B.Botnet (bot)
C.File Infector
D.Logic Bomb
Show answerAnswer
B. Botnet (bot)
A process running as a low-privilege user ('nobody') and making 'outbound connections to various external IP addresses on high-numbered, ephemeral ports' without a legitimate reason is highly indicative of a botnet agent (bot). Bots are typically designed to communicate with a command and control (C2) server, often using random high ports to evade simple firewall rules, and often run with minimal privileges to avoid detection or reduce impact if discovered.
15. A security analyst is investigating a series of alerts indicating that multiple internal hosts are attempting to connect to various external IP addresses on non-standard ports. The traffic patterns are sporadic and do not align with known business operations. Further investigation reveals that these internal hosts are also communicating with each other over unusual ports. What type of attack framework is most likely indicated by these observations?
Security Concepts
A.SQL Injection
B.Phishing Campaign
C.Command and Control (C2)
D.Denial of Service (DoS)
Show answerAnswer
C. Command and Control (C2)
The observed behavior of internal hosts communicating with external IP addresses on non-standard ports, coupled with internal host-to-host communication over unusual ports, is characteristic of a Command and Control (C2) framework. This framework allows attackers to maintain persistent access and control over compromised systems within a network.
16. A financial institution is developing a new mobile banking application. The security team insists that all sensitive data stored on the mobile device must be protected even if the device is lost or stolen. Which endpoint security concept is critical to implement for this requirement?
Security Concepts
A.Network Access Control (NAC)
B.Full Disk Encryption (FDE)
C.Endpoint Detection and Response (EDR)
D.Application Whitelisting
Show answerAnswer
B. Full Disk Encryption (FDE)
Full Disk Encryption (FDE) protects all data on a device at rest by encrypting the entire storage volume. If the device is lost or stolen, the data remains unreadable without the correct decryption key, directly addressing the requirement to protect sensitive data on a lost or stolen device.
17. A security operations center (SOC) analyst observes a series of suspicious events originating from an internal server: multiple failed login attempts to an external SSH server, followed by a successful connection, and then a large outbound data transfer to an unknown IP address. The analyst suspects command and control (C2) communication. Which port is most commonly associated with SSH, and thus a strong indicator in this C2 scenario?
Security Concepts
A.Port 23
B.Port 22
C.Port 21
D.Port 80
Show answerAnswer
B. Port 22
SSH (Secure Shell) typically operates on TCP port 22. In a C2 scenario, attackers often use SSH for encrypted communication and remote control of compromised systems, making traffic on port 22 to an external unknown IP highly suspicious, especially after failed logins.
18. A security analyst is configuring a SIEM to ingest logs from various network devices. The analyst needs to ensure that the SIEM can accurately parse and normalize logs from a new Cisco ASA firewall, which uses syslog for event reporting. Which of the following is the most critical step to ensure effective security monitoring from this new log source?
Security Monitoring
A.Configure the ASA to send logs to a non-standard UDP port.
B.Ensure the SIEM has the correct parsing rules (parsers) for Cisco ASA syslog format.
C.Disable timestamping on the ASA logs to reduce data volume.
D.Only ingest critical alerts (severity 0-2) from the ASA.
Show answerAnswer
B. Ensure the SIEM has the correct parsing rules (parsers) for Cisco ASA syslog format.
For a SIEM to effectively analyze and correlate logs, it must first be able to understand their format. Different devices and vendors use varying log formats. Having the correct parsing rules (often called parsers or connectors) ensures that the SIEM can correctly extract fields like source IP, destination IP, event type, and severity, which is crucial for normalization, correlation, and effective security monitoring.
19. A security architect is designing a system that requires ensuring data not only remains confidential and its integrity is preserved, but also that the sender of the data cannot later deny having sent it. Which cryptographic principle is specifically addressed by the requirement that the sender cannot deny sending the data?
Security Concepts
A.Confidentiality
B.Non-repudiation
C.Integrity
D.Availability
Show answerAnswer
B. Non-repudiation
Non-repudiation is the cryptographic principle that ensures that a party cannot successfully deny the authenticity of their signature on a document or the sending of a message that they originated. This is typically achieved through digital signatures.
20. A security analyst is investigating a series of anomalies on a web server. The server logs show numerous HTTP POST requests to a login page with varying usernames and passwords, originating from a single IP address over a short period. Many of these attempts are failing due to incorrect credentials. Which common attack vector is most likely being observed?
Security Concepts
A.Denial of Service (DoS)
B.SQL Injection
C.Cross-Site Scripting (XSS)
D.Credential Stuffing
Show answerAnswer
D. Credential Stuffing
Credential stuffing involves using compromised username/password pairs obtained from a data breach on one service to attempt to gain unauthorized access to accounts on other, unrelated services. The scenario describes repeated login attempts with varying credentials, which aligns with this attack vector.
21. A cybersecurity firm is developing a new intrusion detection system (IDS) that uses a database of known attack patterns to identify malicious network traffic. This IDS is designed to flag traffic only when it precisely matches an entry in its database. Which detection method is primarily being employed?
Security Concepts
A.Heuristic Detection
B.Behavioral Detection
C.Anomaly-based Detection
D.Signature-based Detection
Show answerAnswer
D. Signature-based Detection
Signature-based detection systems rely on a database of known attack patterns or signatures. They flag traffic only when it exactly matches one of these pre-defined patterns. This method is effective against known threats but struggles with novel or zero-day attacks.
22. A security operations center (SOC) analyst is reviewing alerts from the SIEM. One alert indicates 'Multiple failed attempts to access a critical database using SQL queries containing 'UNION SELECT' and 'pg_sleep()'. The source IP is from an external, untrusted network. Which vulnerability is the attacker most likely attempting to exploit?
Security Monitoring
A.SQL Injection
B.Buffer Overflow
C.Cross-Site Request Forgery (CSRF)
D.Directory Traversal
Show answerAnswer
A. SQL Injection
The presence of 'UNION SELECT' and 'pg_sleep()' within SQL queries is a classic signature of SQL injection attempts. 'UNION SELECT' is used to extract data, and 'pg_sleep()' is often used for time-based blind SQL injection.
23. A security team is implementing a new access control system. The policy dictates that users should only have the minimum necessary access rights to perform their job functions, and these rights should be revoked automatically when their role changes or they leave the company. Which security principle is being enforced by this policy?
Security Concepts
A.Separation of Duties
B.Defense in Depth
C.Least Privilege
D.Implicit Deny
Show answerAnswer
C. Least Privilege
The principle of least privilege dictates that users, programs, or processes should be granted only the minimum access necessary to perform their legitimate functions. Revoking access when roles change or employment ends further reinforces this principle by ensuring privileges are always kept to the absolute minimum required.
24. A security auditor is reviewing an organization's access control policies. The auditor notes that a database administrator has full read and write access to all customer data, including highly sensitive financial records, even though their daily tasks only require access to a subset of non-financial customer data. Which security principle is being violated?
Security Concepts
A.Least Privilege
B.Separation of Duties
C.Defense in Depth
D.Need-to-Know
Show answerAnswer
A. Least Privilege
The Principle of Least Privilege dictates that users, programs, or processes should be granted only the minimum necessary authorizations to perform their legitimate tasks. The database administrator having full access when only a subset is needed is a direct violation of this principle.
25. A security analyst is investigating a series of alerts indicating unusual outbound network connections from several internal workstations to an external IP address known for hosting C2 (Command and Control) infrastructure. The connections are occurring over TCP port 443, but the traffic does not appear to be legitimate HTTPS. What technique is the attacker most likely employing?
Security Monitoring
A.SMB Relay Attack
B.Protocol Mismatching
C.DNS Tunneling
D.ICMP Exfiltration
Show answerAnswer
B. Protocol Mismatching
Protocol mismatching, also known as protocol evasion or port masquerading, involves using a standard port (like 443 for HTTPS) for non-standard or malicious traffic to bypass firewall rules that typically allow outbound traffic on common ports. The key indicator is that traffic on port 443 'does not appear to be legitimate HTTPS'.
A proactive security program element focused on integrating security considerations into the initial planning, design, and implementation phases of systems, applications, and infrastructure.
Aims to build security in from the ground up ('Secure by Design').
A list of publicly disclosed cybersecurity vulnerabilities, each assigned a unique identifier (CVE ID) to facilitate data sharing and enable automation.
Standardizes vulnerability identification.
Maintained by MITRE Corporation.
Used by security vendors and researchers worldwide.
A mathematical scheme for demonstrating the authenticity of digital messages or documents. A valid digital signature gives a recipient reason to believe that the message was created by a known sender (authentication), that the sender cannot deny having sent the message (non-repudiation), and that the message was not altered in transit (integrity).
A type of penetration test where the tester has no prior knowledge of the target system's internal structure or source code, simulating an external attacker.
Mimics a real-world external attacker.
Focuses on identifying vulnerabilities visible from the outside.
A brute-force attack is a trial-and-error method used to obtain information such as a user password or personal identification number (PIN). It involves systematically checking all possible passwords until the correct one is found.
Characterized by numerous failed login attempts.
Can target various services (SSH, RDP, web logins).
Often originates from multiple IPs to evade rate limiting.
The continuous process of collecting, analyzing, and reviewing data from various sources (e.g., logs, network traffic) to detect and respond to security incidents and anomalies.
A type of Denial of Service (DoS) attack that exploits the TCP three-way handshake. The attacker sends a high volume of SYN requests to a target server but does not respond to the server's SYN-ACKs, leaving many half-open connections that exhaust the server's resources and prevent legitimate connections.
The practice of incorporating actionable information about current and emerging cyber threats into an organization's security operations, including vulnerability management, to make more informed decisions.
Provides context on attacker TTPs.
Aids in prioritizing vulnerabilities based on real-world risk.
A method of detecting threats by comparing observed data (e.g., network traffic, file content) against a database of known malicious patterns or signatures.
Effective against known threats.
Requires frequent updates to the signature database.
Ineffective against zero-day attacks or polymorphic malware.
The process of intercepting and recording network traffic (packet capture) and subsequently converting encrypted traffic back into readable plaintext (decryption) to analyze its contents.
Essential for deep inspection of network payload data.
Requires access to encryption keys/certificates for encrypted traffic.
Tools like Wireshark are used for capture and analysis.
A botnet is a network of compromised computers (bots) controlled by a threat actor (bot-herder) via a command and control (C2) server. Bots often run with low privileges and communicate covertly with the C2.
Performs C2 communication (often via HTTP, DNS, or custom protocols).
Often runs as a low-privilege user.
Used for DDoS, spam, data theft, and other malicious activities.
A communication channel used by attackers to control compromised systems (bots or agents) within a target network. It enables attackers to issue commands, exfiltrate data, and maintain persistent access.
Establishes persistent communication with compromised hosts.
Uses various protocols and ports, often non-standard ones, to evade detection.
Allows attackers to remotely manage and direct malicious activities.
A security feature that encrypts all data on a hard drive or storage device, protecting it from unauthorized access if the device is lost, stolen, or accessed by an unauthorized party.
Encrypts the entire storage volume, including operating system and user data.
Data is unreadable without the correct decryption key or password.
A cryptographic network protocol for operating network services securely over an unsecured network. It is typically used for remote command-line login and remote command execution, but also supports tunneling, port forwarding, and file transfers.
Uses TCP port 22 by default.
Provides strong authentication and encrypted communication.
The process by which a SIEM system extracts relevant data fields from raw, unstructured log messages and transforms them into a standardized, structured format for easier analysis and correlation.
Essential for making heterogeneous log data usable.
Involves identifying timestamps, source/destination IPs, event types, etc.
Enables cross-source correlation and consistent querying.
A security principle that guarantees that the sender of a message or the performer of an action cannot later deny having sent the message or performed the action.
Often achieved using digital signatures and cryptographic hashing.
An attack where an attacker takes a list of compromised username-password pairs, often obtained from a data breach on one service, and attempts to use them to log into a large number of other, unrelated online services.
Relies on users reusing passwords across multiple sites.
SQL injection signatures are specific keywords, functions, or patterns found within attacker-crafted SQL queries that indicate an attempt to exploit database vulnerabilities.
Common keywords: 'UNION SELECT', 'OR 1=1', 'DROP TABLE'.
Functions for enumeration: '@@version', 'user()', 'database()'.
Functions for timing attacks: 'SLEEP()', 'pg_sleep()'.
A security principle requiring that users, programs, or processes be granted only the essential access rights or permissions needed to perform their assigned functions, and no more. This minimizes the potential damage from errors, compromises, or malicious actions.
A technique where attackers use a well-known port (e.g., 80, 443) for a protocol other than its standard, often to bypass firewall rules and network monitoring.
Leverages trust in common ports to hide malicious traffic.
Requires deep packet inspection (DPI) to detect.
Often used for C2 communication or data exfiltration.
Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.