100% found this document useful (1 vote)
200 views17 pages

Simulation Practice Questions

The document outlines a series of security-related questions and scenarios for a security administrator, including identifying a network infection originating from host 192.168.10.22 and classifying other hosts as clean or infected. It also covers configuring a site-to-site VPN, designing a resilient application, creating a network diagram for a payment application, addressing vulnerabilities found in a penetration test, and investigating data leaks on the dark web. Each question requires specific actions or selections to enhance security measures and ensure system integrity.

Uploaded by

oscahute
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
100% found this document useful (1 vote)
200 views17 pages

Simulation Practice Questions

The document outlines a series of security-related questions and scenarios for a security administrator, including identifying a network infection originating from host 192.168.10.22 and classifying other hosts as clean or infected. It also covers configuring a site-to-site VPN, designing a resilient application, creating a network diagram for a payment application, addressing vulnerabilities found in a penetration test, and investigating data leaks on the dark web. Each question requires specific actions or selections to enhance security measures and ensure system integrity.

Uploaded by

oscahute
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Question-1: As a security administrator, you are investigating a potential network

infection. Click on each host and the firewall to analyze their logs. Identify the host that
initially introduced the infection and classify the remaining hosts as either clean or
infected.

The logs indicate that [Link] is the origin of the infection. This host is running an
unusual instance of [Link] on port 443, which is generating a significant number of
outbound connections to various IPs—suggesting botnet activity.

Firewall records reveal that [Link] has been in contact with [Link], another
compromised system within the engineering network. This host exhibits similar
suspicious behavior, with [Link] communicating on port 443 and numerous
outbound connections.

Meanwhile, [Link] and [Link] in the R&D network appear to be


unaffected, as no anomalous processes or connections have been detected on them.
Question-2 Match each attack with its corresponding remediation by selecting the
appropriate options from the drop-down lists.

INSTRUCTIONS

Some attacks and remediation actions may not be used.

If you need to reset the simulation to its original state, click the 'Reset All' button at any
time.
Question-3:

A systems administrator is configuring a site-to-site VPN between two branch offices.


Some of the settings have already been configured correctly. The systems administrator
has been provided the following requirements as part of completing the configuration:
•Most secure algorithms should be selected

•All traffic should be encrypted over the VPN

•A secret password will be used to authenticate the two VPN concentrators.


Questioın-4:

HOTSPOT

A security architect is tasked with designing a highly resilient, business-critical


application. The application SLA is 99.999%.

INSTRUCTIONS

Select the network, power, and server components for the appropriate locations to
achieve application resiliency.

A component should be selected for each location, and components may be selected
more than once. If at any time you would like to bring back the initial state of the
simulation, please click the Reset All button
Question 5:

Topic 1

A security analyst is creating the firrst draft of a network diagram for the company’s
new customer-facing payment application that will be hosted by a third-party cloud
service provider.

INSTRUCTIONS

Click the ? to select the appropriate icons to create a secure, redundant web
application. Then use the dropdown menu to select the appropriate subnet type.
Every space in the diagram must be filled.

If at any time you would like to bring back the initial state of the simulation, please
click the Reset All button
Question 6:

A recent black-box penetration test of [Link] discovered that


external website vulnerabilities exist, such as directory traversals, cross-site
scripting, cross-site forgery, and insecure protocols. You are tasked with reducing
the attack space and enabling secure protocols.

INSTRUCTIONS

Part 1

Use the drop-down menus to select the appropriate technologies for each location
to implement a secure and resilient web architecture. Not all technologies will be
used, and technologies may be used multiple times.

Part 2

Use the drop-down menus to select the appropriate command snippets from the
drop-down menus. Each command section must be filled.
Question 7:

An organization has learned that its data is being exchanged on the dark web. The
CIO has requested that you investigate and implement the most secure solution to
protect employee accounts.

INSTRUCTIONS

Review the data to identify weak security practices and provide the most
appropriate security solution to meet the CIO's requirements

Common questions

Powered by AI

To mitigate external website vulnerabilities such as directory traversal, cross-site scripting, and insecure protocols, one can implement secure and resilient web architecture by selecting appropriate technologies such as secure communication protocols and using command snippets to enforce security controls consistently .

The host responsible for the initial introduction of the network infection was 192.168.10.22. This conclusion is based on behavior characterized by running an unusual instance of svchost.exe on port 443, generating numerous outbound connections to various IPs, indicative of botnet activity .

Designing a highly resilient, business-critical application with a 99.999% SLA requires selecting appropriate network, power, and server components for each location, emphasizing redundancy and fault-tolerance to prevent single points of failure and ensure continuous operation .

Ensuring the security of communication between two branch offices through VPN configuration involves using the most secure algorithms, encrypting all traffic over the VPN, and utilizing a secret password to authenticate the two VPN concentrators, thereby maintaining the confidentiality and integrity of data transmitted across the network .

Security practices that need reviewing include examining current authentication mechanisms, ensuring robust password policies, using multi-factor authentication, and monitoring for unauthorized data access or exfiltration to protect employee accounts from exposure on the dark web .

Firewall data can reveal compromised hosts through records of suspicious activity, such as unusual communication patterns or connections to known malicious IPs. In this context, 192.168.10.22's communications with 10.10.9.18 indicate compromised systems exchanging or forwarding malicious activities across the network .

Svchost.exe, when identified with unusual network activity such as connections on non-standard ports and excessive outbound connections, serves as an indicator of potential network infection and botnet involvement. In the case of 192.168.10.22, it connects to multiple IPs over port 443 indicating its role in botnet-like activities .

A security architect should employ secure design principles by selecting appropriate icons to depict secure architecture components and choosing redundant elements to prevent data loss or service interruptions. Additionally, selecting the appropriate subnet type is vital to ensure data is segmented and secure, minimizing exposure to potential threats .

A security architect can utilize a simulation environment by selecting power, network, and server components from available options to build a model that meets or surpasses the desired 99.999% SLA. This involves iterative trial-and-error testing, ensuring choices in architecture provide appropriate redundancies and failover capabilities .

Creating a network diagram for a third-party hosted application requires ensuring redundancy, security, and compliance with best practices by selecting the correct icons and network components, defining clear data flow and secure network segments, and considering potential failure points and mitigation strategies .

You might also like