Security Operations Flashcards
7 cards from real CISSP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security Operations flashcards as text
What is the PRIMARY objective of conducting a lessons-learned review after an incident has been resolved?
Answer: Improving processes and controls to prevent recurrence
Lessons-learned reviews identify gaps in detection, response, and prevention so that controls and procedures can be improved before the next incident.
An administrator sets an account lockout policy that triggers after 5 failed login attempts within 10 minutes. Which attack does this PRIMARILY mitigate?
Answer: Online brute-force attack
Account lockout thresholds stop online brute-force attacks by locking the account after a defined number of consecutive failed attempts.
Which data destruction method is MOST appropriate for ensuring that sensitive data on a solid-state drive (SSD) cannot be recovered?
Answer: Cryptographic erasure followed by physical destruction
SSDs use wear leveling that prevents reliable overwriting; cryptographic erasure destroys the encryption key, and physical destruction eliminates any remaining data.
A SOC analyst observes repeated DNS queries from an internal host to randomly generated domain names at regular intervals. Which attack technique does this MOST likely indicate?
Answer: Domain generation algorithm (DGA) based C2 communication
Malware using a Domain Generation Algorithm (DGA) generates many pseudo-random domain names and queries them to locate an active command-and-control server.
Which physical security control uses two interlocking doors where the first must close before the second opens, preventing tailgating?
Answer: Mantrap (airlock)
A mantrap is a small room with two controlled doors that requires authentication and ensures only one person enters at a time, preventing tailgating.
What is the key distinction between a warm site and a hot site in business continuity planning?
Answer: A warm site has hardware but requires time to restore data; a hot site is fully operational and can assume production immediately
A hot site mirrors production in real time and can take over immediately, while a warm site has hardware ready but needs backup restoration before it can operate.
When performing vulnerability scanning in an operational environment, which approach minimizes risk to production system availability?
Answer: Conducting unauthenticated scans during off-peak hours with change management approval
Scanning during off-peak hours with change management approval reduces the chance that scan traffic disrupts production services.