01. Dependency, secrets, infrastructure-as-code and image scanning are all enabled across a large estate, and the combined backlog has reached tens of thousands of open findings. The same underlying issue frequently appears three or four times from different scanners, and application teams say they cannot tell which of the findings are theirs to fix.
Which approach BEST addresses this?
a) Publish a combined report from each scanner on a fixed schedule and ask every application team to search it for the repositories they own ahead of each release, escalating anything they cannot place
b) Raise the severity threshold on each scanner until the number of open findings is small enough for a team to work through within a release cycle
c) Correlate every scanner's output with application and ownership context — repository, service, owning team and deployed asset — so duplicates collapse and each finding is routed to its owner
d) Consolidate on a single scanner for each artifact class so that no issue is reported twice and the total volume falls to what one tool produces
02. Secrets scanning flags a long-lived cloud credential committed to a repository that several teams contribute to. The commit is three weeks old, the repository is mirrored to a build cache and images built from it are already running in production.
What should the security engineering team do FIRST?
a) Rewrite the repository history to purge the commit and force-push the cleaned branches to every mirror
b) Add a pre-commit hook and a pipeline gate that stop a credential reaching the repository
c) Rebuild and redeploy every image that was produced from the repository after the commit landed
d) Revoke the credential and issue a replacement
03. A team is building a nightly job that pulls findings out of the platform into the organization's data warehouse. The job runs unattended from the scheduling system.
Which two practices apply to the credential that job presents?
(Choose two.)
a) Reuse the credential presented by the identity integration, covering human and machine access with one identity.
b) Attribute it to the named export service rather than to an engineer, and rotate it on a defined schedule.
c) Embed it in the scheduling system's job definition, leaving the job with no external dependency at run time.
d) Grant the credential an administrative scope for the first few runs and narrow it afterwards, once the job's own logs have shown which calls it actually makes.
e) Scope it to the read operations the export performs and nothing wider.
04. The security engineering team at a multi-account organization has finished its agent rollout and now has to plan how runtime enforcement is turned on. Application teams own their own accounts and have asked not to be surprised by blocks.
Which enablement sequence should the team adopt?
a) Turn prevention on everywhere at once and add exclusions as teams report false blocks.
b) Stay in alert mode across the whole estate indefinitely and let the response team act on what it sees, since prevention in a shared estate risks blocking legitimate work.
c) Enable prevention in production for the highest-severity rules immediately, then extend alerting to the remaining environments once the critical workloads are covered.
d) Alert in every environment first, then switch non-production to prevent, then prevent in production for the rules that have proved high-confidence.
05. Data science teams at a retail organization have been creating managed AI services, notebooks and training datasets in their own accounts without involving security. Leadership asks the security engineering team to establish what AI is running across the estate and how exposed it is.
Which capability is scoped to that question?
a) KSPM, which evaluates the clusters the training jobs are scheduled on and reports their configuration into the same queue.
b) CIEM, which flags the over-permissioned service identities the new AI workloads were created with.
c) AI-SPM, which brings models, notebooks and training data into inventory and then reports shadow services, publicly reachable models and over-permissioned AI identities.
d) DSPM, which discovers and classifies the data held in those accounts and therefore already covers the models, the notebooks and the service identities and applications that consume them.
06. In a financial services organization with several hundred cloud accounts, the number of workloads carrying a runtime agent has risen in each of the last three months. Over the same three months, the share of discovered workloads that carry one has fallen.
The monthly report to the security committee cites the rising agent count as evidence that the rollout is on track.
What should the engineer tell the committee?
a) The estate is growing faster than the rollout, and the widening gap is itself the finding to report
b) The agent count is the wrong measure of progress, so the report should track the runtime detections each account raises instead
c) The rollout is proceeding as designed, and the falling share reflects resources that a runtime agent does not protect
d) Discovery is over-reporting, so the inventory should be narrowed to the accounts in scope
07. An organization's pipeline has failed the build on any finding of any severity since the gate was introduced. A review finds a documented skip step now present in most services' pipeline configuration, and the scan running on only a small minority of builds.
Leadership has proposed tightening the severity policy further.
Which two considerations should MOST influence the response?
(Choose two.)
a) The skip step shows the delivery teams are not treating the severities seriously, which is an argument for a stricter policy.
b) Recording every skipped build as an accepted risk keeps the policy intact while the teams work down the backlog.
c) The control is protecting nothing as it stands, because a gate that is skipped on most builds stops no artifact from reaching release.
d) The proportion of builds on which the gate was overridden is the measurement that shows its threshold needs re-tuning.
e) Moving the check to the developers' editors restores build speed without giving up coverage of the same findings.
08. On a Monday morning no member of the security team can sign in to the console; the browser is handed to the identity provider and the attempt then fails. The scheduled export jobs that call the platform's API ran overnight and completed, and the runtime agents across the estate are still reporting. The identity team carried out planned maintenance over the weekend.
Which two conclusions does the scope of the failure support?
(Choose two.)
a) The tenant has been suspended or its subscription has lapsed, so every authenticated path into the platform is being refused.
b) The agents' own certificates have to be re-issued alongside the human sign-in path, because both trust the certificate the identity team replaced.
c) Network reachability to the console has been lost, which is why no session can be established.
d) The failure is confined to the federated sign-in path, since the programmatic and agent paths authenticate by a different mechanism and are unaffected.
e) The identity provider's signing certificate is the first thing to examine, as a replaced signing key breaks assertion validation while leaving every other path working.
09. Console sign-in at a software organization is already federated to the corporate identity provider, but roles are still granted by assigning them to each federated user by hand. Engineers who move between teams keep the access their previous team needed, and two leavers were found still holding roles a month after their last day.
Which change BEST addresses this?
a) Introduce a quarterly access review in which each team lead re-certifies the individual role assignments held by everyone reporting to them, with unclaimed assignments removed.
b) Drive role assignment from identity-provider group membership so that a move or a departure changes console access at the provider.
c) Shorten the console session lifetime so that a user whose provider account has been disabled loses console access when their current session expires.
d) Require the joiner, mover and leaver process to raise a console role change ticket for each move or departure.
10. During a design review, a security engineering team plans an integration with the organization's SOAR platform so that certain findings trigger an automated containment workflow. A reviewer asks how this integration changes what the platform knows about the estate.
Which statement correctly describes the SOAR integration's role?
a) It consumes the findings the platform produces and acts on them in an external workflow, not supplying data the platform analyzes.
b) It supplies additional asset and identity context to the platform, which joins that context onto existing findings when it correlates them into risks.
c) It acts as the identity source for platform access, mapping automation users onto platform roles.
d) It takes over routing decisions from the alert rules, so which findings are raised is decided outside the platform.