TechNuggets Academy

Systems and Application Security

Free Systems Security Certified Practitioner practice — 6 questions on Systems and Application Security, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Domain 7: Systems and Application Security
A security engineer reviews a production Kubernetes cluster and finds several pods running with the --privileged flag, root as the container user, and the Docker socket mounted inside the container. If one of these containers is compromised via an application vulnerability, an attacker could escape to the underlying host. Which hardening action BEST reduces this container escape risk?
Removing --privileged and unmounting the Docker socket eliminates direct kernel/host access; running as non-root with user namespace remapping means even a container root user maps to an unprivileged host UID, containing damage if the container is breached.
Question 2 of 6 · Domain 7: Systems and Application Security
An attacker gains initial access to a workstation and uses only built-in PowerShell cmdlets and WMI calls to move laterally, never writing an executable file to disk. Signature-based antivirus reports no detections. Which endpoint security capability is MOST likely to detect this activity?
Fileless, living-off-the-land attacks abuse legitimate system binaries, so they leave no malicious file for signature scanning to catch. EDR behavioral/heuristic analytics that examine process ancestry, unusual command-line patterns, and memory-resident activity can flag the anomalous use of PowerShell/WMI even without a malicious file.
Question 3 of 6 · Domain 7: Systems and Application Security
A cloud provider is designing a new multi-tenant IaaS platform and must maximize isolation between tenant virtual machines while minimizing the attack surface exposed to the hypervisor layer. Which hypervisor architecture should be selected?
A Type 1 bare-metal hypervisor runs directly on hardware without a full general-purpose host OS underneath it, reducing the code base and attack surface exposed between tenants and providing stronger isolation, which is why virtually all production multi-tenant cloud platforms use Type 1 hypervisors.
Question 4 of 6 · Domain 7: Systems and Application Security
A newly purchased IoT sensor ships with Telnet enabled by default, the same hardcoded administrator password across every unit, and a firmware update mechanism that accepts any unsigned image over HTTP. Which single set of changes BEST hardens this device before deployment?
Effective IoT/embedded hardening requires closing unnecessary remote-access services (disable Telnet), eliminating shared default credentials with unique strong per-device credentials, and enforcing signed, encrypted firmware updates to prevent malicious firmware injection — addressing all three exposed weaknesses simultaneously.
Question 5 of 6 · Domain 7: Systems and Application Security
Which combination of an OS-level memory protection technique and a compiler-level technique is specifically designed to mitigate exploitation of buffer overflow vulnerabilities by randomizing memory locations and preventing code execution from data segments?
ASLR randomizes the memory addresses of key data areas (stack, heap, libraries) making it harder for an attacker to predict target addresses, while DEP/NX marks stack and heap memory as non-executable, together forming the classic OS-level defense against buffer overflow exploitation used in memory-corruption attacks.
Question 6 of 6 · Domain 7: Systems and Application Security
A company runs a multi-node Hadoop cluster storing sensitive customer data. Security testing reveals that any host on the network can register itself as a DataNode and that inter-node communication is unauthenticated, allowing potential data node impersonation and unauthorized data access. Which control should be implemented FIRST to address this risk?
Kerberos provides strong mutual authentication between NameNodes, DataNodes, and clients in a Hadoop environment, preventing rogue or impersonating nodes from joining the cluster or accessing data, which directly resolves the identified impersonation and unauthorized access weakness.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →