20:00

Free Test
/ 10

Quiz

1/10
Topic 1, Case Study Scenario
Overview
It is recommended that you read through the case study before answering any questions. You can
always return to the case study while viewing any of the twenty questions.
Introduction
As the threat landscape has grown over past years and continues to evolve unpredictably, cyber-
attacks on organizations are now unavoidable. Security is no longer about averting attacks; it is all
about preparing for them.
In recent years, large corporate data breaches have impacted millions of customers and revealed
personal information that can be used in follow-on crimes. The longer a cyber-attack goes unnoticed,
the more damage it does to the business and the more money and time it will cost to recover.
Hackers steal financial, medical, and other sensitive information to sell online or use in cybercrimes.
This unpredictable security threat landscape has resulted in a challenging scenario for all
organizations.


Business Description

Certification Exam D-SF-A-24: Dell-EMC Dell Security Foundations Achievement Dell-EMC Dell-EMC-D-SF-A-24 1-1908889223

A .R.T.I.E. is a midsize social media company whose key customers are 18- to 28-year-olds. Using the
organization's platform, customers can share content such as photos, videos and post status updates
and views. The organization has a in-built messenger app that helps users to interact. The platform
also has an option to make in-app purchases and play games with other users.
One key characteristic of A .R.T.I.E. is that it supports social influencers and has attracted large firms
as advertisers.
With 450 employees, who work from different locations, the main goal of A .R.T.I.E. is to provide high
quality of services to a user base of 15K individuals and associates. The employees have access to the
apps, platform, data, and systems through an internal network that uses a virtual private network
(VPN) to secure access from remote locations.


Business Problem

Certification Exam D-SF-A-24: Dell-EMC Dell Security Foundations Achievement Dell-EMC Dell-EMC-D-SF-A-24 2-1408597374

Senior management of A .R.T.I.E. expects the core business to continue to grow rapidly due to an
increase in user traffic and increased demand of its advertising platform especially by big
organizations.
Based on their current business-critical needs for their solutions and client base, the organization is
planning to move towards a global operational geography and have migrated some of its key
applications to the public cloud. Deployment of the applications to the public cloud provides:
. Ability to scale.
. Higher data transfer speeds and more efficient access management.
. Faster time-to-market and better control of IT costs.
However, with progress comes new challenges as public cloud environments broaden the attack
surface from which attackers can try to gain unauthorized access to an organization's resources. A
.R.T.I.E. also must comply with various regulations and cloud security controls and have to come up
with holistic security capabilities that ensure security across the organization, core-to-edge-to-cloud.
Even though the IT team of the organization constantly monitor their IT environment and assets
along with watching for unauthorized profiles, information disclosure, fake accounts, and other
threats, the CIO of A.R.I.T.E. is aware that the nature of their business being an open platform makes
them a prime target for attackers and other cybercriminals.
Due to the growing business and untrained employees, the organization is constantly under the fear
of threat. This fear increased tenfold when they had discovered two back-to-back cyberattacks
resulting in unauthorized access to databases containing user information.
In the first attack, the attackers performed data theft techniques to exfiltrate vulnerable information
and held internal systems for ransom. This incident led to the company negotiating a ransom
payment to recover dat
a. Also, an unexplained surge in requests to a single webpage occurred along with unusual network
traffic patterns which indicated a second attack. These attacks were concerning not only for the
financial impact but also for the amount of data exposed.
Requirements
The key requirements to address the primary challenges to the business includes:
. Understanding the cyber threat landscape specific to the organizational risk tolerance.
. Secure migration of applications to the public cloud.
. Implement a suitable security framework to tackle current and emerging threats.
. Identify possible vulnerabilities and threats.
. Create an incident management plan based on knowledge, experience, and real-time information
to prevent future attacks.
. Learn about the tools and technologies used to avert the attacks and determine which tools will be
appropriate for them.
. Take measures to implement secure solutions and control: Zero Trust, Security hardening, IAM
techniques.


Dell Services Team

Certification Exam D-SF-A-24: Dell-EMC Dell Security Foundations Achievement Dell-EMC Dell-EMC-D-SF-A-24 3-2081891856

To improve the overall cyber security posture and implement better security policies as the company
grows, A .R.T.I.E. contacted Dell Services.
Dell clients use their services and solutions to collectively monitor thousands of devices, systems,
and applications. Some clients have a significant workforce with minimal IT knowledge, which opens
greater security risks and technological gaps.
Strategic advisory team
. Commonly known as the core security team which has a global presence.
. Helps organizations to evaluate and gauge their exposure to cybersecurity risk.
. Supports various organizations in developing a vision and strategy for handling cyberattacks.
. Provides advice on the implementation of standard cybersecurity frameworks.
Ethical hackers
. Works within the defined boundaries to legally infiltrate the organization's network environment
with their permission.
. Exposes vulnerabilities in customers IT systems.
Threat intelligence and incident management team
. The team help to keep the organization apprised of the latest developments in the security
landscape.
. The cyber security intelligence team investigates methodologies and technologies to help
organizations detect, understand, and deflect advanced cybersecurity threats and attacks on their IT
infrastructure, and in the cloud.
. The incident management team helps consider what they would do when under attack. The team
may simulate an attack to ensure that non-technical staff members know how to respond.
. The simulated attack is managed by the incident management team. This team also helps to
prevent future attacks based on the information gathered.
Identity and Access Management team
. Reviews and accesses the access rights for each member and user.
. During their analysis the Dell cyber team did a thorough analysis to help create a secure
environment for A .R.T.I.E. and mitigate potential attacks.
Outcomes
With the rapid and thorough analysis of security events originating from both internal and external
sources to A .R.T.I.E. complete, the Dell Services team could detect anomalies, uncover advanced
threats and remove false positives. The Threat Intelligence team was also able to provide a list of
potentially malicious IP addresses, malware, and threat actors.
Along with this, the team also implemented methods that helped determine what is being attacked
and how to stop an attack providing A .R.T.I.E. with real time threat detection mechanisms,
knowledge on cyber security. The common outcomes after implementation of the Dell
recommendations were:
. Prioritization of threat and impact - Determine threat intelligence, vulnerability status and network
communications to evaluate accurate vulnerability risk.
. Secure workforce and educate employees about best practices to be adopted to mitigate attacks,
security frameworks and policies.
. Implementation of incident management plan and build an organization-wide security strategy to
avert future attacks.
. Identification of at-risk users and authorized users, account takeover, disgruntled employees,
malware actions.
. Streamlining of security solutions while reducing operational costs and staffing requirements.
. Increased effectiveness to address the continual growth of IT environments, along with the sharp
rise in the number of threats and attacks.
The objective was to consolidate data from the organization's multiple sources such as: networks,
servers, databases, applications, and so on; thus, supports centralized monitoring.
A .R.T.I.E. has an evolving need, which was amplified during the incidents. Their complex and
dispersed IT environments have thousands of users, applications, and resources to manage. Dell
found that the existing Identity and Access Management was limited in its ability to apply expanding
IAM protection to applications beyond the core financial and human resource management
application. A .R.T.I.E. also did not have many options for protecting their access especially in the
cloud. A .R.T.I.E. were also not comfortable exposing their applications for remote access.
Dell recommended adopting robust IAM techniques like mapping out connections between


privileged users and admin accounts, and the use multifactor authentication.

Certification Exam D-SF-A-24: Dell-EMC Dell Security Foundations Achievement Dell-EMC Dell-EMC-D-SF-A-24 4-3002407769

The Dell Services team suggest implementing a system that requires individuals to provide a PIN and
biometric information to access their device.
Which type of multifactor authentication should be suggested?
Select the answer
1 correct answer
A.
Something you have and something you are.
B.
Something you have and something you know.
C.
Something you know and something you are.

Quiz

2/10
Topic 1, Case Study Scenario
Overview
It is recommended that you read through the case study before answering any questions. You can
always return to the case study while viewing any of the twenty questions.
Introduction
As the threat landscape has grown over past years and continues to evolve unpredictably, cyber-
attacks on organizations are now unavoidable. Security is no longer about averting attacks; it is all
about preparing for them.
In recent years, large corporate data breaches have impacted millions of customers and revealed
personal information that can be used in follow-on crimes. The longer a cyber-attack goes unnoticed,
the more damage it does to the business and the more money and time it will cost to recover.
Hackers steal financial, medical, and other sensitive information to sell online or use in cybercrimes.
This unpredictable security threat landscape has resulted in a challenging scenario for all
organizations.


Business Description

Certification Exam D-SF-A-24: Dell-EMC Dell Security Foundations Achievement Dell-EMC Dell-EMC-D-SF-A-24 1-1908889223

A .R.T.I.E. is a midsize social media company whose key customers are 18- to 28-year-olds. Using the
organization's platform, customers can share content such as photos, videos and post status updates
and views. The organization has a in-built messenger app that helps users to interact. The platform
also has an option to make in-app purchases and play games with other users.
One key characteristic of A .R.T.I.E. is that it supports social influencers and has attracted large firms
as advertisers.
With 450 employees, who work from different locations, the main goal of A .R.T.I.E. is to provide high
quality of services to a user base of 15K individuals and associates. The employees have access to the
apps, platform, data, and systems through an internal network that uses a virtual private network
(VPN) to secure access from remote locations.


Business Problem

Certification Exam D-SF-A-24: Dell-EMC Dell Security Foundations Achievement Dell-EMC Dell-EMC-D-SF-A-24 2-1408597374

Senior management of A .R.T.I.E. expects the core business to continue to grow rapidly due to an
increase in user traffic and increased demand of its advertising platform especially by big
organizations.
Based on their current business-critical needs for their solutions and client base, the organization is
planning to move towards a global operational geography and have migrated some of its key
applications to the public cloud. Deployment of the applications to the public cloud provides:
. Ability to scale.
. Higher data transfer speeds and more efficient access management.
. Faster time-to-market and better control of IT costs.
However, with progress comes new challenges as public cloud environments broaden the attack
surface from which attackers can try to gain unauthorized access to an organization's resources. A
.R.T.I.E. also must comply with various regulations and cloud security controls and have to come up
with holistic security capabilities that ensure security across the organization, core-to-edge-to-cloud.
Even though the IT team of the organization constantly monitor their IT environment and assets
along with watching for unauthorized profiles, information disclosure, fake accounts, and other
threats, the CIO of A.R.I.T.E. is aware that the nature of their business being an open platform makes
them a prime target for attackers and other cybercriminals.
Due to the growing business and untrained employees, the organization is constantly under the fear
of threat. This fear increased tenfold when they had discovered two back-to-back cyberattacks
resulting in unauthorized access to databases containing user information.
In the first attack, the attackers performed data theft techniques to exfiltrate vulnerable information
and held internal systems for ransom. This incident led to the company negotiating a ransom
payment to recover dat
a. Also, an unexplained surge in requests to a single webpage occurred along with unusual network
traffic patterns which indicated a second attack. These attacks were concerning not only for the
financial impact but also for the amount of data exposed.
Requirements
The key requirements to address the primary challenges to the business includes:
. Understanding the cyber threat landscape specific to the organizational risk tolerance.
. Secure migration of applications to the public cloud.
. Implement a suitable security framework to tackle current and emerging threats.
. Identify possible vulnerabilities and threats.
. Create an incident management plan based on knowledge, experience, and real-time information
to prevent future attacks.
. Learn about the tools and technologies used to avert the attacks and determine which tools will be
appropriate for them.
. Take measures to implement secure solutions and control: Zero Trust, Security hardening, IAM
techniques.


Dell Services Team

Certification Exam D-SF-A-24: Dell-EMC Dell Security Foundations Achievement Dell-EMC Dell-EMC-D-SF-A-24 3-2081891856

To improve the overall cyber security posture and implement better security policies as the company
grows, A .R.T.I.E. contacted Dell Services.
Dell clients use their services and solutions to collectively monitor thousands of devices, systems,
and applications. Some clients have a significant workforce with minimal IT knowledge, which opens
greater security risks and technological gaps.
Strategic advisory team
. Commonly known as the core security team which has a global presence.
. Helps organizations to evaluate and gauge their exposure to cybersecurity risk.
. Supports various organizations in developing a vision and strategy for handling cyberattacks.
. Provides advice on the implementation of standard cybersecurity frameworks.
Ethical hackers
. Works within the defined boundaries to legally infiltrate the organization's network environment
with their permission.
. Exposes vulnerabilities in customers IT systems.
Threat intelligence and incident management team
. The team help to keep the organization apprised of the latest developments in the security
landscape.
. The cyber security intelligence team investigates methodologies and technologies to help
organizations detect, understand, and deflect advanced cybersecurity threats and attacks on their IT
infrastructure, and in the cloud.
. The incident management team helps consider what they would do when under attack. The team
may simulate an attack to ensure that non-technical staff members know how to respond.
. The simulated attack is managed by the incident management team. This team also helps to
prevent future attacks based on the information gathered.
Identity and Access Management team
. Reviews and accesses the access rights for each member and user.
. During their analysis the Dell cyber team did a thorough analysis to help create a secure
environment for A .R.T.I.E. and mitigate potential attacks.
Outcomes
With the rapid and thorough analysis of security events originating from both internal and external
sources to A .R.T.I.E. complete, the Dell Services team could detect anomalies, uncover advanced
threats and remove false positives. The Threat Intelligence team was also able to provide a list of
potentially malicious IP addresses, malware, and threat actors.
Along with this, the team also implemented methods that helped determine what is being attacked
and how to stop an attack providing A .R.T.I.E. with real time threat detection mechanisms,
knowledge on cyber security. The common outcomes after implementation of the Dell
recommendations were:
. Prioritization of threat and impact - Determine threat intelligence, vulnerability status and network
communications to evaluate accurate vulnerability risk.
. Secure workforce and educate employees about best practices to be adopted to mitigate attacks,
security frameworks and policies.
. Implementation of incident management plan and build an organization-wide security strategy to
avert future attacks.
. Identification of at-risk users and authorized users, account takeover, disgruntled employees,
malware actions.
. Streamlining of security solutions while reducing operational costs and staffing requirements.
. Increased effectiveness to address the continual growth of IT environments, along with the sharp
rise in the number of threats and attacks.
The objective was to consolidate data from the organization's multiple sources such as: networks,
servers, databases, applications, and so on; thus, supports centralized monitoring.
A Zero Trust security strategy is defined by which of the primary approaches?
Select the answer
1 correct answer
A.
IAM and security awareness training
B.
VPNs and IAM
C.
Network segmenting and access control
D.
Micro-segmenting and Multi-factor authentication

Quiz

3/10
Topic 1, Case Study Scenario
Overview
It is recommended that you read through the case study before answering any questions. You can
always return to the case study while viewing any of the twenty questions.
Introduction
As the threat landscape has grown over past years and continues to evolve unpredictably, cyber-
attacks on organizations are now unavoidable. Security is no longer about averting attacks; it is all
about preparing for them.
In recent years, large corporate data breaches have impacted millions of customers and revealed
personal information that can be used in follow-on crimes. The longer a cyber-attack goes unnoticed,
the more damage it does to the business and the more money and time it will cost to recover.
Hackers steal financial, medical, and other sensitive information to sell online or use in cybercrimes.
This unpredictable security threat landscape has resulted in a challenging scenario for all
organizations.


Business Description

Certification Exam D-SF-A-24: Dell-EMC Dell Security Foundations Achievement Dell-EMC Dell-EMC-D-SF-A-24 1-1908889223

A .R.T.I.E. is a midsize social media company whose key customers are 18- to 28-year-olds. Using the
organization's platform, customers can share content such as photos, videos and post status updates
and views. The organization has a in-built messenger app that helps users to interact. The platform
also has an option to make in-app purchases and play games with other users.
One key characteristic of A .R.T.I.E. is that it supports social influencers and has attracted large firms
as advertisers.
With 450 employees, who work from different locations, the main goal of A .R.T.I.E. is to provide high
quality of services to a user base of 15K individuals and associates. The employees have access to the
apps, platform, data, and systems through an internal network that uses a virtual private network
(VPN) to secure access from remote locations.


Business Problem

Certification Exam D-SF-A-24: Dell-EMC Dell Security Foundations Achievement Dell-EMC Dell-EMC-D-SF-A-24 2-1408597374

Senior management of A .R.T.I.E. expects the core business to continue to grow rapidly due to an
increase in user traffic and increased demand of its advertising platform especially by big
organizations.
Based on their current business-critical needs for their solutions and client base, the organization is
planning to move towards a global operational geography and have migrated some of its key
applications to the public cloud. Deployment of the applications to the public cloud provides:
. Ability to scale.
. Higher data transfer speeds and more efficient access management.
. Faster time-to-market and better control of IT costs.
However, with progress comes new challenges as public cloud environments broaden the attack
surface from which attackers can try to gain unauthorized access to an organization's resources. A
.R.T.I.E. also must comply with various regulations and cloud security controls and have to come up
with holistic security capabilities that ensure security across the organization, core-to-edge-to-cloud.
Even though the IT team of the organization constantly monitor their IT environment and assets
along with watching for unauthorized profiles, information disclosure, fake accounts, and other
threats, the CIO of A.R.I.T.E. is aware that the nature of their business being an open platform makes
them a prime target for attackers and other cybercriminals.
Due to the growing business and untrained employees, the organization is constantly under the fear
of threat. This fear increased tenfold when they had discovered two back-to-back cyberattacks
resulting in unauthorized access to databases containing user information.
In the first attack, the attackers performed data theft techniques to exfiltrate vulnerable information
and held internal systems for ransom. This incident led to the company negotiating a ransom
payment to recover dat
a. Also, an unexplained surge in requests to a single webpage occurred along with unusual network
traffic patterns which indicated a second attack. These attacks were concerning not only for the
financial impact but also for the amount of data exposed.
Requirements
The key requirements to address the primary challenges to the business includes:
. Understanding the cyber threat landscape specific to the organizational risk tolerance.
. Secure migration of applications to the public cloud.
. Implement a suitable security framework to tackle current and emerging threats.
. Identify possible vulnerabilities and threats.
. Create an incident management plan based on knowledge, experience, and real-time information
to prevent future attacks.
. Learn about the tools and technologies used to avert the attacks and determine which tools will be
appropriate for them.
. Take measures to implement secure solutions and control: Zero Trust, Security hardening, IAM
techniques.


Dell Services Team

Certification Exam D-SF-A-24: Dell-EMC Dell Security Foundations Achievement Dell-EMC Dell-EMC-D-SF-A-24 3-2081891856

To improve the overall cyber security posture and implement better security policies as the company
grows, A .R.T.I.E. contacted Dell Services.
Dell clients use their services and solutions to collectively monitor thousands of devices, systems,
and applications. Some clients have a significant workforce with minimal IT knowledge, which opens
greater security risks and technological gaps.
Strategic advisory team
. Commonly known as the core security team which has a global presence.
. Helps organizations to evaluate and gauge their exposure to cybersecurity risk.
. Supports various organizations in developing a vision and strategy for handling cyberattacks.
. Provides advice on the implementation of standard cybersecurity frameworks.
Ethical hackers
. Works within the defined boundaries to legally infiltrate the organization's network environment
with their permission.
. Exposes vulnerabilities in customers IT systems.
Threat intelligence and incident management team
. The team help to keep the organization apprised of the latest developments in the security
landscape.
. The cyber security intelligence team investigates methodologies and technologies to help
organizations detect, understand, and deflect advanced cybersecurity threats and attacks on their IT
infrastructure, and in the cloud.
. The incident management team helps consider what they would do when under attack. The team
may simulate an attack to ensure that non-technical staff members know how to respond.
. The simulated attack is managed by the incident management team. This team also helps to
prevent future attacks based on the information gathered.
Identity and Access Management team
. Reviews and accesses the access rights for each member and user.
. During their analysis the Dell cyber team did a thorough analysis to help create a secure
environment for A .R.T.I.E. and mitigate potential attacks.
Outcomes
With the rapid and thorough analysis of security events originating from both internal and external
sources to A .R.T.I.E. complete, the Dell Services team could detect anomalies, uncover advanced
threats and remove false positives. The Threat Intelligence team was also able to provide a list of
potentially malicious IP addresses, malware, and threat actors.
Along with this, the team also implemented methods that helped determine what is being attacked
and how to stop an attack providing A .R.T.I.E. with real time threat detection mechanisms,
knowledge on cyber security. The common outcomes after implementation of the Dell
recommendations were:
. Prioritization of threat and impact - Determine threat intelligence, vulnerability status and network
communications to evaluate accurate vulnerability risk.
. Secure workforce and educate employees about best practices to be adopted to mitigate attacks,
security frameworks and policies.
. Implementation of incident management plan and build an organization-wide security strategy to
avert future attacks.
. Identification of at-risk users and authorized users, account takeover, disgruntled employees,
malware actions.
. Streamlining of security solutions while reducing operational costs and staffing requirements.
. Increased effectiveness to address the continual growth of IT environments, along with the sharp
rise in the number of threats and attacks.
The objective was to consolidate data from the organization's multiple sources such as: networks,
servers, databases, applications, and so on; thus, supports centralized monitoring.
To optimize network performance and reliability, low latency network path for customer traffic,
A.R.T.I.E created a modern edge solution. The edge solution helped the organization to analyze and
process diverse data and identify related business opportunities. Edge computing also helped them
to create and distribute content and determine how the users consume it. But as compute and data
creation becomes more decentralized and distributed, A .R.T.I.E. was exposed to various risks and
security challenges inevitably became more complex. Unlike the cloud in a data center, it is physically
impossible to wall off the edge.
Which type of edge security risk A .R.T.I.E. is primarily exposed?
Select the answer
1 correct answer
A.
Data risk
B.
Internet of Things risk
C.
Protection risk
D.
Hardware risk

Quiz

4/10
Topic 1, Case Study Scenario
Overview
It is recommended that you read through the case study before answering any questions. You can
always return to the case study while viewing any of the twenty questions.
Introduction
As the threat landscape has grown over past years and continues to evolve unpredictably, cyber-
attacks on organizations are now unavoidable. Security is no longer about averting attacks; it is all
about preparing for them.
In recent years, large corporate data breaches have impacted millions of customers and revealed
personal information that can be used in follow-on crimes. The longer a cyber-attack goes unnoticed,
the more damage it does to the business and the more money and time it will cost to recover.
Hackers steal financial, medical, and other sensitive information to sell online or use in cybercrimes.
This unpredictable security threat landscape has resulted in a challenging scenario for all
organizations.


Business Description

Certification Exam D-SF-A-24: Dell-EMC Dell Security Foundations Achievement Dell-EMC Dell-EMC-D-SF-A-24 1-1908889223

A .R.T.I.E. is a midsize social media company whose key customers are 18- to 28-year-olds. Using the
organization's platform, customers can share content such as photos, videos and post status updates
and views. The organization has a in-built messenger app that helps users to interact. The platform
also has an option to make in-app purchases and play games with other users.
One key characteristic of A .R.T.I.E. is that it supports social influencers and has attracted large firms
as advertisers.
With 450 employees, who work from different locations, the main goal of A .R.T.I.E. is to provide high
quality of services to a user base of 15K individuals and associates. The employees have access to the
apps, platform, data, and systems through an internal network that uses a virtual private network
(VPN) to secure access from remote locations.


Business Problem

Certification Exam D-SF-A-24: Dell-EMC Dell Security Foundations Achievement Dell-EMC Dell-EMC-D-SF-A-24 2-1408597374

Senior management of A .R.T.I.E. expects the core business to continue to grow rapidly due to an
increase in user traffic and increased demand of its advertising platform especially by big
organizations.
Based on their current business-critical needs for their solutions and client base, the organization is
planning to move towards a global operational geography and have migrated some of its key
applications to the public cloud. Deployment of the applications to the public cloud provides:
. Ability to scale.
. Higher data transfer speeds and more efficient access management.
. Faster time-to-market and better control of IT costs.
However, with progress comes new challenges as public cloud environments broaden the attack
surface from which attackers can try to gain unauthorized access to an organization's resources. A
.R.T.I.E. also must comply with various regulations and cloud security controls and have to come up
with holistic security capabilities that ensure security across the organization, core-to-edge-to-cloud.
Even though the IT team of the organization constantly monitor their IT environment and assets
along with watching for unauthorized profiles, information disclosure, fake accounts, and other
threats, the CIO of A.R.I.T.E. is aware that the nature of their business being an open platform makes
them a prime target for attackers and other cybercriminals.
Due to the growing business and untrained employees, the organization is constantly under the fear
of threat. This fear increased tenfold when they had discovered two back-to-back cyberattacks
resulting in unauthorized access to databases containing user information.
In the first attack, the attackers performed data theft techniques to exfiltrate vulnerable information
and held internal systems for ransom. This incident led to the company negotiating a ransom
payment to recover dat
a. Also, an unexplained surge in requests to a single webpage occurred along with unusual network
traffic patterns which indicated a second attack. These attacks were concerning not only for the
financial impact but also for the amount of data exposed.
Requirements
The key requirements to address the primary challenges to the business includes:
. Understanding the cyber threat landscape specific to the organizational risk tolerance.
. Secure migration of applications to the public cloud.
. Implement a suitable security framework to tackle current and emerging threats.
. Identify possible vulnerabilities and threats.
. Create an incident management plan based on knowledge, experience, and real-time information
to prevent future attacks.
. Learn about the tools and technologies used to avert the attacks and determine which tools will be
appropriate for them.
. Take measures to implement secure solutions and control: Zero Trust, Security hardening, IAM
techniques.


Dell Services Team

Certification Exam D-SF-A-24: Dell-EMC Dell Security Foundations Achievement Dell-EMC Dell-EMC-D-SF-A-24 3-2081891856

To improve the overall cyber security posture and implement better security policies as the company
grows, A .R.T.I.E. contacted Dell Services.
Dell clients use their services and solutions to collectively monitor thousands of devices, systems,
and applications. Some clients have a significant workforce with minimal IT knowledge, which opens
greater security risks and technological gaps.
Strategic advisory team
. Commonly known as the core security team which has a global presence.
. Helps organizations to evaluate and gauge their exposure to cybersecurity risk.
. Supports various organizations in developing a vision and strategy for handling cyberattacks.
. Provides advice on the implementation of standard cybersecurity frameworks.
Ethical hackers
. Works within the defined boundaries to legally infiltrate the organization's network environment
with their permission.
. Exposes vulnerabilities in customers IT systems.
Threat intelligence and incident management team
. The team help to keep the organization apprised of the latest developments in the security
landscape.
. The cyber security intelligence team investigates methodologies and technologies to help
organizations detect, understand, and deflect advanced cybersecurity threats and attacks on their IT
infrastructure, and in the cloud.
. The incident management team helps consider what they would do when under attack. The team
may simulate an attack to ensure that non-technical staff members know how to respond.
. The simulated attack is managed by the incident management team. This team also helps to
prevent future attacks based on the information gathered.
Identity and Access Management team
. Reviews and accesses the access rights for each member and user.
. During their analysis the Dell cyber team did a thorough analysis to help create a secure
environment for A .R.T.I.E. and mitigate potential attacks.
Outcomes
With the rapid and thorough analysis of security events originating from both internal and external
sources to A .R.T.I.E. complete, the Dell Services team could detect anomalies, uncover advanced
threats and remove false positives. The Threat Intelligence team was also able to provide a list of
potentially malicious IP addresses, malware, and threat actors.
Along with this, the team also implemented methods that helped determine what is being attacked
and how to stop an attack providing A .R.T.I.E. with real time threat detection mechanisms,
knowledge on cyber security. The common outcomes after implementation of the Dell
recommendations were:
. Prioritization of threat and impact - Determine threat intelligence, vulnerability status and network
communications to evaluate accurate vulnerability risk.
. Secure workforce and educate employees about best practices to be adopted to mitigate attacks,
security frameworks and policies.
. Implementation of incident management plan and build an organization-wide security strategy to
avert future attacks.
. Identification of at-risk users and authorized users, account takeover, disgruntled employees,
malware actions.
. Streamlining of security solutions while reducing operational costs and staffing requirements.
. Increased effectiveness to address the continual growth of IT environments, along with the sharp
rise in the number of threats and attacks.
The objective was to consolidate data from the organization's multiple sources such as: networks,
servers, databases, applications, and so on; thus, supports centralized monitoring.
The cybersecurity team performed a quantitative risk analysis on A .R.T.I.E.'s IT systems during the
risk management process.
What is the focus of a quantitative risk analysis?
Select the answer
1 correct answer
A.
Rank and handle risk to use time and resources more wisely.
B.
Evaluators discretion for resources.
C.
Knowledge and experience to determine risk likelihood.
D.
Objective and mathematical models to provide risk acumens.

Quiz

5/10
Topic 1, Case Study Scenario
Overview
It is recommended that you read through the case study before answering any questions. You can
always return to the case study while viewing any of the twenty questions.
Introduction
As the threat landscape has grown over past years and continues to evolve unpredictably, cyber-
attacks on organizations are now unavoidable. Security is no longer about averting attacks; it is all
about preparing for them.
In recent years, large corporate data breaches have impacted millions of customers and revealed
personal information that can be used in follow-on crimes. The longer a cyber-attack goes unnoticed,
the more damage it does to the business and the more money and time it will cost to recover.
Hackers steal financial, medical, and other sensitive information to sell online or use in cybercrimes.
This unpredictable security threat landscape has resulted in a challenging scenario for all
organizations.


Business Description

Certification Exam D-SF-A-24: Dell-EMC Dell Security Foundations Achievement Dell-EMC Dell-EMC-D-SF-A-24 1-1908889223

A .R.T.I.E. is a midsize social media company whose key customers are 18- to 28-year-olds. Using the
organization's platform, customers can share content such as photos, videos and post status updates
and views. The organization has a in-built messenger app that helps users to interact. The platform
also has an option to make in-app purchases and play games with other users.
One key characteristic of A .R.T.I.E. is that it supports social influencers and has attracted large firms
as advertisers.
With 450 employees, who work from different locations, the main goal of A .R.T.I.E. is to provide high
quality of services to a user base of 15K individuals and associates. The employees have access to the
apps, platform, data, and systems through an internal network that uses a virtual private network
(VPN) to secure access from remote locations.


Business Problem

Certification Exam D-SF-A-24: Dell-EMC Dell Security Foundations Achievement Dell-EMC Dell-EMC-D-SF-A-24 2-1408597374

Senior management of A .R.T.I.E. expects the core business to continue to grow rapidly due to an
increase in user traffic and increased demand of its advertising platform especially by big
organizations.
Based on their current business-critical needs for their solutions and client base, the organization is
planning to move towards a global operational geography and have migrated some of its key
applications to the public cloud. Deployment of the applications to the public cloud provides:
. Ability to scale.
. Higher data transfer speeds and more efficient access management.
. Faster time-to-market and better control of IT costs.
However, with progress comes new challenges as public cloud environments broaden the attack
surface from which attackers can try to gain unauthorized access to an organization's resources. A
.R.T.I.E. also must comply with various regulations and cloud security controls and have to come up
with holistic security capabilities that ensure security across the organization, core-to-edge-to-cloud.
Even though the IT team of the organization constantly monitor their IT environment and assets
along with watching for unauthorized profiles, information disclosure, fake accounts, and other
threats, the CIO of A.R.I.T.E. is aware that the nature of their business being an open platform makes
them a prime target for attackers and other cybercriminals.
Due to the growing business and untrained employees, the organization is constantly under the fear
of threat. This fear increased tenfold when they had discovered two back-to-back cyberattacks
resulting in unauthorized access to databases containing user information.
In the first attack, the attackers performed data theft techniques to exfiltrate vulnerable information
and held internal systems for ransom. This incident led to the company negotiating a ransom
payment to recover dat
a. Also, an unexplained surge in requests to a single webpage occurred along with unusual network
traffic patterns which indicated a second attack. These attacks were concerning not only for the
financial impact but also for the amount of data exposed.
Requirements
The key requirements to address the primary challenges to the business includes:
. Understanding the cyber threat landscape specific to the organizational risk tolerance.
. Secure migration of applications to the public cloud.
. Implement a suitable security framework to tackle current and emerging threats.
. Identify possible vulnerabilities and threats.
. Create an incident management plan based on knowledge, experience, and real-time information
to prevent future attacks.
. Learn about the tools and technologies used to avert the attacks and determine which tools will be
appropriate for them.
. Take measures to implement secure solutions and control: Zero Trust, Security hardening, IAM
techniques.


Dell Services Team

Certification Exam D-SF-A-24: Dell-EMC Dell Security Foundations Achievement Dell-EMC Dell-EMC-D-SF-A-24 3-2081891856

To improve the overall cyber security posture and implement better security policies as the company
grows, A .R.T.I.E. contacted Dell Services.
Dell clients use their services and solutions to collectively monitor thousands of devices, systems,
and applications. Some clients have a significant workforce with minimal IT knowledge, which opens
greater security risks and technological gaps.
Strategic advisory team
. Commonly known as the core security team which has a global presence.
. Helps organizations to evaluate and gauge their exposure to cybersecurity risk.
. Supports various organizations in developing a vision and strategy for handling cyberattacks.
. Provides advice on the implementation of standard cybersecurity frameworks.
Ethical hackers
. Works within the defined boundaries to legally infiltrate the organization's network environment
with their permission.
. Exposes vulnerabilities in customers IT systems.
Threat intelligence and incident management team
. The team help to keep the organization apprised of the latest developments in the security
landscape.
. The cyber security intelligence team investigates methodologies and technologies to help
organizations detect, understand, and deflect advanced cybersecurity threats and attacks on their IT
infrastructure, and in the cloud.
. The incident management team helps consider what they would do when under attack. The team
may simulate an attack to ensure that non-technical staff members know how to respond.
. The simulated attack is managed by the incident management team. This team also helps to
prevent future attacks based on the information gathered.
Identity and Access Management team
. Reviews and accesses the access rights for each member and user.
. During their analysis the Dell cyber team did a thorough analysis to help create a secure
environment for A .R.T.I.E. and mitigate potential attacks.
Outcomes
With the rapid and thorough analysis of security events originating from both internal and external
sources to A .R.T.I.E. complete, the Dell Services team could detect anomalies, uncover advanced
threats and remove false positives. The Threat Intelligence team was also able to provide a list of
potentially malicious IP addresses, malware, and threat actors.
Along with this, the team also implemented methods that helped determine what is being attacked
and how to stop an attack providing A .R.T.I.E. with real time threat detection mechanisms,
knowledge on cyber security. The common outcomes after implementation of the Dell
recommendations were:
. Prioritization of threat and impact - Determine threat intelligence, vulnerability status and network
communications to evaluate accurate vulnerability risk.
. Secure workforce and educate employees about best practices to be adopted to mitigate attacks,
security frameworks and policies.
. Implementation of incident management plan and build an organization-wide security strategy to
avert future attacks.
. Identification of at-risk users and authorized users, account takeover, disgruntled employees,
malware actions.
. Streamlining of security solutions while reducing operational costs and staffing requirements.
. Increased effectiveness to address the continual growth of IT environments, along with the sharp
rise in the number of threats and attacks.
The objective was to consolidate data from the organization's multiple sources such as: networks,
servers, databases, applications, and so on; thus, supports centralized monitoring.
A R.T.I.E.'s business is forecast to grow tremendously in the next year, the organization will not only
need to hire new employees but also requires contracting with third-party vendors to continue
seamless operations. A .R.T.I.E. uses a VPN to support its employees on the corporate network, but
the organization is facing a security challenge in supporting the third-party business vendors.
To better meet A .R.T.I.E.'s security needs, the cybersecurity team suggested adopting a Zero Trust
architecture (ZTA). The main aim was to move defenses from static, network-based perimeters to
focus on users, assets, and resources. Zero Trust continuously ensures that a user is authentic and the
request for resources is also valid. ZTA also helps to secure the attack surface while supporting
vendor access.
What is the main challenge that ZTA addresses?
Select the answer
1 correct answer
A.
Authorization of A .R.T.I.E. employees.
B.
Malware attacks.
C.
Access to the corporate network for third-party vendors.
D.
Proactive defense in-depth strategy.

Quiz

6/10
Topic 1, Case Study Scenario
Overview
It is recommended that you read through the case study before answering any questions. You can
always return to the case study while viewing any of the twenty questions.
Introduction
As the threat landscape has grown over past years and continues to evolve unpredictably, cyber-
attacks on organizations are now unavoidable. Security is no longer about averting attacks; it is all
about preparing for them.
In recent years, large corporate data breaches have impacted millions of customers and revealed
personal information that can be used in follow-on crimes. The longer a cyber-attack goes unnoticed,
the more damage it does to the business and the more money and time it will cost to recover.
Hackers steal financial, medical, and other sensitive information to sell online or use in cybercrimes.
This unpredictable security threat landscape has resulted in a challenging scenario for all
organizations.


Business Description

Certification Exam D-SF-A-24: Dell-EMC Dell Security Foundations Achievement Dell-EMC Dell-EMC-D-SF-A-24 1-1908889223

A .R.T.I.E. is a midsize social media company whose key customers are 18- to 28-year-olds. Using the
organization's platform, customers can share content such as photos, videos and post status updates
and views. The organization has a in-built messenger app that helps users to interact. The platform
also has an option to make in-app purchases and play games with other users.
One key characteristic of A .R.T.I.E. is that it supports social influencers and has attracted large firms
as advertisers.
With 450 employees, who work from different locations, the main goal of A .R.T.I.E. is to provide high
quality of services to a user base of 15K individuals and associates. The employees have access to the
apps, platform, data, and systems through an internal network that uses a virtual private network
(VPN) to secure access from remote locations.


Business Problem

Certification Exam D-SF-A-24: Dell-EMC Dell Security Foundations Achievement Dell-EMC Dell-EMC-D-SF-A-24 2-1408597374

Senior management of A .R.T.I.E. expects the core business to continue to grow rapidly due to an
increase in user traffic and increased demand of its advertising platform especially by big
organizations.
Based on their current business-critical needs for their solutions and client base, the organization is
planning to move towards a global operational geography and have migrated some of its key
applications to the public cloud. Deployment of the applications to the public cloud provides:
. Ability to scale.
. Higher data transfer speeds and more efficient access management.
. Faster time-to-market and better control of IT costs.
However, with progress comes new challenges as public cloud environments broaden the attack
surface from which attackers can try to gain unauthorized access to an organization's resources. A
.R.T.I.E. also must comply with various regulations and cloud security controls and have to come up
with holistic security capabilities that ensure security across the organization, core-to-edge-to-cloud.
Even though the IT team of the organization constantly monitor their IT environment and assets
along with watching for unauthorized profiles, information disclosure, fake accounts, and other
threats, the CIO of A.R.I.T.E. is aware that the nature of their business being an open platform makes
them a prime target for attackers and other cybercriminals.
Due to the growing business and untrained employees, the organization is constantly under the fear
of threat. This fear increased tenfold when they had discovered two back-to-back cyberattacks
resulting in unauthorized access to databases containing user information.
In the first attack, the attackers performed data theft techniques to exfiltrate vulnerable information
and held internal systems for ransom. This incident led to the company negotiating a ransom
payment to recover dat
a. Also, an unexplained surge in requests to a single webpage occurred along with unusual network
traffic patterns which indicated a second attack. These attacks were concerning not only for the
financial impact but also for the amount of data exposed.
Requirements
The key requirements to address the primary challenges to the business includes:
. Understanding the cyber threat landscape specific to the organizational risk tolerance.
. Secure migration of applications to the public cloud.
. Implement a suitable security framework to tackle current and emerging threats.
. Identify possible vulnerabilities and threats.
. Create an incident management plan based on knowledge, experience, and real-time information
to prevent future attacks.
. Learn about the tools and technologies used to avert the attacks and determine which tools will be
appropriate for them.
. Take measures to implement secure solutions and control: Zero Trust, Security hardening, IAM
techniques.


Dell Services Team

Certification Exam D-SF-A-24: Dell-EMC Dell Security Foundations Achievement Dell-EMC Dell-EMC-D-SF-A-24 3-2081891856

To improve the overall cyber security posture and implement better security policies as the company
grows, A .R.T.I.E. contacted Dell Services.
Dell clients use their services and solutions to collectively monitor thousands of devices, systems,
and applications. Some clients have a significant workforce with minimal IT knowledge, which opens
greater security risks and technological gaps.
Strategic advisory team
. Commonly known as the core security team which has a global presence.
. Helps organizations to evaluate and gauge their exposure to cybersecurity risk.
. Supports various organizations in developing a vision and strategy for handling cyberattacks.
. Provides advice on the implementation of standard cybersecurity frameworks.
Ethical hackers
. Works within the defined boundaries to legally infiltrate the organization's network environment
with their permission.
. Exposes vulnerabilities in customers IT systems.
Threat intelligence and incident management team
. The team help to keep the organization apprised of the latest developments in the security
landscape.
. The cyber security intelligence team investigates methodologies and technologies to help
organizations detect, understand, and deflect advanced cybersecurity threats and attacks on their IT
infrastructure, and in the cloud.
. The incident management team helps consider what they would do when under attack. The team
may simulate an attack to ensure that non-technical staff members know how to respond.
. The simulated attack is managed by the incident management team. This team also helps to
prevent future attacks based on the information gathered.
Identity and Access Management team
. Reviews and accesses the access rights for each member and user.
. During their analysis the Dell cyber team did a thorough analysis to help create a secure
environment for A .R.T.I.E. and mitigate potential attacks.
Outcomes
With the rapid and thorough analysis of security events originating from both internal and external
sources to A .R.T.I.E. complete, the Dell Services team could detect anomalies, uncover advanced
threats and remove false positives. The Threat Intelligence team was also able to provide a list of
potentially malicious IP addresses, malware, and threat actors.
Along with this, the team also implemented methods that helped determine what is being attacked
and how to stop an attack providing A .R.T.I.E. with real time threat detection mechanisms,
knowledge on cyber security. The common outcomes after implementation of the Dell
recommendations were:
. Prioritization of threat and impact - Determine threat intelligence, vulnerability status and network
communications to evaluate accurate vulnerability risk.
. Secure workforce and educate employees about best practices to be adopted to mitigate attacks,
security frameworks and policies.
. Implementation of incident management plan and build an organization-wide security strategy to
avert future attacks.
. Identification of at-risk users and authorized users, account takeover, disgruntled employees,
malware actions.
. Streamlining of security solutions while reducing operational costs and staffing requirements.
. Increased effectiveness to address the continual growth of IT environments, along with the sharp
rise in the number of threats and attacks.
The objective was to consolidate data from the organization's multiple sources such as: networks,
servers, databases, applications, and so on; thus, supports centralized monitoring.
During the analysis, the threat intelligence team disclosed a possible threat which went unnoticed
when an A .R.T.I.E. employee sent their friend a slide deck containing the personal information of a
colleague. The exposed information included employee first and last names, date of birth and
employee ID.
What kind of attack occurred?
Select the answer
1 correct answer
A.
Ransomware
B.
Data breach
C.
Advance Persistent Threat
D.
Supply chain attack

Quiz

7/10
Topic 1, Case Study Scenario
Overview
It is recommended that you read through the case study before answering any questions. You can
always return to the case study while viewing any of the twenty questions.
Introduction
As the threat landscape has grown over past years and continues to evolve unpredictably, cyber-
attacks on organizations are now unavoidable. Security is no longer about averting attacks; it is all
about preparing for them.
In recent years, large corporate data breaches have impacted millions of customers and revealed
personal information that can be used in follow-on crimes. The longer a cyber-attack goes unnoticed,
the more damage it does to the business and the more money and time it will cost to recover.
Hackers steal financial, medical, and other sensitive information to sell online or use in cybercrimes.
This unpredictable security threat landscape has resulted in a challenging scenario for all
organizations.


Business Description

Certification Exam D-SF-A-24: Dell-EMC Dell Security Foundations Achievement Dell-EMC Dell-EMC-D-SF-A-24 1-1908889223

A .R.T.I.E. is a midsize social media company whose key customers are 18- to 28-year-olds. Using the
organization's platform, customers can share content such as photos, videos and post status updates
and views. The organization has a in-built messenger app that helps users to interact. The platform
also has an option to make in-app purchases and play games with other users.
One key characteristic of A .R.T.I.E. is that it supports social influencers and has attracted large firms
as advertisers.
With 450 employees, who work from different locations, the main goal of A .R.T.I.E. is to provide high
quality of services to a user base of 15K individuals and associates. The employees have access to the
apps, platform, data, and systems through an internal network that uses a virtual private network
(VPN) to secure access from remote locations.


Business Problem

Certification Exam D-SF-A-24: Dell-EMC Dell Security Foundations Achievement Dell-EMC Dell-EMC-D-SF-A-24 2-1408597374

Senior management of A .R.T.I.E. expects the core business to continue to grow rapidly due to an
increase in user traffic and increased demand of its advertising platform especially by big
organizations.
Based on their current business-critical needs for their solutions and client base, the organization is
planning to move towards a global operational geography and have migrated some of its key
applications to the public cloud. Deployment of the applications to the public cloud provides:
. Ability to scale.
. Higher data transfer speeds and more efficient access management.
. Faster time-to-market and better control of IT costs.
However, with progress comes new challenges as public cloud environments broaden the attack
surface from which attackers can try to gain unauthorized access to an organization's resources. A
.R.T.I.E. also must comply with various regulations and cloud security controls and have to come up
with holistic security capabilities that ensure security across the organization, core-to-edge-to-cloud.
Even though the IT team of the organization constantly monitor their IT environment and assets
along with watching for unauthorized profiles, information disclosure, fake accounts, and other
threats, the CIO of A.R.I.T.E. is aware that the nature of their business being an open platform makes
them a prime target for attackers and other cybercriminals.
Due to the growing business and untrained employees, the organization is constantly under the fear
of threat. This fear increased tenfold when they had discovered two back-to-back cyberattacks
resulting in unauthorized access to databases containing user information.
In the first attack, the attackers performed data theft techniques to exfiltrate vulnerable information
and held internal systems for ransom. This incident led to the company negotiating a ransom
payment to recover dat
a. Also, an unexplained surge in requests to a single webpage occurred along with unusual network
traffic patterns which indicated a second attack. These attacks were concerning not only for the
financial impact but also for the amount of data exposed.
Requirements
The key requirements to address the primary challenges to the business includes:
. Understanding the cyber threat landscape specific to the organizational risk tolerance.
. Secure migration of applications to the public cloud.
. Implement a suitable security framework to tackle current and emerging threats.
. Identify possible vulnerabilities and threats.
. Create an incident management plan based on knowledge, experience, and real-time information
to prevent future attacks.
. Learn about the tools and technologies used to avert the attacks and determine which tools will be
appropriate for them.
. Take measures to implement secure solutions and control: Zero Trust, Security hardening, IAM
techniques.


Dell Services Team

Certification Exam D-SF-A-24: Dell-EMC Dell Security Foundations Achievement Dell-EMC Dell-EMC-D-SF-A-24 3-2081891856

To improve the overall cyber security posture and implement better security policies as the company
grows, A .R.T.I.E. contacted Dell Services.
Dell clients use their services and solutions to collectively monitor thousands of devices, systems,
and applications. Some clients have a significant workforce with minimal IT knowledge, which opens
greater security risks and technological gaps.
Strategic advisory team
. Commonly known as the core security team which has a global presence.
. Helps organizations to evaluate and gauge their exposure to cybersecurity risk.
. Supports various organizations in developing a vision and strategy for handling cyberattacks.
. Provides advice on the implementation of standard cybersecurity frameworks.
Ethical hackers
. Works within the defined boundaries to legally infiltrate the organization's network environment
with their permission.
. Exposes vulnerabilities in customers IT systems.
Threat intelligence and incident management team
. The team help to keep the organization apprised of the latest developments in the security
landscape.
. The cyber security intelligence team investigates methodologies and technologies to help
organizations detect, understand, and deflect advanced cybersecurity threats and attacks on their IT
infrastructure, and in the cloud.
. The incident management team helps consider what they would do when under attack. The team
may simulate an attack to ensure that non-technical staff members know how to respond.
. The simulated attack is managed by the incident management team. This team also helps to
prevent future attacks based on the information gathered.
Identity and Access Management team
. Reviews and accesses the access rights for each member and user.
. During their analysis the Dell cyber team did a thorough analysis to help create a secure
environment for A .R.T.I.E. and mitigate potential attacks.
Outcomes
With the rapid and thorough analysis of security events originating from both internal and external
sources to A .R.T.I.E. complete, the Dell Services team could detect anomalies, uncover advanced
threats and remove false positives. The Threat Intelligence team was also able to provide a list of
potentially malicious IP addresses, malware, and threat actors.
Along with this, the team also implemented methods that helped determine what is being attacked
and how to stop an attack providing A .R.T.I.E. with real time threat detection mechanisms,
knowledge on cyber security. The common outcomes after implementation of the Dell
recommendations were:
. Prioritization of threat and impact - Determine threat intelligence, vulnerability status and network
communications to evaluate accurate vulnerability risk.
. Secure workforce and educate employees about best practices to be adopted to mitigate attacks,
security frameworks and policies.
. Implementation of incident management plan and build an organization-wide security strategy to
avert future attacks.
. Identification of at-risk users and authorized users, account takeover, disgruntled employees,
malware actions.
. Streamlining of security solutions while reducing operational costs and staffing requirements.
. Increased effectiveness to address the continual growth of IT environments, along with the sharp
rise in the number of threats and attacks.
The objective was to consolidate data from the organization's multiple sources such as: networks,
servers, databases, applications, and so on; thus, supports centralized monitoring.
A .R.T.I.E. is planning to deploy some of their applications in a public cloud. A major concern is how
to share and protect data off premises. Also, how data can be used in decision making without
exposing it to anyone who should not have access. Dell Services briefed them about various control
mechanisms to secure data in the public cloud.
Which control mechanism should be selected in this scenario?
Select the answer
1 correct answer
A.
Proactive control mechanism
B.
Detective control mechanism
C.
Corrective control mechanism

Quiz

8/10
Topic 1, Case Study Scenario
Overview
It is recommended that you read through the case study before answering any questions. You can
always return to the case study while viewing any of the twenty questions.
Introduction
As the threat landscape has grown over past years and continues to evolve unpredictably, cyber-
attacks on organizations are now unavoidable. Security is no longer about averting attacks; it is all
about preparing for them.
In recent years, large corporate data breaches have impacted millions of customers and revealed
personal information that can be used in follow-on crimes. The longer a cyber-attack goes unnoticed,
the more damage it does to the business and the more money and time it will cost to recover.
Hackers steal financial, medical, and other sensitive information to sell online or use in cybercrimes.
This unpredictable security threat landscape has resulted in a challenging scenario for all
organizations.


Business Description

Certification Exam D-SF-A-24: Dell-EMC Dell Security Foundations Achievement Dell-EMC Dell-EMC-D-SF-A-24 1-1908889223

A .R.T.I.E. is a midsize social media company whose key customers are 18- to 28-year-olds. Using the
organization's platform, customers can share content such as photos, videos and post status updates
and views. The organization has a in-built messenger app that helps users to interact. The platform
also has an option to make in-app purchases and play games with other users.
One key characteristic of A .R.T.I.E. is that it supports social influencers and has attracted large firms
as advertisers.
With 450 employees, who work from different locations, the main goal of A .R.T.I.E. is to provide high
quality of services to a user base of 15K individuals and associates. The employees have access to the
apps, platform, data, and systems through an internal network that uses a virtual private network
(VPN) to secure access from remote locations.


Business Problem

Certification Exam D-SF-A-24: Dell-EMC Dell Security Foundations Achievement Dell-EMC Dell-EMC-D-SF-A-24 2-1408597374

Senior management of A .R.T.I.E. expects the core business to continue to grow rapidly due to an
increase in user traffic and increased demand of its advertising platform especially by big
organizations.
Based on their current business-critical needs for their solutions and client base, the organization is
planning to move towards a global operational geography and have migrated some of its key
applications to the public cloud. Deployment of the applications to the public cloud provides:
. Ability to scale.
. Higher data transfer speeds and more efficient access management.
. Faster time-to-market and better control of IT costs.
However, with progress comes new challenges as public cloud environments broaden the attack
surface from which attackers can try to gain unauthorized access to an organization's resources. A
.R.T.I.E. also must comply with various regulations and cloud security controls and have to come up
with holistic security capabilities that ensure security across the organization, core-to-edge-to-cloud.
Even though the IT team of the organization constantly monitor their IT environment and assets
along with watching for unauthorized profiles, information disclosure, fake accounts, and other
threats, the CIO of A.R.I.T.E. is aware that the nature of their business being an open platform makes
them a prime target for attackers and other cybercriminals.
Due to the growing business and untrained employees, the organization is constantly under the fear
of threat. This fear increased tenfold when they had discovered two back-to-back cyberattacks
resulting in unauthorized access to databases containing user information.
In the first attack, the attackers performed data theft techniques to exfiltrate vulnerable information
and held internal systems for ransom. This incident led to the company negotiating a ransom
payment to recover dat
a. Also, an unexplained surge in requests to a single webpage occurred along with unusual network
traffic patterns which indicated a second attack. These attacks were concerning not only for the
financial impact but also for the amount of data exposed.
Requirements
The key requirements to address the primary challenges to the business includes:
. Understanding the cyber threat landscape specific to the organizational risk tolerance.
. Secure migration of applications to the public cloud.
. Implement a suitable security framework to tackle current and emerging threats.
. Identify possible vulnerabilities and threats.
. Create an incident management plan based on knowledge, experience, and real-time information
to prevent future attacks.
. Learn about the tools and technologies used to avert the attacks and determine which tools will be
appropriate for them.
. Take measures to implement secure solutions and control: Zero Trust, Security hardening, IAM
techniques.


Dell Services Team

Certification Exam D-SF-A-24: Dell-EMC Dell Security Foundations Achievement Dell-EMC Dell-EMC-D-SF-A-24 3-2081891856

To improve the overall cyber security posture and implement better security policies as the company
grows, A .R.T.I.E. contacted Dell Services.
Dell clients use their services and solutions to collectively monitor thousands of devices, systems,
and applications. Some clients have a significant workforce with minimal IT knowledge, which opens
greater security risks and technological gaps.
Strategic advisory team
. Commonly known as the core security team which has a global presence.
. Helps organizations to evaluate and gauge their exposure to cybersecurity risk.
. Supports various organizations in developing a vision and strategy for handling cyberattacks.
. Provides advice on the implementation of standard cybersecurity frameworks.
Ethical hackers
. Works within the defined boundaries to legally infiltrate the organization's network environment
with their permission.
. Exposes vulnerabilities in customers IT systems.
Threat intelligence and incident management team
. The team help to keep the organization apprised of the latest developments in the security
landscape.
. The cyber security intelligence team investigates methodologies and technologies to help
organizations detect, understand, and deflect advanced cybersecurity threats and attacks on their IT
infrastructure, and in the cloud.
. The incident management team helps consider what they would do when under attack. The team
may simulate an attack to ensure that non-technical staff members know how to respond.
. The simulated attack is managed by the incident management team. This team also helps to
prevent future attacks based on the information gathered.
Identity and Access Management team
. Reviews and accesses the access rights for each member and user.
. During their analysis the Dell cyber team did a thorough analysis to help create a secure
environment for A .R.T.I.E. and mitigate potential attacks.
Outcomes
With the rapid and thorough analysis of security events originating from both internal and external
sources to A .R.T.I.E. complete, the Dell Services team could detect anomalies, uncover advanced
threats and remove false positives. The Threat Intelligence team was also able to provide a list of
potentially malicious IP addresses, malware, and threat actors.
Along with this, the team also implemented methods that helped determine what is being attacked
and how to stop an attack providing A .R.T.I.E. with real time threat detection mechanisms,
knowledge on cyber security. The common outcomes after implementation of the Dell
recommendations were:
. Prioritization of threat and impact - Determine threat intelligence, vulnerability status and network
communications to evaluate accurate vulnerability risk.
. Secure workforce and educate employees about best practices to be adopted to mitigate attacks,
security frameworks and policies.
. Implementation of incident management plan and build an organization-wide security strategy to
avert future attacks.
. Identification of at-risk users and authorized users, account takeover, disgruntled employees,
malware actions.
. Streamlining of security solutions while reducing operational costs and staffing requirements.
. Increased effectiveness to address the continual growth of IT environments, along with the sharp
rise in the number of threats and attacks.
The objective was to consolidate data from the organization's multiple sources such as: networks,
servers, databases, applications, and so on; thus, supports centralized monitoring.
Which framework should be recommended to A .R.T.I.E. to enhance the overall security and
resilience of their critical infrastructure, and outline methods to reduce their cybersecurity risk?
Select the answer
1 correct answer
A.
NIST CSF
B.
COBIT
C.
PCIDSS
D.
HIPAA

Quiz

9/10
Topic 1, Case Study Scenario
Overview
It is recommended that you read through the case study before answering any questions. You can
always return to the case study while viewing any of the twenty questions.
Introduction
As the threat landscape has grown over past years and continues to evolve unpredictably, cyber-
attacks on organizations are now unavoidable. Security is no longer about averting attacks; it is all
about preparing for them.
In recent years, large corporate data breaches have impacted millions of customers and revealed
personal information that can be used in follow-on crimes. The longer a cyber-attack goes unnoticed,
the more damage it does to the business and the more money and time it will cost to recover.
Hackers steal financial, medical, and other sensitive information to sell online or use in cybercrimes.
This unpredictable security threat landscape has resulted in a challenging scenario for all
organizations.


Business Description

Certification Exam D-SF-A-24: Dell-EMC Dell Security Foundations Achievement Dell-EMC Dell-EMC-D-SF-A-24 1-1908889223

A .R.T.I.E. is a midsize social media company whose key customers are 18- to 28-year-olds. Using the
organization's platform, customers can share content such as photos, videos and post status updates
and views. The organization has a in-built messenger app that helps users to interact. The platform
also has an option to make in-app purchases and play games with other users.
One key characteristic of A .R.T.I.E. is that it supports social influencers and has attracted large firms
as advertisers.
With 450 employees, who work from different locations, the main goal of A .R.T.I.E. is to provide high
quality of services to a user base of 15K individuals and associates. The employees have access to the
apps, platform, data, and systems through an internal network that uses a virtual private network
(VPN) to secure access from remote locations.


Business Problem

Certification Exam D-SF-A-24: Dell-EMC Dell Security Foundations Achievement Dell-EMC Dell-EMC-D-SF-A-24 2-1408597374

Senior management of A .R.T.I.E. expects the core business to continue to grow rapidly due to an
increase in user traffic and increased demand of its advertising platform especially by big
organizations.
Based on their current business-critical needs for their solutions and client base, the organization is
planning to move towards a global operational geography and have migrated some of its key
applications to the public cloud. Deployment of the applications to the public cloud provides:
. Ability to scale.
. Higher data transfer speeds and more efficient access management.
. Faster time-to-market and better control of IT costs.
However, with progress comes new challenges as public cloud environments broaden the attack
surface from which attackers can try to gain unauthorized access to an organization's resources. A
.R.T.I.E. also must comply with various regulations and cloud security controls and have to come up
with holistic security capabilities that ensure security across the organization, core-to-edge-to-cloud.
Even though the IT team of the organization constantly monitor their IT environment and assets
along with watching for unauthorized profiles, information disclosure, fake accounts, and other
threats, the CIO of A.R.I.T.E. is aware that the nature of their business being an open platform makes
them a prime target for attackers and other cybercriminals.
Due to the growing business and untrained employees, the organization is constantly under the fear
of threat. This fear increased tenfold when they had discovered two back-to-back cyberattacks
resulting in unauthorized access to databases containing user information.
In the first attack, the attackers performed data theft techniques to exfiltrate vulnerable information
and held internal systems for ransom. This incident led to the company negotiating a ransom
payment to recover dat
a. Also, an unexplained surge in requests to a single webpage occurred along with unusual network
traffic patterns which indicated a second attack. These attacks were concerning not only for the
financial impact but also for the amount of data exposed.
Requirements
The key requirements to address the primary challenges to the business includes:
. Understanding the cyber threat landscape specific to the organizational risk tolerance.
. Secure migration of applications to the public cloud.
. Implement a suitable security framework to tackle current and emerging threats.
. Identify possible vulnerabilities and threats.
. Create an incident management plan based on knowledge, experience, and real-time information
to prevent future attacks.
. Learn about the tools and technologies used to avert the attacks and determine which tools will be
appropriate for them.
. Take measures to implement secure solutions and control: Zero Trust, Security hardening, IAM
techniques.


Dell Services Team

Certification Exam D-SF-A-24: Dell-EMC Dell Security Foundations Achievement Dell-EMC Dell-EMC-D-SF-A-24 3-2081891856

To improve the overall cyber security posture and implement better security policies as the company
grows, A .R.T.I.E. contacted Dell Services.
Dell clients use their services and solutions to collectively monitor thousands of devices, systems,
and applications. Some clients have a significant workforce with minimal IT knowledge, which opens
greater security risks and technological gaps.
Strategic advisory team
. Commonly known as the core security team which has a global presence.
. Helps organizations to evaluate and gauge their exposure to cybersecurity risk.
. Supports various organizations in developing a vision and strategy for handling cyberattacks.
. Provides advice on the implementation of standard cybersecurity frameworks.
Ethical hackers
. Works within the defined boundaries to legally infiltrate the organization's network environment
with their permission.
. Exposes vulnerabilities in customers IT systems.
Threat intelligence and incident management team
. The team help to keep the organization apprised of the latest developments in the security
landscape.
. The cyber security intelligence team investigates methodologies and technologies to help
organizations detect, understand, and deflect advanced cybersecurity threats and attacks on their IT
infrastructure, and in the cloud.
. The incident management team helps consider what they would do when under attack. The team
may simulate an attack to ensure that non-technical staff members know how to respond.
. The simulated attack is managed by the incident management team. This team also helps to
prevent future attacks based on the information gathered.
Identity and Access Management team
. Reviews and accesses the access rights for each member and user.
. During their analysis the Dell cyber team did a thorough analysis to help create a secure
environment for A .R.T.I.E. and mitigate potential attacks.
Outcomes
With the rapid and thorough analysis of security events originating from both internal and external
sources to A .R.T.I.E. complete, the Dell Services team could detect anomalies, uncover advanced
threats and remove false positives. The Threat Intelligence team was also able to provide a list of
potentially malicious IP addresses, malware, and threat actors.
Along with this, the team also implemented methods that helped determine what is being attacked
and how to stop an attack providing A .R.T.I.E. with real time threat detection mechanisms,
knowledge on cyber security. The common outcomes after implementation of the Dell
recommendations were:
. Prioritization of threat and impact - Determine threat intelligence, vulnerability status and network
communications to evaluate accurate vulnerability risk.
. Secure workforce and educate employees about best practices to be adopted to mitigate attacks,
security frameworks and policies.
. Implementation of incident management plan and build an organization-wide security strategy to
avert future attacks.
. Identification of at-risk users and authorized users, account takeover, disgruntled employees,
malware actions.
. Streamlining of security solutions while reducing operational costs and staffing requirements.
. Increased effectiveness to address the continual growth of IT environments, along with the sharp
rise in the number of threats and attacks.
The objective was to consolidate data from the organization's multiple sources such as: networks,
servers, databases, applications, and so on; thus, supports centralized monitoring.
In the cloud, there are numerous configuration options for the services provided. If not properly set,
these configurations can leave the environment in an unsecure state where an attacker can read and
modify the transmitted data packets and send their own requests to the client.
Which types of attack enable an attacker to read and modify the transmitted data packets and send
their own requests to the client?
Select the answer
1 correct answer
A.
Data loss
B.
Shared technology
C.
TCP hijacking
D.
Dumpster diving

Quiz

10/10
Topic 1, Case Study Scenario
Overview
It is recommended that you read through the case study before answering any questions. You can
always return to the case study while viewing any of the twenty questions.
Introduction
As the threat landscape has grown over past years and continues to evolve unpredictably, cyber-
attacks on organizations are now unavoidable. Security is no longer about averting attacks; it is all
about preparing for them.
In recent years, large corporate data breaches have impacted millions of customers and revealed
personal information that can be used in follow-on crimes. The longer a cyber-attack goes unnoticed,
the more damage it does to the business and the more money and time it will cost to recover.
Hackers steal financial, medical, and other sensitive information to sell online or use in cybercrimes.
This unpredictable security threat landscape has resulted in a challenging scenario for all
organizations.


Business Description

Certification Exam D-SF-A-24: Dell-EMC Dell Security Foundations Achievement Dell-EMC Dell-EMC-D-SF-A-24 1-1908889223

A .R.T.I.E. is a midsize social media company whose key customers are 18- to 28-year-olds. Using the
organization's platform, customers can share content such as photos, videos and post status updates
and views. The organization has a in-built messenger app that helps users to interact. The platform
also has an option to make in-app purchases and play games with other users.
One key characteristic of A .R.T.I.E. is that it supports social influencers and has attracted large firms
as advertisers.
With 450 employees, who work from different locations, the main goal of A .R.T.I.E. is to provide high
quality of services to a user base of 15K individuals and associates. The employees have access to the
apps, platform, data, and systems through an internal network that uses a virtual private network
(VPN) to secure access from remote locations.


Business Problem

Certification Exam D-SF-A-24: Dell-EMC Dell Security Foundations Achievement Dell-EMC Dell-EMC-D-SF-A-24 2-1408597374

Senior management of A .R.T.I.E. expects the core business to continue to grow rapidly due to an
increase in user traffic and increased demand of its advertising platform especially by big
organizations.
Based on their current business-critical needs for their solutions and client base, the organization is
planning to move towards a global operational geography and have migrated some of its key
applications to the public cloud. Deployment of the applications to the public cloud provides:
. Ability to scale.
. Higher data transfer speeds and more efficient access management.
. Faster time-to-market and better control of IT costs.
However, with progress comes new challenges as public cloud environments broaden the attack
surface from which attackers can try to gain unauthorized access to an organization's resources. A
.R.T.I.E. also must comply with various regulations and cloud security controls and have to come up
with holistic security capabilities that ensure security across the organization, core-to-edge-to-cloud.
Even though the IT team of the organization constantly monitor their IT environment and assets
along with watching for unauthorized profiles, information disclosure, fake accounts, and other
threats, the CIO of A.R.I.T.E. is aware that the nature of their business being an open platform makes
them a prime target for attackers and other cybercriminals.
Due to the growing business and untrained employees, the organization is constantly under the fear
of threat. This fear increased tenfold when they had discovered two back-to-back cyberattacks
resulting in unauthorized access to databases containing user information.
In the first attack, the attackers performed data theft techniques to exfiltrate vulnerable information
and held internal systems for ransom. This incident led to the company negotiating a ransom
payment to recover dat
a. Also, an unexplained surge in requests to a single webpage occurred along with unusual network
traffic patterns which indicated a second attack. These attacks were concerning not only for the
financial impact but also for the amount of data exposed.
Requirements
The key requirements to address the primary challenges to the business includes:
. Understanding the cyber threat landscape specific to the organizational risk tolerance.
. Secure migration of applications to the public cloud.
. Implement a suitable security framework to tackle current and emerging threats.
. Identify possible vulnerabilities and threats.
. Create an incident management plan based on knowledge, experience, and real-time information
to prevent future attacks.
. Learn about the tools and technologies used to avert the attacks and determine which tools will be
appropriate for them.
. Take measures to implement secure solutions and control: Zero Trust, Security hardening, IAM
techniques.


Dell Services Team

Certification Exam D-SF-A-24: Dell-EMC Dell Security Foundations Achievement Dell-EMC Dell-EMC-D-SF-A-24 3-2081891856

To improve the overall cyber security posture and implement better security policies as the company
grows, A .R.T.I.E. contacted Dell Services.
Dell clients use their services and solutions to collectively monitor thousands of devices, systems,
and applications. Some clients have a significant workforce with minimal IT knowledge, which opens
greater security risks and technological gaps.
Strategic advisory team
. Commonly known as the core security team which has a global presence.
. Helps organizations to evaluate and gauge their exposure to cybersecurity risk.
. Supports various organizations in developing a vision and strategy for handling cyberattacks.
. Provides advice on the implementation of standard cybersecurity frameworks.
Ethical hackers
. Works within the defined boundaries to legally infiltrate the organization's network environment
with their permission.
. Exposes vulnerabilities in customers IT systems.
Threat intelligence and incident management team
. The team help to keep the organization apprised of the latest developments in the security
landscape.
. The cyber security intelligence team investigates methodologies and technologies to help
organizations detect, understand, and deflect advanced cybersecurity threats and attacks on their IT
infrastructure, and in the cloud.
. The incident management team helps consider what they would do when under attack. The team
may simulate an attack to ensure that non-technical staff members know how to respond.
. The simulated attack is managed by the incident management team. This team also helps to
prevent future attacks based on the information gathered.
Identity and Access Management team
. Reviews and accesses the access rights for each member and user.
. During their analysis the Dell cyber team did a thorough analysis to help create a secure
environment for A .R.T.I.E. and mitigate potential attacks.
Outcomes
With the rapid and thorough analysis of security events originating from both internal and external
sources to A .R.T.I.E. complete, the Dell Services team could detect anomalies, uncover advanced
threats and remove false positives. The Threat Intelligence team was also able to provide a list of
potentially malicious IP addresses, malware, and threat actors.
Along with this, the team also implemented methods that helped determine what is being attacked
and how to stop an attack providing A .R.T.I.E. with real time threat detection mechanisms,
knowledge on cyber security. The common outcomes after implementation of the Dell
recommendations were:
. Prioritization of threat and impact - Determine threat intelligence, vulnerability status and network
communications to evaluate accurate vulnerability risk.
. Secure workforce and educate employees about best practices to be adopted to mitigate attacks,
security frameworks and policies.
. Implementation of incident management plan and build an organization-wide security strategy to
avert future attacks.
. Identification of at-risk users and authorized users, account takeover, disgruntled employees,
malware actions.
. Streamlining of security solutions while reducing operational costs and staffing requirements.
. Increased effectiveness to address the continual growth of IT environments, along with the sharp
rise in the number of threats and attacks.
The objective was to consolidate data from the organization's multiple sources such as: networks,
servers, databases, applications, and so on; thus, supports centralized monitoring.
During the analysis, the threat intelligence team disclosed that attackers not only encrypted files, but
also attempted to encrypt backups and shared, networked, and cloud drives.
Which type of ransomware is used for this attack?
Select the answer
1 correct answer
A.
Cryptolocker
B.
Double extortion
C.
Crypto
D.
Locker
Looking for more questions?Buy now

D-SF-A-24: Dell-EMC Dell Security Foundations Achievement Practice test unlocks all online simulator questions

Thank you for choosing the free version of the D-SF-A-24: Dell-EMC Dell Security Foundations Achievement practice test! Further deepen your knowledge on Dell-EMC Simulator; by unlocking the full version of our D-SF-A-24: Dell-EMC Dell Security Foundations Achievement Simulator you will be able to take tests with over 20 constantly updated questions and easily pass your exam. 98% of people pass the exam in the first attempt after preparing with our 20 questions.

BUY NOW

What to expect from our D-SF-A-24: Dell-EMC Dell Security Foundations Achievement practice tests and how to prepare for any exam?

The D-SF-A-24: Dell-EMC Dell Security Foundations Achievement Simulator Practice Tests are part of the Dell-EMC Database and are the best way to prepare for any D-SF-A-24: Dell-EMC Dell Security Foundations Achievement exam. The D-SF-A-24: Dell-EMC Dell Security Foundations Achievement practice tests consist of 20 questions and are written by experts to help you and prepare you to pass the exam on the first attempt. The D-SF-A-24: Dell-EMC Dell Security Foundations Achievement database includes questions from previous and other exams, which means you will be able to practice simulating past and future questions. Preparation with D-SF-A-24: Dell-EMC Dell Security Foundations Achievement Simulator will also give you an idea of the time it will take to complete each section of the D-SF-A-24: Dell-EMC Dell Security Foundations Achievement practice test . It is important to note that the D-SF-A-24: Dell-EMC Dell Security Foundations Achievement Simulator does not replace the classic D-SF-A-24: Dell-EMC Dell Security Foundations Achievement study guides; however, the Simulator provides valuable insights into what to expect and how much work needs to be done to prepare for the D-SF-A-24: Dell-EMC Dell Security Foundations Achievement exam.

BUY NOW

D-SF-A-24: Dell-EMC Dell Security Foundations Achievement Practice test therefore represents an excellent tool to prepare for the actual exam together with our Dell-EMC practice test . Our D-SF-A-24: Dell-EMC Dell Security Foundations Achievement Simulator will help you assess your level of preparation and understand your strengths and weaknesses. Below you can read all the quizzes you will find in our D-SF-A-24: Dell-EMC Dell Security Foundations Achievement Simulator and how our unique D-SF-A-24: Dell-EMC Dell Security Foundations Achievement Database made up of real questions:

Info quiz:

  • Quiz name:D-SF-A-24: Dell-EMC Dell Security Foundations Achievement
  • Total number of questions:20
  • Number of questions for the test:50
  • Pass score:80%

You can prepare for the D-SF-A-24: Dell-EMC Dell Security Foundations Achievement exams with our mobile app. It is very easy to use and even works offline in case of network failure, with all the functions you need to study and practice with our D-SF-A-24: Dell-EMC Dell Security Foundations Achievement Simulator.

Use our Mobile App, available for both Android and iOS devices, with our D-SF-A-24: Dell-EMC Dell Security Foundations Achievement Simulator . You can use it anywhere and always remember that our mobile app is free and available on all stores.

Our Mobile App contains all D-SF-A-24: Dell-EMC Dell Security Foundations Achievement practice tests which consist of 20 questions and also provide study material to pass the final D-SF-A-24: Dell-EMC Dell Security Foundations Achievement exam with guaranteed success. Our D-SF-A-24: Dell-EMC Dell Security Foundations Achievement database contain hundreds of questions and Dell-EMC Tests related to D-SF-A-24: Dell-EMC Dell Security Foundations Achievement Exam. This way you can practice anywhere you want, even offline without the internet.

BUY NOW