問題1
Which asset would be the MOST desirable for a financially motivated attacker to obtain from a health insurance company?
Which asset would be the MOST desirable for a financially motivated attacker to obtain from a health insurance company?
正確答案: D
問題2
A security professional discovers a new ransomware strain that disables antivirus on the endpoint during an infection. Which location would be the BEST place for the security professional to find technical information about this malware?
A security professional discovers a new ransomware strain that disables antivirus on the endpoint during an infection. Which location would be the BEST place for the security professional to find technical information about this malware?
正確答案: D
問題3
An administrator investigating intermittent network communication problems has identified an excessive amount of traffic from an external-facing host to an unknown location on the Internet. Which of the following BEST describes what is occurring?
An administrator investigating intermittent network communication problems has identified an excessive amount of traffic from an external-facing host to an unknown location on the Internet. Which of the following BEST describes what is occurring?
正確答案: B
問題4
During the forensic analysis of a compromised computer image, the investigator found that critical files are missing, caches have been cleared, and the history and event log files are empty. According to this scenario, which of the following techniques is the suspect using?
During the forensic analysis of a compromised computer image, the investigator found that critical files are missing, caches have been cleared, and the history and event log files are empty. According to this scenario, which of the following techniques is the suspect using?
正確答案: A
問題5
A company website was hacked via the following SQL query:
email, passwd, login_id, full_name FROM members
WHERE email = "[email protected]"; DROP TABLE members; -"
Which of the following did the hackers perform?
A company website was hacked via the following SQL query:
email, passwd, login_id, full_name FROM members
WHERE email = "[email protected]"; DROP TABLE members; -"
Which of the following did the hackers perform?
正確答案: D
問題6
During a malware-driven distributed denial of service attack, a security researcher found excessive requests to a name server referring to the same domain name and host name encoded in hexadecimal. The malware author used which type of command and control?
During a malware-driven distributed denial of service attack, a security researcher found excessive requests to a name server referring to the same domain name and host name encoded in hexadecimal. The malware author used which type of command and control?
正確答案: D
問題7
A security operations center (SOC) analyst observed an unusually high number of login failures on a particular database server. The analyst wants to gather supporting evidence before escalating the observation to management. Which of the following expressions will provide login failure data for 11/24/2015?
A security operations center (SOC) analyst observed an unusually high number of login failures on a particular database server. The analyst wants to gather supporting evidence before escalating the observation to management. Which of the following expressions will provide login failure data for 11/24/2015?
正確答案: A
問題8
Which of the following is a method of reconnaissance in which a ping is sent to a target with the expectation of receiving a response?
Which of the following is a method of reconnaissance in which a ping is sent to a target with the expectation of receiving a response?
正確答案: B
問題9
Which of the following are well-known methods that are used to protect evidence during the forensics process? (Choose three.)
Which of the following are well-known methods that are used to protect evidence during the forensics process? (Choose three.)
正確答案: B,E,F
問題10
An automatic vulnerability scan has been performed. Which is the next step of the vulnerability assessment process?
An automatic vulnerability scan has been performed. Which is the next step of the vulnerability assessment process?
正確答案: D