問題1
Using open-source intelligence gathered from technical forums, a threat actor compiles and tests a malicious downloader to ensure it will not be detected by the victim organization ' s endpoint security protections.
Which of the following stages of the Cyber Kill Chain best aligns with the threat actor ' s actions?
Using open-source intelligence gathered from technical forums, a threat actor compiles and tests a malicious downloader to ensure it will not be detected by the victim organization ' s endpoint security protections.
Which of the following stages of the Cyber Kill Chain best aligns with the threat actor ' s actions?
正確答案: D
說明:(僅 NewDumps 成員可見)
問題2
Which of the following is the best way to provide realistic training for SOC analysts?
Which of the following is the best way to provide realistic training for SOC analysts?
正確答案: C
說明:(僅 NewDumps 成員可見)
問題3
Which of the following best describes the key elements of a successful information security program?
Which of the following best describes the key elements of a successful information security program?
正確答案: B
說明:(僅 NewDumps 成員可見)
問題4
An analyst reviews the following web server log entries:
%2E%2E/%2E%2E/%2ES2E/%2E%2E/%2E%2E/%2E%2E/etc/passwd
No attacks or malicious attempts have been discovered. Which of the following most likely describes what took place?
An analyst reviews the following web server log entries:
%2E%2E/%2E%2E/%2ES2E/%2E%2E/%2E%2E/%2E%2E/etc/passwd
No attacks or malicious attempts have been discovered. Which of the following most likely describes what took place?
正確答案: B
說明:(僅 NewDumps 成員可見)
問題5
An incident response team is working with law enforcement to investigate an active web server compromise.
The decision has been made to keep the server running and to implement compensating controls for a period of time. The web service must be accessible from the internet via the reverse proxy and must connect to a database server. Which of the following compensating controls will help contain the adversary while meeting the other requirements? (Select two).
An incident response team is working with law enforcement to investigate an active web server compromise.
The decision has been made to keep the server running and to implement compensating controls for a period of time. The web service must be accessible from the internet via the reverse proxy and must connect to a database server. Which of the following compensating controls will help contain the adversary while meeting the other requirements? (Select two).
正確答案: A,B
說明:(僅 NewDumps 成員可見)
問題6
A systems administrator is reviewing after-hours traffic flows from data-center servers and sees regular outgoing HTTPS connections from one of the servers to a public IP address. The server should not be making outgoing connections after hours. Looking closer, the administrator sees this traffic pattern around the clock during work hours as well. Which of the following is the most likely explanation?
A systems administrator is reviewing after-hours traffic flows from data-center servers and sees regular outgoing HTTPS connections from one of the servers to a public IP address. The server should not be making outgoing connections after hours. Looking closer, the administrator sees this traffic pattern around the clock during work hours as well. Which of the following is the most likely explanation?
正確答案: A
說明:(僅 NewDumps 成員可見)
問題7
A SOC team lead occasionally collects some DNS information for investigations. The team lead assigns this task to a new junior analyst. Which of the following is the best way to relay the process information to the junior analyst?
A SOC team lead occasionally collects some DNS information for investigations. The team lead assigns this task to a new junior analyst. Which of the following is the best way to relay the process information to the junior analyst?
正確答案: C
說明:(僅 NewDumps 成員可見)
問題8
The Chief Information Security Officer is directing a new program to reduce attack surface risks and threats as part of a zero trust approach. The IT security team is required to come up with priorities for the program.
Which of the following is the best priority based on common attack frameworks?
The Chief Information Security Officer is directing a new program to reduce attack surface risks and threats as part of a zero trust approach. The IT security team is required to come up with priorities for the program.
Which of the following is the best priority based on common attack frameworks?
正確答案: A
說明:(僅 NewDumps 成員可見)
問題9
Which of the following is instituting a security policy that users must lock their systems when stepping away from their desks an example of?
Which of the following is instituting a security policy that users must lock their systems when stepping away from their desks an example of?
正確答案: B
說明:(僅 NewDumps 成員可見)
問題10
When starting an investigation, which of the following must be done first?
When starting an investigation, which of the following must be done first?
正確答案: B
說明:(僅 NewDumps 成員可見)
問題11
A security analyst is responding to an incident that involves a malicious attack on a network data closet.
Which of the following best explains how the analyst should properly document the incident?
A security analyst is responding to an incident that involves a malicious attack on a network data closet.
Which of the following best explains how the analyst should properly document the incident?
正確答案: B
說明:(僅 NewDumps 成員可見)
問題12
An analyst produces a weekly endpoint status report for the management team. The report includes specific details for each endpoint in relation to organizational baselines. Which of the following best describes the report type?
An analyst produces a weekly endpoint status report for the management team. The report includes specific details for each endpoint in relation to organizational baselines. Which of the following best describes the report type?
正確答案: A
說明:(僅 NewDumps 成員可見)