All questions without description (e.g. Question #1) are from the premium version of Exam Topics. I always choosed the community answer if possible for them. The rest is from the specific documents, written in the header of each question.
The Chief Information Security Officer for an organization recently received approval to install a new EDR solution. Following the installation, the number of alerts that require remediation by an analyst has tripled. Which of the following should the organization utilize to best centralize the workload for the internal security team? (Choose two.)
Answer
B. SIEM
A. SOAR
E. XDR
D. NGFW
F. DLP
C. MSP
Card 202
Question
Question #201
Which of the following best describes the threat concept in which an organization works to ensure that all network users only open attachments from known sources?
Answer
D. Nation-state threat
A. Hacktivist threat
C. Unintentional insider threat
B. Advanced persistent threat
Card 203
Question
Question #202
A security analyst has received an incident case regarding malware spreading out of control on a customer's network. The analyst is unsure how to respond. The configured EDR has automatically obtained a sample of the malware and its signature. Which of the following should the analyst perform next to determine the type of malware based on its telemetry?
Answer
A. Cross-reference the signature with open-source threat intelligence.
B. Configure the EDR to perform a full scan.
D. Log in to the affected systems and run netstat.
C. Transfer the malware to a sandbox environment.
Card 204
Question
Question #203
A network analyst notices a long spike in traffic on port 1433 between two IP addresses on opposite sides of a WAN connection. Which of the following is the most likely cause?
Answer
A. A local red team member is enumerating the local RFC1918 segment to enumerate hosts
B. A threat actor has a foothold on the network and is sending out control beacons
D. An insider threat actor is running Responder on the local segment, creating traffic replication
C. An administrator executed a new database replication process without notifying the SOC
Card 205
Question
Question #204
Which of the following is a useful tool for mapping, tracking, and mitigating identified threats and vulnerabilities with the likelihood and impact of occurrence?
Answer
A. Risk register
D. Compliance report
C. Penetration test
B. Vulnerability assessment
Card 206
Question
Question #205
Which of the following is often used to keep the number of alerts to a manageable level when establishing a process to track and analyze violations?
Answer
A. Log retention
B. Log rotation
C. Maximum log size
D. Threshold value
Card 207
Question
Question #206
While reviewing web server logs, a security analyst discovers the following suspicious line:
Which of the following should be updated after a lessons-learned review?
Answer
D. Incident response plan
A. Disaster recovery plan
B. Business continuity plan
C. Tabletop exercise
Card 209
Question
Question #208
A software developer has been deploying web applications with common security risks to include insufficient logging capabilities. Which of the following actions would be most effective to reduce risks associated with the application development?
Answer
B. Deploy compensating controls into the environment
C. Implement server-side logging and automatic updates
D. Conduct regular code reviews using OWASP best practices
A. Perform static analyses using an integrated development environment
Card 210
Question
Question #209
An analyst suspects cleartext passwords are being sent over the network. Which of the following tools would best support the analyst's investigation?
Answer
A. OpenVAS
D. Maltego
C. Wireshark
B. Angry IP Scanner
Card 211
Question
Question #210
Using open-source intelligence gathered from technical forums, a threat actor compiles and tests a malicious downloader to ensure it will not be detected by the victim organization's endpoint security protections. Which of the following stages of the Cyber Kill Chain best aligns with the threat actor's actions?
Answer
B. Reconnaissance
A. Delivery
C. Exploitation
D. Weaponization
Card 212
Question
Question #211
An organization would like to ensure its cloud infrastructure has a hardened configuration. A requirement is to create a server image that can be deployed with a secure template. Which of the following is the best resource to ensure secure configuration?
Answer
D. ISO 27001
C. OWASP Top Ten
A. CIS Benchmarks
B. PCI DSS
Card 213
Question
Question #212
A security analyst reviews the following Arachni scan results for a web application that stores PII data:
Which of the following should be remediated first?
Answer
C. XSS
A. SQL injection
B. RFI
D. Code injection
Card 214
Question
Question #213
Which of the following stakeholders are most likely to receive a vulnerability scan report? (Choose two.)
Answer
D. Legal
C. Marketing
E. Product owner
B. Law enforcement
A. Executive management
F. Systems administration
Card 215
Question
Question #214
Which of the following techniques can help a SOC team to reduce the number of alerts related to the internal security activities that the analysts have to triage?
Answer
A. Enrich the SIEM-ingested data to include all data required for triage
C. Filter all alarms in the SIEM with low seventy
B. Schedule a task to disable alerting when vulnerability scans are executing
D. Add a SOAR rule to drop irrelevant and duplicated notifications
Card 216
Question
Question #215
An analyst is evaluating a vulnerability management dashboard. The analyst sees that a previously remediated vulnerability has reappeared on a database server. Which of the following is the most likely cause?
Answer
C. The vulnerability scanner was configured without credentials.
D. The vulnerability management software needs to be updated.
A. The finding is a false positive and should be ignored.
B. A rollback had been executed on the instance.
Card 217
Question
Question #216
A company has decided to expose several systems to the internet. The systems are currently available internally only. A security analyst is using a subset of CVSS3.1 exploitability metrics to prioritize the vulnerabilities that would be the most exploitable when the systems are exposed to the internet. The systems and the vulnerabilities are shown below:
Which of the following systems should be prioritized for patching?
Answer
D. sullivan
C. blane
B. grey
A. brown
Card 218
Question
Question #217
During an incident in which a user machine was compromised, an analyst recovered a binary file that potentially caused the exploitation. Which of the following techniques could be used for further analysis?
Answer
C. Sandboxing
A. Fuzzing
B. Static analysis
D. Packet capture
Card 219
Question
Question #218
A leader on the vulnerability management team is trying to reduce the team's workload by automating some simple but time-consuming tasks. Which of the following activities should the team leader consider first?
Answer
A. Assigning a custom recommendation for each finding
D. Regularly checking agent communication with the central console
B. Analyzing false positives
C. Rendering an additional executive report
Card 220
Question
Question #219
The Chief Information Security Officer (CISO) of a large management firm has selected a cybersecurity framework that will help the organization demonstrate its investment in tools and systems to protect its data. Which of the following did the CISO most likely select?
Answer
C. ISO 27001
B. COBIT
D. ITIL
A. PCI DSS
How to use this set
Read the preview and check whether the content and answers suit your learning goal. You can add the public set to your sets to study it. Your account shows the available actions.