All questions without description (e.g. Question #1) are from the premium version of Exam Topics. I always choosed the community answer if possible for them. The rest is from the specific documents, written in the header of each question.
Which of the following best describes the goal of a tabletop exercise?
Answer
A. To test possible incident scenarios and how to react properly
B. To perform attack exercises to check response effectiveness
D. To check the effectiveness of the business continuity plan
C. To understand existing threat actors and how to replicate their techniques
Card 82
Question
Question #81
A virtual web server in a server pool was infected with malware after an analyst used the internet to research a system issue. After the server was rebuilt and added back into the server pool, users reported issues with the website, indicating the site could not be trusted. Which of the following is the most likely cause of the server issue?
Answer
B. The server was supporting weak TLS protocols for client connections.
A. The server was configured to use SSL to securely transmit data.
C. The malware infected all the web servers in the pool.
D. The digital certificate on the web server was self-signed.
Card 83
Question
A zero-day command injection vulnerability was published. A security administrator is analyzing the following logs for evidence of adversaries attempting to exploit the vulnerability:
Which of the following log entries provides evidence of the attempted exploit?
Answer
A. Log entry 1
D. Log entry 4
C. Log entry 3
B. Log entry 2
Card 84
Question
Question #83
A security analyst needs to ensure that systems across the organization are protected based on the sensitivity of the content each system hosts. The analyst is working with the respective system owners to help determine the best methodology that seeks to promote confidentiality, availability, and integrity of the data being hosted. Which of the following should the security analyst perform first to categorize and prioritize the respective systems?
Answer
A. Interview the users who access these systems.
B. Scan the systems to see which vulnerabilities currently exist.
C. Configure alerts for vendor-specific zero-day exploits.
D. Determine the asset value of each system.
Card 85
Question
Question #84
A security analyst is reviewing the following alert that was triggered by FIM on a critical system:
Which of the following best describes the suspicious activity that is occurring?
Answer
B. A network drive was added to allow exfiltration of data.
C. A new program has been set to execute on system start.
D. The host firewall on 192.168.1.10 was disabled.
A. A fake antivirus program was installed by the user.
Card 86
Question
Question #85
Which of the following best describes the document that defines the expectation to network customers that patching will only occur between 2:00 a.m. and 4:00 a.m.?
Answer
A. SLA
B. LOI
C. MOU
D. KPI
Card 87
Question
Question #86
A cybersecurity analyst is reviewing SIEM logs and observes consistent requests originating from an internal host to a blocklisted external server. Which of the following best describes the activity that is taking place?
Answer
A. Data exfiltration
C. Scanning
B. Rogue device
D. Beaconing
Card 88
Question
Question #87
An incident response team is working with law enforcement to investigate an active web server compromise. The decision has been made to keep the server running and to implement compensating controls for a period of time. The web service must be accessible from the internet via the reverse proxy and must connect to a database server. Which of the following compensating controls will help contain the adversary while meeting the other requirements? (Choose two).
Answer
D. Use microsegmentation to restrict connectivity to/from the web and database servers.
F. Move the database from the database server to the web server.
C. Stop the httpd service on the web server so that the adversary can not use web exploits.
E. Comment out the HTTP account in the /etc/passwd file of the web server.
A. Drop the tables on the database server to prevent data exfiltration.
B. Deploy EDR on the web server and the database server to reduce the adversary’s capabilities.
Card 89
Question
Question #88
An incident response team member is triaging a Linux server. The output is shown below:
Which of the following is the adversary most likely trying to do?
Answer
A. Create a backdoor root account named zsh.
C. Send a beacon to a command-and-control server.
D. Perform a denial-of-service attack on the web server.
B. Execute commands through an unsecured service account.
Card 90
Question
Question #89
A SOC analyst identifies the following content while examining the output of a debugger command over a client-server application:
Which of the following is the most likely vulnerability in this system?
Answer
A. Lack of input validation
C. Hard-coded credential
B. SQL injection
D. Buffer overflow
Card 91
Question
Question #90
A technician is analyzing output from a popular network mapping tool for a PCI audit:
Which of the following best describes the output?
Answer
D. The Secure Shell port on this host is closed.
A. The host is not up or responding.
B. The host is running excessive cipher suites.
C. The host is allowing insecure cipher suites.
Card 92
Question
Question #91
A managed security service provider is having difficulty retaining talent due to an increasing workload caused by a client doubling the number of devices connected to the network. Which of the following would best aid in decreasing the workload without increasing staff?
Answer
A. SIEM
B. XDR
D. EDR
C. SOAR
Card 93
Question
Question #92
An employee is suspected of misusing a company-issued laptop. The employee has been suspended pending an investigation by human resources. Which of the following is the best step to preserve evidence?
Answer
D. Make a forensic image of the device and create a SHA-1 hash.
A. Disable the user’s network account and access to web resources.
C. Place a legal hold on the device and the user’s network share.
B. Make a copy of the files as a backup on the server.
Card 94
Question
Question #93
An analyst receives threat intelligence regarding potential attacks from an actor with seemingly unlimited time and resources. Which of the following best describes the threat actor attributed to the malicious activity?
Answer
B. Ransomware group
C. Nation-state
A. Insider threat
D. Organized crime
Card 95
Question
Question #94
A systems analyst is limiting user access to system configuration keys and values in a Windows environment. Which of the following describes where the analyst can find these configuration items?
Answer
A. config.ini
D. Registry
B. ntds.dit
C. Master boot record
Card 96
Question
Question #95
While reviewing web server logs, a security analyst found the following line:
< IMG SRC='vbscript:msgbox("test")' >
Which of the following malicious activities was attempted?
Answer
A. Command injection
C. Server-side request forgery
D. Cross-site scripting
B. XML injection
Card 97
Question
Question #96
A security analyst at a company called ACME Commercial notices there is outbound traffic to a host IP that resolves to https://office365password.acme.co. The site’s standard VPN logon page is www.acme.com/logon. Which of the following is most likely true?
Answer
C. A new VPN gateway has been deployed.
D. A social engineering attack is underway.
A. This is a normal password change URL.
B. The security operations center is performing a routine password audit.
Card 98
Question
Question #97
A security analyst is performing vulnerability scans on the network. The analyst installs a scanner appliance, configures the subnets to scan, and begins the scan of the network. Which of the following would be missing from a scan performed with this configuration?
Answer
B. Registry key values
A. Operating system version
D. IP address
C. Open ports
Card 99
Question
Question #98
A security analyst discovers an LFI vulnerability that can be exploited to extract credentials from the underlying host. Which of the following patterns can the security analyst use to search the web server logs for evidence of exploitation of that particular vulnerability?
Answer
D. cat /proc/self/
C. ; printenv
A. /etc/shadow
B. curl localhost
Card 100
Question
Question #99
A company is in the process of implementing a vulnerability management program. Which of the following scanning methods should be implemented to minimize the risk of OT/ICS devices malfunctioning due to the vulnerability identification process?
Answer
D. Credentialed scanning
C. Agent-based scanning
A. Non-credentialed scanning
B. Passive scanning
How to use this set
Read the preview and check whether the content and answers suit your learning goal. You can add the public set to your sets to study it. Your account shows the available actions.