All questions without description (e.g. Question #1) are from the premium version of Exam Topics. I always choosed the community answer if possible for them. The rest is from the specific documents, written in the header of each question.
An organization enabled a SIEM rule to send an alert to a security analyst distribution list when ten failed logins occur within one minute. However, the control was unable to detect an attack with nine failed logins. Which of the following best represents what occurred?
Answer
C. False negative
D. True positive
B. True negative
A. False positive
Card 142
Question
Question #141
A cybersecurity analyst is tasked with scanning a web application to understand where the scan will go and whether there are URIs that should be denied access prior to more in-depth scanning. Which of following best fits the type of scanning activity requested?
Answer
A. Uncredentialed scan
B. Discovery scan
C. Vulnerability scan
D. Credentialed scan
Card 143
Question
Question #142
Which of the following best describes the process of requiring remediation of a known threat within a given time frame?
Answer
A. SLA
D. Organizational governance
C. Best-effort patching
B. MOU
Card 144
Question
Question #143
Which of the following risk management principles is accomplished by purchasing cyber insurance?
Answer
C. Mitigate
B. Avoid
D. Transfer
A. Accept
Card 145
Question
Question #144
A recent audit of the vulnerability management program outlined the finding for increased awareness of secure coding practices. Which of the following would be best to address the finding?
Answer
A. Establish quarterly SDLC training on the top vulnerabilities for developers
B. Conduct a yearly inspection of the code repositories and provide the report to management.
D. Deploy more vulnerability scanners for increased coverage
C. Hire an external penetration test of the network
Card 146
Question
Question #145
An organization has deployed a cloud-based storage system for shared data that is in phase two of the data life cycle. Which of the following controls should the security team ensure are addressed? (Choose two.)
Answer
D. Encryption
C. Data loss prevention
B. Data destruction
A. Data classification
F. Access controls
E. Backups
Card 147
Question
Question #146
An analyst is conducting routine vulnerability assessments on the company infrastructure. When performing these scans, a business-critical server crashes, and the cause is traced back to the vulnerability scanner. Which of the following is the cause of this issue?
Answer
B. The scanner is running in active mode.
C. The scanner is segmented improperly
A. The scanner is running without an agent installed.
D. The scanner is configured with a scanning window
Card 148
Question
Question #147
An organization's threat intelligence team notes a recent trend in adversary privilege escalation procedures. Multiple threat groups have been observed utilizing native Windows tools to bypass system controls and execute commands with privileged credentials. Which of the following controls would be most effective to reduce the rate of success of such attempts?
Answer
B. Implement MFA requirements for all internal resources
A. Set user account control protection to the most restrictive level on all devices
C. Harden systems by disabling or removing unnecessary services
D. Implement controls to block execution of untrusted applications
Card 149
Question
Question #148
A new zero-day vulnerability was released. A security analyst is prioritizing which systems should receive deployment of compensating controls deployment first. The systems have been grouped into the categories shown below:
Which of the following groups should be prioritized for compensating controls?
Answer
A. Group A
D. Group D
B. Group B
C. Group C
Card 150
Question
Question #149
A Chief Information Security Officer wants to map all the attack vectors that the company faces each day. Which of the following recommendations should the company align their security controls around?
Answer
A. OSSTMM
B. Diamond Model of Intrusion Analysis
D. MITRE ATT&CK
C. OWASP
Card 151
Question
Question #150
Which of the following actions would an analyst most likely perform after an incident has been investigated?
Answer
A. Risk assessment
B. Root cause analysis
D. Tabletop exercise
C. Incident response plan
Card 152
Question
Question #151
After completing a review of network activity, the threat hunting team discovers a device on the network that sends an outbound email via a mail client to a non-company email address daily at 10:00 p.m. Which of the following is potentially occurring?
Answer
A. Irregular peer-to-peer communication
B. Rogue device on the network
C. Abnormal OS process behavior
D. Data exfiltration
Card 153
Question
Question #152
A vulnerability scanner generates the following output:
The company has an SLA for patching that requires time frames to be met for high-risk vulnerabilities. Which of the following should the analyst prioritize first for remediation?
Answer
B. Cisco Webex
C. Redis Server
A. Oracle JDK
D. SSL Self-signed Certificate
Card 154
Question
Question #153
A web application team notifies a SOC analyst that there are thousands of HTTP/404 events on the public-facing web server. Which of the following is the next step for the analyst to take?
Answer
B. Escalate the event to an incident and notify the SOC manager of the activity
C. Notify the incident response team that there is a DDoS attack occurring
A. Instruct the firewall engineer that a rule needs to be added to block this external server
D. Identify the IP/hostname for the requests and look at the related activity
Card 155
Question
Question #154
Which of the following best describes the reporting metric that should be utilized when measuring the degree to which a system application, or user base is affected by an uptime availability outage?
Answer
C. Impact
D. Scope
A. Timeline
B. Evidence
Card 156
Question
Question #155
A security analyst needs to provide evidence of regular vulnerability scanning on the company's network for an auditing process. Which of the following is an example of a tool that can produce such evidence?
Answer
B. Burp Suite
A. OpenVAS
C. Nmap
D. Wireshark
Card 157
Question
Question #156
A security analyst performs a vulnerability scan. Based on the metrics from the scan results, the analyst must prioritize which hosts to patch. The analyst runs the tool and receives the following output:
Which of the following hosts should be patched first, based on the metrics?
Answer
B. host02
C. host03
A. host01
D. host04
Card 158
Question
Question #157
An organization receives a legal hold request from an attorney. The request pertains to emails related to a disputed vendor contract. Which of the following is the best step for the security team to take to ensure compliance with the request?
Answer
A. Publicly disclose the request to other vendors
C. Establish a chain of custody starting with the attorney's request
B. Notify the departments involved to preserve potentially relevant information
D. Back up the mailboxes on the server and provide the attorney with a copy
Card 159
Question
Question #158
A company has the following security requirements:
• No public IPs
• All data secured at rest
• No insecure ports/protocols
After a cloud scan is completed a security analyst receives reports that several misconfigurations are putting the company at risk. Given the following cloud scanner output:
Which of the following should the analyst recommend be updated first to meet the security requirements and reduce risks?
Answer
B. VM_DEV_DB
A. VM_PRD_DB
D. VM_PRD_Web01
C. VM_DEV_Web02
Card 160
Question
Question #159
Which of the following best describes the actions taken by an organization after the resolution of an incident that addresses issues and reflects on the growth opportunities for future incidents?
Answer
C. Root cause analysis
A. Lessons learned
D. Regulatory compliance
B. Scrum review
How to use this set
Read the preview and check whether the content and answers suit your learning goal. You can add the public set to your sets to study it. Your account shows the available actions.