All questions without description (e.g. Question #1) are from the premium version of Exam Topics. I always choosed the community answer if possible for them. The rest is from the specific documents, written in the header of each question.
An analyst is becoming overwhelmed with the number of events that need to be investigated for a timeline. Which of the following should the analyst focus on in order to move the incident forward?
Answer
C. Mean time to detect
A. Impact
D. Isolation
B. Vulnerability score
Card 162
Question
Question #161
To minimize the impact of a security incident, a cybersecurity analyst has configured audit settings in the organization’s cloud services. Which of the following security controls has the analyst configured?
Answer
A. Preventive
B. Corrective
C. Directive
D. Detective
Card 163
Question
Question #162
A web developer reports the following error that appeared on a development server when testing a new application:
Which of the following tools can be used to identify the application’s point of failure?
Answer
C. Immunity debugger
D. Burp Suite
B. Angry IP scanner
A. OpenVAS
Card 164
Question
Question #163
Which of the following describes a contract that is used to define the various levels of maintenance to be provided by an external business vendor in a secure environment?
Answer
C. BIA
D. SLA
A. MOU
B. NDA
Card 165
Question
Question #164
A security team is concerned about recent Layer 4 DDoS attacks against the company website. Which of the following controls would best mitigate the attacks?
Answer
D. Implement a load balancer
A. Block the attacks using firewall rules
B. Deploy an IPS in the perimeter network
C. Roll out a CDN
Card 166
Question
Question #165
An analyst is reviewing system logs while threat hunting:
Which of the following hosts should be investigated first?
Answer
A. PC1
B. PC2
E. PC5
D. PC4
C. PC3
Card 167
Question
Question #166
An organization needs to bring in data collection and aggregation from various endpoints. Which of the following is the best tool to deploy to help analysts gather this data?
Answer
A. DLP
C. EDR
B. NAC
D. NIDS
Card 168
Question
Question #167
A regulated organization experienced a security breach that exposed a list of customer names with corresponding PII data. Which of the following is the best reason for developing the organization's communication plans?
Answer
B. To ensure incidents are immediately reported to a regulatory agency
A. For the organization's public relations department to have a standard notification
C. To automate the notification to customers who were impacted by the breach
D. To have approval from executive leadership on when communication should occur
Card 169
Question
Question #168
Following an incident, a security analyst needs to create a script for downloading the configuration of all assets from the cloud tenancy. Which of the following authentication methods should the analyst use?
Answer
A. MFA
C. PAM
D. Key pair
B. User and password
Card 170
Question
Question #169
A penetration tester is conducting a test on an organization's software development website. The penetration tester sends the following request to the web interface:
Which of the following exploits is most likely being attempted?
Answer
B. Local file inclusion
C. Cross-site scripting
A. SQL injection
D. Directory traversal
Card 171
Question
Question #170
Two employees in the finance department installed a freeware application that contained embedded malware. The network is robustly segmented based on areas of responsibility. These computers had critical sensitive information stored locally that needs to be recovered. The department manager advised all department employees to turn off their computers until the security team could be contacted about the issue. Which of the following is the first step the incident response staff members should take when they arrive?
Answer
A. Turn on all systems, scan for infection, and back up data to a USB storage device.
D. Log on to the impacted systems with an administrator account that has privileges to perform backups.
C. Explain that malware cannot truly be removed and then reimage the devices.
B. Identify and remove the software installed on the impacted systems in the department.
E. Segment the entire department from the network and review each computer offline.
Card 172
Question
Question #171
A manufacturer has hired a third-party consultant to assess the security of an OT network that includes both fragile and legacy equipment. Which of the following must be considered to ensure the consultant does no harm to operations?
Answer
A. Employing Nmap Scripting Engine scanning techniques
B. Preserving the state of PLC ladder logic prior to scanning
C. Using passive instead of active vulnerability scans
D. Running scans during off-peak manufacturing hours
Card 173
Question
Question #172
A team of analysts is developing a new internal system that correlates information from a variety of sources, analyzes that information, and then triggers notifications according to company policy. Which of the following technologies was deployed?
Answer
A. SIEM
B. SOAR
D. CERT
C. IPS
Card 174
Question
Question #173
Which of following would best mitigate the effects of a new ransomware attack that was not properly stopped by the company antivirus?
Answer
A. Install a firewall.
B. Implement vulnerability management.
C. Deploy sandboxing.
D. Update the application blocklist.
Card 175
Question
Question #174
A Chief Information Security Officer wants to implement security by design, starting with the implementation of a security scanning method to identify vulnerabilities, including SQL injection, RFI, XSS, etc. Which of the following would most likely meet the requirement?
Answer
C. Dynamic application security testing
B. Known environment testing
A. Reverse engineering
D. Code debugging
Card 176
Question
Question #175
A security analyst scans a host and generates the following output:
Which of the following best describes the output?
Answer
D. The host is vulnerable to web-based exploits.
B. The host is running a vulnerable mail server.
C. The host is allowing unsecured FTP connections.
A. The host is unresponsive to the ICMP request.
Card 177
Question
Question #176
The security team at a company, which was a recent target of ransomware, compiled a list of hosts that were identified as impacted and in scope for this incident. Based on the following host list:
Which of the following systems was most pivotal to the threat actor in its distribution of the encryption binary via Group Policy?
Answer
B. WK10-Sales07
A. SQL01
C. WK7-Plant01
D. DCEast01
E. HQAdmin9
Card 178
Question
Question #177
After a security assessment was done by a third-party consulting firm, the cybersecurity program recommended integrating DLP and CASE to reduce analyst alert fatigue. Which of the following is the best possible outcome that this effort hopes to achieve?
Answer
C. False positive rates drop to 20%.
B. Phishing alerts drop by 20%.
D. The MTTR decreases by 20%.
A. SIEM ingestion logs are reduced by 20%.
Card 179
Question
Question #178
Which of the following threat actors is most likely to target a company due to its questionable environmental policies?
Answer
B. Organized crime
D. Lone wolf
C. Nation-state
A. Hacktivist
Card 180
Question
Question #179
A cybersecurity analyst is recording the following details:
• ID
• Name
• Description
• Classification of information
• Responsible party
In which of the following documents is the analyst recording this information?
Answer
B. Change control documentation
D. Incident response plan
C. Incident response playbook
A. Risk register
How to use this set
Read the preview and check whether the content and answers suit your learning goal. You can add the public set to your sets to study it. Your account shows the available actions.