0022
A security analyst is reviewing the following output from an IPS:
Given this output, which of the following can be concluded? (Select two.)
Answer
The source IP of the attack is coming from 250.19.18.22.
The source IP of the attack is coming from 250.19.18.71.
The attacker sent a malformed IGAP packet, triggering the alert.
The attacker sent a malformed TCP packet, triggering the alert.
The TTL value is outside of the expected range, triggering the alert.
Card 2
Question
0053
A security administrator has found a hash in the environment known to belong to malware. The administrator
then finds this file to be in in the pre-update area of the OS, which indicates it was pushed from the central patch
system.
The administrator pulls a report from the patch management system with the following output:
Given the above outputs, which of the following MOST likely happened?
Answer
The file was corrupted after it left the patch system.
The file was infected when the patch manager downloaded it.
The file was not approved in the application whitelist system.
The file was embedded with a logic bomb to evade detection.
Card 3
Question
0152
After a routine audit, a company discovers that engineering documents have been leaving the network on a
particular port. The company must allow outbound traffic on this port, as it has a legitimate business use. Blocking
the port would cause an outage. Which of the following technology controls should the company implement?
Answer
NAC
DLP
Web proxy
ACL
Card 4
Question
0174
The security administrator receives an email on a non-company account from a coworker stating that some
reports are not exporting correctly. Attached to the email was an example report file with several customer’s
names and credit card numbers with the PIN.
Which of the following is the BEST technical controls that will help mitigate this risk of disclosing sensitive data?
Answer
Configure the mail server to require TLS connections for every email to ensure all transport data is encrypted
Create a user training program to identify the correct use of email and perform regular audits to ensure compliance
Implement a DLP solution on the email gateway to scan email and remove sensitive data or files
Classify all data according to its sensitivity and inform the users of data that is prohibited to share
Card 5
Question
0192
While reviewing the monthly internet usage it is noted that there is a large spike in traffic classified as "unknown"
and does not appear to be within the bounds of the organizations Acceptable Use Policy.
Which of the following tool or technology would work BEST for obtaining more information on this traffic?
Answer
IDS logs
Firewall logs
Protocol analyzer
Increased spam filtering
Card 6
Question
0242
A computer on a company network was infected with a zero-day exploit after an employee accidently opened an
email that contained malicious content. The employee recognized the email as malicious and was attempting to
delete it, but accidently opened it.
Which of the following should be done to prevent this scenario from occurring again in the future?
Answer
Install host-based firewalls on all computers that have an email client installed
Set the email program default to open messages in plain text
Install end-point protection on all computers that access web email
Create new email spam filters to delete all messages from that sender
Card 7
Question
0271
A security administrator needs to implement a system that detects possible intrusions based upon a vendor
provided list.
Which of the following BEST describes this type of IDS?
Answer
Signature based
Behavior-based
Anomaly-based
Heuristic
Card 8
Question
0297
Joe, a website administrator, believes he owns the intellectual property for a company invention and has been
replacing image files on the company's public facing website in the DMZ. Joe is using steganography to hide stolen
data.
Which of the following controls can be implemented to mitigate this type of inside threat?
Answer
Digital signatures
File integrity monitoring
Access controls
Change management
Stateful inspection firewall
Card 9
Question
0326
A security administrator suspects that data on a server has been exfiltrated as a result of unauthorized remote
access.
Which of the following would assist the administrator in confirming the suspicions? (Select TWO)
Answer
Network access control
DLP alerts
File integrity monitoring
Log analysis
Host firewall rules
Card 10
Question
0344
An administrator thinks the UNIX systems may be compromised, but a review of system log files provides no useful
information. After discussing the situation with the security team, the administrator suspects that the attacker
may be altering the log files and removing evidence of intrusion activity.
Which of the following actions will help detect attacker attempts to further alter log files?
Answer
Change the permissions on the user‘s home directory
Enable verbose system logging
Implement remote syslog
Set the bash_history log file to "read only"
Card 11
Question
0405
The Chief Information Security Officer (CISO) is asking for ways to protect against zero-day exploits. The CISO is
concerned that an unrecognized threat could compromise corporate data and result in regulatory fines as well as
poor corporate publicity. The network is mostly flat, with split staff/guest wireless functionality. Which of the
following equipment MUST be deployed to guard against unknown threats?
Answer
Implementation of an off-site datacenter hosting all company data, as well as deployment of VDI for all client computing needs
Cloud-based antivirus solution, running as local admin, with push technology for definition updates
Host-based heuristic IPS, segregated on a management VLAN, with direct control of the perimeter firewall ACLs
Behavior-based IPS with a communication link to a cloud-based vulnerability and threat feed
Card 12
Question
0406
An organization has several production-critical SCADA1 supervisory systems that cannot follow the normal 30-day
patching policy. Which of the following BEST maximizes the protection of these systems from malicious software?
Answer
Configure a firewall with deep packet inspection that restricts traffic to the systems.
Configure a separate zone for the systems and restrict access to known ports.
Configure the systems to ensure only necessary applications are able to run.
Configure the host firewall to ensure only the necessary applications have listening ports
Card 13
Question
0419
A security administrator learns that PII, which was gathered by the organization, has been found in an open forum.
As a result, several C-IeveI executives found their identities were compromised, and they were victims of a recent
whaling attack. Which of the following would prevent these problems in the future? (Select TWO).
Answer
Implement a reverse proxy.
Implement an email DLP.
Implement a spam filter.
Implement a HIDS.
Card 14
Question
0434
A technician receives a device with the following anomalies:
- Frequent pop-up ads
- Slow response time switching between active programs
- Unresponsive peripherals
The technician reviews the following log file entries:
Based on the above output, which of the following should be reviewed?
Answer
The file integrity check
The web application firewall
The data execution prevention
The removable media control
Card 15
Question
0487
A security administrator installed a new network scanner that identifies new host systems on the network. Which
of the following did the security administrator install?
Answer
Vulnerability scanner
Network-based IDS
Rogue system detection
Configuration compliance scanner
Card 16
Question
0502
A security administrator is trying to eradicate a worm, which is spreading throughout the organization, using an
old remote vulnerability in the SMB protocol. The worm uses Nmap to identify target hosts within the company.
The administrator wants to implement a solution that will eradicate the current worm and any future attacks that
may be using zero-day vulnerabilities. Which of the following would BEST meet the requirements when
implemented?
Answer
Host-based firewall
Network-based intrusion prevention system
Enterprise patch management system
Application blacklisting
File integrity checking
Card 17
Question
0544
A security analyst receives a notification from the IDS after working hours, indicating a spike in network traffic.
Which of the following BEST describes this type of IDS?
Answer
Stateful
Anomaly-based
Host-based
Signature-based
Card 18
Question
0547
A company recently experienced data exfiltration via the corporate network. In response to the breach, a security
analyst recommends deploying an out-of-band IDS solution. The analyst says the solution can be implemented
without purchasing any additional network hardware. Which of the following solutions will be used to deploy the
IDS?
Answer
Network tap
Network proxy
Port mirroring
Honeypot
Card 19
Question
0548
An organization wants to implement a solution that allows for automated logical controls for network defense. An
engineer plans to select an appropriate network security component, which automates response actions based on
security threats to the network. Which of the following would be MOST appropriate based on the engineer’s
requirements?
Answer
NIPS
HIDS
Elastic load balancer
Web proxy
NAC
Card 20
Question
0554
A small-to-medium sized company wants to block the use of USB devices on its network. Which of the following is
the MOST cost-effective way for the security analyst to prevent this?
Answer
Implement a DLP system
Apply a GPO
Conduct user awareness training
Enforce the AUP
How to use this set
Read the preview and check whether the content and answers suit your learning goal. You can add the public set to your sets to study it. Your account shows the available actions.