QuestionQ1
Forensics TechniquesWhat is the anti-forensics technique known as steganography?
QuestionQ2
Incident Response ProcessesAn employee receives an email from a "trusted" person that contains a hyperlink involving malvertising. The employee clicks the link, and malware is downloaded. An information analyst notices an alert in the SIEM and engages the cybersecurity team to analyze the incident according to the incident response plan. Which event detail should be included in this root cause analysis?
Community Discussion
QuestionQ3
Incident Response ProcessesAn incident response team recommends changes after reviewing a recent compromise in which:
- A large number of events and logs were involved.
- Team members could not identify anomalous behavior and escalate it promptly.
- Several network systems were affected because detection was delayed.
- Security engineers mitigated the threat and restored systems to a stable state.
- The issue recurred shortly afterward and systems became unstable again because the correct information was not collected during the initial identification phase.
Which two recommendations should be made to improve the incident response process?
Community Discussion
QuestionQ4
Fundamentals
Refer to the exhibit. Which encoding method does this HEX string represent?
Community Discussion
QuestionQ5
Incident Response ProcessesA security team identified an above-average number of inbound tcp/135 connection attempts from unidentified senders. The security team is responding according to its incident response playbook. Which two elements are included in the eradication phase for this incident?












Community Discussion