An employee receives an email from a "trusted" person that contains a hyperlink involving malvertising. The employee clicks the link, and malware is downloaded. An information analyst notices an alert in the SIEM and engages the cybersecurity team to analyze the incident according to the incident response plan. Which event detail should be included in this root cause analysis?
Aphishing email sent to the victim
Balarm raised by the SIEM
Cinformation from the email header
Dalert identified by the cybersecurity team
0
Community Discussion
No comments yet. Be the first to start the discussion!
An incident response team recommends changes after reviewing a recent compromise in which:
A large number of events and logs were involved.
Team members could not identify anomalous behavior and escalate it promptly.
Several network systems were affected because detection was delayed.
Security engineers mitigated the threat and restored systems to a stable state.
The issue recurred shortly afterward and systems became unstable again because the correct information was not collected during the initial identification phase.
Which two recommendations should be made to improve the incident response process?
Choose two
AFormalize reporting requirements and responsibilities to update management and internal stakeholders throughout the incident-handling process effectively.
BImprove the mitigation phase to ensure causes can be quickly identified, and systems returned to a functioning state.
CImplement an automated operation to pull systems events/logs and bring them into an organizational context.
DAllocate additional resources for the containment phase to stabilize systems in a timely manner and reduce an attack's breadth.
EModify the incident handling playbook and checklist to ensure alignment and agreement on roles, responsibilities, and steps before an incident occurs.
0
Community Discussion
No comments yet. Be the first to start the discussion!
A security team identified an above-average number of inbound tcp/135 connection attempts from unidentified senders. The security team is responding according to its incident response playbook. Which two elements are included in the eradication phase for this incident?
Choose two
Aanti-malware software
Bdata and workload isolation
Ccentralized user management
Dintrusion prevention system
Eenterprise block listing solution
0
Community Discussion
No comments yet. Be the first to start the discussion!
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Refer to the exhibit. Which two conclusions should be made about the attack from the Apache access logs?
Choose two
AThe attacker used r57 exploit to elevate their privilege.
BThe attacker uploaded the word press file manager trojan.
CThe attacker performed a brute force attack against word press and used sql injection against the backend database.
DThe attacker used the word press file manager plugin to upoad r57.php.
EThe attacker logged on normally to word press admin page.
Refer to the exhibit. An HR department submitted a ticket to the IT helpdesk reporting slow performance on an internal share server. The helpdesk engineer checked the server using a real-time monitoring tool and did not observe anything suspicious. After reviewing the event logs, the engineer found an event that occurred 48 hours earlier. Which two indicators of compromise should be identified from this information?
Choose two
Aunauthorized system modification
Bprivilege escalation
Cdenial of service attack
Dcompromised root access
Emalware outbreak
Refer to the exhibit. Which IOC threat and URL appear in this STIX JSON snippet?
What is one concern when collecting forensic evidence in public cloud environments?
AHigh Cost: Cloud service providers typically charge high fees for allowing cloud forensics.
BConfiguration: Implementing security zones and proper network segmentation.
CTimeliness: Gathering forensics evidence from cloud service providers typically requires substantial time.
DMultitenancy: Evidence gathering must avoid exposure of data from other tenants.
Refer to the exhibit. A network engineer is reviewing a Wireshark capture to identify the HTTP request that triggered download of the initial Ursnif banking Trojan binary. Which filter did the engineer use to sort the Wireshark traffic logs?
Ahttp.request.un matches
Btls.handshake.type ==1
Ctcp.port eq 25
Dtcp.window_size ==0
Which magic byte identifies an analyzed file as a PDF file?
AcGRmZmlsZQ
B706466666
C255044462d
D0a0ah4cg
An engineer receives a call to help with an active DDoS attack. The Apache server is the target, and its availability is affected. Which action should be performed to determine the threat’s origin?
AAn engineer should check the list of usernames currently logged in by running the command $ who | cut ""d' "˜ -f1| sort | uniq
BAn engineer should check the server's processes by running commands ps -aux and sudo ps -a.
CAn engineer should check the services on the machine by running the command service -status-all.
DAn engineer should check the last hundred entries of a web server with the command sudo tail -100 /var/log/apache2/access.log.
An engineer is reviewing a ticket for an unexpected server shutdown and determines that the web server exhausted usable memory and crashed.
Which data is required for further investigation?
A/var/log/access.log
B/var/log/messages.log
C/var/log/httpd/messages.log
D/var/log/httpd/access.log
Refer to the exhibit. A company using only the Unix platform has implemented an intrusion detection system. After the initial configuration, the alert volume is overwhelming, and an engineer must analyze and classify the alerts. The largest number of alerts was generated by the signature shown in the exhibit.
Which classification should the engineer assign to this event?
ATrue Negative alert
BFalse Negative alert
CFalse Positive alert
DTrue Positive alert
Refer to the exhibit. Based on the SNORT alert, what is the attacker doing?
Abrute-force attack against the web application user accounts
BXSS attack against the target webserver
Cbrute-force attack against directories and files on the target webserver
DSQL injection attack against the target webserver
Refer to the exhibit. What can be determined from this Apache log?
AA module named mod_ssl is needed to make SSL connections.
BThe private key does not match with the SSL certificate.
CThe certificate file has been maliciously modified
DThe SSL traffic setup is improper
Refer to the exhibit. An engineer is analyzing a TCP stream in Wireshark following a suspicious email containing a URL. What should be determined about the SMB traffic from this stream?
AIt is redirecting to a malicious phishing website,
BIt is exploiting redirect vulnerability
CIt is requesting authentication on the user site.
DIt is sharing access to files and printers.
Refer to the exhibit. An employee observes unexpected changes and configuration modifications on their workstation and opens an incident ticket. A support specialist reviews processes and services but finds nothing suspicious. The ticket is escalated to an analyst, who reviews this event log and also finds that the workstation has multiple large data dumps on network shares. What should be determined from this information?
Adata obfuscation
Breconnaissance attack
Cbrute-force attack
Dlog tampering
Which script searches a log file for the IP address 192.168.100.100, creates an output file named parsed_host.log, and prints the results to the console?
A
B
C
D
An engineer is reviewing a ticket from the accounting department after a user found an unexpected application on their workstation. The intrusion detection system shows several alerts for unknown outbound internet traffic from that workstation. The engineer also observes degraded processing capability, which makes the analysis process more difficult. Which two actions should the engineer take?
Choose two
ARestore to a system recovery point.
BReplace the faulty CPU.
CDisconnect from the network.
DFormat the workstation drives.
ETake an image of the workstation.
Refer to the exhibit. Which two actions should be performed based on this information?
Choose two
AUpdate the AV to block any file with hash "cf2b3ad32a8a4cfb05e9dfc45875bd70".
BBlock all emails sent from an @state.gov address.
CBlock all emails with pdf attachments.
DBlock emails sent from [email protected] with an attached pdf file with md5 hash "cf2b3ad32a8a4cfb05e9dfc45875bd70".
EBlock all emails with subject containing "cf2b3ad32a8a4cfb05e9dfc45875bd70".
A security team is reviewing lessons learned and proposing process changes after a security-breach incident. During the incident, security-team members did not report abnormal system activity because of a heavy project workload. In addition, once the incident was identified, the response required six hours because management was unavailable to provide the necessary approvals. Which two actions will prevent these problems from occurring in the future?
Choose two
AIntroduce a priority rating for incident response workloads.
BProvide phishing awareness training for the fill security team.
CConduct a risk audit of the incident response workflow.
DCreate an executive team delegation plan.
EAutomate security alert timeframes with escalation triggers.
Refer to the exhibit. An engineer is reviewing a .LNK (shortcut) file recently received as an email attachment and blocked by email security as suspicious. What should the engineer do next?
ADelete the suspicious email with the attachment as the file is a shortcut extension and does not represent any threat.
BUpload the file to a virus checking engine to compare with well-known viruses as the file is a virus disguised as a legitimate extension.
CQuarantine the file within the endpoint antivirus solution as the file is a ransomware which will encrypt the documents of a victim.
DOpen the file in a sandbox environment for further behavioral analysis as the file contains a malicious script that runs on execution.
Refer to the exhibit. What should an engineer conclude from this Wireshark capture of suspicious network traffic?
AThere are signs of SYN flood attack, and the engineer should increase the backlog and recycle the oldest half-open TCP connections.
BThere are signs of a malformed packet attack, and the engineer should limit the packet size and set a threshold of bytes as a countermeasure.
CThere are signs of a DNS attack, and the engineer should hide the BIND version and restrict zone transfers as a countermeasure.
DThere are signs of ARP spoofing, and the engineer should use Static ARP entries and IP address-to-MAC address mappings as a countermeasure.
Community Discussion