An analyst receives an alert that a user clicked on a malicious link. The analyst verifies that the link is malicious and was intended to capture credentials. The analyst verifies that the user visited the website, but no evidence indicates that the credentials were used. The analyst recommends that the user take remedial training and closes the case.
Which of the following steps in the incident response process did the analyst neglect?
AAnalysis
BContainment
CRecovery
DPost-incident
0
Community Discussion
No comments yet. Be the first to start the discussion!
A server was recently compromised. A security analyst needs to collect artifacts for further analysis before disconnecting the server from the network. Which of the following artifacts should the analyst collect first?
AShellBags
BHard disk
CAddress Resolution Protocol table
DNetstat output
0
Community Discussion
No comments yet. Be the first to start the discussion!
An incident response team is investigating a possible data leak, and various IT systems are used to collect evidence. Which of the following processes is required to ensure that evidentiary artifacts are properly recorded?
APackaging and labeling
BChain of custody
CPost incident reporting
DStorage and containment
0
Community Discussion
No comments yet. Be the first to start the discussion!
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Which of the following best describes the main benefits of the MITRE ATT&CK Navigator?
AReplicating adversary behavior and blocking gaps in defenses
BMonitoring adversary behavior and performing malware reverse engineering
CResponding to adversary behavior and building security defense tools
DUnderstanding adversary behavior and identifying gaps in defenses
A security analyst is responding to an alert involving identity and access management (IAM) activity in a cloud environment. The attacker is currently attempting to gain access from one isolated cloud subscription to another isolated cloud subscription by using a compromised user role.
Which of the following aspects of the MITRE ATT&CK framework is the attacker attempting to perform?
APrivilege escalation
BLateral movement
CPersistence
DExecution
ECredential access
A security operations center analyst receives an alert from the security information and event management (SIEM) system. The analyst quickly reviews the alert and sees a workstation infected with malware. The analyst then uses the endpoint detection and response (EDR) tool to isolate the workstation from the network.
Which of the following best describes the steps that occurred in this scenario?
AAnalysis, containment, and eradication
BAnalysis, eradication, and recovery
CDetection, analysis, and containment
DIsolation, mitigation, and analysis
A security operations center (SOC) manager has made significant updates to the incident response plan and wants to test these updates together with all stakeholders in a collaborative manner. Which of the following is the best way to accomplish this task?
ARed-teaming event
BTabletop exercise
CSecurity awareness training
DPenetration test
Even though malware has been removed from some of the affected hosts, several of an organization's internal resources remain unavailable two weeks after a major incident was discovered. Which of the following best describes this phase?
AEradication
BPost-incident
CDetection
DAnalysis
EPreparation
After an incident has been resolved, which of the following is commonly used to identify efficiencies and corrective actions related to the activities performed during the incident response process?
ALessons learned
BKey performance indicators (KPIs) and performance metrics
CExecutive summary
DRoot cause analysis
A security operations center manager is concerned that after-action reporting is not being completed in a timely manner. Which of the following metrics will allow the manager to quantify this concern?
AMean time to remediate
BMean time to close
CMean time between failures
DMean time to respond
Which of the following report types is the most comprehensive when documenting a closed security incident?
ALessons-learned
BSituation
CRoot cause analysis
DAfter action
A Chief Information Security Officer (CISO) is notified of an ongoing incident. Which of the following explains why the CISO instructs the Chief Executive Officer not to discuss the incident over email?
AThe security team discovered a vulnerability in the Short Message Service email gateway.
BThe email system may be compromised.
CEmails are not encrypted in transit.
DThe CISO has not notified the public relations team of the incident.
Which of the following will inhibit remediation when attempting to resolve a vulnerability?
AControlled systems
BLegacy systems
CShared systems
DClosed systems
What does the click rate from a phishing simulation campaign measure?
AThe effectiveness of an organization's email filters
BThe false-positive rate of data leakage prevention behavior
CThe employees' security awareness
DThe speed of responding to a social engineering attack
Which of the following contains stakeholder contact information used for incident response reporting?
AThe company organization chart
BThe communication plan
CThe last incident report
DThe standard operating procedures
A security operations center (SOC) manager reviews a document that has been signed by the Chief Financial Officer (CFO), the sales director, and a customer, in order to determine whether a contract breach has occurred. Which of the following best describes the document that includes key performance indicators (KPIs)?
ATactics, techniques, and procedures (TTPs)
BReturn on investment report
CService-level agreement (SLA)
DRisk management plan
EMemorandum of understanding
A vulnerability analyst performs a credentialed vulnerability scan that covers all addressable enterprise assets. After completing the scan, the analyst finds a large number of critical vulnerabilities that cannot be remediated right away. Which of the following are the most likely reasons these vulnerabilities cannot be immediately addressed?
ALack of technical skills, the absence of a test environment, and the absence of an asset inventory
BPhysical access challenges, the absence of vendor support, and a lack of system documentation
CInaccurate asset inventory, a lack of system documentation, and an absence of authorization
DLegacy and proprietary systems, a lack of patch availability, and vendor dependencies
A security analyst is notified of a potential data breach. The report identifies unauthorized, recent access dates for files located in the following personnel archives:
Which action should the analyst take first?
APerform log correlation.
BReset user credentials.
CRestore files from backup.
DEstablish a timeline.
EEstablish a legal hold.
A security analyst suspects that a web application server has been compromised, based on recent security alerts. The analyst reviews the following server output:
Which of the following best describes what has occurred?
AAn initiated unauthorized session
BToo many users logged in at the same time
CHigh resource consumption
DAbnormal idle times for each user
A security architect examines a report from a third-party incident-response consultant and notes the following:
Which of the following frameworks did the consultant use to conduct the analysis?
ASpoofing, tampering, repudiation, information disclosure, denial of service, elevation of privilege (STRIDE)
BMITRE ATT&CK
CDiamond Model of Intrusion Analysis
DNational Institute of Standards and Technology (NIST) Cybersecurity Framework
ECyber Kill Chain
A new security operations center (SOC) manager joins a team that struggles to meet service-level agreements (SLAs). The alert backlog continues to increase daily. Which of the following will the manager most likely need to do?
AAutomate escalation.
BImprove the triage processes.
CUpgrade threat intelligence.
DEnhance the customer service response.
A Chief Information Security Officer (CISO) reviews a threat heat map and observes a significant rise in custom scanning and enumeration activity. The CISO wants to collect as much information as possible about these activities targeting the company in order to help prioritize mitigations. Which of the following solutions would best accomplish this goal?
AConfiguring a honeypot in a separate environment to gather attacker techniques
BLeveraging canary tokens on all production systems to detect valid intrusion attempts
CSubscribing to information-sharing and threat intelligence reports for the industry
DImplementing a web application firewall in front of all applications and having it log attacks
Which of the following should a cybersecurity analyst use when a notification is inaccurate?
Community Discussion