Loading provider exams...
Loading provider exams...
The insider risk matrix comprises the vectors of technical literacy and business-process knowledge. Based on this matrix, what conclusion can be drawn?
The commercially valuable product of intellect that includes copyrights and trademarks is called:
The service organization that delivers 24x7 computer security incident-response services to any user, company, government agency, or organization is called:
Insiders understand corporate business functions. What is the correct order of activities that insiders perform to damage company assets?
The greatest number of cyber-attacks are carried out by:
Go ad-free and unlock Learn Mode, Exam Mode, AstroTutor AI and every premium tool — everything you need to walk in prepared, and confident.
During the Control Analysis phase of NIST’s risk assessment methodology, technical and nontechnical control methods are grouped into two categories. What are those two control categories?
An organization experienced an information security incident in which a disgruntled employee shared sensitive access-control information with a competitor. After investigating, the organization’s incident response manager determined that the incident must be addressed within a few hours on the same day to preserve business continuity and market competitiveness. How should this information security incident be categorized?
Conducting a Vulnerability Assessment is an example of:
The correct order or sequence of the computer forensic processes is:
The person who recovers, analyzes, and preserves computers and related materials for presentation as evidence in a court of law; identifies the evidence; estimates the potential impact of malicious activity on the victim; and assesses the perpetrator’s intent and identity is called:
A payroll system contains a vulnerability that current technology cannot exploit. Which of the following is correct for this scenario?
A systematic set of techniques and procedures for collecting evidence from computer equipment, various storage devices, and digital media, which can be presented coherently and meaningfully in a court of law, is called:
Business Continuity offers a planning methodology that enables continued business operations:
The state of incident-response preparedness that allows an organization to maximize its ability to use digital evidence while minimizing investigation costs is called:
To respond to DDoS attacks, one of the following strategies may be used:
The flowchart presents the different roles performed by different CSIRT personnel. Identify the incident-response personnel denoted by A, B, C, D, E, F, and G.

Multiple-component incidents involve a combination of two or more attacks within a system. Which of the following is not a multiple-component incident?
The usual sequence of activities a CSIRT uses when handling a case is:
During a DDoS attack, attackers initially compromise multiple systems and then use them to directly attack a specific target. What are those systems called?
Incident-handling and response steps help detect, identify, respond to, and manage an incident. Which of the following helps recognize and separate infected hosts from the information system?
Organizations or incident-response teams must safeguard evidence for any future legal actions that may be brought against perpetrators who intentionally attacked the computer system. Evidence protection is also necessary to satisfy legal-compliance issues. Which of the following documents helps protect evidence against physical or logical damage:
The ability of an agency to remain operational after a disastrous event—achieved by deploying redundant hardware and software, using fault-tolerant systems, and maintaining a sound backup and recovery strategy—is known as:
Which command does a Digital Forensic Examiner use to show every open port and its associated IP address on a victim computer, in order to identify the established connections on that computer?
Common name(s) for a CSIRT include:
Which of the following could be regarded as an insider threat?
Community Discussion