Question 61
Refer to the exhibit.

Which asset has the highest risk value?

Which asset has the highest risk value?
Question 62
An employee who often travels abroad logs in from a first-seen country during non-working hours. The SIEM tool generates an alert that the user is forwarding an increased amount of emails to an external mail domain and then logs out. The investigation concludes that the external domain belongs to a competitor. Which two behaviors triggered UEBA? (Choose two.)
Question 63
Refer to the exhibit.

What is occurring in this packet capture?

What is occurring in this packet capture?
Question 64
A SOC analyst is investigating a recent email delivered to a high-value user for a customer whose network their organization monitors. The email includes a suspicious attachment titled "Invoice RE: 0004489". The hash of the file is gathered from the Cisco Email Security Appliance. After searching Open Source Intelligence, no available history of this hash is found anywhere on the web. What is the next step in analyzing this attachment to allow the analyst to gather indicators of compromise?
Question 65
Refer to the exhibit.

Where does it signify that a page will be stopped from loading when a scripting attack is detected?

Where does it signify that a page will be stopped from loading when a scripting attack is detected?
