Question 61

Refer to the exhibit.

Which asset has the highest risk value?
  • Question 62

    An employee who often travels abroad logs in from a first-seen country during non-working hours. The SIEM tool generates an alert that the user is forwarding an increased amount of emails to an external mail domain and then logs out. The investigation concludes that the external domain belongs to a competitor. Which two behaviors triggered UEBA? (Choose two.)
  • Question 63

    Refer to the exhibit.

    What is occurring in this packet capture?
  • Question 64

    A SOC analyst is investigating a recent email delivered to a high-value user for a customer whose network their organization monitors. The email includes a suspicious attachment titled "Invoice RE: 0004489". The hash of the file is gathered from the Cisco Email Security Appliance. After searching Open Source Intelligence, no available history of this hash is found anywhere on the web. What is the next step in analyzing this attachment to allow the analyst to gather indicators of compromise?
  • Question 65

    Refer to the exhibit.

    Where does it signify that a page will be stopped from loading when a scripting attack is detected?