Question 86

A customer is using a central device to manage network devices over SNMPv2. A remote attacker caused a denial of service condition and can trigger this vulnerability by issuing a GET request for the ciscoFlashMIB OID on an affected device. Which should be disabled to resolve the issue?
  • Question 87


    Refer to the exhibit. Which data format is being used?
  • Question 88

    An engineer received an incident ticket of a malware outbreak and used antivirus and malware removal tools to eradicate the threat. The engineer notices that abnormal processes are still occurring in the system and determines that manual intervention is needed to clean the infected host and restore functionality. What is the next step the engineer should take to complete this playbook step?
  • Question 89

    Refer to the exhibit.

    An engineer configured this SOAR solution workflow to identify account theft threats and privilege escalation, evaluate risk, and respond by resolving the threat. This solution is handling more threats than Security analysts have time to analyze. Without this analysis, the team cannot be proactive and anticipate attacks. Which action will accomplish this goal?
  • Question 90

    A SOC team is informed that a UK-based user will be traveling between three countries over the next 60 days.
    Having the names of the 3 destination countries and the user's working hours, what must the analyst do next to detect an abnormal behavior?