Question 81

An organization's hunt team thinks a persistent threats exists and already has a foothold in the enterprise network.
Which of the following techniques would be BEST for the hunt team to use to entice the adversary to uncover malicious activity?
  • Question 82

    A security engineer needs to implement a solution to increase the security posture of user endpoints by providing more visibility and control over local administrator accounts. The endpoint security team is overwhelmed with alerts and wants a solution that has minimal operational burdens. Additionally, the solution must maintain a positive user experience after implementation.
    Which of the following is the BEST solution to meet these objectives?
  • Question 83

    A company security engineer arrives at work to face the following scenario:
    1) Website defacement
    2) Calls from the company president indicating the website needs to be fixed Immediately because It Is damaging the brand
    3) A Job offer from the company's competitor
    4) A security analyst's investigative report, based on logs from the past six months, describing how lateral movement across the network from various IP addresses originating from a foreign adversary country resulted in exfiltrated data Which of the following threat actors Is MOST likely involved?
  • Question 84

    After a security incident, a network security engineer discovers that a portion of the company's sensitive external traffic has been redirected through a secondary ISP that is not normally used.
    Which of the following would BEST secure the routes while allowing the network to function in the event of a single provider failure?
  • Question 85

    A company has decided to purchase a license for software that is used to operate a mission-critical process.
    The third-party developer is new to the industry but is delivering what the company needs at this time.
    Which of the following BEST describes the reason why utilizing a source code escrow will reduce the operational risk to the company if the third party stops supporting the application?