Question 16

A security analyst detected a malicious PowerShell attack on a single server. The malware used the Invoke-Expression function to execute an external malicious script. The security analyst scanned the disk with an antivirus application and did not find any IOCs. The security analyst now needs to deploy a protection solution against this type of malware.
Which of the following BEST describes the type of malware the solution should protect against?
  • Question 17

    A cybersecurity analyst discovered a private key that could have been exposed.
    Which of the following is the BEST way for the analyst to determine if the key has been compromised?
  • Question 18

    A security analyst is reviewing the following vulnerability assessment report:

    Which of the following should be patched FIRST to minimize attacks against Internet-facing hosts?
  • Question 19

    An application server was recently upgraded to prefer TLS 1.3, and now users are unable to connect their clients to the server. Attempts to reproduce the error are confirmed, and clients are reporting the following:
    ERR_SSL_VERSION_OR_CIPHER_MISMATCH
    Which of the following is MOST likely the root cause?
  • Question 20

    A penetration tester obtained root access on a Windows server and, according to the rules of engagement, is permitted to perform post-exploitation for persistence.
    Which of the following techniques would BEST support this?