Question 91

A company security engineer arrives at work to face the following scenario:
1) Website defacement
2) Calls from the company president indicating the website needs to be fixed Immediately because It Is damaging the brand
3) A Job offer from the company's competitor
4) A security analyst's investigative report, based on logs from the past six months, describing how lateral movement across the network from various IP addresses originating from a foreign adversary country resulted in exfiltrated data Which of the following threat actors Is MOST likely involved?
  • Question 92

    An analyst execute a vulnerability scan against an internet-facing DNS server and receives the following report:
    - Vulnerabilities in Kernel-Mode Driver Could Allow Elevation of
    Privilege
    - SSL Medium Strength Cipher Suites Supported
    - Vulnerability in DNS Resolution Could Allow Remote Code Execution
    - SMB Host SIDs allows Local User Enumeration
    Which of the following tools should the analyst use FIRST to validate the most critical vulnerability?
  • Question 93

    A threat analyst notices the following URL while going through the HTTP logs.

    Which of the following attack types is the threat analyst seeing?
  • Question 94

    A company plans to build an entirely remote workforce that utilizes a cloud-based infrastructure. The Chief Information Security Officer asks the security engineer to design connectivity to meet the following requirements:
    Only users with corporate-owned devices can directly access servers hosted by the cloud provider.
    The company can control what SaaS applications each individual user can access.
    User browser activity can be monitored.
    Which of the following solutions would BEST meet these requirements?
  • Question 95

    All staff at a company have started working remotely due to a global pandemic. To transition to remote work, the company has migrated to SaaS collaboration tools. The human resources department wants to use these tools to process sensitive information but is concerned the data could be:
    Leaked to the media via printing of the documents
    Sent to a personal email address
    Accessed and viewed by systems administrators
    Uploaded to a file storage site
    Which of the following would mitigate the department's concerns?