Question 106

A security analyst observes the following while looking through network traffic in a company's cloud log:

Which of the following steps should the security analyst take FIRST?
  • Question 107

    A security analyst is evaluating the security of an online customer banking system. The analyst has a 12-character password for the test account. At the login screen, the analyst is asked to enter the third, eighth, and eleventh characters of the password. Which of the following describes why this request is a security concern? (Choose two.)
  • Question 108

    A company makes consumer health devices and needs to maintain strict confidentiality of unreleased product designs.
    Recently unauthorized photos of products still in development have been for sale on the dark web.
    The Chief Information Security Officer (CISO) suspects an insider threat, but the team that uses the secret outdoor testing area has been vetted many times and nothing suspicious has been found.
    Which of the following is the MOST likely cause of the unauthorized photos?
  • Question 109

    A security engineer has been asked to close all non-secure connections from the corporate network. The engineer is attempting to understand why the corporate UTM will not allow users to download email via IMAPS. The engineer formulates a theory and begins testing by creating the firewall ID 58, and users are able to download emails correctly by using IMAP instead. The network comprises three VLANs:

    The security engineer looks at the UTM firewall rules and finds the following:

    Which of the following should the security engineer do to ensure IMAPS functions properly on the corporate user network?
  • Question 110

    A user forwarded a suspicious email to a security analyst for review. The analyst examined the email and found that neither the URL nor the attachment showed any indication of malicious activities. Which of the following intelligence collection methods should the analyst use to confirm the legitimacy of the email?