Question 36

A company that relies on an COL system must keep it operating until a new solution is available Which of the following is the most secure way to meet this goal?
  • Question 37

    A security analyst is reviewing suspicious log-in activity and sees the following data in the SICM:

    Which of the following is the most appropriate action for the analyst to take?
  • Question 38

    A security analyst is reviewing the following authentication logs:

    Which of the following should the analyst do first?
  • Question 39

    An organization recently acquired another company that is running a different EDR solution. A SOC analyst wants to automate the isolation of endpoints that are found to be compromised.
    Which of the following workflows best mitigates the risk of false positives and reduces the spread of malicious code?
  • Question 40

    An organization with a remote workforce has a new client with the following requirements:
    - Consultants need to travel to the client site.
    - The company has proprietary information on its hard drives.
    - The company prohibits BYOD.
    Which of the following would be the most beneficial for the organization to implement?