Question 111

After an incident response exercise, a security administrator reviews the following table:

Which of the following should the administrator do to beat support rapid incident response in the future?
  • Question 112

    A security analyst is reviewing suspicious log-in activity and sees the following data in the SICM:

    Which of the following is the most appropriate action for the analyst to take?
  • Question 113

    After a penetration test on the internal network, the following report was generated:

    Which of the following should be recommended to remediate the attack?
  • Question 114

    A security architect wants to develop a baseline of security configurations These configurations automatically will be utilized machine is created Which of the following technologies should the security architect deploy to accomplish this goal?
  • Question 115

    A security engineer is reviewing the SIEM logs after a server crashed. The following list of events represents the timeline of actions collected from the SIEM:

    Which of the following TTPs is most likely associated with this SIEM log?