Question 256

After several companies in the financial industry were affected by a similar incident, they shared information about threat intelligence and the malware used for exploitation. Which of the following should the companies do to best indicate whether the attacks are being conducted by the same actor?
  • Question 257

    An organization must provide access to its internal system data. The organization requires that this access complies with the following:
    Access must be automated.
    Data confidentiality must be preserved.
    Access must be authenticated.
    Data must be preprocessed before it is retrieved.
    Which of the following actions should the organization take to meet these requirements?
  • Question 258

    An external SaaS solution user reports a bug associated with the role-based access control module. This bug allows users to bypass system logic associated with client segmentation in the multitenant deployment model.
    When assessing the bug report, the developer finds that the same bug was previously identified and addressed in an earlier release. The developer then determines the bug was reintroduced when an existing software component was integrated from a prior version of the platform. Which of the following is the best way to prevent this scenario?
  • Question 259

    Users are experiencing a variety of issues when trying to access corporate resources. Examples include:
    - Connectivity issues between local computers and file servers within
    branch offices
    - Inability to download corporate applications on mobile endpoints
    while working remotely
    - Certificate errors when accessing internal web applications
    Which of the following actions are the most relevant when troubleshooting the reported issues?
    (Choose two.)
  • Question 260

    A security analyst notices a number of SIEM events that show the following activity:
    10/30/2020 - 8:01 UTC - 192.168.1.1 - sc stop HinDctend
    10/30/2020 - 8:05 UTC - 192.168.1.2 - c:\program files\games\comptidcasp.exe
    10/30/2020 - 8:07 UTC - 192.168.1.1 - c:\windows\system32\cmd.exe /c powershell
    10/30/2020 - 8:07 UTC - 192.168.1.1 - powershell -> 40.90.23.154:443
    Which of the following response actions should the analyst take first?