Question 51

A malicious artifact was collected during an incident response procedure. A security analyst is unable to run it in a sandbox to understand its features and method of operation. Which of the following procedures is the BEST approach to perform a further analysis of the malware's capabilities?
  • Question 52

    A cybersecurity analyst is dissecting an intrusion down to the specific techniques and wants to organize them in a logical manner. Which of the following frameworks would BEST apply in this situation?
  • Question 53

    A security analyst receives an alert from the SIEM about a possible attack happening on the network The analyst opens the alert and sees the IP address of the suspected server as 192.168.54.66. which is part of the network 192 168 54 0/24. The analyst then pulls all the command history logs from that server and sees the following

    Which of the following activities is MOST likely happening on the server?
  • Question 54

    Which of the following BEST explains the function of trusted firmware updates as they relate to hardware assurance?
  • Question 55

    An organization wants to implement controls for protecting private information at rest. Which of the following would meet the organization's need?