Question 196

A security analyst is trying to determine if a host is active on a network. The analyst first attempts the following:

The analyst runs the following command next:

Which of the following would explain the difference in results?
  • Question 197

    A security analyst is attempting to utilize the blowing threat intelligence for developing detection capabilities:

    In which of the following phases is this APT MOST likely to leave discoverable artifacts?
  • Question 198

    The SOC has received reports of slowness across all workstation network segments. The currently installed antivirus has not detected anything, but a different anti-malware product was just downloaded
    and has revealed a worm is spreading
    Which of the following should be the NEXT step in this incident response?
  • Question 199

    An organization announces that all employees will need to work remotely for an extended period of time. All employees will be provided with a laptop and supported hardware to facilitate this requirement. The organization asks the information security division to reduce the risk during this time. Which of the following is a technical control that will reduce the risk of data loss if a laptop is lost or stolen?
  • Question 200

    An application has been updated to fix a vulnerability. Which of the following would ensure that previously patched vulnerabilities have not been reintroduced?