Question 226

An organization was alerted to a possible compromise after its proprietary data was found for sale on the Internet. An analyst is reviewing the logs from the next-generation UTM in an attempt to find evidence of this breach. Given the following output:

Which of the following should be the focus of the investigation?
  • Question 227

    A security analyst at a small regional bank has received an alert that nation states are attempting to infiltrate financial institutions via phishing campaigns. Which of the following techniques should the analyst recommend as a proactive measure to defend against this type of threat?
  • Question 228

    A consultant evaluating multiple threat intelligence leads to assess potential risks for a client. Which of the following is the BEST approach for the consultant to consider when modeling the client's attack surface?
  • Question 229

    A security analyst is auditing firewall rules with the goal of scanning some known ports to check the firewall's behavior and responses. The analyst executes the following commands:

    The analyst then compares the following results for port 22:
    nmap returns "Closed"
    hping3 returns "flags=RA"
    Which of the following BEST describes the firewall rule?
  • Question 230

    A security analyst is investigating a compromised Linux server. The analyst issues the ps command and receives the following output:

    Which of the following commands should the administrator run next to further analyze the compromised system?