Question 126

A cybersecurity analyst notices unusual network scanning activity coming from a country that the company does not do business with. Which of the following is the best mitigation technique?
  • Question 127

    During a cybersecurity incident, one of the web servers at the perimeter network was affected by ransomware.
    Which of the following actions should be performed immediately?
  • Question 128

    An organization enabled a SIEM rule to send an alert to a security analyst distribution list when ten failed logins occur within one minute. However, the control was unable to detect an attack with nine failed logins. Which of the following best represents what occurred?
  • Question 129

    An analyst is reviewing a vulnerability report for a server environment with the following entries:

    Which of the following systems should be prioritized for patching first?
  • Question 130

    A security analyst obtained the following table of results from a recent vulnerability assessment that was conducted against a single web server in the environment:

    Which of the following should be completed first to remediate the findings?