Question 181

An organization has tracked several incidents that are listed in the following table:
Which of the following is the organization's MTTD?
  • Question 182

    A security alert was triggered when an end user tried to access a website that is not allowed per organizational policy. Since the action is considered a terminable offense, the SOC analyst collects the authentication logs, web logs, and temporary files, reflecting the web searches from the user's workstation, to build the case for the investigation. Which of the following is the best way to ensure that the investigation complies with HR or privacy policies?
  • Question 183

    Which of the following risk management principles is accomplished by purchasing cyber insurance?
  • Question 184

    An organization's email account was compromised by a bad actor. Given the following Information:
    Which of the following is the length of time the team took to detect the threat?
  • Question 185

    As a proactive threat-hunting technique, hunters must develop situational cases based on likely attack scenarios derived from the available threat intelligence information. After forming the basis of the scenario, which of the following may the threat hunter construct to establish a framework for threat assessment?