Question 186

A security analyst was transferred to an organization's threat-hunting team to track specific activity throughout the enterprise environment. The analyst must observe and assess the number to times this activity occurs and aggregate the results.
Which of the following is the BEST threat-hunting method for the analyst to use?
  • Question 187

    During an incident involving phishing, a security analyst needs to find the source of the malicious email.
    Which of the following techniques would provide the analyst with this information?
  • Question 188

    The developers recently deployed new code to three web servers. A daffy automated external device scan report shows server vulnerabilities that are failure items according to PCI DSS.
    If the venerability is not valid, the analyst must take the proper steps to get the scan clean.
    If the venerability is valid, the analyst must remediate the finding.
    After reviewing the information provided in the network diagram, select the STEP 2 tab to complete the simulation by selecting the correct Validation Result and Remediation Action for each server listed using the drop-down options.
    INTRUCTIONS:
    The simulation includes 2 steps.
    Step1:Review the information provided in the network diagram and then move to the STEP 2 tab.


    STEP 2: Given the Scenario, determine which remediation action is required to address the vulnerability.

    Question 189

    Which of the following is the first step that should be performed when establishing a disaster recovery plan?
  • Question 190

    A recent penetration test discovered that several employees were enticed to assist attackers by visiting specific websites and running downloaded files when prompted by phone calls. Which of the following would best address this issue?