Question 196

After completing a review of network activity. the threat hunting team discovers a device on the network that sends an outbound email via a mail client to a non-company email address daily at 10:00 p.m. Which of the following is potentially occurring?
  • Question 197

    A security analyst is reviewing the following alert that was triggered by FIM on a critical system:

    Which of the following best describes the suspicious activity that is occurring?
  • Question 198

    A security analyst needs to develop a solution to protect a high-value asset from an exploit like a recent zero-day attack. Which of the following best describes this risk management strategy?
  • Question 199

    Which of the following best explains the importance of communicating with staff regarding the official public communication plan related to incidents impacting the organization?
  • Question 200

    A cybersecurity analyst is reviewing SIEM logs and observes consistent requests originating from an internal host to a blocklisted external server. Which of the following best describes the activity that is taking place?