Question 21

Which of the following is most appropriate to use with SOAR when the security team would like to automate actions across different vendor platforms?
  • Question 22

    A security analyst has found the following suspicious DNS traffic while analyzing a packet capture:
    * DNS traffic while a tunneling session is active.
    * The mean time between queries is less than one second.
    * The average query length exceeds 100 characters.
    Which of the following attacks most likely occurred?
  • Question 23

    The vulnerability analyst reviews threat intelligence regarding emerging vulnerabilities affecting workstations that are used within the company:

    Which of the following vulnerabilities should the analyst be most concerned about, knowing that end users frequently click on malicious links sent via email?
  • Question 24

    An analyst is evaluating a vulnerability management dashboard. The analyst sees that a previously remediated vulnerability has reappeared on a database server. Which of the following is the most likely cause?
  • Question 25

    Due to reports of unauthorized activity that was occurring on the internal network, an analyst is performing a network discovery. The analyst runs an Nmap scan against a corporate network to evaluate which devices were operating in the environment. Given the following output:

    Which of the following choices should the analyst look at first?