Question 31

During an incident, a security analyst discovers a large amount of Pll has been emailed externally from an employee to a public email address. The analyst finds that the external email is the employee's personal email. Which of the following should the analyst recommend be done first?
  • Question 32

    A company uses an FTP server to support its critical business functions. The FTP server is configured as follows:
    - The FTP service is running with the data directory configured in /opt/ftp/data.
    - The FTP server hosts employees' home directories in /home.
    - Employees may store sensitive information in their home directories.
    An IoC revealed that an FTP directory traversal attack resulted in sensitive data loss.
    Which of the following should a server administrator implement to reduce the risk of current and future directory traversal attacks targeted at the FTP server?
  • Question 33

    An incident responder was able to recover a binary file through the network traffic. The binary file was also found in some machines with anomalous behavior. Which of the following processes most likely can be performed to understand the purpose of the binary file?
  • Question 34

    K company has recently experienced a security breach via a public-facing service. Analysis of the event on the server was traced back to the following piece of code:
    SELECT ' From userjdata WHERE Username = 0 and userid8 1 or 1=1;-
    Which of the following controls would be best to implement?
  • Question 35

    After updating the email client to the latest patch, only about 15% of the workforce is able to use email. Windows 10 users do not experience issues, but Windows 11 users have constant issues.
    Which of the following did the change management team fail to do?