Question 16
There is an alert coming from the security information and event management system. Which of the following is the first task an analyst should complete?
Question 17
A public threat intelligence report includes indicators of compromise (IoCs) for threat actors. The threat actors are exploiting a zero-day vulnerability that the vendor has not fixed. Which of the following techniques should be used until a patch is available?
Question 18
As part of a quality assurance test, a developer wants to examine how the code behaves after an application has been fully compiled and is running. Which of the following best describes the type of testing that the developer should perform?
Question 19
A security analyst receives a notice about a possible data breach. The report identifies unapproved, current access dates for files found in the following personnel archives:

Which of the following actions should the analyst take first?

Which of the following actions should the analyst take first?
Question 20
Which of the following is the main concept behind the use of an attack methodology framework?
