Question 21
An analyst reviews a summarized vulnerability report through a governance, risk, and compliance (GRC) reporting tool. The following report correlates asset information from the configuration management database (CMDB) against detected vulnerabilities:

Which of the following servers should the analyst prioritize based on the target value, the risk, and the likelihood of exploitation?

Which of the following servers should the analyst prioritize based on the target value, the risk, and the likelihood of exploitation?
Question 22
Which of the following is the most important component to include in the preparation phase of an incident response plan?
Question 23
Which of the following is the most likely reason an organization might implement compensating controls?
Question 24
A threat intelligence analyst needs to gather TTPs from attackers. Which of the following is the most comprehensive resource for this task?
Question 25
A security analyst runs an Nmap scan against a host with multiple open ports using the following command:
nmap 10.10.10.1 -p-
The following output is obtained after the scan:
Starting Nmap 7.95 ( https://nmap.org ) at 2025-07-15 15:55 UTC
Note: Host seems down.
Nmap done: 1 IP address (0 hosts up) scanned in 3.16 seconds
Which of the following is the most accurate way to scan the target IP for open ports?
nmap 10.10.10.1 -p-
The following output is obtained after the scan:
Starting Nmap 7.95 ( https://nmap.org ) at 2025-07-15 15:55 UTC
Note: Host seems down.
Nmap done: 1 IP address (0 hosts up) scanned in 3.16 seconds
Which of the following is the most accurate way to scan the target IP for open ports?
