Question 21

An analyst reviews a summarized vulnerability report through a governance, risk, and compliance (GRC) reporting tool. The following report correlates asset information from the configuration management database (CMDB) against detected vulnerabilities:

Which of the following servers should the analyst prioritize based on the target value, the risk, and the likelihood of exploitation?
  • Question 22

    Which of the following is the most important component to include in the preparation phase of an incident response plan?
  • Question 23

    Which of the following is the most likely reason an organization might implement compensating controls?
  • Question 24

    A threat intelligence analyst needs to gather TTPs from attackers. Which of the following is the most comprehensive resource for this task?
  • Question 25

    A security analyst runs an Nmap scan against a host with multiple open ports using the following command:
    nmap 10.10.10.1 -p-
    The following output is obtained after the scan:
    Starting Nmap 7.95 ( https://nmap.org ) at 2025-07-15 15:55 UTC
    Note: Host seems down.
    Nmap done: 1 IP address (0 hosts up) scanned in 3.16 seconds
    Which of the following is the most accurate way to scan the target IP for open ports?