Question 26

An analyst receives an alert that a user clicked on a malicious link. The analyst verifies that the link is malicious and was intended to capture credentials. The analyst verifies that the user visited the website, but no evidence indicates that the credentials were used. The analyst recommends that the user take remedial training and closes the case. Which of the following steps in the incident response process did the analyst neglect?
  • Question 27

    An analyst must provide a visualization of data received from threat intelligence sources. The data includes the Internet Protocols, services, and tools used by threat actors. Which of the following is the best framework for the analyst to follow to display this data?
  • Question 28

    A new security operations center (SOC) manager joins a team that struggles to meet service- level agreements (SLAs). The alert backlog continues to increase daily. Which of the following will the manager most likely need to do?
  • Question 29

    A binary file that might contain malicious code is hosted on an isolated machine. An analyst wants to quickly detect the malicious code. Which of the following should the analyst use?
  • Question 30

    Before merging with a software company, the acquiring company's legal team requires a detailed software scan to determine if all code base is using open-source or paid licensed libraries. The vulnerability management analyst needs to provide this report. Which of the following scan methods will best meet this requirement?