Question 31
SIMULATION
A healthcare organization must develop an action plan based on the findings from a risk assessment. The action plan must consist of a recommended list of security controls.
INSTRUCTIONS
Select the appropriate control to implement for each risk finding. Findings may be used only once.
If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.

A healthcare organization must develop an action plan based on the findings from a risk assessment. The action plan must consist of a recommended list of security controls.
INSTRUCTIONS
Select the appropriate control to implement for each risk finding. Findings may be used only once.
If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.

Question 32
Which of the following network architectures would best implement a perimeter-less network topology?
Question 33
Hotspot Question
An organization receives an indication that one of its hosts is part of a DDoS attack against a victim. The proxy server is supposed to handle all web page requests from all internal hosts.
INSTRUCTIONS
Click on each workstation and server to review outputs and a log file.
Identify the compromised host and executable, and determine an appropriate remediation for the issue.
If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.









An organization receives an indication that one of its hosts is part of a DDoS attack against a victim. The proxy server is supposed to handle all web page requests from all internal hosts.
INSTRUCTIONS
Click on each workstation and server to review outputs and a log file.
Identify the compromised host and executable, and determine an appropriate remediation for the issue.
If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.









Question 34
Multiple users report unexpected mouse movements and terminal windows opening. An analyst reviewing the network traffic logs observes the following:

Which of the following is the most likely reason for the reported symptoms?

Which of the following is the most likely reason for the reported symptoms?
Question 35
Customers are unable to upload files to an SFTP server. Firewall logs show the following activity sourced from multiple IP addresses in one geographic region:

The analyst reviewing the logs notices that the session_end_reason does not change for any of the log entries. Which of the following is the next step the analyst should take to determine what is occurring?

The analyst reviewing the logs notices that the session_end_reason does not change for any of the log entries. Which of the following is the next step the analyst should take to determine what is occurring?

