Question 91

The CIRT is reviewing an incident that involved a human resources recruiter exfiltration sensitive company data. The CIRT found that the recruiter was able to use HTTP over port 53 to upload documents to a web server. Which of the following security infrastructure devices could have identified and blocked this activity?
  • Question 92

    An administrator discovers that some files on a database server were recently encrypted. The administrator sees from the security logs that the data was last accessed by a domain user. Which of the following best describes the type of attack that occurred?
  • Question 93

    After a recent vulnerability scan, a security engineer needs to harden the routers within the corporate network. Which of the following is the most appropriate to disable?
  • Question 94

    A security administrator would like to protect data on employees' laptops. Which of the following encryption techniques should the security administrator use?
  • Question 95

    A security administrator is deploying a DLP solution to prevent the exfiltration of sensitive customer data.
    Which of the following should the administrator do first?