Question 166

A security analyst is reviewing alerts in the SIEM related to potential malicious network traffic coming from an employee's corporate laptop. The security analyst has determined that additional data about the executable running on the machine is necessary to continue the investigation.
Which of the following logs should the analyst use as a data source?
  • Question 167

    Which of the following methods to secure data is most often used to protect data in transit?
  • Question 168

    A security administrator identifies an application that is storing data using MD5. Which of the following best identifies the vulnerability likely present in the application?
  • Question 169

    Which of the following phases of the incident response process attempts to minimize disruption?
  • Question 170

    A security engineer would like to enhance the use of automation and orchestration within the SIEM. Which of the following would be the primary benefit of this enhancement?