Which of the following is the most important reason why tactics, techniques, and procedures (TTP) are beneficial to a defensive strategy?
An analyst reviews the following log entries:

Which of the following conclusions should the analyst reach? (Choose two.)
A security analyst runs an Nmap scan against a host with multiple open ports using the following command:
nmap 10.10.10.1 -p-
The following output is obtained after the scan:
Starting Nmap 7.95 ( https://nmap.org ) at 2025-07-15 15:55 UTC
Note: Host seems down.
Nmap done: 1 IP address (0 hosts up) scanned in 3.16 seconds
Which of the following is the most accurate way to scan the target IP for open ports?
A Chief Information Security Officer (CISO) evaluates a threat heat map and notices a substantial increase in custom scanning and enumeration activities. The CISO wants to gather as much information as possible about the activities targeting the company to help prioritize mitigations.
Which of the following solutions is the best way to accomplish this goal?
An analyst is configuring a security information and event management system to capture fileless malware execution events.
Which of the following log files requires additional configuration to accomplish this task?
A security team deploys a new scanning solution that requires root, domain administrator, and local server administrator permissions on all systems.
Which of the following is the best way to help mitigate the risk for this level of access?
A security analyst reruns infrastructure as code (IaC) to tear down and rebuild a new environment after a ransomware attack.
Which of the following describes this phase?
An analyst receives an alert that a user clicked on a malicious link. The analyst verifies that the link is malicious and was intended to capture credentials. The analyst verifies that the user visited the website, but no evidence indicates that the credentials were used. The analyst recommends that the user take remedial training and closes the case.
Which of the following steps in the incident response process did the analyst neglect?
Which of the following occurs during the analysis phase of the incident response process?
Which of the following is the most likely reason an organization might implement compensating controls?