Weekend Sale Special - 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: estly75

A Chief Information Security Officer (CISO) is notified of an ongoing incident.

Which of the following explains why the CISO instructs the Chief Executive Officer not to discuss the incident over email?

A.

The security team discovered a vulnerability in the Short Message Service email gateway.

B.

The email system may be compromised.

C.

Emails are not encrypted in transit.

D.

The CISO has not notified the public relations team of the incident.

Which of the following describes the main benefits of MITRE ATT & CK Navigator?

A.

Replicating adversary behavior and blocking gaps in defenses

B.

Monitoring adversary behavior and performing malware reverse engineering

C.

Responding to adversary behavior and building security defense tools

D.

Understanding adversary behavior and identifying gaps in defenses

An analyst prepares an after action report following an incident in which multiple systems were compromised over several days.

The analyst provides raw event logs from each compromised system in the report and determines that a patient-zero system cannot be found.

Which of the following should the analyst do to determine the patient-zero system?

A.

Establish an accurate timeline of events.

B.

Enable monitoring on the compromised systems.

C.

Isolate the compromised systems before remediation.

D.

Improve the content for incident updates during shift handoff.

E.

Perform a reverse composition analysis on malware packages.

A new security operations center (SOC) manager joins a team that struggles to meet service-level agreements (SLAs). The alert backlog continues to increase daily.

Which of the following will the manager most likely need to do?

A.

Automate escalation.

B.

Improve the triage processes.

C.

Upgrade threat intelligence.

D.

Enhance the customer service response.

A security operations center manager is concerned that after action reporting is not being completed in a timely manner.

Which of the following will allow the manager to quantify this concern?

A.

Mean time to remediate

B.

Mean time to close

C.

Mean time between failures

D.

Mean time to respond

Which of the following is the most important component to include in the preparation phase of an incident response plan?

A.

Roles and responsibilities

B.

After action reports

C.

Data integrity validation

D.

Chain of custody

An analyst must provide a visualization of data received from threat intelligence sources. The data includes the Internet Protocols, services, and tools used by threat actors.

Which of the following is the best framework for the analyst to follow to display this data?

A.

Diamond Model of Intrusion Analysis

B.

Exploit Prediction Scoring System

C.

Cyber Kill Chain

D.

MITRE Adversarial Tactics, Techniques, and Common Knowledge and Detection, Denial, and Disruption Framework Empowering Network Defense

Which of the following is commonly used after an incident has been resolved to identify efficiencies and corrective actions related to activities performed during the incident response process?

A.

Lessons learned

B.

Key performance indicators (KPIs) and performance metrics

C.

Executive summary

D.

Root cause analysis

A security operations center (SOC) manager reviews a document signed by the Chief Financial Officer (CFO), the sales director, and a customer to decide whether a contract breach occurred.

Which of the following best describes the document that includes key performance indicators (KPIs)?

A.

Tactics, techniques, and procedures (TTPs)

B.

Return on investment report

C.

Service-level agreement (SLA)

D.

Risk management plan

E.

Memorandum of understanding

A public threat intelligence report includes indicators of compromise (IoCs) for threat actors. The threat actors are exploiting a zero-day vulnerability that the vendor has not fixed.

Which of the following techniques should be used until a patch is available?

A.

Sinkholing

B.

Eradication techniques

C.

Continuous monitoring

D.

Evidence acquisition