A Chief Information Security Officer (CISO) is notified of an ongoing incident.
Which of the following explains why the CISO instructs the Chief Executive Officer not to discuss the incident over email?
Which of the following describes the main benefits of MITRE ATT & CK Navigator?
An analyst prepares an after action report following an incident in which multiple systems were compromised over several days.
The analyst provides raw event logs from each compromised system in the report and determines that a patient-zero system cannot be found.
Which of the following should the analyst do to determine the patient-zero system?
A new security operations center (SOC) manager joins a team that struggles to meet service-level agreements (SLAs). The alert backlog continues to increase daily.
Which of the following will the manager most likely need to do?
A security operations center manager is concerned that after action reporting is not being completed in a timely manner.
Which of the following will allow the manager to quantify this concern?
Which of the following is the most important component to include in the preparation phase of an incident response plan?
An analyst must provide a visualization of data received from threat intelligence sources. The data includes the Internet Protocols, services, and tools used by threat actors.
Which of the following is the best framework for the analyst to follow to display this data?
Which of the following is commonly used after an incident has been resolved to identify efficiencies and corrective actions related to activities performed during the incident response process?
A security operations center (SOC) manager reviews a document signed by the Chief Financial Officer (CFO), the sales director, and a customer to decide whether a contract breach occurred.
Which of the following best describes the document that includes key performance indicators (KPIs)?
A public threat intelligence report includes indicators of compromise (IoCs) for threat actors. The threat actors are exploiting a zero-day vulnerability that the vendor has not fixed.
Which of the following techniques should be used until a patch is available?