Which of the following best explains the importance of playbooks for incident response teams?
A. Playbooks define compliance controls and help keep the monitoring process that is in place fully aligned with regulatory requirements as designed by international rules.
B. Playbooks help implement mitigation controls to prevent the occurrence of incidents in accordance with internal policies and procedures as designed by the IT team.
C. Playbooks set baseline requirements that are implemented before incidents happen to ensure the proper monitoring process in order to collect metrics and KPIs that will be used for lessons-learned procedures after a postmortem analysis.
D. Playbooks help minimize negative impacts and restore data, systems, and operations through highly detailed, preplanned procedures that will be followed when particular types of incidents occur.
Show Answer
Correct Answer: D
Explanation: Incident response playbooks provide detailed, predefined procedures for handling specific types of security incidents. They enable consistent, rapid, and coordinated response efforts to minimize damage, contain incidents, and restore affected systems and operations efficiently. The other options describe compliance, preventive controls, or monitoring baselines rather than the primary purpose of incident response playbooks.
Question 92
After updating the email client to the latest patch, only about 15% of the workforce is able to use email. Windows 10 users do not experience issues, but Windows 11 users have constant issues. Which of the following did the change management team fail to do?
A. Implementation
B. Testing
C. Rollback
D. Validation
Show Answer
Correct Answer: B
Explanation: The issue affects Windows 11 users but not Windows 10 users after deploying the latest email client patch, indicating the change was not adequately tested across supported environments before implementation. Implementation clearly occurred, rollback is a recovery step after problems are detected, and validation confirms the change met objectives after deployment, but the OS-specific compatibility issue should have been identified during testing.
Question 93
An analyst notices that logs contain multiple events for computer account changes during monthly patch maintenance windows, resulting in a flood of tickets. The events generated are from the same system and time frame. The analyst determines that these tickets could be closed without human interaction. Which of the following is the best tool for automatically closing tickets containing the same information?
A. SOAR
B. EDR
C. CASB
D. SIEM
Show Answer
Correct Answer: A
Explanation: SOAR (Security Orchestration, Automation, and Response) is designed to automate security workflows, including ticket handling and case management. In this scenario, repeated, known-benign events occurring during scheduled maintenance can be automatically identified and the associated tickets closed without analyst intervention. A SIEM aggregates and correlates logs but does not primarily automate ticket closure workflows; EDR focuses on endpoint detection and response, and CASB secures cloud service usage.
Question 94
Security analysts can review the Windows Registry on endpoints to get insights into:
A. domain account privileges.
B. mandatory access control zones.
C. system-critical configuration items.
D. application and security event logs.
Show Answer
Correct Answer: C
Explanation: The Windows Registry is a hierarchical database that stores operating system and application configuration, hardware and driver settings, user profiles, startup entries, and security-related policies. Reviewing it provides insight into system-critical configuration items. Domain account privileges are primarily managed in Active Directory or local security policy, mandatory access control zones are not represented by the Registry, and application/security event logs are stored in Windows Event Logs rather than the Registry.
Question 95
An analyst finds that duplicate entries may exist in the asset inventory, which is skewing vulnerability scan data. Which of the following is the best way for the analyst to improve the effectiveness of the vulnerability scan?
A. Device fingerprinting
B. Network mapping
C. Uncredentialed reports
D. Dynamic scans
Show Answer
Correct Answer: A
Explanation: Device fingerprinting uniquely identifies assets based on stable characteristics such as hardware, operating system, services, and other attributes. This helps detect and consolidate duplicate asset records, improving inventory accuracy and preventing duplicated or skewed vulnerability scan results. Network mapping identifies topology, uncredentialed reports affect scan depth, and dynamic scans do not address duplicate inventory entries.
Question 96
While performing a dynamic analysis of a malicious file, a security analyst notices the memory address changes every time the process runs. Which of the following controls is most likely preventing the analyst from finding the proper memory address of the piece of malicious code?
A. Address space layout randomization
B. Data execution prevention
C. Stack canary
D. Code obfuscation
Show Answer
Correct Answer: A
Explanation: Address Space Layout Randomization (ASLR) randomizes the locations of a process's memory regions each time it runs, causing the memory address of code (including malicious code) to change between executions. DEP prevents execution from non-executable memory, stack canaries detect stack corruption, and code obfuscation makes code harder to understand but does not randomize runtime memory addresses.
Question 97
An IDS is triggered during after-hours operations. The indicator records an abnormal amount of SYN requests being sent to port 21 from numerous external systems. A security analyst reports this information to the IR team for further investigation. Which of the following best describes this incident?
A. A sniff attack through the DNS port
B. A buffer overflow attack through the Telnet port
C. A reconnaissance attack through the SSH port
D. A DDoS attack through the FTP port
Show Answer
Correct Answer: D
Explanation: Port 21 is FTP. A high volume of TCP SYN packets from numerous external systems indicates a distributed SYN flood, which is a form of DDoS targeting the FTP service. The other options mismatch the protocol/port mappings or attack characteristics.
Question 98
After a series of UEBA alerts, a company’s SOC observes an extended period of suspicious outbound traffic all with the same destination. Which of the following steps of the cyber kill chain has this attack completed?
A. Weaponization
B. Command and control
C. Reconnaissance
D. Exploitation
Show Answer
Correct Answer: B
Explanation: An extended period of suspicious outbound traffic to the same destination is characteristic of malware maintaining communication with an attacker-controlled server. In the Cyber Kill Chain, this indicates the command-and-control (C2) phase has been reached, meaning the compromise has progressed beyond reconnaissance, weaponization, and exploitation.
Question 99
Which of the following best describes the benefit of implementing a PAM solution?
A. Measuring and validating the integrity of the database
B. Controlling and monitoring the use of administrative accounts
C. Storing and protecting PKI certificate private keys
D. Configuring and enforcing password complexity requirements
Show Answer
Correct Answer: B
Explanation: PAM (Privileged Access Management) is designed to secure, control, and monitor privileged or administrative accounts and their use. It provides credential vaulting, session monitoring, least-privilege enforcement, and auditing. The other options describe different security technologies: database integrity (A), HSM/key management for private keys (C), and password policy enforcement (D).
Question 100
A security analyst has just received an incident ticket regarding a ransomware attack. Which of the following would most likely help an analyst properly triage the ticket?
A. Incident response plan
B. Lessons learned
C. Playbook
D. Tabletop exercise
Show Answer
Correct Answer: C
Explanation: A playbook provides incident-specific, step-by-step procedures for handling and triaging a particular type of security event, such as ransomware. It guides initial assessment, classification, containment, escalation, and response actions. An incident response plan is broader and defines overall processes and roles, lessons learned occur after the incident, and a tabletop exercise is a training activity rather than an operational triage resource.
$19
Get all 534 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.