Which of the following is a circumstance in which a security operations manager would most likely consider using automation?
A. The generation of NIDS rules based on received STIX messages
B. The fulfillment of privileged access requests to enterprise domain controllers.
C. The verification of employee identities prior to initial PKI enrollment
D. The analysis of suspected malware binaries captured by an email gateway
Show Answer
Correct Answer: A
Explanation: Automation is most appropriate for high-volume, repeatable, data-driven tasks with low need for human judgment. Automatically generating or updating NIDS rules from STIX threat intelligence feeds fits this perfectly, as indicators can be programmatically parsed and applied to defenses in near real time. The other options involve sensitive access approval, identity verification, or complex malware analysis, all of which typically require human oversight and judgment rather than full automation.
Question 117
A threat intelligence analyst is updating a document according to the MITRE ATT&CK framework. The analyst detects the following behavior from a malicious actor:
“The malicious actor will attempt to achieve unauthorized access to the vulnerable system.”
In which of the following phases should the analyst include the detection?
A. Procedures
B. Techniques
C. Tactics
D. Subtechniques
Show Answer
Correct Answer: C
Explanation: In the MITRE ATT&CK framework, tactics describe the adversary’s high-level goals or objectives. The behavior described—attempting to achieve unauthorized access—reflects an objective (e.g., Initial Access), which maps to a tactic. Techniques and subtechniques would specify how access is gained, and procedures are adversary-specific implementations.
Question 118
Which of the following is the best framework for assessing how attackers use techniques over an infrastructure to exploit a target’s information assets?
A. Structured Threat Information Expression
B. OWASP Testing Guide
C. Open Source Security Testing Methodology Manual
D. Diamond Model of Intrusion Analysis
Show Answer
Correct Answer: D
Explanation: The Diamond Model of Intrusion Analysis is specifically designed to analyze how adversaries use capabilities and infrastructure to exploit targets. It models intrusions through four core elements—adversary, infrastructure, capability, and victim—making it the best framework for assessing attacker techniques over infrastructure against information assets. The other options are standards or testing guides, not analytical intrusion frameworks.
Question 119
A company classifies security groups by risk level. Any group with a high-risk classification requires multiple levels of approval for member or owner changes. Which of the following inhibitors to remediation is the company utilizing?
A. Organizational governance
B. MOU
C. SLA
D. Business process interruption
Show Answer
Correct Answer: A
Explanation: Requiring multiple layers of approval for changes to high-risk security groups reflects organizational governance. Governance structures define policies, oversight, and approval hierarchies that control how remediation actions are performed, and these controls can slow or inhibit rapid remediation.
Question 120
An analyst has discovered the following suspicious command:
"; $xyz = ($_REQUEST['xyz']); system($xyz); echo ""; die; }?>
Which of the following would best describe the outcome of the command?
A. Cross-site scripting
B. Reverse shell
C. Backdoor attempt
D. Logic bomb
Show Answer
Correct Answer: C
Explanation: The PHP snippet takes user-supplied input from an HTTP request parameter and passes it directly to system(), allowing arbitrary command execution on the server. This behavior is characteristic of a remote command execution backdoor that an attacker can invoke at will, not XSS, a reverse shell, or a logic bomb.
Question 121
Which of the following is the most likely reason for an organization to assign different internal departmental groups during the post-incident analysis and improvement process?
A. To expose flaws in the incident management process related to specific work areas
B. To ensure all staff members get exposure to the review process and can provide feedback
C. To verify that the organization playbook was properly followed throughout the incident
D. To allow cross-training for staff who are not involved in the incident response process
Show Answer
Correct Answer: A
Explanation: Assigning different internal departmental groups in the post-incident analysis is primarily intended to uncover weaknesses or gaps specific to each functional area. Diverse perspectives help identify process flaws tied to particular work areas, leading to more effective, targeted improvements in the overall incident management process. The other options may be secondary benefits but are not the main reason.
Question 122
A security analyst is assisting a software engineer with the development of a custom log collection and alerting tool (SIEM) for a proprietary system. The analyst is concerned that the tool will not detect known attacks and behavioral IoCs. Which of the following should be configured in order to resolve this issue?
A. Randomly generate and store all possible file hash values.
B. Create a default rule to alert on any change to the system.
C. Integrate with an open-source threat intelligence feed.
D. Manually add known threat signatures into the tool.
Show Answer
Correct Answer: C
Explanation: To detect known attacks and behavioral indicators of compromise, the SIEM needs up‑to‑date knowledge of attacker tools, techniques, and signatures. Integrating an open‑source threat intelligence feed provides continuously updated IoCs (hashes, IPs, domains, TTPs) that the tool can use for detection. Random hash generation is meaningless, alerting on any change would be noisy, and manually adding signatures is inefficient and not scalable.
Question 123
An auditor is reviewing an evidence log associated with a cyber crime. The auditor notices that a gap exists between individuals who were responsible for holding onto and transferring the evidence between individuals responsible for the investigation. Which of the following best describes the evidence handling process that was not property followed?
A. Validating data integrity
B. Preservation
C. Legal hold
D. Chain of custody
Show Answer
Correct Answer: D
Explanation: A documented gap between individuals handling and transferring evidence indicates a breakdown in tracking who possessed the evidence at each point in time. This process is known as the chain of custody, which ensures continuous accountability and integrity of evidence from collection through investigation and potential legal proceedings.
Question 124
A company is in the middle of an incident, and customer data has been breached. Which of the following should the company contact first?
A. Media
B. Public relations
C. Law enforcement
D. Legal
Show Answer
Correct Answer: D
Explanation: In a data breach, the company should contact Legal first. Legal counsel determines regulatory and notification obligations, preserves attorney-client privilege, manages liability and evidence handling, and coordinates when and how to involve law enforcement, public relations, regulators, and customers. Contacting others prematurely can create legal risk.
Question 125
Which of the following is the best reason to implement an MOU?
A. To create a business process for configuration management
B. To allow internal departments to understand security responsibilities
C. To allow an expectation process to be defined for legacy systems
D. To ensure that all metrics on service levels are properly reported
Show Answer
Correct Answer: B
Explanation: An MOU is used to formally document mutual understanding between parties, including roles, responsibilities, and expectations. Among the options, allowing internal departments to understand and agree on security responsibilities best reflects the purpose of an MOU. The other options relate to specific operational processes (configuration management, legacy system expectations, or service-level metrics) that are more appropriate for policies, procedures, SLAs, or OLAs rather than an MOU.
$19
Get all 528 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.