An employee received a phishing email that contained malware targeting the company. Which of the following is the best way for a security analyst to get more details about the malware and avoid disclosing information?
A. Upload the malware to the VirusTotal website.
B. Share the malware with the EDR provider.
C. Hire an external consultant to perform the analysis.
D. Use a local sandbox in a microsegmented environment.
Show Answer
Correct Answer: D
Explanation: The requirement is to analyze the malware in depth while avoiding disclosure of sensitive information. Uploading to VirusTotal or sharing with third parties (EDR provider or consultant) exposes samples and metadata externally. A local sandbox in a microsegmented environment allows safe, controlled malware execution and analysis entirely within the organization, minimizing data leakage risk.
Question 137
Several critical bugs were identified during a vulnerability scan. The SLA risk requirement is that all critical vulnerabilities should be patched within 24 hours. After sending a notification to the asset owners, the patch cannot be deployed due to planned, routine system upgrades. Which of the following is the best method to remediate the bugs?
A. Reschedule the upgrade and deploy the patch.
B. Request an exception to exclude the patch from installation.
C. Update the risk register and request a change to the SLA.
D. Notify the incident response team and rerun the vulnerability scan.
Show Answer
Correct Answer: A
Explanation: The SLA explicitly requires that all critical vulnerabilities be patched within 24 hours. Planned routine upgrades do not override this risk requirement. The most appropriate remediation is to reschedule the upgrade so the critical patches can be deployed immediately and the SLA met. Requesting exceptions, changing the SLA, or involving incident response does not remediate the vulnerabilities in the required timeframe.
Question 138
Which of the following will most likely cause severe issues with authentication and logging?
A. Virtualization
B. Multifactor authentication
C. Federation
D. Time synchronization
Show Answer
Correct Answer: D
Explanation: Time synchronization is critical for both authentication and logging. Authentication systems like Kerberos rely on closely synchronized clocks to validate time-bound tickets and prevent replay attacks; clock skew can cause widespread login failures. Unsynchronized timestamps also break log correlation, making event timelines inaccurate or unusable during troubleshooting and incident response.
Question 139
A manufacturing company’s assembly line machinery only functions on an end-of-life OS. Consequently, no patches exist for several highly exploitable OS vulnerabilities. Which of the following is the best mitigating control to reduce the risk of these current conditions?
A. Enforce strict network segmentation to isolate vulnerable systems from the production network.
B. Increase the system resources for vulnerable devices to prevent denial of service.
C. Perform penetration testing to verify the exploitability of these vulnerabilities.
D. Develop in-house patches to address these vulnerabilities.
Show Answer
Correct Answer: A
Explanation: When systems must run an end-of-life OS with unpatchable, exploitable vulnerabilities, the most effective risk-reducing control is compensating controls. Strict network segmentation limits exposure and attack paths by isolating the vulnerable machinery from the broader network, reducing the likelihood and impact of compromise. The other options do not reduce exploitability or exposure: adding resources does not address security flaws, penetration testing only identifies issues without mitigating them, and developing in-house patches is typically infeasible and risky for EOL operating systems.
Question 140
An incident responder was able to recover a binary file through the network traffic. The binary file was also found in some machines with anomalous behavior. Which of the following processes most likely can be performed to understand the purpose of the binary file?
A. File debugging
B. Traffic analysis
C. Reverse engineering
D. Machine isolation
Show Answer
Correct Answer: C
Explanation: To understand the purpose and functionality of an unknown binary recovered from network traffic and anomalous hosts, analysts would perform reverse engineering. Reverse engineering involves disassembling or decompiling the binary to analyze its logic, capabilities, and potential malicious behavior. Traffic analysis focuses on network flows, machine isolation is a containment step, and file debugging is aimed at fixing software errors rather than understanding an unknown binary’s intent.
Question 141
A SOC analyst wants to improve the proactive detection of malicious emails before they are delivered to the destination inbox. Which of the following is the best approach the SOC analyst can recommend?
A. Install UEBA software on the network.
B. Validate and quarantine emails with invalid DKIM and SPF headers.
C. Implement an EDR system on each endpoint.
D. Deploy a DLP platform to block unauthorized and suspicious content.
Show Answer
Correct Answer: B
Explanation: The goal is proactive detection of malicious emails before delivery. Validating DKIM and SPF allows the email security gateway to identify spoofed or unauthenticated senders and quarantine those messages early in the mail flow. UEBA, EDR, and DLP focus on user behavior, endpoints, or data protection after delivery rather than preventing malicious emails from reaching inboxes.
Question 142
Which of the following documents sets requirements and metrics for a third-party response during an event?
A. BIA
B. DRP
C. SLA
D. MOU
Show Answer
Correct Answer: C
Explanation: A Service Level Agreement (SLA) defines specific requirements, performance metrics, and response expectations for a third party, including response times and responsibilities during an incident or event. BIA analyzes impact, DRP outlines internal recovery procedures, and an MOU is a high-level agreement without detailed performance metrics.
Question 143
During a tabletop exercise, engineers discovered that an ICS could not be updated due to hardware versioning incompatibility. Which of the following is the most likely cause of this issue?
A. Legacy system
B. Business process interruption
C. Degrading functionality
D. Configuration management
Show Answer
Correct Answer: A
Explanation: Hardware versioning incompatibility preventing updates indicates the system is too old to support newer updates. This is characteristic of a legacy system, not business process issues, general degradation, or configuration management problems.
Question 144
Which of the following most accurately describes the Cyber Kill Chain methodology?
A. It is used to correlate events to ascertain the TTPs of an attacker.
B. It is used to ascertain lateral movements of an attacker, enabling the process to be stopped.
C. It provides a clear model of how an attacker generally operates during an intrusion and the actions to take at each stage.
D. It outlines a clear path for determining the relationships between the attacker, the technology used, and the target.
Show Answer
Correct Answer: C
Explanation: The Cyber Kill Chain is a high-level intrusion model describing the typical stages an attacker follows (e.g., reconnaissance through actions on objectives) and how defenders can disrupt or stop the attack at each stage. Options A, B, and D describe other frameworks or specific activities (event correlation, lateral movement focus, or relationship modeling), not the Kill Chain itself.
Question 145
Following an attack, an analyst needs to provide a summary of the event to the Chief Information Security Officer. The summary needs to include the who-what-when information and evaluate the effectiveness of the plans in place. Which of the following incident management life cycle processes does this describe?
A. Business continuity plan
B. Lessons learned
C. Forensic analysis
D. Incident response plan
Show Answer
Correct Answer: B
Explanation: The activity described occurs after an incident and focuses on summarizing who/what/when and evaluating how effective existing plans and controls were. This aligns with the Lessons Learned phase of the incident management life cycle, which documents the incident, assesses response effectiveness, and identifies improvements. The other options describe plans or technical analysis rather than post-incident evaluation.
$19
Get all 528 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.