Which of the following is a benefit of the Diamond Model of Intrusion Analysis?
A. It provides analytical pivoting and identifies knowledge gaps.
B. It guarantees that the discovered vulnerability will not be exploited again in the future.
C. It provides concise evidence that can be used in court.
D. It allows for proactive detection and analysis of attack events.
Show Answer
Correct Answer: A
Explanation: The Diamond Model of Intrusion Analysis is designed to help analysts understand relationships between adversary, victim, infrastructure, and capability. A key benefit is analytical pivoting—moving between these elements to uncover related activity—and identifying knowledge gaps that guide further investigation. The other options describe guarantees or outcomes (prevention, legal evidence, proactive detection) that the model itself does not inherently provide.
Question 187
An analyst is imaging a hard drive that was obtained from the system of an employee who is suspected of going rogue. The analyst notes that the initial hash of the evidence drive does not match the resultant hash of the imaged copy. Which of the following best describes the reason for the conflicting investigative findings?
A. Chain of custody was not maintained for the evidence drive.
B. Legal authorization was not obtained prior to seizing the evidence drive.
C. Data integrity of the imaged drive could not be verified.
D. Evidence drive imaging was performed without a write blocker.
Show Answer
Correct Answer: D
Explanation: A mismatch between the original drive hash and the image hash indicates the source media was altered during acquisition. This most commonly occurs when imaging is performed without a write blocker, allowing the system to write to the evidence drive and change its contents, invalidating hash verification.
Question 188
When investigating a potentially compromised host, an analyst observes that the process BGInfo.exe (PID 1024), a Sysinternals tool used to create desktop backgrounds containing host details, has been running for over two days. Which of the following activities will provide the best insight into this potentially malicious process, based on the anomalous behavior?
A. Changes to system environment variables
B. SMB network traffic related to the system process
C. Recent browser history of the primary user
D. Activities taken by PID 1024
Show Answer
Correct Answer: D
Explanation: BGInfo.exe is a legitimate Sysinternals tool that normally runs briefly. Its execution for multiple days is anomalous and could indicate misuse, persistence, or process replacement. The most effective way to assess this risk is to directly analyze the actions of PID 1024 itself—such as spawned child processes, file and registry modifications, network connections, injected code, and command-line arguments. These behaviors provide direct evidence of malicious activity, whereas environment variables, SMB traffic, or browser history are indirect and less relevant to this specific anomaly.
Question 189
Which of the following attributes is part of the Diamond Model of Intrusion Analysis?
A. Delivery
B. Weaponization
C. Command and control
D. Capability
Show Answer
Correct Answer: D
Explanation: The Diamond Model of Intrusion Analysis defines four core attributes: Adversary, Capability, Infrastructure, and Victim. Among the options given, only Capability is one of these attributes; Delivery, Weaponization, and Command and Control belong to other models such as the Cyber Kill Chain.
Question 190
A vulnerability scan of a web server that is exposed to the internet was recently completed. A security analyst is reviewing the resulting vector strings:
Which of the following vulnerabilities should be patched first?
A. Vulnerability 1
B. Vulnerability 2
C. Vulnerability 3
D. Vulnerability 4
Show Answer
Correct Answer: A
Explanation: Vulnerabilities that are remotely exploitable over the network and have a high impact on confidentiality present the greatest immediate risk, especially on an internet-facing web server. Such flaws can be exploited without local access and can lead to significant data exposure, so Vulnerability 1 should be patched first.
Question 191
When undertaking a cloud migration of multiple SaaS applications, an organization’s systems administrators struggled with the complexity of extending identity and access management to cloud-based assets. Which of the following service models would have reduced the complexity of this project?
A. OpenID
B. SASE
C. ZTNA
D. SWG
Show Answer
Correct Answer: A
Explanation: The core challenge described is the complexity of extending identity and access management across multiple SaaS applications. Federated identity directly addresses this problem. OpenID (commonly implemented today as OpenID Connect) allows organizations to centralize authentication through a single identity provider and enable single sign-on across many cloud-based SaaS services. This significantly reduces administrative overhead and integration complexity.
SASE, ZTNA, and SWG are security architectures or controls focused on network access and traffic enforcement. While they may consume identity signals, they do not themselves simplify or replace SaaS authentication and identity federation. Therefore, OpenID is the best answer.
Question 192
After a recent vulnerability report for a server is presented, a business must decide whether to secure the company’s web-based storefront or shut it down. The developer is not able to fix the zero-day vulnerability because a patch does not exist yet. Which of the following is the best option for the business?
A. Limit the API request for new transactions until a patch exists.
B. Take the storefront offline until a patch exists.
C. Identify the degrading functionality.
D. Put a WAF in front of the storefront.
Show Answer
Correct Answer: D
Explanation: When a zero-day vulnerability has no available patch, the best risk-based mitigation is to reduce exposure while maintaining business operations. Placing a Web Application Firewall (WAF) in front of the storefront can inspect, filter, and block malicious traffic and exploit attempts targeting the vulnerability. This provides compensating controls without shutting down the storefront. Taking the site offline is a last resort, and limiting API requests or identifying degrading functionality does not adequately mitigate exploitation risk.
Question 193
A vulnerability analyst is writing a report documenting the newest, most critical vulnerabilities identified in the past month. Which of the following public MITRE repositories would be best to review?
A. Cyber Threat Intelligence
B. Common Vulnerabilities and Exposures
C. Cyber Analytics Repository
D. ATT&CK
Show Answer
Correct Answer: B
Explanation: MITRE’s Common Vulnerabilities and Exposures (CVE) repository is the authoritative public database for newly disclosed security vulnerabilities, providing standardized identifiers and descriptions. It is the primary resource for reviewing the most recent and critical vulnerabilities identified within a given time period.
Question 194
Each time a vulnerability assessment team shares the regular report with other teams, inconsistencies regarding versions and patches in the existing infrastructure are discovered. Which of the following is the best solution to decrease the inconsistencies?
A. Implementing credentialed scanning
B. Changing from a passive to an active scanning approach
C. Implementing a central place to manage IT assets
D. Performing agentless scanning
Show Answer
Correct Answer: C
Explanation: The problem is recurring inconsistencies in reported versions and patch levels across teams, which points to a lack of a single authoritative inventory. Implementing a centralized IT asset management system provides a single source of truth for asset versions, patch status, and configurations, reducing discrepancies between reports. Credentialed, active, or agentless scanning can improve scan accuracy, but they do not solve cross-team inconsistencies caused by fragmented or unmanaged asset data.
Question 195
A SOC receives several alerts indicating user accounts are connecting to the company’s identity provider through non-secure communications. User credentials for accessing sensitive, business-critical systems could be exposed. Which of the following logs should the SOC use when determining malicious intent?
A. DNS
B. tcpdump
C. Directory
D. IDS
Show Answer
Correct Answer: D
Explanation: The SOC is trying to determine *malicious intent* related to users connecting to an identity provider over non-secure communications. IDS logs are specifically designed to analyze network traffic and flag suspicious or policy-violating behavior, such as cleartext authentication, downgrade attacks, or known attack signatures. While tcpdump can capture raw traffic, it requires manual analysis and is not a log source typically used first by a SOC to assess intent. Directory logs focus on authentication outcomes, not network security posture, and DNS logs only show name resolution. Therefore, IDS logs are the most appropriate source for identifying malicious intent in this scenario.
$19
Get all 528 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.