A vulnerability scan of a web server that is exposed to the internet was recently completed. A security analyst is reviewing the resulting vector strings:
Which of the following vulnerabilities should be patched first?
A. Vulnerability 1
B. Vulnerability 2
C. Vulnerability 3
D. Vulnerability 4
Show Answer
Correct Answer: A
Explanation: Based on the available information, the full CVSS vector strings are not included, so a definitive comparison is not possible. If Vulnerability 1 is the one with a Network Attack Vector (AV:N) and the highest overall impact/severity among the listed vectors, it should be prioritized because internet-exposed, remotely exploitable vulnerabilities generally present the greatest immediate risk.
Question 242
When undertaking a cloud migration of multiple SaaS applications, an organization’s systems administrators struggled with the complexity of extending identity and access management to cloud-based assets. Which of the following service models would have reduced the complexity of this project?
A. OpenID
B. SASE
C. ZTNA
D. SWG
Show Answer
Correct Answer: A
Explanation: OpenID (in practice, OpenID Connect) provides federated identity and single sign-on across multiple SaaS applications, reducing the complexity of extending identity and access management to cloud-based assets. SASE, ZTNA, and SWG are security/network access models or services, but they do not primarily solve federated IAM across multiple SaaS applications.
Question 243
After a recent vulnerability report for a server is presented, a business must decide whether to secure the company’s web-based storefront or shut it down. The developer is not able to fix the zero-day vulnerability because a patch does not exist yet. Which of the following is the best option for the business?
A. Limit the API request for new transactions until a patch exists.
B. Take the storefront offline until a patch exists.
C. Identify the degrading functionality.
D. Put a WAF in front of the storefront.
Show Answer
Correct Answer: D
Explanation: A Web Application Firewall (WAF) is the best compensating control when a zero-day vulnerability affecting a web application cannot yet be patched. It can provide virtual patching by filtering and blocking malicious HTTP/S requests, reducing exploitability while allowing the storefront to remain available. Taking the site offline sacrifices business operations, while rate limiting API requests is too narrow and may not mitigate the vulnerability. Identifying degrading functionality is part of assessment, not an effective immediate mitigation.
Question 244
A vulnerability analyst is writing a report documenting the newest, most critical vulnerabilities identified in the past month. Which of the following public MITRE repositories would be best to review?
A. Cyber Threat Intelligence
B. Common Vulnerabilities and Exposures
C. Cyber Analytics Repository
D. ATT&CK
Show Answer
Correct Answer: B
Explanation: The best MITRE repository for reviewing newly identified public vulnerabilities is Common Vulnerabilities and Exposures (CVE). CVE provides standardized identifiers and descriptions for publicly disclosed vulnerabilities, making it the primary source for tracking recent critical vulnerabilities. ATT&CK catalogs adversary tactics and techniques rather than vulnerability disclosures, Cyber Threat Intelligence is not the MITRE repository for vulnerability listings, and the Cyber Analytics Repository focuses on detection analytics, not vulnerability tracking.
Question 245
Each time a vulnerability assessment team shares the regular report with other teams, inconsistencies regarding versions and patches in the existing infrastructure are discovered. Which of the following is the best solution to decrease the inconsistencies?
A. Implementing credentialed scanning
B. Changing from a passive to an active scanning approach
C. Implementing a central place to manage IT assets
D. Performing agentless scanning
Show Answer
Correct Answer: A
Explanation: Credentialed scanning queries systems with authenticated access, providing authoritative information about installed software versions and patch levels. This reduces inconsistencies in reports about versions and patches that can occur with unauthenticated or passive techniques. A centralized asset inventory is valuable for asset management, but it does not by itself verify the actual installed versions and patch state on endpoints.
Question 246
A SOC receives several alerts indicating user accounts are connecting to the company’s identity provider through non-secure communications. User credentials for accessing sensitive, business-critical systems could be exposed. Which of the following logs should the SOC use when determining malicious intent?
A. DNS
B. tcpdump
C. Directory
D. IDS
Show Answer
Correct Answer: D
Explanation: The key part of the question is determining malicious intent after alerts about insecure communications to the identity provider. IDS logs are specifically intended to identify suspicious or malicious network behavior and correlate indicators of compromise. While a packet capture (tcpdump) can show credentials traversing an unencrypted connection, it does not by itself indicate malicious intent. Directory logs focus on authentication events, and DNS logs on name resolution, neither being the best source for assessing malicious intent in network activity.
Question 247
A security team needs to demonstrate how prepared the team is in the event of a cyberattack. Which of the following would best demonstrate a real-world incident without impacting operations?
A. Review lessons-learned documentation and create a playbook.
B. Gather all internal incident response party members and perform a simulation.
C. Deploy known malware and document the remediation process.
D. Schedule a system recovery to the DR site for a few applications.
Show Answer
Correct Answer: B
Explanation: A simulation (such as a tabletop or incident response exercise) is the best way to demonstrate real-world cyberattack preparedness without affecting production operations. It tests communication, coordination, decision-making, and incident response procedures in a controlled environment. Reviewing documentation alone does not validate readiness, deploying real malware risks operational impact, and failing over to a DR site tests disaster recovery rather than cyber incident response.
Question 248
Which of the following best describes the importance of KPIs in an incident response exercise?
A. To identify the personal performance of each analyst
B. To describe how incidents were resolved
C. To reveal what the team needs to prioritize
D. To expose which tools should be used
Show Answer
Correct Answer: C
Explanation: KPIs (Key Performance Indicators) in an incident response exercise measure operational effectiveness, such as detection, response, containment, and recovery times. Their purpose is to highlight performance trends and gaps so the team can identify improvement areas and prioritize future efforts. They are not primarily used to evaluate individual analysts, document incident resolution, or determine which tools should be used.
Question 249
Which of the following in the digital forensics process is considered a critical activity that often includes a graphical representation of process and operating system events?
A. Registry editing
B. Network mapping
C. Timeline analysis
D. Write blocking
Show Answer
Correct Answer: C
Explanation: Timeline analysis is a core digital forensics activity that reconstructs and correlates events over time using timestamps, logs, process activity, and operating system artifacts. Investigators commonly use graphical timelines to visualize the sequence of process and OS events. The other options are distinct forensic tasks or tools and do not describe this analytical activity.
Question 250
Exploit code for a recently disclosed critical software vulnerability was publicly available for download for several days before being removed. Which of the following CVSS v.3.1 temporal metrics was most impacted by this exposure?
A. Remediation level
B. Exploit code maturity
C. Report confidence
D. Availability
Show Answer
Correct Answer: B
Explanation: The CVSS v3.1 Temporal metric most affected is Exploit Code Maturity (E), which measures the availability and sophistication of exploit techniques or code. Publicly available exploit code increases this metric. Remediation Level concerns the availability of fixes, Report Confidence concerns confidence in the existence of the vulnerability, and Availability is a Base metric impact, not the Temporal metric described.
$19
Get all 534 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.