A security team needs to demonstrate how prepared the team is in the event of a cyberattack. Which of the following would best demonstrate a real-world incident without impacting operations?
A. Review lessons-learned documentation and create a playbook.
B. Gather all internal incident response party members and perform a simulation.
C. Deploy known malware and document the remediation process.
D. Schedule a system recovery to the DR site for a few applications.
Show Answer
Correct Answer: B
Explanation: A simulation (tabletop or functional exercise) lets the incident response team practice roles, communication, decision-making, and procedures in a realistic scenario without disrupting production systems. It best demonstrates real-world preparedness while avoiding operational impact.
Question 197
Which of the following best describes the importance of KPIs in an incident response exercise?
A. To identify the personal performance of each analyst
B. To describe how incidents were resolved
C. To reveal what the team needs to prioritize
D. To expose which tools should be used
Show Answer
Correct Answer: C
Explanation: KPIs in an incident response exercise are used to highlight strengths and gaps in the team’s performance so leadership can understand what areas require attention and improvement. They guide prioritization (e.g., detection speed, response effectiveness, containment) rather than documenting resolutions, evaluating individuals, or selecting tools.
Question 198
Which of the following in the digital forensics process is considered a critical activity that often includes a graphical representation of process and operating system events?
A. Registry editing
B. Network mapping
C. Timeline analysis
D. Write blocking
Show Answer
Correct Answer: C
Explanation: Timeline analysis is a core digital forensics activity focused on reconstructing and correlating events over time using logs, timestamps, and system artifacts. It commonly uses graphical timelines or event charts to visualize process and operating system activity. The other options do not center on event reconstruction or graphical timelines.
Question 199
Exploit code for a recently disclosed critical software vulnerability was publicly available for download for several days before being removed. Which of the following CVSS v.3.1 temporal metrics was most impacted by this exposure?
A. Remediation level
B. Exploit code maturity
C. Report confidence
D. Availability
Show Answer
Correct Answer: B
Explanation: The public availability of working exploit code directly affects the CVSS v3.1 temporal metric Exploit Code Maturity, which measures how developed and accessible exploit code is. Publicly downloadable exploit code indicates higher maturity, increasing the risk of exploitation.
Question 200
While reviewing the web server logs, a security analyst notices the following snippet:
..\../..\../boot.ini
Which of the following is being attempted?
A. Directory traversal
B. Remote file inclusion
C. Cross-site scripting
D. Remote code execution
E. Enumeration of /etc/passwd
Show Answer
Correct Answer: A
Explanation: The path string "..\../..\../boot.ini" uses parent-directory references (..\) to move up the directory hierarchy and attempt access to a sensitive system file outside the web root. This is the classic pattern of a directory (path) traversal attack, not file inclusion, XSS, code execution, or enumeration of /etc/passwd.
Question 201
A security analyst has found a moderate-risk item in an organization’s point-of-sale application. The organization is currently in a change freeze window and has decided that the risk is not high enough to correct at this time. Which of the following inhibitors to remediation does this scenario illustrate?
A. Service-level agreement
B. Business process interruption
C. Degrading functionality
D. Proprietary system
Show Answer
Correct Answer: B
Explanation: The scenario describes a change freeze window, meaning changes are intentionally restricted to avoid disrupting operations. Remediating the moderate-risk issue now would interrupt normal business processes, which is why the organization defers the fix. This directly illustrates business process interruption as an inhibitor to remediation.
Question 202
An organization has tracked several incidents that are listed in the following table:
Which of the following is the organization’s MTTD?
A. 140
B. 150
C. 160
D. 180
Show Answer
Correct Answer: C
Explanation: MTTD (Mean Time to Detect) is calculated by averaging the detection times for all incidents. The detection times are 180, 150, 170, and 140 minutes. Their sum is 640 minutes, and dividing by 4 incidents gives 160 minutes.
Question 203
During the rollout of a patch to the production environment, it was discovered that required connections to remote systems are no longer possible. Which of the following steps would have most likely revealed this gap?
A. Implementation
B. User acceptance testing
C. Validation
D. Rollback
Show Answer
Correct Answer: C
Explanation: Validation is the phase where a patch is tested in a controlled, production-like environment to ensure it works as intended and does not break existing functionality. Connectivity to required remote systems is a technical integration requirement that would be explicitly checked during validation, making this step the most likely to reveal the gap before full production rollout.
Question 204
Due to an incident involving company devices, an incident responder needs to take a mobile phone to the lab for further investigation. Which of the following tools should be used to maintain the integrity of the mobile phone while it is transported? (Choose two.)
A. Signal-shielded bag
B. Tamper-evident seal
C. Thumb drive
D. Crime scene tape
E. Write blocker
F. Drive duplicator
Show Answer
Correct Answer: A, B
Explanation: A signal-shielded (Faraday) bag prevents the mobile phone from sending or receiving signals during transport, protecting it from remote access, tracking, or remote wiping that could alter evidence. A tamper-evident seal provides visible proof if the device or its container has been accessed or altered during transport, preserving chain of custody and evidentiary integrity.
Question 205
Before adopting a disaster recovery plan, some team members need to gather in a room to review the written scenarios. Which of the following best describes what the team is doing?
A. Simulation
B. Tabletop exercise
C. Full test
D. Parallel test
Show Answer
Correct Answer: B
Explanation: Reviewing written disaster scenarios together in a room, discussing actions and decisions without actually running systems or operations, is a tabletop exercise. It is discussion-based and low impact, unlike simulations, full tests, or parallel tests, which involve operational execution.
$19
Get all 528 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.