A security analyst is assessing the security of a cloud environment. The following output is generated when the assessment runs:
Authentication error -
Instance not found on preset location
Which of the following should the analyst use to fix the issue?
A. run module_name and exec
B. --session and --module-args=" "
C. set_regions and set_key
D. --whoami and --data
Show Answer
Correct Answer: C
Explanation: The error indicates both an authentication problem and an incorrect or missing region configuration. Cloud tools commonly require explicit configuration of access credentials (keys) and the target region where the instance resides. Using set_key resolves the authentication error, and set_regions ensures the tool looks for the instance in the correct location, fixing the combined error message.
Question 16
To comply with regulatory requirements, the Chief Executive Officer (CEO) must lead the company through simulations to find which steps are missing m emergency situations or incident processes. Which of the following should the CEO do?
A. Implement the incident response plan.
B. Leverage the appropriate playbook.
C. Develop a business continuity plan.
D. Perform a tabletop exercise.
Show Answer
Correct Answer: D
Explanation: The question asks about leading simulations to identify missing steps in emergency or incident processes. A tabletop exercise is specifically designed for this purpose: it is a discussion-based simulation where executives and key stakeholders walk through hypothetical scenarios to uncover gaps in procedures, roles, communication, and decision-making. Implementing a plan, leveraging a playbook, or developing a business continuity plan do not themselves simulate scenarios to find missing steps.
Question 17
A security analyst is looking for information that would serve as an indicator that a given IP address is Involved in other attacks. Which of the following sources of information should the analyst use to achieve this objective?
A. AbuseIPDB
B. Autonomous System Number
C. Whois
D. Cuckoo Sandbox
Show Answer
Correct Answer: A
Explanation: The analyst wants an indicator of whether an IP address has been involved in other attacks. AbuseIPDB is a threat intelligence database that aggregates community reports and reputation data about malicious IP addresses, directly addressing this need. ASN, Whois, and Cuckoo Sandbox provide ownership, registration, or malware analysis information, not direct evidence of prior malicious activity by an IP.
Question 17
An incident responder is investigating a possible server data exfiltration incident with the intent to prosecute if necessary. The responder:
• Captures live memory and an image of the drives.
• Is given a copy of the firewall logs.
• Pulls the drives from the server.
Which of the following would most likely create an issue?
A. Lack of network capture
B. Chain of custody failure
C. Corrupt drives
D. Encrypted files
Show Answer
Correct Answer: B
Explanation: Because the responder intends to prosecute, legal admissibility is critical. The actions described (capturing memory, imaging drives, receiving copied firewall logs, and pulling drives) raise the highest risk of a chain of custody failure—especially being "given a copy" of logs rather than collecting them directly with documented handling. Without a properly documented chain of custody, evidence can be challenged or excluded in court, making prosecution difficult. The other options are technical obstacles, not legal showstoppers.
Question 18
Which of the following is the best technical method to protect sensitive data at an organizational level?
A. Deny all traffic on port 8080 with sensitive information on the VLAN.
B. Develop a Python script to review email traffic for PII.
C. Employ a restrictive policy for the use and distribution of sensitive information.
D. Implement a DLP for all egress and ingress of sensitive information on the network.
Show Answer
Correct Answer: D
Explanation: The question asks for the best *technical* method at an organizational level. A Data Loss Prevention (DLP) solution is specifically designed to technically control, monitor, and prevent unauthorized transmission of sensitive data across the organization, covering network egress/ingress, endpoints, and sometimes data at rest. Option C is administrative, not technical. Options A and B are narrow and insufficient controls. Therefore, D is the best answer.
Question 18
A company discovers that its proprietary information is being sold on the dark web. A security analyst uses threat hunting to search for signs of compromise. After running a network packet capture tool, the analyst identifies millions of packets similar to the following:
The analyst does not detect or identify any other abnormalities. Which of the following is most likely the malicious activity in this scenario?
A. An insider is using an IP command-and-control to sell proprietary information.
B. A threat actor is performing exfiltration over an alternative protocol.
C. A machine was infected with a virus that is trying to propagate.
D. A hacktivist is conducting an ICMP DDoS attack against the company.
Show Answer
Correct Answer: B
Explanation: Large volumes of otherwise normal-looking packets (e.g., ICMP) with no other anomalies commonly indicate data being covertly exfiltrated using a nonstandard or alternative protocol to bypass detection. This aligns with proprietary data appearing on the dark web without other signs of malware propagation or DDoS activity.
Question 19
A DevOps analyst implements a webhook to trigger code vulnerability scanning for submissions to the repository. Which of the following is the primary benefit of this enhancement?
A. To increase coverage by making the process occur automatically with uploads
B. To create a single pane of glass dashboard for the vulnerability management process
C. To include a threat feed component into the software development life cycle
D. To employ data enrichment for new code commits to enhance project documentation
Show Answer
Correct Answer: A
Explanation: A webhook triggers actions automatically when an event (such as a code commit or submission) occurs. Integrating it to launch vulnerability scanning ensures scans run automatically with each upload, increasing coverage and consistency without manual intervention. The other options describe capabilities (dashboards, threat feeds, documentation enrichment) that are not the primary function of a webhook-triggered scan.
Question 19
A security analyst is implementing a process to perform vulnerability management on an ОТ environment:
• Systems must remain on an isolated network.
• The process should focus on external threats.
• No additional software can be deployed on the systems.
• Transmitted packets cannot be modified or dropped.
• Additional processing delays are not tolerated.
Which of the following is the best way to securely meet the requirements?
A. Implement agentless sensors at the network edge.
B. Use reverse engineering to detect flaws on the in-scope systems.
C. Deploy an IPS In-line with the network traffic.
D. Check the compatibility of an EDR agent with the OSs used on the ОТ environment.
Show Answer
Correct Answer: A
Explanation: Agentless sensors deployed at the network edge can passively monitor traffic without installing software on OT systems, modifying or dropping packets, or introducing latency. This approach supports isolated networks and focuses on detecting external threats, making it the best fit for sensitive OT environments.
Question 20
The DevSecOps team is remediating an SSRF issue on the company's public-facing website. Which of the following is the best mitigation technique to address this issue?
A. Place a WAF in front of the web server.
B. Install a CASB in front of the web server
C. Put a forward proxy in front of the web server.
D. Implement MFA in front of the web server
Show Answer
Correct Answer: A
Explanation: SSRF exploits malicious inbound HTTP requests to coerce the server into making unintended internal or external requests. A Web Application Firewall (WAF) can detect and block common SSRF patterns (e.g., suspicious URLs, IP ranges like localhost or metadata services) before requests reach the application. CASB, forward proxies, and MFA do not directly mitigate inbound SSRF attack vectors.
Question 20
A security analyst receives the following information about the company's systems. They need to prioritize which systems should be given the resources to improve security.
Which of the following systems should the analyst remediate first?
A. Computer1
B. Server1
C. Computer2
D. Server2
Show Answer
Correct Answer: B
Explanation: Server1 is running an end-of-life operating system (Windows Server 2008 R2), which no longer receives security patches. This presents a critical, systemic risk that cannot be mitigated without remediation, making it a higher priority than systems with misconfigurations or outdated applications that can still be patched or secured.
$19
Get all 528 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.