A security administrator is tasked with modifying the vulnerability scan process to reduce the network traffic but maintain thorough checks. Which of the following scanning approaches should be implemented?
A. Credentialed scans
B. Individual scans
C. Security baseline scans
D. Agent-based scans
Show Answer
Correct Answer: D
Explanation: Agent-based scans deploy lightweight agents on hosts to perform local vulnerability checks and then report results centrally. This approach minimizes network traffic compared to network-based or credentialed scans while still providing deep, thorough visibility into configurations, patches, and software.
Question 21
The security team is reviewing a list of vulnerabilities present on the environment, and they want to prioritize the remediation based on the CVSS v4.0 metrics:
Which of the following vulnerabilities should the security manager request to fix first?
A. System A
B. System B
C. System C
D. System D
E. System E
Show Answer
Correct Answer: D
Explanation: Under CVSS v4.0, remediation priority is based on the overall severity score driven by exploitability, impact, and supplemental metrics. Among the listed options, System D has the highest CVSS v4.0 risk profile, making it the most critical vulnerability to remediate first.
Question 22
A SOC team lead occasionally collects some DNS information for investigations. The team lead assigns this task to a new junior analyst. Which of the following is the best way to relay the process information to the junior analyst?
A. Ask another team member to demonstrate their process.
B. Email a link to a website that shows someone demonstrating a similar process.
C. Let the junior analyst research and develop a process.
D. Write a step-by-step document on the team wiki outlining the process.
Show Answer
Correct Answer: D
Explanation: Writing a step-by-step document on the team wiki provides clear, standardized, and repeatable guidance. It ensures the junior analyst can follow the exact process consistently, supports knowledge sharing, and serves as ongoing reference documentation for the entire SOC.
Question 22
An application security analyst needs to test a web application for input validation vulnerabilities. The analyst does not have the source code and does not have documentation for the APIs. Which of the following techniques will best aid the analyst in vulnerability testing?
A. Fuzzing operation
B. Agentless scanning
C. Reverse engineering
D. Use of a SAST tool
Show Answer
Correct Answer: A
Explanation: The analyst is performing black-box testing with no source code or API documentation. Fuzzing is specifically designed for this scenario: it sends malformed, unexpected, or random inputs to application interfaces to discover input validation flaws and other weaknesses based solely on observed behavior. SAST requires source code, reverse engineering is unnecessary and inefficient for this goal, and agentless scanning is broader and less focused on systematic input validation testing than fuzzing.
Question 23
Which of the following does a security policy do?
A. Establishes a cost model for security activity
B. Identifies and clarifies security goals and objectives
C. Enables management to define system access rules
D. Allows management to define system recovery requirements
Show Answer
Correct Answer: B
Explanation: A security policy is a high-level management document that states the organization’s security goals, objectives, and overall intent. It provides direction and guidance for security-related decisions. Cost models belong to budgeting, access rules are defined in specific access control policies, and recovery requirements are addressed in disaster recovery or business continuity plans.
Question 23
The website of a large retail chain is falling to enforce encrypted HTTPS connections, leaving customer account credentials exposed. Which of the following is the best corrective action for resolving this issue?
A. Remove any redirect settings of HTTP connections to HTTPS.
B. Implement HTTP Strict Transport Security Headers.
C. Install a self-signed certificate on the web server.
D. Reduce the default timeout period for all web-based sessions.
Show Answer
Correct Answer: B
Explanation: The problem is that the site does not enforce encrypted HTTPS connections, allowing credentials to be exposed over HTTP. HTTP Strict Transport Security (HSTS) instructs browsers to only connect to the site using HTTPS and prevents downgrade and SSL‑stripping attacks, which simple redirects cannot fully stop. The other options do not enforce secure transport: removing redirects worsens security, a self‑signed certificate does not provide trusted encryption, and session timeouts are unrelated to transport security. Therefore, implementing HSTS is the best corrective action.
Question 24
A report contains IoC and TTP information for a zero-day exploit that leverages vulnerabilities in a specific version of a web application. Which of the following actions should a SOC analyst take first after receiving the report?
A. Implement a vulnerability scan to determine whether the environment is at risk.
B. Block the IP addresses and domains from the report in the web proxy and firewalls.
C. Verify whether the information is relevant to the organization.
D. Analyze the web application logs to identify any suspicious or malicious activity.
Show Answer
Correct Answer: C
Explanation: The first priority is to determine whether the reported zero-day exploit is relevant to the organization. A SOC analyst must confirm whether the specific web application and vulnerable version are actually present and exposed in the environment. This scoping step prevents wasted effort and ensures subsequent actions—such as scanning, blocking IoCs, or log analysis—are focused on a real, applicable risk rather than a theoretical one.
Question 24
During a routine review of DNS logs, a security analyst observes that Host X has been making frequent DNS requests to domains with random alphanumeric strings (e.g.. atd8ekthj.xyz). IPS anomaly rules are blocking these domains. This behavior started shortly after a new software Installation on the host. Which of the following should the analyst do first to determine whether Host X has been compromised?
A. Allow the domains because the DNS requests are part of a misconfigured software update.
B. Check the software installation logs for errors and reinstall the software.
C. Block all outbound connections from the host to prevent further DNS queries.
D. Use threat intelligence to check if the queried domains are associated with legitimate sites.
Show Answer
Correct Answer: D
Explanation: Frequent DNS queries to domains with random-looking alphanumeric names are a classic indicator of a Domain Generation Algorithm (DGA) used by malware. The first step is to determine whether these domains are known malicious or benign. Using threat intelligence to check the reputation and associations of the queried domains helps validate whether the behavior is malicious before taking disruptive actions like blocking all traffic or reinstalling software.
Question 25
The Chief Information Security Officer wants the same level of security to be present whether a remote worker logs in at home or at a coffee shop. Which of the following should be recommended as a starting point?
A. Non-persistent virtual desktop infrastructures
B. Passwordless authentication
C. Standard-issue laptops
D. Serverless workloads
Show Answer
Correct Answer: A
Explanation: Non-persistent VDI centralizes the desktop environment and enforces identical security controls regardless of user location. Sessions reset after logout, preventing local data persistence, and allow consistent patching, monitoring, and policy enforcement whether the user connects from home or a public network. The other options improve specific areas but do not ensure uniform end-to-end security across locations.
Question 25
A security analyst is working on a suspicious email forwarded from a user. The email contains an attachment asking the user to open it. Which of the following should the security analyst review to best determine email authentication and its attack origin?
A. DMARC
B. SMTP
C. Joe Sandbox
D. URL rewriting
Show Answer
Correct Answer: A
Explanation: DMARC provides visibility into email authentication results by tying together SPF and DKIM and offering reporting that helps identify whether an email is legitimately sent from a domain or spoofed. Reviewing DMARC information best determines email authentication status and helps infer the attack’s origin. The other options do not focus on authentication or origin determination.
$19
Get all 528 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.