A company wants to implement protection mechanisms after an incident in which customer information was sent to a third party. Which of the following tools should the company implement?
A. SIEM
B. EDR
C. CASB
D. DLP
Show Answer
Correct Answer: D
Explanation: Data Loss Prevention (DLP) is designed to monitor, detect, and prevent unauthorized transmission of sensitive information such as customer data to external parties. SIEM focuses on log aggregation and security monitoring, EDR protects endpoints by detecting and responding to endpoint threats, and CASB governs security for cloud service usage but is not the primary control for preventing data exfiltration across channels.
Question 42
A security analyst investigates a malware alert from a critical system. The following information is present in the ticket:
Which of the following should the analyst do first?
A. Block the suspicious IP address 128.210.175.23.
B. Determine whether sssh is a malicious program.
C. Delete the suspicious files.
D. Review the Apache logs.
Show Answer
Correct Answer: B
Explanation: The first step is to validate the alert before taking containment or remediation actions. A process named 'sssh' may be a masquerading or typosquatted binary, but it should first be verified as malicious. Blocking an IP, deleting files, or reviewing specific logs are subsequent investigative or response actions once the suspicious process has been assessed.
Question 43
A SOC manager who recently switched companies notices that their new company's SOC analysts have significantly poorer operational metrics compared to their previous company, without any major difference in alert volume or team size. Which of the following are most likely to be the cause? (Choose two.)
A. Use of OSSTMM
B. Integration of webhooks
C. Lack of SOAR implementation
D. Absence of single pane of glass
E. Morale issues among SOC staff
F. Usage of API gateways
Show Answer
Correct Answer: C, D
Explanation: Poorer SOC operational metrics with similar alert volume and staffing most strongly point to inefficient workflows and tooling. A lack of SOAR reduces automation, increasing manual triage and response time. The absence of a single pane of glass forces analysts to switch between multiple tools, slowing investigations and reducing efficiency. OSSTMM and API gateways are not primary drivers of SOC operational metrics in this context, and while morale can affect performance, the scenario most directly indicates process/tooling differences.
Question 44
Which of the following best explains the importance of utilizing an incident response playbook?
A. It prioritizes the business-critical assets for data recovery.
B. It establishes actions to execute when inputs trigger an event.
C. It documents the organization asset management and configuration.
D. It defines how many disaster recovery sites should be staged.
Show Answer
Correct Answer: B
Explanation: An incident response playbook provides predefined, step-by-step actions to take when specific events or triggers occur, ensuring a consistent, coordinated, and efficient response. The other options describe disaster recovery planning, asset management, or business continuity activities rather than the purpose of an incident response playbook.
Question 45
Which of the following best describes root cause analysis?
A. It describes the tactics, techniques, and procedures used in an incident.
B. It provides a detailed path outlining the origin of an issue and how to eliminate it permanently.
C. It outlines the who-what-when-where-why, which is often used in conjunction with legal proceedings.
D. It generates a report of ongoing activities, including what was done, what is being done, and what will be done next.
Show Answer
Correct Answer: B
Explanation: Root cause analysis (RCA) is a systematic process for identifying the underlying cause of a problem or incident and determining corrective actions to prevent recurrence. It traces the origin of the issue and supports permanent resolution, unlike incident timelines, TTP descriptions, or status reports.
Question 46
A security analyst runs the following command:
Which of the following should the analyst recommend first to harden the system?
A. Disable all protocols that do not use encryption.
B. Configure client certificates for domain services.
C. Ensure that this system is behind a NGFW.
D. Deploy a publicly trusted root CA for secure websites.
Show Answer
Correct Answer: A
Explanation: The presence of Telnet (TCP/23) indicates an unencrypted remote access protocol. The first hardening recommendation is to disable insecure protocols that do not provide encryption, replacing them with secure alternatives such as SSH. The other options are broader architectural or PKI changes and do not address the immediate exposure shown.
Question 47
A company received a shipment of new network switches. Immediately after installing the switches, a security analyst notices suspicious traffic coming from one of the new switches. Which of the following best describes the threat actor?
A. Insider threat
B. Supply chain
C. Nation-state
D. Organized crime
Show Answer
Correct Answer: B
Explanation: Suspicious traffic beginning immediately after installation of newly received network switches strongly indicates the devices were compromised before deployment. That is characteristic of a supply chain compromise, where hardware or firmware is altered during manufacturing, distribution, or delivery. While a nation-state could be behind such an attack, the scenario asks for the best description based on the evidence provided, which is a supply chain threat.
Question 48
A group of hacktivists has breached and exfiltrated data from several of a bank’s competitors. Given the following network log output:
Which of the following represents the greatest concerns with regard to potential data exfiltration? (Choose two.)
A. 1
B. 2
C. 3
D. 4
E. 5
F. 6
G. 7
Show Answer
Correct Answer: D, G
Explanation: Based on the available context, the most likely concerns are the entry representing an outbound connection to an external IP address and the entry using an insecure file transfer protocol for potential data exfiltration. However, the referenced network log is not included, so this conclusion cannot be fully verified.
Question 49
Which of the following explains the reason a security analyst would map an attack route?
A. To find critical paths that can be used to stop an adversary from advancing
B. To create an inventory of all IT assets to import into a database
C. To operationalize intelligence gathered from a previous step in the investigation
D. To categorize the tactics according to the MITRE ATT&CK framework
Show Answer
Correct Answer: A
Explanation: Attack route mapping is used to identify the sequence of systems and actions an adversary can take to move through an environment, allowing defenders to identify critical choke points and interrupt the attack path. The other options describe different security activities: asset inventory, intelligence operationalization, and MITRE ATT&CK categorization.
Question 50
Which of the following is best suited for determining the methods of an adversary?
A. ОWASP
B. Cyber Kill Chain
C. MITRE ATT&CK
D. Diamond Model of Intrusion Analysis
Show Answer
Correct Answer: C
Explanation: MITRE ATT&CK is a knowledge base of adversary tactics, techniques, and procedures (TTPs) specifically intended to describe and analyze how adversaries operate. OWASP focuses on web application security, the Cyber Kill Chain describes attack phases rather than detailed methods, and the Diamond Model is an intrusion analysis framework relating adversary, capability, infrastructure, and victim rather than a catalog of adversary methods.
$19
Get all 534 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.