Which of the following best explains the importance of playbooks for incident response teams?
A. Playbooks define compliance controls and help keep the monitoring process that is in place fully aligned with regulatory requirements as designed by international rules.
B. Playbooks help implement mitigation controls to prevent the occurrence of incidents in accordance with internal policies and procedures as designed by the IT team.
C. Playbooks set baseline requirements that are implemented before incidents happen to ensure the proper monitoring process in order to collect metrics and KPIs that will be used for lessons-learned procedures after a postmortem analysis.
D. Playbooks help minimize negative impacts and restore data, systems, and operations through highly detailed, preplanned procedures that will be followed when particular types of incidents occur.
Show Answer
Correct Answer: D
Explanation: Incident response playbooks provide predefined, detailed procedures for handling specific incident types, enabling teams to respond quickly, consistently, and effectively. Their primary importance is minimizing impact and restoring systems and operations by guiding actions during an incident, rather than focusing on compliance, preventive controls, or pre-incident metrics.
Question 41
A company wants to grant access to identity administrators who are completing similar tasks. Which of the following access control models should the company use?
A. Mandatory access
B. Role-based access
C. Attribute-based access
D. Discretionary access
Show Answer
Correct Answer: B
Explanation: When multiple users perform the same job functions, permissions should be assigned based on roles rather than individuals. Role-Based Access Control (RBAC) groups permissions by job role (e.g., identity administrators), making access management efficient and scalable.
Question 42
After updating the email client to the latest patch, only about 15% of the workforce is able to use email. Windows 10 users do not experience issues, but Windows 11 users have constant issues. Which of the following did the change management team fail to do?
A. Implementation
B. Testing
C. Rollback
D. Validation
Show Answer
Correct Answer: B
Explanation: The issue appeared only after deployment and affects a specific platform (Windows 11), indicating the change was not adequately tested across all affected environments before rollout. Proper testing would have revealed compatibility issues prior to implementation.
Question 42
A SOC manager is looking for a solution that can improve the response time and execute predetermined instructions. Which of the following is the best solution based on these requirements?
A. XDR
B. SIEM
C. CASB
D. SOAR
Show Answer
Correct Answer: D
Explanation: The requirement is to improve response time and execute predetermined instructions. SOAR platforms are built to automate and orchestrate incident response through predefined playbooks, integrating multiple security tools and reducing mean time to respond. XDR and SIEM focus on detection and correlation, and CASB focuses on cloud access control, not automated response execution.
Question 43
An analyst notices that logs contain multiple events for computer account changes during monthly patch maintenance windows, resulting in a flood of tickets. The events generated are from the same system and time frame. The analyst determines that these tickets could be closed without human interaction. Which of the following is the best tool for automatically closing tickets containing the same information?
A. SOAR
B. EDR
C. CASB
D. SIEM
Show Answer
Correct Answer: A
Explanation: SOAR platforms are designed to automate incident and ticket workflows. They can correlate identical events from the same system and time frame, apply predefined playbooks, and automatically close tickets without human intervention. SIEM focuses on log aggregation and alerting, while EDR and CASB address endpoint and cloud security, not ticket automation.
Question 43
A security analyst wants to implement new monitoring controls in order to find abnormal account activity for traveling employees. Which of the following techniques would deliver the expected results?
A. Malicious command interpretation
B. Network monitoring
C. User behavior analysis
D. SSL inspection
Show Answer
Correct Answer: C
Explanation: Detecting abnormal account activity for traveling employees requires identifying deviations from a user’s normal patterns, such as unusual login locations, times, devices, or access behavior. User Behavior Analysis (UBA) establishes baselines of typical user activity and flags anomalies like impossible travel or atypical resource access. The other options do not focus on per-user behavioral baselining and anomaly detection.
Question 44
Security analysts can review the Windows Registry on endpoints to get insights into:
A. domain account privileges.
B. mandatory access control zones.
C. system-critical configuration items.
D. application and security event logs.
Show Answer
Correct Answer: C
Explanation: The Windows Registry stores low-level, system-wide and per-user configuration data for the OS and installed applications, including startup settings, drivers, services, and security-related configurations. Reviewing it provides insight into system-critical configuration items, not event logs (which are in Event Viewer), domain privileges (in Active Directory), or mandatory access control zones.
Question 44
A security manager reviews the permissions for the approved users of a shared folder and finds accounts that are not on the approved access list. While investigating an incident, a user discovers data discrepancies in the file. Which of the following best describes this activity?
A. Filesystem anomaly
B. Illegal software
C. Unauthorized changes
D. Data exfiltration
Show Answer
Correct Answer: C
Explanation: The presence of user accounts with permissions that are not on the approved access list, combined with discovered data discrepancies, indicates that the file contents were modified without proper authorization. This is a data integrity issue best described as unauthorized changes, not merely an anomaly, illegal software, or data exfiltration.
Question 45
An analyst finds that duplicate entries may exist in the asset inventory, which is skewing vulnerability scan data. Which of the following is the best way for the analyst to improve the effectiveness of the vulnerability scan?
A. Device fingerprinting
B. Network mapping
C. Uncredentialed reports
D. Dynamic scans
Show Answer
Correct Answer: A
Explanation: Duplicate entries in an asset inventory usually occur when the same device appears under different IP addresses, hostnames, or scan instances. Device fingerprinting uniquely identifies assets using stable characteristics such as MAC address, OS, hardware details, and software profiles. This allows the analyst to correlate scans to the same underlying device, eliminate duplicates, and therefore improve the accuracy and effectiveness of vulnerability scan results. The other options do not directly resolve duplicate asset identification.
Question 45
A security analyst has just received an incident ticket regarding a ransomware attack. Which of the following would most likely help an analyst properly triage the ticket?
A. Incident response plan
B. Lessons learned
C. Playbook
D. Tabletop exercise
Show Answer
Correct Answer: C
Explanation: A playbook provides incident-specific, step-by-step guidance for handling events like ransomware, including triage actions, severity assessment, containment, evidence collection, and escalation. This makes it the most useful resource for quickly and consistently triaging an active ransomware incident.
$19
Get all 528 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.