During an audit, an organization's ability to establish key performance indicators for its service hosting solution is discovered to be weak.
What could be the cause of this?
Reveal answer details Close answer details
Correct answerB
CertNexus · CFR-410
Preview real exam questions, verified answers and available explanations before choosing a study plan.
|
Single choice
During an audit, an organization's ability to establish key performance indicators for its service hosting solution is discovered to be weak. What could be the cause of this? Reveal answer details Close answer detailsCorrect answerB
Single choice
What is the primary purpose of the "information security incident triage and processing function" in the (CSIRT) Computer Security Incident Response Team Services Framework? Reveal answer details Close answer detailsCorrect answerB
Single choice
Which of the following tools can help to detect suspicious or unauthorized changes to critical system configuration files? Reveal answer details Close answer detailsCorrect answerA
Single choice
Recently, a cybersecurity research lab discovered that there is a hacking group focused on hacking into the computers of financial executives in Company A to sell the exfiltrated information to Company B. Which of the following threat motives does this MOST likely represent? Reveal answer details Close answer detailsCorrect answerD
Single choice
An organization recently suffered a breach due to a human resources administrator emailing employee names and Social Security numbers to a distribution list. Which of the following tools would help mitigate this risk from recurring? Reveal answer details Close answer detailsCorrect answerA
Single choice
Which of the following plans helps IT security staff detect, respond to, and recover from a cyber attack? Reveal answer details Close answer detailsCorrect answerB
Single choice
After a security breach, a security consultant is hired to perform a vulnerability assessment for a company's web application. Which of the following tools would the consultant use? Reveal answer details Close answer detailsCorrect answerA
Single choice
An incident at a government agency has occurred and the following actions were taken: 1. Users have regained access to email accounts Which of the following phases of the incident response process match the actions taken? Reveal answer details Close answer detailsCorrect answerA
Single choice
An organization recently suffered a data breach involving a server that had Transmission Control Protocol (TCP) port 1433 inadvertently exposed to the Internet. Which of the following services was vulnerable? Reveal answer details Close answer detailsCorrect answerC
Single choice
Which of the following can increase an attack surface? Reveal answer details Close answer detailsCorrect answerA
Single choice
Which of the following can be used as a vulnerability management and assessment tool? Reveal answer details Close answer detailsCorrect answerA
Single choice
An incident responder discovers that the CEO logged in from their New York City office and then logged in from a location in Beijing an hour later. The incident responder suspects that the CEO's account has been compromised. Which of the following anomalies MOST likely contributed to the incident responder's suspicion? Reveal answer details Close answer detailsCorrect answerC
Single choice
A system administrator identifies unusual network traffic from outside the local network. Which of the following is the BEST method for mitigating the threat? Reveal answer details Close answer detailsCorrect answerC
Single choice
A system administrator pulls records from a database that only requires the use of their general user vs. domain admin account. Reveal answer details Close answer detailsCorrect answerC
Single choice
Which of the following technologies would reduce the risk of a successful SQL injection attack? Reveal answer details Close answer detailsCorrect answerB
Single choice
Nmap is a tool most commonly used to: Reveal answer details Close answer detailsCorrect answerC
Single choice
A Linux administrator is trying to determine the character count on many log files. Which of the following command and flag combinations should the administrator use? Reveal answer details Close answer detailsCorrect answerC
Single choice
A network administrator has determined that network performance has degraded due to excessive use of social media and Internet streaming services. Which of the following would be effective for limiting access to these types of services, without completely restricting access to a site? Reveal answer details Close answer detailsCorrect answerB
Single choice
Which of the following security best practices should a web developer reference when developing a new web-based application? Reveal answer details Close answer detailsCorrect answerD
Multiple choice
What are three benefits of security logging and monitoring? (Choos) Reveal answer details Close answer detailsCorrect answersB, C, D
Single choice
Which of the following is BEST suited to prevent piggybacking into a sensitive or otherwise restricted area of a facility? Reveal answer details Close answer detailsCorrect answerA
Multiple choice
Which of the following, when exposed together, constitutes PII? (Choose two.) Reveal answer details Close answer detailsCorrect answersA, C
Single choice
A web server is under a denial of service (DoS) attack. The administrator reviews logs and creates an access control list (ACL) to stop the attack. Which of the following technologies could perform these steps automatically in the future? Reveal answer details Close answer detailsCorrect answerB
Single choice
A secretary receives an email from a friend with a picture of a kitten in it. The secretary forwards it to the~COMPANYWIDE mailing list and, shortly thereafter, users across the company receive the following message: "You seem tense. Take a deep breath and relax!" The incident response team is activated and opens the picture in a virtual machine to test it. After a short analysis, the following code is found in C: \Temp\chill.exe:Powershell.exe -Command "do {(for /L %i in (2,1,254) do shutdown /r /m Error! Hyperlink Which of the following BEST represents what the attacker was trying to accomplish? Reveal answer details Close answer detailsCorrect answerB
Multiple choice
A cybersecurity expert assigned to be the IT manager of a middle-sized company discovers that there is little endpoint security implementation on the company's systems. Which of the following could be included in an endpoint security solution? (Choose two.) Reveal answer details Close answer detailsCorrect answersA, B
Single choice
Which encryption technology was built into Mac OS X? Reveal answer details Close answer detailsCorrect answerB
Single choice
Which common source of vulnerability should be addressed to BEST mitigate against URL redirection attacks? Reveal answer details Close answer detailsCorrect answerA |