Question No.11

Which CVSSv3 Attack Vector metric value requires the attacker to physically touch or manipulate the vulnerable component?

  1. local

  2. physical

  3. network

  4. adjacent

Correct Answer: B

Question No.12

Which option has a drastic impact on network traffic because it can cause legitimate traffic to be blocked?

  1. true positive

  2. true negative

  3. false positive

  4. false negative

Correct Answer: C

Question No.13

In the context of incident handling phases, which two activities fall under scoping? (Choose two.)

  1. determining the number of attackers that are associated with a security incident

  2. ascertaining the number and types of vulnerabilities on your network

  3. identifying the extent that a security incident is impacting protected resources on the network

  4. determining what and how much data may have been affected

  5. identifying the attackers that are associated with a security incident

Correct Answer: CE

Question No.14

Which feature is used to find possible vulnerable services running on a server?

  1. CPU utilization

  2. security policy

  3. temporary internet files

  4. listening ports

Correct Answer: D

Question No.15

Which element is included in an incident response plan?

  1. organization mission

  2. junior analyst approval

  3. day-to-day firefighting

  4. siloed approach to communications

Correct Answer: A

Question No.16

Which option can be addressed when using retrospective security techniques?

  1. if the affected host needs a software update

  2. how the malware entered our network

  3. why the malware is still in our network

  4. if the affected system needs replacement

Correct Answer: B

Question No.17

From a security perspective, why is it important to employ a clock synchronization protocol on a network?

  1. so that everyone knows the local time

  2. to ensure employees adhere to work schedule

  3. to construct an accurate timeline of events when responding to an incident

  4. to guarantee that updates are pushed out according to schedule

Correct Answer: C

Question No.18

Which CVSSv3 metric value increases when attacks consume network bandwidth, processor cycles, or disk space?

  1. confidentiality

  2. integrity

  3. availability

  4. complexity

Correct Answer: C

Question No.19

In VERIS, an incident is viewed as a series of events that adversely affects the information assets of an organization. Which option contains the elements that every event is comprised of according to VERIS incident model#39;?

  1. victim demographics, incident description, incident details, discovery amp; response

  2. victim demographics, incident details, indicators of compromise, impact assessment

  3. actors, attributes, impact, remediation

  4. actors, actions, assets, attributes

Correct Answer: D

Question No.20

Which two options can be used by a threat actor to determine the role of a server? (Choose two.)

  1. PCAP

  2. tracert

  3. running processes

  4. hard drive configuration

  5. applications

Correct Answer: CE

