200-201 Exam Question 16
Which regex matches only on all lowercase letters?
200-201 Exam Question 17
What does cyber attribution identity in an investigation?
200-201 Exam Question 18
An analyst received an alert on their desktop computer showing that an attack was successful on the host.
After investigating, the analyst discovered that no mitigation action occurred during the attack. What is the reason for this discrepancy?
After investigating, the analyst discovered that no mitigation action occurred during the attack. What is the reason for this discrepancy?
200-201 Exam Question 19
What are two differences in how tampered and untampered disk images affect a security incident? (Choose two.)
200-201 Exam Question 20
What is a difference between signature-based and behavior-based detection?