200-201 Exam Question 146

Drag and drop the event term from the left onto the description on the right.

200-201 Exam Question 147

An analyst is investigating an incident in a SOC environment.
Which method is used to identify a session from a group of logs?
  • 200-201 Exam Question 148

    Which two compliance frameworks require that data be encrypted when it is transmitted over a public network?
    (Choose two.)
  • 200-201 Exam Question 149

    A security analyst notices a sudden surge of incoming traffic and detects unknown packets from unknown senders After further investigation, the analyst learns that customers claim that they cannot access company servers According to NIST SP800-61, in which phase of the incident response process is the analyst?
  • 200-201 Exam Question 150

    Drag and drop the definition from the left onto the phase on the right to classify intrusion events according to the Cyber Kill Chain model.