200-201 Exam Question 166

Which step in the incident response process researches an attacking host through logs in a SIEM?
  • 200-201 Exam Question 167

    An investigator is examining a copy of an ISO file that is stored in CDFS format. What type of evidence is this file?
  • 200-201 Exam Question 168

    An engineer discovered a breach, identified the threat's entry point, and removed access. The engineer was able to identify the host, the IP address of the threat actor, and the application the threat actor targeted. What is the next step the engineer should take according to the NIST SP 800-61 Incident handling guide?
  • 200-201 Exam Question 169

    Refer to the exhibit.

    What is occurring?
  • 200-201 Exam Question 170

    Refer to the exhibit.
    An analyst was given a PCAP file, which is associated with a recent intrusion event in the company FTP server Which display filters should the analyst use to filter the FTP traffic?