200-201 Exam Question 166
Which step in the incident response process researches an attacking host through logs in a SIEM?
200-201 Exam Question 167
An investigator is examining a copy of an ISO file that is stored in CDFS format. What type of evidence is this file?
200-201 Exam Question 168
An engineer discovered a breach, identified the threat's entry point, and removed access. The engineer was able to identify the host, the IP address of the threat actor, and the application the threat actor targeted. What is the next step the engineer should take according to the NIST SP 800-61 Incident handling guide?
200-201 Exam Question 169
Refer to the exhibit.

What is occurring?

What is occurring?
200-201 Exam Question 170
Refer to the exhibit.
An analyst was given a PCAP file, which is associated with a recent intrusion event in the company FTP server Which display filters should the analyst use to filter the FTP traffic?
An analyst was given a PCAP file, which is associated with a recent intrusion event in the company FTP server Which display filters should the analyst use to filter the FTP traffic?
