200-201 Exam Question 71

A security engineer deploys an enterprise-wide host/endpoint technology for all of the company's corporate PCs. Management requests the engineer to block a selected set of applications on all PCs.
Which technology should be used to accomplish this task?
  • 200-201 Exam Question 72

    An engineer runs a suspicious file in a sandbox analysis tool to see the outcome. The analysis report shows that outbound callouts were made post infection.
    Which two pieces of information from the analysis report are needed to investigate the callouts? (Choose two.)
  • 200-201 Exam Question 73

    Refer to the exhibit.

    Drag and drop the element name from the left onto the correct piece of the PCAP file on the right.

    200-201 Exam Question 74

    An analyst received a ticket regarding a degraded processing capability for one of the HR department's servers. On the same day, an engineer noticed a disabled antivirus software and was not able to determine when or why it occurred. According to the NIST Incident Handling Guide, what is the next phase of this investigation?
  • 200-201 Exam Question 75

    At a company party a guest asks questions about the company's user account format and password complexity. How is this type of conversation classified?