CS0-002 Exam Question 51

A security analyst is reviewing packet captures from a system that was compromised. The system was already isolated from the network, but it did have network access for a few hours after being compromised. When viewing the capture in a packet analyzer, the analyst sees the following:

Which of the following can the analyst conclude?
  • CS0-002 Exam Question 52

    A security analyst has received information from a third-party intelligence-sharing resource that indicates employee accounts were breached.
    Which of the following is the NEXT step the analyst should take to address the issue?
  • CS0-002 Exam Question 53

    A company recently experienced financial fraud, which included shared passwords being compromised and improper levels of access being granted The company has asked a security analyst to help
    improve its controls.
    Which of the following will MOST likely help the security analyst develop better controls?
  • CS0-002 Exam Question 54

    A security analyst is building a malware analysis lab. The analyst wants to ensure malicious applications are not capable of escaping the virtual machines and pivoting to other networks.
    To BEST mitigate this risk, the analyst should use .
  • CS0-002 Exam Question 55

    While reviewing proxy logs, the security analyst noticed a suspicious traffic pattern. Several internal hosts were observed communicating with an external IP address over port 80 constantly.
    An incident was declared, and an investigation was launched. After interviewing the affected users, the analyst determined the activity started right after deploying a new graphic design suite.
    Based on this information, which of the following actions would be the appropriate NEXT step in the investigation?