CS0-002 Exam Question 136

A security administrator needs to provide access from partners to an Isolated laboratory network inside an organization that meets the following requirements:
* The partners' PCs must not connect directly to the laboratory network.
* The tools the partners need to access while on the laboratory network must be available to all partners
* The partners must be able to run analyses on the laboratory network, which may take hours to complete Which of the following capabilities will MOST likely meet the security objectives of the request?
  • CS0-002 Exam Question 137

    A security analyst is reviewing packet captures from a system that was compromised. The system was already isolated from the network, but it did have network access for a few hours after being compromised. When viewing the capture in a packet analyzer, the analyst sees the following:

    Which of the following can the analyst conclude?
  • CS0-002 Exam Question 138

    A cybersecurity analyst is contributing to a team hunt on an organization's endpoints.
    Which of the following should the analyst do FIRST?
  • CS0-002 Exam Question 139

    A security analyst received a series of antivirus alerts from a workstation segment, and users reported ransomware messages. During lessons- learned activities, the analyst determines the antivirus was able to alert to abnormal behavior but did not stop this newest variant of ransomware. Which of the following actions should be taken to BEST mitigate the effects of this type of threat in the future?
  • CS0-002 Exam Question 140

    An organization prohibits users from logging in to the administrator account. If a user requires elevated permissions. the user's account should be part of an administrator group, and the user should escalate permission only as needed and on a temporary basis. The organization has the following reporting priorities when reviewing system activity:
    * Successful administrator login reporting priority - high
    * Failed administrator login reporting priority - medium
    * Failed temporary elevated permissions - low
    * Successful temporary elevated permissions - non-reportable
    A security analyst is reviewing server syslogs and sees the following:
    Which of the following events is the HIGHEST reporting priority?