CS0-002 Exam Question 141

A security analyst is investigating malicious traffic from an internal system that attempted to download proxy avoidance software as identified from the firewall logs but the destination IP is blocked and not captured. Which of the following should the analyst do?
  • CS0-002 Exam Question 142

    The help desk informed a security analyst of a trend that is beginning to develop regarding a suspicious email that has been reported by multiple users.
    The analyst has determined the email includes an attachment named invoice.zip that contains the following files:
    * Locky.js
    * xerty.ini
    * xerty.lib
    Further analysis indicates that when the .zip file is opened, it is installing a new version of ransomware on the devices.
    Which of the following should be done FIRST to prevent data on the company NAS from being encrypted by infected devices?
  • CS0-002 Exam Question 143

    A security analyst is building a malware analysis lab. The analyst wants to ensure malicious applications are not capable of escaping the virtual machines and pivoting to other networks.
    To BEST mitigate this risk, the analyst should use.
  • CS0-002 Exam Question 144

    A manufacturing company uses a third-party service provider lor Tier 1 security support One of the requirements is that the provider must only source talent from its own country due to geopolitical and national security interests Which of the following can the manufacturing company implement to ensure the third-party service provider meets this requirement?
  • CS0-002 Exam Question 145

    A security analyst inspects the header of an email that is presumed to be malicious and sees the following:

    Which of the following is inconsistent with the rest of the header and should be treated as suspicious?