CS0-002 Exam Question 221

A company's incident response team is handling a threat that was identified on the network.
Security analysts have determined a web server is making multiple connections from TCP port
445 outbound to servers inside its subnet as well as at remote sites. Which of the following is the MOST appropriate next step in the incident response plan?
  • CS0-002 Exam Question 222

    While conoXicting a cloud assessment, a security analyst performs a Prowler scan, which generates the following within the report:

    Based on the Prowler report, which of the following is the BEST recommendation?
  • CS0-002 Exam Question 223

    An online gaming company was impacted by a ransomware attack. An employee opened an attachment that was received via an SMS attack on a company-issued mobile device while connected to the network. Which of the following actions would help during the forensic analysis of the mobile device? (Select TWO).
  • CS0-002 Exam Question 224

    An organization is adopting loT devices at an increasing rate and will need to account for firmware updates in its vulnerability management programs. Despite the number of devices being deployed, the organization has only focused on software patches so far. leaving hardware-related weaknesses open to compromise. Which of the following best practices will help the organization to track and deploy trusted firmware updates as part of its vulnerability management programs?
  • CS0-002 Exam Question 225

    A security analyst needs to provide the development learn with secure connectivity from the corporate network to a three-tier cloud environment. The developers require access to servers in all three tiers in order to perform various configuration tasks. Which of the following technologies should the analyst implement to provide secure transport?