CS0-002 Exam Question 16

An organization prohibits users from logging in to the administrator account. If a user requires elevated permissions. the user's account should be part of an administrator group, and the user should escalate permission only as needed and on a temporary basis. The organization has the following reporting priorities when reviewing system activity:
* Successful administrator login reporting priority - high
* Failed administrator login reporting priority - medium
* Failed temporary elevated permissions - low
* Successful temporary elevated permissions - non-reportable
A security analyst is reviewing server syslogs and sees the following:
Which of the following events is the HIGHEST reporting priority?
  • CS0-002 Exam Question 17

    A security analyst responds to a series of events surrounding sporadic bandwidth consumption from an endpoint device. The security analyst then identifies the following additional details:
    * Bursts of network utilization occur approximately every seven days.
    * The content being transferred appears to be encrypted or obfuscated.
    * A separate but persistent outbound TCP connection from the host to infrastructure in a third-party cloud is in place.
    * The HDD utilization on the device grows by 10GB to 12GB over the course of every seven days.
    * Single file sizes are 10GB.
    Which of the following describes the most likely cause of the issue?
  • CS0-002 Exam Question 18

    After analyzing and correlating activity from multiple sensors, the security analyst has determined a group from a high-risk country is responsible for a sophisticated breach of the company network and continuous administration of targeted attacks for the past three months. Until now, the attacks went unnoticed. This is an example of:
  • CS0-002 Exam Question 19

    In SIEM software, a security analysis selected some changes to hash signatures from monitored files during the night followed by SMB brute-force attacks against the file servers Based on this behavior, which of the following actions should be taken FIRST to prevent a more serious compromise?
  • CS0-002 Exam Question 20

    An organisation is assessing risks so it can prioritize its mitigation actions. Following are the risks and their probability and impact:

    Which of the following is the order of priority for risk mitigation from highest to lowest?