SY0-601 Exam Question 16
An organization recently released a zero-trust policy that will enforce who is able to remotely access certain dat a. Authenticated users who access the data must have a need to know, depending on their level of permissions.
Which of the following is the first step the organization should take when implementing the policy?
Which of the following is the first step the organization should take when implementing the policy?
SY0-601 Exam Question 17
Which of the following would produce the closet experience of responding to an actual incident response scenario?
SY0-601 Exam Question 18
An analyst is working on an investigation with multiple alerts for multiple hosts. The hosts are showing signs of being compromised by a fast-spreading worm. Which of the following should be the next step in order to stop the spread?
SY0-601 Exam Question 19
A customer has reported that an organization's website displayed an image of a smiley (ace rather than the expected web page for a short time two days earlier. A security analyst reviews log tries and sees the following around the lime of the incident:

Which of the following is MOST likely occurring?

Which of the following is MOST likely occurring?
SY0-601 Exam Question 20
The SIEM at an organization has detected suspicious traffic coming a workstation in its internal network. An analyst in the SOC the workstation and discovers malware that is associated with a botnet is installed on the device A review of the logs on the workstation reveals that the privileges of the local account were escalated to a local administrator. To which of the following groups should the analyst report this real-world event?
