SY0-701 Exam Question 206
Which of the following security concepts is the best reason for permissions on a human resources fileshare to follow the principle of least privilege?
SY0-701 Exam Question 207
The CIRT is reviewing an incident that involved a human resources recruiter exfiltrating sensitive company data. The CIRT found that the recruiter was able to use HTTP over port 53 to upload documents to a web server. Which of the following security infrastructure devices could have identified and blocked this activity?
SY0-701 Exam Question 208
A security analyst identifies an incident in the network. Which of the following incident response activities would the security analyst perform next?
SY0-701 Exam Question 209
A security administrator receives multiple reports about the same suspicious email. Which of the following is the most likely reason for the malicious email's continued delivery?
SY0-701 Exam Question 210
A Chief Information Security Officer is developing procedures to guide detective and corrective activities associated with common threats, including phishing, social engineering, and business email compromise. Which of the following documents would be most relevant to revise as part of this process?
