CS0-002 Exam Question 111
During routine monitoring, a security analyst discovers several suspicious websites that are communicating with a local host. The analyst queries for IP 192.168.50.2 for a 24-hour period:

To further investigate, the analyst should request PCAP for SRC 192.168.50.2 and __________.

To further investigate, the analyst should request PCAP for SRC 192.168.50.2 and __________.
CS0-002 Exam Question 112
A security analyst is performing a forensic analysis on a machine that was the subject of some historic SIEM alerts.
The analyst noticed some network connections utilizing SSL on non-common ports, copies of svchost.exe and cmd.exe in %TEMP% folder, and RDP files that had connected to external IPs.
Which of the following threats has the security analyst uncovered?
The analyst noticed some network connections utilizing SSL on non-common ports, copies of svchost.exe and cmd.exe in %TEMP% folder, and RDP files that had connected to external IPs.
Which of the following threats has the security analyst uncovered?
CS0-002 Exam Question 113
A security analyst is performing ongoing scanning and continuous monitoring of the corporate datacenter. Over time, these scans are repeatedly showing susceptibility to the same vulnerabilities and an increase in new vulnerabilities on a specific group of servers that are clustered to run the same application. Which of the following vulnerability management processes should be implemented?
CS0-002 Exam Question 114
A company discovers an unauthorized device accessing network resources through one of many network drops in a common area used by visitors.
The company decides that is wants to quickly prevent unauthorized devices from accessing the network but policy prevents the company from making changes on every connecting client.
Which of the following should the company implement?
The company decides that is wants to quickly prevent unauthorized devices from accessing the network but policy prevents the company from making changes on every connecting client.
Which of the following should the company implement?
CS0-002 Exam Question 115
During a cyber incident, which of the following is the BEST course of action?
