CS0-002 Exam Question 41
During routine monitoring, a security analyst discovers several suspicious websites that are communicating with a local host. The analyst queries for IP 192.168.50.2 for a 24-hour period:

To further investigate, the analyst should request PCAP for SRC 192.168.50.2 and __________.

To further investigate, the analyst should request PCAP for SRC 192.168.50.2 and __________.
CS0-002 Exam Question 42
A cybersecurity analyst is responding to an incident. The company's leadership team wants to attribute the incident to an attack group. Which of the following models would BEST apply to the situation?
CS0-002 Exam Question 43
An incident response team is responding to a breach of multiple systems that contain PII and PHI. Disclosing the incident to external entities should be based on:
CS0-002 Exam Question 44
Which of the following sets of attributes BEST illustrates the characteristics of an insider threat from a security perspective?
CS0-002 Exam Question 45
A company was recently awarded several large government contracts and wants to determine its current risk from one specific APT.
Which of the following threat modeling methodologies would be the MOST appropriate to use during this analysis?
Which of the following threat modeling methodologies would be the MOST appropriate to use during this analysis?
