CS0-002 Exam Question 66
The help desk informed a security analyst of a trend that is beginning to develop regarding a suspicious email that has been reported by multiple users.
The analyst has determined the email includes an attachment named invoice.zip that contains the following files:
* Locky.js
* xerty.ini
* xerty.lib
Further analysis indicates that when the .zip file is opened, it is installing a new version of ransomware on the devices.
Which of the following should be done FIRST to prevent data on the company NAS from being encrypted by infected devices?
The analyst has determined the email includes an attachment named invoice.zip that contains the following files:
* Locky.js
* xerty.ini
* xerty.lib
Further analysis indicates that when the .zip file is opened, it is installing a new version of ransomware on the devices.
Which of the following should be done FIRST to prevent data on the company NAS from being encrypted by infected devices?
CS0-002 Exam Question 67
A security analyst gathered forensics from a recent intrusion in preparation for legal proceedings. The analyst used EnCase to gather the digital forensics, cloned the hard drive, and took the hard drive home for further analysis. Which of the following did the security analyst violate?
CS0-002 Exam Question 68
A security analyst is reviewing the following log from an email security service.

Which of the following BEST describes the reason why the email was blocked?

Which of the following BEST describes the reason why the email was blocked?
CS0-002 Exam Question 69
During an incident, a cybersecurity analyst found several entries in the web server logs that are related to an IP with a bad reputation . Which of the following would cause the analyst to further review the incident?
A)

B)

C)

D)

E)

A)

B)

C)

D)

E)

CS0-002 Exam Question 70
During an investigation, an analyst discovers the following rule in an executive's email client:
IF * TO <[email protected]> THEN mailto: <[email protected]> SELECT FROM 'sent' THEN DELETE FROM <[email protected]> The executive is not aware of this rule. Which of the following should the analyst do FIRST to evaluate the potential impact of this security incident?
IF * TO <[email protected]> THEN mailto: <[email protected]> SELECT FROM 'sent' THEN DELETE FROM <[email protected]> The executive is not aware of this rule. Which of the following should the analyst do FIRST to evaluate the potential impact of this security incident?
