CS0-002 Exam Question 146
After running a packet analyzer on the network, a security analyst has noticed the following output:

Which of the following is occurring?

Which of the following is occurring?
CS0-002 Exam Question 147
A security analyst suspects a malware infection was caused by a user who downloaded malware after clicking http://<malwaresource>/a.php in a phishing email.
To prevent other computers from being infected by the same malware variation, the analyst should create a rule on the __________.
To prevent other computers from being infected by the same malware variation, the analyst should create a rule on the __________.
CS0-002 Exam Question 148
An analyst needs to provide recommendations for the AUP Which of the following is the BEST recommendation to protect the company's intellectual property?
CS0-002 Exam Question 149
A security operations team was alerted to abnormal DNS activity coming from a user's machine.
The team performed a forensic investigation and discovered a host had been compromised.
Malicious code was using DNS as a tunnel to extract data from the client machine, which had been leaked and transferred to an unsecure public Internet site. Which of the following BEST describes the attack?
The team performed a forensic investigation and discovered a host had been compromised.
Malicious code was using DNS as a tunnel to extract data from the client machine, which had been leaked and transferred to an unsecure public Internet site. Which of the following BEST describes the attack?
CS0-002 Exam Question 150
A security analyst is reviewing the following log from an email security service.

Which of the following BEST describes the reason why the email was blocked?

Which of the following BEST describes the reason why the email was blocked?
