CS0-002 Exam Question 221

An organization suspects it has had a breach, and it is trying to determine the potential impact.
The organization knows the following:
- The source of the breach is linked to an IP located in a foreign
country.
- The breach is isolated to the research and development servers.
- The hash values of the data before and after the breach are
unchanged.
- The affected servers were regularly patched, and a recent scan showed no vulnerabilities.
Which of the following conclusions can be drawn with respect to the threat and impact? (Choose two.)
  • CS0-002 Exam Question 222

    Joe, a penetration tester, used a professional directory to identify a network administrator and ID administrator for a client's company. Joe then emailed the network administrator, identifying himself as the ID administrator, and asked for a current password as part of a security exercise.
    Which of the following techniques were used in this scenario?
  • CS0-002 Exam Question 223

    Which of the following software security best practices would prevent an attacker from being able to run arbitrary SQL commands within a web application? (Choose two.)
  • CS0-002 Exam Question 224

    When reviewing the system logs, the cybersecurity analyst noticed a suspicious log entry:
    wmic /node: HRDepartment1 computersystem get username
    Which of the following combinations describes what occurred, and what action should be taken in this situation?
  • CS0-002 Exam Question 225

    A security analyst reviews the following aggregated output from an Nmap scan and the border firewall ACL:

    Which of the following should the analyst reconfigure to BEST reduce organizational risk while maintaining current functionality?