CS0-002 Exam Question 246
Which of the following secure coding techniques can be used to prevent cross-site request forgery attacks?
CS0-002 Exam Question 247
An analyst received a forensically sound copy of an employee's hard drive. The employee's manager suspects inappropriate images may have been deleted from the hard drive. Which of the following could help the analyst recover the deleted evidence?
CS0-002 Exam Question 248
A security administrator determines several months after the first instance that a local privileged user has been routinely logging into a server interactively as "root" and browsing the Internet. The administrator determines this by performing an annual review of the security logs on that server.
For which of the following security architecture areas should the administrator recommend review and modification? (Select TWO).
For which of the following security architecture areas should the administrator recommend review and modification? (Select TWO).
CS0-002 Exam Question 249
A security analyst is reviewing logs and discovers that a company-owned computer issued to an employee is generating many alerts and warnings. The analyst continues to review the log events and discovers that a non-company-owned device from a different, unknown IP address is generating the same events. The analyst informs the manager of these findings, and the manager explains that these activities are already known and part of an ongoing events. Given this scenario, which of the following roles are the analyst, the employee, and the manager filling?
CS0-002 Exam Question 250
A security analyst is attempting to utilize the blowing threat intelligence for developing detection capabilities:

In which of the following phases is this APT MOST likely to leave discoverable artifacts?

In which of the following phases is this APT MOST likely to leave discoverable artifacts?
