CS0-002 Exam Question 31

A security analyst is building a malware analysis lab. The analyst wants to ensure malicious applications are not capable of escaping the virtual machines and pivoting to other networks.
To BEST mitigate this risk, the analyst should use __________.
  • CS0-002 Exam Question 32

    A security analyst is conducting traffic analysis and observes an HTTP POST to a web server.
    The POST header is approximately 1000 bytes in length. During transmission, one byte is delivered every ten seconds. Which of the following attacks is the traffic indicative of?
  • CS0-002 Exam Question 33

    A team of security analysts has been alerted to potential malware activity. The initial examination indicates one of the affected workstations is beaconing on TCP port 80 to five IP addresses and attempting to spread across the network over port 445. Which of the following should be the team's NEXT step during the detection phase of this response process?
  • CS0-002 Exam Question 34

    A company's security officer needs to implement geographical IP blocks for nation-state actors from a foreign country On which of the following should the blocks be implemented'?
  • CS0-002 Exam Question 35

    An employee was conducting research on the Internet when a message from cyber criminals appeared on the screen, stating the hard drive was just encrypted by a ransomware variant. An analyst observes the following:
    * Antivirus signatures were updated recently
    * The desktop background was changed
    * Web proxy logs show browsing to various information security sites and ad network traffic
    * There is a high volume of hard disk activity on the file server
    * SMTP server shown the employee recently received several emails from blocked senders
    * The company recently switched web hosting providers
    * There are several IPS alerts for external port scans
    Which of the following describes how the employee got this type of ransomware?