CS0-002 Exam Question 31

A threat feed notes malicious actors have been infiltrating companies and exfiltrating data to a specific set of domains. Management at an organization wants to know if it is a victim. Which of the following should the security analyst recommend to identify this behavior without alerting any potential malicious actors?
  • CS0-002 Exam Question 32

    Organizational policies require vulnerability remediation on severity 7 or greater within one week.
    Anything with a severity less than 7 must be remediated within 30 days. The organization also requires security teams to investigate the details of a vulnerability before performing any remediation. If the investigation determines the finding is a false positive, no remediation is performed and the vulnerability scanner configuration is updates to omit the false positive from future scans:
    The organization has three Apache web servers:

    The results of a recent vulnerability scan are shown below:

    The team performs some investigation and finds a statement from Apache:

    Which of the following actions should the security team perform?
  • CS0-002 Exam Question 33

    A security analyst is building a malware analysis lab. The analyst wants to ensure malicious applications are not capable of escaping the virtual machines and pivoting to other networks.
    To BEST mitigate this risk, the analyst should use.
  • CS0-002 Exam Question 34

    During a recent audit, there were a lot of findings similar to and including the following:

    Which of the following would be the BEST way to remediate these findings and minimize similar findings in the future?
  • CS0-002 Exam Question 35

    A user received an invalid password response when trying to change the password. Which of the following policies could explain why the password is invalid?