CS0-002 Exam Question 91

In SIEM software, a security analysis selected some changes to hash signatures from monitored files during the night followed by SMB brute-force attacks against the file servers Based on this behavior, which of the following actions should be taken FIRST to prevent a more serious compromise?
  • CS0-002 Exam Question 92

    An organization suspects it has had a breach, and it is trying to determine the potential impact. The organization knows the following:
    * The source of the breach is linked to an IP located in a foreign country.
    * The breach is isolated to the research and development servers.
    * The hash values of the data before and after the breach are unchanged.
    * The affected servers were regularly patched, and a recent scan showed no vulnerabilities.
    Which of the following conclusions can be drawn with respect to the threat and impact? (Choose two.)
  • CS0-002 Exam Question 93

    While conducting a cloud assessment, a security analyst performs a Prowler scan, which generates the following within the report:

    Based on the Prowler report, which of the following is the BEST recommendation?
  • CS0-002 Exam Question 94

    A software development team asked a security analyst to review some code for security vulnerabilities. Which of the following would BEST assist the security analyst while performing this task?
  • CS0-002 Exam Question 95

    A security analyst discovers a vulnerability on an unpatched web server that is used for testing machine learning on Bing Data sets. Exploitation of the vulnerability could cost the organization $1.5 million in lost productivity. The server is located on an isolated network segment that has a 5% chance of being compromised. Which of the following is the value of this risk?