CS0-002 Exam Question 41

A security analyst is investigating a reported phishing attempt that was received by many users throughout the company The text of one of the emails is shown below:

Office 365 User.
It looks like you account has been locked out Please click this <a href=Tittp7/accountfix-office356 com/login php">link</a> and follow the pfompts to restore access Regards.
Security Team
Due to the size of the company and the high storage requirements, the company does not log DNS requests or perform packet captures of network traffic, but rt does log network flow data Which of the following commands will the analyst most likely execute NEXT?
  • CS0-002 Exam Question 42

    An analyst determines a security incident has occurred Which of the following is the most appropnate NEXT step in an incident response plan?
  • CS0-002 Exam Question 43

    During a review of recent network traffic, an analyst realizes the team has seen this same traffic multiple times in the past three weeks, and it resulted in confirmed malware activity The analyst also notes there is no other alert in place for this traffic After resolving the security incident, which of the following would be the BEST action for the analyst to take to increase the chance of detecting this traffic in the future?
  • CS0-002 Exam Question 44

    An analyst is reviewing the following output as part of an incident:

    Which of the Wowing is MOST likely happening?
  • CS0-002 Exam Question 45

    A security administrator needs to provide access from partners to an Isolated laboratory network inside an organization that meets the following requirements:
    * The partners' PCs must not connect directly to the laboratory network.
    * The tools the partners need to access while on the laboratory network must be available to all partners
    * The partners must be able to run analyses on the laboratory network, which may take hours to complete Which of the following capabilities will MOST likely meet the security objectives of the request?