CS0-003 Exam Question 11

After completing a review of network activity. the threat hunting team discovers a device on the network that sends an outbound email via a mail client to a non-company email address daily at 10:00 p.m. Which of the following is potentially occurring?
  • CS0-003 Exam Question 12

    A company that has a geographically diverse workforce and dynamic IPs wants to implement a vulnerability scanning method with reduced network traffic. Which of the following would best meet this requirement?
  • CS0-003 Exam Question 13

    A security analyst is tasked with prioritizing vulnerabilities for remediation. The relevant company security policies are shown below:
    Security Policy 1006: Vulnerability Management
    1. The Company shall use the CVSSv3.1 Base Score Metrics (Exploitability and Impact) to prioritize the remediation of security vulnerabilities.
    2. In situations where a choice must be made between confidentiality and availability, the Company shall prioritize confidentiality of data over availability of systems and data.
    3. The Company shall prioritize patching of publicly available systems and services over patching of internally available system.
    According to the security policy, which of the following vulnerabilities should be the highest priority to patch?
  • CS0-003 Exam Question 14

    An analyst has been asked to validate the potential risk of a new ransomware campaign that the Chief Financial Officer read about in the newspaper. The company is a manufacturer of a very small spring used in the newest fighter jet and is a critical piece of the supply chain for this aircraft. Which of the following would be the best threat intelligence source to learn about this new campaign?
  • CS0-003 Exam Question 15

    After identifying a threat, a company has decided to implement a patch management program to remediate vulnerabilities. Which of the following risk management principles is the company exercising?