CS0-003 Exam Question 151

Numerous emails were sent to a company's customer distribution list. The customers reported that the emails contained a suspicious link. The company's SOC determined the links were malicious. Which of the following is the best way to decrease these emails?
  • CS0-003 Exam Question 152

    A disgruntled open-source developer has decided to sabotage a code repository with a logic bomb that will act as a wiper. Which of the following parts of the Cyber Kill Chain does this act exhibit?
  • CS0-003 Exam Question 153

    Which of the following best describes the importance of implementing TAXII as part of a threat intelligence program?
  • CS0-003 Exam Question 154

    A group of hacktivists has breached and exfiltrated data from several of a bank's competitors. Given the following network log output:
    ID
    Source
    Destination
    Protocol
    Service
    1
    172.16.1.1
    172.16.1.10
    ARP
    AddrResolve
    2
    172.16.1.10
    172.16.1.20
    TCP 135
    RPC Kerberos
    3
    172.16.1.10
    172.16.1.30
    TCP 445
    SMB WindowsExplorer
    4
    172.16.1.30
    5.29.1.5
    TCP 443
    HTTPS Browser.exe
    5
    11.4.11.28
    172.16.1.1
    TCP 53
    DNS Unknown
    6
    20.109.209.108
    172.16.1.1
    TCP 443
    HTTPS WUS
    7
    172.16.1.25
    bank.backup.com
    TCP 21
    FTP FileZilla
    Which of the following represents the greatest concerns with regard to potential data exfiltration? (Select two.)
  • CS0-003 Exam Question 155

    A security analyst reviews a packet capture and identifies the following output as anomalous:
    13:49:57.553161 TP10.203.10.17.45701>10.203.10.22.12930:Flags[FPU],seq108331482,win1024,urg0, length0
    13:49:57.553162 IP10.203.10.17.45701>10.203.10.22.48968:Flags[FPU],seq108331482,win1024,urg0, length0
    ...
    Which of the following activities explains the output?