CS0-003 Exam Question 136

An organization enabled a SIEM rule to send an alert to a security analyst distribution list when ten failed logins occur within one minute. However, the control was unable to detect an attack with nine failed logins.
Which of the following best represents what occurred?
  • CS0-003 Exam Question 137

    The Chief Information Security Officer wants to eliminate and reduce shadow IT in the enterprise. Several high-risk cloud applications are used that increase the risk to the organization. Which of the following solutions will assist in reducing the risk?
  • CS0-003 Exam Question 138

    Due to reports of unauthorized activity that was occurring on the internal network, an analyst is performing a network discovery. The analyst runs an Nmap scan against a corporate network to evaluate which devices were operating in the environment. Given the following output:

    Which of the following choices should the analyst look at first?
  • CS0-003 Exam Question 139

    Which of the following is the first step that should be performed when establishing a disaster recovery plan?
  • CS0-003 Exam Question 140

    An analyst is evaluating the following vulnerability report:

    Which of the following vulnerability report sections provides information about the level of impact on data confidentiality if a successful exploitation occurs?