CS0-003 Exam Question 151
The SOC received a threat intelligence notification indicating that an employee's credentials were found on the dark web. The user's web and log-in activities were reviewed for malicious or anomalous connections, data uploads/downloads, and exploits. A review of the controls confirmed multifactor authentication was enabled. Which of the following should be done first to mitigate impact to the business networks and assets?
CS0-003 Exam Question 152
A company is deploying new vulnerability scanning software to assess its systems. The current network is highly segmented, and the networking team wants to minimize the number of unique firewall rules. Which of the following scanning techniques would be most efficient to achieve the objective?
CS0-003 Exam Question 153
Which of the following is a KPI that is used to monitor or report on the effectiveness of an incident response reporting and communication program?
CS0-003 Exam Question 154
Which of the following is the best reason to implement an MOU?
CS0-003 Exam Question 155
Which of the following makes STIX and OpenloC information readable by both humans and machines?
