CS0-003 Exam Question 206

A Chief Information Security Officer (CISO) is concerned that a specific threat actor who is known to target the company's business type may be able to breach the network and remain inside of it for an extended period of time.
Which of the following techniques should be performed to meet the CISO's goals?
  • CS0-003 Exam Question 207

    A security analyst needs to provide evidence of regular vulnerability scanning on the company's network for an auditing process. Which of the following is an example of a tool that can produce such evidence?
  • CS0-003 Exam Question 208

    A company receives a penetration test report summary from a third party. The report summary indicates a proxy has some patches that need to be applied. The proxy is sitting in a rack and is not being used, as the company has replaced it with a new one. The CVE score of the vulnerability on the proxy is a 9.8.
    Which of the following best practices should the company follow with this proxy?
  • CS0-003 Exam Question 209

    A company is in the process of implementing a vulnerability management program, and there are concerns about granting the security team access to sensitive dat a. Which of the following scanning methods can be implemented to reduce the access to systems while providing the most accurate vulnerability scan results?
  • CS0-003 Exam Question 210

    Approximately 100 employees at your company have received a Phishing email. AS a security analyst. you have been tasked with handling this Situation.



    Review the information provided and determine the following:
    1. HOW many employees Clicked on the link in the Phishing email?
    2. on how many workstations was the malware installed?
    3. what is the executable file name of the malware?