CS0-003 Exam Question 46

Which of the following best describes the key goal of the containment stage of an incident response process?
  • CS0-003 Exam Question 47

    Which of the following techniques can help a SOC team to reduce the number of alerts related to the internal security activities that the analysts have to triage?
  • CS0-003 Exam Question 48

    A security analyst is improving an organization's vulnerability management program. The analyst cross- checks the current reports with the system's infrastructure teams, but the reports do not accurately reflect the current patching levels. Which of the following will most likely correct the report errors?
  • CS0-003 Exam Question 49

    A security alert was triggered when an end user tried to access a website that is not allowed per organizational policy. Since the action is considered a terminable offense, the SOC analyst collects the authentication logs, web logs, and temporary files, reflecting the web searches from the user's workstation, to build the case for the investigation. Which of the following is the best way to ensure that the investigation complies with HR or privacy policies?
  • CS0-003 Exam Question 50

    An organization has tracked several incidents that are listed in the following table:
    Which of the following is the organization ' s MTTD?