CS0-003 Exam Question 111
Which of the following best describes the process of requiring remediation of a known threat within a given time frame?
CS0-003 Exam Question 112
An analyst discovers unusual outbound connections to an IP that was previously blocked at the web proxy and firewall. Upon further investigation, it appears that the proxy and firewall rules that were in place were removed by a service account that is not recognized. Which of the following parts of the Cyber Kill Chain does this describe?
CS0-003 Exam Question 113
A cybersecurity team quarantines a virtual machine (VM) that has triggered alerts. However, this action does not stop the threat. Similar alerts are occurring for other VMs in the same broadcast domain. Which of the following steps in the incident response process should the team take next?
CS0-003 Exam Question 114
Using open-source intelligence gathered from technical forums, a threat actor compiles and tests a malicious downloader to ensure it will not be detected by the victim organization ' s endpoint security protections.
Which of the following stages of the Cyber Kill Chain best aligns with the threat actor ' s actions?
Which of the following stages of the Cyber Kill Chain best aligns with the threat actor ' s actions?
CS0-003 Exam Question 115
Several reports with sensitive information are being disclosed via file sharing services. The company would like to improve its security posture against this threat. Which of the following security controls would best support the company in this scenario?
