CS0-003 Exam Question 86

A SOC receives several alerts indicating user accounts are connecting to the company's identity provider through non-secure communications.
User credentials for accessing sensitive, business-critical systems could be exposed.
Which of the following logs should the SOC use when determining malicious intent?
  • CS0-003 Exam Question 87

    A security analyst needs to identify a computer based on the following requirements to be mitigated:
    * The attack method is network-based with low complexity.
    * No privileges or user action is needed.
    * The confidentiality and availability level is high, with a low integrity level.
    Given the following CVSS 3.1 output:
    * Computer1: CVSS3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:H
    * Computer2: CVSS3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H
    * Computer3: CVSS3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H
    * Computer4: CVSS3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H
    Which of the following machines should the analyst mitigate?
  • CS0-003 Exam Question 88

    An analyst has received an IPS event notification from the SIEM stating an IP address, which is known to be malicious, has attempted to exploit a zero-day vulnerability on several web servers. The exploit contained the following snippet:
    /wp-json/trx_addons/V2/get/sc_layout?sc=wp_insert_user&role=administrator Which of the following controls would work best to mitigate the attack represented by this snippet?
  • CS0-003 Exam Question 89

    A security analyst is improving an organization's vulnerability management program. The analyst cross- checks the current reports with the system's infrastructure teams, but the reports do not accurately reflect the current patching levels. Which of the following will most likely correct the report errors?
  • CS0-003 Exam Question 90

    An organization has tracked several incidents that are listed in the following table:
    Which of the following is the organization ' s MTTD?