CS0-003 Exam Question 11

Which of the following is a KPI that is used to monitor or report on the effectiveness of an incident response reporting and communication program?
  • CS0-003 Exam Question 12

    Which of the following actions would an analyst most likely perform after an incident has been investigated?
  • CS0-003 Exam Question 13

    An incident response team is assessing attack vectors of malware that is encrypting data with ransomware.
    There are no indications of a network-based intrusion.
    Which of the following is the most likely root cause of the incident?
  • CS0-003 Exam Question 14

    A security analyst needs to identify an asset that should be remediated based on the following information:
    * File ServerCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H/
    * Web ServerCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/
    * Mail Server (corrected from "Mall server")CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/
    * Domain ControllerCVSS:3.1/AV:N/AC:L/PR:R/UI:R/S:U/C:H/I:H/A:H/
    Which of the following assets should the analyst remediate first?
  • CS0-003 Exam Question 15

    The SOC received a threat intelligence notification indicating that an employee's credentials were found on the dark web. The user's web and log-in activities were reviewed for malicious or anomalous connections, data uploads/downloads, and exploits. A review of the controls confirmed multifactor authentication was enabled. Which of the following should be done first to mitigate impact to the business networks and assets?