CS0-003 Exam Question 46

A security analyst observed the following activity from a privileged account:
. Accessing emails and sensitive information
. Audit logs being modified
. Abnormal log-in times
Which of the following best describes the observed activity?
  • CS0-003 Exam Question 47

    A vulnerability scan of a web server that is exposed to the internet was recently completed. A security analyst is reviewing the resulting vector strings:
    Vulnerability 1: CVSS: 3.0/AV:N/AC: L/PR: N/UI : N/S: U/C: H/I : L/A:L
    Vulnerability 2: CVSS: 3.0/AV: L/AC: H/PR:N/UI : N/S: U/C: L/I : L/A: H Vulnerability 3: CVSS: 3.0/AV:A/AC: H/PR: L/UI : R/S: U/C: L/I : H/A:L Vulnerability 4: CVSS: 3.0/AV: P/AC: L/PR: H/UI : N/S: U/C: H/I:N/A:L Which of the following vulnerabilities should be patched first?
  • CS0-003 Exam Question 48

    The security team at a company, which was a recent target of ransomware, compiled a list of hosts that were identified as impacted and in scope for this incident. Based on the following host list:

    Which of the following systems was most pivotal to the threat actor in its distribution of the encryption binary via Group Policy?
  • CS0-003 Exam Question 49

    An analyst is becoming overwhelmed with the number of events that need to be investigated for a timeline.
    Which of the following should the analyst focus on in order to move the incident forward?
  • CS0-003 Exam Question 50

    Which of the following best describes the goal of a disaster recovery exercise as preparation for possible incidents?