CS0-003 Exam Question 76

A threat intelligence analyst is updating a document according to the MITRE ATT & CK framework. The analyst detects the following behavior from a malicious actor: "The malicious actor will attempt to achieve unauthorized access to the vulnerable system." In which of the following phases should the analyst include the detection?
  • CS0-003 Exam Question 77

    A security analyst receives the below information about the company ' s systems. They need to prioritize which systems should be given the resources to improve security.
    Host
    OS
    Key Software
    AV
    Server 1
    Windows Server 2008 R2
    Microsoft IIS
    Kaspersky
    Server 2
    Ubuntu Server 22.04 LTS
    Apache 2.4.29
    None
    Computer 1
    Windows 11 Professional
    N/A
    Windows Defender
    Computer 2
    Windows 10 Professional
    N/A
    Windows Defender
    Which of the following systems should the analyst remediate first?
  • CS0-003 Exam Question 78

    A high volume of failed RDP authentication attempts was logged on a critical server within a one-hour period.
    All of the attempts originated from the same remote IP address and made use of a single valid domain user account. Which of the following would be the most effective mitigating control to reduce the rate of success of this brute-force attack?
  • CS0-003 Exam Question 79

    After completing a review of network activity. the threat hunting team discovers a device on the network that sends an outbound email via a mail client to a non-company email address daily at 10:00 p.m. Which of the following is potentially occurring?
  • CS0-003 Exam Question 80

    A security analyst is validating a particular finding that was reported in a web application vulnerability scan to make sure it is not a false positive. The security analyst uses the snippet below:

    Which of the following vulnerability types is the security analyst validating?