<< Prev Question Next Question >>

Question 2/60

You receive an alert for malicious code that exploits Internet Explorer and runs arbitrary code on the site visitor machine. The malicous code is on an external site that is being visited by hosts on your network. Which user agent in the HTTP headers in the requests from your internal hosts warrants further investigation?

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (60q)
Question 1: Which goal of data normalization is true?...
Question 2: You receive an alert for malicious code that exploits Intern...
Question 3: Which option creates a display filter on Wireshark on a host...
Question 4: Which of the following are not components of the 5-tuple of ...
Question 5: What mechanism does the Linux operating system provide to co...
Question 6: Which of the following is not an example of the VERIS main s...
Question 7: Which option can be addressed when using retrospective secur...
Question 8: Refer to the exhibit. (Exhibit) We have performed a malware ...
1 commentQuestion 9: What is Data mapping used for? (Choose two)...
Question 10: Which netstat command show ports? (Choose two)...
Question 11: Which identifies both the source and destination location?...
Question 12: Which of the following is an example of a managed security o...
1 commentQuestion 13: In the context of incident handling phases, which two activi...
Question 14: What is accomplished in the identification phase of incident...
Question 15: Which process is being utilized when IPS events are removed ...
Question 16: DRAG DROP Drag and drop the elements of incident handling fr...
Question 17: Which CVSSv3 metric value increases when attacks consume net...
Question 18: Which element is included in an incident response plan?...
Question 19: Which string matches the regular expression r(ege)+x?...
Question 20: Which of the following is not a metadata feature of the Diam...
Question 21: Which option allows a file to be extracted from a TCP stream...
Question 22: Which type of analysis assigns values to scenarios to see wh...
Question 23: Which option is generated when a file is run through an algo...
Question 24: Which of the following is typically a responsibility of a PS...
Question 25: What is NAC?
3 commentQuestion 26: Which CVSSv3 Attack Vector metric value requires the attacke...
Question 27: Which information must be left out of a final incident repor...
1 commentQuestion 28: When performing threat hunting against a DNS server, which t...
Question 29: Refer to the Exhibit. (Exhibit) A customer reports that they...
Question 30: Which of the following is an example of a managed security o...
Question 31: You have run a suspicious file in a sandbox analysis tool to...
Question 32: Refer to the exhibit. (Exhibit) Which type of log is this an...
Question 33: Which source provides reports of vulnerabilities in software...
Question 34: Which of the following steps in the kill chain would come be...
Question 35: Which of the following is the team that handles the investig...
Question 36: Which of the following are core responsibilities of a nation...
1 commentQuestion 37: You see 100 HTTP GET and POST requests for various pages on ...
Question 38: What attribute belonging VERIS schema?...
Question 39: Which option is a misuse variety per VERIS enumerations?...
Question 40: Which feature is used to find possible vulnerable services r...
Question 41: CORRECT TEXT What is the definition of confidentiality accor...
Question 42: In VERIS, an incident is viewed as a series of events that a...
Question 43: Which network device creates and sends the initial packet of...
Question 44: What protocol is related to NAC?...
Question 45: CORRECT TEXT Based on nistsp800-61R2 what are the recommende...
Question 46: Which data type is protected under the PCI compliance framew...
1 commentQuestion 47: DRAG DROP Drag and drop the type of evidence from the left o...
Question 48: Which of the following is one of the main goals of data norm...
3 commentQuestion 49: Refer to the exhibit. (Exhibit) Which type of log is this an...
Question 50: Which of the following are the three broad categories of cyb...
Question 51: Which CVSSv3 metric value increases when the attacker is abl...
Question 52: A user on your network receives an email in their mailbox th...
Question 53: Which element is part of an incident response plan?...
Question 54: Filtering ports in wireshark?
Question 55: Which two options can be used by a threat actor to determine...
Question 56: Which option has a drastic impact on network traffic because...
Question 57: Which of the following are the three metrics, or "scores," o...
Question 58: Which CVSSv3 metric captures the level of access that is req...
1 commentQuestion 59: DRAG DROP Refer to the exhibit. (Exhibit) Drag and drop the ...
Question 60: Which type of analysis allows you to see how likely an explo...