<< Prev Question Next Question >>

Question 211/346

What should be the FIRST action for a security administrator who detects an intrusion on the network based on precursors and other indicators?

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (346q)
Question 1: Which of the following methods MOST efficiently manages user...
Question 2: What is the BEST location in a network to place Virtual Priv...
Question 3: The core component of Role Based Access control (RBAC) must ...
Question 4: What is the MAIN purpose of a change management policy?...
Question 5: Reciprocal backup site agreements are considered to be...
Question 6: Which of the following authorization standards is built to h...
Question 7: Knowing the language in which an encrypted message was origi...
Question 8: When dealing with shared, privilaged accounts, especially th...
Question 9: Which of the following prevents improper aggregation of priv...
Question 10: During an investigation of database theft from an organizati...
Question 11: During a fingerprint verification process, which of the foll...
Question 12: Without proper signal protection, embedded systems may be pr...
Question 13: In a financial institution, who has the responsibility for a...
Question 14: Which of the following represents the GREATEST risk to data ...
Question 15: Which of the following is a standard Access Control List (AC...
Question 16: A health care provider is considering Internet access for th...
Question 17: Which security action should be taken FIRST when computer pe...
Question 18: Which of the following MUST a security professional do in or...
Question 19: What is the MOST important reason to configure unique user I...
Question 20: What type of attack sends Internet Control Message Protocol ...
Question 21: An organization has a short-term agreement with a public Clo...
Question 22: In configuration management, what baseline configuration inf...
Question 23: Which of the following activities BEST identifies operationa...
Question 24: Which of the following does the Encapsulating Security Paylo...
Question 25: Host-Based Intrusion Protection (HIPS) systems are often dep...
Question 26: How can lessons learned from business continuity training an...
Question 27: Network-based logging has which advantage over host-based lo...
Question 28: Which of the following is a function of Security Assertion M...
Question 29: Which is the second phase of public key Infrastructure (pk1)...
Question 30: Which of the following BEST avoids data remanence disclosure...
Question 31: How does an organization verify that an information system's...
Question 32: Including a Trusted Platform Module (TPM) in the design of a...
Question 33: Which of the following is part of a Trusted Platform Module ...
Question 34: A user downloads a file from the Internet, then applies the ...
Question 35: Which of the following information MUST be provided for user...
Question 36: A security professional has been asked to evaluate the optio...
Question 37: A user sends an e-mail request asking for read-only access t...
Question 38: What type of wireless network attack BEST describes an Elect...
Question 39: Which of the following is the BEST defense against password ...
Question 40: What technique BEST describes antivirus software that detect...
Question 41: A network scan found 50% of the systems with one or more cri...
Question 42: Which factors MUST be considered when classifying informatio...
Question 43: In which order, from MOST to LEAST impacted, does user aware...
Question 44: When developing solutions for mobile devices, in which phase...
Question 45: Which of the following mechanisms will BEST prevent a Cross-...
Question 46: Which of the following provides effective management assuran...
Question 47: Which of the following is a direct monetary cost of a securi...
Question 48: What access control scheme uses fine-grained rules to specif...
Question 49: Contingency plan exercises are intended to do which of the f...
Question 50: A client has reviewed a vulnerability assessment report and ...
Question 51: An organization plan on purchasing a custom software product...
Question 52: A criminal organization is planning an attack on a governmen...
Question 53: Which of the following is considered the last line defense i...
Question 54: Why is a system's criticality classification important in la...
Question 55: An organization has hired a security services firm to conduc...
Question 56: The use of private and public encryption keys is fundamental...
Question 57: Why do certificate Authorities (CA) add value to the securit...
Question 58: Which Redundant Array c/ Independent Disks (RAID) Level does...
Question 59: A client has reviewed a vulnerability assessment report and ...
Question 60: What is the PRIMARY advantage of using automated application...
Question 61: Why should Open Web Application Security Project (OWASP) App...
Question 62: With what frequency should monitoring of a control occur whe...
Question 63: Which of the following is BEST achieved through the use of e...
Question 64: Why might a network administrator choose distributed virtual...
Question 65: Data remanence is the biggest threat in which of the followi...
Question 66: Backup information that is critical to the organization is i...
Question 67: Which of the following job functions MUST be separated to ma...
Question 68: An employee of a retail company has been granted an extended...
Question 69: Which of the following is a characteristic of convert securi...
Question 70: Which of the following is the BEST countermeasure to brute f...
Question 71: When using third-party software developers, which of the fol...
Question 72: Which of the following steps should be performed FIRST when ...
Question 73: For the purpose of classification, which of the following is...
Question 74: Who determines the required level of independence for securi...
Question 75: The goal of a Business Continuity Plan (BCP) training and aw...
Question 76: Which of the following is the MAIN reason that system re-cer...
Question 77: Which of the following can BEST prevent security flaws occur...
Question 78: Unused space in a disk cluster is important in media analysi...
Question 79: Match the objectives to the assessment questions in the gove...
Question 80: Which of the following is the PRIMARY security consideration...
Question 81: Which of the following presents the PRIMARY concern to an or...
Question 82: What is the FIRST step required in establishing a records re...
Question 83: The restoration priorities of a Disaster Recovery Plan (DRP)...
Question 84: Which of the following is the FIRST step of a penetration te...
Question 85: Discretionary Access Control (DAC) restricts access accordin...
Question 86: Digital certificates used in Transport Layer Security (TLS) ...
Question 87: Given a file containing ordered number, i.e. "123456789," ma...
Question 88: When implementing controls in a heterogeneous end-point netw...
Question 89: A thorough review of an organization's audit logs finds that...
Question 90: Which of the following is a security feature of Global Syste...
Question 91: It is MOST important to perform which of the following to mi...
Question 92: The configuration management and control task of the certifi...
Question 93: Which one of the following considerations has the LEAST impa...
Question 94: After a thorough analysis, it was discovered that a perpetra...
Question 95: Intellectual property rights are PRIMARY concerned with whic...
Question 96: An organization is selecting a service provider to assist in...
Question 97: What is the process called when impact values are assigned t...
Question 98: A development operations team would like to start building n...
Question 99: Which of the following management processes allots ONLY thos...
Question 100: Which of the following is an effective method for avoiding m...
Question 101: Which of the following is the GREATEST security risk associa...
Question 102: Which of the following could be considered the MOST signific...
Question 103: As one component of a physical security system, an Electroni...
Question 104: Which of the following types of security testing is the MOST...
Question 105: A vulnerability assessment report has been submitted to a cl...
Question 106: An external attacker has compromised an organization's netwo...
Question 107: Within the company, desktop clients receive Internet Protoco...
Question 108: An important principle of defense in depth is that achieving...
Question 109: Secure Sockets Layer (SSL) encryption protects...
Question 110: Which of the following MUST be scalable to address security ...
Question 111: While investigating a malicious event, only six days of audi...
Question 112: Which of the following is a weakness of Wired Equivalent Pri...
Question 113: Which of the following is MOST important when assigning owne...
Question 114: In what phase of the System Development Life Cycle (SDLC) sh...
Question 115: Refer to the information below to answer the question. An or...
Question 116: Which of the following can be used to calculate the loss eve...
Question 117: Which of the following is the MOST important consideration w...
Question 118: What is the expected outcome of security awareness in suppor...
Question 119: copyright provides protection for which of the following?...
Question 120: Sensitive customer data is going to be added to a database. ...
Question 121: Which of the following BEST describes the responsibilities o...
Question 122: Refer to the information below to answer the question. An or...
Question 123: When implementing a secure wireless network, which of the fo...
Question 124: Which of the following is a characteristic of a challenge/re...
Question 125: Which of the following is the MOST important part of an awar...
Question 126: When writing security assessment procedures, what is the MAI...
Question 127: A company was ranked as high in the following National Insti...
Question 128: When in the Software Development Life Cycle (SDLC) MUST soft...
Question 129: Which of the following is a MAJOR concern when there is a ne...
Question 130: Refer to the information below to answer the question. A new...
Question 131: Although code using a specific program language may not be s...
Question 132: Who is ultimately responsible to ensure that information ass...
Question 133: During an audit, the auditor finds evidence of potentially i...
Question 134: Which of the following is an important requirement when desi...
Question 135: Configuring a Wireless Access Point (WAP) with the same Serv...
Question 136: What is the PRIMARY goal for using Domain Name System Securi...
Question 137: What is the BEST method if an investigator wishes to analyze...
Question 138: An organization operates a legacy Industrial Control System ...
Question 139: During the risk assessment phase of the project the CISO dis...
Question 140: The birthday attack is MOST effective against which one of t...
Question 141: Which of the following is the MOST important reason for usin...
Question 142: When deploying en Intrusion Detection System (IDS) on a high...
Question 143: A mobile device application that restricts the storage of us...
Question 144: Which of the following is the MOST effective preventative me...
Question 145: Retaining system logs for six months or longer can be valuab...
Question 146: Refer to the information below to answer the question. A lar...
Question 147: Internet Protocol (IP) source address spoofing is used to de...
Question 148: A Business Continuity Plan/Disaster Recovery Plan (BCP/DRP) ...
Question 149: As a best practice, the Security Assessment Report (SAR) sho...
Question 150: In order for a security policy to be effective within an org...
Question 151: When determining who can accept the risk associated with a v...
Question 152: Which of the following is a physical security control that p...
Question 153: Why is planning in Disaster Recovery (DR) an interactive pro...
Question 154: Which of the following is the BEST way to mitigate circumven...
Question 155: Which of the following techniques is effective to detect tap...
Question 156: Which of the following is an attacker MOST likely to target ...
Question 157: When defining a set of security controls to mitigate a risk,...
Question 158: In order for application developers to detect potential vuln...
Question 159: What protocol is often used between gateway hosts on the Int...
Question 160: Which of the following is the BEST reason for writing an inf...
Question 161: Which one of the following activities would present a signif...
Question 162: Information security metrics provide the GREATEST value tp m...
Question 163: Which of the following is the MOST important goal of informa...
Question 164: An application developer is deciding on the amount of idle s...
Question 165: Which of the following approaches is the MOST effective way ...
Question 166: Refer to the information below to answer the question. In a ...
Question 167: Which of the following is the MOST appropriate action when r...
Question 168: What is the BEST way to correlate large volumes of disparate...
Question 169: When conducting a security assessment of access controls, wh...
Question 170: What is the MOST important element when considering the effe...
Question 171: Which of the following would an internal technical security ...
Question 172: What are the steps of a risk assessment?...
Question 173: Which type of test would an organization perform in order to...
Question 174: What is the second phase of public key infrastructure (PKI) ...
Question 175: What is the MAIN goal of information security awareness and ...
Question 176: Which of the following is the PRIMARY risk with using open s...
Question 177: In fault-tolerant systems, what do rollback capabilities per...
Question 178: Which of the following needs to be included in order for Hig...
Question 179: Which of the following was developed to support multiple pro...
Question 180: Which of the following in the BEST way to reduce the impact ...
Question 181: Which of the following is a security weakness in the evaluat...
Question 182: Which security approach will BEST minimize Personally Identi...
Question 183: Refer to the information below to answer the question. A lar...
Question 184: Which of the following MUST system and database administrato...
Question 185: A company-wide penetration test result shows customers could...
Question 186: Which type of test suite should be run for fast feedback dur...
Question 187: What is one way to mitigate the risk of security flaws in cu...
Question 188: Which of the following is the MOST important reason for time...
Question 189: Why are mobile devices something difficult to investigate in...
Question 190: An organization has discovered that users are visiting unaut...
Question 191: At which layer of the Open Systems Interconnect (OSI) model ...
Question 192: While impersonating an Information Security Officer (ISO), a...
Question 193: By allowing storage communications to run on top of Transmis...
Question 194: Which of the following is the BEST reason to review audit lo...
Question 195: Refer to the information below to answer the question. A sec...
Question 196: An organization discovers that its secure file transfer prot...
Question 197: Which of the following activities is MOST likely to be perfo...
Question 198: How should the retention period for an organization's social...
Question 199: Which of the following is the PRIMARY reason to perform regu...
Question 200: When using Security Assertion markup language (SAML), it is ...
Question 201: How long should the records on a project be retained?...
Question 202: How does identity as a service (IDaaS) provide an easy mecha...
Question 203: Which of the following BEST describes the standard used to e...
Question 204: Which of the following elements MUST a compliant EU-US Safe ...
Question 205: What is the second step in the identity and access provision...
Question 206: Attack trees are MOST useful for which of the following?...
Question 207: Recovery strategies of a Disaster Recovery planning (DRIP) M...
Question 208: A security compliance manager of a large enterprise wants to...
Question 209: Which of the following mandates the amount and complexity of...
Question 210: The BEST method to mitigate the risk of a dictionary attack ...
Question 211: What should be the FIRST action for a security administrator...
Question 212: Why are packet filtering routers used in low-risk environmen...
Question 213: As users switch roles within an organization, their accounts...
Question 214: Identify the component that MOST likely lacks digital accoun...
Question 215: Which of the following is the MOST likely cause of a non-mal...
Question 216: Organization A is adding a large collection of confidential ...
Question 217: Which of the following is a responsibility of the informatio...
Question 218: What should happen when an emergency change to a system must...
Question 219: Place the following information classification steps in sequ...
Question 220: The MAIN use of Layer 2 Tunneling Protocol (L2TP) is to tunn...
Question 221: The process of mutual authentication involves a computer sys...
Question 222: Which of the following combinations would MOST negatively af...
Question 223: When is a Business Continuity Plan (BCP) considered to be va...
Question 224: What is the MOST significant benefit of an application upgra...
Question 225: When designing a vulnerability test, which one of the follow...
Question 226: Which Identity and Access Management (IAM) process can be us...
Question 227: Refer to the information below to answer the question. A sec...
Question 228: Which of the following is the MOST significant benefit to im...
Question 229: Which of the following methods provides the MOST protection ...
Question 230: Physical Access Control Systems (PACS) allow authorized secu...
Question 231: Which layer handle packet fragmentation and reassembly in th...
Question 232: Which of the following is the MOST important security goal w...
Question 233: What is the PRIMARY purpose of auditing, as it relates to th...
Question 234: The amount of data that will be collected during an audit is...
Question 235: A security architect is responsible for the protection of a ...
Question 236: An organization has outsourced its financial transaction pro...
Question 237: Which of the following is the MOST common method of memory p...
Question 238: If an attacker in a SYN flood attack uses someone else's val...
Question 239: Refer to the information below to answer the question. An or...
Question 240: Which of the following is the BEST way to determine if a par...
Question 241: A vehicle of a private courier company that transports backu...
Question 242: Which of the following is the reason that transposition ciph...
Question 243: Match the functional roles in an external audit to their res...
Question 244: By carefully aligning the pins in the lock, which of the fol...
Question 245: Which of the following BEST describes the purpose of perform...
Question 246: What is the best way for mutual authentication of devices be...
Question 247: Which of the following types of data would be MOST difficult...
Question 248: For an organization considering two-factor authentication fo...
Question 249: Which of the following practices provides the development te...
Question 250: A chemical plan wants to upgrade the Industrial Control Syst...
Question 251: Application of which of the following Institute of Electrica...
Question 252: Which of the following restricts the ability of an individua...
Question 253: The design review for an application has been completed and ...
Question 254: An organization has developed a major application that has u...
Question 255: What are the roles within a scrum methodoligy?...
Question 256: Why MUST a Kerberos server be well protected from unauthoriz...
Question 257: What is an important characteristic of Role Based Access Con...
Question 258: What is the GREATEST challenge to identifying data leaks?...
Question 259: Which of the following is the PRIMARY consideration when det...
Question 260: Which of the following describes the BEST configuration mana...
Question 261: Which of the following is the primary advantage of segmentin...
Question 262: Asymmetric algorithms are used for which of the following wh...
Question 263: Which of the following is the MOST critical success factor i...
Question 264: What is the BEST approach for controlling access to highly s...
Question 265: Which of the following is the BEST definition of Cross-Site ...
Question 266: Who in the organization is accountable for classification of...
Question 267: A financial company has decided to move its main business ap...
Question 268: Which of the following MOST applies to session initiation pr...
Question 269: An organization's data policy MUST include a data retention ...
Question 270: Which of the following BEST describes an access control meth...
Question 271: Which of the following provides the minimum set of privilege...
Question 272: Refer to the information below to answer the question. A sec...
Question 273: Which of the following practices provides the development of...
Question 274: Which of the following assessment metrics is BEST used to un...
Question 275: With data labeling, which of the following MUST be the key d...
Question 276: Which of the following types of technologies would be the MO...
Question 277: Which of the following authorization standards is built to h...
Question 278: What is the BEST first step for determining if the appropria...
Question 279: Which of the following is an example of two-factor authentic...
Question 280: How does a Host Based Intrusion Detection System (HIDS) iden...
Question 281: The 802.1x standard provides a framework for what?...
Question 282: Which of the following would BEST describe the role directly...
Question 283: Which of the following is MOST critical in a contract in a c...
Question 284: Which of the following is MOST effective in detecting inform...
Question 285: Following the completion of a network security assessment, w...
Question 286: Which of the following is MOST important when deploying digi...
Question 287: Which of the following is a peor entity authentication metho...
Question 288: Directive controls are a form of change management policy an...
Question 289: What does the result of Cost-Benefit Analysis (C8A) on new s...
Question 290: In which identity management process is the subject's identi...
Question 291: An analysis finds unusual activity coming from a computer th...
Question 292: During a Disaster Recovery (DR) assessment, additional cover...
Question 293: Once the types of information have been identified, who shou...
Question 294: Which of the following is a security limitation of File Tran...
Question 295: Which of the following BEST describes a Protection Profile (...
Question 296: Order the below steps to create an effective vulnerability m...
Question 297: What type of access control determines the authorization to ...
Question 298: Which of the following is a MAJOR consideration in implement...
Question 299: If a content management system (CSM) is implemented, which o...
Question 300: Individual access to a network is BEST determined based on...
Question 301: A company has decided that they need to begin maintaining as...
Question 302: Which of the following is the MOST important consideration t...
Question 303: An advantage of link encryption in a communications network ...
Question 304: An Intrusion Detection System (IDS) has recently been deploy...
Question 305: A security professional should ensure that clients support w...
Question 306: Which methodology is recommended for penetration testing to ...
Question 307: Who is essential for developing effective test scenarios for...
Question 308: Drag the following Security Engineering terms on the left to...
Question 309: What is the PRIMARY role of a scrum master in agile developm...
Question 310: Which of the following roles has the obligation to ensure th...
Question 311: Which of the following techniques BEST prevents buffer overf...
Question 312: Which of the following is the MOST important consideration w...
Question 313: Which of the following is the BEST reason for the use of sec...
Question 314: The goal of software assurance in application development is...
Question 315: Due to system constraints, a group of system administrators ...
Question 316: Which would result in the GREATEST import following a breach...
Question 317: What operations role is responsible for protecting the enter...
Question 318: When network management is outsourced to third parties, whic...
Question 319: Which of the following is the PRIMARY security concern assoc...
Question 320: Which of the following is an effective control in preventing...
Question 321: When using Generic Routing Encapsulation (GRE) tunneling ove...
Question 322: Which of the following technologies would provide the BEST a...
Question 323: The security accreditation task of the System Development Li...
Question 324: The MAIN reason an organization conducts a security authoriz...
Question 325: After following the processes defined within the change mana...
Question 326: Refer to the information below to answer the question. Durin...
Question 327: Two companies wish to share electronic inventory and purchas...
Question 328: Which of the following controls is the most for a system ide...
Question 329: When building a data center, site location and construction ...
Question 330: Which of the following processes has the PRIMARY purpose of ...
Question 331: Which of the following is a characteristic of an internal au...
Question 332: What is the BEST method to detect the most common improper i...
Question 333: How should an organization determine the priority of its rem...
Question 334: Refer to the information below to answer the question. A lar...
Question 335: Which one of the following affects the classification of dat...
Question 336: Which of the following questions can be answered using user ...
Question 337: Refer to the information below to answer the question. Deskt...
Question 338: During a Disaster Recovery (DR) simulation, it is discovered...
Question 339: If a content management system (CMC) is implemented, which o...
Question 340: Which of the following statements is TRUE for point-to-point...
Question 341: Which of the following is the PRIMARY concern when using an ...
Question 342: Which of the following is a network intrusion detection tech...
Question 343: Which of the following is generally indicative of a replay a...
Question 344: A security professional has been requested by the Board of D...
Question 345: Which of the following is a recommended alternative to an in...
Question 346: A software security engineer is developing a black box-based...