An analyst reviews the following system logs from a recent breach attempt:

Which of the following techniques did the attacker attempt to use?
A security analyst analyzes the output of a web application access log for a company based in the United States.
Given the following output:

Which of the following users should be investigated first?
A binary file that might contain malicious code is hosted on an isolated machine. An analyst wants to quickly detect the malicious code.
Which of the following should the analyst use?
A security architect works with a client on security operations center (SOC) capabilities. The security architect wants to ensure the log correlation and investigation activities are accurate across the infrastructure.
Which of the following is the best for the client to implement?
Which of the following best describes why operational technology (OT) devices use compensating controls?
An analyst performs Nmap scans to determine which hosts may need to be targeted to deploy a critical Windows patch. The patch for the vulnerability is to address a critical security flaw that targets open Server Message Block (SMB) ports on Windows systems only.
The analyst scans with the following command:

$sudo nmap -Pn 10.203.10.0/24
The analyst then receives the following output:
Which of the following hosts should the analyst prioritize for patching?
Which of the following contains stakeholder contact information for incident response reporting?
An analyst executes the top command on a Linux system for an unresponsive application and observes the following output:

Which of the following is the most likely cause of this issue?
Which of the following is the most difficult for threat actors to change according to the Pyramid of Pain model?
Which of the following best describes a type of risk that exists after mitigations or controls are enacted and implemented?
The Chief Information Officer (CIO) is requiring users to phase out a legacy system that no longer receives security updates because the system will be decommissioned soon.
Which of the following risk management strategies is the CIO using?
A systems administrator is reviewing the output of a vulnerability scan.
INSTRUCTIONS -
Review the information in each tab.
Based on the organization’s environment architecture and remediation standards, select the server to be patched within 14 days and select the appropriate technique and mitigation.
If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.




Which of the following actions should an incident response analyst take during the recovery phase of the incident response process?
Which of the following best explains why sensitive data should be encrypted at rest on laptops?
A public threat intelligence report includes indicators of compromise (IoCs) for threat actors. The threat actors are exploiting a zero-day vulnerability that the vendor has not fixed.
Which of the following techniques should be used until a patch is available?
A security team deploys a new scanning solution that requires root, domain administrator, and local server administrator permissions on all systems.
Which of the following is the best way to help mitigate the risk for this level of access?
Which of the following is the best reason to heavily segment business-critical assets from within the network?
A new security operations center (SOC) manager joins a team that struggles to meet service-level agreements (SLAs). The alert backlog continues to increase daily.
Which of the following will the manager most likely need to do?
The Chief Information Security Officer wants to improve internal security measures by continuously validating and verifying access to the production environment.
Which of the following concepts best describes this practice?