An analyst is preparing for a technical security compliance check on all Apache servers. Which of the following will be the BEST to use? (choose one and why)
A.CIS benchmark
B. Nagios
C. OWASP
D. Untidy
E. Cain&Abel
OWASP = Open Web Application Security Project.
It is an international organisation that provides network security services along with documentation, tools and help through seminars. OWASP produces an awareness document on yeary basis. The document is OWASP's top 10. This document lists top security threats for that year and provides with adequate solutions for those problems.
An analyst is preparing for a technical security compliance check on all Apache servers. Which of...
156. A cybersecurity analyst is hired to review the security posture of a company. The cybersecurity analyst notices a very high network bandwidth consumption due to SYN floods from a small number of IP addresses. Which of the following would be the BEST action to take to support incident response? A. Increase the company's bandwidth. B. Apply ingress filters at the routers. C. Install a packet capturing tool. D. Block all SYN packets. My guess: B _______________________________________ 161. The security...
A security analyst discovers a network intrusion and quickly solves the problem by closing an unused port. Which of the following should be completed? (choose one and why) A. Vulnerability report B. Memorandum of agreement C. Reverse-engineering incident report D. Lessons learned report
376. A security analyst receives a mobile device with symptoms of a virus infection. The virus is morphing whenever it is from sandbox to sandbox to analyze. Which of the following will help to identify the number of variations through the analysis life cycle? A. Journaling B. Hashing utilities C. Log viewers D. OS and process analysis My guess: C Other’s answer: D __________________________________________________ 378. Which of the following BEST describes why vulnerabilities found in ICS and SCADA can be...
Malicious users utilized brute force to access a system. A cyber security analyst is investigating these attacks and recommends methods to management that would help secure the system. Which of the following controls should the analyst recommend? (Choose three.) A. Multifactor authentication B. Network segmentation C. Single sign-on D. Encryption E. Complexity policy F. Biometrics G. Obfuscation --------------------------------------------------------------------------------------------------------- A cyber security analyst was tasked with providing recommendations of technologies that are PKI X.509 compliant for a variety of secure functions....
A staff member reported that a laptop has degraded performance. The security analyst has investigated the issue and discovered that CPU utilization, memory utilization, and outbound network traffic are consuming the laptop resources. Which of the following is the BEST course of actions to resolve the problem? (choose one and why) Identify and remove malicious processes. Disable scheduled tasks. Suspend virus scan. Increase laptop memory. Ensure the laptop OS is properly patched.
Which type of security safeguard is human dependent? Key attributes of an EHR are: Select one: Oa. Accessibility via secure servers O b. Fast patient billing Select one a. Administrators and manuals b. Physical c. Technical d. All of the above O O c.Almost instant information retrieval. O d. A and C are correct.. Health Level 7 (HL-7) sèts standards for all of the following e ment structure related to patient medical reco Who is liable related to legal issues...
A cyber security analyst finds that unpatched servers have
undetected vulnerabilities because the vulnerability scanner does
not have the latest set of signatures. Management directed the
security team to have personnel update the scanners with the latest
signatures at least 24 hours before conducting any scans, but the
outcome is unchanged. Which of the following is the BEST logical
control to address the failure?
A. Manually validate that the existing update is being
performed.
B. Configure a script to automatically...
Which of the following is not a motivation to manipulate earnings? A. Remain in compliance with debt covenants. B. Meet analyst expectation. C. Reduce tax obligation. D. All of the above.
During a table top exercise, it is determined that a security analyst is required to ensure patching and scan reports are available during an incident, as well as documentation of all critical systems. To which of the following stakeholders should the analyst provide the reports? A Management B Affected Vendors C Security Operations D Legal
The help desk informed a security analyst of a trend that is beginning to develop regarding a suspicious email that has been reported by multiple users. The analyst has determined the email includes an attachment named invoice.zip that contains the following files: Locky.js xerty.ini xerty.lib Further analysis indicates that when the zip file is opened, it is installing a new version of ransomware on the devices. Which of the following should be done FIRST to prevent data on the company...