01. During which of the following incident response phases would root cause analysis occur?
a) Post-incident activity
b) Detection and analysis
c) Containment, eradication, and recovery
d) Preparation
02. A manufacturing company's assembly line machinery only functions on an end-of-life operating system. Consequently, no patches exist for several highly exploitable operating system vulnerabilities. Which of the following is the best mitigating control to reduce the risk of these current conditions?
a) Perform penetration testing to verify the exploitability of these vulnerabilities.
b) Increase the system resources for vulnerable devices to prevent denial of service.
c) Develop in-house patches to address these vulnerabilities.
d) Enforce strict network segmentation to isolate vulnerable systems from the production network.
03. During a cybersecurity incident, one of the web servers at the perimeter network was affected by ransomware. Which of the following actions should be performed immediately?
a) Reimage the server.
b) Update the OS to latest version.
c) Quarantine the server.
d) Shut down the server.
04. An organization's security operations team has been dealing with fake news reports about potential cyberattacks that could impact the organization's systems. Which of the following is the most trusted source for gathering threat intelligence?
a) Dark web cyber resource groups
b) Industry-related government bulletins
c) Popular hacker blogs
d) Cybersecurity social media groups
05. A SOC analyst determined that a significant number of the reported alarms could be closed after removing the duplicates. Which of the following could help the analyst reduce the number of alarms with the least effort?
a) SOAR
b) API
c) REST
d) XDR
06. A cybersecurity analyst is doing triage in a SIEM and notices that the time stamps between the firewall and the host under investigation are off by 43 minutes. Which of the following is the most likely scenario occurring with the time stamps?
a) The host with the logs is offline.
b) The NTP server is not configured on the host.
c) The cybersecurity analyst is looking at the wrong information.
d) The firewall is using UTC time.
07. There are several reports of sensitive information being disclosed through file sharing services. The company would like to improve its security posture against this threat. Which of the following security controls would best support the company in this scenario?
a) Increase password complexity standards
b) Deploy mobile device management
c) Improve employee training and awareness
d) Implement step-up authentication for administrators
08. Which of the following best describes the document that defines the expectation to network customers that patching will occur only between 2:00 a.m. and 4:00 a.m.?
a) SLA
b) LOI
c) MOU
d) KPI
09. A company receives a penetration test report summary from a third party. The summary indicates that a proxy has some patches that need to be applied. The proxy is sitting in a rack and is not being used, as the company has replaced it with a new one. The CVSS score of the vulnerability on the proxy is 9.8.
Which of the following best practices should the company follow with this proxy?
a) Leave the proxy as is.
b) Patch the proxy.
c) Migrate the proxy to the cloud.
d) Decommission the proxy.
10. You are reviewing the following CVSS vector for a reported vulnerability:
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which of the following attributes correctly describes this vulnerability?
a) A user is required to exploit this vulnerability.
b) The complexity to exploit the vulnerability is high.
c) The vulnerability is network based.
d) The vulnerability does not affect confidentiality.