An analyst must provide a visualization of data received from threat intelligence sources. The data includes the Internet Protocols, services, and tools used by threat actors.
Which of the following is the best framework for the analyst to follow to display this data?
A vulnerability analyst must perform a security assessment on an edge device running various services.
The analyst runs an Nmap port scan and sees the following output:

Which of the following should the analyst do next to validate the discovered remote access service is secure?
A security analyst responds to an alert regarding identity and access management activity within the cloud environment. The attacker is currently trying to gain access from one isolated cloud subscription to another via a compromised user role.
Which of the following aspects of the MITRE ATT & CK framework is the attacker trying to perform?
An analyst executes the top command on a Linux system for an unresponsive application and observes the following output:

Which of the following is the most likely cause of this issue?
An analyst reviews the following system logs from a recent breach attempt:

Which of the following techniques did the attacker attempt to use?
The vulnerability management team must scan the cloud environment to establish security baselines.
Which of the following assessment tools should the team use to perform this task?
An analyst prepares an after action report following an incident in which multiple systems were compromised over several days.
The analyst provides raw event logs from each compromised system in the report and determines that a patient-zero system cannot be found.
Which of the following should the analyst do to determine the patient-zero system?
A security architect reviews a report from a third-party incident response consultant and observes the following:

Which of the following frameworks did the consultant use to perform analysis?
Which of the following phases of the incident response process will permanently remove an attacker’s access to corporate resources?
Multiple users report unexpected mouse movements and terminal windows opening.
An analyst reviewing the network traffic logs observes the following:

Which of the following is the most likely reason for the reported symptoms?
An incident response team identifies a malicious uniform resource locator (URL) associated with a required business process and performs the following activities:
• Access to the URL has been restricted only to the necessary users through firewall rules and Cloud Security Group rules.
• Additional monitoring has been enabled for traffic related to that site and the allowed users.
• All application servers that need to access that site have been patched with the latest security and software updates.
• Application owners have been notified of the severity and need to remediate this reported issue.
Which of the following best describes the overall mitigation the security team is performing?
Which of the following network architectures would best implement a perimeter-less network topology?
An analyst reviews the following log entries:

Which of the following conclusions should the analyst reach? (Choose two.)
Before merging with a software company, the acquiring company's legal team requires a detailed software scan to determine if all code base is using open-source or paid licensed libraries. The vulnerability management analyst needs to provide this report.
Which of the following scan methods will best meet this requirement?
A server was recently compromised. A security analyst needs to collect artifacts for further analysis before disconnecting the server from the network.
Which of the following artifacts should the analyst collect first?
Which of the following is the most likely reason an organization might implement compensating controls?
A cybersecurity analyst receives an unstructured text document that contains advanced persistent threat (APT)-related indicators of compromise (IoCs). The analyst needs to extract the IPv4 addresses.
Which of the following is the best tool to accomplish this task?
An analyst reviews a summarized vulnerability report through a governance, risk, and compliance (GRC) reporting tool.
The following report correlates asset information from the configuration management database (CMDB) against detected vulnerabilities:

Which of the following servers should the analyst prioritize based on the target value, the risk, and the likelihood of exploitation?
An analyst needs to perform a baseline security evaluation of the company's cloud infrastructure.
Which of the following tools is most appropriate for this task?
Which of the following actions should an incident response analyst take during the recovery phase of the incident response process?