A recent zero-day vulnerability is being actively exploited, requires no user interaction or privilege escalation, and has a significant impact to confidentiality and integrity but not to availability. Which of the following CVE metrics would be most accurate for this zero-day threat?
Answer and explanation
Correct answer: A
Question 2
Which of the following tools would work best to prevent the exposure of PII outside of an organization?
Answer and explanation
Correct answer: D
Question 3
An organization conducted a web application vulnerability assessment against the corporate website, and the following output was observed:Which of the following tuning recommendations should the security analyst share?
Answer and explanation
Correct answer: C
Question 4
Multiple answers
Which of the following items should be included in a vulnerability scan report? (Choose two.)
Answer and explanation
Correct answers: D, E
Question 5
The Chief Executive Officer of an organization recently heard that exploitation of new attacks in the industry was happening approximately 45 days after a patch was released. Which of the following would best protect this organization?
Answer and explanation
Correct answer: A
Question 6
A security analyst recently joined the team and is trying to determine which scripting language is being used in a production script to determine if it is malicious. Given the following script:Which of the following scripting languages was used in the script?
Answer and explanation
Correct answer: A
Question 7
A company's user accounts have been compromised. Users are also reporting that the company's internal portal is sometimes only accessible through HTTP, other times; it is accessible through HTTPS. Which of the following most likely describes the observed activity?
Answer and explanation
Correct answer: B
Question 8
A security analyst is tasked with prioritizing vulnerabilities for remediation. The relevant company security policies are shown below:Security Policy 1006: Vulnerability Management1. The Company shall use the CVSSv3.1 Base Score Metrics (Exploitability and Impact) to prioritize the remediation of security vulnerabilities.2. In situations where a choice must be made between confidentiality and availability, the Company shall prioritize confidentiality of data over availability of systems and data.3. The Company shall prioritize patching of publicly available systems and services over patching of internally available system.According to the security policy, which of the following vulnerabilities should be the highest priority to patch?
Answer and explanation
Correct answer: B
Question 9
Which of the following will most likely ensure that mission-critical services are available in the event of an incident?
Answer and explanation
Correct answer: A
Question 10
The Chief Information Security Officer wants to eliminate and reduce shadow IT in the enterprise. Several high-risk cloud applications are used that increase the risk to the organization. Which of the following solutions will assist in reducing the risk?
Answer and explanation
Correct answer: A
Question 11
A security analyst is reviewing a new cloud architecture proposal that utilizes a dedicated secure access layer to connect users to applications. The architecture combines SD-WAN capabilities with comprehensive security functions such as SWG, CASB, FWaaS, and ZTNA, delivered primarily as a service. Which of the following terms BEST describes this architecture?
Secure Access Service Edge (SASE) is a network architecture that combines WAN capabilities (like SD-WAN) with comprehensive cloud-native security functions (SWG, CASB, FWaaS, ZTNA) to support dynamic, secure access needs. The diagram illustrates users connecting to a unified cloud edge that applies security policies before granting access to resources.
Question 12
During a vulnerability scan analysis, an analyst identifies a critical finding on a legacy server. The vulnerability allows remote code execution (RCE) but requires the attacker to have an existing low-privileged user account on the system. The server is located in a segmented VLAN with no direct internet access. When calculating the CVSS v3.1 score to prioritize this vulnerability, which Attack Vector (AV) metric should be selected?
Answer and explanation
Correct answer: A
The Attack Vector (AV) is 'Network' (N) because the vulnerability is exploitable remotely over the network (the VLAN). Even though the server is internal and requires a user account (which affects Privileges Required, not Attack Vector), the technical means of exploitation is the network stack. 'Local' would imply the attacker needs physical access or a shell.
Question 13
A SOC analyst is investigating a suspicious process on a Windows endpoint. The process svchost.exe is initiating outbound connections to an external IP address on port 4444. The analyst runs Get-Process in PowerShell and notices the process has no parent ID link to services.exe and is running from C:\Temp. Which phase of the Cyber Kill Chain is MOST likely being observed?
Answer and explanation
Correct answer: C
The scenario describes an active malware implant (masquerading as svchost.exe) communicating externally on a non-standard port (4444). This outbound communication to receive instructions or exfiltrate data is the definition of the Command and Control (C2) phase. The file location (Temp) and parent process mismatch confirm it is not a legitimate service.
Question 14
An organization is preparing its quarterly executive security report. The CISO requests a metric that best communicates the efficiency of the security team in neutralizing confirmed threats once they are detected. Which of the following KPIs should be highlighted?
Answer and explanation
Correct answer: B
Mean Time to Respond (MTTR) measures the average time it takes to control, remediate, or eradicate a threat after it has been detected. This is the primary metric for efficiency in neutralizing threats. MTTD focuses on the time before detection.
Question 15
A security analyst is writing a Python script to parse a large volume of JSON logs from a web application firewall. The goal is to identify IP addresses that have triggered more than 100 SQL injection alerts in the last hour. Which of the following logical structures would be MOST appropriate for this task?
Answer and explanation
Correct answer: A
Using a dictionary (hash map) is the most efficient way to count occurrences of IP addresses. The script would iterate through the logs, incrementing the count for each IP found in an SQLi alert, and then filter for counts > 100. Arrays or lists are less efficient for lookups and counting unique items.