An incident response team identifies a malicious uniform resource locator (URL) associated with a required business process and performs the following activities:
• Access to the URL has been restricted only to the necessary users through firewall rules and Cloud Security Group rules.
• Additional monitoring has been enabled for traffic related to that site and the allowed users.
• All application servers that need to access that site have been patched with the latest security and software updates.
• Application owners have been notified of the severity and need to remediate this reported issue.
Which of the following best describes the overall mitigation the security team is performing?
A security analyst isolates a Windows 11 workstation from the network after known malware is detected. The list of security information and event management (SIEM) events during the malware installation and timeline does not identify a specific user who was logged in. The security analyst uses the local administrative account to log in and would like a list of logins to the machine.
Which of the following PowerShell commands should the analyst use?
An analyst is configuring a security information and event management system to capture fileless malware execution events.
Which of the following log files requires additional configuration to accomplish this task?
Which of the following best explains why sensitive data should be encrypted at rest on laptops?
Which of the following best explains the purpose of the Pyramid of Pain in threat intelligence?
An analyst prepares an after action report following an incident in which multiple systems were compromised over several days.
The analyst provides raw event logs from each compromised system in the report and determines that a patient-zero system cannot be found.
Which of the following should the analyst do to determine the patient-zero system?
The Chief Information Officer (CIO) is requiring users to phase out a legacy system that no longer receives security updates because the system will be decommissioned soon.
Which of the following risk management strategies is the CIO using?
A vulnerability analyst conducts a security assessment on the Remote Desktop Protocol (RDP) security posture within the environment.
The analyst issues the following command for the assessment: nmap -p 3389 --script rdp* 10.0.0.0/24 The analyst receives responses, which are divided into one of the two categories, from 13 out of the 254 hosts:

Which of the following conclusions can the analyst make about the output on Category 2?
A security analyst receives a notice about a possible data breach. The report identifies unapproved, current access dates for files found in the following personnel archives:

Which of the following actions should the analyst take first?
An analyst reviews a summarized vulnerability report through a governance, risk, and compliance (GRC) reporting tool.
The following report correlates asset information from the configuration management database (CMDB) against detected vulnerabilities:

Which of the following servers should the analyst prioritize based on the target value, the risk, and the likelihood of exploitation?