Logical Operations CyberSec First Responder - CFR-210무료 덤프문제 풀어보기

A security analyst for a financial services firm is monitoring blogs and reads about a zero-day vulnerability
being exploited by a little-known group of hackers. The analyst wishes to independently validate and
corroborate the blog's posting. Which of the following sources of information will provide the MOST
credible supporting threat intelligence in this situation?

정답: D
An organization's public information website has been defaced. The incident response team is actively
engaged in the following actions:
-Installing patches on the web server
-Turning off unnecessary services on web server
-Adding new ACL rules to the WAF
-Changing all passwords on web server accounts
Which of the following incident response phases is the team MOST likely conducting?

정답: D
Organizations should exercise their Incident Response (IR) plan following initial creation. The primary
objective for this first I R plan exercise is to identify:

정답: D
A high-level government official uses anonymous bank accounts to transfer a requested amount of funds
to individuals in another country. These individuals are known for defacing government websites and
exfiltrating sensitive data. Which of the following BEST describes the involved threat actors?

정답: A
From a compromised system, an attacker bypasses a proxy server and sends a large amount of data to a
remote location. A security analyst is tasked with finding the conduit that was used by the attacker to
bypass the proxy. Which of the following Windows tools should be used to find the conduit?

정답: B
A security analyst discovers a zero-day vulnerability affecting Windows, which has not been publicly
identified. The security analyst assumes this vulnerability is present on millions of computer system and
feels an obligation to share this information with other security professionals. Which of the following would
be the MOST adverse consequences of the analyst sharing this information?

정답: B
During a malware outbreak, a security analyst has been asked to capture network traffic in hourly
increments for analysis by the incident response team . Which of the following tcpdump commands would
generate hourly pcap files?

정답: D
When determining the threats/vulnerabilities to migrate, it is important to identify which are applicable.
Which of the following is the FIRST step to determine applicability?

정답: B
During a network-based attack, which of the following data sources will provide the BEST data to quickly
determine the attacker's point of origin? (Choose two.)

정답: B,E
During the course of an investigation, an incident responder discovers illegal material on a user's hard
drive. Which of the following is the incident responder's MOST important next step?

정답: B

우리와 연락하기

문의할 점이 있으시면 메일을 보내오세요. 12시간이내에 답장드리도록 하고 있습니다.

근무시간: ( UTC+9 ) 9:00-24:00
월요일~토요일

서포트: 바로 연락하기 

English Deutsch 繁体中文 日本語