A vulnerability scan of a web server that is exposed to the internet was recently completed. A security analyst is reviewing the resulting vector strings:Vulnerability 1: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L, Vulnerability 2: CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H, Vulnerability 3: CVSS:3.0/AV:A/AC:H/PR:L/UI:R/S:U/C:L/I:H/A:L, Vulnerability 4: CVSS:3.0/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:L.Which of the following vulnerabilities should be patched first?
Rationale
A SOC analyst identifies the following content while examining the output of a debugger command over a client-server application: getConnection(database01,'alpha','AxTv.127GdCx94GTd'); Which of the following is the most likely vulnerability in this system?
Rationale
A malicious actor has gained access to an internal network by means of social engineering. The actor does not want to lose access in order to continue the attack. Which of the following best describes the current stage of the Cyber Kill Chain that the threat actor is currently operating in?
Rationale
A new SOC manager reviewed findings regarding the strengths and weaknesses of the last tabletop exercise in order to make improvements. Which of the following should the SOC manager utilize to improve the process?
Rationale
The security team reviews a web server for XSS and runs the following Nmap scan# nmap -p80 --script http-unsafe-output-escaping 172.31.15.2 PORT STATE SERVICE REASON 80/tcp open http syn-ack | http-unsafe-output-escaping: | Characters ["] ['] reflected in parameter id at | http://172.31.15.2/1.php?id=2 |_ Characters [>] ["] ['] reflected.Which of the following most accurately describes the result of the scan?
Rationale
Which of the following is the most important reason why tactics, techniques, and procedures (TTP) are beneficial to a defensive strategy?
Rationale
An analyst reviews a recent government alert on new zero-day threats and finds the following CVE metrics for the most critical of the vulnerabilities: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:W/RC:R. Which of the following represents the exploit code maturity of this critical vulnerability?
Rationale
A security operations center analyst is using the command line to display specific traffic. The analyst uses the following command: `$ tshark -r file.pcap -Y 'http or udp'`. Which of the following will the command line display?
Rationale
A threat intelligence analyst is updating a document according to the MITRE ATT&CK framework. The analyst detects the following behavior from a malicious actor: 'The malicious actor will attempt to achieve unauthorized access to the vulnerable system.' In which of the following phases should the analyst include the detection?
Rationale
Which of the following best describes root cause analysis?
Rationale
A security operations center (SOC) manager advises the team to collaborate with other divisions and deliver a documented plan for configuring the security information and event management (SIEM) solution by the end of the week. Which of the following is the best way to accomplish this objective?
Rationale
Which of the following best explains the importance of playbooks for incident response teams?
Rationale
A web developer reports the following error that appeared on a development server when testing a new application. Which of the following tools can be used to identify the application's point of failure?
Rationale
An analyst is becoming overwhelmed with the number of events that need to be investigated for a timeline. Which of the following should the analyst focus on in order to move the incident forward?
Rationale
An analyst is evaluating a vulnerability management dashboard. The analyst sees that a previously remediated vulnerability has reappeared on a database server. Which of the following is the most likely cause?
Rationale
What would you like to do with your progress?
What would you like to do before switching?
You finished this free practice quiz.
Help us improve by flagging this content.
How helpful was this material?