Which of the following enables security personnel to have the BEST security incident recovery practices?
A. Incident response plan
B. Disaster recovery plan
C. Occupant emergency plan
D. Crisis communication plan
正解:B
質問 2:
To minimize vulnerability, which steps should an organization take before deploying a new Internet of Things (IoT) device? (Choose two.)
A. Setting up new users
B. Changing the default password
C. Disabling IPv6
D. Enabling the firewall
E. Updating the device firmware
正解:D,E
質問 3:
Recently, a cybersecurity research lab discovered that there is a hacking group focused on hacking into the computers of financial executives in Company A to sell the exfiltrated information to Company B.
Which of the following threat motives does this MOST likely represent?
A. Desire for power
B. Association/affiliation
C. Desire for financial gain
D. Reputation/recognition
正解:C
質問 4:
While reviewing some audit logs, an analyst has identified consistent modifications to the sshd_config file for an organization's server. The analyst would like to investigate and compare contents of the current file with archived versions of files that are saved weekly. Which of the following tools will be MOST effective during the investigation?
A. cat * | cut -d ',' -f 2,5,7
B. diff
C. sort *
D. more * | grep
正解:B
質問 5:
An administrator believes that a system on VLAN 12 is Address Resolution Protocol (ARP) poisoning clients on the network. The administrator attaches a system to VLAN 12 and uses Wireshark to capture traffic. After reviewing the capture file, the administrator finds no evidence of ARP poisoning. Which of the following actions should the administrator take next?
A. Enable port mirroring on the switch.
B. Configure the network adapter to promiscuous mode.
C. Clear the ARP cache on their system.
D. Filter Wireshark to only show ARP traffic.
正解:B
質問 6:
Which of the following security best practices should a web developer reference when developing a new web- based application?
A. Control Objectives for Information and Related Technology (COBIT)
B. Open Web Application Security Project (OWASP)
C. Risk Management Framework (RMF)
D. World Wide Web Consortium (W3C)
正解:B
質問 7:
The incident response team has completed root cause analysis for an incident. Which of the following actions should be taken in the next phase of the incident response process? (Choose two.)
A. Updating policies and procedures
B. Providing a briefing to management
C. Drafting a recovery plan for the incident
D. Investigating responsible staff
E. Training staff for future incidents
正解:A,C
質問 8:
Various logs are collected for a data leakage case to make a forensic analysis. Which of the following are MOST important for log integrity? (Choose two.)
A. Log type
B. Log path
C. Modified date/time
D. Time stamp
E. Hash value
正解:D,E
1693 お客様のコメント





斉*瞳 -
この参考書はとても助けになるのではないでしょうか。とても読みやすいCFR-310参考書で丁寧な解説ですね。