Which of the following best explains the purpose of the Pyramid of Pain in threat intelligence?
A. To show that changing to different types of indicators and behaviors is difficult for an adversary
B. To measure how much operational damage a threat actor can cause before detection occurs
C. To organize attack activity into categories such as spoofing, tampering, and repudiation
D. To compare open-source intelligence (OSINT) with closed-source intelligence based on collection cost
正解:A
解説: (Pass4Test メンバーにのみ表示されます)
質問 2:
An analyst reviews the following list of vulnerabilities:

The analyst determines that CVE-2023-8524 is the highest priority for remediation and should be patched immediately. Which of the following did the analyst use to determine the priority of remediation efforts?
A. Recurrence
B. Criticality
C. Exploit availability
D. Context awareness
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 3:
A security analyst receives a notice about a possible data breach. The report identifies unapproved, current access dates for files found in the following personnel archives:

Which of the following actions should the analyst take first?
A. Perform log correlation.
B. Establish a timeline.
C. Establish a legal hold.
D. Reset user credentials.
E. Restore files from backup.
正解:C
解説: (Pass4Test メンバーにのみ表示されます)
質問 4:
Which of the following uses simulated traffic to a website to evaluate performance?
A. Log analysis
B. War gaming
C. Packet inspection
D. Synthetic monitoring
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 5:
An analyst performs Nmap scans to determine which hosts may need to be targeted to deploy a critical Windows patch. The patch for the vulnerability is to address a critical security flaw that targets open Server Message Block (SMB) ports on Windows systems only. The analyst scans with the following command:
$sudo nmap -Pn 10.203.10.0/24
The analyst then receives the following output:

Which of the following hosts should the analyst prioritize for patching?
A. 10.203.10.12
B. 10.203.10.16
C. 10.203.10.11
D. 10.203.10.13
正解:C
解説: (Pass4Test メンバーにのみ表示されます)
質問 6:
A team lead asks an analyst to integrate multiple security tools to provide an enhanced view into data that is not readily available in the tool console. Which of the following will best meet this requirement?
A. Templating with infrastructure as code
B. Using playbooks
C. Deploying security orchestration, automation, and response
D. Utilizing application programming interfaces
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 7:
A SOC has SIEM configured to receive threat intelligence feeds from multiple external sources.
For certain tasks, there is no need for human interaction. Which of the following is the best solution to correlate events and provide valuable information to the analysts?
A. Single pane of glass
B. Data enrichment
C. Webhooks
D. Threat feed combination
正解:B
解説: (Pass4Test メンバーにのみ表示されます)
質問 8:
A vendor releases details of a new vulnerability. When an analyst reviews the scheduled scans, no vulnerabilities are identified. The vulnerability is only discovered after a configuration change.
Which of the following scan types did the analyst configure?
A. Credentialed
B. Agent-based
C. External
D. Network
正解:B
解説: (Pass4Test メンバーにのみ表示されます)
916 お客様のコメント





须藤** -
これを取得するのに短時間で十分でした。試験にももちろん受かりました。