An analyst reviews the following log entries:

Which of the following conclusions should the analyst reach? (Choose two.)
A security team deploys a new scanning solution that requires root, domain administrator, and local server administrator permissions on all systems.
Which of the following is the best way to help mitigate the risk for this level of access?
Which of the following is the main concept behind the use of an attack methodology framework?
An analyst executes the top command on a Linux system for an unresponsive application and observes the following output:

Which of the following is the most likely cause of this issue?
Which of the following will inhibit remediation when attempting to resolve a vulnerability?
An organization receives an indication that one of its hosts is part of a DDoS attack against a victim. The proxy server is supposed to handle all web page requests from all internal hosts.
INSTRUCTIONS
Click on each workstation and server to review outputs and a log file.
Identify the compromised host and executable, and determine an appropriate remediation for the issue.
If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.









An analyst performs Nmap scans to determine which hosts may need to be targeted to deploy a critical Windows patch. The patch for the vulnerability is to address a critical security flaw that targets open Server Message Block (SMB) ports on Windows systems only.
The analyst scans with the following command:

$sudo nmap -Pn 10.203.10.0/24
The analyst then receives the following output:
Which of the following hosts should the analyst prioritize for patching?
A vulnerability scanner shows discrepancies between the number of Internet Protocol (IP) addresses across the sites being scanned and the number of systems reporting into the patching system.
Which of the following actions will resolve this issue?
The Chief Information Security Officer (CISO) reviews the following security operations metrics from the last month:

Which of the following is the best action to improve overall security operations efficiency?
Which of the following is the most important component to include in the preparation phase of an incident response plan?