A cybersecurity analyst requests a paid subscription to a threat intelligence feed relevant to a company's industry. Which of the following best describes this type of feed?
Answer : D
HOTSPOT -
A systems administrator is reviewing the output of a vulnerability scan.
INSTRUCTIONS -
Review the information in each tab.
Based on the organization’s environment architecture and remediation standards, select the server to be patched within 14 days and select the appropriate technique and mitigation.
If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.


Answer :
A security team reviews a penetration testing report of a web application that contains multiple cross-site scripting (XSS) and Structured Query Language injection (SQLi) vulnerabilities. Which of the following is most likely causing these to occur?
Answer : B
The Chief Information Officer (CIO) is requiring users to phase out a legacy system that no longer receives security updates because the system will be decommissioned soon. Which of the following risk management strategies is the CIO using?
Answer : A
A security team deploys a new scanning solution that requires root, domain administrator, and local server administrator permissions on all systems. Which of the following is the best way to help mitigate the risk for this level of access?
Answer : B
Before merging with a software company, the acquiring company's legal team requires a detailed software scan to determine if all code base is using open-source or paid licensed libraries. The vulnerability management analyst needs to provide this report. Which of the following scan methods will best meet this requirement?
Answer : C
Which of the following is the most likely reason an organization might implement compensating controls?
Answer : A
A vulnerability analyst must perform a security assessment on an edge device running various services. The analyst runs an Nmap port scan and sees the following output:
Which of the following should the analyst do next to validate the discovered remote access service is secure?
Answer : C
An analyst performs Nmap scans to determine which hosts may need to be targeted to deploy a critical Windows patch. The patch for the vulnerability is to address a critical security flaw that targets open Server Message Block (SMB) ports on Windows systems only. The analyst scans with the following command:
$sudo nmap -Pn 10.203.10.0/24
The analyst then receives the following output:
Which of the following hosts should the analyst prioritize for patching?
Answer : A
An analyst receives the following output:
Which of the following is the correct number of discovered systems that are allowing unencrypted traffic?
Answer : B
An incident response team identifies a malicious uniform resource locator (URL) associated with a required business process and performs the following activities:
• Access to the URL has been restricted only to the necessary users through firewall rules and Cloud Security Group rules.
• Additional monitoring has been enabled for traffic related to that site and the allowed users.
• All application servers that need to access that site have been patched with the latest security and software updates.
• Application owners have been notified of the severity and need to remediate this reported issue.
Which of the following best describes the overall mitigation the security team is performing?
Answer : C
A vendor releases details of a new vulnerability. When an analyst reviews the scheduled scans, no vulnerabilities are identified. The vulnerability is only discovered after a configuration change. Which of the following scan types did the analyst configure?
Answer : C
A vulnerability analyst conducts a security assessment on the Remote Desktop Protocol (RDP) security posture within the environment. The analyst issues the following command for the assessment: nmap -p 3389 --script rdp* 10.0.0.0/24
The analyst receives responses, which are divided into one of the two categories, from 13 out of the 254 hosts:
Which of the following conclusions can the analyst make about the output on Category 2?
Answer : C
An analyst needs to perform a baseline security evaluation of the company's cloud infrastructure. Which of the following tools is most appropriate for this task?
Answer : C
The vulnerability management team must scan the cloud environment to establish security baselines. Which of the following assessment tools should the team use to perform this task?
Answer : B
Have any questions or issues ? Please dont hesitate to contact us