|283 Questions with Accurate answers
Ans✓✓✓
!= or <> refers to Not Equal in which scripting language?
Ans✓✓✓Python
!= or <> refers to Not Equal in the Python scripting language.
-ne refers to Not Equal in the Bash scripting language.
ne refers to Not Equal in the PowerShell scripting language.
PuTTY is an SSH and Telnet client that was originally developed for the
Windows platform.
12.1 Incident Response Ans✓✓✓As you study this section, answer the
following questions:
> Why is the chain of custody so important in a forensic investigation?
> How do you ensure the integrity of collected digital evidence?
> When conducting a forensic investigation, what methods can you use
to save the contents of memory?
> What would a computer forensic investigator analyze when
conducting a live analysis compared to a dead analysis?
,> What actions should you take when an incident occurs?
In this section, you will learn to:
> Analyze and record forensic evidence.
> Use a forensic tool to gather and authenticate forensic information
from a system.
12.1.2 Incident Response Process Facts Ans✓✓✓This lesson covers the
following topics:
> Security incident
> Incident response process
12.1.4 Incident Response Frameworks and Management Facts
Ans✓✓✓This lesson covers the following topics:
> Attack frameworks
> Stakeholder management
> Internal policies
12.1.5 Section Quiz Ans✓✓✓CIST 1601
12.2 Mitigation of an Incident Ans✓✓✓As you study this section,
answer the following questions:
Why would you use whitelisting?
> How can you protect network endpoints?
,> When would you use the mitigation technique of quarantining?
> Why is it important to keep a firewall configuration up-to-date?
In this section, you will learn to:
> Distinguish between whitelisting and blacklisting applications.
> Use isolation, quarantining, containment, and segmentation
appropriately.
> Create a runbook for a network.
Indentify when to use a playbook.
12.2.2 Reconfigure and Protect Endpoints Facts Ans✓✓✓This lesson
covers the following topics:
> Application endpoint protection
> Endpoint security configuration
12.2.4 Isolate and Containment Facts Ans✓✓✓This lesson covers the
following topics:
> Isolation, containment, and segmentation
> ISecurity orchestration, automation and response (SOAR)
> IIncident plans
12.2.5 Section Quiz Ans✓✓✓CIST 1601
, 12.3 Log Management Ans✓✓✓As you study this section, answer the
following questions:
> What does a security information and event management (SIEM)
system do?
> Why are trends important for network management?
> What part does event correlation play in a SIEM?
> How do IT security teams use alerts?
In this section, you will learn to:
> Use vulnerability scan outputs as part of SIEM.
> Identify trends and use them appropriately.
> Identify uses for SIEM.
12.3.10 Monitoring Data and Metadata Facts Ans✓✓✓This lesson
covers the following topics:
> Bandwidth monitors
> Metadata
> Data analyzers
12.3.11 Section Quiz Ans✓✓✓CIST 1601
12.3.3 SIEM and Log Management Facts Ans✓✓✓A security
information and event management (SIEM) system combines security
information management (SIM) and security event management (SEM)
functions into one security management system.