answers
A company manages the personal data of citizens from several Eastern
Union (EU) countries.
Which compliance act must they adhere to when investigating security
incidents involving EU citizens? Ans✓✓✓GDPR
A French company sells items online and processes credit card
payments.
Which compliance framework must this company adhere to in order to
reduce security incidents involving credit cards purchases?
Ans✓✓✓PCI-DSS
A protocol that enables network administrators to monitor and manage
network performance. Ans✓✓✓SNMP
According to NIST, in which phase of the Incident Response Life Cycle
do you perform event correlation? Ans✓✓✓Detection & Analysis
An adversary is obtaining an automated tool to deliver a malware
payload after having identified a potential vulnerability in the email
server of an organization.
Which step of the Cyber Kill Chain framework does this represent?
Ans✓✓✓Weaponization
, Details the organizational approach, strategies, and resources for
incident response and includes how the team will communicate with
internal and external parties. Ans✓✓✓Incident Response Plan
Details the purpose, objectives, and scope for incident response and
includes the prioritization of incidents and performance measures.
Ans✓✓✓Incident Response Policy
Determine if an incident has occurred. Ans✓✓✓Detection & Analysis
Phase
Employees in the finance department are reporting slow traffic and poor
performance on an internal webserver. As a junior cybersecurity analyst,
you review the output of some event logs and packet captures and notice
numerous packets from the IP address are flooding the network.
What should you do first? Ans✓✓✓Escalate the issue to a more senior
analyst for further investigation.
Establish the incident response team. Ans✓✓✓Preparation Phase
Hold a lessons learned meeting. Ans✓✓✓Post-Incident Activity Phase
In which order should you collect digital evidence from a computer
system? Ans✓✓✓Contents of RAM, Contents of Fixed Disk, Archived
Backup