2026
Which of the following can be determined by capturing and analyzing network traffic?
A. Intent of Insider Threat actors and logs of their activity
B. Communication and connections between hosts
C. Open files and Registry handles on individual hosts
D. Firewall and Intrusion Detection rules for the gateway - Answers B. Communication and connections
between hosts
Which of the following is a method to detect an incident?
A. IDS alarm
B. Log analysis
C. 3rd Party Information
D. Public or attacker announcement
E. All of the above
, F. None of the above - Answers E. All of the above
Which of the following describes hash analysis?
A. Validating file integrity by matching before and after hash values
B. Organizing data sets into key and hash value pairs
C. Matching file hash values against a set of known hash values
D. Identifying file types by analyzing individual hash values - Answers C. Matching file hash values against
a set of known hash values
Which of the following is NOT a goal of triage?
A. Quickly identify indicators of compromise
B. Identify vectors used to compromise the systems
C. Determine normal and abnormal network behavior
D. Determine which systems require in-depth analysis - Answers C. Determine normal and abnormal
network behavior
What is the order of the stages of attacker methodology?