Which option can be addressed when using retrospective security techniques?

A.    if the affected host needs a software update
B.    how the malware entered our network
C.    why the malware is still in our network
D.    if the affected system needs replacement

Answer: B

Which CVSSv3 Attack Vector metric value requires the attacker to physically touch or manipulate the vulnerable component?

A.    local
B.    physical
C.    network
D.    adjacent

Answer: B

Which option is a misuse variety per VERIS enumerations?

A.    snooping
B.    hacking
C.    theft
D.    assault

Answer: B

In the context of incident handling phases, which two activities fall under scoping? (Choose two.)

A.    determining the number of attackers that are associated with a security incident
B.    ascertaining the number and types of vulnerabilities on your network
C.    identifying the extent that a security incident is impacting protected resources on the network
D.    determining what and how much data may have been affected
E.    identifying the attackers that are associated with a security incident

Answer: DE

Which regular expression matches “color” and “colour”?

A.    col[0-9]+our
B.    colo?ur
C.    colou?r
D.    ]a-z]{7}

Answer: C

Which kind of evidence can be considered most reliable to arrive at an analytical assertion?

A.    direct
B.    corroborative
C.    indirect
D.    circumstantial
E.    textual

Answer: A

You see 100 HTTP GET and POST requests for various pages on one of your webservers. The user agent in the requests contain php code that, if executed, creates and writes to a new php file on the webserver. Which category does this event fall under as defined in the Diamond Model of Intrusion?

A.    delivery
B.    reconnaissance
C.    action on objectives
D.    installation
E.    exploitation

Answer: A

Which string matches the regular expression r(ege)+x?

A.    rx
B.    regeegex
C.    r(ege)x
D.    rege+x

Answer: B

Which statement about threat actors is true?

A.    They are any company assets that are threatened.
B.    They are any assets that are threatened.
C.    They are perpetrators of attacks.
D.    They are victims of attacks.

Answer: C

Which data element must be protected with regards to PCI?

A.    past health condition
B.    geographic location
C.    full name
D.    recent payment amount

Answer: C

