A security analyst recently read a report about a flaw in several of the organization's printer models that causes credentials to be sent over the network in cleartext, regardless of the encryption settings. Which of the following would be best to use to validate this finding?
Answer(s): A
A development team is launching a new public-facing web product. The Chief Information Security Officer has asked that the product be protected from attackers who use malformed or invalid inputs to destabilize the system. Which of the following practices should the development team implement?
During an annual review of the system design, an engineer identified a few issues with the currently released design. Which of the following should be performed next according to best practices?
Answer(s): D
Which of the following is best to use when determining the severity of a vulnerability?
An organization experienced a security breach that allowed an attacker to send fraudulent wire transfers from a hardened PC exclusively to the attacker's bank through remote connections. A security analyst is creating a timeline of events and has found a different PC on the network containing malware. Upon reviewing the command history, the analyst finds the following:PS>.\mimikatz.exe "sekurlsa::pth /user:localadmin /domain:corp-domain.com / ntlm:B4B9B02E1F29A3CF193EAB28C8D617D3F327Which of the following best describes how the attacker gained access to the hardened PC?
Answer(s): B
Which of the following is the best resource to consult for information on the most common application exploitation methods?
A security analyst is reviewing the logs on an organization's DNS server and notices the following unusual snippet:Which of the following attack techniques was most likely used?
Answer(s): C
A security analyst at an organization observed several user logins from outside the organization's network. The analyst determined that these logins were not performed by individuals within the organization. Which of the following recommendations would reduce the likelihood of future attacks? (Choose two.)
Answer(s): B,D
Share your comments for CompTIA SY0-701 exam with other users:
What are incident response processes?Incident response processes are the organized steps an organization follows to identify, manage, and recover from a security incident. Typical stages are:
Question 142:Correct answer: A — Determining the root cause of the incident The post-incident review—also called a lessons-learned review—analyzes what happened and why. Determining the root cause helps the organization fix the underlying weakness and prevent recurrence. Why the other options are less suitable: