Cisco 200-201 Practice Test - Questions Answers, Page 15
Related questions
Which NIST IR category stakeholder is responsible for coordinating incident response among various business units, minimizing damage, and reporting to regulatory agencies?
CSIRT
PSIRT
public affairs
management
Which incidence response step includes identifying all hosts affected by an attack?
detection and analysis
post-incident activity
preparation
containment, eradication, and recovery
Which two elements are used for profiling a network? (Choose two.)
session duration
total throughput
running processes
listening ports
OS fingerprint
Which category relates to improper use or disclosure of PII data?
legal
compliance
regulated
contractual
Which type of evidence supports a theory or an assumption that results from initial evidence?
probabilistic
indirect
best
corroborative
Which two elements are assets in the role of attribution in an investigation? (Choose two.)
context
session
laptop
firewall logs
threat actor
What is personally identifiable information that must be safeguarded from unauthorized access?
date of birth
driver's license number
gender
zip code
In a SOC environment, what is a vulnerability management metric?
code signing enforcement
full assets scan
internet exposed devices
single factor authentication
A security expert is working on a copy of the evidence, an ISO file that is saved in CDFS format. Which type of evidence is this file?
CD data copy prepared in Windows
CD data copy prepared in Mac-based system
CD data copy prepared in Linux system
CD data copy prepared in Android-based system
Which two elements of the incident response process are stated in NIST Special Publication 800-61 r2? (Choose two.)
detection and analysis
post-incident activity
vulnerability management
risk assessment
vulnerability scoring
Question