200-201試験無料問題集「Cisco Understanding Cisco Cybersecurity Operations Fundamentals 認定」
A security specialist notices 100 HTTP GET and POST requests for multiple pages on the web servers. The agent in the requests contains PHP code that, if executed, creates and writes to a new PHP file on the webserver. Which event category is described?
正解:D
解答を投票する
解説: (GoShiken メンバーにのみ表示されます)
A SOC analyst detected connections to known C&C and port scanning activity to main HR database servers from one of the HR endpoints via Cisco StealthWatch. What are the two next steps of the SOC team according to the NISTSP800-61 incident handling process? (Choose two)
正解:A,E
解答を投票する
解説: (GoShiken メンバーにのみ表示されます)
Drag and drop the definition from the left onto the phase on the right to classify intrusion events according to the Cyber Kill Chain model.
正解:
An engineer is addressing a connectivity issue between two servers where the remote server is unable to establish a successful session. Initial checks show that the remote server is not receiving an SYN-ACK while establishing a session by sending the first SYN. What is causing this issue?
正解:A
解答を投票する
解説: (GoShiken メンバーにのみ表示されます)