Author: ITExam Editorial Team
The ITExamAnswers Editorial Team is a dedicated group of certified IT professionals and network engineers. We rigorously review, verify, and update all exam materials to ensure you receive the most accurate and reliable resources for your certification journey.
1. What part of the Diamond Model represents the threat actor? adversary infrastructure direction capability result victim 2. What part of the Diamond model represents the network path that is used for an exploit? adversary infrastructure direction capability result victim 3. What part of the Diamond Model represents …
1. In which step does the threat actor exploit the vulnerability and gain control of the target? reconnaissance action on objectives installation delivery exploitation 2. In which step is the weapon transmitted to the target through the use of a website, removable USB media, an email attachment, or …
1. Which type of evidence was indisputably in the possession of the accused? indirect evidence direct evidence corroborating evidence best evidence 2. Which type of evidence supports an assertation that is developed from best evidence? direct evidence indirect evidence corroborating evidence best evidence 3. Which type of evidence …
1. Which technique involves assessment and extraction of relevant information from collected data? reporting collection analysis examination 2. Which technique involves drawing conclusions from the data? examination analysis collection reporting 3. Which is technique incudes identification of potential sources of forensic data and acquisition, handling, and storage of …
1. Which type of alert would have no incident reported and no incident has occurred? false negative true negative true positive true negative 2. Which type of alert has happened when an alert is received, but no incident has occurred? true positive true negative false positive false negative …
1. What type of event occurs when malicious activity that can affect the availability, integrity and confidentiality of a host and its data occurs? Intrusion Host or Endpoint NetFlow Configuration Network Discovery Connection 2. What kind of event is logged when a host first appears on the network? …
1. What is used to generate and view full packet captures? NetFlow tcpdump Proxy Logs Syslog 2. What two values are part of all NetFlow flow records? (Choose two.) beginning timestamp full packet details ending timestamp DNS server requests application identifiers 3. What does Application Visibility and Control …
1. What Windows security level is logged when a remote login was unsuccessfully attempted by an unauthorized user? Error Fatal Warning Information Success Audit Failure Audit 2. What Windows security level is logged when a process that is required has successfully loaded on a workstation? Error Fatal Warning …
1. Which type of network monitoring data includes detailed protocol and payload information for all traffic on a network segment? full-packet capture transaction data session data alert data extracted content statistical data 2. What type of network monitoring data summarizes or analyzes network flow or performance data? full-packet …
1. Which of the following spreads malware-infected files and creates vulnerabilities on a network? ACL Encryption Tunneling NAT/Pat P2P 2. Which of the following can be defeated by packets containing spoofed IP addresses? P2P TOR ACL encryption NAT/PAT 3. Which of the following makes message contents and file …