Refer to the exhibit.
A threat actor behind a single computer exploited a cloud-based application by sending multiple
concurrent API requests. These requests made the application unresponsive. Which solution protects
the application from being overloaded and ensures more equitable application access across the
end-user community?
A
DRAG DROP
An organization lost connectivity to critical servers, and users cannot access business applications
and internal websites. An engineer checks the network devices to investigate the outage and
determines that all devices are functioning. Drag and drop the steps from the left into the sequence
on the right to continue investigating this issue. Not all options are used.

A threat actor attacked an organization’s Active Directory server from a remote location, and in a
thirty-minute timeframe, stole the password for the administrator account and attempted to access
3 company servers. The threat actor successfully accessed the first server that contained sales data,
but no files were downloaded. A second server was also accessed that contained marketing
information and 11 files were downloaded. When the threat actor accessed the third server that
contained corporate financial data, the session was disconnected, and the administrator’s account
was disabled. Which activity triggered the behavior analytics tool?
C
Refer to the exhibit.
A security analyst needs to investigate a security incident involving several suspicious connections
with a possible attacker. Which tool should the analyst use to identify the source IP of the offender?
A
Refer to the exhibit.
Cisco Advanced Malware Protection installed on an end-user desktop has automatically submitted a
low prevalence file to the Threat Grid analysis engine for further analysis. What should be concluded
from this report?
C
The physical security department received a report that an unauthorized person followed an
authorized individual to enter a secured premise. The incident was documented and given to a
security specialist to analyze. Which step should be taken at this stage?
D
A new malware variant is discovered hidden in pirated software that is distributed on the Internet.
Executives have asked for an organizational risk assessment. The security officer is given a list of all
assets. According to NIST, which two elements are missing to calculate the risk assessment? (Choose
two.)
BE
Reference:
https://cloudogre.com/risk-assessment/
Refer to the exhibit.
At which stage of the threat kill chain is an attacker, based on these URIs of inbound web requests
from known malicious Internet scanners?
C
Reference:
https://www2.deloitte.com/content/dam/Deloitte/sg/Documents/risk/sea-risk-cyber-
101-july2017.pdf
Refer to the exhibit.
How must these advisories be prioritized for handling?
D
Refer to the exhibit.
Which two steps mitigate attacks on the webserver from the Internet? (Choose two.)
BD
DRAG DROP
Drag and drop the phases to evaluate the security posture of an asset from the left onto the activity
that happens during the phases on the right.

According to GDPR, what should be done with data to ensure its confidentiality, integrity, and
availability?
B
Reference:
https://apdcat.gencat.cat/web/.content/03-documentacio/
Reglament_general_de_proteccio_de_dades/documents/DPIA-Guide.pdf
A payroll administrator noticed unexpected changes within a piece of software and reported the
incident to the incident response team. Which actions should be taken at this step in the incident
response workflow?
B
A company recently completed an internal audit and discovered that there is CSRF vulnerability in 20
of its hosted applications. Based on the audit, which recommendation should an engineer make for
patching?
D
An engineer is analyzing a possible compromise that happened a week ago when the company ?
(Choose two.)
AB