CompTIA CySA+ CS0-003 Incident Response Activities Practice Test

 

Objective 3.2 • 40 original questions

This CompTIA CySA+ CS0-003 practice test focuses on objective 3.2: incident response activities. All questions are original ExamSnap scenarios aligned to the official CS0-003 objective set; they are not copied from live CompTIA exam content. Review every option explanation to understand why a choice fits or does not fit the scenario. For broader exam preparation, review the CompTIA CySA+ CS0-003 Exam Dumps page.

Instructions: Select the best answer unless the question explicitly says Select TWO or Select THREE. Review the explanation and option review after answering.

Question 1

During an investigation at Tailspin Toys, the immediate requirement is to use observed malicious indicators to identify additional affected hosts. What should a SOC lead select? The environment follows least privilege and preserves evidence where incident handling is involved.

  1. IoC-driven detection and analysis
  2. Compensating containment control
  3. Chain of custody
  4. Re-imaging
  5. Data and log analysis

Correct answer: A

Why: Indicators of compromise help analysts identify affected systems and scope suspicious activity during detection and analysis. It directly fits this scenario because the requirement is to use observed malicious indicators to identify additional affected hosts.

Option review:

A: Indicators of compromise help analysts identify affected systems and scope suspicious activity during detection and analysis. It directly fits this scenario because the requirement is to use observed malicious indicators to identify additional affected hosts.

B: A compensating control reduces incident risk when permanent remediation cannot be applied immediately. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to use observed malicious indicators to identify additional affected hosts.

C: Chain of custody documents who collected, transferred, stored, and accessed evidence from collection through disposition. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to use observed malicious indicators to identify additional affected hosts.

D: Re-imaging rebuilds a system from a trusted baseline when confidence in the existing installation cannot be restored. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to use observed malicious indicators to identify additional affected hosts.

E: Correlating endpoint, identity, application, and network data builds a timeline and clarifies attacker actions. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to use observed malicious indicators to identify additional affected hosts.

Learning point: Use IoC-driven detection and analysis when the key requirement is to use observed malicious indicators to identify additional affected hosts.

Question 2

At Proseware Research, a malware analyst has two simultaneous requirements: collect disk, memory, logs, or network evidence from an affected system, and determine how far the incident has spread before choosing containment actions. Which TWO options should be selected? Use the choice that most directly addresses the stated evidence rather than a broader control.

  1. Compensating containment control
  2. Data and log analysis
  3. Evidence acquisition
  4. Isolation
  5. Scope determination

Correct answers: C, E

Why: Evidence acquisition collects relevant data using methods that preserve usefulness for investigation and possible legal review. It directly fits this scenario because the requirement is to collect disk, memory, logs, or network evidence from an affected system. Scoping identifies which systems, users, data, locations, and business processes are affected. It directly fits this scenario because the requirement is to determine how far the incident has spread before choosing containment actions.

Option review:

A: A compensating control reduces incident risk when permanent remediation cannot be applied immediately. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to collect disk, memory, logs, or network evidence from an affected system; determine how far the incident has spread before choosing containment actions.

B: Correlating endpoint, identity, application, and network data builds a timeline and clarifies attacker actions. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to collect disk, memory, logs, or network evidence from an affected system; determine how far the incident has spread before choosing containment actions.

C: Evidence acquisition collects relevant data using methods that preserve usefulness for investigation and possible legal review. It directly fits this scenario because the requirement is to collect disk, memory, logs, or network evidence from an affected system.

D: Isolation contains an incident by separating affected systems or accounts from resources they could harm while preserving needed evidence. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to collect disk, memory, logs, or network evidence from an affected system; determine how far the incident has spread before choosing containment actions.

E: Scoping identifies which systems, users, data, locations, and business processes are affected. It directly fits this scenario because the requirement is to determine how far the incident has spread before choosing containment actions.

Learning point: Use Evidence acquisition, Scope determination when the key requirement is to collect disk, memory, logs, or network evidence from an affected system; determine how far the incident has spread before choosing containment actions.

Question 3

For a managed cloud environment, the team must accomplish both of these goals: maintain an auditable record of every person who handled evidence, and estimate the business and technical consequences of the incident. Which TWO choices together provide the best match? The team wants the most defensible analyst action before expanding the investigation.

  1. Impact assessment
  2. Chain of custody
  3. Remediation
  4. Evidence integrity validation
  5. Isolation

Correct answers: A, B

Why: Impact analysis determines operational, confidentiality, integrity, availability, financial, legal, or reputational consequences. It directly fits this scenario because the requirement is to estimate the business and technical consequences of the incident. Chain of custody documents who collected, transferred, stored, and accessed evidence from collection through disposition. It directly fits this scenario because the requirement is to maintain an auditable record of every person who handled evidence.

Option review:

A: Impact analysis determines operational, confidentiality, integrity, availability, financial, legal, or reputational consequences. It directly fits this scenario because the requirement is to estimate the business and technical consequences of the incident.

B: Chain of custody documents who collected, transferred, stored, and accessed evidence from collection through disposition. It directly fits this scenario because the requirement is to maintain an auditable record of every person who handled evidence.

C: Remediation removes vulnerabilities, malicious artifacts, misconfigurations, or compromised credentials that enabled the incident. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to maintain an auditable record of every person who handled evidence; estimate the business and technical consequences of the incident.

D: Cryptographic hashes and documented procedures help demonstrate that collected evidence has not changed. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to maintain an auditable record of every person who handled evidence; estimate the business and technical consequences of the incident.

E: Isolation contains an incident by separating affected systems or accounts from resources they could harm while preserving needed evidence. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to maintain an auditable record of every person who handled evidence; estimate the business and technical consequences of the incident.

Learning point: Use Chain of custody, Impact assessment when the key requirement is to maintain an auditable record of every person who handled evidence; estimate the business and technical consequences of the incident.

Question 4

In a high-value payment environment, a threat hunter must prove that an evidence image is unchanged after transfer and storage. Which approach is MOST appropriate? Select based on the scenario’s decisive constraint, not on which technology is newest.

  1. Scope determination
  2. Evidence acquisition
  3. Chain of custody
  4. Evidence integrity validation
  5. Compensating containment control

Correct answer: D

Why: Cryptographic hashes and documented procedures help demonstrate that collected evidence has not changed. It directly fits this scenario because the requirement is to prove that an evidence image is unchanged after transfer and storage.

Option review:

A: Scoping identifies which systems, users, data, locations, and business processes are affected. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to prove that an evidence image is unchanged after transfer and storage.

B: Evidence acquisition collects relevant data using methods that preserve usefulness for investigation and possible legal review. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to prove that an evidence image is unchanged after transfer and storage.

C: Chain of custody documents who collected, transferred, stored, and accessed evidence from collection through disposition. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to prove that an evidence image is unchanged after transfer and storage.

D: Cryptographic hashes and documented procedures help demonstrate that collected evidence has not changed. It directly fits this scenario because the requirement is to prove that an evidence image is unchanged after transfer and storage.

E: A compensating control reduces incident risk when permanent remediation cannot be applied immediately. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to prove that an evidence image is unchanged after transfer and storage.

Learning point: Use Evidence integrity validation when the key requirement is to prove that an evidence image is unchanged after transfer and storage.

Question 5

A review at Humongous Insurance finds a gap: the team cannot reliably store acquired evidence so it remains intact for later analysis. Which option best closes that gap? Assume the activity is authorized and must follow normal enterprise change control.

  1. IoC-driven detection and analysis
  2. Evidence preservation
  3. Evidence acquisition
  4. Evidence integrity validation
  5. Scope determination

Correct answer: B

Why: Preservation protects evidence from alteration, loss, contamination, or unauthorized access. It directly fits this scenario because the requirement is to store acquired evidence so it remains intact for later analysis.

Option review:

A: Indicators of compromise help analysts identify affected systems and scope suspicious activity during detection and analysis. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to store acquired evidence so it remains intact for later analysis.

B: Preservation protects evidence from alteration, loss, contamination, or unauthorized access. It directly fits this scenario because the requirement is to store acquired evidence so it remains intact for later analysis.

C: Evidence acquisition collects relevant data using methods that preserve usefulness for investigation and possible legal review. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to store acquired evidence so it remains intact for later analysis.

D: Cryptographic hashes and documented procedures help demonstrate that collected evidence has not changed. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to store acquired evidence so it remains intact for later analysis.

E: Scoping identifies which systems, users, data, locations, and business processes are affected. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to store acquired evidence so it remains intact for later analysis.

Learning point: Use Evidence preservation when the key requirement is to store acquired evidence so it remains intact for later analysis.

Question 6

a SOC analyst at Contoso Health is comparing several approaches. The deciding requirement is to prevent potentially relevant evidence from being deleted by normal retention rules. Which option should be chosen? Assume no additional product-specific features are available beyond the concepts listed.

  1. Remediation
  2. Isolation
  3. Legal hold
  4. Compensating containment control
  5. Scope determination

Correct answer: C

Why: A legal hold suspends normal deletion or disposal for information relevant to anticipated or active litigation or investigation. It directly fits this scenario because the requirement is to prevent potentially relevant evidence from being deleted by normal retention rules.

Option review:

A: Remediation removes vulnerabilities, malicious artifacts, misconfigurations, or compromised credentials that enabled the incident. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to prevent potentially relevant evidence from being deleted by normal retention rules.

B: Isolation contains an incident by separating affected systems or accounts from resources they could harm while preserving needed evidence. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to prevent potentially relevant evidence from being deleted by normal retention rules.

C: A legal hold suspends normal deletion or disposal for information relevant to anticipated or active litigation or investigation. It directly fits this scenario because the requirement is to prevent potentially relevant evidence from being deleted by normal retention rules.

D: A compensating control reduces incident risk when permanent remediation cannot be applied immediately. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to prevent potentially relevant evidence from being deleted by normal retention rules.

E: Scoping identifies which systems, users, data, locations, and business processes are affected. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to prevent potentially relevant evidence from being deleted by normal retention rules.

Learning point: Use Legal hold when the key requirement is to prevent potentially relevant evidence from being deleted by normal retention rules.

Question 7

While supporting an airline operations network, a security operations engineer is asked to reconstruct what happened by correlating multiple telemetry sources. Which concept or tool is the clearest match? The organization wants a vendor-neutral approach that can be explained during audit review.

  1. Evidence acquisition
  2. Data and log analysis
  3. Evidence preservation
  4. Evidence integrity validation
  5. Impact assessment

Correct answer: B

Why: Correlating endpoint, identity, application, and network data builds a timeline and clarifies attacker actions. It directly fits this scenario because the requirement is to reconstruct what happened by correlating multiple telemetry sources.

Option review:

A: Evidence acquisition collects relevant data using methods that preserve usefulness for investigation and possible legal review. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to reconstruct what happened by correlating multiple telemetry sources.

B: Correlating endpoint, identity, application, and network data builds a timeline and clarifies attacker actions. It directly fits this scenario because the requirement is to reconstruct what happened by correlating multiple telemetry sources.

C: Preservation protects evidence from alteration, loss, contamination, or unauthorized access. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to reconstruct what happened by correlating multiple telemetry sources.

D: Cryptographic hashes and documented procedures help demonstrate that collected evidence has not changed. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to reconstruct what happened by correlating multiple telemetry sources.

E: Impact analysis determines operational, confidentiality, integrity, availability, financial, legal, or reputational consequences. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to reconstruct what happened by correlating multiple telemetry sources.

Learning point: Use Data and log analysis when the key requirement is to reconstruct what happened by correlating multiple telemetry sources.

Question 8

A new security procedure at Lucerne Publishing must enable analysts to determine how far the incident has spread before choosing containment actions. Which option is the BEST choice? Base the decision on the primary security requirement, not on implementation convenience.

  1. Scope determination
  2. Remediation
  3. Re-imaging
  4. Impact assessment
  5. Evidence integrity validation

Correct answer: A

Why: Scoping identifies which systems, users, data, locations, and business processes are affected. It directly fits this scenario because the requirement is to determine how far the incident has spread before choosing containment actions.

Option review:

A: Scoping identifies which systems, users, data, locations, and business processes are affected. It directly fits this scenario because the requirement is to determine how far the incident has spread before choosing containment actions.

B: Remediation removes vulnerabilities, malicious artifacts, misconfigurations, or compromised credentials that enabled the incident. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine how far the incident has spread before choosing containment actions.

C: Re-imaging rebuilds a system from a trusted baseline when confidence in the existing installation cannot be restored. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine how far the incident has spread before choosing containment actions.

D: Impact analysis determines operational, confidentiality, integrity, availability, financial, legal, or reputational consequences. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine how far the incident has spread before choosing containment actions.

E: Cryptographic hashes and documented procedures help demonstrate that collected evidence has not changed. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine how far the incident has spread before choosing containment actions.

Learning point: Use Scope determination when the key requirement is to determine how far the incident has spread before choosing containment actions.

Question 9

The primary objective for Fabrikam Finance is to estimate the business and technical consequences of the incident. Which selection best satisfies that objective in an online banking environment? The environment follows least privilege and preserves evidence where incident handling is involved.

  1. Evidence acquisition
  2. Remediation
  3. Impact assessment
  4. Isolation
  5. Re-imaging

Correct answer: C

Why: Impact analysis determines operational, confidentiality, integrity, availability, financial, legal, or reputational consequences. It directly fits this scenario because the requirement is to estimate the business and technical consequences of the incident.

Option review:

A: Evidence acquisition collects relevant data using methods that preserve usefulness for investigation and possible legal review. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to estimate the business and technical consequences of the incident.

B: Remediation removes vulnerabilities, malicious artifacts, misconfigurations, or compromised credentials that enabled the incident. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to estimate the business and technical consequences of the incident.

C: Impact analysis determines operational, confidentiality, integrity, availability, financial, legal, or reputational consequences. It directly fits this scenario because the requirement is to estimate the business and technical consequences of the incident.

D: Isolation contains an incident by separating affected systems or accounts from resources they could harm while preserving needed evidence. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to estimate the business and technical consequences of the incident.

E: Re-imaging rebuilds a system from a trusted baseline when confidence in the existing installation cannot be restored. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to estimate the business and technical consequences of the incident.

Learning point: Use Impact assessment when the key requirement is to estimate the business and technical consequences of the incident.

Question 10

At City Power Utilities, an OT security analyst has two simultaneous requirements: stop a compromised endpoint from communicating with other systems, and maintain an auditable record of every person who handled evidence. Which TWO options should be selected? Use the choice that most directly addresses the stated evidence rather than a broader control.

  1. IoC-driven detection and analysis
  2. Impact assessment
  3. Isolation
  4. Data and log analysis
  5. Chain of custody

Correct answers: C, E

Why: Isolation contains an incident by separating affected systems or accounts from resources they could harm while preserving needed evidence. It directly fits this scenario because the requirement is to stop a compromised endpoint from communicating with other systems. Chain of custody documents who collected, transferred, stored, and accessed evidence from collection through disposition. It directly fits this scenario because the requirement is to maintain an auditable record of every person who handled evidence.

Option review:

A: Indicators of compromise help analysts identify affected systems and scope suspicious activity during detection and analysis. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to stop a compromised endpoint from communicating with other systems; maintain an auditable record of every person who handled evidence.

B: Impact analysis determines operational, confidentiality, integrity, availability, financial, legal, or reputational consequences. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to stop a compromised endpoint from communicating with other systems; maintain an auditable record of every person who handled evidence.

C: Isolation contains an incident by separating affected systems or accounts from resources they could harm while preserving needed evidence. It directly fits this scenario because the requirement is to stop a compromised endpoint from communicating with other systems.

D: Correlating endpoint, identity, application, and network data builds a timeline and clarifies attacker actions. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to stop a compromised endpoint from communicating with other systems; maintain an auditable record of every person who handled evidence.

E: Chain of custody documents who collected, transferred, stored, and accessed evidence from collection through disposition. It directly fits this scenario because the requirement is to maintain an auditable record of every person who handled evidence.

Learning point: Use Isolation, Chain of custody when the key requirement is to stop a compromised endpoint from communicating with other systems; maintain an auditable record of every person who handled evidence.

Question 11

During an investigation at A. Datum Logistics, the immediate requirement is to remove the root technical condition that allowed compromise. What should a security consultant select? The team wants the most defensible analyst action before expanding the investigation.

  1. Data and log analysis
  2. Chain of custody
  3. Evidence preservation
  4. Remediation
  5. Evidence acquisition

Correct answer: D

Why: Remediation removes vulnerabilities, malicious artifacts, misconfigurations, or compromised credentials that enabled the incident. It directly fits this scenario because the requirement is to remove the root technical condition that allowed compromise.

Option review:

A: Correlating endpoint, identity, application, and network data builds a timeline and clarifies attacker actions. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to remove the root technical condition that allowed compromise.

B: Chain of custody documents who collected, transferred, stored, and accessed evidence from collection through disposition. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to remove the root technical condition that allowed compromise.

C: Preservation protects evidence from alteration, loss, contamination, or unauthorized access. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to remove the root technical condition that allowed compromise.

D: Remediation removes vulnerabilities, malicious artifacts, misconfigurations, or compromised credentials that enabled the incident. It directly fits this scenario because the requirement is to remove the root technical condition that allowed compromise.

E: Evidence acquisition collects relevant data using methods that preserve usefulness for investigation and possible legal review. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to remove the root technical condition that allowed compromise.

Learning point: Use Remediation when the key requirement is to remove the root technical condition that allowed compromise.

Question 12

Northwind Traders is updating its security operations standard for a regional distribution network. Which option most directly helps the team restore a heavily compromised endpoint to a known-good operating-system state? Select based on the scenario’s decisive constraint, not on which technology is newest.

  1. Re-imaging
  2. Chain of custody
  3. Impact assessment
  4. Legal hold
  5. Evidence integrity validation

Correct answer: A

Why: Re-imaging rebuilds a system from a trusted baseline when confidence in the existing installation cannot be restored. It directly fits this scenario because the requirement is to restore a heavily compromised endpoint to a known-good operating-system state.

Option review:

A: Re-imaging rebuilds a system from a trusted baseline when confidence in the existing installation cannot be restored. It directly fits this scenario because the requirement is to restore a heavily compromised endpoint to a known-good operating-system state.

B: Chain of custody documents who collected, transferred, stored, and accessed evidence from collection through disposition. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to restore a heavily compromised endpoint to a known-good operating-system state.

C: Impact analysis determines operational, confidentiality, integrity, availability, financial, legal, or reputational consequences. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to restore a heavily compromised endpoint to a known-good operating-system state.

D: A legal hold suspends normal deletion or disposal for information relevant to anticipated or active litigation or investigation. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to restore a heavily compromised endpoint to a known-good operating-system state.

E: Cryptographic hashes and documented procedures help demonstrate that collected evidence has not changed. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to restore a heavily compromised endpoint to a known-good operating-system state.

Learning point: Use Re-imaging when the key requirement is to restore a heavily compromised endpoint to a known-good operating-system state.

Question 13

A ticket at Alpine Ski House asks a cloud security analyst to reduce exposure temporarily while a full fix is being prepared. Which choice addresses the requirement most directly? Assume the activity is authorized and must follow normal enterprise change control.

  1. Isolation
  2. Evidence preservation
  3. Evidence acquisition
  4. Compensating containment control
  5. Legal hold

Correct answer: D

Why: A compensating control reduces incident risk when permanent remediation cannot be applied immediately. It directly fits this scenario because the requirement is to reduce exposure temporarily while a full fix is being prepared.

Option review:

A: Isolation contains an incident by separating affected systems or accounts from resources they could harm while preserving needed evidence. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to reduce exposure temporarily while a full fix is being prepared.

B: Preservation protects evidence from alteration, loss, contamination, or unauthorized access. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to reduce exposure temporarily while a full fix is being prepared.

C: Evidence acquisition collects relevant data using methods that preserve usefulness for investigation and possible legal review. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to reduce exposure temporarily while a full fix is being prepared.

D: A compensating control reduces incident risk when permanent remediation cannot be applied immediately. It directly fits this scenario because the requirement is to reduce exposure temporarily while a full fix is being prepared.

E: A legal hold suspends normal deletion or disposal for information relevant to anticipated or active litigation or investigation. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to reduce exposure temporarily while a full fix is being prepared.

Learning point: Use Compensating containment control when the key requirement is to reduce exposure temporarily while a full fix is being prepared.

Question 14

In a branch-office network, a systems security analyst must use observed malicious indicators to identify additional affected hosts. Which approach is MOST appropriate? Assume no additional product-specific features are available beyond the concepts listed.

  1. IoC-driven detection and analysis
  2. Chain of custody
  3. Compensating containment control
  4. Isolation
  5. Evidence acquisition

Correct answer: A

Why: Indicators of compromise help analysts identify affected systems and scope suspicious activity during detection and analysis. It directly fits this scenario because the requirement is to use observed malicious indicators to identify additional affected hosts.

Option review:

A: Indicators of compromise help analysts identify affected systems and scope suspicious activity during detection and analysis. It directly fits this scenario because the requirement is to use observed malicious indicators to identify additional affected hosts.

B: Chain of custody documents who collected, transferred, stored, and accessed evidence from collection through disposition. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to use observed malicious indicators to identify additional affected hosts.

C: A compensating control reduces incident risk when permanent remediation cannot be applied immediately. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to use observed malicious indicators to identify additional affected hosts.

D: Isolation contains an incident by separating affected systems or accounts from resources they could harm while preserving needed evidence. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to use observed malicious indicators to identify additional affected hosts.

E: Evidence acquisition collects relevant data using methods that preserve usefulness for investigation and possible legal review. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to use observed malicious indicators to identify additional affected hosts.

Learning point: Use IoC-driven detection and analysis when the key requirement is to use observed malicious indicators to identify additional affected hosts.

Question 15

For a manufacturing plant, the team must accomplish both of these goals: collect disk, memory, logs, or network evidence from an affected system, and determine how far the incident has spread before choosing containment actions. Which TWO choices together provide the best match? The organization wants a vendor-neutral approach that can be explained during audit review.

  1. Evidence acquisition
  2. Evidence integrity validation
  3. Legal hold
  4. Evidence preservation
  5. Scope determination

Correct answers: A, E

Why: Evidence acquisition collects relevant data using methods that preserve usefulness for investigation and possible legal review. It directly fits this scenario because the requirement is to collect disk, memory, logs, or network evidence from an affected system. Scoping identifies which systems, users, data, locations, and business processes are affected. It directly fits this scenario because the requirement is to determine how far the incident has spread before choosing containment actions.

Option review:

A: Evidence acquisition collects relevant data using methods that preserve usefulness for investigation and possible legal review. It directly fits this scenario because the requirement is to collect disk, memory, logs, or network evidence from an affected system.

B: Cryptographic hashes and documented procedures help demonstrate that collected evidence has not changed. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to collect disk, memory, logs, or network evidence from an affected system; determine how far the incident has spread before choosing containment actions.

C: A legal hold suspends normal deletion or disposal for information relevant to anticipated or active litigation or investigation. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to collect disk, memory, logs, or network evidence from an affected system; determine how far the incident has spread before choosing containment actions.

D: Preservation protects evidence from alteration, loss, contamination, or unauthorized access. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to collect disk, memory, logs, or network evidence from an affected system; determine how far the incident has spread before choosing containment actions.

E: Scoping identifies which systems, users, data, locations, and business processes are affected. It directly fits this scenario because the requirement is to determine how far the incident has spread before choosing containment actions.

Learning point: Use Evidence acquisition, Scope determination when the key requirement is to collect disk, memory, logs, or network evidence from an affected system; determine how far the incident has spread before choosing containment actions.

Question 16

a security administrator at Fourth Coffee is comparing several approaches. The deciding requirement is to maintain an auditable record of every person who handled evidence. Which option should be chosen? Base the decision on the primary security requirement, not on implementation convenience.

  1. Chain of custody
  2. Remediation
  3. Impact assessment
  4. Data and log analysis
  5. Re-imaging

Correct answer: A

Why: Chain of custody documents who collected, transferred, stored, and accessed evidence from collection through disposition. It directly fits this scenario because the requirement is to maintain an auditable record of every person who handled evidence.

Option review:

A: Chain of custody documents who collected, transferred, stored, and accessed evidence from collection through disposition. It directly fits this scenario because the requirement is to maintain an auditable record of every person who handled evidence.

B: Remediation removes vulnerabilities, malicious artifacts, misconfigurations, or compromised credentials that enabled the incident. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to maintain an auditable record of every person who handled evidence.

C: Impact analysis determines operational, confidentiality, integrity, availability, financial, legal, or reputational consequences. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to maintain an auditable record of every person who handled evidence.

D: Correlating endpoint, identity, application, and network data builds a timeline and clarifies attacker actions. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to maintain an auditable record of every person who handled evidence.

E: Re-imaging rebuilds a system from a trusted baseline when confidence in the existing installation cannot be restored. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to maintain an auditable record of every person who handled evidence.

Learning point: Use Chain of custody when the key requirement is to maintain an auditable record of every person who handled evidence.

Question 17

For a customer-facing messaging service, a response lead must satisfy all three needs: prove that an evidence image is unchanged after transfer and storage; determine how far the incident has spread before choosing containment actions; and restore a heavily compromised endpoint to a known-good operating-system state. Select THREE. The environment follows least privilege and preserves evidence where incident handling is involved.

  1. Chain of custody
  2. Scope determination
  3. Re-imaging
  4. Evidence integrity validation
  5. Remediation

Correct answers: B, C, D

Why: Scoping identifies which systems, users, data, locations, and business processes are affected. It directly fits this scenario because the requirement is to determine how far the incident has spread before choosing containment actions. Re-imaging rebuilds a system from a trusted baseline when confidence in the existing installation cannot be restored. It directly fits this scenario because the requirement is to restore a heavily compromised endpoint to a known-good operating-system state. Cryptographic hashes and documented procedures help demonstrate that collected evidence has not changed. It directly fits this scenario because the requirement is to prove that an evidence image is unchanged after transfer and storage.

Option review:

A: Chain of custody documents who collected, transferred, stored, and accessed evidence from collection through disposition. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to prove that an evidence image is unchanged after transfer and storage; determine how far the incident has spread before choosing containment actions; restore a heavily compromised endpoint to a known-good operating-system state.

B: Scoping identifies which systems, users, data, locations, and business processes are affected. It directly fits this scenario because the requirement is to determine how far the incident has spread before choosing containment actions.

C: Re-imaging rebuilds a system from a trusted baseline when confidence in the existing installation cannot be restored. It directly fits this scenario because the requirement is to restore a heavily compromised endpoint to a known-good operating-system state.

D: Cryptographic hashes and documented procedures help demonstrate that collected evidence has not changed. It directly fits this scenario because the requirement is to prove that an evidence image is unchanged after transfer and storage.

E: Remediation removes vulnerabilities, malicious artifacts, misconfigurations, or compromised credentials that enabled the incident. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to prove that an evidence image is unchanged after transfer and storage; determine how far the incident has spread before choosing containment actions; restore a heavily compromised endpoint to a known-good operating-system state.

Learning point: Use Evidence integrity validation, Scope determination, Re-imaging when the key requirement is to prove that an evidence image is unchanged after transfer and storage; determine how far the incident has spread before choosing containment actions; restore a heavily compromised endpoint to a known-good operating-system state.

Question 18

A new security procedure at Adventure Works must enable analysts to store acquired evidence so it remains intact for later analysis. Which option is the BEST choice? Use the choice that most directly addresses the stated evidence rather than a broader control.

  1. Evidence preservation
  2. Data and log analysis
  3. Chain of custody
  4. Scope determination
  5. Evidence acquisition

Correct answer: A

Why: Preservation protects evidence from alteration, loss, contamination, or unauthorized access. It directly fits this scenario because the requirement is to store acquired evidence so it remains intact for later analysis.

Option review:

A: Preservation protects evidence from alteration, loss, contamination, or unauthorized access. It directly fits this scenario because the requirement is to store acquired evidence so it remains intact for later analysis.

B: Correlating endpoint, identity, application, and network data builds a timeline and clarifies attacker actions. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to store acquired evidence so it remains intact for later analysis.

C: Chain of custody documents who collected, transferred, stored, and accessed evidence from collection through disposition. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to store acquired evidence so it remains intact for later analysis.

D: Scoping identifies which systems, users, data, locations, and business processes are affected. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to store acquired evidence so it remains intact for later analysis.

E: Evidence acquisition collects relevant data using methods that preserve usefulness for investigation and possible legal review. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to store acquired evidence so it remains intact for later analysis.

Learning point: Use Evidence preservation when the key requirement is to store acquired evidence so it remains intact for later analysis.

Question 19

The primary objective for Wide World Importers is to prevent potentially relevant evidence from being deleted by normal retention rules. Which selection best satisfies that objective in a global corporate network? The team wants the most defensible analyst action before expanding the investigation.

  1. Data and log analysis
  2. Impact assessment
  3. Scope determination
  4. Legal hold
  5. Evidence acquisition

Correct answer: D

Why: A legal hold suspends normal deletion or disposal for information relevant to anticipated or active litigation or investigation. It directly fits this scenario because the requirement is to prevent potentially relevant evidence from being deleted by normal retention rules.

Option review:

A: Correlating endpoint, identity, application, and network data builds a timeline and clarifies attacker actions. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to prevent potentially relevant evidence from being deleted by normal retention rules.

B: Impact analysis determines operational, confidentiality, integrity, availability, financial, legal, or reputational consequences. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to prevent potentially relevant evidence from being deleted by normal retention rules.

C: Scoping identifies which systems, users, data, locations, and business processes are affected. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to prevent potentially relevant evidence from being deleted by normal retention rules.

D: A legal hold suspends normal deletion or disposal for information relevant to anticipated or active litigation or investigation. It directly fits this scenario because the requirement is to prevent potentially relevant evidence from being deleted by normal retention rules.

E: Evidence acquisition collects relevant data using methods that preserve usefulness for investigation and possible legal review. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to prevent potentially relevant evidence from being deleted by normal retention rules.

Learning point: Use Legal hold when the key requirement is to prevent potentially relevant evidence from being deleted by normal retention rules.

Question 20

Datum Fabrication is designing a combined control. It must reconstruct what happened by correlating multiple telemetry sources, and reduce exposure temporarily while a full fix is being prepared. Which TWO options are most appropriate? Select based on the scenario’s decisive constraint, not on which technology is newest.

  1. IoC-driven detection and analysis
  2. Data and log analysis
  3. Compensating containment control
  4. Evidence acquisition
  5. Evidence preservation

Correct answers: B, C

Why: Correlating endpoint, identity, application, and network data builds a timeline and clarifies attacker actions. It directly fits this scenario because the requirement is to reconstruct what happened by correlating multiple telemetry sources. A compensating control reduces incident risk when permanent remediation cannot be applied immediately. It directly fits this scenario because the requirement is to reduce exposure temporarily while a full fix is being prepared.

Option review:

A: Indicators of compromise help analysts identify affected systems and scope suspicious activity during detection and analysis. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to reconstruct what happened by correlating multiple telemetry sources; reduce exposure temporarily while a full fix is being prepared.

B: Correlating endpoint, identity, application, and network data builds a timeline and clarifies attacker actions. It directly fits this scenario because the requirement is to reconstruct what happened by correlating multiple telemetry sources.

C: A compensating control reduces incident risk when permanent remediation cannot be applied immediately. It directly fits this scenario because the requirement is to reduce exposure temporarily while a full fix is being prepared.

D: Evidence acquisition collects relevant data using methods that preserve usefulness for investigation and possible legal review. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to reconstruct what happened by correlating multiple telemetry sources; reduce exposure temporarily while a full fix is being prepared.

E: Preservation protects evidence from alteration, loss, contamination, or unauthorized access. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to reconstruct what happened by correlating multiple telemetry sources; reduce exposure temporarily while a full fix is being prepared.

Learning point: Use Data and log analysis, Compensating containment control when the key requirement is to reconstruct what happened by correlating multiple telemetry sources; reduce exposure temporarily while a full fix is being prepared.

Question 21

During an investigation at Tailspin Toys, the immediate requirement is to determine how far the incident has spread before choosing containment actions. What should a SOC lead select? Assume the activity is authorized and must follow normal enterprise change control.

  1. IoC-driven detection and analysis
  2. Remediation
  3. Scope determination
  4. Data and log analysis
  5. Impact assessment

Correct answer: C

Why: Scoping identifies which systems, users, data, locations, and business processes are affected. It directly fits this scenario because the requirement is to determine how far the incident has spread before choosing containment actions.

Option review:

A: Indicators of compromise help analysts identify affected systems and scope suspicious activity during detection and analysis. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine how far the incident has spread before choosing containment actions.

B: Remediation removes vulnerabilities, malicious artifacts, misconfigurations, or compromised credentials that enabled the incident. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine how far the incident has spread before choosing containment actions.

C: Scoping identifies which systems, users, data, locations, and business processes are affected. It directly fits this scenario because the requirement is to determine how far the incident has spread before choosing containment actions.

D: Correlating endpoint, identity, application, and network data builds a timeline and clarifies attacker actions. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine how far the incident has spread before choosing containment actions.

E: Impact analysis determines operational, confidentiality, integrity, availability, financial, legal, or reputational consequences. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine how far the incident has spread before choosing containment actions.

Learning point: Use Scope determination when the key requirement is to determine how far the incident has spread before choosing containment actions.

Question 22

Proseware Research is updating its security operations standard for a restricted research segment. Which option most directly helps the team estimate the business and technical consequences of the incident? Assume no additional product-specific features are available beyond the concepts listed.

  1. Impact assessment
  2. Compensating containment control
  3. IoC-driven detection and analysis
  4. Evidence integrity validation
  5. Data and log analysis

Correct answer: A

Why: Impact analysis determines operational, confidentiality, integrity, availability, financial, legal, or reputational consequences. It directly fits this scenario because the requirement is to estimate the business and technical consequences of the incident.

Option review:

A: Impact analysis determines operational, confidentiality, integrity, availability, financial, legal, or reputational consequences. It directly fits this scenario because the requirement is to estimate the business and technical consequences of the incident.

B: A compensating control reduces incident risk when permanent remediation cannot be applied immediately. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to estimate the business and technical consequences of the incident.

C: Indicators of compromise help analysts identify affected systems and scope suspicious activity during detection and analysis. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to estimate the business and technical consequences of the incident.

D: Cryptographic hashes and documented procedures help demonstrate that collected evidence has not changed. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to estimate the business and technical consequences of the incident.

E: Correlating endpoint, identity, application, and network data builds a timeline and clarifies attacker actions. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to estimate the business and technical consequences of the incident.

Learning point: Use Impact assessment when the key requirement is to estimate the business and technical consequences of the incident.

Question 23

A ticket at Wingtip Services asks a SOC analyst to stop a compromised endpoint from communicating with other systems. Which choice addresses the requirement most directly? The organization wants a vendor-neutral approach that can be explained during audit review.

  1. Re-imaging
  2. Scope determination
  3. Chain of custody
  4. Isolation
  5. Impact assessment

Correct answer: D

Why: Isolation contains an incident by separating affected systems or accounts from resources they could harm while preserving needed evidence. It directly fits this scenario because the requirement is to stop a compromised endpoint from communicating with other systems.

Option review:

A: Re-imaging rebuilds a system from a trusted baseline when confidence in the existing installation cannot be restored. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to stop a compromised endpoint from communicating with other systems.

B: Scoping identifies which systems, users, data, locations, and business processes are affected. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to stop a compromised endpoint from communicating with other systems.

C: Chain of custody documents who collected, transferred, stored, and accessed evidence from collection through disposition. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to stop a compromised endpoint from communicating with other systems.

D: Isolation contains an incident by separating affected systems or accounts from resources they could harm while preserving needed evidence. It directly fits this scenario because the requirement is to stop a compromised endpoint from communicating with other systems.

E: Impact analysis determines operational, confidentiality, integrity, availability, financial, legal, or reputational consequences. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to stop a compromised endpoint from communicating with other systems.

Learning point: Use Isolation when the key requirement is to stop a compromised endpoint from communicating with other systems.

Question 24

In a high-value payment environment, a threat hunter must remove the root technical condition that allowed compromise. Which approach is MOST appropriate? Base the decision on the primary security requirement, not on implementation convenience.

  1. Chain of custody
  2. Legal hold
  3. Evidence acquisition
  4. Remediation
  5. Scope determination

Correct answer: D

Why: Remediation removes vulnerabilities, malicious artifacts, misconfigurations, or compromised credentials that enabled the incident. It directly fits this scenario because the requirement is to remove the root technical condition that allowed compromise.

Option review:

A: Chain of custody documents who collected, transferred, stored, and accessed evidence from collection through disposition. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to remove the root technical condition that allowed compromise.

B: A legal hold suspends normal deletion or disposal for information relevant to anticipated or active litigation or investigation. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to remove the root technical condition that allowed compromise.

C: Evidence acquisition collects relevant data using methods that preserve usefulness for investigation and possible legal review. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to remove the root technical condition that allowed compromise.

D: Remediation removes vulnerabilities, malicious artifacts, misconfigurations, or compromised credentials that enabled the incident. It directly fits this scenario because the requirement is to remove the root technical condition that allowed compromise.

E: Scoping identifies which systems, users, data, locations, and business processes are affected. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to remove the root technical condition that allowed compromise.

Learning point: Use Remediation when the key requirement is to remove the root technical condition that allowed compromise.

Question 25

During a security review, a risk analyst must address two separate needs: restore a heavily compromised endpoint to a known-good operating-system state, and store acquired evidence so it remains intact for later analysis. Select TWO. The environment follows least privilege and preserves evidence where incident handling is involved.

  1. Re-imaging
  2. Compensating containment control
  3. Evidence preservation
  4. Impact assessment
  5. Scope determination

Correct answers: A, C

Why: Re-imaging rebuilds a system from a trusted baseline when confidence in the existing installation cannot be restored. It directly fits this scenario because the requirement is to restore a heavily compromised endpoint to a known-good operating-system state. Preservation protects evidence from alteration, loss, contamination, or unauthorized access. It directly fits this scenario because the requirement is to store acquired evidence so it remains intact for later analysis.

Option review:

A: Re-imaging rebuilds a system from a trusted baseline when confidence in the existing installation cannot be restored. It directly fits this scenario because the requirement is to restore a heavily compromised endpoint to a known-good operating-system state.

B: A compensating control reduces incident risk when permanent remediation cannot be applied immediately. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to restore a heavily compromised endpoint to a known-good operating-system state; store acquired evidence so it remains intact for later analysis.

C: Preservation protects evidence from alteration, loss, contamination, or unauthorized access. It directly fits this scenario because the requirement is to store acquired evidence so it remains intact for later analysis.

D: Impact analysis determines operational, confidentiality, integrity, availability, financial, legal, or reputational consequences. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to restore a heavily compromised endpoint to a known-good operating-system state; store acquired evidence so it remains intact for later analysis.

E: Scoping identifies which systems, users, data, locations, and business processes are affected. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to restore a heavily compromised endpoint to a known-good operating-system state; store acquired evidence so it remains intact for later analysis.

Learning point: Use Re-imaging, Evidence preservation when the key requirement is to restore a heavily compromised endpoint to a known-good operating-system state; store acquired evidence so it remains intact for later analysis.

Question 26

a SOC analyst at Contoso Health is comparing several approaches. The deciding requirement is to reduce exposure temporarily while a full fix is being prepared. Which option should be chosen? Use the choice that most directly addresses the stated evidence rather than a broader control.

  1. Evidence integrity validation
  2. Data and log analysis
  3. Compensating containment control
  4. Scope determination
  5. Chain of custody

Correct answer: C

Why: A compensating control reduces incident risk when permanent remediation cannot be applied immediately. It directly fits this scenario because the requirement is to reduce exposure temporarily while a full fix is being prepared.

Option review:

A: Cryptographic hashes and documented procedures help demonstrate that collected evidence has not changed. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to reduce exposure temporarily while a full fix is being prepared.

B: Correlating endpoint, identity, application, and network data builds a timeline and clarifies attacker actions. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to reduce exposure temporarily while a full fix is being prepared.

C: A compensating control reduces incident risk when permanent remediation cannot be applied immediately. It directly fits this scenario because the requirement is to reduce exposure temporarily while a full fix is being prepared.

D: Scoping identifies which systems, users, data, locations, and business processes are affected. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to reduce exposure temporarily while a full fix is being prepared.

E: Chain of custody documents who collected, transferred, stored, and accessed evidence from collection through disposition. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to reduce exposure temporarily while a full fix is being prepared.

Learning point: Use Compensating containment control when the key requirement is to reduce exposure temporarily while a full fix is being prepared.

Question 27

While supporting an airline operations network, a security operations engineer is asked to use observed malicious indicators to identify additional affected hosts. Which concept or tool is the clearest match? The team wants the most defensible analyst action before expanding the investigation.

  1. Evidence integrity validation
  2. IoC-driven detection and analysis
  3. Data and log analysis
  4. Scope determination
  5. Impact assessment

Correct answer: B

Why: Indicators of compromise help analysts identify affected systems and scope suspicious activity during detection and analysis. It directly fits this scenario because the requirement is to use observed malicious indicators to identify additional affected hosts.

Option review:

A: Cryptographic hashes and documented procedures help demonstrate that collected evidence has not changed. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to use observed malicious indicators to identify additional affected hosts.

B: Indicators of compromise help analysts identify affected systems and scope suspicious activity during detection and analysis. It directly fits this scenario because the requirement is to use observed malicious indicators to identify additional affected hosts.

C: Correlating endpoint, identity, application, and network data builds a timeline and clarifies attacker actions. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to use observed malicious indicators to identify additional affected hosts.

D: Scoping identifies which systems, users, data, locations, and business processes are affected. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to use observed malicious indicators to identify additional affected hosts.

E: Impact analysis determines operational, confidentiality, integrity, availability, financial, legal, or reputational consequences. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to use observed malicious indicators to identify additional affected hosts.

Learning point: Use IoC-driven detection and analysis when the key requirement is to use observed malicious indicators to identify additional affected hosts.

Question 28

Lucerne Publishing is designing a combined control. It must collect disk, memory, logs, or network evidence from an affected system, and determine how far the incident has spread before choosing containment actions. Which TWO options are most appropriate? Select based on the scenario’s decisive constraint, not on which technology is newest.

  1. Impact assessment
  2. Evidence acquisition
  3. Evidence integrity validation
  4. Scope determination
  5. IoC-driven detection and analysis

Correct answers: B, D

Why: Evidence acquisition collects relevant data using methods that preserve usefulness for investigation and possible legal review. It directly fits this scenario because the requirement is to collect disk, memory, logs, or network evidence from an affected system. Scoping identifies which systems, users, data, locations, and business processes are affected. It directly fits this scenario because the requirement is to determine how far the incident has spread before choosing containment actions.

Option review:

A: Impact analysis determines operational, confidentiality, integrity, availability, financial, legal, or reputational consequences. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to collect disk, memory, logs, or network evidence from an affected system; determine how far the incident has spread before choosing containment actions.

B: Evidence acquisition collects relevant data using methods that preserve usefulness for investigation and possible legal review. It directly fits this scenario because the requirement is to collect disk, memory, logs, or network evidence from an affected system.

C: Cryptographic hashes and documented procedures help demonstrate that collected evidence has not changed. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to collect disk, memory, logs, or network evidence from an affected system; determine how far the incident has spread before choosing containment actions.

D: Scoping identifies which systems, users, data, locations, and business processes are affected. It directly fits this scenario because the requirement is to determine how far the incident has spread before choosing containment actions.

E: Indicators of compromise help analysts identify affected systems and scope suspicious activity during detection and analysis. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to collect disk, memory, logs, or network evidence from an affected system; determine how far the incident has spread before choosing containment actions.

Learning point: Use Evidence acquisition, Scope determination when the key requirement is to collect disk, memory, logs, or network evidence from an affected system; determine how far the incident has spread before choosing containment actions.

Question 29

During a security review, a vulnerability analyst must address two separate needs: maintain an auditable record of every person who handled evidence, and estimate the business and technical consequences of the incident. Select TWO. Assume the activity is authorized and must follow normal enterprise change control.

  1. Scope determination
  2. Remediation
  3. Chain of custody
  4. Isolation
  5. Impact assessment

Correct answers: C, E

Why: Chain of custody documents who collected, transferred, stored, and accessed evidence from collection through disposition. It directly fits this scenario because the requirement is to maintain an auditable record of every person who handled evidence. Impact analysis determines operational, confidentiality, integrity, availability, financial, legal, or reputational consequences. It directly fits this scenario because the requirement is to estimate the business and technical consequences of the incident.

Option review:

A: Scoping identifies which systems, users, data, locations, and business processes are affected. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to maintain an auditable record of every person who handled evidence; estimate the business and technical consequences of the incident.

B: Remediation removes vulnerabilities, malicious artifacts, misconfigurations, or compromised credentials that enabled the incident. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to maintain an auditable record of every person who handled evidence; estimate the business and technical consequences of the incident.

C: Chain of custody documents who collected, transferred, stored, and accessed evidence from collection through disposition. It directly fits this scenario because the requirement is to maintain an auditable record of every person who handled evidence.

D: Isolation contains an incident by separating affected systems or accounts from resources they could harm while preserving needed evidence. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to maintain an auditable record of every person who handled evidence; estimate the business and technical consequences of the incident.

E: Impact analysis determines operational, confidentiality, integrity, availability, financial, legal, or reputational consequences. It directly fits this scenario because the requirement is to estimate the business and technical consequences of the incident.

Learning point: Use Chain of custody, Impact assessment when the key requirement is to maintain an auditable record of every person who handled evidence; estimate the business and technical consequences of the incident.

Question 30

At City Power Utilities, the response plan has three distinct requirements: prove that an evidence image is unchanged after transfer and storage; determine how far the incident has spread before choosing containment actions; and restore a heavily compromised endpoint to a known-good operating-system state. Which THREE options should be selected? Assume no additional product-specific features are available beyond the concepts listed.

  1. Scope determination
  2. Data and log analysis
  3. Evidence integrity validation
  4. Re-imaging
  5. Impact assessment

Correct answers: A, C, D

Why: Scoping identifies which systems, users, data, locations, and business processes are affected. It directly fits this scenario because the requirement is to determine how far the incident has spread before choosing containment actions. Cryptographic hashes and documented procedures help demonstrate that collected evidence has not changed. It directly fits this scenario because the requirement is to prove that an evidence image is unchanged after transfer and storage. Re-imaging rebuilds a system from a trusted baseline when confidence in the existing installation cannot be restored. It directly fits this scenario because the requirement is to restore a heavily compromised endpoint to a known-good operating-system state.

Option review:

A: Scoping identifies which systems, users, data, locations, and business processes are affected. It directly fits this scenario because the requirement is to determine how far the incident has spread before choosing containment actions.

B: Correlating endpoint, identity, application, and network data builds a timeline and clarifies attacker actions. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to prove that an evidence image is unchanged after transfer and storage; determine how far the incident has spread before choosing containment actions; restore a heavily compromised endpoint to a known-good operating-system state.

C: Cryptographic hashes and documented procedures help demonstrate that collected evidence has not changed. It directly fits this scenario because the requirement is to prove that an evidence image is unchanged after transfer and storage.

D: Re-imaging rebuilds a system from a trusted baseline when confidence in the existing installation cannot be restored. It directly fits this scenario because the requirement is to restore a heavily compromised endpoint to a known-good operating-system state.

E: Impact analysis determines operational, confidentiality, integrity, availability, financial, legal, or reputational consequences. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to prove that an evidence image is unchanged after transfer and storage; determine how far the incident has spread before choosing containment actions; restore a heavily compromised endpoint to a known-good operating-system state.

Learning point: Use Evidence integrity validation, Scope determination, Re-imaging when the key requirement is to prove that an evidence image is unchanged after transfer and storage; determine how far the incident has spread before choosing containment actions; restore a heavily compromised endpoint to a known-good operating-system state.

Question 31

For a newly acquired subsidiary, the team must accomplish both of these goals: store acquired evidence so it remains intact for later analysis, and remove the root technical condition that allowed compromise. Which TWO choices together provide the best match? The organization wants a vendor-neutral approach that can be explained during audit review.

  1. Impact assessment
  2. Compensating containment control
  3. Evidence preservation
  4. Isolation
  5. Remediation

Correct answers: C, E

Why: Preservation protects evidence from alteration, loss, contamination, or unauthorized access. It directly fits this scenario because the requirement is to store acquired evidence so it remains intact for later analysis. Remediation removes vulnerabilities, malicious artifacts, misconfigurations, or compromised credentials that enabled the incident. It directly fits this scenario because the requirement is to remove the root technical condition that allowed compromise.

Option review:

A: Impact analysis determines operational, confidentiality, integrity, availability, financial, legal, or reputational consequences. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to store acquired evidence so it remains intact for later analysis; remove the root technical condition that allowed compromise.

B: A compensating control reduces incident risk when permanent remediation cannot be applied immediately. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to store acquired evidence so it remains intact for later analysis; remove the root technical condition that allowed compromise.

C: Preservation protects evidence from alteration, loss, contamination, or unauthorized access. It directly fits this scenario because the requirement is to store acquired evidence so it remains intact for later analysis.

D: Isolation contains an incident by separating affected systems or accounts from resources they could harm while preserving needed evidence. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to store acquired evidence so it remains intact for later analysis; remove the root technical condition that allowed compromise.

E: Remediation removes vulnerabilities, malicious artifacts, misconfigurations, or compromised credentials that enabled the incident. It directly fits this scenario because the requirement is to remove the root technical condition that allowed compromise.

Learning point: Use Evidence preservation, Remediation when the key requirement is to store acquired evidence so it remains intact for later analysis; remove the root technical condition that allowed compromise.

Question 32

Northwind Traders is designing a combined control. It must prevent potentially relevant evidence from being deleted by normal retention rules, and restore a heavily compromised endpoint to a known-good operating-system state. Which TWO options are most appropriate? Base the decision on the primary security requirement, not on implementation convenience.

  1. Re-imaging
  2. Chain of custody
  3. Legal hold
  4. Scope determination
  5. Data and log analysis

Correct answers: A, C

Why: Re-imaging rebuilds a system from a trusted baseline when confidence in the existing installation cannot be restored. It directly fits this scenario because the requirement is to restore a heavily compromised endpoint to a known-good operating-system state. A legal hold suspends normal deletion or disposal for information relevant to anticipated or active litigation or investigation. It directly fits this scenario because the requirement is to prevent potentially relevant evidence from being deleted by normal retention rules.

Option review:

A: Re-imaging rebuilds a system from a trusted baseline when confidence in the existing installation cannot be restored. It directly fits this scenario because the requirement is to restore a heavily compromised endpoint to a known-good operating-system state.

B: Chain of custody documents who collected, transferred, stored, and accessed evidence from collection through disposition. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to prevent potentially relevant evidence from being deleted by normal retention rules; restore a heavily compromised endpoint to a known-good operating-system state.

C: A legal hold suspends normal deletion or disposal for information relevant to anticipated or active litigation or investigation. It directly fits this scenario because the requirement is to prevent potentially relevant evidence from being deleted by normal retention rules.

D: Scoping identifies which systems, users, data, locations, and business processes are affected. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to prevent potentially relevant evidence from being deleted by normal retention rules; restore a heavily compromised endpoint to a known-good operating-system state.

E: Correlating endpoint, identity, application, and network data builds a timeline and clarifies attacker actions. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to prevent potentially relevant evidence from being deleted by normal retention rules; restore a heavily compromised endpoint to a known-good operating-system state.

Learning point: Use Legal hold, Re-imaging when the key requirement is to prevent potentially relevant evidence from being deleted by normal retention rules; restore a heavily compromised endpoint to a known-good operating-system state.

Question 33

A ticket at Alpine Ski House asks a cloud security analyst to reconstruct what happened by correlating multiple telemetry sources. Which choice addresses the requirement most directly? The environment follows least privilege and preserves evidence where incident handling is involved.

  1. Compensating containment control
  2. Legal hold
  3. Data and log analysis
  4. Evidence preservation
  5. Evidence acquisition

Correct answer: C

Why: Correlating endpoint, identity, application, and network data builds a timeline and clarifies attacker actions. It directly fits this scenario because the requirement is to reconstruct what happened by correlating multiple telemetry sources.

Option review:

A: A compensating control reduces incident risk when permanent remediation cannot be applied immediately. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to reconstruct what happened by correlating multiple telemetry sources.

B: A legal hold suspends normal deletion or disposal for information relevant to anticipated or active litigation or investigation. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to reconstruct what happened by correlating multiple telemetry sources.

C: Correlating endpoint, identity, application, and network data builds a timeline and clarifies attacker actions. It directly fits this scenario because the requirement is to reconstruct what happened by correlating multiple telemetry sources.

D: Preservation protects evidence from alteration, loss, contamination, or unauthorized access. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to reconstruct what happened by correlating multiple telemetry sources.

E: Evidence acquisition collects relevant data using methods that preserve usefulness for investigation and possible legal review. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to reconstruct what happened by correlating multiple telemetry sources.

Learning point: Use Data and log analysis when the key requirement is to reconstruct what happened by correlating multiple telemetry sources.

Question 34

In a branch-office network, a systems security analyst must determine how far the incident has spread before choosing containment actions. Which approach is MOST appropriate? Use the choice that most directly addresses the stated evidence rather than a broader control.

  1. Scope determination
  2. Remediation
  3. Evidence preservation
  4. Data and log analysis
  5. Isolation

Correct answer: A

Why: Scoping identifies which systems, users, data, locations, and business processes are affected. It directly fits this scenario because the requirement is to determine how far the incident has spread before choosing containment actions.

Option review:

A: Scoping identifies which systems, users, data, locations, and business processes are affected. It directly fits this scenario because the requirement is to determine how far the incident has spread before choosing containment actions.

B: Remediation removes vulnerabilities, malicious artifacts, misconfigurations, or compromised credentials that enabled the incident. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine how far the incident has spread before choosing containment actions.

C: Preservation protects evidence from alteration, loss, contamination, or unauthorized access. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine how far the incident has spread before choosing containment actions.

D: Correlating endpoint, identity, application, and network data builds a timeline and clarifies attacker actions. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine how far the incident has spread before choosing containment actions.

E: Isolation contains an incident by separating affected systems or accounts from resources they could harm while preserving needed evidence. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine how far the incident has spread before choosing containment actions.

Learning point: Use Scope determination when the key requirement is to determine how far the incident has spread before choosing containment actions.

Question 35

A review at Litware Manufacturing finds a gap: the team cannot reliably estimate the business and technical consequences of the incident. Which option best closes that gap? The team wants the most defensible analyst action before expanding the investigation.

  1. Impact assessment
  2. Chain of custody
  3. Remediation
  4. Isolation
  5. Compensating containment control

Correct answer: A

Why: Impact analysis determines operational, confidentiality, integrity, availability, financial, legal, or reputational consequences. It directly fits this scenario because the requirement is to estimate the business and technical consequences of the incident.

Option review:

A: Impact analysis determines operational, confidentiality, integrity, availability, financial, legal, or reputational consequences. It directly fits this scenario because the requirement is to estimate the business and technical consequences of the incident.

B: Chain of custody documents who collected, transferred, stored, and accessed evidence from collection through disposition. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to estimate the business and technical consequences of the incident.

C: Remediation removes vulnerabilities, malicious artifacts, misconfigurations, or compromised credentials that enabled the incident. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to estimate the business and technical consequences of the incident.

D: Isolation contains an incident by separating affected systems or accounts from resources they could harm while preserving needed evidence. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to estimate the business and technical consequences of the incident.

E: A compensating control reduces incident risk when permanent remediation cannot be applied immediately. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to estimate the business and technical consequences of the incident.

Learning point: Use Impact assessment when the key requirement is to estimate the business and technical consequences of the incident.

Question 36

a security administrator at Fourth Coffee is comparing several approaches. The deciding requirement is to stop a compromised endpoint from communicating with other systems. Which option should be chosen? Select based on the scenario’s decisive constraint, not on which technology is newest.

  1. IoC-driven detection and analysis
  2. Compensating containment control
  3. Isolation
  4. Impact assessment
  5. Scope determination

Correct answer: C

Why: Isolation contains an incident by separating affected systems or accounts from resources they could harm while preserving needed evidence. It directly fits this scenario because the requirement is to stop a compromised endpoint from communicating with other systems.

Option review:

A: Indicators of compromise help analysts identify affected systems and scope suspicious activity during detection and analysis. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to stop a compromised endpoint from communicating with other systems.

B: A compensating control reduces incident risk when permanent remediation cannot be applied immediately. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to stop a compromised endpoint from communicating with other systems.

C: Isolation contains an incident by separating affected systems or accounts from resources they could harm while preserving needed evidence. It directly fits this scenario because the requirement is to stop a compromised endpoint from communicating with other systems.

D: Impact analysis determines operational, confidentiality, integrity, availability, financial, legal, or reputational consequences. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to stop a compromised endpoint from communicating with other systems.

E: Scoping identifies which systems, users, data, locations, and business processes are affected. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to stop a compromised endpoint from communicating with other systems.

Learning point: Use Isolation when the key requirement is to stop a compromised endpoint from communicating with other systems.

Question 37

While supporting a customer-facing messaging service, a response lead is asked to remove the root technical condition that allowed compromise. Which concept or tool is the clearest match? Assume the activity is authorized and must follow normal enterprise change control.

  1. IoC-driven detection and analysis
  2. Legal hold
  3. Evidence acquisition
  4. Remediation
  5. Evidence integrity validation

Correct answer: D

Why: Remediation removes vulnerabilities, malicious artifacts, misconfigurations, or compromised credentials that enabled the incident. It directly fits this scenario because the requirement is to remove the root technical condition that allowed compromise.

Option review:

A: Indicators of compromise help analysts identify affected systems and scope suspicious activity during detection and analysis. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to remove the root technical condition that allowed compromise.

B: A legal hold suspends normal deletion or disposal for information relevant to anticipated or active litigation or investigation. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to remove the root technical condition that allowed compromise.

C: Evidence acquisition collects relevant data using methods that preserve usefulness for investigation and possible legal review. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to remove the root technical condition that allowed compromise.

D: Remediation removes vulnerabilities, malicious artifacts, misconfigurations, or compromised credentials that enabled the incident. It directly fits this scenario because the requirement is to remove the root technical condition that allowed compromise.

E: Cryptographic hashes and documented procedures help demonstrate that collected evidence has not changed. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to remove the root technical condition that allowed compromise.

Learning point: Use Remediation when the key requirement is to remove the root technical condition that allowed compromise.

Question 38

A new security procedure at Adventure Works must enable analysts to restore a heavily compromised endpoint to a known-good operating-system state. Which option is the BEST choice? Assume no additional product-specific features are available beyond the concepts listed.

  1. Evidence acquisition
  2. Evidence integrity validation
  3. IoC-driven detection and analysis
  4. Re-imaging
  5. Remediation

Correct answer: D

Why: Re-imaging rebuilds a system from a trusted baseline when confidence in the existing installation cannot be restored. It directly fits this scenario because the requirement is to restore a heavily compromised endpoint to a known-good operating-system state.

Option review:

A: Evidence acquisition collects relevant data using methods that preserve usefulness for investigation and possible legal review. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to restore a heavily compromised endpoint to a known-good operating-system state.

B: Cryptographic hashes and documented procedures help demonstrate that collected evidence has not changed. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to restore a heavily compromised endpoint to a known-good operating-system state.

C: Indicators of compromise help analysts identify affected systems and scope suspicious activity during detection and analysis. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to restore a heavily compromised endpoint to a known-good operating-system state.

D: Re-imaging rebuilds a system from a trusted baseline when confidence in the existing installation cannot be restored. It directly fits this scenario because the requirement is to restore a heavily compromised endpoint to a known-good operating-system state.

E: Remediation removes vulnerabilities, malicious artifacts, misconfigurations, or compromised credentials that enabled the incident. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to restore a heavily compromised endpoint to a known-good operating-system state.

Learning point: Use Re-imaging when the key requirement is to restore a heavily compromised endpoint to a known-good operating-system state.

Question 39

The primary objective for Wide World Importers is to reduce exposure temporarily while a full fix is being prepared. Which selection best satisfies that objective in a global corporate network? The organization wants a vendor-neutral approach that can be explained during audit review.

  1. Compensating containment control
  2. Evidence integrity validation
  3. Evidence preservation
  4. Chain of custody
  5. Legal hold

Correct answer: A

Why: A compensating control reduces incident risk when permanent remediation cannot be applied immediately. It directly fits this scenario because the requirement is to reduce exposure temporarily while a full fix is being prepared.

Option review:

A: A compensating control reduces incident risk when permanent remediation cannot be applied immediately. It directly fits this scenario because the requirement is to reduce exposure temporarily while a full fix is being prepared.

B: Cryptographic hashes and documented procedures help demonstrate that collected evidence has not changed. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to reduce exposure temporarily while a full fix is being prepared.

C: Preservation protects evidence from alteration, loss, contamination, or unauthorized access. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to reduce exposure temporarily while a full fix is being prepared.

D: Chain of custody documents who collected, transferred, stored, and accessed evidence from collection through disposition. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to reduce exposure temporarily while a full fix is being prepared.

E: A legal hold suspends normal deletion or disposal for information relevant to anticipated or active litigation or investigation. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to reduce exposure temporarily while a full fix is being prepared.

Learning point: Use Compensating containment control when the key requirement is to reduce exposure temporarily while a full fix is being prepared.

Question 40

At Datum Fabrication, a security architect needs to use observed malicious indicators to identify additional affected hosts. Which option is the BEST fit for a mixed Windows and Linux estate? Base the decision on the primary security requirement, not on implementation convenience.

  1. Remediation
  2. Legal hold
  3. Evidence preservation
  4. Data and log analysis
  5. IoC-driven detection and analysis

Correct answer: E

Why: Indicators of compromise help analysts identify affected systems and scope suspicious activity during detection and analysis. It directly fits this scenario because the requirement is to use observed malicious indicators to identify additional affected hosts.

Option review:

A: Remediation removes vulnerabilities, malicious artifacts, misconfigurations, or compromised credentials that enabled the incident. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to use observed malicious indicators to identify additional affected hosts.

B: A legal hold suspends normal deletion or disposal for information relevant to anticipated or active litigation or investigation. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to use observed malicious indicators to identify additional affected hosts.

C: Preservation protects evidence from alteration, loss, contamination, or unauthorized access. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to use observed malicious indicators to identify additional affected hosts.

D: Correlating endpoint, identity, application, and network data builds a timeline and clarifies attacker actions. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to use observed malicious indicators to identify additional affected hosts.

E: Indicators of compromise help analysts identify affected systems and scope suspicious activity during detection and analysis. It directly fits this scenario because the requirement is to use observed malicious indicators to identify additional affected hosts.

Learning point: Use IoC-driven detection and analysis when the key requirement is to use observed malicious indicators to identify additional affected hosts.

Popular posts

img