Which expression creates a filter on a host IP address or name?
A. [src|dst] host
B. [tcp|udp] [src|dst] port
C. ether [src|dst] host
D. gateway host
Correct Answer: A


Which CVSSv3 metric value increases when the attacker is able to modify all files protected by the vulnerable
A. confidentiality
B. integrity
C. availability
D. complexity
Correct Answer: B


Which function does an internal CSIRT provide?
A. incident handling services across various CSIRTs
B. incident handling services for a country\\’s government
C. incident handling services for a parent organization
D. incident handling services as a service for other organization
Correct Answer: C


Which statement about threat actors is true?
A. They are any company assets that are threatened.
B. They are any assets that are threatened.
C. They are perpetrators of attacks.
D. They are victims of attacks.
Correct Answer: C


Employees are allowed access to internal websites. An employee connects to an internal website and IDS reports it as
malicious behavior. What is this example of?
A. true positive
B. false negative
C. false positive
D. true negative
Correct Answer: C


You see 100 HTTP GET and POST requests for various pages on one of your webservers. The user agent in the
requests contain php code that, if executed, creates and writes to a new php file on the webserver. Which category does
this event fall under as defined in the Diamond Model of Intrusion?
A. delivery
B. reconnaissance
C. action on objectives
D. installation
E. exploitation
Correct Answer: D

Which of the following Linux file systems not only supports journaling but also modifies important data structures of the
file system, such as the ones destined to store the file data for better performance and reliability?
C. Ext4
D. FAT32
Correct Answer: C


Which type of analysis assigns values to scenarios to see what the outcome might be in each scenario?
A. deterministic
B. exploratory
C. probabilistic
D. descriptive
Correct Answer: A


According to NIST-SP800-61R2, which option should be contained in the issue tracking system?
A. incidents related to the current incident
B. incident unrelated to the current incident
C. actions taken by nonincident handlers
D. latest public virus signatures
Correct Answer: A


Refer to the exhibit. Drag and drop the element name from the left onto the correct piece of the PCAP file on the right.lead4pass 210-255 exam question q10

Select and Place:

lead4pass 210-255 exam question q10-1

Correct Answer:

lead4pass 210-255 exam question q10-2


What are two security goals of data normalization? (Choose two.)
A. purge redundant data
B. reduce size of data on disk
C. increase data exposure
D. maintain data integrity
E. create data for abstraction
Correct Answer: AD


Which type verification typically consists of using tools to compute the message digest of the original and copies data,
then comparing the digests to make sure that they are the same?
A. evidence collection order
B. data integrity
C. data preservation
D. volatile data collection
Correct Answer: B


Which information must be left out of a final incident report?
A. server hardware configurations
B. exploit or vulnerability used
C. impact and/or the financial loss
D. how the incident was detected
Correct Answer: A

