What is a difference between a threat and a vulnerability?
Answer : B
A software development company develops high-end technology for the customer that will go through the HIPAA audit program. The technology will be hosted in the cloud, and the healthcare, employee names, and contact information will be stored on two separate logically isolated private cloud services. The patents and inventions will be hosted on a separate encrypted database. A compliance team is asked to analyze the cloud infrastructure and architecture to identify the protected data. Which two types of protected data should be identified? (Choose two.)
Answer : B, C
Refer to the exhibit.

What is occurring within the exhibit?
What is a disadvantage of the asymmetric encryption system?
Answer : A
Which items is an end-point application greylist used?
Answer : D
A greylist in endpoint applications refers to a list of items that are not yet classified as either good (whitelisted) or bad (blacklisted).
The primary function of a greylist is to hold applications, processes, or files that are under observation due to their unknown status.
These items are neither trusted nor immediately flagged as harmful, allowing security teams to monitor them closely for any suspicious behavior.
By placing items on a greylist, security operations can prevent potential threats without disrupting legitimate processes, awaiting further analysis to determine their true nature.
Reference
Cisco Cybersecurity Operations Fundamentals
Endpoint Security Best Practices
Greylisting Concepts in Cybersecurity
Which data format is the most efficient to build a baseline of traffic seen over an extended period of time?
An employee of a company receives an email with an attachment. They notice that this email is from a suspicious source, and they decide not to open the attached file. After further investigation, a security analyst concludes that this file is malware. To which category of the Cyber Kill Chain model does this event belong?
Answer : D