Despite removing malware from some of the affected hosts, several of an organization's internal resources are still unavailable two weeks after the discovery of a major incident.
Which of the following best describes this phase?
Answer : A
The organization remains in the eradication phase because malicious artifacts are still being removed from affected systems and the environment has not yet reached a trusted state suitable for complete restoration. The phrase ''removing malware from some of the affected hosts'' indicates that responders are actively eliminating the threat across the compromised estate rather than merely observing or documenting it.
Eradication addresses malware, attacker persistence, exploited vulnerabilities, unauthorized accounts, malicious configurations, compromised credentials, and other mechanisms that could permit reinfection or renewed access. Only after responders have sufficiently eliminated those causes should affected resources progress fully into recovery and return to normal operation. NIST's current incident-response model identifies containment, eradication, and recovery as related but distinct activities and emphasizes restoring assets only after appropriate incident handling has occurred.
Detection would have occurred when the incident was initially discovered. Analysis determines scope, cause, and impact. Preparation takes place before incidents by establishing plans, tools, procedures, and capabilities. Post-incident activities occur after response and restoration and focus on organizational improvement.
The two-week duration does not determine the phase. The activity being performed does: continued removal of malware indicates eradication.
Study Guide Reference: Incident Response and Management Containment Eradication Malware Removal Persistence Removal System Validation Recovery.
A security operations center manager is concerned that after action reporting is not being completed in a timely manner.
Which of the following will allow the manager to quantify this concern?
Answer : B
Mean time to close is the most relevant measurement because the manager needs to quantify how long cases or incidents remain open before all required closure activities---including after-action documentation---are completed.
An incident may already be technically contained and remediated while administrative closure remains outstanding. Mean time to remediate measures how long it takes to correct or neutralize the security problem, but it does not necessarily include final reporting and formal case closure. Mean time to respond measures how quickly responders begin or perform response activity after detection. Mean time between failures is primarily a reliability metric describing the average operating duration between failures and does not measure SOC reporting performance.
Current Microsoft Sentinel SOC guidance explicitly includes mean time to closure and time-to-closure percentiles among incident-management metrics used to evaluate SOC performance. This directly maps to the manager's concern: if after-action reports delay completion of incidents, the organization's mean closure time will increase and can be trended by analyst, severity, team, or incident category.
Therefore, B provides the quantitative evidence needed to determine whether after-action reporting is preventing incidents from being closed promptly.
Study Guide Reference: Reporting and Communication Incident Metrics Mean Time to Close After-Action Reporting SOC Performance Measurement Continuous Improvement.
A Chief Information Security Officer (CISO) evaluates a threat heat map and notices a substantial increase in custom scanning and enumeration activities. The CISO wants to gather as much information as possible about the activities targeting the company to help prioritize mitigations.
Which of the following solutions is the best way to accomplish this goal?
Answer : A
A honeypot is the strongest choice because the objective is not merely to block activity but to collect detailed intelligence about how adversaries are scanning, enumerating, and interacting with the organization. A properly isolated honeypot deliberately presents an attractive target while allowing defenders to observe attacker behavior without exposing legitimate production assets.
The resulting telemetry can reveal source infrastructure, targeted services, enumeration sequences, exploit attempts, command patterns, tools, payloads, and potentially broader TTPs. MITRE D3FEND defines a decoy environment as hosts and networks established specifically to deceive an attacker, and describes honeypots as decoy network resources that can expose an attacker's potential intent and strategy.
Canary tokens are valuable high-confidence tripwires but generally provide narrower detection evidence. Threat-intelligence subscriptions provide external intelligence and may help with prioritization, yet they will not provide the same organization-specific visibility into actors actively interacting with the company's exposed environment. A WAF can log web attacks and block malicious requests, but its visibility is primarily limited to web application traffic.
Study Guide Reference: Security Operations Threat Intelligence Threat Hunting Deception Technologies Honeypots/Honeynets Adversary TTP Collection.
A vulnerability analyst must perform a security assessment on an edge device running various services.
The analyst runs an Nmap port scan and sees the following output:

Which of the following should the analyst do next to validate the discovered remote access service is secure?
Answer : C
The relevant follow-up is to assess the security configuration of the discovered VPN/IKE remote-access service, making option C the appropriate examination answer. Internet Key Exchange supports different negotiation modes, and Nmap includes specific capabilities for assessing IKE services. Nmap's ike-version script probes UDP port 500 and tests both Main and Aggressive Mode while identifying supported transforms and vendor characteristics.
Nmap's IKE library likewise explicitly supports generating either Main Mode or Aggressive Mode requests, enabling analysts to characterize the configuration of an exposed VPN endpoint. The security concern traditionally associated with this distinction is that Aggressive Mode exposes more negotiation information and has historically enabled offline attacks in some pre-shared-key configurations; Main Mode provides stronger identity protection during IKEv1 negotiation.
The other choices do not validate the security of the remote-access service. A web-server certificate is relevant to TLS-enabled HTTP services, BGP route publication relates to network routing, and ICMP ping only demonstrates basic reachability.
The analyst should therefore move from port discovery to service-specific configuration validation.
Study Guide Reference: Vulnerability Management Nmap Service Enumeration VPN/IKE UDP 500 Main Mode/Aggressive Mode Configuration Validation.
Which of the following describes the main benefits of MITRE ATT&CK Navigator?
Answer : D
MITRE ATT&CK Navigator is primarily a visualization and analytical tool for understanding adversary behavior and evaluating defensive coverage against ATT&CK tactics and techniques. Analysts can create layers over ATT&CK matrices, highlight techniques associated with specific threat groups, compare adversary profiles, record detection coverage, and identify techniques for which defensive visibility or controls are insufficient.
MITRE explicitly states that ATT&CK Navigator can be used to visualize defensive coverage, support red-team and blue-team planning, and represent the frequency of detected techniques. MITRE's ATT&CK design guidance also recognizes defensive gap assessment as a means of identifying areas where an enterprise lacks sufficient defenses or visibility.
Navigator itself does not replicate adversary behavior; adversary-emulation platforms and red-team tools perform that function. It is not a malware reverse-engineering platform, nor does it independently build defensive tools or execute incident-response actions.
Its major operational value is translating ATT&CK's behavioral knowledge base into a visual map that lets defenders answer two questions: What behaviors are relevant to the threats we face, and where do our detections or controls have gaps?
Study Guide Reference: Security Operations MITRE ATT&CK ATT&CK Navigator Tactics and Techniques Threat Mapping Detection Coverage Gap Analysis.
A binary file that might contain malicious code is hosted on an isolated machine. An analyst wants to quickly detect the malicious code.
Which of the following should the analyst use?
Answer : D
YARA is specifically designed to identify and classify suspicious or malicious files through pattern-based rules. A YARA rule can contain textual strings, hexadecimal byte sequences, regular expressions, metadata, file characteristics, and Boolean conditions. This makes YARA particularly effective when an analyst already has a binary specimen on an isolated analysis system and needs to determine whether it contains patterns associated with malware.
The official YARA documentation describes YARA as a tool for helping malware researchers identify and classify malware samples using textual and binary patterns. Rules consist primarily of strings and logical conditions that determine whether a file matches the defined characteristics.
The strings utility can reveal printable characters embedded within a binary and is useful during preliminary static analysis, but it does not itself classify the file against structured malware-detection signatures. VirusTotal can perform multi-engine analysis, but submitting a potentially sensitive binary from an isolated environment to an external service may be inappropriate and is unnecessary when local YARA detection is available. WHOIS provides registration information about internet resources and has no direct binary-malware detection capability.
Study Guide Reference: Security Operations Malware Analysis Static Analysis YARA Signature and Pattern Matching Binary/File Analysis.
Which of the following best explains the purpose of the Pyramid of Pain in threat intelligence?
Answer : A
The Pyramid of Pain illustrates the increasing operational difficulty imposed on an adversary when defenders successfully detect and deny progressively more behavioral indicators. At the lower levels are artifacts that attackers can replace relatively easily, such as hash values and IP addresses. Higher levels include domain names, network or host artifacts, tools, and ultimately tactics, techniques, and procedures (TTPs).
Its central defensive lesson is that not all indicators impose equal cost on an attacker. Blocking one IP address may require the attacker only to obtain another server. Detecting a specific malware hash can often be defeated by recompiling or modifying the file. Detecting the attacker's established behaviors and operational methods creates substantially greater difficulty because the adversary may need to redesign procedures, change tooling, retrain operators, or alter an established intrusion methodology.
The Pyramid of Pain was developed specifically to describe this relationship between indicators and the amount of operational ''pain'' defenders impose when those indicators are denied.
Option B describes impact measurement, not indicator durability. Option C concerns intelligence-source classification. Option D resembles threat-modeling approaches such as STRIDE rather than the Pyramid of Pain.
Study Guide Reference: Security Operations Threat Intelligence Pyramid of Pain Indicators of Compromise Tools TTPs Behavioral Detection.