Question 6 of 91How can an engineer verify if results will return for a potential detection based on historical events within the organization?
Correct Answer: C
Question 7 of 91Which of the following is not a type of metadata that can be returned by the metadata command?
Correct Answer: D
Question 8 of 91MITRE D3FEND™ is designed to compliment MITRE's list of adversarial tactics, techniques, and common knowledge (ATT&CK®). Which tactics are associated with MITRE D3FEND™ in order to detect, deny, and disrupt adversarial efforts?
Correct Answer: D
Question 9 of 91Below is an example of a sysmon process create log. Which EventCode would be associated to this log entry?
Correct Answer: C
Question 10 of 91Based on a recent red team exercise, an organization is highly concerned about pass the hash attacks especially including tools like Empire. Which EventСode associated to PowerShell Script Block Logging would be used to detect this activity?