Multiple Choice
During an incident, a cybersecurity analyst found several entries in the web server logs that are related to an IP with a bad reputation. Which of the following would cause the analyst to further review the incident?
A) BadReputationIp - - [2019-04-12 10:43Z] "GET /etc/passwd" 403 1023
B) BadReputationIp - - [2019-04-12 10:43Z] "GET /index.html?src=../.ssh/id_rsa" 401 17044
C) BadReputationIp - - [2019-04-12 10:43Z] "GET /a.php?src=/etc/passwd" 403 11056
D) BadReputationIp - - [2019-04-12 10:43Z] "GET /a.php?src=../../.ssh/id_rsa" 200 15036
E) BadReputationIp - - [2019-04-12 10:43Z] "GET /favicon.ico?src=../usr/share/icons" 200 19064
Correct Answer:

Verified
Correct Answer:
Verified
Q42: A security analyst has received information from
Q43: An incident responder successfully acquired application binaries
Q44: A security analyst needs to reduce the
Q45: A security analyst at a technology solutions
Q46: A security analyst is required to stay
Q48: A user's computer has been running slowly
Q49: Massivelog.log has grown to 40GB on a
Q50: Which of the following attacks can be
Q51: A security analyst reviews the following aggregated
Q52: A security analyst is reviewing the logs