This certification validates networking skills in enterprise networking, including design, configuration, troubleshooting, and secure operations. It is intended for professionals responsible for reliable connectivity across enterprise environments.
The Security Operations Center receives two alerts in security information and event management about two separate possible attacks. The first alert concerns brute force attempts on a domain controller, and the second attack concerns the flooding of a network. After an initial investigation, the team confirms that both alerts are valid and begins a detailed investigation.
According to the CAPEC model, which vulnerability criteria should the team prioritize in the investigation?
Which threat hunting methodology aims to understand how adversaries think?
What is a characteristic of a memory-resident attack?
What should be considered when using machine learning for data analysis in a SOC?
According to the MITRE ATT&CK framework, how is the password spraying technique classified?