CompTIA ITF+ helps professionals to decide if a career in IT is right for
them or to develop a broader understanding of IT.
ITF+ is the only pre-career certification that helps students or career changers
determine if they have a competency for information technology and if it is the
right career path for them.
ITF+ is the only single certification that covers all areas of IT foundations,
creating a broader understanding of IT making it ideal for non-technical
professionals.
ITF+ establishes an IT education framework for students in middle school and
high school.
About the exam The CompTIA IT Fundamentals exam focuses on the essential IT skills and
knowledge needed to perform tasks commonly performed by advanced end-users and
entry-level IT professionals alike, including:
Using features and functions of common operating systems and establishing
network connectivity
Identifying common software applications and their purpose
Using security and web browsing best practices
This exam is intended for candidates who are advanced end users and/or are
considering a career in IT. The exam is also a good fit for individuals
interested in pursuing professional-level certifications, such as A+.
What Skills Will You Learn?
HARDWARE IT CONCEPTS & TERMINOLOGY Comprehend notational systems, illustrate the basics of computing and
explain the value of data and troubleshooting
WINDOWS OPERATING SYSTEMS INFRASTRUCTURE Know how to set up and install common peripheral devices to a laptop/PC or
secure a basic wireless network
SOFTWARE TROUBLESHOOTING APPLICATIONS & SOFTWARE Manage applications software, understand the various components of an
operating system and explain the purpose of methods of application architecture
NETWORKING SOFTWARE DEVELOPMENT Comprehend programming language categories, interpret logic, and understand
the purpose of programming concepts
HARDWARE & NETWORK TROUBLESHOOTING DATABASE FUNDAMENTALS Able to explain database concepts, structures, and purpose, as well as
understands methods used to interface
SECURITY
Understand confidentiality, integrity, and availability concerns of secure
devices and best practice methods
Who would benefit from ITF+? Students considering a career in IT.
Professionals working in fields that require a broad understanding of IT.
Marketing, sales and operations staff in IT-based organizations.
Why would you benefit from ITF+? In 2017, nearly 5.4 million individuals worked as technology professionals
across the U.S., representing an increase of 2.1%, or nearly 110,000 net new
jobs. CompTIA ITF+ will help you determine if this is the field for you.
Twelve years ago, technology spending outside of IT was 20 percent of total
technology spending; it will become almost 90 percent by the end of the decade,
according to Gartner, Inc. All workers need fundamental IT skills to use these
technologies.
Exam Details Exam Codes Exam FC0-U61
Launch Date September 4, 2018
Exam Details The new CompTIA IT Fundamentals exam focuses on the knowledge and
skills required to identify and explain the basics of computing, IT
infrastructure, software development, and database use. With this new version
comes the addition of the + to further distinguish ourselves within the
marketplace and represent CompTIA quality and standards.
Number of Questions Maximum of 75 questions per exam
Type of Questions Multiple choice
Length of Test 60 Minutes
Passing Score 650 (on a scale of 900)
Recommended Experience No prior experience necessary
Languages English
Retirement Usually three years after launch
Testing Provider Pearson VUE
Testing Centers Online Testing
CompTIA IT Fundamentals FC0-U61:
What’s in this version The exam will certify the successful candidate has the knowledge and skills
required to identify and explain the basics of computing, IT infrastructure,
application and software, software development, database fundamentals and
security. In addition, candidates will have the ability to demonstrate their
knowledge to:
Install software Establish basic network connectivity
Identify/prevent basic security risks
Explain troubleshooting theory and preventative maintenance of devices
Renewal The CompTIA IT Fundamentals certification is considered good for life and
does not need to be renewed.
For certifications that are part of the CompTIA Continuing Education program and
that can be renewed, please go to our Continuing Education page.
Good for Life Certifications IT Fundamentals is good for life.
QUESTION 1 Which of the following would MOST likely prevent malware sent as compromised
file via email from infecting a person’s computer?
A. Email previewing
B. Patching
C. Clear browsing cache
D. Kill process
Correct Answer: B
QUESTION 2 A user wants to use a laptop outside the house and still remain connected to
the Internet. Which of the following would be the BEST choice to accomplish this
task?
A. Thunderbolt cable
B. Bluetooth module
C. Infrared port
D. WLAN card
Correct Answer: D
QUESTION 3 Joe, a user, finds out his password for a social media site has been
compromised. Joe tells a friend that his email and banking accounts are probably
also compromised. Which of the following has Joe MOST likely performed?
A. Password reuse
B. Snooping
C. Social engineering
D. Phishing
Correct Answer: A
QUESTION 4 A technician is installing a new wireless network and wants to secure the
wireless network to prevent unauthorized access. Which of the following
protocols would be the MOST secure?
A. WPA
B. SSID
C. WEP
D. WPA2
Correct Answer: D
QUESTION 5 Which of the following network protocols will MOST likely be used when
sending and receiving Internet email? (Select TWO.)
What’s on the new CompTIA CySA+ exam?
Ensure you are well-prepared on test day with comprehensive online training for
CySA+, only from CompTIA. Certkingdom Learn is interactive and self-paced,
combining instructional lessons with videos, practice questions, and
performance-based questions to help you prepare for your certification exam and
a career in IT.
Included in Certkingdom Learn for CySA+: 100% coverage of exam objectives
Over 25 hours of engaging content and videos
12 lessons with scenario-based Performance-Based Questions
120 practice questions with immediate feedback
90-question final assessment
Exclusive Certkingdom Learn features that help you nail the material and ace
your exam: Instructional lessons, images, and videos to help you learn the material
Practice questions and performance-based questions to assess and apply what you
know
Achievement badges, flashcards and a game center to keep you engaged
A personalized dashboard to track progress
Daily study tasks and a countdown calendar to keep you on pace
Feel confident when you’ve prepared for your exam with CompTIA Certkingdom
Learn!
The new CompTIA CySA+ exam applies behavioral analytics to networks and devices
to prevent, detect and combat cybersecurity threats through continuous security
monitoring.
Like its predecessor, CompTIA CySA+ (CS0-002) still covers core cybersecurity
analyst skills while emphasizing software and application security, automation,
threat hunting and IT regulatory compliance.
With the end goal of proactively defending and continuously improving the
security of an organization, people who have CompTIA CySA+ have the hands-on
knowledge and skills required to do the following:
Leverage intelligence and threat detection techniques
Analyze and interpret data
Identify and address vulnerabilities
Suggest preventative measures
Effectively respond to and recover from incidents
Download the exam objectives for free to find out everything that’s covered.
How much does CompTIA CySA+ cost? The retail price for CompTIA CySA+ (CS0-002) is $370. CompTIA offers
numerous ways to reduce this cost. Check out our article on how to save on exam
vouchers as well as information about financing options.
How can I train for CompTIA CySA+? Start by downloading the exam objectives and practice test questions to
understand what topics are covered and get examples of questions that you might
see. If you’re ready to start studying now, you can work through the self-paced
CompTIA Certkingdom Learn and Certkingdom Practice online training products that
are available now. The Official CompTIA CySA+ Study Guide eBook for CS0-002 is
expected in early June. If classroom study is more your speed, you can also
watch for instructor-led training options to come over the next few months.
The amount of time you’ll need to prepare for CompTIA CySA+ depends on your
existing knowledge on the topics and your hands-on cybersecurity experience. We
recommend that you have CompTIA Network+, CompTIA Security+ or the equivalent
knowledge plus a minimum of four years of hands-on information security or
related experience.
We also suggest that you dedicate between 30 and 40 hours of studying before
sitting for the exam.
Why would I choose CompTIA CySA+ over other cybersecurity certifications?
CompTIA CySA+ is the only intermediate high-stakes cybersecurity analyst
certification with hands-on, performance-based questions and multiple-choice
questions that covers the most up-to-date core cybersecurity analyst skills and
upcoming job skills used by threat intelligence analysts, application security
analysts, compliance analysts, incident responders/handlers and threat hunters,
bringing new techniques for combating threats inside and outside of the Security
Operations Center (SOC).
CompTIA exams are developed through an intensive process that includes workshops
where IT pros come together and discuss what knowledge, skills and abilities are
required to do certain job roles. So, the topics covered by CompTIA CySA+ match
the knowledge, skills and abilities cybersecurity analysts need today.
Can I still take the CompTIA CySA (CS0-001)? Yes. Older versions of CompTIA exams are generally available for about six
months after the new version comes out. The CompTIA CySA+ (CS0-001) exam will be
available until October 2020.
I’ve been studying for CompTIA CySA+ (CS0-001). Should I switch gears and study
for CompTIA CySA+ (CS0-002) instead?
If you’ve been studying for the CompTIA CySA+ (CS0-001), we would recommend
reviewing the exam objectives to see how much of what you’ve already studied is
on the new exam. If it makes sense for your time and level of knowledge, you may
want to switch gears and prepare for the new exam (CS0-002).
Some of the benefits of taking the new CompTIA CySA+ is that it covers the
latest subject matter with an emphasis on software and application security,
automation, threat hunting and IT regulatory compliance.
The following cybersecurity job roles align with CompTIA CySA+:
Cybersecurity Analyst
Threat intelligence analyst
Application security analyst
Incident response or handler
Threat hunter
Compliance analyst
Keep in mind that if you choose to pursue CS0-001, you must take it before it
retires in October 2020 to get your CompTIA CySA+ certification.
What can I expect from the CompTIA CySA+ exam?
You can expect performance-based and multiple-choice questions across five
domains:
Threat and Vulnerability Management
Software and Systems Security
IT careers are made here - click to subscribe and get a 10% discount on CompTIA
products
Security Operations and Monitoring
Incident Response
Compliance and Assessment
These domains relate back to the primary job of a cybersecurity analyst, which
is to monitor and identify vulnerabilities introduced on the network as a result
of nonsecure systems and software, regardless of the language, and respond to
the threats.
You should also be familiar with three broad categories of tools used by
cybersecurity analysts:
Packet Capture: Wireshark
Intrusion Detection System (IDS): Zeek and Snort
Security Information and Event Management (SIEM): AT&T Cybersecurity/AlienVault
OSSIM
For example, a cybersecurity analyst would need to plan, install, configure,
monitor and analyze an IDS or SIEM. Analyzing the output from the tool to
determine threats would be an example of a performance-based question you might
find on the exam. Or you may find a question on continuous monitoring activities
such as log reviews, impact analysis and response. To learn more about potential
topics, please download the exam objectives.
Can I go straight to CompTIA CySA+ instead of getting CompTIA Security+?
You can, but it’s not recommended because you need to know how a network works (CompTIA
Network+) and how to secure it (CompTIA Security+) before you can analyze it (CompTIA
CySA+). The CompTIA Cybersecurity Career Pathway shows how each certification
builds on the previous one, and skipping CompTIA Security+ could leave a gap in
your baseline cybersecurity skills.
We recommend having a minimum of four years of hands-on information security or
related experience before taking the CompTIA CySA+ exam.
How long is CompTIA CySA+ good for, and how can it be renewed? As with many CompTIA certifications, CySA+ is good for three years. CompTIA
offers a number of ways for you to renew your certifications. Learn more in the
continuing education (CE) section of our website.
I need to renew my CompTIA Security+ certification. If I pass CompTIA CySA+
will that renew it? Yes, CompTIA CySA+ will renew CompTIA Security+, since it’s considered a
higher-level certification. Learn more about renewing with a higher-level
certification in the CE section of our website.
Is CompTIA CySA+ approved by the DoD for 8570 requirements? Yes! CompTIA CySA+ is U.S. Department of Defense (DoD) 8570 approved. It
complies with government regulations under the Federal Information Security
Management Act (FISMA).
DoD 8570, DoD 8570.01-m and DoD 8140 identify the skills needed for a
cyber-ready workforce and align those skills with certain IT certifications.
Learn more about DoD regulations and how you can apply them in the private
sector.
Ready to start studying? Writing out your plan will set you up for success.
Download our free training plan worksheet to help get organized and make your
dream a reality.
Audience The Foundation Level syllabus forms the basis of the International Software
Testing Qualifications Board (ISTQB®) Certified Tester Scheme.
ISTQB® Foundation Level is relevant across software delivery practices including
Waterfall, Agile, DevOps and Continuous Delivery.
The 2018 Foundation Level qualification is suitable for anyone who needs to
demonstrate practical knowledge of the fundamental concepts of software testing
including people in roles such as testers, test analysts, test engineers, test
consultants, test managers, user acceptance testers and software developers.
It is also appropriate for individuals who need a basic understanding of
software testing including project managers, quality managers, software
development managers, business analysts, IT directors and management
consultants.
The new 2018 syllabus is recognised as a pre-requisite to other ISTQB®
certifications where Foundation Level is required (note: all previous releases
of Foundation Level, including the 2011 syllabus and “grandfathered” Foundation
Level certifications, will remain valid).
Training for 2018 Certified Tester Foundation Level is available from Accredited
Training Providers (classroom, virtual and e-learning). We highly recommend
attending accredited training as an ISTQB® Member Board will have assessed the
materials for relevance and consistency against the syllabus. Information about
Accredited Training Providers can be found here or contact your local ISTQB®
Member Board or Exam Provider
Self-study, using the syllabus and recommended reading material, is also an
option when preparing for the Foundation Level exam. Your local ISTQB® Member
Board or Exam Provider will be able to provide information on exams e.g.
languages available, where to find an exam centre etc.
Have a look at the Foundation Level introduction video.
Business Outcomes
The Business Outcomes expected of a candidate who has achieved the 2018
Foundation Level certification are as follows:
Promote efficient and effective communication by using a common vocabulary for
software testing.
Understand fundamental concepts of software testing.
Demonstrate understanding of how different development and testing practices,
and different constraints on testing, may apply in optimizing testing to
different contexts.
Contribute effectively in reviews.
Use established techniques for designing tests at all test levels.
Interpret and execute tests from given test specifications. Report on test
results.
Understand test management principles for resources, strategies, planning,
project control and risk management
Write and communicate clear and understandable defect reports
Understand the project factors that drive the test priorities and test approach
Understand the value that software testing brings to stakeholders
Appreciate how testing activities and work products align with project
objectives, measures and targets
Assist in the selection and implementation process of testing tool
Learning Objectives
Learning objectives are indicated for each section in the syllabus and
classified as follows:
K1: remember, recognize, recall
K2: understand, explain, give reasons, compare, classify, categorize, give
examples, summarize
K3: apply, use
K4: analyze
There are 62 Learning objectives in the 2018 Foundation syllabus:
15 K1
40 K2
7 K3
The 2018 Foundation Level Learning objectives are as follows:
Chapter 1 Fundamentals of Testing
1.1 What is Testing?
LO-1.1.1 Identify typical objectives of testing (K1)
LO-1.1.2 Differentiate testing from debugging (K2)
1.2 Why is Testing Necessary?
LO-1.2.1 Give examples of why testing is necessary (K2)
LO-1.2.2 Describe the relationship between testing and quality assurance and
give examples of how testing contributes to higher quality (K2)
LO-1.2.3 Distinguish between error, defect, and failure (K2)
LO-1.2.4 Distinguish between the root cause of a defect and its effects (K2)
1.3 Seven Testing Principles (K2)
LO-1.3.1 Explain the seven principles of testing (K2)
1.4 Test Process
LO-1.4.1 Explain the impact of context on the test process (K2)
LO-1.4.2 Describe the test activities and respective tasks within the test
process (K2)
LO-1.4.3 Differentiate the work products that support the test process (K2)
LO-1.4.4 Explain the value of maintaining traceability between the test basis
and the test work products (K2)
1.5 The Psychology of Testing (K2)
LO-1.5.1 Identify the psychological factors that influence the success of
testing (K1)
LO-1.5.2 Explain the difference between the mindset required for test activities
and the mindset required for development activities (K2)
Chapter 2 Testing Throughout the Software Development Lifecycle
2.1. Software Development Lifecycle Models
LO-2.1.1 Explain the relationships between software development activities and
test activities in the software development lifecycle (K2)
LO-2.1.2 Identify reasons why software development lifecycle models must be
adapted to the context of project and product characteristics (K1)
LO-2.1.3 Recall characteristics of good testing that are applicable to any life
cycle model (K1)
2.2 Test Levels (K2)
LO-2.2.1 Compare the different test levels from the perspective of objectives,
test basis, test objects, typical defects and failures, and approaches and
responsibilities (K2)
2.3 Test Types (K2)
LO-2.3.1 Compare functional, non-functional and white-box testing (K2)
LO-2.3.2 Recognize that functional and structural tests occur at any test level
(K1)
LO-2.3.3 Recognize that functional, non-functional and white-box tests occur at
any test level (K1)
LO-2.3.4 Compare the purposes of confirmation testing and regression testing
(K2)
2.4 Maintenance Testing (K2)
LO-2.4.1 Summarize triggers for maintenance testing (K2)
LO-2.4.2 Describe the role of impact analysis in maintenance testing (K2)
LO-2.4.3 Describe the role of impact analysis in maintenance testing (K2)
Chapter 3 Static Testing
3.1 Static Testing Basics
LO-3.1.1 Recognize types of software work product that can be examined by the
different static testing techniques (K1)
LO-3.1.2 Use examples to describe the value of static testing (K2)
LO-3.1.3 Explain the difference between static and dynamic techniques,
considering objectives, types of defects to be identified, and the role of these
techniques within the software lifecycle (K2)
3.2 Review Process
LO-3.2.1 Summarize the activities of the work product review process (K2)
LO-3.2.2 Recognize the different roles and responsibilities in a formal review
(K1)
LO-3.2.3 Explain the differences between different review types: informal
review, walkthrough, technical review and inspection (K2)
LO-3.2.4 Apply a review technique to a work product to find defects (K3)
LO-3.2.5 Explain the factors that contribute to a successful review (K2)
Chapter 4 Test Techniques
4.1 Categories of Test Techniques
LO-4.1.1 Explain the characteristics, commonalities, and differences between
black-box test techniques, white-box test techniques and experience-based test
techniques (K2)
4.2 Black-box Test Techniques
LO-4.2.1 Apply equivalence partitioning to derive test cases from given
requirements (K3)
LO-4.2.2 Apply boundary value analysis to derive test cases from given
requirements (K3)
LO-4.2.3 Apply decision table testing to derive test cases from given
requirements (K3)
LO-4.2.4 Apply state transition testing to derive test cases from given
requirements (K3)
LO-4.2.5 Explain how to derive test cases from a use case (K2)
4.3 White-box Test Techniques
LO-4.3.1 Explain statement coverage (K2)
LO-4.3.2 Explain decision coverage (K2)
LO-4.3.3 Explain the value of statement and decision coverage (K2)
5.1 Test Organization LO-5.1.1 Explain the benefits and drawbacks of independent testing (K2)
LO-5.1.2 Identify the tasks of a test manager and tester (K1)
5.2 Test Planning and Estimation
LO-5.2.1 Summarize the purpose and content of a test plan (K2)
LO-5.2.2 Differentiate between various test approaches (K2)
LO-5.2.3 Give examples of potential entry and exit criteria (K2)
LO-5.2.4 Apply knowledge of prioritization, and technical and logical
dependencies, to schedule test execution for a given set of test cases (K3)
LO-5.2.5 Identify factors that influence the effort related to testing (K1)
LO-5.2.6 Explain the difference between two estimation techniques: the
metrics-based technique and the expert-based technique (K2)
5.3 Test Monitoring and Control
LO-5.3.1 Recall metrics used for testing (K1)
LO-5.3.2 Summarize the purposes, contents, and audiences for test reports (K2)
5.5 Risks and Testing
LO-5.5.1 Define risk level by using likelihood and impact (K1)
LO-5.5.2 Distinguish between project and product risks (K2)
LO-5.5.3 Describe, by using examples, how product risk analysis may influence
thoroughness and scope of testing (K2)
5.6 Defect Management
LO-5.6.1 Write a defect report, covering defects found during testing (K3)
Chapter 6. Tool Support for Testing
6.1 Test tool considerations LO-6.1.1 Classify test tools according to their purpose and the test
activities they support (K2)
LO-6.1.2 Identify benefits and risks of test automation (K1)
LO-6.1.3 Remember special considerations for test execution and test management
tools (K1)
6.2 Test Planning and Estimation (K3) LO-6.2.1 Identify the main principles for selecting a tool (K1)
LO-6.2.2 Recall the objectives for using pilot projects to introduce tools (K1)
LO-6.2.3 Identify the success factors for evaluation, implementation, deployment
and on-going support of test tools in an organization (K1)
Syllabus The Foundation Level Syllabus forms the basis for the International Software
Testing Qualification at the Foundation Level.
The International Software Testing Qualifications Board® (ISTQB®) provides it to
the national examination bodies for them to accredit the training providers and
to derive examination questions in their local language.
Training providers will produce courseware and determine appropriate teaching
methods for accreditation, and the syllabus will help candidates in their
preparation for the examination.
The Certified Tester Foundation Level in Software Testing
The Foundation Level qualification is aimed at anyone involved in software
testing. This includes people in roles such as testers, test analysts, test
engineers, test consultants, test managers, user acceptance testers and software
developers.
This Foundation Level qualification is also appropriate for anyone who wants a
basic understanding of software testing, such as project managers, quality
managers, software development managers, business analysts, IT directors and
management consultants. Holders of the Foundation Certificate will be able to go
on to a higher level software testing qualification.
The Foundation Level Syllabus 2018 is available in Materials for download
section.
QUESTION 1
You are about to release a test progress report to a senior manager, who is not
a test specialist. Which of the following topics should NOT be included in the
test progress report?
A. Product risks which have been mitigated and those which are outstanding.
B. Recommendations for taking controlling actions
C. Status compared against the started exit criteria
D. Detailed overview of the risk-based test approach being used to ensure the
exit criteria to be achieved
Correct Answer: D
QUESTION 2 Explain how the above mentioned report may differ from a report that you
produce for the project manager, who is a test specialist Select TWO items from
the following options that can be used to report to the project
manager and would not be included in a report to senior management.
A. Show details on effort spent
B. List of all outstanding defects with their priority and severity
C. Give product risk status
D. Show trend analysis
E. State recommendations for release
Correct Answer: AB
QUESTION 3 Consider the typical objectives of testing. Which of the following metrics
can be used to measure the effectiveness of the testing process in achieving one
of those objectives?
A. Average number of days between defect discovery and resolution
B. Percentage of requirements covered
C. Lines of code written per developer per day
D. Percentage of test effort spent on regression testing
Correct Answer: B
QUESTION 4 You have been given responsibility for the non-functional testing of a
safety-critical monitoring & diagnostics
package in the medical area. Which of the following would you least expect to
see addressed in the test plan?
A. Availability
B. Safety
C. Portability
D. Reliability
Correct Answer: C
QUESTION 5 Since the system is in the medical domain and therefore in the safety
critical area, testing needs to be rigorous
and evidence is required that the system has been adequately tested. Identify
THREE measures that would
typically be part of the test approach in this domain and which are not always
applicable in other domains!
A. High level of documentation
B. Failure Mode and Effect Analysis (FMEA) sessions
C. Traceability to requirements
D. Non-functional testing
E. Master test planning
F. Test design techniques
G. Reviews
There are 4 Advanced modules - Word Processing, Spreadsheets, Database,
Presentation - and you can get an ECDL Advanced Certificate for each of them.
If you pass all 4 Advanced modules you will earn the certificate ECDL Advanced
Expert.
Content/Moduls: ECDL Advanced modules:
Advanced Word Processing written on orange puzzle piece - Apply advanced formatting
- Create tables of content and indexes
- Use fields, forms and templates
- Work with macros
- Integrate data; share documents
Advanced Spreadsheets, written on orange puzzle piece - Apply conditional and customised formatting
- Use functions of different categories
- Analyse, filter and sort tables and lists
- Work with named cell ranges
- Use linking, embedding and importing features
Advanced Database, written on orange puzzle piece - Understand key database concepts
- Create an advanced database structure and outputs
- Design and use queries, perform calculations
- Enhance forms and improve functionality
- Work with macros, linking and importing features
Advanced Presentation, written on orange puzzle piece - Understand target audience
- Use templates and format slide backgrounds
- Insert drawing objects, movies and sound
- Apply advanced chart formatting features
- Control a slide show.
Benefits: You have expert computer skills in the office applications.
Your educational level is comparable.
You get an international certificate to prove your qualification.
Prerequisites: ECDL Standard level skills in the module you want to take.
Preparation for tests: Course at Test Center (not compulsory)
Self-study (choose among the wide range of approved learning materials)
Software: MS Office 2016
MS Office 2013
MS Office 2010
MS Office 2007
Test:
If you want to take a test - contact an authorised ECDL Test Centers.
The tests are based on the current ECDL Advanced syllabi (Syllabi ).
Exam time: 45 minutes per certificate
QUESTION: 1 Which of the following statements will you use to delete a table from a
database?
A. DROP TABLE <table_name>
B. DELETE TABLE <table_name> FROM DATABASE
C. REMOVE TABLE <table_name>
D. DELETE TABLE <table_name>
Answer: A
Explanation:
You will use the DROP TABLE statement to delete a table from a database. The
syntax is as follows:
DROP TABLE <table_name>
Here, the DROP TABLE statement is used to drop the table and the <table_name>
specifies the name
of the table to be deleted.
The DROP TABLE statement removes the table from the database. It can only be
recovered if the
backup of the database is present.
Answer options D, C, and B are incorrect. There are no such types of statements
available.
Reference: ECDL/ICDL Exam Course Manual, Contents: "DROP TABLE statement"
Chapter: DATABASE, ADVANCED-LEVEL
Objective: Query Design
QUESTION: 2 Which of the following queries is used to see the relationship of data
between two fields?
A. Parameter
B. Select
C. Action
D. Crosstab
Answer: D
Explanation:
A crosstab query is a powerful analysis tool used to see the relationship of
data between two fields.
It calculates and restructures data for easier analysis. A user can use a
crosstab query to calculate a
sum, average, count, or other type of total for data that is grouped by two
types of information- one
down the left side of the datasheet and one across the top. The cell at the
junction of each row and
column displays the results of the query's calculation. This view is just like a
spreadsheet with unique
values of one field as rows, unique values of another field as columns, and the
summary of another
field as the cells in the matrix. How to create a crosstab query?
Take the following steps to create a crosstab query:
QUESTION: 4
Which of the following is a list of the references in a legal document, such as
cases, statutes, and rules, along with the page numbers on which the references
appear?
A. Table of Authorities
B. Table of Contents
C. Table of Pictures
D. Table of Figures
Answer: A
Explanation:
Table of Authorities is a list of the references in a legal document, such as
cases, statutes, and rules,
along with the page numbers on which the references appear.
Answer option B is incorrect. Table of Contents is a list of chapters and their
sections of a book or a
document. Use the list along with the respective page numbers of the chapters
and their sections for
easy navigation.
Answer option D is incorrect. Table of Figures is a list of the captions for
pictures, charts, graphs,
slides, or other illustrations in a document. Table of Figures given along with
the page numbers on
which the captions appear.
Answer option C is incorrect. It is not a valid type of list.
Reference: ECDL/ICDL Exam Course Manual, Contents: "Table of Authorities"
Chapter: ADVANCED WORD PROCESSING
Objective: Collaborative Editing
Certified Ethical Hacker (CEH) Version 11 CEH provides an in-depth understanding of ethical hacking phases, various
attack vectors, and preventative countermeasures. It will teach you how hackers
think and act maliciously so that you will be better positioned to set up your
security infrastructure and defend future attacks.
Understanding system weaknesses and vulnerabilities help organizations
strengthen their system security controls to minimize the risk of an incident.
CEH was built to incorporate a hands-on environment and systematic process
across every ethical hacking domain and methodology, giving you the opportunity
to work towards proving the required knowledge and skills needed to perform the
job of an ethical hacker. You will be exposed to an entirely different posture
towards the responsibilities and measures required to be secure. In its 11th
version, CEH continues to evolve with the latest operating systems, tools,
tactics, exploits,
and technologies. Here are some critical updates of CEH v11:
Incorporating Parrot Security OS When compared to Kali Linux, Parrot Security OS offers better performance on
lower-powered laptops and machines while offering an intuitive look and feel
with a larger repository of general tools.
Re-Mapped to NIST/NICE Framework CEH v11 is mapped rigorously to important
Specialty Areas under the NIST/NICE framework’s Protect and Defend (PR) job role
category overlapping with other job roles, including Analyze
(AN) and Securely Provision (SP).
Enhanced Cloud Security, IoT, and OT Modules CEH v11 covers updated Cloud and IoT modules to incorporate CSP’s Container
Technologies (e.g., Docker, Kubernetes), Cloud Computing threats, and a number
of IoT hacking tools (e.g. Shikra, Bus Pirate, Facedancer21, and more). This is
critical as the world moves towards broader and deeper cloud adoptions.
Cloud−Based Threats As the cloud industry is estimated to reach $354 billion by 2022, the
businesses struggle to limit the frequency of data theft incidents due to
misconfigured cloud environments. January to April 2020 alone saw a 630% spike
in cloud-based attacks. Learn how to avoid, identify, and respond to cloud-based
attacks with CEH v11.
CERTIFIED ETHICAL HACKER 04
IoT Threats
Market reports anticipate that the worldwide IoT-connected devices are expected
to reach 43 billion by 2023. To support this rapid expansion, the prominent
players of the internet, including Amazon Web Services, Google, IBM, Microsoft,
are swiftly shifting to private cloud services, creating complexities in IoT
ecosystems. Learn to deal with IoTbased attacks with the CEH v11 course that
covers the latest IoT hacking tools, such as Shikra, Bus Pirate, Facedancer21,
and many others.
Operational Technology (OT} Attacks Last year, businesses experienced a 2,000%
increase in OT based incidents. You can gain expertise in OT, IT, and IIoT
(industrial IoT) to secure a critical enterprise OT/IoT deployments.
To learn the advanced skills of OT, CEH covers concepts of OT, such as ICS,
SCADA, and PLC, various challenges of OT, OT hacking methodology, tools,
communication protocols of an OT network like Modbus, Profinet, HART-IP, SOAP,
CANopen, DeviceNet, Zigbee, Profibus, etc., and gaining Remote Access using DNP3
protocol.
Modern Malware Analysis CEH v11 now includes the latest malware analysis tactics for ransomware,
banking and financial malware, IoT botnets, OT malware analysis, Android malware,
and more! Covering the Latest Threats - Fileless Malware
As the security community observed a rise in fileless attacks, it began to raise
concerns about fileless malware attacks. As fileless malware is a relatively new
form of malware attack, organizations find it difficult to detect with endpoint
security solutions. With the CEH v11, you can now learn various fileless malware
techniques with associated defensive strategies, as the course focuses on the
taxonomy of fileless malware threats, fileless malware obfuscation techniques to
bypass antivirus, launching fileless malware through script-based injection,
launching fileless malware through phishing, and more.
New Lab Designs and Operating Systems This latest iteration of CEH v11 includes new operating systems, including
Windows Server 2019, Windows Server 2016, and Windows 10 configured with Domain
Controller, firewalls, and vulnerable web applications for practicing and
improving hacking skills.
Increased Lab Time and Hands−on Focus More than 50% of the CEH v11 course is dedicated to practical skills in live
ranges via EC-Council labs. EC-Council leads in this aspect of the industry.
Industry’s Most Comprehensive Tools Library The CEH v11 course includes a
library of the latest tools required by security practitioners and pen testers
across the world.
CERTIFIED ETHICAL HACKER 05
BREAK-THE-CODE Challenge! BTC takes Gamification to the next level, packed with 24 incredible Hacking
Challenges (on steroids!), across 4 levels of complexity covering 18 attack
vectors, including the OWASP Top 10!
Covers vulnerabilities ranging from a basic cross-site script to advanced
multi-level pivoting, ultimately giving access to the entire server.
Learners are required to possess varied skills and procedures in order to
capture the flag of each vulnerability at different levels.
Comes with an interactive UI, to which learners connect through a VPN to access
applications.
Contains a dynamic scoring system tracking a learner’s rise up levels, with
competitors watching this on the portal’s dashboard. Some of the vulnerabilities
covered are XSS, SQLi, IDoR, and Remote Code Execution.
CERTIFIED ETHICAL HACKER 06 Introduction to Ethical Hacking
Footprinting and Reconnaissance
Scanning Networks
Enumeration
Vulnerability Analysis
System Hacking
Malware Threats
Sniffing
Social Engineering
Denial-of-Service
Session Hijacking
Evading IDS, Firewalls, and Honeypots
Hacking Web Servers
Hacking Web Applications
SQL Injection
Hacking Wireless Networks
Hacking Mobile Platforms
IoT and OT Hacking
Cloud Computing
Cryptography
CERTIFIED ETHICAL HACKER 07 What You Will Learn ?
• Key issues include plaguing the information security world, ethical hacking,
information security controls, laws, and standards.
• Perform footprinting and reconnaissance using the latest footprinting
techniques and tools as a critical pre-attack phase required in ethical hacking.
• Network scanning techniques and scanning countermeasures.
• Enumeration techniques and enumeration countermeasures.
• Vulnerability analysis to identify security loopholes in the target
organization’s network, communication infrastructure, and end systems.
• System hacking methodology, steganography, steganalysis attacks, and covering
tracks to discover system and network vulnerabilities.
• Different types of malware (Trojan, Virus, worms, etc.), system auditing for
malware attacks, malware analysis, and countermeasures.
• Packet sniffing techniques to discover network vulnerabilities and
countermeasures to defend sniffing.
• Social engineering techniques and how to identify theft attacks to audit
humanlevel vulnerabilities and suggest social engineering countermeasures.
• DoS/DDoS attack techniques and tools to audit a target and DoS/DDoS
countermeasures.
• Session hijacking techniques to discover network-level session management,
authentication/authorization, cryptographic weaknesses, and countermeasures.
• Web server attacks and a comprehensive attack methodology to audit
vulnerabilities in web server infrastructure, and countermeasures.
• Web application attacks and comprehensive web application hacking methodology
to audit vulnerabilities in web applications, and countermeasures.
• SQL injection attack techniques, injection detection tools to detect SQL
injection attempts, and countermeasures.
• Wireless encryption, wireless hacking methodology, wireless hacking tools, and
Wi-Fi security tools.
• Mobile platform attack vector, android vulnerability exploitations, and mobile
security guidelines and tools.
• Firewall, IDS and honeypot evasion techniques, evasion tools and techniques to
audit a network perimeter for weaknesses, and countermeasures.
• Cloud computing concepts (Container technology, serverless computing), various
threats/attacks, and security techniques and tools.
• Penetration testing, security audit, vulnerability assessment, and penetration
testing roadmap.
• Threats to IoT and OT platforms and learn how to defend IoT and OT devices
securely.
• Cryptography ciphers, Public Key Infrastructure (PKI), cryptography attacks,
and cryptanalysis tools.
CERTIFIED ETHICAL HACKER 08 Target Audience
• Information Security Analyst / Administrator
• Information Assurance (IA) Security Officer
• Information Security Manager / Specialist
• Information Systems Security Engineer / Manager
• Information Security Professionals / Officers
• Information Security / IT Auditors
• Risk / Threat/Vulnerability Analyst
• System Administrators
• Network Administrators and Engineers
CERTIFIED ETHICAL HACKER 10 Eligibility Criteria for CEH Exam
To be eligible to challenge the EC-Council CEH certification examination, the
candidate has two options:
Attend Official Network Security Training by EC-Council:
If a candidate has completed an official EC-Council training either at an
Accredited Training Center, via the iClass platform, or at an approved academic
institution, the candidate is eligible to challenge the relevant EC-Council exam
without going through the application process.
Attempt the Exam without Official EC-Council Training:
In order to be considered for the EC-Council CEH exam without attending official
network security training, the candidate must have at least 2 years of work
experience in the Information Security domain. If the candidate has the required
work experience, they can submit an eligibility application form along with USD
100.00, a non-refundable fee
What About EC Council CEH v11 Certified Ethical Hacker Course? CEH v11 Certified Ethical Hacker program is The most desired information
security educational program within the industry, the accredited course provides
the advanced hacking tools & techniques employed by hackers & information
security professionals alike to interrupt a corporation.
CEH offers in-depth knowledge of moral hacking levels, diverse assault vectors,
and preventative countermeasures. It’ll educate you on ways hackers think and
act maliciously in order that you may be higher placed to installation your
protection infrastructure and guard against future assaults. Understanding
machine weaknesses and vulnerabilities assist groups to give a boost to their
device protection controls to limit the chance of an incident.
Certified Ethical Hacker Exam Fee? You must pass the Certified Ethical Hacker exam $100 application fee. For
more details visit www.eccouncil.org.
What’s New in EC Council CEH v11 Course? Ethical hacking concepts, cyber kill chain concepts, a summary of data
security, security controls, and various laws and regulations associated with
information security.
Footprinting concepts and methodologies and utilizing footprinting tools
alongside the countermeasures
Concepts of vulnerability assessment, its types, and solutions alongside a
hands-on experience of commercial tools used
Phases of system hacking, attacking techniques to get, escalate, and maintain
access on victim alongside covering tracks.
Malware threats, analysis of varied viruses, worms, and trojans like Emotet and
battling them to stop data. APT and Fileless Malware concepts are introduced to
the present domain.
Packet sniffing concepts, techniques, and protection against an equivalent.
Social engineering concepts and related terminologies like fraud, impersonation,
insider threats, social engineering techniques, and countermeasures
Denial of Service (DoS) and Distributed Denial of Service (DDoS) attacks, use
cases, and attack and defense tools
Security solutions like firewall, IPS, honeypots, their evasion, and protection
Web server and web application-based attacks, methodologies
SQL injection, hijacking, and evasion techniques
Wireless encryption, wireless hacking, and Bluetooth hacking-related concepts
Mobile device management, mobile platform attack vectors, and vulnerabilities
associated with Android and iOS systems
Recognizing the vulnerabilities in IoT and ensuring the security of IoT devices
Encryption algorithms, Public Key Infrastructure (PKI), cryptographic attacks,
and cryptanalysis
Cloud computing, threats and security, essentials of container technology and
serverless computing
What do we Learn EC Council CEH v11 Course?
CEH v11 Certified Ethical Hacker Course
CEH v11 Certified Ethical Hacker Course
Introduction to Ethical Hacking
Footprinting and Reconnaissance
Scanning Networks
Enumeration
Vulnerability Analysis
System Hacking
Malware Threats
Sniffing
Social Engineering
Denial-of-Service
Session Hijacking
Evading IDS, Firewalls, and Honeypots
Hacking Web Servers
Hacking Web Applications
SQL Injection
Hacking Wireless Networks
Hacking Mobile Platforms
IoT and OT Hacking
Cloud Computing
Cryptography
Who This Course is For?
Information Security Analyst
Information Assurance (IA) Security
Officer
Information Security Manager
Information Systems Security Engineer
Information Security Professionals,
Officers
Information Security
Risk, Threat, Vulnerability Analyst
System Administrators
Network Administrators and Engineers
QUESTION 1 While performing online banking using a Web browser, a user receives an
email that contains a link to an interesting Web site. When the user clicks on
the link, another Web browser session starts and displays a video of cats
playing a piano. The next business day, the user receives what looks like an
email from his bank, indicating that his bank account has been accessed from a
foreign country. The email asks the user to call his bank and verify the
authorization of a funds transfer that took place. What Web browser-based
security vulnerability was exploited to compromise the user?
A. Clickjacking
B. Cross-Site Scripting
C. Cross-Site Request Forgery
D. Web form input validation
Correct Answer: C
QUESTION 2 Which service in a PKI will vouch for the identity of an individual or
company?
A. KDC
B. CR
C. CBC
D. CA
Correct Answer: D
QUESTION 3 Identify the web application attack where the attackers exploit
vulnerabilities in dynamically generated web pages to inject client-side script
into web pages viewed by other users.
A. LDAP Injection attack
B. Cross-Site Scripting (XSS)
C. SQL injection attack
D. Cross-Site Request Forgery (CSRF)
Correct Answer: B
QUESTION 4 User A is writing a sensitive email message to user B outside the local
network. User A has chosen to use PKI to secure his message and ensure only user
B can read the sensitive email. At what layer of the OSI layer does the
encryption and decryption of the message take place?
A. Application
B. Transport
C. Session
D. Presentation
Description The "SAP Certified Application Associate - SAP SuccessFactors Succession
Management 2H/2020" certification exam verifies that the candidate possesses the
basic knowledge in the area of the SAP SuccessFactors Succession Management
application. This certificate proves that the candidate has a basic and overall
understanding within this consultant profile of the industry solution, and can
implement this knowledge practically in projects under guidance of an
experienced consultant. It is recommended as an entry-level qualification to
allow consultants to get acquainted with the fundamentals of SAP SuccessFactors
Succession Management.
Notes To ensure success, SAP recommends combining education courses and hands-on
experience to prepare for your certification exam as questions will test your
ability to apply the knowledge you have gained in training.
You are not allowed to use any reference materials during the certification test
(no access to online documentation or to any SAP system).
This certification is not intended for customers. If you are a customer
administrator, please explore the customer training catalogue and become
accredited via the SFX Accreditation program.
Please note that with passing this exam you will be asked to keep your
certification current with every new product release. For more information click
here . Once you pass the exam, you will be required to pass regular assessments
to stay current for all subsequent SAP SuccessFactors releases to maintain your
certification status and SAP Global Certification digital badge. SAP Learning
Hub subscription will be required.
Topic Areas Please see below the list of topics that may be covered within this
certification and the courses that cover them. Its accuracy does not constitute
a legitimate claim; SAP reserves the right to update the exam content (topics,
items, weighting) at any time.
Nominations > 12% Select the nomination type and identify nomination methods.
THR80 (SUCCESSFACTORS HCM SUITE)
THR85 (SUCCESSFACTORS HCM SUITE)
Position Management > 12% Create and configure MDF positions.
THR80 (SUCCESSFACTORS HCM SUITE)
THR85 (SUCCESSFACTORS HCM SUITE)
Succession Data Model > 12% Configure the Succesion Data Model.
THR80 (SUCCESSFACTORS HCM SUITE)
THR85 (SUCCESSFACTORS HCM SUITE)
Succession Org Chart and Lineage Chart 8% - 12% Customize talent review fields used in the Succession Org Chart.
THR80 (SUCCESSFACTORS HCM SUITE)
THR85 (SUCCESSFACTORS HCM SUITE)
Talent Pools 8% - 12% Configure MDF Talent Pools and link them to MDF picklists.
THR80 (SUCCESSFACTORS HCM SUITE)
THR85 (SUCCESSFACTORS HCM SUITE)
Processes and Presentations 8% - 12% Create processes and presentations and work with the successor import and
the nomination history.
THR80 (SUCCESSFACTORS HCM SUITE)
THR85 (SUCCESSFACTORS HCM SUITE)
General Information All SAP consultant certifications are available as Cloud Certifications in
the Certification Hub and can be booked with product code CER006. With CER006 –
SAP Certification in the Cloud, you can take up to six exams attempts of your
choice in one year – from wherever and whenever it suits you! Test dates can be
chosen and booked individually.
Each specific certification comes with its own set of preparation tactics. We
define them as "Topic Areas" and they can be found on each exam description. You
can find the number of questions, the duration of the exam, what areas you will
be tested on, and recommended course work and content you can reference.
Certification exams might contain unscored items that are being tested for
upcoming releases of the exam. These unscored items are randomly distributed
across the certification topics and are not counted towards the final score. The
total number of items of an examination as advertised in the Training Shop is
never exceeded when unscored items are used.
Please be aware that the professional- level certification also requires several
years of practical on-the-job experience and addresses real-life scenarios.
For more information refer to our FAQs. SAP Global Certification FAQ - Overview
SAP Global Certification FAQ - Exam Process
SAP Global Certification FAQ - Post-Exam Process
Safeguarding the Value of Certification SAP Education has worked hard together with the Certification & Enablement
Influence Council to enhance the value of certification and improve the exams.
An increasing number of customers and partners are now looking towards
certification as a reliable benchmark to safeguard their investments.
Unfortunately, the increased demand for certification has brought with it a
growing number of people who to try and attain SAP certification through unfair
means. This ongoing issue has prompted SAP Education to place a new focus on
test security. Please take a look at our post to understand what you can do to
help to protect the credibility of your certification status.
Our Certification Test Security Guidelines will help you as test taker to
understand the testing experience.
Security Guidelines
QUESTION: No: 1 To permanently remove a position from the system when importing the legacy
position file,
what should the Action column include?
Please choose the correct answer.
Response:
A. Reactivate
B. Purge
C. A 'nuII' value
D. Delete
Answer: B
QUESTION: No: 2 Prior to implementing Succession Management, your customer gathered talent
review information. The
customer wants to import the risk of loss and impact of loss for users.
Where in Admin Tools does the customer import this data?
Please choose the correct answer.
Response:
A. Under Succession -> Position Management -> Import Positions
B. Under Employee Files -> Employee Fields
C. Under Update User Information -> Import Extended User Information -> Personal
Information
D. Under Update User Information -> Import Extended User Information ->
Background Information
Answer: C
QUESTION: No: 3 Your customer conducted a talent search. When the customer analyzes the
results, some fields are blank.
What are likely reasons for this?
There are 2 correct answers to this question.
Response:
A. Data does NOT exist for that field.
B. Fields are NOT added to the talent search settings under Admin Tools.
C. Fields are NOT configured in the talent search section of the Succession Data
ModeI.
D. The user does NOT have permission to view the data.
CBRFIR Certification: Cisco Certified CyberOps Professional, Cisco Certified
CyberOps Specialist – CyberOps Forensic Analysis and Incident Response
Duration: 90 minutes
Available languages: English
Exam overview This exam tests your knowledge and skills related to cybersecurity forensic
analysis and incident response, including:
Incident response process and playbooks
Advanced incident response
Threat intelligence
Digital forensics concepts
Evidence collection and analysis
Principles of reverse engineering
Exam preparation
Official Cisco training
Conducting Forensic Analysis and Incident Response Using Cisco Technologies for
CyberOps (CBRFIR)
Exam Description: Conducting Forensic Analysis and Incident Response Using Cisco
Technologies for CyberOps v1.0 (CBRFIR 300-215) is a 90-minute exam that is
associated with the Cisco CyberOps Professional Certification. This exam tests a
candidate's knowledge of forensic analysis and incident response fundamentals,
techniques, and processes. The course Conducting Forensic Analysis and Incident
Response Using Cisco Technologies for CyberOps helps candidates to prepare for
this exam.
The following topics are general guidelines for the content likely to be
included on the exam. However, other related topics may also appear on any
specific delivery of the exam. To better reflect the contents of the exam and
for clarity purposes, the guidelines below may change at any time without
notice.
20% 1.0 Fundamentals 1.1 Analyze the components needed for a root cause analysis report
1.2 Describe the process of performing forensics analysis of infrastructure
network devices
1.3 Describe antiforensic tactics, techniques, and procedures
1.4 Recognize encoding and obfuscation techniques (such as, base 64 and hex
encoding)
1.5 Describe the use and characteristics of YARA rules (basics) for malware
identification, classification, and documentation
1.6 Describe the role of:
1.6.a hex editors (HxD, Hiew, and Hexfiend) in DFIR investigations
1.6.b disassemblers and debuggers (such as, Ghidra, Radare, and Evans Debugger)
to perform basic malware analysis
1.6.c deobfuscation tools (such as, XORBruteForces, xortool, and unpacker)
1.7 Describe the issues related to gathering evidence from virtualized
environments (major cloud vendors)
20% 2.0 Forensics Techniques 2.1 Recognize the methods identified in the MITRE attack framework to
perform fileless malware analysis
2.2 Determine the files needed and their location on the host
2.3 Evaluate output(s) to identify IOC on a host
2.3.a process analysis
2.3.b log analysis
2.4 Determine the type of code based on a provided snippet
2.5 Construct Python, PowerShell, and Bash scripts to parse and search logs or
multiple data sources (such as, Cisco Umbrella, Sourcefire IPS, AMP for
Endpoints, AMP for Network, and PX Grid)
2.6 Recognize purpose, use, and functionality of libraries and tools (such as,
Volatility, Systernals, SIFT tools, and TCPdump)
30% 3.0 Incident Response Techniques 3.1 Interpret alert logs (such as, IDS/IPS and syslogs)
3.2 Determine data to correlate based on incident type (host-based and
network-based activities)
3.3 Determine attack vectors or attack surface and recommend mitigation in a
given scenario
3.4 Recommend actions based on post-incident analysis
3.5 Recommend mitigation techniques for evaluated alerts from firewalls,
intrusion prevention systems (IPS), data analysis tools (such as, Cisco Umbrella
Investigate, Cisco Stealthwatch, and Cisco SecureX), and other systems to
responds to cyber incidents
3.6 Recommend a response to 0 day exploitations (vulnerability management)
3.7 Recommend a response based on intelligence artifacts
3.8 Recommend the Cisco security solution for detection and prevention, given a
scenario
3.9 Interpret threat intelligence data to determine IOC and IOA (internal and
external sources)
3.10 Evaluate artifacts from threat intelligence to determine the threat actor
profile
3.11 Describe capabilities of Cisco security solutions related to threat
intelligence (such as, Cisco Umbrella, Sourcefire IPS, AMP for Endpoints, and
AMP for Network)
15% 4.0 Forensics Processes 4.1 Describe antiforensic techniques (such as, debugging, Geo location, and
obfuscation)
4.2 Analyze logs from modern web applications and servers (Apache and NGINX)
4.3 Analyze network traffic associated with malicious activities using network
monitoring tools (such as, NetFlow and display filtering in Wireshark)
4.4 Recommend next step(s) in the process of evaluating files based on
distinguished characteristics of files in a given scenario
4.5 Interpret binaries using objdump and other CLI tools (such as, Linux,
Python, and Bash)
15% 5.0 Incident Response Processes 5.1 Describe the goals of incident response
5.2 Evaluate elements required in an incident response playbook
5.3 Evaluate the relevant components from the ThreatGrid report
5.4 Recommend next step(s) in the process of evaluating files from endpoints and
performing ad-hoc scans in a given scenario
5.5 Analyze threat intelligence provided in different formats (such as, STIX and
TAXII)
QUESTION 1 A security team is discussing lessons learned and suggesting process changes
after a security breach incident. During the incident, members of the security
team failed to report the abnormal system activity due to
a high project workload. Additionally, when the incident was identified, the
response took six hours due to management being unavailable to provide the
approvals needed. Which two steps will prevent these issues
from occurring in the future? (Choose two.)
A. Introduce a priority rating for incident response workloads.
B. Provide phishing awareness training for the fill security team.
C. Conduct a risk audit of the incident response workflow.
D. Create an executive team delegation plan.
E. Automate security alert timeframes with escalation triggers.
Correct Answer: A,E
QUESTION 2 An engineer is investigating a ticket from the accounting department in
which a user discovered an unexpected application on their workstation. Several
alerts are seen from the intrusion detection system of unknown outgoing internet
traffic from this workstation. The engineer also notices a degraded processing
capability, which complicates the analysis process. Which two actions should the
engineer take? (Choose two.)
A. Restore to a system recovery point.
B. Replace the faulty CPU.
C. Disconnect from the network.
D. Format the workstation drives.
E. Take an image of the workstation.
Correct Answer: A,E
QUESTION 3 What is a concern for gathering forensics evidence in public cloud
environments?
A. High Cost: Cloud service providers typically charge high fees for allowing
cloud forensics.
B. Configuration: Implementing security zones and proper network segmentation.
C. Timeliness: Gathering forensics evidence from cloud service providers
typically requires substantial time.
D. Multitenancy: Evidence gathering must avoid exposure of data from other
tenants.