Which of the following services should the security team investigate further? (Select two).Option B is right, it directly addresses risk reduction and compliance. C might look tempting if you miss that agile/testing isn’t the main point here. Quick check: does the question mean "best for regulatory compliance" or just general software quality? That could change things.
This kind of scenario pops up often in practice sets and guides. SIEM and SOAR together really help centralize alerts and automate responses. If the question said "most secure" instead of "centralize," would XDR (E) make more sense?
HOTSPOT An organization has noticed large amounts of data are being sent out of its network. An analyst is identifying the cause of the data exfiltration. INSTRUCTIONS Select the command that generated the output in tabs 1 and 2. Review the output text in all tabs and identify the file responsible for the malicious behavior. If at any time you would like to bring back the initial state of the simulation, please click the Reset All button. 





cmd.exe.SIMULATION An organization's website was maliciously altered. INSTRUCTIONS Review information in each tab to select the source IP the analyst should be concerned about, the indicator of compromise, and the two appropriate corrective actions. 


Source IP: 10.7.34.82
Indicator: suspicious login times
Actions: disable sjames account, reset web server
I saw a similar question but not totally sure if the internal IP is right here since it connects right before the change. Did anyone else pick these values?

