CompTIA Security+ SY0-701 Practice Question
Your organization is employing multiple security measures to protect against various cyber threats. You have come across findings that suggest a potentially compromised website that is often visited by the research department. Which security measure in place is best suited to investigate whether this scenario is indicative of a sophisticated cyber threat aiming to exploit the frequent visitors of this website?
The SuspiciousAnalysisTool should be used to detect any anomalies in network traffic that could indicate complex cyber threats or attack patterns against the organization.
The DomainReputationChecker would provide the best insights into whether the website's sudden suspicious nature is part of a watering hole attack by evaluating its trustworthiness based on various reputational factors.
The SiteContentValidator should be deployed to check the website for known indicators of compromise such as malware or unexpected content changes.
The TrafficFilteringGateway would be the key to determining whether the website's traffic is part of a larger, targeted campaign against the research department's online activities.