exam questions

Exam CIS-SIR All Questions

View all questions & answers for the CIS-SIR exam

Exam CIS-SIR topic 1 question 79 discussion

Actual exam question from ServiceNow's CIS-SIR
Question #: 79
Topic #: 1
[All CIS-SIR Questions]

Select the one capability that retrieves a list of active network connections from a host or endpoint.

  • A. Sightings Search
  • B. Block Action
  • C. Get Running Processes
  • D. Publish Watchlist
  • E. Isolate Host
  • F. Get Network Statistics
Show Suggested Answer Hide Answer
Suggested Answer: F 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
sephereth
9 months, 3 weeks ago
Selected Answer: F
Explanation: ebook p.147, "Get Network Stattistics: retrievs a list of active network connections from an endpoint or host. This capability is used for incident enrichment during investigations."
upvoted 2 times
...
stophs
10 months, 4 weeks ago
Selected Answer: F
f is correct https://docs.servicenow.com/en-US/bundle/utah-security-management/page/product/security-operations-common/concept/get-network-statistics-capability.html
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago