Courseiva

Cisco CyberOps Associate 200-201 (200-201) — Questions 1–75

968 questions total · 13pages · All types, answers revealed

Page 1 of 13

Page 2
1
MCQhard

A multinational manufacturer handles personal data of employees in several countries and wants to ensure its security program aligns with recognized international standards for establishing, implementing, maintaining, and continually improving an information security management system. Which framework should the security team adopt as the primary basis for this program?

A.CIS Critical Security Controls
B.ISO/IEC 27001
C.PCI DSS
D.NIST Cybersecurity Framework
AnswerB

ISO/IEC 27001 specifies requirements for establishing, implementing, maintaining, and continually improving an information security management system, which is exactly what the scenario describes. It is internationally recognized and applicable across jurisdictions, making it suitable for a multinational manufacturer. The standard's management-system approach also supports certification, which provides external validation of the program.

Why this answer

ISO/IEC 27001 is the internationally recognized standard that specifies requirements for establishing, implementing, maintaining, and continually improving an information security management system. That scope matches the manufacturer's goal of a globally aligned, certifiable security program. The NIST Cybersecurity Framework, CIS Controls, and PCI DSS serve different purposes: voluntary taxonomy, technical safeguards, and payment card requirements, respectively.

Exam trap

The trap here is selecting a widely known security framework based on familiarity, without checking whether it defines a certifiable management system, which is the specific requirement described.

2
MCQhard

An organization wants to ensure that a received email genuinely came from the claimed sender and has not been altered. Which cryptographic mechanism provides both authentication and integrity?

A.Digital signature
B.Hash function
C.Public key infrastructure (PKI)
D.Symmetric encryption
AnswerA

A digital signature is created with the sender's private key and verified with their public key, so successful verification proves origin and confirms the message was not altered in transit. This delivers both authentication and integrity, matching the stem's requirements.

Why this answer

A digital signature uses the sender's private key to sign the message, and the recipient verifies it with the sender's public key. This process provides authentication (proving the sender's identity) and integrity (detecting any alteration) because any change to the message invalidates the signature. Hash functions alone provide integrity but not authentication, while PKI is the infrastructure that supports digital signatures but is not the mechanism itself.

Exam trap

Cisco often tests the distinction between a mechanism (digital signature) and the supporting infrastructure (PKI), leading candidates to mistakenly select PKI because they associate it with certificates and authentication.

How to eliminate wrong answers

Option B is wrong because a hash function provides integrity by producing a fixed-size digest, but it does not authenticate the sender; an attacker can replace both the message and its hash. Option C is wrong because PKI is a framework of policies, roles, and certificates that enables digital signatures and encryption, but it is not a cryptographic mechanism that directly provides both authentication and integrity. Option D is wrong because symmetric encryption provides confidentiality (secrecy) but does not inherently authenticate the sender or ensure integrity; an attacker with the shared key could modify the ciphertext.

3
Multi-Selectmedium

A healthcare organization must comply with HIPAA. Which THREE security measures are typically required under HIPAA? (Choose three.)

Select 3 answers
A.Regular vulnerability scanning of all internet-facing systems
B.Encryption of electronic protected health information (ePHI)
C.Annual penetration testing by an external firm
D.Implementation of access controls to limit who can view ePHI
E.Audit controls to record and examine access to ePHI
AnswersB, D, E

HIPAA's Security Rule treats encryption of electronic protected health information as an addressable implementation specification, protecting confidentiality and integrity during storage and transmission. It satisfies the stem's ePHI protection constraint, alongside access controls and audit logging required for compliance.

Why this answer

Option B is correct because HIPAA's Security Rule identifies encryption of electronic protected health information (ePHI) as an addressable implementation specification under both transmission security and encryption/decryption safeguards, meaning covered entities must implement it or document an equivalent alternative. Option D is correct because the Security Rule's Access Control standard (45 CFR 164.312(a)(1)) requires technical policies and procedures that limit ePHI access to authorized persons or software programs, such as unique user IDs, role-based access, and emergency access procedures. Option E is correct because the Audit Controls standard (45 CFR 164.312(b)) requires hardware, software, and procedural mechanisms that record and examine activity in information systems containing or using ePHI.

Option A is not a specifically mandated HIPAA requirement; vulnerability scanning supports risk analysis but HIPAA does not prescribe it as a standalone required measure. Option C is likewise not required by HIPAA, which mandates risk analysis and periodic evaluation rather than an annual external penetration test.

Exam trap

200-201 often tests the confusion between HIPAA's actual named requirements and generic best practices like annual pen testing or vulnerability scanning, which are not explicitly mandated by the Security Rule.

4
MCQhard

During a security audit, an analyst finds that a third-party vendor has access to sensitive customer data beyond what is necessary for their services. Which principle of least privilege should the policy enforce?

A.Implement an incident response plan for data leaks
B.Update the end-user license agreement
C.Enforce a data classification and access control policy
D.Invoke a service-level agreement
AnswerC

Enforcing data classification with access control directly limits vendor permissions to only the sensitivity level their service requires, satisfying the least-privilege constraint. Classification tags data, and access control policies grant rights based on those tags, so vendors cannot reach sensitive customer data beyond their defined scope.

Why this answer

The principle of least privilege requires that users and third parties have only the minimum access necessary to perform their function. Enforcing a data classification and access control policy ensures sensitive customer data is categorized and that vendor access is restricted based on that classification, directly addressing excessive access.

Exam trap

200-201 often tests whether candidates confuse preventive controls (access control policies) with reactive ones (incident response) — the trap is picking the incident response plan when the question asks how to enforce least privilege.

How to eliminate wrong answers

Option A is wrong because an incident response plan addresses what to do after a breach, not how to prevent excessive access in the first place. Option B is wrong because updating the end-user license agreement is a legal/contractual action that does not technically restrict access to data. Option D is wrong because invoking a service-level agreement is a contractual remedy for performance issues, not an access control mechanism.

5
MCQeasy

An analyst detects HTTPS traffic to a domain that was registered only 24 hours ago and has no web content. The traffic occurs at odd hours and with consistent packet sizes. What technique is likely being used for C2?

A.DNS tunneling
B.HTTPS beaconing to a malicious domain
C.HTTP POST exfiltration
D.Domain Generation Algorithm (DGA)
AnswerB

HTTPS to a suspicious domain is common C2.

Why this answer

Attackers often use newly registered domains (DGAs or manually registered) for C2 to avoid blacklists. HTTPS provides encryption to hide the beaconing.

6
Multi-Selectmedium

A SOC analyst is investigating a suspected network intrusion and reviews NetFlow records. The analyst observes a sudden increase in outbound traffic from a single internal host to an external IP address, with large data volumes during off-hours. Which two additional indicators should the analyst examine to confirm data exfiltration? (Choose two.)

Select 2 answers
A.The duration and consistency of the outbound flow to the external IP
B.The number of distinct destination ports contacted by the internal host
C.The number of failed login attempts on the internal host
D.The ratio of outbound bytes to inbound bytes for the host
E.The presence of repeated DNS queries to known benign domains
AnswersA, D

Sustained, consistent outbound flows to the same external IP over an extended period suggest an automated transfer of data. Combined with large volumes during off-hours, this pattern supports exfiltration rather than normal user activity. Analyzing flow duration and consistency helps distinguish a deliberate data transfer from sporadic or interactive traffic.

Why this answer

To confirm exfiltration from flow records, the analyst should look at the outbound-to-inbound byte ratio and the duration and consistency of the outbound flow. A high ratio and a sustained, consistent transfer to the same external IP, especially during off-hours, strongly support data exfiltration. Port counts, benign DNS queries, and failed logins are less directly related to confirming outbound data theft.

Exam trap

The trap here is focusing on port-based or authentication indicators instead of the volume and directionality of data, which are the key flow characteristics for confirming exfiltration.

7
MCQmedium

An IDS/IPS alert shows a signature named 'ET POLICY Outgoing HTTP Request with Suspicious User-Agent' with severity high. What is the most likely next step for an analyst?

A.Immediately block the source IP on the firewall
B.Reset the IDS/IPS signature database
C.Investigate the source IP and user-agent for malicious activity
D.Ignore the alert as it is not a critical signature
AnswerC

The signature flags an unusual User-Agent in outbound HTTP, which may indicate malware beaconing or command-and-control traffic. Correlating the source IP with the User-Agent string confirms whether the host is compromised, satisfying the need to validate the alert before escalation.

Why this answer

The 'ET POLICY Outgoing HTTP Request with Suspicious User-Agent' signature indicates a policy violation, not necessarily a confirmed attack. An analyst must first investigate the source IP and user-agent to determine if the traffic is malicious (e.g., command-and-control communication, data exfiltration) or benign (e.g., a legitimate application using a non-standard user-agent). Immediate blocking (Option A) could disrupt legitimate services, while ignoring the alert (Option D) risks missing a real threat.

Exam trap

Cisco often tests the distinction between 'policy' and 'exploit' signatures, where candidates mistakenly treat a policy violation as an immediate threat and jump to blocking, rather than following the proper incident response process of investigation first.

How to eliminate wrong answers

Option A is wrong because immediately blocking the source IP on the firewall is an overly aggressive response without confirming malicious activity; it could cause a denial of service for legitimate users and violates the principle of 'verify before blocking'. Option B is wrong because resetting the IDS/IPS signature database does not address the alert; it would remove all signatures, including legitimate ones, and is not a standard troubleshooting step for a single alert. Option D is wrong because ignoring the alert is negligent; even though it is a policy-based signature, it may indicate reconnaissance, scanning, or malware activity that requires investigation.

8
MCQhard

An organization wants to ensure that data sent over the internet cannot be read if intercepted. Which cryptographic method should be used?

A.Digital signature using RSA
B.Hash-based message authentication code (HMAC)
C.Symmetric encryption with AES
D.Hashing with SHA-256
AnswerC

AES is a symmetric block cipher whose confidentiality guarantee renders intercepted ciphertext unreadable without the shared key, satisfying the stem's interception constraint. Symmetric encryption suits bulk data protection, whereas asymmetric algorithms are typically reserved for key exchange and digital signatures.

Why this answer

Symmetric encryption with AES transforms plaintext into ciphertext using a shared secret key, so an attacker who intercepts the data over the internet cannot read it without the key. AES is the standard, NIST-approved symmetric cipher (FIPS 197) used in TLS, VPNs, and disk encryption. This directly satisfies the requirement that intercepted data cannot be read.

Exam trap

The trap is that candidates equate 'cryptographic method' with 'security' and pick hashing or HMAC because they sound protective, forgetting that only encryption provides confidentiality — hashing and signing do not hide data.

How to eliminate wrong answers

Option A is wrong because a digital signature using RSA provides authenticity, integrity, and non-repudiation — it proves who sent the data and that it was not altered, but it does not hide the content, which remains readable. Option B is wrong because HMAC provides integrity and authenticity via a shared key and hash, but it does not encrypt the message; the plaintext is still exposed. Option D is wrong because SHA-256 is a one-way hash function used for integrity checks; it does not provide confidentiality and cannot be reversed to recover the original data.

9
MCQeasy

A security analyst is monitoring network traffic and notices a large number of TCP SYN packets being sent to a single host on various ports. Which type of attack is most likely occurring?

A.Man-in-the-middle
B.ARP spoofing
C.DNS amplification
D.Port scan
AnswerD

A port scan sends TCP SYN packets to many ports on one host, seeking open services; the half-open responses distinguish it from a SYN flood, which targets a single port. This matches the stem's multiple-ports-to-one-host pattern.

Why this answer

A port scan involves sending packets to multiple ports on a target to discover open ports. The description matches a TCP SYN scan.

10
MCQmedium

A security analyst is analyzing a PCAP file in Wireshark and wants to isolate all HTTPS traffic. Which display filter should the analyst use?

A.tcp.dstport == 443
B.https
C.tcp.port == 443
D.port 443
AnswerC

Filtering on `tcp.port == 443` matches packets where either source or destination TCP port is 443, isolating HTTPS flows regardless of direction. This satisfies the analyst's requirement to display all HTTPS traffic in the PCAP, since HTTPS conventionally runs over TCP port 443.

Why this answer

The display filter `tcp.port == 443` in Wireshark captures all TCP traffic where either the source or destination port is 443, which is the default port for HTTPS. HTTPS traffic is HTTP over TLS/SSL, encapsulated in TCP, so filtering on port 443 effectively isolates all HTTPS sessions. This filter is symmetric, meaning it includes both client-to-server and server-to-client packets, ensuring complete visibility of the HTTPS conversation.

Exam trap

Cisco often tests the distinction between capture filters and display filters, and the trap here is that candidates confuse the simpler capture filter syntax (`port 443`) with the required display filter syntax (`tcp.port == 443`), leading them to choose Option D.

How to eliminate wrong answers

Option A is wrong because `tcp.dstport == 443` only filters packets where the destination port is 443, missing packets where the source port is 443 (e.g., server responses). Option B is wrong because `https` is not a valid Wireshark display filter; Wireshark does not have a built-in protocol name filter for HTTPS since it is encrypted and not directly dissectable as a separate protocol. Option D is wrong because `port 443` is a capture filter syntax (used in tcpdump or Wireshark's capture filter field), not a display filter; display filters require a different syntax (e.g., `tcp.port == 443`).

11
Multi-Selecthard

A security analyst is reviewing a recent security incident where an attacker gained unauthorized access to a server. The analyst needs to determine which factors contributed to the incident by examining the vulnerability, threat, and risk. Which TWO of the following best describe the relationship between these concepts in this scenario? (Choose two.)

Select 2 answers
A.Risk is the same as vulnerability and can be used interchangeably.
B.A vulnerability is a weakness in the server's software that the attacker exploited.
C.Risk is the potential for loss or damage when a threat exploits a vulnerability.
D.A threat is the potential cause of an incident that exploits a vulnerability.
E.A threat is always a deliberate attack by a human actor.
AnswersB, D

A vulnerability is a flaw or weakness in a system that can be exploited to violate security. In this scenario, the attacker gained access by exploiting a weakness, such as an unpatched service or misconfiguration. This definition correctly describes the role of a vulnerability in the incident.

Why this answer

A vulnerability is a weakness that can be exploited, and a threat is the potential cause that exploits it. Together, they create risk, which is the potential for loss. The correct options define vulnerability and threat accurately in the context of the incident, while the others either misdefine terms or are too narrow.

Exam trap

The trap here is equating risk with vulnerability or assuming all threats are human attackers, which oversimplifies the risk formula and ignores natural or accidental threats.

12
MCQmedium

A company's security policy requires that all servers have host-based intrusion detection (HIDS) installed and configured to send alerts to the SIEM. During a routine check, you find that a critical database server has HIDS installed but is not sending alerts because the agent service is stopped. The server administrator says he stopped the service because it was using too much CPU. The policy requires that any deviation from baseline must be approved by the security team. What should you do?

A.Restart the service on the server and submit a change request for CPU optimization.
B.Accept the server administrator's justification and document it.
C.Recommend setting the HIDS process priority to low to reduce CPU impact.
D.Report the non-compliance to the security manager and disable the server until compliance is restored.
AnswerA

Restarting the HIDS agent restores the mandated monitoring baseline, ensuring alerts reach the SIEM, while the change request documents the CPU deviation for security approval. This satisfies the policy requiring approved deviations without leaving the critical database server unmonitored.

Why this answer

The security policy requires HIDS to be running and sending alerts to the SIEM. The server administrator stopped the service without approval, which is a policy violation. The correct action is to restore compliance by restarting the service and then submit a change request for CPU optimization if needed.

This ensures the security baseline is met while addressing the administrator's concern through proper channels.

Exam trap

The trap is choosing the seemingly pragmatic option (B or C) that addresses the administrator's concern but ignores the policy requirement for approval; candidates must prioritize compliance and proper change control.

How to eliminate wrong answers

Option B is wrong because accepting the administrator's justification without security team approval violates the policy; deviations must be approved. Option C is wrong because setting the process priority to low might reduce CPU impact but does not address the immediate non-compliance and still requires approval; it also may not be sufficient. Option D is wrong because disabling the server is an overreaction and not required by policy; the policy requires restoring compliance, not taking the server offline.

13
Multi-Selecthard

A SOC analyst is tuning a SIEM correlation rule to detect port scanning. The rule should generate an alert when a single source IP connects to many different destination ports on multiple hosts within a short time. Which THREE conditions should be included in the rule?

Select 3 answers
A.Count of unique destination IPs > threshold
B.Destination port is well-known
C.Single source IP
D.Average packet count per connection is high (e.g., >100)
E.Count of unique destination ports > threshold
AnswersA, C, E

Counting unique destination IPs above a threshold captures the horizontal spread of a scan, where one source probes many hosts. Combined with port and time-window conditions, it satisfies the stem's requirement to detect scanning across multiple hosts rather than a single target.

Why this answer

Option A is correct because a port scan is characterized by one source touching many distinct targets, so counting unique destination IPs above a threshold captures the horizontal spread across multiple hosts required by the rule. Option C is correct because the scenario specifies a single source IP, and grouping or filtering on that single source is what ties the many connections together as one scanning event rather than unrelated traffic. Option E is correct because counting unique destination ports above a threshold detects the vertical sweep of many ports, which is the defining signature of port scanning.

Option B is not required because scans can target any port range, not just well-known ports, so restricting to well-known ports would miss scans of high or ephemeral ports. Option D is not appropriate because port scans typically involve small, often single-packet connections, so a high average packet count per connection would indicate data transfer or a different behavior, not scanning.

14
MCQhard

In Zeek (Bro), which log file would an analyst examine to identify HTTP methods, URIs, and response codes from web traffic?

A.files.log
B.dns.log
C.conn.log
D.http.log
AnswerD

The http.log records HTTP transactions, capturing request methods, URIs, host headers, response status codes and user agents. This directly satisfies the stem's requirement to identify HTTP methods, URIs and response codes from web traffic, whereas conn.log, dns.log and ssl.log lack application-layer HTTP detail.

Why this answer

Zeek's http.log contains detailed HTTP transaction information including methods, URIs, and status codes.

15
MCQmedium

Which of the following is a common indicator of DNS tunneling used for exfiltration?

A.DNS queries with long subdomain strings
B.Frequent DNS queries to known domains
C.DNS responses with large payloads
D.DNS queries using TCP instead of UDP
AnswerA

DNS tunnelling encodes stolen data into subdomain labels, so queries carrying long, high-entropy subdomain strings that exceed normal hostname lengths are a hallmark indicator. This satisfies the stem's requirement for a common exfiltration indicator, since legitimate DNS lookups rarely use such extended labels.

Why this answer

DNS tunneling exploits the DNS protocol to encapsulate non-DNS data within DNS queries and responses. A common indicator is DNS queries with unusually long subdomain strings, as attackers encode exfiltrated data into the query name to bypass network security controls.

Exam trap

Cisco often tests the distinction between a general anomaly (like large DNS responses) and a specific tunneling indicator (long subdomain strings), where candidates mistakenly focus on response size or protocol choice rather than the query structure.

How to eliminate wrong answers

Option B is wrong because frequent DNS queries to known domains are typical of legitimate client behavior (e.g., CDN lookups) and not a specific sign of tunneling. Option C is wrong because while DNS responses can carry large payloads in tunneling, the primary indicator is the query side; moreover, standard DNS responses are limited to 512 bytes (or up to 4096 bytes with EDNS0), so large responses alone are not definitive. Option D is wrong because DNS queries normally use UDP, but tunneling can use TCP for reliability; however, TCP usage is not a common indicator because many legitimate operations (e.g., zone transfers) also use TCP.

16
MCQhard

A security analyst is examining a Windows 10 host and suspects that an attacker has established persistence using a scheduled task. The analyst runs 'schtasks /query /fo LIST /v' and observes a task named 'WindowsUpdateCheck' with the action 'C:\Users\Public\update.exe' and a trigger set to run every 5 minutes. Which of the following best describes the attacker's technique?

A.The attacker is using a WMI event subscription to maintain persistence and execute a malicious binary at regular intervals.
B.The attacker is using a registry Run key to maintain persistence and execute a malicious binary at regular intervals.
C.The attacker is using a scheduled task to maintain persistence and execute a malicious binary at regular intervals.
D.The attacker is using a service to maintain persistence and execute a malicious binary at regular intervals.
AnswerC

Scheduled tasks are a common persistence mechanism. The task name 'WindowsUpdateCheck' mimics a legitimate update check, but the action points to a binary in C:\Users\Public, which is an unusual location for a legitimate update executable. The frequent trigger (every 5 minutes) ensures the malware runs regularly, maintaining persistence and possibly beaconing to a command-and-control server.

Why this answer

Scheduled tasks are frequently abused by attackers to establish persistence. The task name 'WindowsUpdateCheck' is designed to look benign, but the executable path in C:\Users\Public and the 5-minute interval are suspicious. Attackers use such tasks to ensure their malware runs regularly, even after reboots.

Analysts should investigate the binary and the task's origin.

Exam trap

The trap here is assuming that a task with a legitimate-sounding name is safe, but the executable path and frequency are key indicators of malicious intent.

17
MCQhard

An analyst is investigating a potential data exfiltration via DNS. In Zeek DNS logs, the analyst sees many queries for subdomains like 'a1b2c3.malicious.com', 'd4e5f6.malicious.com' etc. from an internal host. Which technique is likely being used?

A.DNS cache poisoning
B.DNS amplification
C.DNS tunneling
D.DNS zone transfer
AnswerC

DNS tunneling uses subdomains to encode data.

Why this answer

The repeated pattern of unique, seemingly random subdomains (e.g., 'a1b2c3.malicious.com') from a single internal host is a classic indicator of DNS tunneling. This technique encodes exfiltrated data into DNS query subdomains, leveraging the fact that DNS traffic is often allowed through firewalls. The malicious server decodes the subdomain strings to reconstruct the stolen data.

Exam trap

Cisco often tests the distinction between DNS tunneling (data exfiltration) and DNS amplification (DDoS), where candidates mistakenly associate any unusual DNS pattern with a volumetric attack rather than a covert channel.

How to eliminate wrong answers

Option A is wrong because DNS cache poisoning (spoofing) corrupts a resolver's cache with forged records to redirect traffic, not to exfiltrate data via subdomain queries. Option B is wrong because DNS amplification is a reflection-based DDoS attack that uses open resolvers to flood a victim with large responses, not a data exfiltration method. Option D is wrong because a DNS zone transfer is a legitimate mechanism for replicating DNS records between authoritative servers, not a technique for encoding data in subdomain queries.

18
Multi-Selecteasy

Which TWO pieces of information are essential for an analyst to correlate when investigating an intrusion alert from a network-based sensor?

Select 2 answers
A.The color of the network cables
B.Source and destination IP addresses
C.The brand of the sensor
D.Timestamp of the alert
E.The name of the security team lead
AnswersB, D

Source and destination IP addresses identify the communicating hosts, letting the analyst map the alert to specific endpoints and pivot to their logs. This correlation satisfies the stem's requirement to trace the intrusion's origin and target across network telemetry.

Why this answer

Option B (Source and destination IP addresses) is correct because correlating the source and destination IPs lets the analyst identify the communicating hosts, pivot to related logs (firewall, NetFlow, IDS/IPS), and determine whether the traffic is internal-to-external, external-to-internal, or lateral movement. Option D (Timestamp of the alert) is correct because the timestamp enables time-based correlation across disparate data sources, which is essential for reconstructing the sequence of events and aligning the sensor alert with firewall, proxy, and endpoint logs. The unmarked options do not belong: cable color (A) and sensor brand (C) are irrelevant physical/vendor details that do not help correlate events, and the security team lead's name (E) is an administrative fact, not investigative data.

Exam trap

Cisco often tests the distinction between operational data (IP addresses, timestamps) and irrelevant administrative or physical details, trapping candidates who confuse 'essential for correlation' with 'nice to have' or 'commonly known' information.

19
Multi-Selecteasy

Which TWO of the following are best practices for configuring syslog in a secure monitoring environment? (Choose two.)

Select 2 answers
A.Use UDP as the transport protocol to ensure reliable delivery
B.Set log files to overwrite daily
C.Configure a maximum log file size to prevent disk exhaustion
D.Change the default syslog port to avoid detection by attackers
E.Send syslog messages to a centralized log server over a dedicated management network
AnswersC, E

Capping the maximum log file size enforces a hard ceiling on local disk consumption, satisfying the requirement to prevent disk exhaustion. Without this limit, verbose or looping syslog sources can fill the volume, causing the logging daemon to fail and creating a monitoring blind spot.

Why this answer

Option C is correct because configuring a maximum log file size (via log rotation parameters such as maxsize in rsyslog or size in logrotate) prevents a single log file from consuming all available disk space, which would otherwise cause a denial of service on the logging host. Option E is correct because forwarding syslog messages to a centralized log server over a dedicated management network isolates log traffic from user and production traffic, protects log integrity, and ensures logs survive a compromise of the source host. Option A is wrong because UDP is connectionless and unreliable; syslog over UDP can silently drop messages, so TCP or TLS (e.g., rsyslog's omfwd with TLS) is preferred for reliable, secure delivery.

Option B is wrong because overwriting log files daily destroys audit evidence and breaks retention and forensic requirements; logs should be rotated and archived, not simply overwritten. Option D is wrong because security by obscurity is not a best practice, and changing the default syslog port (514/udp, 514/tcp) can break interoperability with standard collectors without providing real protection.

Exam trap

Cisco often tests the misconception that changing default ports or using UDP provides security, when in fact these practices do not address real threats like interception or data loss.

20
MCQmedium

A security analyst is analyzing a suspicious PE file. Using a hex editor, the analyst sees the ASCII string 'MZ' at the beginning. What does this indicate?

A.The file is a plain text file
B.The file is a Windows Portable Executable
C.The file is a Linux ELF binary
D.The file is a PDF document
AnswerB

The ASCII characters 'MZ' (0x4D5A) form the DOS header magic number that every Windows Portable Executable begins with, as defined by the PE format specification. Its presence at offset zero identifies the file as a Windows PE binary rather than a script or document.

Why this answer

The ASCII string 'MZ' at the beginning of a file is the DOS MZ header signature, which identifies the file as a Windows Portable Executable (PE) or a DOS executable. 'MZ' stands for Mark Zbikowski, the Microsoft engineer who designed the format. This signature is the first two bytes of every PE file and is used by Windows loaders to recognize executable images.

Exam trap

200-201 often tests magic-number recognition, and candidates confuse 'MZ' (Windows PE/DOS) with 'ELF' (Linux) or 'PDF' signatures — the key is memorizing the exact byte sequences for each file type.

How to eliminate wrong answers

Option A is wrong because plain text files do not have a mandatory binary signature — they contain readable characters throughout, not a specific 'MZ' magic number. Option C is wrong because Linux ELF binaries begin with the magic bytes 0x7F 0x45 0x4C 0x46 (which spell '\x7fELF'), not 'MZ'. Option D is wrong because PDF documents begin with the signature '%PDF-' (hex 25 50 44 46 2D), not 'MZ'.

21
MCQhard

You are a senior analyst in a SOC that monitors a large financial institution. The SIEM correlates events from firewalls, IDS, endpoints, and database servers. Over the past week, you have noticed multiple low-priority alerts from the IDS indicating 'ET SCAN NMAP -sS' scans from internal IP 10.0.0.50, which is a print server. The alerts occur at random times during business hours. The number of alerts has increased from 5 per day to 20 per day. The print server runs a standard OS and printer management software. No other alerts are triggered from that host. The firewall logs show outbound connections from the print server to IPs on the internet on port 443, which is abnormal for a print server. You check the printer management software and see no recent updates. The user of the print server, the IT administrator, reports no issues. What is your best course of action?

A.Increase the alert threshold to reduce noise and continue monitoring
B.Disable the printer service on the server and monitor for recurrence
C.Dismiss the alerts as false positives because print servers often perform network discovery
D.Isolate the print server from the network and conduct a forensic investigation
AnswerD

Internal scanning from a print server, escalating alert volume, and abnormal outbound port 443 connections indicate compromise. Isolating the host preserves volatile evidence while halting exfiltration or lateral movement, and forensic investigation establishes scope and root cause before remediation or restoration.

Why this answer

The print server at 10.0.0.50 is exhibiting multiple indicators of compromise: it is performing NMAP SYN scans (ET SCAN NMAP -sS) from an internal IP, and firewall logs show abnormal outbound HTTPS connections to internet IPs on port 443. These behaviors are inconsistent with a standard print server's role and suggest the host may be compromised, possibly acting as a pivot point for reconnaissance or command-and-control communication. Isolating the host and conducting a forensic investigation is the appropriate incident response step to contain the threat and determine the root cause before it can cause further damage.

Exam trap

Cisco often tests the candidate's ability to recognize that a combination of seemingly low-severity alerts (NMAP scans) and abnormal outbound traffic on a non-web server indicates a compromise, rather than dismissing them as false positives or tuning them out.

How to eliminate wrong answers

Option A is wrong because increasing the alert threshold would ignore potentially malicious activity, allowing a compromised host to continue scanning and exfiltrating data. Option B is wrong because disabling the printer service does not address the underlying compromise; the attacker could still use other services or persistence mechanisms on the server. Option C is wrong because print servers do not normally perform NMAP SYN scans or make outbound HTTPS connections to arbitrary internet IPs; dismissing these as false positives ignores clear signs of anomalous behavior.

22
MCQeasy

An analyst is examining a syslog message from a Cisco ASA showing: %ASA-4-106023: Deny udp src outside:192.0.2.1/123 dst inside:10.0.0.5/123. Which type of traffic is being denied?

A.HTTP traffic
B.SNMP traffic
C.NTP traffic
D.DNS traffic
AnswerC

Both source and destination ports are 123, the well-known port for Network Time Protocol. The ASA deny message therefore identifies NTP traffic, not DNS, SNMP or syslog, which use ports 53, 161 and 514 respectively.

Why this answer

The syslog message %ASA-4-106023 shows a UDP deny from source 192.0.2.1 port 123 to destination 10.0.0.5 port 123. Port 123 is the well-known port for Network Time Protocol (NTP), which is used for clock synchronization. Therefore, the denied traffic is NTP traffic.

Exam trap

The trap here is that candidates may confuse port 123 with other common UDP services like DNS (port 53) or SNMP (ports 161/162), or assume the '123' is a random number rather than a standard port assignment.

How to eliminate wrong answers

Option A is wrong because HTTP traffic uses TCP port 80 or 8080, not UDP port 123. Option B is wrong because SNMP traffic uses UDP ports 161 (queries) and 162 (traps), not port 123. Option D is wrong because DNS traffic uses UDP port 53 (or TCP for zone transfers), not port 123.

23
MCQmedium

A SOC analyst is reviewing a packet capture from an internal web server and notices that a single external IP sent 4,000 TCP segments with the ACK flag set to a closed port, and each segment received a RST response. No SYN packets preceded these segments. Which type of scan is this host most likely performing?

A.UDP port sweep
B.TCP ACK scan
C.TCP SYN stealth scan
D.TCP FIN scan
AnswerB

An ACK scan sends packets with only the ACK flag set to map firewall rule sets and determine whether ports are filtered or unfiltered. Because the target responds with RST to both open and closed ports, the scanner learns filtering behavior rather than port state. The absence of a preceding SYN and the flood of ACK segments to a closed port match this technique exactly.

Why this answer

The scanner sent only ACK-flagged TCP segments to a closed port and received RST replies, which is the signature of an ACK scan used to probe firewall filtering rather than open services. A SYN scan would require an initial SYN, a FIN scan would use the FIN flag, and a UDP sweep would not produce TCP RST responses. The pattern uniquely identifies an ACK scan.

Exam trap

The trap here is assuming any scan that receives RST responses is a SYN scan, when the flag combination and absence of a handshake determine the actual scan type.

24
MCQhard

A SOC Tier 2 analyst is investigating an alert that was escalated by Tier 1. The analyst needs to perform deeper correlation and malware analysis. Which of the following actions is most appropriate for Tier 2?

A.Analyze the malware sample in a sandbox and correlate with other indicators.
B.Conduct threat hunting to proactively search for threats.
C.Develop new detection rules for the SIEM.
D.Perform initial triage and basic investigation.
AnswerA

Sandbox detonation executes the sample in an isolated environment, revealing runtime behaviour such as command-and-control callbacks, dropped files and registry persistence that static inspection misses. Correlating those artefacts with other indicators satisfies the Tier 2 requirement for deeper malware analysis and cross-event correlation, exceeding Tier 1 triage scope.

Why this answer

Tier 2 analysts are responsible for deeper investigation, including malware analysis and correlating indicators across multiple data sources. Analyzing a malware sample in a sandbox allows safe execution and observation of behavior, while correlation with other indicators (e.g., IOCs from other alerts) helps determine scope and impact. This aligns with the escalation from Tier 1, which typically handles initial triage.

Options B and C are more advanced or proactive tasks often handled by Tier 3 or threat hunting teams, and D is a Tier 1 responsibility.

Exam trap

The trap here is confusing the responsibilities of different SOC tiers, particularly assuming that proactive tasks like threat hunting or detection engineering are part of Tier 2's reactive investigation role.

How to eliminate wrong answers

Option B is wrong because threat hunting is a proactive activity typically performed by Tier 3 or dedicated threat hunting teams, not a reactive escalation task for Tier 2. Option C is wrong because developing new detection rules is a engineering or Tier 3 responsibility, not part of the immediate investigation of an escalated alert. Option D is wrong because initial triage and basic investigation are Tier 1 duties, and the scenario explicitly states the alert was escalated to Tier 2, meaning Tier 1 has already completed those steps.

25
Multi-Selecthard

Which TWO of the following are valid reasons to use a proxy server for security monitoring? (Choose two.)

Select 2 answers
A.To reduce network latency for monitored traffic
B.To provide a complete log of all network traffic for forensics
C.To inspect encrypted traffic by acting as a man-in-the-middle with SSL decryption
D.To enforce outbound access policies and block connections to known malicious destinations
E.To replace the need for endpoint anti-malware software
AnswersC, D

SSL interception lets the proxy terminate the client's TLS session, decrypt the payload, inspect it, then re-encrypt toward the destination. This satisfies the stem's monitoring requirement by exposing threats hidden inside HTTPS, which passive network capture cannot read. Microsoft Entra ID conditional access is unaffected, as the proxy sits inline on the traffic path.

Why this answer

Option C is correct because a proxy can terminate TLS connections and perform SSL/TLS inspection (SSL decryption or break-and-inspect), decrypting traffic so it can be examined for malicious content before re-encrypting it to the destination. Option D is correct because a forward proxy sits inline on outbound traffic and can enforce access-control policies, URL/domain filtering, and block connections to known malicious destinations via threat-intelligence feeds. Option A is not a security-monitoring reason and proxies typically add latency rather than reduce it.

Option B is inaccurate because a proxy only logs traffic that is routed through it, not all network traffic, so it cannot provide a complete forensic record. Option E is wrong because a proxy does not replace endpoint anti-malware; host-based protection is still required for local threats.

Exam trap

200-201 often tests the capabilities and limitations of proxy servers; candidates may think proxies reduce latency or replace endpoint security, but they actually add latency and are not a substitute for anti-malware.

26
MCQmedium

During an incident, a SOC Tier 1 analyst identifies a series of failed login attempts from an internal IP address. The analyst escalates the alert. What is the primary role of a Tier 2 analyst in this scenario?

A.Monitor alerts and perform initial triage
B.Make decisions on business impact and notification
C.Conduct threat hunting and advanced forensics
D.Perform deeper investigation and correlate events
AnswerD

Tier 2 analysts handle escalated alerts requiring deeper forensic analysis, correlating the failed logins with other telemetry to determine scope and intent. This satisfies the scenario's need to validate whether the internal IP indicates compromise rather than routine user error.

Why this answer

Tier 2 analysts take escalated alerts from Tier 1 and perform deeper investigation, correlating events across multiple log sources, endpoints, and network telemetry to determine scope and root cause. In this scenario, the failed login attempts from an internal IP require correlation with authentication logs, endpoint activity, and threat intelligence — exactly the Tier 2 function.

Exam trap

200-201 often tests role boundaries in the SOC — the trap is selecting 'threat hunting' or 'business impact decisions' for Tier 2 when those belong to Tier 3 or management, while the correct answer is the narrower 'deeper investigation and correlation.'

How to eliminate wrong answers

Option A is wrong because monitoring alerts and initial triage is the Tier 1 responsibility, not Tier 2. Option B is wrong because decisions on business impact and stakeholder notification are typically made by incident response management or Tier 3/leadership, not the Tier 2 analyst's primary role. Option C is wrong because proactive threat hunting and advanced forensics are generally Tier 3 or dedicated threat-hunting team activities, beyond the reactive escalation scope of Tier 2.

27
MCQeasy

Which Windows registry hive contains user-specific configuration settings that can be modified by applications?

A.HKEY_CLASSES_ROOT
B.HKEY_LOCAL_MACHINE
C.HKEY_CURRENT_USER
D.HKEY_USERS
AnswerC

HKEY_CURRENT_USER stores the per-user profile configuration, including application settings, mapped drives and desktop preferences, loaded from the user's NTUSER.DAT file at sign-in. It satisfies the stem's requirement for user-specific settings that applications can modify, unlike machine-wide hives such as HKEY_LOCAL_MACHINE.

Why this answer

HKEY_CURRENT_USER (HKCU) is the correct answer because it stores user-specific configuration settings, such as desktop preferences, environment variables, and application settings, that are loaded from the NTUSER.DAT file when a user logs in. Applications modify this hive to persist per-user customizations, making it the primary location for user-level registry changes.

Exam trap

The trap here is that candidates confuse HKEY_CURRENT_USER with HKEY_LOCAL_MACHINE, assuming all configuration settings are system-wide, but Cisco tests the distinction that per-user application settings are stored in HKCU, not HKLM.

How to eliminate wrong answers

Option A is wrong because HKEY_CLASSES_ROOT (HKCR) stores file association and COM class registration data, not user-specific application settings. Option B is wrong because HKEY_LOCAL_MACHINE (HKLM) contains system-wide configuration settings that apply to all users and require administrative privileges to modify, not per-user settings. Option D is wrong because HKEY_USERS (HKU) contains all loaded user hives on the system, but applications typically write to the current user's hive via HKCU, which is a symbolic link to the specific user's subkey under HKU; direct modification of HKU is uncommon for application settings.

28
MCQhard

A security auditor reviews the SNMP configuration. Which security concern should be reported?

A.The location and contact information is exposed
B.SNMP is disabled on the router
C.The community strings are set to default values
D.The private community string is read-only
AnswerC

Default community strings such as "public" and "private" are effectively shared passwords sent in cleartext by SNMPv1 and SNMPv2c, so any host on the management network can read or alter device data. This directly satisfies the auditor's concern about weak SNMP authentication, unlike SNMPv3, which provides hashing and encryption.

Why this answer

Default SNMP community strings (e.g., 'public' for read-only, 'private' for read-write) are well-known and widely documented. An attacker who discovers these defaults can query or modify the device's MIB, leading to information disclosure or unauthorized configuration changes. This is a critical security concern that must be reported.

Exam trap

Cisco often tests the distinction between the existence of a default community string (a critical vulnerability) versus the access level (read-only vs. read-write) or the exposure of non-sensitive MIB objects like sysLocation.

How to eliminate wrong answers

Option A is wrong because exposing location and contact information is a low-severity information disclosure issue, not the primary security concern when default community strings are in use. Option B is wrong because disabling SNMP is actually a security best practice, not a security concern. Option D is wrong because a read-only private community string is actually more secure than a read-write one; the problem is that the string itself is set to a default value, not its access level.

29
Multi-Selecthard

Which TWO network behaviors suggest an ARP spoofing attack is occurring? (Choose two.)

Select 2 answers
A.A high number of TCP RST packets
B.A single host sending numerous ARP requests
C.Packets originating from a MAC address that does not match the IP's legitimate MAC
D.An increase in broadcast ARP traffic
E.Multiple IP addresses mapping to the same MAC address
AnswersC, E

Gratuitous ARP replies mapping one IP to an attacker-controlled MAC create frames whose source MAC contradicts the IP's legitimate binding, so hosts overwrite their ARP cache and route traffic to the attacker. This directly satisfies the stem's requirement for a network behaviour indicating ARP spoofing, since the forged MAC-to-IP pairing is the defining signature.

Why this answer

Option C is correct because in ARP spoofing the attacker sends forged ARP replies that bind its own MAC address to a victim's IP address, so traffic for that IP arrives from a MAC that does not match the legitimate owner's MAC. Option E is correct because a classic ARP poisoning signature is multiple IP addresses (for example, the gateway and another host) resolving to the same attacker MAC address, indicating the attacker is impersonating several hosts. Option A is not specific to ARP spoofing, since TCP RST floods indicate session teardown or DoS activity rather than ARP cache manipulation.

Option B is not a reliable indicator, as a single host sending many ARP requests is normal behavior during address resolution or scanning. Option D is also weak, because increased broadcast ARP traffic can result from legitimate network growth, misconfiguration, or scanning and does not by itself prove spoofing.

Exam trap

Cisco often tests the distinction between normal ARP traffic (e.g., broadcasts for resolution) and malicious ARP behavior (e.g., multiple IPs on one MAC or MAC-IP mismatches), so candidates mistakenly choose high ARP volume or TCP RSTs as spoofing indicators.

30
MCQmedium

A security analyst observes repeated failed login attempts from a single external IP address, causing the authentication server to become unresponsive. Which type of attack is occurring?

A.Denial of Service
B.Reconnaissance
C.Brute force attack
D.Man-in-the-middle
AnswerA

Flooding authentication with repeated failed logins from one external IP exhausts server resources until it stops responding, which is the defining effect of a Denial of Service attack. The stem's unresponsive authentication server confirms availability, not confidentiality, is the target.

Why this answer

The scenario describes repeated failed login attempts from a single external IP that render the authentication server unresponsive — this is a Denial of Service (DoS) condition, where the volume of authentication requests exhausts server resources (CPU, connection table, lock contention) and denies service to legitimate users. The defining symptom is availability loss, not credential compromise or information gathering. A brute force attack would aim to guess credentials, but here the observed outcome is service unavailability.

Exam trap

200-201 often tests the confusion between brute force and DoS when both involve failed logins — the discriminator is the attacker's objective: credential compromise (brute force) versus service unavailability (DoS).

How to eliminate wrong answers

Option B is wrong because reconnaissance involves scanning and enumeration to gather information (e.g., port scans, banner grabbing) without necessarily causing resource exhaustion or service outage. Option C is wrong because a brute force attack's objective is to successfully authenticate by trying many password combinations; while it generates failed logins, the question's emphasis on the server becoming unresponsive indicates the attack's effect is denial of service, not credential guessing. Option D is wrong because a man-in-the-middle attack requires the adversary to intercept and relay traffic between two parties, which is not described by a flood of failed logins from a single IP.

31
MCQeasy

Which SOC tier is responsible for threat hunting and advanced forensic analysis?

A.Tier 1
B.Tier 3
C.All tiers equally
D.Tier 2
AnswerB

Tier 3 analysts handle proactive threat hunting and deep forensic investigation, the highest analytical escalation level. Tier 1 performs triage and monitoring, Tier 2 handles incident response escalation; advanced forensics and hunting sit with Tier 3, matching the responsibilities named in the question.

Why this answer

Tier 3 SOC analysts are the most senior and are responsible for advanced threat hunting, malware reverse engineering, and deep forensic analysis. Tier 1 handles initial triage and alert monitoring, while Tier 2 performs deeper investigation and incident response. Threat hunting and forensics are explicitly Tier 3 responsibilities in the standard SOC tier model.

Exam trap

The trap here is confusing Tier 2's incident response duties with Tier 3's proactive threat hunting and forensic analysis — candidates often pick Tier 2 because it sounds 'advanced' enough.

How to eliminate wrong answers

Option A is wrong because Tier 1 analysts perform initial alert triage, ticket creation, and basic escalation — they do not conduct threat hunting or forensic analysis. Option C is wrong because responsibilities are not shared equally across tiers; the tiered model exists precisely to distribute escalating skill levels and duties. Option D is wrong because Tier 2 handles incident investigation and response but stops short of the advanced hunting and forensic deep dives reserved for Tier 3.

32
Drag & Dropmedium

Drag and drop the steps to configure a VLAN on a Cisco switch into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct sequence for VLAN configuration on a Cisco switch is to first enter global configuration mode with 'configure terminal', then create the VLAN using 'vlan vlan-id', which places you in VLAN configuration mode. Next, assign a name with 'name vlan-name', and finally exit VLAN config mode and configure interfaces to belong to the VLAN using 'switchport access vlan vlan-id'. This order ensures the VLAN exists and has a meaningful identifier before ports are assigned.

33
MCQhard

Based on the exhibit, what does the sequence of events indicate?

A.The wmiprvse.exe process is known to spawn svchost.exe for system health checks.
B.A process masquerading as svchost.exe was spawned by wmiprvse.exe (likely via WMI), and then that malicious process launched calc.exe, a suspicious behavior.
C.The user is executing a macro that opens Calculator.
D.A legitimate system process (wmiprvse.exe) launched a service host, which then launched calc.exe for maintenance.
AnswerB

The parent-child sequence shows wmiprvse.exe spawning a process named svchost.exe, which is anomalous because the genuine svchost.exe is launched by services.exe. That masquerading process then spawning calc.exe confirms malicious WMI-based execution rather than legitimate system activity.

Why this answer

The exhibit shows wmiprvse.exe (the WMI Provider Host) spawning svchost.exe, which then launches calc.exe. In normal operations, wmiprvse.exe does not spawn svchost.exe; svchost.exe is a generic host process for Windows services and is typically launched by services.exe. The sequence indicates process masquerading: an attacker used WMI to execute a malicious binary named svchost.exe, which then launched calc.exe as a suspicious payload.

This is a classic indicator of lateral movement or privilege escalation via WMI.

Exam trap

Cisco often tests the misconception that svchost.exe is always legitimate and that wmiprvse.exe only spawns itself or system processes, when in fact attackers can use WMI to launch arbitrary executables with a misleading name.

How to eliminate wrong answers

Option A is wrong because wmiprvse.exe does not spawn svchost.exe for system health checks; svchost.exe is started by services.exe, and WMI does not initiate such a process for health monitoring. Option C is wrong because the exhibit shows a process chain (wmiprvse.exe → svchost.exe → calc.exe), not a user directly executing a macro; macros typically run within an Office application, not via WMI and svchost.exe. Option D is wrong because a legitimate system process (wmiprvse.exe) does not launch svchost.exe for maintenance; svchost.exe is a service host, not a maintenance tool, and calc.exe is not a standard maintenance binary.

34
MCQeasy

Which organization facilitates threat intelligence sharing among members in a specific sector, such as finance or healthcare?

A.MISP
B.ISAC
C.STIX
D.TAXII
AnswerB

ISACs are sector-specific non-profit organisations that collect, analyse and share threat intelligence among members within industries such as finance or healthcare. They satisfy the stem's requirement for a sector-focused sharing body, unlike cross-sector or government-led alternatives.

Why this answer

ISACs (Information Sharing and Analysis Centers) are sector-specific organizations that facilitate threat intelligence sharing among members in industries such as finance (FS-ISAC), healthcare (H-ISAC), and aviation. They provide a trusted forum for members to exchange threat data, best practices, and incident information relevant to their sector.

Exam trap

200-201 often tests the confusion between threat intelligence sharing organizations (ISACs) and the standards/platforms used to share intelligence (STIX, TAXII, MISP), tricking candidates into selecting a technology instead of an organization.

How to eliminate wrong answers

Option A is wrong because MISP (Malware Information Sharing Platform) is an open-source threat intelligence platform for storing and sharing indicators, not an organization that facilitates sector-specific sharing. Option C is wrong because STIX (Structured Threat Information Expression) is a standardized language for representing threat intelligence, not an organization. Option D is wrong because TAXII (Trusted Automated Exchange of Intelligence Information) is a protocol for transporting threat intelligence over HTTPS, not an organization.

35
MCQhard

A Cisco Firepower appliance generates an intrusion specific event with the message 'MALWARE-CNC generic command and control traffic detected'. The analyst needs to determine if the alert is a true positive. Which additional data source would provide the most corroborating evidence?

A.Application control logs
B.URL filtering logs
C.NetFlow records
D.DNS query logs
AnswerD

Command-and-control traffic typically relies on domain resolution, so DNS query logs reveal whether the host contacted the malicious domain named in the alert. Correlating those lookups with the Firepower event confirms or refutes the true positive.

Why this answer

DNS query logs are the most corroborating evidence because malware command-and-control (C2) traffic often relies on DNS to resolve the IP address of the C2 server. A sudden spike in NXDOMAIN responses, queries to algorithmically generated domains (DGA), or requests to known malicious domains in the DNS logs would directly confirm the C2 activity. This aligns with the 'MALWARE-CNC' signature, which specifically targets C2 communication patterns.

Exam trap

Cisco often tests the misconception that NetFlow or URL filtering logs are sufficient for C2 detection, but the key is that DNS logs reveal the domain resolution step that is almost always part of C2 communication, making them the most direct corroborating source.

How to eliminate wrong answers

Option A is wrong because application control logs identify which applications (e.g., HTTP, FTP) are in use but do not reveal the destination domain or IP of C2 traffic, making them insufficient for corroborating C2-specific alerts. Option B is wrong because URL filtering logs show only HTTP/HTTPS requests with full URLs, but C2 traffic often uses non-standard ports or protocols (e.g., DNS tunneling, IRC) that bypass URL filtering entirely. Option C is wrong because NetFlow records provide IP addresses, ports, and byte counts but lack the domain name resolution data needed to confirm C2 domain lookups; they cannot distinguish between a legitimate DNS query and a DGA-based query without additional context.

36
MCQmedium

An attacker uses a tool to capture keystrokes on a compromised system. What type of malware is most likely in use?

A.Spyware
B.Rootkit
C.Ransomware
D.Keylogger
AnswerD

A keylogger is malware that records every keystroke typed on a compromised host, typically storing or transmitting them to the attacker. Capturing keystrokes is its sole defining capability, so it matches the described tool exactly.

Why this answer

A keylogger is a type of malware specifically designed to capture and record keystrokes on a compromised system. The question directly describes the behavior of capturing keystrokes, which is the primary function of a keylogger, making it the most likely malware in use.

Exam trap

Cisco often tests the distinction between a general category (spyware) and a specific type (keylogger), so the trap here is that candidates may choose spyware because it is a broader term, but the question asks for the most likely malware based on the specific behavior described.

How to eliminate wrong answers

Option A is wrong because spyware is a broader category of malware that focuses on collecting information about a user's activities, such as browsing habits or login credentials, but it does not specifically specialize in capturing keystrokes; a keylogger is a subset of spyware, but the question asks for the most likely type, and keylogger is more precise. Option B is wrong because a rootkit is designed to hide the presence of other malware or provide persistent, stealthy access to a system by modifying operating system kernel or system calls, not to capture keystrokes directly. Option C is wrong because ransomware is malware that encrypts files or locks the system to demand a ransom, and it does not typically include keystroke capture as its primary function.

37
MCQmedium

A security analyst is reviewing logs and notices that an attacker has intercepted and modified communications between two devices on the same network. Which attack technique is being used?

A.Reconnaissance
B.ARP spoofing
C.Man-in-the-Middle
D.DNS poisoning
AnswerC

Man-in-the-Middle attacks satisfy the on-path interception constraint: the adversary inserts themselves between two communicating devices, relaying and altering traffic without either party detecting it. Unlike passive sniffing, which only copies packets, MitM actively modifies data in transit, matching the stem's intercepted and modified communications.

Why this answer

A man-in-the-middle attack is when an attacker intercepts and modifies communications between two parties who believe they are talking directly to each other. The scenario describes interception and modification of traffic between two devices on the same network, which is the defining behavior of a MITM attack. ARP spoofing is often the technique used to enable MITM on a LAN, but the attack technique described is MITM itself.

Exam trap

The trap is that ARP spoofing is the enabling mechanism for a LAN MITM, so candidates pick the technique rather than the attack category the question is asking about.

How to eliminate wrong answers

Option A is wrong because reconnaissance is information gathering (scanning, enumeration) and does not involve intercepting or modifying communications. Option B is wrong because ARP spoofing is a specific Layer 2 technique that poisons ARP caches to redirect traffic; it is a means to an end, not the general attack technique described, and the question asks for the technique being used. Option D is wrong because DNS poisoning corrupts DNS responses to redirect users to malicious sites; it does not describe interception and modification of an ongoing communication between two devices.

38
Multi-Selectmedium

An analyst is examining a Linux system for signs of an attacker establishing persistence. Which TWO of the following locations should the analyst check? (Choose two.)

Select 2 answers
A./etc/passwd
B./proc/self/status
C./etc/systemd/system/
D./etc/crontab
E./home/user/.bash_history
AnswersC, D

Correct. Systemd services can be used for persistence.

Why this answer

Option C, /etc/systemd/system/, is correct because attackers commonly drop malicious .service unit files there to establish persistence via systemd, causing their payload to execute at boot or on a trigger. Option D, /etc/crontab, is correct because scheduled tasks in this file (and related cron directories) are a classic persistence mechanism, allowing an attacker to re-execute code at defined intervals. Option A, /etc/passwd, is not the best choice here since it stores user account information rather than a direct persistence trigger, though it can be abused to add accounts.

Option B, /proc/self/status, is a runtime process status file and does not provide a persistence location. Option E, /home/user/.bash_history, is useful for forensic reconstruction of past commands but is not itself a persistence mechanism.

Exam trap

200-201 often tests persistence locations, and candidates confuse forensic artifacts (like .bash_history) with actual persistence mechanisms — the key is identifying locations that cause automatic code execution across reboots or schedules.

39
MCQmedium

A security manager is developing a business continuity plan (BCP) for a critical e-commerce application. The application has a recovery time objective (RTO) of 4 hours and a recovery point objective (RPO) of 15 minutes. The manager must choose a backup strategy that meets these objectives. Which strategy is most appropriate?

A.Weekly incremental backups to a warm site with manual failover.
B.Continuous data replication to a hot site with automated failover.
C.Daily differential backups to a cold site with tape restoration.
D.Nightly full backups stored offsite with manual restore.
AnswerB

Continuous replication keeps the recovery site synchronized with minimal data loss, meeting the 15-minute RPO. A hot site with automated failover can bring the application online within the 4-hour RTO. This strategy provides the highest availability and is suitable for critical e-commerce. It aligns with both objectives by minimizing downtime and data loss.

Why this answer

The RTO of 4 hours requires recovery within that time, and the RPO of 15 minutes requires minimal data loss. Continuous replication to a hot site with automated failover can achieve both by keeping data synchronized and enabling rapid switchover. Other strategies like nightly, weekly, or daily backups introduce too much data loss and longer recovery times, failing to meet the objectives.

Exam trap

The trap here is selecting a backup strategy based on cost or simplicity without checking whether it satisfies both the RTO and RPO, especially the 15-minute RPO which requires near-real-time replication.

40
MCQhard

An analyst is configuring a Snort rule to detect a known exploit targeting Apache web servers. The exploit sends a malicious HTTP POST request with a long User-Agent string. Which Snort rule header and options are most appropriate?

A.alert icmp any any -> any 80 (content:"POST"; pcre:"/User-Agent:.{200,}/R"; sid:1000001;)
B.alert tcp any any -> any 443 (content:"POST"; pcre:"/User-Agent:.{200,}/R"; sid:1000001;)
C.alert tcp any any -> any 80 (content:"POST"; pcre:"/User-Agent:.{200,}/R"; sid:1000001;)
D.alert udp any any -> any 80 (content:"GET"; pcre:"/User-Agent:.{200,}/R"; sid:1000001;)
AnswerC

The rule alerts on TCP port 80, matching the HTTP POST, and the pcre option detects a User-Agent exceeding 200 characters, which is the exploit's signature. The content match on POST plus the regex satisfies the requirement to detect this Apache-targeting request.

Why this answer

The rule must alert on TCP traffic to port 80 because HTTP POST requests use TCP, and Apache web servers typically listen on port 80 for unencrypted HTTP. The content match for 'POST' and the PCRE regex looking for a User-Agent string of 200 or more characters correctly targets the described exploit. This combination of protocol, port, and payload inspection is the most appropriate Snort rule.

Exam trap

The trap is that candidates focus on the payload content ('POST', User-Agent regex) and overlook the protocol and port in the rule header — a rule with the right content but wrong protocol (ICMP/UDP) or wrong port (443) will never fire on the actual exploit traffic.

How to eliminate wrong answers

Option A is wrong because it uses the `icmp` protocol, but HTTP POST requests are TCP-based, so the rule would never match the exploit traffic. Option B is wrong because it targets port 443 (HTTPS), where traffic is TLS-encrypted and Snort cannot inspect the plaintext HTTP payload without SSL inspection configured. Option D is wrong because it uses UDP (HTTP is TCP) and matches 'GET' instead of 'POST', so it would miss the malicious POST request entirely.

41
Multi-Selecthard

An analyst is triaging a suspected FTP brute-force campaign against an internal server. The IDS reports many failed authentication attempts from a single external address. Which TWO data points, gathered from the FTP server and network logs, most directly support confirming and characterizing the attack? (Choose two.)

Select 2 answers
A.The average size of files previously transferred by legitimate users of the FTP service.
B.Count of distinct usernames attempted and the number of failed 530 responses per source IP over time.
C.The server's TLS certificate expiration date for FTPS connections.
D.The server's operating system patch level for the FTP daemon.
E.Timestamps of successful logins from the same source IP immediately following the failures.
AnswersB, E

Tracking distinct usernames alongside failed authentication response codes per source IP reveals whether the source is spraying many accounts or hammering one, and the rate over time distinguishes brute force from occasional user error. This directly characterizes the campaign's scope and supports blocking or rate-limiting decisions. It is the core evidence that confirms the activity is systematic rather than incidental.

Why this answer

Confirming and characterizing an FTP brute-force campaign depends on authentication telemetry: the number of distinct usernames and failed response codes per source IP shows the attack's shape and rate, while a successful login from the same source after repeated failures confirms compromise. Certificate expiry, historical transfer sizes, and daemon patch level describe configuration or baseline behavior and cannot establish whether the attack occurred or succeeded.

Exam trap

The trap here is selecting configuration or baseline metrics such as patch level or average file size, which feel relevant to server security but do not actually confirm or measure the authentication attack.

42
MCQhard

An analyst is examining a Windows 10 host and discovers that a service named 'WinDefendSvc' is registered with a binary path of C:\ProgramData\svchost.exe and a display name of 'Windows Defender Service'. The legitimate Windows Defender service uses a different name and binary path. Which conclusion is most accurate?

A.The service is a leftover from a Windows Update that failed to clean up and can be safely ignored, since the binary is named svchost.exe.
B.This is a benign third-party antivirus service that has registered itself under a Microsoft-like name to be trusted by the operating system.
C.This is a legitimate alternate Windows Defender service name used on some Windows 10 builds and should be verified with Get-Service before further action.
D.This indicates a masquerading attempt, because the service name mimics Windows Defender while its binary is placed in a user-writable directory, which is typical of malware persistence.
AnswerD

C:\ProgramData is writable by standard users, unlike system directories, making it a common staging ground for malicious binaries. The service name 'WinDefendSvc' closely mimics the legitimate 'WinDefend' to evade casual inspection. Combined with the non-standard binary path, this is a classic masquerading persistence technique. The analyst should treat it as malicious and investigate the binary and its network behavior.

Why this answer

Legitimate Windows Defender registers as the WinDefend service with its binary under C:\Program Files\Windows Defender. A service named WinDefendSvc pointing to C:\ProgramData\svchost.exe combines two red flags: a typosquatted name impersonating a security product and a binary in a user-writable directory. This pattern is characteristic of masquerading persistence, and the analyst should investigate the binary, its signature, and its network activity rather than dismissing it as legitimate.

Exam trap

The trap here is trusting a service because its name resembles a known Microsoft component, without verifying the actual binary path and digital signature.

43
MCQhard

A security analyst is examining a PCAP and observes a TCP stream where the client sends a single packet with the PSH, ACK flags set, and the server responds with a single packet with the RST, ACK flags set. The client then sends no further packets. What is the most likely explanation for this behavior?

A.The client is performing a TCP port scan using a half-open scan.
B.The server is terminating the connection abruptly, possibly due to an application error or security policy.
C.The network is experiencing packet loss, causing the server to reset the connection.
D.The server rejected the connection attempt because the destination port is closed.
AnswerB

A PSH, ACK from the client indicates it is sending data to the server. The server's RST, ACK response means it is abruptly resetting the connection, which can occur if the application encounters an error, the server is enforcing a security policy (e.g., IPS blocking), or the service is misconfigured. The client then stops sending, consistent with a reset. This is the most likely explanation for the observed flags.

Why this answer

The sequence of a client sending a PSH, ACK (data) followed by a server RST, ACK indicates that the server is abruptly terminating the connection. This can happen due to application errors, security policies, or misconfigurations. The client then ceases communication, which is typical after a reset.

Other explanations like closed port, port scan, or packet loss do not align with the observed flags.

Exam trap

The trap here is assuming a RST always means a closed port, but in this case the connection was already established, so the RST indicates an abrupt termination after data was sent.

44
MCQeasy

Refer to the exhibit. What does this syslog message indicate?

A.Failed telnet attempt
B.Denied SSH connection attempt
C.Successful SSH connection
D.Allowed TCP traffic
AnswerB

The syslog message records that the firewall or access control denied an inbound SSH connection attempt, meaning TCP port 22 traffic was blocked. It reflects a rejected connection rather than a successful login or an established session.

Why this answer

The syslog message '%SEC_LOGIN-4-LOGIN_FAILED: Login failed [user: admin] [Source: 10.1.1.1] [localport: 22]' indicates a failed login attempt on port 22, which is the default port for SSH. Since the message explicitly shows 'localport: 22' and the login failed, it corresponds to a denied SSH connection attempt, not a successful one or a Telnet attempt (which uses port 23).

Exam trap

The trap here is that candidates may confuse the 'Login failed' message with a generic 'denied' message, but Cisco specifically tests the ability to identify the protocol by the port number (22 for SSH vs. 23 for Telnet) in the syslog output.

How to eliminate wrong answers

Option A is wrong because the syslog message shows 'localport: 22', which is the default port for SSH, not Telnet (port 23); a failed Telnet attempt would reference port 23. Option C is wrong because the message explicitly states 'Login failed', indicating the connection was denied, not successful. Option D is wrong because the message indicates a failed login, not allowed TCP traffic; allowed traffic would generate a different syslog message (e.g., 'LOGIN_SUCCESS' or an ACL permit log).

45
MCQeasy

Refer to the exhibit. What type of activity does this log represent?

A.Man-in-the-middle attack.
B.Denial-of-service (DoS) attack.
C.Brute force SSH attack.
D.Port scan.
AnswerC

The log shows repeated failed authentication attempts against the SSH service from a single source within a short interval, which is the signature of automated credential guessing. Successful login following many failures confirms a brute force SSH attack rather than normal administrative access.

Why this answer

The log shows repeated SSH connection attempts with 'Failed password' messages from the same source IP (10.10.0.5) to the same destination IP (10.10.0.3) for user 'admin'. This pattern of multiple failed authentication attempts in a short time window is characteristic of a brute force SSH attack, where an attacker systematically tries different passwords to gain unauthorized access.

Exam trap

Cisco often tests the distinction between a brute force attack (repeated authentication attempts) and a port scan (probing multiple ports), so the trap here is that candidates see multiple connection attempts and mistakenly think it is a port scan rather than recognizing the SSH-specific 'Failed password' messages.

How to eliminate wrong answers

Option A is wrong because a man-in-the-middle attack would involve intercepting or altering communications between two parties, not repeated failed login attempts. Option B is wrong because a denial-of-service attack aims to overwhelm a service with traffic to make it unavailable, whereas this log shows targeted authentication failures without evidence of resource exhaustion. Option D is wrong because a port scan typically involves sending packets to multiple ports to discover open services, not repeated login attempts to a single service (SSH on port 22).

46
MCQeasy

A security analyst is investigating an alert that indicates a potential SQL injection attack. Which of the following HTTP request patterns is most indicative of a SQL injection attempt?

A.GET /login?user=admin&pass=password123
B.GET /search?q=<script>alert('XSS')</script>
C.GET /products?id=1 UNION SELECT * FROM users
D.GET /index.html HTTP/1.1
AnswerC

The UNION SELECT payload is injected directly into the id parameter, attempting to append rows from the users table to the query result. This satisfies the SQL injection indicator, unlike plain numeric values or encoded characters that carry no SQL syntax.

Why this answer

The UNION SELECT payload is the classic SQL injection signature: it appends a second SELECT statement to the original query, allowing the attacker to retrieve data from other tables such as 'users'. The presence of SQL keywords (UNION, SELECT, FROM) inside a URL parameter that should only contain a numeric ID is a strong indicator of SQLi. This pattern targets the backend database directly, unlike script tags which target the browser.

Exam trap

The trap here is confusing SQL injection with XSS — both inject code into input fields, but SQLi targets the database with SQL syntax while XSS targets the browser with script tags; candidates who see '<script>' often reflexively pick it.

How to eliminate wrong answers

Option A is wrong because it is a normal login request with plaintext credentials in the query string — suspicious for using GET, but not an injection pattern. Option B is wrong because '<script>alert('XSS')</script>' is a cross-site scripting (XSS) payload, not SQL injection; it targets the client browser, not the database. Option D is wrong because it is a benign static file request for index.html with no parameters and no injection vector.

47
MCQhard

A security analyst observes a sudden spike in outbound traffic from a critical server to an external IP address on TCP port 443. The server is a web application server that normally only receives inbound connections. Which type of intrusion is most likely occurring?

A.Distributed denial-of-service (DDoS) attack from the server
B.Brute-force attack on the server's SSH service
C.SQL injection attack against the server
D.Command-and-control (C2) communication from malware on the server
AnswerD

Outbound TCP 443 from a server that normally only receives inbound connections indicates beaconing to an external controller. Malware establishes command-and-control channels over HTTPS to blend with legitimate traffic, matching the observed spike and the server's atypical outbound behaviour.

Why this answer

A sudden spike in outbound traffic from a server that normally only receives inbound connections is a classic indicator of command-and-control (C2) communication. Malware on the server often establishes outbound HTTPS (TCP 443) connections to a C2 server to exfiltrate data or receive instructions, bypassing firewalls that typically allow outbound web traffic.

Exam trap

Cisco often tests the distinction between inbound attack types (like SQL injection or brute-force) and outbound indicators of compromise (like C2 traffic), leading candidates to confuse the direction of the traffic with the attack vector.

How to eliminate wrong answers

Option A is wrong because a DDoS attack from the server would involve sending a high volume of traffic to a target, but the question describes a spike to a single external IP, not a distributed flood, and the server is not typically used as an attack source. Option B is wrong because a brute-force attack on SSH would target TCP port 22, not 443, and would generate inbound traffic, not outbound spikes. Option C is wrong because an SQL injection attack is an inbound web application attack that manipulates database queries, not a cause of outbound traffic spikes to an external IP on port 443.

48
MCQeasy

Which protocol and port pair is commonly used for secure web traffic?

A.HTTPS 443
B.FTP 21
C.HTTP 80
D.SSH 22
AnswerA

HTTPS uses TLS over TCP port 443 to encrypt web traffic, satisfying the stem's requirement for a secure web protocol and port pair. Plain HTTP on port 80 provides no transport encryption, so 443 is the standard secure alternative.

Why this answer

HTTPS (HTTP Secure) uses port 443 for encrypted web traffic.

49
MCQhard

When analyzing a suspicious PE file, the analyst calculates the file's entropy and finds it to be 7.8. What does a high entropy value typically indicate, and why is it relevant to malware analysis?

A.The file is likely packed or encrypted to evade signature-based detection.
B.The file contains no executable code.
C.The file is likely a legitimate application with high compression.
D.The file's imports are all standard Windows DLLs.
AnswerA

Entropy near 7.8 approaches the theoretical maximum of 8, indicating compressed or encrypted data rather than readable code. Packers and crypters use this to obscure payloads, defeating signature-based detection. This satisfies the stem's requirement to explain what high entropy indicates and its malware-analysis relevance.

Why this answer

A high entropy value (close to 8.0) indicates that the data within the file is highly random, which is a strong sign of packing or encryption. Malware authors use packers to obfuscate the original executable code, making it harder for signature-based detection engines to identify known malicious patterns. In malware analysis, entropy is a quick heuristic to flag files that may be hiding their true content.

Exam trap

Cisco often tests the misconception that high entropy always means the file is malicious, when in fact it only indicates obfuscation or packing—legitimate files can also be packed (e.g., some installers), so entropy must be combined with other indicators like suspicious imports or network signatures.

How to eliminate wrong answers

Option B is wrong because a file with high entropy can still contain executable code that is simply obfuscated; the entropy value does not indicate the absence of code. Option C is wrong because legitimate applications rarely achieve entropy values near 7.8 through compression alone—standard compression algorithms like ZIP or LZMA produce entropy values around 6.5–7.0, not 7.8, and such high entropy is more characteristic of encryption or strong packing. Option D is wrong because the entropy calculation is based on the byte distribution of the entire file, not on the import table; a file with standard Windows DLL imports could still have high entropy if its code section is packed.

50
MCQhard

A security analyst is investigating a Windows host for signs of fileless malware. The analyst runs a memory analysis tool and observes a process named 'powershell.exe' with a parent process of 'winword.exe'. The command line includes '-enc' followed by a long base64 string. Which technique is most likely being used by the attacker?

A.Malicious macro execution
B.Process hollowing
C.DLL injection
D.Scheduled task persistence
AnswerA

The parent process winword.exe spawning powershell.exe with an encoded command is a classic sign of a malicious Microsoft Word macro. Attackers use macros to execute PowerShell commands that download or run payloads, often encoding the command to evade detection. The '-enc' parameter indicates base64-encoded script, a common obfuscation method in macro-based attacks, making this the most likely technique.

Why this answer

The scenario describes winword.exe spawning powershell.exe with an encoded command, a hallmark of malicious macro execution. Attackers embed macros in Word documents that execute PowerShell to download or run payloads, often using base64 encoding to hide the script. Other techniques like DLL injection, process hollowing, or scheduled tasks do not match the observed parent-child relationship and command-line pattern, making macro execution the most likely.

Exam trap

The trap here is assuming that any PowerShell with encoded command is fileless malware, without considering the parent process, which in this case strongly indicates macro execution.

51
MCQhard

You are a security analyst for a financial institution. Over the past hour, the intrusion detection system has generated multiple alerts for outbound traffic from a single internal host (10.0.0.50) to various external IP addresses on port 443. The alerts indicate that the host is making HTTPS connections to IPs that are associated with known command and control servers. Additionally, the host has been observed making DNS queries for domains that are algorithmically generated (e.g., rgj3k2.example.com, fh7d8s.example.net). The host is a Windows 10 workstation used by an employee in the accounting department. The employee reports that they have not noticed any unusual behavior, but they did click on a link in a phishing email yesterday. The network administrator confirms that the host's firewall rules allow outbound HTTPS traffic. You have access to endpoint logs, network flow data, and packet captures. Which course of action should you take FIRST?

A.Isolate the host from the network to prevent further C2 communication
B.Analyze packet captures to determine the full extent of the compromise
C.Block all outbound HTTPS traffic from the network
D.Reimage the host immediately to remove the malware
AnswerA

Isolating the host immediately halts active command-and-control communication, containing the confirmed compromise before lateral movement or data theft occurs. Forensic preservation and remediation follow afterwards, but severing the C2 channel is the urgent first action given the algorithmic DNS and known malicious destinations.

Why this answer

The immediate priority when confirmed C2 communication is detected is to contain the threat by isolating the host from the network. The combination of outbound HTTPS connections to known C2 servers and algorithmically generated domain (AGD) DNS queries strongly indicates active malware infection. Isolating the host (e.g., via network access control or switch port shutdown) stops data exfiltration and further command reception, which is the first step in incident response containment before any analysis or remediation.

Exam trap

Cisco often tests the incident response priority order, and the trap here is that candidates choose analysis (Option B) or remediation (Option D) first, forgetting that containment (Option A) is the immediate required step per NIST SP 800-61 and Cisco's own incident handling framework.

How to eliminate wrong answers

Option B is wrong because analyzing packet captures to determine the full extent of compromise is a secondary step; the first action must be containment to prevent ongoing C2 traffic and lateral movement. Option C is wrong because blocking all outbound HTTPS traffic from the network is an overly broad and disruptive measure that would break legitimate business operations, and it is not a targeted containment action. Option D is wrong because reimaging the host immediately destroys volatile evidence (e.g., memory-resident malware, active network connections) and should only be performed after forensic data collection and containment.

52
MCQhard

A security analyst is selecting a symmetric encryption algorithm for encrypting data at rest. Which of the following is a suitable symmetric algorithm?

A.AES
B.ECC
C.RSA
D.SHA-256
AnswerA

AES is the only symmetric block cipher listed, satisfying the data-at-rest requirement. It encrypts and decrypts with one shared key, unlike RSA and ECC, which are asymmetric. AES-256 offers strong resistance to brute-force attacks and is the standard choice for protecting stored data.

Why this answer

AES (Advanced Encryption Standard) is a symmetric block cipher, meaning it uses the same key for both encryption and decryption, making it suitable for encrypting data at rest. It is widely adopted, standardized by NIST, and available in 128-, 192-, and 256-bit key lengths. AES is the de facto standard for symmetric encryption in modern systems.

Exam trap

The trap is that candidates see 'SHA-256' and assume it is an encryption algorithm because it sounds cryptographic — but hashing is one-way and cannot encrypt/decrypt data, and asymmetric algorithms like RSA/ECC are often confused with symmetric ones under exam pressure.

How to eliminate wrong answers

Option B is wrong because ECC (Elliptic Curve Cryptography) is an asymmetric algorithm used for key exchange and digital signatures, not symmetric bulk encryption. Option C is wrong because RSA is also an asymmetric algorithm, typically used for key transport and signatures, and is too slow for bulk data encryption. Option D is wrong because SHA-256 is a cryptographic hash function, not an encryption algorithm — it produces a fixed-size digest and is not reversible, so it cannot be used to encrypt data at rest.

53
MCQhard

An investigator seizes a laptop as evidence from a crime scene. At the scene, the laptop is turned on and a log file is open. What should the investigator do to preserve evidence according to chain of custody procedures?

A.Close the log file and copy it to a USB drive
B.Shut down the laptop and remove the hard drive
C.Execute the log file to ensure it is legitimate
D.Photograph the screen and create a forensic image
AnswerD

This captures the current state and preserves the evidence.

Why this answer

The investigator must first document the volatile state of the evidence by photographing the screen (capturing the open log file) and then create a forensic image (bit-for-bit copy) of the entire hard drive. This preserves the original data integrity and adheres to chain of custody procedures, ensuring that the evidence is not altered and can be verified later via hash verification (e.g., MD5 or SHA-256).

Exam trap

Cisco often tests the misconception that shutting down a live system is safe, but the trap here is that volatile data (like the open log file's contents in memory) is lost and the shutdown process itself can alter the disk, making forensic imaging the only correct preservation method.

How to eliminate wrong answers

Option A is wrong because closing the log file and copying it to a USB drive modifies the file's metadata (e.g., last accessed time) and risks altering the original evidence, violating forensic best practices. Option B is wrong because shutting down the laptop can cause loss of volatile data (e.g., RAM contents, open network connections) and may trigger write operations during the shutdown process, corrupting evidence. Option C is wrong because executing the log file could modify system state, trigger malware, or alter timestamps, which compromises the integrity of the evidence and is not a standard forensic procedure.

54
MCQhard

A security team wants to adopt a framework that provides a common language for describing cyberthreats, including tactics, techniques, and procedures observed in real intrusions. Which framework should the team use to map adversary behavior?

A.ISO/IEC 27001
B.MITRE ATT&CK
C.NIST Cybersecurity Framework
D.CVSS
AnswerB

MITRE ATT&CK is a curated knowledge base of adversary tactics and techniques derived from real-world observations. It gives defenders a common vocabulary such as initial access, persistence, and credential dumping, letting teams map detections, prioritize coverage, and compare intrusions. The scenario explicitly asks for a framework that describes tactics, techniques, and procedures observed in real intrusions, which is exactly what ATT&CK provides.

Why this answer

MITRE ATT&CK is the framework that catalogs real-world adversary tactics and techniques, giving defenders a shared vocabulary for describing intrusions. Teams use it to map detections to techniques, identify coverage gaps, and communicate findings consistently. Governance standards and vulnerability scoring systems serve different purposes and do not describe adversary behavior.

Exam trap

The trap here is selecting a well-known security framework by reputation alone, when only one framework actually catalogs adversary tactics and techniques.

55
Multi-Selecthard

A security analyst is tasked with developing a data loss prevention (DLP) strategy for the organization. The strategy must align with the CyberOps Associate curriculum and address both endpoint and network-based data exfiltration. Which two actions should the analyst include in the strategy? (Choose two.)

Select 2 answers
A.Deploy network DLP solutions to inspect outbound traffic for sensitive data patterns and block unauthorized transfers.
B.Implement role-based access control (RBAC) to limit access to sensitive data.
C.Implement endpoint DLP agents to monitor and control data transfers to removable media and cloud storage.
D.Configure full-disk encryption on all endpoints to prevent data loss if a device is stolen.
E.Establish a security awareness program to educate employees about data handling policies.
AnswersA, C

Network DLP monitors data in transit across the network perimeter. It can detect and block sensitive information leaving the organization via email, web uploads, or other protocols. This complements endpoint DLP by providing a centralized enforcement point and covering devices that may not have agents installed. Together, they form a layered defense against data exfiltration, as recommended by security best practices.

Why this answer

The two actions to include are endpoint DLP and network DLP. Endpoint DLP controls data transfers at the device level, such as to USB drives or cloud services, while network DLP inspects outbound traffic for sensitive data. Together, they provide comprehensive coverage for data exfiltration across both endpoints and the network.

These technical controls directly address the requirement to monitor and prevent unauthorized data transfers, aligning with the CyberOps Associate curriculum's focus on data protection.

Exam trap

The trap here is confusing data-at-rest protection like encryption with data-in-motion controls, which are the core of DLP.

56
MCQmedium

A security analyst is investigating an alert that indicates a host is sending a large number of DNS queries to an external domain. The analyst wants to determine if the traffic is malicious and if it is using a DNS tunnel. Which type of analysis should the analyst perform to confirm the presence of a DNS tunnel?

A.Analyze the payload size and query frequency of the DNS packets to detect anomalous patterns.
B.Check the volume of DNS traffic from the host to identify any increase over baseline.
C.Examine the source IP addresses of the DNS queries to see if they originate from multiple hosts.
D.Review the firewall logs to identify any blocked DNS queries to the external domain.
AnswerA

DNS tunnelling encodes data in query names, producing abnormally large or numerous queries to one domain. Examining payload size and query frequency reveals those anomalies, confirming tunnelling rather than relying on reputation lookups or header inspection alone.

Why this answer

DNS tunneling typically involves encoding data within DNS queries or responses, resulting in abnormally large payload sizes and unusual query frequencies. By analyzing these specific packet attributes, an analyst can detect the anomalous patterns characteristic of a DNS tunnel, such as high query rates to a single domain or payloads exceeding standard DNS message sizes (e.g., >512 bytes for UDP). This direct inspection of DNS packet content is the most reliable method to confirm tunneling activity.

Exam trap

Cisco often tests the distinction between detecting a general anomaly (e.g., high traffic volume) and confirming a specific technique (e.g., DNS tunneling), where candidates mistakenly choose a broad indicator like traffic volume (Option B) instead of the packet-level analysis that directly reveals the tunneling mechanism.

How to eliminate wrong answers

Option B is wrong because simply checking the volume of DNS traffic against a baseline may indicate an anomaly but does not specifically confirm a DNS tunnel; legitimate applications (e.g., frequent updates) can also cause increased volume. Option C is wrong because examining source IP addresses to see if queries originate from multiple hosts is more relevant to identifying a distributed attack (e.g., DDoS) or a compromised network segment, not a single-host DNS tunnel. Option D is wrong because reviewing firewall logs for blocked queries only shows which queries were denied, not whether a tunnel exists; a DNS tunnel often uses allowed queries (e.g., to an external domain) and may not be blocked at all.

57
MCQmedium

What is the primary difference between symmetric and asymmetric encryption?

A.Asymmetric encryption is used only for hashing
B.Symmetric uses two keys, asymmetric uses one
C.Symmetric is slower than asymmetric
D.Symmetric uses a single shared key; asymmetric uses a key pair
AnswerD

Symmetric encryption relies on one shared secret key for both encryption and decryption, whereas asymmetric encryption uses a mathematically linked key pair: a public key to encrypt and a private key to decrypt. This directly satisfies the stem's request for the primary distinction between the two encryption schemes.

Why this answer

Symmetric encryption uses a single shared key for both encryption and decryption, while asymmetric encryption uses a key pair: a public key for encryption and a private key for decryption. This fundamental difference in key usage is the primary distinction.

Exam trap

200-201 often tests the confusion between key usage and performance characteristics, or the misconception that asymmetric encryption is used only for hashing. Candidates might also mix up which type uses one key versus two.

How to eliminate wrong answers

Option A is wrong because asymmetric encryption is not used only for hashing; hashing is a separate cryptographic operation. Asymmetric encryption is used for encryption/decryption and digital signatures. Option B is wrong because it reverses the key usage: symmetric uses one key, asymmetric uses two.

Option C is wrong because symmetric encryption is generally faster than asymmetric, but this is a performance characteristic, not the primary difference in key management.

58
Multi-Selectmedium

An analyst identifies a series of SMB authentication attempts from a compromised host to multiple internal servers. The authentication uses NTLM hashes. Which TWO techniques are most likely being used for lateral movement? (Select 2)

Select 2 answers
A.Kerberoasting
B.SMB relay
C.Brute force
D.Golden ticket
E.Pass-the-hash
AnswersB, E

Relays authentication to other hosts.

Why this answer

SMB relay (B) is correct because the attacker can intercept NTLM authentication attempts from the compromised host and relay them to other internal servers, gaining unauthorized access without needing to crack the hash. This technique leverages the SMB protocol's lack of channel binding in older implementations, allowing the relayed hash to authenticate to multiple targets.

Exam trap

Cisco often tests the distinction between 'pass-the-hash' (reusing a hash directly from the compromised host) and 'SMB relay' (forwarding the authentication challenge to another server), which candidates confuse as the same technique.

59
MCQeasy

A network administrator has configured a SPAN port to send traffic to an intrusion detection system (IDS). However, the IDS is not seeing traffic from a specific VLAN. What is the most likely cause?

A.The SPAN source does not include that VLAN.
B.The IDS interface is set to promiscuous mode.
C.The SPAN destination port is in trunk mode.
D.The IDS is in inline mode.
AnswerA

A SPAN session only mirrors traffic from the sources explicitly defined in its configuration, so a VLAN omitted from the source list is never copied to the destination port. Since the IDS receives only mirrored frames, it cannot detect traffic from that VLAN until the source is amended to include it.

Why this answer

A SPAN (Switched Port Analyzer) port copies traffic from specified source interfaces or VLANs to a destination port. If the IDS is not seeing traffic from a specific VLAN, the most likely cause is that the SPAN configuration does not include that VLAN as a source. The administrator must explicitly specify the VLAN(s) to monitor using the `monitor session` command with the `vlan` keyword; otherwise, traffic from that VLAN will not be forwarded to the IDS.

Exam trap

Cisco often tests the misconception that SPAN automatically mirrors all VLANs on a trunk port, when in fact the administrator must explicitly specify which VLANs to monitor using the `vlan` keyword in the SPAN configuration.

How to eliminate wrong answers

Option B is wrong because setting the IDS interface to promiscuous mode is a requirement for the IDS to receive all packets on a SPAN destination, not a cause of missing VLAN traffic. Option C is wrong because the SPAN destination port being in trunk mode is irrelevant; SPAN destination ports are typically access ports or configured as trunk only if needed for encapsulation, but trunk mode does not prevent traffic from a specific VLAN from being seen. Option D is wrong because if the IDS were in inline mode, it would be placed directly in the traffic path and would inherently see all VLAN traffic; the problem described is about a SPAN-based (out-of-band) deployment, so inline mode is not applicable.

60
MCQeasy

What is the primary goal of the 'integrity' pillar of the CIA triad?

A.Keep data secret from unauthorized users
B.Ensure data is accessible when needed
C.Provide proof that a user performed an action
D.Protect data from unauthorized modification
AnswerD

Integrity guarantees data remains accurate and unaltered unless changed by an authorised process, directly satisfying the stem's focus on detecting or preventing unauthorised modification. Unlike confidentiality, which restricts read access, integrity targets write and alteration operations, ensuring trustworthiness of stored and transmitted information.

Why this answer

The 'integrity' pillar of the CIA triad ensures that data is not altered or tampered with by unauthorized parties. This is achieved through mechanisms such as hashing (e.g., SHA-256), checksums, and digital signatures that detect any unauthorized modification. Option D correctly identifies this goal, as protecting data from unauthorized modification is the core purpose of integrity controls.

Exam trap

Cisco often tests the distinction between integrity and non-repudiation, as candidates may confuse 'proof of action' (non-repudiation) with 'data unchanged' (integrity), leading them to incorrectly select Option C.

How to eliminate wrong answers

Option A is wrong because keeping data secret from unauthorized users is the goal of the 'confidentiality' pillar, not integrity. Option B is wrong because ensuring data is accessible when needed is the goal of the 'availability' pillar, not integrity. Option C is wrong because providing proof that a user performed an action is the goal of 'non-repudiation', which is often associated with digital signatures and audit logs, not the integrity pillar itself.

61
MCQmedium

An IDS alert indicates that a server received HTTP requests containing long strings of the form ../../../../etc/passwd in a URL parameter. The web server returned HTTP 200 responses to these requests. Which conclusion should the analyst draw while continuing the investigation?

A.The alert is a false positive because directory traversal cannot appear in URL parameters.
B.The server is confirmed compromised because directory traversal strings were sent and accepted.
C.The requests warrant deeper inspection of response bodies and server file access logs to determine whether traversal succeeded.
D.The activity is normal because web browsers routinely send relative path characters in requests.
AnswerC

The traversal attempt is a strong indicator, but the HTTP 200 alone does not establish success. Reviewing whether the response body contained file contents, and checking web server or file system access logs for reads of sensitive paths, determines whether the attack actually worked. This evidence-driven step correctly separates an attempt from a confirmed breach and guides containment decisions.

Why this answer

A traversal attempt returning HTTP 200 is suspicious but not conclusive, because the status code reflects request handling rather than file disclosure. Confirmation requires examining response bodies for sensitive file contents and correlating with server-side file access logs. The other choices either overstate the evidence as confirmed compromise, wrongly dismiss the alert, or mischaracterize traversal strings as normal browser behavior.

Exam trap

The trap here is equating an HTTP 200 response with successful exploitation, when the status code only shows the request was processed and not that sensitive data was exposed.

62
MCQmedium

You are analyzing network traffic from a compromised host. The host is running Windows and is connected to a corporate network. The IDS generated an alert for a known malware signature matching traffic from the host to an external IP on port 443. However, you see that the traffic is encrypted and the destination IP is a cloud storage provider. The host also shows periodic DNS queries to a domain that closely resembles the cloud provider's domain but with a single character difference (typosquatting). The employee on that host reports no unusual activity. Which step should you take first to confirm the compromise?

A.Check DNS logs to see if the typosquatted domain resolved recently and correlate with the encrypted traffic timestamps.
B.Dismiss the alert as a false positive because the user reports no issues.
C.Examine the full packet capture for the encrypted session to see the payload.
D.Enable SSL/TLS decryption on the corporate firewall to inspect the encrypted traffic.
AnswerA

Correlating DNS resolution records with the encrypted session timestamps confirms whether the host actually contacted the typosquatted domain, establishing command-and-control or exfiltration infrastructure before touching the endpoint. Encrypted port 443 traffic alone cannot be inspected, so resolution evidence is the decisive first artefact.

Why this answer

Correlating DNS logs with encrypted traffic timestamps is the fastest, least intrusive way to confirm whether the host actually communicated with the typosquatted domain. If the DNS query for the lookalike domain resolved just before the encrypted session to the external IP, it strongly indicates the malware is using the typosquatted domain for command-and-control (C2) over HTTPS, bypassing simple domain-based blocklists. This step validates the alert without requiring decryption or assuming user reports are reliable.

Exam trap

Cisco often tests the misconception that encrypted traffic cannot be analyzed at all, leading candidates to choose decryption (Option D) as the first step, when in fact DNS log correlation is a non-disruptive, immediate method to confirm the compromise.

How to eliminate wrong answers

Option B is wrong because user reports are unreliable in compromise scenarios—malware often runs silently without user-visible symptoms, and dismissing the alert based on user feedback ignores the IDS signature and DNS evidence. Option C is wrong because the traffic is encrypted (TLS/SSL), so examining the full packet capture will only show encrypted payloads; without the session keys, you cannot see the plaintext content. Option D is wrong because enabling SSL/TLS decryption on the corporate firewall is a major operational change that requires policy approval, certificate deployment, and may break certificate pinning; it is not a first step and could alert the malware if it checks for interception.

63
MCQhard

A security analyst is reviewing a suspicious email reported by a user. The email appears to come from the CEO and requests an urgent wire transfer. The analyst examines the email headers and notices that the 'From' address is spoofed and the 'Reply-To' address is different from the 'From' address. The email also contains a link to a credential-harvesting page. Which type of attack is this?

A.Spear phishing
B.Business email compromise (BEC)
C.Whaling
D.Phishing
AnswerB

BEC is a sophisticated scam where attackers impersonate executives or trusted partners to trick employees into transferring funds or revealing sensitive information. The scenario describes a spoofed CEO email requesting an urgent wire transfer, which is a classic BEC attack. The mismatched Reply-To and credential-harvesting link further support this classification.

Why this answer

The email impersonates the CEO and requests an urgent wire transfer, which is the hallmark of business email compromise (BEC). BEC attacks often involve spoofed sender addresses and may include links to credential-harvesting sites. While it is a form of phishing, BEC specifically targets financial transactions and is a distinct category.

Exam trap

The trap here is labeling any fraudulent email as phishing; BEC is a specific subtype that involves impersonating executives to commit financial fraud, often without malware.

64
MCQhard

A company's security policy states that all network traffic must be inspected by an IPS. However, encrypted traffic (SSL/TLS) is bypassing inspection. The network team wants to implement SSL decryption. What is the primary policy consideration before implementing?

A.Configure the firewall to block SSL traffic that cannot be decrypted.
B.Notify all users that their traffic will be inspected.
C.Create a certificate authority to issue certificates to all internal servers.
D.Ensure that the SSL decryption device has enough CPU capacity.
E.Obtain legal approval for decryption of user traffic.
AnswerE

SSL decryption exposes otherwise private communications, so privacy law and employee-monitoring regulations typically require documented legal sign-off before deployment. Satisfying the policy's mandate for full IPS inspection depends on this authorisation, making legal approval the primary consideration ahead of technical configuration.

Why this answer

SSL/TLS decryption involves intercepting and inspecting encrypted communications, which can violate privacy laws and regulations such as GDPR, HIPAA, or the Wiretap Act. Before implementing decryption, the organization must obtain legal approval to ensure compliance with applicable laws and to define the scope of inspection, especially regarding personal or sensitive data. Without legal clearance, the company could face severe penalties, even if the technical implementation is sound.

Exam trap

Cisco often tests the distinction between policy considerations (legal, regulatory, organizational) and technical implementation steps (certificates, performance, blocking rules), leading candidates to confuse a technical prerequisite with the primary policy requirement.

How to eliminate wrong answers

Option A is wrong because blocking all SSL traffic that cannot be decrypted is a technical control, not a primary policy consideration; it addresses what to do with non-decryptable traffic after the decision to decrypt is made, but the foundational policy step is legal approval. Option B is wrong because notifying users is an operational or transparency step that should follow legal approval, but it is not the primary policy consideration; notification alone does not satisfy legal or regulatory requirements. Option C is wrong because creating a certificate authority (CA) to issue certificates to internal servers is a technical implementation step for SSL decryption (e.g., for man-in-the-middle inspection), but it does not address the policy or legal justification required before deploying such a solution.

Option D is wrong because ensuring the SSL decryption device has enough CPU capacity is a performance and capacity planning consideration, not a policy consideration; it is a technical prerequisite that comes after the policy and legal framework is established.

65
MCQeasy

A security analyst is examining a suspicious executable found on a compromised host. The analyst runs the command 'strings malware.exe' and sees the string 'cmd.exe /c net user hacker P@ssw0rd /add'. What is the most likely intent of this command?

A.Add the user 'hacker' to the local administrators group.
B.Create a new user account named 'hacker' with a specified password.
C.Modify the password of an existing user account named 'hacker'.
D.Delete the user account named 'hacker'.
AnswerB

The command 'net user hacker P@ssw0rd /add' is used to create a new local user account named 'hacker' with the password 'P@ssw0rd'. This is a common persistence technique used by attackers to maintain access to a compromised system. The '/add' switch explicitly adds the user, and the syntax matches the Windows net user command. This is the most likely intent based on the string.

Why this answer

The command 'net user hacker P@ssw0rd /add' is a classic Windows command to create a new local user account. The '/add' switch is the key indicator of account creation. This technique is often used by attackers for persistence, allowing them to regain access even if other malware is removed.

The other options describe different actions that would require different syntax or switches.

Exam trap

The trap here is confusing the 'net user' command for account creation with group membership changes, which require 'net localgroup' instead.

66
MCQeasy

Which Windows artifact stores evidence of file execution, including the path and run count, and is located in C:\Windows\Prefetch?

A.Windows Event Logs
B.Registry hives
C.Scheduled tasks
D.Prefetch files
AnswerD

Prefetch files, stored in C:\Windows\Prefetch with a .pf extension, record executable name, file path, run count and last-run timestamps. This directly satisfies the stem's requirement for an artifact evidencing file execution with path and run count.

Why this answer

Windows Prefetch files, stored in C:\Windows\Prefetch with a .pf extension, record evidence of program execution including the executable path, run count, and timestamps of recent executions. Forensic analysts use them to prove that a binary ran on a system and how many times. This directly matches the artifact described in the question.

Exam trap

200-201 often tests artifact-to-location mapping — candidates confuse Registry execution artifacts (Amcache, ShimCache) with Prefetch, forgetting that Prefetch specifically lives in C:\Windows\Prefetch and stores run counts.

How to eliminate wrong answers

Option A is wrong because Windows Event Logs (e.g., Security 4688, Sysmon 1) record process creation events but do not store run counts or live in C:\Windows\Prefetch. Option B is wrong because Registry hives (e.g., NTUSER.DAT, Amcache, ShimCache) can contain execution evidence but are not located in the Prefetch folder and do not store the same run-count data. Option C is wrong because Scheduled Tasks are persistence/automation artifacts stored in Task Scheduler, not execution-history artifacts in Prefetch.

67
MCQeasy

A Linux administrator checks authentication logs to investigate a possible brute-force attack. Which log file typically contains records of successful and failed SSH login attempts?

A./var/log/kern.log
B./var/log/auth.log
C./var/log/messages
D./var/log/syslog
AnswerB

/var/log/auth.log records PAM authentication events on Debian-based Linux systems, capturing both successful and failed SSH login attempts with source addresses and usernames. This directly satisfies the stem's requirement to investigate brute-force activity, since repeated failures from one origin become visible there.

Why this answer

On Debian/Ubuntu Linux systems, /var/log/auth.log records authentication-related events including successful and failed SSH logins, sudo usage, and PAM activity. It is the primary log file for investigating brute-force attacks against SSH. This matches the question's requirement.

Exam trap

200-201 often tests Linux log file locations across distributions — candidates pick /var/log/messages or /var/log/syslog assuming they contain auth events, forgetting that Debian/Ubuntu isolate authentication in /var/log/auth.log.

How to eliminate wrong answers

Option A is wrong because /var/log/kern.log records kernel messages (hardware, drivers, kernel panics), not authentication events. Option C is wrong because /var/log/messages is a general system log on some distributions (RHEL/CentOS) but does not specifically capture SSH authentication on Debian-based systems — auth events go to auth.log or secure. Option D is wrong because /var/log/syslog is a general system log aggregating many services; while it may contain some auth entries on certain configurations, auth.log is the canonical, dedicated file for authentication records.

68
MCQeasy

A network administrator is using Cisco ISE to monitor endpoint authentication. Which report provides details on failed authentication attempts and the reasons?

A.RADIUS Authentication Report
B.Endpoint Profiler Report
C.RADIUS Accounting Report
D.Active Session Report
AnswerA

The RADIUS Authentication Report in Cisco ISE logs each endpoint's authentication attempt, including pass/fail status and the specific failure reason (such as invalid credentials or rejected authorisation). This directly satisfies the administrator's need to monitor failed authentications and diagnose their causes.

Why this answer

The RADIUS Authentication Report in Cisco ISE specifically logs all authentication attempts, including failures, and provides detailed reasons for each failure (e.g., invalid credentials, user not found, or authorization policy mismatch). This report is the primary tool for troubleshooting failed authentications because it captures the RADIUS Access-Reject messages and the corresponding failure reasons from the ISE policy evaluation.

Exam trap

Cisco often tests the distinction between RADIUS Authentication (which captures failures and reasons) and RADIUS Accounting (which tracks session usage), leading candidates to mistakenly choose the Accounting report when asked about failed authentications.

How to eliminate wrong answers

Option B is wrong because the Endpoint Profiler Report focuses on endpoint classification and profiling (e.g., OS, device type) based on probe data, not on authentication success or failure details. Option C is wrong because the RADIUS Accounting Report tracks session start, stop, and interim updates (e.g., traffic usage, session duration), not authentication failures or their reasons. Option D is wrong because the Active Session Report shows currently active authenticated sessions, not historical failed attempts or the reasons for those failures.

69
MCQhard

During a risk assessment, a company identifies that the annualized loss expectancy (ALE) for a specific threat is $50,000. The cost to implement a mitigation control is $30,000 with an annual maintenance cost of $5,000. According to risk management principles, what is the most appropriate risk treatment option?

A.Accept the risk because the mitigation cost is higher than the ALE
B.Avoid the risk by discontinuing the activity
C.Transfer the risk by purchasing cyber insurance
D.Mitigate the risk by implementing the control
AnswerD

The control's total annual cost is $35,000, which is lower than the $50,000 ALE, so mitigation yields a positive return and reduces expected loss. This satisfies the risk management principle of selecting treatment where control cost is less than the annualised loss expectancy.

Why this answer

If the cost of mitigation ($30,000 + $5,000 = $35,000) is less than the ALE ($50,000), it is cost-effective to mitigate the risk.

70
MCQmedium

Which Wireshark filter can be used to extract the full TCP data of a specific conversation from a PCAP?

A.tcp.stream
B.tcp.port
C.http.request
D.ip.addr
AnswerA

tcp.stream isolates one complete TCP conversation by its stream index, letting you follow and export all payload bytes for that specific session. This satisfies the requirement to extract the full TCP data of a single conversation rather than filtering individual packets by port or address.

Why this answer

The `tcp.stream` filter in Wireshark isolates a single TCP conversation by its stream index, allowing analysts to follow the entire bidirectional flow of that session. Once filtered, you can right-click and select Follow > TCP Stream to extract the full payload. This is the standard method for reconstructing application-layer data from a specific conversation in a PCAP.

Exam trap

200-201 often tests the confusion between filtering by port/IP (which can match multiple conversations) and using `tcp.stream` to isolate one specific conversation.

How to eliminate wrong answers

Option B is wrong because `tcp.port` filters by port number and may match multiple unrelated conversations sharing that port, not a single specific conversation. Option C is wrong because `http.request` only shows HTTP request packets, missing responses and non-HTTP TCP data in the conversation. Option D is wrong because `ip.addr` filters by IP address and can include multiple TCP streams between the same hosts, not isolating one conversation.

71
MCQmedium

A network analyst is examining a packet capture and notices a series of TCP packets where the client sends a SYN, the server responds with SYN-ACK, and the client never sends an ACK. The client repeats this for many destination ports on the same server. Which conclusion is most accurate?

A.The client is using a legitimate application that only requires half-open connections.
B.The server is misconfigured and is dropping all incoming connections.
C.The client is performing a TCP SYN scan to discover open ports on the server.
D.The client is experiencing network congestion causing packet loss of the final ACK.
AnswerC

A SYN scan sends SYN packets and never completes the three-way handshake. The server responds with SYN-ACK for open ports, but the scanner does not send the final ACK, so no full connection is established. This half-open behavior across many ports on one server is characteristic of a port scan.

Why this answer

The pattern of SYN, SYN-ACK, and no ACK repeated across many ports is a TCP SYN scan. This technique, often called half-open scanning, allows an attacker to discover open ports without completing connections, making it harder to log on the target. It is a common reconnaissance method.

Exam trap

The trap here is interpreting the missing ACK as packet loss, when the systematic repetition across many ports indicates deliberate scanning behavior.

72
MCQeasy

An organization wants to ensure that security logs are tamper-proof and available for forensic analysis. Which logging best practice should be implemented?

A.Retain logs for only 30 days to reduce storage costs
B.Forward logs to a centralized, hardened log server with access controls
C.Encrypt logs before sending them to a remote server
D.Store logs locally on each device with read-only permissions
AnswerB

Forwarding to a centralised hardened server with strict access controls removes write and delete rights from local and potentially compromised hosts, so attackers cannot alter or destroy evidence. This satisfies the tamper-proof and forensic-availability requirements, since retention and integrity are enforced independently of the source system.

Why this answer

Forwarding logs to a centralized, hardened log server with access controls ensures tamper resistance and preserves forensic integrity. Centralization removes logs from the source device where an attacker with local access could alter or delete them, and hardening plus access controls prevents unauthorized modification. This is a core logging best practice for forensic readiness.

Exam trap

The trap is thinking encryption alone equals tamper-proofing — encryption protects confidentiality, not integrity or availability, so candidates who pick 'encrypt logs' miss the centralization and access-control requirement.

How to eliminate wrong answers

Option A is wrong because retaining logs for only 30 days is insufficient for many forensic and compliance requirements, and short retention increases the risk that evidence is lost before an investigation. Option C is wrong because encrypting logs in transit protects confidentiality but does not prevent tampering or deletion at the source or destination; encryption alone does not make logs tamper-proof. Option D is wrong because storing logs locally on each device, even read-only, leaves them vulnerable to local compromise, disk failure, and tampering by an attacker with administrative access.

73
Multi-Selecthard

An analyst is tuning Snort IDS rules and wants to reduce false positives. Which TWO rule options can be adjusted to decrease sensitivity?

Select 2 answers
A.Change the rule action from 'alert' to 'drop'
B.Add a 'suppress' rule to ignore traffic from known benign IPs
C.Change protocol from TCP to UDP
D.Increase the rule priority from low to high
E.Use the 'detection_filter' to require a certain number of matches within a time window
AnswersB, E

The suppress option tells Snort to ignore traffic matching a specified source or rule, so known benign IPs stop generating alerts. This directly reduces false positives, satisfying the stem's sensitivity-reduction goal, because trusted hosts no longer trigger signatures during routine activity.

Why this answer

Option B is correct because a 'suppress' rule in Snort tells the IDS to ignore alerts generated by a specific rule for a given source or destination IP, which directly eliminates false positives caused by known benign hosts. Option E is correct because 'detection_filter' (or its predecessor 'threshold') requires a specified number of matches within a time interval before an alert fires, raising the bar for triggering and thereby reducing sensitivity to isolated or incidental events. Option A is incorrect because changing the action from 'alert' to 'drop' alters the response mode (inline IPS behavior) rather than decreasing detection sensitivity, and it may even increase impact.

Option C is incorrect because switching the protocol from TCP to UDP changes what traffic the rule inspects, not the sensitivity threshold, and would likely miss the intended traffic. Option D is incorrect because increasing priority from low to high only affects alert ranking and does not reduce the number of false positives generated.

74
Multi-Selectmedium

An organization is implementing a security policy that requires all remote access to the corporate network to be authenticated using multi-factor authentication (MFA). Which TWO of the following are valid MFA factors?

Select 2 answers
A.IP address whitelist
B.Smart card
C.Password
D.Fingerprint scan
E.Security question
AnswersB, D

Smart card is a possession factor.

Why this answer

Smart card (Option B) is a valid MFA factor because it falls under the 'something you have' category. Multi-factor authentication requires at least two different categories from 'something you know' (e.g., password), 'something you have' (e.g., smart card, token), and 'something you are' (e.g., biometric). A smart card stores a digital certificate and private key, used for cryptographic authentication, typically requiring a PIN (knowledge factor) to unlock it, thus providing two-factor authentication when combined.

Exam trap

Cisco often tests the distinction between authentication factors and access control lists; the trap here is that candidates mistake an IP address whitelist (a security policy control) for an authentication factor, or think a security question counts as a separate factor when it is merely another form of 'something you know'.

75
MCQeasy

During a security monitoring review, an analyst notices an unusual amount of traffic on port 445. Which protocol is most likely associated with this port?

A.HTTPS
B.SMB
C.DNS
D.HTTP
AnswerB

Port 445 carries SMB (Server Message Block), Microsoft's protocol for file and printer sharing, named pipes and remote administration. Unusual volumes on 445 often indicate ransomware propagation, lateral movement or data exfiltration, making SMB the protocol to investigate.

Why this answer

Port 445 is the default port for Microsoft's implementation of the Server Message Block (SMB) protocol, used for file and printer sharing over a network. An unusual amount of traffic on this port often indicates SMB-related activity, such as legitimate file transfers or potential exploitation attempts like the EternalBlue vulnerability (MS17-010).

Exam trap

Cisco often tests the association of well-known ports with their protocols, and the trap here is that candidates may confuse port 445 with HTTPS (443) or HTTP (80) due to similar numbering, or assume DNS uses a non-standard port.

How to eliminate wrong answers

Option A is wrong because HTTPS uses port 443, not 445, and is secured with TLS/SSL for encrypted web traffic. Option C is wrong because DNS primarily uses UDP port 53 (and TCP port 53 for zone transfers), not port 445. Option D is wrong because HTTP uses port 80 by default, not port 445, and is used for unencrypted web traffic.

Page 1 of 13

Page 2