Courseiva

Cisco CyberOps Associate 200-201 (200-201) — Questions 751–825

968 questions total · 13pages · All types, answers revealed

Page 10

Page 11 of 13

Page 12
751
MCQhard

Refer to the exhibit. An analyst sees repeated denied TCP connections from the same source to the same destination web server. Which of the following actions should the analyst take first?

A.Increase the logging level to get more details.
B.Create a permit rule for the source IP to allow legitimate traffic.
C.Investigate the source IP for malicious activity.
D.Block the source IP globally.
AnswerC

Repeated denied TCP connections from one source to one web server suggest scanning or brute-force activity. Investigating the source IP establishes whether it is an internal compromised host or external attacker, guiding the appropriate containment response.

Why this answer

Repeated denied TCP connections from the same source to the same destination web server are a classic indicator of a potential reconnaissance or attack pattern, such as a port scan or brute-force attempt. The first priority in security monitoring is to investigate the source IP for malicious activity (Option C) to determine intent and scope before taking any irreversible action. This aligns with the incident response process of identification and analysis before containment or eradication.

Exam trap

Cisco often tests the candidate's understanding of the incident response order of operations, where the trap is to jump to a containment action (like blocking or permitting) without first performing analysis and validation of the threat.

How to eliminate wrong answers

Option A is wrong because increasing the logging level may provide more detail but does not address the immediate need to determine if the source IP is malicious; it delays the investigative step and could overwhelm the analyst with noise. Option B is wrong because creating a permit rule for the source IP would allow all traffic from that IP, which could enable an attacker to bypass security controls if the source is indeed malicious; this action should only be taken after confirming the source is legitimate. Option D is wrong because blocking the source IP globally is a premature containment action that could disrupt legitimate business operations if the source is a false positive; it should only be performed after investigation confirms malicious intent.

752
MCQeasy

A security policy mandates that all employees complete annual security awareness training. Which of the following metrics best demonstrates the effectiveness of this training?

A.Results of a post-training quiz
B.Percentage of employees who completed the training
C.Number of help desk tickets related to phishing
D.Decrease in security incidents attributed to user error
AnswerD

A reduction in incidents caused by user error directly measures behavioural change resulting from training, unlike completion rates which only show attendance. This metric satisfies the effectiveness requirement by evidencing that awareness translated into fewer risky actions.

Why this answer

A decrease in security incidents attributed to user error directly measures the behavioral outcome of the training. Effective security awareness training should reduce the frequency of incidents caused by human mistakes, such as clicking malicious links or mishandling data. This metric reflects the ultimate goal of the training, not just participation or short-term knowledge retention.

Exam trap

Cisco often tests the distinction between 'compliance metrics' (e.g., completion rates) and 'effectiveness metrics' (e.g., incident reduction), trapping candidates who confuse activity with outcome.

How to eliminate wrong answers

Option A is wrong because a post-training quiz only measures immediate recall, not long-term behavioral change or real-world application; employees can pass a quiz but still make errors in practice. Option B is wrong because completion percentage only tracks attendance, not whether the training was effective; it ignores the quality of learning and subsequent behavior. Option C is wrong because the number of help desk tickets related to phishing may decrease due to improved reporting or filtering, not necessarily due to training; it is an indirect metric that can be influenced by other factors like better spam filters.

753
MCQmedium

A company implements a policy requiring all employees to use a hardware token for remote access. This is an example of which type of security control?

A.Compensating
B.Deterrent
C.Preventive
D.Detective
AnswerC

Hardware tokens enforce authentication before access is granted, blocking unauthorised sessions outright rather than detecting them afterwards. This satisfies the stem's requirement for a control that stops remote access attempts pre-emptively, which is the defining characteristic of a preventive control.

Why this answer

A hardware token for remote access implements multifactor authentication (something you have), which directly prevents unauthorized access by requiring a physical device in addition to credentials. This is a preventive control because it stops the threat before it can occur, aligning with the NIST definition of preventive controls that block or mitigate attacks.

Exam trap

Cisco often tests the distinction between preventive and deterrent controls by using a technology that physically blocks access (like a token or firewall) and expecting candidates to recognize that 'deterrent' applies only to psychological discouragement, not technical enforcement.

How to eliminate wrong answers

Option A is wrong because compensating controls are alternative measures that provide equivalent protection when a primary control cannot be used (e.g., using software tokens instead of hardware tokens due to cost), not the primary control itself. Option B is wrong because deterrent controls discourage malicious behavior through fear of consequences (e.g., warning banners or surveillance signs), but a hardware token does not deter; it physically prevents access. Option D is wrong because detective controls identify and log incidents after they occur (e.g., intrusion detection systems or audit logs), whereas a hardware token actively blocks unauthorized access in real time.

754
MCQmedium

A security team implements a network-based IPS. During testing, they find that legitimate traffic is frequently blocked. Which tuning approach should they prioritize?

A.Change the IPS to fail-open mode.
B.Increase the number of IPS sensors.
C.Disable or modify signatures causing false positives.
D.Reduce the IPS sensitivity level to lower.
AnswerC

Modifying or disabling signatures that trigger on legitimate traffic directly reduces false positives, which caused the over-blocking described. Signature-based IPS engines match known patterns, so tuning those specific rules preserves detection of genuine threats while restoring legitimate flows. This satisfies the stem's constraint of frequent blocking of valid traffic.

Why this answer

False positives occur when IPS signatures incorrectly match legitimate traffic. The most direct and effective tuning approach is to disable or modify the specific signatures causing the false positives, which reduces unnecessary blocking without compromising overall security posture.

Exam trap

Cisco often tests the distinction between tuning signatures (which addresses false positives directly) versus changing operational modes or sensitivity levels, which are broader, less precise adjustments that can introduce new risks.

How to eliminate wrong answers

Option A is wrong because changing the IPS to fail-open mode would cause the device to pass all traffic if it fails, but this does not address the root cause of false positives; it merely bypasses the IPS functionality, potentially allowing attacks through. Option B is wrong because increasing the number of IPS sensors does not resolve signature misclassification; it would only distribute the same false-positive traffic across more sensors, amplifying the problem. Option D is wrong because reducing the IPS sensitivity level to lower may decrease false positives but also increases the risk of missing real threats (false negatives), as sensitivity controls the threshold for alerting, not the specific signature logic.

755
Multi-Selecteasy

Which TWO of the following are symmetric encryption algorithms? (Choose two.)

Select 2 answers
A.AES
B.RSA
C.Diffie-Hellman
D.ECC
E.3DES
AnswersA, E

AES is a symmetric block cipher: the same secret key both encrypts and decrypts data. It satisfies the question's requirement, unlike asymmetric algorithms such as RSA or Diffie-Hellman, which use separate public and private keys.

Why this answer

AES (Option A) is correct because it is a symmetric block cipher that uses the same secret key for both encryption and decryption, operating on 128-bit blocks with key sizes of 128, 192, or 256 bits. 3DES (Option E) is also correct because it is a symmetric block cipher that applies the DES algorithm three times to each data block using the same shared secret key for encryption and decryption. RSA (Option B) is not correct because it is an asymmetric algorithm that uses a public key for encryption and a private key for decryption. Diffie-Hellman (Option C) is not correct because it is an asymmetric key-exchange protocol used to establish a shared secret, not a symmetric encryption algorithm itself.

ECC (Option D) is not correct because it is an asymmetric public-key cryptography approach based on elliptic curve mathematics.

Exam trap

Cisco often tests the distinction between symmetric encryption, asymmetric encryption, and key exchange protocols, so candidates mistakenly select Diffie-Hellman or ECC as encryption algorithms when they are actually used for key agreement or asymmetric operations.

756
MCQeasy

Which log type would an analyst examine to view details about HTTP methods (GET, POST), response codes, and user-agent strings?

A.Web server logs
B.System logs
C.Firewall logs
D.DNS logs
AnswerA

Web server logs record each HTTP request, capturing the method (GET, POST), status code and User-Agent header, so they directly satisfy the stem's requirement for those three fields. Other log types, such as firewall or authentication logs, lack this application-layer detail.

Why this answer

Web server logs record HTTP requests and responses, including methods, URLs, response codes, and user-agent information.

757
Drag & Dropmedium

Drag and drop the steps to analyze a packet capture for suspicious activity into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct sequence for packet capture analysis starts by opening the capture file, then applying filters to isolate relevant traffic, examining the filtered packets for anomalies, correlating findings across different packets or sessions, and finally documenting the analysis results for reporting and future reference. This order ensures efficiency and accuracy.

758
MCQmedium

During a host-based analysis, a Windows system is found to have a suspicious service that starts automatically. Which command-line tool can be used to query the status and configuration of services, particularly to identify non-standard service names or paths?

A.sc query
B.services.msc
C.tasklist /svc
D.net start
AnswerA

The sc query command interrogates the Windows Service Control Manager, returning each service's status, start type and binary path. This directly satisfies the need to spot non-standard service names or executable paths during host-based analysis, since the SCM holds the authoritative configuration.

Why this answer

The 'sc query' command queries the Service Control Manager for service status and configuration, and with 'sc qc' it reveals the binary path, start type, and service account — exactly what's needed to spot non-standard service names or paths. It works from the command line, making it suitable for scripted forensic triage. Analysts use 'sc query state= all' to enumerate all services and 'sc qc <name>' to inspect suspicious ones.

Exam trap

The trap is confusing service enumeration (sc query) with process-to-service mapping (tasklist /svc) or GUI tools (services.msc) — candidates pick tasklist /svc because it shows services, but it lacks configuration details like binary path.

How to eliminate wrong answers

Option B is wrong because services.msc is a GUI tool, not a command-line utility, and cannot be easily scripted or used in automated forensic collection. Option C is wrong because tasklist /svc only maps running processes to hosted services — it does not show service configuration, binary paths, or start types, so it cannot identify non-standard paths. Option D is wrong because 'net start' only lists running services and can start them; it does not reveal configuration details like ImagePath or start type.

759
MCQeasy

Which Windows registry hive is most likely to contain evidence of malware persistence via a service?

A.HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
B.HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
C.HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
D.HKEY_LOCAL_MACHINE\SAM
AnswerB

Services configured for persistence are recorded under HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services, where each subkey holds the service's ImagePath, Start type and parameters. This satisfies the stem's requirement for the registry hive most likely to evidence service-based malware persistence, since the SYSTEM hive stores all service definitions.

Why this answer

The HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services registry hive stores the configuration for all Windows services, including their executable paths and startup types. Malware often installs itself as a service to achieve persistence, and evidence of this can be found by examining the ImagePath value under a suspicious service subkey. This is the correct location for service-based persistence, unlike the Run keys which handle startup programs for users.

Exam trap

Cisco often tests the distinction between Run keys (user logon persistence) and Services keys (system service persistence), and the trap here is that candidates confuse the Run keys with service persistence because both are common persistence mechanisms, but only the Services hive stores service-specific configurations.

How to eliminate wrong answers

Option A is wrong because HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run is used for auto-starting programs at user logon, not for services; malware using this key persists via Run registry entries, not as a service. Option C is wrong because HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run is a per-user Run key that only affects the currently logged-in user, not system-wide service persistence. Option D is wrong because HKEY_LOCAL_MACHINE\SAM stores Security Account Manager data (user and group hashes) and is not related to service configuration or persistence mechanisms.

760
MCQmedium

A security analyst discovers that a server's configuration allows users to access files outside of their intended directory. In security terminology, what is this weakness called?

A.Exploit
B.Vulnerability
C.Threat
D.Risk
AnswerB

A vulnerability is a weakness in a system's configuration or design that a threat could exploit. Directory traversal access outside intended directories is exactly such a flaw, so this term precisely describes the weakness the analyst found.

Why this answer

A vulnerability is a weakness or flaw in a system's design, configuration, or code that could be exploited to violate security. The scenario describes a path traversal weakness in the server configuration, which is a classic vulnerability. This is the precise security term for the condition described.

Exam trap

200-201 often tests the distinction between vulnerability, threat, risk, and exploit — candidates pick 'exploit' or 'risk' because the scenario sounds like an active attack, but the question asks for the weakness itself.

How to eliminate wrong answers

Option A is wrong because an exploit is the actual code or technique that takes advantage of a vulnerability, not the weakness itself. Option C is wrong because a threat is any potential cause of harm (e.g., an attacker, malware, or natural disaster), not the configuration flaw. Option D is wrong because risk is the combination of the likelihood and impact of a threat exploiting a vulnerability, not the weakness itself.

761
MCQmedium

Refer to the exhibit. A network analyst sees these firewall logs. What is the most likely interpretation?

A.An attacker is performing a port scan on internal hosts from the outside
B.The firewall rule OUTSIDE_IN is misconfigured and blocking all traffic
C.A malware is trying to phone home to an external C2 server
D.A user is trying to access internal web servers legitimately but is blocked by ACL
AnswerA

The logs show sequential connection attempts across multiple destination ports from one external source, which is the signature of a TCP port scan. This satisfies the stem's requirement to interpret repeated inbound probes against internal hosts, confirming reconnaissance activity rather than legitimate traffic or a single-service attack.

Why this answer

The firewall logs show multiple denied TCP connection attempts from a single external IP to various internal IPs on different ports (e.g., 80, 443, 22). This pattern of sequential probes across multiple destinations and ports is characteristic of a port scan, where an attacker systematically probes for open services. The rule OUTSIDE_IN is correctly logging and blocking these attempts, indicating the firewall is functioning as designed to prevent reconnaissance.

Exam trap

Cisco often tests the distinction between a port scan (multiple destinations/ports from one source) and a C2 beacon (single destination, periodic traffic), where candidates mistakenly interpret any blocked external traffic as malware callbacks.

How to eliminate wrong answers

Option B is wrong because the firewall is actively logging and blocking traffic, which shows the rule is working correctly, not misconfigured; a misconfigured rule would either allow all traffic or block all traffic without such selective logging. Option C is wrong because malware phoning home typically uses a single, consistent destination (C2 server) on a fixed port, not a broad scan across multiple internal hosts and ports. Option D is wrong because legitimate internal web server access would originate from internal IPs, not an external source, and the logs show the source is external (e.g., 203.0.113.5), not a user inside the network.

762
MCQeasy

A security monitoring tool generates an alert for a user accessing a sensitive file at an unusual hour. What is the most appropriate next step?

A.Ignore the alert since it is likely a false positive.
B.Contact the user to confirm if the access was legitimate.
C.Escalate the alert to the incident response team.
D.Block the user's account immediately.
AnswerB

Contacting the user directly verifies whether the unusual-hour access was legitimate, satisfying the need to validate the alert before escalation. This human confirmation quickly distinguishes authorised activity from a genuine compromise, avoiding wasted incident response effort on false positives while preserving evidence if the access proves malicious.

Why this answer

The alert indicates an anomaly (unusual hour), but not necessarily malicious activity. The most appropriate first step is to verify the user's intent through direct communication, as this aligns with the principle of validation before escalation. In security monitoring, contacting the user helps confirm whether the access was authorized, reducing false positives and unnecessary incident response activation.

Exam trap

Cisco often tests the distinction between triage and escalation, trapping candidates who jump to escalation or containment without first performing the basic verification step of contacting the user.

How to eliminate wrong answers

Option A is wrong because ignoring the alert outright violates the fundamental security monitoring principle of investigating anomalies; even if it is a false positive, the alert must be triaged, not dismissed without analysis. Option C is wrong because escalating directly to the incident response team bypasses the initial triage step; escalation should occur only after preliminary verification (e.g., user confirmation or log correlation) indicates a genuine security incident. Option D is wrong because immediately blocking the user's account is an overreaction that could disrupt legitimate business operations; account lockdown should be reserved for confirmed threats, not based solely on a single anomalous access time.

763
MCQhard

MedSecure is a healthcare organization with a security policy that requires all security incidents to be handled following the NIST framework. A system administrator discovers that an unauthorized user has accessed a database containing patient records. The administrator immediately disconnects the server from the network. The security analyst is called to investigate. The analyst finds that the server was not part of the centralized logging system, and the only logs available are the database audit logs. The security policy mandates preservation of evidence and chain of custody. The analyst needs to collect the database audit logs. Which action should the analyst take to ensure proper evidence collection?

A.Make a bit-for-bit copy of the audit log files using a forensic tool, hash the original and copy, and document the process
B.Export the logs to a CSV file and email them to the security team
C.Use a write-blocker to create a forensic image of the entire hard drive
D.Copy the audit logs to a USB drive and store it in a locked drawer
AnswerA

A bit-for-bit forensic image preserves the audit logs exactly, and hashing both original and copy proves integrity while documenting the process establishes chain of custody. This satisfies the policy's evidence-preservation and chain-of-custody mandates without altering the source data.

Why this answer

To ensure proper evidence collection and preservation of chain of custody, the analyst should make a bit-for-bit copy of the audit log files using a forensic tool, hash both the original and the copy, and document the process. This maintains the integrity of the evidence and provides a verifiable record. Hashing ensures that any tampering can be detected, and documentation establishes the chain of custody.

Exam trap

200-201 often tests the importance of hashing and documentation in evidence collection. Candidates may choose to image the entire drive, but that is not always necessary or practical. The key is to focus on the specific evidence (audit logs) and ensure integrity through hashing and chain of custody.

How to eliminate wrong answers

Option B is wrong because exporting logs to CSV and emailing them does not preserve the original format, may alter metadata, and lacks a secure chain of custody. Option C is wrong because using a write-blocker to image the entire hard drive is overkill and may not be feasible if the server is in production; it also does not focus on the specific audit logs. Option D is wrong because copying logs to a USB drive without hashing or documentation fails to preserve integrity and chain of custody.

764
Multi-Selectmedium

A network analyst is investigating a suspected DNS tunneling attack. Which THREE of the following are indicators of DNS tunneling?

Select 3 answers
A.DNS queries for well-known domains like google.com
B.Unusually high volume of DNS queries to a single domain
C.DNS queries with long subdomain names containing encoded characters
D.Low volume of DNS queries from internal hosts
E.DNS responses with large TXT record sizes
AnswersB, C, E

Tunnelling tools continuously encode and transmit data, producing far more queries to a single domain than legitimate resolution patterns. This sustained query volume to one domain satisfies the stem's requirement for a DNS tunnelling indicator.

Why this answer

DNS tunneling often involves high volumes of DNS queries to a single domain, large payloads in TXT records, and encoded data in subdomains to exfiltrate data.

765
Multi-Selecthard

An analyst is investigating a host that is suspected of being compromised. The host's security logs show multiple failed login attempts followed by a successful login from an unusual IP address, and then a series of outbound connections to known malicious destinations. Which TWO actions should the analyst take immediately? (Choose two.)

Select 2 answers
A.Delete the malicious files found on the host
B.Isolate the host from the network
C.Collect a forensic image of the host's hard drive
D.Reboot the host to clear any malware from memory
E.Run a full antivirus scan on the host
AnswersB, C

Isolating the host stops ongoing malicious activity and prevents lateral movement.

Why this answer

Isolating the host from the network immediately stops the outbound connections to known malicious destinations, preventing further data exfiltration, lateral movement, or command-and-control (C2) communication. This containment step is critical in incident response to limit the blast radius before any other investigative or remediation actions are taken.

Exam trap

Cisco often tests the misconception that immediate remediation (deleting files, running antivirus) is the priority, when in fact containment (isolation) and evidence preservation (forensic imaging) are the correct first steps in a structured incident response process.

766
MCQmedium

A hospital's security team discovers that a network device is silently forwarding copies of all traffic to an internal host that no administrator recognizes. The device is a managed switch that connects the radiology VLAN to the core. Which attack has most likely been implemented against this switch?

A.ARP cache poisoning
B.MAC flooding
C.VLAN hopping via double tagging
D.SPAN port misconfiguration
AnswerD

A Switched Port Analyzer session copies traffic from a source VLAN or interface to a destination port for monitoring. If an attacker with management access creates a SPAN session pointing at their own host, the switch transparently duplicates every frame from the radiology VLAN to that host, matching the observed silent copy of all traffic without disrupting normal forwarding.

Why this answer

A SPAN session on a managed switch replicates traffic from a source interface or VLAN to a destination port. When a rogue administrator or attacker with device access creates such a session aimed at an unknown internal host, every frame on the radiology VLAN is duplicated there while normal forwarding continues unaffected. The other techniques either degrade forwarding, enable cross-VLAN access, or manipulate host caches rather than producing a sustained, targeted copy of one VLAN's traffic.

Exam trap

The trap here is assuming that any traffic duplication on a switch must be an attack on the switch's forwarding tables, when a legitimate built-in monitoring feature can be abused to mirror traffic.

767
MCQhard

A company operating in the EU experiences a data breach involving personal data of EU citizens. Under GDPR, what is the maximum timeframe to notify the supervisory authority?

A.96 hours
B.72 hours
C.24 hours
D.48 hours
AnswerB

GDPR Article 33 requires notification of the supervisory authority within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in risk. This satisfies the stem's EU personal data scenario.

Why this answer

Under Article 33 of the GDPR, a controller must notify the supervisory authority of a personal data breach without undue delay and, where feasible, no later than 72 hours after becoming aware of it. This 72-hour window is the maximum timeframe, making option B correct for the 200-201 exam context.

Exam trap

Cisco often tests the exact GDPR notification timeframe (72 hours) versus other common breach notification periods (e.g., 48 hours for some US state laws or 24 hours for PCI DSS), so candidates must memorize the precise 72-hour requirement for EU personal data breaches.

How to eliminate wrong answers

Option A is wrong because 96 hours exceeds the GDPR-mandated 72-hour notification window, reflecting a common misconception that a longer period is allowed. Option C is wrong because 24 hours is too short; GDPR does not require notification within 24 hours, though some other regulations (e.g., certain state breach laws) may have shorter timelines. Option D is wrong because 48 hours is not the GDPR standard; while some organizations aim for internal escalation within 48 hours, the regulatory requirement is 72 hours.

768
MCQmedium

An analyst is examining a firewall log entry: '2023-10-25 14:30:00 ACTION=DENY SRC=10.0.0.5 DST=203.0.113.50 PROTO=TCP SPT=445 DPT=445'. Which statement best describes this event?

A.An internal host attempted to establish an SMB connection to an external IP and was blocked.
B.A DNS query was made from an internal host to an external server.
C.An external host attempted to access an internal SMB server on port 445 and was blocked.
D.An internal host successfully connected to an external server on port 445.
AnswerA

Port 445 is SMB, and the DENY action confirms the firewall dropped the session. The log shows an internal host (10.0.0.5) initiating TCP/445 toward an external address, so the outbound SMB connection attempt was blocked.

Why this answer

The log entry shows a deny action for traffic from internal IP 10.0.0.5 to external IP 203.0.113.50 on TCP port 445, which is the default port for SMB (Server Message Block) protocol. Since the source is internal (RFC 1918 address) and the destination is external, this indicates an outbound connection attempt that was blocked by the firewall. SMB is commonly used for file sharing and is often restricted outbound to prevent data exfiltration or malware propagation.

Exam trap

Cisco often tests the ability to interpret firewall log fields (SRC, DST, ACTION, PROTO, SPT, DPT) and map them to network directionality, where candidates mistakenly reverse source/destination or confuse port numbers with unrelated protocols like DNS.

How to eliminate wrong answers

Option B is wrong because the log shows TCP port 445 (SMB), not UDP/TCP port 53 (DNS), and there is no indication of a DNS query in the fields. Option C is wrong because the source IP (10.0.0.5) is internal and the destination (203.0.113.50) is external, meaning this is an outbound attempt from an internal host, not an inbound attempt from an external host. Option D is wrong because the ACTION field is 'DENY', not 'ALLOW', so the connection was blocked, not successful.

769
MCQmedium

Which of the following is an example of a symmetric encryption algorithm?

A.SHA-256
B.RSA
C.AES
D.ECC
AnswerC

AES is a symmetric block cipher using the same secret key for encryption and decryption, satisfying the stem's requirement for a symmetric algorithm. Operating on 128-bit blocks with key sizes of 128, 192, or 256 bits, it contrasts with asymmetric algorithms such as RSA, which use separate public and private keys.

Why this answer

AES (Advanced Encryption Standard) is a symmetric encryption algorithm, meaning the same secret key is used for both encryption and decryption. It operates on fixed-size blocks (128 bits) with key sizes of 128, 192, or 256 bits and is the current NIST standard for symmetric encryption. Because both parties must share the same key, AES is fast and efficient for bulk data encryption.

Exam trap

The trap here is confusing hashing (SHA) and asymmetric algorithms (RSA, ECC) with symmetric encryption — candidates often assume any 'crypto-sounding' acronym is symmetric, but only AES among these uses a single shared key.

How to eliminate wrong answers

Option A is wrong because SHA-256 is a cryptographic hash function (part of the SHA-2 family), not an encryption algorithm — it produces a one-way 256-bit digest and cannot be decrypted. Option B is wrong because RSA is an asymmetric algorithm that uses a public/private key pair for encryption and digital signatures. Option D is wrong because ECC (Elliptic Curve Cryptography) is also asymmetric, relying on elliptic curve mathematics for key exchange and signatures rather than symmetric encryption.

770
MCQeasy

During which phase of the NIST SP 800-61 Rev 2 incident response process does an organization develop an incident response plan and assemble a team?

A.Containment, Eradication, and Recovery
B.Detection and Analysis
C.Preparation
D.Post-Incident Activity
AnswerC

Preparation is the first NIST SP 800-61 Rev 2 phase, covering creation of the incident response plan, team structure, tools and training before any incident occurs. It directly satisfies the stem's requirement for the phase where planning and team assembly happen.

Why this answer

The Preparation phase includes developing the IR plan, team, tools, and conducting exercises.

771
Multi-Selectmedium

Which TWO are common indicators of a compromised host? (Choose two.)

Select 2 answers
A.User logging in during business hours.
B.Scheduled tasks running at regular intervals.
C.Unusual spikes in outbound network traffic at odd hours.
D.Unexpected outbound connections to known malicious IPs.
E.Antivirus updates occurring daily.
AnswersC, D

May indicate data exfiltration.

Why this answer

Unusual spikes in outbound network traffic at odd hours (Option C) are a common indicator of a compromised host because they often signal data exfiltration, command-and-control (C2) beaconing, or botnet activity. Attackers frequently schedule malicious traffic during off-peak hours to evade detection, and the abnormal volume or timing relative to baseline behavior is a key anomaly in security monitoring.

Exam trap

Cisco often tests the distinction between normal administrative activity (scheduled tasks, daily updates) and true behavioral anomalies (unusual timing, unexpected destinations), so candidates must avoid confusing routine operations with compromise indicators.

772
MCQmedium

A SOC analyst is reviewing a Windows 10 endpoint that is suspected of being compromised by malware that hides its network connections. The analyst runs 'netstat -anob' on the live system but does not see any suspicious outbound connections. Which Windows artifact should the analyst examine next to identify network connections that may have been hidden from the live API?

A.The SRUM database (SRUDB.dat) parsed with a tool such as srum-dump
B.The Amcache.hve registry hive parsed with AmcacheParser
C.The ShimCache (AppCompatCache) entries in the SYSTEM hive
D.The Windows Prefetch files parsed with PECmd
AnswerA

SRUM (System Resource Usage Monitor) records per-application network usage and bytes sent/received over time, stored in SRUDB.dat. Malware that hooks live APIs to hide from netstat still generates SRUM entries because the ESE database is populated by the ESE-based SRUM service, not by the APIs the malware hooks. Parsing it can reveal a process that communicated externally even when live tooling shows nothing.

Why this answer

SRUM maintains a rolling record of per-application resource usage, including bytes sent and received and network interface activity, in the SRUDB.dat ESE database. Because it is populated by the SRUM service rather than by the APIs malware commonly hooks to hide from netstat or GetTcpTable, it can surface external communications that live commands miss. Parsing SRUM therefore gives the analyst network evidence the live system concealed.

Exam trap

The trap here is assuming that if netstat shows nothing suspicious, the host made no suspicious network connections, when API-hooking malware can hide from live queries while SRUM still logs the traffic.

773
Drag & Dropmedium

Drag and drop the steps to configure SSH access on a Cisco IOS switch into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

SSH configuration requires domain name, RSA keys, a local user, and enabling SSH on vty lines.

774
MCQhard

An organization's security policy requires that all traffic between the corporate network and the internet be inspected by an IPS. However, encrypted traffic (HTTPS) cannot be inspected without breaking encryption. Which solution best meets the policy requirement?

A.Allow all HTTPS traffic without inspection
B.Implement SSL/TLS interception using a proxy with a trusted certificate
C.Rely on endpoint security only
D.Disable HTTPS for internal users
AnswerB

SSL/TLS interception terminates encrypted sessions at a proxy holding a trusted certificate, decrypting traffic so the IPS can inspect it before re-encryption. This satisfies the policy's inspection requirement for HTTPS, which passive IPS monitoring cannot otherwise examine.

Why this answer

SSL/TLS interception using a proxy with a trusted certificate allows the IPS to decrypt, inspect, and re-encrypt HTTPS traffic. The proxy acts as a man-in-the-middle, presenting a certificate trusted by internal clients, so the IPS can apply security policies to the decrypted content before forwarding it to the internet.

Exam trap

Cisco often tests the misconception that encrypted traffic cannot be inspected at all, leading candidates to choose 'allow without inspection' or 'disable encryption,' rather than understanding that SSL/TLS interception with a trusted proxy is the standard enterprise solution.

How to eliminate wrong answers

Option A is wrong because allowing all HTTPS traffic without inspection violates the security policy requirement that all traffic be inspected by the IPS, leaving encrypted threats undetected. Option C is wrong because relying solely on endpoint security does not provide network-level inspection of encrypted traffic, and endpoints can be compromised or misconfigured, bypassing policy enforcement. Option D is wrong because disabling HTTPS for internal users is impractical, breaks modern web functionality, and does not meet the requirement to inspect traffic; it simply removes the encryption rather than enabling inspection.

775
MCQmedium

During a host-based investigation, an analyst finds a process named 'svchost.exe' consuming high CPU. The process path is 'C:\Windows\Temp\svchost.exe'. What should the analyst conclude?

A.It is a legitimate Windows service host process
B.It is a third-party application that requires investigation
C.It is likely malware disguised as a legitimate process
D.It is a temporary file created by Windows Update
AnswerC

Legitimate svchost.exe instances always reside in C:\Windows\System32 and are launched by services.exe; a copy running from C:\Windows\Temp violates that invariant, indicating masquerading malware. The anomalous path, combined with sustained high CPU, satisfies the stem's evidence of process impersonation rather than normal service-host behaviour.

Why this answer

The legitimate svchost.exe (Service Host) runs from C:\Windows\System32, not C:\Windows\Temp. The Temp directory is a common location for malware to masquerade as system processes to evade detection. High CPU usage combined with an anomalous path strongly indicates malicious activity, as legitimate svchost.exe instances are signed by Microsoft and reside in System32.

Exam trap

Cisco often tests the misconception that any process named 'svchost.exe' is automatically legitimate, but the trap here is that the file path is the critical differentiator—malware frequently uses the same name as a trusted system binary but runs from an unauthorized location.

How to eliminate wrong answers

Option A is wrong because the legitimate svchost.exe is located in C:\Windows\System32, not C:\Windows\Temp; any svchost.exe outside System32 is not a genuine Windows service host. Option B is wrong because while third-party applications can run from Temp, the name 'svchost.exe' is specifically chosen to impersonate a Windows system process, making it far more likely to be malware than a benign third-party app. Option D is wrong because Windows Update does not create svchost.exe in the Temp directory; it uses trusted binaries in System32 and may create temporary files with different names (e.g., .tmp) in C:\Windows\Temp.

776
MCQmedium

Refer to the exhibit. A host-based analyst reviews auth.log. What does the accepted password log entry indicate?

A.The root account was successfully compromised
B.The system prevented a brute-force attack on the admin account
C.The admin login is legitimate because it was accepted
D.The admin account was accessed by an attacker after brute-forcing root
AnswerD

The log entry shows a successful login as 'admin' followed by failed attempts for 'root', indicating the attacker first gained access via the admin account and then attempted to escalate to root.

Why this answer

The log entry shows 'Accepted password for admin from 10.10.10.10 port 22 ssh2' followed by 'Failed password for root from 10.10.10.10 port 22 ssh2'. The sequence indicates that the attacker first successfully logged in as 'admin' (accepted password), then attempted to escalate privileges by brute-forcing the 'root' account. Option D correctly identifies that the admin account was accessed by an attacker who then attempted to brute-force root, as evidenced by the failed root attempts after a successful admin login.

Exam trap

Cisco often tests the trap that 'Accepted password' automatically implies a legitimate user, but in host-based analysis, the context of subsequent failed attempts reveals malicious intent, so candidates must correlate multiple log entries rather than evaluating them in isolation.

How to eliminate wrong answers

Option A is wrong because the log shows 'Failed password for root', meaning the root account was not compromised—only an attempt was made. Option B is wrong because the system did not prevent a brute-force attack on the admin account; in fact, the admin login was accepted, indicating a successful authentication, not a prevention. Option C is wrong because the admin login being 'accepted' does not automatically make it legitimate—it could be an attacker using a valid credential, and the subsequent failed root attempts suggest malicious intent.

777
MCQeasy

A security analyst is reviewing Windows Event Logs to determine if a user account was recently created on a compromised host. Which Windows Event ID should the analyst look for in the Security log to identify user account creation events?

A.Event ID 4672
B.Event ID 4720
C.Event ID 4624
D.Event ID 4625
AnswerB

Event ID 4720 is generated when a new user account is created. It includes the target username and the subject (the account that performed the creation). This is the correct event ID to identify user account creation activity, which is a common persistence technique used by attackers to maintain access to a compromised system.

Why this answer

Windows Security Event ID 4720 is specifically logged when a user account is created. It contains fields such as TargetUserName (the new account) and SubjectUserName (the account that created it). This event is critical for detecting unauthorized account creation, which attackers often use for persistence.

Other event IDs like 4624 (logon) or 4625 (failed logon) do not indicate account creation.

Exam trap

The trap here is confusing logon-related event IDs (such as 4624 or 4625) with account management events like 4720.

778
MCQmedium

A financial services firm must comply with regulations covering cardholder data. The security team is mapping its controls to the PCI DSS framework and wants to confirm that the framework's requirements are being met before an upcoming assessment. Which statement best describes what PCI DSS provides to the organization?

A.A set of mandatory requirements and control objectives for organizations that store, process, or transmit cardholder data
B.A voluntary advisory publication that suggests best practices but carries no compliance obligations for the merchant
C.A prescriptive technical configuration baseline that dictates exact settings for every operating system and application in the environment
D.A legal statute enacted by a national government that replaces all contractual security obligations with statutory penalties
AnswerA

PCI DSS is a mandatory framework of requirements and control objectives that applies to any entity storing, processing, or transmitting cardholder data. It defines what must be achieved, such as encrypting transmission of cardholder data over open networks, while leaving implementation choices to the organization. This matches the scenario's need to confirm compliance before an assessment.

Why this answer

PCI DSS is an industry-mandated framework of requirements and control objectives that applies to any organization handling cardholder data. It specifies outcomes, such as protecting stored data and encrypting transmission over open networks, but leaves specific technical implementation to the organization. It is enforced contractually through acquiring banks, not as advisory guidance or as government legislation.

Exam trap

The trap here is confusing a framework of control objectives with a prescriptive technical baseline, when PCI DSS deliberately states requirements while allowing each organization to choose how to implement them.

779
MCQmedium

A security analyst is examining a PCAP and observes a series of TCP packets with the PSH flag set and small payload sizes, sent from an internal host to an external IP. The packets are spaced roughly 30 seconds apart. Which type of malicious activity is MOST likely indicated?

A.A TCP SYN flood attack
B.A TCP port scan using FIN packets
C.A command-and-control (C2) beacon
D.A large file transfer using FTP
AnswerC

C2 beacons often use periodic, small payloads to check in with the attacker. The PSH flag indicates data is being pushed, and the 30-second interval suggests a beaconing pattern. This is typical of malware communicating with a C2 server.

Why this answer

The combination of small payloads, PSH flag, and regular 30-second intervals strongly suggests C2 beaconing. Malware often beacons to its C2 server at set intervals to receive commands or exfiltrate small amounts of data. This pattern is distinct from floods, file transfers, or scans.

Exam trap

The trap here is assuming any TCP packet with PSH is benign interactive traffic, but regular small beacons are a hallmark of C2 communication.

780
MCQeasy

A small retail company uses a cloud-based point-of-sale (POS) system. The IT manager receives an alert from the cloud provider that the POS application is generating an unusually high number of outbound connections to an IP address in a foreign country. The POS application is only supposed to communicate with the cloud provider's servers in the United States. The IT manager checks the POS terminal logs and finds that a new user account was created locally on the terminal with administrative privileges two days ago. The terminal does not have antivirus installed. What should the IT manager do first to contain the incident and prevent data loss?

A.Reset the password for the new user account and disable it.
B.Install antivirus software on the terminal and run a full scan.
C.Contact the cloud provider to block the outbound IP address.
D.Disconnect the POS terminal from the network immediately.
AnswerD

Severing network connectivity halts the command-and-control channel and blocks further exfiltration, the immediate containment priority. The unauthorised admin account and foreign outbound connections indicate active compromise, so isolation precedes forensic imaging, password resets or antivirus installation.

Why this answer

Disconnecting the POS terminal from the network immediately halts the suspected data exfiltration and prevents further loss.

781
MCQeasy

An intrusion detection system (IDS) generates an alert for a packet containing the string '/etc/passwd'. What type of attack is likely detected?

A.Directory traversal
B.Cross-site scripting
C.Buffer overflow
D.SQL injection
AnswerA

The string '/etc/passwd' in a packet indicates directory traversal, satisfying the stem's attack-classification requirement. Attackers use ../ sequences to escape the web root and read files such as /etc/passwd, so a signature matching that path detects traversal attempts.

Why this answer

The string '/etc/passwd' is a classic indicator of a directory traversal attack, where an attacker attempts to access files outside the web root directory by manipulating path parameters. An IDS detecting this string in a packet payload (e.g., in a URL or HTTP request) suggests the attacker is trying to read the Unix password file, which is a common target in path traversal exploits. This attack exploits insufficient input validation to navigate the file system using '../' sequences or absolute paths.

Exam trap

Cisco often tests the distinction between attack types by using a specific string like '/etc/passwd' to mislead candidates into thinking of SQL injection or XSS, when the key is recognizing that file path references in payloads indicate directory traversal.

How to eliminate wrong answers

Option B is wrong because cross-site scripting (XSS) involves injecting malicious scripts (e.g., JavaScript) into web pages viewed by other users, not file path strings like '/etc/passwd'. Option C is wrong because a buffer overflow attack exploits memory corruption by overflowing a buffer with excessive data, not by referencing a specific file path in a request. Option D is wrong because SQL injection targets database queries by inserting SQL commands (e.g., ' OR 1=1 --) into input fields, not by requesting a file path like '/etc/passwd'.

782
Multi-Selectmedium

Which TWO of the following are indicators of a network intrusion? (Choose two.)

Select 2 answers
A.High bandwidth usage during business hours
B.A single failed login attempt from an internal user
C.Regular ICMP echo requests to external hosts
D.A sudden increase in DNS queries to unknown domains from a single host
E.Multiple outbound connections from a server to an external IP on port 445
AnswersD, E

This could indicate malware beaconing or DNS tunneling.

Why this answer

A sudden spike in DNS queries to unknown domains from a single host is a classic sign of DNS tunneling or command-and-control (C2) activity. Attackers often use DNS to exfiltrate data or communicate with external servers by encoding data in DNS queries, bypassing traditional firewall rules that allow DNS traffic.

Exam trap

Cisco often tests the distinction between normal administrative traffic (like ICMP pings or a single failed login) and true indicators of compromise (like anomalous DNS queries or outbound SMB connections), trapping candidates who mistake benign activity for malicious.

783
Multi-Selectmedium

A SOC analyst is reviewing DNS logs and suspects that a host is communicating with a domain generation algorithm (DGA) used by malware. Which TWO characteristics in the DNS logs would most strongly support this suspicion? (Choose two.)

Select 2 answers
A.DNS queries using only TCP instead of UDP for all requests.
B.Repeated DNS queries for the same domain at precise, regular intervals.
C.A large number of NXDOMAIN responses for queries with long, nonsensical domain names.
D.A high volume of DNS queries for domains with seemingly random alphanumeric strings and varying top-level domains.
E.DNS queries for domains that resolve to private IP addresses within the corporate network.
AnswersC, D

DGA malware generates many domains, most of which are not registered, resulting in NXDOMAIN responses. A spike in NXDOMAIN for long, random-looking names is a classic DGA indicator, as the malware probes many candidates before finding an active C2 domain.

Why this answer

DGA malware generates numerous pseudo-random domain names to locate its C2 server. This results in a high volume of queries for random-looking domains, often with varied TLDs, and many NXDOMAIN responses for unregistered names. These two characteristics together strongly indicate DGA behavior.

Exam trap

The trap here is focusing on the protocol (TCP vs UDP) or regular intervals, which are not primary DGA indicators; the randomness and volume of domain names are the key signals.

784
MCQhard

A network security analyst is examining a packet capture in Wireshark and notices a series of TCP packets with the PSH, ACK flags set, and a payload containing the string 'cmd.exe /c whoami'. The packets are destined to port 445 on an internal server. Which type of malicious activity is most likely indicated?

A.DNS tunneling for data exfiltration
B.SMB lateral movement and command execution
C.SMTP email-based malware delivery
D.HTTP command-and-control communication
AnswerB

The combination of SMB port 445 and a command shell payload like 'cmd.exe /c whoami' strongly suggests an attacker using SMB for lateral movement and executing commands on a remote system. This is a common technique in ransomware and APT campaigns, where SMB is used to propagate and run commands.

Why this answer

The presence of SMB traffic on port 445 carrying a command shell payload such as 'cmd.exe /c whoami' is a strong indicator of lateral movement and remote command execution. Attackers often use SMB to move between systems and execute commands, making this the most likely malicious activity in the scenario.

Exam trap

The trap here is focusing on the PSH, ACK flags and assuming it is a generic data transfer, while overlooking the SMB port and the command execution string that point to lateral movement.

785
MCQmedium

A SOC analyst is investigating a suspected data exfiltration event on a corporate network. The analyst runs a Wireshark display filter on a captured PCAP and sees a large volume of outbound packets from an internal workstation to an external IP address, all with the same destination port and with the TCP PSH flag set on nearly every packet. The payloads are small but consistently sized, and the transfer continues for over 30 minutes. Which statement best explains why this traffic pattern is suspicious in the context of network intrusion analysis?

A.The PSH flag indicates the sender is bypassing TCP flow control, which is a known evasion technique used by rootkits to hide data in the TCP header.
B.The presence of the PSH flag on nearly every packet means the connection is using TCP Fast Open, which is only seen in malicious command-and-control channels.
C.The use of a single destination port for all outbound packets indicates the traffic is encrypted, and encrypted exfiltration cannot be detected by network analysis.
D.The steady, long-duration outbound flow with consistent packet sizes suggests a scripted or automated transfer, which is consistent with data exfiltration rather than normal interactive user activity.
AnswerD

A sustained, uniform outbound flow over 30 minutes with uniform packet sizes and PSH on nearly every packet strongly suggests an automated tool pushing data out, not a human browsing or emailing. Exfiltration tools often chunk data into consistent sizes to optimize throughput. In intrusion analysis, this beaconing-like regularity is a key indicator of malicious data transfer rather than legitimate user traffic.

Why this answer

The correct answer focuses on behavioral indicators: a long, steady, automated-looking outbound flow with uniform packet sizes and the PSH flag set on most packets. This pattern is typical of data exfiltration tools that chunk and push data continuously, unlike bursty interactive user traffic. The other options misattribute meaning to TCP flags or make incorrect claims about detection limits, which would mislead an analyst.

Exam trap

The trap here is assuming that a TCP flag like PSH is inherently malicious or that a single destination port implies encryption, when the real signal is the sustained, automated transfer pattern.

786
MCQhard

A financial services firm is building a threat model and wants to classify an attacker who is highly skilled, well funded, and focused on stealing intellectual property from a specific set of companies over a long period. Which threat actor category best fits this profile?

A.Script kiddie
B.Hacktivist
C.Insider threat
D.Advanced persistent threat
AnswerD

An advanced persistent threat is a well-resourced actor, often state-sponsored, that conducts prolonged campaigns against specific targets. The combination of high skill, significant funding, focus on a defined set of victims, and long-term intellectual property theft matches the APT profile exactly. APTs prioritize stealth and persistence over quick disruption, which is consistent with the described behavior.

Why this answer

An advanced persistent threat is characterized by significant resources, advanced skills, and sustained, stealthy operations against specific targets, often for espionage or intellectual property theft. The scenario's emphasis on long duration, funding, and a defined victim set aligns with APT behavior. Hacktivists are ideologically driven, script kiddies lack sophistication and resources, and insider threats are authorized users, so none matches the described external, well-funded, persistent actor.

Exam trap

The trap here is focusing on the theft of intellectual property alone, which any actor might attempt, instead of weighing the funding, skill, and long-term persistence that define an advanced persistent threat.

787
MCQmedium

An analyst is examining a Windows system for evidence of malware that maintains persistence by modifying the Image File Execution Options (IFEO) registry key. Which of the following best describes how this technique works?

A.The malware adds a new service that runs under the context of the SYSTEM account.
B.The malware sets the 'Debugger' value for a legitimate process, causing the debugger to execute instead of the intended process.
C.The malware creates a shortcut in the Startup folder to launch automatically.
D.The malware modifies the 'Shell' value in the Winlogon registry key to execute on user logon.
AnswerB

IFEO allows developers to attach a debugger to a process. Malware can abuse this by setting the 'Debugger' value under the IFEO key for a legitimate process (e.g., notepad.exe) to point to a malicious executable. When the legitimate process is launched, the malicious 'debugger' runs instead, achieving persistence and potentially privilege escalation.

Why this answer

Image File Execution Options (IFEO) is a registry key that allows setting a debugger for a specific executable. Malware abuses this by setting the Debugger value to its own binary, so when the targeted process is launched, the malicious debugger runs instead. This provides persistence and can be used to hijack trusted processes, making detection challenging.

Exam trap

The trap here is confusing IFEO with other persistence mechanisms like services or Winlogon; IFEO specifically uses the Debugger value to redirect execution.

788
MCQhard

An organization wants to ensure that a user cannot deny having sent an email. Which security goal does this address?

A.Non-repudiation
B.Availability
C.Integrity
D.Confidentiality
AnswerA

Non-repudiation provides cryptographic proof of origin through digital signatures, binding the sender's identity to the message so they cannot later deny sending it. This directly satisfies the scenario's requirement that a user cannot deny having sent an email, unlike confidentiality, integrity or availability goals.

Why this answer

Non-repudiation ensures that a party cannot deny having performed a specific action, such as sending an email. This is typically achieved through digital signatures using asymmetric cryptography (e.g., RSA or ECDSA) and public key infrastructure (PKI), where the sender's private key creates a signature that can be verified by anyone with the sender's public key. The goal is to provide irrefutable proof of origin and integrity, preventing the sender from later claiming they did not send the message.

Exam trap

Cisco often tests the distinction between integrity and non-repudiation, where candidates mistakenly choose integrity because they associate hashing with proof of origin, but integrity alone does not link the data to a specific sender.

How to eliminate wrong answers

Option B (Availability) is wrong because availability ensures that systems and data are accessible when needed, often through redundancy and fault tolerance, not by preventing denial of actions. Option C (Integrity) is wrong because integrity guarantees that data has not been altered in transit or storage, typically via hashing (e.g., SHA-256) or checksums, but does not tie an action to a specific user. Option D (Confidentiality) is wrong because confidentiality protects data from unauthorized disclosure using encryption (e.g., AES or TLS), but does not provide proof of origin or prevent repudiation.

789
MCQmedium

Refer to the exhibit. An analyst sees this syslog message from a Cisco ASA. What does this log entry indicate?

A.The access-group 'OUTSIDE_IN' permitted the traffic.
B.An internal host attempted to connect to an external web server.
C.An external host attempted to connect to an internal web server and was blocked.
D.The ASA allowed the connection because it is a stateful firewall.
AnswerC

Matches the deny action and direction.

Why this answer

The syslog message shows a deny action for traffic from an external IP (10.10.10.10) to an internal IP (192.168.1.100) on TCP port 443 (HTTPS). The access-group 'OUTSIDE_IN' is applied to the outside interface, and the deny indicates the packet was blocked by an ACL entry. This matches the scenario of an external host attempting to connect to an internal web server and being blocked.

Exam trap

Cisco often tests the ability to interpret syslog message fields (source/destination IPs and ports) to determine traffic direction and action, and the trap here is assuming that any syslog message from an ASA implies a permitted connection, when the 'deny' keyword clearly indicates a block.

How to eliminate wrong answers

Option A is wrong because the log entry explicitly shows 'deny', meaning the access-group 'OUTSIDE_IN' blocked the traffic, not permitted it. Option B is wrong because the source IP (10.10.10.10) is external (not RFC 1918), and the destination IP (192.168.1.100) is internal, indicating an inbound connection from outside to inside, not an internal host connecting outbound. Option D is wrong because while the ASA is stateful, the log entry shows a deny action, meaning the connection was not allowed; stateful inspection would only permit traffic that matches an existing session or an explicit permit ACL.

790
MCQmedium

During the Containment, Eradication, and Recovery phase, the incident response team collects evidence from a compromised system. Which document is used to record the chain of custody?

A.Data classification policy
B.Acceptable Use Policy
C.Incident response plan
D.Chain of custody form
AnswerD

The chain of custody form records each transfer, handler, timestamp and storage location of evidence. Completing it during collection creates the auditable trail proving the evidence was never tampered with, which is required for it to be admissible.

Why this answer

Chain of custody documentation tracks who handled evidence from collection to court presentation.

791
MCQhard

A threat hunter identifies a binary that uses a Domain Generation Algorithm (DGA) to create domain names like 'eksdghf23.com', 'mzncxv89.net' each day. The malware contacts these domains over HTTPS. Which phase of the Cyber Kill Chain is most directly associated with this technique?

A.Installation
B.Exploitation
C.Command and Control
D.Actions on Objectives
AnswerC

DGA-generated domains provide resilient command and control infrastructure, letting malware receive instructions and exfiltrate data despite takedown attempts. The HTTPS beaconing to algorithmically generated names is the defining C2 signature, directly satisfying the stem's requirement to identify the Cyber Kill Chain phase for this technique.

Why this answer

The use of a DGA to generate domain names that the malware contacts over HTTPS is the defining characteristic of the Command and Control (C2) phase. The malware is attempting to reach its operator's infrastructure to receive instructions or send data. This occurs after the malware is installed and before the attacker achieves their objectives.

Exam trap

The trap is confusing C2 with Installation or Actions on Objectives — candidates may see 'malware contacts domains' and think Installation, or see 'HTTPS' and think exfiltration (Actions on Objectives), but the key is that DGA beaconing is the C2 channel.

How to eliminate wrong answers

Option A is wrong because Installation refers to the malware being placed on the system (e.g., via a dropper), not the subsequent beaconing to DGA domains. Option B is wrong because Exploitation is the phase where a vulnerability is leveraged to execute code, which happens before C2. Option D is wrong because Actions on Objectives is the final phase where the attacker accomplishes their goal (data theft, destruction), which follows C2 establishment.

792
MCQmedium

A company's security policy requires that sensitive data be encrypted at rest using AES-256. Which type of encryption does AES-256 represent?

A.Hashing algorithm
B.Digital signature
C.Asymmetric encryption
D.Symmetric encryption
AnswerD

AES-256 uses a single shared secret key for both encryption and decryption, making it symmetric. Asymmetric algorithms such as RSA instead use a public-private key pair. The policy's requirement for AES-256 therefore specifies symmetric encryption, not hashing or asymmetric cryptography.

Why this answer

AES-256 is a symmetric encryption algorithm, meaning it uses the same key for both encryption and decryption. It is widely used for data at rest due to its strength and efficiency. The '256' refers to the key size in bits, making it highly resistant to brute-force attacks.

Exam trap

The trap is confusing symmetric and asymmetric encryption. Candidates might think AES is asymmetric because it's strong, but the key characteristic is that it uses a single shared key. Also, hashing is sometimes mistaken for encryption, but it's irreversible.

How to eliminate wrong answers

Option A is wrong because a hashing algorithm (e.g., SHA-256) is a one-way function used for integrity, not encryption; it does not use a key and cannot be decrypted. Option B is wrong because a digital signature uses asymmetric cryptography to provide authenticity and integrity, not symmetric encryption. Option C is wrong because asymmetric encryption (e.g., RSA) uses a key pair (public and private), while AES is symmetric.

793
MCQeasy

A junior analyst is asked to determine which log source would best reveal an attacker attempting to authenticate to a Windows file server with stolen credentials over the network. Which source should the analyst consult first?

A.Windows Security event log entries for logon events, including the logon type and source workstation fields.
B.Application event log entries written by the installed line-of-business database engine.
C.Windows System event log entries generated by the Service Control Manager during service start and stop.
D.Windows Defender operational log entries recording scheduled scan completion status.
AnswerA

Security event IDs 4624 and 4625 capture successful and failed logons with fields such as Logon Type and Source Network Address, which directly expose network authentication attempts against the server. Logon Type 3 indicates a network logon such as SMB, making this the most direct evidence of credential use against the file server in the scenario.

Why this answer

Network authentication against a Windows file server is recorded in the Security log as logon events, which include the account, logon type, and originating address. Correlating successful and failed entries reveals password spraying, credential stuffing, or lateral movement with stolen credentials, making the Security log the correct first source for this question.

Exam trap

The trap here is choosing a log by file name familiarity instead of by the security question being asked, when only the Security log records account authentication events.

794
MCQhard

An analyst is investigating a potential data exfiltration incident. The only available data is NetFlow records from Cisco routers. Which NetFlow field would be most useful to identify large outbound transfers to an unusual external host?

A.Input interface and output interface
B.Next-hop IP address and autonomous system number
C.Destination IP address and byte count
D.Source port and TCP flags
AnswerC

NetFlow records include source/destination IP, ports, protocol, and byte/packet counts. To identify large outbound transfers, the destination IP and byte count are critical. An unusual external host receiving a high volume of bytes from an internal host suggests exfiltration. Other fields like source port or TCP flags are less directly indicative of data volume.

Why this answer

NetFlow records capture metadata about flows, including source/destination IP, ports, protocol, and byte/packet counts. To detect large outbound transfers to an unusual external host, the analyst should focus on the destination IP address and the byte count. A high byte count from an internal host to an external IP that is not a known service indicates potential exfiltration.

Other fields like source port, TCP flags, or interface information provide context but are not as directly useful for identifying data volume.

Exam trap

The trap here is focusing on connection-oriented fields like TCP flags or ports, which indicate the nature of the connection but not the volume of data transferred.

795
MCQhard

An analyst is investigating lateral movement and observes SMB authentication attempts from host A to multiple other hosts using NTLM authentication with a hash value instead of a password. Which attack technique is most likely being used?

A.Pass-the-hash attack
B.Brute force attack
C.Kerberos golden ticket attack
D.SMB relay attack
AnswerA

Pass-the-hash exploits NTLM's design, where the password hash itself authenticates without knowing the plaintext. Replaying a captured hash across multiple hosts via SMB produces exactly the observed pattern of lateral authentication attempts, distinguishing it from credential guessing or Kerberos abuse.

Why this answer

Pass-the-hash exploits the NTLM challenge-response protocol by replaying a captured NTLM hash directly to authenticate, without ever needing the plaintext password. The tell-tale sign is SMB authentication where the credential material is a hash rather than a password, especially when one host authenticates to many others in a fan-out pattern typical of lateral movement. Tools like Mimikatz, Impacket's psexec.py, and CrackMapExec perform this by injecting the hash into the NTLM authentication exchange.

Exam trap

200-201 often tests the distinction between pass-the-hash (replaying a stolen hash) and SMB relay (forwarding someone else's authentication) — candidates confuse the two because both involve NTLM and SMB lateral movement.

How to eliminate wrong answers

Option B is wrong because brute force involves repeatedly guessing passwords against an authentication service, producing many failed logon events (4625) rather than successful hash-based authentications. Option C is wrong because a Kerberos golden ticket forges a TGT using the KRBTGT account hash and is validated via Kerberos (port 88), not NTLM over SMB. Option D is wrong because an SMB relay forwards a victim's authentication to a third-party server to impersonate the victim; it does not involve the attacker supplying a hash directly from host A to multiple targets.

796
MCQmedium

An analyst is reviewing Windows Event Logs and finds Event ID 4648. What does this event typically indicate?

A.A failed logon attempt
B.An account creation event
C.A successful logon event
D.A logon using explicit credentials
AnswerD

Event ID 4648 is generated when a process explicitly supplies alternate credentials for a logon, such as RunAs or scheduled tasks using stored credentials. It records the target account and the subject initiating it, distinguishing explicit credential use from ordinary interactive logons.

Why this answer

Windows Security Event ID 4648 is logged when a process attempts an explicit-credential logon — that is, when a user or service supplies alternate credentials (via runas, New-PSSession -Credential, or similar) rather than using the current session's token. It records the account that requested the logon and the account whose credentials were used.

Exam trap

200-201 often tests the confusion between 4648 (explicit credentials) and 4624 (successful logon) — candidates pick 4624 because both involve credentials, missing that 4648 specifically flags alternate-credential use.

How to eliminate wrong answers

Option A is wrong because failed logon attempts are Event ID 4625 (with substatus codes explaining the failure reason). Option B is wrong because account creation is Event ID 4720 (and 4722 for enablement). Option C is wrong because a successful interactive logon is Event ID 4624, which logs the logon type (2, 3, 10, etc.) and the resulting session.

797
Multi-Selecteasy

Which TWO actions are characteristic of a port scan performed by an attacker? (Choose two.)

Select 2 answers
A.Using TCP SYN packets without completing the three-way handshake.
B.Sending multiple connection requests to various ports on a single host.
C.Randomly selecting target ports without any pattern.
D.Spoofing the source IP address to evade detection.
E.Sending packets at a very low rate to avoid triggering threshold-based alerts.
AnswersA, B

A SYN scan sends TCP SYN packets to target ports and never completes the three-way handshake, so no full connection is established. This half-open technique lets the attacker map open ports quickly and stealthily, avoiding application-level logging.

Why this answer

Option A is correct because a TCP SYN scan (half-open scan) sends SYN packets and never completes the three-way handshake — the attacker replies to any SYN/ACK with RST or simply ignores it, which is the defining behavior of tools like Nmap's default -sS scan. Option B is correct because a port scan's core purpose is probing many ports on a single host (or a set of hosts) with connection attempts to discover which services are listening, whether via TCP connect, SYN, FIN, or UDP probes. Option C is not characteristic: port scans typically iterate through ports sequentially or in a defined list/range (e.g., 1-1024 or top-1000), and random port selection is more associated with evasion or worm behavior than with a standard scan.

Option D is not inherent to port scanning; source IP spoofing would prevent the attacker from receiving SYN/ACK or RST responses needed to determine port state, so it is used in other attack types (e.g., DoS reflection), not normal scanning. Option E is not characteristic either: while slow scanning (e.g., Nmap -T0/-T1) can evade threshold-based IDS alerts, it is an optional evasion technique, not a defining action of a port scan, which is normally fast and noisy.

Exam trap

Cisco often tests the distinction between a port scan's core mechanism (SYN packets without completing the handshake) and optional evasion techniques (like low rate or IP spoofing), leading candidates to mistakenly choose evasion methods as defining characteristics.

798
MCQeasy

A security analyst discovers that a malicious actor is using a technique to gather information about employees by searching social media sites. Which type of attack is being performed?

A.Active reconnaissance
B.Passive reconnaissance
C.Denial of Service
D.Social engineering
AnswerB

Searching social media for employee details involves no direct interaction with the target's systems, so nothing is sent that could trigger detection. That absence of engagement with the target's infrastructure is precisely what makes it passive reconnaissance rather than active scanning.

Why this answer

Passive reconnaissance involves gathering information about a target without directly interacting with its systems, such as searching public social media sites for employee details. Because the attacker only observes publicly available data and does not send packets or queries to the target's infrastructure, it is classified as passive. This contrasts with active reconnaissance, which involves direct interaction (e.g., port scanning).

Exam trap

The trap is confusing passive reconnaissance with social engineering — both involve people, but social engineering requires interaction/deception, while passive reconnaissance only observes public information without contacting the target.

How to eliminate wrong answers

Option A is wrong because active reconnaissance requires direct interaction with the target (e.g., scanning, banner grabbing), which is not occurring when merely browsing social media. Option C is wrong because a Denial of Service attack aims to disrupt availability, not gather employee information. Option D is wrong because social engineering involves manipulating people into divulging information or performing actions, whereas here the attacker is only collecting publicly posted data without deception or interaction.

799
MCQhard

An attacker intercepts communication between a client and a server, allowing the attacker to read, insert, and modify messages in both directions. Which type of network attack is this?

A.Denial of Service
B.ARP spoofing
C.DNS poisoning
D.Man-in-the-middle
AnswerD

A man-in-the-middle attack places the adversary between client and server, relaying traffic while reading, inserting and modifying messages in both directions. This active interception, rather than passive eavesdropping or denial of service, matches the bidirectional read-write-modify capability described in the scenario.

Why this answer

A man-in-the-middle (MITM) attack occurs when an attacker intercepts and relays communication between two parties, allowing them to read, insert, and modify messages. This matches the scenario exactly. The attacker positions themselves between the client and server, often without either party's knowledge.

Exam trap

The trap here is confusing MITM with specific techniques like ARP spoofing or DNS poisoning; the question describes the outcome, not the method.

How to eliminate wrong answers

Option A is wrong because a Denial of Service attack aims to disrupt availability, not intercept and modify communications. Option B is wrong because ARP spoofing is a technique to facilitate MITM on a local network, but it is not the attack type itself; the question describes the broader MITM attack. Option C is wrong because DNS poisoning redirects traffic to malicious sites but does not inherently allow bidirectional message modification.

800
Multi-Selectmedium

A threat hunter is examining a Linux web server that is suspected of being compromised. The hunter wants to identify suspicious processes that may be communicating with external command-and-control infrastructure and to understand what files those processes have open. Which TWO artifacts or commands should the hunter use to accomplish these goals? (Choose two.)

Select 2 answers
A.Review /var/log/secure for failed authentication attempts
B.Run 'ss -tunap' to enumerate listening and established sockets with their owning processes
C.Inspect /proc/<pid>/net/tcp and /proc/<pid>/fd to map network sockets and open file descriptors for each process
D.Parse the wtmp and btmp binary logs with the 'last' command
E.Examine /etc/crontab for scheduled jobs
AnswersB, C

The ss utility with -tunap lists TCP, UDP, and Unix sockets, including established connections and the process name and PID that owns each socket. This directly exposes outbound connections to external addresses and identifies the responsible process, which is precisely what the hunter needs to spot C2 communication on the compromised web server.

Why this answer

Mapping C2 traffic and open files on Linux requires live process-to-socket visibility. The ss command with -tunap enumerates sockets together with owning processes, exposing established outbound connections. The /proc filesystem complements this by exposing per-process socket inodes and open file descriptors, letting the hunter pivot from a suspicious PID to the exact files and connections it holds.

Together they reveal both the communication channel and the process context.

Exam trap

The trap here is gravitating toward log files like /var/log/secure or cron because they are familiar, when the scenario asks specifically about live process network and file-descriptor visibility.

801
Multi-Selecthard

A SOC analyst is reviewing proxy logs and wants to identify indicators of potential data exfiltration over HTTP. Which two patterns should the analyst treat as suspicious? (Choose two.)

Select 2 answers
A.Large outbound POST requests to a single external IP address at regular intervals.
B.Outbound connections to a newly registered domain with a high volume of data uploaded.
C.HTTP 404 errors generated by users mistyping URLs in the browser.
D.Repeated GET requests to the same internal web server for static images.
E.Downloading software updates from a known vendor's HTTPS site.
AnswersA, B

Large outbound POST requests at regular intervals suggest automated data transfer to an external host. Legitimate user browsing rarely produces consistent, large uploads on a schedule. This pattern is consistent with exfiltration tools that beacon or upload data in chunks, making it a suspicious indicator worth investigating.

Why this answer

Exfiltration over HTTP often appears as large outbound uploads, especially to new or untrusted destinations. Regular large POST requests and high-volume uploads to newly registered domains both indicate data leaving the environment in a manner inconsistent with normal business traffic. These patterns warrant deeper investigation.

Exam trap

The trap here is focusing on inbound downloads or benign errors, when exfiltration is characterized by outbound uploads to suspicious destinations.

802
MCQeasy

During network intrusion analysis, an analyst observes a TCP connection with the SYN flag set but no subsequent ACK. This pattern is indicative of:

A.SYN flood attack
B.DNS resolution
C.Normal three-way handshake
D.ICMP echo request
AnswerA

A SYN flood exploits the TCP three-way handshake by sending numerous SYN packets without completing the ACK, exhausting the server's half-open connection backlog. The stem's single SYN-without-ACK pattern directly matches this mechanism, confirming the attack type observed during intrusion analysis.

Why this answer

A SYN flood attack is a type of denial-of-service (DoS) attack where the attacker sends a high volume of TCP SYN packets to a target server but never completes the three-way handshake by sending the final ACK. This leaves the server with half-open connections, consuming resources and potentially exhausting the connection backlog, which prevents legitimate clients from establishing connections.

Exam trap

Cisco often tests the distinction between a normal three-way handshake and an incomplete handshake pattern, where candidates mistakenly think any SYN packet indicates a legitimate connection attempt rather than recognizing the missing ACK as the hallmark of a SYN flood.

How to eliminate wrong answers

Option B is wrong because DNS resolution uses UDP (or TCP for zone transfers) and does not involve TCP SYN flags; it relies on query/response pairs over port 53. Option C is wrong because a normal three-way handshake requires a SYN, SYN-ACK, and then an ACK; the absence of the final ACK indicates an incomplete handshake, not a normal one. Option D is wrong because ICMP echo request is a network-layer diagnostic message (type 8) that does not use TCP flags or ports; it operates at the Internet layer and is not part of TCP connection establishment.

803
MCQeasy

A SOC Tier 1 analyst receives an alert for a potential malware infection. What is the primary responsibility of the Tier 1 analyst?

A.Communicate with the media
B.Develop detection signatures
C.Conduct advanced malware analysis
D.Perform initial triage and basic investigation
AnswerD

Tier 1 handles alert monitoring and initial triage, validating whether an alert is a true positive and gathering basic evidence before escalation. Deep malware reverse engineering and enterprise-wide containment decisions belong to Tier 2 or Tier 3, so basic investigation is the correct scope.

Why this answer

Tier 1 analysts monitor alerts and perform initial triage to determine if further investigation is needed.

804
Multi-Selectmedium

A SOC Tier 3 analyst is performing advanced threat analysis. Which TWO activities are typical for this tier?

Select 2 answers
A.Forensic analysis of compromised systems
B.Correlating multiple alerts
C.Monitoring SIEM dashboards
D.Initial triage of alerts
E.Threat hunting
AnswersA, E

Forensic analysis of compromised systems involves deep-diving into artefacts, memory, and disk images to determine attacker techniques and scope. This is a Tier 3 activity because it requires advanced expertise beyond Tier 1 triage or Tier 2 escalation, satisfying the advanced threat analysis requirement.

Why this answer

Forensic analysis of compromised systems (A) is a Tier 3 activity because it requires deep expertise in memory, disk, and artifact examination to reconstruct attacker actions and determine root cause. Threat hunting (E) is also typical for Tier 3, as it involves proactively searching for hidden adversaries using hypotheses, advanced analytics, and tools beyond routine alert handling. In contrast, correlating multiple alerts (B) and initial triage of alerts (D) are generally Tier 1 or Tier 2 responsibilities, and monitoring SIEM dashboards (C) is a routine Tier 1 monitoring task rather than advanced analysis.

805
MCQmedium

A NetFlow analysis shows that a single internal IP sent 10 GB of data to an external IP within one hour, whereas the baseline for that host is typically 100 MB per day. Which type of activity does this indicate?

A.Denial of service attack
B.Network scanning
C.Normal business activity
D.Data exfiltration
AnswerD

A single host transferring 10 GB externally within an hour, vastly exceeding its 100 MB daily baseline, indicates bulk data movement outbound. This volume anomaly, visible in NetFlow byte counters, is characteristic of data exfiltration rather than normal business traffic or routine backup activity.

Why this answer

The massive outbound transfer of 10 GB from an internal host to an external IP, far exceeding the 100 MB/day baseline, is a classic indicator of data exfiltration. Exfiltration involves unauthorized data transfer from inside the network to an external destination, often after a compromise. The volume and direction (internal to external) align with this activity, not with inbound flooding or scanning.

Exam trap

The trap here is confusing the direction and volume of traffic: candidates might associate large transfers with DoS or scanning, but exfiltration is characterized by outbound data from internal to external, often in large volumes.

How to eliminate wrong answers

Option A is wrong because a denial of service attack typically involves a high volume of inbound traffic or resource exhaustion, not a large outbound transfer from a single internal host. Option B is wrong because network scanning generates many small connections to multiple ports or hosts, not a single large outbound data transfer. Option C is wrong because normal business activity would not deviate so drastically from the established baseline without a known business justification.

806
MCQmedium

An analyst is investigating a Linux web server that is exhibiting unusual outbound network traffic. The analyst runs 'lsof -i' and notices that the process 'apache2' has an established connection to an external IP address on port 4444. Further investigation shows that a file named 'update.php' in the web root contains obfuscated code. Which type of compromise does this most likely represent?

A.A web shell providing remote command and control
B.A scheduled backup process transferring data to a remote server
C.A legitimate plugin communicating with an update server
D.A misconfigured Apache module causing unexpected connections
AnswerA

A web shell is a malicious script uploaded to a web server that allows remote attackers to execute commands and maintain persistence. The outbound connection on a non-standard port like 4444 (often used by Metasploit) from the web server process suggests a reverse shell initiated by the web shell. The obfuscated PHP file is a common indicator.

Why this answer

The combination of an outbound connection from the web server process on a common reverse shell port (4444) and an obfuscated PHP file in the web root is a classic indication of a web shell. Attackers use web shells to execute commands and maintain access, often leading to data exfiltration or further network compromise.

Exam trap

The trap here is assuming the connection is benign because it originates from a legitimate process, ignoring the suspicious port and obfuscated file.

807
MCQhard

A security analyst is investigating a Linux server that is exhibiting unusual outbound network traffic. The analyst runs 'netstat -tulpn' and observes a listening service on TCP port 4444, but the process name is 'sshd'. The analyst knows that SSH normally listens on port 22. Which of the following is the most likely explanation for this finding?

A.The server is running an SSH honeypot on port 4444 to attract attackers.
B.A backdoor or reverse shell is masquerading as the SSH daemon.
C.The SSH daemon is configured to use port 4444 for SFTP transfers only.
D.The SSH daemon has been reconfigured to listen on port 4444 for security through obscurity.
AnswerB

Attackers often name malicious processes after legitimate services like 'sshd' to avoid detection. Port 4444 is commonly used by Metasploit and other penetration testing tools for reverse shells. The combination of an unexpected port and a process name that does not match the expected behavior (SSH on port 22) strongly indicates a backdoor or reverse shell masquerading as sshd.

Why this answer

The presence of a service named 'sshd' listening on port 4444, especially with unusual outbound traffic, is a red flag for a backdoor or reverse shell. Attackers frequently use common ports like 4444 for command-and-control and name their processes after legitimate services to blend in. Legitimate SSH should listen on port 22 unless explicitly changed, and such a change would be documented.

Exam trap

The trap here is assuming that a process with a familiar name like 'sshd' is benign, but attackers can easily rename their malicious binaries.

808
MCQhard

A security analyst is reviewing Zeek connection logs and sees the following entry: '192.168.1.10:12345 > 10.0.0.1:80 (tcp) duration 0.001 sec, service http, bytes 60, state S0'. Based on the state 'S0', what does this indicate about the connection?

A.Data was transferred successfully and the connection closed normally.
B.A SYN packet was sent but no reply was received.
C.The connection was established successfully.
D.The connection was reset by the remote host.
AnswerB

Zeek's S0 state records a connection attempt where the originator sent a SYN but received no SYN-ACK, so the handshake never completed. This matches the stem's unanswered SYN, distinguishing it from established (SF) or reset (RST) states.

Why this answer

In Zeek, S0 indicates that a SYN packet was sent but no SYN-ACK was received (connection attempt without completion). This could be part of a port scan or a half-open connection.

809
Multi-Selecteasy

Which TWO of the following are typical indicators of a C2 beaconing communication?

Select 2 answers
A.Regular intervals of communication at consistent times
B.Large outbound data transfers to an external IP
C.Multiple failed login attempts from a single source
D.ICMP echo requests to multiple hosts
E.DNS queries for domains that are rarely visited
AnswersA, E

Beaconing malware contacts its command-and-control server on a fixed schedule, so traffic recurs at predictable intervals rather than randomly. This periodicity, often with consistent packet sizes, distinguishes automated beaconing from bursty human browsing and satisfies the stem's requirement for a typical C2 indicator.

Why this answer

Option A is correct because C2 beaconing is characterized by periodic check-ins from an infected host to its command-and-control server, producing highly regular, consistent communication intervals (often with jitter added to evade detection). Option E is correct because beaconing frequently abuses DNS for command-and-control or data exfiltration, generating queries to unusual, rarely visited, or algorithmically generated (DGA) domains that stand out against normal browsing patterns. Option B is not typical of beaconing itself, since beaconing traffic is usually small and low-volume; large outbound transfers suggest exfiltration rather than the beacon check-in.

Option C describes a brute-force or password-guessing attack, not C2 beaconing. Option D describes ICMP echo requests (ping sweeps) used for host discovery or network reconnaissance, not command-and-control beaconing.

Exam trap

200-201 often tests whether candidates can distinguish C2 beaconing (small, periodic callbacks) from exfiltration (large outbound transfers) — the word 'outbound' in both options is the bait.

810
MCQeasy

An analyst is reviewing Windows Event Logs and sees Event ID 4625. What does this event indicate?

A.Credential validation was attempted
B.An account logon failed
C.An account was created
D.An account was successfully logged on
AnswerB

Windows Event ID 4625 is logged in the Security log whenever a logon attempt fails, recording the account, source workstation and failure reason. It directly satisfies the stem's requirement to identify what this event indicates.

Why this answer

Event ID 4625 in the Security log indicates a failed logon attempt. This is often used to detect brute-force attacks or unauthorized access attempts.

811
MCQhard

An organization is conducting a risk assessment and wants to assign numerical values to the likelihood and impact of risks. Which type of risk assessment is being performed?

A.Quantitative risk assessment
B.Operational risk assessment
C.Qualitative risk assessment
D.Hybrid risk assessment
AnswerA

Quantitative risk assessment assigns numerical values to both likelihood and impact, satisfying the stem's requirement for numeric scoring. Unlike qualitative methods, which use descriptive scales such as high, medium or low, it enables arithmetic calculation of expected loss and direct cost-benefit comparison of controls.

Why this answer

Quantitative risk assessment uses numerical values (e.g., monetary, percentages) to calculate risk.

812
MCQmedium

An analyst is investigating a Windows system where a suspicious executable is running. Using Process Explorer, the analyst observes that the process 'svchost.exe' has a parent process of 'cmd.exe'. What is the significance of this parent-child relationship?

A.It shows that svchost.exe is a critical system process and is safe
B.It indicates that svchost.exe is likely malicious, as it should be spawned by services.exe
C.It suggests that svchost.exe is a child of explorer.exe, which is normal
D.It is normal behavior; svchost.exe often has cmd.exe as parent
AnswerB

Legitimate svchost.exe instances are launched by services.exe, so a cmd.exe parent reveals a process masquerading under that name — a common malware technique. The anomalous parentage, not the filename itself, is the indicator satisfying the scenario's suspicious-executable constraint.

Why this answer

Legitimate svchost.exe processes are spawned by services.exe, not cmd.exe. A parent of cmd.exe indicates that svchost.exe was launched manually, which is abnormal and suggests malicious activity.

813
MCQhard

A security analyst is examining a Windows 10 host that is suspected of being compromised. The analyst runs `wmic process get name,processid,executablepath,commandline` and notices a process named `svchost.exe` with an executable path of `C:\Users\Public\svchost.exe`. Which conclusion is most accurate?

A.The process is a legitimate svchost.exe because the name matches the system process.
B.The process is a legitimate svchost.exe running from a non-standard location due to a Windows update.
C.The process is likely malware masquerading as svchost.exe.
D.The process is likely a legitimate svchost.exe that was copied to the Public folder by a user.
AnswerC

Legitimate svchost.exe processes reside in %SystemRoot%\System32. An instance running from C:\Users\Public is a strong indicator of malware, as attackers often name their binaries after system processes and place them in user-writable directories to evade detection. The analyst should investigate further, such as checking digital signatures and parent process.

Why this answer

Legitimate svchost.exe always runs from %SystemRoot%\System32\svchost.exe. An instance with an executable path in C:\Users\Public is almost certainly malware masquerading as a system process. Attackers use this technique to blend in with normal system activity.

Analysts should verify the digital signature, parent process, and loaded modules to confirm maliciousness.

Exam trap

The trap here is trusting the process name and assuming it is legitimate, when the executable path is the key indicator of masquerading.

814
MCQhard

A security analyst is investigating an incident where an employee received an email that appeared to be from the company's IT department, requesting the employee to verify their account by clicking a link and entering their credentials. The employee complied, and later the attacker used those credentials to access the corporate VPN. Which combination of attack types best describes this incident?

A.Pretexting and privilege escalation
B.Phishing and man-in-the-middle
C.Spear phishing and credential theft
D.Vishing and brute force
AnswerC

The email targeted a specific employee while impersonating internal IT, which is spear phishing rather than generic phishing. The captured credentials were then reused to access the corporate VPN, directly constituting credential theft, matching both elements the scenario describes.

Why this answer

The incident involves a targeted email that appears to be from the IT department, requesting credential verification—this is spear phishing because it's tailored to the organization. The employee providing credentials leads to credential theft, which the attacker then uses to access the VPN. Thus, spear phishing and credential theft best describe the attack.

Exam trap

The trap is misclassifying the attack as pretexting or man-in-the-middle. Pretexting is a component of spear phishing but not the primary label; man-in-the-middle requires interception. Candidates might also think privilege escalation occurred because the attacker accessed the VPN, but that's unauthorized access, not escalation.

How to eliminate wrong answers

Option A is wrong because pretexting involves creating a fabricated scenario, but here the primary attack is phishing; privilege escalation did not occur—the attacker used existing credentials, not elevated privileges. Option B is wrong because man-in-the-middle involves intercepting communications, which is not described; the attacker directly used stolen credentials. Option D is wrong because vishing is voice phishing (phone), and brute force involves guessing passwords, neither of which occurred.

815
Multi-Selectmedium

An analyst investigates a suspected data exfiltration event and captures outbound traffic from a compromised host. The traffic uses HTTPS to an unfamiliar external domain and shows consistent large uploads at regular intervals. Which two indicators would most strongly support the conclusion that this is automated exfiltration rather than normal user browsing? (Choose two.)

Select 2 answers
A.The connection uses TLS version 1.2
B.The TLS certificate uses a self-signed issuer
C.The uploads occur at fixed intervals with near-identical byte counts
D.The destination domain was registered recently and has no reputation history
E.The client sends data without any corresponding inbound user-driven requests
AnswersC, E

Automated exfiltration tools typically beacon or upload on a schedule with consistent payload sizes, producing regular intervals and near-identical byte counts. Human browsing is irregular in both timing and volume. This periodicity and uniformity are strong behavioral indicators that a script or malware, not a person, is generating the traffic, making it a reliable discriminator in this scenario.

Why this answer

Automated exfiltration is best identified by behavior: uploads at fixed intervals with near-identical sizes indicate a scheduled tool, and outbound data with no matching user-driven inbound requests shows the transfer is not interactive browsing. Domain age, certificate issuer, and TLS version describe infrastructure or protocol choices that legitimate and malicious traffic share, so they are weaker indicators and do not specifically demonstrate automation.

Exam trap

The trap here is favoring infrastructure clues like new domains or self-signed certificates over behavioral patterns that actually reveal automation.

816
MCQeasy

During a security audit, an analyst discovers that several employees have shared their login credentials with colleagues to expedite work. Which policy enforcement mechanism would be most effective in preventing this behavior?

A.Implement a password complexity policy.
B.Implement multi-factor authentication.
C.Enforce a password change policy every 30 days.
D.Conduct annual security awareness training.
AnswerB

Multi-factor authentication binds each login to a second factor the colleague lacks, so a shared password alone no longer grants access. This directly defeats credential sharing, which password policies or awareness training cannot reliably prevent.

Why this answer

Multi-factor authentication (MFA) is the most effective enforcement mechanism because it requires a second factor (e.g., a one-time passcode from an authenticator app, a hardware token, or a biometric) in addition to the password. Even if employees share their passwords, MFA prevents unauthorized access because the second factor is tied to the individual's device or identity and cannot be easily shared. This directly addresses the root cause of credential sharing by making shared credentials useless without the additional factor.

Exam trap

The trap here is that candidates often choose security awareness training (Option D) because it seems like a logical educational fix, but Cisco tests the distinction between administrative controls (training) and technical enforcement mechanisms (MFA) that actually prevent the behavior at the authentication layer.

How to eliminate wrong answers

Option A is wrong because a password complexity policy only enforces the strength of the password (e.g., length, character types) but does nothing to prevent users from voluntarily sharing those strong passwords with colleagues. Option C is wrong because enforcing a password change every 30 days may reduce the window of exposure but does not prevent sharing; users can simply share the new password after each change. Option D is wrong because annual security awareness training educates users about policy but relies on voluntary compliance and does not technically enforce or prevent the behavior; users may still share credentials despite knowing the policy.

817
MCQeasy

In the Cyber Kill Chain, which phase involves sending a malicious attachment to a targeted user?

A.Exploitation
B.Delivery
C.Weaponization
D.Reconnaissance
AnswerB

Delivery is the phase where the adversary transmits the weaponised payload — such as a malicious attachment or link — to the target. Exploitation occurs only after the user opens it, so transmission itself sits in Delivery.

Why this answer

In the Lockheed Martin Cyber Kill Chain, Delivery is the phase where the attacker transmits the weaponised payload to the victim — for example, via a phishing email with a malicious attachment, a malicious link, or a USB drop. Sending the malicious attachment to a targeted user is the textbook definition of Delivery. Weaponization (the prior phase) is where the attacker pairs the exploit with the payload, but the actual transmission to the target is Delivery.

Exam trap

200-201 often tests the boundary between Weaponization and Delivery — candidates pick Weaponization because the attachment is 'malicious', but the act of sending it is what defines Delivery.

How to eliminate wrong answers

Option A is wrong because Exploitation is when the delivered payload actually triggers a vulnerability to execute code on the target — it happens after delivery. Option C is wrong because Weaponization is the preparation step where the attacker couples malware with an exploit into a deliverable payload; nothing has been sent to the victim yet. Option D is wrong because Reconnaissance is information gathering (OSINT, scanning) that occurs before any payload is created or sent.

818
MCQeasy

A security analyst is reviewing the organization's password policy. The policy currently requires passwords to be at least 8 characters and changed every 60 days. The analyst recommends aligning with NIST SP 800-63B guidelines. Which change should the analyst recommend?

A.Increase the minimum password length to 12 characters and require complexity.
B.Remove the periodic password expiration and instead enforce a longer minimum length with a blocklist of common passwords.
C.Require passwords to be changed every 30 days to reduce the window of compromise.
D.Implement a requirement for passwords to include at least one special character and one number.
AnswerB

NIST SP 800-63B advises against arbitrary password expiration because it leads to weaker passwords and user frustration. Instead, it recommends a minimum length of 8 characters (preferably more) and checking new passwords against a list of compromised or common passwords. This approach improves security by preventing easily guessed passwords and reducing the need for frequent changes, which often result in incremental variations that attackers can predict.

Why this answer

The analyst should recommend removing periodic password expiration and instead enforcing a longer minimum length with a blocklist of common passwords. NIST SP 800-63B emphasizes that password expiration can degrade security by encouraging weak, predictable passwords. A blocklist prevents users from choosing easily guessed or compromised passwords, and a longer minimum length increases resistance to brute-force attacks.

This approach aligns with modern best practices and reduces the burden on users and help desk.

Exam trap

The trap here is assuming that frequent password changes and complexity requirements are always more secure, when NIST guidelines actually discourage them in favor of length and breach checks.

819
MCQmedium

A change management policy requires that all network configuration changes be approved by a change advisory board (CAB) before implementation. An urgent security vulnerability requires an immediate firewall rule change to block an active exploit. What should the network administrator do?

A.Convene an emergency CAB meeting before making the change
B.Apply the change immediately and then submit an emergency change request for post-approval
C.Ignore the vulnerability until the next scheduled CAB meeting
D.Wait for CAB approval to ensure compliance with policy
AnswerB

Emergency change procedures exist precisely for active exploits, where delay causes ongoing harm. Applying the firewall rule immediately contains the threat, then submitting an emergency change request for retrospective CAB approval satisfies the policy's governance intent without waiting for a convened board. This preserves both incident response speed and documented change accountability.

Why this answer

In an urgent security situation where an active exploit must be blocked immediately, the network administrator should apply the change immediately and then submit an emergency change request for post-approval. This aligns with ITIL change management practices, which allow for emergency changes to be implemented first and documented/approved afterward to address critical incidents.

Exam trap

200-201 often tests the application of change management principles in urgent situations, where candidates might rigidly adhere to pre-approval processes, not realizing that emergency changes allow for post-approval to mitigate immediate threats.

How to eliminate wrong answers

Option A is wrong because convening an emergency CAB meeting before making the change would delay the mitigation, potentially allowing the exploit to cause harm; emergency changes are designed to bypass the normal pre-approval process. Option C is wrong because ignoring the vulnerability until the next scheduled CAB meeting is negligent and could lead to a security breach. Option D is wrong because waiting for CAB approval, even in an emergency, could take too long and is not appropriate for an active exploit; emergency change procedures exist for this purpose.

820
MCQmedium

Refer to the exhibit. A security analyst notices repeated login failures. According to the company's security policy, what action should be taken?

A.Block the source IP at the firewall
B.Ignore because it's only three failures
C.Investigate for brute force attack
D.Disable the user account
AnswerC

Repeated login failures across accounts indicate credential-guessing activity, so investigating for brute force determines whether the pattern is an attack or user error. This satisfies the policy requirement to act on suspicious authentication behaviour before lockout or escalation.

Why this answer

Repeated login failures are a classic indicator of a brute-force attack, where an attacker attempts to guess credentials by trying many passwords. The security policy should require investigation to confirm the attack pattern (e.g., frequency, source, target accounts) before taking irreversible actions like blocking or disabling. Option C is correct because it follows the principle of verify-then-act, aligning with incident response procedures.

Exam trap

Cisco often tests the candidate's ability to distinguish between reactive actions (block, disable) and proper incident response steps (investigate first), where the trap is to jump to a technical fix without following the security policy's investigation requirement.

How to eliminate wrong answers

Option A is wrong because blocking the source IP at the firewall may be premature without confirming the attack is malicious (e.g., a user with a forgotten password could trigger failures) and could cause denial of service to legitimate users. Option B is wrong because three failures can be part of a larger brute-force attempt; security policies typically define thresholds (e.g., 5 failures in 5 minutes) that trigger investigation, not dismissal. Option D is wrong because disabling the user account without investigation could lock out a legitimate user and does not address the root cause (e.g., the account may not be the target; the attacker could be targeting multiple accounts).

821
MCQeasy

During the Cyber Kill Chain, which phase involves sending a malicious attachment to a target user via email?

A.Exploitation
B.Weaponization
C.Delivery
D.Reconnaissance
AnswerC

Delivery is the phase where the adversary transmits the weaponised payload to the victim, such as a malicious attachment sent by email. Exploitation occurs only after the user opens it, so delivery is the correct phase.

Why this answer

Delivery is the phase where the attacker transmits the weaponized payload to the target, such as via email attachments.

822
MCQhard

An analyst examining a PCAP sees an internal host sending ICMP echo requests where the payload length is consistently 1,100 bytes and the payload bytes change on every packet, while the destination is an external IP that returns echo replies of normal size. The host has no monitoring tool installed and no legitimate reason to send large ICMP. Which technique is most likely being used?

A.A ping flood denial-of-service attack against the external host.
B.Path MTU discovery using oversized ICMP packets to find fragmentation limits.
C.ICMP tunneling used to exfiltrate or relay data inside echo request payloads.
D.A smurf attack reflecting ICMP echo requests off the external host to a broadcast address.
AnswerC

Large, consistently sized ICMP echo requests with payloads that change on every packet indicate data is being carried inside the ICMP payload rather than standard reachability testing. Normal ping payloads are small and static, often a fixed pattern. The external host returning normal-sized replies fits a covert channel where the request carries the data outbound. This is a classic ICMP tunneling signature that warrants payload inspection and host isolation.

Why this answer

Normal ICMP echo traffic uses small, fixed payloads for reachability. Large echo requests whose payload changes on every packet indicate the ICMP payload is being used as a transport for data, a covert channel known as ICMP tunneling. The external endpoint returning ordinary replies supports a request-carries-data-out model.

Flood, MTU discovery, and smurf do not produce varying large payloads from a single internal host.

Exam trap

The trap here is treating any large ICMP packet as a denial-of-service or MTU issue, when varying payload contents inside echo requests reveal a covert data channel instead.

823
Multi-Selecthard

A security manager is preparing an incident response plan for a retail company. The plan must define how the organization will handle incidents consistently and must satisfy auditors. Which TWO elements are essential components of an incident response policy? (Choose two.)

Select 2 answers
A.A requirement to classify incidents by severity with corresponding escalation and notification criteria
B.A complete list of every vulnerability scanner signature and detection rule deployed in the environment
C.The exact command syntax used to isolate a compromised endpoint from the network
D.A copy of the organization's entire business continuity plan as an appendix
E.Clearly defined roles and responsibilities for the incident response team, including authority to act during an incident
AnswersA, E

Severity classification with escalation and notification criteria ensures incidents of similar impact are handled consistently and that the right stakeholders, including legal and executive management, are informed on time. This directly supports the scenario's need for consistent handling and provides auditors with a measurable decision framework. Without it, response effort and notifications become arbitrary.

Why this answer

An incident response policy governs how incidents are handled consistently by defining team roles, decision authority, and severity-based escalation and notification criteria. Those elements give responders clear direction and give auditors measurable expectations. Detection signatures, exact command syntax, and the full business continuity plan belong to tooling, procedures, or a separate discipline, so they are not essential policy components.

Exam trap

The trap here is treating highly technical operational details, such as scanner signatures or command syntax, as policy content, when a policy defines governance, roles, and decision criteria rather than technical execution.

824
MCQmedium

A security analyst is using Zeek to analyze network traffic. Which Zeek log would be most useful for identifying HTTP requests to a known malicious domain?

A.http.log
B.ssl.log
C.conn.log
D.dns.log
AnswerA

Zeek's http.log records HTTP request metadata including the Host header and URI, so requests to a known malicious domain are directly visible there. conn.log lacks application-layer detail, and dns.log only captures name resolution, not the subsequent HTTP request itself.

Why this answer

Zeek's http.log records all HTTP requests and responses, including the host header, URI, method, and user agent. To identify HTTP requests to a known malicious domain, the http.log is the most direct source because it contains the destination host and URL. Analysts can search this log for the malicious domain in the 'host' or 'uri' fields.

Exam trap

The trap is selecting dns.log because it shows domain lookups, but the question asks for HTTP requests, which are only fully captured in http.log; candidates must distinguish between resolution and actual request.

How to eliminate wrong answers

Option B is wrong because ssl.log records SSL/TLS handshake details and certificate information, but not the full HTTP request URL or host header, so it cannot directly show HTTP requests to a domain (though SNI may be present). Option C is wrong because conn.log records connection-level metadata (IPs, ports, duration, bytes) but not application-layer HTTP details like the requested domain or URI. Option D is wrong because dns.log records DNS queries and responses, which can show that a domain was resolved, but not the subsequent HTTP requests to that domain.

825
Multi-Selectmedium

A security operations center is building detection rules for man-in-the-middle attacks on its internal network. The team wants to identify techniques an attacker on the same Layer 2 segment could use to intercept or redirect traffic between two hosts. (Choose two.)

Select 2 answers
A.DNS cache poisoning to redirect a victim to an attacker-controlled server
B.On-path routing manipulation using forged ICMP redirect messages
C.VLAN hopping by double-tagging 802.1Q frames to reach another segment
D.ARP spoofing to associate the attacker's MAC address with the default gateway IP
E.MAC flooding to overflow the switch CAM table and force hub-like flooding
AnswersB, D

Forged ICMP redirects tell a host to send traffic for a destination through a different next hop, which can be the attacker's address. This places the attacker on the path between two hosts and enables interception or alteration. Detection looks for unexpected ICMP redirect messages and hosts accepting redirects when they should not.

Why this answer

ARP spoofing and forged ICMP redirects both manipulate how a host forwards traffic so the attacker becomes an on-path device, enabling interception and modification. ARP spoofing targets the mapping of IP to MAC on the local segment, while ICMP redirect manipulation alters the next-hop decision. Both are detectable through switch features such as dynamic ARP inspection and through monitoring for unexpected redirect messages.

Exam trap

The trap here is treating MAC flooding or VLAN hopping as interception methods, when they expose or redirect traffic without placing the attacker inline between the two communicating hosts.

Page 10

Page 11 of 13

Page 12