Courseiva

Cisco CyberOps Associate 200-201 (200-201) — Questions 826–900

968 questions total · 13pages · All types, answers revealed

Page 11

Page 12 of 13

Page 13
826
MCQeasy

A security analyst discovers that an attacker used a publicly available tool to scan a company's network for open ports and services. What type of attack is this?

A.Passive reconnaissance
B.Denial of Service
C.Social engineering
D.Active reconnaissance
AnswerD

Active reconnaissance involves directly interacting with target systems, such as port scanning with tools like Nmap, generating traffic the target can detect. This matches the stem's constraint of using a publicly available tool to scan for open ports and services.

Why this answer

Using a publicly available tool to scan a company's network for open ports and services involves directly interacting with the target systems by sending probes (e.g., TCP SYN packets, UDP datagrams) and analyzing responses. This constitutes active reconnaissance, as the attacker's actions generate traffic that can be detected by intrusion detection systems (IDS) or firewall logs, unlike passive methods that only observe existing traffic.

Exam trap

Cisco often tests the distinction between active and passive reconnaissance by presenting a scenario where a tool is used to 'scan' or 'probe' the network, and candidates mistakenly choose passive reconnaissance because they think 'scanning' is non-intrusive, but any direct interaction with the target (sending packets) is active.

How to eliminate wrong answers

Option A is wrong because passive reconnaissance involves gathering information without directly interacting with the target network, such as sniffing traffic or using public records (e.g., WHOIS, DNS lookups), not sending probes to identify open ports. Option B is wrong because a Denial of Service (DoS) attack aims to disrupt or degrade service availability by overwhelming resources (e.g., SYN flood, ICMP flood), not to enumerate open ports and services for later exploitation. Option C is wrong because social engineering exploits human psychology to manipulate individuals into divulging confidential information or performing actions, not technical scanning of network ports and services.

827
MCQhard

A security analyst is reviewing an incident in which an attacker gained initial access to a corporate workstation by exploiting a vulnerability in a browser plugin. After gaining access, the attacker moved laterally to a file server and exfiltrated data. The analyst must map these activities to the cyber kill chain. Which phase of the kill chain does the browser plugin exploitation represent?

A.Command and control, because the attacker established a channel to manage the compromised host.
B.Weaponization, because the attacker prepared an exploit payload for the browser plugin.
C.Reconnaissance, because the attacker gathered information about the target before the attack.
D.Exploitation, because the attacker took advantage of the vulnerability to execute code on the workstation.
AnswerD

Exploitation is the kill chain phase where the attacker leverages a vulnerability to execute code or gain access. Exploiting the browser plugin vulnerability to gain initial access on the workstation is precisely this phase. The subsequent lateral movement and exfiltration are later phases, but the plugin exploitation itself maps to exploitation, making this the correct mapping.

Why this answer

The browser plugin vulnerability was leveraged to gain code execution and initial access on the workstation. In the cyber kill chain, that action is exploitation, which follows reconnaissance and weaponization and precedes actions such as command and control, lateral movement, and exfiltration. The later lateral movement and data theft are separate phases, so the exploitation itself maps to the exploitation phase.

Exam trap

The trap here is confusing weaponization with exploitation, because both involve preparing and using an exploit, but weaponization occurs before delivery while exploitation is the actual triggering of the vulnerability.

828
Multi-Selectmedium

A security analyst is evaluating the security posture of a new web application. The analyst needs to identify which TWO of the following are examples of security controls that fall under the category of technical controls. (Choose two.)

Select 2 answers
A.Intrusion prevention system (IPS)
B.Access control lists (ACLs) on a router
C.Background checks for new hires
D.Security awareness training for employees
E.Security policy document
AnswersA, B

An intrusion prevention system is a technical control because it uses hardware or software to automatically detect and block malicious network traffic. It enforces security policies through technical mechanisms, such as signature matching or anomaly detection. This falls squarely under technical controls, making it a correct choice for this scenario.

Why this answer

Technical controls are security measures implemented through technology, such as hardware, software, or firmware. An intrusion prevention system and router access control lists both use technical mechanisms to enforce security policies. Security awareness training, policy documents, and background checks are administrative controls that rely on human processes rather than technical enforcement.

Exam trap

The trap here is confusing administrative controls like policies and training with technical controls, as both aim to reduce risk but only technical controls are enforced by technology.

829
Multi-Selecthard

An analyst is reviewing web server logs and sees the following entries: 'GET /admin/login.php HTTP/1.1' returning 404, followed by 'GET /admin/login.html' returning 404, then 'GET /admin/login.asp' returning 200. Which TWO observations are most relevant?

Select 2 answers
A.The attacker is probing for valid login page paths
B.The requests indicate a brute-force login attempt
C.The source IP is likely performing a SQL injection
D.The server is misconfigured to reveal directory listings
E.The successful 200 response indicates the attacker accessed the login page
AnswersA, E

Requesting the same path with .php, .html, then .asp extensions, mostly returning 404, shows systematic enumeration of login page filenames. The attacker is probing for valid login page paths rather than exploiting a known vulnerability.

Why this answer

Option A is correct because the sequence of GET requests for /admin/login.php, /admin/login.html, and /admin/login.asp shows the source systematically trying different file extensions to discover a valid login page path, which is classic forced-browsing or path enumeration behavior. Option E is correct because the final request returned HTTP 200, meaning the server successfully served /admin/login.asp, so the attacker did reach a valid login page. Option B is not supported because brute-force attacks involve repeated authentication attempts with credential guesses, not simple GET requests for different filenames.

Option C is not supported because SQL injection would require malicious input in parameters or payloads, and none is shown in these URLs. Option D is not supported because a 404 response indicates the requested resource was not found, not that directory listings were exposed.

Exam trap

The trap here is confusing enumeration (probing for valid paths) with brute-force (guessing credentials) or injection attacks, as all involve multiple requests to a login page.

830
MCQeasy

An organization implements encryption for all sensitive data at rest and in transit to prevent unauthorized access. Which element of the CIA triad is being primarily addressed?

A.Non-repudiation
B.Integrity
C.Availability
D.Confidentiality
AnswerD

Encryption at rest and in transit renders data unintelligible to anyone lacking the decryption key, directly preventing unauthorised disclosure. This satisfies the stem's constraint of preventing unauthorised access, which maps to confidentiality within the CIA triad. Integrity concerns alteration, and availability concerns uptime, neither of which encryption primarily delivers.

Why this answer

Encryption of data at rest and in transit ensures that only authorized parties can read the data, thus addressing confidentiality. Confidentiality is the element of the CIA triad focused on preventing unauthorized access to information.

Exam trap

200-201 often tests the distinction between confidentiality and integrity; candidates may confuse encryption with hashing, but encryption primarily provides confidentiality.

How to eliminate wrong answers

Option A is wrong because non-repudiation ensures that a party cannot deny having performed an action, often achieved through digital signatures, not encryption alone. Option B is wrong because integrity ensures data is not altered, typically addressed by hashing or checksums, not encryption. Option C is wrong because availability ensures data and systems are accessible when needed, which encryption does not directly address.

831
MCQmedium

A SOC analyst is reviewing network telemetry from Cisco Stealthwatch and notices a host inside the corporate network initiating repeated outbound connections to a single external IP address. Each connection is short-lived (less than 5 seconds) and occurs at irregular intervals, with varying destination ports. The analyst suspects command-and-control activity. Which approach would best confirm this suspicion using available telemetry?

A.Correlate NetFlow records with DNS logs to identify the domain associated with the external IP and check its reputation.
B.Review firewall logs to see if any inbound connections from the external IP were blocked.
C.Capture full packet data for the host and inspect the payload for known malware signatures.
D.Check the host's ARP cache for entries mapping the external IP to a MAC address.
AnswerA

Correlating NetFlow records with DNS logs links the external IP to a domain, which can then be checked against threat intelligence. This confirms whether the destination is a known C2 server. Short-lived connections with varying ports are typical of beaconing, and identifying the domain helps validate the suspicion, making this the most effective approach.

Why this answer

The correct approach is to correlate NetFlow data with DNS logs. NetFlow reveals the external IP and connection patterns, while DNS logs can link that IP to a domain. Checking the domain's reputation against threat intelligence confirms whether it is associated with known C2 infrastructure.

This method leverages existing telemetry efficiently and is a standard practice in security monitoring.

Exam trap

The trap here is assuming that full packet capture is always necessary, when flow and DNS correlation often provide faster and sufficient confirmation of C2 activity.

832
MCQeasy

A financial institution must comply with PCI DSS requirements for handling cardholder data. A security administrator is asked to implement the control that directly addresses the requirement to protect stored cardholder data. Which technology should the administrator deploy to meet this specific PCI DSS requirement?

A.Tokenization of the primary account number (PAN)
B.Full-disk encryption on all employee laptops
C.Network segmentation between the DMZ and internal network
D.Multifactor authentication for all administrative access
AnswerA

PCI DSS Requirement 3 mandates protection of stored cardholder data. Tokenization replaces the PAN with a surrogate value, so the actual PAN is not stored in the cardholder data environment, directly satisfying the requirement. It reduces scope and is a recognized method for protecting stored cardholder data under PCI DSS.

Why this answer

PCI DSS requires that stored cardholder data be rendered unreadable, and tokenization replaces the PAN with a non-sensitive surrogate, directly fulfilling that requirement. Other controls such as endpoint encryption, segmentation, and MFA are valuable but do not address the specific protection of stored cardholder data. Tokenization also reduces the scope of the cardholder data environment, which is a key compliance benefit.

Exam trap

The trap here is confusing general security controls that reduce scope or harden access with the specific PCI DSS requirement to render stored cardholder data unreadable.

833
MCQmedium

A security policy requires that all changes to firewall rules be approved by two administrators. This is an example of which security principle?

A.Need to know
B.Defense in depth
C.Separation of duties
D.Least privilege
AnswerC

Requiring two administrators to approve each firewall change splits authority so no single person can alter rules alone. This is separation of duties, distributing a sensitive task across multiple parties to prevent unilateral or fraudulent modification.

Why this answer

The requirement that two administrators must approve firewall rule changes enforces separation of duties, a security principle that prevents any single individual from having exclusive control over a critical operation. This reduces the risk of unauthorized or malicious rule modifications by ensuring collusion or independent review is required. In firewall management, this is often implemented via change management workflows with distinct approval and implementation roles.

Exam trap

Cisco often tests separation of duties by contrasting it with least privilege, where candidates mistakenly think limiting who can change rules is the same as limiting what they can access, but the key difference is that separation of duties focuses on dividing critical tasks among multiple people to prevent fraud or error.

How to eliminate wrong answers

Option A is wrong because 'need to know' restricts access to information based on job requirements, not the approval process for changes. Option B is wrong because 'defense in depth' involves multiple layers of security controls (e.g., firewall, IDS, antivirus), not a procedural check on administrative actions. Option D is wrong because 'least privilege' limits user permissions to the minimum necessary for their role, whereas this policy controls how changes are authorized, not the baseline access level.

834
MCQmedium

A company's security policy states that all remote access must be through a VPN. An employee complains that the VPN is too slow and asks for an exception to access a specific internal server directly over the internet. What should the security analyst recommend?

A.Configure a separate VPN profile with lower encryption.
B.Allow direct access but only from the employee's home IP.
C.Grant the exception temporarily and monitor the connection.
D.Investigate the VPN performance issue and optimize if possible.
AnswerD

Investigating VPN performance directly addresses the employee's complaint while preserving the mandated remote-access control. Optimising throughput, MTU or split tunnelling resolves the slowness without breaching policy, unlike granting direct internet exposure to an internal server. This satisfies the constraint that all remote access must traverse the VPN.

Why this answer

The security policy mandates VPN for all remote access, and bypassing it would violate the principle of least privilege and expose the internal server directly to the internet. The analyst should first investigate the VPN performance issue—common causes include MTU mismatch, high latency, or encryption overhead—and optimize it (e.g., adjusting MTU, using split tunneling, or upgrading hardware) rather than granting an exception that undermines security.

Exam trap

Cisco often tests the principle that security policies must be enforced consistently, and the trap here is that candidates think a temporary or IP-based exception is acceptable, when in fact any direct access bypasses the VPN's encryption and authentication, violating the core security requirement.

How to eliminate wrong answers

Option A is wrong because lowering encryption (e.g., from AES-256 to AES-128 or disabling PFS) weakens confidentiality and integrity, violating security policy and potentially compliance requirements like PCI DSS. Option B is wrong because allowing direct access from the employee's home IP still exposes the internal server to the public internet, bypassing the VPN's authentication and encryption, and the home IP can change or be spoofed. Option C is wrong because a temporary exception still creates a security gap—attackers could exploit the window, and monitoring does not prevent a direct attack on the exposed server.

835
MCQmedium

A network analyst notices a high volume of traffic from a single external IP address to multiple internal hosts on port 443. The traffic includes incomplete TCP handshakes. Which type of reconnaissance is being performed?

A.Social engineering attack
B.Active reconnaissance via port scanning
C.Denial of Service attack
D.Passive reconnaissance using WHOIS
AnswerB

Incomplete TCP handshakes across many internal hosts on port 443 indicate a SYN scan probing for live services. This is active reconnaissance: the attacker sends packets directly to targets, unlike passive monitoring, and the half-open connections reveal port scanning behaviour.

Why this answer

A high volume of connections to port 443 with incomplete TCP handshakes (SYN sent, no ACK) from one external IP to many internal hosts is the signature of a TCP SYN scan — an active reconnaissance technique used to discover which hosts and ports are open. The incomplete handshakes occur because the scanner does not complete the three-way handshake, either to avoid logging or to speed up the scan.

Exam trap

200-201 often tests the distinction between active reconnaissance (scanning, generates traffic) and passive reconnaissance (WHOIS, DNS, no target traffic) — candidates confuse the two when they see 'reconnaissance' in the question.

How to eliminate wrong answers

Option A is wrong because social engineering targets people (phishing, pretexting), not network ports, and produces no TCP handshake traffic. Option C is wrong because a DoS attack aims to exhaust resources and typically uses complete or spoofed connections at high volume to a single target, not a scan pattern across many hosts. Option D is wrong because passive reconnaissance (WHOIS, DNS lookups) generates no traffic to the target's internal hosts — it queries third-party registries.

836
MCQmedium

A network administrator is creating a baseline for normal traffic patterns. Which of the following should be considered typical for a web server during business hours?

A.High volume of TCP SYN packets to port 443
B.High volume of DNS queries to external domains
C.High volume of SSH connections on port 22
D.High volume of ICMP echo requests
AnswerA

A web server accepting HTTPS connections legitimately receives many TCP SYN packets to port 443 as clients initiate TLS handshakes. This high connection-initiation volume is expected baseline behaviour during business hours, distinguishing normal client demand from anomalies such as scanning or denial-of-service floods.

Why this answer

A web server during business hours typically receives a high volume of incoming TCP SYN packets to port 443 (HTTPS) as clients initiate secure connections. This is normal traffic for a web server providing HTTPS services. The SYN packets are part of the TCP three-way handshake for new connections, and a high volume is expected during peak usage.

Exam trap

The trap is selecting DNS queries as typical because web servers do resolve domains, but the volume is usually low; the most typical high-volume traffic is incoming HTTPS connections (SYN to 443).

How to eliminate wrong answers

Option B is wrong because while a web server may make some DNS queries for external resources, a high volume of DNS queries to external domains is not typical for a web server's normal operation; it could indicate malware or misconfiguration. Option C is wrong because a high volume of SSH connections on port 22 is not typical for a web server; SSH is for management, and such traffic would be suspicious. Option D is wrong because a high volume of ICMP echo requests (pings) is not typical for a web server's normal business traffic; it could indicate scanning or a ping flood.

837
Multi-Selectmedium

An incident responder is analyzing a Windows machine for evidence of malware persistence. Which TWO registry keys are commonly abused to achieve automatic execution at user logon?

Select 2 answers
A.HKLM\Software\Microsoft\Windows\CurrentVersion\Run
B.HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs
C.HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
D.HKCU\Software\Microsoft\Windows\CurrentVersion\Run
E.HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
AnswersA, D

The HKLM Run key applies machine-wide, launching listed programs at logon for every user. Writing to it requires administrative privileges, so malware using this location typically arrives via elevation or an installer, giving persistence across all accounts.

Why this answer

Options A and D are correct because HKLM\Software\Microsoft\Windows\CurrentVersion\Run and HKCU\Software\Microsoft\Windows\CurrentVersion\Run are the canonical Run keys that Windows automatically processes at user logon, launching any listed program for all users (HKLM) or the specific user (HKCU), which is why malware commonly writes here for persistence. Option C (RunOnce) also triggers at logon but is designed for one-time execution and the value is deleted after it runs, so it is not the standard persistent automatic-execution key the question targets. Option B (AppInit_DLLs) is a DLL-injection mechanism loaded into processes using User32.dll, not a logon-triggered program launcher.

Option E (Image File Execution Options) is abused for debugger hijacking or executable redirection, not for automatic execution at logon.

Exam trap

The trap is confusing RunOnce (one-time execution) with Run (persistent execution), or picking AppInit_DLLs which is a different persistence type not tied to logon.

838
MCQmedium

After containing a security incident, the incident response team eradicates the malware and restores systems from clean backups. Which phase of the NIST SP 800-61 Rev 2 process does this represent?

A.Preparation
B.Containment, Eradication, and Recovery
C.Post-Incident Activity
D.Detection and Analysis
AnswerB

Eradication removes the malware and recovery restores systems from clean backups, both grouped with containment in this single NIST SP 800-61 Rev 2 phase. The stem's containment-then-eradicate-then-restore sequence therefore maps directly onto it, not onto post-incident activity.

Why this answer

Eradication removes the threat, and recovery restores normal operations.

839
MCQmedium

In Wireshark, an analyst follows a TCP stream and sees plaintext usernames and passwords. Which protocol is likely in use?

A.HTTPS
B.SFTP
C.FTP
D.SSH
AnswerC

FTP transmits credentials in cleartext over TCP, so a followed stream exposes usernames and passwords directly. Unlike FTPS or SFTP, which negotiate TLS or SSH encryption before authentication, plain FTP offers no confidentiality, matching the plaintext credentials observed in the capture.

Why this answer

FTP (File Transfer Protocol) transmits data, including login credentials, in cleartext over TCP. When an analyst follows a TCP stream in Wireshark and sees plaintext usernames and passwords, it indicates that no encryption is applied. HTTPS, SFTP, and SSH all encrypt their payloads, so credentials would not be visible in plaintext.

Therefore, FTP is the likely protocol.

Exam trap

The trap here is confusing FTP with SFTP or assuming that all file transfer protocols are encrypted; candidates might overlook that FTP sends credentials in plaintext while SFTP and FTPS do not.

How to eliminate wrong answers

Option A is wrong because HTTPS uses TLS/SSL to encrypt HTTP traffic, so usernames and passwords would be encrypted and not visible in plaintext. Option B is wrong because SFTP (SSH File Transfer Protocol) runs over SSH and encrypts all data, including authentication credentials. Option D is wrong because SSH provides an encrypted tunnel for remote login and file transfers, so credentials are not sent in cleartext.

840
MCQmedium

An analyst detects multiple SMB authentication attempts from a single internal host to several other internal hosts using NTLM hashes instead of plaintext passwords. Which technique is most likely being used?

A.Brute force
B.Kerberoasting
C.Golden ticket attack
D.Pass-the-hash
AnswerD

Pass-the-hash reuses captured NTLM password hashes directly for authentication, bypassing plaintext password knowledge entirely. The multiple SMB connections between internal hosts using hashes rather than credentials match this technique's signature, distinguishing it from credential cracking.

Why this answer

Pass-the-hash is the technique where an attacker uses a captured NTLM hash to authenticate to remote systems without knowing the plaintext password. The scenario — one internal host authenticating to many others using NTLM hashes — is the canonical lateral-movement signature of pass-the-hash, typically executed with tools like Mimikatz, CrackMapExec, or Impacket. The fan-out pattern from a single source to multiple targets is a strong indicator of automated credential reuse.

Exam trap

200-201 often tests the distinction between pass-the-hash (replaying a stolen NTLM hash) and Kerberoasting (cracking Kerberos service tickets) — candidates pick Kerberoasting because both involve credential theft, but only pass-the-hash uses NTLM hashes over SMB.

How to eliminate wrong answers

Option A is wrong because brute force generates many failed authentication attempts against a target, not successful hash-based logons across many hosts. Option B is wrong because Kerberoasting targets Kerberos service tickets (TGS-REPs) for offline cracking of service account passwords — it does not involve NTLM hash authentication over SMB. Option C is wrong because a golden ticket forges a Kerberos TGT using the KRBTGT hash and is validated through Kerberos, not NTLM.

841
MCQeasy

A junior analyst is reviewing a packet capture and sees a workstation repeatedly sending ICMPv4 Type 8 packets to an external IP address with varying payload sizes. The analyst wants to confirm whether this activity is a covert channel. Which characteristic of the ICMP traffic would most strongly suggest that the ICMP payload is being used to exfiltrate data?

A.The ICMP payload data changes on every request and contains non-printable, high-entropy bytes.
B.The ICMP echo requests are sent at a fixed interval of exactly one second.
C.The ICMP echo requests contain a consistent sequence number and identifier.
D.The ICMP echo requests receive echo replies from the same external IP address.
AnswerA

Legitimate ping payloads are usually fixed patterns such as alphabetic strings or zeros. When the payload varies on every request and contains high-entropy, non-printable bytes, it suggests data is being encoded into the ICMP data field for exfiltration. This is a classic indicator of an ICMP tunnel or covert channel, especially when combined with a consistent external destination.

Why this answer

Covert ICMP channels hide data inside the payload of echo requests and replies. Benign pings use fixed, printable payload patterns, so a payload that changes on every packet and contains high-entropy, non-printable bytes strongly suggests encoded data is being transmitted. Combined with an external destination, this pattern points to ICMP-based exfiltration rather than routine connectivity testing.

Exam trap

The trap here is focusing on packet timing or reply behaviour, which are normal for ping, instead of inspecting the payload content where covert data actually hides.

842
MCQmedium

A security analyst is reviewing the risk associated with a new cloud service. The service provider stores data in multiple countries, and the data includes personal information of EU citizens. The analyst must ensure compliance with GDPR. Which principle of GDPR is most directly relevant to this scenario?

A.Cross-border data transfer restrictions
B.Data protection impact assessment (DPIA)
C.Data minimization
D.Right to erasure
AnswerA

GDPR imposes strict rules on transferring personal data outside the EU/EEA. The scenario highlights that data is stored in multiple countries, which triggers the need to ensure adequate safeguards such as Standard Contractual Clauses or adequacy decisions. This principle directly addresses the legality of transferring EU citizens' data to other jurisdictions, making it the most relevant GDPR principle in this scenario.

Why this answer

GDPR restricts the transfer of personal data of EU citizens to countries outside the EU/EEA unless adequate protections are in place. The scenario describes data stored in multiple countries, which directly implicates cross-border data transfer restrictions. Data minimization, right to erasure, and DPIA are important but not as directly tied to the geographic storage of data.

Exam trap

The trap here is selecting a well-known GDPR principle like the right to erasure or data minimization simply because it sounds relevant, without focusing on the specific trigger of data being stored in multiple countries.

843
MCQmedium

An analyst is examining a Linux system for persistence mechanisms. Which of the following files should be reviewed to detect cron-based persistence?

A./var/log/auth.log
B./etc/passwd
C./home/user/.bash_history
D./var/spool/cron/crontabs
AnswerD

User crontab entries are stored under /var/spool/cron/crontabs, one file per user, so reviewing this directory reveals scheduled jobs an attacker added for persistence. System-wide schedules live in /etc/crontab and /etc/cron.d, making this the correct user-level location.

Why this answer

The correct answer is /var/spool/cron/crontabs because this directory stores user-specific cron jobs on Debian-based Linux systems. Attackers often add malicious entries here to maintain persistence by scheduling recurring tasks. Reviewing this directory reveals unauthorized scheduled jobs that could execute malware or reverse shells at regular intervals.

Exam trap

The trap here is confusing log files or user account files with actual persistence configuration files; candidates might pick /var/log/auth.log because it logs cron activity, but the question asks for the file to review to detect the persistence mechanism itself.

How to eliminate wrong answers

Option A is wrong because /var/log/auth.log contains authentication logs, not cron job definitions; it may show cron execution but not the persistence mechanism itself. Option B is wrong because /etc/passwd stores user account information, not scheduled tasks; while attackers may add rogue users, that is a different persistence method. Option C is wrong because /home/user/.bash_history records interactive shell commands, not cron jobs; it might show an attacker creating a cron job, but the actual persistence file is elsewhere.

844
MCQeasy

In the context of risk management, which term describes the risk that remains after implementing security controls?

A.Acceptable risk
B.Inherent risk
C.Transfer risk
D.Residual risk
AnswerD

Residual risk is the exposure that persists once security controls have been applied, directly matching the stem's requirement for risk remaining after implementation. Inherent risk exists before controls; residual risk is what survives them, and it must be accepted, transferred, mitigated further, or avoided through risk management decisions.

Why this answer

Residual risk is the risk left after controls are applied. It must be accepted or further treated.

845
MCQmedium

An attacker sends an email posing as the company's IT department, asking employees to click a link and enter their credentials. Which type of social engineering attack is this?

A.Vishing
B.Phishing
C.Pretexting
D.Spear phishing
AnswerB

Phishing fits because the attacker uses a fraudulent email impersonating the IT department to trick employees into revealing credentials via a deceptive link. This satisfies the scenario's defining constraint: mass, electronic, credential-harvesting deception. Unlike spear phishing, it is not individually researched, and unlike vishing or smishing, the channel is email, matching the stem exactly.

Why this answer

B is correct because the attack uses email as the delivery vector to trick recipients into revealing credentials, which is the classic definition of phishing. Phishing is a broad category of social engineering that employs deceptive electronic communications (typically email) to steal sensitive information.

Exam trap

Cisco often tests the distinction between phishing (mass, untargeted) and spear phishing (targeted), so the trap here is that candidates may confuse the generic email to all employees with a targeted attack, leading them to incorrectly choose spear phishing.

How to eliminate wrong answers

Option A is wrong because vishing (voice phishing) uses telephone calls or voice messages, not email. Option C is wrong because pretexting involves fabricating a scenario or identity to gain trust and extract information, but it does not specifically require an email with a link to harvest credentials. Option D is wrong because spear phishing is a targeted version of phishing aimed at a specific individual or organization, whereas the question describes a generic email sent to all employees, which is a mass phishing campaign.

846
MCQhard

A threat hunter reviews Cisco Stealthwatch flow data and sees an internal server sending periodic 300-byte outbound flows to an external IP every 60 seconds, with consistent packet sizes and no matching inbound response beyond TCP acknowledgments. The server's DNS queries for that IP resolve through a newly registered domain. Which monitoring approach best characterizes this activity as beaconing rather than normal application traffic?

A.Compare the flow's byte count against the organization's top-talkers report
B.Check whether the destination IP appears on a threat intelligence blocklist
C.Analyze flow periodicity and packet-size consistency over time
D.Verify that the server's operating system is fully patched and current
AnswerC

Beaconing is identified by repeated connections at regular intervals with near-constant payload sizes, which distinguishes it from bursty or variable user-driven traffic. Stealthwatch's flow records preserve timestamps and byte counts, so plotting inter-arrival times and sizes exposes the 60-second cadence. Correlating that pattern with the newly registered domain strengthens the characterization of automated C2 beaconing rather than normal application behavior.

Why this answer

Beaconing is a behavioral pattern characterized by regular connection intervals and consistent payload sizes, often with minimal server response. Flow telemetry preserves the timing and byte counts needed to detect that cadence, so periodicity and size consistency analysis is the right approach. Volume ranking, blocklist matching, and patch verification do not evaluate the temporal pattern that separates automated C2 from normal traffic.

Exam trap

The trap here is focusing on the low byte count and concluding the traffic is too small to matter instead of examining its timing regularity.

847
MCQeasy

Which component of the NIST Cybersecurity Framework involves taking action to stop an ongoing attack?

A.Identify
B.Detect
C.Respond
D.Protect
AnswerC

The Respond function covers the actions taken once an incident is detected, containing its impact and stopping the ongoing attack. Identify, Protect, Detect and Recover address other phases, so Respond satisfies the stem's requirement to halt active compromise.

Why this answer

The Respond function includes activities to contain and mitigate incidents.

848
MCQhard

A Zeek connection log shows a high number of connections from a single internal IP to many different external IPs on port 25, with small payload sizes. Which behavior is most likely indicated?

A.DNS tunneling
B.Secure web browsing
C.Data exfiltration using FTP
D.Spam email campaign or SMTP scanning
AnswerD

Many outbound connections to diverse external hosts on port 25, with tiny payloads, indicate SMTP scanning or spam relay activity. A legitimate mail server contacts few destinations with larger message bodies; this fan-out pattern from one internal host satisfies the stem's high-connection, small-payload constraint.

Why this answer

Port 25 is the default SMTP port used for email transmission. A high volume of connections from a single internal IP to many different external IPs on port 25, with small payload sizes, is characteristic of a spam email campaign or SMTP scanning. This pattern suggests the host is either sending bulk spam emails or probing external mail servers for open relay or user enumeration.

Exam trap

Cisco often tests the association of well-known ports with their protocols, and the trap here is that candidates may confuse port 25 with other common ports like 53 (DNS) or 21 (FTP), leading them to select DNS tunneling or FTP exfiltration instead of recognizing the SMTP spam pattern.

How to eliminate wrong answers

Option A is wrong because DNS tunneling typically uses UDP port 53 (or TCP 53 for large queries) and involves encoding data in DNS queries/responses, not SMTP port 25. Option B is wrong because secure web browsing uses HTTPS on port 443, not port 25, and would show larger payload sizes due to encrypted web content. Option C is wrong because data exfiltration using FTP would use port 21 (control) or port 20 (data), not port 25, and would involve larger file transfers rather than small payloads.

849
MCQmedium

A security analyst is investigating a host that is suspected of being used as a pivot point in a network intrusion. The analyst needs to identify which process initiated an outbound connection to a known malicious IP address. Which host-based analysis approach should the analyst use to correlate the network connection to the specific process?

A.Run 'netstat -b' on the Windows host to display active connections with the associated process executable.
B.Examine the Windows Firewall log to see the source and destination IP addresses and ports for outbound traffic.
C.Review Windows Security Event Log for Event ID 4688 (Process Creation) for the timeline of process starts.
D.Use PowerShell cmdlet 'Get-NetTCPConnection' to list current TCP connections and their states.
AnswerA

netstat -b maps each active connection to the owning executable on Windows, directly correlating the outbound session to the malicious IP with the process that opened it. This identifies the pivot tool without packet capture.

Why this answer

Running 'netstat -b' on a Windows host displays active TCP connections along with the executable name of the process that created each connection. This directly correlates the outbound connection to the malicious IP with the specific process, which is exactly what the analyst needs to identify the pivot point.

Exam trap

Cisco often tests the distinction between network-level logs (firewall logs) and host-level process-to-connection correlation, and the trap here is that candidates may choose 'Get-NetTCPConnection' (Option D) because it lists connections, but they overlook that it does not show the associated process executable without additional scripting.

How to eliminate wrong answers

Option B is wrong because the Windows Firewall log records source/destination IPs and ports but does not associate traffic with a specific process executable; it only logs network-level metadata. Option C is wrong because Event ID 4688 logs process creation events but does not include network connection details, so it cannot correlate a specific outbound connection to a process. Option D is wrong because 'Get-NetTCPConnection' lists TCP connections and their states but does not show the associated process executable; it lacks the -b flag's process-to-connection mapping.

850
MCQhard

A security auditor reviews a company's security policies and finds that the password policy requires a minimum length of 8 characters and complexity including uppercase, lowercase, digit, and special character. However, the policy does not mandate password expiration. Which of the following is the most significant risk due to this omission?

A.Stolen credentials could be used for extended periods without detection
B.Users may choose weak passwords that are easy to guess
C.Help desk will receive an increased number of password reset requests
D.Users might reuse passwords across different systems
AnswerA

Without password expiration, compromised credentials remain valid indefinitely, letting an attacker maintain persistent access. Expiration limits the window in which stolen passwords can be reused, so its absence directly enables prolonged undetected misuse, satisfying the stem's constraint about extended unauthorised access.

Why this answer

Without mandatory password expiration, an attacker who obtains valid credentials (e.g., via phishing or credential dumping) can maintain access indefinitely, as the password never needs to be changed. This increases the window of opportunity for lateral movement, data exfiltration, or privilege escalation. In contrast, periodic expiration forces re-authentication and reduces the lifespan of compromised credentials.

Exam trap

Cisco often tests the misconception that password complexity alone prevents credential theft, when in fact the absence of expiration creates a persistent risk of undetected long-term access by attackers.

How to eliminate wrong answers

Option B is wrong because the policy already mandates complexity (uppercase, lowercase, digit, special character) and a minimum length of 8 characters, which directly mitigates weak or guessable passwords. Option C is wrong because password expiration typically increases help desk calls due to forgotten passwords, not the absence of expiration. Option D is wrong because password reuse across systems is primarily prevented by password history policies or single sign-on (SSO), not by expiration; expiration alone does not stop reuse.

851
MCQmedium

During an intrusion analysis, a SOC analyst reviews logs showing an outbound connection from an internal host to an external IP at 03:00 AM every 60 seconds. The traffic is HTTPS to a suspicious domain with a high entropy name. Which phase of the Cyber Kill Chain does this activity represent?

A.Actions on Objectives
B.Delivery
C.Command and Control (C2)
D.Weaponisation
AnswerC

Regular beaconing at fixed 60-second intervals to an external suspicious high-entropy domain over HTTPS indicates an implanted host checking in with its controller. This periodic callback traffic is the hallmark of the Command and Control phase of the Cyber Kill Chain.

Why this answer

Periodic outbound HTTPS connections to a suspicious high-entropy domain at fixed intervals are the classic signature of Command and Control (C2) beaconing, where an implant checks in with its controller for instructions. The regularity (every 60 seconds) and the high-entropy domain name (typical of DGA or attacker-registered infrastructure) are the defining indicators. This activity occurs after exploitation and installation, when the malware establishes its channel back to the attacker.

Exam trap

200-201 often tests whether candidates can distinguish C2 (periodic callbacks to attacker infrastructure) from Delivery (initial payload transmission) — the presence of 'external IP' in the question tempts candidates toward Delivery.

How to eliminate wrong answers

Option A is wrong because Actions on Objectives is the final phase where the attacker achieves their goal (data theft, encryption, destruction) — beaconing is the channel setup, not the objective execution. Option B is wrong because Delivery is the initial transmission of the payload to the victim, which happens before any C2 channel exists. Option D is wrong because Weaponisation is the preparation of the payload with an exploit, occurring before delivery and long before any network callback.

852
MCQeasy

A security analyst is triaging an alert about a user downloading a suspicious file. According to the NIST SP 800-61 Rev 2 incident response process, in which phase does initial triage occur?

A.Containment, Eradication, and Recovery
B.Post-Incident Activity
C.Preparation
D.Detection and Analysis
AnswerD

Detection and Analysis covers monitoring, alert triage and initial validation, so the analyst's first assessment of the suspicious download sits here. It precedes containment, meaning triage data gathered now determines whether the incident escalates to the containment, eradication and recovery phase.

Why this answer

Initial triage is part of the Detection and Analysis phase, where alerts are evaluated to determine if they are actual incidents.

853
MCQmedium

You are a security operations analyst for a medium-sized enterprise. The company's security policy requires that all endpoint devices have antivirus software installed and updated. During a routine check, you find that a group of 50 laptops used by the sales team have not received antivirus updates for over three months. The policy also states that any non-compliant devices must be quarantined from the network until they are remediated. The sales team manager argues that quarantining the laptops will disrupt critical sales activities. The company's incident response policy has a clause that allows for temporary exceptions in business-critical situations, but requires approval from the CISO. What is the best course of action?

A.Ignore the issue to avoid disrupting sales activities
B.Quarantine the laptops immediately as per policy
C.Request a temporary exception from the CISO while expediting the updates
D.Update the antivirus without quarantining, then report to management
AnswerC

Requesting a CISO-approved temporary exception satisfies the policy's business-critical clause while the updates are expedited, avoiding quarantine disruption to sales. Approval must precede any network access, since the exception clause is the only mechanism permitting non-compliant devices to remain connected; remediation then restores full compliance.

Why this answer

It balances security policy compliance with business continuity. The incident response policy explicitly allows temporary exceptions for business-critical situations with CISO approval, and expediting the updates ensures the 50 laptops are remediated quickly. Quarantining without considering the business impact could violate the company's own exception clause, while ignoring the issue or updating without quarantining bypasses the security controls required by policy.

Exam trap

Cisco often tests the balance between strict policy enforcement and business continuity, trapping candidates who choose immediate quarantine (Option B) without considering documented exception processes, or who choose to update without quarantine (Option D) thinking it's a practical workaround.

How to eliminate wrong answers

Option A is wrong because ignoring the issue violates the security policy requiring quarantine of non-compliant devices, leaving the network exposed to potential malware outbreaks from outdated antivirus definitions. Option B is wrong because while quarantine is the default policy, it fails to leverage the incident response policy's exception clause for business-critical situations, potentially causing unnecessary disruption without CISO oversight. Option D is wrong because updating antivirus without quarantining bypasses the policy's quarantine requirement and does not address the root cause of non-compliance; reporting after the fact does not obtain the required prior approval for an exception.

854
Multi-Selectmedium

A security analyst is reviewing the organization's security policies and notices that the Acceptable Use Policy (AUP) is outdated. The analyst is asked to identify key elements that should be included in an effective AUP. Which two elements are essential components of an AUP? (Choose two.)

Select 2 answers
A.List of all software vulnerabilities and patches
B.Detailed network diagram of the organization's infrastructure
C.Consequences for policy violations
D.Definition of acceptable and unacceptable use of organizational assets
E.Step-by-step incident response procedures
AnswersC, D

An effective AUP must outline the consequences of violating the policy, which may include disciplinary action, termination, or legal action. This element deters misuse and ensures consistent enforcement. It also protects the organization legally by establishing that violations are taken seriously. Thus, consequences are an essential component of an AUP.

Why this answer

An Acceptable Use Policy must clearly define acceptable and unacceptable use of organizational assets and specify consequences for violations. These elements set expectations and enable enforcement. Technical details like network diagrams, incident response procedures, and vulnerability lists belong in other documents and are not core components of an AUP.

Exam trap

The trap here is thinking that technical details such as network diagrams or vulnerability lists belong in an AUP, when they are actually part of separate technical or operational documents.

855
Multi-Selectmedium

A security policy mandates that all network devices must have logging enabled and that logs must be reviewed regularly. Which TWO practices are essential for effective log review?

Select 2 answers
A.Aggregating logs from all devices into a central server.
B.Reviewing logs only when an incident occurs.
C.Automated log analysis with correlation tools.
D.Storing logs for at least one year.
E.Ensuring logs are in a common format like Syslog.
AnswersA, C

Centralising logs from every device removes the need to inspect each host individually, which is impractical at scale. A single aggregation point preserves chronological ordering across sources, enabling correlation of events that span multiple devices and satisfying the policy's regular-review mandate.

Why this answer

Option A is correct because aggregating logs from all network devices into a central server (e.g., a syslog server or SIEM) is essential for effective review, as it consolidates disparate sources into one searchable location and enables cross-device analysis rather than requiring administrators to inspect each device individually. Option C is correct because automated log analysis with correlation tools (such as a SIEM) is essential to handle the high volume of log data, normalize events, and correlate activity across devices to detect patterns and anomalies that manual review would miss. Option B is incorrect because reviewing logs only after an incident is reactive and defeats the purpose of regular, proactive review mandated by policy.

Option D is incorrect because while long retention (e.g., one year) supports forensics and compliance, retention alone does not constitute effective review. Option E is incorrect because a common format like Syslog aids parsing and normalization but is a supporting convenience, not an essential practice for effective log review itself.

Exam trap

The trap here is confusing log retention or log format with log review; candidates pick 'store logs for one year' or 'use Syslog' because they sound like best practices, but the question asks specifically about review practices, not storage or formatting.

856
MCQmedium

During an incident response, an analyst checks for persistence mechanisms and finds an entry under HKCU\Software\Microsoft\Windows\CurrentVersion\Run. What is the most likely purpose of this registry key?

A.It lists recently accessed documents.
B.It specifies programs to run automatically at user logon.
C.It stores user interface settings for the current user.
D.It controls Windows Defender exclusions.
AnswerB

The Run key under HKCU executes listed programs automatically each time that user logs on, giving malware persistence without administrative rights. This satisfies the stem's persistence mechanism: the entry survives reboots and relaunches the payload at user logon, unlike one-time execution or system-wide services requiring elevation.

Why this answer

It specifies programs to run automatically at user logon is correct because the HKCU\Software\Microsoft\Windows\CurrentVersion\Run registry key is a common autostart location that executes programs when the user logs in. Attackers often use this key for persistence to ensure their malware runs after a reboot or logon.

Exam trap

200-201 often tests the knowledge of common persistence mechanisms. Candidates might confuse the Run key with other registry keys that store user settings or recent documents, but the Run key is specifically for autostart programs.

How to eliminate wrong answers

Option A is wrong because recently accessed documents are tracked in the RecentDocs key or via jump lists, not in the Run key. Option C is wrong because user interface settings are stored in various keys under HKCU\Software, but not specifically in the Run key. Option D is wrong because Windows Defender exclusions are stored in a different registry location, such as HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions.

857
Multi-Selectmedium

Which THREE are essential components of a security monitoring strategy? (Choose three.)

Select 3 answers
A.Antivirus software on all endpoints.
B.Data encryption at rest.
C.Defined incident response procedures.
D.Centralized log collection from critical systems.
E.Correlation rules to identify suspicious patterns.
AnswersC, D, E

Ensures proper handling.

Why this answer

Defined incident response procedures (Option C) are essential because they provide a structured, repeatable workflow for detecting, analyzing, and containing security incidents. Without pre-defined procedures, a security team cannot consistently execute the 'Respond' phase of the NIST SP 800-61 incident response lifecycle, leading to delayed containment and increased dwell time.

Exam trap

Cisco often tests the distinction between preventive controls (antivirus, encryption) and detective/monitoring controls (log collection, correlation, incident response procedures), causing candidates to mistakenly include security hygiene measures as monitoring components.

858
MCQeasy

An organization's data classification policy defines four levels: Public, Internal, Confidential, and Restricted. An employee accidentally sends an email containing customer payment card information (PCI) to the entire company mailing list. The data should have been classified as which level?

A.Public
B.Restricted
C.Internal
D.Confidential
AnswerB

Payment card data is regulated by PCI DSS, and the Restricted tier is reserved for data whose disclosure causes severe legal, financial or regulatory harm. Customer card numbers therefore demand the highest classification, not Confidential or Internal.

Why this answer

Payment card information is regulated by PCI DSS and, in most data classification schemes, falls under the highest sensitivity tier — Restricted — because exposure triggers regulatory notification, fines, and identity-theft risk. Restricted is reserved for data whose unauthorized disclosure causes severe legal, financial, or reputational harm, which PCI data clearly qualifies as. Confidential is typically a tier below Restricted and covers internal sensitive data not subject to the same regulatory penalties.

Exam trap

The trap is confusing Confidential with Restricted — candidates often pick Confidential because it sounds highly sensitive, but PCI data maps to the highest tier (Restricted) due to regulatory and financial impact.

How to eliminate wrong answers

Option A is wrong because Public data is intentionally shareable with anyone and carries no confidentiality requirement — PCI data is the opposite. Option C is wrong because Internal data is only meant to stay within the organization and does not carry the regulatory weight of PCI; misclassifying PCI as Internal would understate the required controls. Option D is wrong because Confidential, while sensitive, is a lower tier than Restricted in a four-level scheme; PCI data demands the strictest controls (encryption, tokenization, access logging) that map to Restricted.

859
MCQhard

An organization must comply with a regulation that requires protecting the privacy of EU citizens' personal data. Which compliance framework applies?

A.HIPAA
B.ISO 27001
C.PCI DSS
D.GDPR
AnswerD

GDPR directly governs the protection of EU citizens' personal data, satisfying the stem's regulatory privacy requirement. It imposes binding obligations on organisations processing that data, regardless of where the organisation is established, making it the applicable compliance framework rather than a security control or technical standard.

Why this answer

The General Data Protection Regulation (GDPR) is the EU regulation specifically designed to protect the privacy and personal data of EU citizens. It applies to any organization that processes or controls the personal data of individuals in the EU, regardless of where the organization is based. This makes GDPR the correct compliance framework for the scenario described.

Exam trap

Cisco often tests the distinction between data privacy regulations (like GDPR) and data security standards (like PCI DSS or HIPAA), where candidates mistakenly apply a US-centric regulation to an EU privacy requirement.

How to eliminate wrong answers

Option A is wrong because HIPAA (Health Insurance Portability and Accountability Act) applies only to protected health information (PHI) in the United States, not to EU citizens' personal data. Option B is wrong because ISO 27001 is an international standard for information security management systems (ISMS), not a regulation that specifically addresses EU privacy requirements. Option C is wrong because PCI DSS (Payment Card Industry Data Security Standard) governs the security of credit card data, not the privacy of EU citizens' personal data.

860
MCQhard

During an incident investigation, the IR team collects evidence from a compromised server. The evidence must be admissible in court. Which documentation is essential to maintain the chain of custody?

A.A log of who accessed the evidence and when
B.The CVSS score of the vulnerability
C.A copy of the incident response plan
D.The organization's acceptable use policy
AnswerA

A chain-of-custody log records every individual who handled, transferred or accessed the evidence, with timestamps and signatures. This continuous audit trail satisfies the admissibility constraint by proving the evidence was never tampered with between seizure and courtroom presentation.

Why this answer

Chain of custody documentation must include a log of who accessed the evidence, when, and for what purpose, to ensure integrity and admissibility in court. This log creates an auditable trail that proves the evidence has not been tampered with. Without it, the evidence may be deemed inadmissible.

Exam trap

200-201 often tests the misconception that technical details like CVSS scores or policies are part of chain of custody, when the essential element is the access log.

How to eliminate wrong answers

Option B is wrong because the CVSS score is a severity rating for vulnerabilities and is not part of chain of custody documentation. Option C is wrong because the incident response plan is a procedural document, not evidence-specific documentation. Option D is wrong because the acceptable use policy is an organizational policy and does not track evidence handling.

861
MCQeasy

A security analyst is reviewing a Wireshark capture and notices a large number of TCP SYN packets sent to multiple ports on a single host from the same source IP. Which type of network activity is most likely being observed?

A.DNS amplification attack
B.ARP spoofing
C.Port scan
D.Man-in-the-middle attack
AnswerC

TCP SYN packets to many ports on one host from a single source form the classic half-open scan pattern: the attacker sends SYNs without completing handshakes, seeking open ports. This fan-out to numerous ports on a single target distinguishes scanning from normal connection attempts.

Why this answer

A port scan is characterized by multiple connection attempts to different ports on a target host, often using SYN packets.

862
MCQmedium

A security analyst is investigating a potential brute force attack. Which SIEM correlation rule would best detect this activity?

A.Alert on a single failed login from any IP
B.Alert when more than 10 failed logins from the same IP occur within one minute
C.Alert when a successful login occurs after midnight
D.Alert when a user logs in from a new geographic location
AnswerB

Counting failed logins per source IP within one minute detects the rapid, repeated authentication attempts from one origin that define brute forcing, filtering out isolated failures. This logic directly identifies the activity the analyst is investigating.

Why this answer

A typical brute force detection rule monitors for multiple failed authentication attempts from the same source within a short time window.

863
MCQmedium

An analyst suspects a Windows workstation is beaconing to a command-and-control server. The host's DNS cache contains an entry for a domain that resolves to an IP address, but the analyst cannot find any active network connection or process associated with that domain. Which Windows artifact should the analyst examine to determine whether a process previously resolved this domain and when?

A.The Windows Firewall log at %systemroot%\system32\LogFiles\Firewall\pfirewall.log
B.The DNS Client event log (Microsoft-Windows-DNS-Client/Operational)
C.The Application event log
D.The System event log
AnswerB

The Microsoft-Windows-DNS-Client/Operational log records DNS query events, including the process name, query name, query type, and timestamp. In this scenario, it can reveal which process resolved the suspicious domain and when, even if the connection is no longer active. This directly addresses the need to correlate a domain with a process and time.

Why this answer

The Microsoft-Windows-DNS-Client/Operational log is designed to record DNS client query events, including the query name, query type, timestamp, and the process that initiated the query. When a host is beaconing, the DNS cache may only show the resolved IP, but the operational log can show which process resolved the domain and when, enabling the analyst to link the beaconing behavior to a specific executable.

Exam trap

The trap here is assuming that the DNS cache or firewall log provides process attribution and timestamps for domain resolution, when only the DNS Client operational log records that level of detail.

864
MCQmedium

A SIEM correlation rule triggers an alert when more than 10 failed login attempts from the same source IP occur within 60 seconds. Which attack is this rule designed to detect?

A.Phishing attack
B.Man-in-the-middle
C.SQL injection
D.Brute force attack
AnswerD

Repeated authentication failures from one source within a short window match the brute force pattern, where an attacker rapidly guesses credentials against a single account or host. The rule's thresholds — more than 10 attempts in 60 seconds from the same IP — directly encode that volume-based signature.

Why this answer

This SIEM rule detects a brute force attack by correlating a high volume of failed login attempts (more than 10) from the same source IP within a short time window (60 seconds). Brute force attacks rely on rapid, repeated authentication attempts to guess credentials, and this threshold-based correlation is a classic detection method for such behavior.

Exam trap

Cisco often tests the distinction between brute force and other attack types by focusing on the specific behavior of repeated failed logins from a single source, which candidates may confuse with phishing or SQL injection due to overlapping terminology like 'credential theft' or 'authentication bypass'.

How to eliminate wrong answers

Option A is wrong because phishing attacks involve social engineering to trick users into revealing credentials or installing malware, not automated failed login attempts from a single IP. Option B is wrong because man-in-the-middle attacks intercept or modify communications between two parties, typically without generating repeated failed logins from one source. Option C is wrong because SQL injection exploits vulnerabilities in database queries via input fields, not through authentication failure logs or repeated login attempts.

865
MCQmedium

Which Linux log file is most appropriate for reviewing failed SSH login attempts?

A./var/log/auth.log
B./var/log/messages
C./var/log/kern.log
D./var/log/syslog
AnswerA

On Debian and Ubuntu systems, the SSH daemon writes authentication events, including failed login attempts, to /var/log/auth.log via the authpriv facility. This makes it the appropriate file for reviewing failed SSH logins on those distributions.

Why this answer

/var/log/auth.log is the standard Linux log file that records authentication events, including successful and failed SSH login attempts, sudo usage, and PAM-related messages. On Debian/Ubuntu systems, sshd logs authentication failures here via the authpriv facility. This makes it the most appropriate file for reviewing failed SSH logins.

Exam trap

200-201 often tests the confusion between general system logs (syslog, messages) and dedicated authentication logs (auth.log, secure) — candidates may pick syslog because it 'contains everything' when auth.log is the precise answer for SSH failures.

How to eliminate wrong answers

Option B is wrong because /var/log/messages is a general system log on some distributions (like RHEL/CentOS) but does not specifically capture authentication events — SSH failures are typically in /var/log/secure on those systems. Option C is wrong because /var/log/kern.log records kernel messages, not user authentication or SSH login attempts. Option D is wrong because /var/log/syslog is a general system log that may contain some SSH messages but is not the dedicated authentication log; auth.log is more specific and reliable for failed logins.

866
MCQhard

A security analyst is using Cisco Umbrella and notices a high volume of DNS queries from a single internal host to randomly generated domain names that do not resolve. The queries are for domains like 'a1b2c3d4.com', 'e5f6g7h8.net', etc. What type of malicious activity is most likely occurring?

A.Domain generation algorithm (DGA) used by malware for command and control.
B.A phishing campaign attempting to redirect users to fake websites.
C.A misconfigured application repeatedly querying non-existent domains.
D.DNS tunneling for data exfiltration.
AnswerA

DGAs generate many random domain names that malware queries to locate its C2 server. The high volume of non-resolving queries to random domains is a classic sign of DGA activity. Cisco Umbrella would log these queries, and the pattern of random, unresolvable domains strongly indicates malware attempting to establish C2 communication.

Why this answer

The high volume of DNS queries to randomly generated, non-resolving domains is a hallmark of a domain generation algorithm (DGA). Malware uses DGAs to generate many potential C2 domains, hoping one will resolve and allow communication. Cisco Umbrella logs these queries, and the pattern is a strong indicator of infection.

DNS tunneling and misconfigurations would present differently.

Exam trap

The trap here is confusing DGA with DNS tunneling; DGA generates many random domains, while tunneling uses a single domain with encoded data.

867
Multi-Selecthard

Which THREE are required steps in a proper incident response procedure? (Choose three.)

Select 3 answers
A.Change Management Processing
B.Containment, Eradication, and Recovery
C.Post-Incident Activity (Lessons Learned)
D.Detection and Analysis
E.System Hardening
AnswersB, C, D

Containment, eradication and recovery form the core sequential phases that stop the spread, remove the root cause and restore normal operations. They sit between identification and lessons learned, making them mandatory steps in any proper incident response procedure.

Why this answer

The three correct answers map directly to the phases of the NIST SP 800-61 incident response lifecycle. Option D, Detection and Analysis, is required because an incident must first be identified and its scope, impact, and nature analyzed before any response actions can be taken. Option B, Containment, Eradication, and Recovery, is required because responders must limit the damage (containment), remove the root cause or malware (eradication), and restore affected systems to normal operation (recovery).

Option C, Post-Incident Activity (Lessons Learned), is required because after recovery the organization must review what happened, update procedures and controls, and document findings to improve future response. Option A, Change Management Processing, is a supporting IT governance process rather than a required incident response phase, and Option E, System Hardening, is a preventive security control performed outside the incident response lifecycle, so neither belongs in the core required steps.

Exam trap

Cisco often tests the NIST incident response lifecycle phases and includes attractive distractors like Change Management or System Hardening that are related to security operations but are not part of the mandatory incident response procedure steps.

868
MCQhard

An analyst is triaging an alert generated by Cisco Secure Network Analytics (Stealthwatch) showing a host inside the network communicating with a known command-and-control IP. The analyst wants to determine whether the communication has already resulted in data theft. Which additional telemetry source would provide the most direct evidence of successful exfiltration?

A.DHCP lease logs showing the internal host renewed its IP address.
B.NetFlow records showing outbound byte volume from the internal host to the C2 address.
C.Authentication logs showing the user logged into the host via RDP.
D.Syslog entries from the host's antivirus agent showing a signature update occurred.
AnswerB

NetFlow volume counters directly quantify how much data left the internal host toward the command-and-control address. A large, sustained outbound byte count relative to the host's normal baseline is the most direct flow-level indicator that data was actually transferred rather than merely attempted. This makes it the strongest evidence of successful exfiltration among the available telemetry sources.

Why this answer

Confirming exfiltration requires evidence of data actually leaving the network. NetFlow byte counters toward the command-and-control address provide that measurement directly and can be compared against the host's normal egress baseline. Signature updates, DHCP leases, and authentication events are useful for context and attribution but cannot quantify outbound transfer volume, so they do not answer whether theft occurred.

Exam trap

The trap here is equating detection of command-and-control contact with proof of data theft; contact alone shows a channel exists, while flow byte counts are what demonstrate that data actually moved across it.

869
MCQeasy

Refer to the exhibit. A Windows security log shows several events with Event ID 4625 (failed logon). What type of attack is indicated?

A.Brute force attack
B.Pass-the-hash attack
C.Kerberos golden ticket attack
D.Man-in-the-middle attack
AnswerA

Repeated Event ID 4625 failures within a short window indicate many authentication attempts against accounts. This pattern of rapid, repeated failed logons is characteristic of a brute force attack rather than a single mistyped password.

Why this answer

Event ID 4625 indicates a failed logon attempt. A high volume of these events in a short period is characteristic of a brute force attack, where an attacker systematically tries multiple username/password combinations to gain unauthorized access. This is a direct indicator of repeated authentication failures, not a more sophisticated attack.

Exam trap

Cisco often tests the distinction between brute force attacks (which generate many failed logon events) and pass-the-hash or golden ticket attacks (which succeed without repeated failures), so the trap is assuming any failed logon event indicates a credential theft or replay attack rather than a simple password guessing attempt.

How to eliminate wrong answers

Option B is wrong because a pass-the-hash attack uses captured NTLM hashes to authenticate without needing the plaintext password, and it would not generate a high volume of failed logon events (Event ID 4625) since the attacker already has a valid hash. Option C is wrong because a Kerberos golden ticket attack forges a Ticket Granting Ticket (TGT) using the KRBTGT account hash, allowing persistent access without triggering repeated failed logon events; it would instead show successful logon events (Event ID 4624). Option D is wrong because a man-in-the-middle attack intercepts and potentially modifies communications between two parties, but it does not inherently generate a high volume of failed logon events; it might cause a single failed logon if credentials are replayed, not a flood of 4625 events.

870
MCQmedium

An analyst is examining a PE file and notices that the 'TimeDateStamp' in the optional header is 0x00000000. What does this suggest?

A.The timestamp has been deliberately erased or not set, possibly to avoid forensic analysis.
B.The file is digitally signed.
C.The file was compiled on January 1, 1970 (Unix epoch).
D.The file is a DLL rather than an executable.
AnswerA

A zero TimeDateStamp means the PE compiler timestamp was never written or was overwritten. Legitimate builds normally carry a real compilation time, so this absence suggests deliberate erasure to hinder timeline correlation during forensic analysis.

Why this answer

A timestamp of zero often indicates the linker did not set it, which is common for malware or files compiled with certain tools that omit the timestamp.

871
MCQeasy

A security analyst is investigating an alert from a Windows system log that shows multiple failed logon attempts for the same user account within a short period, followed by a successful logon. Which type of attack does this pattern suggest?

A.Brute-force attack
B.Pass-the-hash attack
C.Denial-of-service attack
D.Phishing attack
AnswerA

Repeated failed logons for one account followed by success is the signature of a brute-force attack, where an attacker systematically guesses credentials until one works. The volume within a short window distinguishes it from isolated user error.

Why this answer

A burst of failed logons for one account followed by a success is the classic signature of a brute-force (or password-spraying) attack that eventually guessed the correct credential. Windows Security log events 4625 (failed logon) repeated, then 4624 (successful logon), from the same source within a short window confirm this. The pattern indicates the attacker iterated passwords until one worked.

Exam trap

200-201 often tests the difference between brute force (many failures then success on one account) and password spraying (one failure per many accounts) — candidates pick brute force for both, or confuse the failed-then-success pattern with pass-the-hash, which never shows failures.

How to eliminate wrong answers

Option B is wrong because pass-the-hash uses a stolen NTLM hash to authenticate directly — it produces a successful logon (4624 with logon type 3/9) without a preceding storm of 4625 failures. Option C is wrong because a DoS attack aims to make a service unavailable (SYN floods, resource exhaustion) and does not produce a sequence of failed-then-successful authentication events. Option D is wrong because phishing steals credentials via a fake page or email; the resulting logon would typically be a single success from an unusual location, not repeated failures followed by success on the same account.

872
MCQeasy

Which of the following is a primary goal of the CIA triad?

A.Redundancy
B.Scalability
C.Availability
D.Maintainability
AnswerC

Availability ensures systems and data remain accessible to authorised users when needed, forming one of the three CIA triad pillars alongside confidentiality and integrity. It addresses the goal of preventing disruption and maintaining uptime for critical services.

Why this answer

The CIA triad's primary goals are confidentiality, integrity, and availability. Availability ensures that authorized users have reliable and timely access to data and resources when needed, which is a core security objective. Option C is correct because availability is explicitly one of the three pillars of the CIA triad.

Exam trap

Cisco often tests the distinction between a primary goal of the CIA triad and a supporting mechanism or operational characteristic, so candidates may confuse redundancy (a means to achieve availability) with availability itself.

How to eliminate wrong answers

Option A is wrong because redundancy is a design strategy to improve availability, not a primary goal of the CIA triad itself. Option B is wrong because scalability refers to the ability to handle increased load, which is a performance characteristic, not a security goal of the CIA triad. Option D is wrong because maintainability concerns the ease of updating or repairing a system, which is an operational concern, not a core security objective of the CIA triad.

873
Multi-Selecthard

Which TWO are best practices for managing SIEM alerts to reduce false positives? (Choose two.)

Select 2 answers
A.Disable all alerts that generate more than 100 events per day.
B.Use a separate SIEM for each department.
C.Regularly tune correlation rules based on feedback.
D.Increase the number of log sources.
E.Maintain a whitelist of known benign activity.
AnswersC, E

Adapts to environment.

Why this answer

SIEM correlation rules must be regularly tuned based on feedback from incident investigations and alert reviews. This iterative process adjusts thresholds, filters, and logic to match the actual threat landscape, reducing noise from benign events that match rule patterns but are not malicious.

Exam trap

Cisco often tests the misconception that more data (Option D) or volume-based suppression (Option A) is a valid way to reduce false positives, when in fact proper tuning and whitelisting are the correct approaches.

874
MCQeasy

A junior analyst is asked to review a Linux server for evidence of unauthorized access. They want to see a chronological record of authentication-related messages, including successful and failed logins, generated by the system's authentication services. Which file should the analyst examine?

A./var/log/dpkg.log
B./var/log/auth.log
C./var/log/boot.log
D./var/log/kern.log
AnswerB

On Debian and Ubuntu systems, /var/log/auth.log is the primary file where the authentication subsystem writes messages about successful and failed logins, sudo usage, and PAM events. Reviewing it gives the analyst the chronological authentication record they need to spot unauthorized access attempts on the server.

Why this answer

Authentication-related messages on Debian and Ubuntu are written to /var/log/auth.log by services such as sshd, sudo, and PAM. Because this file captures both successful and failed login attempts in chronological order, it is the correct source for reviewing unauthorized access on the server.

Exam trap

The trap here is assuming all Linux distributions use the same authentication log path, when Red Hat-based systems instead write to /var/log/secure and some use journald.

875
MCQhard

An intrusion analyst is analyzing a series of alerts from a network-based IDS. The alerts are triggered by the signature 'OVERFLOW-ICMP-ECHO' with a payload size of 65535 bytes. The source IP is a trusted internal server. What is the most likely explanation?

A.The server is performing a ping sweep
B.There is a network error causing packet fragmentation
C.The IDS signature is incorrectly configured
D.The server is under a DDoS attack
AnswerC

The payload size exceeds the maximum possible, so it's a false positive.

Why this answer

The ICMP Echo (ping) payload size is limited to 65535 bytes, but the actual data portion of an ICMP packet cannot exceed 65535 minus the IP and ICMP header sizes (typically 20 + 8 = 28 bytes), making a payload of exactly 65535 bytes impossible under normal operation. Since the source IP is a trusted internal server, the most plausible cause is that the IDS signature is misconfigured—likely with an incorrect payload size threshold or a false positive trigger—rather than an actual overflow attempt.

Exam trap

The trap here is that candidates assume a large ICMP payload must indicate an attack (like a Ping of Death or DDoS), but Cisco tests the understanding that a payload of exactly 65535 bytes is impossible in a single unfragmented ICMP packet, pointing to a signature misconfiguration rather than a real threat.

How to eliminate wrong answers

Option A is wrong because a ping sweep involves sending multiple ICMP Echo requests to different hosts, not a single oversized payload; the signature specifically flags payload size, not volume or destination range. Option B is wrong because network errors causing fragmentation would result in fragmented packets with smaller payloads per fragment, not a single packet claiming a 65535-byte payload; fragmentation occurs at the IP layer and does not change the total payload size reported in the ICMP header. Option D is wrong because a DDoS attack would typically involve a high volume of traffic from multiple sources, not a single oversized ICMP packet from a trusted internal server; the signature is triggered by payload size, not traffic volume or source diversity.

876
MCQeasy

A network security analyst is reviewing firewall logs and sees repeated denied inbound connection attempts from various external IP addresses to TCP port 3389 on several internal hosts. Which type of activity does this most likely represent?

A.A brute-force attack against Remote Desktop Protocol
B.A denial-of-service attack targeting the RDP service
C.A misconfigured application attempting to connect to a database
D.A legitimate remote administration session from an IT administrator
AnswerA

Port 3389 is used by Microsoft Remote Desktop Protocol (RDP). Repeated inbound connection attempts from multiple external IPs to this port indicate an attempt to gain unauthorized access, often through brute-force or password spraying. The fact that the connections are denied means the firewall is blocking them, but the pattern is characteristic of an RDP brute-force attack.

Why this answer

Port 3389 is the default for Microsoft RDP. Multiple external IPs attempting to connect to this port on internal hosts, with the firewall denying the connections, is a classic sign of an RDP brute-force or scanning attack. Legitimate administrative sessions would come from trusted sources and likely succeed.

DoS would involve higher volume from fewer sources, and database connections would use different ports. The correct answer is a brute-force attack against RDP.

Exam trap

The trap here is assuming that any traffic to port 3389 is legitimate remote administration, overlooking that external IPs attempting to connect is a major red flag.

877
MCQhard

Refer to the exhibit. Based on the intrusion event, what is the likely intent of the traffic?

A.Denial of service
B.Normal web browsing
C.Port scan
D.Buffer overflow attempt
AnswerD

Oversized input sent to a service that fails to bound-check its buffers causes memory corruption, letting an attacker overwrite adjacent memory and redirect execution. The exhibit's malformed, unusually long payload targeting a listening service is characteristic of this attempt to gain code execution or crash the process.

Why this answer

The intrusion event shows a long string of 'A' characters (0x41) being sent to an HTTP server, which is a classic pattern for a buffer overflow attack. The intent is to overflow a buffer in the web server software, potentially overwriting memory and executing arbitrary code, making D the correct answer.

Exam trap

Cisco often tests the ability to distinguish between attack types by focusing on payload characteristics—candidates may confuse a buffer overflow with a DoS because both involve excessive data, but the structured pattern of repeated characters is the key differentiator.

How to eliminate wrong answers

Option A is wrong because denial of service (DoS) typically involves flooding the target with traffic to exhaust resources, not sending a specific pattern of data to exploit a memory vulnerability. Option B is wrong because normal web browsing does not involve sending repeated, non-standard characters like a long string of 'A's; HTTP requests are structured with valid headers and payloads. Option C is wrong because a port scan uses techniques like SYN, FIN, or NULL packets to probe open ports, not a single connection with a malformed payload to a specific service.

878
MCQhard

A security policy states that all portable media must be encrypted. An employee loses a USB drive containing customer data. The drive was encrypted with AES-256. Which of the following is true regarding policy compliance?

A.The policy was followed, but the incident still needs to be reported per incident response procedures
B.The employee violated policy because the drive was lost
C.The policy was followed because the data was encrypted, so a breach is not reportable
D.Encryption is not sufficient, the employee should have used a different media
AnswerA

AES-256 encryption satisfies the portable media encryption requirement, so the policy itself was followed. Loss of the drive is still a security incident involving customer data, triggering mandatory reporting under incident response procedures regardless of encryption.

Why this answer

The security policy mandates encryption for portable media, and AES-256 encryption was applied to the USB drive, so the policy was technically followed. However, the loss of a device containing customer data still triggers incident response procedures, as the encryption key or the possibility of decryption could be compromised, and reporting is required to assess risk and comply with breach notification laws.

Exam trap

Cisco often tests the distinction between policy compliance and incident response obligations, trapping candidates who assume encryption alone eliminates the need to report a lost device.

How to eliminate wrong answers

Option B is wrong because the policy does not prohibit loss of media; it requires encryption, which was applied, so the employee did not violate the policy itself. Option C is wrong because encryption does not automatically exempt an incident from reporting; many regulations (e.g., GDPR, HIPAA) require breach notification if there is any risk of data exposure, and the loss of the drive must be evaluated. Option D is wrong because AES-256 is a strong, approved encryption standard, and the policy does not specify a different media type; the issue is not the encryption strength but the physical loss and reporting obligation.

879
MCQeasy

A network security analyst is configuring a SPAN session on a Cisco switch so that a Cisco Firepower sensor can inspect traffic between the internal user VLAN and the internet-facing router. The switch has a single physical uplink carrying that traffic. Which configuration goal must the analyst keep in mind to ensure the sensor receives complete sessions?

A.The sensor interface must be set to promiscuous mode and assigned an IP address on the monitored VLAN.
B.The SPAN session must be configured with the encapsulation replicate option to copy VLAN tags.
C.The SPAN source must include both transmit and receive directions of the monitored interface.
D.The SPAN destination port must be configured as a trunk carrying all VLANs.
AnswerC

To reconstruct complete TCP sessions, the sensor needs to see packets flowing in both directions. If only one direction is mirrored, the sensor sees half-conversations, which degrades detection and can prevent session reassembly. Configuring the source interface to capture both ingress and egress traffic is therefore the essential requirement for this deployment.

Why this answer

Session reassembly requires visibility into both directions of a conversation. When a SPAN source mirrors only one direction, the sensor sees SYN packets without replies or requests without responses, crippling detection and logging. Configuring the source to capture both transmit and receive traffic on the monitored interface ensures the sensor receives full bidirectional sessions for accurate analysis.

Exam trap

The trap here is focusing on destination-port settings like trunking or VLAN tag replication, when the actual determinant of complete session capture is mirroring both directions at the SPAN source.

880
MCQeasy

An analyst notices repeated failed SSH attempts from an external IP to a server. The analyst wants to quickly see all SSH-related events from that IP in the last hour. Which approach is most efficient?

A.Search the SIEM for events with destination port 22 and source IP.
B.Review all firewall logs for the past hour.
C.Run a packet capture on the server's network interface.
D.Check the server's auth.log file manually.
AnswerA

Filtering the SIEM by destination port 22 and the source IP returns exactly the SSH-related events from that address within the last hour. This is the most efficient approach, avoiding manual log review across multiple servers.

Why this answer

A SIEM indexes and correlates log data from multiple sources, allowing an analyst to quickly filter events by destination port 22 (SSH) and source IP without manually sifting through raw logs. This approach leverages the SIEM's search capabilities to retrieve only relevant events from the past hour, making it the most efficient method for targeted threat hunting.

Exam trap

Cisco often tests the distinction between centralized log analysis (SIEM) and raw data inspection (packet capture or manual log review), trapping candidates who overlook the efficiency of indexed search versus unfiltered data retrieval.

How to eliminate wrong answers

Option B is wrong because reviewing all firewall logs for the past hour would include irrelevant traffic (e.g., web, DNS) and lacks the specific filter for SSH (port 22) and the external IP, requiring manual parsing and wasting time. Option C is wrong because running a packet capture on the server's network interface captures all traffic in real-time or from a buffer, but it does not provide historical data for the past hour unless a capture was already running, and it generates large volumes of data that must be analyzed with tools like tcpdump or Wireshark, which is inefficient for a quick check. Option D is wrong because checking the server's auth.log file manually is a host-based approach that only shows authentication attempts on that specific server, not all SSH-related events from the IP (e.g., connection attempts blocked by a firewall), and it requires direct access to the server, which may not be scalable or centralized.

881
MCQeasy

A NetFlow analysis shows a single internal host communicating with many external IP addresses on port 443, but the traffic volumes are very low (small packets). What is the most likely explanation?

A.Phishing
B.Web browsing
C.Port scanning
D.C2 communication
AnswerD

Malware beacons often use low-volume periodic connections on port 443.

Why this answer

The combination of a single internal host communicating with many external IPs on port 443 (HTTPS) with very low traffic volumes and small packets is a classic indicator of command-and-control (C2) beaconing. C2 malware often uses HTTPS to blend in with legitimate web traffic, but the small, periodic packets (e.g., keep-alive or heartbeat messages) distinguish it from normal web browsing, which would involve larger data transfers and consistent payload sizes.

Exam trap

Cisco often tests the distinction between 'many destinations with low volume' (C2 beaconing) and 'many destinations with high volume' (normal web browsing or data exfiltration), trapping candidates who overlook the packet size and volume clues.

How to eliminate wrong answers

Option A is wrong because phishing typically involves a single or limited number of external servers hosting malicious content, not a pattern of many external IPs, and phishing traffic often includes larger payloads (e.g., email attachments or web page downloads). Option B is wrong because normal web browsing to many external HTTPS sites would generate larger, variable-sized packets due to page content, images, and scripts, not consistently small packets. Option C is wrong because port scanning on port 443 would involve a high volume of SYN packets (often without completing the TCP handshake) or other probe packets, not established HTTPS sessions with small data exchanges.

882
MCQeasy

In the OSI model, which layer is primarily targeted by a SYN flood attack?

A.Network Layer (Layer 3)
B.Application Layer (Layer 7)
C.Transport Layer (Layer 4)
D.Data Link Layer (Layer 2)
AnswerC

A SYN flood exploits the TCP three-way handshake by sending repeated SYN packets without completing the connection, exhausting the backlog of half-open connections. This handshake operates at the Transport Layer (Layer 4), so that layer is the attack's direct target.

Why this answer

A SYN flood attack targets the Transport Layer (Layer 4) by exploiting the TCP three-way handshake. The attacker sends a high volume of SYN packets with spoofed source IP addresses, causing the target server to allocate resources for half-open connections that never complete, eventually exhausting its connection queue and denying service to legitimate users.

Exam trap

Cisco often tests the distinction between the Transport Layer (Layer 4) and the Network Layer (Layer 3), where candidates mistakenly associate IP spoofing (a Layer 3 technique) with the attack's target layer, rather than recognizing that the attack exploits TCP's stateful handshake at Layer 4.

How to eliminate wrong answers

Option A is wrong because the Network Layer (Layer 3) handles IP routing and packet forwarding, not the TCP handshake mechanics that SYN floods exploit. Option B is wrong because the Application Layer (Layer 7) deals with protocols like HTTP, DNS, and SMTP, whereas SYN floods operate below this layer at the transport protocol level. Option D is wrong because the Data Link Layer (Layer 2) manages MAC addresses and frame delivery on a local network segment, and has no role in TCP connection state management.

883
MCQeasy

A Linux analyst wants to identify all listening TCP ports on a system. Which command is most appropriate?

A.netstat -an
B.ss -tlnp
C.lsof -i
D.ps aux
AnswerB

The `ss -tlnp` command combines `-t` for TCP sockets, `-l` for listening state, `-n` for numeric ports, and `-p` for owning processes, directly satisfying the requirement to enumerate every listening TCP port on the Linux host.

Why this answer

ss -tlnp shows listening TCP sockets with process info.

884
MCQhard

In a PKI, what is the role of a Certificate Authority (CA)?

A.Generates private keys for users
B.Provides symmetric keys for session encryption
C.Encrypts data for secure transmission
D.Issues and validates digital certificates
AnswerD

The CA is the trusted third party within a PKI that issues digital certificates, binding a public key to a verified identity, and validates those certificates through its registration and revocation processes. This satisfies the stem's requirement for trusted certificate issuance and validation.

Why this answer

A Certificate Authority (CA) is a trusted entity that issues and validates digital certificates. It verifies the identity of certificate applicants and signs the certificates with its private key, thereby binding a public key to an identity. This is the core function of a CA in a PKI.

Exam trap

200-201 often tests the misconception that the CA generates private keys or performs encryption; candidates must remember that the CA only issues and validates certificates.

How to eliminate wrong answers

Option A is wrong because the CA does not generate private keys for users; users generate their own key pairs, and the CA only certifies the public key. Option B is wrong because symmetric keys for session encryption are typically generated by the communicating parties, not the CA. Option C is wrong because the CA does not encrypt data for transmission; it only provides certificates that enable encryption through public key cryptography.

885
MCQhard

A network engineer is deploying a Cisco Next-Generation IPS (NGIPS) in inline mode. The security team wants to ensure that the device can block malicious traffic while also providing contextual information about the attack. Which of the following Cisco NGIPS features provides detailed information about the attack and the target, including vulnerability mapping?

A.FireSIGHT (now Cisco Firepower) correlation and impact flags
B.Access Control Policy with URL filtering
C.Network Analysis Policy (NAP)
D.Security Intelligence (SI)
AnswerA

FireSIGHT (now integrated into Cisco Firepower) correlates intrusion events with host vulnerability data to provide impact flags and contextual information. This helps analysts understand the severity and potential impact of an attack by mapping it to known vulnerabilities on the target host.

Why this answer

The correct answer is the feature that correlates intrusion events with host vulnerability data. Cisco Firepower's FireSIGHT technology provides impact flags that indicate whether an attack is relevant to the target's vulnerabilities, giving analysts the context needed to prioritize response. This goes beyond simple signature matching.

Exam trap

The trap here is confusing policy configuration features with analysis and contextual features; only FireSIGHT provides vulnerability mapping and impact assessment.

886
MCQhard

A NetFlow report shows that host 10.0.0.5 has sent 1 GB of data to external IP 198.51.100.10 over port 443 in the last hour, while other hosts average 100 MB. This anomaly is most indicative of:

A.Port scan activity
B.Normal video streaming
C.DNS amplification attack
D.Data exfiltration
AnswerD

Sustained outbound transfer over port 443 to one external address, at ten times the peer baseline, indicates data leaving the network. Port 443 is commonly abused to blend with HTTPS traffic, and the volume deviation from other hosts satisfies the anomaly constraint in the stem.

Why this answer

The sudden, disproportionate egress of 1 GB of data from a single host to an external IP over port 443 (HTTPS) is a classic indicator of data exfiltration. While HTTPS traffic is common, the volume anomaly—10x the average of other hosts—suggests unauthorized copying of sensitive data, as attackers often use encrypted channels to blend in with normal traffic.

Exam trap

Cisco often tests the distinction between 'volume anomalies' and 'connection anomalies'—the trap here is confusing a large data transfer (exfiltration) with a volumetric attack (like DDoS) or reconnaissance (like port scanning), when the key is the direction and volume of the traffic to a single external host.

How to eliminate wrong answers

Option A is wrong because port scan activity typically generates many small packets to multiple ports or IPs, not a large volume of data to a single destination over a single port. Option B is wrong because normal video streaming would show consistent, high-bandwidth flows from many hosts, not a single host sending 10x the average to one external IP. Option C is wrong because a DNS amplification attack uses small queries to generate large responses to a victim, characterized by high UDP traffic on port 53, not a single host sending large amounts of TCP data over port 443.

887
Multi-Selectmedium

An analyst is examining network alerts for lateral movement. Which TWO of the following are typical indicators of lateral movement using SMB?

Select 2 answers
A.A single SMB connection to a file server
B.Multiple SMB connection attempts from a single host to many different hosts
C.NTLM authentication using a hash instead of a password
D.DNS queries for internal hostnames
E.HTTP requests to a web server
AnswersB, C

Lateral movement tools such as PsExec and Cobalt Strike's SMB beacon rapidly authenticate to many hosts from one source. A single host initiating SMB sessions to numerous distinct hosts deviates from normal peer-to-peer patterns and indicates propagation.

Why this answer

Option B is correct because lateral movement via SMB typically manifests as one compromised host rapidly initiating SMB (TCP 445) connections to numerous distinct internal hosts, reflecting an attempt to fan out and find accessible targets or admin shares such as C$ or ADMIN$. Option C is correct because pass-the-hash attacks, a hallmark of SMB-based lateral movement, authenticate with an NTLM hash via NTLM challenge-response rather than a cleartext password, which is anomalous and strongly indicative of credential theft and reuse. Option A is not an indicator because a single SMB connection to a file server is normal, benign business activity.

Option D is not specific to SMB lateral movement, since DNS queries for internal hostnames occur routinely during normal name resolution. Option E is unrelated, as HTTP requests to a web server involve the HTTP protocol on ports 80/443, not SMB.

Exam trap

200-201 often tests the confusion between normal SMB traffic and malicious lateral movement, and the misconception that any NTLM authentication is suspicious when only hash-based authentication is a red flag.

888
MCQeasy

Which protocol and port combination is commonly used for secure remote administration of network devices?

A.Telnet on port 23
B.SSH on port 22
C.RDP on port 3389
D.HTTP on port 80
AnswerB

SSH encrypts the entire session, including credentials and commands, unlike Telnet on port 23, which transmits everything in cleartext. Port 22 is SSH's registered port, so it satisfies the requirement for secure remote administration of network devices.

Why this answer

SSH (Secure Shell) on port 22 is the correct answer because it provides encrypted, authenticated remote administration of network devices, replacing insecure protocols like Telnet. SSH uses public-key cryptography to establish a secure channel over an unsecured network, ensuring confidentiality and integrity of management traffic. This is the standard for secure CLI-based device management in enterprise environments.

Exam trap

Cisco often tests the distinction between Telnet and SSH, where candidates mistakenly choose Telnet because it is historically common for device management, forgetting that the question explicitly asks for 'secure' remote administration.

How to eliminate wrong answers

Option A is wrong because Telnet uses port 23 but transmits all data, including credentials, in cleartext, making it vulnerable to packet sniffing and man-in-the-middle attacks; it is not secure. Option C is wrong because RDP (Remote Desktop Protocol) on port 3389 is designed for remote GUI access to Windows desktops and servers, not for CLI-based network device administration. Option D is wrong because HTTP on port 80 is unencrypted and used for web traffic, not for secure remote administration; HTTPS (port 443) would be the secure alternative for web-based management.

889
MCQmedium

An analyst is investigating an incident and needs to determine the source of a piece of malware. The analyst finds that the malware uses a domain generation algorithm to contact command-and-control servers. Which term best describes this capability?

A.Persistence
B.Command and control
C.Lateral movement
D.Privilege escalation
AnswerB

Command and control (C2) describes the communication channel between malware and its operator. A domain generation algorithm produces many possible domain names that the malware queries to find an active C2 server, making it harder for defenders to block a single domain. The scenario explicitly mentions contacting command-and-control servers, so this capability is best described as command and control. It is the correct term for the malware's remote communication mechanism.

Why this answer

A domain generation algorithm creates a large set of pseudo-random domain names that malware periodically queries to find an active command-and-control server. This technique helps the malware evade static blocklists and takedown attempts, because defenders cannot easily predict or block every possible domain. The scenario states the malware contacts command-and-control servers, so the capability is command and control.

Persistence, privilege escalation, and lateral movement describe different phases or objectives of an intrusion.

Exam trap

The trap here is associating any advanced evasion technique with persistence, when the domain generation algorithm specifically supports locating and communicating with C2 infrastructure.

890
MCQmedium

A security analyst observes a NetFlow record showing a single internal IP communicating with many external IPs on port 445 within seconds. This pattern is indicative of:

A.DNS tunneling
B.Data exfiltration
C.SMB scanning
D.Port scan
AnswerC

SMB scanning matches the record precisely: port 445 is SMB, and one internal host contacting many external IPs within seconds indicates horizontal sweeps seeking exposed file shares. The high fan-out and short timeframe satisfy the stem's beaconing-free, rapid connection pattern, distinguishing it from single-target exploitation or data transfer.

Why this answer

A single internal host contacting many external IPs on TCP/445 in a short window is the signature of SMB scanning — the host is enumerating SMB services across the internet or a target range. Port 445 is the SMB-over-TCP port, and the fan-out to many destinations distinguishes scanning from a single-target connection. This is often a precursor to SMB exploitation (EternalBlue, SMBGhost) or lateral movement.

Exam trap

200-201 often tests the distinction between a port scan (many ports, few hosts) and service scanning (one port, many hosts) — candidates default to 'port scan' whenever they see many connections, missing that the single-port fan-out indicates SMB service enumeration.

How to eliminate wrong answers

Option A is wrong because DNS tunneling uses UDP/TCP port 53 with encoded subdomains, not port 445 to many external IPs. Option B is wrong because data exfiltration typically shows large outbound transfers to a small number of destinations, not many short connections to many IPs on one port. Option D is wrong because a generic port scan would hit many ports on one or a few hosts; here the pattern is one port (445) across many hosts, which is service-specific scanning, not a broad port sweep.

891
MCQmedium

A SOC analyst reviewing a packet capture notices that a single internal host has initiated hundreds of short-lived TCP sessions to the same external web server over the past hour, and every session completed a full three-way handshake before being torn down with FIN/ACK. No single session transferred more than a few kilobytes. Which traffic characteristic should the analyst use to classify this activity?

A.Possible beaconing or automated application behavior, because repeated uniform short sessions at regular volume suggest periodic callbacks.
B.A TCP SYN flood, because many connection attempts were made to one destination in a short period.
C.A slowloris-style denial of service, because each session stayed open for a short time.
D.A port scan, because the host contacted the same server repeatedly.
AnswerA

Repeated, uniform, short-lived completed TCP sessions to the same external endpoint are characteristic of beaconing malware or an automated client polling a service on a timer. The consistent small transfer size and full handshake/teardown pattern distinguish it from scanning or flooding. The analyst should baseline the interval and correlate with process and destination reputation to confirm whether it is malicious command-and-control.

Why this answer

Repeated short TCP sessions with complete handshakes and consistent small payloads point to periodic automated communication such as malware beaconing, not resource-exhaustion attacks or scanning. A SYN flood and slowloris both leave connections incomplete by design, while a port scan varies destination ports and usually never completes a session. The distinguishing evidence is the uniform, repeating, fully established flow pattern.

Exam trap

The trap here is assuming that high connection volume to one destination automatically means a denial-of-service flood, when the state of the handshake and teardown reveals the true nature of the traffic.

892
Multi-Selectmedium

Which THREE of the following are common types of malware?

Select 3 answers
A.Patch
B.Virus
C.Ransomware
D.Worm
E.Firewall
AnswersB, C, D

A virus is a self-replicating malware type that attaches to legitimate files or executables, spreading when those hosts run. It satisfies the stem's requirement for a common malware category, distinct from standalone threats such as worms or trojans. Microsoft Entra ID documentation and standard security curricula classify viruses among the core malware families.

Why this answer

Option B (Virus) is correct because a virus is a classic malware category: self-replicating code that attaches to a host file or program and spreads when the host is executed. Option C (Ransomware) is correct because ransomware is a well-known malware type that encrypts or locks victim data and demands payment, often using symmetric keys like AES with an asymmetric-wrapped key. Option D (Worm) is correct because a worm is standalone self-replicating malware that spreads across networks (e.g., via SMB or email) without needing a host file.

Option A (Patch) does not belong because a patch is a legitimate software update that fixes vulnerabilities, not malicious code. Option E (Firewall) does not belong because a firewall is a security control that filters network traffic by rules, not a malware type.

Exam trap

Cisco often tests the distinction between security tools (like patches and firewalls) and actual malware types, leading candidates to mistakenly classify protective measures as malicious software.

893
Multi-Selecthard

During an incident response, an analyst finds evidence of lateral movement. Which THREE of the following are common techniques used for lateral movement?

Select 3 answers
A.Remote Desktop Protocol (RDP) connections
B.SMB authentication attempts across multiple hosts
C.DNS tunneling
D.Pass-the-hash attacks
E.ICMP echo requests
AnswersA, B, D

RDP gives an attacker an interactive graphical session on a remote host once valid credentials are obtained, enabling direct control of additional systems. That remote-access mechanism moves the intrusion sideways across the estate, matching the stem's lateral movement evidence.

Why this answer

SMB authentication attempts, pass-the-hash, and RDP are common lateral movement techniques.

894
MCQmedium

An analyst reviews an alert that triggered on a network signature for 'shellcode' in a payload. The payload contains a sequence of NOP sleds followed by executable code. Which type of exploitation technique does this indicate?

A.Return-oriented programming (ROP)
B.Heap spray
C.Buffer overflow with NOP sled
D.Format string attack
AnswerC

A NOP sled preceding executable code is the signature of a buffer overflow exploit, where the sled provides a landing zone for the overwritten return address to jump into. The network signature detecting shellcode in the payload confirms this exploitation technique.

Why this answer

A NOP sled (a long run of no-operation instructions) immediately preceding shellcode is the classic signature of a stack-based buffer overflow exploit. The sled gives the attacker a large landing zone so the overwritten return address only needs to jump somewhere into the sled, which then slides execution into the payload.

Exam trap

200-201 often tests whether candidates can distinguish NOP-sled buffer overflows from heap sprays and ROP, since all three involve shellcode delivery but use different memory structures and bypass techniques.

How to eliminate wrong answers

Option A is wrong because ROP chains together short existing code gadgets ending in return instructions to bypass DEP, and does not rely on a NOP sled. Option B is wrong because heap spray fills heap memory with repeated copies of shellcode (often using NOP-like padding) to increase the odds of a jump landing in the payload, but the described sequence of NOP sled plus executable code in a single payload is the buffer overflow pattern. Option D is wrong because format string attacks abuse printf-style format specifiers like %n to write to memory, not NOP sleds.

895
MCQmedium

An organization is developing an Acceptable Use Policy (AUP). Which of the following topics is typically covered in an AUP?

A.Password complexity requirements
B.Incident reporting procedures
C.Data classification levels
D.Prohibition of using company resources for illegal activities
AnswerD

An Acceptable Use Policy defines permitted and forbidden employee behaviour on organisational systems. Prohibiting use of company resources for illegal activities is a core AUP clause, establishing legal boundaries and enabling disciplinary action, directly satisfying the typical AUP content requirement.

Why this answer

An AUP defines acceptable use of IT resources, including prohibiting unauthorized access, personal use guidelines, and security responsibilities.

896
MCQeasy

Which best practice helps ensure accurate network intrusion analysis when reviewing logs from multiple sources?

A.Use synchronized time across all devices.
B.Disable all logging except firewall logs.
C.Rely solely on automated analysis tools.
D.Store logs in different formats for each source.
AnswerA

Correlating events across firewalls, IDS and hosts requires a common timeline; without synchronised clocks via NTP, packet timestamps drift between devices, making it impossible to reconstruct the true sequence of an intrusion and producing false conclusions about causality.

Why this answer

Synchronized time (via NTP) ensures that logs from different sources share a consistent timestamp, which is critical for correlating events across network devices during intrusion analysis. Without time synchronization, an attacker's actions might appear out of order or be missed entirely, leading to inaccurate incident reconstruction.

Exam trap

Cisco often tests the misconception that log format consistency is more important than time synchronization, but without synchronized time, even identical formats cannot provide accurate event correlation.

How to eliminate wrong answers

Option B is wrong because disabling all logging except firewall logs eliminates valuable data from sources like IDS/IPS, servers, and endpoints, which are essential for detecting multi-stage attacks. Option C is wrong because relying solely on automated analysis tools can miss context-dependent attacks or generate false positives; human analysis is needed to validate alerts. Option D is wrong because storing logs in different formats for each source increases parsing complexity and hinders correlation, whereas standardized formats (e.g., syslog, CEF) simplify analysis.

897
Multi-Selecthard

During PCAP analysis, a security analyst observes the following pattern: a series of TCP SYN packets to multiple ports on a target, followed by RST packets from the target for closed ports. Which TWO characteristics describe this scan?

Select 2 answers
A.It uses ICMP echo requests
B.It is a SYN scan
C.It is a UDP scan
D.It completes the TCP three-way handshake
E.It is a stealthy scan that may avoid logging
AnswersB, E

Sending SYN packets to multiple ports and interpreting RST replies for closed ports is the defining behaviour of a half-open SYN scan, which never completes the handshake. This matches the packet pattern in the stem, distinguishing it from a full-connect scan that completes the three-way handshake.

Why this answer

The SYN scan sends SYN packets and listens for SYN-ACK (open) or RST (closed). It is a stealthy scan because it doesn't complete the TCP handshake.

898
MCQmedium

A company is developing a new security policy for cloud storage. Which principle should be the foundation of the policy to ensure data confidentiality and integrity?

A.Access logs must be retained for at least one year.
B.Only authorized users can access the cloud storage.
C.All data must be encrypted at rest and in transit.
D.Data must be backed up daily.
AnswerC

Encrypting data at rest and in transit directly enforces confidentiality and integrity, satisfying the policy's core requirement. At rest, AES protects stored objects from unauthorised disk access; in transit, TLS prevents interception or tampering. This combination addresses both stated goals, unlike availability-focused or access-control-only measures.

Why this answer

Encryption at rest and in transit directly protects data confidentiality and integrity by rendering data unreadable without the proper decryption keys and by ensuring data is not tampered with during transmission. In cloud storage, encryption at rest (e.g., AES-256) safeguards data stored on disk, while encryption in transit (e.g., TLS 1.2/1.3) prevents interception or modification during upload/download. This dual-layer approach is the foundational security control for meeting confidentiality and integrity objectives, as defined in the CIA triad.

Exam trap

Cisco often tests the distinction between foundational security principles (encryption) and supporting controls (logging, access control, backups), trapping candidates who confuse a necessary but insufficient measure like 'only authorized users' with the core requirement for confidentiality and integrity.

How to eliminate wrong answers

Option A is wrong because retaining access logs for one year supports auditing and incident response but does not directly enforce data confidentiality or integrity; logs are a detective control, not a preventive or protective measure. Option B is wrong because only allowing authorized users to access cloud storage addresses confidentiality through access control, but it does not ensure integrity (e.g., authorized users could still modify data) and provides no protection against data exposure if the storage medium is compromised. Option D is wrong because daily backups ensure availability and disaster recovery, not confidentiality or integrity; backups can be encrypted, but the act of backing up alone does not protect data from unauthorized access or tampering.

899
MCQeasy

A security analyst detects a host infected with ransomware on the corporate network. According to incident response procedures, what should be the first action?

A.Reimage the host immediately
B.Update antivirus signatures
C.Notify the IT management team
D.Isolate the host from the network
AnswerD

Isolating the host immediately halts lateral spread and further encryption of network shares, which is the priority while the ransomware is still active. Containment precedes eradication, recovery and analysis, so cutting network connectivity first preserves evidence and limits damage.

Why this answer

The first action when a host is infected with ransomware is to isolate it from the network to prevent lateral movement and further encryption of shared resources. Ransomware often uses SMB, RDP, or other network protocols to spread, so disconnecting the host (e.g., by disabling the switch port or unplugging the cable) stops the propagation immediately. This aligns with the NIST incident response framework's containment phase, which prioritizes stopping the attack before any remediation.

Exam trap

Cisco often tests the misconception that immediate eradication (reimaging) or notification is the priority, but the correct first step is always containment to stop the spread, as per the NIST and SANS incident response frameworks.

How to eliminate wrong answers

Option A is wrong because reimaging the host immediately destroys forensic evidence (e.g., memory dumps, registry keys, or ransomware binary) that could be critical for attribution and understanding the attack vector. Option B is wrong because updating antivirus signatures is a preventive measure that does not stop an active ransomware infection; the ransomware is already executing and may evade signature-based detection. Option C is wrong because notifying IT management is a communication step that should occur after containment; delaying isolation to notify first allows the ransomware to spread further across the network.

900
MCQmedium

During a security incident, the incident handler identifies that the breach involves personally identifiable information (PII) of customers. Which role is primarily responsible for determining if legal notification requirements apply?

A.Legal counsel
B.Incident handler
C.HR
D.CISO
AnswerA

Legal counsel determines whether legal notification requirements apply, as they interpret breach-notification statutes and regulations governing PII. This satisfies the scenario's constraint: assessing statutory obligations after a PII breach. Security analysts and incident handlers identify and contain the incident, but only legal counsel can judge mandatory disclosure duties to customers, regulators, or authorities.

Why this answer

Legal counsel is primarily responsible for interpreting breach notification laws (e.g., GDPR, CCPA, HIPAA) and determining whether the incident triggers mandatory legal notifications. They assess factors such as the type of data involved, the number of affected individuals, and the jurisdiction to decide if notification is required. The incident handler focuses on technical containment and recovery, not legal analysis.

Exam trap

The trap here is confusing the technical incident response role with the legal compliance role; candidates might assume the incident handler or CISO determines notification requirements, but legal counsel is the correct authority.

How to eliminate wrong answers

Option B is wrong because the incident handler's role is to manage the technical response, not to interpret legal statutes or determine notification obligations. Option C is wrong because HR handles employee-related matters, not customer data breach notifications. Option D is wrong because the CISO oversees the overall security program and may be informed, but legal counsel is the authority on legal notification requirements.

Page 11

Page 12 of 13

Page 13