Courseiva

Cisco CyberOps Associate 200-201 (200-201) — Questions 901–968

968 questions total · 13pages · All types, answers revealed

Page 12

Page 13 of 13

901
MCQeasy

Which data source provides the most detailed information about the application layer payload in network traffic?

A.NetFlow
B.Syslog
C.Full packet capture (PCAP)
D.SNMP
AnswerC

Full packet capture records entire packet contents, including application layer headers and payload, enabling deep inspection of protocols and data. Flow logs and metadata sources only summarise traffic, so PCAP provides the detailed payload visibility required.

Why this answer

Full packet capture (PCAP) provides the most detailed information because it records the entire raw network packet, including headers and the complete application-layer payload. This allows deep inspection of protocols like HTTP, DNS, or SMTP at the byte level, which is essential for detecting malware, data exfiltration, or application-specific anomalies.

Exam trap

Cisco often tests the misconception that NetFlow provides deep packet inspection because it can report application information via NBAR, but NBAR is a classification engine that still does not capture the raw payload; the trap is confusing flow metadata with full packet content.

How to eliminate wrong answers

Option A is wrong because NetFlow only exports metadata (e.g., IP addresses, ports, protocol, byte counts) and never includes the application payload; it summarizes flows rather than capturing full packet contents. Option B is wrong because Syslog is a logging protocol for system events and messages from devices or applications, not a network traffic capture mechanism; it cannot provide packet-level payload data. Option D is wrong because SNMP is used for monitoring and managing network device status (e.g., CPU, interface counters) via MIBs, and it does not capture or transmit network traffic payloads.

902
MCQmedium

An analyst notices that a DNS query for 'www.attacker.com' contains a long subdomain with Base64-encoded data. This activity is observed every 5 minutes. What exfiltration technique is most likely in use?

A.Steganography
B.DNS tunneling
C.HTTP POST exfiltration
D.FTP exfiltration
AnswerB

DNS tunneling uses DNS queries to exfiltrate data.

Why this answer

DNS tunneling encodes data within DNS queries and responses, often using Base64 or hex in subdomains, and is characterized by periodic, high-volume queries to a single domain. The long Base64-encoded subdomain and 5-minute interval are classic indicators of data exfiltration via DNS. Attackers use this because DNS is rarely blocked and often overlooked by security controls.

Exam trap

The trap here is confusing DNS tunneling with other exfiltration methods; candidates may pick HTTP POST because they see 'data exfiltration' but miss the DNS-specific indicators like Base64 subdomains and periodic queries.

How to eliminate wrong answers

Option A is wrong because steganography hides data inside images or other media files, not in DNS query strings. Option C is wrong because HTTP POST exfiltration would show large outbound HTTP payloads to an external server, not encoded subdomains in DNS queries. Option D is wrong because FTP exfiltration involves file transfers over ports 20/21, which would not appear as DNS queries with Base64-encoded subdomains.

903
MCQhard

A security analyst needs to verify that a downloaded software update has not been tampered with. The update's publisher provides a file containing a hash value. Which process should the analyst use to verify integrity?

A.Decrypt the file using the publisher's public key
B.Use a digital signature to sign the file
C.Compute the file's hash and compare it with the provided hash
D.Encrypt the file using the publisher's private key
AnswerC

Hashing is deterministic, so the analyst recomputes the digest of the downloaded file using the same algorithm and compares it against the publisher's supplied value; any mismatch proves the file was altered in transit or storage.

Why this answer

Verifying file integrity involves computing a cryptographic hash (e.g., SHA-256) of the downloaded file and comparing it to the hash provided by the publisher. If the hashes match, the file has not been altered; any tampering would produce a different hash value. This is a standard integrity check, not a confidentiality or authentication mechanism.

Exam trap

Cisco often tests the distinction between integrity (hash comparison) and authenticity (digital signatures), leading candidates to mistakenly choose digital signature verification when the question only asks about integrity.

How to eliminate wrong answers

Option A is wrong because decrypting a file with the publisher's public key would only work if the file were encrypted with the publisher's private key, which is used for confidentiality or non-repudiation, not for integrity verification of a hash. Option B is wrong because signing the file with a digital signature is a process the publisher performs to provide authenticity and integrity, but the analyst does not sign the file; the analyst verifies the signature using the publisher's public key. Option D is wrong because encrypting the file with the publisher's private key is not a standard integrity check; private key encryption is used for digital signatures or to prove origin, and the analyst would not have access to the publisher's private key.

904
MCQhard

An organization is developing a new cloud-based application. The security policy requires that all data be encrypted in transit and at rest. Which combination of controls meets this requirement?

A.Use a VPN for all connections
B.Encrypt the database using Transparent Data Encryption (TDE)
C.Use HTTPS for all communication
D.Use HTTPS and encrypt the database with TDE
AnswerD

HTTPS enforces TLS between client and server, covering data in transit. Transparent Data Encryption encrypts database files and backups at rest without application changes. Together they satisfy both halves of the policy's encryption mandate across the application's communication and storage layers.

Why this answer

The requirement is encryption both in transit and at rest. HTTPS (TLS) encrypts data in transit between clients and the application, while Transparent Data Encryption (TDE) encrypts the database files at rest. Using both together satisfies the dual requirement, making option D the only complete answer.

Exam trap

200-201 often tests the misconception that a single control (VPN, HTTPS, or TDE) satisfies both in-transit and at-rest requirements — candidates must recognize that two distinct controls are needed.

How to eliminate wrong answers

Option A is wrong because a VPN only encrypts traffic between network endpoints and does not address data at rest, nor does it cover all application-layer communication paths. Option B is wrong because TDE alone only encrypts data at rest and leaves data in transit unprotected. Option C is wrong because HTTPS alone only encrypts data in transit and leaves the database files unencrypted at rest.

905
MCQeasy

A security analyst at a financial services company is reviewing the organization's security program. The CISO wants to ensure that the confidentiality, integrity, and availability of information assets are protected by administrative, physical, and technical controls. Which security concept is the CISO describing?

A.The AAA framework, which governs authentication, authorization, and accounting for user access.
B.The OSI model, which defines seven layers of network communication used to design secure protocols.
C.The CIA triad, which defines the three core objectives of information security that controls must protect.
D.The principle of least privilege, which restricts users to only the access required to perform their jobs.
AnswerC

The CIA triad is exactly what the CISO describes: confidentiality, integrity, and availability are the three foundational objectives of information security. Administrative, physical, and technical controls are implemented specifically to protect these three properties of information assets. This aligns with the Cisco CyberOps objective of understanding the core security principles that guide the design of a security program.

Why this answer

The scenario names confidentiality, integrity, and availability as the properties controls must protect. These three objectives form the CIA triad, the foundational model of information security. Administrative, physical, and technical controls are all implemented to preserve these properties, so the concept described is the CIA triad rather than an access framework, a network model, or a single control principle.

Exam trap

The trap here is confusing the CIA triad with the AAA framework because both use three-letter acronyms and relate to security, but only the CIA triad describes confidentiality, integrity, and availability.

906
Multi-Selectmedium

A security analyst is investigating a network breach. Which TWO activities are examples of passive reconnaissance? (Choose two.)

Select 2 answers
A.Reviewing LinkedIn profiles of employees
B.Sending ping sweeps to identify live hosts
C.Using a vulnerability scanner to find weaknesses
D.Searching WHOIS records for domain registration details
E.Performing a port scan on the target network
AnswersA, D

Reviewing LinkedIn profiles gathers employee names, roles and technologies without touching the target's systems, so no packets reach the organisation. This indirect, non-intrusive collection satisfies the stem's passive-reconnaissance constraint, unlike scanning or banner grabbing, which generate detectable traffic.

Why this answer

Option A (Reviewing LinkedIn profiles of employees) is correct because it is passive reconnaissance: the analyst gathers publicly available employee information from social media without directly interacting with the target's systems, so no packets are sent to the organization's infrastructure. Option D (Searching WHOIS records for domain registration details) is also correct because WHOIS queries retrieve publicly registered domain ownership, contact, and nameserver data from third-party registries, again without touching the target network. By contrast, option B (ping sweeps) and option E (port scans) are active reconnaissance techniques that send ICMP echo requests or TCP/UDP probes directly to target hosts, and option C (vulnerability scanning) is active because it transmits crafted probes to identify weaknesses on the target systems.

Exam trap

200-201 often tests whether candidates can distinguish passive from active reconnaissance — candidates incorrectly classify WHOIS lookups as active because they involve querying a server, but WHOIS queries go to a third-party registry, not the target.

907
Multi-Selecteasy

A healthcare organization uses an online patient portal where patients can view their medical records. Recently, it was discovered that patient records were being modified by an unauthorized insider, and the system suffered a ransomware attack that encrypted the database, making it inaccessible for three days. Which TWO security principles were primarily violated? (Choose two.)

Select 2 answers
A.Confidentiality
B.Authentication
C.Integrity
D.Availability
E.Non-repudiation
AnswersC, D

Unauthorised modification of patient records directly breaches integrity, which guarantees data remains accurate and unaltered except by authorised parties. The insider's tampering satisfies this constraint precisely, independent of the ransomware's availability impact, so integrity is one of the two principles primarily violated.

Why this answer

Option C (Integrity) is correct because an unauthorized insider modified patient records, which is a direct violation of data integrity—the assurance that data has not been altered or tampered with by unauthorized parties. Option D (Availability) is correct because the ransomware attack encrypted the database and rendered it inaccessible for three days, directly violating availability, which ensures systems and data are accessible to authorized users when needed. Option A (Confidentiality) is not marked correct because the scenario describes modification and encryption-for-ransom rather than unauthorized disclosure or exposure of patient data.

Option B (Authentication) is not marked correct because no failure of identity verification is described; the insider was authorized but acted improperly, and the ransomware is not framed as an authentication bypass. Option E (Non-repudiation) is not marked correct because the scenario does not involve disputing the origin or receipt of a transaction or proving that a specific party performed an action.

Exam trap

Cisco often tests the distinction between confidentiality (unauthorized viewing) and integrity (unauthorized modification), so the trap here is confusing the insider's modification of records as a confidentiality breach rather than an integrity violation.

908
MCQmedium

An organization is required to protect cardholder data. Which compliance framework applies to this requirement?

A.ISO 27001
B.HIPAA
C.GDPR
D.PCI DSS
AnswerD

PCI DSS is the payment card industry standard governing organisations that store, process or transmit cardholder data. Its twelve requirements mandate controls such as encryption, access restriction and network monitoring, directly satisfying the stem's cardholder data protection obligation.

Why this answer

PCI DSS is the Payment Card Industry Data Security Standard, which applies to organizations that handle credit card data.

909
Multi-Selectmedium

A security policy requires that all data at rest be encrypted. Which TWO of the following are considered best practices for implementing encryption?

Select 2 answers
A.Implement encryption at the application layer only.
B.Store encryption keys separately from the encrypted data.
C.Use weak encryption algorithms to reduce performance impact.
D.Use hardware-based encryption if available.
E.Use the same key for all data to simplify management.
AnswersB, D

Separating keys from ciphertext ensures a compromised data store does not expose the keys needed to decrypt it, directly satisfying the policy's data-at-rest protection goal. This is a foundational key-management practise: compromise of one asset must not yield both the locked data and the means to unlock it.

Why this answer

Option B is correct because storing encryption keys separately from the encrypted data is a fundamental key-management best practice: it ensures that if the data store is compromised, the attacker does not automatically obtain the keys needed to decrypt it, and it supports separation of duties and use of a dedicated KMS or HSM. Option D is correct because hardware-based encryption (for example, self-encrypting drives, TPMs, or HSMs) offloads cryptographic operations from the CPU, improving performance while providing tamper-resistant key storage and stronger protection of keys at rest. Option A is not a best practice because relying on application-layer encryption alone leaves data unprotected at other layers (disk, database, backup), so defense-in-depth is preferred.

Option C is wrong because weak algorithms such as DES or RC4 undermine confidentiality and should never be chosen for performance reasons; strong algorithms like AES-256 are used instead. Option E is wrong because reusing a single key for all data creates a single point of failure and broadens the blast radius of any key compromise; per-data or per-tenant keys with proper rotation are preferred.

Exam trap

200-201 often tests whether candidates confuse 'encryption exists' with 'encryption is done well' — the trap is picking convenience options (single key, weak algorithm) that undermine the security goal.

910
MCQhard

An analyst inspects a PCAP and finds a TCP stream where the client and server exchange data in alternating small chunks, each packet's payload is roughly 40 to 60 bytes, and the conversation lasts over two hours with consistent inter-packet delays of about ten seconds. The destination port is 443 but the payload is not TLS. Which conclusion is best supported?

A.The traffic is a large file transfer that has been fragmented by the network
B.The traffic is a reverse shell or command-and-control channel using interactive command semantics
C.The traffic is a DNS-over-HTTPS session resolving names for a busy client
D.The traffic is a misconfigured TLS session negotiating an unusually small cipher block
AnswerB

Alternating small payloads, long duration, and steady delays are hallmarks of an interactive remote shell or beacon where each request and response carries a short command or result. A reverse shell keeps the session alive for hours, and the ten-second cadence reflects either human interaction or a beacon interval. The non-TLS payload on port 443 confirms deliberate port masquerading to blend with expected HTTPS traffic.

Why this answer

Long-lived sessions with alternating short payloads and a steady interval are characteristic of interactive command-and-control or reverse shells, where each message carries a command or its output. Bulk transfers, TLS cipher negotiation, and DNS-over-HTTPS all produce different payload sizes, framing, and timing. The use of port 443 without TLS framing strengthens the conclusion that the port is being used to evade egress filtering rather than for legitimate web traffic.

Exam trap

The trap here is treating the destination port as proof of the protocol, when the payload inspection shows no TLS and the timing profile contradicts normal web browsing.

911
MCQmedium

You are a SOC analyst monitoring traffic on a corporate network. The network uses a next-generation firewall (NGFW) with intrusion prevention system (IPS). You receive an alert that the IPS detected a SQL injection attempt against the internal web application server (10.0.1.10) from an external IP (203.0.113.5). The IPS action was set to "alert" only, not "drop". Further investigation shows that the web server logs indicate the SQL injection succeeded and data was exfiltrated to 203.0.113.5. The web application is a custom application developed in-house. The database server (10.0.1.20) contains customer PII. Which of the following is the BEST immediate action to contain the incident?

A.Apply a software patch to the web application to fix the SQL injection vulnerability
B.Restore the web server from a known good backup
C.Block the attacker's IP address at the firewall and implement a temporary rule to drop all traffic from 203.0.113.5
D.Shut down the database server to prevent further data loss
AnswerC

Blocking 203.0.113.5 at the firewall and dropping its traffic immediately severs the exfiltration channel and prevents further exploitation, containing the active incident. The IPS was alert-only, so enforcement must be applied at the firewall to stop the ongoing attack.

Why this answer

The immediate priority is to stop the active data exfiltration and prevent further exploitation. Since the IPS was configured to 'alert' only, it did not block the malicious traffic. Blocking the attacker's IP at the firewall with a temporary drop rule is the fastest way to sever the attacker's access to the web server and stop the ongoing data theft, containing the incident while preserving forensic evidence.

Exam trap

Cisco often tests the distinction between containment, eradication, and recovery actions, and the trap here is that candidates confuse a long-term fix (patching) or a disruptive action (shutting down the database) with the immediate need to stop active data exfiltration.

How to eliminate wrong answers

Option A is wrong because applying a software patch is a remediation step, not an immediate containment action; it takes time to develop, test, and deploy, during which the attacker can continue exfiltrating data. Option B is wrong because restoring the web server from a known good backup is a recovery step that destroys volatile evidence (e.g., logs, active connections) and does not stop the attacker if they still have network access. Option D is wrong because shutting down the database server would cause immediate denial of service to legitimate users and may corrupt data; it also does not prevent the attacker from re-establishing access via the web server if the firewall remains open.

912
Multi-Selecthard

A SOC analyst is correlating multiple data sources after a suspected web application compromise on an internet-facing server. The analyst has access to web server logs, firewall logs, and endpoint detection and response (EDR) telemetry. Which TWO log sources or record types would most directly help identify the initial exploitation attempt and the subsequent post-exploitation activity? (Choose two.)

Select 2 answers
A.Web server access logs containing HTTP request methods, URIs, status codes, and user-agent strings
B.DHCP lease logs from the corporate network
C.EDR process creation and command-line telemetry from the web server host
D.Firewall logs showing allowed and denied connections between the internet and the DMZ
E.Switch port mirroring statistics showing interface utilization
AnswersA, C

Web server access logs record each request's method, URI, status code, and user-agent, making them the primary source for spotting exploitation attempts such as SQL injection, path traversal, or command injection in request parameters. They reveal the initial attack vector and timing, which anchors the rest of the investigation. Correlating these entries with endpoint activity identifies the exploited process and any spawned child processes.

Why this answer

Web server access logs expose the initial malicious HTTP request and its parameters, while EDR process and command-line telemetry reveals the resulting execution on the host, such as spawned shells or web shell activity. Together they connect the attack vector to post-exploitation behavior. Firewall, DHCP, and interface statistics provide useful context but lack the application and endpoint detail required to attribute and reconstruct the intrusion.

Exam trap

The trap here is selecting network-layer sources such as firewall logs because they sound comprehensive, when identifying exploitation and post-exploitation activity requires application-layer and endpoint-level telemetry.

913
MCQmedium

A SOC Tier 2 analyst is investigating an alert that was escalated from Tier 1. The analyst suspects the malware is using a new variant of ransomware. What is the most appropriate next step for the Tier 2 analyst?

A.Notify legal counsel immediately
B.Escalate directly to Tier 3 for advanced analysis
C.Perform malware analysis and correlate with other alerts
D.Delete the affected files to contain the spread
AnswerC

Malware analysis identifies the ransomware variant's behaviour, indicators, and capabilities, while correlating with other alerts reveals infection scope and lateral movement. This combination is the appropriate Tier 2 next step before escalation, satisfying the need to characterise a suspected new ransomware variant.

Why this answer

A Tier 2 analyst's role is to perform deeper investigation than Tier 1, including malware analysis and correlating the alert with other telemetry to determine scope and impact. Performing malware analysis and correlating with other alerts is the appropriate next step to confirm whether the ransomware is a new variant and to understand its behavior. This informs containment and escalation decisions.

Exam trap

The trap is jumping to containment or escalation before completing Tier 2 analysis — the exam expects the analyst to investigate and correlate first, not delete files or skip to Tier 3.

How to eliminate wrong answers

Option A is wrong because notifying legal counsel is premature before the incident is confirmed and scoped; legal involvement typically follows confirmed data breach or regulatory triggers. Option B is wrong because escalating directly to Tier 3 without doing Tier 2 analysis skips the analyst's responsibility and may waste Tier 3 resources; Tier 2 should first triage and enrich. Option D is wrong because deleting affected files is a containment action that can destroy evidence and may not stop the ransomware; containment should be coordinated after analysis, and evidence preservation is critical.

914
MCQeasy

A junior analyst is triaging a Windows workstation that users report is running slowly. The analyst suspects a malicious process is persisting by masquerading as a legitimate Windows service. Which built-in Windows tool should the analyst use to view services, their binary paths, and their current state without installing additional software?

A.The Services console (services.msc)
B.Performance Monitor (perfmon.msc)
C.Task Manager's Processes tab
D.Event Viewer's Application log
AnswerA

The Services console lists every installed Windows service along with its display name, start type, status, and, under the General tab or via the registry, the path to the service binary. This lets the analyst spot a service whose ImagePath points to an unusual directory or executable, which is a classic masquerading persistence technique. It requires no third-party tools.

Why this answer

The Services console (services.msc) is the native Windows management interface that enumerates all installed services and exposes each one's display name, status, start type, and the path to its executable. By reviewing those paths, the analyst can identify a service whose binary resides in an unexpected location, which is a common masquerading persistence method, without deploying any additional tooling.

Exam trap

The trap here is equating Task Manager's process list with a full service inventory, when Task Manager does not reliably show every service's configured binary path or start type.

915
Multi-Selectmedium

Which TWO of the following are indicators of a potential data exfiltration attempt?

Select 2 answers
A.An internal host transferring large amounts of data to an unknown external IP at 3 AM.
B.A user accessing an internal file server during business hours.
C.An internal host sending large DNS TXT queries to an external server.
D.A failed login attempt from an internal workstation.
E.A spike in ICMP echo requests from an external IP.
AnswersA, C

Unusual time and volume strongly suggest exfiltration.

Why this answer

Data exfiltration often involves transferring large volumes of data to an unknown external IP during off-hours (e.g., 3 AM) to evade detection. This behavior deviates from normal business patterns and is a classic indicator of a data breach or insider threat.

Exam trap

Cisco often tests the distinction between normal network activity (e.g., file server access during business hours) and anomalous patterns (e.g., off-hours bulk transfers or DNS tunneling), so candidates must focus on the context of time, volume, and protocol misuse rather than just the action itself.

916
MCQmedium

An analyst is investigating a Linux host and runs 'cat /proc/1234/cmdline'. What information does this provide?

A.The memory map of the process
B.The command line and arguments used to start the process
C.The environment variables of the process
D.The current working directory of the process
AnswerB

Reading `/proc/<pid>/cmdline` returns the exact command line and arguments that launched process 1234, with arguments separated by null bytes. This directly satisfies the scenario's requirement to identify how the process was started on the Linux host, exposing suspicious flags or scripts an attacker used.

Why this answer

The file /proc/1234/cmdline is a pseudo-file exposed by the Linux kernel's procfs for the process with PID 1234. Reading it returns the exact command line and arguments that were passed to execve() when the process was started, with arguments separated by NUL bytes. This is why 'cat' often shows the arguments run together — the NUL separators are not rendered as visible characters.

Exam trap

The trap here is confusing the various /proc/PID pseudo-files — candidates often pick environ or maps because they vaguely remember 'something about process info in /proc' without mapping the exact filename to the exact data.

How to eliminate wrong answers

Option A is wrong because the memory map of a process is exposed via /proc/1234/maps, not cmdline. Option C is wrong because environment variables are exposed via /proc/1234/environ. Option D is wrong because the current working directory is exposed via the /proc/1234/cwd symbolic link (readable with ls -l or readlink).

917
Multi-Selectmedium

After a security incident, the IR team holds a lessons learned meeting. Which THREE activities are part of the Post-Incident Activity phase?

Select 3 answers
A.Developing metrics to measure IR effectiveness
B.Identifying improvements to the IR process
C.Updating the incident response plan
D.Conducting initial triage of new alerts
E.Restoring systems from backup
AnswersA, B, C

Defining metrics that measure IR effectiveness belongs to Post-Incident Activity, quantifying detection, response and recovery performance after the event. This satisfies the phase's purpose of evaluating what occurred rather than preparing for or containing an incident.

Why this answer

Option A is correct because the Post-Incident Activity phase includes developing metrics (e.g., MTTD, MTTR, containment time) to measure the effectiveness of the incident response process and inform future improvements. Option B is correct because a core output of the lessons learned meeting is identifying improvements to the IR process, such as better detection rules, communication paths, or tooling gaps. Option C is correct because findings from the lessons learned review are used to update the incident response plan, ensuring procedures, playbooks, and roles reflect what was learned.

Option D is not part of this phase; initial triage of new alerts belongs to the Detection and Analysis phase. Option E is also not part of this phase; restoring systems from backup occurs during the Containment, Eradication, and Recovery phase.

Exam trap

The trap is mixing phases — candidates often select 'restore systems from backup' or 'triage alerts' because they sound incident-related, but those belong to Recovery and Detection/Analysis respectively, not Post-Incident Activity.

918
Multi-Selectmedium

A SOC analyst is correlating events in the SIEM after an alert fired for suspicious PowerShell execution on a workstation. The analyst wants to identify additional evidence that would support a ransomware pre-encryption hypothesis. Which two telemetry findings would most strongly support that hypothesis? (Choose two.)

Select 2 answers
A.A spike in SMB write operations to many file shares from a single workstation account.
B.A DHCP lease renewal for the workstation recorded by the local DHCP server.
C.Volume shadow copy deletion events recorded in Windows event logs.
D.An increase in DNS queries for known advertising domains from the workstation.
E.Successful Windows Update installations completing on the workstation overnight.
AnswersA, C

Rapid, widespread writes to numerous network file shares from one account is consistent with a ransomware binary encrypting shared data after initial execution. This pattern distinguishes encryption activity from normal user file access, which is typically limited in scope. Combined with suspicious script execution, it provides strong corroboration of an active or imminent ransomware incident.

Why this answer

Pre-encryption ransomware activity typically includes destroying recovery options and then rapidly encrypting data. Volume shadow copy deletion removes local restore points, while a burst of SMB writes to many shares shows encryption spreading across network storage. Together they form a coherent pattern that corroborates the suspicious PowerShell execution far better than routine DNS, update, or DHCP events.

Exam trap

The trap here is treating any unusual endpoint or network event as supporting evidence, when only behaviors tied to destroying backups and mass-encrypting files actually align with ransomware staging.

919
MCQhard

An analyst is examining a suspicious PE file. The file's entropy is very high (close to 8.0) and the import table is almost empty. What does this indicate?

A.The file is likely packed or obfuscated
B.The file is a DLL file
C.The file is a standard Windows executable with many imports
D.The file has been digitally signed
AnswerA

High entropy and few imports indicate packing.

Why this answer

High entropy close to 8.0 indicates that the file's data is highly random, which is characteristic of packed or encrypted content. An almost empty import table suggests that the file does not statically import many functions, common in packed malware that resolves imports dynamically at runtime. Together, these strongly indicate packing or obfuscation.

Exam trap

200-201 often tests the interpretation of entropy and import tables, and candidates may think high entropy always means malicious, but it can also indicate legitimate packing; however, combined with empty imports, it strongly suggests malicious packing.

How to eliminate wrong answers

Option B is wrong because being a DLL file does not inherently cause high entropy or an empty import table; DLLs can have normal entropy and imports. Option C is wrong because a standard Windows executable with many imports would have a populated import table and lower entropy. Option D is wrong because digital signing does not affect entropy or import table; signed files can still have normal characteristics.

920
Multi-Selectmedium

An analyst is investigating a suspected FTP brute-force attack. The logs show numerous failed login attempts from a single external IP to multiple user accounts on an internal FTP server. Which two additional pieces of evidence would best confirm a brute-force attack? (Choose two.)

Select 2 answers
A.The FTP server is configured to allow anonymous access.
B.A high number of FTP 530 Login incorrect responses within a short time window.
C.The external IP is listed on a threat intelligence feed for credential stuffing.
D.The FTP server uses plaintext authentication.
E.The external IP has a low reputation score but no specific threat intelligence tags.
AnswersB, C

FTP 530 responses indicate failed logins. A high frequency of these within a short period strongly suggests automated brute-force attempts, as legitimate users rarely fail repeatedly in rapid succession. This is a key indicator of brute-force activity.

Why this answer

The correct answers are a high number of FTP 530 Login incorrect responses within a short time window and threat intelligence linking the external IP to credential stuffing. These directly support the brute-force hypothesis: repeated failures indicate automated attempts, and threat intel provides context that the source is malicious.

Exam trap

The trap here is focusing on server configuration weaknesses like anonymous access or plaintext authentication, which are vulnerabilities but do not confirm an ongoing brute-force attack.

921
MCQhard

A security analyst at a financial firm is investigating a potential data breach. The company uses Cisco Firepower NGFW and Stealthwatch for network visibility. Over the past week, an internal server with IP 10.10.10.50 has been sending large amounts of data to an external IP 203.0.113.55 on TCP port 443. The Stealthwatch flow records show that the server typically communicates with only internal hosts and a few known external update servers. The analyst checks the Firepower events and sees no alerts for this traffic. The server is running a custom web application that handles financial transactions. The analyst suspects data exfiltration. What should the analyst do next?

A.Capture a packet trace of the suspicious traffic and analyze the SSL/TLS handshake to determine if the traffic is legitimate.
B.Immediately block the destination IP on the firewall and quarantine the server.
C.Review the server's web server logs for any unusual requests or responses.
D.Check the server's running processes and network connections with a command line tool like netstat.
AnswerA

Inspecting the TLS handshake reveals the server name indication and certificate details, exposing whether 203.0.113.55 is a known update server or an attacker-controlled endpoint. Since Firepower raised no alerts, encrypted exfiltration over 443 bypassed signature detection, so packet-level inspection is the only way to confirm the anomaly Stealthwatch flagged.

Why this answer

The traffic is encrypted over TCP port 443 (HTTPS), so the analyst cannot determine the content or legitimacy of the data transfer without decrypting or inspecting the SSL/TLS handshake. Capturing a packet trace allows the analyst to examine the TLS handshake details, such as the server certificate, cipher suites, and SNI, which can reveal whether the external IP is a legitimate service or an unauthorized endpoint. This step is non-disruptive and provides forensic evidence before taking any blocking or quarantine actions.

Exam trap

Cisco often tests the distinction between flow/event data and full packet inspection, trapping candidates who think firewall logs or netstat alone can confirm exfiltration over encrypted channels.

How to eliminate wrong answers

Option B is wrong because immediately blocking the destination IP and quarantining the server could disrupt legitimate business operations and destroy forensic evidence; the analyst should first verify the traffic is malicious. Option C is wrong because reviewing web server logs only shows HTTP-level requests and responses, but the traffic is encrypted over TLS, so the logs would not reveal the actual data being exfiltrated. Option D is wrong because checking running processes and netstat connections only provides a snapshot of current connections, not the historical flow data or encrypted payload details needed to confirm exfiltration.

922
MCQeasy

Which port is used by RDP (Remote Desktop Protocol) and is a common target for brute force attacks?

A.443
B.3389
C.22
D.1433
AnswerB

RDP listens on TCP port 3389 by default, so this directly satisfies the stem's requirement. Attackers repeatedly target 3389 with brute force credential attempts because exposed RDP endpoints accept authentication requests, making weak passwords exploitable. Restricting access via Microsoft Entra ID conditional access or a VPN mitigates this exposure.

Why this answer

RDP (Remote Desktop Protocol) operates by default on TCP port 3389, a fact that makes it a prime target for brute force attacks because it provides direct interactive access to Windows systems. Attackers frequently scan for open 3389 ports and attempt credential stuffing or password spraying to gain unauthorized remote access. The other ports listed are associated with different services: 443 for HTTPS, 22 for SSH, and 1433 for Microsoft SQL Server.

Exam trap

The trap here is confusing RDP with other common remote access or web protocols, especially SSH on port 22 or HTTPS on 443, because candidates may associate 'remote' with SSH or 'secure' with 443, overlooking that RDP specifically uses 3389.

How to eliminate wrong answers

Option A is wrong because port 443 is used by HTTPS (HTTP over TLS/SSL) for secure web traffic, not RDP. Option C is wrong because port 22 is the default for SSH (Secure Shell), which is a secure remote command-line protocol, not RDP. Option D is wrong because port 1433 is the default port for Microsoft SQL Server database connections, not remote desktop services.

923
MCQhard

An analyst uses Volatility's pstree plugin on a memory dump. The output shows that process 'winlogon.exe' has a child process 'cmd.exe' that is not typical. What is the most likely explanation?

A.An attacker may have used Sticky Keys or similar persistence.
B.A user is running a command prompt remotely.
C.A scheduled task is running.
D.The system is performing a normal update.
AnswerA

Sticky Keys (sethc.exe) can be replaced with cmd.exe to provide a command prompt at login.

Why this answer

In a normal Windows session, winlogon.exe spawns userinit.exe (which then launches explorer.exe) — it should never spawn cmd.exe. A cmd.exe child of winlogon.exe is a classic indicator of the Sticky Keys (sethc.exe) or Utilman accessibility-feature backdoor, where an attacker replaces the binary with cmd.exe so that pressing Shift five times at the logon screen yields a SYSTEM-level shell. This persistence technique survives reboots and is frequently observed in memory forensics via pstree output.

Exam trap

The trap here is assuming any cmd.exe in memory is benign user activity; candidates must recognize that the parent process (winlogon.exe) is the anomaly, not the mere presence of cmd.exe.

How to eliminate wrong answers

Option B is wrong because a remote command prompt would appear as a child of services.exe, svchost.exe, or wsmprovhost.exe (WinRM), not winlogon.exe, and would not require the accessibility-binary swap. Option C is wrong because scheduled tasks execute under taskeng.exe or svchost.exe (Task Scheduler service), producing a different parent-child relationship. Option D is wrong because Windows Update runs under TrustedInstaller.exe or the Windows Update service (wuauclt.exe), never as a cmd.exe child of winlogon.exe.

924
MCQhard

During a forensic examination of a Linux system, an analyst wants to check for persistence mechanisms. Which file or directory should be examined to find user-specific cron jobs that may have been added by an attacker?

A./etc/cron.hourly/
B./etc/cron.d/
C./etc/crontab
D./var/spool/cron/crontabs/
AnswerD

User-specific crontab entries are stored under /var/spool/cron/crontabs/ (or /var/spool/cron/ on some distributions), one file per user. Examining this directory directly reveals attacker-added scheduled jobs, satisfying the requirement to identify user-specific cron persistence rather than system-wide schedules held in /etc/crontab or /etc/cron.d/.

Why this answer

User-specific cron jobs are stored in /var/spool/cron/crontabs/ (on Debian-based systems) or /var/spool/cron/ (on Red Hat-based systems). Each user has a file named after their username containing their cron jobs. Attackers often add entries here for persistence.

The other locations are for system-wide cron jobs.

Exam trap

200-201 often tests the distinction between system-wide cron locations and user-specific crontabs, and the exact path for user crontabs on different Linux distributions.

How to eliminate wrong answers

Option A is wrong because /etc/cron.hourly/ contains scripts run hourly by the system, not user-specific cron jobs. Option B is wrong because /etc/cron.d/ contains system cron jobs with additional fields (like user), but not user-specific crontabs. Option C is wrong because /etc/crontab is the system crontab file that defines run-parts for hourly, daily, etc., and is not user-specific.

925
Multi-Selectmedium

A security analyst is reviewing the organization's business continuity plan (BCP) after a recent power outage disrupted operations. The analyst notes that the plan includes an alternate processing site and a backup generator but lacks other key components. Which TWO additional elements should the analyst recommend including to improve the BCP? (Choose two.)

Select 2 answers
A.Documented roles and responsibilities for the continuity team
B.A list of employee personal social media accounts
C.A marketing plan for attracting new customers after the outage
D.A schedule for regular penetration testing of the alternate site
E.A defined recovery time objective (RTO) for critical systems
AnswersA, E

This is correct because a BCP must clearly assign roles and responsibilities so that team members know what to do during a disruption. Without defined roles, recovery efforts can stall due to confusion or duplication. The scenario identifies missing components, and role clarity is a fundamental part of any effective continuity plan.

Why this answer

A business continuity plan should define recovery time objectives to set acceptable downtime limits and assign clear roles and responsibilities to the continuity team. These elements ensure that recovery efforts are prioritized and coordinated. The alternate site and generator address infrastructure, but without RTOs and defined roles, the organization cannot measure or manage its recovery effectively.

Exam trap

The trap here is selecting security testing or marketing activities as BCP components when the plan actually requires recovery objectives and clear team responsibilities.

926
MCQhard

A company's security policy requires that privileged accounts use multi-factor authentication for all administrative access. An auditor finds that a database administrator logs in with a username and password only, then uses a shared service account with a static password for automation. Which policy violation represents the greater risk to the organization?

A.The use of a shared service account with a static password
B.The database administrator's lack of MFA on administrative login
C.The absence of a password vault for the administrator
D.The failure to log administrative database sessions
AnswerA

A shared static credential used for automation cannot be attributed to a specific person, is rarely rotated, and often spreads across scripts and configuration files where it can be harvested. If compromised, it grants persistent privileged access with no MFA and no clear accountability, making containment difficult. This combination of anonymity, persistence, and wide exposure represents the greater risk.

Why this answer

Shared static credentials used for automation create privileged access that cannot be attributed to a person, is seldom rotated, and is often embedded in scripts where it can be harvested. If exposed, the attacker gains persistent administrative access without MFA and without accountability, complicating containment and forensics. A named administrator missing MFA is serious but remains traceable and revocable, so the shared service account poses the greater organizational risk.

Exam trap

The trap here is focusing on the visible MFA policy breach while overlooking that a shared static credential removes attribution and persists far longer, making it the more dangerous exposure.

927
MCQeasy

An analyst is reviewing a Windows event log and sees Event ID 4625 repeated many times for the same user account from different source workstations within a short period. Which activity does this most likely indicate?

A.A successful privilege escalation by a domain administrator
B.A brute-force or password-spraying attack against the account
C.A user account lockout due to a stale cached credential
D.Normal user behavior when a password has expired
AnswerB

Event ID 4625 is generated on failed logon attempts. A high volume of these events for one account, especially from multiple source workstations, suggests an attacker is trying many passwords. Password spraying uses a few common passwords across many accounts, but repeated failures for a single account from different hosts also align with brute-force or credential-stuffing activity targeting that account.

Why this answer

Repeated Windows Event ID 4625 entries for one account from multiple source workstations indicate many failed logon attempts, which is the signature of a brute-force or password-spraying attack. Legitimate causes such as expired passwords or stale cached credentials would not produce this volume or diversity of source hosts, so the activity should be investigated as a credential attack.

Exam trap

The trap here is treating all 4625 events as routine user error, when a high volume from multiple hosts signals an active credential attack.

928
MCQhard

During a vulnerability assessment, a security team discovers that a web application allows users to upload files without proper validation. An attacker could upload a malicious file and execute it on the server. Which type of vulnerability is this?

A.Cross-site scripting (XSS)
B.SQL injection
C.Remote code execution (RCE)
D.Insecure direct object reference
AnswerC

Unvalidated file uploads let an attacker place executable code that the server later runs, which is remote code execution. This satisfies the stem's stated impact of executing a malicious file on the server, rather than mere cross-site scripting or information disclosure.

Why this answer

The vulnerability allows an attacker to upload a malicious file (e.g., a web shell) and then execute it on the server, which is the definition of remote code execution (RCE). This occurs because the application fails to validate file types, contents, or execution permissions, enabling arbitrary code to run in the server's context.

Exam trap

Cisco often tests the distinction between client-side attacks (XSS) and server-side attacks (RCE), so candidates may confuse file upload RCE with XSS because both involve malicious file or script injection, but the execution context (server vs. client) is the key differentiator.

How to eliminate wrong answers

Option A is wrong because cross-site scripting (XSS) involves injecting client-side scripts (e.g., JavaScript) into web pages viewed by other users, not executing code on the server. Option B is wrong because SQL injection targets database queries by manipulating input to alter SQL statements, not file uploads or server-side code execution. Option D is wrong because insecure direct object reference (IDOR) allows unauthorized access to resources by manipulating object references (e.g., user IDs in URLs), not file uploads or code execution.

929
Multi-Selectmedium

An analyst is investigating a Windows host that likely has malware persistence via the registry. Which TWO registry hives are commonly used to store Run keys for user logon persistence? (Select 2)

Select 2 answers
A.HKEY_CLASSES_ROOT\*\shell
B.HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
C.HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\AppInit_DLLs
D.HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
E.HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
AnswersB, E

The HKLM Run key executes listed programs at logon for every user on the host, making it a machine-wide persistence location. This satisfies the stem's user logon persistence constraint, since malware written here survives reboots and affects all accounts.

Why this answer

The Run keys under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run and HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run are standard locations where Windows executes programs automatically at user logon. Malware commonly writes entries to these keys to achieve persistence, making them critical for host-based analysis.

Exam trap

Cisco often tests the distinction between Run keys (user logon persistence) and other registry locations like AppInit_DLLs or Services, so candidates must know that only the Run paths under HKLM and HKCU are correct for this specific persistence method.

930
Multi-Selecthard

Which THREE are common indicators of a distributed denial-of-service (DDoS) attack? (Choose three.)

Select 3 answers
A.Slow network performance and service unavailability
B.A single IP address generating excessive traffic
C.High bandwidth consumption on the network link
D.Unusual traffic patterns from many different sources
E.Encrypted traffic from a known malware C2 server
AnswersA, C, D

Overwhelmed resources cause slowdowns.

Why this answer

A DDoS attack floods the target with traffic from multiple sources, overwhelming network resources and causing legitimate requests to time out or be dropped. This results in slow network performance and service unavailability as the system struggles to process the excessive load. The distributed nature of the attack makes it difficult to mitigate with simple IP-based filtering.

Exam trap

Cisco often tests the distinction between a single-source DoS and a multi-source DDoS, so candidates may incorrectly select 'a single IP address generating excessive traffic' as a DDoS indicator, but the key is the distributed nature of the attack.

931
MCQmedium

A security operations center analyst is reviewing a vulnerability scan report for a web server. The report identifies that the server is running an outdated version of Apache HTTP Server with a known remote code execution vulnerability. The analyst needs to classify this finding. Which term best describes this vulnerability?

A.A software misconfiguration, because the server is running an unsupported version.
B.A known software vulnerability, because it is a documented flaw in the Apache code that can be exploited.
C.A social engineering attack, because the attacker could trick users into visiting a malicious site.
D.A zero-day exploit, because the vulnerability allows remote code execution.
AnswerB

A known software vulnerability is a documented weakness in software code that attackers can exploit. The outdated Apache version contains a published remote code execution flaw, which matches this definition. The analyst should classify it as a known vulnerability and prioritize patching or upgrading, consistent with vulnerability management practices in the CyberOps Security Concepts domain.

Why this answer

The scan reveals an outdated Apache version with a published remote code execution flaw. That is a known software vulnerability: a documented weakness in code for which a fix typically exists. It is not a configuration error, an unknown zero-day, or a human-focused social engineering technique, so the appropriate classification is a known software vulnerability requiring patch or upgrade remediation.

Exam trap

The trap here is assuming any remote code execution flaw is a zero-day, when a zero-day specifically requires that no patch or public knowledge exists yet.

932
MCQeasy

A network administrator is tasked with creating a security policy for handling sensitive data. Which of the following is the most critical element to include?

A.Detailed network topology diagrams.
B.List of antivirus software versions.
C.Data classification and handling procedures.
D.Vendor contact information.
AnswerC

Data classification and handling procedures define how sensitive data is identified, labelled, stored, transmitted and disposed of. Without classification, controls cannot be applied consistently. This element directly satisfies the policy's purpose of governing sensitive data handling across the organisation.

Why this answer

A security policy for sensitive data must first define what data is sensitive and how it must be handled, which is exactly what data classification and handling procedures provide. Classification labels (e.g., Public, Internal, Confidential, Restricted) drive the controls, retention, encryption, and access rules that follow. Without classification, no other policy element can be consistently applied.

Exam trap

The trap is choosing a technical or administrative artifact (topology, AV list, contacts) that feels security-related but does not actually define how sensitive data is identified and protected.

How to eliminate wrong answers

Option A is wrong because network topology diagrams are operational artifacts, not policy elements, and they do not govern how sensitive data is protected. Option B is wrong because a list of antivirus versions is a point-in-time inventory detail, not a policy control, and it addresses only one threat vector. Option D is wrong because vendor contact information is administrative reference data, not a security control or policy requirement for handling sensitive data.

933
MCQmedium

In Windows, prefetch files (C:\Windows\Prefetch\*.pf) are used by the system to speed up application loading. How can an analyst leverage prefetch files during host-based analysis?

A.They provide evidence of file execution, including frequency and timestamps.
B.They store network connection logs.
C.They store registry keys modified by the application.
D.They contain the contents of the running process memory.
AnswerA

Prefetch files record each executable's name, run count and last-run timestamps, so analysts can confirm that a program executed on the host, how often, and when. This directly satisfies the need to establish file execution evidence during host-based analysis.

Why this answer

Prefetch files in Windows record metadata about application launches, including the executable path, run count, and last run timestamp. During host-based analysis, an analyst can examine these .pf files to determine which executables have been executed, how often, and when, providing crucial evidence of file execution activity.

Exam trap

Cisco often tests the specific purpose of prefetch files versus other forensic artifacts, and the trap here is confusing prefetch files with memory dumps or registry logs, leading candidates to select options that describe unrelated Windows components.

How to eliminate wrong answers

Option B is wrong because prefetch files do not store network connection logs; network connection logs are typically found in Windows Event Logs (e.g., Security log with Event ID 5156) or firewall logs. Option C is wrong because prefetch files do not store registry keys modified by the application; registry modifications are tracked in the Registry hive files (e.g., NTUSER.DAT, SYSTEM, SOFTWARE) and can be analyzed via tools like RegRipper. Option D is wrong because prefetch files do not contain the contents of the running process memory; process memory contents are captured in memory dumps (e.g., .dmp files) or via forensic tools like Volatility.

934
MCQmedium

A security analyst is reviewing PCAP data and sees a TCP stream with interactive shell commands such as 'whoami', 'ls -la', and 'cat /etc/passwd'. The session appears to be bidirectional with a remote IP. Which type of attack is most likely occurring?

A.Reverse shell
B.DNS tunnelling
C.SQL injection
D.Man-in-the-middle attack
AnswerA

A reverse shell is an outbound connection from the victim to an attacker-controlled listener, carrying interactive commands such as whoami, ls -la and cat /etc/passwd. The bidirectional stream to a remote IP matches this pattern rather than inbound exploitation.

Why this answer

Interactive shell commands over TCP indicate a reverse shell, where the attacker has a command shell on the victim.

935
Multi-Selectmedium

An analyst is investigating a Windows host for malware persistence. Which TWO registry locations are commonly abused for persistence by modifying the 'Run' key? (Select TWO)

Select 2 answers
A.HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
B.HKLM\Software\Microsoft\Windows\CurrentVersion\Run
C.HKCU\Software\Microsoft\Windows\CurrentVersion\Run
D.HKLM\System\CurrentControlSet\Services
E.HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
AnswersB, C

The HKLM Run key executes programs at logon for all users and needs administrative privileges to modify. Malware with elevated access writes here for system-wide persistence, satisfying the scenario's requirement for a commonly abused Run-key location on the Windows host.

Why this answer

Both HKLM and HKCU Run keys are commonly used for persistence.

936
MCQmedium

Which tool can be used to extract files from a PCAP file for further analysis?

A.Wireshark (Export Objects)
B.Snort
C.tcpdump
D.nmap
AnswerA

Wireshark's Export Objects feature reconstructs files carried over protocols such as HTTP, SMB and TFTP from captured packets and writes them to disk. This directly satisfies the requirement to extract files from a PCAP for further analysis, unlike tools that only inspect headers or statistics.

Why this answer

Wireshark's 'Export Objects' feature allows you to extract files (e.g., HTTP objects, SMB files, or other application-layer payloads) from a PCAP file. This is essential for further analysis of malware or data exfiltration, as it reconstructs the original files from the captured network streams without needing to replay the traffic.

Exam trap

Cisco often tests the distinction between packet capture tools (tcpdump) and protocol analysis tools (Wireshark), leading candidates to mistakenly think tcpdump can extract files because it can read PCAPs, but it only outputs raw packet data without application-layer reconstruction.

How to eliminate wrong answers

Option B (Snort) is wrong because Snort is an intrusion detection/prevention system (IDS/IPS) that analyzes traffic in real-time using rules, but it does not have a built-in feature to extract files from a PCAP for offline analysis. Option C (tcpdump) is wrong because tcpdump is a command-line packet capture tool that can read PCAP files and display packet headers, but it cannot extract application-layer objects like files; it lacks the protocol dissection and reassembly needed for file extraction. Option D (nmap) is wrong because nmap is a network scanning tool used for host discovery and port scanning, not for parsing PCAP files or extracting embedded objects.

937
MCQmedium

An analyst is reviewing IDS alerts and sees an alert with signature name 'ET POLICY Suspicious inbound to MySQL port 3306'. The source IP is external and destination is an internal database server. What is the best immediate action?

A.Allow the traffic because it is a legitimate database query
B.Ignore the alert as it is a false positive
C.Disable the signature to reduce noise
D.Block the external IP at the firewall
AnswerD

Blocking the external source at the firewall immediately stops further inbound attempts to the MySQL port, containing the threat while investigation proceeds. This satisfies the need for the fastest containment action against a confirmed external probe of an internal database.

Why this answer

An inbound connection from an external IP to a MySQL server (port 3306) is highly suspicious — MySQL is a database service that should never be exposed directly to the internet. The immediate best action is to block the external IP at the firewall to prevent potential exploitation, data exfiltration, or brute-force attacks. This aligns with the principle of least privilege and defense-in-depth, as database servers should only accept connections from trusted internal hosts.

Exam trap

Cisco often tests the misconception that IDS alerts should be analyzed for false positives before taking action, but in this scenario, the immediate risk of an external connection to a database port demands a blocking response first, with analysis to follow.

How to eliminate wrong answers

Option A is wrong because allowing the traffic assumes it is legitimate, but external inbound MySQL traffic is almost always malicious or misconfigured — legitimate database queries should come from internal application servers, not the public internet. Option B is wrong because ignoring the alert as a false positive is premature without investigation; while some alerts may be false positives, an inbound connection to a database port from an external source warrants immediate action due to the high risk. Option C is wrong because disabling the signature reduces visibility and increases risk — the signature is correctly firing on suspicious behavior, and disabling it would allow future attacks to go undetected.

938
MCQmedium

A security engineer is setting up a Snort rule to detect FTP traffic where the source IP is not from the internal network. Which Snort rule header correctly specifies the action, protocol, source, and destination?

A.alert tcp !$HOME_NET any -> any 21
B.alert tcp $HOME_NET any -> any 21
C.alert tcp any any -> any 21
D.alert udp any any -> any 21
AnswerA

The `!$HOME_NET` negation operator matches any source outside the defined internal network, satisfying the "not from the internal network" constraint. `alert tcp` sets the action and protocol, `any` covers all source ports, and `-> any 21` targets FTP destination port 21 on any host.

Why this answer

The rule header alert tcp !$HOME_NET any -> any 21 correctly specifies: action (alert), protocol (tcp), source (!$HOME_NET, i.e., NOT the internal network), source port (any), direction (->), destination (any), and destination port (21, FTP). The ! negation operator inverts the HOME_NET variable, so the rule fires only when the source is external — exactly what the engineer wants.

Exam trap

200-201 often tests Snort header syntax, and candidates forget that ! negates the variable — they pick $HOME_NET thinking it means 'external' when it actually means 'internal,' or they choose UDP for FTP, which is TCP-only.

How to eliminate wrong answers

Option B is wrong because $HOME_NET (without !) matches traffic originating from the internal network, which is the opposite of the requirement. Option C is wrong because 'any any' matches all sources including internal, so it does not restrict to external sources. Option D is wrong because it specifies udp, but FTP uses TCP (control on 21, data on 20 or passive ports), so the rule would never match FTP traffic.

939
MCQeasy

Which of the following is the CORRECT order of the NIST SP 800-61 Rev 2 incident response lifecycle phases?

A.Containment Eradication and Recovery, Detection and Analysis, Preparation, Post-Incident Activity
B.Post-Incident Activity, Preparation, Detection and Analysis, Containment Eradication and Recovery
C.Preparation, Detection and Analysis, Containment Eradication and Recovery, Post-Incident Activity
D.Detection and Analysis, Preparation, Containment Eradication and Recovery, Post-Incident Activity
AnswerC

NIST SP 800-61 Rev 2 orders the incident response lifecycle as Preparation; Detection and Analysis; Containment, Eradication and Recovery; then Post-Incident Activity. This sequence reflects the standard's four-phase structure, with lessons learned occurring only after recovery completes.

Why this answer

The correct order is Preparation, Detection and Analysis, Containment Eradication and Recovery, and Post-Incident Activity.

940
Multi-Selecteasy

Which TWO are common sources of security event data in a Security Information and Event Management (SIEM) system?

Select 2 answers
A.SMTP logs
B.NetFlow records
C.SNMP traps
D.Syslog from network devices
E.DNS queries
AnswersB, D

NetFlow records export metadata about IP flows — source, destination, ports, and byte counts — letting a SIEM correlate traffic patterns and detect anomalies such as scanning or exfiltration. They feed network-level event data alongside logs and alerts.

Why this answer

NetFlow records (B) are a common SIEM data source because they provide flow-level metadata—source/destination IP, ports, protocol, byte/packet counts, and timestamps—that SIEMs use for traffic analysis, anomaly detection, and threat hunting. Syslog from network devices (D) is also a core source, as routers, switches, and firewalls send event messages (e.g., RFC 5424/3164 format) to a SIEM for correlation and alerting. SMTP logs (A) are email-server logs and, while they can be ingested, they are not a common primary SIEM source category in the same way as flow and syslog data.

SNMP traps (C) are asynchronous device notifications used mainly for network management/monitoring, not a standard SIEM event-data source. DNS queries (E) can be logged and analyzed for security (e.g., DNS tunneling), but they are a specialized telemetry type rather than one of the two common sources identified here.

Exam trap

Cisco often tests the distinction between network management protocols (SNMP) and security monitoring sources (syslog, NetFlow), leading candidates to mistakenly select SNMP traps as a security event source because they associate 'traps' with alerts, when in fact SNMP is for device health, not security event logging.

941
MCQeasy

During which phase of the NIST SP 800-61 Rev 2 incident response process would the incident response team conduct initial triage and determine whether an event qualifies as an incident?

A.Detection and Analysis
B.Preparation
C.Containment, Eradication, and Recovery
D.Post-Incident Activity
AnswerA

Detection and Analysis covers initial triage, validating alerts and deciding whether an event meets the incident criteria before escalating to containment. This satisfies the stem's requirement, since qualification happens during that phase rather than Preparation, Containment Eradication and Recovery, or Post-Incident Activity.

Why this answer

Initial triage and identification of incidents occur in the Detection and Analysis phase.

942
Multi-Selectmedium

An analyst is investigating a potential compromise using Indicators of Compromise (IoCs). Which TWO of the following are valid types of IoCs?

Select 2 answers
A.User name
B.IP address
C.Geographic location
D.File hash (MD5)
E.Protocol name
AnswersB, D

An IP address is a network-level IoC, recording the source or destination of malicious traffic such as command-and-control contact. It satisfies the stem's requirement for a valid IoC type because it provides concrete, observable evidence of compromise that analysts can correlate across logs and block at perimeter controls.

Why this answer

Option B (IP address) is a valid IoC because a specific IP address associated with command-and-control (C2) servers, malicious scanning, or exfiltration traffic is a concrete, observable network artifact that analysts can search for in firewall, IDS/IPS, and proxy logs. Option D (File hash (MD5)) is a valid IoC because a cryptographic hash such as an MD5 digest uniquely identifies a known malicious file, allowing endpoint and antivirus tools to detect that exact sample without relying on its filename. By contrast, option A (User name) is generally not an IoC by itself, since usernames are not inherently malicious and are too common to serve as reliable compromise indicators.

Option C (Geographic location) is not a valid IoC type on its own, as geolocation is a derived attribute of an IP address rather than a distinct indicator. Option E (Protocol name) is not a valid IoC, because protocols like HTTP or DNS are legitimate, ubiquitous communication methods and only become suspicious in specific contexts, not as standalone indicators.

Exam trap

Cisco often tests the distinction between an IoC (a specific, observable artifact of compromise) and contextual or behavioral data (like usernames or geographic locations) that may be useful in an investigation but are not valid IoCs themselves.

943
MCQmedium

An analyst sees a Snort alert with the message 'ET POLICY Outbound connection to known malicious IP'. What does this indicate?

A.A malicious IP is connecting to an internal host.
B.The firewall blocked the connection.
C.An internal host is connecting to an IP that is on a threat intelligence blacklist.
D.The connection is encrypted and safe.
AnswerC

The signature name identifies an outbound connection from an internal host to an IP address listed on a threat intelligence blacklist, indicating possible command-and-control or data exfiltration traffic. The rule triggers on the destination reputation, not on payload content, so it flags the connection itself as suspicious.

Why this answer

Snort signature-based IDS alerts on matching rules. This alert indicates a connection from an internal host to a known malicious IP address, likely a command-and-control server.

944
MCQmedium

A network administrator configures an IPS to drop packets that match a signature for SQL injection. However, legitimate web traffic is being blocked. What is the most likely cause?

A.IPS hardware failure
B.Network congestion
C.Signature false positive
D.Signature false negative
AnswerC

A signature false positive occurs when legitimate traffic matches an attack pattern the IPS was not designed to see in that context. Here, benign web requests containing SQL-like strings trigger the SQL injection signature, causing the IPS to drop them. This directly explains the over-blocking of legitimate web traffic described in the stem.

Why this answer

A false positive occurs when the IPS incorrectly identifies legitimate traffic as malicious based on its signature. In this case, the SQL injection signature is matching benign web requests that contain patterns resembling SQL syntax (e.g., 'SELECT', 'DROP'), causing the IPS to drop valid packets. This is a common issue with signature-based detection systems that lack contextual analysis.

Exam trap

Cisco often tests the distinction between false positives and false negatives, and the trap here is that candidates may confuse 'blocking legitimate traffic' with a false negative, not realizing that a false positive is the correct term for incorrectly flagged benign traffic.

How to eliminate wrong answers

Option A is wrong because an IPS hardware failure would typically cause complete loss of inspection or system crashes, not selective blocking of specific traffic patterns. Option B is wrong because network congestion might cause packet loss or latency, but it would not cause the IPS to drop packets based on signature matching; congestion does not alter detection logic. Option D is wrong because a false negative means the IPS fails to detect actual malicious traffic, which would allow SQL injection attacks to pass, not block legitimate traffic.

945
MCQhard

A SIEM correlation rule triggers when a user account is created and then added to a privileged group within 10 minutes. Which activity does this rule detect?

A.Malicious insider data theft.
B.Privileged account creation and elevation.
C.Privilege escalation via token manipulation.
D.Lateral movement using pass-the-hash.
AnswerB

The rule correlates two distinct events: account creation followed by privileged group membership within ten minutes. That sequence captures both the creation of the account and its elevation to privileged rights, which is exactly the behaviour the correlation logic is designed to surface.

Why this answer

The SIEM rule specifically correlates the creation of a user account followed by its addition to a privileged group within a short time window. This sequence directly maps to the definition of privileged account creation and elevation, where a new account is granted administrative rights. The rule does not require any other malicious activity like data theft or lateral movement to trigger.

Exam trap

Cisco often tests the distinction between the administrative action of adding a user to a privileged group (privileged account creation/elevation) and the exploitation of system tokens or authentication protocols, leading candidates to confuse the SIEM rule's trigger with token manipulation or pass-the-hash attacks.

How to eliminate wrong answers

Option A is wrong because malicious insider data theft typically involves exfiltration of sensitive data, not just account creation and group membership changes; the rule does not monitor data access or transfer events. Option C is wrong because privilege escalation via token manipulation involves exploiting operating system mechanisms like SeDebugPrivilege or token duplication, not the administrative action of adding a user to a group via directory services. Option D is wrong because lateral movement using pass-the-hash relies on NTLM hash reuse to authenticate to remote systems, which is unrelated to account creation or group membership modifications.

946
Multi-Selectmedium

A SOC analyst is tuning Cisco Firepower intrusion policies and reviewing alert metadata to prioritize response. Which TWO alert attributes most directly indicate that a detected event represents a successful compromise rather than a blocked attempt? (Choose two.)

Select 2 answers
A.The alert action is recorded as 'Blocked'
B.The rule's signature is classified with a high severity level
C.The event's source is an external IP and the destination is an internal server
D.Subsequent correlated events show the target initiating outbound connections to a known C2 server
E.The alert's impact flag is set to 'Vulnerable'
AnswersD, E

Post-exploitation callback traffic from the target to a known command-and-control address is strong evidence that the earlier exploit succeeded and the host is now under adversary control. Correlation between the initial intrusion event and later outbound C2 activity links cause and effect. This behavioral evidence outweighs static metadata such as severity or direction when assessing compromise.

Why this answer

Successful compromise is indicated by evidence that the target was actually affected, not merely targeted. An impact flag of Vulnerable shows the host matched the exploit's affected configuration, and later outbound connections to known C2 infrastructure demonstrate post-exploitation control. Blocked actions, severity levels, and traffic direction describe the attempt or its potential, but not confirmed success.

Exam trap

The trap here is treating a high-severity signature or a Blocked action as proof of compromise when neither demonstrates that the target host was actually exploited.

947
MCQeasy

An analyst needs to establish a normal traffic pattern baseline for the network. Which activity is most appropriate for this purpose?

A.Capture traffic during a known attack to identify anomalies
B.Use only firewall logs as they are the most reliable
C.Average traffic from multiple different organizations
D.Capture traffic over a period of normal operation, such as a week
AnswerD

Capturing traffic across a representative period such as a week captures diurnal and weekly usage variation, producing a baseline that reflects genuine normal operation. Short captures miss periodic activity, so this duration satisfies the requirement for a reliable traffic-pattern baseline.

Why this answer

Establishing a baseline requires capturing traffic during a period of normal operation, typically over a week, to account for daily and weekly usage patterns. This baseline represents the typical volume, protocol mix, and flow characteristics, enabling the analyst to later detect deviations that may indicate security incidents. Using a representative sample from normal conditions is the foundational step in anomaly-based monitoring.

Exam trap

Cisco often tests the misconception that baselines can be derived from attack traffic or external averages, but the key is that a baseline must be network-specific and captured during normal operations to serve as a valid reference for anomaly detection.

How to eliminate wrong answers

Option A is wrong because capturing traffic during a known attack provides a sample of malicious activity, not a baseline of normal behavior; baselines must reflect benign patterns to identify anomalies. Option B is wrong because firewall logs alone are insufficient for a comprehensive baseline; they lack visibility into internal traffic, application-layer protocols, and non-firewalled segments, and they may miss encrypted or lateral movement traffic. Option C is wrong because averaging traffic from multiple different organizations introduces irrelevant patterns due to differing network architectures, user behaviors, and business operations; a baseline must be specific to the network being monitored.

948
MCQeasy

Which security policy defines the process for reporting discovered security vulnerabilities to the organization?

A.Vulnerability Disclosure Policy
B.Acceptable Use Policy
C.Incident Response Policy
D.Change Management Policy
AnswerA

A Vulnerability Disclosure Policy sets out how researchers and staff report discovered flaws to the organisation, plus expected response timelines. It directly satisfies the stem's requirement for a defined reporting process, unlike awareness or acceptable-use policies that cover behaviour rather than vulnerability intake.

Why this answer

A Vulnerability Disclosure Policy (VDP) defines how external researchers and the public should report security vulnerabilities to an organization, including the scope, reporting channel, and expected response timeline. It is the formal mechanism that governs the inbound reporting process, distinct from internal incident response procedures.

Exam trap

200-201 often tests the confusion between a Vulnerability Disclosure Policy (external reporting) and an Incident Response Policy (internal handling) — candidates pick IR because both involve vulnerabilities.

How to eliminate wrong answers

Option B is wrong because an Acceptable Use Policy governs how employees may use organizational IT resources, not how vulnerabilities are reported. Option C is wrong because an Incident Response Policy defines how the organization handles and responds to security incidents internally, not how external parties disclose vulnerabilities. Option D is wrong because a Change Management Policy governs how changes to IT systems are requested, approved, and implemented, unrelated to vulnerability reporting.

949
Multi-Selecthard

Which TWO characteristics are typical of host-based intrusion detection systems (HIDS) compared to network-based intrusion detection systems (NIDS)?

Select 2 answers
A.Better suited for protecting a large number of devices simultaneously.
B.Visibility into local system events such as file system changes and registry modifications.
C.Ability to inspect encrypted traffic at the host level.
D.Less susceptible to host-based attacks.
E.Lower latency in detecting network attacks.
AnswersB, C

Because a HIDS agent runs on the host itself, it observes local file system changes, registry modifications and process activity that network sensors cannot see. This host-level telemetry satisfies the stem's comparison against NIDS, which only inspects traffic crossing the wire.

Why this answer

Option B is correct because a HIDS agent runs directly on the endpoint and monitors local activity such as file integrity changes, registry modifications, log entries, and process behavior, giving it deep host-level visibility that a NIDS, which only sees network packets, cannot provide. Option C is correct because a HIDS can inspect data after it has been decrypted on the host, so it can analyze encrypted traffic (e.g., TLS/HTTPS sessions) at the endpoint, whereas a NIDS typically sees only ciphertext on the wire and cannot decrypt it. Option A is wrong because protecting many devices simultaneously is a strength of NIDS, which can monitor a whole network segment from a central sensor, while HIDS requires an agent per host.

Option D is wrong because HIDS agents run on the host and are themselves exposed to host-based attacks (e.g., tampering, rootkits), making them more—not less—susceptible. Option E is wrong because lower latency in detecting network attacks is characteristic of NIDS, which inspects traffic in real time on the network path, not of HIDS.

Exam trap

Cisco often tests the misconception that HIDS are better at detecting network attacks or scaling to many devices, but the key differentiator is that HIDS provide host-level visibility (like registry and file changes) and can inspect decrypted traffic, while NIDS are network-focused and cannot see internal host events.

950
Multi-Selectmedium

An organization wants to protect sensitive data at rest and in transit. Which THREE cryptographic methods can provide confidentiality? (Choose three.)

Select 3 answers
A.Digital signature
B.Transport Layer Security (TLS)
C.Symmetric encryption
D.Hashing
E.Asymmetric encryption
AnswersB, C, E

TLS encrypts data in transit using symmetric and asymmetric methods.

Why this answer

TLS (B) is correct because it provides confidentiality for data in transit by encrypting the session between client and server using negotiated symmetric ciphers (e.g., AES) after an asymmetric handshake. Symmetric encryption (C) is correct because it uses a shared secret key with algorithms such as AES to encrypt data at rest or in transit, directly providing confidentiality. Asymmetric encryption (E) is correct because it uses public/private key pairs (e.g., RSA, ECC) to encrypt data so that only the holder of the corresponding private key can decrypt it, protecting confidentiality.

Digital signature (A) is not correct because it provides integrity, authentication, and non-repudiation, not confidentiality. Hashing (D) is not correct because it is a one-way function used for integrity verification and cannot encrypt or conceal data.

951
MCQhard

An analyst is investigating a Windows workstation that exhibits suspicious outbound network traffic. The analyst suspects a malicious process is injecting code into a legitimate process. Which of the following Windows Event Log sources would MOST likely contain evidence of process creation and image loading that could reveal the injection?

A.System
B.Security
C.Application
D.Microsoft-Windows-Sysmon/Operational
AnswerD

Sysmon logs detailed process creation events (Event ID 1) and image loaded events (Event ID 7), which can show if a legitimate process loaded an unexpected DLL or if a process was created with suspicious parameters. This is the most direct source for detecting code injection, as it captures the loading of images into processes.

Why this answer

Sysmon, when installed, provides extensive logging of process creation and image loads, which are critical for identifying code injection. The Microsoft-Windows-Sysmon/Operational log contains Event ID 7 for image loads, allowing analysts to see if a process loaded an unexpected DLL, a common sign of injection.

Exam trap

The trap here is assuming that the Security log's process creation events are sufficient, but they lack image load details that are essential for detecting injection.

952
MCQeasy

A network analyst is reviewing firewall logs and sees repeated inbound connections from a single external IP to TCP port 445 on multiple internal hosts over a short period. The connections are followed by SMB negotiation attempts. Which activity does this most likely represent?

A.A backup server replicating data to internal hosts
B.DNS zone transfer requests to internal DNS servers
C.SMB enumeration or exploitation attempts against internal file-sharing services
D.Normal SMB file access by remote employees using VPN
AnswerC

Repeated inbound connections to TCP 445 across multiple hosts, followed by SMB negotiation, indicate an external actor probing or attacking SMB services. Port 445 is used by SMB for file sharing and is a common target for enumeration and exploitation. The breadth of targets suggests scanning or worm-like behavior rather than a single targeted connection.

Why this answer

Inbound SMB connections to TCP port 445 from one external IP across many internal hosts indicate enumeration or exploitation of file-sharing services. Backup traffic, legitimate VPN-based file access, and DNS zone transfers have different source, port, and pattern characteristics. The sweep across multiple hosts in a short time is the key indicator of malicious SMB activity.

Exam trap

The trap here is treating any SMB traffic as normal file sharing and ignoring that the source is external and the targets are numerous.

953
MCQmedium

A financial services firm must retain security audit logs for a period specified by its regulator and be able to produce them during an examination. Which action BEST ensures the logs remain trustworthy and available for that purpose?

A.Forward logs to a centralized, access-controlled repository with integrity protection
B.Increase the local log file size limit so events are overwritten less frequently
C.Compress logs and email them weekly to the security team's distribution list
D.Store logs only on the originating server with local administrator access
AnswerA

Centralizing logs on a hardened server with restricted access, combined with integrity measures such as hashing or write-once storage, preserves both trustworthiness and availability. If the source host is compromised or destroyed, the copies remain intact for examination. This design also supports retention policies and search during audits, directly meeting the regulator's expectation that records can be produced reliably.

Why this answer

Centralizing logs in an access-controlled repository with integrity protections ensures they survive host compromise or failure and can be trusted during a regulatory examination. Retention enforcement and restricted access are as important as collection, because examiners expect complete, unaltered records that can be produced on demand.

Exam trap

The trap here is equating longer local retention with trustworthy retention, when integrity and centralized control are what actually satisfy an examiner.

954
Multi-Selecteasy

Which two Sysmon Event IDs are most commonly associated with code injection techniques?

Select 2 answers
A.Event ID 3 (Network connect)
B.Event ID 8 (CreateRemoteThread)
C.Event ID 1 (Process creation)
D.Event ID 7 (Image loaded)
E.Event ID 10 (ProcessAccess)
AnswersB, E

Event ID 8 logs CreateRemoteThread, which fires when a process starts a thread inside another process. That cross-process thread creation is the classic Sysmon signature of remote code injection, directly matching the injection technique named in the stem.

Why this answer

Event ID 8 (CreateRemoteThread) is correct because it is logged when a process creates a thread in another process, which is the classic Sysmon signature of remote thread injection (e.g., CreateRemoteThread or NtCreateThreadEx targeting a foreign process). Event ID 10 (ProcessAccess) is correct because it records a process opening a handle to another process, capturing the GrantedAccess mask (such as PROCESS_VM_WRITE and PROCESS_CREATE_THREAD) that injection techniques require to write shellcode and start execution in the target. Event ID 3 (Network connect) only logs outbound TCP/UDP connections and does not reflect in-memory injection behavior.

Event ID 1 (Process creation) documents new process launches and may show a suspicious parent, but it does not capture cross-process memory or thread manipulation. Event ID 7 (Image loaded) records DLL/module loads and can hint at injected modules, yet it is not the primary indicator of the injection act itself.

Exam trap

Cisco often tests the distinction between direct indicators of injection (Event ID 8 and 10) versus indirect artifacts (Event ID 1 or 7), leading candidates to mistakenly choose process creation or image load events as primary injection indicators.

955
MCQmedium

An analyst detects traffic from an internal host that periodically sends small DNS queries to a domain with high entropy subdomains (e.g., 'a3k9f2.example.com'). The domain is not on any blocklist, and the query intervals are consistent every 60 seconds. Which technique is most likely being used?

A.DNS tunnelling for C2 communication
B.DNS amplification attack
C.Normal DNS resolution for a dynamic DNS service
D.DNS cache poisoning attempt
AnswerA

High-entropy subdomains carrying small queries at fixed 60-second intervals indicate data encoded into DNS labels and exfiltrated or commanded through recursive resolvers. The absence from blocklists and regular beaconing fit DNS tunnelling used for command-and-control rather than normal resolution.

Why this answer

DNS tunnelling encodes data in subdomain queries, and periodic beaconing is common for C2. High entropy subdomains and regular intervals suggest DNS tunnelling for C2.

956
MCQmedium

A retail company is updating its security policy framework and needs to align its security controls with a widely recognized U.S. federal standard. The company wants a publication that provides a comprehensive catalog of security and privacy controls for federal information systems and organizations. Which NIST publication should the security team reference?

A.NIST SP 800-53
B.NIST SP 800-61
C.NIST SP 800-37
D.NIST SP 800-30
AnswerA

NIST SP 800-53, 'Security and Privacy Controls for Information Systems and Organizations,' provides a comprehensive catalog of security and privacy controls. It is the primary source for federal agencies and many private organizations to select and implement controls. In this scenario, the retail company needs a control catalog, making SP 800-53 the correct reference.

Why this answer

NIST SP 800-53 is the definitive catalog of security and privacy controls for federal information systems and organizations. It is widely adopted by private sector organizations to build robust security programs. The other NIST publications focus on incident handling, risk assessment, and the risk management framework, respectively, and do not provide the comprehensive control catalog needed.

Exam trap

The trap here is confusing NIST SP 800-37, which describes the Risk Management Framework process, with NIST SP 800-53, which actually contains the control catalog.

957
MCQeasy

A security analyst receives an alert for a known malware signature in an outbound file transfer. After investigation, the file is confirmed as benign software. This alert is classified as:

A.False positive
B.True positive
C.False negative
D.True negative
AnswerA

A false positive occurs when detection logic flags activity that is actually benign, so a confirmed benign file triggering a known-malware signature matches this classification. The alert fired correctly per the signature, but the underlying file is harmless, distinguishing it from a true positive.

Why this answer

A false positive is an alert that fires for benign activity — the detection correctly identified a signature match, but the file was confirmed benign, so the alert is a false positive. In this scenario, the malware signature matched an outbound file transfer, but investigation confirmed the file is legitimate software, making it a false positive.

Exam trap

The 200-201 exam often tests the distinction between false positive and true positive — the trap is confusing 'an alert fired' with 'the alert was correct,' leading candidates to pick true positive when the activity is confirmed benign.

How to eliminate wrong answers

Option B is wrong because a true positive means the alert correctly identified actual malicious activity — here the file is confirmed benign, so the alert is not a true positive. Option C is wrong because a false negative is a missed detection — malicious activity that did not trigger an alert — which is the opposite of this scenario where an alert did fire. Option D is wrong because a true negative is the correct absence of an alert for benign activity — here an alert did fire, so it cannot be a true negative.

958
MCQhard

An organization is implementing a threat intelligence sharing program. They want to exchange both structured indicators and full reports with other members of their ISAC. Which combination of standards/protocols should they choose? (Choose two.)

A.Snort rules
B.TAXII
C.OpenIOC
D.STIX
E.MISP
AnswerB, D

TAXII provides the transport mechanism for exchanging cyber threat intelligence over HTTPS, supporting both structured indicators and full reports through its collections and channels model. It satisfies the ISAC sharing requirement by enabling automated, bidirectional exchange between members, complementing STIX's data representation with the delivery protocol needed for programmatic sharing.

Why this answer

STIX (Structured Threat Information Expression) is the standard for representing structured threat indicators and full reports, enabling both machine-readable indicators and human-readable context. TAXII (Trusted Automated Exchange of Indicator Information) is the transport protocol that defines how STIX content is exchanged over HTTPS. Together, they allow ISAC members to share threat intelligence in a standardized, automated manner.

Snort rules are signatures for intrusion detection, not a sharing standard. OpenIOC is a format for indicators but lacks the report capability and transport protocol. MISP is a platform that can use STIX/TAXII but is not itself a standard or protocol.

Exam trap

Cisco often tests the distinction between a data model (STIX) and a transport protocol (TAXII), and candidates mistakenly choose MISP as a standard instead of recognizing it as a platform that implements these standards.

How to eliminate wrong answers

Option A is wrong because Snort rules are a signature format for intrusion detection systems, not a standard for exchanging threat intelligence between organizations. Option C is wrong because OpenIOC is a format for representing indicators of compromise, but it does not include a transport protocol for sharing full reports or support the structured report exchange required by an ISAC. Option E is wrong because MISP is a platform for threat intelligence sharing, not a standard or protocol; it can use STIX and TAXII for exchange, but MISP itself is not a standard/protocol combination.

959
MCQhard

An analyst is triaging a host that antivirus flagged for a file named svchost.exe running from C:\Users\Public\Downloads. The file has a valid digital signature issued to a legitimate software publisher, and the hash matches a known-good installer component. The process is making outbound SMB connections to several internal servers. Which action best reflects sound security monitoring practice?

A.Close the alert as a false positive because the signature and hash both verify as trusted.
B.Escalate for investigation because a signed binary executing from a user-writable path and initiating internal SMB sessions is anomalous.
C.Ignore the alert because the process name matches a legitimate Windows system binary.
D.Immediately delete the file and the user profile, then document the incident as remediated.
AnswerB

The combination of an unexpected path under a world-writable directory, a system-process name, and outbound SMB connections to multiple internal servers is a strong behavioural anomaly regardless of signature validity. Signed binaries are routinely abused for lateral movement, so the analyst should preserve volatile data and investigate parent process, logon session, and network peers before clearing the alert.

Why this answer

Signature validity and hash reputation address integrity, not intent or context. A trusted binary in a user-writable directory that opens SMB sessions to multiple internal servers is a behavioural red flag consistent with abuse for lateral movement, so the analyst should escalate, preserve evidence, and determine scope rather than dismiss or prematurely remediate the alert.

Exam trap

The trap here is equating a valid digital signature with proof of benign behaviour, when signatures only attest to the publisher and file integrity, not to how or why the binary is running.

960
Multi-Selecteasy

A security analyst is creating a network baseline for normal traffic patterns. Which TWO metrics should be included to detect anomalies?

Select 2 answers
A.Average bandwidth usage per hour
B.Geolocation of source IPs
C.Number of connections per host
D.MAC addresses of devices
E.CPU utilization of servers
AnswersA, C

Average bandwidth usage per hour establishes a quantitative norm for traffic volume, so deviations such as sudden spikes or sustained drops become detectable against the baseline. It directly satisfies the stem's requirement for metrics that reveal anomalies in normal traffic patterns, complementing flow-based measures like protocol distribution or connection counts.

Why this answer

Average bandwidth usage per hour (A) is correct because establishing a normal throughput baseline per time interval lets the analyst spot deviations such as traffic spikes, data exfiltration, or denial-of-service conditions that exceed the expected range. Number of connections per host (C) is correct because connection counts per host reveal abnormal session behavior, such as scanning, beaconing, or worm propagation, that would stand out against the established norm. Geolocation of source IPs (B) is useful context for investigating suspicious traffic but is not itself a traffic-pattern metric for a baseline.

MAC addresses of devices (D) are Layer 2 identifiers used for asset inventory or access control, not for measuring normal traffic patterns. CPU utilization of servers (E) is a host performance metric, not a network traffic baseline metric.

Exam trap

Cisco often tests the distinction between network traffic metrics and host/system metrics, so the trap here is confusing server CPU utilization (a host metric) with network baseline metrics, leading candidates to incorrectly select it as a valid network anomaly detection parameter.

961
MCQmedium

An attacker sends a fraudulent email that appears to come from the company's IT department, requesting that the recipient click a link and enter their login credentials. Which type of social engineering attack is this?

A.Vishing
B.Phishing
C.Pretexting
D.Spear phishing
AnswerB

Phishing uses fraudulent emails impersonating a trusted entity, such as the IT department, to trick recipients into clicking links and surrendering credentials. This matches the stem's constraint of a spoofed internal email harvesting login details.

Why this answer

This is a phishing attack because the attacker uses a fraudulent email that impersonates a trusted entity (the IT department) to trick the recipient into clicking a malicious link and entering sensitive login credentials. Phishing is a broad category of social engineering that relies on deceptive electronic communications, typically email, to harvest credentials or deliver malware.

Exam trap

Cisco often tests the distinction between generic phishing and spear phishing, where the trap is that candidates confuse a broad phishing email with a targeted one, but the question lacks any indication of personalization or specific targeting, making 'Phishing' the correct choice over 'Spear phishing'.

How to eliminate wrong answers

Option A (Vishing) is wrong because vishing (voice phishing) uses voice calls or VoIP systems, not email, to deceive victims. Option C (Pretexting) is wrong because pretexting involves fabricating a scenario or false identity to obtain information, but it does not necessarily use a fraudulent email with a link to harvest credentials; it often relies on direct interaction or impersonation over phone or in person. Option D (Spear phishing) is wrong because spear phishing is a targeted form of phishing aimed at a specific individual or organization, often using personalized details; the question describes a generic email sent to a recipient without indicating targeting, so it fits the broader phishing category.

962
MCQmedium

Which compliance standard specifically applies to organizations that handle credit card information?

A.HIPAA
B.GDPR
C.ISO 27001
D.PCI DSS
AnswerD

PCI DSS is the Payment Card Industry Data Security Standard, mandated for any organisation that stores, processes or transmits cardholder data. The stem's credit card handling constraint maps directly to this standard, unlike HIPAA (health) or GDPR (personal data).

Why this answer

PCI DSS (Payment Card Industry Data Security Standard) is the compliance standard specifically designed for organizations that handle credit card information. It sets requirements for securing cardholder data, including encryption, access control, and network security, and applies to all entities that store, process, or transmit card data.

Exam trap

200-201 often tests the confusion between general data protection regulations (GDPR, HIPAA) and industry-specific standards (PCI DSS), so candidates must associate credit card data with PCI DSS.

How to eliminate wrong answers

Option A is wrong because HIPAA applies to protected health information in the healthcare sector, not credit card data. Option B is wrong because GDPR is a European data protection regulation that governs personal data privacy, not specifically credit card information. Option C is wrong because ISO 27001 is a general information security management standard, not specific to credit card data.

963
MCQeasy

An analyst observes an alert triggered by a single SYN packet to a closed port. The packet did not complete a TCP handshake. What type of attack does this most likely indicate?

A.SYN scan
B.TCP connect scan
C.Ping sweep
D.UDP scan
AnswerA

A SYN scan sends a lone SYN packet to probe a port; a closed port replies with RST, and no handshake completes. This matches the stem's single SYN to a closed port, satisfying the constraint that the connection never finished the TCP three-way handshake.

Why this answer

A single SYN packet to a closed port that does not complete the TCP handshake is the signature of a SYN scan (half-open scan). The scanner sends SYN; if the port is closed, the target responds with RST, and the scanner never sends ACK. This is the classic behavior of tools like Nmap's -sS scan.

Exam trap

The trap is confusing SYN scan with TCP connect scan — candidates may pick TCP connect scan because both involve SYN packets, but only SYN scan leaves the handshake incomplete.

How to eliminate wrong answers

Option B is wrong because a TCP connect scan completes the full three-way handshake (SYN, SYN-ACK, ACK) using the OS's connect() call, which would show a completed handshake in logs. Option C is wrong because a ping sweep uses ICMP Echo requests, not TCP SYN packets. Option D is wrong because a UDP scan sends UDP packets, not TCP SYN, and would not trigger a TCP handshake-related alert.

964
Multi-Selectmedium

A security engineer is analyzing a recent data breach. Which TWO are examples of active reconnaissance techniques? (Select two.)

Select 2 answers
A.Port scanning
B.Ping sweep
C.LinkedIn profiling
D.WHOIS lookup
E.Google dorking
AnswersA, B

Port scanning actively probes target hosts to discover open ports and running services, generating traffic that touches the target directly, which defines active reconnaissance. It contrasts with passive techniques such as searching public records or monitoring traffic, where the attacker never interacts with the target's systems.

Why this answer

Port scanning (A) is an active reconnaissance technique because it sends TCP/UDP probes (e.g., SYN, ACK, or UDP packets via tools like Nmap) directly to target hosts to discover open ports and services, which interacts with the target and can be logged. Ping sweep (B) is also active reconnaissance because it transmits ICMP Echo Request packets (or ARP/TCP probes) across an IP range to identify live hosts, again directly engaging the target network. By contrast, LinkedIn profiling (C), WHOIS lookup (D), and Google dorking (E) are passive reconnaissance techniques, as they gather information from third-party sources or public records without sending traffic to the target's systems.

Exam trap

The trap is misclassifying OSINT techniques like WHOIS, Google dorking, and social media profiling as active — candidates forget that 'active' specifically means sending traffic to the target, not just gathering information about it.

965
MCQmedium

During an incident response, an analyst identifies a PCAP containing an HTTP POST request to a suspicious external IP with a large payload. The response is not typical for web applications. What type of activity is most likely occurring?

A.SQL injection attack
B.Normal web browsing
C.Data exfiltration
D.Command and control beaconing
AnswerC

A large outbound HTTP POST to an untrusted external address, with a response that does not match normal application behaviour, indicates data being uploaded out of the network. Exfiltration over HTTP commonly abuses permitted web traffic to move stolen data past egress controls.

Why this answer

A large HTTP POST to an external IP with an atypical response is the classic signature of data exfiltration — the attacker uses a legitimate-looking outbound channel (HTTP POST) to push stolen data to attacker-controlled infrastructure. The 'large payload' is the stolen data leaving the network, and the unusual response indicates the endpoint is not a real web application but a collection point.

Exam trap

The trap here is confusing any HTTP POST to an external IP with C2 beaconing; candidates must distinguish bulk one-shot egress (exfiltration) from small periodic callbacks (C2).

How to eliminate wrong answers

Option A is wrong because SQL injection is an inbound attack against a web application's database layer, typically seen as malicious GET/POST parameters to a legitimate server, not a large outbound POST to an external suspicious IP. Option B is wrong because normal web browsing produces small, symmetric request/response patterns to known sites, not large one-way payloads to suspicious external IPs. Option D is wrong because C2 beaconing is characterized by small, periodic, low-volume callbacks (often with jitter) to maintain persistence, not a single large POST carrying bulk data.

966
MCQeasy

A security analyst notices repeated failed login attempts from a single IP address against multiple user accounts. What is the best immediate action to take?

A.Increase logging verbosity for the authentication server.
B.Change all user passwords immediately.
C.Disable the affected user accounts.
D.Block the source IP address on the firewall.
AnswerD

Blocking the source IP at the firewall immediately halts the ongoing brute-force attempts against multiple accounts, satisfying the requirement for the fastest containment action. The single attacking address makes a perimeter block effective without disrupting legitimate users.

Why this answer

Blocking the source IP address on the firewall is the best immediate action because it stops the ongoing brute-force attack at the network perimeter, preventing further authentication attempts from that IP without disrupting legitimate users. This aligns with the principle of containment before investigation, as the firewall ACL can be updated quickly to deny traffic from the offending source.

Exam trap

Cisco often tests the candidate's ability to prioritize containment over investigation or remediation; the trap here is that candidates may choose to increase logging (Option A) to gather evidence, but the immediate action must stop the active attack first.

How to eliminate wrong answers

Option A is wrong because increasing logging verbosity does not stop the attack; it only generates more log data, which could overwhelm storage and delay response. Option B is wrong because changing all user passwords is disruptive, time-consuming, and does not address the source of the attack—the attacker can simply continue trying new passwords against the same accounts. Option C is wrong because disabling affected user accounts would deny service to legitimate users and does not prevent the attacker from targeting other accounts from the same IP.

967
MCQhard

A company is implementing a new data classification policy. The policy defines three levels: Public, Internal, and Confidential. An employee accidentally emails a spreadsheet marked 'Confidential' to an external partner. The email system automatically encrypts all outbound emails containing 'Confidential' classification. Which security control is being demonstrated?

A.Auditing
B.Encryption at rest
C.Data Loss Prevention (DLP)
D.Access control
AnswerC

DLP inspects outbound email content and metadata, matching the 'Confidential' classification label, then enforces the policy action of automatic encryption before the message leaves the tenant. This satisfies the stem's constraint that confidential spreadsheets sent to external partners are protected in transit, preventing unauthorised disclosure.

Why this answer

Data Loss Prevention (DLP) is the control that inspects outbound content for sensitive data classifications and takes action such as encryption or blocking. The email system automatically encrypting outbound emails containing 'Confidential' classification is a classic DLP policy enforcement action based on content inspection.

Exam trap

200-201 often tests the distinction between DLP and encryption at rest or access control; candidates see 'encrypts' and pick encryption at rest, missing that the control is triggered by content inspection of outbound email, which is DLP.

How to eliminate wrong answers

Option A is wrong because auditing records activity for later review; it does not automatically encrypt or block data in transit. Option B is wrong because encryption at rest protects data stored on disk, not data being emailed outbound. Option D is wrong because access control governs who can access resources, not what happens to data after it leaves the organization via email.

968
MCQmedium

An analyst is analyzing a PCAP and sees multiple ICMP port unreachable responses from a target host when scanning UDP ports. What does this indicate about the scanned ports?

A.The ports are closed.
B.The scan is a SYN scan.
C.The ports are filtered by a firewall.
D.The ports are open.
AnswerA

An ICMP port unreachable response means the target host received the UDP datagram but no application is listening on that port, which is the definitive indicator that the scanned port is closed rather than filtered.

Why this answer

When a UDP scan sends a packet to a closed port, the target responds with an ICMP port unreachable message.

Page 12

Page 13 of 13