Courseiva

Cisco CyberOps Associate 200-201 (200-201) — Questions 76–150

968 questions total · 13pages · All types, answers revealed

Page 1

Page 2 of 13

Page 3
76
MCQhard

An organization is implementing an AUP that prohibits personal use of corporate resources. However, an employee uses a company laptop to access personal email, which leads to a malware infection. Which policy violation is most directly implicated?

A.Remote access policy
B.Information security policy
C.Password policy
D.Acceptable Use Policy (AUP)
AnswerD

The Acceptable Use Policy defines permitted and prohibited use of corporate resources, including personal email access on a company laptop. The employee's action breaches that policy directly, and the resulting malware infection stems from this specific violation.

Why this answer

The Acceptable Use Policy (AUP) defines acceptable behavior regarding the use of company resources. Personal use that violates the AUP is a direct policy breach.

77
MCQmedium

A security policy requires that all mobile devices connecting to corporate email must have a screen lock and be able to be remotely wiped. An employee's personal phone is lost. The employee reports the loss immediately. The phone is enrolled in MDM with remote wipe capability. However, the employee has not set a screen lock, violating policy. The phone contains synced email and contacts. What should the security team do?

A.Remotely wipe the phone immediately.
B.Ask the employee to set a screen lock remotely.
C.Accept the risk since the phone is lost and wipe is possible.
D.Report the violation and suspend the employee's email access until compliance.
AnswerA

This prevents unauthorized access to corporate data.

Why this answer

Remote wipe is the most critical action to protect corporate data. Option B is wrong because wiping should be done; Option C delays protection; Option D is impossible as the phone is lost.

78
MCQhard

A SOC Tier 3 analyst is performing threat hunting. Which activity best describes the primary focus of a Tier 3 analyst?

A.Monitoring incoming alerts for potential incidents
B.Correlating alerts from multiple sources
C.Proactively searching for advanced threats
D.Creating user accounts and permissions
AnswerC

Tier 3 analysts perform proactive threat hunting, using advanced analytics and intelligence to find threats evading existing detection. This satisfies the stem's focus on hunting, distinguishing it from Tier 1 triage and Tier 2 escalation duties.

Why this answer

A Tier 3 analyst is the most senior level in a SOC, responsible for proactive threat hunting—actively searching for advanced threats that evade existing detection tools. Unlike Tier 1 and Tier 2, which focus on alert triage and correlation, Tier 3 uses hypothesis-driven investigations, threat intelligence, and advanced analytics to uncover stealthy adversaries. This aligns with the primary focus of a Tier 3 analyst as defined in the 200-201 exam objectives.

Exam trap

The trap here is confusing the responsibilities of different SOC tiers, especially assuming that Tier 3 primarily handles alert correlation or monitoring, when in fact those are Tier 1 and Tier 2 duties.

How to eliminate wrong answers

Option A is wrong because monitoring incoming alerts is a Tier 1 responsibility, not Tier 3. Option B is wrong because correlating alerts from multiple sources is typically a Tier 2 task, not the primary focus of Tier 3. Option D is wrong because creating user accounts and permissions is an administrative or IAM function, unrelated to SOC analyst roles.

79
MCQeasy

A security analyst is examining a suspicious executable found on a user's workstation. The file appears to be a legitimate PDF document but when opened, it executes code that encrypts the user's files and demands payment. The analyst determines that the file is actually a malicious program disguised as a benign file. Which type of malware is this?

A.Rootkit
B.Trojan
C.Virus
D.Worm
AnswerB

A Trojan is malware that disguises itself as legitimate software or a benign file to trick users into executing it. In this case, the executable appears to be a PDF but actually performs malicious actions like encrypting files. This deception is the defining characteristic of a Trojan, which often delivers ransomware or other payloads.

Why this answer

The key indicator is the file masquerading as a legitimate PDF while actually being a malicious executable that encrypts files. This deception is the hallmark of a Trojan, which often delivers ransomware payloads. Unlike worms or viruses, Trojans rely on user execution and do not self-replicate.

Exam trap

The trap here is assuming any malware that encrypts files is automatically ransomware; however, the delivery method (disguised as a benign file) defines it as a Trojan.

80
Multi-Selectmedium

An analyst is examining a PCAP file for signs of lateral movement. Which TWO of the following are typical indicators of lateral movement using pass-the-hash?

Select 2 answers
A.Multiple SMB authentication attempts from a single host to multiple other hosts
B.HTTP requests to a web server
C.ICMP timestamp requests
D.Large file transfers using FTP
E.Use of NTLM authentication without a password, only the hash
AnswersA, E

Pass-the-hash lateral movement produces a fan-out pattern: one compromised host authenticating via SMB to many targets in quick succession. This satisfies the stem's requirement for a typical indicator, since legitimate users rarely generate such broad single-source SMB authentication bursts.

Why this answer

Option A is correct because pass-the-hash lateral movement typically manifests as a single compromised host authenticating over SMB (TCP 445) to numerous other hosts in rapid succession, as the attacker reuses the stolen hash to pivot across the network. Option E is correct because the defining characteristic of pass-the-hash is that NTLM authentication succeeds using only the captured NTLM hash (via tools like Mimikatz or Impacket's psexec/smbexec) without ever knowing or supplying the plaintext password. Option B is not a pass-the-hash indicator, since HTTP requests to a web server reflect normal web traffic rather than NTLM-based host-to-host authentication.

Option C is unrelated, as ICMP timestamp requests are diagnostic network probes and not part of the NTLM/SMB authentication process. Option D is also unrelated, because FTP file transfers use a separate cleartext protocol and do not demonstrate hash-based credential reuse.

Exam trap

The trap is that candidates pick generic 'suspicious' traffic like large file transfers or Kerberos requests, missing that pass-the-hash has a very specific signature: NTLM authentication with hash material and SMB fan-out from one host to many.

81
MCQhard

An analyst is reviewing Sysmon logs on a Windows host and sees Event ID 1 (process creation) with a signed parent process but an unsigned child. The child has a CommandLine that includes 'powershell -EncodedCommand'. What is the most likely threat?

A.PowerShell-based malware using encoded commands to evade detection
B.Privilege escalation attempt
C.Process hollowing attack
D.Phishing email attachment
AnswerA

The encoded command hides the payload from casual log inspection, while the unsigned child spawned by a signed parent indicates process injection or masquerading. Sysmon Event ID 1 captures this parent-child mismatch, which is the specific indicator the stem asks you to interpret.

Why this answer

Event ID 1 with a signed parent process and an unsigned child using 'powershell -EncodedCommand' strongly indicates PowerShell-based malware. Attackers use Base64-encoded commands to obfuscate malicious actions and bypass simple string-based detection, as the encoded payload is decoded and executed by PowerShell at runtime.

Exam trap

Cisco often tests the distinction between execution indicators (like encoded PowerShell commands) and other attack stages (like privilege escalation or process hollowing), leading candidates to confuse a common obfuscation technique with a different attack type.

How to eliminate wrong answers

Option B is wrong because privilege escalation typically involves exploiting vulnerabilities to gain higher privileges, not simply executing an encoded PowerShell command from a signed parent. Option C is wrong because process hollowing replaces the memory of a legitimate process with malicious code, which would not manifest as a child process with an encoded PowerShell command. Option D is wrong because a phishing email attachment is a delivery vector, not a direct threat indicator; the Sysmon log shows execution, not the initial infection method.

82
MCQeasy

During network intrusion analysis, an analyst reviews logs and observes an alert for a TCP SYN scan. Which characteristic of a SYN scan would the analyst look for in packet captures?

A.The scan sends SYN packets and expects ICMP unreachable messages for open ports.
B.The scan sends SYN packets and waits for a timeout on closed ports.
C.The scan sends SYN packets and, upon receiving SYN-ACK, sends RST packets.
D.The scan sends SYN packets and completes the three-way handshake for open ports.
AnswerC

A SYN scan probes ports by sending SYN packets; receiving SYN-ACK proves the port is open, and the scanner immediately sends RST to tear down the half-open connection rather than completing the handshake. That SYN-then-RST pattern distinguishes it from a full connect scan.

Why this answer

A SYN scan sends a SYN packet and, upon receiving a SYN-ACK from the target, responds with a RST instead of completing the handshake. This avoids a full connection and is stealthier.

83
MCQmedium

An analyst uses Volatility on a memory dump and runs the 'pstree' command. What specific information does this provide compared to 'pslist'?

A.It shows only hidden processes.
B.It extracts command line arguments.
C.It displays the process tree hierarchy.
D.It lists loaded kernel modules.
AnswerC

The pstree plugin reconstructs parent-child relationships by following inherited process identifiers, revealing the ancestry and nesting that pslist's flat enumeration omits. This satisfies the stem's comparison requirement, exposing processes whose parent has exited and been reparented, which a simple listing cannot show.

Why this answer

The Volatility 'pstree' plugin displays the process tree hierarchy, showing parent-child relationships between processes. Unlike 'pslist', which lists processes in a flat table ordered by creation time, 'pstree' visually indents child processes under their parents. This helps analysts identify suspicious process lineage, such as a web server spawning a shell.

Exam trap

200-201 often tests the specific output of Volatility plugins, and candidates confuse 'pstree' (hierarchy) with 'pslist' (flat list) or 'psscan' (hidden process detection) — the key is remembering that 'pstree' adds parent-child visualization.

How to eliminate wrong answers

Option A is wrong because 'pstree' does not specifically show hidden processes — that is the domain of 'psscan' (which scans for pool-tagged process objects) or 'psxview' (which cross-references multiple sources to find hidden processes). Option B is wrong because command-line arguments are extracted by the 'cmdline' plugin, not 'pstree'. Option D is wrong because loaded kernel modules are listed by the 'modules' plugin, not 'pstree'.

84
MCQmedium

A security analyst is investigating a potential data exfiltration incident. The analyst observes that a large amount of data is being transferred from an internal database server to an external IP address during non-business hours. The transfer is using an encrypted channel that is not typical for the server's normal operations. Which type of threat is this activity most likely associated with?

A.Advanced persistent threat (APT)
B.Phishing
C.Ransomware
D.Distributed denial of service (DDoS)
AnswerA

An advanced persistent threat often involves stealthy, prolonged access to a network to steal data over time. The scenario describes data exfiltration using an encrypted channel during non-business hours, which aligns with APT tactics. APTs aim to maintain persistence and exfiltrate sensitive information without detection, making this the most likely threat type.

Why this answer

An advanced persistent threat is a prolonged and targeted attack where an intruder gains access to a network and remains undetected to steal data. The scenario's characteristics—large data transfer to an external IP, encrypted channel, and non-business hours—are typical of APT exfiltration. DDoS, ransomware, and phishing do not match the observed behavior of stealthy outbound data transfer.

Exam trap

The trap here is assuming that any data transfer is ransomware or DDoS, but the stealthy, encrypted exfiltration during off-hours points to a persistent threat actor.

85
MCQmedium

Which security principle ensures that a user cannot deny having performed an action?

A.Availability
B.Confidentiality
C.Non-repudiation
D.Integrity
AnswerC

Non-repudiation uses cryptographic evidence such as digital signatures to bind an action to a specific identity, so the actor cannot later credibly deny performing it. This directly satisfies the requirement that a user be unable to deny an action.

Why this answer

Non-repudiation ensures that a user cannot deny having performed an action, typically by using cryptographic mechanisms such as digital signatures or audit logs. In network security, this is often implemented through protocols like PKI (Public Key Infrastructure) where a sender signs data with their private key, and the receiver verifies it with the corresponding public key, providing irrefutable proof of origin.

Exam trap

Cisco often tests the distinction between integrity and non-repudiation, where candidates mistakenly choose integrity because they associate hashing with proof of origin, but integrity only verifies data has not changed, not who sent it.

How to eliminate wrong answers

Option A is wrong because availability ensures that systems and data are accessible when needed, often through redundancy and fault tolerance, but it does not prevent denial of actions. Option B is wrong because confidentiality protects data from unauthorized disclosure via encryption or access controls, but it does not provide proof of who performed an action. Option D is wrong because integrity ensures that data has not been altered in transit or at rest, typically via hashing or checksums, but it does not tie an action to a specific user in a non-repudiable way.

86
MCQhard

During incident response, a security analyst reviews a PCAP file and sees TCP packets with only the SYN flag set, followed by RST packets upon receiving a SYN-ACK. No connection is established. Which scanning technique is being used?

A.Half-open scan (SYN scan)
B.FIN scan
C.Christmas tree scan
D.Full connect scan
AnswerA

A half-open scan sends a SYN packet and, on receiving SYN-ACK, replies with RST rather than completing the three-way handshake, so no connection is established. This matches the PCAP exactly: SYN-only packets followed by RST, satisfying the stem's requirement that no session is ever opened.

Why this answer

The described behavior—sending a SYN packet, receiving a SYN-ACK, and immediately replying with an RST—is the hallmark of a half-open (SYN) scan. This technique never completes the three-way handshake, so the target does not log an established connection, making it stealthier than a full connect scan. The RST sent after the SYN-ACK terminates the handshake before it can be fully established, confirming the port is open without creating a full session.

Exam trap

Cisco often tests the distinction between a half-open scan and a full connect scan by focusing on whether the three-way handshake is completed; the trap here is that candidates may confuse the RST sent after SYN-ACK as part of a normal connection teardown, rather than recognizing it as the defining characteristic of a SYN scan that never completes the handshake.

How to eliminate wrong answers

Option B (FIN scan) is wrong because a FIN scan sends a packet with only the FIN flag set, expecting an RST from closed ports and no response from open ports; it does not involve SYN or SYN-ACK exchanges. Option C (Christmas tree scan) is wrong because it sends packets with the FIN, URG, and PSH flags set (a 'lit-up' combination), not just the SYN flag, and relies on different responses from open vs. closed ports per RFC 793. Option D (Full connect scan) is wrong because it completes the full three-way handshake (SYN, SYN-ACK, ACK) before sending an RST to close the connection, whereas the scenario shows an RST sent immediately after the SYN-ACK, before the final ACK.

87
MCQmedium

Which cryptographic method uses the same key for both encryption and decryption, and is typically faster than asymmetric encryption?

A.Digital signature
B.RSA
C.AES
D.SHA-256
AnswerC

AES is a symmetric block cipher, so encryption and decryption share one secret key. This satisfies the stem's same-key requirement, and symmetric ciphers process data far faster than asymmetric algorithms such as RSA, which rely on computationally expensive modular arithmetic.

Why this answer

Symmetric encryption uses a single shared key for both operations.

88
Multi-Selecteasy

Which TWO of the following are examples of malware that rely on user interaction to spread? (Select two.)

Select 2 answers
A.Rootkit
B.Worm
C.Trojan
D.Virus
E.Ransomware
AnswersC, D

A Trojan disguises itself as legitimate software, so the victim must execute or install it before it runs. That dependency on the user launching the file satisfies the stem's user-interaction requirement, unlike worms, which self-propagate across networks without any user action.

Why this answer

Option C (Trojan) is correct because a Trojan horse is malware disguised as legitimate software, and it requires the user to download and execute the file before it can infect the system — the user's action is the trigger for the infection. Option D (Virus) is correct because a virus must attach itself to a host file or program and typically needs the user to run that infected file or share it (e.g., via email attachment or USB drive) for it to propagate. By contrast, Option B (Worm) is incorrect because worms self-replicate and spread across networks automatically without any user interaction.

Option A (Rootkit) is incorrect because it is a stealth tool for maintaining privileged access, not a self-spreading mechanism, and Option E (Ransomware) is incorrect because it is defined by its payload (encrypting data for extortion) rather than by a user-interaction-dependent spreading method.

89
MCQhard

A security team implements an IPS that uses behavioral profiling. Which type of detection method is being used?

A.Heuristic
B.Signature-based
C.Rule-based
D.Anomaly-based
AnswerD

Behavioural profiling establishes a baseline of normal activity, then flags deviations from it. Anomaly-based detection compares current events against that learned baseline, so unusual patterns trigger alerts without relying on known signatures — exactly the mechanism the stem describes.

Why this answer

Behavioral profiling establishes a baseline of normal network traffic patterns and then flags deviations from that baseline as potential threats. This is the core mechanism of anomaly-based detection, which identifies malicious activity by comparing observed behavior against a learned model of normal behavior rather than against predefined signatures or rules.

Exam trap

Cisco often tests the distinction between anomaly-based and heuristic detection, where candidates mistakenly choose heuristic because both involve 'behavior' or 'profiling,' but heuristic relies on predefined rules of thumb while anomaly-based relies on a learned baseline of normal behavior.

How to eliminate wrong answers

Option A is wrong because heuristic detection uses algorithms or rules of thumb to identify suspicious behavior based on general characteristics, not by learning and comparing against a baseline of normal behavior. Option B is wrong because signature-based detection relies on predefined patterns (e.g., byte sequences or known exploit payloads) to match known threats, not on behavioral profiling. Option C is wrong because rule-based detection uses static, manually defined rules (e.g., 'if port 445 and SMB traffic, then alert') rather than dynamically learned behavioral baselines.

90
Multi-Selecteasy

An organization's security policy defines acceptable use of corporate email. Which THREE of the following actions are typically prohibited?

Select 3 answers
A.Using email to subscribe to personal newsletters.
B.Emailing the IT support for assistance.
C.Sending personal emails using the corporate account.
D.Forwarding corporate emails to personal external accounts.
E.Using email to send sensitive customer data without encryption.
AnswersC, D, E

Corporate accounts are provided for business purposes, so personal use breaches the acceptable-use policy and exposes the organisation to data loss and reputational risk. Sending personal email from the corporate account violates the policy's scope-of-use constraint, making it a typically prohibited action.

Why this answer

Option C is correct because sending personal emails through a corporate account violates acceptable use policies, which restrict company resources to business purposes and expose the organization to liability and data leakage. Option D is correct because forwarding corporate email to personal external accounts exfiltrates potentially confidential or regulated data outside the organization's controlled environment, a common policy prohibition. Option E is correct because transmitting sensitive customer data without encryption breaches data protection requirements (e.g., GDPR, HIPAA, PCI DSS) and typical acceptable use policies mandating encryption for sensitive information.

Option A does not belong because subscribing to personal newsletters is a minor personal use that many policies tolerate or address separately, not a typical outright prohibition. Option B does not belong because emailing IT support for assistance is a legitimate business use of corporate email and is never prohibited.

Exam trap

Cisco often tests the distinction between actions that are 'typically prohibited' versus those that are merely discouraged or context-dependent, leading candidates to over-select options like personal newsletter subscriptions (Option A) that are not universally banned.

91
MCQmedium

A Cisco Stealthwatch analyst notices a host on the internal network is sending periodic DNS queries to a single external domain with subdomains that are long, random-looking strings (e.g., a8f3k2j9d0x1.example.com). The queries occur every 60 seconds, and the responses are consistently NXDOMAIN. Which type of malicious activity does this pattern most strongly indicate?

A.DNS tunneling for data exfiltration
B.A misconfigured DNS resolver causing retry storms
C.Normal DNS prefetching by a web browser
D.DNS beaconing from a command-and-control implant
AnswerD

The periodic, fixed-interval queries with random subdomains to one domain, combined with NXDOMAIN responses, are classic signs of a DNS beacon. The implant generates unique subdomains to check in and receives no response because the C2 domain may not be active yet or the analyst is seeing only the beacon attempts. This pattern is a well-known indicator of compromise.

Why this answer

The combination of periodic timing, random subdomains, and consistent NXDOMAIN responses points to a DNS beacon from malware attempting to contact command-and-control. The implant uses DNS because it is often allowed through firewalls. The fixed interval and single destination domain distinguish this from normal DNS traffic or tunneling, which would carry larger payloads and expect responses.

Exam trap

The trap here is assuming any DNS anomaly is tunneling, but tunneling requires bidirectional data transfer, while beaconing only needs periodic check-ins.

92
MCQmedium

An analyst is examining a suspicious executable recovered from a compromised host. Static analysis shows it is packed, and dynamic analysis in a sandbox reveals it creates a mutex, modifies registry Run keys, and attempts to connect to a hardcoded IP address on port 443. The file also contains a section with high entropy. Which characteristic most strongly suggests the file is packed or encrypted?

A.A section with high entropy
B.Connection to a hardcoded IP on port 443
C.Modification of registry Run keys
D.Creation of a mutex
AnswerA

High entropy in a file section indicates compressed or encrypted data, which is typical of packed malware. Packers compress or encrypt the original code to evade signature detection, and the unpacking stub restores it at runtime. The high-entropy section is a strong static indicator that the executable is packed or encrypted.

Why this answer

High entropy in a section is a classic static indicator of packing or encryption, because compressed or encrypted data lacks the patterns of normal executable code. Packers use this to hide the original code and evade signature-based detection. The other observed behaviors are runtime actions related to persistence and command-and-control, not structural evidence of packing.

Exam trap

The trap here is focusing on dynamic behaviors like persistence or C2, which are separate from the static structural clue of high entropy that indicates packing.

93
MCQmedium

During a security incident, a security analyst isolates an affected host and collects a memory dump. According to incident response procedures, what is the next step the analyst should take?

A.Reboot the host to clear any malware from memory
B.Notify the public relations team immediately
C.Restore the host from a known good backup
D.Analyze the memory dump to identify indicators of compromise
AnswerD

With the host isolated and volatile memory captured, the immediate priority is examining that dump for indicators of compromise, since memory holds running processes, injected code and network artefacts lost once power is removed or the system is rebooted.

Why this answer

After isolating the host and collecting a memory dump, the next step is to analyze the dump to extract volatile evidence such as running processes, network connections, and injected code. This analysis identifies indicators of compromise (IoCs) that inform containment and eradication. Skipping analysis would lose critical forensic data and hinder understanding of the attack vector.

Exam trap

Cisco often tests the misconception that immediate remediation (reboot or restore) is the priority, when in fact forensic preservation and analysis must occur first to understand the full scope of the compromise.

How to eliminate wrong answers

Option A is wrong because rebooting the host destroys volatile memory evidence, including malware artifacts and process information, which is essential for forensic analysis. Option B is wrong because notifying the public relations team is a communication step that occurs after technical analysis and containment, not immediately after evidence collection. Option C is wrong because restoring from a known good backup should only occur after the root cause and IoCs are identified, to avoid reintroducing the same vulnerability or missing persistent threats.

94
MCQeasy

A security analyst is notified that an employee's laptop was stolen. The laptop contains sensitive customer data. Which type of threat does this incident represent?

A.Exploit
B.Risk
C.Threat
D.Vulnerability
AnswerC

A stolen laptop containing sensitive customer data represents a physical asset loss enabling data exposure, which falls under threat classification in risk models. The threat is the potential actor or event exploiting the missing device's unencrypted data, satisfying the scenario's requirement to categorise the incident as a threat rather than a vulnerability or exploit.

Why this answer

A threat is any potential cause of an unwanted incident that could harm assets; a stolen laptop containing sensitive data is a threat event because it can lead to unauthorized disclosure. The laptop itself is the asset, the sensitive data is what's at risk, and the theft is the threat action. Exploit, risk, and vulnerability describe different concepts in the threat model.

Exam trap

200-201 often tests the threat vs. vulnerability vs. risk vs. exploit distinction — candidates frequently pick 'vulnerability' for a stolen device because it feels like a weakness, but theft is a threat event, not a weakness in the system.

How to eliminate wrong answers

Option A (Exploit) is wrong because an exploit is a technique or code that takes advantage of a vulnerability, not the theft event itself. Option B (Risk) is wrong because risk is the potential for loss or damage when a threat exploits a vulnerability, calculated as likelihood times impact — it is the outcome, not the event. Option D (Vulnerability) is wrong because a vulnerability is a weakness (e.g., missing encryption, unpatched software) that a threat can exploit; the stolen laptop is not itself a weakness.

95
MCQmedium

An analyst reviews the Cisco ASA syslog message shown in the exhibit. What does this entry indicate?

A.A successful HTTP connection from the outside to the inside server
B.A VPN tunnel initiation that was rejected due to authentication failure
C.An attempted connection from an external host to an internal web server that was blocked by the firewall
D.A NAT translation failure for an outbound connection
AnswerC

The ASA log records a denied inbound TCP connection to the internal web server's port, matching a firewall ACL drop. This confirms traffic from an external host was blocked before reaching the server, exactly the scenario described.

Why this answer

The syslog message shows a deny action for an HTTP connection (port 80) from an external IP (outside) to an internal IP (inside). The '%ASA-4-106023' message indicates a packet was denied by the firewall's access control list (ACL). This matches the scenario of an attempted external-to-internal web connection being blocked, which is option C.

Exam trap

Cisco often tests the ability to distinguish between different syslog message IDs (e.g., 106023 for ACL denies vs. 305006 for NAT failures) and to correctly interpret the 'Deny' keyword as a block, not a successful connection.

How to eliminate wrong answers

Option A is wrong because the syslog explicitly says 'Deny', not 'Allow', so a successful HTTP connection is not indicated. Option B is wrong because VPN tunnel initiation failures are typically logged with different syslog IDs (e.g., 713228 for IKE failure) and involve authentication or phase-1/phase-2 errors, not a simple TCP deny on port 80. Option D is wrong because NAT translation failures generate syslog messages like '%ASA-3-305006' for 'no translation group found', not a deny action on a specific port/protocol.

96
MCQeasy

When performing file analysis, which method is most reliable for determining the actual file type regardless of its extension?

A.Opening the file in a text editor
B.Checking the file extension
C.Examining the file's magic bytes
D.Checking the file size
AnswerC

Magic bytes are fixed signature values at the start of a file's binary content, so they identify the true format independently of the filename extension. An attacker can rename a malicious executable to .txt, but the magic bytes still reveal the actual type, satisfying the requirement to determine file type regardless of extension.

Why this answer

Magic bytes (or file signatures) are unique byte sequences at the beginning of a file that identify its format regardless of the file extension. This method is reliable because it examines the actual binary content, such as the 'PK' header for ZIP files or '‰PNG' for PNG images, rather than relying on user-assigned metadata that can be easily changed.

Exam trap

Cisco often tests the concept that file extensions are user-modifiable metadata and thus unreliable, while magic bytes provide a content-based verification that is independent of the filename.

How to eliminate wrong answers

Option A is wrong because opening a file in a text editor only displays raw text or garbled characters for binary files, and it does not reliably identify the file type; it may also misinterpret encoding or execute harmful content. Option B is wrong because checking the file extension is unreliable—extensions can be renamed arbitrarily (e.g., renaming a .exe to .jpg) and do not reflect the actual file content. Option D is wrong because checking the file size provides no information about the file's structure or format; two files of identical size can be completely different types.

97
MCQhard

A SOC analyst is reviewing firewall logs and sees repeated outbound connections from an internal server to an external IP on TCP port 443, but the traffic is not TLS. Packet capture shows a custom binary protocol with periodic small keepalives. Which type of malicious activity is most consistent with these findings?

A.A misconfigured application using HTTPS on port 443
B.Command-and-control beaconing over a non-standard protocol
C.Data exfiltration over DNS
D.Lateral movement using SMB
AnswerB

Malware often masquerades as HTTPS by using port 443 while speaking a custom binary protocol to evade port-based filtering and TLS inspection. The periodic small keepalives are a hallmark of beaconing, where the implant checks in with its controller at regular intervals. Because the traffic is not actually TLS, signature-based TLS inspection will not flag it, making behavioral analysis essential for detection.

Why this answer

The combination of outbound port 443, absence of TLS, a custom binary protocol, and periodic small keepalives strongly suggests command-and-control beaconing. Attackers commonly use port 443 to blend with normal web traffic while evading TLS inspection by not actually using TLS. The regular check-ins are designed to receive instructions or exfiltrate small amounts of data without drawing attention.

Exam trap

The trap here is assuming port 443 always means TLS and benign web traffic, when attackers frequently abuse it for non-TLS command-and-control.

98
Multi-Selecthard

A SOC analyst is investigating a potential security incident involving a Windows workstation. The analyst has collected network traffic and host logs. Which two artifacts would provide the most direct evidence of a Pass-the-Hash attack? (Choose two.)

Select 2 answers
A.Network traffic showing SMB authentication with NTLMSSP messages containing a username and hash.
B.Windows Security Event ID 4688 showing 'svchost.exe' with parent 'services.exe'.
C.Windows Security Event ID 4624 with Logon Type 3 and NTLM authentication.
D.Windows Security Event ID 4672 indicating special privileges assigned to a new logon.
E.Windows Security Event ID 4768 showing a Kerberos TGT request.
AnswersA, C

Pass-the-Hash attacks often leverage SMB for lateral movement. Capturing network traffic that includes NTLMSSP authentication attempts can reveal the use of NTLM hashes instead of plaintext passwords. Specifically, the NTLMSSP_AUTH message contains the username and the challenge response derived from the hash. If the same hash is used from multiple hosts or in an unusual pattern, it strongly suggests Pass-the-Hash. This artifact provides direct network-level evidence.

Why this answer

Pass-the-Hash is an attack where an adversary uses the NTLM hash of a user's password to authenticate without knowing the plaintext. The most direct evidence comes from authentication events that show NTLM usage, such as Windows Security Event ID 4624 with Logon Type 3 and NTLM, and network captures of SMB NTLMSSP authentication. Other events like process creation or privilege assignment are not specific to this technique.

Exam trap

The trap here is assuming that any NTLM authentication or administrative logon indicates Pass-the-Hash, when in fact NTLM is still used legitimately; the key is the context of hash reuse without plaintext.

99
MCQhard

A security analyst is investigating a Linux server that was compromised. The attacker used a rootkit to hide processes and files. The analyst runs 'lsmod' and notices a kernel module named 'hideproc' that is not recognized. Which command should the analyst use to determine the module's file path and potentially identify the rootkit?

A.lsmod | grep hideproc
B.dmesg | grep hideproc
C.rmmod hideproc
D.modinfo hideproc
AnswerD

modinfo displays information about a kernel module, including its filename, description, author, and license. Running 'modinfo hideproc' will show the full path to the module file, which can then be analyzed or removed. This directly helps identify the rootkit's location.

Why this answer

The analyst needs to find the file path of the suspicious kernel module to analyze or remove it. The modinfo command provides detailed information about a module, including its filename and location. This is the correct tool for identifying where the rootkit module resides on disk, enabling further forensic analysis or cleanup.

Exam trap

The trap here is confusing listing loaded modules with obtaining detailed module information, such as the file path, which requires modinfo.

100
MCQeasy

A new security analyst is reviewing the organization's data classification policy and notices that data labeled 'Restricted' must be encrypted at rest and in transit, while data labeled 'Internal' has no encryption requirement. The analyst asks why the policy distinguishes between these levels. What is the primary purpose of a data classification policy?

A.To provide a legal shield that eliminates liability if data is breached
B.To specify which employees are allowed to access the internet from corporate devices
C.To define handling requirements based on the sensitivity and value of the data
D.To ensure all data receives the same level of protection regardless of sensitivity
AnswerC

This is correct because data classification assigns labels such as 'Restricted' or 'Internal' based on sensitivity, and each label maps to specific handling, encryption, and access requirements. The policy in the scenario applies stronger controls to more sensitive data, which is the core function of classification. It enables risk-based protection aligned with business and compliance needs.

Why this answer

A data classification policy categorizes information by sensitivity and value so that appropriate controls, such as encryption for 'Restricted' data, can be applied consistently. It supports risk-based decision-making, regulatory compliance, and clear handling procedures. The distinction between 'Restricted' and 'Internal' in the scenario exists precisely to ensure stronger protections are applied where the impact of disclosure is greatest.

Exam trap

The trap here is assuming that a data classification policy is about access control lists or legal immunity rather than about mapping data sensitivity to handling requirements.

101
MCQeasy

In network forensics, which Wireshark filter would be used to reconstruct a TCP conversation between two hosts?

A.ip.addr
B.http.request
C.tcp.stream eq 0
D.dns.qry.name
AnswerC

The tcp.stream eq 0 filter isolates a single reassembled TCP conversation by its stream index, letting the analyst follow the full exchange between the two hosts. Following the stream reconstructs the session payload for forensic review.

Why this answer

The filter `tcp.stream eq 0` isolates all packets belonging to a specific TCP stream, identified by Wireshark's internal stream index. This allows you to reconstruct the full conversation between two hosts, including the three-way handshake, data transfer, and teardown. It is the standard method for following a TCP stream in Wireshark, as it groups packets by connection rather than just IP addresses or ports.

Exam trap

The trap here is confusing IP-based filtering with stream-based filtering; candidates might think that filtering by IP address is sufficient to reconstruct a conversation, but it fails to separate multiple connections between the same hosts.

How to eliminate wrong answers

Option A is wrong because `ip.addr` filters packets by IP address but does not distinguish between multiple TCP connections between the same hosts, so it cannot isolate a single conversation. Option B is wrong because `http.request` only displays HTTP request packets, missing responses and other TCP segments, and is not specific to a single TCP stream. Option D is wrong because `dns.qry.name` filters DNS query names, which is unrelated to TCP stream reconstruction.

102
MCQmedium

A Cisco Firepower analyst inspects an inline intrusion policy event where the packet was dropped but only a partial payload was captured. The analyst wants to confirm whether the attack was successful on the target host. Which data source should be correlated with the Firepower event?

A.NetFlow records exported from the Firepower device
B.Syslog messages generated by the Firepower management center
C.Full packet capture stored on the Firepower device
D.Endpoint security product telemetry from the target host
AnswerD

Endpoint detection and response (EDR) or endpoint protection platform telemetry records process execution, file modification, registry changes, and command-line arguments on the target. Correlating the Firepower intrusion event timestamp and source IP with this endpoint data reveals whether the dropped packet was part of a successful exploit chain or whether the host actually spawned a malicious process. This is the authoritative source for confirming host-level compromise after a partial network capture.

Why this answer

When an intrusion event shows a partial payload capture, the network sensor can confirm the attempt but not the outcome on the host. Endpoint telemetry supplies process, file, and registry evidence that ties the network event to actual execution. Correlating the Firepower timestamp and addresses with endpoint records determines whether the attack succeeded, which is the analyst's stated goal.

Exam trap

The trap here is assuming that more packet capture or flow data from the same Firepower sensor can prove host compromise, when only endpoint telemetry shows process-level execution.

103
Multi-Selecthard

A SOC analyst is reviewing Cisco Firepower and NetFlow records for a suspected lateral movement campaign inside the corporate network. Which TWO monitoring observations most strongly support the hypothesis that an attacker is moving laterally using SMB? (Choose two.)

Select 2 answers
A.Repeated authentication attempts using a service account against multiple servers on port 445
B.An internal host sending large volumes of ICMP echo requests to the default gateway
C.A single host resolving many external DNS names over port 53
D.A workstation downloading operating system updates from an internal WSUS server over HTTP
E.Multiple internal hosts receiving TCP connections on port 445 from a single workstation in a short time window
AnswersA, E

Using one service account to authenticate to many servers over SMB suggests credential reuse for lateral movement, especially if the account is not normally used interactively. Attackers commonly harvest service account credentials and spray them across hosts, so this pattern supports the SMB lateral movement hypothesis.

Why this answer

SMB lateral movement is characterized by one host fanning out to many internal systems on port 445 and by credential reuse, such as a service account authenticating to multiple servers. These two observations together distinguish attacker pivoting from normal file share access, making them the strongest supporting evidence.

Exam trap

The trap here is selecting any internal-to-internal traffic as lateral movement, when the distinguishing factors are the fan-out pattern on port 445 and suspicious credential reuse rather than routine update or DNS traffic.

104
MCQmedium

An organization is reviewing its exposure to attack surface. A security architect notes that employees routinely install browser extensions from unapproved sources, and several internal web applications accept unsanitized input. Which concept do these findings primarily describe?

A.Vulnerabilities that expand the attack surface and may be exploited by threat actors
B.A compliance violation of the Payment Card Industry Data Security Standard
C.A social engineering campaign targeting employees through malicious extensions
D.A denial-of-service condition caused by excessive extension usage
AnswerA

Unsanitized input creates injection vulnerabilities such as cross-site scripting, and unapproved browser extensions add untrusted code to endpoints. Together these weaknesses enlarge the attack surface, giving threat actors more paths to exploit. The architect's findings describe exploitable vulnerabilities rather than a specific attack technique or a compliance gap.

Why this answer

The findings are vulnerabilities that enlarge the attack surface. Unsanitized input enables injection flaws, and unapproved extensions introduce untrusted code with broad browser privileges. Both give threat actors additional entry points and increase the likelihood of compromise.

Reducing the attack surface requires application input validation, extension allowlisting, and endpoint policy enforcement, which directly address the weaknesses identified.

Exam trap

The trap here is focusing on the browser extensions as a social engineering issue, when the combined findings describe exploitable vulnerabilities that widen the attack surface.

105
MCQeasy

A SOC analyst is triaging a Cisco Stealthwatch alarm that shows a workstation uploading 4 GB to an external IP address at 02:00, outside normal business hours. The destination has no prior reputation data. Which action should the analyst take first according to the incident response process?

A.Block the external IP address on the perimeter firewall
B.Escalate the alarm directly to the legal department
C.Validate the alarm and identify the internal host and user
D.Disable the user account associated with the workstation
AnswerC

The first step in the incident response process is to validate that the alarm represents a real security event and to identify the affected asset and user. This establishes scope, confirms whether the traffic is expected, and determines whether escalation is warranted. Only after validation and identification can the analyst make informed containment decisions. Jumping to blocking or disabling accounts without this step risks disrupting legitimate business activity and missing related compromised systems.

Why this answer

Incident response follows a defined sequence, and the identification phase requires validating the alarm and determining the affected asset and user before containment. This step confirms whether the activity is malicious, establishes scope, and informs subsequent decisions. Blocking, disabling accounts, or escalating to legal before validation can disrupt legitimate operations and leave related compromised systems undiscovered.

Exam trap

The trap here is equating a large outbound transfer with confirmed exfiltration and skipping validation, when the first response step is always to verify and identify the affected host.

106
MCQhard

Refer to the exhibit. A security analyst is reviewing the ASA configuration. Which traffic will be permitted from the outside interface?

A.Any IP traffic to host 10.1.1.1
B.All traffic from the outside to the inside network
C.TCP traffic to host 10.1.1.1 on port 80
D.HTTP traffic from internal hosts to the outside
AnswerC

The access list permits TCP from any source to host 10.1.1.1 on port 80, so only that specific web traffic is allowed inbound. Other protocols, ports, or destinations are implicitly denied by the trailing ACL rule.

Why this answer

The ASA configuration shown includes an access-list entry that permits TCP traffic from any source to host 10.1.1.1 on port 80. This is the only rule that explicitly allows traffic from the outside interface to the inside network, and since the outside interface has the access-group applied inbound, only traffic matching this permit statement will be allowed.

Exam trap

Cisco often tests the distinction between 'any IP traffic' and 'any TCP traffic' — the trap here is that candidates may assume 'permit tcp any host 10.1.1.1 eq 80' allows all IP traffic to that host, but it strictly permits only TCP with destination port 80.

How to eliminate wrong answers

Option A is wrong because the access-list permits only TCP traffic to host 10.1.1.1, not any IP traffic (which would include UDP, ICMP, etc.). Option B is wrong because the access-list does not permit all traffic from outside to inside; it only permits TCP traffic to a specific host on a specific port. Option D is wrong because the question asks about traffic permitted from the outside interface, not traffic originating from internal hosts; HTTP traffic from internal hosts to the outside would be evaluated by a different access-list applied to the inside interface or by stateful inspection rules.

107
MCQmedium

An analyst is reviewing PCAP and sees a TCP stream with a Wireshark filter 'tcp.stream eq 0'. The conversation shows an interactive shell session with commands like 'whoami' and 'ls'. This is most likely evidence of what?

A.DNS tunneling
B.Reverse shell
C.SQL injection
D.ARP spoofing
AnswerB

An interactive shell where the remote host executes commands such as whoami and ls indicates the attacker's machine is receiving a session from the victim, the defining pattern of a reverse shell. The victim initiated the outbound connection, evading inbound firewall rules.

Why this answer

The PCAP shows an interactive shell session with commands like 'whoami' and 'ls' over TCP. This is characteristic of a reverse shell, where an attacker compromises a host and establishes a command-and-control channel back to their machine, allowing interactive command execution. The use of 'tcp.stream eq 0' in Wireshark simply isolates a specific TCP conversation, and the presence of shell commands confirms a reverse shell.

Exam trap

The trap here is confusing an interactive shell session with other types of attacks that also involve network traffic, such as DNS tunneling or SQL injection, because candidates may not recognize the specific commands and the nature of a reverse shell.

How to eliminate wrong answers

Option A is wrong because DNS tunneling involves encoding data within DNS queries and responses, typically using TXT or NULL records, and would not show interactive shell commands like 'whoami' and 'ls' in a TCP stream. Option C is wrong because SQL injection is an attack against database-driven applications, where malicious SQL statements are inserted into input fields; it would not produce an interactive shell session in a PCAP. Option D is wrong because ARP spoofing is a layer 2 attack that manipulates ARP tables to intercept traffic, and it does not involve an interactive shell session with commands.

108
MCQmedium

An incident response plan specifies that containment must be completed before eradication. A security analyst identifies a malware infection on a critical server. What should be done first?

A.Disconnect the server from the network
B.Run antivirus scans
C.Notify law enforcement
D.Reinstall the operating system
AnswerA

Containment precedes eradication per the plan, and disconnecting the server from the network isolates the malware, preventing lateral spread or data exfiltration. This is the containment step, satisfying the stem's ordering requirement before any eradication or recovery actions begin.

Why this answer

According to the incident response plan, containment must be completed before eradication. Disconnecting the server from the network (Option A) is the immediate containment action that prevents the malware from spreading laterally to other hosts, preserving the integrity of the network and allowing for forensic analysis. This step aligns with the NIST SP 800-61 incident response lifecycle, where containment is prioritized to limit damage before any eradication or recovery steps are taken.

Exam trap

Cisco often tests the strict ordering of the incident response phases (Preparation, Detection & Analysis, Containment, Eradication, Recovery, Post-Incident Activity), and the trap here is that candidates confuse eradication actions (like running antivirus or reinstalling the OS) with the required first containment step, leading them to choose a technically plausible but procedurally incorrect answer.

How to eliminate wrong answers

Option B is wrong because running antivirus scans is an eradication or detection step, not a containment action; performing scans before containment could alert the malware or cause it to spread further. Option C is wrong because notifying law enforcement is a post-containment notification step that occurs after the scope of the incident is understood and evidence is preserved, not the first action. Option D is wrong because reinstalling the operating system is a recovery/eradication step that should only occur after containment is complete and forensic evidence has been collected; doing so first would destroy volatile data and potentially violate chain of custody.

109
MCQeasy

An analyst is investigating a potential DNS tunneling attack. Which characteristic in DNS traffic would most likely indicate DNS tunneling?

A.DNS queries with long, random-looking subdomains to a single domain.
B.Frequent DNS queries to the same domain at regular intervals.
C.DNS queries for domains that are known to be malicious.
D.DNS query responses with unusually large payload sizes.
AnswerA

Long, random-looking subdomains encode exfiltrated data or command payloads, since DNS labels carry limited bytes per query. Repeated queries to one domain, rather than many domains, match tunnelling's need for a stable server endpoint. This pattern satisfies the stem's requirement for a characteristic distinguishing tunnelling from ordinary DNS resolution.

Why this answer

DNS tunneling encodes data (e.g., stolen files, C2 commands) into the query name itself, so the attacker generates long, high-entropy subdomains like 'a8f3k2...exfil.attacker.com' under a single controlled domain. The randomness defeats signature-based detection, and the length maximizes the bytes smuggled per query. This pattern — many unique, long, random labels pointing to one authoritative domain — is the hallmark of tools such as iodine, dnscat2, and DNSExfiltrator.

Exam trap

200-201 often tests the confusion between DNS tunneling (data hidden in long, random query names) and DNS beaconing (regular-interval check-ins) or DNS amplification (large responses), so candidates who pick 'large payload' or 'regular intervals' miss the specific structural signature of tunneling.

How to eliminate wrong answers

Option B is wrong because regular-interval queries to the same domain describe beaconing or normal polling (e.g., NTP-style checks, CDN heartbeats, or malware check-ins), not tunneling — tunneling requires variable, data-bearing query names, not fixed timing. Option C is wrong because a known-malicious domain indicates a blocklist hit or IOC match, which is threat-intel detection, not a structural tunneling characteristic; a tunnel can run over a never-before-seen domain. Option D is wrong because large response payloads point to DNS amplification or oversized TXT/ANY records, whereas tunneling typically shows large *query* names and many small responses — response size alone is a weaker, less specific indicator.

110
MCQhard

A security analyst is evaluating the risk of a new vulnerability in a web application. The vulnerability has a CVSS base score of 9.8 and is remotely exploitable without authentication. The application is internet-facing and processes sensitive customer data. Which risk response strategy is MOST appropriate according to risk management principles?

A.Risk transference
B.Risk avoidance
C.Risk acceptance
D.Risk mitigation
AnswerD

Risk mitigation involves applying controls to reduce the likelihood or impact of a vulnerability. Given the high CVSS score and exposure, patching or implementing a web application firewall is necessary. Mitigation is the most appropriate response to protect sensitive data and maintain compliance.

Why this answer

The vulnerability is critical and remotely exploitable, posing a high risk to sensitive data. Mitigating the risk through patching or other controls is the most appropriate response. Risk acceptance, transference, or avoidance are less suitable because they do not directly reduce the technical exposure in a timely manner.

Exam trap

The trap here is choosing risk transference (e.g., cyber insurance) as a quick fix, but it does not address the underlying vulnerability and is not the primary response for high-severity technical risks.

111
MCQeasy

In a PCAP analysis, an analyst uses the filter 'http.request.uri contains "UNION"' and finds multiple HTTP requests with 'SELECT' and 'UNION SELECT' in the URI parameter. Which type of attack is likely occurring?

A.SQL injection
B.Buffer overflow
C.Cross-site scripting
D.Command injection
AnswerA

The 'UNION SELECT' string in URI parameters is a classic SQL injection signature, used to append attacker-controlled queries onto a legitimate database statement. Its presence across multiple HTTP requests confirms attempts to manipulate backend SQL through unsanitised input.

Why this answer

The filter 'http.request.uri contains "UNION"' detects HTTP requests where the URI contains the SQL keyword 'UNION'. The presence of 'SELECT' and 'UNION SELECT' in URI parameters is a classic signature of SQL injection (SQLi), where an attacker attempts to manipulate backend database queries by injecting SQL code into input fields. This attack targets the database layer, aiming to extract or modify data, and is distinct from other web vulnerabilities.

Exam trap

The trap here is confusing SQL injection with command injection or XSS, as all involve injecting malicious input; candidates must recognize that 'UNION SELECT' is specific to SQL, not OS commands or client-side scripts.

How to eliminate wrong answers

Option B is wrong because buffer overflow involves overwriting memory buffers with excessive data, typically indicated by crashes or memory corruption, not SQL keywords in HTTP requests. Option C is wrong because cross-site scripting (XSS) injects client-side scripts (e.g., JavaScript) into web pages viewed by other users, not SQL commands in the URI. Option D is wrong because command injection targets operating system commands, often using shell metacharacters (e.g., ;, |, &&) to execute system commands, not SQL syntax like 'UNION SELECT'.

112
Multi-Selectmedium

Which THREE indicators are commonly found in network traffic that suggest a host is part of a botnet? (Choose three.)

Select 3 answers
A.Connections to known IRC servers on non-standard ports
B.Large file downloads from external servers
C.Periodic connections to IP addresses with poor reputation
D.High volumes of outbound traffic to multiple destinations
E.Frequent DNS queries to legitimate corporate DNS servers
AnswersA, C, D

IRC remains a common botnet C2 channel; compromised hosts beacon to IRC servers on non-standard ports to evade simple filtering. This satisfies the stem's traffic-indicator requirement, since such connections reveal command-and-control rendezvous rather than legitimate user activity.

Why this answer

Option A is correct because botnets historically use IRC command-and-control (C2) channels, often on non-standard ports like 6667 or 31337 to evade basic filtering, so connections to known IRC servers on such ports are a classic botnet indicator. Option C is correct because bots periodically beacon to C2 infrastructure, and repeated connections to IP addresses with poor reputation (e.g., known malicious hosts, low-reputation ASNs) strongly suggest compromised hosts checking in. Option D is correct because botnets frequently conduct distributed activities such as spam, DDoS, or scanning, producing high volumes of outbound traffic to many destinations, which is anomalous for a normal host.

Option B is not a typical botnet indicator because large file downloads from external servers more often indicate legitimate patching, software distribution, or user activity rather than bot behavior. Option E is not a botnet indicator because frequent DNS queries to legitimate corporate DNS servers are normal in enterprise environments and do not by themselves suggest compromise.

Exam trap

Cisco often tests the distinction between normal network behavior (like large downloads or frequent DNS queries) and specific botnet indicators (IRC on non-standard ports, connections to low-reputation IPs, and asymmetric outbound traffic patterns), trapping candidates who confuse generic high-bandwidth activity with botnet C2 signatures.

113
Multi-Selecteasy

Which TWO are examples of technical security controls? (Select two.)

Select 2 answers
A.Firewall
B.Security policy
C.Security awareness training
D.Background checks
E.Encryption
AnswersA, E

A firewall enforces network traffic filtering through predefined rule sets, directly implementing a preventive technical control that restricts unauthorised access. It satisfies the stem's requirement for technical controls because it operates automatically via hardware or software mechanisms, unlike administrative or physical controls such as policies or locks.

Why this answer

A firewall (A) is a technical security control because it is a hardware or software system that enforces network traffic filtering rules (e.g., ACLs, stateful inspection) to prevent unauthorized access, operating directly on the technology rather than on people or procedures. Encryption (E) is likewise a technical control since it uses cryptographic algorithms and keys (e.g., AES, TLS) to protect data confidentiality and integrity at rest or in transit. The unmarked options do not belong because a security policy (B) is an administrative/management control, while security awareness training (C) and background checks (D) are operational/personnel controls that address human behavior rather than technical mechanisms.

Exam trap

Cisco often tests the distinction between administrative, physical, and technical controls, and the trap here is that candidates confuse a security policy (a document) or training (a human process) with a technical control, because they are all part of a defense-in-depth strategy.

114
MCQmedium

A SOC analyst is tuning IDS signatures and notices that a particular signature triggers frequently on legitimate traffic from a specific internal application. The signature has a high false positive rate. What is the best action to take?

A.Disable the signature entirely.
B.Increase the severity of the signature to get more attention.
C.Create a suppression rule to ignore the specific source IP or application.
D.Change the signature action to 'alert' instead of 'drop'.
AnswerC

Suppression rules let the IDS ignore matching traffic from the specific source IP or application while retaining the signature for all other sources, eliminating the recurring false positives without losing genuine detection coverage. This directly addresses the high false-positive rate constraint.

Why this answer

A suppression rule is the correct tuning action because it preserves the signature's detection capability for all other traffic while filtering out the known-good source IP or application that generates the false positives. This is the standard IDS/IPS tuning practice: narrow the exception rather than removing the detection entirely. It maintains visibility into genuine attacks using the same signature from other sources.

Exam trap

The trap here is confusing 'reduce false positives' with 'disable the noisy rule' — candidates often pick the most drastic action (disable) instead of the surgical one (suppress specific source), missing that the exam tests least-disruptive tuning.

How to eliminate wrong answers

Option A is wrong because disabling the signature entirely removes detection for real attacks that would match it, creating a blind spot — the correct approach is to narrow, not eliminate, coverage. Option B is wrong because raising severity on a noisy signature increases alert fatigue and does nothing to reduce the false positive rate; severity is a prioritization field, not a filtering mechanism. Option D is wrong because changing the action from 'drop' to 'alert' only changes the response mode, not the volume of false positives — the analyst would still receive the same noisy alerts, just without blocking.

115
Multi-Selecthard

During packet analysis in Wireshark, which THREE findings are indicators of potential malicious activity? (Choose THREE.)

Select 3 answers
A.An HTTPS connection to a well-known website.
B.An unusually large ICMP echo request packet (e.g., 65,000 bytes).
C.Unencrypted credentials in an HTTP packet.
D.A normal DNS query for a common domain.
E.A large number of TCP SYN packets to various ports on one host.
AnswersB, C, E

Oversized ICMP echo requests exploit the protocol's normal 64-byte payload ceiling, indicating tunnelling or data exfiltration hidden inside ping traffic. This satisfies the stem's malicious-activity criterion because legitimate diagnostics never require 65,000-byte payloads, and such frames often signal covert channels or ping floods.

Why this answer

Option B is correct because an ICMP echo request of roughly 65,000 bytes is abnormally large for a standard ping (normally 32–64 bytes of payload), indicating possible ICMP tunneling, data exfiltration, or a Ping of Death-style attack. Option C is correct because credentials transmitted in cleartext over HTTP can be captured by anyone sniffing the traffic, which is a clear sign of insecure and potentially malicious credential harvesting or a policy violation. Option E is correct because a flood of TCP SYN packets to multiple ports on a single host is the classic signature of a port scan (e.g., SYN scan), often a precursor to exploitation.

Option A is not an indicator because HTTPS to a well-known website is normal, expected, encrypted traffic. Option D is not an indicator because a routine DNS query for a common domain is ordinary network behavior and not inherently suspicious.

Exam trap

Cisco often tests the distinction between normal traffic patterns and protocol anomalies; the trap here is that candidates may overlook the 'unusually large' qualifier and dismiss ICMP anomalies as benign, or mistake a legitimate HTTPS connection for suspicious activity due to encryption.

116
MCQmedium

A firewall log shows repeated denied packets from IP 10.0.0.5 to destination 192.168.1.10 on port 22. What is the most likely attack?

A.HTTP flood
B.SMB exploit
C.SSH brute force
D.DNS amplification
AnswerC

Repeated denied connections to port 22, the SSH service, from one source indicate automated credential guessing against remote shell access. The firewall's consistent blocking of these attempts confirms brute-force behaviour rather than legitimate administrative traffic, matching the log pattern described in the stem.

Why this answer

Repeated denied packets from a single source IP to a specific destination on port 22 (SSH) indicate a brute-force attack, where an attacker attempts multiple username/password combinations to gain unauthorized access. The firewall logs show the traffic is being blocked, but the pattern of repeated attempts is characteristic of an SSH brute-force attack, not a flood or exploit targeting other services.

Exam trap

Cisco often tests the association between specific port numbers and common attack types, so the trap here is that candidates may confuse port 22 with HTTP (port 80) or SMB (port 445) and pick a wrong answer based on the attack name rather than the port number.

How to eliminate wrong answers

Option A is wrong because an HTTP flood targets port 80 or 443 with a high volume of HTTP requests, not port 22 (SSH). Option B is wrong because an SMB exploit targets port 445 (SMB over TCP) or 139 (NetBIOS), not port 22, and involves exploiting vulnerabilities like EternalBlue, not repeated authentication attempts. Option D is wrong because a DNS amplification attack uses UDP port 53 and involves spoofed source IPs to amplify traffic toward a victim, not repeated TCP connections to port 22.

117
MCQmedium

Which log source would provide the most detailed information about HTTP requests, including URLs and user agents?

A.DNS logs
B.Firewall logs
C.Web server logs
D.System logs
AnswerC

Web server logs record each HTTP transaction, capturing request method, URL path, query strings, status codes and User-Agent headers. This satisfies the requirement for detailed request-level data, unlike firewall logs that show only connection metadata or NetFlow records lacking application-layer detail.

Why this answer

Web server logs capture HTTP requests with details like URL, method, response code, and user-agent. They are the best source for HTTP traffic details.

118
Multi-Selecthard

An organization is implementing a threat intelligence sharing program. Which THREE elements are commonly used standards or platforms for sharing threat intelligence?

Select 3 answers
A.MISP
B.ISAC
C.TAXII
D.STIX
E.OpenIOC
AnswersA, C, D

MISP is an open-source threat intelligence sharing platform where organisations exchange indicators, events and correlated attributes. It satisfies the sharing requirement by providing a common repository and community, complementing the STIX format and TAXII transport protocol named elsewhere.

Why this answer

MISP (Malware Information Sharing Platform) is correct because it is a widely used open-source threat intelligence platform that enables organizations to store, correlate, and share indicators of compromise and threat data with trusted partners. TAXII (Trusted Automated Exchange of Intelligence Information) is correct because it is the OASIS-defined application-layer protocol specifically designed to transport cyber threat intelligence over HTTPS between parties. STIX (Structured Threat Information Expression) is correct because it is the standardized language/schema used to represent cyber threat intelligence in a structured, machine-readable form, and it is commonly paired with TAXII for exchange.

ISACs (Information Sharing and Analysis Centers) are sector-specific sharing organizations rather than a technical standard or platform, and OpenIOC is a proprietary Mandiant indicator format that never became a broadly adopted sharing standard, so neither belongs here.

119
MCQhard

During a security audit, it is discovered that an organization’s network is vulnerable to ARP spoofing attacks. Which type of attack could result from exploiting this vulnerability?

A.DNS poisoning
B.Man-in-the-middle
C.Phishing
D.DoS
AnswerB

ARP spoofing lets an attacker send forged ARP replies, poisoning victims' caches so traffic is redirected through the attacker's machine. Positioned between two communicating hosts, the attacker relays traffic while reading or altering it, producing a man-in-the-middle condition.

Why this answer

ARP spoofing allows an attacker to send forged ARP replies that associate the attacker's MAC address with a legitimate IP (e.g., the default gateway), causing victims to send traffic to the attacker instead of the real destination. The attacker then relays traffic between the victim and the gateway, positioning themselves in the path — a classic man-in-the-middle (MITM) attack that enables eavesdropping, session hijacking, and credential theft.

Exam trap

200-201 often tests the distinction between ARP spoofing's direct effect (MITM) and its secondary effects (DoS, DNS poisoning) — candidates must identify the primary, canonical consequence the question is targeting.

How to eliminate wrong answers

Option A is wrong because DNS poisoning involves corrupting DNS resolver caches or responses to redirect name resolution; while ARP spoofing can facilitate DNS poisoning by intercepting DNS queries, the direct and primary consequence of ARP spoofing is MITM, not DNS cache corruption. Option C is wrong because phishing is a social engineering attack delivered via email or fake websites; it does not result from ARP spoofing, though ARP spoofing could redirect a victim to a phishing site as a secondary effect. Option D is wrong because a DoS attack aims to make a service unavailable; ARP spoofing can cause DoS if the attacker blackholes traffic, but the question asks for the attack type that results from the vulnerability, and MITM is the canonical, direct exploitation.

120
MCQmedium

A host is infected with malware that uses DNS tunneling to exfiltrate data. Which type of analysis would best detect this activity?

A.DNS log analysis
B.Windows event log analysis
C.Firewall log analysis
D.NetFlow analysis
AnswerA

DNS log analysis inspects query records for anomalies such as unusually long subdomains, high query volumes, or TXT record abuse, which are hallmarks of DNS tunnelling. Since the malware exfiltrates data through DNS queries, examining these logs directly satisfies the stem's requirement to detect the tunnelling activity.

Why this answer

DNS tunneling encodes exfiltrated data within DNS queries or responses, often using TXT or A record types to bypass network security controls. DNS log analysis is the most direct detection method because it reveals anomalous patterns such as unusually long domain names, excessive NXDOMAIN responses, or high volumes of DNS traffic to a single external server, which are hallmarks of tunneling activity.

Exam trap

Cisco often tests the misconception that firewall logs or NetFlow are sufficient for detecting application-layer tunneling, when in fact only DNS-specific logs provide the granularity to see the encoded payloads within DNS queries.

How to eliminate wrong answers

Option B is wrong because Windows event log analysis focuses on system-level events (e.g., process creation, user logins) and does not capture network-layer DNS traffic, so it would miss the outbound data exfiltration. Option C is wrong because firewall logs typically record IP addresses, ports, and protocols but lack the DNS query/response payload details needed to detect the encoded data within DNS messages. Option D is wrong because NetFlow analysis provides metadata (source/destination IP, bytes transferred) but does not inspect the content of DNS packets, making it unable to identify the tunneling pattern or the data being exfiltrated.

121
MCQhard

Refer to the exhibit. A network administrator notices that remote SSH logins to the router succeed, but the router is not sending accounting records. Based on the configuration, what is the most likely cause?

A.The AAA authorization method is set to local, not TACACS+.
B.The TACACS+ server key is not configured correctly.
C.The AAA authentication method uses local database instead of TACACS+.
D.The accounting command references a TACACS+ group that is not defined.
AnswerD

The accounting command points to a TACACS+ server group name that has no matching aaa group server tacacs+ definition. Authentication succeeds through a valid method list, but accounting records cannot be sent because the referenced group does not exist.

Why this answer

The `accounting exec default` command references a TACACS+ server group named 'tacacs_server_group' that is not defined in the configuration. Without a defined server group, the router cannot send accounting records to any TACACS+ server, even though SSH authentication succeeds via the local database.

Exam trap

Cisco often tests the distinction between authentication, authorization, and accounting (AAA) components, and the trap here is that candidates assume a working authentication implies accounting is also functional, overlooking that accounting requires a correctly defined and referenced server group.

How to eliminate wrong answers

Option A is wrong because the AAA authorization method is not the issue; authorization controls what commands or services a user can execute, not whether accounting records are sent. Option B is wrong because the TACACS+ server key is configured correctly with the `key cisco123` command under the TACACS+ server definition, so key mismatch is not the cause. Option C is wrong because the AAA authentication method uses the local database for login, which allows SSH access to succeed, but accounting is independent of authentication; the problem is that the accounting method references an undefined server group, not that authentication uses local.

122
MCQhard

A network baseline shows that a server typically sends 1-2 MB of data per hour to external IPs. Suddenly, the server sends 50 MB of data to an IP in a foreign country within 10 minutes. The traffic is encrypted. Which monitoring tool would best confirm data exfiltration?

A.NetFlow/IPFIX analysis comparing current traffic to baseline
B.Snort IDS with a rule to detect large file transfers
C.Wireshark packet capture with a display filter for the destination IP
D.Windows Event Logs for file access
AnswerA

NetFlow/IPFIX records flow metadata — source, destination, byte counts and timestamps — letting the analyst compare the 50 MB foreign transfer against the 1-2 MB hourly baseline. Encryption hides payload contents, but flow volume and destination still confirm exfiltration.

Why this answer

NetFlow/IPFIX provides flow records with byte counts, enabling detection of unusual data volumes, even with encrypted payloads.

123
Multi-Selectmedium

A security analyst is examining system logs for signs of privilege escalation. Which THREE events are most relevant to detect such activity?

Select 3 answers
A.Execution of commands with sudo
B.Multiple failed login attempts
C.Modification of user group memberships
D.User account creation with administrator privileges
E.Successful SSH login from a remote IP
AnswersA, C, D

Sudo execution records commands run with elevated privileges, making it a direct indicator of privilege escalation attempts. Monitoring these events reveals when a user gains or attempts root-level access, satisfying the requirement to detect escalation activity in system logs.

Why this answer

Option A is correct because execution of commands with sudo directly indicates a user is attempting to run processes with elevated (root) privileges, which is a primary vector for privilege escalation and should be audited via /var/log/auth.log or journalctl. Option C is correct because modification of user group memberships (e.g., adding an account to the sudo or wheel group) grants persistent elevated privileges, a classic privilege-escalation technique detectable through changes to /etc/group or usermod/gpasswd events. Option D is correct because creating a user account with administrator privileges (e.g., UID 0 or membership in an admin group) establishes a new high-privilege identity, which is a strong indicator of malicious persistence or escalation.

Option B is not the best fit because multiple failed login attempts primarily indicate brute-force or password-guessing attempts against authentication, not privilege escalation after access is obtained. Option E is also not the best fit because a successful SSH login from a remote IP only shows initial remote access, without evidence that privileges were elevated on the system.

Exam trap

The trap is that 'failed login attempts' feels security-relevant and candidates select it, but the question specifically asks about privilege escalation — authentication failures are a different attack phase and do not demonstrate elevated access.

124
Multi-Selectmedium

During memory analysis using Volatility, an analyst wants to identify processes with suspicious network connections and potentially injected code. Which THREE plugins should the analyst use? (Select THREE)

Select 3 answers
A.hashdump
B.pstree
C.hivelist
D.malfind
E.netscan
AnswersB, D, E

pstree renders the parent-child process hierarchy, exposing anomalous parentage such as a word processor spawning cmd.exe, which hints at injected or masquerading code. Combined with network and injection plugins, it satisfies the requirement to identify suspicious processes during memory analysis.

Why this answer

Option B, pstree, is correct because it displays the process list as a parent-child tree, which helps the analyst spot anomalous process relationships and suspicious processes that may be tied to injected code or malicious network activity. Option D, malfind, is correct because it scans process memory for signs of code injection such as MZ/PE headers in non-image memory regions with PAGE_EXECUTE_READWRITE permissions, directly addressing the injected-code requirement. Option E, netscan, is correct because it enumerates network artifacts (TCP connections, listening sockets, and UDP endpoints) from memory, allowing identification of processes with suspicious network connections.

Option A, hashdump, is not appropriate here because it extracts password hashes from the SAM database rather than analyzing processes or network connections. Option C, hivelist, is not appropriate because it only lists registry hives loaded in memory and does not reveal process, injection, or network details.

Exam trap

The trap here is confusing memory analysis plugins that serve different purposes: hashdump and hivelist are for credential and registry analysis, not for process or network inspection, so candidates might select them if they only associate Volatility with general forensic artifacts.

125
MCQhard

An analyst is reviewing a PCAP and observes a TCP stream where the client sends a packet with the PSH and ACK flags set, containing an HTTP GET request. The server responds with a packet with the FIN and ACK flags set, but the client continues to send data. Later, the client sends a packet with the RST flag set. Which statement best describes what is happening?

A.The server is initiating a graceful connection termination, but the client is ignoring it and continuing to send data, eventually forcing a reset.
B.The client is using TCP fast open, which allows data transmission after the server sends FIN.
C.The server is experiencing a denial-of-service condition because the client is flooding it with data after the FIN.
D.The client is performing a TCP reset attack to terminate the connection prematurely.
AnswerA

The server sends FIN+ACK to start a graceful close, meaning it has no more data to send. The client, however, continues to transmit data, which is a violation of TCP half-close semantics. Eventually, the client sends an RST, abruptly terminating the connection. This could indicate a malfunctioning client or an attempt to disrupt the session.

Why this answer

The server's FIN+ACK indicates it wants to close its half of the connection. The client should respond with a FIN and stop sending data. Instead, the client continues to send data, which is a TCP protocol violation.

The eventual RST from the client abruptly terminates the connection. This behavior could be due to a buggy application, a misconfigured client, or a deliberate attempt to cause a reset.

Exam trap

The trap here is interpreting the RST as a separate attack, when it is actually the client's response to the server's FIN after ignoring it and continuing to send data.

126
Multi-Selectmedium

A security analyst is classifying security controls for a new data center. Which TWO of the following are examples of physical controls? (Choose two.)

Select 2 answers
A.Security awareness training for staff
B.Full-disk encryption on employee laptops
C.Bollards installed at the building entrance
D.Security guards stationed at the lobby
E.Access control lists on the core router
AnswersC, D

Bollards are physical barriers that prevent vehicles from ramming into a building or accessing restricted areas. They are tangible structures designed to deter or block physical threats, which makes them a classic physical control. In a data center, bollards help protect the facility from vehicle-borne attacks and accidental damage. This option is correct because it directly addresses physical access and protection of the premises.

Why this answer

Physical controls are measures that protect tangible assets, facilities, and people. Bollards and security guards both operate in the physical world: bollards block vehicle access, and guards control and monitor entry. Access control lists, full-disk encryption, and awareness training are technical or administrative controls because they address logical access, data protection, or human behavior rather than physical barriers or presence.

Only the two physical measures fit the requested category.

Exam trap

The trap here is treating any security measure as a physical control, when the category depends on whether it protects tangible space and assets rather than data or behavior.

127
MCQhard

A security engineer is designing a network to prevent an attacker who gains access to a web server from easily pivoting to the internal database server. Which architecture best achieves this goal?

A.Place both servers on the internal network with host-based firewalls
B.Place the web server in a DMZ and the database server on the internal network, with a firewall blocking outbound traffic from DMZ to internal
C.Use a VPN between the web server and database server
D.Place both servers on the same VLAN with a firewall between them
AnswerB

Segmenting the web server into a DMZ with the database on the internal network, plus a firewall denying DMZ-to-internal outbound traffic, prevents a compromised web server from initiating connections inward. This blocks lateral pivoting, satisfying the stem's containment goal.

Why this answer

Placing the web server in a DMZ and the database server on the internal network, with a firewall blocking outbound traffic from the DMZ to internal, prevents an attacker who compromises the web server from initiating connections to the internal database server. This implements a default-deny rule for DMZ-to-internal traffic, forcing all database access to be initiated from the internal network only, which breaks the pivot chain. The DMZ acts as a buffer zone, isolating publicly accessible services from sensitive internal resources.

Exam trap

Cisco often tests the misconception that host-based firewalls or VLANs alone provide sufficient segmentation, when in fact network-level DMZ isolation with explicit direction-based firewall rules is required to prevent lateral movement after a perimeter breach.

How to eliminate wrong answers

Option A is wrong because placing both servers on the internal network with host-based firewalls still allows the compromised web server to directly reach the database server if the host firewall is misconfigured or bypassed, and it lacks network-level segmentation to prevent lateral movement. Option C is wrong because a VPN between the web server and database server encrypts traffic but does not restrict the direction of connection initiation; an attacker on the web server could still use the VPN tunnel to pivot to the database server. Option D is wrong because placing both servers on the same VLAN with a firewall between them still permits Layer 2 adjacency and potential ARP spoofing or VLAN hopping attacks, and the firewall would need to inspect all traffic, which is less effective than true network segmentation with a DMZ.

128
MCQmedium

A security analyst is reviewing firewall logs and notices a high number of denied outbound connections from an internal workstation to various external IP addresses on port 445 (SMB). What is the most likely explanation for this activity?

A.The user is browsing the web and the firewall is blocking HTTP
B.The workstation is performing a DNS lookup
C.The workstation is infected with malware attempting to spread via SMB
D.The workstation is performing a legitimate file transfer using FTP
AnswerC

SMB on port 445 is used by ransomware and worms such as WannaCry to propagate laterally. Repeated outbound attempts to many external addresses indicate the workstation scanning for reachable SMB shares, consistent with infection rather than legitimate file sharing.

Why this answer

Port 445 is used by SMB (Server Message Block) for file sharing and network communication. A high volume of denied outbound connections from a single workstation to many external IPs on this port is a classic indicator of malware attempting to propagate via SMB vulnerabilities, such as EternalBlue (MS17-010). Legitimate SMB traffic is typically confined to internal networks, not external scanning.

Exam trap

Cisco often tests the association of specific ports with their services (e.g., SMB = 445) and expects candidates to recognize that anomalous outbound scanning on a file-sharing port indicates malware, not a benign application.

How to eliminate wrong answers

Option A is wrong because HTTP traffic uses ports 80 and 443, not port 445, and the firewall would block HTTP on those ports, not SMB. Option B is wrong because DNS lookups use UDP or TCP port 53, not port 445, and would not generate denied outbound connections to multiple external IPs. Option D is wrong because FTP uses ports 20 and 21 for control and data transfer, not port 445, and legitimate file transfers would not exhibit a high volume of denied connections to random external IPs.

129
Multi-Selecteasy

Which two are best practices for deploying network-based intrusion detection systems? (Choose two.)

Select 2 answers
A.Place sensors behind firewalls to reduce false positives.
B.Enable all signatures to maximize detection.
C.Use tap or SPAN ports to ensure traffic visibility.
D.Use inline mode for all sensors to enable blocking.
E.Deploy sensors at network choke points.
AnswersC, E

Passive monitoring avoids impacting network performance.

Why this answer

Network-based intrusion detection systems (NIDS) must have full visibility into network traffic to detect malicious activity. Using a network tap or a SPAN (Switched Port Analyzer) port on a switch provides a copy of all traffic traversing a segment without introducing latency or single points of failure, ensuring the sensor can inspect packets without interfering with production traffic.

Exam trap

Cisco often tests the distinction between NIDS and IPS, and the trap here is that candidates confuse 'detection' with 'prevention,' leading them to select inline mode (Option D) even though the question specifically asks about intrusion detection systems, not prevention systems.

130
MCQmedium

You are a cybersecurity analyst in a SOC. The company uses a combination of Snort NIDS and Windows Event Log monitoring. At 3:00 PM, you receive a critical alert: 'ET TROJAN Observed Malicious SSL Certificate (Fake Google)'. The alert shows that a workstation (IP 10.0.1.45) initiated an SSL connection to IP 192.0.2.10 on port 443. The certificate presented by the server is self-signed and claims to be 'google.com'. The destination IP is not in any known Google IP range. You check the firewall logs and see that the outbound connection was allowed. The workstation's host logs show that the user is a marketing employee who frequently accesses webmail. The user reports no unusual behavior. You also check the company's web proxy logs and see that the user accessed 'http://www.google.com' earlier today, but the SSL connection is to a different IP. What should be your next step?

A.Ignore the alert because the user is unaware of any issue
B.Isolate the workstation from the network and perform a forensic analysis
C.Wait and monitor the workstation for further alerts before taking action
D.Block the destination IP 192.0.2.10 on the firewall
AnswerB

The self-signed certificate claiming google.com from a non-Google IP indicates likely command-and-control or credential theft, so isolating the host contains the threat before lateral movement. Forensic analysis then determines scope and persistence while preserving evidence.

Why this answer

The alert indicates a potential man-in-the-middle (MITM) attack or malware using a self-signed SSL certificate impersonating google.com. Isolating the workstation is critical to prevent lateral movement or data exfiltration while preserving evidence for forensic analysis. The combination of Snort NIDS detecting the malicious certificate and the connection to an unknown IP (192.0.2.10) strongly suggests compromise, regardless of user reports.

Exam trap

Cisco often tests the principle that user reports of 'no unusual behavior' are unreliable in incident response, and that immediate containment (isolation) takes precedence over monitoring or partial blocking.

How to eliminate wrong answers

Option A is wrong because ignoring the alert based solely on user denial is a security risk; users are often unaware of silent compromise (e.g., malware or MITM). Option C is wrong because waiting for further alerts could allow the attacker to exfiltrate data or pivot to other hosts; immediate containment is required. Option D is wrong because blocking the destination IP alone does not address the potential compromise of the workstation; the attacker could use other IPs or the malware may already be active locally.

131
MCQmedium

An analyst is examining a suspicious file that appears to be a PDF but when checking the magic bytes at offset 0, sees '50 4B 03 04'. What does this indicate?

A.The file is a genuine PDF file
B.The file is a plain text file
C.The file is a ZIP archive
D.The file is an executable
AnswerC

The magic bytes 50 4B 03 04 are the ZIP local file header signature ('PK\x03\x04'). Despite the .pdf extension, the file's actual container format is ZIP, which is typical of Office documents and JAR archives and indicates the extension has been spoofed.

Why this answer

The magic bytes '50 4B 03 04' at offset 0 are the ZIP file signature (PK\x03\x04). A genuine PDF must begin with '%PDF' (hex 25 50 44 46). Since the file claims to be a PDF but its header identifies it as a ZIP archive, this is a classic file-extension spoofing or polyglot technique used by malware to evade detection.

Exam trap

200-201 often tests whether candidates trust file extensions over actual file signatures — the trap is assuming a .pdf extension means the file is a PDF, when magic bytes reveal the true type.

How to eliminate wrong answers

Option A is wrong because a real PDF starts with the ASCII bytes '%PDF' (25 50 44 46), not 50 4B 03 04. Option B is wrong because plain text files have no fixed magic number and would not begin with the ZIP signature. Option D is wrong because Windows executables begin with 'MZ' (4D 5A), and ELF binaries begin with 7F 45 4C 46 — neither matches 50 4B 03 04.

132
MCQeasy

A security analyst is examining a Cisco Umbrella Investigate report for a domain that has been flagged as malicious. The report shows a high 'security score' and lists multiple categories including 'Malware' and 'Command and Control'. Which action should the analyst take first?

A.Add the domain to a watchlist and continue monitoring for 24 hours
B.Submit the domain to Cisco Talos for reclassification
C.Block the domain at the DNS layer and investigate any internal hosts that queried it
D.Report the domain to the ISP and wait for their response
AnswerC

When a domain is categorized as malware and command-and-control with a high security score, the immediate priority is to prevent further communication and identify affected hosts. Blocking at DNS via Umbrella stops resolution, and querying logs for internal clients that resolved the domain helps scope the incident. This aligns with containment and investigation best practices.

Why this answer

A domain flagged as malware and command-and-control with a high security score should be blocked immediately to sever communication. The analyst must also identify internal hosts that resolved the domain to determine the scope of compromise. This two-step approach of containment and investigation is the correct first response.

Exam trap

The trap here is treating the report as a suggestion rather than actionable intelligence, leading to delayed containment.

133
MCQeasy

A junior SOC analyst receives an alert indicating that a workstation attempted to resolve a domain associated with a known malware family. The analyst wants to determine whether the workstation actually connected to the malicious domain or if the resolution attempt was blocked. Which data source would most directly answer this question?

A.The organization's password policy configuration
B.The workstation's local hosts file
C.The endpoint's installed application inventory
D.DNS server response logs showing query results and response codes
AnswerD

DNS server response logs record whether a query received a valid answer, an NXDOMAIN, or a blocked response from a protective DNS service. This directly shows if the domain was resolved or denied, answering whether the workstation could have connected. Correlating these responses with firewall or proxy logs then confirms whether an actual connection followed the resolution.

Why this answer

DNS server response logs capture the outcome of each query, including successful answers, NXDOMAIN responses, and blocks from protective DNS filtering. This directly determines whether the workstation received an address for the malicious domain. Following up with firewall or proxy logs confirms whether an outbound connection actually occurred, allowing the analyst to decide whether endpoint containment is required.

Exam trap

The trap here is assuming that an alert for a DNS resolution attempt proves a successful connection, when the response code in DNS logs determines whether the name was actually resolved or blocked.

134
MCQeasy

A security analyst reviews the firewall log. What is the most likely reason for the denied connection?

A.The destination port is blocked by default
B.The source IP address is an external threat
C.The destination IP is a known malicious host
D.The access control list does not permit the traffic
AnswerD

Firewall logs record denied connections when a rule or access control list evaluates the traffic and drops it. The most likely cause is that no ACL entry permits the flow, so the implicit deny terminates the session before it reaches the destination.

Why this answer

The firewall log shows a denied connection, and the most likely reason is that the access control list (ACL) does not permit the traffic. Firewalls enforce security policies by evaluating traffic against ACL rules; if no rule explicitly allows the packet (based on source/destination IP, port, and protocol), the implicit deny at the end of the ACL drops the connection. This is the default behavior for stateful firewalls and is the most common cause of denied connections in logs.

Exam trap

Cisco often tests the concept that the implicit deny at the end of an ACL is the most common reason for denied traffic, tempting candidates to overthink with threat-based answers like external IPs or malicious hosts.

How to eliminate wrong answers

Option A is wrong because destination ports are not 'blocked by default' in a generic sense; firewalls block traffic based on ACL rules, not a default port blocklist, and many ports (e.g., 80, 443) are often permitted unless explicitly denied. Option B is wrong because the source IP being an external threat is a specific threat intelligence match, not the most likely reason for a denied connection; firewalls deny traffic primarily due to ACL mismatches, not because of external threat lists unless a rule explicitly references them. Option C is wrong because the destination IP being a known malicious host would require the firewall to have a threat intelligence feed or a specific block rule; without such a rule, the firewall would not deny traffic based solely on reputation, and the log entry would typically indicate a threat block, not a generic ACL deny.

135
Multi-Selectmedium

Which TWO of the following are best practices when configuring a SIEM for security monitoring?

Select 2 answers
A.Tune rules to reduce false positives.
B.Disable logging for low-security systems.
C.Prioritize alerts based on risk.
D.Use the same log source for all event types.
E.Enable all default correlation rules.
AnswersA, C

Tuning improves alert accuracy and reduces noise.

Why this answer

Tuning SIEM rules to reduce false positives is a best practice because it improves the signal-to-noise ratio, ensuring that security analysts focus on genuine threats rather than being overwhelmed by irrelevant alerts. By adjusting thresholds, whitelisting known benign activity, or refining correlation logic, the SIEM becomes more efficient and reduces alert fatigue, which is critical for effective security monitoring.

Exam trap

Cisco often tests the misconception that more logging or more rules always equals better security, when in fact untuned defaults and excessive logging degrade monitoring effectiveness and increase operational burden.

136
MCQhard

You are a security analyst for a medium-sized enterprise. The network includes a DMZ with a web server (10.0.1.10) and a database server (10.0.2.10) in the internal network. Users access the web server via HTTPS from the internet. The web server queries the database server on TCP 3306. Recently, users reported that the web application sometimes returns database errors. You review firewall logs and see the following: - Allowed inbound HTTPS to 10.0.1.10 from various external IPs. - Denied outbound from 10.0.1.10 to 10.0.2.10 on port 3306. - Allowed outbound from 10.0.1.10 to external IPs on port 443. You also notice that the web server's outbound traffic to the database server is being blocked. The firewall has a default deny rule. Which action should you take to restore normal operation while maintaining security?

A.Create a rule allowing inbound traffic on TCP 3306 to the database server from any source.
B.Move the database server to the DMZ to avoid firewall restrictions.
C.Create a rule allowing all outbound traffic from the DMZ to the internal network.
D.Create a rule allowing outbound traffic from the web server IP (10.0.1.10) to the database server IP (10.0.2.10) on TCP 3306.
AnswerD

The default deny rule is dropping the web server's database queries, causing the application errors. A rule permitting only 10.0.1.10 to reach 10.0.2.10 on TCP 3306 restores that specific flow while keeping all other outbound traffic blocked, preserving the DMZ segmentation.

Why this answer

The firewall logs show that outbound traffic from the web server (10.0.1.10) to the database server (10.0.2.10) on TCP 3306 is being denied, which causes the database errors. Since the web server initiates the connection to the database, a rule allowing this specific outbound traffic from the web server to the database server on port 3306 restores functionality while maintaining the default-deny posture. This is the most secure approach because it permits only the necessary traffic between the two specific hosts and port, without opening broader access.

Exam trap

Cisco often tests the misconception that you need an inbound rule for the database server when the traffic is actually initiated from the web server outbound, leading candidates to choose Option A or C.

How to eliminate wrong answers

Option A is wrong because allowing inbound traffic on TCP 3306 to the database server from any source would expose the database directly to the internet, bypassing the web server and creating a severe security risk. Option B is wrong because moving the database server to the DMZ would expose it to the same network segment as the web server and potentially the internet, increasing the attack surface and violating the principle of defense in depth. Option C is wrong because allowing all outbound traffic from the DMZ to the internal network would permit any DMZ host to reach any internal host on any port, which is overly permissive and could enable lateral movement by an attacker who compromises a DMZ device.

137
MCQhard

An analyst is examining a PCAP and sees a series of TCP packets where the client sends a SYN, receives a SYN-ACK, and then sends an ACK. Immediately after, the client sends a packet with the RST flag set, terminating the connection before any application data is exchanged. This pattern repeats across many destination ports on the same server. Which activity does this most likely represent?

A.TCP SYN scan
B.TCP ACK scan
C.TCP connect scan
D.TCP FIN scan
AnswerC

A TCP connect scan completes the full three-way handshake for each port and then immediately sends an RST to tear down the connection. This matches the observed SYN, SYN-ACK, ACK, and RST sequence. It is used when the scanner does not have raw packet privileges and relies on the OS connect() call.

Why this answer

The full three-way handshake followed by an immediate RST indicates a TCP connect scan. This scan type uses the operating system's connect() function to establish a complete TCP connection, then resets it. It is less stealthy than a SYN scan because it generates more logs on the target, but it works without raw socket privileges.

Exam trap

The trap here is assuming that any scan with an RST is a SYN scan, but a SYN scan never completes the handshake, whereas a connect scan does.

138
Multi-Selectmedium

A security engineer is implementing controls to meet compliance requirements. Which TWO of the following frameworks are specifically designed for protecting personal data?

Select 2 answers
A.HIPAA
B.NIST Cybersecurity Framework
C.GDPR
D.PCI DSS
E.ISO 27001
AnswersA, C

HIPAA safeguards protected health information, a subset of personal data, through its Privacy and Security Rules. It satisfies the compliance constraint by mandating administrative, physical and technical safeguards for individually identifiable health data, making it a framework specifically designed to protect personal information rather than general security controls.

Why this answer

HIPAA (A) is correct because it is a U.S. regulation specifically designed to protect the privacy and security of protected health information (PHI), which is a category of personal data. GDPR (C) is correct because it is an EU regulation explicitly focused on the protection of personal data and the privacy rights of individuals. NIST Cybersecurity Framework (B) is a voluntary framework for managing cybersecurity risk generally, not specifically for personal data protection.

PCI DSS (D) is designed to protect payment card data, which is a narrower and different scope than personal data. ISO 27001 (E) is a general information security management standard, not specifically focused on personal data protection.

Exam trap

Cisco often tests the distinction between frameworks that are specifically designed for personal data protection (like HIPAA and GDPR) versus general cybersecurity or information security frameworks (like NIST CSF, PCI DSS, and ISO 27001) that may include data protection but are not their primary purpose.

139
MCQhard

A SOC team is implementing a security monitoring solution for a cloud-based infrastructure. Which of the following is the most important consideration for effective monitoring?

A.Centralized logging from all cloud services and on-premises.
B.Encrypting all logs at rest.
C.Reducing log retention to save cost.
D.Using only native cloud monitoring tools.
AnswerA

Effective monitoring requires correlating events across every environment; centralised logging from all cloud services and on-premises gives the SOC one aggregated source, enabling detection of lateral movement and cross-boundary attacks that siloed, per-service logs would miss.

Why this answer

Centralized logging is the most important consideration because it provides a single, unified view of security events across all cloud services and on-premises infrastructure. Without aggregation, the SOC cannot correlate events, detect distributed attacks, or perform effective threat hunting. This aligns with the principle of 'visibility first' in security monitoring.

Exam trap

Cisco often tests the misconception that encryption or cost-saving measures are the top priority in monitoring, when in fact the foundational requirement is complete visibility through centralized logging.

How to eliminate wrong answers

Option B is wrong because encrypting logs at rest protects confidentiality but does not address the core requirement of visibility and correlation; encryption is a secondary control, not the primary monitoring consideration. Option C is wrong because reducing log retention to save cost directly undermines forensic analysis and compliance requirements; logs must be retained long enough to support incident investigation and meet regulatory mandates. Option D is wrong because using only native cloud monitoring tools creates silos and blind spots; a hybrid environment requires a centralized solution that aggregates logs from multiple sources, including third-party and on-premises tools.

140
MCQhard

An analyst is reviewing Cisco Firepower intrusion events and sees an alert for a TCP connection to an internal web server on port 80 with the rule message 'SERVER-WEBAPP Apache Struts2 remote code execution attempt'. The packet payload contains the string 'Content-Type: %{(#_='multipart/form-data')'. The server is running Apache Struts2 version 2.3.15. What should the analyst do next?

A.Check the web server logs and file system for signs of compromise, and verify whether the server was patched.
B.Ignore the alert because the server is behind a firewall and the attack is not likely to succeed.
C.Block the source IP address at the firewall and consider the incident resolved.
D.Update the Snort signature to detect the specific payload string and wait for the next alert.
AnswerA

The alert indicates an attempted exploit against a known vulnerable version of Apache Struts2. The analyst must determine if the exploit succeeded by examining web server logs, looking for unusual processes or files, and confirming the patch level. This response aligns with incident handling: validate the alert, assess impact, and contain if necessary.

Why this answer

The alert shows a remote code execution attempt against a known vulnerable Apache Struts2 version. The analyst must verify whether the exploit succeeded by examining server logs, processes, and files. This is critical because the traffic reached the internal server, and the payload matches a known exploit.

Proper incident response requires validation and scoping before containment.

Exam trap

The trap here is focusing on blocking the source IP or updating signatures instead of investigating whether the vulnerable server was actually compromised.

141
MCQmedium

An organization uses both network-based intrusion detection (NIDS) and host-based intrusion detection (HIDS). A HIDS alert reports that a critical server's registry key was modified. The NIDS shows no corresponding network activity. The change occurred during a scheduled maintenance window. What is the best course of action for the analyst?

A.Ignore the alert because it occurred during maintenance
B.Check the change management system to see if the modification was authorized
C.Escalate the alert as a potential security incident
D.Immediately revert the registry change
AnswerB

A registry modification with no matching network activity during a scheduled maintenance window suggests legitimate administrative change rather than intrusion. Verifying the change management system confirms whether the modification was authorised, preventing a false positive escalation before treating the HIDS alert as a genuine compromise.

Why this answer

The registry modification occurred during a scheduled maintenance window, which is a legitimate time for authorized changes. The analyst should first verify the change management system to confirm whether the modification was planned and approved, as this aligns with standard change control processes. The absence of NIDS alerts further suggests the change was likely local and non-malicious, but confirmation via change management is essential before taking any action.

Exam trap

Cisco often tests the concept that maintenance windows do not automatically validate all changes; candidates must remember to verify against change management records rather than assuming safety or immediately escalating.

How to eliminate wrong answers

Option A is wrong because ignoring the alert solely because it occurred during maintenance is a dangerous assumption; maintenance windows can be exploited by attackers, and the alert must be verified against authorized changes. Option C is wrong because escalating immediately as a potential security incident without first checking the change management system could waste resources and cause unnecessary alarm, especially since the NIDS showed no corresponding network activity. Option D is wrong because immediately reverting the registry change could disrupt legitimate maintenance work and potentially cause system instability; the change should only be reverted after confirming it was unauthorized.

142
MCQhard

A security analyst is examining a Linux server that is suspected of being compromised. The analyst runs `ls -l /proc/<PID>/exe` for a suspicious process and sees that the symbolic link points to `/tmp/.hidden/update` but the file no longer exists on disk. Which conclusion is most accurate?

A.The process is a kernel thread and does not have an executable on disk.
B.The process is running from a memory-mapped file and has no on-disk executable.
C.The process is a zombie and has already terminated.
D.The executable file was deleted while the process is still running.
AnswerD

On Linux, when an executable is deleted while a process is running, the /proc/<PID>/exe symlink still exists but points to the original path with a ' (deleted)' suffix, and the file is no longer visible on disk. This is a common malware technique to hide the binary while keeping it running. The analyst can recover the binary from /proc/<PID>/exe before the process exits.

Why this answer

On Linux, the /proc/<PID>/exe symlink points to the executable file. If that file is deleted while the process is running, the symlink remains but the target path is marked as deleted, and the file is no longer accessible via the filesystem. This is a known malware tactic to hinder forensic analysis.

The analyst should copy /proc/<PID>/exe to preserve the binary before the process terminates.

Exam trap

The trap here is interpreting a broken /proc/<PID>/exe symlink as evidence that the process is a zombie or kernel thread, when it actually indicates a deleted executable still running from memory.

143
MCQeasy

Which OSI layer is responsible for logical addressing and routing, and is commonly targeted by IP spoofing attacks?

A.Application layer
B.Network layer
C.Transport layer
D.Data Link layer
AnswerB

The Network layer (Layer 3) handles logical addressing and routing, satisfying the stem's requirement. IP spoofing attacks forge source addresses within IP packets at this layer, exploiting the lack of authentication in the IP protocol. This makes Layer 3 the precise target, unlike the Transport layer's ports or Data Link layer's MAC addresses.

Why this answer

The Network layer (Layer 3) handles logical addressing (IP addresses) and routing. IP spoofing involves falsifying the source IP address at this layer.

144
MCQmedium

An analyst sees an alert: 'ET POLICY Outgoing HTTP Request with Suspicious User-Agent (Mozilla/5.0 compatible; MSIE 6.0; Windows NT 5.1)'. The source is an internal host that typically uses Windows 10. What should the analyst suspect?

A.The traffic is from a web proxy
B.The host is running Windows XP
C.The host is running a browser update
D.The traffic is likely generated by malware
AnswerD

The legacy MSIE 6.0 user-agent on Windows NT 5.1 (XP) contradicts the host's expected Windows 10 baseline, so the string is spoofed rather than genuine. Malware commonly hard-codes outdated user-agents for HTTP command-and-control or payload retrieval, making this anomalous egress consistent with infection.

Why this answer

The User-Agent string 'Mozilla/5.0 compatible; MSIE 6.0; Windows NT 5.1' mimics Internet Explorer 6 on Windows XP (NT 5.1). Since the source host normally runs Windows 10, this outdated and mismatched User-Agent is a strong indicator of malware attempting to disguise its traffic as legacy browser activity to evade detection.

Exam trap

Cisco often tests the concept that an anomalous User-Agent string inconsistent with the host's known OS is a red flag for malware, not an indication of the actual OS version.

How to eliminate wrong answers

Option A is wrong because a web proxy typically preserves the original client's User-Agent or adds its own header, not fabricate a legacy Windows XP User-Agent. Option B is wrong because the host is known to run Windows 10, not Windows XP; the alert indicates the traffic is spoofing XP, not that the OS is actually XP. Option C is wrong because browser updates do not change the User-Agent to an older, incompatible version like MSIE 6.0 on Windows NT 5.1; updates would use a current User-Agent string.

145
MCQeasy

During an intrusion investigation, an analyst needs to determine whether a specific internal host communicated with a known malicious IP address. The analyst has full packet capture for the relevant window but only wants to see the TCP stream from that host to the suspect address. Which Wireshark display filter isolates that conversation?

A.ip.addr == 10.10.5.20 && ip.addr == 203.0.113.77
B.ip.src == 10.10.5.20 && ip.dst == 203.0.113.77
C.ip.addr == 10.10.5.20 || ip.addr == 203.0.113.77
D.tcp.port == 445 && ip.addr == 10.10.5.20
AnswerA

Using ip.addr twice with the AND operator matches packets where either field equals the first address and either field equals the second, effectively isolating bidirectional traffic between the two hosts. This is the standard way to view a conversation regardless of direction, which is exactly what the analyst needs when the role of client and server may vary during the exchange.

Why this answer

Repeating the address field with the AND operator restricts output to packets where the two addresses appear in either direction, which captures the full bidirectional conversation. A direction-specific filter hides responses, adding a port constraint may exclude the actual traffic, and using OR broadens the result to unrelated hosts. The bidirectional address pair is the reliable way to isolate one conversation.

Exam trap

The trap here is choosing a directional filter or an OR combination, when the goal is a two-host bidirectional conversation that requires both addresses joined with AND.

146
MCQmedium

A security analyst at a mid-sized company is reviewing a packet capture from the DMZ and notices a series of TCP SYN packets sent to multiple ports on a single internal web server, all originating from the same external IP address within a 3-second window. None of the SYN packets are followed by a completed three-way handshake. The analyst must classify this activity to determine the appropriate response. Which type of attack is most consistent with this traffic pattern?

A.UDP amplification attack
B.SYN flood denial-of-service attack
C.ARP poisoning attack
D.DNS tunneling attack
AnswerB

A SYN flood sends numerous TCP SYN packets to open ports without completing the three-way handshake, exhausting the server's connection backlog. The scenario describes exactly this: multiple SYNs to different ports from one source with no completed handshakes. This matches the classic half-open connection pattern used to deny service to legitimate users.

Why this answer

The traffic pattern of many TCP SYN packets to multiple ports from a single source without completed handshakes is the hallmark of a SYN flood. This attack consumes server resources by leaving connections half-open, preventing legitimate users from establishing sessions. Recognizing this pattern allows the analyst to apply mitigations such as SYN cookies or rate limiting.

Exam trap

The trap here is confusing a SYN flood with a port scan, because both send SYNs to multiple ports; however, a port scan typically completes or resets connections and aims to discover services, while a SYN flood deliberately leaves connections half-open to exhaust resources.

147
MCQmedium

An organization is reviewing its risk management process and identifies a risk with a high probability and high impact. Management decides to stop the activity causing the risk. Which risk treatment option is being applied?

A.Risk mitigation
B.Risk acceptance
C.Risk avoidance
D.Risk transfer
AnswerC

Risk avoidance eliminates the risk by discontinuing the activity entirely, which matches management stopping the process outright. Unlike mitigation, which reduces likelihood or impact, or transfer, which shifts financial consequence, avoidance removes the exposure at source.

Why this answer

Risk avoidance is the treatment option where the organization eliminates the risk entirely by discontinuing the activity that creates it. Since management decided to stop the activity causing the high-probability, high-impact risk, this is avoidance. It is the only option that removes the risk rather than reducing, accepting, or transferring it.

Exam trap

200-201 often tests the distinction between avoidance and mitigation — candidates pick mitigation because 'stopping the activity' sounds like a control, but avoidance specifically means eliminating the activity, not reducing its risk.

How to eliminate wrong answers

Option A is wrong because risk mitigation reduces likelihood or impact through controls but does not stop the activity — the risk still exists in reduced form. Option B is wrong because risk acceptance means acknowledging the risk and taking no action, which is the opposite of stopping the activity. Option D is wrong because risk transfer shifts the risk to a third party (e.g., insurance) while the activity continues, which does not match management's decision to stop the activity.

148
MCQmedium

Refer to the exhibit. A security analyst reviews the ACL configuration applied outbound on the external interface. Which statement is true about traffic from the 192.168.1.0/24 network to the internet?

A.All outbound traffic is denied except HTTP and HTTPS.
B.Only HTTP and HTTPS traffic is allowed.
C.HTTP and HTTPS traffic from the internal network is allowed, but SSH is denied.
D.SSH traffic is only denied if it originates from the 192.168.1.0/24 network.
AnswerC

HTTP and HTTPS are permitted because the ACL explicitly matches TCP ports 80 and 443, satisfying the requirement to allow web browsing outbound. SSH is denied since port 22 is absent from the permit statements and the implicit deny any catches it, blocking remote shell access from 192.168.1.0/24 to the internet.

Why this answer

The ACL contains permit statements for HTTP (port 80) and HTTPS (port 443) from the 192.168.1.0/24 network. It also includes an explicit deny statement for SSH (port 22) and a final permit ip any any statement (line 40). As a result, HTTP and HTTPS traffic are allowed, SSH traffic is denied, and all other traffic is permitted.

Therefore, option C is correct.

Exam trap

The ACL includes an explicit deny for SSH (port 22) on line 30, so SSH is explicitly denied, not just by the implicit deny. Candidates may incorrectly think the final 'permit ip any any' allows SSH, but since the explicit deny comes before, SSH is blocked.

How to eliminate wrong answers

Option A is wrong because it states 'all outbound traffic is denied except HTTP and HTTPS' — this is too broad; the ACL only applies to traffic from 192.168.1.0/24, not all outbound traffic, and it does not deny all other protocols (e.g., ICMP could be implicitly denied but not explicitly). Option B is wrong because it says 'only HTTP and HTTPS traffic is allowed' — while this is true for the 192.168.1.0/24 network, the statement omits the source network restriction and implies it applies to all traffic, which is inaccurate. Option D is wrong because it claims 'SSH traffic is only denied if it originates from the 192.168.1.0/24 network' — the ACL denies all traffic not matching the permit statements, so SSH from any source (including other internal networks) would be denied by the implicit deny, not just from 192.168.1.0/24.

149
MCQeasy

Which risk treatment option involves implementing security controls to reduce the likelihood or impact of a risk?

A.Avoid
B.Mitigate
C.Transfer
D.Accept
AnswerB

Mitigate reduces risk through controls.

Why this answer

Mitigate is the risk treatment option that involves implementing security controls to reduce the likelihood or impact of a risk. This can include technical controls (e.g., firewalls, encryption), administrative controls (e.g., policies, training), or physical controls (e.g., locks, guards). Mitigation aims to bring the risk down to an acceptable level rather than eliminating it entirely.

Exam trap

200-201 often tests the confusion between Mitigate and Transfer, since both involve taking action; candidates must remember that Mitigate reduces risk through controls, while Transfer shifts the financial or operational burden to another party.

How to eliminate wrong answers

Option A is wrong because Avoid involves eliminating the risk by not performing the activity that introduces it (e.g., discontinuing a service). Option C is wrong because Transfer shifts the risk to a third party, such as through insurance or outsourcing, without reducing it. Option D is wrong because Accept means acknowledging the risk and taking no action, often because the cost of mitigation exceeds the potential loss.

150
Multi-Selectmedium

Which TWO of the following are common network security protocols? (Choose two.)

Select 2 answers
A.IPsec
B.FTP
C.SSL
D.HTTP
E.SNMP
AnswersA, C

IPsec is a suite of protocols that authenticates and encrypts IP packets at the network layer, securing site-to-site VPNs and host-to-host traffic. It satisfies the question's requirement for a common network security protocol, operating at Layer 3 rather than the application layer.

Why this answer

IPsec (A) is a correct answer because it is a suite of protocols that secures IP communications by providing authentication, integrity, and confidentiality through mechanisms such as AH and ESP, commonly used in VPNs. SSL (C) is also correct because it is a cryptographic protocol designed to provide secure, encrypted communication over a network, forming the basis for TLS used in HTTPS. FTP (B) is not a security protocol; it transfers files in cleartext and lacks built-in encryption.

HTTP (D) is an application-layer protocol for web communication and is not inherently secure unless wrapped in TLS. SNMP (E) is a management protocol for monitoring network devices and is not primarily a security protocol, though it can use security features in its v3 form.

Exam trap

Cisco often tests the distinction between protocols that are inherently secure (like IPsec and SSL/TLS) versus those that are not (like FTP, HTTP, and SNMPv1/v2c), leading candidates to mistakenly select common but insecure protocols as security protocols.

Page 1

Page 2 of 13

Page 3