Courseiva

Cisco CyberOps Associate 200-201 (200-201) — Questions 151–225

968 questions total · 13pages · All types, answers revealed

Page 2

Page 3 of 13

Page 4
151
MCQeasy

A security team is implementing a defense-in-depth strategy and wants to ensure that even if an attacker compromises a web server, the attacker cannot easily move laterally to the internal database server. Which security principle is being applied when the team segments the network and restricts traffic between the web tier and the database tier?

A.Network segmentation
B.Zero trust
C.Least privilege
D.Defense in depth
AnswerA

Network segmentation divides a network into isolated zones and enforces traffic controls between them. By restricting traffic from the web tier to the database tier, the team limits lateral movement, so a compromised web server cannot freely reach the database. This directly matches the described control and its purpose.

Why this answer

Segmenting the network and restricting traffic between the web and database tiers limits an attacker's ability to move laterally after compromising a web server. This is the principle of network segmentation, which reduces the attack surface and contains breaches within a zone.

Exam trap

The trap here is choosing the umbrella term defense in depth when the scenario describes the specific control of network segmentation.

152
Multi-Selecthard

Which THREE of the following are key principles of zero trust security? (Choose three.)

Select 3 answers
A.Least privilege
B.Perimeter-based security
C.Never trust, always verify
D.Assume breach
E.Implicit trust
AnswersA, C, D

Least privilege limits each identity to the minimum access needed for its task, reducing blast radius if credentials are compromised. Zero trust assumes breach, so scoping permissions tightly is a core principle alongside verify explicitly.

Why this answer

Least privilege (A) is a core zero trust principle because users, devices, and workloads are granted only the minimum access rights needed for a specific task, limiting lateral movement if an identity is compromised. 'Never trust, always verify' (C) is the foundational zero trust tenet: every access request must be authenticated and authorized based on identity, device health, context, and policy regardless of network location. Assume breach (D) is also a key zero trust principle, requiring organizations to design as if adversaries are already inside the environment, using microsegmentation, encryption, and continuous monitoring to contain and detect threats. Perimeter-based security (B) is not a zero trust principle because zero trust explicitly rejects relying on a trusted internal network boundary, and implicit trust (E) is the opposite of zero trust, which eliminates automatic trust based on network location or prior authentication.

Exam trap

Cisco often tests whether candidates confuse zero trust with traditional perimeter defense, so the trap here is that 'perimeter-based security' sounds like a valid security principle but is actually the outdated model that zero trust aims to replace.

153
Multi-Selecthard

Which TWO locations in a Linux filesystem should be checked for evidence of malware persistence?

Select 2 answers
A./proc
B./var/spool/cron/crontabs
C./var/log/syslog
D./etc/init.d
E./etc/passwd
AnswersB, D

Per-user cron jobs are stored as individual files under /var/spool/cron/crontabs, so attackers can schedule recurring malicious execution without touching the shared /etc/crontab. This satisfies the persistence requirement because these entries survive reboots and re-launch the payload.

Why this answer

Option B (/var/spool/cron/crontabs) is correct because this directory stores per-user crontab files on Debian-based Linux systems, and attackers commonly plant scheduled jobs here to re-execute malware at recurring intervals for persistence. Option D (/etc/init.d) is correct because it holds SysV init scripts that start services at boot; malicious or modified scripts here can relaunch malware automatically on system startup. Option A (/proc) is a virtual, in-memory pseudo-filesystem exposing kernel and process state, not a persistent storage location where malware would be planted.

Option C (/var/log/syslog) is a log file used for recording events and auditing, not a persistence mechanism. Option E (/etc/passwd) is the user account database; while it can be abused for account creation, it is not a standard malware persistence location in the sense of scheduled or boot-time execution.

Exam trap

Cisco often tests the distinction between locations that store persistent configuration (like crontabs and init.d) versus runtime or log-only directories (like /proc and /var/log), so candidates mistakenly choose /proc or /var/log/syslog because they are commonly examined during live analysis, but they do not hold persistence artifacts.

154
MCQhard

A network engineer is designing a segmented network to protect a sensitive database. The database must be accessible only from a specific application server. Which security concept best describes this design?

A.Defense in depth
B.Separation of duties
C.Weakest link
D.Least privilege
AnswerD

Least privilege grants each subject only the access required for its function. Restricting database reachability to one specific application server, and denying all other hosts, enforces exactly that minimal access, satisfying the segmentation constraint in the scenario.

Why this answer

Least privilege, is correct because the design restricts access to the sensitive database to only the specific application server that requires it. This principle dictates that users, processes, or systems should be granted the minimum permissions necessary to perform their functions, thereby reducing the attack surface. By implementing network access control lists (ACLs) or firewall rules that permit traffic solely from the application server's IP address to the database port, the engineer enforces least privilege at the network layer.

Exam trap

Cisco often tests least privilege by framing it as a network segmentation or access control question, and the trap here is confusing it with defense in depth because both involve multiple layers, but least privilege specifically focuses on granting only the necessary permissions rather than layering controls.

How to eliminate wrong answers

Option A is wrong because defense in depth is a layered security strategy that employs multiple, overlapping controls (e.g., firewalls, IDS/IPS, encryption) to protect assets, not a single restriction between two specific hosts. Option B is wrong because separation of duties divides critical tasks among different individuals to prevent fraud or error (e.g., one admin creates accounts, another approves them), which is unrelated to network segmentation for database access. Option C is wrong because the weakest link concept refers to the idea that a system's security is only as strong as its most vulnerable component, not a design principle for restricting access between a specific application server and a database.

155
MCQmedium

A company's legal counsel is involved in an incident response due to a data breach. What is the primary role of legal counsel during the incident?

A.Make decisions about business impact
B.Communicate with the public
C.Conduct forensic analysis of affected systems
D.Advise on data breach notification requirements
AnswerD

Legal counsel interprets breach notification statutes and contractual obligations, advising when and to whom affected parties and regulators must be told. This satisfies the stem's data breach scenario, since notification deadlines and wording carry legal weight distinct from technical containment or forensic analysis.

Why this answer

Legal counsel ensures compliance with data breach notification laws.

156
MCQmedium

A security analyst is reviewing firewall logs and notices a rule that denies traffic from source IP 10.0.0.5 to destination port 3389. What service is being blocked?

A.RDP
B.SNMP
C.SMTP
D.SSH
AnswerA

Port 3389 is the registered TCP port for Remote Desktop Protocol, so a deny rule targeting it blocks RDP sessions. The stem's constraint — destination port 3389 — maps directly to RDP, Microsoft's protocol for remote graphical access to Windows hosts. No other listed service uses this port.

Why this answer

Port 3389 is the default port for Remote Desktop Protocol (RDP), which is used for remote graphical desktop access to Windows systems. The firewall rule denying traffic from 10.0.0.5 to this port blocks RDP connections, preventing that host from initiating remote desktop sessions.

Exam trap

Cisco often tests the association of default port numbers with common services, and the trap here is that candidates may confuse RDP (3389) with SSH (22) or SMTP (25) due to similar remote access or management functions.

How to eliminate wrong answers

Option B (SNMP) is wrong because SNMP uses UDP ports 161 (queries) and 162 (traps), not TCP 3389. Option C (SMTP) is wrong because SMTP uses TCP port 25 for email relay, with submissions on port 587 or 465, not 3389. Option D (SSH) is wrong because SSH uses TCP port 22 for secure remote shell access, not port 3389.

157
MCQeasy

A security analyst is investigating a Windows host suspected of malware infection. Which tool would allow the analyst to view parent-child relationships of running processes and inspect command line arguments?

A.Process Explorer
B.Task Manager
C.tasklist command
D.Resource Monitor
AnswerA

Process Explorer displays a live process tree, exposing parent-child relationships that reveal suspicious spawning, such as Office launching PowerShell. Its command-line column shows the exact arguments passed to each process, satisfying the investigation's requirement to inspect execution details on the suspect Windows host.

Why this answer

Process Explorer, part of Microsoft Sysinternals, provides a hierarchical view of running processes, showing parent-child relationships and allowing inspection of command-line arguments via the process properties. It also offers advanced features like VirusTotal integration and handle/ DLL views, making it the ideal tool for this investigation.

Exam trap

The trap is confusing basic process listing tools (Task Manager, tasklist) with advanced forensic tools; candidates must remember that only Process Explorer (and similar tools like Process Hacker) shows both parent-child relationships and command-line arguments natively.

How to eliminate wrong answers

Option B is wrong because Task Manager shows a flat list of processes and does not display parent-child relationships or full command-line arguments by default. Option C is wrong because the tasklist command lists processes but does not show parent PIDs or command-line arguments (unless used with /v, which still lacks parent info). Option D is wrong because Resource Monitor focuses on resource utilization (CPU, disk, network) and does not provide process lineage or command-line details.

158
MCQeasy

Which risk treatment option involves taking actions to reduce the likelihood or impact of a risk?

A.Mitigate
B.Accept
C.Transfer
D.Avoid
AnswerA

Mitigation reduces risk through controls.

Why this answer

Mitigation (also called risk reduction) is the risk treatment option where an organization takes deliberate actions to lower either the likelihood that a risk materializes or the severity of its impact if it does. Examples include applying patches, adding firewalls, or implementing MFA. It is the only option that actively modifies the risk itself rather than shifting, eliminating, or tolerating it.

Exam trap

The trap here is confusing 'transfer' with 'mitigate' — candidates often assume buying insurance reduces risk, but transfer only shifts financial liability, not the likelihood or impact of the event itself.

How to eliminate wrong answers

Option B is wrong because acceptance means acknowledging the risk and choosing to take no action (or only monitoring it), which does not reduce likelihood or impact. Option C is wrong because transfer shifts the financial or operational burden to a third party (e.g., cyber insurance or outsourcing) without reducing the underlying likelihood or impact. Option D is wrong because avoidance eliminates the risk entirely by discontinuing the activity that creates it, rather than reducing it.

159
MCQmedium

A company's remote access policy requires VPN connections to use two-factor authentication (2FA). An employee reports they cannot connect because their token is not syncing. What is the best course of action?

A.Disable 2FA for the employee
B.Replace the token and allow access anyway
C.Temporarily allow connections without 2FA
D.Provide a new token and synchronize it correctly
AnswerD

Replacing the faulty hardware token and completing a correct re-synchronisation restores the second authentication factor the VPN policy demands, letting the employee authenticate again. Troubleshooting the existing unsynced token wastes time; issuing a fresh, properly synchronised token directly satisfies the mandated 2FA requirement.

Why this answer

The core issue is a synchronization problem between the employee's token and the authentication server. Two-factor authentication (2FA) relies on time-based one-time passwords (TOTP) or event-based (HOTP) algorithms; if the token's clock drifts or the counter becomes out of sync, authentication fails. Providing a new token and correctly synchronizing it (e.g., via NTP time alignment or reseeding the HMAC-based OTP counter) restores secure access without bypassing the security policy.

Exam trap

Cisco often tests the misconception that any token failure should be resolved by temporarily disabling security controls (like 2FA) rather than fixing the underlying technical issue, tempting candidates to choose options that weaken security instead of following proper troubleshooting procedures.

How to eliminate wrong answers

Option A is wrong because disabling 2FA for the employee violates the remote access policy and eliminates the second authentication factor, leaving the VPN connection protected only by a password, which is a security downgrade. Option B is wrong because replacing the token without ensuring proper synchronization will likely result in the same sync failure; simply allowing access anyway bypasses authentication controls and undermines the 2FA requirement. Option C is wrong because temporarily allowing connections without 2FA creates a window of vulnerability where an attacker could exploit the lack of a second factor, and it violates the explicit policy requiring 2FA for all VPN connections.

160
MCQhard

An organization's incident response team has identified a malware infection on a critical server. They need to collect evidence for potential legal action. Which of the following is the most important step to ensure the admissibility of the evidence?

A.Contacting legal counsel before proceeding
B.Documenting the chain of custody for all evidence
C.Creating a forensic image of the affected hard drive
D.Isolating the server from the network
AnswerB

Chain-of-custody documentation records every transfer, handler and storage condition of the seized media, proving the evidence was not altered or tampered with. Without this unbroken audit trail, courts may rule the malware artefacts inadmissible, regardless of how technically sound the forensic acquisition itself was.

Why this answer

Maintaining a proper chain of custody documents who handled the evidence and ensures it has not been tampered with, which is critical for legal admissibility.

161
MCQhard

Which type of traffic is most prominent in this NetFlow data?

A.SSH
B.HTTP
C.DNS
D.HTTPS
AnswerB

HTTP dominates the NetFlow records, evidenced by the highest volume of flows to web service ports 80 and 443. This traffic profile identifies web browsing as the most prominent activity, satisfying the stem's requirement to name the leading protocol.

Why this answer

HTTP traffic is most prominent because the NetFlow data shows a high volume of packets and bytes on TCP port 80, which is the default port for HTTP. NetFlow records summarize traffic flows, and the large number of flows and bytes on port 80 indicates that HTTP is the dominant protocol in the captured data.

Exam trap

Cisco often tests the ability to distinguish between HTTP and HTTPS by port number, and the trap here is that candidates might assume HTTPS is more common due to modern encryption trends, but the NetFlow data explicitly shows higher traffic on port 80.

How to eliminate wrong answers

Option A is wrong because SSH uses TCP port 22, and the NetFlow data does not show significant traffic on that port. Option C is wrong because DNS primarily uses UDP port 53 (and sometimes TCP for zone transfers), and the data does not indicate a high volume of traffic on port 53. Option D is wrong because HTTPS uses TCP port 443, and while it may appear in the data, the question specifies that HTTP is the most prominent, meaning port 80 traffic exceeds port 443 traffic in this sample.

162
MCQmedium

A multinational retailer is aligning its security program with the NIST Cybersecurity Framework. The CISO wants to prioritize activities that improve the ability to detect and respond to cybersecurity events. Which Function in the NIST CSF Core is specifically described as encompassing activities to identify the occurrence of a cybersecurity event?

A.Protect
B.Identify
C.Detect
D.Respond
AnswerC

Detect is the NIST CSF Function that includes activities to identify the occurrence of a cybersecurity event, covering anomalies and events, continuous security monitoring, and detection processes. For the retailer's goal of improving event discovery, Detect is the correct focus because it addresses monitoring, analysis, and timely awareness. Investments in this Function, such as SIEM tuning and endpoint detection, directly strengthen the ability to notice malicious activity quickly.

Why this answer

The NIST CSF Core defines Detect as the Function containing activities to identify the occurrence of a cybersecurity event, including continuous monitoring and detection processes. Identify, Protect, and Respond address asset understanding, safeguards, and post-detection actions respectively. For a retailer seeking faster awareness of incidents, strengthening the Detect Function is the direct match.

Exam trap

The trap here is conflating Identify, which is about understanding assets and risk before events, with Detect, which is about recognizing that an event is happening.

163
MCQeasy

You are a security analyst at a mid-sized company. The company uses a SIEM to collect logs from firewalls, IDS, and servers. Recently, the SIEM generated an alert for a potential brute-force attack against the company's VPN server. The alert is based on a correlation rule that triggers when more than 30 failed authentication attempts from a single source IP occur within 10 minutes. You investigate and see that the source IP is 203.0.113.50, which is a known IP address of a partner company that uses the VPN for remote access. The failed attempts are all from the same username 'john.doe'. You also notice that the attempts are happening every 5 seconds, exactly 6 attempts per minute. The partner company has a policy that locks accounts after 3 failed attempts. Based on this scenario, what is the most likely cause of the alert?

A.The user 'john.doe' has forgotten his password and is repeatedly trying to log in.
B.A script or automated process at the partner site is misconfigured and repeatedly trying to authenticate with an incorrect password.
C.A man-in-the-middle attack is replaying captured authentication packets.
D.The partner's account 'john.doe' has been compromised and an attacker is attempting to gain access.
AnswerB

The exact timing and same username point to a script; the lockout policy would lock the account after 3 attempts, but the script may be retrying from the same source, causing the SIEM alert before the lockout.

Why this answer

The alert is triggered by a correlation rule that detects more than 30 failed authentication attempts from a single source IP within 10 minutes. The observed pattern—exactly 6 attempts per minute, every 5 seconds—is highly regular and mechanical, which is characteristic of an automated script or misconfigured process, not human behavior. Since the partner company locks accounts after 3 failed attempts, a human user would be locked out quickly and could not sustain 30+ attempts; only a script ignoring the lockout policy or using a cached incorrect password could produce this pattern.

Exam trap

Cisco often tests the distinction between human behavior and automated patterns by including precise timing data; the trap here is that candidates focus on the source IP being a 'known partner' and assume compromise or user error, ignoring the mechanical regularity that points to a script.

How to eliminate wrong answers

Option A is wrong because a human user forgetting their password would not produce exactly 6 attempts per minute at precise 5-second intervals; human behavior is irregular and would stop after the account is locked (3 failed attempts). Option C is wrong because a man-in-the-middle attack replaying captured authentication packets would not cause repeated failed attempts from a single source IP with the same username; replay attacks typically cause successful authentications or session hijacking, not a steady stream of failures. Option D is wrong because if the account were compromised, an attacker would likely use a password spraying or credential stuffing tool with multiple usernames or random timing, not a fixed 5-second interval with the same username; the regular pattern suggests a misconfigured script, not an active attacker.

164
MCQeasy

Which Cisco tool provides network-wide visibility and can detect anomalies using NetFlow and behavioral analysis?

A.Cisco Firepower Threat Defense (FTD)
B.Cisco Catalyst 9300 Switch
C.Cisco Identity Services Engine (ISE)
D.Cisco Secure Network Analytics (Stealthwatch)
AnswerD

Cisco Secure Network Analytics, formerly Stealthwatch, consumes NetFlow and other flow telemetry to build network-wide visibility, then applies behavioural analytics and machine learning to flag anomalies such as unusual traffic patterns or potential exfiltration that signature-based tools would miss.

Why this answer

Cisco Secure Network Analytics (formerly Stealthwatch) is the correct answer because it is a dedicated network visibility and security analytics platform that leverages NetFlow, IPFIX, and other telemetry sources to perform behavioral analysis and detect anomalies across the entire network. Unlike a firewall or switch, its primary function is to ingest flow data and apply machine learning models to identify threats such as lateral movement, data exfiltration, and command-and-control traffic.

Exam trap

The trap here is that candidates confuse a device that generates NetFlow data (like a Catalyst switch) with a tool that analyzes NetFlow data for security anomalies, leading them to select the switch instead of the dedicated analytics platform.

How to eliminate wrong answers

Option A is wrong because Cisco Firepower Threat Defense (FTD) is a next-generation firewall and IPS appliance that inspects packets inline for threats, but it does not provide network-wide visibility or behavioral analysis based on NetFlow; its visibility is limited to traffic passing through the firewall. Option B is wrong because the Cisco Catalyst 9300 Switch is a network switching platform that can generate NetFlow data but lacks the analytics engine to perform behavioral analysis or detect anomalies itself; it is a data source, not an analysis tool. Option C is wrong because Cisco Identity Services Engine (ISE) focuses on identity management, policy enforcement, and network access control (e.g., 802.1X, profiling), not on flow-based anomaly detection or behavioral analysis of network traffic.

165
MCQmedium

An analyst is examining a Linux server and notices an unusual systemd service that starts automatically. Which command would be used to disable this service?

A.systemctl disable servicename
B.systemctl stop servicename
C.systemctl remove servicename
D.systemctl mask servicename
AnswerA

systemctl disable removes the service's symlinks from the systemd unit configuration, preventing it from starting automatically at boot while leaving the unit file intact. This directly addresses the autostart constraint, unlike stop, which only halts the running instance.

Why this answer

The 'systemctl disable' command prevents a service from starting automatically at boot.

166
MCQmedium

An analyst reviews network logs and sees a large outbound FTP transfer of 500 MB from a workstation to an external IP at 2:00 AM. The workstation regularly sends 10 MB daily. What should the analyst suspect?

A.C2 beaconing
B.Normal backup operation
C.Software update
D.Data exfiltration
AnswerD

A 500 MB outbound FTP transfer at 2:00 AM, vastly exceeding the workstation's normal 10 MB daily volume, indicates bulk data leaving the network. This anomalous volume and timing point to data exfiltration rather than routine activity or a benign transfer.

Why this answer

Large outbound data transfers outside normal patterns, especially at odd hours, are typical of data exfiltration.

167
Multi-Selecthard

A security analyst is reviewing the organization's data classification policy. The policy defines four levels: Public, Internal, Confidential, and Restricted. Which TWO handling requirements are typically associated with data classified as 'Restricted'? (Choose two.)

Select 2 answers
A.Data can be declassified to Public after 30 days automatically.
B.Access is limited to a need-to-know basis with strict approval workflows.
C.Data must be stored only on removable media for physical security.
D.Data can be shared freely within the organization without additional controls.
E.Data must be encrypted both at rest and in transit.
AnswersB, E

Restricted data is usually subject to strict access controls, where only individuals with a specific need-to-know and proper approvals can access it. This minimizes the risk of insider threats and accidental exposure. Need-to-know access is a hallmark of handling requirements for the most sensitive data classifications.

Why this answer

Restricted data, as the highest classification, requires strong protections such as encryption at rest and in transit, and access limited to a need-to-know basis with strict approvals. These controls reduce the risk of unauthorized disclosure. Free sharing, mandatory removable media storage, and automatic declassification are not typical requirements and would weaken security.

Exam trap

The trap here is assuming that all sensitive data can be handled the same way, when in fact Restricted data demands the strictest controls, including encryption and need-to-know access.

168
MCQmedium

An analyst notices that an internal host is sending periodic ICMP echo requests to an external IP, and the echo replies contain payloads that are longer than the default Windows ping payload. The payload bytes appear to be encoded and change with each reply. Which activity is most likely occurring?

A.ICMP tunneling used for command-and-control or data transfer
B.Path MTU discovery performed by the host
C.Network latency measurement by a monitoring tool
D.Smurf attack reflection against the external host
AnswerA

ICMP tunneling hides data inside echo request and reply payloads, allowing covert communication through firewalls that permit ping. Non-default payload sizes and changing encoded bytes in replies are strong indicators that data is being exchanged, not just reachability tested. This matches the pattern of an ICMP-based covert channel.

Why this answer

Non-default ICMP payload sizes with changing encoded bytes in echo replies indicate that data is being tunneled inside ICMP, a common covert channel for command-and-control or exfiltration. Latency measurement, path MTU discovery, and Smurf attacks produce different packet characteristics and do not involve variable encoded payloads in replies.

Exam trap

The trap here is dismissing ICMP as harmless because ping is allowed, while overlooking that payload size and content, not the protocol itself, reveal the tunnel.

169
MCQeasy

During alert triage, an analyst determines that an alert fired but no actual attack or malicious activity occurred on the network. How should this alert be classified?

A.True negative
B.False negative
C.True positive
D.False positive
AnswerD

A false positive is an alert that fires without any genuine malicious activity, exactly matching the scenario where triage confirms no attack occurred. The classification axis here is whether the detected event reflects real threat activity: benign or expected behaviour triggering detection logic is a false positive, distinct from a true positive.

Why this answer

A false positive occurs when an alert fires but no actual malicious activity is present. The analyst determined that no attack occurred, so the alert is a false positive. This is a common occurrence in security operations and requires tuning of detection rules to reduce noise.

Exam trap

200-201 often tests the definitions of true/false positives/negatives. Candidates may confuse false positive with true negative, but the key is that an alert fired (so not negative) and no attack occurred (so false).

How to eliminate wrong answers

Option A is wrong because a true negative is when no alert fires and no malicious activity occurs, which is the correct benign state. Option B is wrong because a false negative is when malicious activity occurs but no alert fires, which is a dangerous miss. Option C is wrong because a true positive is when an alert fires and malicious activity is confirmed, which is not the case here.

170
MCQeasy

A SOC analyst receives an alert that a user account successfully authenticated to the VPN from two geographically distant locations within four minutes. Both sessions remain active. The identity team confirms the user is traveling and has only one device. Which monitoring conclusion is most appropriate?

A.This indicates a split-tunnel misconfiguration, since split tunneling causes a user to appear from multiple source networks simultaneously.
B.This is expected behavior because VPN concentrators load-balance sessions and users commonly appear from multiple regions.
C.This is a low-severity event because both sessions authenticated successfully, and successful authentication rules out misuse.
D.This is impossible-travel behavior consistent with credential theft, so the account should be treated as compromised pending verification.
AnswerD

Two simultaneous active VPN sessions from distant geographies within four minutes cannot be produced by one traveler with one device, since physical travel between those points is impossible in that interval. This pattern is a classic indicator of stolen credentials being used in parallel with the legitimate user. Treating the account as compromised and verifying with the user is the correct monitoring response.

Why this answer

Impossible travel detection compares authentication events across time and geography to find sessions that one person could not physically produce. Two concurrent VPN sessions from distant locations, with one confirmed device and one traveling user, indicate a second party using the same credentials. The appropriate action is to treat the account as compromised, verify with the user through an out-of-band channel, and review session activity for data access or lateral movement.

Exam trap

The trap here is treating a successful login as proof of legitimate access, when valid credentials presented by an unauthorized party authenticate just as successfully.

171
MCQeasy

Which of the following best describes a vulnerability?

A.A weakness in a system that could be exploited
B.The act of taking advantage of a weakness
C.The likelihood that a threat will exploit a weakness
D.A potential event that could cause harm
AnswerA

A vulnerability is precisely a weakness or flaw in a system that an attacker could exploit to violate confidentiality, integrity or availability; this definition distinguishes it from a threat, which is the potential cause of harm.

Why this answer

A vulnerability is a flaw or weakness in a system's design, implementation, or configuration that can be exploited by a threat actor. Option A correctly captures this as a weakness that could be exploited, which aligns with the standard definition in cybersecurity (e.g., NIST SP 800-30). It is not the act of exploitation itself, nor the likelihood of exploitation, nor the potential event causing harm.

Exam trap

The trap here is confusing vulnerability with exploit, risk, or threat, as these terms are often used interchangeably in casual conversation but have distinct meanings in cybersecurity.

How to eliminate wrong answers

Option B is wrong because it describes an exploit (the act of taking advantage of a weakness), not the vulnerability itself. Option C is wrong because it describes risk (the likelihood that a threat will exploit a weakness), which combines threat, vulnerability, and impact. Option D is wrong because it describes a threat (a potential event that could cause harm), not a vulnerability.

172
Multi-Selectmedium

Which TWO actions are recommended when tuning IDS signatures to reduce false positives?

Select 2 answers
A.Increase alert severity for all signatures
B.Replace IDS with a next-generation firewall
C.Modify signature thresholds to match typical traffic patterns
D.Disable signatures that generate frequent alerts
E.Whitelist known good behavior
AnswersC, E

Adjusting signature thresholds to reflect normal traffic baselines reduces alerts triggered by legitimate activity. This satisfies the false-positive constraint because thresholds set above routine peaks stop benign traffic from matching signatures while genuine anomalies still fire.

Why this answer

Option C is correct because tuning a signature's threshold (for example, raising a detection count or time window so it only fires after N matches within T seconds) aligns the rule with the normal baseline of your environment, so benign traffic bursts no longer trigger alerts. Option E is correct because whitelisting known good behavior—such as trusted source IPs, internal vulnerability scanners, or approved application flows—suppresses alerts for activity you have verified as legitimate, directly cutting false positives without losing coverage. Options A, B, and D are not recommended: raising severity for all signatures only increases noise and does not reduce false positives; replacing the IDS with a next-generation firewall is an architectural change, not a signature-tuning action; and disabling frequently alerting signatures removes detection capability and can create blind spots rather than properly tuning the rule.

Exam trap

200-201 often tests the misconception that disabling noisy signatures is a valid tuning method, but the recommended approach is to tune thresholds and whitelist, not disable.

173
MCQeasy

A security analyst is reviewing a Windows system for signs of malware persistence. The analyst notices a suspicious executable named 'updater.exe' in the Startup folder. Which Windows feature is being abused by the malware in this scenario?

A.Registry Run Keys
B.Windows Services
C.Task Scheduler
D.Startup Folder
AnswerD

The Startup folder is a directory that contains shortcuts or executables that run automatically when a user logs in. Malware often places a copy of itself or a shortcut in this folder to achieve persistence. The scenario describes an executable named 'updater.exe' in the Startup folder, which is a classic persistence technique. Thus, the Startup folder is the correct answer.

Why this answer

The Startup folder is a well-known location that Windows uses to automatically launch programs when a user logs in. Malware frequently places a copy of itself or a shortcut in this folder to ensure it runs every time the user logs in. The presence of 'updater.exe' in the Startup folder indicates that this persistence mechanism is being abused.

Other methods like Services, Task Scheduler, or Registry Run keys are also used by malware but are not described in this scenario.

Exam trap

The trap here is confusing the Startup folder with other persistence mechanisms like Registry Run keys, which are often used but are not the same as placing a file in the Startup folder.

174
Matchingmedium

Match each network protocol to its well-known port number.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

22

443

53

25

3389

Why these pairings

Standard well-known port assignments: HTTP=80, HTTPS=443, SSH=22, DNS=53. Common confusions include swapping HTTP/HTTPS ports or confusing SSH with Telnet.

175
MCQmedium

Which component of a SIEM is responsible for converting log data from various sources into a standard format?

A.Aggregation
B.Alerting
C.Correlation
D.Normalization
AnswerD

Normalization standardizes log data.

Why this answer

Normalization is the SIEM component that parses incoming log data from diverse sources (e.g., syslog, Windows Event Log, NetFlow) and maps the fields into a common, standardized schema. This process ensures that fields like source IP, destination IP, and timestamp are consistently named and formatted, enabling effective correlation and analysis across heterogeneous devices.

Exam trap

The trap here is that candidates confuse normalization with aggregation, thinking that simply collecting logs from multiple sources is enough to make them comparable, when in fact normalization is the crucial step that standardizes the data format.

How to eliminate wrong answers

Option A is wrong because aggregation refers to the collection and consolidation of log data from multiple sources into a central repository, not the conversion of that data into a standard format. Option B is wrong because alerting is the function that generates notifications based on predefined rules or thresholds, not the transformation of log formats. Option C is wrong because correlation involves analyzing relationships between events to identify patterns or incidents, which depends on already-normalized data.

176
MCQmedium

During a security incident, an analyst captures network traffic and observes multiple connections from an internal host to a remote IP on port 4444, with irregular packet timing and small payloads. Which type of activity is most likely indicated?

A.C2 beaconing
B.DNS tunneling
C.File transfer
D.VoIP communication
AnswerA

Port 4444 with regular small payloads and jittered timing matches beaconing, where infected hosts poll a command-and-control server for instructions. The irregular intervals evade simple threshold detection, and the low data volume distinguishes it from bulk exfiltration or normal interactive traffic.

Why this answer

The observed traffic—multiple connections from an internal host to a remote IP on TCP port 4444, with irregular timing and small payloads—is a classic signature of command-and-control (C2) beaconing. Attackers often use non-standard high ports like 4444 to evade detection, and the irregular intervals (jitter) are intentionally introduced to avoid pattern-based anomaly detection, while small payloads minimize data transfer and reduce the chance of triggering network thresholds.

Exam trap

Cisco often tests the distinction between C2 beaconing and DNS tunneling by presenting port 4444 (a common C2 port) and irregular timing, hoping candidates confuse it with DNS tunneling because both can use small payloads, but DNS tunneling specifically leverages DNS protocol fields and port 53, not a direct TCP connection on a high port.

How to eliminate wrong answers

Option B (DNS tunneling) is wrong because DNS tunneling typically uses UDP port 53 and encodes data within DNS queries/responses, not direct TCP connections to port 4444 with small payloads. Option C (File transfer) is wrong because file transfers usually involve larger, consistent payload sizes and predictable timing (e.g., SMB on port 445 or FTP on port 21), not the irregular, small-payload pattern described. Option D (VoIP communication) is wrong because VoIP uses protocols like SIP (UDP 5060) or RTP (dynamic UDP ports) with real-time, steady packet flows, not irregular TCP connections to a single high port like 4444.

177
MCQmedium

An organization experiences a ransomware attack where files are encrypted and a ransom is demanded. Which element of the CIA triad is most directly impacted?

A.Availability
B.Integrity
C.Non-repudiation
D.Confidentiality
AnswerA

Ransomware encryption renders files unreadable, directly denying legitimate access to data and systems. Availability is the CIA element concerned with ensuring authorised users can access resources when required, so encryption that blocks access satisfies the stem's constraint of disrupted data access. Confidentiality and integrity remain intact; the data is neither exposed nor altered.

Why this answer

A ransomware attack encrypts files and demands payment, directly preventing users from accessing their data and systems. This loss of access is a direct impact on Availability, which ensures that information and resources are accessible when needed. The CIA triad's Availability element is most immediately compromised because the organization cannot retrieve or use its encrypted files.

Exam trap

Cisco often tests the distinction between Integrity and Availability by presenting a scenario where data is altered (encryption) but the primary consequence is loss of access, leading candidates to mistakenly choose Integrity because they focus on the modification rather than the resulting denial of service.

How to eliminate wrong answers

Option B is wrong because Integrity is about ensuring data has not been tampered with or altered; while ransomware does modify files by encrypting them, the primary impact is the loss of access, not the verification of data correctness. Option C is wrong because Non-repudiation refers to the ability to prove that an action or transaction occurred, typically through digital signatures or logs, which is not directly relevant to file encryption and ransom demands. Option D is wrong because Confidentiality involves protecting data from unauthorized disclosure; ransomware does not primarily expose data to unauthorized parties (unless exfiltration occurs), but rather locks authorized users out.

178
MCQhard

An organization's security policy requires data classification labels to be applied to all documents. A manager sends a spreadsheet containing employee PII (personally identifiable information) to the entire company without labeling. Which policy has been violated?

A.Acceptable Use Policy
B.Data Classification Policy
C.Remote Access Policy
D.Incident Response Policy
AnswerB

The Data Classification Policy mandates that every document carry a sensitivity label before distribution. Sending unlabelled employee PII company-wide breaches that requirement directly, since the spreadsheet lacked the classification the policy demands. This satisfies the stem's constraint that labels must be applied to all documents.

Why this answer

The Data Classification Policy defines how data should be categorized and labeled based on sensitivity, such as PII. Sending an unlabeled spreadsheet containing PII violates this policy because it fails to apply the required classification label. The Acceptable Use Policy governs how resources can be used, not labeling.

Exam trap

200-201 often tests the distinction between different security policies, and candidates may confuse data classification with acceptable use. The trap is focusing on the act of sending PII rather than the missing label, which points to the Data Classification Policy.

How to eliminate wrong answers

Option A is wrong because the Acceptable Use Policy typically covers appropriate use of company assets and resources, not data labeling. Option C is wrong because the Remote Access Policy governs how remote connections are made, not data classification. Option D is wrong because the Incident Response Policy outlines steps to handle security incidents, not data labeling requirements.

179
Multi-Selecteasy

Which two are common techniques used in network intrusion analysis? (Choose two.)

Select 2 answers
A.Threat intelligence feeds
B.Sandboxing
C.Signature-based detection
D.Heuristic analysis
E.Anomaly-based detection
AnswersC, E

Signature-based detection compares observed traffic against a database of known attack patterns, such as Snort or Suricata rules, matching the stem's requirement for a common network intrusion analysis technique. It identifies previously catalogued exploits by byte or protocol pattern, complementing anomaly-based methods that flag deviations from normal behaviour.

Why this answer

Signature-based detection (C) is a core network intrusion analysis technique because it compares traffic or payloads against known attack patterns (Snort/Suricata rules, IDS signatures) to identify previously documented exploits and malware with high precision and low false positives. Anomaly-based detection (E) is also fundamental because it baselines normal network behavior and flags deviations such as unusual ports, protocol misuse, or traffic-volume spikes, allowing detection of novel or zero-day activity that signatures miss. Together they represent the two canonical IDS/IPS detection methodologies.

Threat intelligence feeds (A) are data sources that can enrich analysis but are not themselves an analysis technique, sandboxing (B) is dynamic malware execution used mainly for endpoint/file analysis rather than network intrusion analysis, and heuristic analysis (D) is a related but broader/rule-of-thumb method often grouped under anomaly or behavioral detection rather than one of the two standard network IDS techniques.

Exam trap

Cisco often tests the distinction between detection techniques (signature-based and anomaly-based) and supporting tools (threat intelligence feeds, sandboxing) or host-based methods (heuristic analysis), leading candidates to incorrectly select options that are not primary network intrusion analysis techniques.

180
MCQhard

An alert shows a high volume of outbound traffic from an internal host to an external IP using FTP. The data includes files with names matching internal document names. This activity is most likely:

A.C2 beaconing
B.Normal backup operation
C.Port scanning
D.Data exfiltration
AnswerD

FTP transfers of internal document names to an external IP indicate unauthorised data movement off the network. The high outbound volume, external destination and sensitive file naming together satisfy the exfiltration pattern rather than normal FTP use or scanning.

Why this answer

The scenario describes an internal host sending a high volume of outbound FTP traffic to an external IP, with file names matching internal document names. This pattern is characteristic of data exfiltration, where an attacker steals sensitive data by transferring it to an external command-and-control (C2) or staging server. FTP is commonly used because it is a standard protocol that may not be blocked, and the file names indicate the data is likely proprietary or confidential.

The volume and direction (outbound) further support exfiltration rather than normal backup or scanning.

Exam trap

The trap here is confusing high-volume outbound traffic with benign activities like backups or C2, when the key indicators are the external destination and the sensitive file names, which point to exfiltration.

How to eliminate wrong answers

Option A is wrong because C2 beaconing typically involves small, periodic connections (often HTTP/HTTPS or DNS) to maintain control, not high-volume FTP transfers of document files. Option B is wrong because normal backup operations usually go to internal servers or authorized cloud storage, not to arbitrary external IPs, and would not use FTP with internal document names in this suspicious context. Option C is wrong because port scanning involves probing multiple ports on a target, not transferring large files outbound.

181
MCQeasy

A security analyst is examining a suspicious file and calculates its SHA-256 hash. The analyst then queries Cisco Talos Intelligence for the hash. The result shows that the file is known malware with a detection name of 'Trojan.GenericKD.123456'. Which of the following does this result indicate?

A.The file is confirmed malicious and matches a known malware signature in the Talos database.
B.The file is benign but has a similar hash to known malware.
C.The file is suspicious but requires further dynamic analysis to confirm maliciousness.
D.The file has been quarantined by Cisco AMP for Endpoints automatically.
AnswerA

Cisco Talos Intelligence maintains a database of file hashes associated with malware. When a hash query returns a known malware detection name, it means the exact file has been previously identified as malicious. This is a strong indicator that the file is indeed malware, and the analyst should treat it as such, initiating incident response procedures.

Why this answer

Cisco Talos Intelligence provides reputation and threat data for files, IPs, and domains. When a SHA-256 hash is queried and returns a known malware detection, it means the exact file has been previously analyzed and confirmed malicious. This is a reliable indicator, and the analyst should proceed with containment and remediation.

Other options either misinterpret the result or assume actions that are not part of the query process.

Exam trap

The trap here is thinking that a hash match requires further validation or that it only indicates similarity, when in fact it is a definitive identification of the exact file.

182
MCQhard

An organization is required to preserve data that may be relevant to a lawsuit. Which legal process is invoked to prevent destruction of this data?

A.E-discovery
B.Legal hold
C.Chain of custody
D.Data retention policy
AnswerB

Legal hold suspends normal retention and deletion schedules, preserving data that may be relevant to anticipated or active litigation. It satisfies the stem's requirement to prevent destruction of lawsuit-relevant data, unlike spoliation, which describes the improper loss itself. Microsoft Entra ID and Microsoft Purview apply holds to mailboxes, sites and identities.

Why this answer

A legal hold is the process invoked to preserve data that may be relevant to litigation, preventing its destruction or modification. It overrides normal retention and deletion policies, ensuring electronically stored information (ESI) is retained until the hold is released. In Microsoft 365, this is implemented via Litigation Hold or eDiscovery holds on mailboxes and sites.

Exam trap

The trap is confusing e-discovery (the overall process) with legal hold (the specific preservation action) — candidates pick e-discovery because it sounds like the legal process, but the question asks what prevents destruction.

How to eliminate wrong answers

Option A is wrong because e-discovery is the broader process of identifying, collecting, and producing ESI for litigation; it may include a hold, but the hold itself is the preservation mechanism. Option C is wrong because chain of custody documents the handling and transfer of evidence to ensure integrity; it does not prevent data destruction. Option D is wrong because a data retention policy defines how long data is kept and when it is deleted; it does not specifically preserve data for litigation and may even cause deletion.

183
Multi-Selecteasy

Which THREE of the following are common indicators of compromise (IOCs) that a security monitoring system might trigger on?

Select 3 answers
A.Unusual outbound network connections to unfamiliar IP addresses.
B.Packets with destination IP addresses from a threat intelligence feed.
C.High CPU usage on a server.
D.Successful logon from a domain administrator account.
E.Changes to critical system files or registry keys.
AnswersA, B, E

Common C2 indicator.

Why this answer

Unusual outbound network connections to unfamiliar IP addresses are a common indicator of compromise (IOC) because they often signal command-and-control (C2) communication, data exfiltration, or malware beaconing. Security monitoring systems analyze netflow or firewall logs to detect connections to IP addresses not in the organization's baseline or known threat intelligence feeds. This behavior deviates from normal traffic patterns and is a key trigger for alerts in SIEM or IDS/IPS systems.

Exam trap

Cisco often tests the distinction between performance metrics (like CPU usage) and true security indicators, so candidates mistakenly select high CPU usage as an IOC when it is actually a symptom that requires further investigation, not a direct compromise indicator.

184
Multi-Selecthard

Which TWO of the following are valid reasons to create an exception to a security policy? (Choose two.)

Select 2 answers
A.The employee finds the policy inconvenient.
B.The policy is too new and employees are not yet trained.
C.The employee is a senior executive.
D.A business-critical application cannot function with the policy control.
E.Temporary exception to avoid disrupting operations during a migration.
AnswersD, E

A business-critical application that cannot function under a policy control justifies an exception because operational continuity outweighs the control's risk reduction. The exception is scoped to that application's specific technical incompatibility, not a blanket policy waiver, and should carry compensating controls, documented approval and a review date to limit exposure.

Why this answer

Option D is correct because a documented exception is justified when a business-critical application genuinely cannot operate under the policy control, since the exception balances security with the organization's operational needs. Option E is correct because a temporary exception during a migration is a legitimate, time-bound risk acceptance that prevents disruption of operations while the transition is completed. Option A is not valid because personal convenience is not a business justification for weakening security controls.

Option B is not valid because lack of training is a process and awareness failure, not a reason to grant a policy exception. Option C is not valid because seniority or rank does not justify bypassing a security policy; exceptions must be based on business or technical need.

Exam trap

Cisco often tests the misconception that seniority or personal inconvenience can justify policy exceptions, but the correct reasoning must always tie back to business continuity or technical necessity, not status or preference.

185
MCQhard

An organization wants to implement a security framework that includes functions such as Identify, Protect, Detect, Respond, and Recover. Which framework aligns with this structure?

A.NIST Cybersecurity Framework
B.HIPAA Security Rule
C.PCI DSS
D.ISO 27001
AnswerA

The NIST Cybersecurity Framework is structured around the five core functions: Identify, Protect, Detect, Respond, and Recover. No other framework in the stem's list uses this exact function set, so it directly matches the required structure.

Why this answer

The NIST Cybersecurity Framework (CSF) is explicitly organized around five core functions: Identify, Protect, Detect, Respond, and Recover. This structure provides a common language for managing cybersecurity risk and is widely adopted across industries. The framework's functions cover the full lifecycle of cybersecurity activities, from understanding assets and risks to recovering from incidents.

Exam trap

The trap here is confusing a security framework with a regulation or standard; candidates may pick HIPAA or PCI DSS because they are well-known in security, but only the NIST CSF explicitly defines the five functions.

How to eliminate wrong answers

Option B is wrong because the HIPAA Security Rule is a U.S. regulation focused on protecting electronic protected health information (ePHI) and does not define a framework with those five functions; it specifies administrative, physical, and technical safeguards. Option C is wrong because PCI DSS is a payment card industry standard that prescribes specific security controls for cardholder data environments, not a framework with Identify, Protect, Detect, Respond, and Recover functions. Option D is wrong because ISO 27001 is an international standard for information security management systems (ISMS) that requires a risk-based approach but does not use the five-function structure; it focuses on Plan-Do-Check-Act and Annex A controls.

186
Multi-Selecteasy

Which TWO of the following are common sources of security events used in security monitoring?

Select 2 answers
A.Employee attendance records
B.Firewall logs
C.Marketing campaign results
D.Company newsletter subscriptions
E.DNS query logs
AnswersB, E

Firewall logs capture allowed and denied connection attempts with source, destination and port details, satisfying the security-event source requirement. They reveal scanning, policy violations and lateral movement attempts, providing essential network telemetry for security monitoring and incident investigation.

Why this answer

Firewall logs (B) are a primary source of security events because they record allowed and denied traffic based on access control lists (ACLs), providing critical data on attempted intrusions, policy violations, and reconnaissance scans. DNS query logs (E) are equally vital as they capture domain resolution requests, enabling detection of malware command-and-control (C2) communication, DNS tunneling, and connections to known malicious domains. Both are standard inputs for SIEM systems and security monitoring platforms.

Exam trap

Cisco often tests the distinction between operational business data (HR, marketing) and actual security telemetry sources, expecting candidates to recognize that only logs from network infrastructure (firewalls, DNS servers, IDS/IPS) generate actionable security events.

187
MCQhard

During a penetration test, a security engineer uses publicly available information from LinkedIn and Google to gather details about employees and organizational structure. Which type of reconnaissance is being performed?

A.Active reconnaissance
B.Social engineering
C.Passive reconnaissance
D.Internal reconnaissance
AnswerC

Passive reconnaissance relies on publicly available sources without directly interacting with the target's systems, so no packets reach the organisation's infrastructure. LinkedIn and Google searches match this exactly, satisfying the stem's constraint of gathering employee and structural details covertly, leaving no trace in the target's logs.

Why this answer

The security engineer is gathering information from publicly available sources (LinkedIn, Google) without directly interacting with the target's systems. This is the definition of passive reconnaissance, which involves collecting data from open-source intelligence (OSINT) without sending any packets to the target network.

Exam trap

Cisco often tests the distinction between active and passive reconnaissance by describing an activity that uses public sources but might seem 'active' to a novice; the trap here is confusing passive information gathering with active scanning or social engineering.

How to eliminate wrong answers

Option A is wrong because active reconnaissance involves direct interaction with the target, such as sending probes, scans, or packets (e.g., using Nmap or ping sweeps), which is not described here. Option B is wrong because social engineering involves manipulating people to divulge confidential information, not simply collecting publicly available data from websites. Option D is wrong because internal reconnaissance is performed from within the target's network, often after gaining initial access, whereas this activity occurs externally using public sources.

188
MCQeasy

A healthcare organization is developing an incident response plan. The security manager wants to ensure that the plan includes a phase where the team practices and tests their response capabilities before an actual incident occurs. According to the NIST incident response lifecycle, which phase involves preparing and preventing incidents through activities like training and exercises?

A.Post-Incident Activity
B.Containment, Eradication, and Recovery
C.Detection and Analysis
D.Preparation
AnswerD

Preparation is the first phase of the NIST incident response lifecycle. It encompasses establishing an incident response capability, developing plans, training personnel, and conducting exercises. In this scenario, the security manager wants to ensure the team practices and tests capabilities, which is exactly what happens during Preparation. This phase sets the foundation for effective incident handling.

Why this answer

According to the NIST incident response lifecycle, Preparation is the phase dedicated to establishing and maintaining incident response capabilities, including training, exercises, and plan development. The other phases are reactive and occur during or after an incident. Therefore, the security manager should focus on Preparation to ensure the team is ready before an incident happens.

Exam trap

The trap here is assuming that Post-Incident Activity includes training, but that phase is about reviewing and learning from the incident, not practicing beforehand.

189
MCQhard

An analyst examining a PCAP sees a host send an HTTP GET request where the User-Agent string contains a long, random-looking hexadecimal value, the request path includes a similarly random string, and the server responds with a 404 status code but a response body of several kilobytes. This pattern repeats every 60 seconds. Which activity is most likely occurring?

A.Command-and-control beaconing over HTTP with data hidden in request and response fields
B.A content delivery network serving cached assets to a browser with a corrupted user agent
C.A misconfigured application retrying a failed API call with exponential backoff
D.An automated vulnerability scanner fuzzing the web application
AnswerA

A fixed 60-second interval, random-looking identifiers in the User-Agent and URI, and a large response body despite a 404 status are classic HTTP beaconing with covert channel encoding. Legitimate clients do not send random hex in these fields, and a true 404 would not carry kilobytes of meaningful content. The implant is polling for instructions and receiving tasking data disguised as an error page.

Why this answer

The fixed 60-second cadence, random hex identifiers in both the User-Agent and URI, and a substantial response body paired with a 404 status together indicate HTTP-based command-and-control. Implants poll at set intervals for tasking, encode session identifiers to evade signatures, and hide instructions in what appears to be an error response. Normal CDN traffic, vulnerability scanning, and backoff retries all produce different timing, field content, and response characteristics.

Exam trap

The trap here is dismissing the traffic because of the 404 status, when attackers deliberately return error codes while smuggling data in the response body.

190
MCQhard

A large e-commerce company experiences a data breach where customer credit card numbers are stolen. The investigation reveals that an attacker exploited a SQL injection vulnerability in the web application to extract the data from the database. The company's web development team claims they use parameterized queries and prepared statements. However, the forensic analysis shows that the injection occurred through a search functionality that concatenates user input directly into the SQL query. The application logs indicate that the search function was developed by a third-party vendor and integrated into the application six months ago. The company wants to prevent such incidents in the future. Which of the following is the most effective long-term solution?

A.Replace the third-party search module with a custom-developed one.
B.Establish a secure software development lifecycle (SSDLC) that includes security reviews for all third-party components.
C.Implement a web application firewall (WAF) with OWASP rules.
D.Conduct regular vulnerability scans and patch management.
AnswerB

An SSDLC embeds security reviews, threat modelling and testing into every phase, so third-party search components are assessed before integration. This prevents vulnerable concatenated queries from reaching production, addressing the root cause rather than the single injection point.

Why this answer

The root cause is a failure in the security review process for third-party components. Even though the company uses parameterized queries elsewhere, the third-party search module concatenates user input directly into SQL queries, bypassing that protection. Establishing an SSDLC with mandatory security reviews for all third-party components ensures that such vulnerabilities are caught before integration, addressing the process gap rather than just the symptom.

Exam trap

Cisco often tests the distinction between reactive controls (WAF, patching) and proactive process improvements (SSDLC), leading candidates to choose a technical fix like a WAF instead of addressing the root cause of insecure third-party code integration.

How to eliminate wrong answers

Option A is wrong because simply replacing the third-party module with a custom-developed one does not guarantee security; the custom code could also contain SQL injection flaws if not developed under secure coding practices. Option C is wrong because a WAF is a reactive, signature-based control that can be bypassed by sophisticated SQL injection payloads (e.g., using encoding or obfuscation) and does not fix the underlying insecure code. Option D is wrong because vulnerability scans and patch management are point-in-time checks that may miss logic flaws like SQL injection in custom or third-party code, and they do not enforce secure coding or review processes.

191
Multi-Selectmedium

A security analyst is reviewing the organization's defense-in-depth strategy. The analyst must recommend TWO controls that specifically reduce the risk of successful phishing attacks against employees. Which two controls should the analyst recommend? (Choose two.)

Select 2 answers
A.Implementing email filtering that blocks messages with malicious attachments and links.
B.Configuring network segmentation to isolate the finance department from the rest of the network.
C.Deploying a web application firewall (WAF) to inspect HTTP traffic to the company's public website.
D.Enabling full-disk encryption on all employee laptops.
E.Conducting regular security awareness training that teaches employees to recognize phishing attempts.
AnswersA, E

Email filtering inspects incoming messages and blocks those containing known malicious attachments, URLs, or sender reputations. This directly reduces the volume of phishing emails reaching user inboxes, lowering the chance of a successful attack. It is a preventive control that operates before the user interacts with the message, making it a core component of anti-phishing defense in depth.

Why this answer

Email filtering and security awareness training are both direct anti-phishing controls. Filtering blocks malicious messages before delivery, while training helps users recognize and avoid phishing attempts that bypass filters. Together they form a layered defense.

The other options address different threats such as web application attacks, data-at-rest protection, and lateral movement containment.

Exam trap

The trap here is selecting network segmentation because it sounds like defense in depth, but it mitigates impact rather than preventing phishing success.

192
MCQmedium

A security analyst is investigating a recent security incident and needs to determine the extent of the compromise. The analyst wants to understand which systems were affected and what data may have been accessed. Which phase of the incident response process is the analyst currently performing?

A.Detection and analysis
B.Post-incident activity
C.Preparation
D.Containment, eradication, and recovery
AnswerA

Detection and analysis is the phase where analysts validate whether an incident occurred, determine its scope, and identify affected systems and data. The analyst's goal of understanding which systems were compromised and what data was accessed aligns directly with this phase. This step precedes containment and eradication and is critical for making informed decisions about subsequent response actions.

Why this answer

The detection and analysis phase of incident response involves validating incidents, determining their scope, and identifying affected systems and data. The analyst's investigation into which systems were compromised and what data was accessed is a textbook example of this phase, which must be completed before containment and eradication can be effectively planned.

Exam trap

The trap here is thinking that any investigative activity belongs to containment, when scope determination is specifically part of detection and analysis.

193
MCQmedium

A security analyst is configuring a new SIEM platform. The organization has multiple log sources, including Windows Event Logs, Linux syslog, and firewall logs. The analyst wants to ensure that logs are not lost if the SIEM becomes unavailable. Which approach best addresses this requirement?

A.Configure the SIEM to pull logs from sources via Syslog over TCP.
B.Configure log sources to send logs to a centralized collector with local storage and forwarding capabilities.
C.Implement log replication between SIEM nodes.
D.Increase the storage capacity of the SIEM to hold more logs.
AnswerB

A centralised collector buffers events in local storage and forwards them once the SIEM recovers, preventing loss during outages. Direct source-to-SIEM shipping would drop logs while the platform is unavailable, so the collector satisfies the no-loss constraint.

Why this answer

Deploying a centralized collector with local storage and forwarding capabilities creates a buffer that ensures logs are not lost during SIEM unavailability. The collector receives logs from sources, stores them locally (e.g., on disk or in a queue), and forwards them to the SIEM when it becomes available again. This decouples log generation from SIEM ingestion, preventing data loss even during extended outages.

Exam trap

Cisco often tests the distinction between reliable transport (TCP) and guaranteed delivery with buffering; the trap here is assuming that Syslog over TCP alone prevents data loss, when in fact it only ensures in-transit reliability, not resilience against SIEM unavailability.

How to eliminate wrong answers

Option A is wrong because Syslog over TCP provides reliable delivery only if the SIEM is reachable; if the SIEM goes down, the TCP connection fails and logs are dropped (unless the source has its own buffering, which is not guaranteed). Option C is wrong because log replication between SIEM nodes addresses high availability and redundancy of the SIEM itself, but does not protect against data loss if all SIEM nodes become unavailable simultaneously. Option D is wrong because increasing SIEM storage capacity only helps retain more logs once they are ingested; it does nothing to prevent loss during an outage when logs cannot be received.

194
MCQhard

A Linux host has an unusual cron job that runs a script from /tmp every minute. The analyst checks /etc/crontab and /var/spool/cron/ but finds nothing. Where else could the cron job be defined?

A./etc/cron.d/
B./etc/cron.hourly/
C./etc/cron.allow
D.~/.bashrc
AnswerA

This directory contains per-package cron definitions.

Why this answer

The cron job is defined in /etc/cron.d/ because this directory allows system administrators to drop individual cron configuration files that are parsed by the cron daemon. Unlike /etc/crontab and /var/spool/cron/ (which contain user-specific crontabs), /etc/cron.d/ is a standard location for package-maintained or custom cron jobs that run with system privileges. The fact that the analyst found nothing in the other two locations strongly suggests the job is defined in /etc/cron.d/.

Exam trap

Cisco often tests the distinction between cron configuration directories and control files, trapping candidates who confuse /etc/cron.allow (an access control list) with a location where cron jobs are actually defined.

How to eliminate wrong answers

Option B is wrong because /etc/cron.hourly/ is a directory for scripts that run on an hourly schedule, not for defining arbitrary cron jobs with specific minute-level intervals; it uses run-parts and does not support custom cron syntax like 'every minute'. Option C is wrong because /etc/cron.allow is a control file that lists users allowed to use cron, not a location where cron jobs are defined. Option D is wrong because ~/.bashrc is a shell initialization script executed for interactive login shells, not a cron configuration file; cron jobs cannot be defined there.

195
Multi-Selecthard

A SOC analyst is investigating a suspected ARP poisoning attack on a local subnet. Which two indicators would most strongly support this conclusion? (Choose two.)

Select 2 answers
A.A high rate of unsolicited ARP replies on the subnet
B.An increase in TCP retransmissions across the subnet
C.Multiple IP addresses mapping to the same MAC address in the ARP cache
D.Duplicate IP address conflict messages in system logs
E.A sudden increase in DNS query volume from a single host
AnswersA, C

Legitimate ARP is request-driven, so a flood of unsolicited ARP replies, especially gratuitous ones claiming an IP already in use, indicates an attacker updating victims' caches. This behavior is characteristic of ARP poisoning tools that continuously send forged replies. Detecting a high rate of unsolicited replies is a reliable network-level indicator.

Why this answer

ARP poisoning is confirmed by layer-2 evidence: multiple IP addresses resolving to one MAC address in the ARP cache, and a high volume of unsolicited ARP replies. DNS query spikes, duplicate IP conflict messages, and TCP retransmissions may accompany network problems but are not specific to forged ARP activity, so they do not strongly support the conclusion.

Exam trap

The trap here is choosing generic connectivity symptoms such as retransmissions or DNS spikes instead of the ARP-specific evidence that directly shows cache manipulation.

196
Multi-Selectmedium

A security analyst is analyzing system logs and notices multiple failed authentication events followed by a successful login from the same user account, and then a privilege escalation event. Which THREE events should be correlated to detect a potential attack?

Select 3 answers
A.Successful authentication event
B.Privilege escalation event
C.Failed authentication events
D.Network share access event
E.Account creation event
AnswersA, B, C

The successful login is the pivot point: after repeated failures, it signals the attacker guessed valid credentials and gained access. Correlating it with the preceding failures and the following privilege escalation confirms a brute-force-to-compromise chain rather than isolated noise.

Why this answer

The scenario describes a classic brute-force-then-compromise pattern, so the three events that must be correlated are C, the failed authentication events, which indicate repeated unsuccessful login attempts against the same account; A, the successful authentication event, which shows the attacker eventually guessed or cracked the credentials and gained access; and B, the privilege escalation event, which reveals that the compromised account was then used to obtain higher-level rights, confirming the attack progressed beyond initial access. Correlating these three in sequence (many failures → one success → escalation) is what distinguishes a real intrusion from benign failed logins. D (network share access) and E (account creation) are not part of the described sequence and, while potentially suspicious in other contexts, are not the events the analyst should correlate here to detect this specific attack chain.

Exam trap

Cisco often tests the concept that a single successful login alone is not suspicious, but when combined with preceding failed attempts and subsequent privilege escalation, it forms a clear attack pattern that candidates must recognize as a three-event correlation.

197
MCQhard

An analyst observes that an internal host is sending ICMP echo requests with payloads containing random data to an external IP. The payload size is larger than typical. What is the most likely technique?

A.Ping of death
B.Traceroute
C.Smurf attack
D.ICMP tunneling
AnswerD

ICMP normally carries small, predictable payloads. Oversized echo requests with random data hide exfiltrated or tunnelled traffic inside a protocol firewalls often permit, letting the host bypass egress filtering while appearing as benign ping activity.

Why this answer

ICMP tunneling encapsulates non-ICMP data (e.g., command-and-control traffic) within ICMP echo request/reply packets. The random payload data and larger-than-typical payload size are hallmarks of this technique, as the attacker uses the ICMP protocol to bypass firewalls and exfiltrate data or establish covert communication.

Exam trap

Cisco often tests the distinction between attacks that exploit ICMP for denial of service (e.g., ping of death, Smurf) versus those that use ICMP for covert data transfer (ICMP tunneling), so candidates must focus on the presence of random payload data rather than just the protocol or packet size.

How to eliminate wrong answers

Option A is wrong because a ping of death exploits a buffer overflow by sending an oversized ICMP packet (typically >65535 bytes) to crash the target, not by using random data in normal-sized payloads. Option B is wrong because traceroute uses ICMP echo requests with varying TTL values to map network hops, not random payloads or large payload sizes. Option C is wrong because a Smurf attack sends ICMP echo requests to a broadcast address with a spoofed source IP, causing amplification, not random data in the payload.

198
MCQeasy

A security policy mandates that all administrative access to network devices must be encrypted. Which of the following protocols should be used to comply with this policy?

A.Telnet
B.SSH
C.TFTP
D.SNMPv2c
AnswerB

SSH encrypts the entire session, including authentication credentials and configuration commands, whereas Telnet transmits everything in cleartext. This satisfies the policy's mandate that administrative access to network devices be encrypted, protecting against credential interception and session eavesdropping on the management path.

Why this answer

SSH (Secure Shell) encrypts all traffic, including authentication credentials and commands, between an administrator and a network device. This satisfies the policy requirement for encrypted administrative access, unlike Telnet which sends everything in plaintext.

Exam trap

Cisco often tests the misconception that Telnet is acceptable if a password is set, but the trap is that Telnet never encrypts the session, so it fails any policy requiring encryption regardless of authentication.

How to eliminate wrong answers

Option A is wrong because Telnet transmits data, including usernames and passwords, in cleartext, violating the encryption mandate. Option C is wrong because TFTP (Trivial File Transfer Protocol) is used for file transfers, not interactive administrative access, and it lacks any encryption or authentication. Option D is wrong because SNMPv2c uses community strings in plaintext for authentication and does not provide encryption for administrative sessions; it is a network management protocol, not a remote access protocol.

199
MCQeasy

A hospital must protect patient records under a regulation that specifies administrative, physical, and technical safeguards for electronic protected health information. Which U.S. regulation establishes these requirements?

A.SOX
B.HIPAA Security Rule
C.GDPR
D.PCI DSS
AnswerB

The HIPAA Security Rule sets national standards for protecting electronic protected health information and is organized precisely around administrative, physical, and technical safeguards. It applies to covered entities such as hospitals and to their business associates. The rule requires risk analysis, access controls, audit controls, integrity controls, and transmission security, making it the direct match for the scenario's described obligations.

Why this answer

The HIPAA Security Rule is the U.S. regulation that requires covered entities to implement administrative, physical, and technical safeguards for electronic protected health information. Its three safeguard categories map directly to the scenario, and compliance is enforced through risk analysis and documented policies rather than a prescriptive control checklist.

Exam trap

The trap here is confusing broadly similar privacy laws, when only one regulation is built around administrative, physical, and technical safeguards for health data.

200
MCQmedium

An analyst is reviewing alerts from an IDS. A signature matched 'script' and 'alert' in HTTP request parameters. The analyst inspects the packet and sees <script>alert('XSS')</script> in the URI. What is the most accurate classification of this alert?

A.False negative
B.False positive
C.True negative
D.True positive
AnswerD

The signature correctly matched genuine XSS payload characters in the URI, and inspection confirms an actual attack attempt rather than benign traffic. A true positive means the IDS alerted on real malicious activity, satisfying the stem's requirement for accurate classification of the confirmed script injection.

Why this answer

The alert corresponds to a real attack (cross-site scripting) in the traffic, so it is a true positive.

201
MCQeasy

A security analyst is monitoring network traffic and notices a high volume of TCP SYN packets sent to various ports on a single host. Which type of attack is most likely occurring?

A.DNS amplification
B.Smurf attack
C.Port scan
D.ARP spoofing
AnswerC

A port scan sends TCP SYN packets to many ports on one host, seeking open services. The half-open SYN pattern, with no completed handshake, distinguishes scanning from a SYN flood, which targets a single port. This matches the stem's high-volume SYN traffic to various ports.

Why this answer

A high volume of TCP SYN packets to various ports on a single host is the signature of a port scan, most commonly an SYN (half-open) scan using tools like Nmap with -sS. The scanner sends SYN to many ports and analyzes SYN-ACK (open) versus RST (closed) responses without completing the three-way handshake. This pattern of many SYNs to different ports on one target is the classic reconnaissance footprint.

Exam trap

The trap is that 'high volume of SYN packets' can sound like a SYN flood (DoS), but the key detail is 'to various ports on a single host' — that is reconnaissance (port scan), not a flood, and candidates who fixate on volume alone pick the wrong category.

How to eliminate wrong answers

Option A is wrong because DNS amplification is a reflection/volumetric DDoS attack that floods a victim with large DNS responses, not a stream of SYNs to many ports on one host. Option B is wrong because a Smurf attack uses ICMP echo requests to a broadcast address with a spoofed source, amplifying ICMP replies to the victim — it involves ICMP, not TCP SYN. Option D is wrong because ARP spoofing poisons the ARP cache to redirect Layer 2 traffic; it does not generate TCP SYN packets to many ports and is not detectable by SYN volume.

202
Multi-Selectmedium

Which TWO of the following are valid sources of security monitoring data in a Cisco security architecture?

Select 2 answers
A.RADIUS accounting
B.SNMP traps
C.Syslog messages
D.WMI queries
E.NetFlow records
AnswersC, E

Syslog messages are a standard telemetry source, carrying device and application events into a Cisco security architecture for correlation. Firewall and IDS platforms emit syslog, making it a valid monitoring input alongside NetFlow and endpoint telemetry.

Why this answer

Syslog messages (C) are a core source of security monitoring data because network devices, firewalls, and IPS/IDS appliances forward event, error, and audit messages to a central syslog collector or SIEM for correlation and alerting. NetFlow records (E) provide flow-level metadata (source/destination IP, ports, protocol, byte/packet counts, timestamps) that enable traffic profiling, anomaly detection, and threat hunting in a Cisco security architecture. RADIUS accounting (A) is primarily used for user session accounting and billing/AAA purposes rather than as a general security monitoring telemetry source.

SNMP traps (B) are mainly for device health and fault management, not security event monitoring. WMI queries (D) are a Windows management mechanism and are not a standard Cisco security monitoring data source.

Exam trap

Cisco often tests the distinction between data sources used for security monitoring (Syslog, NetFlow) versus management or authentication protocols (RADIUS, SNMP, WMI), leading candidates to confuse RADIUS accounting or SNMP traps as valid monitoring inputs.

203
MCQhard

An analyst is investigating a potential security incident and reviews the Cisco ASA firewall logs. The logs show the following entry: 'Deny tcp src outside:203.0.113.5/443 dst inside:10.1.1.10/3389'. Which of the following does this log entry indicate?

A.An external host successfully connected to an internal host on RDP.
B.An internal host attempted to connect to an external host on RDP, but the connection was blocked.
C.An external host attempted to connect to an internal host on RDP, but the connection was blocked by the firewall.
D.An internal host attempted to connect to an external host on HTTPS, but the connection was blocked.
AnswerC

The log shows a denied TCP connection from an external IP (203.0.113.5) on port 443 to an internal IP (10.1.1.10) on port 3389. Port 3389 is used for RDP. The firewall denied the connection, indicating an attempt to access RDP from the outside was blocked. This is a common indicator of scanning or exploitation attempts.

Why this answer

The Cisco ASA log entry shows a denied TCP connection from an external IP address to an internal IP address on port 3389, which is the default port for RDP. The 'Deny' action indicates the firewall blocked the attempt. This is a common scenario where an external host tries to exploit RDP, but the firewall prevents it.

Understanding log format, including source/destination and port numbers, is essential for incident analysis.

Exam trap

The trap here is misreading the direction of the connection or confusing the source port with the destination port, leading to an incorrect interpretation of the log entry.

204
MCQhard

An analyst is reviewing DNS logs and sees repeated queries from an internal workstation to randomly generated subdomains of a single domain, such as a1b2c3.example.com, d4e5f6.example.com, and so on. The responses are consistently NXDOMAIN. Which technique is most consistent with this pattern?

A.Fast flux DNS used to rotate IP addresses for a botnet.
B.DNS cache poisoning attempt against the internal resolver.
C.DNS tunneling used to exfiltrate data through TXT record queries.
D.Domain generation algorithm (DGA) used by malware for command-and-control resolution.
AnswerD

DGAs produce many pseudo-random subdomains that malware queries until one resolves to a C2 server. The NXDOMAIN responses for most queries are expected because only a few generated domains are registered by the attacker. This pattern, with high volumes of random-looking names under one domain, is a classic DGA indicator in DNS logs.

Why this answer

Randomly generated subdomains under a single domain with mostly NXDOMAIN responses are a hallmark of a domain generation algorithm. Malware uses DGAs to evade static blocklists by cycling through many candidate C2 domains, and DNS logs are the primary place to detect this behavior.

Exam trap

The trap here is confusing DGA traffic with DNS tunneling, even though tunneling usually shows successful, data-carrying queries rather than repeated NXDOMAIN responses.

205
MCQhard

A company's security policy includes a clause that all software installed on company devices must be approved by the IT department. An employee installs an unapproved application that later causes a malware infection. Which policy was violated?

A.Incident Response Policy
B.Acceptable Use Policy
C.Data Retention Policy
D.Remote Access Policy
AnswerB

An Acceptable Use Policy governs employee conduct on company systems, explicitly prohibiting installation of unauthorised software. The stem's clause requiring IT approval before installation is a use restriction, not a technical control, so the employee breached the AUP's behavioural mandate rather than any configuration-based safeguard.

Why this answer

The Acceptable Use Policy (AUP) defines what activities and software are permitted on company devices. By installing an unapproved application without IT authorization, the employee violated the AUP, which directly led to the malware infection. This policy is the primary control for preventing unauthorized software installations that bypass security baselines.

Exam trap

Cisco often tests the distinction between a proactive policy (AUP) that prevents unauthorized actions and a reactive policy (Incident Response) that handles the aftermath, causing candidates to confuse the policy that was violated with the policy that describes the response to the violation.

How to eliminate wrong answers

Option A is wrong because the Incident Response Policy governs the procedures for detecting, containing, and remediating security incidents after they occur, not the prohibition of unauthorized software installations. Option C is wrong because the Data Retention Policy specifies how long data must be kept and when it should be deleted, and has no relation to software installation approvals. Option D is wrong because the Remote Access Policy controls how external users connect to the internal network (e.g., VPN authentication, split tunneling rules), not the installation of local applications.

206
MCQeasy

While reviewing firewall logs, an analyst notices repeated inbound connections from a single external IP to multiple internal hosts on TCP port 3389 within a short time window. Each connection lasts only a few seconds and is followed by a new connection to a different internal host. Which activity does this pattern most likely represent?

A.A load balancer health check against RDP servers
B.A vulnerability scan of internal RDP services
C.An administrator using Remote Desktop to manage multiple servers
D.A backup application replicating data over RDP
AnswerB

Short-lived connections to TCP port 3389 across many internal hosts in rapid succession match a scan probing for reachable RDP services. Scanners often open and close sessions quickly to test responsiveness rather than complete authentication. The fan-out to multiple hosts from one external source reinforces scanning behavior, so this pattern indicates reconnaissance against RDP endpoints rather than any legitimate administrative session.

Why this answer

One external source rapidly opening short-lived TCP/3389 sessions to many internal hosts is characteristic of scanning for exposed RDP services. Legitimate RDP administration uses longer authenticated sessions from internal management addresses, backups use different protocols, and health checks come from internal load balancers at regular intervals. The burst of brief, fan-out connections therefore points to reconnaissance against RDP endpoints.

Exam trap

The trap here is assuming any RDP traffic is administrative; scanning also touches port 3389 but with short, fan-out sessions.

207
MCQhard

During a security incident, the CISO decides to contain a compromised server by isolating it from the network. Which role is primarily responsible for making this containment decision based on business impact?

A.CISO
B.Incident handler
C.Legal counsel
D.PR representative
AnswerA

The CISO owns the risk decision, weighing containment's operational and financial consequences against continued exposure. Isolating a critical server can halt revenue-generating services, so authority rests with the executive accountable for business impact rather than the technical responders.

Why this answer

The CISO is the decision-maker for business impact and authorizes containment actions.

208
Multi-Selecthard

An analyst is correlating telemetry after a suspected Kerberoasting attack against an Active Directory environment. Which two artifacts, when found together, most strongly support that the attack succeeded in obtaining crackable service ticket material? (Choose two.)

Select 2 answers
A.Windows Security event 4769 logged with RC4 encryption type (0x17) for service accounts, generated in a short burst from one workstation.
B.A Group Policy update pushed to all domain-joined computers changing the minimum password length requirement.
C.LDAP search traffic enumerating accounts with a servicePrincipalName attribute set, originating from a workstation rather than a domain controller.
D.A spike in Windows Security event 4625 failed logons against many user accounts from a single source over a brief interval.
E.A sudden increase in SMB file share access to the finance department's documents from a user in the engineering group.
AnswersA, C

Event 4769 records Kerberos service ticket requests. A burst of requests for multiple service principal names using RC4, the weaker encryption type, from a single non-server host matches the Kerberoasting pattern, since the attacker requests tickets and cracks them offline. The volume, encryption downgrade, and unusual requesting host together distinguish this from normal service access.

Why this answer

Kerberoasting requires two observable steps: discovery of accounts with service principal names, and requests for their service tickets using weak encryption that can be cracked offline. A workstation issuing broad LDAP queries for the servicePrincipalName attribute, followed by a burst of event 4769 entries with RC4 encryption for service accounts, together demonstrate both steps. Failed logons or policy changes do not evidence ticket acquisition, and share access belongs to a different attack phase.

Exam trap

The trap here is pairing any credential-related anomaly, such as failed logons, with ticket activity, when Kerberoasting requires no password guessing and produces successful ticket requests instead.

209
Multi-Selecthard

Which THREE are typical sources of log data used in security monitoring? (Choose three.)

Select 3 answers
A.Printer spool logs.
B.HVAC system logs.
C.Windows Event Logs.
D.Firewall logs.
E.DNS server logs.
AnswersC, D, E

Contain authentication and system events.

Why this answer

Windows Event Logs are a primary source of security monitoring data because they record critical security events such as logon attempts, account changes, and process creation (Event IDs 4624, 4625, 4688). Security Information and Event Management (SIEM) systems ingest these logs to detect unauthorized access, privilege escalation, and malware execution.

Exam trap

Cisco often tests the distinction between logs that are security-relevant versus operational or environmental logs, so candidates mistakenly choose printer or HVAC logs because they are 'logs' in a general sense, but they lack the authentication, network, or system event data required for security monitoring.

210
MCQeasy

A junior analyst is asked to identify which log source would best confirm that an internal workstation attempted to resolve a suspicious domain shortly before an alert fired. The environment forwards DNS query logs from its recursive resolvers to the SIEM. Which action should the analyst take first?

A.Run a reverse DNS lookup on the workstation's IP address to see its registered name.
B.Query the forwarded DNS logs for the workstation's IP and the suspicious domain name.
C.Inspect the workstation's local hosts file for static entries mapping the suspicious domain.
D.Search the firewall session logs for outbound connections to the suspicious domain's IP address.
AnswerB

Because recursive resolver query logs are already forwarded to the SIEM, searching for the workstation's source IP paired with the suspicious domain directly confirms whether the host issued that lookup and when. This is the most direct and authoritative evidence of resolution attempts. It also establishes a timeline anchor that the analyst can use to pivot to proxy, firewall, and endpoint data for corroboration.

Why this answer

When recursive resolver query logs are already centralized in the SIEM, searching them for the workstation's IP and the suspicious domain is the fastest authoritative way to confirm the lookup and its timestamp. Firewall logs show IP connections rather than names, reverse lookups describe the workstation itself, and the hosts file only covers static overrides, so none of those directly answer whether the domain was resolved.

Exam trap

The trap here is pivoting to firewall or reverse-lookup data first, when the DNS query log is the only source that directly records the name the host asked to resolve.

211
Multi-Selectmedium

A security analyst is assessing the risk profile of a new cloud-based collaboration application that employees want to adopt. The analyst must identify which factors contribute to the overall risk of introducing this application into the environment. (Choose two.)

Select 2 answers
A.The likelihood that a threat will exploit a vulnerability in the application or its supporting infrastructure.
B.The marketing team's preferred color scheme for the application's user interface.
C.The number of employees who have requested access to the application for productivity purposes.
D.The vendor's stock price over the past fiscal quarter.
E.The potential impact to the organization if the application's data is compromised or the service becomes unavailable.
AnswersA, E

Risk is a function of likelihood and impact. The probability that a threat actor will exploit a weakness in the application or its cloud infrastructure directly contributes to the overall risk level. Without considering likelihood, the analyst cannot estimate how probable a loss event is. This factor is a core component of risk assessment in the Security Concepts domain.

Why this answer

Risk assessment combines the likelihood that a threat will exploit a vulnerability with the impact that exploitation would have on the organization. These two factors produce the overall risk rating for the collaboration application. User demand, UI color schemes, and vendor stock price do not measure security risk, so likelihood and impact are the two factors the analyst must evaluate.

Exam trap

The trap here is treating business popularity or vendor financial metrics as risk factors, when risk specifically requires assessing both the probability of exploitation and the resulting impact.

212
MCQhard

A security analyst is examining a Linux system for signs of a rootkit. The analyst runs `lsmod` and notices a kernel module named `hideproc` that is not recognized. The analyst then runs `rmmod hideproc` but receives an error that the module is in use. Which of the following is the MOST likely reason the module cannot be removed?

A.The module's reference count is artificially incremented to prevent removal.
B.The module was loaded with `modprobe` and requires `modprobe -r` to remove.
C.The module is compiled into the kernel and cannot be removed.
D.The module is currently being used by a legitimate process such as `systemd`.
AnswerA

Rootkits often manipulate the module's reference count (refcount) to prevent removal. They may increment it or hook the `delete_module` syscall to return an error. This makes the module appear 'in use' even when no legitimate process uses it. Thus, the rootkit maintains persistence by blocking `rmmod`. This is a common rootkit technique.

Why this answer

Rootkits frequently manipulate kernel structures to prevent their removal. By incrementing the module's reference count or hooking the `delete_module` system call, they make `rmmod` fail with 'in use'. This ensures the rootkit remains loaded.

Analysts should use memory forensics or reboot to a trusted environment to remove such modules.

Exam trap

The trap here is assuming that 'in use' always means a legitimate process is using the module, when a rootkit can fake the reference count to block removal.

213
MCQmedium

An analyst is investigating a Windows system for potential malware persistence. The analyst discovers a scheduled task that runs a PowerShell script every hour. The script downloads and executes a payload from a remote server. Which of the following Windows artifacts would BEST provide the original creation time and the author of this scheduled task?

A.C:\Windows\Tasks\<TaskName>
B.C:\Windows\System32\Tasks\<TaskName>
C.C:\Windows\System32\winevt\Logs\Microsoft-Windows-TaskScheduler%4Operational.evtx
D.C:\Windows\Prefetch\<TaskName>.pf
AnswerB

This file stores the XML definition of the scheduled task, including its creation time, author, and actions. It is the authoritative source for the task's configuration and metadata. Analyzing this file can reveal when and by whom the task was created, which is crucial for determining if it is malicious.

Why this answer

The scheduled task definition file in C:\Windows\System32\Tasks\ contains an XML representation that includes metadata such as the task's creation time and author. This is the most direct artifact for determining the origin of a suspicious scheduled task, as it is written when the task is created.

Exam trap

The trap here is confusing the task scheduler operational log with the task definition file; the log records execution events, not creation metadata.

214
MCQhard

During an incident, a first responder pulls the network cable of a compromised server. Later, the incident response team is unable to collect volatile data such as running processes. Which policy or procedure was violated?

A.Chain of Custody Procedure
B.Incident Response Procedure for evidence preservation
C.Forensic Analysis Procedure
D.Escalation Procedure
AnswerB

Pulling the network cable removed power-dependent state before capture, destroying running processes and memory-resident artefacts. The evidence preservation procedure requires collecting volatile data in order of volatility before any containment action. Isolating the host via network-level controls instead would have preserved that volatile evidence while still containing the compromise.

Why this answer

Pulling the network cable of a compromised server causes the loss of volatile data such as running processes, memory contents, and network connections. The Incident Response Procedure for evidence preservation dictates that volatile data must be collected before any action that could destroy it. By pulling the cable, the first responder violated this procedure, leading to the inability to collect volatile evidence.

Exam trap

The trap here is confusing the different incident response procedures. Candidates might choose Chain of Custody because it sounds related to evidence, but the specific violation is about preserving volatile data, which falls under evidence preservation, not chain of custody.

How to eliminate wrong answers

Option A is wrong because Chain of Custody Procedure deals with documenting the handling of evidence, not with the initial collection of volatile data. Option C is wrong because Forensic Analysis Procedure is about the detailed examination of evidence, not about the immediate response actions. Option D is wrong because Escalation Procedure is about notifying higher-level personnel, not about preserving volatile data.

215
MCQmedium

A security analyst is reviewing the organization's data classification policy. The policy defines four levels: Public, Internal, Confidential, and Restricted. A new marketing campaign document contains strategic pricing information that, if disclosed, could cause competitive harm. According to typical data classification practices, how should this document be classified?

A.Confidential
B.Internal
C.Restricted
D.Public
AnswerA

Confidential data is defined as information whose unauthorized disclosure could cause harm to the organization, such as competitive harm. Strategic pricing information fits this definition because its exposure could damage the company's market position. This classification aligns with the policy's description and ensures appropriate handling controls are applied.

Why this answer

Data classification policies typically define Confidential as information whose unauthorized disclosure could cause harm, including competitive harm. Strategic pricing information fits that definition, so it should be classified as Confidential. Public and Internal are too low, and Restricted is generally reserved for more severe impact, making Confidential the appropriate level for this document.

Exam trap

The trap here is assuming that any sensitive business information must be Restricted, when most policies reserve that level for the most severe impact and use Confidential for competitive harm.

216
MCQmedium

A SOC analyst reviews a firewall log with the following entry: action=deny, source IP=192.168.1.100, destination IP=10.0.0.1, destination port=22. The analyst knows that 10.0.0.1 is an SSH server. What does this log entry indicate?

A.A DNS query resolved to 10.0.0.1
B.An attempted SSH connection that was blocked by the firewall
C.A successful SSH connection from 192.168.1.100 to 10.0.0.1
D.A misconfigured firewall allowing SSH traffic
AnswerB

The deny action combined with destination port 22 shows a connection attempt to the SSH service that the firewall rejected. The source host never established a session, so the entry records blocked traffic rather than a successful login.

Why this answer

The log entry shows 'action=deny', which explicitly indicates the firewall blocked the packet. Since destination port 22 is the default port for SSH, this log entry represents an attempted SSH connection from 192.168.1.100 to 10.0.0.1 that was denied by the firewall. The analyst's knowledge that 10.0.0.1 is an SSH server confirms the nature of the traffic.

Exam trap

Cisco often tests the ability to read a firewall log entry literally—candidates may overlook the 'action=deny' field and incorrectly assume any connection attempt to port 22 is automatically successful or that the firewall is misconfigured.

How to eliminate wrong answers

Option A is wrong because DNS queries use UDP or TCP port 53, not TCP port 22, and the log shows a destination port of 22, which is SSH, not DNS. Option C is wrong because the 'action=deny' field means the connection was blocked, not successful; a successful connection would show 'action=allow' or 'action=permit'. Option D is wrong because the firewall is correctly enforcing a deny rule for SSH traffic to 10.0.0.1, which is the opposite of a misconfiguration allowing SSH traffic.

217
Multi-Selectmedium

An analyst is investigating a suspected ARP poisoning attack on a local subnet. The analyst captures traffic and reviews ARP packets. Which two characteristics would most likely indicate that ARP poisoning is occurring? (Choose two.)

Select 2 answers
A.ARP packets with a sender MAC address that is a multicast address
B.ARP request packets with a broadcast destination MAC address
C.Multiple ARP replies from the same MAC address claiming different IP addresses
D.ARP requests sent to a unicast destination MAC address
E.Gratuitous ARP replies that are not preceded by an ARP request
AnswersC, E

In ARP poisoning, an attacker sends gratuitous ARP replies to associate their MAC address with multiple IP addresses, or to impersonate the gateway. Seeing a single MAC address claiming ownership of several IPs is a strong indicator. Legitimate hosts typically have one IP per MAC address (or a few in specific configurations), so this behavior is suspicious.

Why this answer

The correct indicators are multiple ARP replies from one MAC claiming different IPs and gratuitous ARP replies not preceded by a request. Both are hallmarks of ARP poisoning, where an attacker floods the network with forged ARP mappings to intercept traffic. Normal ARP requests are broadcast and are not malicious.

The other options describe normal or invalid but non-indicative behavior.

Exam trap

The trap here is assuming that any broadcast ARP request is malicious, when in fact broadcast requests are normal; poisoning is signaled by unsolicited replies and MAC/IP mismatches.

218
MCQmedium

An analyst finds a registry modification under 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options'. What is the primary use of this registry key?

A.To configure network firewall rules for the image
B.To set a debugger that runs when the image is executed
C.To change the file extension association for the image
D.To log all execution of the image to the Event Log
AnswerB

Image File Execution Options supports a Debugger value that Windows launches instead of the named executable. Attackers abuse this for persistence by pointing the debugger at malicious code, so the key's legitimate purpose is specifying a debugger for the image.

Why this answer

The Image File Execution Options (IFEO) registry key is used to specify a debugger that launches when a particular executable is started. Attackers abuse this by setting a 'Debugger' value to a malicious binary, achieving persistence and execution hijacking. Legitimate use includes attaching debuggers to specific processes, but the primary security-relevant function is debugger redirection.

Exam trap

The trap is assuming IFEO is a benign debugging-only feature; candidates forget that its debugger redirection is a well-known persistence mechanism, so they overlook the malicious potential and pick a logging or firewall answer.

How to eliminate wrong answers

Option A is wrong because firewall rules for images are configured through Windows Firewall policies, not through IFEO, which is strictly about process execution behavior. Option C is wrong because file extension associations are stored under HKEY_CLASSES_ROOT and user shell settings, not under IFEO. Option D is wrong because IFEO does not log execution to the Event Log; it only redirects execution to a debugger, and any logging would be a side effect of the debugger itself, not a built-in feature.

219
MCQeasy

A security analyst notices that an internal web server is receiving HTTP requests where the User-Agent string is identical across thousands of requests originating from a single external IP address, and each request targets a different URL path on the server. The requests occur at a rate of several hundred per second. Which activity does this pattern most likely represent?

A.Automated directory brute-forcing or content discovery
B.Web content scraping by a search engine crawler
C.Cross-site request forgery against authenticated users
D.HTTP response splitting attack
AnswerA

A single source sending hundreds of requests per second to many different URL paths with an identical User-Agent is characteristic of automated content discovery or directory brute-forcing tools. These tools enumerate paths to find hidden files or administrative interfaces. The high rate and fixed User-Agent distinguish it from normal user browsing or legitimate crawling.

Why this answer

The pattern of one external IP sending hundreds of requests per second to many different URL paths with a constant User-Agent is a classic signature of automated content discovery and directory brute-forcing. These tools enumerate paths to uncover hidden resources. Legitimate crawlers rate-limit and identify themselves, while CSRF and response splitting involve different traffic characteristics.

Exam trap

The trap here is dismissing high-volume web requests as harmless crawler traffic without checking the request rate, source diversity, and User-Agent consistency.

220
MCQmedium

A security engineer discovers that an attacker has inserted fake entries into a DNS resolver's cache, redirecting users to a malicious website. Which attack has occurred?

A.DDoS
B.DNS poisoning
C.Man-in-the-middle
D.ARP spoofing
AnswerB

DNS poisoning corrupts a resolver's cache with forged records, so subsequent queries return the attacker's IP address and redirect victims. This matches the stem exactly: fake entries inserted into the cache, sending users to a malicious site.

Why this answer

DNS poisoning, also known as DNS cache poisoning, occurs when an attacker inserts forged DNS resource records into a resolver's cache. This causes the resolver to return a malicious IP address for a legitimate domain, redirecting users to an attacker-controlled site without their knowledge.

Exam trap

Cisco often tests the distinction between DNS poisoning and ARP spoofing by presenting a scenario involving redirection to a malicious site, leading candidates to confuse the Layer 2 ARP attack with the Layer 7 DNS cache corruption.

How to eliminate wrong answers

Option A is wrong because a DDoS (Distributed Denial of Service) attack aims to overwhelm a target with traffic to disrupt service, not to insert fake DNS entries. Option C is wrong because a man-in-the-middle (MITM) attack intercepts and potentially alters communications between two parties in real time, whereas DNS poisoning corrupts the resolver's stored cache records. Option D is wrong because ARP spoofing links an attacker's MAC address to a legitimate IP address on a local network, targeting Layer 2 address resolution, not the DNS resolver's cache.

221
MCQmedium

A SOC analyst is reviewing NetFlow records exported from a border router and notices a single internal host initiating outbound connections to more than 300 distinct external IP addresses on TCP port 443 within a five-minute window, with each flow carrying only a few hundred bytes. Which security monitoring conclusion is best supported by this evidence?

A.The host is likely exfiltrating a large database to a single external cloud storage provider.
B.The host is likely the victim of a reflected DNS amplification attack.
C.The host is likely performing a port scan or host sweep against external targets.
D.The host is likely performing beaconing to a command-and-control server over HTTPS.
AnswerC

Hundreds of distinct destination addresses contacted in a very short window, each with minimal data transferred, is the classic NetFlow signature of a host sweep. Because the flows target port 443, the sweep is aimed at discovering reachable HTTPS services. NetFlow's IP, port, and byte-count fields are sufficient to identify this fan-out behavior without full packet capture.

Why this answer

NetFlow captures metadata rather than payloads, but the metadata here is decisive: one internal host opening connections to hundreds of distinct external addresses on the same port with uniformly tiny byte counts is a host sweep. Beaconing would target few destinations; exfiltration would move large volumes to one destination; amplification would be inbound UDP. The fan-out pattern uniquely supports scanning activity.

Exam trap

The trap here is assuming that any burst of outbound HTTPS traffic is command-and-control beaconing, when the distinguishing factor is the number of distinct destinations and the near-constant small flow size, not the port used.

222
Multi-Selecteasy

A security analyst is implementing multifactor authentication. Which TWO are considered factors? (Select two.)

Select 2 answers
A.Password
B.Last login time
C.User ID
D.Security group membership
E.RSA token
AnswersA, E

A password is a knowledge factor: something the user knows. Multifactor authentication requires factors from different categories, so pairing it with a possession or inherence factor satisfies the two-factor requirement rather than duplicating the same category.

Why this answer

A password (A) is a knowledge factor — something the user knows — and is one of the three classic authentication factor categories (knowledge, possession, inherence), so it qualifies as a factor in MFA. An RSA token (E) is a possession factor — something the user has — generating a one-time passcode (e.g., TOTP/HOTP), which is exactly the second factor MFA combines with a password. The remaining options are not authentication factors: last login time (B) is audit/log data, a user ID (C) is an identifier rather than a verifier, and security group membership (D) is an authorization attribute, not a factor used to prove identity.

Exam trap

Cisco often tests the distinction between identification (user ID) and authentication (factors that prove identity), leading candidates to mistakenly select user ID as a factor when it is only an identifier.

223
Multi-Selecthard

An analyst is using Volatility to analyze a memory dump. Which TWO plugins are most effective for detecting code injection?

Select 2 answers
A.ldrmodules
B.pslist
C.malfind
D.pstree
E.netscan
AnswersA, C

ldrmodules enumerates loaded modules via three linked lists (InLoad, InInit, InMem) and flags discrepancies, exposing injected DLLs unlinked from the loader's lists. This directly satisfies the scenario's requirement to detect code injection in the memory dump.

Why this answer

Option A, ldrmodules, is correct because it compares the three DLL/module lists maintained in the PEB (InLoad, InInit, InMem) and flags modules that appear in memory but are absent from the loader list, a classic sign of injected or unlinked DLLs. Option C, malfind, is correct because it scans process memory for pages with MZ/PE headers that are not backed by a file on disk and have suspicious protection flags such as PAGE_EXECUTE_READWRITE, which is the standard indicator of injected code. The unmarked options do not belong: pslist merely walks the doubly linked process list to enumerate running processes, pstree shows parent-child process relationships, and netscan lists network connections and sockets; none of these inspect module lists or memory pages for injected code.

Exam trap

200-201 often tests the specific Volatility plugins for different forensic tasks; candidates may confuse pslist/pstree (process listing) with malfind/ldrmodules (injection detection).

224
MCQmedium

What is the primary purpose of a digital certificate in a Public Key Infrastructure (PKI)?

A.To encrypt all network traffic
B.To bind a public key to an identity
C.To provide a backup of private keys
D.To prevent malware infections
AnswerB

A digital certificate binds a public key to a verified identity by having a trusted certificate authority digitally sign the certificate, which contains the subject's public key and identifying details. This binding lets relying parties confirm the key genuinely belongs to the claimed entity, preventing impersonation and enabling trusted encryption and authentication.

Why this answer

The primary purpose of a digital certificate in a Public Key Infrastructure (PKI) is to bind a specific public key to a verified identity (such as a person, device, or organization). This binding is achieved through the certificate authority (CA) signing the certificate, which cryptographically asserts that the public key belongs to the named subject. Without this binding, there would be no trusted way to associate a public key with its owner, making secure communications and authentication impossible.

Exam trap

Cisco often tests the misconception that a digital certificate itself encrypts data or contains the private key, when in fact it only binds the public key to an identity and never holds the private key.

How to eliminate wrong answers

Option A is wrong because encrypting all network traffic is not the role of a digital certificate; encryption of traffic is performed by protocols like TLS using the public/private key pair, but the certificate itself only provides the binding and does not perform encryption. Option C is wrong because a digital certificate contains only the public key and identity information, never the private key; backing up private keys is a separate key management task, and exposing the private key in a certificate would break the entire security model. Option D is wrong because preventing malware infections is a function of security controls such as antivirus software, firewalls, and endpoint protection, not of digital certificates or PKI.

225
MCQeasy

Which protocol is used by SNMP to send traps from network devices to the management station?

A.TCP port 162
B.TCP port 161
C.UDP port 162
D.UDP port 161
AnswerC

SNMP traps are unsolicited notifications sent from agents to the manager, and they travel over UDP port 162. The manager listens on 162, while queries use UDP 161. This connectionless transport suits one-way alert delivery without acknowledgement overhead.

Why this answer

SNMP traps are sent from agents to managers using UDP port 162. SNMP uses UDP, not TCP.

Page 2

Page 3 of 13

Page 4