\" in the URL parameter. Which TWO…","url":"https://courseiva.com/questions/cisco/cisco-cyberops-associate/an-analyst-identifies-http-traffic-containing-the-string-s-w61pz"},{"@type":"ListItem","position":177,"name":"An analyst reviews network logs and sees a large outbound FTP transfer of 500 MB from a workstation to an external IP at…","url":"https://courseiva.com/questions/cisco/cisco-cyberops-associate/an-analyst-reviews-network-logs-and-sees-a-large-outbound-ft-62zsi"},{"@type":"ListItem","position":178,"name":"A company is creating an incident response policy. Which TWO elements should be included to ensure proper handling of se…","url":"https://courseiva.com/questions/cisco/cisco-cyberops-associate/a-company-is-creating-an-incident-response-policy-which-two-d5tlz"},{"@type":"ListItem","position":179,"name":"An analyst investigating a Linux host notices an unusual process running as root. Which command would provide the most d…","url":"https://courseiva.com/questions/cisco/cisco-cyberops-associate/an-analyst-investigating-a-linux-host-notices-an-unusual-pro-37yn2"},{"@type":"ListItem","position":180,"name":"A Linux system administrator notices unauthorized SSH logins in /var/log/auth.log. Which of the following log entries wo…","url":"https://courseiva.com/questions/cisco/cisco-cyberops-associate/a-linux-system-administrator-notices-unauthorized-ssh-logins-1zrmb"},{"@type":"ListItem","position":181,"name":"A security engineer is analyzing a recent breach. The attacker gained access by sending an email that appeared to be fro…","url":"https://courseiva.com/questions/cisco/cisco-cyberops-associate/a-security-engineer-is-analyzing-a-recent-breach-the-attack-vygn7"},{"@type":"ListItem","position":182,"name":"During alert triage, an analyst determines that an alert fired but no actual attack or malicious activity occurred on th…","url":"https://courseiva.com/questions/cisco/cisco-cyberops-associate/during-alert-triage-an-analyst-determines-that-an-alert-fir-5zus4"},{"@type":"ListItem","position":183,"name":"Which of the following best describes a vulnerability?","url":"https://courseiva.com/questions/cisco/cisco-cyberops-associate/which-of-the-following-best-describes-a-vulnerability-8h9se"},{"@type":"ListItem","position":184,"name":"Refer to the exhibit from a Cisco Firepower event. Which action is most appropriate for the analyst?","url":"https://courseiva.com/questions/cisco/cisco-cyberops-associate/refer-to-the-exhibit-from-a-cisco-firepower-event-which-act-7w7m4"},{"@type":"ListItem","position":185,"name":"Which TWO actions are recommended when tuning IDS signatures to reduce false positives?","url":"https://courseiva.com/questions/cisco/cisco-cyberops-associate/which-two-actions-are-recommended-when-tuning-ids-signatures-gjoms"},{"@type":"ListItem","position":186,"name":"Match each network protocol to its well-known port number.","url":"https://courseiva.com/questions/cisco/cisco-cyberops-associate/match-each-network-protocol-to-its-well-known-port-number-ht7oa"},{"@type":"ListItem","position":187,"name":"Which component of a SIEM is responsible for converting log data from various sources into a standard format?","url":"https://courseiva.com/questions/cisco/cisco-cyberops-associate/which-component-of-a-siem-is-responsible-for-converting-log-uh0p6"},{"@type":"ListItem","position":188,"name":"A multinational company has a security policy that all data at rest in cloud storage must be encrypted using company-man…","url":"https://courseiva.com/questions/cisco/cisco-cyberops-associate/a-multinational-company-has-a-security-policy-that-all-data-rtmhw"},{"@type":"ListItem","position":189,"name":"During a security incident, an analyst captures network traffic and observes multiple connections from an internal host …","url":"https://courseiva.com/questions/cisco/cisco-cyberops-associate/during-a-security-incident-an-analyst-captures-network-traf-28b8a"},{"@type":"ListItem","position":190,"name":"An organization experiences a ransomware attack where files are encrypted and a ransom is demanded. Which element of the…","url":"https://courseiva.com/questions/cisco/cisco-cyberops-associate/an-organization-experiences-a-ransomware-attack-where-files-5wbk3"},{"@type":"ListItem","position":191,"name":"Which two are common techniques used in network intrusion analysis? (Choose two.)","url":"https://courseiva.com/questions/cisco/cisco-cyberops-associate/which-two-are-common-techniques-used-in-network-intrusion-an-377ez"},{"@type":"ListItem","position":192,"name":"An alert shows a high volume of outbound traffic from an internal host to an external IP using FTP. The data includes fi…","url":"https://courseiva.com/questions/cisco/cisco-cyberops-associate/an-alert-shows-a-high-volume-of-outbound-traffic-from-an-int-1wy7y"},{"@type":"ListItem","position":193,"name":"An organization is required to preserve data that may be relevant to a lawsuit. Which legal process is invoked to preven…","url":"https://courseiva.com/questions/cisco/cisco-cyberops-associate/an-organization-is-required-to-preserve-data-that-may-be-rel-apsln"},{"@type":"ListItem","position":194,"name":"Which THREE of the following are common indicators of compromise (IOCs) that a security monitoring system might trigger …","url":"https://courseiva.com/questions/cisco/cisco-cyberops-associate/which-three-of-the-following-are-common-indicators-of-compro-h7yhv"},{"@type":"ListItem","position":195,"name":"Which TWO of the following are valid reasons to create an exception to a security policy? (Choose two.)","url":"https://courseiva.com/questions/cisco/cisco-cyberops-associate/which-two-of-the-following-are-valid-reasons-to-create-an-ex-8ra1u"},{"@type":"ListItem","position":196,"name":"An organization wants to implement a security framework that includes functions such as Identify, Protect, Detect, Respo…","url":"https://courseiva.com/questions/cisco/cisco-cyberops-associate/an-organization-wants-to-implement-a-security-framework-that-72vjl"},{"@type":"ListItem","position":197,"name":"A junior analyst reports that the network-based intrusion detection system (NIDS) has been generating alerts for a signa…","url":"https://courseiva.com/questions/cisco/cisco-cyberops-associate/a-junior-analyst-reports-that-the-network-based-intrusion-de-sbjc2"},{"@type":"ListItem","position":198,"name":"Which TWO of the following are common sources of security events used in security monitoring?","url":"https://courseiva.com/questions/cisco/cisco-cyberops-associate/which-two-of-the-following-are-common-sources-of-security-ev-w4oqk"},{"@type":"ListItem","position":199,"name":"During a security awareness training session, an employee reports they clicked a link in a phishing email but did not en…","url":"https://courseiva.com/questions/cisco/cisco-cyberops-associate/during-a-security-awareness-training-session-an-employee-re-mh5sz"},{"@type":"ListItem","position":200,"name":"During a penetration test, a security engineer uses publicly available information from LinkedIn and Google to gather de…","url":"https://courseiva.com/questions/cisco/cisco-cyberops-associate/during-a-penetration-test-a-security-engineer-uses-publicly-jre7z"},{"@type":"ListItem","position":201,"name":"A SOC analyst is investigating a web server log and sees the following entry: 192.168.1.10 - - [15/May/2023:10:15:30 +00…","url":"https://courseiva.com/questions/cisco/cisco-cyberops-associate/a-soc-analyst-is-investigating-a-web-server-log-and-sees-the-kyhan"},{"@type":"ListItem","position":202,"name":"A large e-commerce company experiences a data breach where customer credit card numbers are stolen. The investigation re…","url":"https://courseiva.com/questions/cisco/cisco-cyberops-associate/a-large-e-commerce-company-experiences-a-data-breach-where-c-umfhp"},{"@type":"ListItem","position":203,"name":"A security analyst is configuring a new SIEM platform. The organization has multiple log sources, including Windows Even…","url":"https://courseiva.com/questions/cisco/cisco-cyberops-associate/a-security-analyst-is-configuring-a-new-siem-platform-the-o-d1qi7"},{"@type":"ListItem","position":204,"name":"A Linux host has an unusual cron job that runs a script from /tmp every minute. The analyst checks /etc/crontab and /var…","url":"https://courseiva.com/questions/cisco/cisco-cyberops-associate/a-linux-host-has-an-unusual-cron-job-that-runs-a-script-from-tenwp"},{"@type":"ListItem","position":205,"name":"A security analyst is analyzing system logs and notices multiple failed authentication events followed by a successful l…","url":"https://courseiva.com/questions/cisco/cisco-cyberops-associate/a-security-analyst-is-analyzing-system-logs-and-notices-mult-kqn7q"},{"@type":"ListItem","position":206,"name":"An analyst observes that an internal host is sending ICMP echo requests with payloads containing random data to an exter…","url":"https://courseiva.com/questions/cisco/cisco-cyberops-associate/an-analyst-observes-that-an-internal-host-is-sending-icmp-ec-49qgc"},{"@type":"ListItem","position":207,"name":"Which TWO of the following are key components of a security policy framework according to Cisco? (Choose two.)","url":"https://courseiva.com/questions/cisco/cisco-cyberops-associate/which-two-of-the-following-are-key-components-of-a-security-wrnit"},{"@type":"ListItem","position":208,"name":"Which TWO of the following are valid classifications for alerts during triage?","url":"https://courseiva.com/questions/cisco/cisco-cyberops-associate/which-two-of-the-following-are-valid-classifications-for-ale-v965b"},{"@type":"ListItem","position":209,"name":"A security policy mandates that all administrative access to network devices must be encrypted. Which of the following p…","url":"https://courseiva.com/questions/cisco/cisco-cyberops-associate/a-security-policy-mandates-that-all-administrative-access-to-nt7ak"},{"@type":"ListItem","position":210,"name":"An analyst is reviewing alerts from an IDS. A signature matched 'script' and 'alert' in HTTP request parameters. The ana…","url":"https://courseiva.com/questions/cisco/cisco-cyberops-associate/an-analyst-is-reviewing-alerts-from-an-ids-a-signature-matc-vrmbv"},{"@type":"ListItem","position":211,"name":"A security analyst is monitoring network traffic and notices a high volume of TCP SYN packets sent to various ports on a…","url":"https://courseiva.com/questions/cisco/cisco-cyberops-associate/a-security-analyst-is-monitoring-network-traffic-and-notices-qf687"},{"@type":"ListItem","position":212,"name":"Which TWO of the following are valid sources of security monitoring data in a Cisco security architecture?","url":"https://courseiva.com/questions/cisco/cisco-cyberops-associate/which-two-of-the-following-are-valid-sources-of-security-mon-9m6lf"},{"@type":"ListItem","position":213,"name":"During a security incident, an analyst uses Wireshark to examine a pcap. The TCP stream shows the string 'GET /malware.e…","url":"https://courseiva.com/questions/cisco/cisco-cyberops-associate/during-a-security-incident-an-analyst-uses-wireshark-to-exa-p1a93"},{"@type":"ListItem","position":214,"name":"A company's security policy requires that all laptops accessing the corporate network must have full-disk encryption ena…","url":"https://courseiva.com/questions/cisco/cisco-cyberops-associate/a-company-s-security-policy-requires-that-all-laptops-access-3203d"},{"@type":"ListItem","position":215,"name":"What is the meaning of this syslog message?","url":"https://courseiva.com/questions/cisco/cisco-cyberops-associate/what-is-the-meaning-of-this-syslog-message-3xw7v"},{"@type":"ListItem","position":216,"name":"An analyst is examining a PCAP for signs of pass-the-hash attack. Which THREE indicators would be consistent with pass-t…","url":"https://courseiva.com/questions/cisco/cisco-cyberops-associate/an-analyst-is-examining-a-pcap-for-signs-of-pass-the-hash-at-hyqgl"},{"@type":"ListItem","position":217,"name":"A company's security policy includes a clause that all software installed on company devices must be approved by the IT …","url":"https://courseiva.com/questions/cisco/cisco-cyberops-associate/a-company-s-security-policy-includes-a-clause-that-all-softw-qxq2a"},{"@type":"ListItem","position":218,"name":"An analyst is investigating a host that was compromised via a web exploit. The analyst has a pcap file of the network tr…","url":"https://courseiva.com/questions/cisco/cisco-cyberops-associate/an-analyst-is-investigating-a-host-that-was-compromised-via-4ddld"},{"@type":"ListItem","position":219,"name":"During a security incident, the CISO decides to contain a compromised server by isolating it from the network. Which rol…","url":"https://courseiva.com/questions/cisco/cisco-cyberops-associate/during-a-security-incident-the-ciso-decides-to-contain-a-co-8c8by"},{"@type":"ListItem","position":220,"name":"An analyst is reviewing a memory dump using Volatility. They want to identify processes with potential code injection. W…","url":"https://courseiva.com/questions/cisco/cisco-cyberops-associate/an-analyst-is-reviewing-a-memory-dump-using-volatility-they-jzrqz"},{"@type":"ListItem","position":221,"name":"Which THREE are typical sources of log data used in security monitoring? (Choose three.)","url":"https://courseiva.com/questions/cisco/cisco-cyberops-associate/which-three-are-typical-sources-of-log-data-used-in-security-20ga4"},{"@type":"ListItem","position":222,"name":"A network security monitoring analyst is analyzing firewall logs and sees the following traffic: Source IP 10.1.1.50 to …","url":"https://courseiva.com/questions/cisco/cisco-cyberops-associate/a-network-security-monitoring-analyst-is-analyzing-firewall-4i0fi"},{"@type":"ListItem","position":223,"name":"During an incident, a first responder pulls the network cable of a compromised server. Later, the incident response team…","url":"https://courseiva.com/questions/cisco/cisco-cyberops-associate/during-an-incident-a-first-responder-pulls-the-network-cabl-kz4kk"},{"@type":"ListItem","position":224,"name":"A SOC analyst reviews a firewall log with the following entry: action=deny, source IP=192.168.1.100, destination IP=10.0…","url":"https://courseiva.com/questions/cisco/cisco-cyberops-associate/a-soc-analyst-reviews-a-firewall-log-with-the-following-entr-vtbmx"},{"@type":"ListItem","position":225,"name":"Which two pieces of evidence are strong indicators of compromise (IOC) in network traffic?","url":"https://courseiva.com/questions/cisco/cisco-cyberops-associate/which-two-pieces-of-evidence-are-strong-indicators-of-compro-9ppdi"}]}
A security analyst is analyzing a memory dump using Volatility. The command 'volatility -f mem.dump malfind' returns several results with VAD tags 'VadS' and 'Vadl'. What does this indicate?
A.The process has no suspicious memory regions
B.The process has legitimate DLLs loaded in memory
C.The process likely has injected code, as these VAD tags indicate executable writable memory
D.The process is a kernel-mode driver
AnswerC
Correct. PAGE_EXECUTE_READWRITE memory is a strong indicator of code injection.
Why this answer
Malfind detects injected code by scanning for VADs with specific protection flags. 'VadS' indicates a VAD with PAGE_EXECUTE_READWRITE protection, common for shellcode injection. 'Vadl' is for large pages. The presence of these tags strongly suggests code injection.
An analyst sees an alert: 'ET POLICY Outgoing HTTP Request with Suspicious User-Agent (Mozilla/5.0 compatible; MSIE 6.0; Windows NT 5.1)'. The source is an internal host that typically uses Windows 10. What should the analyst suspect?
A.The traffic is from a web proxy
B.The host is running Windows XP
C.The host is running a browser update
D.The traffic is likely generated by malware
AnswerD
Malware often uses old User-Agents to evade detection.
Why this answer
The User-Agent string 'Mozilla/5.0 compatible; MSIE 6.0; Windows NT 5.1' mimics Internet Explorer 6 on Windows XP (NT 5.1). Since the source host normally runs Windows 10, this outdated and mismatched User-Agent is a strong indicator of malware attempting to disguise its traffic as legacy browser activity to evade detection.
Exam trap
Cisco often tests the concept that an anomalous User-Agent string inconsistent with the host's known OS is a red flag for malware, not an indication of the actual OS version.
How to eliminate wrong answers
Option A is wrong because a web proxy typically preserves the original client's User-Agent or adds its own header, not fabricate a legacy Windows XP User-Agent. Option B is wrong because the host is known to run Windows 10, not Windows XP; the alert indicates the traffic is spoofing XP, not that the OS is actually XP. Option C is wrong because browser updates do not change the User-Agent to an older, incompatible version like MSIE 6.0 on Windows NT 5.1; updates would use a current User-Agent string.
An organization is reviewing its risk management process and identifies a risk with a high probability and high impact. Management decides to stop the activity causing the risk. Which risk treatment option is being applied?
A.Risk mitigation
B.Risk acceptance
C.Risk avoidance
D.Risk transfer
AnswerC
Stopping the activity avoids the risk entirely.
Why this answer
Avoidance means eliminating the risk by discontinuing the activity.
Which TWO of the following are common network security protocols? (Choose two.)
Select 2 answers
A.IPsec
B.FTP
C.SSL
D.HTTP
E.SNMP
AnswersA, C
IPsec provides secure IP communications.
Why this answer
IPsec is a suite of protocols used to secure IP communications by authenticating and encrypting each IP packet in a data stream. It operates at the network layer (Layer 3) and is commonly used in VPNs to provide confidentiality, integrity, and authentication. This makes it a fundamental network security protocol.
Exam trap
Cisco often tests the distinction between protocols that are inherently secure (like IPsec and SSL/TLS) versus those that are not (like FTP, HTTP, and SNMPv1/v2c), leading candidates to mistakenly select common but insecure protocols as security protocols.
Which THREE of the following are key principles of zero trust security? (Choose three.)
Select 3 answers
A.Least privilege
B.Perimeter-based security
C.Never trust, always verify
D.Assume breach
E.Implicit trust
AnswersA, C, D
Least privilege limits access to only what is necessary.
Why this answer
Least privilege is a core principle of zero trust because it ensures users, devices, and applications are granted only the minimum permissions necessary to perform their functions. This limits the blast radius of a potential compromise by restricting lateral movement and access to sensitive resources. In zero trust, least privilege is enforced through granular policies, often using micro-segmentation and identity-based access controls, rather than relying on network location.
Exam trap
Cisco often tests whether candidates confuse zero trust with traditional perimeter defense, so the trap here is that 'perimeter-based security' sounds like a valid security principle but is actually the outdated model that zero trust aims to replace.
A user receives an email that appears to be from the company's IT department asking for their password to perform a security check. The email contains a link to a fake login page. Which type of social engineering attack is this?
A.Spear phishing
B.Vishing
C.Pretexting
D.Phishing
AnswerD
Phishing is a broad attack using fraudulent emails and websites.
Why this answer
Phishing typically uses deceptive emails and fake websites to trick users into revealing sensitive information.
Which TWO locations in a Linux filesystem should be checked for evidence of malware persistence?
Select 2 answers
A./proc
B./var/spool/cron/crontabs
C./var/log/syslog
D./etc/init.d
E./etc/passwd
AnswersB, D
Cron jobs can run malware periodically.
Why this answer
Cron is a standard Linux mechanism for scheduling recurring tasks, and malware often uses cron jobs to re-execute itself after a reboot or at specific intervals. The crontabs directory under /var/spool/cron/ contains the actual cron job files for each user, making it a primary location to check for unauthorized persistence entries. Malware can add a cron entry that downloads or runs a malicious script, ensuring its continued presence on the system.
Exam trap
Cisco often tests the distinction between locations that store persistent configuration (like crontabs and init.d) versus runtime or log-only directories (like /proc and /var/log), so candidates mistakenly choose /proc or /var/log/syslog because they are commonly examined during live analysis, but they do not hold persistence artifacts.
A network engineer is designing a segmented network to protect a sensitive database. The database must be accessible only from a specific application server. Which security concept best describes this design?
A.Defense in depth
B.Separation of duties
C.Weakest link
D.Least privilege
AnswerD
Least privilege ensures that entities have only the access necessary to perform their functions.
Why this answer
Least privilege, is correct because the design restricts access to the sensitive database to only the specific application server that requires it. This principle dictates that users, processes, or systems should be granted the minimum permissions necessary to perform their functions, thereby reducing the attack surface. By implementing network access control lists (ACLs) or firewall rules that permit traffic solely from the application server's IP address to the database port, the engineer enforces least privilege at the network layer.
Exam trap
Cisco often tests least privilege by framing it as a network segmentation or access control question, and the trap here is confusing it with defense in depth because both involve multiple layers, but least privilege specifically focuses on granting only the necessary permissions rather than layering controls.
How to eliminate wrong answers
Option A is wrong because defense in depth is a layered security strategy that employs multiple, overlapping controls (e.g., firewalls, IDS/IPS, encryption) to protect assets, not a single restriction between two specific hosts. Option B is wrong because separation of duties divides critical tasks among different individuals to prevent fraud or error (e.g., one admin creates accounts, another approves them), which is unrelated to network segmentation for database access. Option C is wrong because the weakest link concept refers to the idea that a system's security is only as strong as its most vulnerable component, not a design principle for restricting access between a specific application server and a database.
A security analyst is reviewing firewall logs and notices a rule that denies traffic from source IP 10.0.0.5 to destination port 3389. What service is being blocked?
A.RDP
B.SNMP
C.SMTP
D.SSH
AnswerA
RDP uses port 3389.
Why this answer
Port 3389 is the default port for Remote Desktop Protocol (RDP), which is used for remote graphical desktop access to Windows systems. The firewall rule denying traffic from 10.0.0.5 to this port blocks RDP connections, preventing that host from initiating remote desktop sessions.
Exam trap
Cisco often tests the association of default port numbers with common services, and the trap here is that candidates may confuse RDP (3389) with SSH (22) or SMTP (25) due to similar remote access or management functions.
How to eliminate wrong answers
Option B (SNMP) is wrong because SNMP uses UDP ports 161 (queries) and 162 (traps), not TCP 3389. Option C (SMTP) is wrong because SMTP uses TCP port 25 for email relay, with submissions on port 587 or 465, not 3389. Option D (SSH) is wrong because SSH uses TCP port 22 for secure remote shell access, not port 3389.
Which MITRE ATT&CK tactic corresponds to the Cyber Kill Chain phase 'Actions on Objectives'?
A.Privilege Escalation
B.Impact
C.Command and Control
D.Exfiltration
AnswerB
Impact includes data destruction, denial of service, etc.
Why this answer
In MITRE ATT&CK, the tactic 'Impact' covers actions that disrupt or damage systems, similar to 'Actions on Objectives' where the attacker achieves their goal.
A security analyst is investigating a Windows host suspected of malware infection. Which tool would allow the analyst to view parent-child relationships of running processes and inspect command line arguments?
A.Process Explorer
B.Task Manager
C.tasklist command
D.Resource Monitor
AnswerA
Process Explorer is a Sysinternals tool that provides a hierarchical process tree and command line arguments.
Why this answer
Process Explorer provides detailed process tree view and command line information, unlike Task Manager's default view or tasklist.
Which THREE of the following are key elements of a security monitoring and analysis strategy? (Choose three.)
Select 3 answers
A.Establishing a feedback loop for continuous improvement
B.Focusing only on network-based monitoring to reduce complexity
C.Regularly tuning detection mechanisms to reduce false positives
D.Automating all incident response decisions to eliminate human error
E.Centralized log management and correlation across multiple sources
AnswersA, C, E
Continuous improvement adapts the monitoring to new threats and changing environments.
Why this answer
Establishing a feedback loop for continuous improvement (A) is a key element because security monitoring is not a static process; it requires iterative refinement based on lessons learned from incidents, false positives, and changes in the threat landscape. This loop ensures that detection rules, response playbooks, and monitoring configurations evolve to maintain effectiveness against new attack vectors and reduce noise over time.
Exam trap
Cisco often tests the misconception that security monitoring can be purely network-focused or fully automated, but the correct approach requires a balanced, multi-source strategy with human oversight and continuous tuning.
A company's remote access policy requires VPN connections to use two-factor authentication (2FA). An employee reports they cannot connect because their token is not syncing. What is the best course of action?
A.Disable 2FA for the employee
B.Replace the token and allow access anyway
C.Temporarily allow connections without 2FA
D.Provide a new token and synchronize it correctly
AnswerD
This resolves the issue while maintaining policy compliance.
Why this answer
The core issue is a synchronization problem between the employee's token and the authentication server. Two-factor authentication (2FA) relies on time-based one-time passwords (TOTP) or event-based (HOTP) algorithms; if the token's clock drifts or the counter becomes out of sync, authentication fails. Providing a new token and correctly synchronizing it (e.g., via NTP time alignment or reseeding the HMAC-based OTP counter) restores secure access without bypassing the security policy.
Exam trap
Cisco often tests the misconception that any token failure should be resolved by temporarily disabling security controls (like 2FA) rather than fixing the underlying technical issue, tempting candidates to choose options that weaken security instead of following proper troubleshooting procedures.
How to eliminate wrong answers
Option A is wrong because disabling 2FA for the employee violates the remote access policy and eliminates the second authentication factor, leaving the VPN connection protected only by a password, which is a security downgrade. Option B is wrong because replacing the token without ensuring proper synchronization will likely result in the same sync failure; simply allowing access anyway bypasses authentication controls and undermines the 2FA requirement. Option C is wrong because temporarily allowing connections without 2FA creates a window of vulnerability where an attacker could exploit the lack of a second factor, and it violates the explicit policy requiring 2FA for all VPN connections.
An organization's incident response team has identified a malware infection on a critical server. They need to collect evidence for potential legal action. Which of the following is the most important step to ensure the admissibility of the evidence?
A.Contacting legal counsel before proceeding
B.Documenting the chain of custody for all evidence
C.Creating a forensic image of the affected hard drive
D.Isolating the server from the network
AnswerB
Chain of custody documentation is essential for legal proceedings to prove evidence integrity.
Why this answer
Maintaining a proper chain of custody documents who handled the evidence and ensures it has not been tampered with, which is critical for legal admissibility.
Which type of traffic is most prominent in this NetFlow data?
A.SSH
B.HTTP
C.DNS
D.HTTPS
AnswerB
Port 80 is HTTP and has the most packets and bytes.
Why this answer
HTTP traffic is most prominent because the NetFlow data shows a high volume of packets and bytes on TCP port 80, which is the default port for HTTP. NetFlow records summarize traffic flows, and the large number of flows and bytes on port 80 indicates that HTTP is the dominant protocol in the captured data.
Exam trap
Cisco often tests the ability to distinguish between HTTP and HTTPS by port number, and the trap here is that candidates might assume HTTPS is more common due to modern encryption trends, but the NetFlow data explicitly shows higher traffic on port 80.
How to eliminate wrong answers
Option A is wrong because SSH uses TCP port 22, and the NetFlow data does not show significant traffic on that port. Option C is wrong because DNS primarily uses UDP port 53 (and sometimes TCP for zone transfers), and the data does not indicate a high volume of traffic on port 53. Option D is wrong because HTTPS uses TCP port 443, and while it may appear in the data, the question specifies that HTTP is the most prominent, meaning port 80 traffic exceeds port 443 traffic in this sample.
A SOC analyst is investigating a potential data exfiltration incident. Which TWO Indicators of Compromise (IoCs) would be most relevant for tracking the exfiltration of files over the network?
Select 2 answers
A.URLs
B.IP addresses
C.Mutex names
D.Registry keys
E.File hashes (MD5/SHA-256)
AnswersA, E
URLs can show where data was sent.
Why this answer
URLs are correct because they can indicate the destination of exfiltrated data, such as a cloud storage endpoint or a command-and-control server. File hashes (MD5/SHA-256) are correct because they uniquely identify the specific files being transferred, allowing the analyst to track known malicious or sensitive files across the network.
Exam trap
Cisco often tests the distinction between host-based IoCs (mutexes, registry keys) and network-based IoCs (URLs, IPs, file hashes) in data exfiltration scenarios, leading candidates to mistakenly select mutex or registry options.
You are a security analyst at a mid-sized company. The company uses a SIEM to collect logs from firewalls, IDS, and servers. Recently, the SIEM generated an alert for a potential brute-force attack against the company's VPN server. The alert is based on a correlation rule that triggers when more than 30 failed authentication attempts from a single source IP occur within 10 minutes. You investigate and see that the source IP is 203.0.113.50, which is a known IP address of a partner company that uses the VPN for remote access. The failed attempts are all from the same username 'john.doe'. You also notice that the attempts are happening every 5 seconds, exactly 6 attempts per minute. The partner company has a policy that locks accounts after 3 failed attempts. Based on this scenario, what is the most likely cause of the alert?
A.The user 'john.doe' has forgotten his password and is repeatedly trying to log in.
B.A script or automated process at the partner site is misconfigured and repeatedly trying to authenticate with an incorrect password.
C.A man-in-the-middle attack is replaying captured authentication packets.
D.The partner's account 'john.doe' has been compromised and an attacker is attempting to gain access.
AnswerB
The exact timing and same username point to a script; the lockout policy would lock the account after 3 attempts, but the script may be retrying from the same source, causing the SIEM alert before the lockout.
Why this answer
The alert is triggered by a correlation rule that detects more than 30 failed authentication attempts from a single source IP within 10 minutes. The observed pattern—exactly 6 attempts per minute, every 5 seconds—is highly regular and mechanical, which is characteristic of an automated script or misconfigured process, not human behavior. Since the partner company locks accounts after 3 failed attempts, a human user would be locked out quickly and could not sustain 30+ attempts; only a script ignoring the lockout policy or using a cached incorrect password could produce this pattern.
Exam trap
Cisco often tests the distinction between human behavior and automated patterns by including precise timing data; the trap here is that candidates focus on the source IP being a 'known partner' and assume compromise or user error, ignoring the mechanical regularity that points to a script.
How to eliminate wrong answers
Option A is wrong because a human user forgetting their password would not produce exactly 6 attempts per minute at precise 5-second intervals; human behavior is irregular and would stop after the account is locked (3 failed attempts). Option C is wrong because a man-in-the-middle attack replaying captured authentication packets would not cause repeated failed attempts from a single source IP with the same username; replay attacks typically cause successful authentications or session hijacking, not a steady stream of failures. Option D is wrong because if the account were compromised, an attacker would likely use a password spraying or credential stuffing tool with multiple usernames or random timing, not a fixed 5-second interval with the same username; the regular pattern suggests a misconfigured script, not an active attacker.
During an incident, an analyst needs to determine if a specific user account 'jsmith' was used from a remote IP during a breach window. Which log sources should the analyst check first?
A.NetFlow records from the core switch.
B.VPN concentrator logs.
C.File server audit logs.
D.Windows Security Event Logs (Event ID 4624, 4625).
AnswerD
Contains logon events with username and source IP.
Why this answer
Windows Security Event Logs with Event ID 4624 (successful logon) and 4625 (failed logon) are the authoritative source for interactive and remote logon events on a Windows system. They record the target user account (jsmith), the source IP address of the remote connection, and the timestamp, making them the direct and most reliable log source to determine if a specific user account was used from a remote IP during a breach window.
Exam trap
Cisco often tests the misconception that NetFlow or VPN logs can identify user-level authentication details, when in fact only Windows Security Event Logs (or equivalent OS authentication logs) contain the specific user account and source IP for a logon event.
How to eliminate wrong answers
Option A is wrong because NetFlow records provide metadata about network flows (IP addresses, ports, protocols, and byte counts) but do not log user account names or authentication events, so they cannot identify which user account was used. Option B is wrong because VPN concentrator logs show when a user establishes a VPN tunnel and the assigned IP, but they do not log individual authentication attempts to a specific Windows workstation or server, and the remote IP seen in the VPN logs is the VPN client's external IP, not the internal IP of the machine where the logon occurred. Option C is wrong because file server audit logs track access to files and folders (e.g., reads, writes, deletes) but do not record interactive or remote logon events for a specific user account on a different system; they only show file-level operations after authentication has already occurred.
Based on the Cisco ASA syslog message, what does this event indicate?
A.A DNS response from an external server to an internal client was allowed.
B.An inbound UDP packet from an external source to an internal destination was denied.
C.The access-group "OUTSIDE_IN" is misconfigured.
D.An outbound UDP connection was denied.
AnswerB
The syslog clearly states 'Deny udp src outside:... dst inside:...'.
Why this answer
The syslog message indicates that an inbound UDP packet from an external source to an internal destination was denied by the Cisco ASA. The message includes the source and destination IP addresses and ports, and the action is 'denied' due to the access-group 'OUTSIDE_IN' applied to the outside interface. This matches option B, which correctly identifies the denied inbound UDP traffic.
Exam trap
Cisco often tests the ability to distinguish between inbound and outbound traffic based on source/destination IPs in syslog messages, leading candidates to confuse the direction when the access-group name suggests an inbound policy but the traffic flow is misinterpreted.
How to eliminate wrong answers
Option A is wrong because the event is a denial, not an allowance, and it involves UDP, not DNS specifically (though DNS uses UDP, the message does not indicate a response). Option C is wrong because the access-group 'OUTSIDE_IN' is correctly referenced in the syslog message; there is no evidence of misconfiguration—the denial is the expected behavior based on the ACL. Option D is wrong because the traffic is inbound (from external to internal), not outbound; the syslog shows source as external and destination as internal.
Which Cisco tool provides network-wide visibility and can detect anomalies using NetFlow and behavioral analysis?
A.Cisco Firepower Threat Defense (FTD)
B.Cisco Catalyst 9300 Switch
C.Cisco Identity Services Engine (ISE)
D.Cisco Secure Network Analytics (Stealthwatch)
AnswerD
It uses NetFlow and behavioral analysis for anomaly detection.
Why this answer
Cisco Secure Network Analytics (formerly Stealthwatch) is the correct answer because it is a dedicated network visibility and security analytics platform that leverages NetFlow, IPFIX, and other telemetry sources to perform behavioral analysis and detect anomalies across the entire network. Unlike a firewall or switch, its primary function is to ingest flow data and apply machine learning models to identify threats such as lateral movement, data exfiltration, and command-and-control traffic.
Exam trap
The trap here is that candidates confuse a device that generates NetFlow data (like a Catalyst switch) with a tool that analyzes NetFlow data for security anomalies, leading them to select the switch instead of the dedicated analytics platform.
How to eliminate wrong answers
Option A is wrong because Cisco Firepower Threat Defense (FTD) is a next-generation firewall and IPS appliance that inspects packets inline for threats, but it does not provide network-wide visibility or behavioral analysis based on NetFlow; its visibility is limited to traffic passing through the firewall. Option B is wrong because the Cisco Catalyst 9300 Switch is a network switching platform that can generate NetFlow data but lacks the analytics engine to perform behavioral analysis or detect anomalies itself; it is a data source, not an analysis tool. Option C is wrong because Cisco Identity Services Engine (ISE) focuses on identity management, policy enforcement, and network access control (e.g., 802.1X, profiling), not on flow-based anomaly detection or behavioral analysis of network traffic.
An analyst is examining a Linux server and notices an unusual systemd service that starts automatically. Which command would be used to disable this service?
A.systemctl disable servicename
B.systemctl stop servicename
C.systemctl remove servicename
D.systemctl mask servicename
AnswerA
disable prevents the service from starting at boot.
Why this answer
The 'systemctl disable' command prevents a service from starting automatically at boot.
An analyst identifies HTTP traffic containing the string "<script>alert('XSS')</script>" in the URL parameter. Which TWO attack types are likely being attempted?
Select 2 answers
A.LDAP injection
B.HTML injection
C.Command injection
D.Cross-site scripting (XSS)
E.SQL injection
AnswersB, D
Injecting HTML tags is HTML injection.
Why this answer
The script tag is classic XSS; HTML injection occurs when attacker injects HTML content.
An analyst reviews network logs and sees a large outbound FTP transfer of 500 MB from a workstation to an external IP at 2:00 AM. The workstation regularly sends 10 MB daily. What should the analyst suspect?
A.C2 beaconing
B.Normal backup operation
C.Software update
D.Data exfiltration
AnswerD
Anomalous large transfer is suspicious for exfiltration.
Why this answer
Large outbound data transfers outside normal patterns, especially at odd hours, are typical of data exfiltration.
A company is creating an incident response policy. Which TWO elements should be included to ensure proper handling of security incidents?
Select 2 answers
A.Contact information for law enforcement
B.A list of employee performance metrics
C.A step-by-step procedure for containment, eradication, and recovery
D.A schedule for quarterly vulnerability scans
E.List of approved vendors for forensic tools
AnswersA, C
Having contact information for law enforcement is a key part of an incident response communication plan.
Why this answer
An incident response policy must include contact information for law enforcement to ensure timely reporting of crimes such as data breaches or ransomware attacks, as required by regulations like GDPR or state breach notification laws. This enables proper legal handling and chain-of-custody preservation. Option C is correct because a step-by-step procedure for containment, eradication, and recovery is the core operational framework of the NIST SP 800-61 incident response lifecycle, ensuring consistent and effective response actions.
Exam trap
Cisco often tests the distinction between proactive security controls (like vulnerability scans or vendor lists) and reactive incident response procedures, causing candidates to mistakenly include operational or procurement details as policy elements.
An analyst investigating a Linux host notices an unusual process running as root. Which command would provide the most detailed process listing including parent PID and CPU usage?
A.ss -tlnp
B.ps aux
C.lsof
D.top
AnswerD
top provides an interactive process listing that can be customized to show PPID and includes CPU usage by default, making it the best choice for the given requirements.
Why this answer
The question requires a command that provides parent PID (PPID) and CPU usage. While `ps aux` shows CPU usage, it does not include PPID. Among the options, `top` is the only command that can be configured to display PPID (by adding the PPID column) and shows CPU usage by default.
The other options either show network connections (`ss`), open files (`lsof`), or lack PPID (`ps aux`). Therefore, `top` is the most detailed process listing that includes both PPID and CPU usage.
Exam trap
Candidates may assume 'ps aux' is the most detailed because it includes CPU usage, but it lacks PPID which the question explicitly requires.
A Linux system administrator notices unauthorized SSH logins in /var/log/auth.log. Which of the following log entries would indicate a failed SSH login attempt?
A.Failed password for root
B.Connection closed by authenticating user
C.Session opened for user
D.Accepted publickey for root
AnswerA
This explicitly indicates a failed password attempt.
Why this answer
In auth.log, failed SSH logins typically contain 'Failed password' messages. Accepted password indicates success, and Invalid user may accompany failed attempts but the key indicator is 'Failed password'.
A security engineer is analyzing a recent breach. The attacker gained access by sending an email that appeared to be from the CEO, requesting the recipient to transfer funds. What type of social engineering attack is this?
A.Spear phishing
B.Vishing
C.Phishing
D.Pretexting
AnswerA
Targeted attack on a specific person with personalized email.
Why this answer
Spear phishing targets a specific individual with personalized content, often impersonating a trusted source.
During alert triage, an analyst determines that an alert fired but no actual attack or malicious activity occurred on the network. How should this alert be classified?
A.True negative
B.False negative
C.True positive
D.False positive
AnswerD
False positive is an alert without an actual attack.
Why this answer
A false positive is an alert that triggers incorrectly when no real attack exists. True positive means attack confirmed, false negative means attack missed, true negative means no alert and no attack.
Refer to the exhibit from a Cisco Firepower event. Which action is most appropriate for the analyst?
A.Escalate to law enforcement
B.Investigate the source host for compromise
C.Block the destination IP
D.Disable the intrusion signature
AnswerB
Correct. The source is internal and the alert indicates suspicious activity, so the host may be compromised.
Why this answer
The exhibit shows a single intrusion event from a specific source IP to a destination IP. The most appropriate first step is to investigate the source host for compromise because the event indicates a potential exploit attempt originating from that host. Without additional context (e.g., multiple events, confirmed data exfiltration), escalating to law enforcement or blocking the IP is premature, and disabling the signature would blind the sensor to future threats.
Exam trap
Cisco often tests the principle of 'investigate before act' — the trap here is that candidates see a security event and immediately choose a reactive action (block, disable, escalate) instead of the proper investigative step.
How to eliminate wrong answers
Option A is wrong because law enforcement escalation is reserved for confirmed, high-severity incidents (e.g., active data breach, child exploitation) with legal authority, not a single unverified intrusion event. Option C is wrong because blocking the destination IP without first verifying the source host's compromise could disrupt legitimate traffic and fails to address the root cause (the potentially compromised source). Option D is wrong because disabling the intrusion signature would prevent detection of that exploit across all hosts, weakening the security posture and violating the principle of maintaining detection coverage.
Which TWO actions are recommended when tuning IDS signatures to reduce false positives?
Select 2 answers
A.Increase alert severity for all signatures
B.Replace IDS with a next-generation firewall
C.Modify signature thresholds to match typical traffic patterns
D.Disable signatures that generate frequent alerts
E.Whitelist known good behavior
AnswersC, E
Adjusting thresholds reduces false positives.
Why this answer
Options C and E are correct. Modifying signature thresholds to match typical traffic patterns (C) and whitelisting known good behavior (E) are standard IDS tuning practices to reduce false positives. Option A is ineffective because increasing severity does not reduce false positive counts.
Option B replaces the system rather than tuning it. Option D may remove detection of actual threats and is not recommended.
Match each network protocol to its well-known port number.
Drag a concept onto its matching description — or click a concept then click the description.
Concepts
Matches
22
443
53
25
3389
Why these pairings
Standard well-known port assignments: HTTP=80, HTTPS=443, SSH=22, DNS=53. Common confusions include swapping HTTP/HTTPS ports or confusing SSH with Telnet.
Which component of a SIEM is responsible for converting log data from various sources into a standard format?
A.Aggregation
B.Alerting
C.Correlation
D.Normalization
AnswerD
Normalization standardizes log data.
Why this answer
Normalization is the SIEM component that parses incoming log data from diverse sources (e.g., syslog, Windows Event Log, NetFlow) and maps the fields into a common, standardized schema. This process ensures that fields like source IP, destination IP, and timestamp are consistently named and formatted, enabling effective correlation and analysis across heterogeneous devices.
Exam trap
The trap here is that candidates confuse normalization with aggregation, thinking that simply collecting logs from multiple sources is enough to make them comparable, when in fact normalization is the crucial step that standardizes the data format.
How to eliminate wrong answers
Option A is wrong because aggregation refers to the collection and consolidation of log data from multiple sources into a central repository, not the conversion of that data into a standard format. Option B is wrong because alerting is the function that generates notifications based on predefined rules or thresholds, not the transformation of log formats. Option C is wrong because correlation involves analyzing relationships between events to identify patterns or incidents, which depends on already-normalized data.
A multinational company has a security policy that all data at rest in cloud storage must be encrypted using company-managed keys. The cloud administrator, due to performance concerns, configured server-side encryption with AWS managed keys instead. The security team discovers this during an audit. The policy does not differentiate between encryption types. The data stored includes financial records. What should the security team do?
A.Perform a risk assessment and present options to management, including the risk of not using company-managed keys.
B.Require the administrator to migrate the data to use company-managed keys immediately.
C.Accept the current configuration and update the policy to allow AWS managed keys for performance.
D.Disable the cloud storage until compliance is achieved.
AnswerA
This informs decision-makers with proper analysis.
Why this answer
A risk assessment allows the security team to evaluate the actual risk of using AWS managed keys versus company-managed keys, and then present the trade-offs to management for a decision. Option B is too disruptive without management input; Option C prematurely accepts the configuration without analysis; Option D causes unnecessary business interruption.
During a security incident, an analyst captures network traffic and observes multiple connections from an internal host to a remote IP on port 4444, with irregular packet timing and small payloads. Which type of activity is most likely indicated?
A.C2 beaconing
B.DNS tunneling
C.File transfer
D.VoIP communication
AnswerA
Beaconing involves regular small packets to a command-and-control server.
Why this answer
The observed traffic—multiple connections from an internal host to a remote IP on TCP port 4444, with irregular timing and small payloads—is a classic signature of command-and-control (C2) beaconing. Attackers often use non-standard high ports like 4444 to evade detection, and the irregular intervals (jitter) are intentionally introduced to avoid pattern-based anomaly detection, while small payloads minimize data transfer and reduce the chance of triggering network thresholds.
Exam trap
Cisco often tests the distinction between C2 beaconing and DNS tunneling by presenting port 4444 (a common C2 port) and irregular timing, hoping candidates confuse it with DNS tunneling because both can use small payloads, but DNS tunneling specifically leverages DNS protocol fields and port 53, not a direct TCP connection on a high port.
How to eliminate wrong answers
Option B (DNS tunneling) is wrong because DNS tunneling typically uses UDP port 53 and encodes data within DNS queries/responses, not direct TCP connections to port 4444 with small payloads. Option C (File transfer) is wrong because file transfers usually involve larger, consistent payload sizes and predictable timing (e.g., SMB on port 445 or FTP on port 21), not the irregular, small-payload pattern described. Option D (VoIP communication) is wrong because VoIP uses protocols like SIP (UDP 5060) or RTP (dynamic UDP ports) with real-time, steady packet flows, not irregular TCP connections to a single high port like 4444.
An organization experiences a ransomware attack where files are encrypted and a ransom is demanded. Which element of the CIA triad is most directly impacted?
A.Availability
B.Integrity
C.Non-repudiation
D.Confidentiality
AnswerA
Ransomware prevents access to data, impacting availability.
Why this answer
A ransomware attack encrypts files and demands payment, directly preventing users from accessing their data and systems. This loss of access is a direct impact on Availability, which ensures that information and resources are accessible when needed. The CIA triad's Availability element is most immediately compromised because the organization cannot retrieve or use its encrypted files.
Exam trap
Cisco often tests the distinction between Integrity and Availability by presenting a scenario where data is altered (encryption) but the primary consequence is loss of access, leading candidates to mistakenly choose Integrity because they focus on the modification rather than the resulting denial of service.
How to eliminate wrong answers
Option B is wrong because Integrity is about ensuring data has not been tampered with or altered; while ransomware does modify files by encrypting them, the primary impact is the loss of access, not the verification of data correctness. Option C is wrong because Non-repudiation refers to the ability to prove that an action or transaction occurred, typically through digital signatures or logs, which is not directly relevant to file encryption and ransom demands. Option D is wrong because Confidentiality involves protecting data from unauthorized disclosure; ransomware does not primarily expose data to unauthorized parties (unless exfiltration occurs), but rather locks authorized users out.
Which two are common techniques used in network intrusion analysis? (Choose two.)
Select 2 answers
A.Threat intelligence feeds
B.Sandboxing
C.Signature-based detection
D.Heuristic analysis
E.Anomaly-based detection
AnswersC, E
Common network intrusion detection technique.
Why this answer
Signature-based detection (C) is a core technique in network intrusion analysis where predefined patterns (signatures) of known attacks—such as specific byte sequences in a packet payload or known malicious IP addresses—are matched against network traffic. This method is highly effective for detecting known threats with low false-positive rates, as it relies on exact pattern matching rather than behavioral baselines.
Exam trap
Cisco often tests the distinction between detection techniques (signature-based and anomaly-based) and supporting tools (threat intelligence feeds, sandboxing) or host-based methods (heuristic analysis), leading candidates to incorrectly select options that are not primary network intrusion analysis techniques.
An alert shows a high volume of outbound traffic from an internal host to an external IP using FTP. The data includes files with names matching internal document names. This activity is most likely:
A.C2 beaconing
B.Normal backup operation
C.Port scanning
D.Data exfiltration
AnswerD
Large outbound FTP transfers of internal documents indicate exfiltration.
Why this answer
Exfiltration via FTP is a common technique to steal data by transferring it to an external server.
Which THREE of the following are common indicators of compromise (IOCs) that a security monitoring system might trigger on?
Select 3 answers
A.Unusual outbound network connections to unfamiliar IP addresses.
B.Packets with destination IP addresses from a threat intelligence feed.
C.High CPU usage on a server.
D.Successful logon from a domain administrator account.
E.Changes to critical system files or registry keys.
AnswersA, B, E
Common C2 indicator.
Why this answer
Unusual outbound network connections to unfamiliar IP addresses are a common indicator of compromise (IOC) because they often signal command-and-control (C2) communication, data exfiltration, or malware beaconing. Security monitoring systems analyze netflow or firewall logs to detect connections to IP addresses not in the organization's baseline or known threat intelligence feeds. This behavior deviates from normal traffic patterns and is a key trigger for alerts in SIEM or IDS/IPS systems.
Exam trap
Cisco often tests the distinction between performance metrics (like CPU usage) and true security indicators, so candidates mistakenly select high CPU usage as an IOC when it is actually a symptom that requires further investigation, not a direct compromise indicator.
Which TWO of the following are valid reasons to create an exception to a security policy? (Choose two.)
Select 2 answers
A.The employee finds the policy inconvenient.
B.The policy is too new and employees are not yet trained.
C.The employee is a senior executive.
D.A business-critical application cannot function with the policy control.
E.Temporary exception to avoid disrupting operations during a migration.
AnswersD, E
If the control breaks a critical app, a temporary exception with compensatory controls may be needed.
Why this answer
A business-critical application that cannot function with a security policy control represents a legitimate operational need that may require a temporary exception. Security policies should support business objectives, and if a control (e.g., a firewall rule, an antivirus exclusion, or an application whitelisting policy) prevents a critical application from running, an exception can be granted after a risk assessment and compensating controls are implemented. This aligns with the principle of balancing security with business continuity.
Exam trap
Cisco often tests the misconception that seniority or personal inconvenience can justify policy exceptions, but the correct reasoning must always tie back to business continuity or technical necessity, not status or preference.
An organization wants to implement a security framework that includes functions such as Identify, Protect, Detect, Respond, and Recover. Which framework aligns with this structure?
A.NIST Cybersecurity Framework
B.HIPAA Security Rule
C.PCI DSS
D.ISO 27001
AnswerA
The NIST CSF includes Identify, Protect, Detect, Respond, Recover.
Why this answer
The NIST Cybersecurity Framework is built around these five core functions.
A junior analyst reports that the network-based intrusion detection system (NIDS) has been generating alerts for a signature that detects a known exploit of a web server. The alert triggers on every connection to the company's internal web server over port 80. The analyst has verified that the web server is fully patched and the traffic is normal HTTP requests. The analyst asks you for advice. What should you recommend as the first step?
A.Verify that the web server is fully patched and configure a patch management system.
B.Reconfigure the web server to use a non-standard port.
C.Run a packet capture to analyze the HTTP requests.
D.Disable the specific signature for the web server's IP address in the IDS.
AnswerD
This reduces false positives while keeping detection for other servers.
Why this answer
The NIDS is generating false positives: the signature matches normal HTTP traffic to a fully patched web server. Disabling the signature for that specific IP address eliminates the noise without compromising security, as the server is not vulnerable to the exploit. This is a standard tuning action in intrusion detection to reduce alert fatigue while maintaining coverage for other hosts.
Exam trap
Cisco often tests the candidate's ability to distinguish between a true positive and a false positive, and the trap here is that candidates may choose to investigate further (Option C) or apply a security fix (Option A) instead of recognizing that the immediate priority is to tune the IDS to reduce alert noise.
How to eliminate wrong answers
Option A is wrong because the analyst has already verified the web server is fully patched; re-verifying and configuring a patch management system does not address the false positive alerts from the NIDS. Option B is wrong because changing the web server to a non-standard port is an unnecessary workaround that can break client configurations and does not solve the root cause of the signature triggering on legitimate HTTP traffic. Option C is wrong because running a packet capture to analyze HTTP requests is an investigative step that may be useful later, but it is not the first step; the analyst already confirmed the traffic is normal HTTP requests, so capturing packets adds delay without addressing the immediate false positive issue.
Which TWO of the following are common sources of security events used in security monitoring?
Select 2 answers
A.Employee attendance records
B.Firewall logs
C.Marketing campaign results
D.Company newsletter subscriptions
E.DNS query logs
AnswersB, E
Firewall logs provide information on allowed and denied connections.
Why this answer
Firewall logs (B) are a primary source of security events because they record allowed and denied traffic based on access control lists (ACLs), providing critical data on attempted intrusions, policy violations, and reconnaissance scans. DNS query logs (E) are equally vital as they capture domain resolution requests, enabling detection of malware command-and-control (C2) communication, DNS tunneling, and connections to known malicious domains. Both are standard inputs for SIEM systems and security monitoring platforms.
Exam trap
Cisco often tests the distinction between operational business data (HR, marketing) and actual security telemetry sources, expecting candidates to recognize that only logs from network infrastructure (firewalls, DNS servers, IDS/IPS) generate actionable security events.
During a security awareness training session, an employee reports they clicked a link in a phishing email but did not enter credentials. Which policy violation is most likely involved?
A.Data classification policy
B.Acceptable use policy
C.Incident reporting policy
D.Password policy
AnswerC
Employees should report suspicious activity; failing to do so is a policy violation.
Why this answer
Clicking a suspected phishing link without reporting it violates the incident reporting policy. Option A is wrong because the employee did not enter credentials, so password policy is intact. Option B is wrong because the link itself is not necessarily prohibited by AUP unless it involves inappropriate content.
Option D is wrong because data classification policy is about handling data, not email links.
During a penetration test, a security engineer uses publicly available information from LinkedIn and Google to gather details about employees and organizational structure. Which type of reconnaissance is being performed?
A.Active reconnaissance
B.Social engineering
C.Passive reconnaissance
D.Internal reconnaissance
AnswerC
Using public sources like LinkedIn and Google without touching the target's systems is passive.
Why this answer
The security engineer is gathering information from publicly available sources (LinkedIn, Google) without directly interacting with the target's systems. This is the definition of passive reconnaissance, which involves collecting data from open-source intelligence (OSINT) without sending any packets to the target network.
Exam trap
Cisco often tests the distinction between active and passive reconnaissance by describing an activity that uses public sources but might seem 'active' to a novice; the trap here is confusing passive information gathering with active scanning or social engineering.
How to eliminate wrong answers
Option A is wrong because active reconnaissance involves direct interaction with the target, such as sending probes, scans, or packets (e.g., using Nmap or ping sweeps), which is not described here. Option B is wrong because social engineering involves manipulating people to divulge confidential information, not simply collecting publicly available data from websites. Option D is wrong because internal reconnaissance is performed from within the target's network, often after gaining initial access, whereas this activity occurs externally using public sources.
A SOC analyst is investigating a web server log and sees the following entry: 192.168.1.10 - - [15/May/2023:10:15:30 +0000] 'POST /login.php HTTP/1.1' 200 1245 'http://example.com/login.php' 'Mozilla/5.0'. Which observation is most suspicious?
Correct. The 200 response code indicates a successful login, which is the most suspicious observation because it could represent the successful culmination of a brute-force attack.
Why this answer
The log entry shows a successful HTTP 200 response to a POST request to a login page. While a single 200 is normal, it is the most suspicious observation among the options because it indicates a successful login, which could be part of a brute force or credential stuffing attack if many attempts preceded it. The correct answer is A.
Exam trap
Candidates may dismiss the 200 response code as normal, but in a security context, a successful login from an internal IP could be the result of a brute-force attack, making it the most suspicious element in a single log entry.
A large e-commerce company experiences a data breach where customer credit card numbers are stolen. The investigation reveals that an attacker exploited a SQL injection vulnerability in the web application to extract the data from the database. The company's web development team claims they use parameterized queries and prepared statements. However, the forensic analysis shows that the injection occurred through a search functionality that concatenates user input directly into the SQL query. The application logs indicate that the search function was developed by a third-party vendor and integrated into the application six months ago. The company wants to prevent such incidents in the future. Which of the following is the most effective long-term solution?
A.Replace the third-party search module with a custom-developed one.
B.Establish a secure software development lifecycle (SSDLC) that includes security reviews for all third-party components.
C.Implement a web application firewall (WAF) with OWASP rules.
D.Conduct regular vulnerability scans and patch management.
AnswerB
An SSDLC integrates security into every phase of development, preventing vulnerabilities from being introduced in the first place.
Why this answer
The root cause is a failure in the security review process for third-party components. Even though the company uses parameterized queries elsewhere, the third-party search module concatenates user input directly into SQL queries, bypassing that protection. Establishing an SSDLC with mandatory security reviews for all third-party components ensures that such vulnerabilities are caught before integration, addressing the process gap rather than just the symptom.
Exam trap
Cisco often tests the distinction between reactive controls (WAF, patching) and proactive process improvements (SSDLC), leading candidates to choose a technical fix like a WAF instead of addressing the root cause of insecure third-party code integration.
How to eliminate wrong answers
Option A is wrong because simply replacing the third-party module with a custom-developed one does not guarantee security; the custom code could also contain SQL injection flaws if not developed under secure coding practices. Option C is wrong because a WAF is a reactive, signature-based control that can be bypassed by sophisticated SQL injection payloads (e.g., using encoding or obfuscation) and does not fix the underlying insecure code. Option D is wrong because vulnerability scans and patch management are point-in-time checks that may miss logic flaws like SQL injection in custom or third-party code, and they do not enforce secure coding or review processes.
A security analyst is configuring a new SIEM platform. The organization has multiple log sources, including Windows Event Logs, Linux syslog, and firewall logs. The analyst wants to ensure that logs are not lost if the SIEM becomes unavailable. Which approach best addresses this requirement?
A.Configure the SIEM to pull logs from sources via Syslog over TCP.
B.Configure log sources to send logs to a centralized collector with local storage and forwarding capabilities.
C.Implement log replication between SIEM nodes.
D.Increase the storage capacity of the SIEM to hold more logs.
AnswerB
Collector can buffer logs and forward when SIEM recovers.
Why this answer
Deploying a centralized collector with local storage and forwarding capabilities creates a buffer that ensures logs are not lost during SIEM unavailability. The collector receives logs from sources, stores them locally (e.g., on disk or in a queue), and forwards them to the SIEM when it becomes available again. This decouples log generation from SIEM ingestion, preventing data loss even during extended outages.
Exam trap
Cisco often tests the distinction between reliable transport (TCP) and guaranteed delivery with buffering; the trap here is assuming that Syslog over TCP alone prevents data loss, when in fact it only ensures in-transit reliability, not resilience against SIEM unavailability.
How to eliminate wrong answers
Option A is wrong because Syslog over TCP provides reliable delivery only if the SIEM is reachable; if the SIEM goes down, the TCP connection fails and logs are dropped (unless the source has its own buffering, which is not guaranteed). Option C is wrong because log replication between SIEM nodes addresses high availability and redundancy of the SIEM itself, but does not protect against data loss if all SIEM nodes become unavailable simultaneously. Option D is wrong because increasing SIEM storage capacity only helps retain more logs once they are ingested; it does nothing to prevent loss during an outage when logs cannot be received.
A Linux host has an unusual cron job that runs a script from /tmp every minute. The analyst checks /etc/crontab and /var/spool/cron/ but finds nothing. Where else could the cron job be defined?
A./etc/cron.d/
B./etc/cron.hourly/
C./etc/cron.allow
D.~/.bashrc
AnswerA
This directory contains per-package cron definitions.
Why this answer
The cron job is defined in /etc/cron.d/ because this directory allows system administrators to drop individual cron configuration files that are parsed by the cron daemon. Unlike /etc/crontab and /var/spool/cron/ (which contain user-specific crontabs), /etc/cron.d/ is a standard location for package-maintained or custom cron jobs that run with system privileges. The fact that the analyst found nothing in the other two locations strongly suggests the job is defined in /etc/cron.d/.
Exam trap
Cisco often tests the distinction between cron configuration directories and control files, trapping candidates who confuse /etc/cron.allow (an access control list) with a location where cron jobs are actually defined.
How to eliminate wrong answers
Option B is wrong because /etc/cron.hourly/ is a directory for scripts that run on an hourly schedule, not for defining arbitrary cron jobs with specific minute-level intervals; it uses run-parts and does not support custom cron syntax like 'every minute'. Option C is wrong because /etc/cron.allow is a control file that lists users allowed to use cron, not a location where cron jobs are defined. Option D is wrong because ~/.bashrc is a shell initialization script executed for interactive login shells, not a cron configuration file; cron jobs cannot be defined there.
A security analyst is analyzing system logs and notices multiple failed authentication events followed by a successful login from the same user account, and then a privilege escalation event. Which THREE events should be correlated to detect a potential attack?
Select 3 answers
A.Successful authentication event
B.Privilege escalation event
C.Failed authentication events
D.Network share access event
E.Account creation event
AnswersA, B, C
The success after failures indicates the attacker gained access.
Why this answer
A successful authentication event following multiple failed attempts is a key indicator of a brute-force or password-spraying attack. The analyst must correlate the failed attempts with the eventual success to identify that the attacker gained access after guessing or cracking the credentials.
Exam trap
Cisco often tests the concept that a single successful login alone is not suspicious, but when combined with preceding failed attempts and subsequent privilege escalation, it forms a clear attack pattern that candidates must recognize as a three-event correlation.
An analyst observes that an internal host is sending ICMP echo requests with payloads containing random data to an external IP. The payload size is larger than typical. What is the most likely technique?
A.Ping of death
B.Traceroute
C.Smurf attack
D.ICMP tunneling
AnswerD
ICMP tunneling uses the payload of ICMP packets for covert communication.
Why this answer
ICMP tunneling encapsulates non-ICMP data (e.g., command-and-control traffic) within ICMP echo request/reply packets. The random payload data and larger-than-typical payload size are hallmarks of this technique, as the attacker uses the ICMP protocol to bypass firewalls and exfiltrate data or establish covert communication.
Exam trap
Cisco often tests the distinction between attacks that exploit ICMP for denial of service (e.g., ping of death, Smurf) versus those that use ICMP for covert data transfer (ICMP tunneling), so candidates must focus on the presence of random payload data rather than just the protocol or packet size.
How to eliminate wrong answers
Option A is wrong because a ping of death exploits a buffer overflow by sending an oversized ICMP packet (typically >65535 bytes) to crash the target, not by using random data in normal-sized payloads. Option B is wrong because traceroute uses ICMP echo requests with varying TTL values to map network hops, not random payloads or large payload sizes. Option C is wrong because a Smurf attack sends ICMP echo requests to a broadcast address with a spoofed source IP, causing amplification, not random data in the payload.
Which TWO of the following are key components of a security policy framework according to Cisco? (Choose two.)
Select 2 answers
A.Guidelines
B.Standards
C.Incident Response Plan
D.Audit Logs
E.Firewalls
AnswersA, B
Guidelines offer best practices for policies.
Why this answer
In Cisco's security policy framework, guidelines and standards are foundational components. Guidelines offer recommended practices and flexible advice for implementing security controls, while standards define mandatory, specific technical requirements (e.g., encryption algorithms, password complexity) that must be followed. Together, they provide the structure for consistent security enforcement across an organization.
Exam trap
Cisco often tests the distinction between policy framework components (guidelines, standards) and operational or technical elements (incident response plans, audit logs, firewalls), leading candidates to confuse procedural or tool-based answers with the written policy structure.
A security policy mandates that all administrative access to network devices must be encrypted. Which of the following protocols should be used to comply with this policy?
A.Telnet
B.SSH
C.TFTP
D.SNMPv2c
AnswerB
SSH provides strong encryption for remote administrative sessions, ensuring compliance.
Why this answer
SSH (Secure Shell) encrypts all traffic, including authentication credentials and commands, between an administrator and a network device. This satisfies the policy requirement for encrypted administrative access, unlike Telnet which sends everything in plaintext.
Exam trap
Cisco often tests the misconception that Telnet is acceptable if a password is set, but the trap is that Telnet never encrypts the session, so it fails any policy requiring encryption regardless of authentication.
How to eliminate wrong answers
Option A is wrong because Telnet transmits data, including usernames and passwords, in cleartext, violating the encryption mandate. Option C is wrong because TFTP (Trivial File Transfer Protocol) is used for file transfers, not interactive administrative access, and it lacks any encryption or authentication. Option D is wrong because SNMPv2c uses community strings in plaintext for authentication and does not provide encryption for administrative sessions; it is a network management protocol, not a remote access protocol.
An analyst is reviewing alerts from an IDS. A signature matched 'script' and 'alert' in HTTP request parameters. The analyst inspects the packet and sees <script>alert('XSS')</script> in the URI. What is the most accurate classification of this alert?
A.False negative
B.False positive
C.True negative
D.True positive
AnswerD
The attack payload is present, confirming a real attack.
Why this answer
The alert corresponds to a real attack (cross-site scripting) in the traffic, so it is a true positive.
A security analyst is monitoring network traffic and notices a high volume of TCP SYN packets sent to various ports on a single host. Which type of attack is most likely occurring?
A.DNS amplification
B.Smurf attack
C.Port scan
D.ARP spoofing
AnswerC
Port scans send SYN packets to various ports to identify open services.
Why this answer
A port scan uses TCP SYN packets to probe for open ports on a target host. Excessive SYN packets to multiple ports indicate a port scan.
Which TWO of the following are valid sources of security monitoring data in a Cisco security architecture?
Select 2 answers
A.RADIUS accounting
B.SNMP traps
C.Syslog messages
D.WMI queries
E.NetFlow records
AnswersC, E
Syslog is a standard for security event logging.
Why this answer
Syslog messages (C) are a standard protocol for logging events from network devices, servers, and applications, making them a primary source of security monitoring data. NetFlow records (E) provide IP traffic flow statistics, enabling network behavior analysis and anomaly detection. Both are explicitly listed as valid data sources in Cisco's security monitoring architecture.
Exam trap
Cisco often tests the distinction between data sources used for security monitoring (Syslog, NetFlow) versus management or authentication protocols (RADIUS, SNMP, WMI), leading candidates to confuse RADIUS accounting or SNMP traps as valid monitoring inputs.
During a security incident, an analyst uses Wireshark to examine a pcap. The TCP stream shows the string 'GET /malware.exe HTTP/1.1'. Which is the most likely type of attack?
A.Cross-site scripting
B.Trojan download
C.Directory traversal
D.SQL injection
AnswerB
Request to download an executable is typical of malware delivery.
Why this answer
The TCP stream shows an HTTP GET request for a file named 'malware.exe', which indicates the client is downloading an executable from a server. This is characteristic of a Trojan download attack, where a user is tricked into downloading and executing malicious software, often disguised as a legitimate file. The use of Wireshark to capture the HTTP request confirms the network-level activity of a file transfer, aligning with the Trojan's delivery mechanism.
Exam trap
Cisco often tests the distinction between attack types based on the specific HTTP method and payload; the trap here is that candidates may confuse a simple file download with injection-based attacks like XSS or SQLi, overlooking that the GET request for an executable directly indicates a Trojan download rather than an injection vector.
How to eliminate wrong answers
Option A is wrong because cross-site scripting (XSS) involves injecting malicious scripts into web pages, typically via parameters in HTTP requests or responses, not a direct GET request for an executable file. Option C is wrong because directory traversal attacks exploit path manipulation (e.g., '../') to access restricted files, not a straightforward download of a named executable. Option D is wrong because SQL injection targets database queries through input fields (e.g., in POST data or URL parameters), not a simple GET request for a static file.
A company's security policy requires that all laptops accessing the corporate network must have full-disk encryption enabled. During a routine audit, an analyst discovers that a manager's laptop does not have encryption enabled. What is the most appropriate first step according to standard security incident response procedures?
A.Disconnect the laptop from the network immediately.
B.Document the finding and escalate to the incident response team.
C.Install encryption software on the laptop without notifying the user.
D.Wipe the laptop and reinstall the operating system.
AnswerB
Proper procedure is to document and escalate; the IR team will handle remediation.
Why this answer
The first step in standard incident response procedures (as defined by NIST SP 800-61 and Cisco's IR framework) is to document the finding and escalate to the incident response team. This ensures that the potential policy violation is formally recorded and that trained responders can assess the risk, determine if sensitive data was exposed, and coordinate remediation without prematurely destroying evidence or causing operational disruption.
Exam trap
Cisco often tests the distinction between 'immediate containment' and 'proper escalation' in incident response, trapping candidates who confuse a policy violation with an active security breach requiring urgent network disconnection.
How to eliminate wrong answers
Option A is wrong because immediately disconnecting the laptop from the network is a reactive containment step that should only be taken after the incident response team has assessed the situation; doing so prematurely could destroy volatile evidence (e.g., active network connections, running processes) and disrupt legitimate business operations. Option C is wrong because installing encryption software without notifying the user violates change management policies and could overwrite existing data or trigger unintended system behavior, bypassing proper authorization and documentation. Option D is wrong because wiping the laptop and reinstalling the OS is a destructive remediation step that destroys all forensic evidence and should only be performed after a full investigation and data preservation have been completed.
A.A TCP connection from outside to inside was denied.
B.A TCP connection from inside to outside was denied.
C.The access group name is incorrect.
D.A TCP connection was allowed from inside to outside.
AnswerA
The source is outside and destination inside, and it was denied.
Why this answer
The syslog message indicates that a TCP connection attempt from an outside (lower-security) zone to an inside (higher-security) zone was denied by the ASA's implicit or explicit access control. By default, the Cisco ASA denies all inbound traffic from a lower security level to a higher security level unless explicitly permitted by an access-list applied to the interface. The message 'denied' confirms the packet was dropped, not allowed.
Exam trap
Cisco often tests the default security-level behavior of the ASA, where candidates mistakenly assume that all denied traffic is from inside to outside, or that the message indicates an error in the access group name rather than a simple deny action.
How to eliminate wrong answers
Option B is wrong because the message specifies 'outside to inside' (inbound), not 'inside to outside' (outbound). Option C is wrong because the syslog message does not reference an access group name or any configuration error; it simply reports a denied connection. Option D is wrong because the message explicitly states 'denied', not 'allowed', and the direction is outside to inside, not inside to outside.
A company's security policy includes a clause that all software installed on company devices must be approved by the IT department. An employee installs an unapproved application that later causes a malware infection. Which policy was violated?
A.Incident Response Policy
B.Acceptable Use Policy
C.Data Retention Policy
D.Remote Access Policy
AnswerB
Software installation rules are part of acceptable use.
Why this answer
The Acceptable Use Policy (AUP) defines what activities and software are permitted on company devices. By installing an unapproved application without IT authorization, the employee violated the AUP, which directly led to the malware infection. This policy is the primary control for preventing unauthorized software installations that bypass security baselines.
Exam trap
Cisco often tests the distinction between a proactive policy (AUP) that prevents unauthorized actions and a reactive policy (Incident Response) that handles the aftermath, causing candidates to confuse the policy that was violated with the policy that describes the response to the violation.
How to eliminate wrong answers
Option A is wrong because the Incident Response Policy governs the procedures for detecting, containing, and remediating security incidents after they occur, not the prohibition of unauthorized software installations. Option C is wrong because the Data Retention Policy specifies how long data must be kept and when it should be deleted, and has no relation to software installation approvals. Option D is wrong because the Remote Access Policy controls how external users connect to the internal network (e.g., VPN authentication, split tunneling rules), not the installation of local applications.
An analyst is investigating a host that was compromised via a web exploit. The analyst has a pcap file of the network traffic. Which TWO pieces of evidence would indicate that the attacker established a persistent backdoor?
Select 2 answers
A.A single large file upload to a cloud service
B.Regular beaconing to an external IP on a high port
C.A change in the host's registry
D.An SSH connection from an external IP
E.DNS queries with subdomains that encode data
AnswersB, E
Regular beaconing is a hallmark of persistent C2 communication, indicating a backdoor that periodically checks in.
Why this answer
Regular beaconing to an external IP on a high port (Option B) is a classic indicator of a persistent backdoor because the compromised host periodically initiates outbound connections to a command-and-control (C2) server, often using non-standard high ports (e.g., 4444, 8080, or 1337) to evade firewall rules. This behavior maintains a communication channel that allows the attacker to issue commands or exfiltrate data over time, even if the initial exploit vector is patched.
Exam trap
Cisco often tests the distinction between network-based evidence (pcap) and host-based evidence (registry changes), so candidates may incorrectly select Option C because they confuse persistence mechanisms with the type of data available in a packet capture.
During a security incident, the CISO decides to contain a compromised server by isolating it from the network. Which role is primarily responsible for making this containment decision based on business impact?
A.CISO
B.Incident handler
C.Legal counsel
D.PR representative
AnswerA
The CISO evaluates business impact and authorizes containment.
Why this answer
The CISO is the decision-maker for business impact and authorizes containment actions.
An analyst is reviewing a memory dump using Volatility. They want to identify processes with potential code injection. Which TWO Volatility plugins would be most appropriate for detecting injected code?
Select 2 answers
A.cmdline
B.dlllist
C.netscan
D.pslist
E.malfind
AnswersB, E
Correct. dlllist can show unusual DLLs that may indicate injection.
Why this answer
malfind scans for injected code by finding memory regions with suspicious permissions (e.g., RWX). dlllist lists loaded DLLs, and ldrmodules can find hidden or suspicious modules.
Which THREE are typical sources of log data used in security monitoring? (Choose three.)
Select 3 answers
A.Printer spool logs.
B.HVAC system logs.
C.Windows Event Logs.
D.Firewall logs.
E.DNS server logs.
AnswersC, D, E
Contain authentication and system events.
Why this answer
Windows Event Logs are a primary source of security monitoring data because they record critical security events such as logon attempts, account changes, and process creation (Event IDs 4624, 4625, 4688). Security Information and Event Management (SIEM) systems ingest these logs to detect unauthorized access, privilege escalation, and malware execution.
Exam trap
Cisco often tests the distinction between logs that are security-relevant versus operational or environmental logs, so candidates mistakenly choose printer or HVAC logs because they are 'logs' in a general sense, but they lack the authentication, network, or system event data required for security monitoring.
A network security monitoring analyst is analyzing firewall logs and sees the following traffic: Source IP 10.1.1.50 to Destination IP 203.0.113.5 on port 443, protocol TCP, with a large amount of data transferred in both directions during business hours. The analyst suspects data exfiltration. Which TWO additional indicators would most strongly support this suspicion? (Choose two.)
Select 2 answers
A.The traffic uses TLS encryption with a self-signed certificate.
B.The destination IP belongs to a cloud storage provider commonly used for backups.
C.The data transfer rate is consistently high for several hours.
D.The destination port is used by a well-known web service.
E.The source IP has never communicated with this destination IP before.
AnswersA, E
Self-signed certificates in data transfers can indicate attempts to hide exfiltration.
Why this answer
A self-signed TLS certificate is often used by attackers to encrypt exfiltrated data without the overhead of obtaining a legitimate certificate from a trusted CA. Legitimate services typically use certificates signed by a recognized CA, so a self-signed certificate in traffic to an external IP on port 443 is a strong indicator of malicious activity, especially when combined with large data transfers.
Exam trap
Cisco often tests the misconception that any encrypted traffic or high data transfer is automatically suspicious, when in fact the context of the certificate type and communication history is what distinguishes malicious exfiltration from legitimate business use.
During an incident, a first responder pulls the network cable of a compromised server. Later, the incident response team is unable to collect volatile data such as running processes. Which policy or procedure was violated?
A.Chain of Custody Procedure
B.Incident Response Procedure for evidence preservation
C.Forensic Analysis Procedure
D.Escalation Procedure
AnswerB
Immediate disconnection prevented capture of volatile data.
Why this answer
Incident response procedures typically require preserving volatile data before disconnecting the system. By pulling the network cable first, the first responder violated the evidence preservation steps, making option B the correct answer.
A SOC analyst reviews a firewall log with the following entry: action=deny, source IP=192.168.1.100, destination IP=10.0.0.1, destination port=22. The analyst knows that 10.0.0.1 is an SSH server. What does this log entry indicate?
A.A DNS query resolved to 10.0.0.1
B.An attempted SSH connection that was blocked by the firewall
C.A successful SSH connection from 192.168.1.100 to 10.0.0.1
D.A misconfigured firewall allowing SSH traffic
AnswerB
Deny action indicates the firewall blocked the packet.
Why this answer
The log entry shows 'action=deny', which explicitly indicates the firewall blocked the packet. Since destination port 22 is the default port for SSH, this log entry represents an attempted SSH connection from 192.168.1.100 to 10.0.0.1 that was denied by the firewall. The analyst's knowledge that 10.0.0.1 is an SSH server confirms the nature of the traffic.
Exam trap
Cisco often tests the ability to read a firewall log entry literally—candidates may overlook the 'action=deny' field and incorrectly assume any connection attempt to port 22 is automatically successful or that the firewall is misconfigured.
How to eliminate wrong answers
Option A is wrong because DNS queries use UDP or TCP port 53, not TCP port 22, and the log shows a destination port of 22, which is SSH, not DNS. Option C is wrong because the 'action=deny' field means the connection was blocked, not successful; a successful connection would show 'action=allow' or 'action=permit'. Option D is wrong because the firewall is correctly enforcing a deny rule for SSH traffic to 10.0.0.1, which is the opposite of a misconfiguration allowing SSH traffic.
Which two pieces of evidence are strong indicators of compromise (IOC) in network traffic?
Select 2 answers
A.Communication with a known malicious IP address
B.Encrypted traffic using unrecognized SSL certificates
C.Regular DNS queries to corporate DNS servers
D.Normal SMTP traffic to internal mail server
E.Standard HTTP traffic to a known content delivery network
AnswersA, B
Malicious IPs are direct IOCs.
Why this answer
Communication with a known malicious IP address is a strong indicator of compromise because it directly suggests the host is interacting with a command-and-control (C2) server or a malware distribution point. Threat intelligence feeds and blocklists (e.g., AlienVault OTX, MISP) provide curated lists of known malicious IPs; matching traffic to these lists provides high-fidelity evidence of an active compromise.
Exam trap
Cisco often tests the distinction between 'normal' traffic and 'anomalous' traffic, and the trap here is that candidates may mistake encrypted traffic (Option B) as always suspicious, but the question asks for 'strong indicators' — and unrecognized SSL certificates are indeed a strong IOC, while regular DNS, SMTP, and CDN traffic are not.