Courseiva

Cisco CyberOps Associate 200-201 (200-201) — Questions 226–300

968 questions total · 13pages · All types, answers revealed

Page 3

Page 4 of 13

Page 5
226
MCQeasy

Which element of the CIA triad ensures that data cannot be modified by unauthorized parties?

A.Availability
B.Non-repudiation
C.Integrity
D.Confidentiality
AnswerC

Integrity guarantees data remains accurate and unaltered unless changed by authorised parties. Hashing, checksums and digital signatures detect unauthorised modification, directly satisfying the requirement that data cannot be modified by unauthorised parties, unlike confidentiality or availability controls.

Why this answer

Integrity is the CIA triad element that ensures data has not been altered or tampered with by unauthorized parties. It guarantees that information remains accurate, complete, and trustworthy throughout its lifecycle, typically enforced through hashing, checksums, digital signatures, and access controls.

Exam trap

The trap is mixing up confidentiality and integrity — candidates often think 'unauthorized parties' implies confidentiality, but the question specifically says 'cannot be modified,' which is integrity, not secrecy.

How to eliminate wrong answers

Option A is wrong because availability ensures that data and systems are accessible to authorized users when needed, not that data is unmodified. Option B is wrong because non-repudiation ensures that a party cannot deny the authenticity of their signature or the sending of a message — it is related to accountability, not data modification. Option D is wrong because confidentiality ensures that data is only accessible to authorized parties, preventing unauthorized disclosure, but it does not address modification.

227
Multi-Selecteasy

A company needs to comply with regulations that protect personal data of EU citizens. Which TWO compliance frameworks are directly relevant to this requirement? (Choose two.)

Select 1 answer
A.PCI DSS
B.GDPR
C.ISO 27001
D.NIST Cybersecurity Framework
E.HIPAA
AnswersB

GDPR is the EU regulation governing protection of personal data of EU citizens, imposing lawful processing, consent and breach-notification duties. It directly satisfies the stem's requirement for a compliance framework relevant to safeguarding EU citizens' personal data.

Why this answer

GDPR (B) is directly relevant because the General Data Protection Regulation is the EU legal framework that governs the protection of personal data of EU citizens, imposing requirements on data controllers and processors regarding consent, data subject rights, breach notification, and cross-border transfers. ISO 27001 (C) is not correct because it is a voluntary international standard for establishing an Information Security Management System (ISMS), not a regulation that directly protects EU citizens' personal data. PCI DSS (A) is not correct because it applies specifically to organizations that store, process, or transmit cardholder data (payment card information), not to personal data of EU citizens generally.

NIST Cybersecurity Framework (D) is not correct because it is a voluntary US-origin framework for managing cybersecurity risk rather than a data protection regulation aimed at EU personal data. HIPAA (E) is not correct because it governs protected health information in the United States, not the personal data of EU citizens.

Exam trap

200-201 often tests the confusion between general security frameworks and specific regulations; candidates may incorrectly select NIST, PCI DSS, or ISO 27001 when asked about EU personal data protection.

228
MCQmedium

A security analyst is reviewing Windows Event Logs on a domain controller. The analyst sees multiple Event ID 4769 (Kerberos service ticket was requested) with the same user account but different service names, occurring in a short time frame. Which of the following attacks is MOST likely indicated?

A.Kerberoasting
B.Golden Ticket
C.Pass-the-Hash
D.DCSync
AnswerA

Kerberoasting involves requesting Kerberos service tickets (TGS) for service accounts and cracking them offline. Event ID 4769 is logged when a TGS is requested. Multiple requests for different services in a short time by the same user is a classic sign. The attacker then extracts the ticket and attempts to crack the service account's password.

Why this answer

Kerberoasting is an attack where an adversary requests Kerberos service tickets for service accounts and then cracks them offline. Event ID 4769 is generated for each TGS request. A burst of 4769 events with different service names from the same user is a strong indicator.

Monitoring for such patterns helps detect Kerberoasting attempts.

Exam trap

The trap here is confusing Kerberoasting with other Kerberos attacks; 4769 specifically logs service ticket requests, which are central to Kerberoasting, not Golden Ticket or DCSync.

229
MCQeasy

A security analyst notices a sudden spike in NetFlow data from a single workstation to multiple external IP addresses on port 443. What is the most likely explanation for this traffic pattern?

A.Internal network scanning
B.Normal web browsing activity
C.Potential data exfiltration
D.A scheduled software update
AnswerC

Outbound connections to many external hosts on port 443, with a sharp NetFlow volume increase, match data exfiltration over HTTPS: stolen data is tunnelled through encrypted web traffic to attacker-controlled endpoints, evading content inspection. The single-workstation-to-multiple-destinations fan-out distinguishes it from normal browsing or a single command-and-control channel.

Why this answer

A single workstation sending a sudden spike of NetFlow data to multiple external IP addresses on port 443 (HTTPS) is a classic indicator of data exfiltration. Attackers often encrypt stolen data in HTTPS tunnels to evade detection, and the abrupt increase in outbound connections to many distinct external hosts is not typical of normal user behavior. NetFlow records showing a high volume of flows from one source to many destinations on the same port strongly suggest an automated process, such as a data theft tool, rather than legitimate traffic.

Exam trap

Cisco often tests the misconception that any HTTPS traffic is benign, but the trap here is that a sudden spike in outbound HTTPS flows from a single source to many external IPs is abnormal and indicates data exfiltration, not normal web browsing.

How to eliminate wrong answers

Option A is wrong because internal network scanning would target internal IP addresses, not external IP addresses, and would typically use ports like ICMP or TCP 445/3389, not exclusively port 443. Option B is wrong because normal web browsing activity is distributed across many users and times, not a sudden spike from a single workstation to multiple external IPs; a single user's browsing would not generate a sharp, sustained increase in NetFlow data volume. Option D is wrong because a scheduled software update usually contacts a single or few known update servers (e.g., Microsoft or Adobe CDNs), not multiple random external IPs, and updates typically use HTTP/HTTPS but with predictable patterns and destinations.

230
Multi-Selecteasy

A security policy requires that employees use strong passwords. Which TWO of the following are characteristics of a strong password? (Select two.)

Select 2 answers
A.Uses a mix of uppercase, lowercase, numbers, and special characters
B.Is changed every 90 days
C.Is a common dictionary word
D.Contains the user's username
E.At least 8 characters
AnswersA, E

Complexity across character classes directly satisfies the policy's strength requirement: combining uppercase, lowercase, digits and symbols expands the search space an attacker must exhaust, defeating brute-force and dictionary attacks. Length alone is insufficient if the password remains a single-case dictionary word, so this mixed composition is a defining characteristic of strong passwords.

Why this answer

Option A is correct because a strong password uses complexity — a mix of uppercase letters, lowercase letters, digits, and special characters — which increases the search space and makes brute-force and dictionary attacks far less likely to succeed. Option E is correct because length is a primary strength factor; a minimum of at least 8 characters provides enough entropy to resist rapid guessing, and longer passwords are even stronger. Option B does not belong because a 90-day rotation schedule is a password-expiration/aging policy, not an inherent characteristic of the password's strength itself, and frequent forced changes can even lead to weaker, predictable patterns.

Option C is wrong because a common dictionary word is trivially defeated by dictionary and hybrid attacks. Option D is wrong because including the username makes the password guessable and violates the principle of not deriving credentials from publicly known identifiers.

Exam trap

Cisco often tests the distinction between password policy requirements (like expiration intervals) and intrinsic password strength characteristics, leading candidates to mistakenly select 'changed every 90 days' as a strength attribute.

231
MCQmedium

A network engineer configures a SPAN port to send traffic from a critical server to an IDS. After configuration, the IDS sees no traffic. What is the most likely issue?

A.The IDS is in a different subnet.
B.The monitor session source interface is incorrectly specified.
C.The SPAN destination interface is not connected to the IDS.
D.The server is using VLAN tagging.
AnswerB

A SPAN session only mirrors traffic when its source interface matches the actual ingress or egress port carrying the server's frames. If the source is misconfigured, the switch replicates nothing, so the IDS receives no packets despite the destination being reachable.

Why this answer

The most likely issue is that the monitor session source interface is incorrectly specified. SPAN (Switched Port Analyzer) requires the engineer to designate the correct source interface (the port connected to the critical server) and a destination interface (the port connected to the IDS). If the source interface is misconfigured—for example, pointing to the wrong switch port or using a VLAN instead of a specific port—the IDS will receive no mirrored traffic.

This is a common configuration error when setting up local SPAN on Cisco switches.

Exam trap

Cisco often tests the distinction between source and destination misconfiguration in SPAN, trapping candidates who assume the IDS must be in the same subnet (Option A) or that VLAN tagging (Option D) would block mirrored traffic, when the real issue is an incorrect source interface specification.

How to eliminate wrong answers

Option A is wrong because the IDS being in a different subnet does not prevent SPAN from sending traffic to it; SPAN operates at Layer 2 and forwards frames regardless of IP subnet, as long as the destination interface is correctly connected and configured. Option C is wrong because if the SPAN destination interface were not connected to the IDS, the IDS would not be physically linked, which would be a cabling or connectivity issue, but the question states the IDS sees no traffic, implying a configuration problem rather than a physical disconnection. Option D is wrong because VLAN tagging on the server does not inherently block SPAN; SPAN can copy tagged frames, and the IDS would still see them if the source interface is correctly specified and the destination interface is configured to accept tagged traffic.

232
MCQeasy

A company wants to protect its internal network from external threats. Which security principle involves deploying multiple layers of security controls?

A.Least privilege
B.Defense in depth
C.Risk management
D.Separation of duties
AnswerB

Defense in depth satisfies the requirement by layering independent controls—firewalls, segmentation, endpoint protection and identity checks—so no single failure exposes the internal network. Each layer targets a different attack vector, meaning an external threat must defeat several controls in sequence, which directly matches the stem's demand for multiple layers.

Why this answer

Defense in depth (option B) is the correct answer because it describes the strategy of layering independent security controls—such as firewalls, intrusion prevention systems (IPS), endpoint protection, and access controls—so that if one layer fails, another can still block or mitigate an attack. This principle ensures that no single point of failure can compromise the entire network, which is essential for protecting internal assets from external threats.

Exam trap

Cisco often tests the distinction between a broad security strategy (defense in depth) and a specific access control principle (least privilege), so candidates mistakenly choose least privilege when they see 'multiple layers' because they confuse 'layers of permissions' with 'layers of controls.'

How to eliminate wrong answers

Option A (Least privilege) is wrong because it focuses on granting users only the minimum permissions needed to perform their tasks, not on deploying multiple layers of security controls. Option C (Risk management) is wrong because it is a broader process of identifying, assessing, and prioritizing risks, not a specific design principle for implementing layered defenses. Option D (Separation of duties) is wrong because it prevents fraud or error by dividing critical tasks among multiple individuals, which is an administrative control, not a technical architecture for layered security.

233
MCQmedium

A host-based analysis tool reports that a file has a digital signature that is valid but from an untrusted publisher. What should the analyst interpret from this?

A.The file is definitely malicious because the publisher is untrusted
B.The file's signature was revoked
C.The file may be malicious or legitimate; further analysis is needed
D.The file is definitely safe because the signature is valid
AnswerC

A valid signature only proves the file was signed and not altered since signing; it does not vouch for the signer's trustworthiness. Since the publisher is untrusted, reputation and behaviour must be assessed before judging intent, so the file could be either benign or malicious.

Why this answer

A valid digital signature confirms the file has not been tampered with since signing, but it does not guarantee the publisher is trustworthy. An untrusted publisher means the signing certificate is not in the system's trusted root store or has been flagged by a security policy, so the file could be either legitimate (e.g., from a new or self-signed publisher) or malicious (e.g., signed with a stolen certificate). Therefore, further analysis—such as checking the file's reputation, behavior, or origin—is required to determine its safety.

Exam trap

Cisco often tests the distinction between signature validity (cryptographic integrity) and publisher trust (certificate chain trust), leading candidates to mistakenly equate a valid signature with safety or an untrusted publisher with guaranteed malice.

How to eliminate wrong answers

Option A is wrong because a valid signature from an untrusted publisher does not automatically mean the file is malicious; the publisher may simply not be in the trusted store (e.g., a self-signed certificate). Option B is wrong because a revoked signature would be reported as invalid, not as valid but from an untrusted publisher; revocation is checked via CRL or OCSP and would cause the signature to fail verification. Option D is wrong because a valid signature does not imply safety; the publisher could be malicious or compromised, and the signature only ensures integrity, not trustworthiness.

234
MCQmedium

During a network intrusion analysis, a security analyst observes repeated TCP SYN packets sent to a range of ports on a target host, each followed by an RST response. No subsequent ACK packets are observed. Which phase of the Cyber Kill Chain is the attacker most likely executing?

A.Reconnaissance
B.Delivery
C.Weaponization
D.Exploitation
AnswerA

SYN packets followed by RST responses, with no completed handshake, indicate a port scan probing which ports are open or closed. This information-gathering activity against the target host characterises the Reconnaissance phase of the Cyber Kill Chain.

Why this answer

Repeated TCP SYN packets to multiple ports followed by RST responses indicate a port scan, which is a hallmark of the Reconnaissance phase of the Cyber Kill Chain. The attacker is probing for open ports and services without completing the TCP handshake, which is typical of a SYN stealth scan. This activity occurs before any exploitation or delivery.

Exam trap

200-201 often tests the distinction between Reconnaissance and Exploitation. Candidates may see SYN packets and think 'attack' but must recognize that incomplete handshakes with RST responses indicate scanning, not exploitation.

How to eliminate wrong answers

Option B is wrong because Delivery involves transmitting the weaponized payload to the target (e.g., via email or USB), not scanning for open ports. Option C is wrong because Weaponization is the creation of the malware or exploit, which happens entirely on the attacker's side and is not observable in network traffic. Option D is wrong because Exploitation would involve actual attempts to leverage a vulnerability, often with completed connections or malformed packets, not just SYN probes.

235
Drag & Dropmedium

Drag and drop the steps for initial configuration of a Cisco IOS device after booting into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

After booting, you must enter privileged mode, then global config, set hostname, set enable secret, and save.

236
MCQmedium

While analyzing a packet capture in Wireshark, an analyst observes a series of TCP packets with the PSH, ACK flags set and a payload containing the string 'cmd.exe /c whoami'. The destination port is 4444. Which type of activity is most likely indicated?

A.A DNS tunneling session exfiltrating data
B.A web server serving content on a non-standard port
C.A legitimate remote administration session using SSH
D.A reverse shell established by malware
AnswerD

Port 4444 is commonly used by Metasploit and other penetration testing or malware tools for reverse shells. The command 'cmd.exe /c whoami' is a typical reconnaissance command executed through a shell. The combination of a non-standard high port and command execution strongly suggests a reverse shell, where the compromised host connects back to the attacker's listener.

Why this answer

The packet capture shows TCP traffic to port 4444 with a payload containing a Windows command. This is a classic indicator of a reverse shell, where malware on a compromised host connects back to an attacker-controlled listener. SSH would be encrypted and on port 22, web traffic would be HTTP on standard ports, and DNS tunneling would use port 53.

The correct answer is the reverse shell.

Exam trap

The trap here is overlooking the non-standard port and cleartext command, assuming it might be legitimate remote administration, when reverse shells often use high ports like 4444.

237
Multi-Selectmedium

An analyst is investigating a potential malware infection. Which TWO of the following are indicators of command and control (C2) communication?

Select 2 answers
A.Large file transfers to a peer host
B.SYN scans to multiple hosts
C.Regular HTTP requests to a known update server
D.DNS queries with long, random subdomains
E.Periodic beaconing to an unusual domain
AnswersD, E

Long, random subdomains indicate DNS tunnelling, where malware encodes stolen data or instructions within query names to bypass perimeter controls. This satisfies the C2 detection requirement because the victim resolves high-entropy domains belonging to an attacker-controlled authoritative nameserver, revealing beaconing traffic that standard domain reputation filtering would miss.

Why this answer

Option D is correct because DNS queries with long, random subdomains are a classic sign of DNS tunneling or domain generation algorithm (DGA) activity used by malware to reach C2 infrastructure while evading domain reputation filtering. Option E is correct because periodic beaconing to an unusual domain reflects the regular check-in pattern malware uses to receive commands from its C2 server, often at fixed intervals with jitter. Option A is not specific to C2, as large file transfers to a peer host more commonly indicate data exfiltration or normal file sharing rather than command-and-control traffic.

Option B is not specific to C2 either, since SYN scans to multiple hosts indicate reconnaissance or port scanning activity, not an established C2 channel. Option C is not an indicator of C2 because regular HTTP requests to a known update server are typical of legitimate software update behavior.

Exam trap

The trap is confusing other malicious activities like scanning or exfiltration with C2; candidates might select options that are indicators of different attack stages.

238
MCQhard

During incident response, an analyst notices that a compromised host is making outbound SMB connections to several internal servers on TCP port 445 using the same domain user account within minutes. Which activity is most likely occurring?

A.Normal user access to multiple file shares
B.Lateral movement using stolen credentials
C.A backup application scanning file shares
D.A vulnerability scanner enumerating SMB services
AnswerB

Outbound SMB connections to multiple internal servers on port 445 using a single domain account within a short window strongly suggest lateral movement. Attackers who have compromised one host often use stolen credentials to access file shares or administrative shares on other systems, spreading malware or establishing additional footholds. This pattern is a classic indicator that should trigger immediate containment and credential reset.

Why this answer

Rapid outbound SMB connections to multiple internal servers using the same domain account indicate lateral movement with stolen credentials. Attackers use tools like PsExec or built-in SMB to pivot across the network, access shares, and deploy payloads. This behavior should be treated as a high-severity incident, triggering isolation of the source host and a review of the compromised account's activity.

Exam trap

The trap here is dismissing the SMB fan-out as routine file share access, when the speed and account reuse point to credential-based lateral movement.

239
MCQmedium

A security analyst is reviewing the organization's incident response plan. The plan currently defines containment, eradication, and recovery but does not include a formal step to determine the root cause of an incident. Which phase of the NIST SP 800-61 incident response lifecycle should the analyst add to address this gap?

A.Post-incident activity
B.Containment, eradication, and recovery
C.Preparation
D.Detection and analysis
AnswerA

Post-incident activity is the final phase of the NIST SP 800-61 lifecycle, where the team reviews what happened, identifies the root cause, documents lessons learned, and updates procedures. Adding this phase directly fills the gap because root cause analysis is a core activity of the post-incident review, not of containment, eradication, or recovery.

Why this answer

The NIST SP 800-61 lifecycle includes preparation; detection and analysis; containment, eradication, and recovery; and post-incident activity. Root cause analysis and lessons learned belong to the post-incident activity phase, which the plan lacks. Adding it ensures the organization systematically identifies why the incident occurred and improves future response.

Exam trap

The trap here is assuming that root cause analysis happens during detection and analysis, when it is formally part of the post-incident activity phase.

240
Multi-Selectmedium

An analyst is investigating a Windows system for signs of malware persistence. Which TWO registry locations are commonly used by malware to achieve automatic startup? (Choose two.)

Select 2 answers
A.HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
B.HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce
C.HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce
D.HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
E.HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\AppInit_DLLs
AnswersA, D

User-specific Run key.

Why this answer

A is correct because the HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run registry key is a standard autostart location that launches programs when the current user logs in. Malware frequently writes a value here to achieve persistence without requiring administrative privileges, as it affects only the current user's session.

Exam trap

Cisco often tests the distinction between Run and RunOnce keys, and the trap here is that candidates mistakenly choose RunOnce options (B or C) thinking they provide persistence, when in fact they only execute a program a single time and then remove the entry.

241
Multi-Selecteasy

A security analyst is assessing the risks to a company's data. The analyst identifies a vulnerability in the web application that could allow SQL injection. Which TWO terms correctly describe the elements of this risk scenario? (Choose two.)

Select 2 answers
A.The SQL injection flaw in the application is a threat.
B.The combination of the vulnerability and threat is the exploit.
C.The SQL injection flaw in the application is a vulnerability.
D.The possibility of an attacker exploiting the SQL injection is a vulnerability.
E.The possibility of an attacker exploiting the SQL injection is a threat.
AnswersC, E

A vulnerability is a weakness in a system or application that an attacker could exploit. The SQL injection flaw is precisely such a weakness in the web application, making it the vulnerability element of this risk scenario.

Why this answer

Option C is correct because a SQL injection flaw is a weakness in the web application's code that can be leveraged to compromise the system, which is the definition of a vulnerability. Option E is correct because the possibility of an attacker exploiting that flaw represents a potential danger or adversary action, which is the definition of a threat. Option A is incorrect because the flaw itself is a vulnerability, not a threat; a threat is the actor or event that could exploit it.

Option B is incorrect because an exploit is the specific technique or code that takes advantage of the vulnerability, not the combination of vulnerability and threat. Option D is incorrect because the possibility of exploitation describes a threat, not a vulnerability, which is the actual weakness.

Exam trap

The trap is swapping vulnerability and threat — candidates often call the flaw a 'threat' because it sounds dangerous, but the flaw is the weakness (vulnerability) and the attacker's potential action is the threat.

242
MCQhard

An analyst is examining a Windows system for evidence of credential dumping. The analyst runs 'Get-WinEvent -FilterHashtable @{LogName='Security'; ID=4688}' and filters for processes with 'lsass.exe' as the target. The output shows that a process named 'procdump.exe' was executed with the command line 'procdump.exe -ma lsass.exe lsass.dmp'. Which type of attack does this indicate?

A.A backup process capturing system state
B.Credential dumping via LSASS memory dump
C.A malware family using process injection into LSASS
D.A legitimate troubleshooting step to diagnose LSASS crashes
AnswerB

Procdump is a legitimate Sysinternals tool, but when used to dump the memory of lsass.exe, it is a common technique for credential dumping. The -ma flag captures a full memory dump, which can then be parsed with tools like Mimikatz to extract plaintext passwords or hashes. This is a clear indicator of credential theft.

Why this answer

Using procdump to dump LSASS memory is a well-known credential dumping technique. Attackers often rename procdump or use it directly to avoid detection. The resulting dump file can be exfiltrated and analyzed offline to extract credentials.

Detecting this behavior involves monitoring for process creation of procdump.exe with lsass.exe as an argument, as well as other tools like Task Manager or comsvcs.dll.

Exam trap

The trap here is dismissing procdump as a legitimate tool and missing its malicious use for credential dumping, especially when targeting LSASS.

243
MCQmedium

A security analyst notices repeated failed login attempts to a critical server from a single external IP address over the past 30 minutes. The SIEM has a correlation rule that triggers an alert when the threshold of 10 failed attempts in 5 minutes is exceeded. However, no alert was generated. What is the most likely cause?

A.The SIEM is not receiving logs from the authentication server.
B.The correlation rule uses a sliding window, and the failed attempts occurred over more than 5 minutes.
C.The analyst is monitoring the wrong log source.
D.The SIEM correlation rule requires a minimum of 15 failed attempts.
AnswerB

A sliding window evaluates events only within the trailing five minutes, so ten failures spread across a longer period never accumulate to the threshold at any single evaluation point. The rule therefore stays silent despite the sustained attack.

Why this answer

The SIEM correlation rule uses a sliding window that triggers an alert only when 10 failed attempts occur within a 5-minute window. Since the analyst observed repeated failed attempts over 30 minutes, the attempts are spread across multiple 5-minute windows, so no single window exceeds the threshold. This is a classic case where the event frequency is high overall but does not meet the rule's temporal aggregation criteria.

Exam trap

Cisco often tests the distinction between event frequency over a long period versus event rate within a specific time window, trapping candidates who assume any repeated failed login attempts will trigger an alert regardless of the correlation rule's temporal constraints.

How to eliminate wrong answers

Option A is wrong because if the SIEM were not receiving logs from the authentication server, the analyst would not have observed any failed login attempts at all, but the analyst explicitly notes repeated failed attempts. Option C is wrong because the analyst is monitoring the correct log source (the critical server's authentication logs) as evidenced by the observed failed attempts; the issue is with the correlation rule's window, not the log source. Option D is wrong because the question states the threshold is 10 failed attempts in 5 minutes, not 15; the rule's threshold is clearly defined and not misconfigured to a higher value.

244
MCQeasy

A company wants to ensure that employees report security incidents immediately. Which policy element is most important to include?

A.Specify encryption standards for data at rest
B.List acceptable uses of company resources
C.Define mandatory reporting procedures and contact information
D.Require complex passwords for all accounts
AnswerC

Mandatory reporting procedures with contact details remove ambiguity about when, how and to whom incidents are escalated, directly satisfying the stem's requirement for immediate employee reporting. Without defined channels, staff delay or misroute notifications, extending attacker dwell time.

Why this answer

The core purpose of an incident response policy is to ensure timely reporting. Without mandatory reporting procedures and clear contact information, employees may delay or fail to report security incidents, increasing dwell time and potential damage. This directly supports the incident response lifecycle (NIST SP 800-61) by establishing a clear chain of communication for initial detection and reporting.

Exam trap

Cisco often tests the distinction between preventive/technical controls (encryption, passwords, acceptable use) and procedural/response controls (reporting procedures), leading candidates to confuse a security best practice with the specific policy element needed for incident reporting.

How to eliminate wrong answers

Option A is wrong because encryption standards for data at rest are a data protection control, not a reporting mechanism; they do not address the immediate notification of security incidents. Option B is wrong because acceptable use policies govern proper resource usage, not the process for reporting incidents when they occur. Option D is wrong because requiring complex passwords is an authentication strength measure, unrelated to the procedural requirement of reporting security events.

245
MCQmedium

An analyst finds a YARA rule that matches a file containing the string 'MZ' at offset 0 and includes 'CreateRemoteThread'. This rule likely identifies:

A.A benign PDF
B.A network packet capture
C.A malicious executable
D.A Linux ELF binary
AnswerC

The 'MZ' signature at offset 0 confirms a Windows PE executable, while 'CreateRemoteThread' indicates process injection capability. Together these satisfy the stem's detection criteria for a malicious executable, since legitimate binaries rarely combine a valid PE header with remote thread creation for code injection.

Why this answer

The YARA rule matches a file starting with the 'MZ' magic bytes at offset 0 and containing the string 'CreateRemoteThread', which together identify a Windows Portable Executable (PE) that performs process injection. 'MZ' is the DOS header signature of every Windows executable, and CreateRemoteThread is a Windows API commonly used for DLL injection and process hollowing. This combination strongly indicates a malicious executable.

Exam trap

The trap is that 'MZ' and 'CreateRemoteThread' are individually generic — candidates may overthink and pick a benign file type, but the exam expects recognition that MZ + Windows injection API = malicious Windows PE, not a document or Linux binary.

How to eliminate wrong answers

Option A is wrong because PDF files begin with '%PDF-' magic bytes, not 'MZ', and do not contain Windows API names like CreateRemoteThread. Option B is wrong because a packet capture (pcap) has no 'MZ' header and is a binary stream of network frames, not an executable image. Option D is wrong because Linux ELF binaries begin with the magic bytes 0x7F 0x45 0x4C 0x46 ('\x7fELF'), not 'MZ', and CreateRemoteThread is a Windows-only API not present in ELF binaries.

246
MCQmedium

A security analyst reviews logs and finds multiple failed login attempts from a single IP. This is indicative of what type of attack?

A.Man-in-the-middle
B.Phishing
C.DDoS
D.Brute-force
AnswerD

Repeated failed authentications from one source IP indicate an automated brute-force attempt, where an attacker systematically tries many credential combinations against accounts. The volume and single-origin pattern distinguish it from password spraying or credential stuffing, matching the log evidence described.

Why this answer

Multiple failed login attempts from a single IP address are characteristic of a brute-force attack, where an attacker systematically tries many passwords (or usernames) against a single account or service until successful. This pattern is distinct from other attack types because it involves repeated authentication attempts from one source, aiming to guess credentials rather than intercept traffic, deceive users, or overwhelm resources.

Exam trap

Cisco often tests the distinction between a brute-force attack (single source, many attempts) and a DDoS attack (many sources, high volume of traffic), so the trap here is confusing a single-source authentication attack with a distributed resource exhaustion attack.

How to eliminate wrong answers

Option A is wrong because a man-in-the-middle attack involves an attacker intercepting and potentially altering communications between two parties (e.g., ARP spoofing or SSL stripping), not repeated login attempts from a single IP. Option B is wrong because phishing relies on social engineering to trick users into revealing credentials or sensitive information via deceptive emails or websites, not on automated, repeated login attempts. Option C is wrong because a DDoS (Distributed Denial of Service) attack aims to overwhelm a target with traffic from multiple sources to disrupt service, not to guess passwords via repeated login failures from a single IP.

247
MCQeasy

A security policy states that user activity logs must be retained for at least one year. What is the primary purpose of this requirement?

A.To support forensic investigations of security incidents
B.To improve system performance through log analysis
C.To comply with regulatory requirements only
D.To enable real-time monitoring of user behavior
AnswerA

Retaining user activity logs for a year preserves the audit trail needed to reconstruct who did what and when, satisfying the policy's forensic requirement. Investigators can correlate events, establish timelines and attribute actions during incident analysis, which is impossible once logs are deleted.

Why this answer

The primary purpose of retaining user activity logs for at least one year is to support forensic investigations of security incidents. When a breach or policy violation occurs, security analysts need historical log data to reconstruct the timeline of events, identify the initial compromise vector, and determine the scope of damage. Without long-term retention, critical evidence may be overwritten or purged before an incident is discovered, making root cause analysis impossible.

Exam trap

Cisco often tests the distinction between the operational benefit (performance tuning) and the security purpose (forensic investigation), leading candidates to choose the compliance option because they confuse a regulatory driver with the underlying security objective.

How to eliminate wrong answers

Option B is wrong because log analysis for performance tuning is a secondary operational benefit, not the primary security-driven reason for a one-year retention mandate; performance analysis typically uses shorter-term metrics. Option C is wrong because while regulatory compliance (e.g., PCI DSS, HIPAA) often mandates retention periods, the question asks for the primary purpose, which is forensic investigation — compliance is a driver, not the purpose itself. Option D is wrong because real-time monitoring relies on current log streams, not historical data retained for a year; long-term retention is for post-incident analysis, not immediate alerting.

248
MCQmedium

An attacker uses a tool to scan all IP addresses in a range to identify which hosts are online and what services are running. Which type of reconnaissance is this?

A.Active reconnaissance
B.Denial of Service
C.Passive reconnaissance
D.Social engineering
AnswerA

Active reconnaissance involves directly interacting with targets, such as scanning IP ranges to elicit responses revealing live hosts and services. This matches the stem's constraint: the attacker's scanning traffic touches the target, unlike passive reconnaissance, which only observes third-party data.

Why this answer

Active reconnaissance involves directly interacting with the target system to gather information, such as scanning IP addresses to identify live hosts and open services. This type of scanning generates traffic that can be detected by the target, distinguishing it from passive reconnaissance.

Exam trap

200-201 often tests the distinction between active and passive reconnaissance; the trap is that candidates may confuse scanning (active) with monitoring (passive) and select the wrong type.

How to eliminate wrong answers

Option B is wrong because a Denial of Service attack aims to disrupt availability, not gather information about hosts and services. Option C is wrong because passive reconnaissance involves collecting information without directly interacting with the target, such as monitoring network traffic or using public sources, which does not generate scan traffic. Option D is wrong because social engineering involves manipulating people to divulge information, not technical scanning of IP ranges.

249
MCQeasy

A network engineer sees the following event in the firewall logs: 'STATUS: intrusion prevented, action: drop, signature: "SQL Injection - SELECT"' on traffic from internal IP to a web server. What type of attack was detected?

A.Command injection
B.Buffer overflow
C.Cross-site scripting
D.SQL injection
AnswerD

The signature name explicitly identifies the SQL Injection - SELECT pattern, and the firewall dropped the matching packet. The internal source sending crafted SELECT statements to a web server confirms a SQL injection attempt was detected and prevented inline.

Why this answer

The log entry explicitly states 'SQL Injection - SELECT' as the signature, which directly identifies the attack as SQL injection. The firewall detected a malicious SQL query (e.g., a SELECT statement with crafted input) in the traffic from an internal IP to a web server and dropped it, preventing the attack. SQL injection exploits improper input validation in web applications to manipulate backend databases.

Exam trap

Cisco often tests the ability to distinguish between web application attacks (SQL injection vs. XSS vs. command injection) by focusing on the specific payload or signature keywords in logs, where candidates may confuse 'injection' with command injection or misinterpret the 'SELECT' keyword as a generic query rather than SQL-specific.

How to eliminate wrong answers

Option A is wrong because command injection involves executing arbitrary OS commands on the server (e.g., via shell metacharacters like ';' or '|'), not SQL queries; the signature explicitly mentions 'SQL Injection', not command execution. Option B is wrong because a buffer overflow attack exploits memory corruption by overflowing a buffer (e.g., stack or heap) to execute arbitrary code, which is unrelated to SQL query manipulation. Option C is wrong because cross-site scripting (XSS) injects malicious client-side scripts (e.g., JavaScript) into web pages viewed by other users, not SQL statements targeting the database.

250
MCQmedium

After resolving a security incident, the IR team conducts a lessons learned meeting. Which of the following are typical outputs of this post-incident activity? (Choose three.)

A.Recommendations for policy or procedure changes
B.Creation of new detection signatures for future incidents
C.Immediate containment of the incident
D.Development of metrics to measure response effectiveness
E.Updated incident response plan based on findings
AnswerA, D, E

The meeting generates recommendations for policy or procedure changes, such as revised escalation paths, access controls or detection rules. These outputs directly address root causes found during the incident, satisfying the post-incident objective of improving organisational defences.

Why this answer

Lessons learned leads to updating the IR plan, identifying metrics to measure performance, and recommending changes to policies.

251
MCQmedium

A Windows event log review shows Event ID 4625 multiple times from a single source IP. What does this event indicate, and which log contains it?

A.Successful logon; System log
B.Service start; System log
C.Failed logon; Security log
D.Account creation; Application log
AnswerC

Event ID 4625 is logged whenever a logon attempt fails, recording the account and source. Repeated occurrences from one source IP suggest brute-force or password-guessing activity, and Windows writes this event to the Security log.

Why this answer

Event ID 4625 is a failed logon attempt, recorded in the Security log.

252
MCQeasy

An analyst sees an alert from the IDS: 'ET TROJAN Possible Zeus Variant Outbound Connection'. What action should the analyst take first?

A.Block the IP address on the firewall
B.Ignore the alert as a false positive
C.Investigate the source host for signs of compromise
D.Reimage the host immediately
AnswerC

The IDS signature names a possible Zeus variant, so the source host may already be infected. Investigating that host for compromise confirms whether the alert is genuine before containment, satisfying the requirement to act first on the affected endpoint.

Why this answer

The first priority when an IDS alerts on a possible Zeus variant (a known Trojan) is to investigate the source host to confirm or rule out compromise. Zeus is a credential-stealing Trojan that often establishes outbound C2 (command-and-control) traffic; blindly blocking the IP (A) could disrupt the investigation and may not stop the malware if it uses domain flux or multiple IPs. Reimaging (D) destroys forensic evidence, and ignoring the alert (B) is negligent given the severity of Zeus.

The analyst must perform host-based analysis (e.g., check processes, registry, network connections) to validate the alert before taking containment actions.

Exam trap

Cisco often tests the principle that IDS/IPS alerts require verification before action—candidates mistakenly choose to block or reimage immediately, but the correct first step is always to investigate the affected host to confirm the alert and preserve evidence.

How to eliminate wrong answers

Option A is wrong because blocking the IP address on the firewall may disrupt the C2 channel but does not address the root cause—the host may still be compromised and could use other IPs or domains (e.g., via DGA). Additionally, blocking without investigation could alert the attacker and destroy forensic evidence. Option B is wrong because ignoring the alert as a false positive is premature; Zeus variants are high-severity threats, and IDS alerts should always be triaged—especially when the signature explicitly names a known Trojan family.

Option D is wrong because reimaging the host immediately destroys volatile data (e.g., memory, running processes, network connections) that are critical for understanding the infection vector and scope of compromise, and it may violate incident response procedures.

253
MCQmedium

Which compliance framework specifically addresses the protection of cardholder data?

A.PCI DSS
B.GDPR
C.ISO 27001
D.HIPAA
AnswerA

PCI DSS is the payment-card industry standard governing storage, transmission and access to cardholder data, so it uniquely satisfies the stem's cardholder-data protection constraint. Other frameworks address health information, financial reporting or general security controls rather than card data specifically.

Why this answer

PCI DSS (Payment Card Industry Data Security Standard) is the compliance framework specifically designed to protect cardholder data — including credit card numbers, expiration dates, and cardholder names — for any organization that stores, processes, or transmits payment card information. It is mandated by the major card brands and enforced through acquirers and payment processors.

Exam trap

The trap is confusing privacy regulations (GDPR) or industry standards (ISO 27001) with the payment-card-specific framework — candidates may pick GDPR because it also deals with data protection, but only PCI DSS is explicitly about cardholder data.

How to eliminate wrong answers

Option B is wrong because GDPR (General Data Protection Regulation) is a European Union regulation focused on personal data privacy and protection for EU residents, not specifically cardholder data. Option C is wrong because ISO 27001 is a generic international standard for information security management systems (ISMS), not a card-specific framework. Option D is wrong because HIPAA (Health Insurance Portability and Accountability Act) governs protected health information (PHI) in the United States, not payment card data.

254
MCQmedium

A security analyst is examining a network capture and observes that an attacker is sending a large volume of SYN packets to a web server with spoofed source IP addresses. The server's connection table is filling up, and legitimate users cannot connect. Which type of attack is the analyst observing?

A.A DNS amplification attack, which uses open resolvers to send large responses to a victim.
B.A man-in-the-middle attack, which intercepts and relays traffic between two parties.
C.A Smurf attack, which uses ICMP echo requests with a spoofed source to amplify traffic.
D.A TCP SYN flood, which exhausts the server's connection table with half-open connections.
AnswerD

A TCP SYN flood sends many SYN packets with spoofed sources. The server allocates resources for each half-open connection and waits for the final ACK that never arrives, exhausting the connection table and denying service to legitimate users. This exactly matches the observed SYN volume, spoofed IPs, and full connection table, making it the correct classification.

Why this answer

The capture shows many SYN packets with spoofed sources, and the server's connection table is exhausted, blocking legitimate users. This is the classic signature of a TCP SYN flood, a denial-of-service attack that abuses the TCP three-way handshake. Smurf uses ICMP, DNS amplification uses resolvers, and man-in-the-middle intercepts traffic, so none match the observed half-open connection exhaustion.

Exam trap

The trap here is grouping all denial-of-service attacks together and overlooking that SYN floods specifically exhaust TCP connection state with spoofed half-open connections.

255
MCQmedium

A security analyst is reviewing the organization's password policy, which currently requires a minimum of eight characters with complexity but no expiration. After a recent audit finding, management wants to align with modern best practices. Which change should the analyst recommend?

A.Allow users to choose any password of any length as long as it contains a special character
B.Reduce the minimum length to six characters and require changes every 30 days
C.Require passwords to be changed every 60 days and prohibit reuse of the last 24 passwords
D.Increase the minimum length to 14 characters and remove forced periodic expiration
AnswerD

This is correct because modern guidance favors longer passwords or passphrases over frequent forced changes, which often lead to predictable increments. A 14-character minimum significantly increases resistance to brute-force and credential-stuffing attacks. Removing expiration aligns with NIST guidance that discourages arbitrary rotation, reducing user frustration and weak password patterns.

Why this answer

Modern password guidance recommends longer minimum lengths, such as 14 characters, and discourages forced periodic expiration unless compromise is suspected. Longer passwords increase the effort required for brute-force attacks, while removing arbitrary expiration reduces predictable user behavior. This combination addresses the audit finding by aligning the policy with current best practices.

Exam trap

The trap here is assuming that frequent password expiration improves security, when it often leads to weaker, predictable passwords and is no longer recommended.

256
MCQeasy

Which OSI layer is responsible for logical addressing and routing?

A.Application layer
B.Data link layer
C.Network layer
D.Transport layer
AnswerC

The Network layer (layer 3) handles logical addressing through IP addresses and determines path selection via routing protocols, forwarding packets between networks. Layers 2 and 4 handle physical addressing and transport respectively, so neither performs routing.

Why this answer

The Network layer (Layer 3) is responsible for logical addressing (e.g., IPv4/IPv6 addresses) and routing decisions that determine the best path for data packets across interconnected networks. Protocols such as OSPF, BGP, and ICMP operate at this layer to manage routing tables and forward packets between different subnets or autonomous systems.

Exam trap

Cisco often tests the distinction between Layer 2 (Data link) and Layer 3 (Network) by having candidates confuse MAC addressing (physical) with IP addressing (logical), leading them to incorrectly select the Data link layer for routing functions.

How to eliminate wrong answers

Option A is wrong because the Application layer (Layer 7) provides network services to end-user applications (e.g., HTTP, FTP, SMTP) and does not handle logical addressing or routing. Option B is wrong because the Data link layer (Layer 2) is responsible for physical addressing (MAC addresses) and frame delivery on the same local network segment, not for logical addressing or routing across networks. Option D is wrong because the Transport layer (Layer 4) manages end-to-end communication, segmentation, and flow control (e.g., TCP/UDP port numbers), but does not perform logical addressing or routing.

257
Matchingmedium

Match each log severity level to its description (syslog).

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

System is unusable

Immediate action required

Critical conditions

Error conditions

Warning conditions

Why these pairings

Syslog severity levels are from 0 (Emergency) to 7 (Debug). Emergency, Alert, Critical, Error, Warning, Notice, Informational, and Debug are standard levels. Common confusions involve swapping levels with similar descriptions.

258
MCQmedium

An analyst observes a series of DNS queries for subdomains like 'ZGVzdGluYXRpb24= .malicious.com' where the subdomain part appears base64-encoded. The volume of DNS traffic from a single host is unusually high. Which exfiltration technique is most likely in use?

A.FTP exfiltration
B.DNS tunnelling
C.HTTP POST exfiltration
D.Steganography in images
AnswerB

Encoding data into DNS query names and pushing it to an authoritative server via high-volume lookups is DNS tunnelling. The base64 subdomains and abnormal query volume from one host match covert channel exfiltration rather than normal resolution traffic.

Why this answer

The base64-encoded subdomains and high volume of DNS queries from a single host are classic indicators of DNS tunnelling, where data is exfiltrated by encoding it into DNS query names (e.g., subdomains) sent to an attacker-controlled domain. DNS is often allowed through firewalls, making it an attractive covert channel. The base64 encoding allows arbitrary binary data to be transmitted as DNS labels, and the high query volume reflects the data transfer.

Exam trap

The trap here is that candidates might see 'base64-encoded' and think of HTTP or other protocols, but the key indicator is the DNS queries themselves; DNS tunnelling specifically uses DNS as the transport, and the base64 encoding is just a way to fit data into DNS labels.

How to eliminate wrong answers

Option A is wrong because FTP exfiltration would involve outbound FTP connections (typically on ports 20/21) and would not manifest as DNS queries with encoded subdomains. Option C is wrong because HTTP POST exfiltration would generate HTTP traffic to a web server, not DNS queries; while HTTP can be used for exfiltration, the observed pattern is specific to DNS. Option D is wrong because steganography in images would involve embedding data within image files and typically transferring those images via HTTP or email, not generating DNS queries with base64-encoded subdomains.

259
MCQmedium

An organization's security policy states that all external connections must be authenticated using multi-factor authentication. Which type of policy is this?

A.Password Policy
B.Data Classification Policy
C.Remote Access Policy
D.Acceptable Use Policy
AnswerC

A remote access policy governs authentication requirements for connections originating outside the trusted network, which is exactly the scope the stem describes. MFA enforcement for all external connections belongs in this policy type rather than an acceptable use or password policy.

Why this answer

A Remote Access Policy specifically governs how external users or devices connect to an internal network, and requiring multi-factor authentication (MFA) for all external connections is a standard control within this policy. This policy defines authentication methods, encryption standards (e.g., IPsec, TLS), and access controls for remote access, directly addressing the security policy's mandate for MFA on external connections.

Exam trap

Cisco often tests the distinction between a Remote Access Policy (which mandates technical controls like MFA for external connections) and an Acceptable Use Policy (which governs user behavior), causing candidates to confuse the two when the question mentions 'authentication'.

How to eliminate wrong answers

Option A is wrong because a Password Policy focuses on password complexity, length, expiration, and reuse rules, not on requiring multiple authentication factors (e.g., something you know plus something you have) for external connections. Option B is wrong because a Data Classification Policy defines how data is categorized (e.g., public, confidential, restricted) and handled based on sensitivity, not the authentication mechanisms for external network access. Option D is wrong because an Acceptable Use Policy outlines what users are allowed to do with organizational resources (e.g., browsing restrictions, software installation), not the technical authentication requirements for external connections.

260
Multi-Selecteasy

Which TWO of the following are functions of a SIEM system in security monitoring?

Select 2 answers
A.Packet capture and analysis
B.Correlation rule engine
C.Firewall rule management
D.Log aggregation and normalization
E.Vulnerability scanning
AnswersB, D

A correlation rule engine ingests and normalises logs from disparate sources, then matches event patterns across them to surface multi-stage attacks that isolated alerts would miss. This directly satisfies the stem's requirement for a security monitoring function, since correlation is a core SIEM capability rather than an endpoint or network control.

Why this answer

A SIEM (Security Information and Event Management) system is built around collecting and consolidating log and event data from many sources, so option D, log aggregation and normalization, is correct: the SIEM ingests logs via agents, syslog, or APIs and parses them into a common schema so disparate formats can be searched and analyzed together. Option B, correlation rule engine, is also correct because the SIEM applies correlation rules and logic (e.g., matching multiple events across sources within a time window) to detect patterns, generate alerts, and support incident detection beyond what individual devices report. The other options do not belong: packet capture and analysis (A) is the role of tools such as Wireshark, tcpdump, or NDR/IDS sensors, not the core SIEM function; firewall rule management (C) is performed on firewalls or via firewall management platforms; and vulnerability scanning (E) is done by dedicated scanners like Nessus, Qualys, or OpenVAS, which may feed findings into a SIEM but are not SIEM functions themselves.

261
MCQeasy

A company's security policy states that employees must not use corporate laptops for personal web browsing. An employee is found to have streamed video during work hours, consuming significant bandwidth. What is the best course of action?

A.Give a verbal warning and take no further action
B.Update the policy to allow streaming under certain conditions
C.Immediately terminate the employee
D.Report the violation to HR for disciplinary action per the existing policy
AnswerD

The Acceptable Use Policy already prohibits personal browsing on corporate laptops, so the streaming is a confirmed policy breach. Reporting to HR applies the established disciplinary process rather than inventing new controls or ignoring the violation.

Why this answer

When a security policy already exists and an employee is found to have violated it, the correct action is to follow the established disciplinary process — typically reporting the violation to HR so the organisation's policy is enforced consistently. This preserves due process, creates an auditable record, and avoids ad-hoc decisions by the security team. Terminating immediately or ignoring the violation both undermine the policy's authority.

Exam trap

200-201 often tests the boundary between technical response and HR/legal process — candidates pick 'terminate' or 'warn' because they sound decisive, but the correct answer is always to follow the documented policy and route through HR.

How to eliminate wrong answers

Option A is wrong because giving only a verbal warning and taking no further action fails to enforce the existing policy and sets a precedent that violations have no consequences. Option B is wrong because changing the policy to accommodate the violation inverts governance — policies should drive behaviour, not be rewritten to excuse it. Option C is wrong because immediate termination is an HR/legal decision, not a security-team action, and bypasses the organisation's disciplinary process.

262
Multi-Selectmedium

A security analyst is investigating a potential security incident and needs to correlate events across multiple data sources. Which two Cisco CyberOps tools or features would provide network flow data and intrusion event details respectively? (Choose two.)

Select 2 answers
A.Cisco Stealthwatch for network flow analysis
B.Cisco Firepower Management Center for intrusion event details
C.Cisco Identity Services Engine for authentication logs
D.Cisco Umbrella for DNS security
E.Cisco Advanced Malware Protection for endpoint
AnswersA, B

Cisco Stealthwatch collects NetFlow and other flow data to provide network visibility and detect anomalies. It is designed for network flow analysis, helping analysts identify unusual traffic patterns and potential threats. In this scenario, it would supply the network flow data needed to understand communication patterns.

Why this answer

Cisco Stealthwatch is purpose-built for network flow analysis using NetFlow and other telemetry, while Firepower Management Center is the central console for intrusion events from Firepower sensors. Together, they provide the flow and intrusion data needed to correlate a security incident. The other tools focus on DNS, identity, or endpoint, which are not the requested data types.

Exam trap

The trap here is confusing Cisco Umbrella's DNS logs with network flow data, or assuming ISE provides intrusion events, when each tool has a specific telemetry focus.

263
MCQhard

During a security incident, a SOC analyst finds that the SIEM is not receiving logs from a critical firewall due to a network issue. The analyst needs to ensure that no alerts are missed during the outage. What should the analyst do?

A.Restart the SIEM collector service.
B.Manually monitor the firewall console.
C.Configure the firewall to queue logs locally and forward when connectivity is restored.
D.Ignore the gap because logs are not critical.
AnswerC

Local queuing preserves log events generated during the outage, then forwards them once connectivity returns, so the SIEM receives the missing data and no alerts are missed. This directly satisfies the stem's requirement to avoid gaps during the network issue.

Why this answer

Configuring the firewall to queue logs locally ensures that log data generated during the network outage is stored in a local buffer (often using syslog buffering or a local log file) and automatically forwarded once connectivity to the SIEM is restored. This prevents any gap in security monitoring and ensures that all alerts are captured for analysis, even during transient network failures.

Exam trap

Cisco often tests the misconception that restarting services or manual monitoring can compensate for a network outage, when the correct approach is to leverage local log queuing or buffering on the source device to prevent data loss.

How to eliminate wrong answers

Option A is wrong because restarting the SIEM collector service does not address the root cause—the network outage preventing log transmission—and would not recover logs that were never sent. Option B is wrong because manually monitoring the firewall console is not scalable, does not provide centralized alerting, and would require constant human attention, which is impractical during an outage and does not guarantee that all alerts are captured. Option D is wrong because ignoring the log gap violates fundamental security monitoring principles; logs from critical firewalls are essential for incident detection, forensics, and compliance, and any gap could allow a security event to go undetected.

264
MCQmedium

A SIEM correlation rule triggers when it detects more than 10 failed login attempts from the same source IP within 1 minute. Which type of attack is this rule designed to detect?

A.Port scan
B.DDoS attack
C.Privilege escalation
D.Brute-force attack
AnswerD

Repeated authentication failures from one source within a short window indicate systematic credential guessing, the defining signature of brute-force attacks. The rule's threshold and time constraint detect this volume-based pattern, distinguishing it from single failed logins or distributed password spraying across many accounts.

Why this answer

A brute-force attack involves repeated login attempts using many password guesses against a single account or a set of accounts. The SIEM rule correlates more than 10 failed login attempts from the same source IP within 1 minute, which is a classic signature of an automated password-guessing tool. This threshold-based detection is specifically designed to identify brute-force activity, not other attack types.

Exam trap

Cisco often tests the distinction between a brute-force attack (repeated login attempts) and a DDoS attack (traffic volume), so candidates may confuse the two because both involve high rates of activity from a single source.

How to eliminate wrong answers

Option A is wrong because a port scan typically sends connection requests (SYN packets) to multiple ports on a target, not repeated login attempts; it would be detected by a rule counting connections to different ports, not failed logins. Option B is wrong because a DDoS attack aims to overwhelm a target with traffic volume, not to authenticate; it would be detected by a rule monitoring bandwidth or packet rates, not failed login attempts. Option C is wrong because privilege escalation involves an attacker gaining higher-level access after initial compromise, often using a single exploit or token manipulation, not repeated failed logins; it would be detected by rules monitoring changes in user permissions or unusual process execution.

265
MCQmedium

An organization has implemented a new password policy requiring 12-character passwords with complexity. Which risk treatment option is this an example of?

A.Risk mitigation
B.Risk transfer
C.Risk acceptance
D.Risk avoidance
AnswerA

Enforcing 12-character complexity passwords applies an administrative control that lowers the likelihood of credential compromise, reducing overall risk exposure. This is mitigation, since the organisation acts to reduce risk rather than accept, transfer or avoid it.

Why this answer

Implementing controls to reduce risk is mitigation.

266
MCQhard

Refer to the exhibit. A firewall log shows denied TCP traffic from an internal host to an external IP on consecutive ports. What type of activity is indicated?

A.Port scanning
B.Worm propagation
C.Denial of service
D.Data exfiltration
AnswerA

Sequential destination ports from one internal host indicate systematic probing of services to discover open listeners. A single connection would be normal traffic; consecutive denied attempts on incrementing ports is the signature of port scanning reconnaissance.

Why this answer

The firewall log shows denied TCP traffic from an internal host to an external IP on consecutive ports. This sequential pattern of connection attempts to multiple ports on the same target is a classic indicator of a port scan, where an attacker probes for open ports to identify potential services to exploit. The firewall's deny action confirms the traffic was blocked, but the behavior itself is characteristic of reconnaissance activity, specifically a TCP connect scan.

Exam trap

Cisco often tests the distinction between reconnaissance (port scanning) and exploitation (worm propagation) by presenting a log of denied traffic to consecutive ports, leading candidates to confuse the scanning phase with the actual attack phase, such as worm propagation or DoS.

How to eliminate wrong answers

Option B (Worm propagation) is wrong because worm propagation typically involves self-replicating code that spreads by exploiting vulnerabilities, often generating traffic to random or specific ports based on the exploit, not a sequential scan of consecutive ports. Option C (Denial of service) is wrong because a DoS attack aims to overwhelm a target with traffic to disrupt service, usually flooding a single port or using high-volume traffic, not probing multiple consecutive ports in a low-and-slow manner. Option D (Data exfiltration) is wrong because data exfiltration involves sending sensitive data out of the network, which would use established connections on a single port (e.g., HTTP/HTTPS, DNS, or FTP), not a series of denied connection attempts to consecutive ports.

267
MCQmedium

A SIEM correlation rule is configured to alert when there are 10 failed login attempts from the same source IP within 1 minute. An analyst receives an alert for source IP 10.0.0.5. Which type of attack is most likely being detected?

A.Brute force attack
B.Man-in-the-middle attack
C.DDoS attack
D.SQL injection attempt
AnswerA

Ten failed authentications from one source within a minute indicates repeated credential guessing against an account, the defining pattern of brute force. The rule's threshold and one-minute window directly capture that volume-based signature, distinguishing it from a single failed attempt or a slow, low-rate password spray.

Why this answer

A brute force attack involves repeatedly attempting to guess login credentials, often from a single source IP, which matches the pattern of 10 failed login attempts within 1 minute. This is a classic indicator of a brute force attack, where an attacker tries multiple username/password combinations rapidly.

Exam trap

200-201 often tests the ability to distinguish between different attack types based on log patterns; the trap is that candidates may confuse brute force with other attacks like DDoS, which also involve multiple attempts but from many sources.

How to eliminate wrong answers

Option B is wrong because a man-in-the-middle attack involves intercepting communications between two parties, not generating multiple failed login attempts from a single IP. Option C is wrong because a DDoS attack aims to overwhelm a service with traffic from many sources, not a series of failed logins from one IP. Option D is wrong because a SQL injection attempt involves injecting malicious SQL code into input fields, which would not typically manifest as multiple failed login attempts from the same IP.

268
MCQmedium

An analyst is investigating a host that is suspected of being compromised. She runs the 'netstat -anb' command and sees an established connection to an unknown IP address on port 4444. The associated process is svchost.exe. Which conclusion is MOST appropriate?

A.The host is definitely compromised because svchost.exe should not make outbound connections.
B.The host may be infected with malware that is injecting code into svchost.exe.
C.The analyst should immediately kill the svchost.exe process.
D.The connection is legitimate because svchost.exe is a critical Windows process.
AnswerB

Port 4444 is a common reverse-shell listener, and svchost.exe legitimately hosts multiple services, so an unexpected outbound connection from it indicates process injection or masquerading. The established session to an unknown host satisfies the compromise indicator, though confirmation requires further host and memory analysis.

Why this answer

Svchost.exe is a legitimate Windows service host process, but it is a common target for malware that uses process injection or DLL sideloading to hide malicious network activity. The established connection to an unknown IP on port 4444 (often associated with Metasploit or backdoor listeners) indicates the process may be hosting injected code, not that svchost.exe itself is inherently malicious. The analyst should investigate further before concluding compromise or taking action.

Exam trap

Cisco often tests the misconception that svchost.exe never makes outbound connections, when in fact many Windows services (e.g., BITS, Windows Update) do; the trap is assuming any outbound connection from a critical process is automatically legitimate or automatically malicious without considering the port and context.

How to eliminate wrong answers

Option A is wrong because svchost.exe can make legitimate outbound connections for Windows services like DNS, DHCP, or Windows Update, so an outbound connection alone does not prove compromise. Option C is wrong because killing svchost.exe could crash critical system services and disrupt the investigation; the analyst should first capture memory and network artifacts to identify the injected code. Option D is wrong because while svchost.exe is a critical Windows process, an established connection to an unknown IP on port 4444 is highly suspicious and should not be dismissed as legitimate without further analysis.

269
MCQmedium

You are a security administrator for a company with 500 employees. The company uses a SIEM with basic correlation rules. Recently, the HR department reported that several employees received phishing emails with a link to a fake login page. The emails bypassed the spam filter. You want to detect if any employees clicked the link. You have access to web proxy logs, DNS logs, and endpoint antivirus logs. The phishing link is 'http://malicious-login.com/verify'. Which action should you take first to identify affected users?

A.Run a vulnerability scan on all employee workstations.
B.Search DNS logs for queries to 'malicious-login.com'.
C.Search endpoint logs for any malware detections.
D.Query the web proxy logs for HTTP requests containing the URL.
AnswerD

Web proxy logs record outbound HTTP requests, so querying them for the exact URL 'http://malicious-login.com/verify' directly identifies which internal hosts reached the fake login page. DNS logs only show resolution attempts, and antivirus logs would not capture the click, making proxy logs the fastest evidence of affected users.

Why this answer

The web proxy logs record all HTTP requests made by clients, including the full URL path. Querying for 'http://malicious-login.com/verify' directly shows which employees clicked the link, because the proxy captures the exact destination and timestamp of each request. This is the most direct and reliable evidence of user interaction with the phishing link.

Exam trap

Cisco often tests the distinction between DNS resolution and actual HTTP request completion, tricking candidates into thinking DNS logs are sufficient to prove a user clicked a link, when in fact only web proxy logs confirm the full URL was requested.

How to eliminate wrong answers

Option A is wrong because a vulnerability scan identifies system weaknesses, not user actions like clicking a link; it would not reveal whether an employee visited the phishing URL. Option B is wrong because DNS logs only show that a client resolved the domain 'malicious-login.com', not that the user actually made an HTTP request to the specific '/verify' path; a DNS query could occur from background processes or pre-fetching without user interaction. Option C is wrong because endpoint antivirus logs only record malware detections; the phishing page itself is not malware, and no malicious file would be detected unless the user downloaded and executed a payload.

270
MCQhard

A security analyst is investigating a breach where an attacker gained access to a server by exploiting a vulnerability in a web application. The analyst needs to determine the type of attack that was used. The server logs show that the attacker sent a specially crafted HTTP request that caused the server to execute arbitrary code. Which type of attack is this?

A.SQL injection
B.Cross-site request forgery (CSRF)
C.Cross-site scripting (XSS)
D.Remote code execution (RCE)
AnswerD

Remote code execution occurs when an attacker can execute arbitrary code on a remote server, often by exploiting a vulnerability in a web application. The scenario describes a crafted HTTP request that causes the server to execute arbitrary code, which is the definition of RCE. This is a severe vulnerability that can lead to full system compromise. Thus, RCE is the correct answer.

Why this answer

The attacker exploited a web application vulnerability to execute arbitrary code on the server. This is the definition of remote code execution (RCE). XSS and CSRF are client-side attacks, and SQL injection is a specific type of injection that may not always lead to code execution.

The scenario clearly points to RCE as the attack type.

Exam trap

The trap here is assuming any web attack that involves crafted input is SQL injection, but the key is that the server executed arbitrary code, which is the hallmark of RCE.

271
Multi-Selecthard

An analyst is using Zeek to monitor network traffic. Which THREE types of logs can Zeek generate to provide visibility into application-layer activity?

Select 3 answers
A.conn.log
B.smtp.log
C.weird.log
D.dns.log
E.http.log
AnswersB, D, E

Zeek's SMTP analyser parses email transactions at the application layer, producing smtp.log with fields such as sender, recipient, subject and helo, satisfying the requirement for application-layer visibility. It captures protocol-level mail activity rather than transport metadata, so it directly evidences application-layer behaviour in the monitored traffic.

Why this answer

Zeek generates smtp.log (B) to record SMTP transactions, including sender/recipient envelopes, subjects, and mail server responses, giving application-layer visibility into email traffic. dns.log (D) captures DNS queries and responses at the application layer, logging query names, record types, and answers. http.log (E) records HTTP requests and replies, including methods, URIs, host headers, user agents, and status codes, which is classic application-layer visibility. conn.log (A) is a transport/network-layer connection summary (IPs, ports, protocol, bytes, duration) and does not describe application-layer activity, while weird.log (C) logs protocol anomalies and unexpected behavior rather than normal application-layer transactions.

Exam trap

Cisco often tests the distinction between network-layer logs (conn.log) and application-layer logs (http.log, dns.log, smtp.log), and candidates may incorrectly assume conn.log covers application-layer activity because it includes port numbers.

272
MCQmedium

A SOC analyst is reviewing a PCAP captured at the perimeter firewall. The analyst notices that a single internal host has sent TCP segments with the FIN, PSH, and URG flags all set simultaneously to multiple destination ports on several external hosts. No corresponding ACK, SYN, or RST packets are observed in the capture. Which type of scan is the analyst most likely observing?

A.TCP NULL scan
B.TCP ACK scan
C.TCP Xmas scan
D.TCP SYN stealth scan
AnswerC

A TCP Xmas scan sets the FIN, PSH, and URG flags simultaneously, which makes the packet look 'lit up like a Christmas tree.' Because these flag combinations are invalid in normal TCP communication, closed ports respond with RST while open ports silently drop the packet, allowing the attacker to infer port state without completing a handshake.

Why this answer

The combination of FIN, PSH, and URG flags in a single TCP segment is the defining signature of a TCP Xmas scan. Because RFC 793 requires closed ports to respond with RST to any segment not containing SYN, and open ports to ignore such segments, attackers use this flag combination to enumerate ports without establishing a full connection and with minimal logging on the target host.

Exam trap

The trap here is assuming any unusual flag combination indicates a NULL scan, when NULL means zero flags set and Xmas specifically means FIN+PSH+URG together.

273
MCQhard

An organization must retain security logs for at least one year due to regulatory compliance. However, their SIEM storage is limited. Which strategy best balances compliance and storage?

A.Archive logs to compressed files after 30 days and retain for one year.
B.Delete logs after 30 days and rely on local log rotation.
C.Only store alerts and drop raw logs.
D.Increase SIEM storage without archiving.
AnswerA

Archiving logs to compressed files after 30 days satisfies the one-year regulatory retention requirement while freeing SIEM capacity, since compression reduces the storage footprint of aged data that is rarely queried. The SIEM retains recent logs for active correlation and hunting, and archived files remain retrievable for compliance audits or investigations.

Why this answer

Archiving logs to compressed files after 30 days and retaining them for one year balances compliance (one-year retention) with limited SIEM storage. This approach moves older logs to cheaper, compressed storage while keeping them accessible for audits. It reduces the active SIEM storage footprint without violating the retention requirement.

Exam trap

200-201 often tests the trade-off between compliance and storage, tempting candidates to choose deletion or only alerts, which fail regulatory requirements.

How to eliminate wrong answers

Option B is wrong because deleting logs after 30 days violates the one-year retention requirement, even if local rotation exists. Option C is wrong because storing only alerts and dropping raw logs fails compliance, as regulations typically require raw log retention for forensic analysis. Option D is wrong because simply increasing SIEM storage without archiving is cost-inefficient and does not address the limited storage constraint strategically.

274
MCQhard

A SOC receives a threat intelligence feed indicating that a specific SHA-256 hash belongs to a trojan. An analyst searches the endpoint telemetry and finds no process with that hash, but the file name appears in several temporary directories. Which explanation best accounts for this result?

A.The malware mutates or is repacked on each execution, so the file content and therefore the hash differ while the name persists.
B.The endpoint agent is not collecting file metadata, so hash matching cannot be performed.
C.The endpoint is using a different hash algorithm, so SHA-256 values cannot be compared.
D.The threat feed is stale and the hash was retired by the vendor before the analyst searched.
AnswerA

Polymorphic and repacked malware changes its bytes between builds or executions, producing a new SHA-256 each time while often retaining a familiar file name. The intelligence feed's hash identifies one specific sample, so the absence of that hash does not mean the malware is absent. This explains why name-based sightings persist without a hash match and why behavioural detection matters.

Why this answer

A SHA-256 value identifies exact file content, so the same malware name appearing with different bytes yields different hashes. Repacking, encryption, or packing layers can change content on every campaign or execution. The analyst should pivot from static hash matching to behavioural and name-based hunting, then capture a live sample to confirm the current variant.

Exam trap

The trap here is treating a threat intelligence hash as a permanent name-based signature, when a hash identifies one exact binary and stops matching the moment the file content changes.

275
MCQmedium

A network security analyst is reviewing traffic logs and notices a series of connections from an internal host to a known command-and-control (C2) server. The connections occur every 5 minutes and are small in size. Which of the following is the MOST likely explanation for this traffic pattern?

A.The host is synchronizing time with an NTP server.
B.The host is running a legitimate software update service that checks for updates every 5 minutes.
C.The host is part of a botnet and is being used to scan other hosts.
D.The host is infected with malware that is beaconing to its C2 server.
AnswerD

Regular, periodic connections to a known C2 server are characteristic of malware beaconing. The interval and small data size suggest the malware is checking in for instructions. This is a common detection for command-and-control activity. The analyst should investigate the host for compromise and block the C2 communication.

Why this answer

Periodic connections to a known C2 server are a strong indicator of malware beaconing. Malware often uses beaconing to maintain communication with its controller, receiving commands and exfiltrating data. The regular interval and small payload size are typical to avoid detection.

Other options describe benign or different malicious activities that do not match the scenario, especially the destination being a known C2 server.

Exam trap

The trap here is dismissing the periodic nature as benign (like updates or NTP) without considering the destination reputation and the context of a known C2 server.

276
Multi-Selectmedium

A security analyst is tuning a SIEM to detect lateral movement. Which THREE log sources would provide the most useful data for this purpose? (Choose THREE.)

Select 3 answers
A.Windows Event Logs showing network connections and process creation.
B.Web server logs for external requests.
C.DNS logs for external domain queries.
D.System logs showing authentication events across hosts.
E.Firewall logs showing connections between internal hosts.
AnswersA, D, E

Windows Event Logs capture process creation (Sysmon Event ID 1) and network connection events (Event ID 3), exposing the parent-child process chains and outbound connections lateral movement tools generate. This directly satisfies the SIEM tuning requirement by supplying host-level telemetry that reveals anomalous execution and remote connection patterns across endpoints.

Why this answer

Option A is correct because Windows Event Logs such as Security Event ID 4688 (process creation) and Sysmon Event ID 3 (network connection) reveal suspicious process-to-network relationships that are hallmarks of lateral movement tools like PsExec or Cobalt Strike. Option D is correct because system logs capturing authentication events (e.g., Windows 4624/4625, Linux sshd and sudo entries) across multiple hosts expose pass-the-hash, credential reuse, and remote logon patterns central to lateral movement. Option E is correct because firewall logs showing internal-to-internal connections (east-west traffic) highlight anomalous host-to-host communication that would otherwise be invisible at the perimeter.

Option B is not appropriate because web server logs for external requests focus on inbound client activity against a service, not host-to-host movement inside the network. Option C is not appropriate because DNS logs for external domain queries are more useful for command-and-control and exfiltration detection than for identifying lateral movement between internal hosts.

277
MCQmedium

In Security Onion, an analyst runs 'squert' and sees a high number of alerts from a single source IP across multiple destination ports. What is the most likely cause?

A.Denial of service
B.SQL injection
C.Port scan
D.Phishing attack
AnswerC

A single source IP contacting many destination ports in rapid succession matches the signature of a port scan, which Squert surfaces as numerous alerts across multiple destination ports. This satisfies the stem's pattern of one source hitting many ports.

Why this answer

Squert is a web interface for Sguil in Security Onion that visualizes alert data from the intrusion detection system (IDS). A high number of alerts from a single source IP targeting multiple destination ports is a classic signature of a port scan, where the attacker probes a range of ports on one or more targets to discover open services. The IDS triggers multiple alerts because each probe (e.g., SYN packets to different ports) matches a detection rule, such as those for TCP SYN scans.

Exam trap

Cisco often tests the distinction between a port scan and a denial of service attack, where candidates mistakenly associate 'high number of alerts' with DoS, but the key differentiator is the single source IP targeting multiple destination ports versus overwhelming a single service.

How to eliminate wrong answers

Option A is wrong because a denial of service (DoS) attack typically floods a single target with traffic to overwhelm it, resulting in alerts from many source IPs or a high volume to a single port, not a single source IP across multiple destination ports. Option B is wrong because SQL injection attacks target web application parameters (e.g., HTTP GET/POST fields) and would generate alerts related to SQL syntax in payloads, not a pattern of probes across many ports. Option D is wrong because phishing attacks involve social engineering via email or malicious links, which would trigger alerts on email headers or URL patterns, not a single IP scanning multiple ports.

278
MCQmedium

A Windows Event Log shows Event ID 4625 multiple times from the same source IP address. What type of activity does this indicate?

A.Failed logon attempts indicating a possible brute-force attack
B.Successful logon after multiple attempts
C.Credential validation by a domain controller
D.A user account was created
AnswerA

Event ID 4625 is logged whenever a logon attempt fails, and repeated occurrences from one source IP address indicate sustained authentication failures consistent with brute-force activity. This directly satisfies the stem's constraint of multiple 4625 events from the same source, distinguishing it from successful logons (4624) or lockouts (4740).

Why this answer

Event ID 4625 indicates a failed logon attempt. Multiple failures from the same source suggest a brute-force attack.

279
MCQmedium

A security analyst is investigating an alert from a host-based intrusion detection system (HIDS) that detected a file modification in the system32 directory. Which log source should the analyst check first to understand the process that made the change?

A.Firewall logs.
B.Windows Event Logs.
C.NetFlow data.
D.DNS logs.
AnswerB

Windows Event Logs, specifically Security auditing entries such as 4663 and 4656, record the process ID and account responsible for file modifications. This gives the analyst the causal process behind the system32 change, which a HIDS alert alone does not identify.

Why this answer

Windows Event Logs (specifically Security Event ID 4656 or 4663) record detailed information about file operations, including the process that initiated the modification. Since the HIDS detected a file change in system32, the Event Logs provide the process name, user account, and timestamp needed to trace the source of the modification.

Exam trap

Cisco often tests the distinction between host-based logs (Windows Event Logs) and network-based logs (firewall, NetFlow, DNS), expecting candidates to recognize that only host logs can reveal the process responsible for a local file change.

How to eliminate wrong answers

Option A is wrong because firewall logs track network traffic (source/destination IPs, ports, protocols) and do not record local file system operations on a host. Option C is wrong because NetFlow data captures network flow metadata (IP conversations, byte counts) and has no visibility into local file modifications. Option D is wrong because DNS logs record domain name resolution queries and responses, not process-level file changes on the endpoint.

280
MCQmedium

A security analyst is reviewing baseline network traffic and notices that the normal HTTP traffic volume has increased by 300% over the past hour. The increase is from a single client IP to a single external web server. What does this indicate?

A.Possible data exfiltration via HTTP
B.A denial-of-service (DoS) attack against the web server
C.A distributed denial-of-service (DDoS) attack from botnets
D.Normal fluctuations during peak hours
AnswerA

A 300% surge from one internal client to a single external server, over HTTP, indicates bulk transfer rather than normal browsing. The single-source, single-destination pattern and sustained volume satisfy the baseline-deviation constraint, pointing to possible data exfiltration via HTTP.

Why this answer

A 300% increase in HTTP traffic from a single client IP to a single external web server is anomalous and strongly suggests data exfiltration. Attackers often use HTTP (port 80) to tunnel stolen data out of a network because it is typically allowed through firewalls and proxies without inspection. The fact that the traffic is from one IP to one server indicates a targeted, non-distributed activity, which aligns with exfiltration rather than a volumetric attack.

Exam trap

Cisco often tests the distinction between a single-source anomaly (exfiltration or DoS) and a multi-source anomaly (DDoS), and the trap here is that candidates confuse a traffic volume increase with a DoS attack, ignoring the single-source indicator that points to exfiltration.

How to eliminate wrong answers

Option B is wrong because a denial-of-service (DoS) attack would typically involve a flood of traffic from a single source to overwhelm the server, but the scenario describes a 300% increase in HTTP traffic volume, which is more consistent with sustained data transfer than a flood designed to cause resource exhaustion. Option C is wrong because a distributed denial-of-service (DDoS) attack involves multiple source IPs (botnets) generating traffic, but the question explicitly states the increase is from a single client IP, ruling out a distributed attack. Option D is wrong because a 300% increase from a single IP to a single external server is not normal peak-hour fluctuation; normal traffic patterns show gradual changes across many clients, not a sudden spike from one source.

281
MCQhard

A security analyst is examining a memory dump from a compromised host and finds a small piece of code that resides only in memory, has no corresponding file on disk, and injects itself into a running legitimate process. The code does not replicate to other systems. Which type of malware best describes this?

A.A fileless malware that operates in memory and injects into processes
B.A worm that spreads across the network
C.A rootkit that hides its presence by modifying the kernel
D.A trojan that disguises itself as legitimate software
AnswerA

Fileless malware resides in memory, often using PowerShell, reflective DLL injection, or process hollowing, and leaves little or no trace on disk. It typically injects into legitimate processes to evade detection. The scenario matches these characteristics: no file on disk, memory-resident, and process injection, without self-replication to other systems.

Why this answer

Fileless malware operates entirely in memory, often by injecting into legitimate processes, and leaves no file on disk. This makes it difficult to detect with traditional file-based antivirus. The absence of a disk file and the process injection behavior are the defining characteristics, distinguishing it from worms, trojans, and rootkits, which typically involve files or kernel modifications.

Exam trap

The trap here is equating any memory-resident code with a rootkit, when the absence of disk files and process injection specifically point to fileless malware.

282
MCQhard

To protect sensitive data at rest, a company uses AES-256 encryption. This primarily ensures which security goal?

A.Confidentiality
B.Availability
C.Integrity
D.Non-repudiation
AnswerA

AES-256 encryption renders stored data unreadable to anyone lacking the cryptographic key, directly satisfying the confidentiality goal for data at rest. Unlike integrity controls such as hashing, encryption specifically prevents unauthorised disclosure, which is the exact protection the scenario demands for sensitive information.

Why this answer

AES-256 encryption transforms plaintext data into ciphertext using a 256-bit symmetric key, rendering it unreadable without the correct decryption key. This directly ensures confidentiality by preventing unauthorized access to the stored data, even if the storage medium is compromised.

Exam trap

Cisco often tests the distinction between encryption (confidentiality) and hashing (integrity), so the trap here is confusing AES-256's role in protecting data from unauthorized reading with the ability to detect tampering, which would require a separate integrity mechanism.

How to eliminate wrong answers

Option B is wrong because availability refers to ensuring data is accessible when needed, typically addressed by redundancy, backups, and fault tolerance, not encryption. Option C is wrong because integrity ensures data has not been tampered with, usually provided by hashing algorithms (e.g., SHA-256) or HMAC, not encryption alone. Option D is wrong because non-repudiation prevents a party from denying an action, achieved through digital signatures and public key infrastructure (PKI), not symmetric encryption like AES-256.

283
MCQhard

A company's security policy requires that all remote access connections be authenticated using a certificate. Which type of control is this?

A.Corrective
B.Preventive
C.Detective
D.Deterrent
AnswerB

Certificate-based authentication blocks connections lacking a valid certificate before access is granted, satisfying the policy's requirement that all remote access be certificate-authenticated. Preventive controls stop the event occurring, unlike detective or corrective controls that act after an attempt.

Why this answer

Requiring a certificate for remote access authentication enforces a specific identity verification method before granting access. This is a preventive control because it stops unauthorized connections from being established by ensuring only devices with a valid certificate can initiate the session, directly blocking access before any data exchange occurs.

Exam trap

Cisco often tests the distinction between preventive and deterrent controls, where candidates mistakenly choose deterrent because they think a certificate requirement 'discourages' attackers, but the correct classification is preventive because it technically enforces authentication and blocks access without it.

How to eliminate wrong answers

Option A is wrong because corrective controls (e.g., restoring from backup after a breach) are applied after an incident to mitigate damage, not before access is granted. Option C is wrong because detective controls (e.g., logging failed authentication attempts) identify ongoing or past violations but do not block the initial connection. Option D is wrong because deterrent controls (e.g., warning banners) discourage malicious behavior through fear of consequences but do not technically enforce authentication like a certificate requirement does.

284
MCQhard

An analyst reviewing network alerts notices a rule triggered for 'ET SCAN NMAP -sU scan' based on traffic to a Linux server. The packet capture shows multiple UDP packets to various ports, and for closed ports, the server responds with ICMP Destination Unreachable (Port Unreachable). Which type of scan is being performed, and how should the analyst classify this alert?

A.TCP SYN scan; true positive
B.UDP scan; true positive
C.UDP scan; false positive
D.TCP connect scan; true negative
AnswerB

Nmap's UDP scan sends zero-byte UDP datagrams to target ports; closed ports return ICMP port unreachable, matching the capture. The rule signature and traffic genuinely reflect scanning activity, so the analyst classifies it as a true positive rather than a false positive.

Why this answer

UDP scans send UDP packets; closed ports respond with ICMP Port Unreachable. This matches the alert signature, indicating a true positive for a UDP scan.

285
MCQmedium

During a security incident, an analyst needs to preserve network evidence for forensic analysis. Which action should be taken first?

A.Isolate the affected systems from the network.
B.Create a forensic image of all hard drives.
C.Shut down the affected systems to prevent further damage.
D.Capture the contents of volatile memory from affected systems.
AnswerD

Volatile memory such as RAM and running processes is lost on shutdown or reboot, so capturing it first preserves evidence that cannot be recovered later. This satisfies the stem's ordering requirement, preceding disk imaging and other less perishable collection steps.

Why this answer

During a security incident, the first priority is to capture volatile memory (RAM) because it contains critical evidence such as running processes, network connections, and encryption keys that will be lost when the system is powered off. Option D is correct because volatile data is ephemeral and must be collected before any action that could alter the system state, such as shutdown or isolation.

Exam trap

Cisco often tests the order of volatility (RFC 3227) and the misconception that isolating or shutting down the system is the safest first step, when in fact it destroys the most volatile evidence.

How to eliminate wrong answers

Option A is wrong because isolating the affected systems from the network may trigger network-level changes (e.g., ARP cache updates, connection teardowns) that alter volatile memory contents, and it does not preserve the current state of memory. Option B is wrong because creating a forensic image of hard drives is a non-volatile data acquisition step that should occur after volatile memory capture, as it does not preserve RAM contents and may be delayed without losing evidence. Option C is wrong because shutting down the system destroys all volatile memory data (e.g., running processes, open network sockets, encryption keys) and may also cause disk writes (e.g., pagefile updates) that overwrite evidence.

286
MCQhard

A threat hunter is examining a Windows 10 host and wants to determine whether a suspicious executable was recently run by a user. The hunter knows that Windows records application execution history in the registry under the UserAssist key. Which location should the hunter inspect to find this data for the currently logged-on user?

A.HKCU\Software\Microsoft\Windows\CurrentVersion\Run
B.HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store
C.HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{GUID}\Count
D.HKLM\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings
AnswerC

The UserAssist key under HKCU stores ROT13-encoded entries for programs launched through Windows Explorer, including the executable name and a run counter. Inspecting the Count subkey under the GUID path reveals execution history for the current user, which is exactly what the threat hunter needs to confirm recent execution.

Why this answer

UserAssist under HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist stores per-user execution history for programs launched through Explorer. The Count subkey under each GUID contains ROT13-encoded values that include the program path and a run counter, letting the hunter confirm recent execution by the current user.

Exam trap

The trap here is confusing execution-history artifacts like UserAssist with autostart persistence keys like Run, which record configuration rather than a history of what actually ran.

287
Multi-Selectmedium

Which TWO of the following are best practices for implementing a security policy?

Select 2 answers
A.Use technical jargon to ensure precision
B.Avoid enforcement to promote user compliance
C.Write the policy once and never change it
D.Review and update the policy annually
E.Obtain management approval and support
AnswersD, E

Scheduled annual review keeps the policy aligned with evolving threats, technology and business changes. Without periodic revision, controls become stale and gaps emerge, so regular review is a recognised lifecycle best practice for maintaining policy effectiveness.

Why this answer

Option D is correct because security policies must be reviewed and updated annually (or whenever significant changes occur in the threat landscape, technology, or business operations) to remain relevant and effective; a stale policy can leave the organization exposed to new risks. Option E is correct because obtaining management approval and support is essential: without executive sponsorship, the policy lacks authority, funding, and the ability to enforce compliance across the organization. Option A is incorrect because technical jargon reduces readability and understanding for non-technical staff, undermining policy adoption.

Option B is incorrect because avoiding enforcement does not promote genuine compliance; policies require consistent enforcement to be effective. Option C is incorrect because writing a policy once and never changing it ignores evolving threats, regulations, and business needs, making the policy obsolete.

Exam trap

Cisco often tests the misconception that security policies are static, one-time documents, when in fact they require periodic review and management buy-in to remain effective and enforceable.

288
MCQeasy

An analyst is monitoring network traffic and sees a large number of TCP SYN packets sent to various ports on a single host from the same source IP. Which type of attack is most likely occurring?

A.DNS amplification
B.ARP poisoning
C.Port scan
D.SYN flood
AnswerC

A port scan sends TCP SYN packets to many ports on one host to map which services are listening. Half-open scans exploit the SYN/ACK or RST response to classify each port as open, closed or filtered, matching the stem's single source IP and multiple destination ports.

Why this answer

A port scan involves an attacker sending TCP SYN packets to multiple ports on a target host to determine which ports are open and listening. The key indicator is the single source IP targeting various ports on a single host, which matches the behavior of a SYN scan (half-open scan) used to map services without completing the full TCP three-way handshake.

Exam trap

Cisco often tests the distinction between a port scan (reconnaissance, multiple ports) and a SYN flood (DoS, single port with high volume), so the trap here is confusing the reconnaissance technique of scanning many ports with the denial-of-service technique of overwhelming a single service.

How to eliminate wrong answers

Option A is wrong because DNS amplification uses spoofed source IPs to send small queries to open DNS resolvers, which then send large responses to the victim, not TCP SYN packets to various ports on a single host. Option B is wrong because ARP poisoning involves sending forged ARP replies to associate the attacker's MAC address with the IP of a legitimate host on a local network, not sending TCP SYN packets to multiple ports. Option D is wrong because a SYN flood targets a single port (or a few ports) with a high volume of SYN packets to exhaust the target's connection queue, not a large number of SYN packets sent to various ports as part of reconnaissance.

289
Multi-Selecthard

A company is implementing a security policy to reduce risk. Which THREE activities are examples of risk mitigation? (Choose three.)

Select 3 answers
A.Implementing access controls
B.Accepting the risk without action
C.Encrypting sensitive data
D.Purchasing cyber insurance
E.Patching vulnerabilities
AnswersA, C, E

Implementing access controls directly satisfies the stem's requirement to reduce risk by limiting who can reach systems and data. Authentication, authorisation and least-privilege enforcement, typically via Microsoft Entra ID, shrink the attack surface and block unauthorised actions, lowering both likelihood and impact of a breach.

Why this answer

Implementing access controls (A) is a risk mitigation activity because it enforces authentication and authorization mechanisms (such as RBAC, least privilege, and MFA) that reduce the likelihood of unauthorized access to systems and data. Encrypting sensitive data (C) mitigates risk by protecting confidentiality, so even if data is intercepted or stolen, it remains unreadable without the proper cryptographic keys (e.g., AES-256). Patching vulnerabilities (E) mitigates risk by remediating known weaknesses (e.g., CVEs) that attackers could exploit, thereby reducing the attack surface.

Accepting the risk without action (B) is risk acceptance, not mitigation, since no controls are applied. Purchasing cyber insurance (D) is risk transference, as the financial impact is shifted to an insurer rather than reduced through technical or administrative controls.

290
Multi-Selecthard

Which THREE components are part of a Public Key Infrastructure (PKI)? (Choose three.)

Select 3 answers
A.Registration Authority (RA)
B.Symmetric encryption key
C.Digital certificate
D.Hash function
E.Certificate Authority (CA)
AnswersA, C, E

The Registration Authority verifies subscriber identity and approves or rejects certificate requests before forwarding them to the Certificate Authority for issuance. It is a core PKI component, separating identity vetting from certificate signing so the CA is not exposed to untrusted request traffic.

Why this answer

A Registration Authority (RA) is a correct component because it acts as the intermediary that verifies subscriber identity and processes certificate requests before forwarding them to the CA, offloading identity-proofing duties from the CA. A digital certificate is correct because it is the core PKI artifact—an X.509 structure binding a subject's public key to identity, signed by the CA. A Certificate Authority (CA) is correct because it is the trust anchor that issues, signs, revokes, and manages certificates, and publishes CRLs or OCSP responses.

A symmetric encryption key is not a PKI component; PKI is built on asymmetric key pairs, and symmetric keys are used for bulk data encryption outside the PKI trust framework. A hash function is a cryptographic primitive used within PKI (e.g., for signing and fingerprints) but is not itself a PKI component or role.

Exam trap

Cisco often tests the distinction between PKI components (CA, RA, digital certificate) and cryptographic primitives (hash functions, symmetric keys), so candidates mistakenly select hash functions or symmetric keys because they are associated with security, but they are not structural PKI components.

291
MCQeasy

Which term describes a weakness in a system that could be exploited by a threat?

A.Vulnerability
B.Risk
C.Exploit
D.Threat
AnswerA

A vulnerability is precisely a weakness or flaw in a system, application, or configuration that a threat actor could exploit to compromise confidentiality, integrity, or availability. This directly matches the stem's requirement for a term describing an exploitable weakness, distinguishing it from a threat (the potential attacker) or risk (the likelihood of exploitation).

Why this answer

A vulnerability is a weakness in a system, such as a missing security patch, misconfiguration, or design flaw, that a threat actor could exploit to compromise confidentiality, integrity, or availability. In the context of the 200-201 exam, this aligns with the core security concept that vulnerabilities are the specific gaps that make an asset susceptible to attack.

Exam trap

Cisco often tests the distinction between vulnerability and exploit by describing a scenario where a tool is used to break into a system, leading candidates to mistakenly select 'exploit' when the question asks for the weakness itself.

How to eliminate wrong answers

Option B (Risk) is wrong because risk is the potential for loss or damage when a threat exploits a vulnerability, not the weakness itself. Option C (Exploit) is wrong because an exploit is the actual code, technique, or tool used to take advantage of a vulnerability, not the weakness. Option D (Threat) is wrong because a threat is any potential danger (e.g., a hacker, malware, or natural disaster) that could cause harm, not the system weakness.

292
Multi-Selectmedium

A security analyst is correlating network and endpoint telemetry to detect a host infected with malware that is attempting to establish persistence and communicate externally. Which TWO artifacts would best support this investigation? (Choose two.)

Select 2 answers
A.Sysmon Event ID 13 registry value set events for Run key modifications
B.NetFlow records showing periodic outbound connections to an external IP
C.DHCP server logs showing IP address leases for the subnet
D.Antivirus scan reports from the previous quarter
E.Windows Event ID 4688 process creation events for every process on all hosts
AnswersA, B

Sysmon Event ID 13 records registry value set operations, including changes to Run keys, which are a common persistence mechanism. By capturing the process that wrote the value and the exact registry path, analysts can identify which executable will launch at logon. This directly supports the persistence portion of the investigation and links the registry change to a specific process on the infected host.

Why this answer

To confirm both persistence and external communication, the analyst needs an endpoint artifact that shows the persistence mechanism and a network artifact that shows beaconing. Sysmon registry value set events reveal Run key modifications used for persistence, while NetFlow records expose periodic outbound connections to an external IP. Together they link the infected host's persistence to its command-and-control channel.

Exam trap

The trap here is choosing high-volume sources like all process creation events instead of the targeted registry and flow artifacts that directly evidence persistence and beaconing.

293
MCQhard

An analyst examines PCAP and sees multiple SMB sessions from internal host 10.1.1.10 to 10.1.1.20, 10.1.1.30, and 10.1.1.40 within seconds. The NTLM authentication contains a hash parameter that is identical across sessions. Which lateral movement technique is most likely being used?

A.Golden ticket
B.Pass-the-hash
C.Kerberoasting
D.Pass-the-ticket
AnswerB

Pass-the-hash reuses a captured NTLM hash to authenticate without cracking the plaintext password, so the identical hash parameter across all three SMB sessions matches the stem's constraint exactly. The single internal source host fanning out to multiple targets within seconds is characteristic of automated lateral movement using stolen credentials.

Why this answer

Pass-the-hash uses the same NTLM hash to authenticate to multiple hosts without knowing the plaintext password.

294
MCQmedium

During incident response on a Linux server, an analyst runs 'ss -tlnp' and sees an SSH service listening on a non-standard high port. Which step should the analyst take next to investigate potential unauthorized access?

A.Review the bash history of root user.
B.Check /etc/crontab for malicious scheduled tasks.
C.Run 'ps aux' to list all processes.
D.Examine /var/log/auth.log for successful logins.
AnswerD

A non-standard SSH port suggests possible backdoor or compromised service, so the analyst must determine whether anyone authenticated successfully. /var/log/auth.log records SSH authentication events, letting the analyst confirm or rule out unauthorised logins before containment.

Why this answer

The correct next step is to examine /var/log/auth.log because it records authentication events, including successful SSH logins. Since the SSH service is listening on a non-standard high port, an attacker may have modified the SSH configuration to evade detection and then logged in. Reviewing auth.log will reveal if any unauthorized successful logins occurred, along with source IPs, usernames, and timestamps, which are critical for determining the scope of the incident.

This directly addresses the potential unauthorized access indicated by the unusual listening port.

Exam trap

The trap here is that candidates may focus on persistence mechanisms (like cron jobs) or process listing instead of the immediate authentication evidence, confusing the step of verifying unauthorized access with later stages of incident response.

How to eliminate wrong answers

Option A is wrong because reviewing root's bash history may show commands executed after login, but it does not confirm whether an unauthorized login occurred or provide authentication details; it is a post-compromise artifact, not the immediate next step to investigate access. Option B is wrong because checking /etc/crontab for malicious scheduled tasks is a persistence mechanism check, not directly related to investigating the SSH service on a non-standard port; it assumes the attacker already established persistence and skips verifying initial access. Option C is wrong because running 'ps aux' lists current processes, which might show the SSH daemon but does not provide historical authentication data or confirm unauthorized access; it is useful for live analysis but less specific than auth.log for login events.

295
Multi-Selecthard

Which TWO of the following are characteristics of behavioral-based anomaly detection in network monitoring? (Select 2)

Select 2 answers
A.Establishes a baseline of normal traffic
B.Relies on predefined signatures
C.Can inspect encrypted traffic without decryption
D.Uses static rules written by administrators
E.Can detect zero-day attacks
AnswersA, E

Behavioural anomaly detection first learns a statistical profile of normal traffic volumes, protocols and peer relationships, then flags deviations from that learned norm. Establishing this baseline satisfies the stem's requirement for a characteristic of behavioural-based anomaly detection.

Why this answer

Option A is correct because behavioral-based anomaly detection works by first establishing a baseline of what constitutes normal network traffic (protocols, volumes, timing, hosts), then flagging deviations from that learned norm. Option E is correct because, since it does not depend on known attack patterns, behavioral anomaly detection can identify previously unknown (zero-day) attacks whose traffic behavior deviates from the established baseline. Option B is incorrect because predefined signatures describe signature-based detection (e.g., IDS/IPS rules), not behavioral anomaly detection.

Option C is incorrect because encrypted traffic cannot be meaningfully inspected for behavior without decryption (or metadata/TLS fingerprinting techniques), and this is not a defining characteristic of anomaly detection. Option D is incorrect because static administrator-written rules describe rule-based detection, whereas behavioral detection relies on dynamically learned baselines rather than static rules.

Exam trap

The trap is mixing characteristics of signature-based and behavioral-based detection; candidates may incorrectly think behavioral detection can inspect encrypted traffic or use static rules.

296
MCQhard

A SOC team is evaluating a SIEM rule that triggers on 'more than 10 failed login attempts from a single source within 5 minutes.' The rule is generating too many alerts from a legitimate external monitoring service. How should the rule be modified?

A.Increase the threshold to 20 failed attempts.
B.Disable the rule and rely on other detection methods.
C.Add an exception for the source IP of the monitoring service.
D.Extend the time window to 10 minutes.
AnswerC

Adding an exception for the monitoring service's source IP prevents the threshold rule from firing on its known, legitimate traffic. This preserves detection of genuine brute-force attempts from other sources while eliminating the false positives that flooded the SOC, satisfying the need to reduce alert noise.

Why this answer

The rule is generating false positives from a known, legitimate source. Adding an exception for the monitoring service's source IP allows the SIEM to continue detecting actual brute-force attacks while ignoring expected traffic from that specific host. This is a standard whitelisting technique in SIEM rule tuning to reduce noise without compromising security coverage.

Exam trap

Cisco often tests the concept that tuning a SIEM rule should preserve detection capability for actual threats, so candidates mistakenly choose threshold or time-window adjustments (A or D) instead of the more precise fix of adding an exception for the known benign source.

How to eliminate wrong answers

Option A is wrong because increasing the threshold to 20 failed attempts would still generate alerts from the monitoring service if it performs more than 20 attempts in 5 minutes, and it could also delay detection of a real brute-force attack that uses fewer than 20 attempts. Option B is wrong because disabling the rule entirely removes detection of brute-force attacks from all sources, creating a critical security gap that cannot be justified by a single false positive source. Option D is wrong because extending the time window to 10 minutes would still trigger on the monitoring service if it performs more than 10 failed attempts in that longer period, and it would also slow down detection of actual attacks by requiring a longer observation window.

297
Multi-Selecthard

A SOC Tier 1 analyst is processing alerts. Which THREE tasks are typical for a Tier 1 analyst? (Select three.)

Select 3 answers
A.Conduct deep malware analysis
B.Develop new detection signatures
C.Execute basic investigation using standard tools
D.Monitor alerts and events
E.Perform initial triage and categorization
AnswersC, D, E

Tier 1 performs basic investigation with standard tooling such as SIEM queries and signature lookups, gathering enough evidence to confirm or dismiss an alert before escalating. Deeper forensics and remediation remain Tier 2 or Tier 3 responsibilities.

Why this answer

Option C is correct because Tier 1 analysts perform basic investigations with standard tools such as SIEM queries, log review, and endpoint/EDR lookups to validate alerts before escalation. Option D is correct because continuous monitoring of alerts and events from sources like SIEM, IDS/IPS, and EDR is a core Tier 1 responsibility. Option E is correct because initial triage and categorization—confirming true/false positive, assigning severity, and routing to the right queue—is exactly the Tier 1 role.

Option A does not belong because deep malware analysis (reverse engineering, sandboxing, code disassembly) is typically Tier 2/Tier 3 or a dedicated malware analyst function. Option B does not belong because developing new detection signatures or rules is an engineering/detection-content task, not a Tier 1 monitoring and triage duty.

298
MCQhard

A security analyst is investigating a Linux server that is suspected of being compromised. The analyst runs 'ls -l /proc/1234/exe' and sees the output: '/proc/1234/exe -> /tmp/.hidden/backdoor (deleted)'. What does this output indicate?

A.The process 1234 is a legitimate system process that was updated, and the old executable was deleted.
B.The process 1234 is a zombie process that has terminated but still appears in the process list.
C.The process 1234 is running from a deleted executable file, which may indicate malware hiding its presence.
D.The process 1234 has a corrupted executable file that needs to be replaced.
AnswerC

The output shows that the executable for process 1234 was deleted from the filesystem but is still running. This is a common technique used by malware to hide its executable, making it difficult to find on disk. The path '/tmp/.hidden/backdoor' suggests a suspicious location. Thus, this indicates potential malware activity.

Why this answer

The output indicates that process 1234 is executing from a file that has been deleted from the filesystem. Malware often deletes its executable after launching to evade detection by file-based scans. The hidden directory and suspicious name 'backdoor' further suggest malicious intent.

Therefore, the correct interpretation is that the process is running from a deleted executable, a common malware hiding technique.

Exam trap

The trap here is assuming that a deleted executable always indicates a benign update, ignoring the suspicious path and the stealth tactic used by malware.

299
MCQmedium

A SIEM correlation rule is designed to detect a brute-force attack. The rule triggers when an event includes 10 or more failed logins from the same source IP within 1 minute. An analyst sees an alert for 12 failed logins from IP 10.0.0.1 in 2 minutes. Why did the rule not trigger?

A.The source IP is not in the watch list
B.The time window is too short; the rule requires 10 failures in 1 minute, but this occurred over 2 minutes
C.The rule only counts successful logins
D.The alert severity is too low
AnswerB

The rule's threshold is bound to a one-minute sliding window, so twelve failures spread across two minutes never accumulate ten events inside any single window. The correlation engine evaluates count per interval, not cumulative totals, so the two-minute duration itself prevents the threshold from being met.

Why this answer

The rule requires 10+ failures in 1 minute. In 2 minutes, the rate is 6 per minute, which is below threshold.

300
MCQmedium

A network analyst notices that a host is sending a large volume of traffic to an external IP address on port 443 during non-business hours. The traffic volume is significantly higher than the established baseline. Which type of data exfiltration technique should be suspected?

A.HTTP post
B.HTTPS exfiltration
C.ICMP tunneling
D.DNS tunneling
AnswerB

Sustained high-volume traffic to an external address on port 443 outside business hours indicates data being tunnelled inside encrypted HTTPS sessions, evading content inspection. The volume and timing deviation from baseline satisfy the scenario's exfiltration indicators.

Why this answer

Port 443 is the default port for HTTPS (HTTP over TLS). The large volume of traffic during non-business hours, exceeding the baseline, strongly suggests the attacker is using encrypted HTTPS connections to hide data exfiltration. Unlike plaintext HTTP, HTTPS encryption makes it difficult for network monitoring tools to inspect the payload, allowing the attacker to blend malicious traffic with legitimate encrypted web traffic.

Exam trap

Cisco often tests the association of common protocols with their default ports; the trap here is that candidates might see 'large volume of traffic' and immediately think of HTTP post (option A) without noticing the port number 443, which clearly indicates encrypted HTTPS traffic.

How to eliminate wrong answers

Option A is wrong because HTTP post uses port 80, not port 443, and while it could be used for data exfiltration, the question specifies port 443 which is HTTPS. Option C is wrong because ICMP tunneling uses ICMP echo request/reply packets (typically on the network layer) and does not use TCP port 443; it would also likely show unusual ICMP traffic patterns, not high-volume TCP traffic on port 443. Option D is wrong because DNS tunneling uses UDP port 53 (or TCP port 53 for large queries) to encode data in DNS queries and responses, not TCP port 443.

Page 3

Page 4 of 13

Page 5