Courseiva

Cisco CyberOps Associate 200-201 (200-201) — Questions 376–450

968 questions total · 13pages · All types, answers revealed

Page 5

Page 6 of 13

Page 7
376
MCQhard

A security analyst is examining a suspicious executable found on a compromised host. The analyst runs the file in a sandbox and observes that it creates a mutex named 'Global\MyMutex123', attempts to connect to an external IP address on port 443, and modifies the registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Run. Which type of analysis is the analyst performing?

A.Static analysis
B.Memory forensics
C.Log analysis
D.Dynamic analysis
AnswerD

Dynamic analysis involves executing malware in a controlled environment, such as a sandbox, and observing its behavior, including process creation, network traffic, and file system changes. The analyst's observations of mutex creation, outbound connections, and registry modification are classic dynamic indicators. This approach reveals runtime actions that static analysis might miss due to obfuscation or packing.

Why this answer

Dynamic analysis is the process of executing malware in a controlled environment and observing its behavior, such as network connections, registry changes, and mutex creation. The analyst's actions in the sandbox directly match this definition. Static analysis, memory forensics, and log analysis do not involve running the sample and monitoring its runtime effects.

Exam trap

The trap here is equating sandbox execution with memory forensics, but memory forensics examines an existing memory image without running the sample.

377
MCQmedium

An analyst receives an IDS alert with signature name 'ET TROJAN Win32.Zeus Checkin' and severity 'high'. The alert shows source IP 192.168.1.50 and destination IP 198.51.100.20 on port 443. Which action should the analyst take FIRST?

A.Isolate the source host from the network to prevent further communication.
B.Check the host's web browsing history for suspicious websites.
C.Immediately block the destination IP on the firewall.
D.Ignore the alert because the traffic is encrypted over port 443.
AnswerA

The signature indicates an active Zeus trojan check-in from internal host 192.168.1.50 to external infrastructure over port 443, confirming likely compromise and command-and-control beaconing. Isolating that host immediately halts exfiltration and lateral movement, the priority containment step before deeper forensic analysis.

Why this answer

The alert indicates a high-severity Zeus Trojan check-in, which is a known malware communicating with a command-and-control (C2) server. The first priority is to contain the threat by isolating the source host (192.168.1.50) to prevent further data exfiltration or lateral movement. Even though the traffic is encrypted over port 443 (HTTPS), the signature confirms malicious activity, so immediate isolation is the correct initial response per incident response best practices.

Exam trap

Cisco often tests the principle that containment (isolating the host) takes precedence over blocking external IPs or performing forensic analysis, and that encryption does not invalidate IDS alerts because signatures can detect malicious patterns in metadata or handshake characteristics.

How to eliminate wrong answers

Option B is wrong because checking web browsing history is a secondary forensic step that delays containment; the immediate priority is to stop active C2 communication. Option C is wrong because blocking the destination IP on the firewall may disrupt the C2 channel but does not prevent the compromised host from communicating with other C2 servers or spreading within the network; isolation of the host is more comprehensive. Option D is wrong because ignoring the alert due to encryption is a dangerous misconception—the IDS signature is based on behavioral or pattern analysis (e.g., JA3 fingerprint, packet timing) that can detect malware even over TLS; encryption does not make the alert invalid.

378
MCQhard

During an incident response, the SOC needs to determine the scope of a compromise by identifying all hosts that communicated with a known malicious IP in the last 30 days. Which data source would best support this analysis?

A.SNMP traps from routers
B.Syslog from the DHCP server
C.Firewall deny logs
D.NetFlow records from the router
AnswerD

NetFlow records capture IP-level flow metadata for every connection traversing the router, letting analysts query 30 days of historical traffic to enumerate all hosts that contacted the malicious IP. This directly satisfies the scope-identification requirement, unlike host-based logs limited to individual endpoints.

Why this answer

NetFlow records capture metadata about all IP traffic flows traversing a router, including source and destination IP addresses, ports, and timestamps. This allows the SOC to query for any host that communicated with the known malicious IP over the past 30 days, providing a complete picture of the compromise's scope. Unlike logs that only record denied traffic or administrative events, NetFlow records all successful communications, making it the ideal data source for this analysis.

Exam trap

Cisco often tests the distinction between logs that record only denied traffic (firewall deny logs) versus logs that record all traffic (NetFlow), leading candidates to mistakenly choose firewall deny logs because they associate firewalls with security monitoring.

How to eliminate wrong answers

Option A is wrong because SNMP traps from routers are used for network device monitoring and fault management (e.g., link up/down, CPU spikes), not for recording per-flow IP communication history with specific destinations. Option B is wrong because syslog from the DHCP server logs IP address lease assignments and client MAC addresses, but does not log the actual network traffic flows or communications between hosts and external IPs. Option C is wrong because firewall deny logs only record traffic that was blocked, not allowed traffic; since the malicious IP was likely contacted successfully, deny logs would miss the very communications needed to identify compromised hosts.

379
Multi-Selectmedium

During memory analysis using Volatility, an analyst wants to identify processes that may be hiding. Which TWO plugins are most useful for detecting hidden or injected code? (Choose two.)

Select 2 answers
A.malfind
B.pslist
C.dlllist
D.psxview
E.cmdline
AnswersA, D

The malfind plugin scans process memory regions for injected code by looking for pages marked executable that lack a corresponding mapped file on disk, exposing code injection and hidden payloads. This directly satisfies the stem's requirement to detect hidden or injected code during memory analysis.

Why this answer

Option A, malfind, is correct because it scans process memory for regions with suspicious characteristics typical of injected or hidden code, such as pages marked PAGE_EXECUTE_READWRITE (RWX) or memory that is not backed by a file on disk, which is a strong indicator of code injection or process hollowing. Option D, psxview, is correct because it cross-references multiple process-listing sources (e.g., pslist, psscan, thrdscan, csrss handles, session processes) and highlights discrepancies where a process appears in some listings but not others, which is a classic sign of a hidden process. Option B, pslist, is not correct here because it simply walks the active process linked list and will not reveal processes that have been unlinked to hide themselves.

Option C, dlllist, is not correct because it enumerates loaded DLLs for a given process and does not by itself detect hidden processes or injected code. Option E, cmdline, is not correct because it only retrieves process command-line arguments and provides no mechanism for detecting hidden or injected code.

Exam trap

200-201 often tests the difference between plugins that list processes (pslist) and those that detect hidden processes (psxview) or injected code (malfind); candidates must remember that pslist alone cannot reveal hidden processes.

380
MCQhard

A security analyst is reviewing a packet capture and notices that an attacker is sending a large number of SYN packets to a web server from spoofed source IP addresses. The server's connection table is filling up, and legitimate users cannot connect. Which type of attack is being described?

A.Smurf attack
B.SYN flood
C.Ping of death
D.UDP flood
AnswerB

A SYN flood is a type of denial-of-service attack where the attacker sends many SYN packets with spoofed source IP addresses. The server allocates resources for each half-open connection, eventually exhausting its connection table and preventing legitimate users from connecting. The scenario matches this exactly: spoofed SYNs, full connection table, and denial of service.

Why this answer

A SYN flood exploits the TCP three-way handshake by sending numerous SYN requests with spoofed source addresses. The server allocates resources for each half-open connection, eventually exhausting its backlog queue and denying service to legitimate clients. The scenario's description of spoofed SYNs and a full connection table confirms this attack.

Exam trap

The trap here is assuming any flood is a UDP flood; the distinguishing factor is the use of SYN packets and the TCP connection table exhaustion.

381
MCQhard

In a Zeek/Bro log, an analyst observes a connection with 'service' field set to 'dns' and 'query' field containing a long, random-looking subdomain. This could be indicative of which type of activity?

A.DNS tunneling for data exfiltration
B.DNS amplification attack
C.DNS cache poisoning
D.Normal DNS resolution for a legitimate service
AnswerA

DNS tunnelling encodes stolen data within subdomain labels of queries sent to an attacker-controlled authoritative nameserver. Zeek's `service` field identifying DNS, combined with an abnormally long, high-entropy subdomain, satisfies the exfiltration indicator: legitimate DNS labels are short and structured, whereas tunnelled payloads appear random to evade signature matching.

Why this answer

A long, random-looking subdomain in a DNS query is a classic indicator of DNS tunneling, where an attacker encodes exfiltrated data into DNS queries to bypass network security controls. Zeek/Bro logs showing a 'service' of 'dns' with such queries suggest the client is using the DNS protocol to covertly transmit data to an external authoritative server, which decodes and reassembles the payload.

Exam trap

Cisco often tests the distinction between DNS tunneling (exfiltration) and DNS amplification (DDoS), where candidates confuse the long query string of tunneling with the large response size of amplification, but the key is that amplification uses spoofed source IPs and small queries, not random subdomains.

How to eliminate wrong answers

Option B is wrong because a DNS amplification attack relies on sending small queries with a spoofed source IP to open resolvers, causing them to flood the victim with large responses; the 'query' field would typically be a fixed, short string (e.g., 'ANY isc.org'), not a long random subdomain. Option C is wrong because DNS cache poisoning involves corrupting a resolver's cache with forged DNS records, which does not manifest as a long random subdomain in the query itself; it would instead show unexpected IP addresses in the answer section. Option D is wrong because legitimate DNS queries for services like CDNs or load balancers may use long hostnames, but they follow a predictable pattern (e.g., 'cdn123.example.com') and are not random-looking; a truly random subdomain is a strong anomaly.

382
MCQhard

A security analyst needs to share threat intelligence with other organizations in a standardized, machine-readable format. Which combination of standards should the analyst use?

A.TAXII and MISP
B.STIX and TAXII
C.ISAC and STIX
D.OpenIOC and MISP
AnswerB

STIX provides the structured, machine-readable schema for describing indicators, threat actors and campaigns, while TAXII defines the transport protocol for exchanging that content between parties. Together they satisfy the requirement for standardised, automated threat-intelligence sharing.

Why this answer

STIX is a language for threat intelligence, and TAXII is a protocol for sharing it. They are commonly used together.

383
MCQeasy

Which type of malware is designed to spread automatically across networks without user interaction?

A.Ransomware
B.Virus
C.Trojan
D.Worm
AnswerD

Worms self-replicate and propagate across networks by exploiting vulnerabilities in services and protocols, requiring no user action such as opening attachments or clicking links. This autonomous spreading mechanism directly satisfies the stem's constraint of automatic network-wide distribution without interaction.

Why this answer

A worm is a standalone malware program that replicates itself to spread to other computers over a network, often exploiting vulnerabilities without any user intervention. Unlike viruses, worms do not require a host file or user action to propagate, making them capable of rapid, automated spread across networks.

Exam trap

Cisco often tests the distinction between a virus and a worm, where the trap is that candidates confuse 'self-replicating' with 'requires a host file,' leading them to incorrectly choose virus instead of worm for autonomous network spread.

How to eliminate wrong answers

Option A is wrong because ransomware typically requires user interaction (e.g., clicking a link or opening an attachment) to execute and encrypt files; it does not self-propagate automatically. Option B is wrong because a virus attaches itself to a legitimate host file or program and relies on user action (e.g., running the infected file) to spread, not autonomous network propagation. Option C is wrong because a Trojan disguises itself as legitimate software to trick users into installing it, and it does not self-replicate or spread automatically across networks.

384
MCQhard

During an incident, a forensic analyst needs to preserve evidence from a compromised hard drive. Which of the following steps is essential to maintain the chain of custody?

A.Deleting unnecessary files to reduce data volume
B.Storing the hard drive in a standard office drawer
C.Documenting the date, time, and person handling the evidence
D.Creating a bit-for-bit copy without write-blocking
AnswerC

Chain of custody requires an unbroken record proving who held the evidence, when, and for what purpose. Documenting date, time, and handler creates this auditable trail, ensuring the drive's integrity can be attested in court and any tampering or gaps are detectable.

Why this answer

Chain of custody requires documenting each transfer, including who handled evidence and when. Write-blocking prevents alteration, and hashing verifies integrity. Documentation of transfers is key.

385
MCQmedium

An analyst is investigating a Linux system and wants to view the current network connections. Which command is most appropriate to list listening TCP ports along with the associated processes?

A.netstat -anp
B.cat /proc/net/tcp
C.lsof -i TCP
D.ss -tlnp
AnswerD

The ss command with -tlnp lists TCP sockets in listening state, numeric ports, and the owning process. It reads kernel socket tables directly, making it faster than netstat and satisfying the requirement to show listening TCP ports with associated processes.

Why this answer

'ss -tlnp' lists TCP (-t) listening (-l) sockets with numeric ports (-n) and the owning process (-p), which is exactly what the analyst needs. The ss utility reads kernel netlink sockets directly, making it faster and more accurate than netstat on modern Linux systems.

Exam trap

The trap is choosing netstat out of habit — the exam expects recognition that ss is the modern, preferred tool for socket enumeration on Linux, and that -tlnp specifically filters listening TCP with processes.

How to eliminate wrong answers

Option A is wrong because 'netstat -anp' shows all sockets (listening and established) with numeric addresses and processes, but it is deprecated on many distributions and less precise than ss for filtering listening TCP ports. Option B is wrong because 'cat /proc/net/tcp' shows raw kernel TCP table entries in hex with no process mapping and no human-readable port names. Option C is wrong because 'lsof -i TCP' lists all TCP connections (not just listening) and requires parsing to isolate listeners.

386
Multi-Selecthard

A security team is implementing a remote access policy. Which TWO controls should be included to ensure secure remote access?

Select 2 answers
A.Multifactor authentication (MFA)
B.Single sign-on (SSO)
C.Password expiration every 90 days
D.Virtual private network (VPN)
E.Guest network access
AnswersA, D

Multifactor authentication satisfies the remote access policy by requiring a second verification factor beyond a password, defeating credential theft and replay attacks. Combined with conditional access in Microsoft Entra ID, it enforces sign-in risk evaluation, ensuring only verified identities reach corporate resources over untrusted networks.

Why this answer

Option A (Multifactor authentication (MFA)) is correct because requiring a second factor beyond a password (e.g., TOTP, push notification, or FIDO2 security key) defends against credential theft, phishing, and password reuse, which are the primary risks for remote access. Option D (Virtual private network (VPN)) is correct because a VPN establishes an encrypted tunnel (e.g., IPsec/IKEv2 or TLS) between the remote endpoint and the corporate network, protecting data in transit from interception and enabling authenticated, policy-controlled access to internal resources. Option B (Single sign-on (SSO)) is not a security control that secures the remote connection itself; it improves user convenience and centralizes authentication but does not encrypt traffic or add a verification factor.

Option C (Password expiration every 90 days) is a legacy practice that is no longer recommended by NIST and does not compensate for weak or stolen credentials. Option E (Guest network access) is an isolated, untrusted network segment and does not provide secure access to corporate resources.

Exam trap

200-201 often tests the misconception that SSO or password expiration are sufficient for secure remote access, when in fact MFA and VPN are the foundational controls.

387
Multi-Selectmedium

A security analyst is investigating a Linux host for signs of compromise. The analyst runs `ps aux` and notices a process named `kworker` with a high CPU usage. The analyst suspects this may be a masquerading malware process. Which TWO commands should the analyst use to verify whether this process is legitimate or malicious? (Choose two.)

Select 2 answers
A.`ls -l /proc/<PID>/exe` to check the executable path
B.`df -h` to check disk usage
C.`netstat -tulpn` to list all listening ports
D.`top -c` to view the process list with command lines
E.`cat /proc/<PID>/cmdline` to view the command line arguments
AnswersA, E

The /proc/<PID>/exe symlink points to the actual executable file. For a legitimate kernel worker, this link is typically absent or points to nothing because kernel threads have no user-space executable. If it points to a file in /tmp or another suspicious location, it indicates a masquerading process. This is a quick and effective check.

Why this answer

Legitimate kernel worker threads (kworker) have no user-space executable and an empty cmdline. Checking /proc/<PID>/exe reveals if the process points to a real binary, and /proc/<PID>/cmdline shows the command line. If either indicates a user-space path or non-empty arguments, the process is likely masquerading.

These two checks together provide strong evidence.

Exam trap

The trap here is relying on process names alone, which can be spoofed, instead of verifying the underlying executable and command line via /proc.

388
MCQhard

A security analyst needs to ensure that a message has not been tampered with during transit and that the sender cannot deny sending it. Which cryptographic method should be used?

A.Digital signature
B.Symmetric encryption
C.Hashing
D.Public key infrastructure (PKI)
AnswerA

A digital signature uses the sender's private key to sign a message hash, letting the recipient verify integrity via the public key and providing non-repudiation, since only the sender could have produced that signature. This satisfies both the tamper-detection and non-deniability requirements.

Why this answer

A digital signature provides both integrity (ensuring the message has not been tampered with) and non-repudiation (preventing the sender from denying they sent it). It works by hashing the message and encrypting that hash with the sender's private key; the recipient verifies the signature using the sender's public key. This cryptographic method uniquely binds the sender to the message, unlike other options that only address one of these requirements.

Exam trap

Cisco often tests the distinction between hashing (which provides integrity only) and digital signatures (which provide both integrity and non-repudiation), leading candidates to mistakenly choose hashing when non-repudiation is required.

How to eliminate wrong answers

Option B (Symmetric encryption) is wrong because it only provides confidentiality (secrecy) and does not provide integrity or non-repudiation; both parties share the same key, so the sender can deny sending the message. Option C (Hashing) is wrong because while it ensures integrity by detecting tampering, it does not provide non-repudiation since there is no key binding the hash to a specific sender. Option D (Public key infrastructure (PKI)) is wrong because PKI is a framework of policies, roles, and procedures for managing digital certificates and keys, not a cryptographic method itself; it enables digital signatures but does not directly provide integrity and non-repudiation.

389
MCQeasy

An organization's security policy requires that all security incidents be reported within one hour of discovery. A junior analyst notices an unauthorized login attempt but is unsure if it qualifies as an incident. What should the analyst do first?

A.Delete the logs to avoid false alarms
B.Wait until the incident is confirmed
C.Investigate on their own without reporting
D.Report the suspicious activity immediately
AnswerD

The one-hour reporting mandate applies from discovery, and uncertainty about classification does not justify delay. Reporting the suspicious activity immediately lets the security team triage whether it qualifies as an incident, satisfying the policy's timeframe while preserving evidence and enabling containment.

Why this answer

Reporting suspicious activity immediately aligns with the policy, even if not confirmed. Waiting or deleting logs could violate reporting requirements.

390
MCQeasy

Refer to the exhibit. Which security protocol is being configured?

A.IPsec VPN (IKE phase 1)
B.SSL VPN
C.MACsec
D.SSH
AnswerA

IKE phase 1 negotiates the ISAKMP security association: encryption and hashing algorithms, authentication method, Diffie-Hellman group and lifetime. Those parameters, shown in the exhibit, establish the secure management tunnel before phase 2 builds the IPsec data SAs.

Why this answer

The exhibit shows the configuration of an IPsec VPN IKE phase 1 policy using the `crypto isakmp policy` command. The parameters set—encryption algorithm (e.g., aes), hash algorithm (e.g., sha), Diffie-Hellman group (e.g., 2), and authentication method (e.g., pre-share)—are all specific to IKE phase 1, which establishes a secure authenticated channel for further key exchange. This is not used for SSL VPN, MACsec, or SSH, as those protocols have distinct configuration syntax and purposes.

Exam trap

Cisco often tests the distinction between IKE phase 1 and phase 2 configuration commands, so the trap here is that candidates see 'crypto isakmp' and incorrectly associate it with SSL VPN or SSH because they overlook the specific protocol hierarchy.

How to eliminate wrong answers

Option B is wrong because SSL VPN is configured using `webvpn` or `crypto ssl` commands, not `crypto isakmp policy`. Option C is wrong because MACsec is configured under interface mode with `mka` or `macsec` commands, not with a global ISAKMP policy. Option D is wrong because SSH is configured using `ip ssh` or `crypto key generate rsa` commands, and it does not use IKE phase 1 parameters like Diffie-Hellman groups or encryption algorithms in a policy block.

391
MCQeasy

A SOC manager is drafting the organization's incident response plan and wants to align it with the NIST SP 800-61 Rev. 2 lifecycle so that phases are clearly defined for auditors. Which sequence correctly represents the four phases of the incident response lifecycle as described in NIST SP 800-61 Rev. 2?

A.Identification, Containment, Eradication, Recovery
B.Preparation, Prevention, Detection, Response
C.Planning, Execution, Monitoring, Closure
D.Preparation; Detection and Analysis; Containment, Eradication, and Recovery; Post-Incident Activity
AnswerD

NIST SP 800-61 Rev. 2 defines exactly these four phases in this order, beginning with preparation before an incident occurs, then detection and analysis, then containment, eradication, and recovery, and finally post-incident activity. Adopting this structure gives the SOC manager a recognized framework that auditors can map to, and it ensures lessons learned feed back into preparation for continuous improvement.

Why this answer

NIST SP 800-61 Rev. 2 organizes incident response into four phases: Preparation; Detection and Analysis; Containment, Eradication, and Recovery; and Post-Incident Activity. A plan built on this structure gives clear entry and exit criteria for each phase, supports role assignment, and provides auditors with a recognizable mapping. The other sequences either describe only response sub-steps or borrow generic project management terms that do not match the standard.

Exam trap

The trap here is assuming the famous containment, eradication, and recovery steps are separate top-level phases rather than a single combined phase in the NIST SP 800-61 Rev. 2 lifecycle.

392
MCQhard

During an investigation, an analyst observes that a workstation resolves an internal hostname to an IP address that does not match the DHCP lease record, and subsequent SMB connections to that hostname reach an attacker-controlled server. Which attack technique best explains this behavior?

A.SMB signing downgrade on the file server
B.DHCP starvation exhausting the address pool
C.DNS spoofing or rogue DNS response injection
D.ARP cache poisoning on the local subnet
AnswerC

When a hostname resolves to an IP inconsistent with the DHCP lease and SMB traffic then reaches an attacker server, the name resolution itself has been manipulated. DNS spoofing or rogue responses inject false A records so clients connect to the attacker. This directly accounts for the mismatched resolution and the redirected SMB sessions, making it the best explanation for the observed behavior.

Why this answer

A hostname resolving to an IP that contradicts the DHCP lease, followed by SMB traffic reaching an attacker server, points to manipulation of name resolution. DNS spoofing or rogue DNS responses inject false records so the client connects to the wrong endpoint. ARP poisoning operates at layer 2 with MAC mappings, DHCP starvation prevents lease acquisition, and SMB signing affects message integrity, so none of those explain the poisoned resolution.

Exam trap

The trap here is blaming layer 2 attacks like ARP poisoning for what is actually a name resolution manipulation at the DNS layer.

393
MCQmedium

An analyst is reviewing a web server log and sees the following entry: '192.168.1.1 - - [25/Oct/2023:10:15:30 -0400] "GET /admin/index.php?cmd=id HTTP/1.1" 200 1532 "-" "Mozilla/5.0"'. What potential attack does this log entry suggest?

A.Command injection
B.SQL injection
C.Directory traversal
D.Cross-site scripting (XSS)
AnswerA

The query string passes 'cmd=id' to a PHP script, indicating the attacker is attempting to execute the shell command 'id' via an unsanitised parameter. A 200 response suggests the command injection succeeded, satisfying the log evidence for this attack type.

Why this answer

The presence of 'cmd=id' in the URL suggests an attempt to execute the 'id' command via a web shell or command injection vulnerability. The response code 200 indicates success, which is concerning.

394
MCQhard

During a forensic analysis, an analyst uses NetworkMiner to extract files from a PCAP. One of the extracted files contains a PE executable with a known signature of a malware variant. Which phase of the Cyber Kill Chain does the file transfer most likely represent?

A.Reconnaissance
B.Weaponization
C.Exploitation
D.Delivery
AnswerD

Extracting a PE executable from the PCAP shows the malicious file being transferred to the target host, which is the Delivery phase of the Cyber Kill Chain. Delivery covers transmission of the weaponised payload via email, web, or USB, satisfying the scenario's file-transfer constraint.

Why this answer

The file transfer from the PCAP represents the Delivery phase because NetworkMiner extracted a PE executable that was transmitted over the network, likely via HTTP, SMTP, or SMB. In the Cyber Kill Chain, Delivery is the phase where the weaponized payload is transmitted to the target system, which is exactly what a file transfer in a PCAP captures. The presence of a known malware signature confirms the payload was delivered, not yet executed or exploited.

Exam trap

Cisco often tests the distinction between Delivery and Exploitation, where candidates mistakenly choose Exploitation because they see a malware file, but the PCAP only shows the transfer, not the execution or vulnerability trigger.

How to eliminate wrong answers

Option A is wrong because Reconnaissance involves gathering information about the target (e.g., scanning, OSINT) and does not include transferring a malware executable. Option B is wrong because Weaponization is the phase where the attacker creates the malicious payload (e.g., coupling exploit with backdoor), but the file transfer itself is not the creation step. Option C is wrong because Exploitation occurs when the delivered payload triggers a vulnerability to execute code; the PCAP file transfer only shows the delivery, not the execution or trigger.

395
MCQmedium

During an incident, the analyst finds that an attacker modified system files. Which security principle was primarily violated?

A.Confidentiality
B.Availability
C.Integrity
D.Non-repudiation
AnswerC

Modifying system files alters their contents without authorisation, violating integrity, which ensures data remains accurate and unaltered. Confidentiality concerns disclosure and availability concerns access, so integrity is the principle primarily breached by the attacker's file modifications.

Why this answer

Integrity ensures that data and system files are not altered by unauthorized entities. When an attacker modifies system files, the trustworthiness and accuracy of those files are compromised, directly violating the integrity principle. This is distinct from confidentiality (unauthorized disclosure) or availability (denial of service).

Exam trap

Cisco often tests the distinction between integrity and availability by presenting a scenario where an attacker modifies files (integrity) rather than deleting them or causing a denial of service (availability), leading candidates to mistakenly choose availability.

How to eliminate wrong answers

Option A is wrong because confidentiality concerns unauthorized access to or disclosure of information, not unauthorized modification. Option B is wrong because availability ensures that systems and data are accessible when needed; file modification does not inherently prevent access. Option D is wrong because non-repudiation provides proof of origin or delivery of data (e.g., via digital signatures), not protection against unauthorized changes.

396
MCQeasy

An employee is suspected of using company resources to access inappropriate websites. Which security policy most directly addresses this behavior?

A.Acceptable Use Policy (AUP)
B.Remote access policy
C.Information security policy
D.Password policy
AnswerA

An Acceptable Use Policy defines permitted employee use of company systems and networks, explicitly prohibiting access to inappropriate websites. It directly governs the behaviour described, making it the policy that addresses misuse of company resources for browsing inappropriate content.

Why this answer

The Acceptable Use Policy defines acceptable use of company resources, including internet usage.

397
Multi-Selectmedium

A security analyst is investigating a potential data breach. Which two actions are examples of passive reconnaissance? (Choose two.)

Select 2 answers
A.Performing a port scan on the company's web server
B.Searching for employee information on LinkedIn
C.Using a ping sweep to identify live hosts
D.Conducting a WHOIS lookup on the company domain
E.Sending a phishing email to employees
AnswersB, D

Searching LinkedIn for employee information gathers publicly available data without directly touching the target's systems, so no traffic reaches company infrastructure. This indirect, non-intrusive collection is passive reconnaissance, unlike active scanning or enumeration, which would interact with and potentially alert the target.

Why this answer

Option B is correct because searching LinkedIn for employee information is passive reconnaissance: the analyst gathers publicly available OSINT about personnel, roles, and organizational structure without sending any packets to or interacting with the target's systems, so it cannot be detected by the target. Option D is correct because a WHOIS lookup queries public registry databases (via port 43 to the registrar/RIR) for domain registration details such as registrant, admin contacts, name servers, and creation/expiry dates; this information is obtained from third-party records rather than from the target's own infrastructure, making it passive. The unmarked options do not belong: A (port scan) and C (ping sweep) are active reconnaissance techniques that directly probe the target's hosts and services and are detectable in logs or IDS/IPS, while E (phishing email) is an active social-engineering attack that interacts with employees and is not reconnaissance at all.

Exam trap

The trap here is confusing any information-gathering activity as passive; candidates often mistakenly classify ping sweeps or port scans as passive because they seem less intrusive than exploitation, but they are active and detectable.

398
MCQmedium

Which of the following are responsibilities of the legal counsel role during incident response? (Choose two.)

A.Determining data breach notification requirements
B.Communicating with the media
C.Conducting technical analysis of malware
D.Approving financial expenditures for containment
E.Issuing a legal hold to preserve relevant data
AnswerA, E

Legal counsel advises on legal obligations to notify affected parties.

Why this answer

Legal counsel advises on breach notification requirements and can place legal holds to preserve evidence for litigation.

399
MCQeasy

Which Windows Prefetch file extension indicates that a program has been executed on the system?

A..evtx
B..pf
C..tmp
D..log
AnswerB

Windows writes a .pf Prefetch file into C:\Windows\Prefetch each time an executable launches, recording the binary name, run count and timestamps. Its presence therefore proves execution, unlike .lnk shortcuts or registry keys, which merely evidence access or configuration.

Why this answer

Prefetch files with the .pf extension are created by Windows when a program is executed, storing metadata about the executable's loading and execution. The presence of a .pf file in C:\Windows\Prefetch is a strong indicator that the program ran on the system. This makes .pf the correct extension for indicating program execution.

Exam trap

200-201 often tests the confusion between Prefetch (.pf) and other forensic artifacts like Event Logs (.evtx) — candidates may pick .evtx because it records events, but .pf specifically indicates program execution.

How to eliminate wrong answers

Option A is wrong because .evtx is the extension for Windows Event Log files, which record system and application events but are not specific to program execution tracking. Option C is wrong because .tmp files are temporary files created by various processes and do not indicate execution. Option D is wrong because .log files are generic text logs and are not the Prefetch file format.

400
MCQhard

GreenTech Inc. is a mid-sized company with 500 employees. The company uses Microsoft Exchange Online for email and has implemented a security policy that requires all employees to report suspicious emails to the security team. The security team uses a phishing simulation tool to train employees. In the past month, several employees have reported receiving emails that appear to be from the CEO requesting urgent wire transfers. The security team has blocked the sender domains and updated the email filters. However, one employee fell for the latest scam and transferred $50,000 to an account before reporting it. The security incident response plan states that any monetary loss must be reported to the board within 24 hours. The security analyst receives the report on Monday morning. What should the analyst do first based on the policy and best practices?

A.Disable email access for all employees to prevent further attacks
B.Launch a full forensic investigation to identify the source
C.Notify the board within the 24-hour window as per policy
D.Immediately contact the bank to attempt to reverse the wire transfer
AnswerD

Contacting the bank immediately maximises the chance of recalling the wire before funds leave the recipient's account, directly addressing the $50,000 loss the incident response plan requires reporting to the board within 24 hours. Containment of financial impact takes precedence over notification, which follows once recovery is attempted.

Why this answer

The immediate priority in a wire-transfer fraud incident is to attempt to recover the funds by contacting the bank as soon as possible — the faster the bank is notified, the higher the chance of reversing or freezing the transfer. Best practices for BEC (Business Email Compromise) incidents place financial recovery first, before forensic investigation or internal notifications, because the 24-hour board notification window is still available while the wire recall window may be minutes to hours.

Exam trap

200-201 often tests incident response prioritization — candidates pick the policy-driven action (notify the board) or the investigative action (forensics) because they sound 'correct' procedurally, but the exam expects you to recognize that immediate financial recovery actions take precedence over reporting and investigation in fraud incidents.

How to eliminate wrong answers

Option A is wrong because disabling email access for all employees is a disproportionate, disruptive action that does not address the immediate financial loss and would cripple business operations. Option B is wrong because launching a full forensic investigation, while important, is not the first step — preserving the chance to recover funds takes precedence, and forensics can proceed in parallel. Option C is wrong because notifying the board within 24 hours is a policy requirement, but it is not the first action; the analyst has time to notify the board after initiating the bank recall, and delaying the bank call could make recovery impossible.

401
Multi-Selecthard

An analyst is analyzing a Linux system that may have been compromised. Which THREE artifacts would provide evidence of attacker activity? (Choose three.)

Select 3 answers
A./proc/cpuinfo
B./var/spool/cron/crontabs/
C./etc/passwd
D./var/log/auth.log
E./home/user/.bash_history
AnswersB, D, E

The /var/spool/cron/crontabs/ directory holds per-user cron schedules on Linux, so any malicious job an attacker added for persistence appears here as a readable file. This directly satisfies the stem's requirement for evidence of attacker activity, revealing scheduled commands that re-establish access or execute payloads after reboot.

Why this answer

Option B, /var/spool/cron/crontabs/, is correct because attackers commonly establish persistence by adding malicious cron jobs here (per-user crontabs on Debian/Ubuntu systems), so unexpected entries provide direct evidence of attacker activity. Option D, /var/log/auth.log, is correct because it records authentication events such as SSH logins, sudo usage, and failed/successful password attempts, which can reveal unauthorized access or brute-force activity. Option E, /home/user/.bash_history, is correct because it preserves the commands a user (or an attacker operating under that account) executed, often exposing reconnaissance, privilege escalation, or data exfiltration commands.

Option A, /proc/cpuinfo, is not relevant because it only exposes CPU hardware details from the kernel and contains no record of user or attacker actions. Option C, /etc/passwd, is not the best evidence of activity because it is a static account database listing users; while tampering (e.g., a rogue UID 0 account) could be suspicious, the file itself does not log activity, and the question asks for artifacts evidencing attacker activity.

Exam trap

The trap is confusing general system files with forensic artifacts; candidates might select /etc/passwd because it relates to user accounts, but it is not as indicative of active attacker activity as the other three.

402
Multi-Selecthard

An analyst is investigating a Windows host and observes a suspicious process with PID 1337. Which THREE of the following Volatility commands would provide useful information about this process? (Choose three.)

Select 3 answers
A.cmdline
B.hivelist
C.pslist
D.connscan
E.dlllist
AnswersA, C, E

Correct. Shows command-line arguments for the process.

Why this answer

The `cmdline` plugin displays the command-line arguments used to start a process, which is critical for identifying malicious or suspicious execution patterns (e.g., obfuscated paths, encoded commands). For PID 1337, this reveals exactly how the process was launched, helping to confirm or refute malicious intent.

Exam trap

Cisco often tests the distinction between process-specific plugins (like `cmdline`, `dlllist`, `pslist`) and system-wide or network plugins (like `hivelist`, `connscan`), leading candidates to select plugins that are useful for general analysis but not directly for investigating a specific process.

403
MCQhard

A security operations center (SOC) manager is developing a playbook for handling phishing incidents. The playbook must specify the first action an analyst should take upon receiving a reported phishing email. Which action should be performed first according to standard incident response procedures?

A.Notify law enforcement about the phishing attempt
B.Isolate the recipient's workstation from the network
C.Preserve the email and analyze its headers and attachments
D.Delete the email from all mailboxes
AnswerC

The first step in phishing response is to preserve the email as evidence and analyze its headers, URLs, and attachments to confirm malicious intent and identify indicators. This analysis informs subsequent actions such as blocking senders, quarantining similar emails, and notifying affected users. It aligns with standard incident response procedures that prioritize identification and containment planning.

Why this answer

Standard incident response procedures for phishing begin with preserving and analyzing the reported email to confirm maliciousness and extract indicators. This step enables accurate containment and remediation, such as blocking malicious domains and quarantining similar messages. Isolating, deleting, or notifying law enforcement are subsequent actions that depend on the initial analysis.

Exam trap

The trap here is jumping to containment or remediation actions before validating the incident and gathering evidence, which can destroy critical information.

404
MCQmedium

A company's web server is overwhelmed by traffic from multiple compromised systems, causing it to become unresponsive to legitimate users. Which type of attack is this?

A.MitM
B.DoS
C.Botnet
D.DDoS
AnswerD

A DDoS attack floods the web server with traffic from many compromised hosts, exhausting its resources so legitimate users cannot connect. This matches the scenario's constraint of multiple compromised systems overwhelming one target, distinguishing it from a single-source DoS attack.

Why this answer

(DDoS) because the scenario describes a distributed denial-of-service attack: traffic originates from multiple compromised systems (a botnet) to overwhelm the web server. A DDoS attack is a subtype of DoS that specifically uses multiple sources, making it harder to mitigate than a single-source DoS. The key clue is 'multiple compromised systems,' which directly maps to the distributed nature of a DDoS.

Exam trap

Cisco often tests the distinction between DoS and DDoS by including the phrase 'multiple compromised systems' as the key differentiator, and the trap here is that candidates may confuse the attack type (DDoS) with the infrastructure used to execute it (botnet).

How to eliminate wrong answers

Option A (MitM) is wrong because a man-in-the-middle attack intercepts or alters communication between two parties (e.g., ARP spoofing, SSL stripping), not overwhelming a server with traffic. Option B (DoS) is wrong because while a DoS attack also aims to make a service unavailable, the question explicitly states 'multiple compromised systems,' which distinguishes it as a distributed attack; a standard DoS originates from a single source. Option C (Botnet) is wrong because a botnet is the network of compromised devices used to launch the attack, not the attack itself; the question asks for the type of attack, not the infrastructure.

405
Multi-Selecthard

An analyst is investigating a suspected SQL injection attack captured in a PCAP. The analyst needs to identify TWO indicators in the HTTP traffic that would confirm a SQL injection attempt. Which two indicators should the analyst look for? (Choose two.)

Select 2 answers
A.Unexpected database error messages in HTTP responses
B.HTTP response containing a large number of directory listings
C.Presence of SQL keywords such as UNION, SELECT, or OR 1=1 in URL parameters or POST data
D.Multiple HTTP 302 redirects to an external domain
E.Presence of encrypted payloads using TLS 1.3
AnswersA, C

When SQL injection is attempted, malformed queries can cause the database to return error messages. These errors, such as syntax errors or unclosed quotation marks, often appear in HTTP responses and reveal that the input affected the SQL query, confirming an injection attempt.

Why this answer

SQL injection attempts are characterized by the injection of SQL syntax into user inputs, often visible as keywords like UNION or OR 1=1 in HTTP requests. Additionally, when the injected query causes a database error, the error message may be returned in the HTTP response, providing confirmation of the attempt. These two indicators together strongly suggest a SQL injection attack.

Exam trap

The trap here is focusing on generic web attack signs like redirects or directory listings, which are not specific to SQL injection, instead of the SQL syntax and error messages that directly indicate database query manipulation.

406
MCQhard

An analyst sees these logs. What should be the immediate course of action?

A.Investigate whether these are legitimate SSH attempts from authorized remote administrators.
B.Change the SSH port to a non-standard port.
C.Block all traffic from the 10.0.0.0/24 subnet.
D.Add an ACL permit rule for SSH from these sources.
E.Disable SSH access to the router.
AnswerA

SSH authentication attempts may originate from sanctioned administrators, so the analyst must first establish whether the source addresses and accounts are authorised. Confirming legitimacy distinguishes routine remote administration from brute-force or intrusion activity before escalation or blocking.

Why this answer

The logs show repeated SSH connection attempts from the 10.0.0.0/24 subnet. The immediate priority is to determine whether these are legitimate administrative activities or malicious brute-force attempts. Investigating first prevents unnecessary disruption to authorized remote administration, which is critical for maintaining network operations and security.

Blocking or changing configurations without verification could inadvertently lock out legitimate administrators or violate change-control policies.

Exam trap

Cisco often tests the principle of 'verify before you act' to trap candidates who jump to reactive measures like blocking or changing ports without first confirming whether the traffic is authorized.

How to eliminate wrong answers

Option B is wrong because changing the SSH port to a non-standard port is a form of security through obscurity that does not address the root cause; attackers can easily scan for open ports, and it may break automated management tools or compliance requirements. Option C is wrong because blocking all traffic from the 10.0.0.0/24 subnet could deny service to legitimate users or systems in that range without confirming malicious intent, potentially causing a denial of service. Option D is wrong because adding an ACL permit rule for SSH from these sources would explicitly allow the traffic, which is the opposite of a security response if the attempts are unauthorized.

Option E is wrong because disabling SSH access to the router outright would prevent all remote administration, including from authorized personnel, and is an overly drastic measure before verifying the nature of the attempts.

407
MCQhard

A security analyst is analyzing a suspicious PE file. Using a hex editor, the analyst sees the MZ header (4D 5A). The file's entropy is calculated as 7.8. What does the high entropy most likely indicate?

A.The file is a legitimate signed binary
B.The file is likely packed or obfuscated
C.The file is corrupted
D.The file contains mostly plain text strings
AnswerB

Entropy near 7.8 approaches the theoretical maximum for byte data, indicating compressed or encrypted content rather than readable code. Packers and obfuscators compress or encrypt the payload, so high entropy in a PE file suggests packing.

Why this answer

High entropy (close to 8) suggests the file is packed or encrypted, as compressed or encrypted data has high randomness. This is often used by malware to evade signature detection.

408
MCQeasy

A security analyst is examining a Linux host and wants to identify which user account was used to execute a specific command that modified a critical system file. Which of the following files would provide the MOST direct evidence of the user who executed the command?

A./var/log/auth.log
B./var/log/syslog
C./var/log/audit/audit.log
D./home/<user>/.bash_history
AnswerC

The audit log, when auditd is configured, records detailed system call and command execution events, including the user ID (UID) and effective user ID (EUID) of the process that executed the command. This provides direct evidence of which user account was used to run the command, making it the most reliable source for this scenario.

Why this answer

The audit log, managed by auditd, is designed to capture security-relevant events, including command execution with user context. It logs the UID and EUID, so an analyst can determine exactly which user account executed the command that modified the critical file. Other logs may not capture this level of detail.

Exam trap

The trap here is assuming that bash_history or auth.log will show the command and user, but bash_history is per-user and modifiable, while auth.log only shows authentication events.

409
MCQmedium

A SOC analyst at Tier 1 receives an alert for a known malware signature. After initial investigation, the analyst finds that the alert is a false positive caused by an outdated signature. What should the analyst do next?

A.Escalate the alert to Tier 2 for further analysis
B.Update the signature database on the security tools
C.Initiate the containment process
D.Close the alert and document the finding
AnswerD

With the alert confirmed as a false positive from an outdated signature, no genuine incident exists, so the analyst closes it and documents the finding. This preserves the audit trail and supports later tuning of the detection signature.

Why this answer

When a Tier 1 analyst determines an alert is a false positive caused by an outdated signature, the correct action is to close the alert and document the finding so the signature can be reviewed and tuned. Escalating or containing would waste resources on a non-incident. Documentation ensures the false positive is tracked and the detection rule can be improved.

Exam trap

200-201 often tests the boundary between triage and response — candidates pick containment or escalation because they sound 'safe,' but the exam expects recognition that a confirmed false positive is closed and documented, not escalated or acted upon.

How to eliminate wrong answers

Option A is wrong because escalating a confirmed false positive to Tier 2 wastes Tier 2 resources and violates triage efficiency — escalation is reserved for unresolved or suspicious alerts. Option C is wrong because containment (isolating hosts, blocking IPs) is an incident response action that should never be triggered by a false positive, as it could disrupt business operations unnecessarily. Option B is wrong because a Tier 1 analyst typically does not have authority or responsibility to update the signature database; that is a detection engineering or signature management task, and the immediate step is to close and document.

410
MCQeasy

A security team is reviewing the confidentiality, integrity, and availability (CIA) triad for a new file-sharing service. The service must ensure that data cannot be altered in transit by unauthorized parties. Which security principle is primarily addressed by implementing TLS for all connections?

A.Integrity
B.Confidentiality
C.Non-repudiation
D.Availability
AnswerA

Integrity ensures that data is not modified by unauthorized parties. TLS uses message authentication codes and encryption to detect tampering, thereby preserving integrity of data in transit. The scenario explicitly states the requirement to prevent unauthorized alteration, which directly maps to the integrity principle of the CIA triad.

Why this answer

The requirement to prevent unauthorized alteration of data in transit directly addresses the integrity principle of the CIA triad. TLS provides integrity through message authentication codes, ensuring that any modification is detected. While TLS also offers confidentiality, the scenario's emphasis on preventing alteration makes integrity the primary principle.

Exam trap

The trap here is focusing on the encryption aspect of TLS and selecting confidentiality, while overlooking that the scenario explicitly requires protection against unauthorized modification.

411
MCQmedium

An analyst notices periodic HTTP GET requests to a suspicious domain every 60 seconds. The payload size is small and consistent. This behavior is characteristic of which phase of the Cyber Kill Chain?

A.Actions on Objectives
B.Command and Control
C.Delivery
D.Installation
AnswerB

Regular, small, consistent beaconing to an external domain indicates an implanted host checking in with its controller. That recurring channel is the Command and Control phase, where the adversary maintains remote direction of compromised systems after exploitation.

Why this answer

Periodic, small, consistent HTTP GET requests to a suspicious external domain are the hallmark of beaconing, which occurs during the Command and Control (C2) phase of the Cyber Kill Chain. The compromised host is checking in with its C2 server at regular intervals to receive instructions or exfiltrate small amounts of data. This regular, low-volume traffic pattern is designed to blend in with normal traffic while maintaining persistent control.

Exam trap

The trap here is confusing the C2 phase with Actions on Objectives because both involve network traffic; candidates must recognize that periodic, small beacons indicate ongoing control, not the final objective.

How to eliminate wrong answers

Option A is wrong because Actions on Objectives is the final phase where the attacker achieves their goal (e.g., data exfiltration, ransomware execution), which typically involves larger or more targeted data transfers, not small periodic beacons. Option C is wrong because Delivery is the phase where the initial payload is delivered (e.g., via phishing email or malicious download), which happens once, not periodically. Option D is wrong because Installation is when the malware establishes persistence on the host, which is a one-time event, not a recurring network pattern.

412
MCQmedium

A SOC analyst notices an internal host transmitting a series of ICMP Echo Request packets to an external IP, each with a payload size of exactly 1024 bytes and a repeating pattern. The echo replies are consistently the same size. Which type of activity does this most likely indicate?

A.Legitimate network latency testing
B.ICMP tunneling
C.Network reconnaissance via ping sweep
D.ICMP flood denial-of-service
AnswerB

Large, fixed-size ICMP payloads with repeating patterns and matching replies indicate data being encapsulated inside ICMP Echo packets. Normal ping payloads are small (often 32-64 bytes) and random. The consistent size and pattern suggest a covert channel using ICMP tunneling tools like ptunnel or icmpsh to exfiltrate or communicate stealthily.

Why this answer

The correct answer is ICMP tunneling because the traffic shows large, fixed-size ICMP payloads with repeating patterns and matching replies, which are hallmarks of data being hidden inside ICMP Echo packets. Normal ICMP usage involves small, variable payloads for diagnostics, not consistent large payloads, indicating a covert channel.

Exam trap

The trap here is assuming that any ICMP traffic is benign network troubleshooting, ignoring the unusual payload size and pattern that point to tunneling.

413
Multi-Selectmedium

A security team is analyzing a malware infection. Which two characteristics are typical of a worm? (Choose two.)

Select 2 answers
A.Exploits vulnerabilities to spread without user interaction
B.Requires a host file to propagate
C.Disguises itself as a legitimate program
D.Attaches to an email to spread
E.Self-replicates across networks
AnswersA, E

Exploiting vulnerabilities lets the worm propagate autonomously across networks, satisfying the stem's requirement for self-replication without user interaction. Unlike viruses, which need a host file or user action to execute, worms spread directly between systems, making this a defining characteristic of worm behaviour during malware analysis.

Why this answer

Option A is correct because a worm actively exploits vulnerabilities (for example, unpatched SMB or RDP flaws) to propagate autonomously across systems without requiring any user action such as clicking a link or opening an attachment. Option E is correct because self-replication is the defining trait of a worm: it copies itself from host to host over network connections, often scanning for new targets and consuming bandwidth. Option B is wrong because requiring a host file to propagate describes a virus, which needs to infect an executable or document, not a worm.

Option C is wrong because disguising itself as a legitimate program is characteristic of a Trojan, which relies on deception rather than self-replication. Option D is wrong because attaching to an email to spread is typical of a mass-mailing virus or email-based malware, not the network-propagating worm behavior described here.

Exam trap

The trap is confusing worm traits with virus or Trojan traits — candidates must remember that 'no user interaction' and 'self-replication across networks' are the two defining worm characteristics.

414
Multi-Selecteasy

Which THREE of the following are common Indicators of Compromise (IoCs) used in threat intelligence?

Select 3 answers
A.IP addresses
B.User-agent strings
C.Port numbers
D.Domain names
E.File hashes (MD5, SHA-256)
AnswersA, D, E

IP addresses are network-layer artefacts recorded in firewall, IDS and proxy logs, letting analysts block or correlate malicious hosts. They satisfy the IoC requirement because they are observable, machine-readable evidence that a compromise may have occurred.

Why this answer

IP addresses (A) are a classic network-based IoC because threat intelligence feeds track malicious or command-and-control (C2) infrastructure by IP, allowing defenders to block or alert on traffic to known-bad hosts. Domain names (D) are equally common IoCs, used to identify malicious domains, C2 servers, and phishing sites via DNS monitoring, sinkholing, or blocklists. File hashes such as MD5 and SHA-256 (E) are host-based IoCs that uniquely identify known malicious files, enabling endpoint and antivirus tools to detect malware by exact signature.

User-agent strings (B) can be suspicious artifacts but are not typically standalone IoCs since they are trivially spoofed and highly variable, and port numbers (C) are not reliable IoCs on their own because legitimate and malicious services frequently share the same ports (e.g., 80, 443).

Exam trap

Cisco often tests the distinction between IoCs (specific, observable artifacts of an intrusion) and contextual data (like user-agent strings or port numbers) that are not reliable or specific enough to be used as standalone indicators in threat intelligence.

415
MCQmedium

A security analyst needs to verify the authenticity and integrity of a software update. The update is signed with a digital signature. Which key is used to verify the signature?

A.Sender's public key
B.Sender's private key
C.Recipient's public key
D.Recipient's private key
AnswerA

The sender signs with their private key, so verification requires the mathematically paired public key. This satisfies the authenticity and integrity constraint: only the matching public key validates the signature, confirming the update originated from the holder of the private key and was not altered.

Why this answer

A digital signature is created by the sender using their private key, and it is verified by anyone using the sender's public key. The public key mathematically validates that the signature was produced by the corresponding private key and that the message has not been altered. Therefore, the recipient uses the sender's public key to verify authenticity and integrity.

Exam trap

200-201 often tests the confusion between signing and encryption keys — candidates must remember that the sender's private key signs and the sender's public key verifies, while the recipient's keys are used for confidentiality, not signature verification.

How to eliminate wrong answers

Option B is wrong because the sender's private key is used to create (sign) the signature, not to verify it — sharing or using it for verification would destroy the security guarantee. Option C is wrong because the recipient's public key is used to encrypt data intended for the recipient, not to verify a signature made by the sender. Option D is wrong because the recipient's private key is used to decrypt data sent to the recipient or to sign the recipient's own messages, not to verify the sender's signature.

416
MCQhard

A security analyst is reviewing the organization's incident response plan and notices that the 'Lessons Learned' phase is scheduled only after major incidents. The analyst recommends that this phase be conducted after all incidents, regardless of severity. What is the primary benefit of this recommendation?

A.It ensures that all incidents are reported to regulatory authorities.
B.It eliminates the need for a formal incident response plan.
C.It reduces the time required for the containment phase of future incidents.
D.It helps identify minor issues that could be precursors to major incidents.
AnswerD

Conducting lessons learned after every incident, even minor ones, helps uncover small gaps or weaknesses that could escalate into major incidents if left unaddressed. This proactive approach improves the overall security posture and prevents future incidents. It also fosters a culture of continuous improvement, where even small incidents are analyzed for root causes and corrective actions.

Why this answer

The primary benefit of conducting lessons learned after every incident is to identify minor issues that could be early indicators of larger problems. This practice enables continuous improvement and helps prevent minor incidents from escalating. It does not directly reduce containment time, ensure regulatory reporting, or replace the need for an incident response plan.

Exam trap

The trap here is assuming that lessons learned is only about post-incident documentation for major events, when its real value is in uncovering small weaknesses that could lead to bigger incidents.

417
MCQhard

An organization has implemented a security information and event management (SIEM) system. The SOC analyst receives an alert indicating a high number of failed login attempts from a single IP address targeting a critical server. The analyst checks the server logs and finds that the server is configured to lock the account after 5 failed attempts. However, the alert shows thousands of attempts. Which of the following explains this discrepancy?

A.The failed attempts are against different usernames, not the same account
B.The attacker is using a brute-force tool that bypasses account lockout
C.The server's logging is not capturing all authentication events
D.The SIEM alert is a false positive due to a misconfiguration
AnswerA

Account lockout counters track failures per account, so thousands of attempts against many distinct usernames never trip the five-attempt threshold. The alert aggregates by source IP, explaining the discrepancy between the SIEM count and the server's lockout behaviour.

Why this answer

The account lockout policy (5 failed attempts) applies per individual username, not per source IP address. If the attacker is attempting to authenticate with many different usernames from the same IP, each username can fail up to 5 times before being locked, allowing thousands of total failed attempts across different accounts. The SIEM aggregates all failed authentication events from that IP, while the server's lockout mechanism only triggers per user, explaining the discrepancy.

Exam trap

Cisco often tests the distinction between account lockout (per user) and failed login events (per source IP), trapping candidates who assume lockout limits total attempts from an IP rather than per-username attempts.

How to eliminate wrong answers

Option B is wrong because brute-force tools cannot bypass account lockout policies enforced by the authentication system (e.g., Windows Active Directory or Linux PAM); lockout is a server-side mechanism that applies regardless of the tool used. Option C is wrong because if the server were missing log entries, the SIEM would show fewer events than the server, not more; the alert shows thousands of attempts, indicating logging is capturing them. Option D is wrong because the alert is not a false positive—it accurately reflects the high volume of failed attempts from that IP; the misconfiguration would be in the analyst's interpretation, not in the SIEM rule.

418
MCQmedium

A security administrator is implementing a privileged access management (PAM) solution. Which practice best enforces the principle of least privilege for administrators?

A.Create shared admin accounts for the team
B.Use Just-in-Time administration to grant temporary privileges
C.Grant permanent admin rights to all senior administrators
D.Monitor admin activity without restricting access
AnswerB

Just-in-Time administration grants elevated rights only for a defined window, then revokes them automatically. This directly enforces least privilege by eliminating standing administrator access, so credentials are not permanently privileged. The temporary elevation satisfies the stem's requirement to minimise exposure whilst still permitting necessary administrative tasks.

Why this answer

Just-in-Time (JIT) administration is the correct practice because it dynamically grants elevated privileges only for the duration of a specific task, then automatically revokes them. This directly enforces the principle of least privilege by ensuring administrators have no standing, permanent access beyond what is immediately needed. In contrast, shared accounts, permanent rights, or mere monitoring all leave excessive or uncontrolled privileges in place.

Exam trap

Cisco often tests the misconception that monitoring or auditing alone satisfies least privilege, when in fact least privilege requires restricting access to the minimum necessary, not just observing it.

How to eliminate wrong answers

Option A is wrong because creating shared admin accounts violates accountability and makes it impossible to attribute actions to specific individuals, while also providing standing privileges that exceed least privilege. Option C is wrong because granting permanent admin rights to all senior administrators gives them continuous, unnecessary access, directly contradicting the principle of least privilege. Option D is wrong because monitoring admin activity without restricting access does nothing to reduce the attack surface; it only observes violations after they occur, failing to enforce least privilege proactively.

419
MCQeasy

A company is updating its security policy to align with the principle of least privilege. The IT director asks the security analyst to recommend a control that enforces this principle for user access to a financial application. Which control should the analyst recommend?

A.Single sign-on (SSO) with multifactor authentication (MFA).
B.Mandatory access control (MAC) using sensitivity labels on all data.
C.Discretionary access control (DAC) where data owners set permissions.
D.Role-based access control (RBAC) that grants permissions based on job functions.
AnswerD

RBAC enforces least privilege by assigning permissions to roles, not individuals, and users are granted only the roles needed for their job. This limits access to what is required to perform duties. It is a standard method to implement least privilege in applications. The financial application scenario fits RBAC because access can be tied to job functions like teller, auditor, or manager.

Why this answer

The principle of least privilege requires that users have only the minimum access necessary to perform their job functions. Role-based access control (RBAC) achieves this by defining roles with specific permissions and assigning users to roles. This limits access based on job needs and simplifies administration.

Other controls like MAC, DAC, or SSO/MFA do not directly enforce least privilege for application access.

Exam trap

The trap here is confusing authentication controls like SSO and MFA with authorization controls that enforce least privilege, when the question specifically asks for an access control method to limit permissions.

420
Multi-Selectmedium

A security analyst is reviewing a Windows host for indicators of credential dumping. The analyst wants to identify artifacts that commonly indicate tools such as Mimikatz have been used on the system. Which two artifacts should the analyst look for? (Choose two.)

Select 2 answers
A.Security Event ID 4656 or 4663 referencing lsass.exe with unusual access rights
B.An increase in Windows Defender signature definition version numbers
C.Presence of a driver named SysmonDrv.sys in the System32\drivers directory
D.Event ID 4688 showing the launch of notepad.exe by the SYSTEM account
E.Creation of a memory dump file such as lsass.dmp in a user-writable directory
AnswersA, E

Security Event IDs 4656 and 4663 record handle requests and object access, and when they reference lsass.exe with rights such as PROCESS_VM_READ, they strongly suggest a tool attempted to read credential material from LSASS memory. This is a classic indicator of credential dumping activity on a Windows host.

Why this answer

Credential dumping targets LSASS memory, so the most reliable host artifacts are security events showing unusual handle access to lsass.exe and the presence of a memory dump file such as lsass.dmp in a user-writable location. Together these indicate that a tool attempted to extract credentials from LSASS on the endpoint.

Exam trap

The trap here is selecting generic or benign system artifacts like Sysmon driver presence or Defender updates, which are unrelated to the LSASS-access behavior that credential dumping produces.

421
MCQhard

An analyst monitoring an internal network observes a host sending a large number of TCP segments with the URG flag set and a non-zero urgent pointer, but the urgent pointer value does not point to actual urgent data. The destination host appears to be processing the data normally. Which explanation best describes what the analyst is observing?

A.The host is performing a legitimate Telnet session where urgent data indicates a break command
B.The host is experiencing a TCP window zero condition caused by application backpressure
C.The host is retransmitting segments because the receiver's ACKs are being lost in transit
D.An attacker is using the TCP urgent pointer as a covert signaling mechanism or IDS evasion technique
AnswerD

Because many IDS engines and applications ignore or mishandle the URG flag and urgent pointer, attackers can abuse them as a side channel or to desynchronize inspection. Setting URG with a meaningless urgent pointer while still delivering normal data lets the attacker signal a cooperating peer or confuse the IDS without disrupting the actual TCP stream.

Why this answer

The TCP urgent pointer is rarely used by modern applications and is inconsistently handled by IDS engines and operating systems. Attackers exploit this by setting URG with a pointer that does not correspond to real urgent data, using the flag pattern as a covert signal to a cooperating peer or to desynchronize the IDS's view of the stream while the actual data is processed normally by the target.

Exam trap

The trap here is assuming URG always indicates legitimate Telnet break handling, when in practice URG with a meaningless pointer is a known evasion and covert-channel technique.

422
MCQhard

A SOC analyst is analyzing NetFlow data and notices a sudden spike in outbound traffic from a single internal host to an external IP address during non-business hours. The traffic volume is significantly higher than the baseline. Which suspicion is most likely?

A.The host is running a backup to cloud storage
B.The host is part of a botnet performing DDoS attack
C.Data exfiltration is occurring
D.The host is performing legitimate software updates
AnswerC

Large outbound transfers from one internal host to an external IP outside business hours, far exceeding baseline, match data exfiltration behaviour. NetFlow records volume and direction, not payload, so the anomaly itself signals possible data theft rather than scanning or denial of service, which produce different traffic patterns.

Why this answer

A sudden increase in outbound traffic to a single external IP, especially outside business hours, often indicates data exfiltration.

423
Multi-Selecthard

A Linux server has been compromised. The analyst checks for persistence mechanisms. Which THREE of the following are common Linux persistence techniques that should be examined? (Select THREE)

Select 3 answers
A.Creating a systemd service unit
B.Cron jobs in /etc/crontab or user crontabs
C.Changing the system timezone
D.Adding SSH public keys to authorized_keys
E.Modifying the /etc/hosts file
AnswersA, B, D

Systemd services can start automatically on boot.

Why this answer

Creating a systemd service unit is a common Linux persistence technique because systemd is the default init system for most modern Linux distributions. An attacker can place a malicious service file (e.g., /etc/systemd/system/evil.service) that automatically starts the malware at boot or after a crash, ensuring continued access even after a reboot.

Exam trap

Cisco often tests the distinction between persistence (automatic code execution) and other system modifications; the trap here is confusing a configuration change (timezone or hosts file) with a mechanism that ensures malware runs repeatedly.

424
Multi-Selectmedium

Which THREE are examples of social engineering attacks? (Select three.)

Select 3 answers
A.Man-in-the-middle
B.Smishing
C.SQL injection
D.Phishing
E.Spear phishing
AnswersB, D, E

Smishing uses SMS messages for deception.

Why this answer

Smishing is a form of social engineering attack that uses SMS (Short Message Service) text messages to trick recipients into revealing sensitive information or clicking malicious links. Unlike technical attacks that exploit system vulnerabilities, smishing relies on psychological manipulation, making it a classic social engineering vector.

Exam trap

Cisco often tests the distinction between technical attacks (like MITM or SQL injection) and social engineering attacks (like smishing, phishing, and spear phishing), where the trap is that candidates confuse a technical attack vector with a human-targeted manipulation technique.

425
MCQmedium

A security analyst is reviewing a packet capture and notices that a host is sending TCP segments with the SYN flag set to a range of ports on a single target, but the source IP address in each segment is spoofed to a different random address. The target replies with SYN-ACK packets to those spoofed addresses, and the host never completes the handshake. Which type of attack is this host performing?

A.Smurf attack
B.UDP flood
C.SYN flood
D.Ping of death
AnswerC

A SYN flood exploits the TCP three-way handshake by sending many SYN packets, often with spoofed source addresses, so the target allocates resources for half-open connections and never receives the final ACK. The scenario describes exactly this: spoofed source IPs, SYN segments to many ports, and no completed handshakes, exhausting the target's connection table.

Why this answer

The traffic pattern shows TCP SYN segments with spoofed source addresses and no completed three-way handshakes. This exhausts the target's half-open connection resources, which is the defining behavior of a SYN flood. UDP floods, Smurf attacks, and ping of death use different protocols and packet structures.

Exam trap

The trap here is assuming any spoofed-source flood is a Smurf attack, when the protocol and packet type determine the actual attack classification.

426
MCQmedium

A security analyst is reviewing a packet capture of traffic entering the corporate network. The analyst notices a large number of TCP SYN packets sent to multiple destination ports on a single internal host, with no corresponding ACK packets. The source IP addresses are spoofed and vary across each packet. Which type of attack is this traffic MOST likely associated with?

A.UDP amplification
B.SYN flood
C.ARP poisoning
D.DNS tunneling
AnswerB

A SYN flood is a denial-of-service attack where the attacker sends many TCP SYN requests with spoofed source IPs, causing the target to allocate resources for half-open connections. The lack of ACKs and use of spoofed sources match this pattern. The goal is to exhaust the target's connection table, preventing legitimate connections.

Why this answer

The traffic pattern of numerous TCP SYN packets from spoofed sources without completing the three-way handshake is characteristic of a SYN flood. This attack exploits the TCP connection setup process to exhaust the target's resources, denying service to legitimate users. The other options involve different protocols or layers and do not match the observed packets.

Exam trap

The trap here is confusing a SYN flood with other denial-of-service attacks that also use spoofed addresses but rely on different protocols or mechanisms.

427
MCQmedium

A security analyst at a medium-sized enterprise notices that an employee's workstation has been sending outbound traffic to a known malicious IP address at irregular intervals. The analyst runs a scan and finds no malware signatures. What should the analyst do next?

A.Block the malicious IP at the firewall and continue monitoring.
B.Escalate to the incident response team for further investigation.
C.Review the employee's recent web browsing history and email attachments.
D.Immediately disconnect the workstation from the network and reimage it.
AnswerB

Absent malware signatures, the irregular beaconing to a known malicious IP still indicates possible command-and-control or compromised credentials. Escalating to the incident response team brings deeper forensic analysis, such as traffic inspection and endpoint telemetry review, which signature scanning alone cannot provide.

Why this answer

Outbound traffic to a known malicious IP with no matching malware signature indicates a potential compromise that evaded signature-based detection — likely a fileless, living-off-the-land, or encrypted C2 channel. The correct next step is to escalate to the incident response team so they can perform deeper analysis (memory forensics, network capture, threat hunting) before taking disruptive action. Escalation preserves evidence and follows the incident response process.

Exam trap

The trap is choosing an immediate disruptive action (block, disconnect, reimage) that feels decisive but destroys evidence or is premature, instead of escalating for proper investigation.

How to eliminate wrong answers

Option A is wrong because simply blocking the IP and monitoring may tip off the attacker and destroy evidence of the compromise without understanding scope or persistence. Option C is wrong because reviewing browsing history and email attachments is a narrow, user-focused check that may miss fileless malware, scheduled tasks, or compromised credentials. Option D is wrong because immediately disconnecting and reimaging destroys volatile evidence (memory, running processes, network connections) and may be premature before the scope is understood.

428
MCQmedium

An analyst reviews IDS alerts and sees multiple alerts for the same signature from different internal IPs targeting the same external server. One common cause is...

A.A false positive
B.A DDoS attack
C.A worm spreading internally
D.A misconfigured server
AnswerC

A worm spreading internally replicates autonomously across hosts, so many internal IPs generate identical signature traffic toward the same external server. This satisfies the stem's pattern of multiple alerts for one signature from different internal sources, distinguishing worm propagation from a single compromised host or policy misconfiguration.

Why this answer

A worm spreading internally (option C) is the most likely cause because worms self-replicate and propagate across a network, generating identical IDS alerts from multiple internal IPs as each infected host attempts to connect to the same external server (e.g., for command-and-control or payload delivery). This pattern—same signature, multiple internal sources, single external target—is a classic indicator of worm activity, where the worm's propagation logic causes each compromised host to initiate similar outbound connections.

Exam trap

Cisco often tests the distinction between a DDoS attack and a worm by focusing on the source distribution—candidates mistakenly choose DDoS because they see multiple sources, but forget that DDoS sources are typically external, not internal, and the signature consistency points to a worm's automated propagation.

How to eliminate wrong answers

Option A is wrong because a false positive would typically produce alerts from a single or few IPs due to benign traffic matching a signature, not a coordinated pattern of multiple distinct internal IPs triggering the same alert. Option B is wrong because a DDoS attack would involve multiple sources targeting a single victim, but the sources are usually external (or a mix), and the alerts would likely show varied signatures or traffic types, not the same signature repeated from internal IPs. Option D is wrong because a misconfigured server would cause alerts from that server's IP only, not from multiple different internal IPs, and the signature would typically reflect the misconfiguration (e.g., protocol violations) rather than a consistent outbound connection pattern.

429
MCQeasy

A security analyst is reviewing a suspicious file found on a user's workstation. The file has a .docx extension but when the analyst inspects its header bytes, the file begins with the magic number for a Windows Portable Executable. The user reports the file arrived as an email attachment. Which type of malware delivery technique does this describe?

A.A file masquerading as a document but actually an executable
B.A rootkit that hides its presence on the system
C.A polymorphic virus that changes its own code to evade detection
D.A macro virus embedded in a legitimate document
AnswerA

The file uses a .docx extension to appear harmless, but its magic number shows it is a Windows Portable Executable. This masquerading technique tricks users into opening what they believe is a document, potentially executing malicious code. The mismatch between the file extension and its actual header is a strong indicator of disguised malware delivered via email attachment.

Why this answer

The file's extension claims it is a Word document, but its header bytes match a Windows Portable Executable. This is a classic masquerading technique where malware is disguised as a benign file type to trick users into executing it. The mismatch between the expected file signature and the actual content is the key indicator, distinguishing it from macro viruses, polymorphic code, or rootkits.

Exam trap

The trap here is focusing on the .docx extension and assuming a macro virus, when the header bytes reveal the file is actually an executable.

430
MCQmedium

An analyst uses 'sc query' on a Windows host and finds a service named 'WindowsUpdate' with a binary path pointing to 'C:\Users\Public\update.exe'. The service is running. Why is this suspicious?

A.The service is running
B.The service name is misspelled
C.The service displays 'WindowsUpdate'
D.The binary path is not in a system directory
AnswerD

Legitimate Windows services almost always execute from protected system locations such as C:\Windows\System32, not user-writable directories. C:\Users\Public is world-writable, allowing any local user to replace update.exe and gain persistence with SYSTEM privileges, since the service runs under a privileged account. This path anomaly satisfies the stem's suspicion constraint.

Why this answer

Legitimate Windows services, especially those mimicking system components like Windows Update, should have their binary paths in protected system directories (e.g., C:\Windows\System32). A binary path pointing to C:\Users\Public\update.exe indicates the executable is in a user-writable location, which is a common technique used by malware to evade detection and maintain persistence. The 'sc query' command reveals the service configuration, and this abnormal path is a strong indicator of compromise.

Exam trap

Cisco often tests the misconception that a service name or display name alone is the red flag, when in fact the critical indicator is the binary path location outside of system directories.

How to eliminate wrong answers

Option A is wrong because a service being running is not inherently suspicious; many legitimate services run continuously. Option B is wrong because the service name 'WindowsUpdate' is not misspelled; it matches the expected name for the Windows Update service. Option C is wrong because the service displaying 'WindowsUpdate' is expected behavior for a service named that; the suspicious element is the binary path, not the display name.

431
MCQmedium

A security manager is developing a business continuity plan (BCP) and needs to determine the maximum tolerable downtime (MTD) for a critical order-processing system. The system generates $10,000 in revenue per hour. If the system is down for more than 4 hours, the company will lose a key customer. What is the MTD for this system?

A.The MTD cannot be determined from the information given.
B.24 hours
C.1 hour
D.4 hours
AnswerD

The maximum tolerable downtime (MTD) is the longest period that a system can be unavailable before unacceptable consequences occur. In this scenario, the company will lose a key customer if the system is down for more than 4 hours, so the MTD is 4 hours. This is the threshold beyond which the business impact becomes intolerable.

Why this answer

The maximum tolerable downtime (MTD) is the longest time a system can be offline before the business suffers unacceptable consequences. Here, the loss of a key customer after 4 hours defines that threshold, so the MTD is 4 hours. Revenue loss per hour is relevant for cost analysis but does not change the MTD.

Exam trap

The trap here is confusing the MTD with the recovery time objective (RTO) or using revenue loss to calculate a different value, when the MTD is directly stated by the business impact threshold.

432
MCQmedium

An analyst is reviewing Windows Event Logs and sees multiple Event ID 4625 entries from a single IP address. What does this indicate?

A.A user account was locked out.
B.A brute-force password guessing attack.
C.A service account password expired.
D.Successful remote logins from that IP.
AnswerB

Event ID 4625 records a failed logon attempt. Many such entries originating from one IP address indicate repeated authentication failures, the signature of a brute-force password guessing attack, rather than a single mistyped password or a successful compromise.

Why this answer

Event ID 4625 in Windows Security logs indicates a failed logon attempt. Multiple such events from a single IP address suggest a brute-force password guessing attack, where an attacker repeatedly tries different passwords. This pattern is a classic indicator of compromise.

Exam trap

The trap is confusing Event ID 4625 with other logon-related events like 4624 (success) or 4740 (lockout); candidates might also think multiple failures indicate a lockout, but lockout is a separate event.

How to eliminate wrong answers

Option A is wrong because account lockout is typically indicated by Event ID 4740 (A user account was locked out), not 4625. Option C is wrong because a service account password expiration would generate a different event, such as 4625 with a specific status code, but multiple 4625s from one IP more strongly indicate brute force. Option D is wrong because successful logins are Event ID 4624, not 4625.

433
MCQeasy

A security analyst is investigating a Windows host and wants to view running processes along with their parent-child relationships and command-line arguments. Which tool is best suited for this task?

A.Volatility
B.tasklist
C.Process Explorer
D.Task Manager
AnswerC

Process Explorer displays a live process tree showing parent-child relationships, and its properties pane exposes full command-line arguments for each process. Task Manager and basic tasklist lack this combined hierarchical and command-line visibility, meeting the analyst's investigative requirement.

Why this answer

Process Explorer provides detailed process information including parent PID and command line, while Task Manager and tasklist show limited details. Volatility is a memory analysis tool, not for live host analysis.

434
MCQeasy

A security analyst is reviewing a Snort alert that triggered on the signature 'ET TROJAN Win.Trojan.Generic'. What is the most likely reason this alert fired?

A.A system infected with a trojan
B.A legitimate Windows update
C.A misconfigured firewall
D.An attacker attempting to exploit a buffer overflow
AnswerA

The signature name 'ET TROJAN Win.Trojan.Generic' explicitly categorises the traffic as trojan-related, so the alert indicates a host is infected with trojan malware. Snort matches packet patterns against this rule, and the ET prefix confirms it originates from the Emerging Threats ruleset, which targets known malicious trojan behaviour.

Why this answer

The Snort signature 'ET TROJAN Win.Trojan.Generic' is designed to detect network traffic patterns or payloads associated with known Trojan malware. When this alert fires, it indicates that the sensor observed data matching the signature's characteristics, most likely from a system that is infected with a Trojan and is communicating with a command-and-control server or performing malicious activity.

Exam trap

Cisco often tests the distinction between signature categories (e.g., Trojan vs. exploit vs. policy violation) to see if candidates understand that each signature type is tailored to a specific threat behavior, not just any anomaly.

How to eliminate wrong answers

Option B is wrong because a legitimate Windows update uses Microsoft's own signed binaries and update servers, and its traffic does not match the specific patterns of a Trojan signature; Snort would not trigger on benign update traffic unless a false positive occurs due to a poorly tuned signature. Option C is wrong because a misconfigured firewall might cause connectivity issues or block legitimate traffic, but it does not generate Trojan-specific network payloads that would match this signature. Option D is wrong because a buffer overflow exploit typically targets a vulnerability in a service or application and would be detected by a different class of signatures (e.g., 'ET EXPLOIT' or 'SHELLCODE'), not a generic Trojan signature.

435
MCQeasy

A healthcare organization has a security policy that mandates immediate reporting of any potential data breach to the privacy officer. An analyst notices that an employee accidentally emailed a patient list to the wrong recipient. The recipient is known to be a trusted partner, but the email contained PHI. The analyst contacts the recipient who acknowledges receipt and agrees to delete the email. What should the analyst do next?

A.Update the access control list to prevent similar mistakes.
B.Do nothing further since the data was deleted.
C.Send a warning email to the employee without reporting.
D.Report the incident as a data breach to the privacy officer as per policy.
AnswerD

Policy mandates immediate reporting of any potential breach involving PHI, regardless of recipient trustworthiness or deletion. The analyst must not self-assess severity; the privacy officer determines notification obligations, so reporting preserves compliance and the audit trail.

Why this answer

Under HIPAA and most organizational security policies, any unauthorized disclosure of PHI — even accidental and even to a trusted partner — must be reported to the privacy officer so it can be assessed and documented. The analyst is not authorized to make the breach determination or to close the incident; only the privacy officer can evaluate whether notification obligations apply. The recipient's verbal agreement to delete the email does not eliminate the disclosure event or the reporting requirement.

Exam trap

The trap here is the assumption that recipient cooperation or data deletion erases the reporting obligation — candidates pick 'do nothing' or 'warn the employee' because the outcome seems benign, but policy and HIPAA require escalation regardless of perceived harm.

How to eliminate wrong answers

Option A is wrong because updating an ACL does not address the already-occurred PHI disclosure and does not satisfy the mandatory reporting policy; ACL changes are a remediation step, not a substitute for incident reporting. Option B is wrong because deletion by the recipient does not undo the unauthorized disclosure, and the analyst has no authority to declare the incident closed. Option C is wrong because sending a warning email to the employee bypasses the required escalation to the privacy officer and could be seen as an attempt to conceal a reportable incident.

436
MCQmedium

Which encryption method uses a single key for both encryption and decryption of data?

A.Asymmetric encryption
B.Symmetric encryption
C.Digital signature
D.Hashing
AnswerB

Symmetric encryption satisfies the single-key constraint by using one shared secret for both encryption and decryption, as with AES. This contrasts with asymmetric algorithms such as RSA, which employ a public key to encrypt and a mathematically related private key to decrypt, requiring two distinct keys.

Why this answer

Symmetric encryption uses a single shared key for both encryption and decryption of data. This is the defining characteristic of symmetric algorithms like AES, DES, and 3DES, where the same secret key must be known to both sender and receiver to protect confidentiality.

Exam trap

Cisco often tests the distinction between symmetric and asymmetric encryption by presenting a scenario where a single key is used, and candidates may confuse 'single key' with the public key in asymmetric encryption, leading them to incorrectly select asymmetric encryption.

How to eliminate wrong answers

Option A is wrong because asymmetric encryption uses a pair of keys (public and private) for encryption and decryption, not a single key. Option C is wrong because a digital signature is a cryptographic mechanism for authentication and non-repudiation, not an encryption method; it uses asymmetric keys to sign and verify, not to encrypt data. Option D is wrong because hashing is a one-way function that produces a fixed-size digest and cannot be reversed to recover the original data, so it does not support both encryption and decryption.

437
MCQeasy

A SOC analyst needs to create a SIEM correlation rule to detect a brute force attack against SSH on a server. Which of the following would be the most effective rule logic?

A.Alert when a single failed SSH login occurs.
B.Alert when more than 10 failed SSH logins from the same source IP occur within 1 minute.
C.Alert when successful SSH logins occur outside business hours.
D.Alert when multiple failed SSH logins from various IPs occur in one hour.
AnswerB

Thresholding failed SSH logins by source IP within a one-minute window captures the high-frequency, single-origin pattern characteristic of brute forcing, while the short window and IP grouping suppress unrelated sporadic failures. This matches the stem's SSH brute force scenario.

Why this answer

A brute force attack is characterized by a high volume of failed authentication attempts from a single source within a short time window. By alerting on more than 10 failed SSH logins from the same source IP within 1 minute, the rule effectively distinguishes malicious automated guessing from isolated user errors, minimizing false positives while capturing the core behavior of a brute force attempt.

Exam trap

Cisco often tests the distinction between a brute force attack (single source, high frequency) and a distributed attack (multiple sources, lower frequency per source), and candidates may incorrectly choose Option D because they conflate 'multiple IPs' with a stronger attack, missing that the question specifically asks for a brute force against SSH.

How to eliminate wrong answers

Option A is wrong because a single failed SSH login is a common benign event (e.g., typo, forgotten password) and would generate excessive false positives, failing to indicate a brute force attack. Option C is wrong because successful SSH logins outside business hours may indicate unauthorized access but do not directly detect the repeated failed attempts that define a brute force attack; this rule would miss the attack entirely. Option D is wrong because multiple failed logins from various IPs in one hour suggests a distributed attack (e.g., credential stuffing) rather than a classic brute force from a single source, and the one-hour window is too long to trigger timely response, allowing many attempts before alerting.

438
Matchingmedium

Match each Cisco CyberOps concept to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Security Operations Center

Confidentiality, Integrity, Availability

Indicator of Compromise

Tactics, Techniques, and Procedures

Adversary, Capability, Infrastructure, Victim

Why these pairings

The correct matches are: IoC = evidence of intrusion, SIEM = log aggregation and analysis system, IPS = traffic monitoring and blocking device. Common confusions include swapping definitions between similar-sounding terms or confusing tools with indicators.

439
MCQhard

An analyst inspects a PCAP and sees an internal host sending HTTP requests where the User-Agent string is unusually long and contains random alphanumeric characters, and the Cookie header carries base64-like data to an external server. The server responds with small HTTP 200 OK messages. Which technique is most consistent with this traffic?

A.HTTP command-and-control beaconing with data exfiltration over headers
B.A misconfigured web proxy caching responses
C.A legitimate browser extension updating its configuration
D.DNS over HTTPS resolution performed by the host
AnswerA

Attackers frequently abuse HTTP headers such as User-Agent and Cookie to blend C2 traffic with normal web activity. Random alphanumeric User-Agent values and base64-encoded Cookie data indicate obfuscated payloads, while small 200 OK responses represent tasking or acknowledgements. This pattern matches HTTP-based C2 with exfiltration embedded in request headers rather than the body.

Why this answer

Randomized User-Agent strings and base64-encoded Cookie values sent to an external server, with small HTTP 200 responses, are characteristic of HTTP-based command-and-control where data is hidden in headers. Legitimate extension updates, proxy caching, and DNS over HTTPS all produce predictable, structured traffic that does not match the randomness or the request-response pattern observed.

Exam trap

The trap here is focusing on the HTTP 200 OK responses as benign web browsing and overlooking that the anomalous User-Agent and Cookie fields carry the malicious payload.

440
Multi-Selectmedium

A security analyst is reviewing logs from a web server and notices a high volume of HTTP requests from a single IP address targeting the same login page within a short time frame. The analyst suspects a brute force attack. Which TWO actions are most appropriate to mitigate this type of attack? (Choose two.)

Select 2 answers
A.Implement rate limiting on the login endpoint.
B.Disable the login page entirely.
C.Block all traffic from the offending IP address permanently.
D.Increase the password complexity requirements.
E.Implement account lockout after a certain number of failed attempts.
AnswersA, E

Rate limiting caps requests per source within a time window, throttling the high-volume login attempts the stem describes. This directly addresses the brute force constraint by slowing credential guessing, making automated attacks impractical without blocking legitimate users.

Why this answer

Option A is correct because rate limiting on the login endpoint directly throttles the high volume of repeated HTTP requests from a single IP address, which is the defining signature of the brute force attack observed in the logs. Option E is correct because account lockout after a certain number of failed attempts stops an attacker from making unlimited password guesses against a given account, complementing rate limiting by protecting the credential itself rather than just the request rate. Option B is not appropriate because disabling the login page entirely would deny legitimate users access and cause a self-inflicted denial of service.

Option C is not the best mitigation because permanently blocking the offending IP address is brittle—attackers can rotate IPs, and legitimate users behind shared or dynamic addresses could be blocked—so it is not a sustainable control. Option D is not appropriate because increasing password complexity requirements is a preventive policy for credential strength and does not stop the ongoing high-volume request pattern of a brute force attack.

Exam trap

The trap here is that candidates may choose permanent IP blocking or disabling the login page as immediate fixes, but these are either too disruptive or easily bypassed; the exam expects understanding of layered, non-disruptive mitigations like rate limiting and account lockout.

441
Multi-Selectmedium

A security analyst is collecting evidence from a compromised system for legal proceedings. Which TWO actions are critical to preserve the integrity of the evidence?

Select 2 answers
A.Store the evidence in a public folder for easy access
B.Compute a cryptographic hash of the original drive before imaging
C.Delete any sensitive files to protect privacy
D.Run the system normally to capture volatile data
E.Use a write-blocker when creating a forensic image
AnswersB, E

Hashing the original drive before imaging creates a verifiable baseline; any later hash mismatch on the copy proves the data was altered. This satisfies the admissibility constraint by demonstrating the evidence remained unmodified from seizure through analysis.

Why this answer

Option B is correct because computing a cryptographic hash (e.g., SHA-256 or MD5) of the original drive before imaging establishes a verifiable baseline value that can later be compared against the hash of the forensic image to prove the copy is bit-for-bit identical and unaltered, which is essential for evidence admissibility. Option E is correct because a hardware or software write-blocker prevents any write operations from reaching the source drive during imaging, ensuring the original evidence is not modified and preserving its integrity for legal proceedings. Option A is wrong because storing evidence in a public folder exposes it to tampering, unauthorized access, and contamination, destroying the chain of custody.

Option C is wrong because deleting files alters the original evidence and constitutes spoliation. Option D is wrong because running the system normally modifies the drive and volatile state, contaminating the evidence rather than preserving it.

442
MCQmedium

An organization classifies data into Public, Internal, Confidential, and Restricted tiers. A developer needs to place a dataset containing customer payment card numbers into the correct tier and apply the required handling controls. According to common data classification practices, which tier and control combination is most appropriate?

A.Restricted, with encryption, strict need-to-know access, and audit logging
B.Confidential, with encryption at rest and in transit
C.Internal, because the data is used only by employees
D.Public, because the numbers are only partial card values
AnswerA

Restricted is the highest sensitivity tier and is appropriate for regulated data such as payment card numbers, which PCI DSS requires to be encrypted and tightly access-controlled. Applying encryption, least-privilege access, and audit logging aligns with both the classification scheme and regulatory expectations. This combination protects the data and provides the accountability needed if a breach occurs.

Why this answer

Payment card numbers are regulated under PCI DSS and represent a high-impact asset if disclosed, so they belong in the most restrictive tier the organization defines. Restricted classification paired with encryption, need-to-know access, and audit logging satisfies both internal policy and regulatory expectations. Lower tiers such as Internal, Confidential, or Public would apply weaker controls than the data warrants and could create compliance exposure.

Exam trap

The trap here is assuming that because only employees use the data it can be labeled Internal, when regulatory sensitivity rather than audience determines the classification tier.

443
MCQmedium

A SOC analyst notices that a workstation is generating NetFlow records showing repeated outbound connections to 203.0.113.45 on port 443 at regular 60-second intervals, with each flow transferring approximately 4 KB. The destination IP has no reputation data. Which analysis approach would best determine whether this traffic represents C2 beaconing?

A.Block all outbound traffic to 203.0.113.45 at the perimeter firewall and monitor for any user complaints about lost connectivity.
B.Correlate the flow timestamps with DNS query logs and endpoint process telemetry to identify the initiating process and any associated domain resolutions.
C.Run a full antivirus scan on the workstation and review the scan results for any detected malware signatures.
D.Increase the NetFlow sampling rate on the router to capture every packet and then analyze the payload contents for malicious strings.
AnswerB

NetFlow alone shows only metadata; correlating timestamps with DNS logs and endpoint telemetry reveals the process responsible and whether it resolves a suspicious domain. This combination is the most reliable way to confirm beaconing behavior and identify the malware family or C2 infrastructure.

Why this answer

The regular 60-second interval and small, consistent transfers are classic beaconing indicators. NetFlow shows the pattern but not the cause. Correlating flow timestamps with DNS logs and endpoint process telemetry identifies the initiating process and any resolved domains, providing definitive evidence of C2 and enabling proper containment.

Exam trap

The trap here is assuming that blocking the destination IP is the best immediate action, when doing so prematurely can destroy evidence and prevent full identification of the compromised host and C2 channel.

444
MCQmedium

While analyzing a PCAP, an analyst uses the Wireshark filter 'http.request' and finds a URI parameter containing '%27%20UNION%20SELECT%201,2,3%20--'. What type of attack is indicated?

A.Cross-site scripting (XSS)
B.SQL injection
C.Command injection
D.Directory traversal
AnswerB

The URI parameter `%27%20UNION%20SELECT%201,2,3%20--` is URL-encoded, where `%27` decodes to a single quote (`'`), `%20` to a space, and `--` to an SQL comment. This payload injects a single quote to break out of a string context, then appends a `UNION SELECT` statement to retrieve arbitrary data, with the comment `--` suppressing the remainder of the original query. This directly satisfies the constraint of manipulating SQL syntax via user-supplied input, confirming SQL injection.

Why this answer

The URL-encoded string decodes to a SQL injection attempt with UNION SELECT. SQL injection often appears in HTTP parameters.

445
MCQeasy

A SOC analyst is investigating a suspicious file on a Windows host. The file hash matches a known malware variant in a threat intelligence feed. What is the next best step for host-based analysis?

A.Run a full antivirus scan on the host
B.Disable the network adapter to prevent further communication
C.Check for persistence mechanisms such as registry Run keys or scheduled tasks
D.Reboot the host to clear the malware from memory
AnswerC

A confirmed hash match establishes the file is malicious, so analysis shifts from identification to impact. Persistence mechanisms such as Run keys and scheduled tasks reveal how the malware survives reboots, satisfying the host-based scope by exposing the adversary's foothold.

Why this answer

After confirming a file hash matches a known malware variant, the immediate priority for host-based analysis is to determine how the malware maintains persistence on the system. Persistence mechanisms such as Registry Run keys (e.g., HKCU\Software\Microsoft\Windows\CurrentVersion\Run) or scheduled tasks (via schtasks.exe) allow malware to survive reboots and re-establish execution. Identifying these artifacts is critical for containment and eradication, as it reveals the malware's foothold and prevents re-infection after removal.

Exam trap

Cisco often tests the distinction between host-based analysis (focusing on local artifacts like persistence, processes, and registry) and network-based containment (like disabling adapters), so candidates mistakenly choose network isolation steps when the question explicitly asks for host-based analysis.

How to eliminate wrong answers

Option A is wrong because running a full antivirus scan is reactive and may not detect the specific malware variant if signatures are outdated or if the malware employs evasion techniques like packing or polymorphism; the hash match already confirms maliciousness, so scanning adds no new forensic value. Option B is wrong because disabling the network adapter is a network-based containment step, not a host-based analysis step; while it may prevent C2 communication, the question specifically asks for the next best step in host-based analysis, which should focus on understanding the malware's local impact and persistence. Option D is wrong because rebooting the host may clear malware from memory (e.g., fileless malware), but it destroys volatile evidence such as running processes, network connections, and memory-resident artifacts, and it does not address persistence mechanisms that would cause the malware to reload on startup.

446
MCQmedium

Which type of malware is designed to replicate itself and spread to other systems without user intervention?

A.Virus
B.Ransomware
C.Trojan
D.Worm
AnswerD

A worm self-replicates and propagates across networks autonomously, exploiting vulnerabilities or weak credentials without requiring a user to open a file or click a link. This matches the stem's constraint of spreading without user intervention, unlike viruses, which need host execution.

Why this answer

A worm is malware that self-replicates and spreads to other systems automatically, without requiring user interaction or a host program. It typically exploits network vulnerabilities or weak credentials to propagate across networks. This autonomous spreading behavior is the defining characteristic that distinguishes worms from other malware types.

Exam trap

200-201 often tests the distinction between viruses and worms — candidates must remember that worms self-replicate without user intervention, while viruses require a host and user action to spread.

How to eliminate wrong answers

Option A is wrong because a virus requires a host file and some form of user action (such as opening an infected attachment) to execute and spread — it does not self-replicate autonomously. Option B is wrong because ransomware is designed to encrypt data and demand payment; while it may spread via other mechanisms, its defining purpose is extortion, not self-replication. Option C is wrong because a Trojan disguises itself as legitimate software and relies on the user installing and running it — it does not self-replicate or spread on its own.

447
MCQeasy

Which principle ensures that a user cannot deny having performed an action?

A.Authentication
B.Accountability
C.Authorization
D.Non-repudiation
AnswerD

Non-repudiation uses cryptographic evidence such as digital signatures and audit logs to prove an action originated from a specific party. It prevents that party from later denying having performed the action, which is precisely the guarantee the question describes.

Why this answer

Non-repudiation ensures that a user cannot deny having performed an action, typically by using digital signatures or cryptographic mechanisms. In network security, this is often achieved through protocols like HMAC or digital certificates that bind an action to a specific identity, providing irrefutable proof. Without non-repudiation, a user could claim they never sent a message or executed a command, undermining audit trails and legal accountability.

Exam trap

Cisco often tests the distinction between accountability and non-repudiation, where candidates confuse logging/tracking (accountability) with cryptographic proof (non-repudiation), leading them to select 'Accountability' instead of 'Non-repudiation'.

How to eliminate wrong answers

Option A is wrong because authentication verifies the identity of a user or device (e.g., via passwords, certificates, or biometrics) but does not prevent the user from later denying they performed an action. Option B is wrong because accountability refers to the ability to trace actions back to a specific entity through logging and auditing, but it does not inherently provide cryptographic proof to prevent denial. Option C is wrong because authorization controls what resources or actions a user is permitted to access (e.g., via ACLs or RBAC), but it does not address the issue of denying past actions.

448
MCQeasy

A network analyst is examining a PCAP and sees a large number of ICMP echo request packets sent from a single internal host to multiple external IP addresses, with varying payload sizes and no corresponding echo replies. The analyst suspects the host is being used for reconnaissance or data exfiltration. Which characteristic of the ICMP traffic would most strongly indicate that it is being used for data exfiltration rather than simple reconnaissance?

A.The payload sizes are consistent and small, matching standard ping requests.
B.The ICMP packets contain non-standard payload data that is base64-encoded and varies in length.
C.The source IP address is spoofed to match the destination IP address.
D.The ICMP echo requests are sent at a constant rate of one per second to a single external IP.
AnswerB

ICMP tunneling for exfiltration often embeds encoded data in the payload, such as base64 strings, which are not present in normal ping requests. The varying length and non-standard content indicate that the ICMP echo requests are carrying hidden data rather than simply testing connectivity. This is a strong indicator of exfiltration or covert channel use.

Why this answer

The presence of non-standard, base64-encoded payload data that varies in length is a classic sign of ICMP tunneling for data exfiltration. Normal ping requests have predictable payloads, often just a repeating pattern or timestamp. When ICMP is used as a covert channel, the payload carries encoded stolen data, making the traffic anomalous.

The other options describe patterns more consistent with reconnaissance or benign monitoring.

Exam trap

The trap here is focusing on the volume or rate of ICMP traffic, when the payload content and encoding are the definitive indicators of exfiltration.

449
MCQeasy

Based on the exhibit, which type of traffic is being denied?

A.Traffic permitted by the access group.
B.TCP traffic to a DNS server.
C.UDP traffic from an internal host to an external DNS server.
D.ICMP traffic from an external host.
AnswerC

The log matches UDP from inside to outside port 53.

Why this answer

The exhibit shows an access control list (ACL) entry that denies UDP traffic from any source to any destination with a destination port of 53, which is the standard port for DNS. Since the ACL is applied inbound on an interface facing the internal network, it specifically blocks UDP traffic originating from an internal host destined for an external DNS server. This matches option C exactly.

Exam trap

Cisco often tests the distinction between UDP and TCP for DNS traffic, leading candidates to assume that all DNS traffic uses UDP, when in fact DNS can use TCP for larger responses or zone transfers, and the ACL only blocks UDP.

How to eliminate wrong answers

Option A is wrong because the ACL is explicitly denying traffic, not permitting it; the access group is used to apply the ACL, but the ACL itself contains a deny statement. Option B is wrong because the ACL denies UDP traffic to port 53, but TCP traffic to a DNS server (port 53) is not affected by this rule; the rule only targets UDP. Option D is wrong because the ACL denies UDP traffic from any source, but ICMP traffic uses a different protocol (type 1) and is not affected by a UDP-specific deny statement.

450
MCQeasy

An analyst needs to review the Windows event logs from a host to determine if a user's account was used to log in at an unusual time. Which log type should the analyst check?

A.Application
B.System
C.Setup
D.Security
AnswerD

Successful and failed logon events, including timestamps and account names, are recorded in the Security log, so it is the only log type that reveals whether an account was used to authenticate at an unusual time.

Why this answer

The Security log in Windows Event Viewer records audit events, including successful and failed logon attempts (Event ID 4624 for successful logons). This log type is the correct source for determining if a user's account was used to log in at an unusual time, as it captures the timestamp and details of each authentication event.

Exam trap

Cisco often tests the distinction between the Security log (which records authentication events) and the System log (which records system-level events), leading candidates to mistakenly choose the System log for logon analysis.

How to eliminate wrong answers

Option A is wrong because the Application log records events from applications and programs, not authentication or logon activities. Option B is wrong because the System log records events from Windows system components (e.g., driver failures, service starts), not user logon events. Option C is wrong because the Setup log records events related to Windows installation and updates, not user authentication or logon activity.

Page 5

Page 6 of 13

Page 7