Courseiva

Cisco CyberOps Associate 200-201 (200-201) — Questions 451–525

968 questions total · 13pages · All types, answers revealed

Page 6

Page 7 of 13

Page 8
451
Multi-Selecthard

A security policy mandates that all network devices must be hardened. Which THREE of the following are common hardening best practices for routers and switches? (Select three.)

Select 3 answers
A.Implement access control lists (ACLs)
B.Disable unused services
C.Enable Telnet for remote management
D.Use default credentials for initial setup
E.Enable SNMPv3 with strong authentication
AnswersA, B, E

ACLs filter traffic by source, destination, port and protocol, restricting management and transit access to only what each interface requires. This enforces least privilege on the device itself, directly satisfying the hardening mandate by preventing unauthorised reachability to routers and switches.

Why this answer

Option A is correct because implementing access control lists (ACLs) on routers and switches restricts which traffic is permitted to reach the management plane and transit the device, enforcing least-privilege filtering as a core hardening control. Option B is correct because disabling unused services (for example, CDP, LLDP, HTTP server, or unused routing protocols) reduces the attack surface by eliminating unnecessary listening ports and daemons that could be exploited. Option E is correct because SNMPv3 with strong authentication (authNoPriv or authPriv using SHA and AES) replaces insecure SNMPv1/v2c community strings with encrypted, authenticated management traffic.

Option C is not a hardening practice because Telnet transmits credentials and session data in cleartext; SSH should be used instead. Option D is not a hardening practice because default credentials are widely known and must be changed immediately during initial setup.

Exam trap

Cisco often tests the distinction between secure and insecure protocols, so the trap here is that candidates may mistakenly consider Telnet acceptable for remote management because it is widely used, ignoring that it lacks encryption and violates hardening standards.

452
MCQhard

An analyst is tuning a Cisco Firepower intrusion policy. A rule fires repeatedly with the message 'MALWARE-CNC Outbound connection to known malicious domain' against a marketing workstation. Packet capture shows the workstation resolving and connecting to a domain that the threat intelligence feed lists, but the endpoint shows no malicious process, no persistence, and the user states they clicked a link in a phishing email an hour earlier. Which action best reflects sound incident handling at this stage?

A.Suppress the rule permanently for the marketing subnet so analysts are not distracted by future alerts.
B.Close the ticket as a false positive because the endpoint security agent reported no malicious process on disk.
C.Treat the alert as a probable compromise: isolate the workstation, capture volatile data, and correlate the connection timing with the phishing email and any subsequent downloads.
D.Block the domain at the DNS layer only and continue monitoring, since blocking prevents any further harm from the connection.
AnswerC

An outbound connection to a known malicious domain from a user who just clicked a phishing link is a strong compromise signal regardless of current endpoint findings. Early malware often leaves little on disk. Isolating preserves evidence, memory capture may reveal injected code or in-memory payloads, and correlating timing with the email establishes the intrusion chain before lateral movement or credential theft occurs.

Why this answer

Network evidence of a live connection to a threat-intelligence-listed domain, occurring shortly after a user clicked a phishing link, justifies treating the workstation as potentially compromised. Endpoint scans often miss fileless or in-memory activity, so a clean disk does not clear the host. The proportionate response is containment with evidence preservation, followed by correlation across email, DNS, proxy, and endpoint telemetry to establish scope and determine whether credentials or data were affected.

Exam trap

The trap here is equating a clean endpoint scan with a clean host, when network evidence of an actual malicious connection can reflect fileless execution that disk-based tools do not detect.

453
MCQhard

A Security Operations Center (SOC) uses Security Information and Event Management (SIEM) with event correlation. Analysts notice that alerts for a specific malware signature have decreased sharply after a new firewall rule was deployed. However, endpoint scans still show infections on several hosts. What is the most likely explanation for the decrease in SIEM alerts?

A.The firewall rule blocks the malware's C2 traffic, so SIEM no longer receives network alerts, but endpoint infections persist
B.The SIEM correlation rules were accidentally disabled during the firewall update
C.The SIEM is not receiving logs from the endpoint detection and response (EDR) tool
D.The malware has mutated into a different variant that evades detection
AnswerA

The firewall rule blocks command-and-control traffic, so the SIEM's network-based correlation rules stop firing. Endpoint scans still detect the malware because the infection persists locally; only its outbound channel is severed, not the implant itself.

Why this answer

The firewall rule specifically blocks command-and-control (C2) traffic, which is the network communication channel the malware uses to send data or receive instructions. Since the SIEM relies on network-based alerts (e.g., from intrusion detection systems or firewall logs) to detect this traffic, blocking the C2 traffic eliminates those network alerts. However, the malware remains on the endpoints because the firewall does not remove the infection; it only prevents outbound communication, so endpoint scans still detect the malware files or processes.

Exam trap

Cisco often tests the concept that blocking C2 traffic reduces network alerts but does not remediate endpoint infections, leading candidates to mistakenly think the firewall rule eliminated the malware entirely.

How to eliminate wrong answers

Option B is wrong because if SIEM correlation rules were accidentally disabled, the SIEM would stop generating alerts for all events, not just for this specific malware signature, and the sharp decrease would be broad, not isolated to one signature. Option C is wrong because the SIEM not receiving logs from the EDR tool would cause a loss of endpoint-based alerts, but the question states that endpoint scans still show infections, implying the EDR is still functioning and reporting; the decrease is in SIEM alerts, which are primarily network-based in this context. Option D is wrong because if the malware mutated into a different variant, it would evade detection by both network and endpoint tools, but endpoint scans still detect the infections, indicating the original signature is still present on the hosts.

454
Multi-Selecteasy

Which TWO of the following are key elements that should be included in an incident response plan?

Select 2 answers
A.Requirements for antivirus software on endpoints
B.List of approved forensic tools
C.Roles and responsibilities of the incident response team
D.Step-by-step technical remediation instructions for specific attack types
E.Communication and escalation procedures
AnswersC, E

Assigning clear roles and responsibilities ensures each team member knows their exact duties during containment, eradication and recovery, preventing duplicated effort or gaps. This directly satisfies the stem's requirement for key incident response plan elements, since an undocumented team structure leaves response coordination ambiguous when an incident occurs.

Why this answer

Option C is correct because a well-structured incident response plan must clearly define the roles and responsibilities of the incident response team, ensuring each member knows their duties (e.g., incident handler, team lead, communications lead) during detection, containment, eradication, and recovery. Option E is correct because communication and escalation procedures are essential plan elements, specifying internal and external notification paths, escalation thresholds, and contact trees so that incidents are reported to the right stakeholders (management, legal, PR, law enforcement) in a timely manner. Options A, B, and D are not key plan elements: antivirus endpoint requirements belong in security baselines or configuration standards, a list of approved forensic tools is an operational/toolkit detail rather than a core plan component, and step-by-step technical remediation instructions for specific attack types belong in playbooks or runbooks that support the plan, not in the plan itself.

Exam trap

Cisco often tests the distinction between the incident response plan (strategic, process-oriented) and incident response playbooks (tactical, attack-specific), causing candidates to mistakenly select detailed technical instructions or tool lists as key elements of the plan.

455
MCQeasy

A security analyst at a mid-sized company is reviewing the organization's risk management strategy. The CIO asks the analyst to describe the primary purpose of a vulnerability assessment. Which statement best describes this purpose?

A.It automatically applies patches to all discovered software flaws without human intervention.
B.It identifies, quantifies, and prioritizes vulnerabilities in a system.
C.It actively exploits vulnerabilities to determine the level of access an attacker could achieve.
D.It provides a real-time dashboard of all security incidents occurring on the network.
AnswerB

A vulnerability assessment systematically scans and evaluates systems to discover weaknesses, then ranks them by severity and potential impact. It does not exploit flaws or simulate an active adversary, but it provides the inventory needed to plan remediation. In this scenario, the analyst would use tools such as vulnerability scanners to produce a prioritized list that helps the CIO allocate patching resources efficiently.

Why this answer

A vulnerability assessment is a systematic review that identifies, quantifies, and prioritizes security weaknesses in an environment. It differs from a penetration test because it does not exploit flaws or simulate an attacker; instead, it produces a list of vulnerabilities ranked by severity so that remediation efforts can be planned. This makes it a foundational risk management activity.

Exam trap

The trap here is confusing a vulnerability assessment with a penetration test, which actively exploits flaws to demonstrate impact.

456
MCQhard

During an incident response engagement, an analyst is examining a Windows Server 2019 host that is suspected of being compromised. The analyst wants to determine which user accounts were used to log on interactively to the console in the last 24 hours. Which Windows artifact should the analyst query to obtain this information?

A.Security Event ID 4672 with Logon Type 2
B.Security Event ID 4624 with Logon Type 3
C.Security Event ID 4634 with Logon Type 2
D.Security Event ID 4624 with Logon Type 2
AnswerD

Security Event ID 4624 records successful logons, and Logon Type 2 specifically indicates an interactive logon at the console. Filtering 4624 events by Logon Type 2 and the desired time window gives the analyst exactly the list of accounts used for interactive console access on the server.

Why this answer

Successful interactive logons at the console are recorded as Security Event ID 4624 with Logon Type 2. Filtering for that combination and the last 24 hours gives the analyst the specific accounts used for interactive console access on the server, which is exactly the requested scope.

Exam trap

The trap here is mixing up logon type numbers, especially selecting Logon Type 3 for network access or using 4634, which records logoffs rather than successful logons.

457
MCQhard

You are a security analyst at a financial institution. The network consists of a traditional perimeter firewall, an internal IDS (Snort), and a separate network monitoring tool that captures full packet data. Recently, the bank experienced a breach where an attacker exfiltrated customer data via DNS tunneling. The attack went undetected for weeks. The CISO wants to improve detection of data exfiltration and has tasked you with proposing a new monitoring strategy. The current IDS has signatures for common malware C2 channels but no specific DNS tunneling rules. You have access to the full packet capture archive. Which approach would be most effective in detecting DNS tunneling while minimizing false positives?

A.Write custom Snort rules that monitor DNS query size, frequency, and domain name entropy, and use full packet capture to baseline typical DNS behavior.
B.Block all DNS queries to external domains not on a whitelist, and log all blocked queries for review.
C.Increase the Snort signature sensitivity for all DNS-related alerts to maximum.
D.Deploy NetFlow monitoring on the DNS server and look for traffic volume anomalies.
AnswerA

Custom Snort rules inspecting DNS query size, frequency and domain entropy target the tunnelling mechanism directly, while full packet capture baselines normal DNS to tune thresholds. This satisfies the requirement to detect DNS exfiltration with minimal false positives, since existing signatures cover only common malware C2 channels.

Why this answer

DNS tunneling exploits legitimate DNS protocol behavior by encoding data in query payloads, making it invisible to signature-based detection. By writing custom Snort rules that monitor query size (typically > 255 bytes for TXT records), frequency (abnormally high query rates per domain), and domain name entropy (random-looking subdomains), and using full packet capture to baseline normal DNS traffic, you can detect anomalies indicative of tunneling with high precision and low false positives.

Exam trap

Cisco often tests the distinction between detection and prevention—candidates may incorrectly choose a blocking strategy (Option B) or a volume-based approach (Option D) instead of a detection method that leverages packet-level analysis and behavioral baselines.

How to eliminate wrong answers

Option B is wrong because blocking all DNS queries to external domains not on a whitelist is a restrictive, policy-based approach that would break normal internet access for users and services, and it does not detect tunneling—it only prevents it, which is not a monitoring strategy. Option C is wrong because increasing Snort signature sensitivity for all DNS-related alerts to maximum would generate an overwhelming number of false positives from legitimate DNS traffic (e.g., normal lookups, NXDOMAIN responses), rendering the IDS alerts useless for actual threat detection. Option D is wrong because NetFlow monitoring on the DNS server for traffic volume anomalies is too coarse—DNS tunneling often uses low-and-slow data transfer that does not create significant volume spikes, and NetFlow lacks the packet-level detail (e.g., query payload size, entropy) needed to distinguish tunneling from normal DNS traffic.

458
MCQeasy

A security analyst discovers that an attacker is using a vulnerability scanning tool to identify open ports on the company's network. Which type of attack is being performed?

A.Social engineering
B.Passive reconnaissance
C.Active reconnaissance
D.Denial of Service
AnswerC

Active reconnaissance involves directly interacting with the target to gather information, such as port scanning, which generates traffic and can be detected. Vulnerability scanning tools probing open ports are actively engaging the network, distinguishing this from passive reconnaissance.

Why this answer

Active reconnaissance involves directly interacting with the target system to gather information, such as port scanning, vulnerability scanning, or banner grabbing. Using a vulnerability scanning tool to identify open ports sends packets to the target and elicits responses, which is the definition of active reconnaissance. This contrasts with passive reconnaissance, which collects information without direct interaction.

Exam trap

The trap is confusing active vs. passive reconnaissance; candidates often think 'scanning' is passive because it's information gathering, but any direct interaction with the target is active.

How to eliminate wrong answers

Option A is wrong because social engineering manipulates people into revealing information, not technical scanning of ports. Option B is wrong because passive reconnaissance gathers information from public sources (e.g., WHOIS, DNS records, social media) without touching the target's systems. Option D is wrong because a Denial of Service attack aims to disrupt availability, not enumerate open ports.

459
MCQmedium

Which threat intelligence sharing standard defines a language and format for representing structured threat information, such as indicators and campaigns?

A.STIX
B.MISP
C.TAXII
D.OpenIOC
AnswerA

STIX (Structured Threat Information Expression) provides a standardised language and serialisation format for structured threat intelligence, covering indicators, campaigns, threat actors and relationships. It satisfies the requirement for a sharing standard that represents structured threat information, unlike transport protocols such as TAXII.

Why this answer

STIX is a standardized language for describing threat intelligence, while TAXII is the protocol to share it.

460
MCQeasy

Which NIST Cybersecurity Framework function involves developing and implementing appropriate safeguards to ensure delivery of critical infrastructure services?

A.Respond
B.Detect
C.Identify
D.Protect
AnswerD

The Protect function covers safeguards that limit or contain the impact of a cybersecurity event, including access control, awareness training, data security and protective technology. Developing and implementing these safeguards to ensure delivery of critical infrastructure services is its stated purpose.

Why this answer

The Protect function of the NIST Cybersecurity Framework involves developing and implementing appropriate safeguards to ensure delivery of critical infrastructure services. It covers access control, awareness training, data security, protective technology, and maintenance. This function limits or contains the impact of a potential cybersecurity event.

Exam trap

200-201 often tests the boundaries between CSF functions — candidates must distinguish Protect (safeguards) from Detect (monitoring) and Identify (asset and risk understanding), since all three sound related but address different phases.

How to eliminate wrong answers

Option A is wrong because Respond involves taking action regarding a detected cybersecurity incident — activities like response planning, communications, analysis, mitigation, and improvements occur after an event. Option B is wrong because Detect involves developing and implementing activities to identify the occurrence of a cybersecurity event, such as continuous monitoring and detection processes. Option C is wrong because Identify involves understanding the cybersecurity risks to systems, people, assets, data, and capabilities — it is about inventory and risk assessment, not safeguards.

461
Multi-Selecthard

A security analyst is reviewing the firewall log exhibit. The analyst suspects that this traffic might be part of a command-and-control (C2) communication based on the packet size and the timing of similar events. Which TWO additional pieces of evidence would most strongly support the suspicion of C2 traffic?

Select 2 answers
A.The packet size is consistently 1452 bytes across multiple connections.
B.The destination IP is listed in a threat intelligence feed as a known C2 server.
C.The same source IP makes similar connections to the same destination IP every 60 seconds.
D.The source IP also connected to multiple other external IPs on port 443 within the same hour.
E.The traffic is using HTTPS (port 443) which is commonly used for covert channels.
AnswersB, C

Threat intelligence provides direct evidence of malicious intent.

Why this answer

A destination IP listed in a threat intelligence feed as a known C2 server directly indicates that the endpoint is associated with malicious command-and-control infrastructure. This external corroboration is strong evidence that the traffic is part of a C2 channel, as threat feeds aggregate confirmed indicators of compromise (IoCs) from multiple sources.

Exam trap

Cisco often tests the distinction between generic network behavior (like consistent packet sizes or common port usage) and specific indicators of compromise (like threat intelligence matches or periodic beaconing), trapping candidates who mistake normal traffic patterns for malicious activity.

462
MCQhard

An attacker intercepts communication between a client and server and modifies the data being transmitted. The client and server are unaware of the modification. Which type of attack is being performed?

A.Man-in-the-Middle
B.ARP spoofing
C.DNS poisoning
D.Replay attack
AnswerA

A man-in-the-middle attack places the adversary inline between client and server, letting them relay and alter transmitted data while both endpoints believe they communicate directly. This interception plus undetected modification is precisely the behaviour described in the scenario.

Why this answer

A Man-in-the-Middle (MITM) attack occurs when an attacker secretly relays and possibly alters the communication between two parties who believe they are directly communicating with each other. In this scenario, the attacker intercepts and modifies the data in transit, and neither the client nor the server detects the modification, which is the hallmark of a MITM attack. MITM is a broad category that encompasses various techniques, including ARP spoofing and DNS poisoning, but the core definition is the active interception and modification of traffic.

Exam trap

200-201 often tests the distinction between broad attack categories and specific techniques, so candidates may incorrectly choose a specific method like ARP spoofing or DNS poisoning when the question describes the general behavior of a MITM attack.

How to eliminate wrong answers

Option B is wrong because ARP spoofing is a specific technique used to enable a MITM attack by poisoning the ARP cache to associate the attacker's MAC address with the IP address of a legitimate host, but it does not inherently include modification of data; it is a means to an end. Option C is wrong because DNS poisoning (or DNS spoofing) involves corrupting DNS records to redirect traffic to a malicious site, but it does not necessarily involve intercepting and modifying data between a client and server; it is a redirection attack. Option D is wrong because a replay attack involves capturing valid data transmission and retransmitting it later to produce an unauthorized effect, but it does not involve modifying the data; the data is simply repeated.

463
MCQmedium

During an investigation, an analyst finds that an internal host has been communicating with a known malicious IP on port 445. Which protocol is most likely involved?

A.SSH
B.RDP
C.SMB
D.HTTP
AnswerC

Port 445 carries SMB, the protocol for Windows file and printer sharing. An internal host connecting outward to a known malicious IP on this port indicates SMB-based lateral movement or data exfiltration, matching the investigation's evidence of command-and-control or ransomware staging traffic.

Why this answer

Port 445 is the default port for Microsoft SMB (Server Message Block) over TCP, used for file sharing, printer sharing, and other network services. Communication with a known malicious IP on this port strongly indicates SMB-based activity, such as exploitation of vulnerabilities like EternalBlue (MS17-010) or unauthorized file access.

Exam trap

Cisco often tests the association of well-known ports with their protocols, and the trap here is that candidates may confuse port 445 with HTTP (80) or RDP (3389) due to common attack narratives, but the specific port 445 uniquely identifies SMB.

How to eliminate wrong answers

Option A is wrong because SSH (Secure Shell) uses port 22, not 445, and is used for secure remote administration, not file sharing. Option B is wrong because RDP (Remote Desktop Protocol) uses port 3389, not 445, and is used for remote graphical desktop access. Option D is wrong because HTTP uses port 80 (or 443 for HTTPS), not 445, and is used for web traffic, not direct file sharing or SMB operations.

464
MCQmedium

A system administrator needs to grant access to a database for a new employee. According to the principle of least privilege, what should be done?

A.Grant only the minimum required permissions
B.Grant temporary admin access
C.Grant no access until manager approves
D.Grant full access and remove later
AnswerA

Least privilege requires granting the new employee only the specific database permissions their role needs, nothing broader. This limits potential damage from error or credential compromise, satisfying the stated principle rather than assigning fixed roles or default access.

Why this answer

The principle of least privilege states that users should be granted only the minimum access necessary to perform their job functions, and no more. For a new employee needing database access, the correct action is to grant only the minimum required permissions (A) — scoped to the specific database objects and operations the role demands. This limits the blast radius of compromise or error and satisfies least privilege.

Exam trap

200-201 often tests whether candidates confuse least privilege with approval workflows or temporary elevation — the trap is picking 'grant no access until approval' (a process control) or 'temporary admin' (elevation) instead of the minimum-necessary-access principle itself.

How to eliminate wrong answers

Option B is wrong because granting temporary admin access violates least privilege — admin rights are far broader than needed and create unnecessary risk, even if temporary. Option C is wrong because granting no access until manager approval is a workflow/approval step, not the least-privilege principle itself; the question asks what least privilege dictates, which is minimum necessary access, not a blanket denial pending approval. Option D is wrong because granting full access and removing later is the opposite of least privilege — it is 'most privilege first,' which exposes the organization to risk during the period of excessive access and relies on timely revocation that often fails.

465
MCQmedium

A company uses a SIEM with correlation rules. They notice that a rule designed to detect brute-force attacks is not triggering even though failed logins are occurring. Which is the most likely cause?

A.The SIEM is receiving too many logs and dropping events.
B.The correlation rule threshold is set too high.
C.The SIEM time zone is misconfigured.
D.The log source is not sending syslog data.
AnswerB

Correlation rules fire only when the count of matching events within the rule's time window reaches the configured threshold. If that threshold is set too high, genuine brute-force activity generating failed logins never accumulates enough events to trigger an alert, explaining the absence of detections.

Why this answer

A SIEM correlation rule for brute-force attacks typically triggers when the number of failed login attempts from a single source exceeds a defined threshold within a specific time window. If the threshold is set too high, the rule will not fire even though failed logins are occurring, because the count never reaches the required value. This is the most direct and common cause for a correlation rule not triggering when expected.

Exam trap

Cisco often tests the concept that a correlation rule's threshold is a direct control over its sensitivity, and candidates may mistakenly attribute the issue to data ingestion problems (like dropped logs or misconfigured time zones) rather than the rule's own configuration.

How to eliminate wrong answers

Option A is wrong because while a SIEM can drop events when overwhelmed, this would typically cause incomplete or missing data, not a consistent failure of a specific correlation rule to trigger; the rule would still fire if the threshold were met in the logs that are processed. Option C is wrong because a time zone misconfiguration would cause timestamps to be offset, potentially affecting time-window calculations, but it would not prevent the rule from triggering entirely if the raw count of failed logins still exceeds the threshold within the adjusted window. Option D is wrong because if the log source were not sending syslog data, the SIEM would not receive any failed login events at all, and the question explicitly states that failed logins are occurring, meaning the logs are being received.

466
MCQmedium

A security analyst is reviewing the access control strategy for a research and development department. The department handles highly sensitive intellectual property, and the organization wants to ensure that employees can only access information strictly necessary for their current project tasks, even if they have previously worked on other projects. Which access control principle is being enforced?

A.Mandatory access control
B.Separation of duties
C.Need to know
D.Least privilege
AnswerC

Need to know restricts access to information only to individuals who require it to perform their specific duties. In this scenario, employees should only access data necessary for their current project tasks, aligning with the need-to-know principle. It ensures that even if an employee had access to other projects previously, that access is revoked when no longer needed.

Why this answer

The need-to-know principle ensures that access to information is granted only to individuals whose current responsibilities require that specific information. In this scenario, the organization wants to restrict access to intellectual property based on project tasks, which directly reflects need-to-know. Least privilege is about minimum permissions, but need-to-know is more granular and focuses on information relevance to the task.

Exam trap

The trap here is confusing need to know with least privilege, as both limit access, but need to know is specifically about information relevance to a task, while least privilege is about minimum permissions for a role.

467
MCQmedium

Your organization recently deployed a new web application that uses HTTPS. The security team notices that the IDS is generating a large number of alerts for 'SSL/TLS handshake anomalies' and 'self-signed certificates'. After investigating, you find that many of these alerts are coming from a legitimate internal scanning tool that uses a self-signed certificate. The IDS also reports a high rate of 'TLS renegotiation' attempts from the same source. The CISO wants to reduce false positives while maintaining visibility. The IDS is based on Suricata and uses a default rule set. What is the best course of action?

A.Create a custom Suricata pass rule that excludes traffic from the specific IP address of the scanning tool.
B.Add a whitelist rule that ignores any traffic from any host using self-signed certificates.
C.Disable the Suricata rules that match self-signed certificates and TLS renegotiation.
D.Recommend removing the scanning tool from the network and using a different tool that uses a trusted certificate.
AnswerA

A Suricata pass rule suppresses alerts for the scanner's IP while other rules still inspect its traffic, cutting false positives without losing visibility. It targets the specific source generating self-signed certificate and TLS renegotiation alerts, satisfying the CISO's requirement to reduce noise while maintaining detection.

Why this answer

Creating a custom Suricata pass rule for the specific IP address of the legitimate scanning tool will suppress alerts for that known source while maintaining full visibility into all other traffic. This approach reduces false positives without disabling broader security monitoring, as the IDS continues to inspect and alert on SSL/TLS anomalies and self-signed certificates from all other hosts.

Exam trap

Cisco often tests the distinction between a targeted exclusion (like a pass rule for a specific IP) and a broad configuration change (like disabling rules or whitelisting entire categories), where candidates mistakenly choose the latter because they think it is simpler, not realizing it sacrifices security visibility.

How to eliminate wrong answers

Option B is wrong because whitelisting any traffic from hosts using self-signed certificates would broadly disable alerts for all self-signed certificate traffic, including potential malicious activity, thereby creating a significant security blind spot. Option C is wrong because disabling the Suricata rules for self-signed certificates and TLS renegotiation would globally remove detection for these events across all traffic, not just the scanning tool, which undermines the CISO's requirement to maintain visibility. Option D is wrong because removing the scanning tool is an unnecessary operational change; the tool is legitimate and can be safely excluded via a targeted pass rule, preserving both security and functionality.

468
MCQmedium

A security policy requires that all remote access be authenticated using a one-time password (OTP) token. Which technology should be implemented?

A.SSH key pairs
B.RADIUS with token server
C.LDAP with username and password
D.VPN with pre-shared key
AnswerB

RADIUS carries authentication requests to an external server, and pairing it with a token server lets that server validate the OTP generated by each user's hardware or software token. This satisfies the policy's requirement that all remote access use one-time passwords.

Why this answer

RADIUS with a token server is the correct choice because RADIUS is the standard protocol for carrying authentication requests from network access devices to an authentication server, and integrating a token server (e.g., RSA SecurID, Duo) enables one-time password validation. The token server generates or validates the OTP, and RADIUS relays the credentials, satisfying the policy requirement for OTP-based remote access authentication.

Exam trap

The trap here is conflating any strong authentication method (SSH keys, PSK, LDAP) with OTP, when only a RADIUS-plus-token-server architecture actually validates one-time passwords.

How to eliminate wrong answers

Option A is wrong because SSH key pairs provide cryptographic authentication but are not one-time passwords and do not satisfy an OTP token policy. Option C is wrong because LDAP with username and password performs static credential authentication, not OTP token validation, and LDAP alone cannot enforce OTP. Option D is wrong because a VPN with a pre-shared key authenticates the tunnel endpoint, not the user, and a PSK is a static shared secret rather than a one-time password.

469
MCQmedium

A security analyst is reviewing a packet capture and observes that a workstation is sending a large volume of TCP SYN packets to many different destination IP addresses on port 445, with no corresponding completed handshakes. The analyst suspects malware is performing reconnaissance. Which type of activity is this workstation most likely performing?

A.A man-in-the-middle attack intercepting SMB traffic
B.TCP port scanning of many hosts on port 445
C.A SYN flood denial-of-service attack against a single target
D.A brute-force attack against SMB credentials
AnswerB

Sending TCP SYN packets to many destination IP addresses on the same port, without completing the three-way handshake, is classic TCP SYN scanning. The goal is to discover which hosts have port 445 (SMB) open. The broad destination range indicates host discovery across a subnet, which matches reconnaissance behavior often performed by worms or scanning malware.

Why this answer

The traffic pattern of many TCP SYN packets to numerous destination addresses on a single port, with no completed handshakes, is the signature of TCP SYN scanning. This is a reconnaissance technique used to identify live hosts and open services, commonly on port 445 for SMB. A SYN flood would focus on one target, and brute-force or man-in-the-middle activity would require established connections.

Exam trap

The trap here is assuming any flood of SYN packets is a SYN flood DoS, when the distinguishing factor is whether the packets target one host or many hosts for discovery.

470
MCQmedium

An analyst is investigating a Windows 10 workstation suspected of being compromised. The analyst runs `wmic process get name,processid,parentprocessid,commandline` and observes a process named `powershell.exe` with the command line `powershell -nop -w hidden -enc SQBFAFgAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAA...`. What does the `-enc` parameter indicate about how the command was executed?

A.The command was encrypted with AES and requires a key to decrypt.
B.The command was signed with a digital certificate to appear legitimate.
C.The command was Base64-encoded to obfuscate its contents.
D.The command was compressed using gzip to reduce its size.
AnswerC

The `-enc` parameter (short for `-EncodedCommand`) tells PowerShell to interpret the following string as Base64-encoded UTF-16LE text. Attackers use this to hide malicious scripts from command-line logging and casual inspection. Decoding the Base64 string reveals the actual PowerShell commands, which often download or execute further payloads.

Why this answer

The `-enc` parameter in PowerShell stands for `-EncodedCommand`, which accepts a Base64-encoded string representing the actual command. Attackers use it to obfuscate malicious scripts and bypass simple command-line logging. An analyst should decode the Base64 string to reveal the true intent, such as downloading a payload or establishing persistence.

Exam trap

The trap here is assuming that `-enc` means encryption requiring a decryption key, when it actually refers to Base64 encoding that anyone can decode.

471
MCQmedium

A financial services company must retain security event logs for a period defined by its policy and applicable regulations. The security architect is documenting how long different log sources must be kept and where. Which statement best reflects a sound log retention practice for security operations?

A.Retain only logs that the SIEM has already correlated into alerts, discarding raw events to save space.
B.Delete logs after 24 hours to reduce the risk of exposing sensitive information in the event of a breach.
C.Define retention periods per log source based on regulatory and business requirements, and store logs centrally with integrity protection.
D.Retain all logs indefinitely on the source system to guarantee availability for any future investigation.
AnswerC

Sound practice is to map each log source to a retention period derived from legal, regulatory, and investigative needs, then centralize storage so logs survive host rebuilds. Central storage with integrity protection, such as write-once or hashed archives, preserves evidentiary value. This approach balances cost with the ability to investigate incidents that may be discovered months after initial activity, and it supports audits by documenting the rationale for each period.

Why this answer

Effective log retention ties each source to a defined period justified by regulation and business need, then centralizes storage with integrity protection so logs remain available and trustworthy. Indefinite retention on source systems, extremely short deletion windows, or keeping only correlated alerts all undermine investigations and compliance. The chosen approach supports both retrospective hunting and evidentiary requirements.

Exam trap

The trap here is equating storage savings with good retention practice, leading to keeping only alerts or deleting logs too quickly.

472
MCQhard

Based on the exhibit, what condition triggers an alert?

A.More than 1000 DNS queries from a single source within 60 seconds.
B.A single DNS query to a known malicious domain.
C.Any UDP traffic to port 53 exceeding 1000 packets per second.
D.More than 1000 UDP connections to port 53 within 60 seconds.
AnswerA

Threshold-based detection fires when a single source exceeds 1000 DNS queries in 60 seconds, matching the exhibit's configured trigger. This rate-based condition identifies DNS tunnelling or amplification activity, where abnormal query volume from one host signals compromise. The specified count and time window are the exact parameters the alert monitors.

Why this answer

The exhibit shows a rule configured to trigger an alert when the number of DNS queries from a single source IP exceeds 1000 within a 60-second sliding window. This is a rate-based threshold designed to detect DNS amplification or tunneling attacks, where a single host generates an abnormally high volume of DNS requests. Option A correctly describes this condition.

Exam trap

Cisco often tests the distinction between a rate-based threshold (counting events over time) and a signature-based match (single event), leading candidates to confuse a single malicious query with a volumetric anomaly.

How to eliminate wrong answers

Option B is wrong because a single DNS query to a known malicious domain would typically be detected by a signature-based or threat-intelligence rule, not by a rate-based threshold as shown in the exhibit. Option C is wrong because the rule specifically counts DNS queries (typically UDP packets to port 53), not all UDP traffic to port 53; the threshold is based on queries, not raw packets, and the exhibit shows a query count, not a packet-per-second rate. Option D is wrong because the rule counts DNS queries, not UDP connections; DNS queries are typically stateless UDP datagrams, not connections, and the exhibit does not reference connection tracking or a 60-second window for connections.

473
MCQeasy

Which element of the CIA triad is primarily compromised when an attacker successfully intercepts and reads encrypted network traffic without authorization?

A.Non-repudiation
B.Confidentiality
C.Integrity
D.Availability
AnswerB

Confidentiality guarantees data is readable only by authorised parties. Intercepting and reading encrypted traffic without authorisation exposes the plaintext content to an unintended party, so the confidentiality element of the CIA triad is the one primarily compromised.

Why this answer

Confidentiality ensures data is not disclosed to unauthorized parties. When an attacker intercepts and reads encrypted traffic, the confidentiality of that data is breached because the adversary gains access to information they were not authorized to see. Integrity concerns unauthorized modification, and availability concerns disruption of access, neither of which is the primary impact of a read-only interception.

Exam trap

The trap here is conflating confidentiality with integrity when the scenario involves interception; candidates often assume any network attack compromises integrity, but a read-only interception specifically targets confidentiality.

How to eliminate wrong answers

Option A is wrong because non-repudiation is not one of the three CIA triad elements; it is a separate security property ensuring a party cannot deny having performed an action, typically provided by digital signatures. Option C is wrong because integrity refers to protecting data from unauthorized alteration, whereas the scenario describes reading/interception, not modification. Option D is wrong because availability refers to ensuring systems and data are accessible to authorized users when needed, which is not affected by passive interception.

474
MCQmedium

A critical security patch for a widely exploited vulnerability is released. The patch requires a system reboot during business hours. According to change management policy, what is the best procedure?

A.Deploy the patch only at the end of the business day
B.Wait for the next scheduled change window
C.Submit an emergency change request for immediate approval
D.Install the patch without approval
AnswerC

An emergency change request satisfies the policy requirement for handling urgent, unplanned changes, allowing immediate approval and deployment. Because the vulnerability is widely exploited and the patch demands a business-hours reboot, standard change procedures would introduce unacceptable exposure delay; emergency change processes exist precisely to authorise such time-critical remediation.

Why this answer

When a critical security patch addresses a widely exploited vulnerability, the immediate risk to the organization outweighs standard change windows. Change management policy typically includes an emergency change process that bypasses normal scheduling to allow rapid deployment with expedited approval, even if a reboot during business hours is required. This aligns with the principle of prioritizing security over availability in high-severity scenarios.

Exam trap

Cisco often tests the misconception that change management always requires waiting for a scheduled window, but the trap here is that emergency change processes exist specifically to handle critical security patches that cannot wait.

How to eliminate wrong answers

Option A is wrong because delaying deployment until the end of the business day leaves the system exposed to active exploitation for several hours, which is unacceptable for a widely exploited vulnerability. Option B is wrong because waiting for the next scheduled change window could mean days or weeks of exposure, violating the urgency required for critical patches. Option D is wrong because installing the patch without any approval bypasses change management controls entirely, risking unauthorized changes that could lead to compliance violations or operational disruptions.

475
MCQhard

An analyst is investigating a potential data exfiltration. The logs show a series of DNS queries with subdomains that appear to be base64-encoded strings. Which technique is likely being used?

A.DNS tunneling
B.DNS amplification
C.Fast flux
D.Domain generation algorithm
AnswerA

DNS tunneling encapsulates data in DNS queries to exfiltrate information.

Why this answer

DNS tunneling encodes data (e.g., exfiltrated files) into subdomains of DNS queries, which are then sent to a malicious authoritative DNS server controlled by the attacker. The base64-encoded subdomains in the logs are a classic indicator of this technique, as the attacker uses the DNS protocol to bypass network security controls and covertly transmit data.

Exam trap

Cisco often tests the distinction between DNS tunneling (data exfiltration via subdomain encoding) and DNS amplification (a volumetric DDoS attack), so candidates must recognize that base64-encoded subdomains point to tunneling, not amplification.

How to eliminate wrong answers

Option B is wrong because DNS amplification is a reflection-based DDoS attack that uses open resolvers to flood a victim with large DNS responses, not a data exfiltration technique. Option C is wrong because fast flux uses rapid changes in DNS A records to hide the IP addresses of malicious servers, not to encode data in subdomains. Option D is wrong because a domain generation algorithm (DGA) is used to periodically generate random domain names for command-and-control communication, not to encode exfiltrated data in subdomain labels.

476
MCQmedium

An analyst runs Volatility's pstree plugin on a memory dump. The output shows that a process 'svchost.exe' is the child of 'explorer.exe'. What is suspicious about this?

A.explorer.exe should not have any child processes
B.Nothing, svchost.exe can be a child of any process
C.svchost.exe should be a child of services.exe, not explorer.exe
D.The pstree output is unreliable
AnswerC

Legitimate svchost.exe instances are spawned by services.exe, which hosts service DLLs. A parent of explorer.exe indicates process injection or masquerading, since explorer.exe never launches service hosts. This parent-child anomaly is the specific indicator the analyst must flag.

Why this answer

In a normal Windows system, svchost.exe is a service host process that should always be a child of services.exe, which is the Service Control Manager (SCM). When svchost.exe appears as a child of explorer.exe, it indicates that a malicious process or attacker has spawned a fake svchost.exe from explorer.exe to evade detection, as legitimate svchost.exe instances are never launched from the Windows shell.

Exam trap

Cisco often tests the misconception that svchost.exe can be a child of any process because it is a common system process, but the trap is that candidates forget the strict parent-child relationship enforced by the Service Control Manager in Windows.

How to eliminate wrong answers

Option A is wrong because explorer.exe can and does have legitimate child processes, such as when a user launches an application from the Start menu or desktop; the statement that it should have no child processes is false. Option B is wrong because svchost.exe should never be a child of any arbitrary process; it must be a direct child of services.exe to be legitimate, as the SCM is the only authorized parent for service host processes. Option D is wrong because the pstree plugin from Volatility is a reliable tool for reconstructing process parent-child relationships from memory dumps; its output is trustworthy when the memory image is intact and properly analyzed.

477
MCQmedium

A company's incident response policy defines four phases: Preparation, Detection & Analysis, Containment Eradication & Recovery, and Post-Incident Activity. During an active ransomware outbreak, the IR team is unable to contain the spread because the containment plan did not account for the malware's use of PowerShell for lateral movement. Which phase had a deficiency?

A.Containment Eradication & Recovery
B.None of the above
C.Preparation
D.Post-Incident Activity
E.Detection & Analysis
AnswerC

Preparation failed because the containment playbook omitted PowerShell-based lateral movement, so the team lacked pre-built scripts, logging and segmentation rules before the outbreak. Preparation must anticipate likely attack techniques and encode them into tested procedures; without that foresight, Containment cannot execute during an active ransomware incident.

Why this answer

The Preparation phase involves creating and maintaining the incident response plan, including playbooks and procedures. If the containment plan did not account for PowerShell-based lateral movement, that is a gap in the planning and preparation stage. The actual containment failure during the incident is a symptom of inadequate preparation, not a deficiency in the Containment phase itself, which is about executing the plan.

Exam trap

The trap here is confusing the phase where the failure manifests (Containment) with the phase where the root cause lies (Preparation). Candidates often pick the phase where the problem occurred rather than the phase that should have prevented it.

How to eliminate wrong answers

Option A is wrong because the Containment Eradication & Recovery phase is about executing the containment measures, not about the plan's completeness; the failure occurred because the plan lacked necessary details, which is a preparation issue. Option B is wrong because there is a clear deficiency in the Preparation phase. Option D is wrong because Post-Incident Activity focuses on lessons learned and improving future responses, not on the initial plan's content.

Option E is wrong because Detection & Analysis is about identifying and validating incidents, not about the containment strategy.

478
MCQmedium

A security analyst is reviewing the chain of custody form for a laptop seized from an employee suspected of intellectual property theft. The form shows the laptop was collected by the IT manager, transported to a storage room, and later examined by an outside forensics firm. The analyst notices that the form lacks signatures for the transfer between the IT manager and the storage room custodian. What is the most likely impact of this omission on the investigation?

A.The outside forensics firm must re-examine the laptop from scratch to restore integrity.
B.The forensic examination results will be automatically inadmissible in court.
C.The IT manager will be held personally liable for any data loss from the laptop.
D.The evidence may be challenged as tampered or unauthenticated in legal proceedings.
AnswerD

A complete chain of custody requires documented, signed transfers at every handoff. Missing signatures for the IT manager to storage room transfer creates a gap where unauthorized access or tampering could have occurred. This weakens the evidence's admissibility and credibility. In legal proceedings, opposing counsel can argue the evidence was not properly controlled, potentially leading to exclusion or reduced weight.

Why this answer

A chain of custody is a chronological documentation of evidence seizure, custody, transfer, and analysis. Each transfer must be signed and dated to prove the evidence was not tampered with. Missing signatures create an unaccounted period, which undermines the evidence's authenticity.

Courts may exclude or discount such evidence, so the correct impact is that it may be challenged as tampered or unauthenticated.

Exam trap

The trap here is assuming that any chain of custody error makes evidence automatically inadmissible, when in reality it typically affects the weight or credibility of the evidence rather than causing automatic exclusion.

479
MCQmedium

A security analyst is reviewing network traffic and observes a large number of DNS queries for randomly generated domain names, such as 'a1b2c3d4e5f6g7h8.com', from a single internal host. The queries are followed by responses with very short TTL values. The analyst suspects the host is compromised. Which type of malicious activity is most likely occurring?

A.Fast flux DNS used to hide the location of a botnet controller
B.DNS cache poisoning attack against the internal resolver
C.Domain generation algorithm (DGA) used by malware for command-and-control (C2) communication
D.DNS tunneling used to exfiltrate sensitive data
AnswerC

DGA malware generates many pseudo-random domain names to avoid static blocklists and to locate its C2 server. The short TTLs and high volume of unique, random-looking queries from one host strongly indicate DGA activity. The host is likely attempting to resolve one of the domains that the attacker has registered to establish C2.

Why this answer

The high volume of unique, random-looking domain queries with short TTLs from a single host is a classic indicator of a domain generation algorithm. Malware uses DGA to periodically generate many domain names and attempt to resolve them, hoping to find the one registered by the attacker for command and control. This evades static domain blocklists and makes takedown difficult.

Exam trap

The trap here is confusing DGA with DNS tunneling or fast flux; DGA involves many random domains, while tunneling uses one domain with encoded data, and fast flux uses one domain with changing IPs.

480
MCQmedium

A SOC analyst sees an alert for 'Possible SQL Injection' on a web server. Reviewing the PCAP, the analyst finds the parameter 'id=1 OR 1=1' in the HTTP request. However, the web server returns a normal page with no signs of compromise. What is the correct classification?

A.True negative
B.False negative
C.False positive
D.True positive
AnswerC

The payload 'id=1 OR 1=1' is a classic tautology injection attempt, but the server returned a normal page with no compromise indicators. Because the attack neither succeeded nor altered behaviour, the alert reflects benign traffic rather than a genuine intrusion, so it is classified as a false positive.

Why this answer

A false positive occurs when a security tool raises an alert for activity that is not actually malicious or successful. Here, the SQL injection payload 'id=1 OR 1=1' was detected in the request, but the server returned a normal page with no signs of compromise, meaning the attack did not succeed and the alert was triggered on suspicious input rather than actual exploitation. Therefore, the alert is a false positive.

Exam trap

200-201 often tests the confusion between false positive and true positive by presenting a detected payload without confirmed compromise — candidates must remember that detection alone does not make it a true positive.

How to eliminate wrong answers

Option A (true negative) is wrong because a true negative means no alert was raised and no malicious activity occurred — here an alert was raised. Option B (false negative) is wrong because a false negative means malicious activity occurred but was not detected — here detection happened. Option D (true positive) is wrong because a true positive requires that the detected activity was actually malicious and/or successful — the server showed no compromise, so the detection was not a true positive.

481
MCQmedium

Which cryptographic technique uses a public and private key pair to provide non-repudiation?

A.Digital signature
B.Symmetric encryption
C.Digital certificate
D.Hashing
AnswerA

A digital signature is generated using the sender's private key, which only they possess, so they cannot later deny creating it. Verification with the corresponding public key provides non-repudiation, the specific property the stem requires.

Why this answer

A digital signature is created by hashing the message and encrypting that hash with the sender's private key. Anyone can verify it using the sender's public key, and because only the sender possesses the private key, the sender cannot later deny having signed it — this is non-repudiation. Symmetric encryption, certificates, and hashing alone do not provide that property.

Exam trap

200-201 often tests the difference between integrity (hashing), confidentiality (encryption), authentication (certificates), and non-repudiation (digital signatures) — candidates confuse digital certificates with digital signatures, but only the signature uses the private key to prove origin.

How to eliminate wrong answers

Option B is wrong because symmetric encryption uses a single shared secret key for both encryption and decryption, so either party could have produced the ciphertext — there is no proof of origin and thus no non-repudiation. Option C is wrong because a digital certificate binds a public key to an identity via a CA's signature; it enables authentication and trust but does not itself sign the message or provide non-repudiation of the message content. Option D is wrong because hashing alone provides integrity (a fixed-length digest) but no key or identity binding — anyone can compute the same hash, so it cannot prove who sent the data.

482
Multi-Selecthard

Which THREE are principles of the CIA triad? (Select three.)

Select 3 answers
A.Non-repudiation
B.Confidentiality
C.Accountability
D.Integrity
E.Availability
AnswersB, D, E

Confidentiality is a core CIA triad principle, ensuring data is accessible only to authorised parties. It satisfies the stem's requirement by protecting information from unauthorised disclosure through mechanisms such as encryption, access controls and data classification. Alongside integrity and availability, it forms the three foundational security objectives the question asks you to identify.

Why this answer

The CIA triad consists of Confidentiality, Integrity, and Availability, so options B, D, and E are correct. Confidentiality (B) ensures data is accessible only to authorized parties, typically enforced through encryption, access control lists, and authentication. Integrity (D) ensures data remains accurate and unaltered in transit or at rest, supported by hashing, checksums, and digital signatures.

Availability (E) ensures systems and data are accessible to authorized users when needed, achieved through redundancy, backups, and DDoS mitigation. Non-repudiation (A) and accountability (C) are related security principles but are not part of the CIA triad; non-repudiation guarantees a party cannot deny an action, and accountability ties actions to identified entities, both often grouped under broader frameworks like the Parkerian hexad or AAA rather than the core CIA triad.

Exam trap

Cisco often tests the distinction between the CIA triad and other security principles like non-repudiation or accountability, leading candidates to mistakenly include them as part of the triad when they are separate concepts.

483
MCQmedium

An attacker intercepts communication between two parties and modifies the data before forwarding it. Which type of attack is this?

A.Man-in-the-middle
B.DNS poisoning
C.Replay attack
D.ARP spoofing
AnswerA

A man-in-the-middle attack places the adversary between two communicating parties, relaying traffic while altering its contents before forwarding, which matches the stem's interception plus modification. The attacker typically achieves this position through ARP spoofing, rogue Wi-Fi access points or DNS poisoning, breaking both confidentiality and integrity.

Why this answer

A man-in-the-middle (MITM) attack occurs when an attacker intercepts and alters communications between two parties without their knowledge. The attacker positions themselves between the sender and receiver, capturing, modifying, and then forwarding the data, which directly matches the scenario described.

Exam trap

Cisco often tests the distinction between the attack type (MITM) and the technique used to achieve it (ARP spoofing), causing candidates to confuse the method with the overarching attack category.

How to eliminate wrong answers

Option B (DNS poisoning) is wrong because it involves corrupting a DNS resolver's cache to redirect traffic to a malicious site, not intercepting and modifying an existing communication stream. Option C (Replay attack) is wrong because it captures valid data and retransmits it later, but does not involve modifying the data before forwarding. Option D (ARP spoofing) is wrong because it is a specific technique used to facilitate MITM attacks by linking the attacker's MAC address to a legitimate IP address, but it is not the attack itself—it is a method to achieve a MITM position.

484
MCQhard

A forensic analyst uses Volatility on a memory dump and runs the 'malfind' plugin. The output shows a process with a VAD region that has PAGE_EXECUTE_READWRITE protection and contains the pattern 'MZ'. What does this indicate?

A.The process has been infected with code injection, likely a PE executable mapped in memory.
B.The process is using a packed executable that was unpacked in memory.
C.The process has a heap spray attack, but not necessarily injected code.
D.The process is a legitimate browser with dynamic code.
AnswerA

A PAGE_EXECUTE_READWRITE VAD containing 'MZ' reveals a PE header mapped into memory, the signature of injected executable code. Legitimate modules are not both writable and executable, so this satisfies the stem's request to interpret the malfind output.

Why this answer

PAGE_EXECUTE_READWRITE protection combined with 'MZ' header suggests code injection, where a malicious executable has been written into the process memory.

485
MCQeasy

A security analyst needs to ensure data integrity. Which control best achieves this?

A.Logging
B.Encryption
C.Access control
D.Hashing
AnswerD

Hashing produces a fixed-length digest from data; any alteration changes the digest, so recomputing and comparing it detects modification. This directly satisfies the integrity requirement by verifying data has not been altered, unlike encryption, which primarily provides confidentiality.

Why this answer

Hashing is the correct control for ensuring data integrity because it produces a fixed-length digest (e.g., SHA-256) from the original data. Any change to the data, even a single bit, results in a completely different hash value, allowing the analyst to detect tampering or corruption. Unlike encryption, hashing is a one-way function that does not conceal the data but verifies its unchanged state.

Exam trap

Cisco often tests the distinction between confidentiality (encryption) and integrity (hashing), so the trap here is that candidates confuse encryption's ability to hide data with the ability to detect tampering, leading them to select encryption instead of hashing.

How to eliminate wrong answers

Option A is wrong because logging records events and provides an audit trail, but it does not verify that the data itself has not been altered. Option B is wrong because encryption protects confidentiality by transforming data into ciphertext, but it does not detect changes to the plaintext; a modified ciphertext may still decrypt to a different plaintext without alerting the analyst. Option C is wrong because access control restricts who can read or write data, but it does not provide a mechanism to verify that the data has remained unchanged after authorized access.

486
Multi-Selecthard

According to the principles of least privilege, which THREE of the following access controls should be implemented for a typical user account? (Choose three.)

Select 3 answers
A.Administrative rights to the local machine
B.Ability to change their own password
C.Ability to install software
D.Write access to their own home directory
E.Read access to shared company calendar
AnswersB, D, E

Allowing users to change their own password supports least privilege by removing reliance on administrators for routine credential management, limiting administrative exposure. It grants no access beyond the account itself, so it does not widen the user's privileges across systems or data.

Why this answer

Option B is correct because allowing users to change their own password supports least privilege by letting them maintain the confidentiality of their own credential without granting broader account-management rights. Option D is correct because write access to their own home directory gives users the minimum file access needed to do their work while keeping other users' data and system files protected. Option E is correct because read access to a shared company calendar is a limited, role-appropriate permission that provides necessary scheduling information without granting modification or administrative control.

Options A and C are not appropriate under least privilege: administrative rights to the local machine and the ability to install software both grant elevated privileges that typical users do not need and that increase the risk of malware execution or system compromise.

Exam trap

Cisco often tests the misconception that 'typical users need administrative rights for productivity,' but the trap here is that candidates confuse convenience with necessity, overlooking that tasks like password changes and home directory access are sufficient for daily work without compromising security.

487
MCQmedium

A SOC analyst is reviewing a Windows 10 endpoint after a suspected compromise. They need to determine which user account was responsible for a specific process that was launched shortly before the alert. Which Windows artifact directly records the user account associated with process creation events and should be queried using Windows Event Log?

A.Security Event ID 4625 with the Account Name field
B.System Event ID 7045 with the ServiceName field
C.Application Event ID 1000 with the Faulting application name field
D.Security Event ID 4688 with the associated user account field
AnswerD

Security Event ID 4688 is generated when a new process is created and, when process creation auditing is enabled, includes the 'SubjectUserName' and 'TargetUserName' fields that identify the account that initiated the process. This directly answers the analyst's need to attribute process execution to a specific user account on the endpoint.

Why this answer

When process creation auditing is enabled, Windows logs Security Event ID 4688 for each new process, and the event includes the subject user name that initiated it. Correlating the process name and timestamp in 4688 with the alert time lets the analyst attribute the suspicious process to a specific user account, which is exactly what is needed here.

Exam trap

The trap here is confusing process creation auditing with logon auditing, so candidates pick 4625 or 7045 when the question specifically asks for the user tied to a launched process.

488
MCQeasy

A healthcare organization stores patient records and must comply with the HIPAA Security Rule. The CISO wants to document the types of safeguards that protect data through encryption, access controls, and audit logging. Which category of safeguards under the HIPAA Security Rule covers these controls?

A.Organizational requirements
B.Technical safeguards
C.Physical safeguards
D.Administrative safeguards
AnswerB

Technical safeguards under the HIPAA Security Rule specifically include access control, audit controls, integrity controls, person or entity authentication, and transmission security such as encryption. Encryption at rest, role-based access, and audit logging are technology-based mechanisms that protect electronic protected health information. This category directly matches the controls the CISO wants documented for protecting patient records.

Why this answer

The HIPAA Security Rule groups safeguards into administrative, physical, and technical categories. Encryption, access controls, and audit logging are technology-based protections applied to electronic protected health information, which places them squarely in the technical safeguards category. Administrative safeguards involve policies and workforce management, while physical safeguards involve facility and device protections, so neither fits the described controls.

Exam trap

The trap here is assuming that any documented security control is an administrative safeguard, when technology-enforced controls such as encryption and audit logging are classified as technical safeguards.

489
MCQmedium

A SOC analyst receives an alert about a Windows workstation that may be infected with malware. The analyst wants to examine the system's boot configuration to determine if the malware modified boot settings to disable driver signature enforcement. Which Windows tool should the analyst use to view the current boot configuration data?

A.regedit
B.msconfig
C.sigverif
D.bcdedit
AnswerD

bcdedit is the correct tool to view and modify Windows Boot Configuration Data (BCD). It displays settings such as nointegritychecks and testsigning, which, if enabled, disable driver signature enforcement. An analyst can run 'bcdedit /enum' to inspect these values and determine if malware altered boot settings to load unsigned drivers.

Why this answer

The correct tool is bcdedit, which manages Windows Boot Configuration Data. Malware often modifies BCD settings such as nointegritychecks or testsigning to bypass driver signature enforcement and load malicious drivers. Inspecting BCD with bcdedit /enum reveals these modifications.

Other tools like msconfig, regedit, or sigverif do not provide direct access to BCD settings, making them unsuitable for this task.

Exam trap

The trap here is confusing general system configuration tools like msconfig with the specific utility that manages boot configuration data, bcdedit.

490
MCQmedium

An analyst discovers that an employee has been using company-issued laptops to run a personal cryptocurrency mining software. Which policy violation has occurred?

A.Incident Response Policy
B.Change Management Policy
C.Acceptable Use Policy
D.Data classification policy
AnswerC

Cryptocurrency mining on company hardware falls outside permitted business use, breaching the Acceptable Use Policy that defines authorised employee behaviour with organisational assets. The policy explicitly governs how company-issued laptops may be used, so unauthorised personal mining constitutes a direct violation of its usage constraints.

Why this answer

An Acceptable Use Policy (AUP) defines how company-owned assets and networks may be used, and typically prohibits personal or unauthorized activities such as cryptocurrency mining on corporate laptops. Running mining software on company hardware violates the AUP because it misuses corporate resources for personal gain and can degrade performance or introduce security risk. The other policies address incident handling, change control, and data handling — none of which directly govern employee use of company devices.

Exam trap

The trap here is conflating a policy violation with an incident response or change management issue — candidates may pick Incident Response because mining is 'an incident,' but the question asks which policy the employee violated, and that is the Acceptable Use Policy.

How to eliminate wrong answers

Option A is wrong because an Incident Response Policy defines how the organization detects, responds to, and recovers from security incidents — it does not dictate what employees may do with company laptops. Option B is wrong because a Change Management Policy governs how changes to IT systems are requested, approved, and implemented; it has no bearing on personal software use. Option D is wrong because a Data Classification Policy defines how data is labeled and handled based on sensitivity (e.g., Public, Internal, Confidential), not how devices may be used.

491
MCQhard

A security analyst is analyzing a memory dump from a compromised Windows system using Volatility. Which command would best reveal hidden or injected code within a process?

A.vol.py netscan
B.vol.py pslist
C.vol.py malfind
D.vol.py dlllist
AnswerC

The malfind plugin scans process memory for pages exhibiting characteristics of injected or hidden code, such as executable permissions combined with no file backing on disk. This directly targets the scenario's goal of revealing injected code within a process from the memory dump.

Why this answer

The vol.py malfind command in Volatility scans process memory for hidden or injected code by looking for memory regions with suspicious characteristics, such as executable permissions and no corresponding file on disk. It is specifically designed to detect code injection and rootkit-like behavior. This makes it the best choice for revealing hidden or injected code within a process.

Exam trap

200-201 often tests the confusion between process listing (pslist) and memory analysis (malfind) — candidates may pick pslist because it shows processes, but it does not reveal injected code hidden within a legitimate process.

How to eliminate wrong answers

Option A is wrong because netscan lists network connections and sockets, which helps identify command-and-control traffic but does not detect injected code. Option B is wrong because pslist enumerates active processes from the process list, which may miss hidden processes and does not analyze memory for injected code. Option D is wrong because dlllist lists loaded DLLs for a process, which can show malicious DLLs but does not detect injected shellcode or memory-resident code without a file.

492
MCQeasy

Which OSI layer is associated with protocols such as HTTP, FTP, and SMTP, and is commonly targeted by application-layer attacks?

A.Layer 2 - Data Link
B.Layer 7 - Application
C.Layer 4 - Transport
D.Layer 3 - Network
AnswerB

HTTP, FTP and SMTP are application-layer protocols operating at Layer 7, where they exchange user-facing data and commands. Application-layer attacks such as injection and cross-site scripting exploit these protocols directly, making Layer 7 the correct association.

Why this answer

HTTP, FTP, and SMTP are application-layer protocols that operate at Layer 7 of the OSI model. Application-layer attacks target this layer by exploiting vulnerabilities in the application logic, input validation, or protocol implementation, such as SQL injection, cross-site scripting (XSS), or buffer overflows in web servers.

Exam trap

Cisco often tests the misconception that HTTP and FTP are transport-layer protocols because they use TCP ports 80 and 21 respectively, but the trap is that these protocols operate at Layer 7, not Layer 4.

How to eliminate wrong answers

Option A is wrong because Layer 2 (Data Link) handles MAC addressing and frame switching, not application protocols like HTTP or FTP. Option C is wrong because Layer 4 (Transport) manages end-to-end communication with protocols like TCP and UDP, not application-specific protocols. Option D is wrong because Layer 3 (Network) is responsible for IP addressing and routing, not the application-layer services targeted by attacks.

493
MCQeasy

Which Windows Event ID corresponds to a successful user logon?

A.4648
B.4776
C.4625
D.4624
AnswerD

Event ID 4624 is written to the Windows Security log whenever an account successfully authenticates, capturing logon type, account name and source. It is the definitive indicator of a successful user logon, unlike 4625, which records failures.

Why this answer

Event ID 4624 is correct because Windows Security auditing logs 4624 for a successful account logon, including the logon type (interactive, network, service, etc.) and the account and workstation involved. It is the canonical event analysts filter on to confirm successful authentication.

Exam trap

The trap is confusing 4624 (successful logon) with 4625 (failed logon) or 4648 (explicit credential use), since all three involve authentication and differ by only a few digits.

How to eliminate wrong answers

Option A is wrong because 4648 indicates a logon was attempted using explicit credentials, such as RunAs or a mapped drive with alternate credentials, not a normal successful logon. Option B is wrong because 4776 is generated by the NTLM credential validation process on the authenticating domain controller, recording credential validation rather than a completed logon session. Option C is wrong because 4625 records a failed logon attempt, the opposite of what the question asks.

494
MCQmedium

A security analyst is reviewing a Windows 10 endpoint that is suspected of being compromised. The analyst opens Task Manager and notices a process named 'lsass.exe' running with a PID of 1234, but its parent process is 'cmd.exe' rather than 'wininit.exe'. The analyst also observes that the process path is 'C:\Users\Public\lsass.exe'. Which type of attack is most likely indicated by these findings?

A.Rootkit infection
B.Process hollowing
C.Process masquerading
D.DLL injection
AnswerC

Process masquerading occurs when malware names its executable after a legitimate system process, such as lsass.exe, but runs from an unusual location and with an unexpected parent. Here, the path 'C:\Users\Public\lsass.exe' and parent 'cmd.exe' are clear indicators that this is a fake lsass.exe, not the genuine one that runs from System32 and is spawned by wininit.exe.

Why this answer

The genuine lsass.exe runs from C:\Windows\System32 and is spawned by wininit.exe. A process named lsass.exe running from C:\Users\Public with cmd.exe as its parent is a strong indicator of process masquerading, where malware mimics a legitimate process name to evade detection. This technique is commonly used by attackers to blend in with normal system activity.

Exam trap

The trap here is assuming that any process with a legitimate name is safe, but the path and parent process are critical for verification.

495
MCQhard

An analyst examines a PCAP and observes that an internal host sends an ICMP echo request containing a payload of 1200 bytes, followed by an ICMP echo reply from an external host with a payload of 1500 bytes. The payload data does not match standard ping patterns and appears to contain encoded file fragments. Which technique is most consistent with this observation?

A.Smurf attack amplification
B.Path MTU discovery using oversized ICMP
C.ICMP redirect manipulation
D.ICMP tunneling for data exfiltration
AnswerD

ICMP tunneling embeds data inside echo request and reply payloads, which is exactly what the oversized, encoded, non-standard payloads indicate. The asymmetry in payload size and the presence of encoded fragments suggest a tool using ICMP as a transport to move data out of the network. This technique bypasses controls that allow ping but do not inspect ICMP payload content.

Why this answer

Oversized ICMP echo packets carrying encoded, non-standard payloads in both directions strongly indicate ICMP tunneling, a common method for covert data transfer and exfiltration. Because many networks permit ping for troubleshooting, attackers abuse it to move data past controls that do not inspect ICMP payloads. The other options describe different ICMP-based behaviors that do not involve encoded data in echo payloads.

Exam trap

The trap here is treating all ICMP traffic as benign troubleshooting traffic and not inspecting the payload size and content of echo request and reply packets.

496
MCQmedium

A SOC analyst is analyzing a PCAP from a suspected intrusion. The traffic shows a series of TCP connections where the client sends a SYN, receives a SYN-ACK, then immediately sends a RST instead of an ACK, and this pattern repeats across multiple ports on the same target. Which type of scan is most likely being performed?

A.UDP scan
B.TCP SYN stealth scan
C.TCP connect scan
D.TCP FIN scan
AnswerB

A TCP SYN stealth scan sends a SYN, receives a SYN-ACK if the port is open, but then sends a RST to tear down the connection before it is fully established. This half-open scanning technique avoids completing the handshake, making it stealthier and matching the described pattern of SYN, SYN-ACK, then RST.

Why this answer

The pattern of SYN, SYN-ACK, then RST indicates a half-open TCP scan, commonly known as a SYN stealth scan. The attacker sends a SYN, receives a SYN-ACK if the port is open, but resets the connection instead of completing the handshake. This avoids establishing a full connection and is often used to evade detection while enumerating open ports.

Exam trap

The trap here is confusing a SYN stealth scan with a TCP connect scan, as both start with a SYN, but only the stealth scan sends a RST after receiving SYN-ACK instead of completing the handshake.

497
MCQeasy

An IDS generates an alert for a signature that matches HTTP traffic containing 'cmd.exe' in the URI. The analyst checks the packet and sees the URI is actually 'cmd.exe?help'. What should the analyst do?

A.Block the source IP
B.Tune the signature to reduce false positives
C.Disable the signature
D.Escalate to incident response
AnswerB

The URI 'cmd.exe?help' is benign query-string content, not malicious execution, so the signature's substring match is over-broad. Tuning it — for example requiring the executable in a command context rather than any URI — suppresses this recurring false positive while preserving detection of genuine 'cmd.exe' abuse.

Why this answer

The IDS signature triggered on the presence of 'cmd.exe' in the URI, but the actual traffic was 'cmd.exe?help', which is a legitimate help request and not an exploitation attempt. Tuning the signature to account for the query string reduces false positives without losing detection capability for actual attacks. This aligns with best practices for IDS management, where signatures are adjusted to match real threat patterns rather than exact strings.

Exam trap

Cisco often tests the distinction between a false positive and a true positive, and the trap here is that candidates may assume any match for 'cmd.exe' is malicious, leading them to choose escalation or blocking instead of recognizing the need for signature tuning.

How to eliminate wrong answers

Option A is wrong because blocking the source IP would be an overreaction to a false positive; the traffic is benign and does not indicate malicious intent. Option C is wrong because disabling the signature entirely would remove detection for actual 'cmd.exe' exploitation attempts, leaving the network vulnerable. Option D is wrong because escalating to incident response is unnecessary for a confirmed false positive; incident response is reserved for verified security incidents, not benign traffic that triggered a signature.

498
MCQhard

A vendor security policy requires that all third-party remote access be limited to specific IP addresses and use multi-factor authentication. During an audit, it is discovered that a vendor's entire office subnet is allowed instead of individual IPs. The vendor argues that the broader range is necessary for redundancy. What is the best way to handle this from a policy perspective?

A.Amend the policy to allow entire subnets for vendors with multi-factor authentication
B.Accept the subnet as long as multi-factor authentication is used
C.Require the vendor to comply with the existing policy exactly as written
D.Work with the vendor to define a list of specific IPs that cover their redundancy needs while adhering to policy
AnswerD

Working with the vendor to enumerate specific IPs satisfies the policy's requirement for individual address restriction while preserving redundancy through multiple discrete entries rather than a whole subnet. This reconciles the vendor's operational need with the audit finding, since Microsoft Entra ID conditional access can then enforce named-location scoping and MFA per address.

Why this answer

The correct approach is to work with the vendor to define specific IPs that satisfy their redundancy needs while still complying with the policy's intent. This preserves the security control (limiting access to known, specific addresses) without simply weakening the policy or ignoring the violation. It balances operational flexibility with the vendor security requirement.

Exam trap

The trap here is choosing the 'pragmatic' answer that accepts the subnet with MFA, confusing authentication strength with network-level least privilege; the exam expects you to preserve the policy's intent while finding a compliant solution.

How to eliminate wrong answers

Option A is wrong because amending the policy to allow entire subnets for all vendors with MFA weakens the least-privilege access control and expands the attack surface beyond what the policy intended. Option B is wrong because accepting the subnet as-is ignores the audit finding and violates the existing policy, even if MFA is present. Option C is wrong because rigidly requiring exact compliance without addressing the vendor's legitimate redundancy concern may be impractical and doesn't seek a workable solution.

499
Multi-Selecthard

Which THREE types of network traffic anomalies are strong indicators of a data exfiltration attempt?

Select 3 answers
A.TCP connections with unusual port numbers (e.g., using SSH on port 80)
B.DNS queries with long subdomains encoding data
C.Frequent ARP requests from a single host
D.High number of SYN packets without corresponding ACKs
E.Large amounts of outbound traffic to a single destination during non-business hours
AnswersA, B, E

Unusual port usage signals protocol tunnelling, where attackers hide exfiltration inside permitted ports to bypass egress filtering. SSH over port 80 evades firewalls expecting HTTP, letting stolen data leave disguised as web traffic. This satisfies the stem's requirement for a strong exfiltration indicator, since legitimate services rarely bind to mismatched ports.

Why this answer

Option A is correct because tunneling protocols over unexpected ports—such as SSH on TCP 80 or other non-standard port mappings—are a classic exfiltration technique that evades port-based firewall rules and blends with allowed traffic. Option B is correct because DNS exfiltration encodes stolen data in long or high-entropy subdomain labels (e.g., base32/base64 chunks) sent to an attacker-controlled authoritative name server, which is a well-known covert channel. Option E is correct because a large outbound volume to one external destination during off-hours deviates from normal baseline behavior and matches the bulk-transfer pattern of data exfiltration.

Option C is not a strong exfiltration indicator; frequent ARP requests typically point to Layer 2 issues such as ARP scanning, misconfiguration, or ARP spoofing on the local segment. Option D is not a strong exfiltration indicator either; many SYNs without ACKs indicate SYN scanning or a SYN flood denial-of-service, not outbound data theft.

Exam trap

Cisco often tests the distinction between network anomalies that indicate data exfiltration versus those that indicate denial-of-service or reconnaissance; the trap here is confusing a SYN flood (Option D) with a covert channel, when exfiltration requires established, often stealthy, outbound connections.

500
MCQhard

An intrusion detection system alerts on HTTP traffic containing the string 'UNION SELECT' in the URI parameter. This is most indicative of what type of attack?

A.SQL injection
B.Command injection
C.Cross-site scripting
D.Directory traversal
AnswerA

The string UNION SELECT combines result sets from separate queries, a hallmark of SQL injection, where attackers append crafted SQL to input fields. Detecting it in a URI parameter indicates an attempt to manipulate the backend database query, satisfying the intrusion signature described.

Why this answer

The alert detects the string 'UNION SELECT' in a URI parameter, which is a classic SQL injection payload used to combine results from multiple database queries. This indicates an attacker is attempting to manipulate SQL queries by injecting malicious SQL code through user input, a hallmark of SQL injection attacks.

Exam trap

Cisco often tests the distinction between injection types by using specific payload strings; the trap here is confusing SQL injection with command injection because both involve 'injection', but the 'UNION SELECT' syntax is unique to SQL and not used in command injection or other attacks.

How to eliminate wrong answers

Option B is wrong because command injection involves executing system commands (e.g., via shell metacharacters like ';' or '|') rather than SQL statements like 'UNION SELECT'. Option C is wrong because cross-site scripting (XSS) typically injects client-side scripts (e.g., JavaScript) into web pages, not SQL syntax in URI parameters. Option D is wrong because directory traversal exploits path traversal sequences (e.g., '../') to access restricted files, not SQL query manipulation.

501
MCQmedium

An organization uses Windows 10 Enterprise workstations with standard user accounts (no local admin). Users run daily tasks including web browsing, document editing, and accessing a corporate intranet. Recently, the security team detected anomalous outbound traffic from one workstation to an IP address in a foreign country. The workstation's host-based firewall shows that a process named 'svch0st.exe' initiated the connection. Additionally, a scheduled task named 'UpdateTask' runs every hour with SYSTEM privileges, executing a script from a hidden folder. The user reports no unusual behavior except occasional system slowdowns. The analyst must determine the best immediate course of action. Which action should the analyst take first?

A.Run an antivirus scan and if nothing is found, ignore the alert as a false positive
B.Immediately disconnect the workstation from the network and perform a full system restore from a known good backup
C.Delete the scheduled task and the script from the hidden folder, then reboot the workstation
D.Disable the scheduled task and terminate the svch0st.exe process, then collect a forensic image of the workstation for further analysis
AnswerD

Terminating the malicious process and disabling the SYSTEM-level scheduled task halts active command-and-control and persistence, satisfying the need to contain the threat immediately. Capturing a forensic image afterwards preserves volatile and disk evidence before remediation destroys artefacts needed to scope the compromise.

Why this answer

The immediate priority is to contain the threat by disabling the scheduled task and terminating the malicious process (svch0st.exe) to stop further outbound communication, while preserving the system state for forensic analysis. Collecting a forensic image ensures that evidence (e.g., the script, scheduled task artifacts, and network logs) is not destroyed, allowing the security team to perform root-cause analysis and determine the full scope of the compromise. This approach balances containment with evidence preservation, which is critical in incident response.

Exam trap

Cisco often tests the distinction between containment (stopping the active threat) and eradication (removing files), where candidates mistakenly choose to delete artifacts immediately (Option C) instead of first containing the process and preserving evidence for analysis.

How to eliminate wrong answers

Option A is wrong because relying solely on an antivirus scan is insufficient; the process 'svch0st.exe' mimics legitimate 'svchost.exe' and may evade signature-based detection, and ignoring the alert could allow persistent access. Option B is wrong because immediately disconnecting and restoring from backup destroys volatile evidence (e.g., running processes, memory contents, and scheduled task details) needed for forensic analysis, and may not remove the threat if the backup is also compromised. Option C is wrong because deleting the scheduled task and script without first containing the active process (svch0st.exe) allows the malware to continue running and potentially re-establish persistence or exfiltrate data; also, rebooting may destroy evidence in memory.

502
Multi-Selecteasy

Which TWO are examples of risk treatment options? (Select two.)

Select 2 answers
A.Neglect
B.Mitigate
C.Ignore
D.Accept
E.Amplify
AnswersB, D

Implementing controls to reduce risk.

Why this answer

Mitigate (B) is a recognized risk treatment option because it involves applying controls or countermeasures to reduce the likelihood and/or impact of a risk to an acceptable level. Accept (D) is also a recognized risk treatment option, meaning the organization acknowledges the risk and decides to retain it without additional controls, typically when the cost of treatment outweighs the benefit or the risk is within tolerance. The other options are not standard risk treatment categories: Neglect (A) and Ignore (C) imply simply disregarding a risk without a formal, documented decision, which is not a valid treatment strategy, and Amplify (E) is not a recognized risk treatment option since treatment aims to reduce or transfer risk, not increase exposure.

503
MCQmedium

A company's web server is overwhelmed with traffic from many compromised devices, causing legitimate users to be unable to access the site. What type of attack is this?

A.ARP spoofing
B.DoS
C.DNS poisoning
D.DDoS
AnswerD

A distributed denial-of-service attack floods the web server with traffic from many compromised devices, exhausting its capacity so legitimate users cannot connect. The stem's defining constraint — numerous geographically dispersed sources overwhelming one target — distinguishes DDoS from a single-source DoS, which one host alone generates.

Why this answer

A DDoS (Distributed Denial of Service) attack uses many compromised devices — often a botnet — to flood a target with traffic, overwhelming its resources so legitimate users cannot connect. The key distinguishing factor in the question is 'many compromised devices,' which indicates distribution across multiple sources rather than a single attacking host. This matches the definition of DDoS and differentiates it from a single-source DoS attack.

Exam trap

200-201 often tests the distinction between DoS and DDoS by embedding the word 'many' or 'distributed' in the scenario — candidates who skim may pick DoS because it is the more familiar term, missing the distribution clue.

How to eliminate wrong answers

Option A is wrong because ARP spoofing is a layer-2 attack that poisons ARP caches to intercept or redirect traffic on a local network segment; it does not generate the volumetric flood described. Option B is wrong because DoS (Denial of Service) originates from a single source or a single attack vector, whereas the question explicitly states traffic comes from many compromised devices. Option C is wrong because DNS poisoning corrupts DNS resolver caches to redirect users to malicious sites; it does not overwhelm a web server with traffic.

504
MCQmedium

A user receives an email that appears to be from their bank, asking them to click a link and verify their account details. The email contains a sense of urgency. Which type of attack is this?

A.Pretexting
B.Vishing
C.Spear phishing
D.Phishing
AnswerD

The email spoofs a trusted bank, demands urgent verification and harvests credentials via a link, matching phishing's social-engineering mechanism. It satisfies the stem's constraints: forged sender identity, urgency pressure and a credential-capture link, distinguishing it from technical exploits that need no user interaction.

Why this answer

Phishing is a social engineering attack that uses deceptive emails to trick recipients into revealing sensitive information.

505
Matchingmedium

Match each Linux command to its function.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Search text using patterns

Capture and analyze network packets

Display network connections and statistics

Configure firewall rules

Change file permissions

Why these pairings

These commands are essential for Linux system administration and security analysis.

506
MCQmedium

An analyst uses Volatility's 'netscan' on a memory dump and finds an established connection to an external IP on port 4444. Which type of activity is this commonly associated with?

A.Email communication
B.DNS query
C.Reverse shell or backdoor
D.Normal web browsing
AnswerC

An established outbound connection to an external host on port 4444, a common Metasploit and netcat listener port, indicates a reverse shell or backdoor. The compromised host initiated the session, letting the attacker bypass inbound firewall rules.

Why this answer

Port 4444 is commonly used by Metasploit and other remote access tools for reverse shells. An established connection to an external IP on this port is indicative of a backdoor or command-and-control communication.

507
MCQeasy

A security analyst notices repeated failed login attempts from a single IP address to the company's VPN gateway. Which action should the analyst take first?

A.Escalate to the incident response team immediately.
B.Block the IP at the firewall immediately.
C.Investigate the source IP for malicious activity.
D.Ignore the activity as it may be a user error.
AnswerC

Investigating the source IP establishes whether the failed logins are brute-force activity, a misconfigured client or a compromised host before any blocking action. This satisfies the stem's requirement to act first, since blocking or alerting without triage could disrupt legitimate users or miss the actual threat.

Why this answer

The first step in security monitoring is to investigate the source IP to determine if the failed login attempts are part of a brute-force attack, a misconfigured client, or a legitimate user error. Without context, blocking the IP or escalating prematurely could disrupt legitimate access or waste resources. The analyst should gather evidence (e.g., logs, timestamps, user accounts targeted) before taking further action.

Exam trap

Cisco often tests the principle that investigation must precede action, tempting candidates to choose immediate blocking (Option B) because it seems proactive, but the correct first step is always to gather context to avoid disrupting legitimate traffic.

How to eliminate wrong answers

Option A is wrong because escalating to the incident response team immediately without investigation is premature; the analyst must first confirm malicious intent to avoid unnecessary escalation. Option B is wrong because blocking the IP at the firewall immediately could deny service to a legitimate user if the IP is shared (e.g., NAT) or if the attempts are due to a forgotten password, and it bypasses the required investigative step. Option D is wrong because ignoring the activity violates security monitoring best practices; repeated failed login attempts are a common indicator of brute-force attacks and must be investigated, not dismissed as user error.

508
MCQmedium

A PCAP contains an HTTP POST request with a parameter containing "UNION SELECT username, password FROM users". This is evidence of:

A.SQL injection
B.Cross-site scripting
C.Path traversal
D.Command injection
AnswerA

The payload contains a UNION SELECT statement appended to a query, the classic signature of SQL injection, where an attacker concatenates a crafted query to extract data such as usernames and passwords. The HTTP POST parameter carrying this syntax confirms database query manipulation rather than cross-site scripting or command injection.

Why this answer

SQL injection attacks often use UNION SELECT statements to extract data from databases via web application vulnerabilities.

509
MCQmedium

Refer to the exhibit. An analyst examines the port security status on a switch interface. What action should the analyst take to restore connectivity to the device connected to this port?

A.Remove the port from the VLAN
B.Clear the MAC address table on the switch
C.Shut down and re-enable the interface
D.Increase the maximum number of MAC addresses allowed
AnswerC

Shutting down and re-enabling the interface clears the err-disabled state caused by a port security violation, allowing the connected device to regain link. This directly restores connectivity, satisfying the stem's requirement, though the analyst should first confirm the violating MAC address is legitimate before re-enabling.

Why this answer

When a port security violation occurs (e.g., a MAC address limit is exceeded or a sticky MAC changes), the switch can be configured to err-disable the interface. The standard remediation is to administratively shut down the interface (shutdown) and then re-enable it (no shutdown), which clears the error condition and restores connectivity. This is the only action that directly addresses the err-disable state caused by the security violation.

Exam trap

Cisco often tests the misconception that clearing the MAC address table or adjusting the MAC limit will restore connectivity, but the trap here is that the interface is in an err-disabled state, which requires a manual or automatic interface reset, not a table or configuration change.

How to eliminate wrong answers

Option A is wrong because removing the port from the VLAN does not clear the err-disable state or the security violation; it would only isolate the port from the network without resolving the underlying issue. Option B is wrong because clearing the MAC address table on the switch removes all dynamically learned MAC entries across all interfaces, but it does not clear the specific port security violation or the err-disable state on the affected interface. Option D is wrong because increasing the maximum number of MAC addresses allowed does not fix the current violation; it only prevents future violations if the current number of MACs is below the new limit, but the port remains err-disabled until it is manually or automatically recovered.

510
MCQmedium

A network analyst is examining a PCAP and notices a series of TCP packets with the PSH flag set and small payload sizes, sent from an internal host to an external IP. The external IP responds with similar small packets. The communication is continuous and occurs at regular intervals. Which type of activity is most likely occurring?

A.Network time synchronization
B.Interactive command-and-control session
C.Denial-of-service attack
D.Large file transfer
AnswerB

Small, regular packets with the PSH flag set often indicate interactive traffic where data is sent immediately. This pattern is typical of command-and-control (C2) communications, where an attacker sends commands and receives output in small chunks, maintaining a persistent session with periodic check-ins.

Why this answer

The combination of small payloads, PSH flag, and regular intervals is indicative of an interactive command-and-control channel. Attackers often use such channels to maintain stealth, sending commands and receiving responses in small packets to avoid detection by volume-based monitoring. This pattern is distinct from bulk transfers or DoS attacks.

Exam trap

The trap here is assuming any regular communication is benign, but the small payloads with PSH and regular intervals are a hallmark of C2 beaconing, not routine traffic like NTP.

511
MCQeasy

A SOC analyst receives an alert for 'Malware Detected' from an endpoint sensor. The analyst checks the endpoint and sees a file named 'invoice.exe' in the Downloads folder. What should the analyst do first?

A.Escalate to a senior analyst.
B.Run a full antivirus scan.
C.Isolate the host from the network.
D.Delete the file immediately.
AnswerC

Isolating the host first contains the threat, preventing lateral movement, command-and-control traffic, and further payload execution while evidence remains intact. Analysis, scoping, and eradication follow only once the endpoint can no longer communicate with other systems or the internet.

Why this answer

The correct first step is to isolate the host from the network (C) because the alert indicates active malware ('invoice.exe' in Downloads). Containment is the immediate priority in incident response to prevent lateral movement and data exfiltration. Isolating the host stops any ongoing C2 communication or propagation over the network, aligning with the NIST SP 800-61 containment strategy.

Exam trap

Cisco often tests the incident response priority of containment over eradication or escalation, and the trap here is that candidates may choose to delete the file (D) or run a scan (B) first, mistaking remediation for the initial response step.

How to eliminate wrong answers

Option A is wrong because escalation to a senior analyst should occur after initial containment, not before; the SOC analyst has the authority and responsibility to isolate the host first. Option B is wrong because running a full antivirus scan is a secondary step that could alert the malware or consume time while the threat remains active on the network. Option D is wrong because deleting the file immediately destroys forensic evidence and does not stop potential in-memory or persistence mechanisms that may already be active.

512
MCQeasy

A junior analyst is asked to identify which type of log would best show whether a Windows workstation attempted to authenticate to a file share on another server. Which log source should the analyst consult?

A.DHCP server logs showing IP address leases.
B.Windows Security event log on the workstation, looking for logon events.
C.Firewall logs showing allowed outbound TCP port 445 traffic.
D.Syslog from the core switch showing interface status changes.
AnswerB

Windows Security event logs record logon and authentication events, including network logons to remote shares. On the workstation, events such as 4624 with logon type 3 indicate a network logon to a server share. This log source directly shows the authentication attempt and its outcome, making it the most relevant place to check.

Why this answer

Windows Security event logs on the workstation capture logon events, including network logons to remote shares. Events like 4624 with logon type 3 show that an account authenticated over the network. This is the most direct evidence of an authentication attempt to a file share.

Exam trap

The trap here is assuming that firewall logs showing allowed SMB traffic prove an authentication attempt, when they only show that a connection was permitted.

513
MCQmedium

An analyst uses Wireshark to examine network traffic and wants to see only packets that contain the string 'password'. Which type of filter should be applied?

A.Display filter
B.Protocol filter
C.Capture filter
D.BPF filter
AnswerA

Display filters in Wireshark operate on captured packets already in memory, letting analysts match payload strings such as 'password' using expressions like frame contains. Capture filters apply earlier via BPF syntax and cannot search arbitrary payload text, so they cannot satisfy this requirement.

Why this answer

A Wireshark display filter is applied after capture to narrow what is shown from already-captured packets, and it supports string matching operators like contains. The filter frame contains "password" (or tcp contains "password") is a display filter that shows only packets whose payload includes that string. Capture filters use BPF syntax and cannot perform arbitrary string matching on payload content.

Exam trap

200-201 often tests whether candidates know that string matching (contains "password") is only possible with display filters, not capture/BPF filters — picking 'capture filter' because it sounds like the pre-analysis step is the classic error.

How to eliminate wrong answers

Option B is wrong because 'protocol filter' is not a Wireshark filter category — protocols are matched within display filters (e.g., http, dns) or capture filters (e.g., tcp port 80), but there is no standalone 'protocol filter' type. Option C is wrong because a capture filter (BPF syntax) is applied before capture and cannot match arbitrary payload strings like 'password' — BPF only supports byte-offset comparisons, not string search. Option D is wrong because BPF (Berkeley Packet Filter) is the syntax used for capture filters, and it likewise cannot perform substring matching on payload content.

514
MCQeasy

An analyst is reviewing a suspicious email reported by a user. The email contains an attachment 'invoice.pdf' and urges the user to open it. Which indicator is most likely to confirm it is a phishing attempt?

A.The email has a company logo.
B.The email was sent from a domain that looks like 'arnazon.com'.
C.The attachment is a PDF file.
D.The email was sent during business hours.
AnswerB

The sender domain 'arnazon.com' substitutes an 'm' for the 'rn' pair, a homoglyph typosquat impersonating amazon.com. Combined with the urgent invoice lure, this lookalike domain is a concrete, verifiable indicator confirming phishing, unlike generic urgency or attachment presence which are merely suspicious.

Why this answer

The most definitive indicator of a phishing attempt is a spoofed sender domain that mimics a legitimate company (e.g., 'arnazon.com' instead of 'amazon.com'). This is a classic typosquatting technique used to deceive users into trusting the email's origin. While other elements like logos or PDF attachments can be part of a phishing campaign, they are not inherently malicious and are commonly used in legitimate business communications.

Exam trap

Cisco often tests the distinction between a suspicious element (like a PDF attachment) and a definitive indicator of phishing (like a spoofed domain), leading candidates to incorrectly choose the attachment type as the answer.

How to eliminate wrong answers

Option A is wrong because a company logo can be easily copied and embedded in any email; its presence does not confirm phishing and is often used in both legitimate and malicious emails. Option C is wrong because PDF files are a standard, legitimate file format used for invoices; the attachment type alone is not an indicator of phishing. Option D is wrong because phishing emails can be sent at any time, including business hours, to blend in with normal traffic; timing is not a reliable indicator of malicious intent.

515
MCQmedium

An analyst reviews PCAP traffic and sees a series of HTTP POST requests from an internal host to an external IP at exactly 60-second intervals. The payload size is consistent. Which phase of the Cyber Kill Chain does this activity most likely represent?

A.Delivery
B.Command and Control
C.Actions on Objectives
D.Installation
AnswerB

Regular 60-second beaconing with consistent payload size to an external IP indicates an implanted host checking in with its controller. This periodic, uniform outbound pattern is characteristic of the Command and Control phase, where compromised systems receive instructions and exfiltrate data.

Why this answer

The consistent 60-second intervals and uniform payload size of HTTP POST requests from an internal host to an external IP are classic indicators of beaconing activity. In the Cyber Kill Chain, this behavior aligns with the Command and Control (C2) phase, where an established foothold communicates with an external C2 server to receive instructions or exfiltrate data. The use of HTTP POST mimics normal web traffic to evade detection, a common technique in C2 channels.

Exam trap

Cisco often tests the distinction between beaconing (C2) and data exfiltration (Actions on Objectives), where candidates mistakenly associate any external HTTP POST with data theft rather than recognizing the periodic pattern as command-and-control signaling.

How to eliminate wrong answers

Option A is wrong because the Delivery phase involves the initial transmission of the exploit or payload to the target (e.g., via phishing email or malicious download), not periodic beaconing after compromise. Option C is wrong because Actions on Objectives refers to the final goal, such as data exfiltration or system destruction, which would show larger or irregular data transfers, not consistent small beacons. Option D is wrong because Installation is the phase where malware is placed on the system (e.g., writing to disk or registry), which occurs before C2 and does not involve periodic network traffic.

516
MCQmedium

A security analyst is examining a suspicious executable found on a compromised host. Static analysis reveals that the file contains a packer and obfuscated strings. When run in a sandbox, it attempts to connect to an external IP address and modifies registry keys for persistence. Which stage of the cyber kill chain does the registry modification represent?

A.Installation
B.Command and Control
C.Exploitation
D.Delivery
AnswerA

Installation is the stage where the attacker establishes persistence on the victim system. Modifying registry keys to ensure the malware runs on startup is a classic installation technique. The sandbox behavior of modifying registry keys aligns with maintaining access after the initial compromise.

Why this answer

Registry modification for persistence is part of the Installation stage of the cyber kill chain, where the attacker ensures the malware survives reboots. The other stages such as Delivery, Exploitation, and Command and Control occur at different points. The sandbox observation of registry changes indicates the malware is establishing a foothold.

Exam trap

The trap here is associating any external connection with Command and Control, but the registry modification specifically serves persistence, which is Installation.

517
MCQmedium

A SIEM correlation rule triggers when more than 10 failed login attempts from a single source IP occur within 1 minute. This rule is designed to detect:

A.Privilege escalation
B.Malware infection
C.Brute force attack
D.DDoS attack
AnswerC

Numerous failed authentications from one IP within a minute reflect automated credential guessing, the signature of a brute-force attack. The rule's source-IP and time-window constraints detect this volume pattern rather than isolated failures or distributed attempts.

Why this answer

A brute force attack involves repeated login attempts using many password guesses. The SIEM rule specifically detects this pattern by counting failed logins from a single source IP within a short time window (1 minute). This matches the signature of an automated password guessing tool, not other attack types.

Exam trap

Cisco often tests the distinction between a brute force attack (repeated failed logins) and a DDoS attack (high traffic volume), so candidates may confuse the two because both involve high event counts from a single source.

How to eliminate wrong answers

Option A is wrong because privilege escalation involves gaining higher-level access after initial compromise, not repeated failed logins. Option B is wrong because malware infection typically involves payload delivery or execution, not a high volume of failed authentication attempts. Option D is wrong because a DDoS attack aims to overwhelm resources with traffic volume, not to guess credentials via repeated login failures.

518
MCQhard

A SOC analyst is reviewing a NetFlow record and sees that a single internal IP has communicated with multiple external IPs on port 445 (SMB) within a short time frame. Which type of activity is most likely indicated?

A.Normal file sharing activity
B.Data exfiltration over SMB
C.SMB scanning or worm propagation
D.DNS tunneling
AnswerC

One internal host contacting many external addresses on port 445 indicates SMB scanning or worm propagation seeking vulnerable shares. The fan-out pattern and SMB port distinguish it from normal file sharing, satisfying the stem's NetFlow scenario.

Why this answer

Port 445 is used by SMB for file sharing, but a single internal IP communicating with many external IPs in a short time frame is characteristic of scanning or worm propagation. Worms like EternalBlue exploit SMB vulnerabilities to spread rapidly, generating many outbound connections to random or sequential external IPs on port 445. This pattern is not typical of normal file sharing, which involves sustained connections to known servers.

Exam trap

Cisco often tests the distinction between normal traffic patterns and malicious scanning by using a single internal IP connecting to many external IPs on a specific port, where candidates may mistakenly associate SMB only with legitimate file sharing (Option A) rather than recognizing the scanning behavior.

How to eliminate wrong answers

Option A is wrong because normal file sharing activity involves consistent connections to a limited set of known file servers, not a burst of connections to many different external IPs. Option B is wrong because data exfiltration over SMB would typically involve large data transfers to a single or few external IPs, not a broad scan pattern; exfiltration focuses on stealthy extraction, not rapid propagation. Option D is wrong because DNS tunneling uses DNS queries (port 53) to encapsulate data, not SMB on port 445; the protocol and port mismatch makes this option irrelevant.

519
Multi-Selectmedium

An analyst reviews an IDS alert indicating a TCP SYN scan against a web server. The analyst wants to confirm the scan by examining packet-level evidence in the PCAP. Which TWO characteristics would confirm a SYN scan rather than legitimate client behavior? (Choose two.)

Select 2 answers
A.The source sends a single SYN and then completes the handshake before sending an HTTP GET
B.The target's firewall logs show the source IP was previously blocked for port scanning
C.The source sends SYN packets with varying TCP window sizes and random source ports across the scan
D.The destination responds with RST packets for closed ports and SYN-ACK for open ports
E.A single source sends SYN packets to many sequential destination ports with no completed three-way handshakes
AnswersC, E

Scanning tools randomize source ports and vary window size and other header fields to evade simple signature matching and to avoid exhausting local ephemeral ports. Combined with the absence of completed handshakes, this header variation supports an automated scanner rather than a browser or API client, which would use one consistent source port per connection and a stable window size negotiated once per session.

Why this answer

A SYN scan is proven by the combination of incomplete handshakes across many destination ports and deliberate header variation. The scanner never finishes the three-way handshake, and it randomizes source ports and window sizes to evade detection. Target responses such as RST or SYN-ACK merely reflect normal TCP behavior, a completed handshake indicates legitimate client activity, and historical firewall blocks are reputation context rather than packet-level confirmation.

Exam trap

The trap here is selecting the target's RST and SYN-ACK responses as evidence, when those are ordinary TCP behavior that any connection attempt would elicit.

520
MCQhard

An organization uses Cisco AMP for Endpoints. A file with a low prevalence score is executed on multiple endpoints, and AMP identifies it as malicious after behavioral analysis. The analyst needs to ensure that all endpoints are protected from this file. Which action should be taken?

A.Create a custom IOC for the file hash and apply it to an outbreak policy.
B.Isolate all endpoints that executed the file.
C.Disable cloud connectivity for AMP to prevent recurrence.
D.Run a scan on each endpoint using the local AMP engine.
AnswerA

A custom IOC containing the file's SHA-256 hash lets the outbreak policy block or quarantine that exact file across all endpoints, regardless of cloud prevalence verdicts. This enforces protection immediately without waiting for a signature update.

Why this answer

Creating a custom IOC for the file hash and applying it to an outbreak policy is correct because Cisco AMP for Endpoints uses outbreak policies to rapidly deploy protections across all endpoints. Once behavioral analysis identifies the file as malicious, the IOC (based on the file's SHA-256 hash) can be pushed via an outbreak policy to block execution, quarantine, or remediate the file on every endpoint, regardless of prior prevalence. This ensures immediate, global protection without waiting for cloud signature updates.

Exam trap

Cisco often tests the distinction between reactive containment (isolation) and proactive prevention (outbreak policies), leading candidates to choose isolation because it seems immediate, but the question asks for ensuring all endpoints are protected, which requires a policy-based push, not just isolating affected systems.

How to eliminate wrong answers

Option B is wrong because isolating all endpoints that executed the file is a reactive containment step that does not prevent the file from executing on other endpoints that have not yet encountered it; it also disrupts user productivity unnecessarily. Option C is wrong because disabling cloud connectivity for AMP would prevent the endpoints from receiving real-time threat intelligence and outbreak policies, leaving them vulnerable to new threats and defeating the purpose of AMP's cloud-based analysis. Option D is wrong because running a local scan using the AMP engine only checks for known signatures already present on the endpoint; it cannot detect or remediate a file that was just identified as malicious via behavioral analysis unless the local signatures are updated, which is slower and less reliable than an outbreak policy.

521
MCQmedium

A network security analyst is reviewing NetFlow records from a perimeter router and observes that an internal server at 172.16.5.20 has transferred approximately 4.5 GB to an external IP address in country X over the past three hours, all during non-business hours. The destination IP has no prior communication history with the organization and the traffic uses port 443. Which analysis approach would best confirm whether this represents data exfiltration?

A.Check the router's interface error counters for packet loss
B.Review the server's antivirus scan history for the past week
C.Verify the server's operating system patch level
D.Capture full packet data for the transfer and perform content inspection to identify the data being sent
AnswerD

Full packet capture with content inspection can reveal the actual payload, file types, and protocols involved in the transfer, confirming whether sensitive data is leaving the network. NetFlow alone shows volume and endpoints but not content. Capturing and inspecting the traffic, or using proxy and TLS inspection logs where decryption is possible, provides the definitive evidence needed to confirm exfiltration.

Why this answer

To confirm exfiltration, the analyst must determine what data is leaving, not just how much. Full packet capture with content inspection, or decrypted proxy and TLS logs where available, reveals file types, protocols, and payloads. NetFlow establishes the anomaly—large volume, unusual destination, off-hours timing—but content-level visibility converts suspicion into confirmation and supports incident response decisions.

Exam trap

The trap here is treating volumetric NetFlow evidence as sufficient proof of exfiltration, when confirming the exfiltration of data requires inspecting the content or metadata of the transfer itself.

522
MCQmedium

An analyst is reviewing a PCAP and sees multiple HTTP requests with the parameter 'id=1 UNION SELECT username,password FROM users'. What type of attack is being attempted?

A.SQL injection
B.Directory traversal
C.Cross-site scripting (XSS)
D.Command injection
AnswerA

The payload injects a UNION SELECT clause into the id parameter, appending a query that returns usernames and passwords. This is classic SQL injection: attacker-supplied SQL is concatenated into the backend query, letting the database return data it should not expose.

Why this answer

The SQL keywords UNION and SELECT in a parameter indicate a SQL injection attempt to extract data from the database.

523
MCQeasy

A security administrator is reviewing the company's incident response plan and wants to ensure that the team understands the difference between a vulnerability, a threat, and a risk. During a tabletop exercise, the administrator presents a scenario: a web server has an unpatched Apache Struts vulnerability, and a known exploit exists publicly. Which term best describes the unpatched Apache Struts vulnerability in this context?

A.Threat
B.Exploit
C.Vulnerability
D.Risk
AnswerC

A vulnerability is a weakness or flaw in a system that can be exploited by a threat. The unpatched Apache Struts vulnerability is a specific software weakness that could allow an attacker to compromise the server. This term accurately describes the condition of the unpatched software.

Why this answer

The unpatched Apache Struts issue is a software flaw that can be leveraged by an attacker, making it a vulnerability. Understanding this distinction is crucial for risk assessment: vulnerabilities are weaknesses, threats are actors or events that can exploit them, and risk is the potential impact. Correctly identifying the vulnerability helps prioritize remediation such as patching.

Exam trap

The trap here is equating a vulnerability with an exploit because a public exploit exists; however, the exploit is the method used to take advantage of the weakness, while the vulnerability is the weakness itself.

524
Drag & Dropmedium

Drag and drop the steps for the DHCP DORA process (dynamic host configuration) into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The DHCP DORA process stands for Discover, Offer, Request, Acknowledge. It begins with the client broadcasting a Discover message to find DHCP servers. Servers respond with an Offer of an available IP address.

The client then sends a Request to accept one of the offers. Finally, the server sends an Acknowledge to confirm the lease, completing the process. This sequence ensures proper assignment of IP addresses and avoids conflicts.

525
Multi-Selectmedium

Which THREE of the following are common types of security policies that organizations typically implement?

Select 3 answers
A.ISO 27001 Standard
B.Data Classification Policy
C.Password Policy
D.Patch Management Procedure
E.Acceptable Use Policy (AUP)
AnswersB, C, E

A Data Classification Policy satisfies the need to categorise information by sensitivity, defining labels such as public, internal, confidential and restricted. It directly governs handling, storage and sharing requirements, making it a recognised security policy type. This structured labelling underpins access control and data protection decisions across the organization.

Why this answer

A Data Classification Policy (B) is a common security policy because it defines how data is categorized (e.g., public, internal, confidential, restricted) and the handling, labeling, and protection requirements for each tier. A Password Policy (C) is a standard security policy that specifies authentication requirements such as minimum length, complexity, expiration, reuse limits, and lockout thresholds. An Acceptable Use Policy (E) is a foundational security policy that defines how employees may use organizational IT assets, networks, and data, including prohibited activities and consequences for violations.

The ISO 27001 Standard (A) is not a policy but an international standard/framework for establishing an information security management system (ISMS), and a Patch Management Procedure (D) is a procedural/operational document describing steps and schedules for vulnerability remediation, not a policy type.

Exam trap

200-201 often tests the distinction between policies, standards, and procedures — candidates pick ISO 27001 (a standard) or Patch Management Procedure (a procedure) because they sound like governance documents.

Page 6

Page 7 of 13

Page 8