Courseiva

Cisco CyberOps Associate 200-201 (200-201) — Questions 526–600

968 questions total · 13pages · All types, answers revealed

Page 7

Page 8 of 13

Page 9
526
Multi-Selecthard

An analyst is investigating a malware infection on a workstation. The malware appears to be a trojan that downloads additional payloads and allows remote control. The analyst needs to classify the malware based on its behavior. Which THREE characteristics match this description? (Choose three.)

Select 3 answers
A.It provides unauthorized remote access to the system.
B.It downloads and installs additional malicious software.
C.It requires user interaction to execute.
D.It self-replicates without user interaction.
E.It encrypts files and demands ransom.
AnswersA, B, C

Remote-access trojans install a backdoor that grants the attacker interactive control of the workstation, satisfying the stem's "allows remote control" constraint. This unauthorised access is the defining behavioural characteristic distinguishing a RAT from payloads that merely download or self-replicate, so it matches the classification requirement directly.

Why this answer

The scenario describes a trojan that downloads additional payloads and allows remote control, so the correct characteristics are A, B, and C. Option A is correct because allowing remote control is precisely unauthorized remote access, the defining behavior of a Remote Access Trojan (RAT). Option B is correct because downloading additional payloads is a dropper/downloader behavior, where the initial malware retrieves and installs further malicious software.

Option C is correct because a trojan typically relies on social engineering or user execution (e.g., opening an attachment or running a file) to activate, unlike worms or exploits that can execute without interaction. Option D is incorrect because self-replication without user interaction describes a worm, not a trojan. Option E is incorrect because encrypting files and demanding ransom describes ransomware, which is not stated in this scenario.

Exam trap

Cisco often tests the distinction between trojans and worms by emphasizing that trojans require user interaction to execute, whereas worms self-replicate and spread automatically without user action.

527
MCQmedium

A security analyst is reviewing logs and notices that an attacker has intercepted and modified communications between two devices without their knowledge. Which type of attack is this?

A.ARP spoofing
B.DNS poisoning
C.Denial of Service (DoS)
D.Man-in-the-middle (MitM)
AnswerD

A man-in-the-middle attack satisfies the interception-and-modification constraint: the adversary covertly relays traffic between two endpoints, terminating each side's session so both devices believe they communicate directly. Sitting inline on the path, the attacker can read and alter data in transit undetected, matching the stem's silent modification of communications.

Why this answer

This scenario describes an attacker intercepting and modifying communications between two devices without their knowledge, which is the defining characteristic of a Man-in-the-Middle (MitM) attack. In a MitM attack, the attacker positions themselves between the two communicating parties, allowing them to eavesdrop, capture, and alter data in transit while both endpoints believe they are communicating directly with each other.

Exam trap

The trap here is that Cisco often tests the distinction between the attack technique (e.g., ARP spoofing) and the broader attack category (MitM), leading candidates to confuse a specific method with the overall attack type described in the question.

How to eliminate wrong answers

Option A is wrong because ARP spoofing is a specific technique used to associate an attacker's MAC address with the IP address of a legitimate device on a local network, enabling traffic interception; however, it is a method to facilitate an attack, not the attack itself described in the question. Option B is wrong because DNS poisoning corrupts the DNS resolver cache to redirect users to malicious sites by altering DNS records, but it does not inherently involve intercepting and modifying communications between two specific devices in real time. Option C is wrong because a Denial of Service (DoS) attack aims to overwhelm a target with traffic to disrupt service availability, not to intercept or modify communications between two devices.

528
MCQmedium

A security manager is drafting an incident response policy and wants to ensure that the organization can legally monitor employee communications during an investigation. The manager asks the legal team what element must be included in the employee handbook and policy documents to support this capability. Which element is most critical?

A.A provision that all incident response activities are exempt from regulatory oversight
B.A requirement that employees report all security incidents within one hour of discovery
C.A statement that employees have no expectation of privacy when using corporate systems
D.A clause requiring employees to surrender personal devices for forensic imaging at any time
AnswerC

This is correct because monitoring is legally defensible when employees are clearly informed that corporate systems are subject to monitoring and that they should not expect privacy. This notice, often included in an Acceptable Use Policy or employee handbook, establishes consent and reduces legal risk. Without it, monitoring during an investigation could violate privacy laws or employment agreements.

Why this answer

The legal basis for monitoring employee communications is established by clearly informing employees that corporate systems are monitored and that privacy should not be expected. This notice, typically embedded in an Acceptable Use Policy or handbook, demonstrates consent and supports investigations. Reporting deadlines and device surrender clauses address different concerns and do not provide the same legal foundation for monitoring.

Exam trap

The trap here is confusing incident reporting requirements or device seizure clauses with the notice-and-consent language that actually legitimizes monitoring of corporate communications.

529
MCQhard

A company processes credit card payments and must comply with a framework that mandates specific security controls for protecting cardholder data. Which compliance framework applies?

A.ISO 27001
B.PCI DSS
C.GDPR
D.HIPAA
AnswerB

PCI DSS applies because the stem specifies credit card payments and cardholder data protection. It is the payment card industry standard that mandates controls such as encryption, access restriction and network monitoring for any entity storing, processing or transmitting cardholder data, directly satisfying the stated compliance requirement.

Why this answer

PCI DSS (Payment Card Industry Data Security Standard) is the framework specifically mandated for organizations that store, process, or transmit cardholder data. It defines 12 requirement categories covering network security, access control, encryption, monitoring, and policy. Any company processing credit card payments must comply with PCI DSS.

Exam trap

200-201 often tests framework recognition — candidates confuse general security standards (ISO 27001) or privacy regulations (GDPR) with the cardholder-data-specific PCI DSS mandate.

How to eliminate wrong answers

Option A is wrong because ISO 27001 is a general information security management system standard — it is not specific to cardholder data and does not mandate the prescriptive controls PCI DSS requires. Option C is wrong because GDPR governs personal data privacy for EU residents; it addresses data protection rights and consent, not cardholder data security controls. Option D is wrong because HIPAA applies to protected health information in the US healthcare sector, not payment card data.

530
MCQmedium

An security auditor finds that the company's backup policy does not include offsite storage. The security policy requires that backups be stored in a geographically separate location. What should the company do?

A.Store backups in a fireproof safe on-site
B.Implement RAID on the backup server
C.Increase backup retention period
D.Use encrypted cloud backup in a different region
AnswerD

Encrypted cloud backup in a separate region satisfies the geographic separation requirement without building a second physical site. Encryption preserves confidentiality while the offsite copy survives a local disaster, directly meeting the policy's mandate for backups stored in a geographically distinct location.

Why this answer

The security policy requires backups to be stored in a geographically separate location. Using encrypted cloud backup in a different region satisfies both the offsite requirement and adds encryption for security. This approach ensures data is stored in a separate geographic location, meeting the policy, while also protecting data in transit and at rest.

Exam trap

200-201 often tests whether candidates confuse redundancy (RAID) or retention with offsite storage, so options like RAID or fireproof safes are common distractors that do not meet the geographic separation requirement.

How to eliminate wrong answers

Option A is wrong because storing backups in a fireproof safe on-site does not meet the geographically separate location requirement. Option B is wrong because RAID provides redundancy against disk failure but does not address offsite storage. Option C is wrong because increasing retention period only extends how long backups are kept, not where they are stored.

531
Multi-Selectmedium

A security analyst is investigating a Linux server that is suspected of hosting a reverse-shell backdoor. The analyst wants to identify which running process is maintaining the outbound connection and which user context it is running under. Which TWO commands would best provide this information? (Choose two.)

Select 2 answers
A.cat /etc/passwd
B.top -b -n 1
C.journalctl -u sshd --since '1 hour ago'
D.lsof -i -P -n
E.ss -tunap
AnswersD, E

lsof with -i lists open Internet sockets, -P suppresses port-name resolution, and -n suppresses hostname resolution. The output shows the owning process name, PID, user, and the remote endpoint, which is exactly what is needed to tie a suspicious outbound connection to a user and process. It complements ss by showing file descriptors and the process that opened each socket.

Why this answer

To attribute a suspicious outbound connection to a specific process and user, the analyst needs socket-to-process mapping. The ss command with -tunap and lsof with -i -P -n both provide this mapping by listing open sockets alongside the owning process and user. Static files such as /etc/passwd, resource monitors like top, and service logs from journalctl do not tie live connections to processes, so they cannot identify the reverse shell.

Exam trap

The trap here is choosing commands that show system state or accounts without socket-to-process mapping, such as top or /etc/passwd, which cannot identify the process holding a reverse-shell connection.

532
Multi-Selecthard

A security analyst discovers that an attacker exfiltrated data using DNS tunneling. Which TWO controls should be implemented to detect or prevent this? (Select two.)

Select 2 answers
A.Monitor DNS query sizes and frequencies
B.Use a DNS sinkhole
C.Disable recursive DNS on the internal DNS server
D.Implement DNSSEC
E.Block all DNS queries to external servers
AnswersA, B

DNS tunnelling hides stolen data inside query payloads, so unusually large or frequent queries to one domain expose it. Monitoring query size and frequency detects this anomaly at the resolver, satisfying the requirement to identify exfiltration without blocking legitimate DNS traffic.

Why this answer

Option A is correct because DNS tunneling works by encoding stolen data into the subdomains and TXT/CNAME records of DNS queries, which produces abnormally long query names and unusually high query volumes or frequencies to a single domain; monitoring query size and rate via DNS logging or an IDS/IPS with DNS inspection detects these anomalies. Option B is correct because a DNS sinkhole redirects queries for known malicious or tunneling domains to a controlled non-routable address, breaking the attacker's command-and-control and exfiltration channel and logging the attempted lookups. Option C is not correct because disabling recursion on an internal resolver does not stop tunneling, which typically uses the resolver's normal recursive lookups to reach external authoritative servers.

Option D is not correct because DNSSEC only provides origin authentication and integrity of DNS responses; it does not detect or block data hidden in query payloads. Option E is not correct because blocking all external DNS would break legitimate name resolution and is an impractical, overbroad control rather than a targeted tunneling defense.

Exam trap

Cisco often tests the misconception that DNSSEC or disabling recursion can stop DNS tunneling, but DNSSEC only signs records and does not inspect payloads, while disabling recursion breaks internal resolution without affecting external tunneling via forwarders.

533
MCQhard

During incident response, an analyst extracts files from a PCAP using Wireshark's Export Objects feature. One extracted file is a PDF that triggers an IDS alert for 'Exploit:PDF/HeapSpray'. Which technique does this alert describe?

A.Return-oriented programming (ROP)
B.Shellcode injection
C.Heap spray
D.Stack buffer overflow
AnswerC

Heap spray describes shellcode placed repeatedly across heap memory to land at a predictable address during exploitation. The PDF object carries that sprayed payload, which is why the IDS signature names heap spray rather than a buffer overflow or denial-of-service technique.

Why this answer

Heap spray is a memory corruption technique where an attacker fills heap memory with shellcode to increase the chance of code execution, often used in PDF exploits.

534
MCQmedium

A SOC analyst is reviewing NetFlow records exported from the border router. A single internal workstation is generating a steady stream of outbound sessions to dozens of unique external IP addresses on TCP port 443, each lasting only a few seconds, every day at 02:00. No corresponding firewall denies are logged. Which security monitoring conclusion is most appropriate?

A.The router is misconfigured and is exporting duplicate flow records, which inflates the session count.
B.The workstation is most likely beaconing to a command-and-control infrastructure and should be escalated for endpoint triage.
C.This is expected behaviour for a patched workstation receiving software updates from a content delivery network.
D.The traffic is a port scan launched from the internet against the workstation and should be blocked inbound.
AnswerB

Periodic, low-volume fan-out to many distinct external hosts on a single common port is a classic beaconing signature, especially outside business hours. Because NetFlow records only metadata, the analyst cannot see payload, so the correct next step is to correlate the flows with endpoint telemetry and DNS logs before concluding compromise, but escalation is warranted.

Why this answer

Periodic outbound sessions to many distinct external hosts on a single port, occurring at a fixed hour, match the behavioural profile of malware beaconing rather than normal user or update traffic. NetFlow alone cannot confirm payload, so the analyst should pivot to DNS and endpoint data, but the pattern itself justifies escalation as a suspected command-and-control channel.

Exam trap

The trap here is assuming that traffic on TCP 443 is automatically benign because it is encrypted web traffic, when the destination diversity and timing are what actually matter.

535
MCQmedium

A security analyst discovers that a former employee's user account remains active 45 days after termination, and audit logs show that the account was used to access a file server twice in the past week. Which element of the access control lifecycle was MOST directly violated?

A.Credential rotation
B.Account deprovisioning
C.Privilege escalation review
D.Account provisioning
AnswerB

Deprovisioning is the lifecycle stage that removes or disables access when a user leaves the organization. The account should have been disabled on the employee's last day, but it remained active for 45 days and was used to reach a file server. This directly indicates a breakdown in the termination workflow, such as missing HR-to-IT notifications or absent automated account-disable rules tied to HR status changes.

Why this answer

The account of a terminated employee should have been disabled as part of the offboarding process. Its continued activity 45 days later shows the deprovisioning step of the identity lifecycle failed. Effective programs integrate HR termination events with identity management so accounts are disabled automatically, and they run periodic access reviews to catch accounts that slip through manual processes.

Exam trap

The trap here is assuming any access problem is a permissions problem, when the real issue is that the identity should no longer have existed at all.

536
MCQmedium

A security analyst observes periodic outbound HTTPS connections to an unusual domain that resolves to different IP addresses each time. This behavior is most indicative of:

A.Exfiltration via FTP
B.DNS tunnelling
C.Port scanning
D.Beaconing using DGA
AnswerD

Periodic outbound HTTPS traffic combined with rotating IP resolutions points to domain generation algorithms, where malware cycles through algorithmically generated domains for command-and-control. The regular interval satisfies the beaconing constraint, while the shifting IP addresses reflect DGA domains resolving to changing infrastructure, distinguishing it from static command-and-control.

Why this answer

Periodic outbound HTTPS connections to an unusual domain that resolves to different IPs each time is the classic signature of beaconing using a Domain Generation Algorithm (DGA). Malware uses DGA to generate many pseudo-random domains and rotates through them to evade blocklists, while beaconing provides regular check-ins to C2.

Exam trap

200-201 often tests the confusion between DGA beaconing and DNS tunnelling — both involve DNS, but DGA is about rotating domains for C2 check-ins, while tunnelling is about encoding data inside DNS queries.

How to eliminate wrong answers

Option A is wrong because FTP exfiltration would typically involve large data transfers over port 21 or explicit FTP traffic, not periodic HTTPS beacons to rotating domains. Option B is wrong because DNS tunnelling encodes data in DNS queries/responses (often TXT or long subdomains) and would show anomalous DNS traffic, not HTTPS connections. Option C is wrong because port scanning involves probing many ports on hosts to find open services, not regular outbound HTTPS to a single rotating domain.

537
MCQmedium

You are the cybersecurity analyst for a small business that has a security policy requiring all network traffic to pass through a proxy server for content filtering. Recently, employees have been complaining that some websites are not loading correctly. You check the proxy logs and see that the proxy is blocking traffic that appears to be from non-standard ports. However, upon investigation, you find that the blocked sites are legitimate business tools that use custom ports. Which action aligns with the security policy?

A.Instruct employees to access the tools via HTTP instead.
B.Configure the proxy to allow all traffic on custom ports for those specific tools.
C.Disable content filtering for the affected employees.
D.Create a security exception based on business need and document it.
AnswerD

The security policy mandates proxy filtering, so bypassing it is not permitted. A documented exception based on verified business need preserves the policy while allowing the legitimate tools on their custom ports, satisfying the requirement to align with policy.

Why this answer

Creating a documented security exception for the legitimate business tools allows them to function while maintaining the security policy's intent. The policy requires traffic to pass through the proxy for content filtering, but legitimate business needs may necessitate exceptions. Documenting the exception ensures auditability and control.

Option A is incorrect because instructing employees to use HTTP instead of the custom ports may not be possible if the tools require specific protocols, and it could introduce security risks. Option B is incorrect because configuring the proxy to allow all traffic on custom ports broadly would bypass content filtering for those ports, potentially allowing malicious traffic. Option C is incorrect because disabling content filtering for affected employees removes the security control entirely, violating the policy.

538
MCQmedium

An analyst is reviewing a Linux host that is suspected of being compromised. The analyst runs 'ls -l /proc/1234/exe' and sees that the symbolic link points to '/tmp/.hidden/backdoor'. The process with PID 1234 is owned by root and was started from an unknown parent process. Which of the following best describes what the analyst has discovered?

A.The process is a kernel thread that has been incorrectly linked to a user-space file.
B.The process is a legitimate system daemon that has been relocated to /tmp for performance reasons.
C.The process is a containerized application that uses /tmp as its working directory.
D.The process is a malicious binary running from a non-standard location, indicating a potential compromise.
AnswerD

The /proc/1234/exe link points to the executable file of the process. A root-owned process running from /tmp/.hidden/backdoor is highly suspicious because /tmp is commonly used by attackers to drop and execute malware, and the hidden directory name suggests an attempt to avoid casual observation. This is a clear indicator of compromise.

Why this answer

The /proc/PID/exe symbolic link reveals the actual executable file backing a running process. A root-owned process executing from a hidden directory under /tmp is a classic sign of malware or an attacker's backdoor, as legitimate system processes rarely reside there. This discovery warrants immediate further investigation, such as examining the binary and its network connections.

Exam trap

The trap here is assuming that any process running from /tmp is automatically malicious, but in this context the combination of root ownership, hidden directory, and unknown parent strongly indicates compromise.

539
MCQhard

A company uses a SIEM that collects logs from firewalls, servers, and endpoints. The SIEM is generating a high volume of low-priority events, causing analysts to miss critical alerts. Which approach would best improve the signal-to-noise ratio?

A.Implement event filtering and correlation rules to reduce false positives.
B.Deploy additional sensors to collect more data.
C.Hire more analysts to review all events.
D.Increase the storage capacity of the SIEM.
AnswerA

Filtering and correlation rules suppress or group low-priority events and link related indicators into single meaningful alerts, directly reducing false positives. This raises the proportion of actionable alerts, so analysts can identify genuine threats instead of being overwhelmed by noise.

Why this answer

The SIEM's high volume of low-priority events indicates a poor signal-to-noise ratio, where benign or irrelevant events drown out critical alerts. Implementing event filtering and correlation rules directly reduces false positives by discarding known noise (e.g., repeated benign scans) and grouping related events into meaningful alerts, allowing analysts to focus on genuine threats. This is the standard approach in SIEM tuning to improve detection fidelity without adding resources or data.

Exam trap

Cisco often tests the misconception that 'more data equals better security' (Option B), but the real goal is to reduce noise through intelligent filtering and correlation, not to increase data volume.

How to eliminate wrong answers

Option B is wrong because deploying additional sensors would increase the total volume of events, likely worsening the noise problem rather than improving the signal-to-noise ratio. Option C is wrong because hiring more analysts does not address the root cause of excessive low-priority events; it merely shifts the bottleneck from missing alerts to manual review, which is inefficient and unsustainable. Option D is wrong because increasing storage capacity only allows the SIEM to retain more events, but does nothing to reduce the volume of low-priority alerts or improve alert prioritization.

540
MCQmedium

A security analyst is reviewing logs from a network-based IPS that detected traffic from an internal host connecting to a known malicious IP address on port 6667. The traffic is encrypted IRC. Which conclusion is most likely?

A.The traffic is a normal application update
B.The host is running a legitimate IRC client
C.The host is compromised and part of a botnet
D.The IPS is generating a false positive
AnswerC

Encrypted IRC on port 6667 to a known malicious address indicates command-and-control beaconing. Legitimate IRC is rarely encrypted on that port, so the internal host is most likely a botnet member receiving instructions from its controller.

Why this answer

Port 6667 is the default port for IRC (Internet Relay Chat), and encrypted IRC traffic to a known malicious IP strongly indicates command-and-control (C2) communication. Botnets commonly use IRC over TLS/SSL to evade detection and issue commands to compromised hosts. Therefore, the host is most likely compromised and part of a botnet.

Exam trap

Cisco often tests the misconception that encrypted traffic is always benign or that port 6667 is only used for legitimate chat, leading candidates to overlook the known malicious IP indicator.

How to eliminate wrong answers

Option A is wrong because normal application updates typically use HTTP/HTTPS on ports 80/443 or vendor-specific ports, not port 6667 with encrypted IRC. Option B is wrong because a legitimate IRC client would not connect to a known malicious IP address; legitimate IRC servers are not blacklisted. Option D is wrong because the IPS signature matched encrypted IRC traffic to a known malicious IP, which is a strong indicator of compromise, not a false positive.

541
MCQmedium

A security analyst suspects that a Windows workstation was compromised by malware that schedules a recurring task to maintain persistence. The analyst opens Task Scheduler and sees dozens of scheduled tasks. Which built-in command-line utility should the analyst use to export a detailed list of all scheduled tasks, including the actions they perform, so the list can be reviewed offline?

A.schtasks /query /fo LIST /v
B.tasklist /v /fo csv
C.wmic startup list full
D.sc query type= service state= all
AnswerA

schtasks with /query lists scheduled tasks, /fo LIST selects a list format, and /v adds verbose details such as the task's action, trigger, author, and run-as account. This gives the analyst the full configuration needed to spot a malicious recurring task offline without clicking through the GUI.

Why this answer

Scheduled tasks are a common persistence mechanism because they can launch a payload on a schedule or at logon. The schtasks utility is the native command-line interface to the Task Scheduler service, and the /query /fo LIST /v combination produces a verbose, exportable inventory of every task, including its action and trigger. That output can be reviewed offline to identify the malicious recurring task.

Exam trap

The trap here is confusing process enumeration with scheduled-task enumeration, since tasklist and schtasks have similar-sounding names but query completely different subsystems.

542
MCQmedium

A Cisco Firepower sensor is generating an alert for a known benign application. The analyst has verified it is a false positive. What is the first step to suppress this alert?

A.Create a network analysis policy exception.
B.Increase the severity threshold.
C.Submit a false positive report to Talos.
D.Disable the intrusion rule globally.
AnswerA

This suppresses the alert for the specific benign traffic without affecting other detections.

Why this answer

A network analysis policy (NAP) exception is the correct first step because it allows you to suppress alerts for specific benign applications without affecting the overall detection posture. In Cisco Firepower, NAP exceptions are applied before intrusion rules are evaluated, so they can filter out known false positives at the preprocessor level, preventing the rule from even triggering. This is more efficient than modifying the intrusion rule itself, as it avoids disabling detection for other traffic.

Exam trap

Cisco often tests the distinction between preprocessor-level suppression (NAP exceptions) and rule-level suppression (disabling rules), where candidates mistakenly choose to disable the rule globally instead of creating a targeted exception.

How to eliminate wrong answers

Option B is wrong because increasing the severity threshold would suppress all alerts below that severity level, not just the specific benign application, potentially missing real threats. Option C is wrong because submitting a false positive report to Talos is a feedback mechanism for improving future rule updates, not an immediate operational step to suppress an alert. Option D is wrong because disabling the intrusion rule globally would stop all alerts from that rule, including for malicious traffic that the rule is designed to detect, which is too broad and risky.

543
MCQmedium

An analyst reviews Snort alert logs and sees many alerts for 'SQL Injection Attempt' from a single external IP to a public-facing web server. Which analysis step is most effective?

A.Block the IP at the firewall immediately
B.Check the web server logs for the same IP
C.Run a port scan against the IP
D.Disable the SQL injection signature
AnswerB

Snort signatures are heuristic and prone to false positives, so corroborating with the web server's own access and error logs confirms whether the SQL injection payload actually reached the application and whether it succeeded, validating the alert against the specific external IP named in the stem.

Why this answer

Checking the web server logs for the same IP is the most effective step because it allows the analyst to correlate the Snort alerts with actual HTTP requests. This confirms whether the SQL injection attempts were successful or merely reconnaissance, and provides context such as the specific URI, parameters, and response codes (e.g., 200 vs 500) needed to assess impact.

Exam trap

The trap here is that candidates often choose to block the IP immediately (Option A) as a 'quick fix' without realizing that incident response requires validation and evidence collection before taking containment actions.

How to eliminate wrong answers

Option A is wrong because immediately blocking the IP at the firewall is a reactive measure that may disrupt legitimate traffic (e.g., shared NAT IPs) and does not provide forensic evidence or confirm the attack's success. Option C is wrong because running a port scan against the IP is an active reconnaissance technique that could be illegal without authorization, and it does not help analyze the existing alerts or validate the SQL injection attempts. Option D is wrong because disabling the SQL injection signature would suppress all future alerts for that attack vector, leaving the web server vulnerable and eliminating visibility into ongoing or future SQL injection attempts.

544
MCQhard

A security analyst is investigating a potential exploit. The PCAP shows a HTTP POST request containing a long string of characters that, when decoded, reveals a series of return-oriented programming (ROP) gadgets. What is the likely purpose of this payload?

A.Lateral movement
B.Privilege escalation
C.Exploitation
D.Persistence
AnswerC

ROP gadgets chained in a decoded payload indicate memory-corruption exploitation, where an attacker hijacks control flow to bypass DEP and execute code. The POST delivers the crafted chain, so the payload's purpose is exploitation rather than reconnaissance or exfiltration.

Why this answer

ROP gadgets are used to bypass non-executable memory protections by chaining together small code sequences to execute arbitrary code. This is an exploitation technique.

545
MCQmedium

An analyst is investigating an alert for a potential ICMP tunneling attack. The analyst reviews a PCAP and notices a series of ICMP Echo Request packets with unusually large payloads (over 1000 bytes) and varying payload contents, sent from an internal host to an external IP address. The external host replies with ICMP Echo Reply packets of similar size. Which characteristic most strongly supports the conclusion that this is ICMP tunneling rather than normal ping traffic?

A.The payload size is consistently large and the contents are non-repetitive, indicating that data is being encapsulated in the ICMP payload.
B.The ICMP packets use Type 8 and Type 0 codes, which are reserved for diagnostic purposes and should not carry data.
C.The ICMP Echo Requests are sent at regular intervals, which is a known signature of ICMP tunneling tools.
D.The external host responds with Echo Replies that have a different IP identification field than the requests, which indicates packet fragmentation.
AnswerA

Normal ping payloads are typically small (e.g., 32 or 64 bytes) and often consist of a repeating pattern or timestamp. Large, varying payloads suggest that actual data is being carried inside the ICMP packets, which is the essence of ICMP tunneling. The consistent size and non-repetitive content further indicate a structured data transfer, supporting the conclusion of tunneling.

Why this answer

The strongest indicator of ICMP tunneling is the presence of large, non-repetitive payloads in Echo Requests and Replies, which suggests data encapsulation. Normal ping uses small, often patterned payloads. The other options describe normal ICMP characteristics, such as standard types, regular timing, or IP header fields, none of which specifically indicate tunneling.

Exam trap

The trap here is focusing on the ICMP type or timing as the malicious indicator, when the real signal is the payload size and content variation that reveals data encapsulation.

546
Multi-Selectmedium

Which two characteristics are commonly associated with a distributed denial-of-service (DDoS) attack?

Select 2 answers
A.High volume of traffic from multiple sources
B.Multiple failed login attempts
C.Slow application response time
D.Unusual increase in ICMP echo requests
E.Traffic from a single IP address
AnswersA, D

DDoS attacks aggregate traffic from many distributed hosts, often a botnet, to overwhelm the target's bandwidth or resources. This satisfies the volumetric constraint because the combined traffic from numerous sources exceeds what a single origin could generate.

Why this answer

Option A is correct because a DDoS attack is by definition distributed: it floods the target with a high volume of traffic originating from many compromised hosts (a botnet), which is what distinguishes it from a single-source DoS attack. Option D is correct because a common DDoS technique is the ICMP flood (e.g., ping flood or smurf attack), which manifests as an unusual surge in ICMP echo requests directed at the victim to exhaust bandwidth and processing resources. Option B is not characteristic of DDoS; multiple failed login attempts indicate a brute-force or password-guessing attack against authentication, not resource exhaustion by traffic volume.

Option C, slow application response time, is a possible symptom of many issues including DDoS, but it is a generic effect rather than a defining characteristic of a DDoS attack. Option E is incorrect because traffic from a single IP address describes a traditional single-source DoS attack, whereas DDoS relies on traffic from multiple distributed sources.

Exam trap

Cisco often tests the distinction between a DoS (single source) and a DDoS (multiple sources), so the trap here is that candidates may incorrectly select 'Traffic from a single IP address' (option E) as a DDoS characteristic, confusing the two attack types.

547
MCQmedium

Which compliance framework is specifically designed to protect the privacy and security of electronic health information in the United States?

A.GDPR
B.ISO 27001
C.HIPAA
D.PCI DSS
AnswerC

HIPAA, the Health Insurance Portability and Accountability Act, sets the US legal requirements for safeguarding protected health information held by covered entities and their business associates. Its Privacy and Security Rules specifically govern electronic health records, matching the scenario's demand for a US health-data framework.

Why this answer

HIPAA (Health Insurance Portability and Accountability Act) is the US federal law that specifically governs the privacy and security of protected health information (PHI) held by covered entities and business associates. It defines the Privacy Rule, Security Rule, and Breach Notification Rule, making it the direct answer for electronic health information in the United States. GDPR, ISO 27001, and PCI DSS address different scopes and jurisdictions.

Exam trap

200-201 often tests the confusion between general data protection regulations (GDPR) and sector-specific US laws (HIPAA), so candidates must anchor on the phrase 'electronic health information in the United States.'

How to eliminate wrong answers

Option A is wrong because GDPR is the European Union's general data protection regulation and, while it covers health data as a special category, it is not a US-specific health information framework. Option B is wrong because ISO 27001 is an international information security management standard, not a health-privacy law, and it is voluntary certification rather than regulation. Option D is wrong because PCI DSS governs payment card data security, not health information, and applies to any organization handling cardholder data regardless of industry.

548
MCQmedium

A security analyst is reviewing logs from a web proxy and sees that a user's machine is making frequent connections to a domain that is registered recently and has a low reputation score. What is the best action?

A.Check if the user has a legitimate need to access the domain.
B.Disable the user's network access.
C.Block the domain immediately.
D.Ignore because it might be a false positive.
AnswerA

Checking whether the user has a legitimate business need directly addresses the low-reputation, newly registered domain indicator, which alone cannot confirm malicious intent. Frequent connections may reflect a compromised host or genuine research. Validating the requirement distinguishes true positives from benign activity before escalation, satisfying the need to confirm intent prior to containment.

Why this answer

The best action is to check if the user has a legitimate need to access the domain because a recently registered domain with a low reputation score is a strong indicator of potential malicious activity, but it could also be a false positive or a legitimate new service. Security analysts must validate the context through user inquiry or additional log correlation before taking irreversible actions like blocking or disabling access. This aligns with the principle of least disruption and evidence-based decision-making in security monitoring.

Exam trap

Cisco often tests the misconception that a low reputation score alone justifies immediate blocking, but the trap here is that the question requires you to prioritize investigation over reaction, as the best action is to gather context before applying a control.

How to eliminate wrong answers

Option B is wrong because disabling the user's network access is an overly aggressive response that disrupts productivity without confirming malicious intent, and it violates the principle of verifying before acting. Option C is wrong because blocking the domain immediately could break legitimate business operations if the domain is a newly registered but legitimate service, and it bypasses the necessary validation step. Option D is wrong because ignoring the alert dismisses a high-risk indicator (recent registration + low reputation) that commonly correlates with command-and-control (C2) traffic or phishing domains, and false positives should be investigated, not ignored.

549
MCQmedium

A company wants to protect its web application from injection attacks by ensuring that user-supplied input is not interpreted as code by the backend database. Which control should be implemented?

A.Web application firewall
B.Output encoding
C.Parameterized queries
D.Input validation
AnswerC

Parameterized queries, also called prepared statements, separate SQL code from data by sending the query structure and parameters separately. The database treats parameters as data, not executable code, which prevents SQL injection even if the input contains malicious characters. This directly meets the requirement.

Why this answer

Parameterized queries ensure that user input is passed as data and never concatenated into the SQL statement, so the database cannot interpret it as code. This is the most effective and fundamental defense against SQL injection, unlike input validation, output encoding, or a WAF.

Exam trap

The trap here is choosing a WAF or input validation as the primary fix, when the root cause is the lack of separation between code and data in the query.

550
Multi-Selecteasy

Which TWO actions should an analyst take when a critical alert is triggered?

Select 2 answers
A.Delete the alert to reduce noise
B.Verify the alert with other sources
C.Escalate to incident response team
D.Search for similar alerts in the past
E.Immediately power off the affected system
AnswersB, C

Correlating the alert against logs, endpoint telemetry and threat intelligence confirms whether the detection reflects genuine malicious activity or a false positive, preventing wasted escalation effort and establishing the factual basis needed before containment decisions.

Why this answer

Option B is correct because verifying a critical alert against other sources (such as SIEM logs, EDR telemetry, IDS/IPS events, or host-based logs) confirms whether the alert represents a true positive before committing resources, reducing the risk of acting on a false positive. Option C is correct because once a critical alert is validated, the analyst should escalate it to the incident response team so that containment, eradication, and recovery follow the organization's documented IR process and chain-of-custody requirements. Option A is wrong because deleting alerts destroys evidence and audit trails and could mask a real compromise.

Option D, while sometimes useful for context, is not one of the two primary actions required at the moment a critical alert fires. Option E is wrong because powering off a system can destroy volatile evidence in memory and may violate incident response procedures; isolation is preferred over shutdown.

Exam trap

Cisco often tests the misconception that immediate containment actions like powering off a system are always the correct first step, when in fact verification and preservation of evidence are prioritized to avoid destroying critical forensic data.

551
MCQeasy

Which of the following is a common indicator of a brute-force attack on an SSH server?

A.A single failed login attempt.
B.Multiple successful logins from the same user.
C.Repeated login attempts with different usernames and passwords in a short period.
D.High CPU usage on the server.
AnswerC

Brute-force attacks generate many authentication failures across varied usernames and passwords within a short window, as the attacker guesses credentials. This volume and variety of failed SSH logins distinguishes it from a single mistyped password.

Why this answer

A brute-force attack on an SSH server is characterized by a high volume of authentication attempts, typically using different usernames and passwords, in a short time window. This pattern aims to guess valid credentials through repeated trial and error, which is distinct from a single failure or a few successful logins. The rapid, automated nature of the attempts is the key indicator that distinguishes brute-force activity from normal user behavior.

Exam trap

Cisco often tests the distinction between a single failed login (normal) and a pattern of repeated failures (attack), leading candidates to mistakenly choose Option A because they focus on the word 'failed' rather than the volume and pattern of attempts.

How to eliminate wrong answers

Option A is wrong because a single failed login attempt is a normal event that can occur due to a typo or forgotten password, and does not indicate a systematic attack. Option B is wrong because multiple successful logins from the same user could indicate legitimate concurrent sessions or a compromised account, but it is not a direct sign of a brute-force attack, which focuses on failed attempts. Option D is wrong because high CPU usage on the server can have many causes, such as resource-intensive processes or denial-of-service attacks, and is not a specific or reliable indicator of SSH brute-force attempts.

552
MCQmedium

Which type of malware is characterized by self-replication and spreading to other systems without user interaction, often causing network congestion?

A.Ransomware
B.Trojan
C.Worm
D.Virus
AnswerC

A worm self-replicates and propagates across networks autonomously, requiring no user interaction or host file, unlike viruses that need a carrier. This satisfies the stem's constraint of spreading without user action, and its rapid, uncontrolled replication consumes bandwidth, directly causing the network congestion described.

Why this answer

A worm is self-replicating malware that spreads autonomously across networks without requiring a user to open a file or click a link, often consuming bandwidth and causing congestion. Classic examples include WannaCry's worm component and Conficker. Ransomware, Trojans, and viruses all require some form of user action or host file execution to propagate.

Exam trap

200-201 often tests the distinction between worms and viruses, so candidates must remember that the defining trait of a worm is autonomous self-replication without user interaction, not the type of damage it causes.

How to eliminate wrong answers

Option A is wrong because ransomware encrypts files and demands payment; while some ransomware (e.g., WannaCry) uses worm-like propagation, ransomware as a category is defined by its payload, not self-replication. Option B is wrong because a Trojan disguises itself as legitimate software and relies on the user to execute it, so it does not self-replicate. Option D is wrong because a virus requires a host file and typically user action (opening an infected document or running an executable) to spread, unlike a worm that propagates on its own.

553
MCQhard

An analyst detects an attack where the attacker uses NTLM authentication with a hashed password instead of the plaintext password. This technique is known as:

A.Password spraying
B.Brute force
C.Kerberos ticket reuse
D.Pass-the-hash
AnswerD

Pass-the-hash exploits the NTLM challenge-response protocol: the attacker captures the static NT hash and replays it directly, authenticating without ever cracking it to plaintext. This matches the stem's constraint of authentication using a hashed password rather than the cleartext credential.

Why this answer

Pass-the-hash is the technique where an attacker uses a captured NTLM password hash directly to authenticate without knowing the plaintext password. Because NTLM authentication accepts the hash as the credential, the attacker can replay it to access systems.

Exam trap

200-201 often tests the distinction between pass-the-hash (NTLM hash reuse) and pass-the-ticket (Kerberos ticket reuse), so candidates must match the credential type to the technique.

How to eliminate wrong answers

Option A is wrong because password spraying involves trying a small number of common passwords across many accounts to avoid lockouts, not using hashes. Option B is wrong because brute force attempts many password guesses against an account, whereas pass-the-hash bypasses guessing entirely by using the hash. Option C is wrong because Kerberos ticket reuse (e.g., pass-the-ticket or golden ticket) involves Kerberos TGT/TGS tickets, not NTLM hashes.

554
MCQhard

A threat hunter reviews Cisco Umbrella DNS logs and notices repeated queries for randomly generated subdomains under a single parent domain, each resolved by a different authoritative name server. The hunter suspects DNS tunneling. Which additional artifact would most directly confirm command-and-control activity rather than legitimate DNS behavior?

A.High volume of A records with short TTL values
B.NXDOMAIN responses for nonexistent subdomains
C.TXT record responses containing long base64-encoded strings
D.Queries originating from multiple internal VLANs
AnswerC

DNS tunneling frequently uses TXT records because they can carry arbitrary data and are often permitted through firewalls. Long base64-encoded strings in TXT responses indicate that the DNS channel is transporting encoded payloads, which is a strong signal of command-and-control or exfiltration. Combined with the random subdomain pattern, this artifact directly confirms that data is being moved over DNS rather than merely resolved. Legitimate TXT records, such as SPF or DKIM, have structured formats and predictable lengths.

Why this answer

DNS tunneling moves data inside DNS queries and responses, most commonly using TXT records because they support larger payloads. Long base64-encoded strings in TXT responses, paired with random subdomains and rotating authoritative servers, show that the DNS channel is carrying encoded command-and-control or exfiltration data. This artifact distinguishes malicious tunneling from ordinary DNS resolution patterns.

Exam trap

The trap here is treating generic DNS anomalies such as short TTLs or NXDOMAIN spikes as proof of tunneling, when only encoded payload content in responses confirms data transfer.

555
Multi-Selecthard

A SOC analyst is analyzing logs from multiple sources. Which THREE log types are most useful for detecting a brute force attack against a web application?

Select 3 answers
A.DNS logs
B.System authentication logs
C.Web server logs
D.IDS/IPS alerts
E.Firewall logs
AnswersB, C, E

System authentication logs record login attempts against the underlying operating system, revealing repeated failed credential submissions from a single source. Correlating these timestamps with web activity exposes brute-force patterns targeting application accounts, satisfying the stem's requirement to identify the attack across multiple log sources.

Why this answer

System authentication logs (B) are correct because they record login attempts and failures (e.g., Windows Security Event ID 4625 or Linux /var/log/auth.log entries), which directly reveal repeated failed authentications characteristic of brute force attacks. Web server logs (C) are correct because they capture HTTP POST requests to login endpoints with status codes like 401 or 403, showing the source IP, user-agent, and request patterns of credential-guessing attempts against the application. Firewall logs (E) are correct because they record connection attempts and can reveal high-volume or repeated traffic from a single source IP to the web server's authentication port, helping identify the brute force source and rate.

DNS logs (A) are not typically useful here since brute force attacks target authentication mechanisms directly and do not necessarily generate distinctive DNS queries. IDS/IPS alerts (D) may detect some brute force activity, but they are derived alerts rather than raw log types and are not among the three most directly useful log sources for this scenario.

Exam trap

Cisco often tests the distinction between raw logs (like authentication, web server, and firewall logs) and derived alerts (like IDS/IPS alerts), tricking candidates into selecting IDS/IPS alerts because they seem directly relevant, but the question specifically asks for log types, not alert types.

556
MCQmedium

A security analyst at a SOC Tier 1 receives an alert about a potential malware infection on a user's workstation. What is the primary responsibility of the Tier 1 analyst in this scenario?

A.Coordinate with legal counsel for data breach notification
B.Conduct initial triage and basic investigation
C.Develop new detection signatures
D.Perform deep forensic analysis of the malware
AnswerB

Tier 1 analysts perform initial triage and basic investigation, validating the alert, gathering preliminary data, and escalating confirmed incidents. This matches the primary responsibility for a potential malware infection, as deeper forensics and remediation belong to Tier 2 or Tier 3.

Why this answer

Tier 1 analysts monitor alerts, perform initial triage, and escalate if needed. They conduct basic investigation.

557
MCQeasy

A security analyst is using a SIEM to create a correlation rule that triggers when more than 10 failed logins are detected from the same source IP within 1 minute. This rule is designed to detect which type of attack?

A.Brute-force attack
B.Phishing attack
C.Privilege escalation
D.Man-in-the-middle attack
AnswerA

More than ten failed logins from one source IP within a minute is rapid, repeated authentication failure, the defining pattern of brute-force attacks. The threshold and time window distinguish it from occasional user error or password spraying across many accounts.

Why this answer

A correlation rule that fires on more than 10 failed logins from the same source IP within 1 minute is the textbook signature of a brute-force attack — an attacker rapidly guessing credentials against an authentication endpoint. The high frequency and single-source pattern distinguish it from slow, distributed password spraying. SIEM correlation rules are commonly tuned to this threshold to catch credential-guessing attempts in near real time.

Exam trap

200-201 often tests attack-type identification from telemetry patterns; candidates may pick 'privilege escalation' because failed logins feel like an access issue, missing that the defining signal is high-volume credential guessing from one source.

How to eliminate wrong answers

Option B is wrong because phishing is a social-engineering attack delivered via email or messaging; it does not inherently generate a burst of failed logins from one IP, and detection would rely on email gateway or URL-click telemetry, not login-failure correlation. Option C is wrong because privilege escalation occurs after initial access, when an attacker elevates permissions (e.g., exploiting a misconfiguration or kernel vulnerability); it does not manifest as repeated failed authentication attempts. Option D is wrong because a man-in-the-middle attack intercepts or relays traffic between two parties and is detected via anomalous TLS certificates, ARP anomalies, or traffic redirection — not via failed-login counts.

558
MCQhard

An organization uses Zeek for network monitoring. An analyst wants to extract files transferred over HTTP from network traffic. Which Zeek script or functionality should they use?

A.Zeek's connection log
B.Zeek's HTTP log
C.Zeek's file extraction script
D.Zeek's DNS log
AnswerC

Zeek's file extraction framework reconstructs files from HTTP sessions by reassembling stream data and writing payloads to disk, satisfying the requirement to extract transferred files from captured traffic. It handles MIME types and connection tracking natively, so no packet-level manual carving is needed.

Why this answer

Zeek's file extraction script (often the File Analysis Framework or specific scripts like extract-all-files) is designed to identify and extract files from network traffic, including those transferred over HTTP. This functionality allows analysts to reconstruct files for further inspection, such as malware analysis.

Exam trap

200-201 often tests the confusion between Zeek's logging capabilities and its file extraction functionality, causing candidates to select log types that only provide metadata rather than actual file contents.

How to eliminate wrong answers

Option A is wrong because the connection log records metadata about network connections (e.g., IPs, ports, duration) but does not extract file contents. Option B is wrong because the HTTP log records HTTP request and response metadata (e.g., URIs, methods, user agents) but not the actual files transferred. Option D is wrong because the DNS log captures DNS queries and responses, which is unrelated to file extraction.

559
MCQeasy

Which of the following is a valid indicator of compromise (IoC)?

A.A file hash (MD5)
B.The company's logo
C.An employee's email address
D.A user's full name
AnswerA

A file hash such as MD5 is a concrete, machine-checkable artefact uniquely identifying known malicious files, making it a valid IoC. It satisfies the indicator requirement because hashes are observable, shareable and directly matchable against endpoint or sandbox telemetry.

Why this answer

An indicator of compromise is a forensic artifact that provides evidence a system or network has been breached. A file hash such as an MD5 (or SHA-1/SHA-256) uniquely identifies a malicious file and can be searched across endpoints and threat feeds, making it a canonical host-based IoC. Hashes, IP addresses, domain names, URLs, and registry keys are all standard IoC types used in detection and threat intelligence.

Exam trap

The 200-201 exam often tests whether candidates can distinguish a technical forensic artifact (hash, IP, domain) from a generic business or identity data point — the trap is picking an email address or name because it 'relates to a person involved in an incident.'

How to eliminate wrong answers

Option B is wrong because a company logo is a branding asset with no forensic value — it does not indicate malicious activity and cannot be used to detect a compromise. Option C is wrong because an employee's email address is an identity attribute, not evidence of compromise; while it may appear in phishing, the address itself is not an IoC. Option D is wrong because a user's full name is a directory attribute and carries no technical signal about system or network compromise.

560
MCQhard

During a threat hunt, an analyst discovers sustained outbound traffic from a workstation to multiple IP addresses in different countries on port 443. The traffic patterns show periodic spikes at 5-minute intervals. The workstation is used by a sales representative who frequently accesses cloud CRM. Which additional evidence would most strongly suggest the workstation is compromised?

A.The CRM application uses port 443
B.The sales representative reported slow performance
C.The outbound traffic includes connections to IPs not associated with the CRM
D.The workstation has antivirus installed and up-to-date
AnswerC

Connections to IPs outside the CRM's known ranges break the expected traffic baseline, indicating command-and-control or exfiltration rather than legitimate cloud access. The periodic five-minute spikes already suggest beaconing, so unmatched destinations confirm compromise rather than benign CRM synchronisation.

Why this answer

Outbound traffic to IP addresses not associated with the CRM application indicates the workstation is communicating with unknown or malicious destinations. Since the CRM is accessed via a known domain or IP range, connections to unrelated IPs on port 443 (HTTPS) suggest the workstation may be part of a botnet or exfiltrating data, especially given the periodic spikes at 5-minute intervals, which are characteristic of beaconing behavior used by malware to maintain command-and-control (C2) communications.

Exam trap

Cisco often tests the concept that legitimate application traffic (e.g., CRM on port 443) can be used as a smokescreen, and candidates mistakenly assume that any traffic on a standard port is benign, overlooking the importance of destination IP analysis and traffic patterns like beaconing.

How to eliminate wrong answers

Option A is wrong because the CRM application legitimately uses port 443 for HTTPS traffic, so this alone does not indicate compromise; it is expected behavior. Option B is wrong because slow performance is a subjective symptom that can be caused by many benign factors (e.g., network congestion, resource-heavy applications) and is not a definitive indicator of compromise. Option D is wrong because having antivirus installed and up-to-date does not guarantee the workstation is not compromised; malware can evade detection through techniques like polymorphism or zero-day exploits, and antivirus is not a real-time indicator of current infection status.

561
MCQeasy

What is the purpose of a security baseline?

A.To define the minimum acceptable security posture
B.To respond to security incidents
C.To encrypt sensitive data
D.To detect malware infections
AnswerA

A security baseline specifies the minimum acceptable security posture, giving a documented configuration standard against which systems are hardened and audited. This matches the stem's request for the baseline's purpose rather than a risk assessment or incident response function.

Why this answer

A security baseline defines the minimum acceptable security posture for systems, networks, and devices. It establishes a standard configuration that must be met to ensure a consistent level of security across the organization, such as requiring specific patch levels, disabling unnecessary services, and enforcing password policies. Without a baseline, there is no reference point to measure compliance or identify deviations that could indicate a security weakness.

Exam trap

Cisco often tests the distinction between a security baseline (a static reference standard) and operational security controls (like incident response or encryption), leading candidates to confuse the baseline with the tools or processes that enforce or detect security issues.

How to eliminate wrong answers

Option B is wrong because responding to security incidents is the purpose of an incident response plan (IRP) and associated procedures, not a security baseline. Option C is wrong because encrypting sensitive data is a specific security control or mechanism, often implemented via protocols like AES or TLS, not the overarching definition of a minimum security posture. Option D is wrong because detecting malware infections is the function of antivirus software, intrusion detection systems (IDS), or endpoint detection and response (EDR) tools, not a security baseline.

562
Multi-Selecthard

Which THREE of the following are common evasion techniques used by attackers?

Select 3 answers
A.Slow scans
B.Fragmentation
C.Using high ports
D.Patching vulnerabilities
E.Encryption
AnswersA, B, E

Slow scans spread probes over extended periods, keeping packet rates below threshold-based IDS and firewall detection windows. This low-and-slow timing evades signature and rate triggers, satisfying the evasion constraint by avoiding the volume spikes that perimeter monitoring relies on.

Why this answer

Slow scans (A) are a common evasion technique because spreading probes over long intervals (e.g., nmap -T0/-T1 or --scan-delay) keeps the traffic below IDS/IPS thresholds and rate-based detection, making the reconnaissance blend into normal traffic. Fragmentation (B) evades detection by splitting packets into tiny fragments (e.g., fragroute or nmap -f) so that IDS/IPS devices cannot reassemble and match signatures against the full payload, while the target host reassembles them. Encryption (E) is a common evasion technique because attackers tunnel or encrypt command-and-control and exfiltration traffic (e.g., TLS, SSH, or custom crypto) so deep packet inspection cannot read payloads or match signatures.

Using high ports (C) is not inherently an evasion technique since high ports are normal for legitimate services and are easily logged and detected. Patching vulnerabilities (D) is a defensive remediation action, the opposite of an attacker evasion technique.

Exam trap

Cisco often tests the distinction between evasion techniques and general security practices; the trap here is that candidates may mistake 'patching vulnerabilities' as an attacker action, when in reality it is a defender's mitigation strategy, not an evasion method.

563
MCQhard

During the containment phase of an incident, the IR team decides to power off a compromised server to prevent further damage. However, they later realize that this action may have destroyed volatile evidence. According to best practices, what should the team have done instead?

A.Disconnect the server from the network but leave it running
B.Perform a live forensic image of the server's memory before powering off
C.Immediately power off the server without any imaging
D.Skip evidence collection and focus solely on containment
AnswerB

Memory contents — running processes, network connections, encryption keys — are volatile and lost on power-off. Capturing a live memory image preserves that evidence for analysis, whereas shutting the server down destroys it irrecoverably, so imaging should precede containment.

Why this answer

Short-term containment should preserve evidence; live imaging captures volatile data before power-off.

564
Multi-Selectmedium

A security analyst is investigating a potential data exfiltration incident. Which TWO of the following are common indicators that data exfiltration may be occurring over DNS? (Choose two.)

Select 2 answers
A.DNS responses with a large number of IP addresses
B.DNS queries for AAAA records (IPv6) from an IPv4-only network
C.High volume of DNS queries to a single domain not normally visited
D.Unusually large DNS TXT record responses
E.DNS query responses with high TTL values
AnswersC, D

A high volume of DNS queries to one unusual domain signals tunnelling, where data is encoded into query names and smuggled out through the resolver. This satisfies the stem's DNS-based exfiltration indicator, since legitimate DNS traffic rarely concentrates on a single unfamiliar domain at volume.

Why this answer

Option C is correct because DNS tunneling and exfiltration tools typically generate a high volume of queries to a single attacker-controlled domain that is not normally seen in the environment, as the malware encodes stolen data into the query names and needs many requests to move the data out. Option D is correct because DNS TXT records can carry arbitrary payloads, so unusually large TXT responses are a classic sign of data being returned or acknowledged over DNS, often used by tunneling utilities like iodine or dnscat2. Options A, B, and E are not valid indicators: multiple IP addresses in a response is normal for load balancing or round-robin DNS, AAAA queries from an IPv4-only network are common on dual-stack clients and OS resolvers, and high TTL values simply reflect caching policy and have no direct relationship to exfiltration.

Exam trap

Cisco often tests the distinction between normal DNS behavior (e.g., CDN responses with many IPs) and anomalous patterns specific to tunneling, so candidates mistakenly pick A or E because they sound 'unusual' without understanding the underlying exfiltration mechanism.

565
Multi-Selectmedium

A security analyst is configuring a firewall to block common reconnaissance techniques. Which THREE types of reconnaissance traffic should be blocked to prevent active reconnaissance? (Choose three.)

Select 3 answers
A.Social engineering
B.WHOIS lookups
C.Vulnerability scanning
D.Port scanning
E.Ping sweeps
AnswersC, D, E

Vulnerability scanning actively probes target systems with crafted packets to identify known weaknesses, generating detectable traffic that a firewall can block. This satisfies the stem's requirement to prevent active reconnaissance, since scanning directly interacts with the target rather than gathering data passively from public sources.

Why this answer

Vulnerability scanning (C) is active reconnaissance because the attacker directly sends probes to the target to identify weaknesses, generating traffic the firewall can detect and block. Port scanning (D) is active reconnaissance since tools like Nmap send TCP SYN, FIN, or UDP packets to enumerate open ports on the target hosts. Ping sweeps (E) are active reconnaissance because ICMP Echo Request packets are sent across an address range to discover live hosts.

WHOIS lookups (B) are passive reconnaissance, as they query public registration databases rather than the target's own systems, so a firewall cannot block them. Social engineering (A) is a human-based attack that involves no network traffic to the firewall and is therefore not a reconnaissance traffic type to filter.

Exam trap

The trap here is confusing passive reconnaissance (e.g., WHOIS, social engineering) with active reconnaissance; candidates may incorrectly select social engineering or WHOIS because they are reconnaissance types, but they do not generate blockable network traffic.

566
MCQmedium

A SOC analyst is reviewing a PCAP captured at the network perimeter. The analyst notices that a single internal host sends a series of ICMP echo requests to multiple external hosts, but the ICMP payload size is unusually large (over 1000 bytes) and the payload contains non-ASCII, high-entropy data. The echo replies from the external hosts are also large and contain similar data. Which type of activity is most likely occurring?

A.ICMP redirect attack
B.Ping flood
C.Smurf attack
D.ICMP tunneling
AnswerD

ICMP tunneling encapsulates data within ICMP echo request and reply packets, often using large payloads with high entropy to hide exfiltration or command-and-control traffic. The scenario describes large, non-ASCII, high-entropy payloads in both directions, which is a classic indicator. Normal ping traffic uses small, predictable payloads, so the unusual size and content strongly suggest tunneling.

Why this answer

The correct answer is ICMP tunneling because the traffic pattern shows large, high-entropy payloads in both ICMP echo requests and replies, which is a known method for covert data exfiltration or command-and-control. Normal ICMP traffic uses small, predictable payloads. The other options describe denial-of-service or routing manipulation attacks that do not match the observed bidirectional data exchange.

Exam trap

The trap here is assuming that any ICMP traffic to multiple hosts is a Smurf or flood attack, ignoring the large, high-entropy payloads that indicate tunneling.

567
MCQhard

Refer to the exhibit. An analyst sees these log messages on a Cisco router. The source IP 10.0.0.2 is an internal server. What is the most likely explanation?

A.An external host is scanning the router.
B.The router is under a brute-force attack on the HTTP server.
C.The internal server is trying to access the router's web interface, which is blocked by an ACL.
D.The router is infected with malware and generating traffic.
AnswerC

The logs show the internal server initiating HTTP access to the router's management address, and the ACL denies it. That matches a blocked attempt to reach the router's web interface, not traffic passing through the router.

Why this answer

The log messages show repeated TCP connection attempts from internal server 10.0.0.2 to the router's IP on port 443 (HTTPS) and port 80 (HTTP), which are denied by an ACL. Since the source is an internal server and the destination is the router's own IP, this indicates the server is trying to reach the router's web interface, but the ACL is blocking those packets. Option C correctly identifies this scenario.

Exam trap

Cisco often tests the distinction between inbound vs. outbound traffic and internal vs. external sources, so the trap here is assuming any denied traffic to a router must be an external attack, when the source IP clearly shows it is an internal host.

How to eliminate wrong answers

Option A is wrong because the source IP 10.0.0.2 is internal, not external, so this is not an external host scanning the router. Option B is wrong because a brute-force attack on the HTTP server would typically show repeated authentication failures (e.g., HTTP 401 or 403 responses) or many login attempts, not simple TCP connection denials by an ACL. Option D is wrong because malware on the router would generate traffic from the router to other hosts, not inbound connection attempts to the router's own web interface; the logs show inbound packets being denied, not outbound traffic.

568
MCQmedium

A security analyst is examining a suspicious executable and wants to extract readable strings to identify potential C2 domains or file paths. The analyst has the file on a Windows workstation and needs to use a built-in or commonly available tool. Which approach is most appropriate?

A.Open the file in Notepad and visually scan for readable text that resembles domain names.
B.Rename the file extension to .txt and open it in a web browser to view the text.
C.Use the Windows Command Prompt to run 'strings.exe' if Sysinternals Suite is installed, then search the output for domain-like patterns.
D.Use the 'type' command in Command Prompt to display the file contents and pipe to 'findstr' for domain patterns.
AnswerC

Sysinternals strings.exe is a widely used tool that extracts ASCII and Unicode strings from binary files. Running it from Command Prompt and searching for domain patterns is a standard, effective method for initial triage of a suspicious executable on Windows.

Why this answer

Sysinternals strings.exe is a standard, reliable tool for extracting ASCII and Unicode strings from binaries on Windows. It allows analysts to quickly identify potential C2 domains, file paths, and other indicators without requiring a full disassembler. Searching the output for domain-like patterns is an efficient triage step.

Exam trap

The trap here is assuming that built-in Windows commands like 'type' or Notepad can effectively extract strings from a binary, when they are not designed for that purpose and will produce unreliable results.

569
Multi-Selecthard

Which THREE of the following are indicators that a network may be compromised by a botnet?

Select 3 answers
A.Unusual outbound traffic to known command-and-control servers.
B.Multiple systems communicating with the same external IP at regular intervals.
C.High volume of ICMP echo requests.
D.Endpoint alerts of known malware signatures.
E.Increase in legitimate business traffic.
AnswersA, B, D

C&C communication is a hallmark of botnet activity.

Why this answer

Botnet-infected systems typically communicate with command-and-control (C2) servers to receive instructions or exfiltrate data. Unusual outbound traffic to known C2 IPs or domains is a strong indicator of botnet activity, as legitimate traffic rarely targets these addresses. Security monitoring tools often use threat intelligence feeds to flag such connections.

Exam trap

Cisco often tests the distinction between generic attack symptoms (like high ICMP volume) and specific botnet indicators (like C2 communication and beaconing), so candidates mistakenly select Option C because they associate any unusual traffic with botnets without considering the precise behavioral patterns.

570
MCQmedium

A security analyst is creating a policy for handling sensitive customer data. The policy must ensure data is encrypted at rest and in transit. Which type of policy most directly addresses this requirement?

A.Incident Response Policy
B.Data Protection Policy
C.Access Control Policy
D.Physical Security Policy
AnswerB

A Data Protection Policy directly mandates encryption controls for sensitive customer data, covering both at-rest and in-transit states. It satisfies the stem's requirement by defining cryptographic safeguards as organisational policy, unlike access control or acceptable use policies that address authorisation and behaviour rather than encryption.

Why this answer

A Data Protection Policy is the governance document that directly specifies how data must be safeguarded, including requirements for encryption at rest and in transit, classification, retention, and handling of sensitive customer data. It is the policy type whose scope explicitly covers the confidentiality controls the analyst must enforce. The other policy types address different control domains and do not directly mandate encryption of data.

Exam trap

The trap here is conflating 'Access Control Policy' with data protection — candidates often pick Access Control because it sounds security-related, but encryption requirements belong to the Data Protection Policy.

How to eliminate wrong answers

Option A is wrong because an Incident Response Policy defines how the organization detects, responds to, and recovers from security incidents — it does not prescribe encryption controls for data at rest or in transit. Option C is wrong because an Access Control Policy governs who may access which resources and under what conditions (authentication/authorization), not the cryptographic protection of the data itself. Option D is wrong because a Physical Security Policy covers facility access, surveillance, and environmental controls, which are unrelated to encryption of data in storage or over the network.

571
MCQeasy

An organization's security policy requires that all data at rest on laptops be encrypted. An employee reports that their laptop was stolen. Which control would most likely prevent data exposure?

A.Remote wipe
B.Biometric authentication
C.Full disk encryption
D.Screen lock with password
AnswerC

Full disk encryption renders the laptop's stored data unreadable without the decryption key, so a thief cannot extract files from the stolen drive. It satisfies the data-at-rest encryption requirement directly, unlike access controls or network-based protections that the attacker bypasses by possessing the device.

Why this answer

Full disk encryption (FDE) is the correct answer because it directly addresses the requirement that data at rest be encrypted. When a laptop is stolen, FDE ensures that the data on the drive is unreadable without the decryption key, which is typically derived from a user password or TPM-stored key. This prevents unauthorized access even if the attacker removes the drive and attempts to read it on another system.

The policy explicitly mandates encryption, so FDE is the control that fulfills that requirement.

Exam trap

The trap here is confusing access controls (biometrics, screen lock) with encryption controls; candidates might think that a screen lock prevents data exposure, but it only protects the running system, not the data at rest.

How to eliminate wrong answers

Option A is wrong because remote wipe requires the laptop to be powered on and connected to the internet, which is not guaranteed after theft; it is a reactive measure, not a preventive control for data at rest. Option B is wrong because biometric authentication is an access control for the running system, not for data at rest; it does not encrypt the drive, so an attacker could bypass it by removing the disk. Option D is wrong because a screen lock with password only protects the system while it is running and locked; it does not encrypt the data, so the disk can be read if removed.

572
MCQhard

A security analyst is reviewing a suspicious file recovered from a compromised endpoint. The file contains a macro that, when opened, launches PowerShell to download a second-stage payload from a remote server. The analyst wants to classify this file based on its behavior. Which classification is most accurate?

A.A dropper that delivers a malicious payload onto the system
B.A rootkit because it hides the PowerShell process
C.Fileless malware because it uses a scripting engine
D.A logic bomb because it triggers on a specific event
AnswerA

A dropper is code whose purpose is to install or download malware onto a target. The macro document fits this role: it executes on open and fetches a second-stage payload, establishing the infection. Classifying it as a dropper correctly describes its function in the attack chain rather than the payload it delivers.

Why this answer

The macro document functions as a dropper: its sole purpose is to execute and pull a second-stage payload onto the host. Droppers are common initial-access vehicles, and classifying by function helps the analyst understand the infection chain and prioritize response. The delivered payload may later exhibit other behaviors, but the file in hand is a dropper.

Exam trap

The trap here is labeling the threat fileless merely because PowerShell is involved, even though a macro document on disk is a clear file-based dropper.

573
MCQhard

A company is implementing a security policy that requires all employees to use multi-factor authentication (MFA) when accessing corporate resources remotely. However, during a recent security audit, it was found that several employees have been using app passwords for legacy applications that do not support MFA. What is the best practice under this policy?

A.Allow app passwords as they provide a second factor.
B.Implement a VPN requirement for legacy application access.
C.Discontinue use of legacy applications until they support MFA.
D.Create a separate policy for legacy applications with compensating controls.
AnswerD

Legacy applications lacking MFA support cannot enforce the policy directly, so a distinct policy with compensating controls—such as IP restrictions, conditional access in Microsoft Entra ID, or monitored app passwords—isolates their risk without weakening MFA enforcement elsewhere. This satisfies the audit finding while maintaining the remote-access security requirement.

Why this answer

When legacy applications cannot support MFA directly, the best practice is to create a separate policy that documents compensating controls—such as network segmentation, IP allowlisting, or strict access logging—to mitigate the risk of using app passwords. App passwords bypass the second factor and are essentially static credentials, so they must be governed by additional security measures rather than being treated as equivalent to MFA.

Exam trap

Cisco often tests the misconception that app passwords are a valid second factor, when in reality they are a static bypass that undermines the MFA policy—candidates must recognize that compensating controls are the correct administrative response for unsupported applications.

How to eliminate wrong answers

Option A is wrong because app passwords are not a true second factor; they are static passwords generated once and bypass the MFA challenge, effectively reducing security to single-factor authentication. Option B is wrong because requiring a VPN does not enforce MFA for the legacy application itself; it only secures the transport layer, leaving the application vulnerable to credential theft or replay attacks. Option C is wrong because discontinuing legacy applications outright is often impractical and not a security policy best practice—compensating controls allow continued operation while managing risk.

574
MCQhard

A security analyst is reviewing an incident response policy that requires the team to preserve evidence for potential legal action. The analyst notices that the policy does not address how to handle evidence when a compromised system must be rebooted to restore services. What should the analyst recommend to balance evidence preservation with operational recovery?

A.Shut down the system and store it in a secure room without further analysis
B.Continue running the compromised system indefinitely to observe attacker behavior
C.Capture volatile memory and disk images before rebooting, and document the sequence of actions
D.Reboot immediately to restore services and collect evidence afterward from backups
AnswerC

This is correct because volatile data such as RAM contents and running processes are lost on reboot, so capturing memory and disk images first preserves critical evidence. Documenting the sequence maintains chain of custody. This approach balances the need to restore services with the legal requirement to preserve evidence, which the current policy fails to address.

Why this answer

When a compromised system must be rebooted, capturing volatile memory and disk images beforehand preserves evidence that would otherwise be lost. Documenting each action maintains chain of custody and supports legal admissibility. This balanced approach allows services to be restored without sacrificing the integrity of the investigation, addressing the gap in the current policy.

Exam trap

The trap here is assuming that rebooting first and collecting evidence later is acceptable, when volatile data such as RAM contents would be permanently lost.

575
MCQeasy

A SOC analyst is reviewing Cisco Firepower intrusion event logs and notices a signature that fired with the message 'OS-COMMAND' on traffic destined to an internal web server on TCP port 80. Which type of activity does this signature most likely indicate?

A.A DNS tunneling session exfiltrating data to an external resolver
B.A brute-force authentication attempt against the web server's SSH service
C.A remote command injection attempt against a web application
D.A normal software update check initiated by the web server
AnswerC

Signatures with the 'OS-COMMAND' prefix in Cisco Firepower/SNORT rule sets are designed to detect attempts to execute operating system commands through an application, commonly via web request parameters. The traffic targeting port 80 on a web server strongly supports a command injection attempt, where an attacker tries to pass shell commands through an HTTP request to gain execution on the host.

Why this answer

An OS-COMMAND signature on HTTP traffic to a web server indicates an application-layer command injection attempt, where an attacker embeds operating system commands in a request to execute them on the target. The port and signature category align with this interpretation, making the remote command injection scenario the correct reading of the alert.

Exam trap

The trap here is assuming any high-severity alert on port 80 is web exploitation generically, rather than recognizing that the OS-COMMAND signature category specifically flags operating system command execution attempts.

576
MCQmedium

A SOC analyst is monitoring network traffic using Cisco Stealthwatch. An alert is generated indicating a large volume of data being transferred from a critical server to an external IP address during off-hours. The analyst observes that the data transfer is using encrypted HTTPS traffic to a cloud storage provider. The server is known to host sensitive customer data. The analyst reviews the server's outbound firewall rules and finds that HTTPS traffic to any destination is allowed. The analyst checks the server's recent login logs and sees an authentication from a user account that is typically used by a contractor who only works during business hours. The contractor's account has not been disabled after the contract ended last week. What should the analyst do first?

A.Ignore the alert because the traffic is encrypted and cannot be inspected.
B.Immediately block the external IP address at the firewall to stop the data transfer.
C.Investigate the alert further by checking the server for any signs of malware or unauthorized access, and then escalate to the incident response team.
D.Disable the contractor's user account and notify the IT manager.
AnswerC

This is the correct first action. The analyst should collect additional evidence (e.g., process lists, network connections, file system changes) to confirm the incident. Only after validation should escalation and containment occur, following the incident response plan.

Why this answer

The analyst should first investigate further by checking the server for signs of malware or unauthorized access, then escalate to the incident response team. This is the correct first step because the alert indicates a potential data exfiltration, but the analyst must gather additional evidence to confirm the incident and determine its scope before taking disruptive actions. Investigating the server can reveal the exact cause, such as compromised credentials or malware, and escalation ensures proper incident response procedures are followed.

Exam trap

200-201 often tests the incident response order, where candidates are tempted to jump to containment (blocking IP or disabling account) before completing investigation and escalation, but the exam expects adherence to the NIST incident response lifecycle.

How to eliminate wrong answers

Option A is wrong because encrypted traffic can still be analyzed for metadata, and ignoring the alert would miss a critical security incident. Option B is wrong because immediately blocking the external IP address may stop the transfer but could also disrupt legitimate business traffic and does not address the root cause; it is a containment action that should come after investigation and escalation. Option D is wrong because disabling the contractor's account is a containment step, but it should not be the first action without confirming the account's involvement and understanding the full scope; it also does not address the potential malware on the server.

577
MCQmedium

A network analyst is troubleshooting a false positive alert from an IPS that blocks traffic to a legitimate database server. The alert signature is triggered by the pattern 'OR 1=1'. The analyst determines that the traffic is from a web application that uses dynamic SQL queries. Which action best reduces false positives while maintaining security?

A.Increase the sensitivity of the signature
B.Add the database server IP to an exception list
C.Change the signature to alert-only mode
D.Disable the signature entirely
AnswerB

Whitelisting known good traffic reduces false positives.

Why this answer

Adding the database server IP to an exception list allows the IPS to ignore traffic matching the 'OR 1=1' pattern specifically when it is destined for the legitimate database server. This preserves security by continuing to block the same pattern when it targets other servers, while eliminating the false positive caused by the web application's dynamic SQL queries. Whitelisting by destination IP is a targeted exception that does not weaken overall detection.

Exam trap

Cisco often tests the distinction between 'reducing false positives' and 'reducing security' — candidates mistakenly choose alert-only mode (option C) thinking it stops the blocking, but fail to realize it also stops blocking real attacks, which is not a security-maintaining action.

How to eliminate wrong answers

Option A is wrong because increasing the sensitivity of the signature would make it trigger on even more benign traffic, worsening the false positive problem. Option C is wrong because changing the signature to alert-only mode would stop blocking the false positive but would also prevent the IPS from blocking actual SQL injection attacks using the same pattern, reducing security. Option D is wrong because disabling the signature entirely removes protection against all 'OR 1=1' attacks across the network, which is an overreaction to a single false positive.

578
MCQhard

During incident response, an analyst is collecting volatile evidence from a compromised Linux server that is still running. The team wants to preserve the current state of active network connections and running processes before any remediation. Which action best preserves this volatile data in a forensically sound manner?

A.Immediately power off the server to freeze memory contents for later analysis.
B.Run the antivirus scanner included with the distribution to quarantine malicious files.
C.Create a full disk image of the server before collecting any memory-resident data.
D.Capture live network connection and process information to external media before remediation.
AnswerD

Volatile data such as active sockets, process listings, and loaded modules exists only while the system runs, so it must be captured first and written to external media to avoid altering the disk. Order of volatility dictates collecting the most perishable evidence earliest. Documenting the commands and timestamps maintains forensic integrity and supports later analysis.

Why this answer

Order of volatility requires collecting the most perishable evidence first. On a live Linux server, active network connections, running processes, and memory contents will change or vanish quickly, so they must be documented and copied to external media before any disk imaging or remediation. Powering off, imaging disk first, or running scanners all destroy or alter this volatile state.

Exam trap

The trap here is assuming that powering off or imaging the disk first is the safest forensic step, when in fact those actions destroy the volatile network and process evidence that must be captured while the system is still running.

579
Multi-Selectmedium

A security analyst is investigating a potential data breach. The analyst identifies that the attacker used a technique to impersonate a legitimate user by spoofing the MAC address and IP address. Which TWO types of network attacks could involve these techniques? (Choose two.)

Select 2 answers
A.ARP spoofing
B.Denial of Service
C.DNS poisoning
D.IP spoofing
E.Phishing
AnswersA, D

ARP spoofing sends forged Address Resolution Protocol replies, binding the attacker's MAC address to a legitimate user's IP address within the victim's cache. This satisfies the stem's requirement for both MAC and IP impersonation, enabling traffic interception or man-in-the-middle positioning on the local subnet.

Why this answer

ARP spoofing (A) is correct because it works by sending forged ARP replies that map the attacker's MAC address to a legitimate user's IP address, effectively spoofing both MAC and IP to impersonate that user on the local subnet. IP spoofing (D) is correct because it involves crafting packets with a forged source IP address (and often a spoofed MAC at layer 2) to make traffic appear to originate from a legitimate host. Denial of Service (B) focuses on exhausting resources or bandwidth rather than impersonating a user via MAC/IP spoofing.

DNS poisoning (C) corrupts DNS resolver cache entries to redirect name resolution, not to impersonate a user's MAC/IP identity. Phishing (E) is a social-engineering attack using deceptive messages or sites, not MAC/IP address spoofing.

Exam trap

Cisco often tests the distinction between IP spoofing (Layer 3) and ARP spoofing (Layer 2), and candidates may incorrectly assume that IP spoofing alone is sufficient for impersonation on a local network, forgetting that ARP resolution is required for actual traffic interception.

580
MCQmedium

In a Linux system, an analyst wants to check for unauthorized cron jobs. Which of the following is a common location for user-specific cron jobs?

A./var/log/cron
B./etc/cron.d/
C./etc/crontab
D./var/spool/cron/crontabs/
AnswerD

On Linux, user-specific cron jobs are stored per-account in /var/spool/cron/crontabs/, with one file per user. Inspecting this directory reveals unauthorised scheduled tasks created by individual accounts, which is exactly what the analyst needs to check.

Why this answer

User-specific cron jobs are stored in /var/spool/cron/crontabs/ (or /var/spool/cron/ on some distributions), named after the user.

581
MCQmedium

An organization uses STIX and TAXII to share threat intelligence with an ISAC. What is the purpose of TAXII in this scenario?

A.It stores threat intelligence locally
B.It is a platform for malware analysis
C.It provides a method to transport threat intelligence
D.It defines the format for threat indicators
AnswerC

TAXII defines the application-layer protocol and services for exchanging cyber threat intelligence over HTTPS, carrying STIX-formatted content between parties. It satisfies the ISAC sharing requirement by providing the transport mechanism, whereas STIX supplies the structured data format itself.

Why this answer

TAXII is a protocol for exchanging STIX data.

582
MCQhard

A security analyst is evaluating risks and calculates that a threat has a likelihood of 0.5 and an impact of $200,000. What is the risk value?

A.$50,000
B.$100,000
C.$400,000
D.$200,000
AnswerB

Multiplying likelihood (0.5) by impact ($200,000) yields $100,000, the quantitative risk value the analyst must report. This satisfies the stem's single-step calculation, giving the expected loss figure that feeds directly into the risk register and subsequent prioritisation decisions.

Why this answer

The risk value is calculated by multiplying the likelihood (0.5) by the impact ($200,000), resulting in $100,000. This is the standard quantitative risk analysis formula used in security assessments to prioritize threats.

Exam trap

Cisco often tests the basic risk calculation formula (Risk = Likelihood × Impact) and the trap here is that candidates may mistakenly use the impact value alone or apply incorrect arithmetic, such as dividing instead of multiplying.

How to eliminate wrong answers

Option A is wrong because $50,000 would result from multiplying 0.25 by $200,000, not 0.5. Option C is wrong because $400,000 would result from multiplying 2.0 by $200,000, which is not a valid probability. Option D is wrong because $200,000 assumes a likelihood of 1.0, ignoring the 0.5 probability factor.

583
MCQmedium

An analyst finds an unknown scheduled task on a Windows system that runs a PowerShell script at system startup. Which tool is best for examining the task's trigger and actions?

A.Services.msc
B.Event Viewer
C.Registry Editor
D.Task Scheduler
AnswerD

Task Scheduler exposes each task's triggers, actions, conditions and author, letting the analyst inspect exactly what the PowerShell script runs and when. Other tools show process or file artefacts but not the task definition itself.

Why this answer

Task Scheduler is the native Windows tool that displays scheduled tasks along with their triggers (e.g., 'At system startup') and actions (e.g., running a PowerShell script). It provides a GUI and command-line interface (schtasks) to inspect, modify, or disable suspicious tasks, making it the best fit for examining the task's configuration.

Exam trap

The trap is assuming Event Viewer or Registry Editor is sufficient because they can show evidence a task ran; the question asks specifically for examining the task's trigger and actions, which only Task Scheduler presents directly.

How to eliminate wrong answers

Option A is wrong because Services.msc manages Windows services and their startup types, not scheduled tasks, so it would not reveal the PowerShell script or its trigger. Option B is wrong because Event Viewer shows logged events and audit records, which can indicate that a task ran but does not display the task's trigger or action definitions. Option C is wrong because Registry Editor can show task-related keys under TaskCache, but it is not the purpose-built tool for viewing triggers and actions and is error-prone for this use case.

584
MCQhard

An analyst is examining a PCAP of what appears to be a covert channel. The analyst observes that the internal host sends ICMP Echo Requests that contain a payload of exactly 48 bytes of non-repeating binary data, and the corresponding Echo Replies always return with a zero-length payload. The payload bytes, when decoded, contain what looks like command strings. Which technique is most consistent with these observations?

A.ICMP redirect attack manipulating the host's routing table
B.ICMP flood denial-of-service attack against the external host
C.Smurf attack using the internal host as an unwitting reflector
D.ICMP tunneling using Echo Request payloads as a data exfiltration and command channel
AnswerD

ICMP tunneling abuses the data field of Echo Request and Echo Reply packets to carry arbitrary payloads. The non-repeating binary content and command-like strings in the Echo Request payload, combined with empty Echo Replies, indicate the host is sending data or receiving instructions inside ICMP rather than performing normal reachability checks.

Why this answer

The defining indicators of ICMP tunneling are Echo Request or Echo Reply packets carrying non-standard, often non-repeating or encoded payloads, especially when those payloads contain structured data such as command strings. Normal ping traffic uses predictable, often repeating payloads like alphabetic patterns. The one-way data flow with empty replies here strongly suggests the channel is being used to deliver commands or exfiltrate data covertly.

Exam trap

The trap here is dismissing the traffic as benign ping activity because ICMP is common, when the abnormal payload size and command-like content are the actual red flags.

585
MCQhard

An analyst uses 'tshark -r capture.pcap -Y "http.request.method == POST"' to display only HTTP POST requests. This is an example of a:

A.Statistical filter
B.Read filter
C.Capture filter
D.Display filter
AnswerD

The -Y flag applies a Wireshark display filter, which restricts which decoded packets tshark prints without altering what was captured. Capture filters, by contrast, use BPF syntax and discard traffic at collection time, so they cannot be applied to an already-saved pcap.

Why this answer

The `-Y` flag in tshark applies a display filter, which operates on packets already read from the capture file. Display filters use a syntax based on protocol fields (e.g., `http.request.method == POST`) to show or hide packets in the output without altering the underlying capture data. This is distinct from capture filters, which discard packets at the kernel level before they are stored.

Exam trap

Cisco often tests the distinction between display filters (`-Y`) and capture filters (`-f`), trapping candidates who confuse the `-Y` flag with a capture filter because both can filter packets, but only capture filters discard data at the point of acquisition.

How to eliminate wrong answers

Option A is wrong because a statistical filter is not a standard tshark filter type; tshark offers capture, read, and display filters, but not a dedicated 'statistical filter' (statistics are generated via separate `-z` options). Option B is wrong because a read filter is applied with the `-R` flag (deprecated) or `-Y` in older contexts, but the official term for `-Y` is a display filter, and read filters are not a separate category in current Wireshark/tshark documentation. Option C is wrong because a capture filter uses the `-f` flag and BPF syntax (e.g., `tcp port 80`) to limit which packets are captured or read from a file; the `-Y` flag does not discard packets from the capture, it only filters the display.

586
MCQhard

Refer to the exhibit. What does this packet capture indicate?

A.SYN flood
B.Port scan
C.Session hijack
D.Normal HTTP traffic
AnswerB

The pattern matches a SYN scan (also known as half-open scan), where the attacker sends SYN packets to multiple ports and does not complete the three-way handshake, allowing them to probe for open ports without establishing a full connection.

Why this answer

The packet capture shows multiple TCP SYN packets sent to a single host (10.10.10.10) targeting different ports (80, 443, 22, 21) with no subsequent ACK or RST responses. This pattern is characteristic of a port scan, specifically a SYN scan, where the attacker sends SYN packets to probe for open ports without completing the three-way handshake.

Exam trap

Cisco often tests the distinction between a SYN flood (volume-based attack on a single port) and a SYN scan (probing multiple ports), where candidates mistakenly associate any SYN traffic with a flood rather than recognizing the multi-port pattern as reconnaissance.

How to eliminate wrong answers

Option A is wrong because a SYN flood involves sending a high volume of SYN packets to a single port to exhaust server resources, not probing multiple ports. Option C is wrong because session hijacking requires an established TCP session with sequence number prediction, which is absent here. Option D is wrong because normal HTTP traffic would show completed three-way handshakes (SYN, SYN-ACK, ACK) and subsequent data transfer, not isolated SYN packets to multiple ports.

587
MCQmedium

In a PCAP, an analyst sees a large outbound data transfer over FTP to an external IP address during non-business hours. The source host is a database server. Which phase of the Cyber Kill Chain does this represent?

A.Installation
B.Actions on Objectives
C.Weaponization
D.Exploitation
AnswerB

Exfiltration of database records to an external FTP endpoint fulfils the attacker's ultimate goal, so it maps to Actions on Objectives. Earlier phases cover reconnaissance, weaponisation, delivery, exploitation, installation and command-and-control; the actual theft of sensitive data is the final stage.

Why this answer

The Cyber Kill Chain's 'Actions on Objectives' phase is where the attacker achieves their ultimate goal, such as exfiltrating data. In this scenario, a large outbound FTP transfer from a database server to an external IP during non-business hours directly indicates data theft, which is the final objective of the intrusion. FTP (port 21/20) is used here as the exfiltration protocol, moving sensitive data out of the network.

Exam trap

Cisco often tests the distinction between 'Actions on Objectives' and 'Exploitation' by presenting a post-compromise activity (like data exfiltration) and expecting candidates to recognize it as the final phase, not the initial breach.

How to eliminate wrong answers

Option A is wrong because 'Installation' refers to deploying malware or a backdoor on the target system, not to the actual data exfiltration seen here. Option C is wrong because 'Weaponization' is the phase where the attacker creates a deliverable payload (e.g., coupling an exploit with a dropper), which occurs before delivery and exploitation. Option D is wrong because 'Exploitation' is the phase where a vulnerability is triggered to gain initial access, not the post-compromise data theft activity.

588
Drag & Dropmedium

Drag and drop the steps to configure a Cisco ASA firewall for basic network access into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct order for basic Cisco ASA configuration is: global configuration mode, interface configuration (nameif, IP address, security-level), ACL creation, ACL application to interface, and verification. This sequence ensures interfaces are ready, ACLs exist before being applied, and verification confirms the policy is active. Common mistakes include creating or applying ACLs before interfaces are configured, or verifying before applying the ACL.

589
MCQmedium

A security analyst is investigating a recent security breach. The analyst discovers that an attacker gained access to the network by exploiting a vulnerability in an unpatched web server. After gaining access, the attacker moved laterally to other systems and exfiltrated sensitive data. The organization wants to improve its security posture to prevent similar incidents. Which security concept best describes the attacker's actions after initial compromise?

A.Reconnaissance
B.Persistence
C.Privilege escalation
D.Lateral movement
AnswerD

Lateral movement refers to the techniques an attacker uses to move through a network after initial compromise, seeking additional access and privileges. In this scenario, the attacker moved from the compromised web server to other systems, which is lateral movement. This phase often involves credential dumping, remote execution, and internal reconnaissance.

Why this answer

After exploiting the web server, the attacker moved to other systems, which is lateral movement. This phase is about expanding access within the network. Privilege escalation, persistence, and reconnaissance are different phases of an attack.

Lateral movement is a key concept in understanding how attackers spread and compromise additional assets.

Exam trap

The trap here is equating any post-compromise activity with privilege escalation; lateral movement specifically involves moving between systems, while privilege escalation is about gaining higher privileges on a single system.

590
Multi-Selectmedium

Which TWO of the following are essential components of an effective security policy framework according to Cisco best practices?

Select 2 answers
A.A high-level security policy that defines management's intent.
B.A network diagram showing all security devices.
C.Standards that define mandatory rules for technology use.
D.A password policy that specifies minimum length and complexity.
E.A log analysis procedure for detecting anomalies.
AnswersA, C

A high-level security policy articulates management's intent, direction and risk tolerance, giving lower-level standards, procedures and guidelines their authority. Cisco's framework treats this documented senior-management commitment as the foundational component from which all other policy artefacts derive.

Why this answer

Option A is correct because Cisco's security policy framework begins with a high-level policy document that articulates management's intent, objectives, and overall security stance, providing the authority and direction for all subordinate policies. Option C is correct because standards are an essential layer of the framework, translating the high-level policy into mandatory, specific rules for technology use (e.g., required encryption algorithms or protocol configurations) that must be followed consistently across the organization. Option B is not essential to the policy framework itself; a network diagram is a supporting documentation artifact rather than a policy component.

Option D is not essential at the framework level because a password policy is a specific control or standard, not one of the core framework components. Option E is not essential as a framework component because log analysis is an operational procedure that supports monitoring and incident response, not a foundational policy element.

Exam trap

Cisco often tests the distinction between policy framework components (high-level intent and mandatory standards) versus operational or procedural documents, leading candidates to mistakenly select specific technical controls (like password policies or log procedures) as essential framework elements.

591
MCQmedium

A security analyst is investigating an incident where an attacker gained initial access to a corporate network. The analyst finds that the attacker sent a phishing email with a link to a malicious website that exploited a vulnerability in the user's browser. Which phase of the Cyber Kill Chain does the browser exploitation represent?

A.Weaponization
B.Installation
C.Reconnaissance
D.Exploitation
AnswerD

Exploitation is the phase where the attacker leverages a vulnerability to gain access, such as exploiting a browser flaw when the user visits a malicious site. In this scenario, the malicious website exploits the browser vulnerability, which is the defining action of the Exploitation phase. This occurs after delivery and before installation of persistent malware.

Why this answer

The Cyber Kill Chain phases are Reconnaissance, Weaponization, Delivery, Exploitation, Installation, Command and Control, and Actions on Objectives. When a user visits a malicious website that exploits a browser vulnerability, that action is Exploitation. It follows Delivery (the phishing email with the link) and precedes Installation of any persistent payload.

Exam trap

The trap here is confusing Delivery with Exploitation, but the delivery is the phishing email, while the actual vulnerability exploitation is the browser compromise.

592
MCQhard

A network analyst finds a PCAP with a series of DNS queries for subdomains like "data12345.example.com" and "data67890.example.com" where the subdomain names appear to contain encoded base64 data. This pattern suggests:

A.Port scan via DNS
B.Normal DNS resolution
C.DGA-based C2
D.DNS tunnelling for exfiltration
AnswerD

Repeated DNS queries carrying base64-encoded labels in subdomains indicate data encoded into DNS requests, a hallmark of DNS tunnelling used to exfiltrate data covertly through permitted DNS traffic, bypassing egress controls that block other channels.

Why this answer

DNS tunnelling for exfiltration encodes stolen data into DNS query names (often base64) and sends it to an attacker-controlled authoritative DNS server. The pattern of many subdomains with encoded-looking labels under the same domain is a classic indicator of data being smuggled out via DNS, which is frequently allowed through firewalls.

Exam trap

200-201 often tests the difference between DGA (random domains for C2 beaconing) and DNS tunnelling (encoded data in subdomains for exfiltration) — candidates see 'encoded subdomains' and wrongly pick DGA.

How to eliminate wrong answers

Option A is wrong because a port scan via DNS would involve queries for many different domains or service records, not a series of encoded subdomains under one domain. Option B is wrong because normal DNS resolution produces human-readable, predictable hostnames, not base64-encoded labels with sequential-looking data. Option C is wrong because DGA-based C2 generates many random-looking domain names across different TLDs to locate a C2 server, whereas here the data is encoded in subdomains of a single domain, indicating exfiltration rather than beaconing.

593
MCQeasy

An analyst receives an alert for 'ET WEB_SERVER Possible SQL Injection Attempt' triggered by a URL parameter containing ' OR 1=1--'. After investigating, the analyst confirms that the web application is not vulnerable to SQL injection and the request was a benign test. How should this alert be classified?

A.False positive
B.True negative
C.False negative
D.True positive
AnswerA

The signature fired on a string resembling SQL injection, but investigation confirmed the application is not vulnerable and the traffic was a benign test. The alert therefore correctly identified suspicious syntax yet wrongly indicated an actual attack, which is a false positive.

Why this answer

A false positive occurs when an alert is triggered but the activity is actually benign. Here, the SQL injection attempt was a benign test and the application is not vulnerable, so the alert is a false positive. This classification is correct because the detection system incorrectly flagged legitimate activity as malicious.

Exam trap

200-201 often tests whether candidates can correctly classify alerts based on the definitions of true/false positives/negatives, so the trap is confusing a false positive with a true negative or true positive when the activity is benign but an alert was raised.

How to eliminate wrong answers

Option B is wrong because a true negative is when no alert is triggered and no malicious activity occurs; here, an alert was triggered. Option C is wrong because a false negative is when malicious activity occurs but no alert is triggered; here, an alert was triggered. Option D is wrong because a true positive is when an alert is triggered and the activity is actually malicious; here, the activity was benign.

594
MCQeasy

Which security concept describes the potential for a threat to exploit a vulnerability, and is often expressed as a combination of likelihood and impact?

A.Risk
B.Exploit
C.Threat
D.Vulnerability
AnswerA

Risk quantifies the potential for a threat to exploit a vulnerability, combining the likelihood of that exploitation with the resulting business impact. This matches the stem's definition precisely, distinguishing it from a vulnerability or threat in isolation.

Why this answer

Risk is defined as the potential for a threat to exploit a vulnerability, typically calculated as likelihood × impact. It is the overarching concept that combines the probability of a threat event with the resulting business or asset damage. In security frameworks like NIST and ISO 27005, risk = f(threat, vulnerability, impact, likelihood), which matches the question's wording exactly.

Exam trap

The trap here is confusing the four related terms — threat, vulnerability, exploit, and risk — because they are often used interchangeably in casual conversation, but the exam requires recognizing that only risk combines likelihood and impact.

How to eliminate wrong answers

Option B is wrong because an exploit is the specific tool, code, or technique that takes advantage of a vulnerability — it is the mechanism of attack, not the combined likelihood/impact measure. Option C is wrong because a threat is only the potential cause of an unwanted incident (e.g., an attacker or malware), not the composite measure of likelihood and impact. Option D is wrong because a vulnerability is merely a weakness in a system, application, or control — it has no inherent likelihood or impact value until paired with a threat and evaluated as risk.

595
MCQmedium

A security analyst is reviewing a packet capture from the DMZ and sees a host at 203.0.113.45 sending a flood of TCP segments with the SYN flag set to many different destination ports on a single internal web server, all within a few seconds. The source IP never completes the three-way handshake. Which type of attack is this host most likely performing?

A.Cross-site scripting attack
B.SYN flood denial-of-service attack
C.UDP amplification attack
D.ARP spoofing attack
AnswerB

A SYN flood exploits the TCP three-way handshake by sending many SYN packets, often with spoofed sources, without completing the handshake. The server allocates resources for each half-open connection, exhausting its backlog queue. The scenario shows exactly this pattern: many SYNs to multiple ports, no completed handshakes, quickly overwhelming the web server's connection table.

Why this answer

The observed traffic matches a SYN flood: a high volume of TCP SYN segments to many ports from one source, with no completed three-way handshakes. Each half-open connection consumes server resources until the backlog is exhausted, denying service to legitimate clients. This is a classic volumetric denial-of-service technique at Layer 4.

Exam trap

The trap here is assuming any flood of packets is a generic DoS without checking the TCP flags and handshake state, which specifically identify a SYN flood.

596
MCQeasy

Which OSI layer is targeted by a TCP SYN flood attack?

A.Layer 7 - Application
B.Layer 4 - Transport
C.Layer 3 - Network
D.Layer 2 - Data Link
AnswerB

TCP operates at Layer 4, where SYN floods exhaust the connection table by sending numerous half-open handshakes. The attack targets the transport-layer three-way handshake mechanism itself, so Layer 4 is the precise target rather than the application payload or network routing.

Why this answer

A TCP SYN flood attack targets the Transport layer (Layer 4) because it exploits the TCP three-way handshake mechanism. The attacker sends a high volume of SYN packets with spoofed source IP addresses, causing the server to allocate resources for half-open connections that never complete, exhausting its connection queue.

Exam trap

Cisco often tests the distinction between the layer where the vulnerability exists (Layer 4, TCP) versus the layer where the packet is encapsulated (Layer 3, IP), leading candidates to mistakenly choose Layer 3 because the attack uses IP packets.

How to eliminate wrong answers

Option A is wrong because Layer 7 (Application) deals with application protocols like HTTP, FTP, and DNS; a SYN flood does not involve application-layer payloads or logic. Option C is wrong because Layer 3 (Network) handles IP routing and addressing; while the attack uses IP packets, the vulnerability lies in the TCP handshake at Layer 4. Option D is wrong because Layer 2 (Data Link) manages MAC addresses and frame delivery on a local network segment; a SYN flood operates above this layer, targeting TCP state management.

597
MCQmedium

A security analyst is investigating a potential data breach. They need to preserve evidence for legal proceedings. Which action should the analyst take to ensure the integrity of the data?

A.Run antivirus scans on the affected system
B.Use a write blocker when creating a forensic image
C.Delete suspicious files to contain the threat
D.Copy files to a network share without write protection
AnswerB

A write blocker enforces a hardware or software read-only mount, preventing any modification to the source drive during imaging. This preserves bit-for-bit integrity and maintains the chain of custody, satisfying the legal requirement that evidence remain unaltered and admissible in proceedings.

Why this answer

A write blocker is a hardware or software tool that prevents any write operations to the storage device while a forensic image is being created, preserving the original evidence and ensuring the image is a bit-for-bit copy. This maintains the integrity and admissibility of evidence in legal proceedings.

Exam trap

The trap is thinking that any copy of data is sufficient for forensics; candidates underestimate how even read operations can alter metadata, and they may choose antivirus scanning or deletion as 'containment' steps that actually destroy evidence.

How to eliminate wrong answers

Option A is wrong because running antivirus scans modifies file metadata and potentially quarantines files, altering the evidence. Option C is wrong because deleting suspicious files destroys evidence and violates chain-of-custody requirements. Option D is wrong because copying files to a network share without write protection can modify timestamps and data, and does not produce a forensically sound image.

598
Multi-Selectmedium

A security analyst is reviewing logs to identify a potential brute force attack. Which TWO log entries would be most suspicious? (Choose TWO.)

Select 2 answers
A.Successful login from IP 10.0.0.9 after 50 failed attempts.
B.A single successful login from a known IP during business hours.
C.A failed login attempt from an external IP at 3:00 AM.
D.50 failed login attempts from IP 10.0.0.9 within 2 minutes.
E.A user changing their password after a successful login.
AnswersA, D

Fifty failed attempts followed by a success from the same IP indicates the attacker eventually guessed valid credentials, confirming a successful brute force. The preceding failures supply the attack signature, while the success shows compromise, making this entry highly suspicious.

Why this answer

Option A is correct because a successful login immediately following 50 failed attempts from the same IP (10.0.0.9) indicates a probable successful brute force or password-guessing attack, where the attacker eventually guessed valid credentials. Option D is correct because 50 failed login attempts from a single IP (10.0.0.9) within only 2 minutes is a classic high-rate authentication failure pattern consistent with automated brute force tools. Option B is not suspicious because a single successful login from a known IP during business hours matches normal, expected user behavior.

Option C is not suspicious on its own because a single failed login from an external IP at 3:00 AM could simply be a mistyped password or a legitimate off-hours attempt, lacking the volume or repetition of brute force. Option E is not suspicious because changing a password after a successful login is a routine, legitimate user action.

Exam trap

Cisco often tests the distinction between a single failed login and a pattern of repeated failures, tricking candidates into thinking any failed login is suspicious, when in fact only a high volume of failures from the same source indicates a brute force attempt.

599
MCQmedium

A security analyst is investigating a potential data exfiltration incident. The analyst notices that a large amount of data has been sent to an external IP address over port 443 during non-business hours. The company uses a proxy server that logs all outbound connections. Which action should the analyst take first to validate the suspicion?

A.Immediately block the external IP address at the firewall.
B.Run a packet capture on the internal server to analyze the payload.
C.Check the proxy logs to see the destination IP and user agent string.
D.Notify the security team lead and wait for further instructions.
AnswerC

The proxy already logs every outbound connection, so reviewing those records confirms the destination IP, timing, and user agent string associated with the port 443 traffic. This validates the exfiltration suspicion before deeper endpoint or packet analysis.

Why this answer

Proxy logs contain the destination IP and user agent string, which are critical for validating whether the external IP is legitimate or malicious. By checking these logs first, the analyst can correlate the outbound connection with known threat intelligence or anomalous user agents without disrupting operations or consuming resources on unnecessary packet captures.

Exam trap

Cisco often tests the candidate's ability to prioritize log analysis over reactive actions, and the trap here is that candidates may jump to blocking the IP (Option A) or escalating (Option D) without first using available logs to validate the suspicion.

How to eliminate wrong answers

Option A is wrong because immediately blocking the external IP at the firewall could disrupt legitimate business traffic if the IP is later found to be benign, and it bypasses the validation step needed to confirm exfiltration. Option B is wrong because running a packet capture on the internal server is resource-intensive and may not be feasible if the server is remote or the traffic is already encrypted over TLS (port 443), making payload analysis ineffective without decryption keys. Option D is wrong because notifying the security team lead and waiting for further instructions delays the investigation and violates the principle of first validating the suspicion with available logs before escalating.

600
MCQmedium

An analyst is investigating a PCAP file and wants to reconstruct a conversation between two hosts. Which Wireshark filter would be most appropriate to follow the entire TCP stream?

A.tcp.stream eq 0
B.dns.qry.name
C.ip.addr == 10.0.0.1
D.http.request
AnswerA

`tcp.stream eq 0` isolates every packet belonging to stream index 0, letting Wireshark reassemble the full bidirectional conversation regardless of ports or IP addresses. This satisfies the stem's requirement to follow the entire TCP stream, since stream indexing groups related segments that Follow TCP Stream also relies on.

Why this answer

The filter 'tcp.stream eq 0' is used in Wireshark to follow a specific TCP stream. When you right-click on a packet and select 'Follow TCP Stream', Wireshark automatically applies this filter with the appropriate stream index. This filter displays all packets belonging to that particular TCP conversation, allowing the analyst to reconstruct the entire session between the two hosts.

Other filters like 'ip.addr' show all traffic to/from an IP, which may include multiple streams, and 'http.request' only shows HTTP requests, not the full stream.

Exam trap

200-201 often tests Wireshark filter syntax and the difference between filtering by IP, protocol, and stream. Candidates might choose 'ip.addr' thinking it shows a conversation, but it includes all traffic to/from that IP, not just one TCP stream.

How to eliminate wrong answers

Option B is wrong because 'dns.qry.name' filters DNS query names, which is unrelated to reconstructing a TCP stream; it would only show DNS traffic. Option C is wrong because 'ip.addr == 10.0.0.1' filters all traffic involving that IP address, which could include multiple TCP streams, UDP, ICMP, etc., and does not isolate a single conversation. Option D is wrong because 'http.request' filters only HTTP request packets, missing responses and other parts of the TCP stream, so it cannot reconstruct the full conversation.

Page 7

Page 8 of 13

Page 9