Courseiva

CCNA Network Intrusion Analysis Questions

75 of 122 questions · Page 1/2 · Network Intrusion Analysis · Answers revealed

1
MCQeasy

An analyst detects HTTPS traffic to a domain that was registered only 24 hours ago and has no web content. The traffic occurs at odd hours and with consistent packet sizes. What technique is likely being used for C2?

A.DNS tunneling
B.HTTPS beaconing to a malicious domain
C.HTTP POST exfiltration
D.Domain Generation Algorithm (DGA)
AnswerB

HTTPS to a suspicious domain is common C2.

Why this answer

Attackers often use newly registered domains (DGAs or manually registered) for C2 to avoid blacklists. HTTPS provides encryption to hide the beaconing.

2
Multi-Selectmedium

A SOC analyst is investigating a suspected network intrusion and reviews NetFlow records. The analyst observes a sudden increase in outbound traffic from a single internal host to an external IP address, with large data volumes during off-hours. Which two additional indicators should the analyst examine to confirm data exfiltration? (Choose two.)

Select 2 answers
A.The duration and consistency of the outbound flow to the external IP
B.The number of distinct destination ports contacted by the internal host
C.The number of failed login attempts on the internal host
D.The ratio of outbound bytes to inbound bytes for the host
E.The presence of repeated DNS queries to known benign domains
AnswersA, D

Sustained, consistent outbound flows to the same external IP over an extended period suggest an automated transfer of data. Combined with large volumes during off-hours, this pattern supports exfiltration rather than normal user activity. Analyzing flow duration and consistency helps distinguish a deliberate data transfer from sporadic or interactive traffic.

Why this answer

To confirm exfiltration from flow records, the analyst should look at the outbound-to-inbound byte ratio and the duration and consistency of the outbound flow. A high ratio and a sustained, consistent transfer to the same external IP, especially during off-hours, strongly support data exfiltration. Port counts, benign DNS queries, and failed logins are less directly related to confirming outbound data theft.

Exam trap

The trap here is focusing on port-based or authentication indicators instead of the volume and directionality of data, which are the key flow characteristics for confirming exfiltration.

3
MCQmedium

Which of the following is a common indicator of DNS tunneling used for exfiltration?

A.DNS queries with long subdomain strings
B.Frequent DNS queries to known domains
C.DNS responses with large payloads
D.DNS queries using TCP instead of UDP
AnswerA

DNS tunnelling encodes stolen data into subdomain labels, so queries carrying long, high-entropy subdomain strings that exceed normal hostname lengths are a hallmark indicator. This satisfies the stem's requirement for a common exfiltration indicator, since legitimate DNS lookups rarely use such extended labels.

Why this answer

DNS tunneling exploits the DNS protocol to encapsulate non-DNS data within DNS queries and responses. A common indicator is DNS queries with unusually long subdomain strings, as attackers encode exfiltrated data into the query name to bypass network security controls.

Exam trap

Cisco often tests the distinction between a general anomaly (like large DNS responses) and a specific tunneling indicator (long subdomain strings), where candidates mistakenly focus on response size or protocol choice rather than the query structure.

How to eliminate wrong answers

Option B is wrong because frequent DNS queries to known domains are typical of legitimate client behavior (e.g., CDN lookups) and not a specific sign of tunneling. Option C is wrong because while DNS responses can carry large payloads in tunneling, the primary indicator is the query side; moreover, standard DNS responses are limited to 512 bytes (or up to 4096 bytes with EDNS0), so large responses alone are not definitive. Option D is wrong because DNS queries normally use UDP, but tunneling can use TCP for reliability; however, TCP usage is not a common indicator because many legitimate operations (e.g., zone transfers) also use TCP.

4
MCQmedium

A SOC analyst is reviewing a packet capture from an internal web server and notices that a single external IP sent 4,000 TCP segments with the ACK flag set to a closed port, and each segment received a RST response. No SYN packets preceded these segments. Which type of scan is this host most likely performing?

A.UDP port sweep
B.TCP ACK scan
C.TCP SYN stealth scan
D.TCP FIN scan
AnswerB

An ACK scan sends packets with only the ACK flag set to map firewall rule sets and determine whether ports are filtered or unfiltered. Because the target responds with RST to both open and closed ports, the scanner learns filtering behavior rather than port state. The absence of a preceding SYN and the flood of ACK segments to a closed port match this technique exactly.

Why this answer

The scanner sent only ACK-flagged TCP segments to a closed port and received RST replies, which is the signature of an ACK scan used to probe firewall filtering rather than open services. A SYN scan would require an initial SYN, a FIN scan would use the FIN flag, and a UDP sweep would not produce TCP RST responses. The pattern uniquely identifies an ACK scan.

Exam trap

The trap here is assuming any scan that receives RST responses is a SYN scan, when the flag combination and absence of a handshake determine the actual scan type.

5
Multi-Selecthard

An analyst is triaging a suspected FTP brute-force campaign against an internal server. The IDS reports many failed authentication attempts from a single external address. Which TWO data points, gathered from the FTP server and network logs, most directly support confirming and characterizing the attack? (Choose two.)

Select 2 answers
A.The average size of files previously transferred by legitimate users of the FTP service.
B.Count of distinct usernames attempted and the number of failed 530 responses per source IP over time.
C.The server's TLS certificate expiration date for FTPS connections.
D.The server's operating system patch level for the FTP daemon.
E.Timestamps of successful logins from the same source IP immediately following the failures.
AnswersB, E

Tracking distinct usernames alongside failed authentication response codes per source IP reveals whether the source is spraying many accounts or hammering one, and the rate over time distinguishes brute force from occasional user error. This directly characterizes the campaign's scope and supports blocking or rate-limiting decisions. It is the core evidence that confirms the activity is systematic rather than incidental.

Why this answer

Confirming and characterizing an FTP brute-force campaign depends on authentication telemetry: the number of distinct usernames and failed response codes per source IP shows the attack's shape and rate, while a successful login from the same source after repeated failures confirms compromise. Certificate expiry, historical transfer sizes, and daemon patch level describe configuration or baseline behavior and cannot establish whether the attack occurred or succeeded.

Exam trap

The trap here is selecting configuration or baseline metrics such as patch level or average file size, which feel relevant to server security but do not actually confirm or measure the authentication attack.

6
MCQeasy

A security analyst is investigating an alert that indicates a potential SQL injection attack. Which of the following HTTP request patterns is most indicative of a SQL injection attempt?

A.GET /login?user=admin&pass=password123
B.GET /search?q=<script>alert('XSS')</script>
C.GET /products?id=1 UNION SELECT * FROM users
D.GET /index.html HTTP/1.1
AnswerC

The UNION SELECT payload is injected directly into the id parameter, attempting to append rows from the users table to the query result. This satisfies the SQL injection indicator, unlike plain numeric values or encoded characters that carry no SQL syntax.

Why this answer

The UNION SELECT payload is the classic SQL injection signature: it appends a second SELECT statement to the original query, allowing the attacker to retrieve data from other tables such as 'users'. The presence of SQL keywords (UNION, SELECT, FROM) inside a URL parameter that should only contain a numeric ID is a strong indicator of SQLi. This pattern targets the backend database directly, unlike script tags which target the browser.

Exam trap

The trap here is confusing SQL injection with XSS — both inject code into input fields, but SQLi targets the database with SQL syntax while XSS targets the browser with script tags; candidates who see '<script>' often reflexively pick it.

How to eliminate wrong answers

Option A is wrong because it is a normal login request with plaintext credentials in the query string — suspicious for using GET, but not an injection pattern. Option B is wrong because '<script>alert('XSS')</script>' is a cross-site scripting (XSS) payload, not SQL injection; it targets the client browser, not the database. Option D is wrong because it is a benign static file request for index.html with no parameters and no injection vector.

7
Multi-Selectmedium

An analyst identifies a series of SMB authentication attempts from a compromised host to multiple internal servers. The authentication uses NTLM hashes. Which TWO techniques are most likely being used for lateral movement? (Select 2)

Select 2 answers
A.Kerberoasting
B.SMB relay
C.Brute force
D.Golden ticket
E.Pass-the-hash
AnswersB, E

Relays authentication to other hosts.

Why this answer

SMB relay (B) is correct because the attacker can intercept NTLM authentication attempts from the compromised host and relay them to other internal servers, gaining unauthorized access without needing to crack the hash. This technique leverages the SMB protocol's lack of channel binding in older implementations, allowing the relayed hash to authenticate to multiple targets.

Exam trap

Cisco often tests the distinction between 'pass-the-hash' (reusing a hash directly from the compromised host) and 'SMB relay' (forwarding the authentication challenge to another server), which candidates confuse as the same technique.

8
MCQmedium

An IDS alert indicates that a server received HTTP requests containing long strings of the form ../../../../etc/passwd in a URL parameter. The web server returned HTTP 200 responses to these requests. Which conclusion should the analyst draw while continuing the investigation?

A.The alert is a false positive because directory traversal cannot appear in URL parameters.
B.The server is confirmed compromised because directory traversal strings were sent and accepted.
C.The requests warrant deeper inspection of response bodies and server file access logs to determine whether traversal succeeded.
D.The activity is normal because web browsers routinely send relative path characters in requests.
AnswerC

The traversal attempt is a strong indicator, but the HTTP 200 alone does not establish success. Reviewing whether the response body contained file contents, and checking web server or file system access logs for reads of sensitive paths, determines whether the attack actually worked. This evidence-driven step correctly separates an attempt from a confirmed breach and guides containment decisions.

Why this answer

A traversal attempt returning HTTP 200 is suspicious but not conclusive, because the status code reflects request handling rather than file disclosure. Confirmation requires examining response bodies for sensitive file contents and correlating with server-side file access logs. The other choices either overstate the evidence as confirmed compromise, wrongly dismiss the alert, or mischaracterize traversal strings as normal browser behavior.

Exam trap

The trap here is equating an HTTP 200 response with successful exploitation, when the status code only shows the request was processed and not that sensitive data was exposed.

9
MCQmedium

Which Wireshark filter can be used to extract the full TCP data of a specific conversation from a PCAP?

A.tcp.stream
B.tcp.port
C.http.request
D.ip.addr
AnswerA

tcp.stream isolates one complete TCP conversation by its stream index, letting you follow and export all payload bytes for that specific session. This satisfies the requirement to extract the full TCP data of a single conversation rather than filtering individual packets by port or address.

Why this answer

The `tcp.stream` filter in Wireshark isolates a single TCP conversation by its stream index, allowing analysts to follow the entire bidirectional flow of that session. Once filtered, you can right-click and select Follow > TCP Stream to extract the full payload. This is the standard method for reconstructing application-layer data from a specific conversation in a PCAP.

Exam trap

200-201 often tests the confusion between filtering by port/IP (which can match multiple conversations) and using `tcp.stream` to isolate one specific conversation.

How to eliminate wrong answers

Option B is wrong because `tcp.port` filters by port number and may match multiple unrelated conversations sharing that port, not a single specific conversation. Option C is wrong because `http.request` only shows HTTP request packets, missing responses and non-HTTP TCP data in the conversation. Option D is wrong because `ip.addr` filters by IP address and can include multiple TCP streams between the same hosts, not isolating one conversation.

10
Multi-Selectmedium

An analyst is examining a PCAP file for signs of lateral movement. Which TWO of the following are typical indicators of lateral movement using pass-the-hash?

Select 2 answers
A.Multiple SMB authentication attempts from a single host to multiple other hosts
B.HTTP requests to a web server
C.ICMP timestamp requests
D.Large file transfers using FTP
E.Use of NTLM authentication without a password, only the hash
AnswersA, E

Pass-the-hash lateral movement produces a fan-out pattern: one compromised host authenticating via SMB to many targets in quick succession. This satisfies the stem's requirement for a typical indicator, since legitimate users rarely generate such broad single-source SMB authentication bursts.

Why this answer

Option A is correct because pass-the-hash lateral movement typically manifests as a single compromised host authenticating over SMB (TCP 445) to numerous other hosts in rapid succession, as the attacker reuses the stolen hash to pivot across the network. Option E is correct because the defining characteristic of pass-the-hash is that NTLM authentication succeeds using only the captured NTLM hash (via tools like Mimikatz or Impacket's psexec/smbexec) without ever knowing or supplying the plaintext password. Option B is not a pass-the-hash indicator, since HTTP requests to a web server reflect normal web traffic rather than NTLM-based host-to-host authentication.

Option C is unrelated, as ICMP timestamp requests are diagnostic network probes and not part of the NTLM/SMB authentication process. Option D is also unrelated, because FTP file transfers use a separate cleartext protocol and do not demonstrate hash-based credential reuse.

Exam trap

The trap is that candidates pick generic 'suspicious' traffic like large file transfers or Kerberos requests, missing that pass-the-hash has a very specific signature: NTLM authentication with hash material and SMB fan-out from one host to many.

11
MCQeasy

During network intrusion analysis, an analyst reviews logs and observes an alert for a TCP SYN scan. Which characteristic of a SYN scan would the analyst look for in packet captures?

A.The scan sends SYN packets and expects ICMP unreachable messages for open ports.
B.The scan sends SYN packets and waits for a timeout on closed ports.
C.The scan sends SYN packets and, upon receiving SYN-ACK, sends RST packets.
D.The scan sends SYN packets and completes the three-way handshake for open ports.
AnswerC

A SYN scan probes ports by sending SYN packets; receiving SYN-ACK proves the port is open, and the scanner immediately sends RST to tear down the half-open connection rather than completing the handshake. That SYN-then-RST pattern distinguishes it from a full connect scan.

Why this answer

A SYN scan sends a SYN packet and, upon receiving a SYN-ACK from the target, responds with a RST instead of completing the handshake. This avoids a full connection and is stealthier.

12
MCQeasy

In network forensics, which Wireshark filter would be used to reconstruct a TCP conversation between two hosts?

A.ip.addr
B.http.request
C.tcp.stream eq 0
D.dns.qry.name
AnswerC

The tcp.stream eq 0 filter isolates a single reassembled TCP conversation by its stream index, letting the analyst follow the full exchange between the two hosts. Following the stream reconstructs the session payload for forensic review.

Why this answer

The filter `tcp.stream eq 0` isolates all packets belonging to a specific TCP stream, identified by Wireshark's internal stream index. This allows you to reconstruct the full conversation between two hosts, including the three-way handshake, data transfer, and teardown. It is the standard method for following a TCP stream in Wireshark, as it groups packets by connection rather than just IP addresses or ports.

Exam trap

The trap here is confusing IP-based filtering with stream-based filtering; candidates might think that filtering by IP address is sufficient to reconstruct a conversation, but it fails to separate multiple connections between the same hosts.

How to eliminate wrong answers

Option A is wrong because `ip.addr` filters packets by IP address but does not distinguish between multiple TCP connections between the same hosts, so it cannot isolate a single conversation. Option B is wrong because `http.request` only displays HTTP request packets, missing responses and other TCP segments, and is not specific to a single TCP stream. Option D is wrong because `dns.qry.name` filters DNS query names, which is unrelated to TCP stream reconstruction.

13
MCQmedium

An analyst is reviewing PCAP and sees a TCP stream with a Wireshark filter 'tcp.stream eq 0'. The conversation shows an interactive shell session with commands like 'whoami' and 'ls'. This is most likely evidence of what?

A.DNS tunneling
B.Reverse shell
C.SQL injection
D.ARP spoofing
AnswerB

An interactive shell where the remote host executes commands such as whoami and ls indicates the attacker's machine is receiving a session from the victim, the defining pattern of a reverse shell. The victim initiated the outbound connection, evading inbound firewall rules.

Why this answer

The PCAP shows an interactive shell session with commands like 'whoami' and 'ls' over TCP. This is characteristic of a reverse shell, where an attacker compromises a host and establishes a command-and-control channel back to their machine, allowing interactive command execution. The use of 'tcp.stream eq 0' in Wireshark simply isolates a specific TCP conversation, and the presence of shell commands confirms a reverse shell.

Exam trap

The trap here is confusing an interactive shell session with other types of attacks that also involve network traffic, such as DNS tunneling or SQL injection, because candidates may not recognize the specific commands and the nature of a reverse shell.

How to eliminate wrong answers

Option A is wrong because DNS tunneling involves encoding data within DNS queries and responses, typically using TXT or NULL records, and would not show interactive shell commands like 'whoami' and 'ls' in a TCP stream. Option C is wrong because SQL injection is an attack against database-driven applications, where malicious SQL statements are inserted into input fields; it would not produce an interactive shell session in a PCAP. Option D is wrong because ARP spoofing is a layer 2 attack that manipulates ARP tables to intercept traffic, and it does not involve an interactive shell session with commands.

14
MCQeasy

An analyst is investigating a potential DNS tunneling attack. Which characteristic in DNS traffic would most likely indicate DNS tunneling?

A.DNS queries with long, random-looking subdomains to a single domain.
B.Frequent DNS queries to the same domain at regular intervals.
C.DNS queries for domains that are known to be malicious.
D.DNS query responses with unusually large payload sizes.
AnswerA

Long, random-looking subdomains encode exfiltrated data or command payloads, since DNS labels carry limited bytes per query. Repeated queries to one domain, rather than many domains, match tunnelling's need for a stable server endpoint. This pattern satisfies the stem's requirement for a characteristic distinguishing tunnelling from ordinary DNS resolution.

Why this answer

DNS tunneling encodes data (e.g., stolen files, C2 commands) into the query name itself, so the attacker generates long, high-entropy subdomains like 'a8f3k2...exfil.attacker.com' under a single controlled domain. The randomness defeats signature-based detection, and the length maximizes the bytes smuggled per query. This pattern — many unique, long, random labels pointing to one authoritative domain — is the hallmark of tools such as iodine, dnscat2, and DNSExfiltrator.

Exam trap

200-201 often tests the confusion between DNS tunneling (data hidden in long, random query names) and DNS beaconing (regular-interval check-ins) or DNS amplification (large responses), so candidates who pick 'large payload' or 'regular intervals' miss the specific structural signature of tunneling.

How to eliminate wrong answers

Option B is wrong because regular-interval queries to the same domain describe beaconing or normal polling (e.g., NTP-style checks, CDN heartbeats, or malware check-ins), not tunneling — tunneling requires variable, data-bearing query names, not fixed timing. Option C is wrong because a known-malicious domain indicates a blocklist hit or IOC match, which is threat-intel detection, not a structural tunneling characteristic; a tunnel can run over a never-before-seen domain. Option D is wrong because large response payloads point to DNS amplification or oversized TXT/ANY records, whereas tunneling typically shows large *query* names and many small responses — response size alone is a weaker, less specific indicator.

15
MCQeasy

In a PCAP analysis, an analyst uses the filter 'http.request.uri contains "UNION"' and finds multiple HTTP requests with 'SELECT' and 'UNION SELECT' in the URI parameter. Which type of attack is likely occurring?

A.SQL injection
B.Buffer overflow
C.Cross-site scripting
D.Command injection
AnswerA

The 'UNION SELECT' string in URI parameters is a classic SQL injection signature, used to append attacker-controlled queries onto a legitimate database statement. Its presence across multiple HTTP requests confirms attempts to manipulate backend SQL through unsanitised input.

Why this answer

The filter 'http.request.uri contains "UNION"' detects HTTP requests where the URI contains the SQL keyword 'UNION'. The presence of 'SELECT' and 'UNION SELECT' in URI parameters is a classic signature of SQL injection (SQLi), where an attacker attempts to manipulate backend database queries by injecting SQL code into input fields. This attack targets the database layer, aiming to extract or modify data, and is distinct from other web vulnerabilities.

Exam trap

The trap here is confusing SQL injection with command injection or XSS, as all involve injecting malicious input; candidates must recognize that 'UNION SELECT' is specific to SQL, not OS commands or client-side scripts.

How to eliminate wrong answers

Option B is wrong because buffer overflow involves overwriting memory buffers with excessive data, typically indicated by crashes or memory corruption, not SQL keywords in HTTP requests. Option C is wrong because cross-site scripting (XSS) injects client-side scripts (e.g., JavaScript) into web pages viewed by other users, not SQL commands in the URI. Option D is wrong because command injection targets operating system commands, often using shell metacharacters (e.g., ;, |, &&) to execute system commands, not SQL syntax like 'UNION SELECT'.

16
MCQhard

An analyst is reviewing a PCAP and observes a TCP stream where the client sends a packet with the PSH and ACK flags set, containing an HTTP GET request. The server responds with a packet with the FIN and ACK flags set, but the client continues to send data. Later, the client sends a packet with the RST flag set. Which statement best describes what is happening?

A.The server is initiating a graceful connection termination, but the client is ignoring it and continuing to send data, eventually forcing a reset.
B.The client is using TCP fast open, which allows data transmission after the server sends FIN.
C.The server is experiencing a denial-of-service condition because the client is flooding it with data after the FIN.
D.The client is performing a TCP reset attack to terminate the connection prematurely.
AnswerA

The server sends FIN+ACK to start a graceful close, meaning it has no more data to send. The client, however, continues to transmit data, which is a violation of TCP half-close semantics. Eventually, the client sends an RST, abruptly terminating the connection. This could indicate a malfunctioning client or an attempt to disrupt the session.

Why this answer

The server's FIN+ACK indicates it wants to close its half of the connection. The client should respond with a FIN and stop sending data. Instead, the client continues to send data, which is a TCP protocol violation.

The eventual RST from the client abruptly terminates the connection. This behavior could be due to a buggy application, a misconfigured client, or a deliberate attempt to cause a reset.

Exam trap

The trap here is interpreting the RST as a separate attack, when it is actually the client's response to the server's FIN after ignoring it and continuing to send data.

17
MCQhard

An analyst is examining a PCAP and sees a series of TCP packets where the client sends a SYN, receives a SYN-ACK, and then sends an ACK. Immediately after, the client sends a packet with the RST flag set, terminating the connection before any application data is exchanged. This pattern repeats across many destination ports on the same server. Which activity does this most likely represent?

A.TCP SYN scan
B.TCP ACK scan
C.TCP connect scan
D.TCP FIN scan
AnswerC

A TCP connect scan completes the full three-way handshake for each port and then immediately sends an RST to tear down the connection. This matches the observed SYN, SYN-ACK, ACK, and RST sequence. It is used when the scanner does not have raw packet privileges and relies on the OS connect() call.

Why this answer

The full three-way handshake followed by an immediate RST indicates a TCP connect scan. This scan type uses the operating system's connect() function to establish a complete TCP connection, then resets it. It is less stealthy than a SYN scan because it generates more logs on the target, but it works without raw socket privileges.

Exam trap

The trap here is assuming that any scan with an RST is a SYN scan, but a SYN scan never completes the handshake, whereas a connect scan does.

18
MCQeasy

During an intrusion investigation, an analyst needs to determine whether a specific internal host communicated with a known malicious IP address. The analyst has full packet capture for the relevant window but only wants to see the TCP stream from that host to the suspect address. Which Wireshark display filter isolates that conversation?

A.ip.addr == 10.10.5.20 && ip.addr == 203.0.113.77
B.ip.src == 10.10.5.20 && ip.dst == 203.0.113.77
C.ip.addr == 10.10.5.20 || ip.addr == 203.0.113.77
D.tcp.port == 445 && ip.addr == 10.10.5.20
AnswerA

Using ip.addr twice with the AND operator matches packets where either field equals the first address and either field equals the second, effectively isolating bidirectional traffic between the two hosts. This is the standard way to view a conversation regardless of direction, which is exactly what the analyst needs when the role of client and server may vary during the exchange.

Why this answer

Repeating the address field with the AND operator restricts output to packets where the two addresses appear in either direction, which captures the full bidirectional conversation. A direction-specific filter hides responses, adding a port constraint may exclude the actual traffic, and using OR broadens the result to unrelated hosts. The bidirectional address pair is the reliable way to isolate one conversation.

Exam trap

The trap here is choosing a directional filter or an OR combination, when the goal is a two-host bidirectional conversation that requires both addresses joined with AND.

19
MCQmedium

An analyst reviews network logs and sees a large outbound FTP transfer of 500 MB from a workstation to an external IP at 2:00 AM. The workstation regularly sends 10 MB daily. What should the analyst suspect?

A.C2 beaconing
B.Normal backup operation
C.Software update
D.Data exfiltration
AnswerD

A 500 MB outbound FTP transfer at 2:00 AM, vastly exceeding the workstation's normal 10 MB daily volume, indicates bulk data leaving the network. This anomalous volume and timing point to data exfiltration rather than routine activity or a benign transfer.

Why this answer

Large outbound data transfers outside normal patterns, especially at odd hours, are typical of data exfiltration.

20
MCQmedium

An analyst notices that an internal host is sending periodic ICMP echo requests to an external IP, and the echo replies contain payloads that are longer than the default Windows ping payload. The payload bytes appear to be encoded and change with each reply. Which activity is most likely occurring?

A.ICMP tunneling used for command-and-control or data transfer
B.Path MTU discovery performed by the host
C.Network latency measurement by a monitoring tool
D.Smurf attack reflection against the external host
AnswerA

ICMP tunneling hides data inside echo request and reply payloads, allowing covert communication through firewalls that permit ping. Non-default payload sizes and changing encoded bytes in replies are strong indicators that data is being exchanged, not just reachability tested. This matches the pattern of an ICMP-based covert channel.

Why this answer

Non-default ICMP payload sizes with changing encoded bytes in echo replies indicate that data is being tunneled inside ICMP, a common covert channel for command-and-control or exfiltration. Latency measurement, path MTU discovery, and Smurf attacks produce different packet characteristics and do not involve variable encoded payloads in replies.

Exam trap

The trap here is dismissing ICMP as harmless because ping is allowed, while overlooking that payload size and content, not the protocol itself, reveal the tunnel.

21
MCQeasy

During alert triage, an analyst determines that an alert fired but no actual attack or malicious activity occurred on the network. How should this alert be classified?

A.True negative
B.False negative
C.True positive
D.False positive
AnswerD

A false positive is an alert that fires without any genuine malicious activity, exactly matching the scenario where triage confirms no attack occurred. The classification axis here is whether the detected event reflects real threat activity: benign or expected behaviour triggering detection logic is a false positive, distinct from a true positive.

Why this answer

A false positive occurs when an alert fires but no actual malicious activity is present. The analyst determined that no attack occurred, so the alert is a false positive. This is a common occurrence in security operations and requires tuning of detection rules to reduce noise.

Exam trap

200-201 often tests the definitions of true/false positives/negatives. Candidates may confuse false positive with true negative, but the key is that an alert fired (so not negative) and no attack occurred (so false).

How to eliminate wrong answers

Option A is wrong because a true negative is when no alert fires and no malicious activity occurs, which is the correct benign state. Option B is wrong because a false negative is when malicious activity occurs but no alert fires, which is a dangerous miss. Option C is wrong because a true positive is when an alert fires and malicious activity is confirmed, which is not the case here.

22
MCQhard

An alert shows a high volume of outbound traffic from an internal host to an external IP using FTP. The data includes files with names matching internal document names. This activity is most likely:

A.C2 beaconing
B.Normal backup operation
C.Port scanning
D.Data exfiltration
AnswerD

FTP transfers of internal document names to an external IP indicate unauthorised data movement off the network. The high outbound volume, external destination and sensitive file naming together satisfy the exfiltration pattern rather than normal FTP use or scanning.

Why this answer

The scenario describes an internal host sending a high volume of outbound FTP traffic to an external IP, with file names matching internal document names. This pattern is characteristic of data exfiltration, where an attacker steals sensitive data by transferring it to an external command-and-control (C2) or staging server. FTP is commonly used because it is a standard protocol that may not be blocked, and the file names indicate the data is likely proprietary or confidential.

The volume and direction (outbound) further support exfiltration rather than normal backup or scanning.

Exam trap

The trap here is confusing high-volume outbound traffic with benign activities like backups or C2, when the key indicators are the external destination and the sensitive file names, which point to exfiltration.

How to eliminate wrong answers

Option A is wrong because C2 beaconing typically involves small, periodic connections (often HTTP/HTTPS or DNS) to maintain control, not high-volume FTP transfers of document files. Option B is wrong because normal backup operations usually go to internal servers or authorized cloud storage, not to arbitrary external IPs, and would not use FTP with internal document names in this suspicious context. Option C is wrong because port scanning involves probing multiple ports on a target, not transferring large files outbound.

23
MCQhard

An analyst examining a PCAP sees a host send an HTTP GET request where the User-Agent string contains a long, random-looking hexadecimal value, the request path includes a similarly random string, and the server responds with a 404 status code but a response body of several kilobytes. This pattern repeats every 60 seconds. Which activity is most likely occurring?

A.Command-and-control beaconing over HTTP with data hidden in request and response fields
B.A content delivery network serving cached assets to a browser with a corrupted user agent
C.A misconfigured application retrying a failed API call with exponential backoff
D.An automated vulnerability scanner fuzzing the web application
AnswerA

A fixed 60-second interval, random-looking identifiers in the User-Agent and URI, and a large response body despite a 404 status are classic HTTP beaconing with covert channel encoding. Legitimate clients do not send random hex in these fields, and a true 404 would not carry kilobytes of meaningful content. The implant is polling for instructions and receiving tasking data disguised as an error page.

Why this answer

The fixed 60-second cadence, random hex identifiers in both the User-Agent and URI, and a substantial response body paired with a 404 status together indicate HTTP-based command-and-control. Implants poll at set intervals for tasking, encode session identifiers to evade signatures, and hide instructions in what appears to be an error response. Normal CDN traffic, vulnerability scanning, and backoff retries all produce different timing, field content, and response characteristics.

Exam trap

The trap here is dismissing the traffic because of the 404 status, when attackers deliberately return error codes while smuggling data in the response body.

24
Multi-Selecthard

A SOC analyst is investigating a suspected ARP poisoning attack on a local subnet. Which two indicators would most strongly support this conclusion? (Choose two.)

Select 2 answers
A.A high rate of unsolicited ARP replies on the subnet
B.An increase in TCP retransmissions across the subnet
C.Multiple IP addresses mapping to the same MAC address in the ARP cache
D.Duplicate IP address conflict messages in system logs
E.A sudden increase in DNS query volume from a single host
AnswersA, C

Legitimate ARP is request-driven, so a flood of unsolicited ARP replies, especially gratuitous ones claiming an IP already in use, indicates an attacker updating victims' caches. This behavior is characteristic of ARP poisoning tools that continuously send forged replies. Detecting a high rate of unsolicited replies is a reliable network-level indicator.

Why this answer

ARP poisoning is confirmed by layer-2 evidence: multiple IP addresses resolving to one MAC address in the ARP cache, and a high volume of unsolicited ARP replies. DNS query spikes, duplicate IP conflict messages, and TCP retransmissions may accompany network problems but are not specific to forged ARP activity, so they do not strongly support the conclusion.

Exam trap

The trap here is choosing generic connectivity symptoms such as retransmissions or DNS spikes instead of the ARP-specific evidence that directly shows cache manipulation.

25
MCQmedium

An analyst is reviewing alerts from an IDS. A signature matched 'script' and 'alert' in HTTP request parameters. The analyst inspects the packet and sees <script>alert('XSS')</script> in the URI. What is the most accurate classification of this alert?

A.False negative
B.False positive
C.True negative
D.True positive
AnswerD

The signature correctly matched genuine XSS payload characters in the URI, and inspection confirms an actual attack attempt rather than benign traffic. A true positive means the IDS alerted on real malicious activity, satisfying the stem's requirement for accurate classification of the confirmed script injection.

Why this answer

The alert corresponds to a real attack (cross-site scripting) in the traffic, so it is a true positive.

26
MCQeasy

While reviewing firewall logs, an analyst notices repeated inbound connections from a single external IP to multiple internal hosts on TCP port 3389 within a short time window. Each connection lasts only a few seconds and is followed by a new connection to a different internal host. Which activity does this pattern most likely represent?

A.A load balancer health check against RDP servers
B.A vulnerability scan of internal RDP services
C.An administrator using Remote Desktop to manage multiple servers
D.A backup application replicating data over RDP
AnswerB

Short-lived connections to TCP port 3389 across many internal hosts in rapid succession match a scan probing for reachable RDP services. Scanners often open and close sessions quickly to test responsiveness rather than complete authentication. The fan-out to multiple hosts from one external source reinforces scanning behavior, so this pattern indicates reconnaissance against RDP endpoints rather than any legitimate administrative session.

Why this answer

One external source rapidly opening short-lived TCP/3389 sessions to many internal hosts is characteristic of scanning for exposed RDP services. Legitimate RDP administration uses longer authenticated sessions from internal management addresses, backups use different protocols, and health checks come from internal load balancers at regular intervals. The burst of brief, fan-out connections therefore points to reconnaissance against RDP endpoints.

Exam trap

The trap here is assuming any RDP traffic is administrative; scanning also touches port 3389 but with short, fan-out sessions.

27
MCQeasy

A junior analyst is asked to identify which log source would best confirm that an internal workstation attempted to resolve a suspicious domain shortly before an alert fired. The environment forwards DNS query logs from its recursive resolvers to the SIEM. Which action should the analyst take first?

A.Run a reverse DNS lookup on the workstation's IP address to see its registered name.
B.Query the forwarded DNS logs for the workstation's IP and the suspicious domain name.
C.Inspect the workstation's local hosts file for static entries mapping the suspicious domain.
D.Search the firewall session logs for outbound connections to the suspicious domain's IP address.
AnswerB

Because recursive resolver query logs are already forwarded to the SIEM, searching for the workstation's source IP paired with the suspicious domain directly confirms whether the host issued that lookup and when. This is the most direct and authoritative evidence of resolution attempts. It also establishes a timeline anchor that the analyst can use to pivot to proxy, firewall, and endpoint data for corroboration.

Why this answer

When recursive resolver query logs are already centralized in the SIEM, searching them for the workstation's IP and the suspicious domain is the fastest authoritative way to confirm the lookup and its timestamp. Firewall logs show IP connections rather than names, reverse lookups describe the workstation itself, and the hosts file only covers static overrides, so none of those directly answer whether the domain was resolved.

Exam trap

The trap here is pivoting to firewall or reverse-lookup data first, when the DNS query log is the only source that directly records the name the host asked to resolve.

28
Multi-Selectmedium

An analyst is investigating a suspected ARP poisoning attack on a local subnet. The analyst captures traffic and reviews ARP packets. Which two characteristics would most likely indicate that ARP poisoning is occurring? (Choose two.)

Select 2 answers
A.ARP packets with a sender MAC address that is a multicast address
B.ARP request packets with a broadcast destination MAC address
C.Multiple ARP replies from the same MAC address claiming different IP addresses
D.ARP requests sent to a unicast destination MAC address
E.Gratuitous ARP replies that are not preceded by an ARP request
AnswersC, E

In ARP poisoning, an attacker sends gratuitous ARP replies to associate their MAC address with multiple IP addresses, or to impersonate the gateway. Seeing a single MAC address claiming ownership of several IPs is a strong indicator. Legitimate hosts typically have one IP per MAC address (or a few in specific configurations), so this behavior is suspicious.

Why this answer

The correct indicators are multiple ARP replies from one MAC claiming different IPs and gratuitous ARP replies not preceded by a request. Both are hallmarks of ARP poisoning, where an attacker floods the network with forged ARP mappings to intercept traffic. Normal ARP requests are broadcast and are not malicious.

The other options describe normal or invalid but non-indicative behavior.

Exam trap

The trap here is assuming that any broadcast ARP request is malicious, when in fact broadcast requests are normal; poisoning is signaled by unsolicited replies and MAC/IP mismatches.

29
MCQeasy

A security analyst notices that an internal web server is receiving HTTP requests where the User-Agent string is identical across thousands of requests originating from a single external IP address, and each request targets a different URL path on the server. The requests occur at a rate of several hundred per second. Which activity does this pattern most likely represent?

A.Automated directory brute-forcing or content discovery
B.Web content scraping by a search engine crawler
C.Cross-site request forgery against authenticated users
D.HTTP response splitting attack
AnswerA

A single source sending hundreds of requests per second to many different URL paths with an identical User-Agent is characteristic of automated content discovery or directory brute-forcing tools. These tools enumerate paths to find hidden files or administrative interfaces. The high rate and fixed User-Agent distinguish it from normal user browsing or legitimate crawling.

Why this answer

The pattern of one external IP sending hundreds of requests per second to many different URL paths with a constant User-Agent is a classic signature of automated content discovery and directory brute-forcing. These tools enumerate paths to uncover hidden resources. Legitimate crawlers rate-limit and identify themselves, while CSRF and response splitting involve different traffic characteristics.

Exam trap

The trap here is dismissing high-volume web requests as harmless crawler traffic without checking the request rate, source diversity, and User-Agent consistency.

30
MCQmedium

During a network intrusion analysis, a security analyst observes repeated TCP SYN packets sent to a range of ports on a target host, each followed by an RST response. No subsequent ACK packets are observed. Which phase of the Cyber Kill Chain is the attacker most likely executing?

A.Reconnaissance
B.Delivery
C.Weaponization
D.Exploitation
AnswerA

SYN packets followed by RST responses, with no completed handshake, indicate a port scan probing which ports are open or closed. This information-gathering activity against the target host characterises the Reconnaissance phase of the Cyber Kill Chain.

Why this answer

Repeated TCP SYN packets to multiple ports followed by RST responses indicate a port scan, which is a hallmark of the Reconnaissance phase of the Cyber Kill Chain. The attacker is probing for open ports and services without completing the TCP handshake, which is typical of a SYN stealth scan. This activity occurs before any exploitation or delivery.

Exam trap

200-201 often tests the distinction between Reconnaissance and Exploitation. Candidates may see SYN packets and think 'attack' but must recognize that incomplete handshakes with RST responses indicate scanning, not exploitation.

How to eliminate wrong answers

Option B is wrong because Delivery involves transmitting the weaponized payload to the target (e.g., via email or USB), not scanning for open ports. Option C is wrong because Weaponization is the creation of the malware or exploit, which happens entirely on the attacker's side and is not observable in network traffic. Option D is wrong because Exploitation would involve actual attempts to leverage a vulnerability, often with completed connections or malformed packets, not just SYN probes.

31
Multi-Selectmedium

An analyst is investigating a potential malware infection. Which TWO of the following are indicators of command and control (C2) communication?

Select 2 answers
A.Large file transfers to a peer host
B.SYN scans to multiple hosts
C.Regular HTTP requests to a known update server
D.DNS queries with long, random subdomains
E.Periodic beaconing to an unusual domain
AnswersD, E

Long, random subdomains indicate DNS tunnelling, where malware encodes stolen data or instructions within query names to bypass perimeter controls. This satisfies the C2 detection requirement because the victim resolves high-entropy domains belonging to an attacker-controlled authoritative nameserver, revealing beaconing traffic that standard domain reputation filtering would miss.

Why this answer

Option D is correct because DNS queries with long, random subdomains are a classic sign of DNS tunneling or domain generation algorithm (DGA) activity used by malware to reach C2 infrastructure while evading domain reputation filtering. Option E is correct because periodic beaconing to an unusual domain reflects the regular check-in pattern malware uses to receive commands from its C2 server, often at fixed intervals with jitter. Option A is not specific to C2, as large file transfers to a peer host more commonly indicate data exfiltration or normal file sharing rather than command-and-control traffic.

Option B is not specific to C2 either, since SYN scans to multiple hosts indicate reconnaissance or port scanning activity, not an established C2 channel. Option C is not an indicator of C2 because regular HTTP requests to a known update server are typical of legitimate software update behavior.

Exam trap

The trap is confusing other malicious activities like scanning or exfiltration with C2; candidates might select options that are indicators of different attack stages.

32
MCQmedium

An analyst observes a series of DNS queries for subdomains like 'ZGVzdGluYXRpb24= .malicious.com' where the subdomain part appears base64-encoded. The volume of DNS traffic from a single host is unusually high. Which exfiltration technique is most likely in use?

A.FTP exfiltration
B.DNS tunnelling
C.HTTP POST exfiltration
D.Steganography in images
AnswerB

Encoding data into DNS query names and pushing it to an authoritative server via high-volume lookups is DNS tunnelling. The base64 subdomains and abnormal query volume from one host match covert channel exfiltration rather than normal resolution traffic.

Why this answer

The base64-encoded subdomains and high volume of DNS queries from a single host are classic indicators of DNS tunnelling, where data is exfiltrated by encoding it into DNS query names (e.g., subdomains) sent to an attacker-controlled domain. DNS is often allowed through firewalls, making it an attractive covert channel. The base64 encoding allows arbitrary binary data to be transmitted as DNS labels, and the high query volume reflects the data transfer.

Exam trap

The trap here is that candidates might see 'base64-encoded' and think of HTTP or other protocols, but the key indicator is the DNS queries themselves; DNS tunnelling specifically uses DNS as the transport, and the base64 encoding is just a way to fit data into DNS labels.

How to eliminate wrong answers

Option A is wrong because FTP exfiltration would involve outbound FTP connections (typically on ports 20/21) and would not manifest as DNS queries with encoded subdomains. Option C is wrong because HTTP POST exfiltration would generate HTTP traffic to a web server, not DNS queries; while HTTP can be used for exfiltration, the observed pattern is specific to DNS. Option D is wrong because steganography in images would involve embedding data within image files and typically transferring those images via HTTP or email, not generating DNS queries with base64-encoded subdomains.

33
MCQmedium

A SOC analyst is reviewing a PCAP captured at the perimeter firewall. The analyst notices that a single internal host has sent TCP segments with the FIN, PSH, and URG flags all set simultaneously to multiple destination ports on several external hosts. No corresponding ACK, SYN, or RST packets are observed in the capture. Which type of scan is the analyst most likely observing?

A.TCP NULL scan
B.TCP ACK scan
C.TCP Xmas scan
D.TCP SYN stealth scan
AnswerC

A TCP Xmas scan sets the FIN, PSH, and URG flags simultaneously, which makes the packet look 'lit up like a Christmas tree.' Because these flag combinations are invalid in normal TCP communication, closed ports respond with RST while open ports silently drop the packet, allowing the attacker to infer port state without completing a handshake.

Why this answer

The combination of FIN, PSH, and URG flags in a single TCP segment is the defining signature of a TCP Xmas scan. Because RFC 793 requires closed ports to respond with RST to any segment not containing SYN, and open ports to ignore such segments, attackers use this flag combination to enumerate ports without establishing a full connection and with minimal logging on the target host.

Exam trap

The trap here is assuming any unusual flag combination indicates a NULL scan, when NULL means zero flags set and Xmas specifically means FIN+PSH+URG together.

34
MCQhard

An analyst reviewing network alerts notices a rule triggered for 'ET SCAN NMAP -sU scan' based on traffic to a Linux server. The packet capture shows multiple UDP packets to various ports, and for closed ports, the server responds with ICMP Destination Unreachable (Port Unreachable). Which type of scan is being performed, and how should the analyst classify this alert?

A.TCP SYN scan; true positive
B.UDP scan; true positive
C.UDP scan; false positive
D.TCP connect scan; true negative
AnswerB

Nmap's UDP scan sends zero-byte UDP datagrams to target ports; closed ports return ICMP port unreachable, matching the capture. The rule signature and traffic genuinely reflect scanning activity, so the analyst classifies it as a true positive rather than a false positive.

Why this answer

UDP scans send UDP packets; closed ports respond with ICMP Port Unreachable. This matches the alert signature, indicating a true positive for a UDP scan.

35
MCQhard

An analyst examines PCAP and sees multiple SMB sessions from internal host 10.1.1.10 to 10.1.1.20, 10.1.1.30, and 10.1.1.40 within seconds. The NTLM authentication contains a hash parameter that is identical across sessions. Which lateral movement technique is most likely being used?

A.Golden ticket
B.Pass-the-hash
C.Kerberoasting
D.Pass-the-ticket
AnswerB

Pass-the-hash reuses a captured NTLM hash to authenticate without cracking the plaintext password, so the identical hash parameter across all three SMB sessions matches the stem's constraint exactly. The single internal source host fanning out to multiple targets within seconds is characteristic of automated lateral movement using stolen credentials.

Why this answer

Pass-the-hash uses the same NTLM hash to authenticate to multiple hosts without knowing the plaintext password.

36
Multi-Selecthard

An analyst is reviewing PCAP from a network intrusion. The attacker used a payload with ROP gadgets and shellcode. Which TWO exploitation indicators are associated with this attack? (Choose two.)

Select 2 answers
A.ROP gadgets
B.NOP sled
C.Heap spray
D.Shellcode
E.DNS tunnelling
AnswersA, D

ROP gadgets are short instruction sequences ending in a return, chained to bypass DEP by reusing existing executable code. Their appearance in the payload is a specific exploitation indicator, matching the attack described in the stem.

Why this answer

Shellcode is the actual executable code injected; ROP gadgets are used to bypass DEP by chaining existing code.

37
MCQeasy

A security analyst observes repeated ICMP port unreachable responses from a target host. The source IP is sending packets to multiple UDP ports. Which type of scan is most likely being performed?

A.TCP SYN scan
B.UDP scan
C.TCP connect scan
D.Ping sweep
AnswerB

A UDP scan sends packets to many UDP ports; closed ports return ICMP port unreachable messages, exactly matching the observed responses. This distinguishes it from TCP-based scans, which rely on SYN, ACK or RST behaviour rather than ICMP errors.

Why this answer

UDP scans elicit ICMP port unreachable messages from closed ports; open ports typically do not respond.

38
MCQhard

During a network intrusion analysis, an analyst observes a series of TCP packets with the FIN flag set but no corresponding ACK, followed by packets with the RST flag set. What is the most likely explanation for this traffic pattern?

A.A SYN flood denial-of-service attack.
B.A TCP session hijacking attempt.
C.A normal TCP connection termination sequence.
D.A TCP port scan using FIN and RST packets.
AnswerD

A FIN scan sends TCP packets with only the FIN flag set to various ports. Closed ports respond with RST, while open ports ignore the packet. The pattern of FIN packets without ACK followed by RST responses is characteristic of a FIN scan, a stealthy scanning technique.

Why this answer

The correct answer is a TCP port scan using FIN and RST packets. A FIN scan sends packets with only the FIN flag; closed ports reply with RST, while open ports ignore them. The observed pattern of FIN packets without ACK followed by RST responses matches this stealthy scanning technique, which can bypass some firewalls.

Exam trap

The trap here is mistaking the FIN and RST packets for a normal connection teardown, overlooking the missing ACKs and the scanning context.

39
MCQmedium

During a network intrusion investigation, an analyst notices repeated SMB authentication attempts from a single host to multiple other hosts using different usernames. Which type of activity does this pattern suggest?

A.Pass-the-hash attack
B.Lateral movement
C.SMB relay attack
D.Brute-force attack on SMB
AnswerB

Repeated SMB authentications from one host to many hosts with varying usernames indicate an attacker pivoting across the network after initial compromise, using harvested credentials to access further systems. This credential-spraying pattern across multiple targets is the hallmark of lateral movement rather than external scanning or exfiltration.

Why this answer

Repeated SMB authentication attempts from one host to many different hosts, using different usernames, is the classic signature of lateral movement — an attacker who has foothold on one machine pivoting across the network to compromise additional systems. The pattern of one-to-many with varying credentials indicates enumeration and spread, not a single-target attack.

Exam trap

200-201 often tests the confusion between pass-the-hash (same credential reused) and lateral movement (one source, many targets, varied credentials) — the 'different usernames to multiple hosts' detail is the discriminator.

How to eliminate wrong answers

Option A is wrong because pass-the-hash uses a stolen NTLM hash to authenticate as a single compromised identity, typically producing repeated logons with the same username, not many different usernames across many hosts. Option C is wrong because an SMB relay attack intercepts and relays authentication to a target, usually involving a man-in-the-middle position and fewer distinct source-to-destination pairs. Option D is wrong because brute-force targets one account on one host with many password attempts, not one source hitting many destinations with different usernames.

40
Multi-Selecthard

During an incident, an analyst observes the following in PCAP: (1) DNS queries with random-looking subdomains to a known malicious domain, (2) large outbound FTP transfers of .zip files, (3) HTTP POST requests with Base64-encoded data in the body. Which THREE exfiltration techniques are being used? (Select 3)

Select 3 answers
A.ICMP exfiltration
B.FTP exfiltration
C.DNS tunneling
D.Steganography
E.HTTP exfiltration (POST)
AnswersB, C, E

FTP exfiltration matches the large outbound transfers of .zip files, since FTP carries bulk file data over dedicated control and data channels. This satisfies the stem's second observation directly, distinguishing it from DNS tunnelling and HTTP POST encoding, which handle covert or encoded channels rather than straightforward bulk archive transfer.

Why this answer

Option B (FTP exfiltration) is correct because the PCAP shows large outbound FTP transfers of .zip files, which is a classic data exfiltration pattern where stolen data is archived and sent over FTP to an external server. Option C (DNS tunneling) is correct because DNS queries with random-looking subdomains to a known malicious domain indicate data being encoded into DNS query names and sent to an attacker-controlled authoritative DNS server, a hallmark of DNS tunneling. Option E (HTTP exfiltration via POST) is correct because HTTP POST requests carrying Base64-encoded data in the body are a common method of covertly exfiltrating data through web traffic that blends in with normal HTTP.

Option A (ICMP exfiltration) does not belong because no ICMP echo request/reply traffic with embedded payloads is described in the PCAP. Option D (Steganography) does not belong because steganography involves hiding data inside other files such as images or audio, and no such carrier files or hidden-content artifacts are mentioned in the observed traffic.

Exam trap

The trap here is that candidates may confuse exfiltration techniques with obfuscation techniques (like steganography) or assume ICMP is always used for covert channels, when the question specifically describes DNS, FTP, and HTTP artifacts.

41
MCQmedium

A security analyst observes a large number of SYN packets sent to various ports on a target host, receiving RST responses for closed ports and no response for open ports. Which phase of the Cyber Kill Chain does this activity represent?

A.Reconnaissance
B.Weaponisation
C.Exploitation
D.Delivery
AnswerA

SYN scanning across multiple ports with RST replies for closed ports and silence for open ones is active port probing, gathering information about live services before exploitation. This maps to Reconnaissance, the first Cyber Kill Chain phase, where adversaries enumerate the target's attack surface.

Why this answer

The observed behavior—sending a large number of SYN packets to various ports and analyzing RST responses (closed ports) versus no response (open ports)—is a classic port scan, specifically a SYN scan. This activity maps the target's attack surface by identifying live hosts and open ports, which aligns with the Reconnaissance phase of the Cyber Kill Chain, where the adversary gathers information to plan an attack.

Exam trap

Cisco often tests the distinction between Reconnaissance and Weaponisation, where candidates mistakenly think that sending crafted packets (SYN) is part of weaponisation, but weaponisation specifically involves creating the exploit or payload, not the scanning activity.

How to eliminate wrong answers

Option B (Weaponisation) is wrong because weaponisation involves coupling a payload with a delivery mechanism (e.g., creating a malicious document or exploit kit), not scanning for open ports. Option C (Exploitation) is wrong because exploitation requires actively leveraging a vulnerability to gain unauthorized access, whereas a SYN scan only identifies potential targets without attempting to compromise them. Option D (Delivery) is wrong because delivery refers to transmitting the weaponized payload to the target (e.g., via email or USB), not the pre-attack reconnaissance of scanning ports.

42
MCQmedium

A SOC analyst monitors outbound traffic from a corporate network and notices a single internal host contacting an external server on TCP port 53, but the payloads contain fixed-length, non-DNS binary data with no query/response structure. The host also makes outbound connections to the same external IP on TCP port 4444. Which technique is the attacker most likely using?

A.DNS over HTTPS (DoH) tunneling
B.SMTP relay abuse for data exfiltration
C.Command-and-control over a non-standard port masquerading as DNS
D.DNS tunneling over TCP port 53
AnswerC

Using TCP port 53 with non-DNS binary payloads while also connecting to TCP port 4444 is a classic masquerading technique: the attacker picks a port commonly allowed through firewalls and tunnels a custom C2 protocol over it. The absence of DNS query/response formatting and the paired 4444 connection confirm a custom C2 channel, not legitimate DNS. This matches real-world malware that abuses trusted ports to evade egress filtering.

Why this answer

Traffic to TCP port 53 that does not follow DNS message formatting, combined with a second connection to TCP port 4444, indicates a custom command-and-control channel deliberately placed on a commonly permitted port. Attackers choose such ports to slip past egress filters that allow DNS. DNS tunneling and DoH would preserve DNS semantics or use TLS on 443, and SMTP abuse would use mail ports and commands, none of which match the observed binary, non-DNS payloads.

Exam trap

The trap here is assuming any traffic on port 53 is DNS; the port number alone does not define the protocol, and payload structure must be inspected.

43
Multi-Selectmedium

A SOC analyst is triaging an alert from a network sensor indicating that an internal host may be performing host discovery on the local subnet. The analyst wants to identify active hosts without generating TCP connections. Which two techniques should the analyst expect to see in the packet capture that are consistent with this goal? (Choose two.)

Select 2 answers
A.ICMP echo requests sent to each address in the subnet range
B.TCP SYN packets sent to port 80 on each address in the subnet
C.UDP datagrams sent to port 53 on each address in the subnet
D.ARP requests broadcast to the subnet for each candidate IP address
E.TCP FIN packets sent to port 443 on each address in the subnet
AnswersA, D

ICMP echo requests to a range of subnet addresses are a classic host discovery method. Hosts that respond with echo replies are confirmed alive, while non-responders are either offline or blocking ICMP. This technique avoids establishing any TCP connections, which matches the analyst's requirement to identify active hosts without TCP sessions. It is commonly used by tools such as nmap with the ping sweep option.

Why this answer

ICMP echo requests and ARP requests are both connectionless techniques that confirm host liveness without establishing TCP sessions. ICMP echo requests work across routed networks, while ARP requests are effective on the local subnet. Both avoid TCP state on targets, which matches the analyst's requirement.

TCP SYN, TCP FIN, and targeted UDP probes either create TCP state or focus on service discovery rather than pure host liveness.

Exam trap

The trap here is assuming that any probe which elicits a response counts as host discovery, when the requirement specifically excludes TCP connections and targets host liveness rather than services.

44
MCQhard

An analyst identifies a PCAP with a reverse shell session. Which characteristic in the traffic would most likely indicate an interactive shell session?

A.Large file transfers over FTP
B.Bidirectional traffic with small packets and command echo patterns
C.Periodic HTTP GET requests at regular intervals
D.Constant stream of UDP packets
AnswerB

Bidirectional small packets with command echo patterns reveal an interactive shell: each keystroke travels to the attacker, the command output returns, and the shell echoes input back. This request-response rhythm, with tiny payloads and echoed characters, satisfies the stem's requirement for identifying live human interaction rather than bulk data transfer.

Why this answer

Reverse shells often exhibit bidirectional traffic with interactive patterns, such as small irregular packets and commands echoed.

45
MCQhard

During an investigation, an analyst observes that a workstation resolves an internal hostname to an IP address that does not match the DHCP lease record, and subsequent SMB connections to that hostname reach an attacker-controlled server. Which attack technique best explains this behavior?

A.SMB signing downgrade on the file server
B.DHCP starvation exhausting the address pool
C.DNS spoofing or rogue DNS response injection
D.ARP cache poisoning on the local subnet
AnswerC

When a hostname resolves to an IP inconsistent with the DHCP lease and SMB traffic then reaches an attacker server, the name resolution itself has been manipulated. DNS spoofing or rogue responses inject false A records so clients connect to the attacker. This directly accounts for the mismatched resolution and the redirected SMB sessions, making it the best explanation for the observed behavior.

Why this answer

A hostname resolving to an IP that contradicts the DHCP lease, followed by SMB traffic reaching an attacker server, points to manipulation of name resolution. DNS spoofing or rogue DNS responses inject false records so the client connects to the wrong endpoint. ARP poisoning operates at layer 2 with MAC mappings, DHCP starvation prevents lease acquisition, and SMB signing affects message integrity, so none of those explain the poisoned resolution.

Exam trap

The trap here is blaming layer 2 attacks like ARP poisoning for what is actually a name resolution manipulation at the DNS layer.

46
MCQhard

During a forensic analysis, an analyst uses NetworkMiner to extract files from a PCAP. One of the extracted files contains a PE executable with a known signature of a malware variant. Which phase of the Cyber Kill Chain does the file transfer most likely represent?

A.Reconnaissance
B.Weaponization
C.Exploitation
D.Delivery
AnswerD

Extracting a PE executable from the PCAP shows the malicious file being transferred to the target host, which is the Delivery phase of the Cyber Kill Chain. Delivery covers transmission of the weaponised payload via email, web, or USB, satisfying the scenario's file-transfer constraint.

Why this answer

The file transfer from the PCAP represents the Delivery phase because NetworkMiner extracted a PE executable that was transmitted over the network, likely via HTTP, SMTP, or SMB. In the Cyber Kill Chain, Delivery is the phase where the weaponized payload is transmitted to the target system, which is exactly what a file transfer in a PCAP captures. The presence of a known malware signature confirms the payload was delivered, not yet executed or exploited.

Exam trap

Cisco often tests the distinction between Delivery and Exploitation, where candidates mistakenly choose Exploitation because they see a malware file, but the PCAP only shows the transfer, not the execution or vulnerability trigger.

How to eliminate wrong answers

Option A is wrong because Reconnaissance involves gathering information about the target (e.g., scanning, OSINT) and does not include transferring a malware executable. Option B is wrong because Weaponization is the phase where the attacker creates the malicious payload (e.g., coupling exploit with backdoor), but the file transfer itself is not the creation step. Option C is wrong because Exploitation occurs when the delivered payload triggers a vulnerability to execute code; the PCAP file transfer only shows the delivery, not the execution or trigger.

47
Multi-Selecthard

An analyst is investigating a suspected SQL injection attack captured in a PCAP. The analyst needs to identify TWO indicators in the HTTP traffic that would confirm a SQL injection attempt. Which two indicators should the analyst look for? (Choose two.)

Select 2 answers
A.Unexpected database error messages in HTTP responses
B.HTTP response containing a large number of directory listings
C.Presence of SQL keywords such as UNION, SELECT, or OR 1=1 in URL parameters or POST data
D.Multiple HTTP 302 redirects to an external domain
E.Presence of encrypted payloads using TLS 1.3
AnswersA, C

When SQL injection is attempted, malformed queries can cause the database to return error messages. These errors, such as syntax errors or unclosed quotation marks, often appear in HTTP responses and reveal that the input affected the SQL query, confirming an injection attempt.

Why this answer

SQL injection attempts are characterized by the injection of SQL syntax into user inputs, often visible as keywords like UNION or OR 1=1 in HTTP requests. Additionally, when the injected query causes a database error, the error message may be returned in the HTTP response, providing confirmation of the attempt. These two indicators together strongly suggest a SQL injection attack.

Exam trap

The trap here is focusing on generic web attack signs like redirects or directory listings, which are not specific to SQL injection, instead of the SQL syntax and error messages that directly indicate database query manipulation.

48
MCQmedium

An analyst notices periodic HTTP GET requests to a suspicious domain every 60 seconds. The payload size is small and consistent. This behavior is characteristic of which phase of the Cyber Kill Chain?

A.Actions on Objectives
B.Command and Control
C.Delivery
D.Installation
AnswerB

Regular, small, consistent beaconing to an external domain indicates an implanted host checking in with its controller. That recurring channel is the Command and Control phase, where the adversary maintains remote direction of compromised systems after exploitation.

Why this answer

Periodic, small, consistent HTTP GET requests to a suspicious external domain are the hallmark of beaconing, which occurs during the Command and Control (C2) phase of the Cyber Kill Chain. The compromised host is checking in with its C2 server at regular intervals to receive instructions or exfiltrate small amounts of data. This regular, low-volume traffic pattern is designed to blend in with normal traffic while maintaining persistent control.

Exam trap

The trap here is confusing the C2 phase with Actions on Objectives because both involve network traffic; candidates must recognize that periodic, small beacons indicate ongoing control, not the final objective.

How to eliminate wrong answers

Option A is wrong because Actions on Objectives is the final phase where the attacker achieves their goal (e.g., data exfiltration, ransomware execution), which typically involves larger or more targeted data transfers, not small periodic beacons. Option C is wrong because Delivery is the phase where the initial payload is delivered (e.g., via phishing email or malicious download), which happens once, not periodically. Option D is wrong because Installation is when the malware establishes persistence on the host, which is a one-time event, not a recurring network pattern.

49
MCQmedium

A SOC analyst notices an internal host transmitting a series of ICMP Echo Request packets to an external IP, each with a payload size of exactly 1024 bytes and a repeating pattern. The echo replies are consistently the same size. Which type of activity does this most likely indicate?

A.Legitimate network latency testing
B.ICMP tunneling
C.Network reconnaissance via ping sweep
D.ICMP flood denial-of-service
AnswerB

Large, fixed-size ICMP payloads with repeating patterns and matching replies indicate data being encapsulated inside ICMP Echo packets. Normal ping payloads are small (often 32-64 bytes) and random. The consistent size and pattern suggest a covert channel using ICMP tunneling tools like ptunnel or icmpsh to exfiltrate or communicate stealthily.

Why this answer

The correct answer is ICMP tunneling because the traffic shows large, fixed-size ICMP payloads with repeating patterns and matching replies, which are hallmarks of data being hidden inside ICMP Echo packets. Normal ICMP usage involves small, variable payloads for diagnostics, not consistent large payloads, indicating a covert channel.

Exam trap

The trap here is assuming that any ICMP traffic is benign network troubleshooting, ignoring the unusual payload size and pattern that point to tunneling.

50
MCQhard

An analyst monitoring an internal network observes a host sending a large number of TCP segments with the URG flag set and a non-zero urgent pointer, but the urgent pointer value does not point to actual urgent data. The destination host appears to be processing the data normally. Which explanation best describes what the analyst is observing?

A.The host is performing a legitimate Telnet session where urgent data indicates a break command
B.The host is experiencing a TCP window zero condition caused by application backpressure
C.The host is retransmitting segments because the receiver's ACKs are being lost in transit
D.An attacker is using the TCP urgent pointer as a covert signaling mechanism or IDS evasion technique
AnswerD

Because many IDS engines and applications ignore or mishandle the URG flag and urgent pointer, attackers can abuse them as a side channel or to desynchronize inspection. Setting URG with a meaningless urgent pointer while still delivering normal data lets the attacker signal a cooperating peer or confuse the IDS without disrupting the actual TCP stream.

Why this answer

The TCP urgent pointer is rarely used by modern applications and is inconsistently handled by IDS engines and operating systems. Attackers exploit this by setting URG with a pointer that does not correspond to real urgent data, using the flag pattern as a covert signal to a cooperating peer or to desynchronize the IDS's view of the stream while the actual data is processed normally by the target.

Exam trap

The trap here is assuming URG always indicates legitimate Telnet break handling, when in practice URG with a meaningless pointer is a known evasion and covert-channel technique.

51
MCQhard

An analyst inspects a PCAP and sees an internal host sending HTTP requests where the User-Agent string is unusually long and contains random alphanumeric characters, and the Cookie header carries base64-like data to an external server. The server responds with small HTTP 200 OK messages. Which technique is most consistent with this traffic?

A.HTTP command-and-control beaconing with data exfiltration over headers
B.A misconfigured web proxy caching responses
C.A legitimate browser extension updating its configuration
D.DNS over HTTPS resolution performed by the host
AnswerA

Attackers frequently abuse HTTP headers such as User-Agent and Cookie to blend C2 traffic with normal web activity. Random alphanumeric User-Agent values and base64-encoded Cookie data indicate obfuscated payloads, while small 200 OK responses represent tasking or acknowledgements. This pattern matches HTTP-based C2 with exfiltration embedded in request headers rather than the body.

Why this answer

Randomized User-Agent strings and base64-encoded Cookie values sent to an external server, with small HTTP 200 responses, are characteristic of HTTP-based command-and-control where data is hidden in headers. Legitimate extension updates, proxy caching, and DNS over HTTPS all produce predictable, structured traffic that does not match the randomness or the request-response pattern observed.

Exam trap

The trap here is focusing on the HTTP 200 OK responses as benign web browsing and overlooking that the anomalous User-Agent and Cookie fields carry the malicious payload.

52
MCQmedium

While analyzing a PCAP, an analyst uses the Wireshark filter 'http.request' and finds a URI parameter containing '%27%20UNION%20SELECT%201,2,3%20--'. What type of attack is indicated?

A.Cross-site scripting (XSS)
B.SQL injection
C.Command injection
D.Directory traversal
AnswerB

The URI parameter `%27%20UNION%20SELECT%201,2,3%20--` is URL-encoded, where `%27` decodes to a single quote (`'`), `%20` to a space, and `--` to an SQL comment. This payload injects a single quote to break out of a string context, then appends a `UNION SELECT` statement to retrieve arbitrary data, with the comment `--` suppressing the remainder of the original query. This directly satisfies the constraint of manipulating SQL syntax via user-supplied input, confirming SQL injection.

Why this answer

The URL-encoded string decodes to a SQL injection attempt with UNION SELECT. SQL injection often appears in HTTP parameters.

53
MCQeasy

A network analyst is examining a PCAP and sees a large number of ICMP echo request packets sent from a single internal host to multiple external IP addresses, with varying payload sizes and no corresponding echo replies. The analyst suspects the host is being used for reconnaissance or data exfiltration. Which characteristic of the ICMP traffic would most strongly indicate that it is being used for data exfiltration rather than simple reconnaissance?

A.The payload sizes are consistent and small, matching standard ping requests.
B.The ICMP packets contain non-standard payload data that is base64-encoded and varies in length.
C.The source IP address is spoofed to match the destination IP address.
D.The ICMP echo requests are sent at a constant rate of one per second to a single external IP.
AnswerB

ICMP tunneling for exfiltration often embeds encoded data in the payload, such as base64 strings, which are not present in normal ping requests. The varying length and non-standard content indicate that the ICMP echo requests are carrying hidden data rather than simply testing connectivity. This is a strong indicator of exfiltration or covert channel use.

Why this answer

The presence of non-standard, base64-encoded payload data that varies in length is a classic sign of ICMP tunneling for data exfiltration. Normal ping requests have predictable payloads, often just a repeating pattern or timestamp. When ICMP is used as a covert channel, the payload carries encoded stolen data, making the traffic anomalous.

The other options describe patterns more consistent with reconnaissance or benign monitoring.

Exam trap

The trap here is focusing on the volume or rate of ICMP traffic, when the payload content and encoding are the definitive indicators of exfiltration.

54
MCQmedium

A SOC analyst sees an alert for 'Possible SQL Injection' on a web server. Reviewing the PCAP, the analyst finds the parameter 'id=1 OR 1=1' in the HTTP request. However, the web server returns a normal page with no signs of compromise. What is the correct classification?

A.True negative
B.False negative
C.False positive
D.True positive
AnswerC

The payload 'id=1 OR 1=1' is a classic tautology injection attempt, but the server returned a normal page with no compromise indicators. Because the attack neither succeeded nor altered behaviour, the alert reflects benign traffic rather than a genuine intrusion, so it is classified as a false positive.

Why this answer

A false positive occurs when a security tool raises an alert for activity that is not actually malicious or successful. Here, the SQL injection payload 'id=1 OR 1=1' was detected in the request, but the server returned a normal page with no signs of compromise, meaning the attack did not succeed and the alert was triggered on suspicious input rather than actual exploitation. Therefore, the alert is a false positive.

Exam trap

200-201 often tests the confusion between false positive and true positive by presenting a detected payload without confirmed compromise — candidates must remember that detection alone does not make it a true positive.

How to eliminate wrong answers

Option A (true negative) is wrong because a true negative means no alert was raised and no malicious activity occurred — here an alert was raised. Option B (false negative) is wrong because a false negative means malicious activity occurred but was not detected — here detection happened. Option D (true positive) is wrong because a true positive requires that the detected activity was actually malicious and/or successful — the server showed no compromise, so the detection was not a true positive.

55
MCQhard

An analyst examines a PCAP and observes that an internal host sends an ICMP echo request containing a payload of 1200 bytes, followed by an ICMP echo reply from an external host with a payload of 1500 bytes. The payload data does not match standard ping patterns and appears to contain encoded file fragments. Which technique is most consistent with this observation?

A.Smurf attack amplification
B.Path MTU discovery using oversized ICMP
C.ICMP redirect manipulation
D.ICMP tunneling for data exfiltration
AnswerD

ICMP tunneling embeds data inside echo request and reply payloads, which is exactly what the oversized, encoded, non-standard payloads indicate. The asymmetry in payload size and the presence of encoded fragments suggest a tool using ICMP as a transport to move data out of the network. This technique bypasses controls that allow ping but do not inspect ICMP payload content.

Why this answer

Oversized ICMP echo packets carrying encoded, non-standard payloads in both directions strongly indicate ICMP tunneling, a common method for covert data transfer and exfiltration. Because many networks permit ping for troubleshooting, attackers abuse it to move data past controls that do not inspect ICMP payloads. The other options describe different ICMP-based behaviors that do not involve encoded data in echo payloads.

Exam trap

The trap here is treating all ICMP traffic as benign troubleshooting traffic and not inspecting the payload size and content of echo request and reply packets.

56
MCQmedium

A SOC analyst is analyzing a PCAP from a suspected intrusion. The traffic shows a series of TCP connections where the client sends a SYN, receives a SYN-ACK, then immediately sends a RST instead of an ACK, and this pattern repeats across multiple ports on the same target. Which type of scan is most likely being performed?

A.UDP scan
B.TCP SYN stealth scan
C.TCP connect scan
D.TCP FIN scan
AnswerB

A TCP SYN stealth scan sends a SYN, receives a SYN-ACK if the port is open, but then sends a RST to tear down the connection before it is fully established. This half-open scanning technique avoids completing the handshake, making it stealthier and matching the described pattern of SYN, SYN-ACK, then RST.

Why this answer

The pattern of SYN, SYN-ACK, then RST indicates a half-open TCP scan, commonly known as a SYN stealth scan. The attacker sends a SYN, receives a SYN-ACK if the port is open, but resets the connection instead of completing the handshake. This avoids establishing a full connection and is often used to evade detection while enumerating open ports.

Exam trap

The trap here is confusing a SYN stealth scan with a TCP connect scan, as both start with a SYN, but only the stealth scan sends a RST after receiving SYN-ACK instead of completing the handshake.

57
MCQhard

An intrusion detection system alerts on HTTP traffic containing the string 'UNION SELECT' in the URI parameter. This is most indicative of what type of attack?

A.SQL injection
B.Command injection
C.Cross-site scripting
D.Directory traversal
AnswerA

The string UNION SELECT combines result sets from separate queries, a hallmark of SQL injection, where attackers append crafted SQL to input fields. Detecting it in a URI parameter indicates an attempt to manipulate the backend database query, satisfying the intrusion signature described.

Why this answer

The alert detects the string 'UNION SELECT' in a URI parameter, which is a classic SQL injection payload used to combine results from multiple database queries. This indicates an attacker is attempting to manipulate SQL queries by injecting malicious SQL code through user input, a hallmark of SQL injection attacks.

Exam trap

Cisco often tests the distinction between injection types by using specific payload strings; the trap here is confusing SQL injection with command injection because both involve 'injection', but the 'UNION SELECT' syntax is unique to SQL and not used in command injection or other attacks.

How to eliminate wrong answers

Option B is wrong because command injection involves executing system commands (e.g., via shell metacharacters like ';' or '|') rather than SQL statements like 'UNION SELECT'. Option C is wrong because cross-site scripting (XSS) typically injects client-side scripts (e.g., JavaScript) into web pages, not SQL syntax in URI parameters. Option D is wrong because directory traversal exploits path traversal sequences (e.g., '../') to access restricted files, not SQL query manipulation.

58
MCQmedium

A PCAP contains an HTTP POST request with a parameter containing "UNION SELECT username, password FROM users". This is evidence of:

A.SQL injection
B.Cross-site scripting
C.Path traversal
D.Command injection
AnswerA

The payload contains a UNION SELECT statement appended to a query, the classic signature of SQL injection, where an attacker concatenates a crafted query to extract data such as usernames and passwords. The HTTP POST parameter carrying this syntax confirms database query manipulation rather than cross-site scripting or command injection.

Why this answer

SQL injection attacks often use UNION SELECT statements to extract data from databases via web application vulnerabilities.

59
MCQmedium

A network analyst is examining a PCAP and notices a series of TCP packets with the PSH flag set and small payload sizes, sent from an internal host to an external IP. The external IP responds with similar small packets. The communication is continuous and occurs at regular intervals. Which type of activity is most likely occurring?

A.Network time synchronization
B.Interactive command-and-control session
C.Denial-of-service attack
D.Large file transfer
AnswerB

Small, regular packets with the PSH flag set often indicate interactive traffic where data is sent immediately. This pattern is typical of command-and-control (C2) communications, where an attacker sends commands and receives output in small chunks, maintaining a persistent session with periodic check-ins.

Why this answer

The combination of small payloads, PSH flag, and regular intervals is indicative of an interactive command-and-control channel. Attackers often use such channels to maintain stealth, sending commands and receiving responses in small packets to avoid detection by volume-based monitoring. This pattern is distinct from bulk transfers or DoS attacks.

Exam trap

The trap here is assuming any regular communication is benign, but the small payloads with PSH and regular intervals are a hallmark of C2 beaconing, not routine traffic like NTP.

60
MCQmedium

An analyst reviews PCAP traffic and sees a series of HTTP POST requests from an internal host to an external IP at exactly 60-second intervals. The payload size is consistent. Which phase of the Cyber Kill Chain does this activity most likely represent?

A.Delivery
B.Command and Control
C.Actions on Objectives
D.Installation
AnswerB

Regular 60-second beaconing with consistent payload size to an external IP indicates an implanted host checking in with its controller. This periodic, uniform outbound pattern is characteristic of the Command and Control phase, where compromised systems receive instructions and exfiltrate data.

Why this answer

The consistent 60-second intervals and uniform payload size of HTTP POST requests from an internal host to an external IP are classic indicators of beaconing activity. In the Cyber Kill Chain, this behavior aligns with the Command and Control (C2) phase, where an established foothold communicates with an external C2 server to receive instructions or exfiltrate data. The use of HTTP POST mimics normal web traffic to evade detection, a common technique in C2 channels.

Exam trap

Cisco often tests the distinction between beaconing (C2) and data exfiltration (Actions on Objectives), where candidates mistakenly associate any external HTTP POST with data theft rather than recognizing the periodic pattern as command-and-control signaling.

How to eliminate wrong answers

Option A is wrong because the Delivery phase involves the initial transmission of the exploit or payload to the target (e.g., via phishing email or malicious download), not periodic beaconing after compromise. Option C is wrong because Actions on Objectives refers to the final goal, such as data exfiltration or system destruction, which would show larger or irregular data transfers, not consistent small beacons. Option D is wrong because Installation is the phase where malware is placed on the system (e.g., writing to disk or registry), which occurs before C2 and does not involve periodic network traffic.

61
Multi-Selectmedium

An analyst reviews an IDS alert indicating a TCP SYN scan against a web server. The analyst wants to confirm the scan by examining packet-level evidence in the PCAP. Which TWO characteristics would confirm a SYN scan rather than legitimate client behavior? (Choose two.)

Select 2 answers
A.The source sends a single SYN and then completes the handshake before sending an HTTP GET
B.The target's firewall logs show the source IP was previously blocked for port scanning
C.The source sends SYN packets with varying TCP window sizes and random source ports across the scan
D.The destination responds with RST packets for closed ports and SYN-ACK for open ports
E.A single source sends SYN packets to many sequential destination ports with no completed three-way handshakes
AnswersC, E

Scanning tools randomize source ports and vary window size and other header fields to evade simple signature matching and to avoid exhausting local ephemeral ports. Combined with the absence of completed handshakes, this header variation supports an automated scanner rather than a browser or API client, which would use one consistent source port per connection and a stable window size negotiated once per session.

Why this answer

A SYN scan is proven by the combination of incomplete handshakes across many destination ports and deliberate header variation. The scanner never finishes the three-way handshake, and it randomizes source ports and window sizes to evade detection. Target responses such as RST or SYN-ACK merely reflect normal TCP behavior, a completed handshake indicates legitimate client activity, and historical firewall blocks are reputation context rather than packet-level confirmation.

Exam trap

The trap here is selecting the target's RST and SYN-ACK responses as evidence, when those are ordinary TCP behavior that any connection attempt would elicit.

62
MCQmedium

An analyst is reviewing a PCAP and sees multiple HTTP requests with the parameter 'id=1 UNION SELECT username,password FROM users'. What type of attack is being attempted?

A.SQL injection
B.Directory traversal
C.Cross-site scripting (XSS)
D.Command injection
AnswerA

The payload injects a UNION SELECT clause into the id parameter, appending a query that returns usernames and passwords. This is classic SQL injection: attacker-supplied SQL is concatenated into the backend query, letting the database return data it should not expose.

Why this answer

The SQL keywords UNION and SELECT in a parameter indicate a SQL injection attempt to extract data from the database.

63
MCQhard

During incident response, an analyst extracts files from a PCAP using Wireshark's Export Objects feature. One extracted file is a PDF that triggers an IDS alert for 'Exploit:PDF/HeapSpray'. Which technique does this alert describe?

A.Return-oriented programming (ROP)
B.Shellcode injection
C.Heap spray
D.Stack buffer overflow
AnswerC

Heap spray describes shellcode placed repeatedly across heap memory to land at a predictable address during exploitation. The PDF object carries that sprayed payload, which is why the IDS signature names heap spray rather than a buffer overflow or denial-of-service technique.

Why this answer

Heap spray is a memory corruption technique where an attacker fills heap memory with shellcode to increase the chance of code execution, often used in PDF exploits.

64
MCQmedium

A security analyst observes periodic outbound HTTPS connections to an unusual domain that resolves to different IP addresses each time. This behavior is most indicative of:

A.Exfiltration via FTP
B.DNS tunnelling
C.Port scanning
D.Beaconing using DGA
AnswerD

Periodic outbound HTTPS traffic combined with rotating IP resolutions points to domain generation algorithms, where malware cycles through algorithmically generated domains for command-and-control. The regular interval satisfies the beaconing constraint, while the shifting IP addresses reflect DGA domains resolving to changing infrastructure, distinguishing it from static command-and-control.

Why this answer

Periodic outbound HTTPS connections to an unusual domain that resolves to different IPs each time is the classic signature of beaconing using a Domain Generation Algorithm (DGA). Malware uses DGA to generate many pseudo-random domains and rotates through them to evade blocklists, while beaconing provides regular check-ins to C2.

Exam trap

200-201 often tests the confusion between DGA beaconing and DNS tunnelling — both involve DNS, but DGA is about rotating domains for C2 check-ins, while tunnelling is about encoding data inside DNS queries.

How to eliminate wrong answers

Option A is wrong because FTP exfiltration would typically involve large data transfers over port 21 or explicit FTP traffic, not periodic HTTPS beacons to rotating domains. Option B is wrong because DNS tunnelling encodes data in DNS queries/responses (often TXT or long subdomains) and would show anomalous DNS traffic, not HTTPS connections. Option C is wrong because port scanning involves probing many ports on hosts to find open services, not regular outbound HTTPS to a single rotating domain.

65
MCQhard

A security analyst is investigating a potential exploit. The PCAP shows a HTTP POST request containing a long string of characters that, when decoded, reveals a series of return-oriented programming (ROP) gadgets. What is the likely purpose of this payload?

A.Lateral movement
B.Privilege escalation
C.Exploitation
D.Persistence
AnswerC

ROP gadgets chained in a decoded payload indicate memory-corruption exploitation, where an attacker hijacks control flow to bypass DEP and execute code. The POST delivers the crafted chain, so the payload's purpose is exploitation rather than reconnaissance or exfiltration.

Why this answer

ROP gadgets are used to bypass non-executable memory protections by chaining together small code sequences to execute arbitrary code. This is an exploitation technique.

66
MCQmedium

An analyst is investigating an alert for a potential ICMP tunneling attack. The analyst reviews a PCAP and notices a series of ICMP Echo Request packets with unusually large payloads (over 1000 bytes) and varying payload contents, sent from an internal host to an external IP address. The external host replies with ICMP Echo Reply packets of similar size. Which characteristic most strongly supports the conclusion that this is ICMP tunneling rather than normal ping traffic?

A.The payload size is consistently large and the contents are non-repetitive, indicating that data is being encapsulated in the ICMP payload.
B.The ICMP packets use Type 8 and Type 0 codes, which are reserved for diagnostic purposes and should not carry data.
C.The ICMP Echo Requests are sent at regular intervals, which is a known signature of ICMP tunneling tools.
D.The external host responds with Echo Replies that have a different IP identification field than the requests, which indicates packet fragmentation.
AnswerA

Normal ping payloads are typically small (e.g., 32 or 64 bytes) and often consist of a repeating pattern or timestamp. Large, varying payloads suggest that actual data is being carried inside the ICMP packets, which is the essence of ICMP tunneling. The consistent size and non-repetitive content further indicate a structured data transfer, supporting the conclusion of tunneling.

Why this answer

The strongest indicator of ICMP tunneling is the presence of large, non-repetitive payloads in Echo Requests and Replies, which suggests data encapsulation. Normal ping uses small, often patterned payloads. The other options describe normal ICMP characteristics, such as standard types, regular timing, or IP header fields, none of which specifically indicate tunneling.

Exam trap

The trap here is focusing on the ICMP type or timing as the malicious indicator, when the real signal is the payload size and content variation that reveals data encapsulation.

67
MCQhard

An analyst detects an attack where the attacker uses NTLM authentication with a hashed password instead of the plaintext password. This technique is known as:

A.Password spraying
B.Brute force
C.Kerberos ticket reuse
D.Pass-the-hash
AnswerD

Pass-the-hash exploits the NTLM challenge-response protocol: the attacker captures the static NT hash and replays it directly, authenticating without ever cracking it to plaintext. This matches the stem's constraint of authentication using a hashed password rather than the cleartext credential.

Why this answer

Pass-the-hash is the technique where an attacker uses a captured NTLM password hash directly to authenticate without knowing the plaintext password. Because NTLM authentication accepts the hash as the credential, the attacker can replay it to access systems.

Exam trap

200-201 often tests the distinction between pass-the-hash (NTLM hash reuse) and pass-the-ticket (Kerberos ticket reuse), so candidates must match the credential type to the technique.

How to eliminate wrong answers

Option A is wrong because password spraying involves trying a small number of common passwords across many accounts to avoid lockouts, not using hashes. Option B is wrong because brute force attempts many password guesses against an account, whereas pass-the-hash bypasses guessing entirely by using the hash. Option C is wrong because Kerberos ticket reuse (e.g., pass-the-ticket or golden ticket) involves Kerberos TGT/TGS tickets, not NTLM hashes.

68
MCQmedium

A SOC analyst is reviewing a PCAP captured at the network perimeter. The analyst notices that a single internal host sends a series of ICMP echo requests to multiple external hosts, but the ICMP payload size is unusually large (over 1000 bytes) and the payload contains non-ASCII, high-entropy data. The echo replies from the external hosts are also large and contain similar data. Which type of activity is most likely occurring?

A.ICMP redirect attack
B.Ping flood
C.Smurf attack
D.ICMP tunneling
AnswerD

ICMP tunneling encapsulates data within ICMP echo request and reply packets, often using large payloads with high entropy to hide exfiltration or command-and-control traffic. The scenario describes large, non-ASCII, high-entropy payloads in both directions, which is a classic indicator. Normal ping traffic uses small, predictable payloads, so the unusual size and content strongly suggest tunneling.

Why this answer

The correct answer is ICMP tunneling because the traffic pattern shows large, high-entropy payloads in both ICMP echo requests and replies, which is a known method for covert data exfiltration or command-and-control. Normal ICMP traffic uses small, predictable payloads. The other options describe denial-of-service or routing manipulation attacks that do not match the observed bidirectional data exchange.

Exam trap

The trap here is assuming that any ICMP traffic to multiple hosts is a Smurf or flood attack, ignoring the large, high-entropy payloads that indicate tunneling.

69
MCQhard

An analyst is examining a PCAP of what appears to be a covert channel. The analyst observes that the internal host sends ICMP Echo Requests that contain a payload of exactly 48 bytes of non-repeating binary data, and the corresponding Echo Replies always return with a zero-length payload. The payload bytes, when decoded, contain what looks like command strings. Which technique is most consistent with these observations?

A.ICMP redirect attack manipulating the host's routing table
B.ICMP flood denial-of-service attack against the external host
C.Smurf attack using the internal host as an unwitting reflector
D.ICMP tunneling using Echo Request payloads as a data exfiltration and command channel
AnswerD

ICMP tunneling abuses the data field of Echo Request and Echo Reply packets to carry arbitrary payloads. The non-repeating binary content and command-like strings in the Echo Request payload, combined with empty Echo Replies, indicate the host is sending data or receiving instructions inside ICMP rather than performing normal reachability checks.

Why this answer

The defining indicators of ICMP tunneling are Echo Request or Echo Reply packets carrying non-standard, often non-repeating or encoded payloads, especially when those payloads contain structured data such as command strings. Normal ping traffic uses predictable, often repeating payloads like alphabetic patterns. The one-way data flow with empty replies here strongly suggests the channel is being used to deliver commands or exfiltrate data covertly.

Exam trap

The trap here is dismissing the traffic as benign ping activity because ICMP is common, when the abnormal payload size and command-like content are the actual red flags.

70
MCQmedium

In a PCAP, an analyst sees a large outbound data transfer over FTP to an external IP address during non-business hours. The source host is a database server. Which phase of the Cyber Kill Chain does this represent?

A.Installation
B.Actions on Objectives
C.Weaponization
D.Exploitation
AnswerB

Exfiltration of database records to an external FTP endpoint fulfils the attacker's ultimate goal, so it maps to Actions on Objectives. Earlier phases cover reconnaissance, weaponisation, delivery, exploitation, installation and command-and-control; the actual theft of sensitive data is the final stage.

Why this answer

The Cyber Kill Chain's 'Actions on Objectives' phase is where the attacker achieves their ultimate goal, such as exfiltrating data. In this scenario, a large outbound FTP transfer from a database server to an external IP during non-business hours directly indicates data theft, which is the final objective of the intrusion. FTP (port 21/20) is used here as the exfiltration protocol, moving sensitive data out of the network.

Exam trap

Cisco often tests the distinction between 'Actions on Objectives' and 'Exploitation' by presenting a post-compromise activity (like data exfiltration) and expecting candidates to recognize it as the final phase, not the initial breach.

How to eliminate wrong answers

Option A is wrong because 'Installation' refers to deploying malware or a backdoor on the target system, not to the actual data exfiltration seen here. Option C is wrong because 'Weaponization' is the phase where the attacker creates a deliverable payload (e.g., coupling an exploit with a dropper), which occurs before delivery and exploitation. Option D is wrong because 'Exploitation' is the phase where a vulnerability is triggered to gain initial access, not the post-compromise data theft activity.

71
MCQhard

A network analyst finds a PCAP with a series of DNS queries for subdomains like "data12345.example.com" and "data67890.example.com" where the subdomain names appear to contain encoded base64 data. This pattern suggests:

A.Port scan via DNS
B.Normal DNS resolution
C.DGA-based C2
D.DNS tunnelling for exfiltration
AnswerD

Repeated DNS queries carrying base64-encoded labels in subdomains indicate data encoded into DNS requests, a hallmark of DNS tunnelling used to exfiltrate data covertly through permitted DNS traffic, bypassing egress controls that block other channels.

Why this answer

DNS tunnelling for exfiltration encodes stolen data into DNS query names (often base64) and sends it to an attacker-controlled authoritative DNS server. The pattern of many subdomains with encoded-looking labels under the same domain is a classic indicator of data being smuggled out via DNS, which is frequently allowed through firewalls.

Exam trap

200-201 often tests the difference between DGA (random domains for C2 beaconing) and DNS tunnelling (encoded data in subdomains for exfiltration) — candidates see 'encoded subdomains' and wrongly pick DGA.

How to eliminate wrong answers

Option A is wrong because a port scan via DNS would involve queries for many different domains or service records, not a series of encoded subdomains under one domain. Option B is wrong because normal DNS resolution produces human-readable, predictable hostnames, not base64-encoded labels with sequential-looking data. Option C is wrong because DGA-based C2 generates many random-looking domain names across different TLDs to locate a C2 server, whereas here the data is encoded in subdomains of a single domain, indicating exfiltration rather than beaconing.

72
MCQeasy

An analyst receives an alert for 'ET WEB_SERVER Possible SQL Injection Attempt' triggered by a URL parameter containing ' OR 1=1--'. After investigating, the analyst confirms that the web application is not vulnerable to SQL injection and the request was a benign test. How should this alert be classified?

A.False positive
B.True negative
C.False negative
D.True positive
AnswerA

The signature fired on a string resembling SQL injection, but investigation confirmed the application is not vulnerable and the traffic was a benign test. The alert therefore correctly identified suspicious syntax yet wrongly indicated an actual attack, which is a false positive.

Why this answer

A false positive occurs when an alert is triggered but the activity is actually benign. Here, the SQL injection attempt was a benign test and the application is not vulnerable, so the alert is a false positive. This classification is correct because the detection system incorrectly flagged legitimate activity as malicious.

Exam trap

200-201 often tests whether candidates can correctly classify alerts based on the definitions of true/false positives/negatives, so the trap is confusing a false positive with a true negative or true positive when the activity is benign but an alert was raised.

How to eliminate wrong answers

Option B is wrong because a true negative is when no alert is triggered and no malicious activity occurs; here, an alert was triggered. Option C is wrong because a false negative is when malicious activity occurs but no alert is triggered; here, an alert was triggered. Option D is wrong because a true positive is when an alert is triggered and the activity is actually malicious; here, the activity was benign.

73
MCQmedium

An analyst is investigating a PCAP file and wants to reconstruct a conversation between two hosts. Which Wireshark filter would be most appropriate to follow the entire TCP stream?

A.tcp.stream eq 0
B.dns.qry.name
C.ip.addr == 10.0.0.1
D.http.request
AnswerA

`tcp.stream eq 0` isolates every packet belonging to stream index 0, letting Wireshark reassemble the full bidirectional conversation regardless of ports or IP addresses. This satisfies the stem's requirement to follow the entire TCP stream, since stream indexing groups related segments that Follow TCP Stream also relies on.

Why this answer

The filter 'tcp.stream eq 0' is used in Wireshark to follow a specific TCP stream. When you right-click on a packet and select 'Follow TCP Stream', Wireshark automatically applies this filter with the appropriate stream index. This filter displays all packets belonging to that particular TCP conversation, allowing the analyst to reconstruct the entire session between the two hosts.

Other filters like 'ip.addr' show all traffic to/from an IP, which may include multiple streams, and 'http.request' only shows HTTP requests, not the full stream.

Exam trap

200-201 often tests Wireshark filter syntax and the difference between filtering by IP, protocol, and stream. Candidates might choose 'ip.addr' thinking it shows a conversation, but it includes all traffic to/from that IP, not just one TCP stream.

How to eliminate wrong answers

Option B is wrong because 'dns.qry.name' filters DNS query names, which is unrelated to reconstructing a TCP stream; it would only show DNS traffic. Option C is wrong because 'ip.addr == 10.0.0.1' filters all traffic involving that IP address, which could include multiple TCP streams, UDP, ICMP, etc., and does not isolate a single conversation. Option D is wrong because 'http.request' filters only HTTP request packets, missing responses and other parts of the TCP stream, so it cannot reconstruct the full conversation.

74
MCQhard

In a PCAP, an analyst sees an interactive shell session over TCP with irregular command prompts and responses. Which tool was likely used to generate this traffic?

A.File transfer tool
B.Port scanner
C.Reverse shell payload
D.SQL injection tool
AnswerC

A reverse shell payload initiates the TCP connection from the compromised host back to the attacker, then carries an interactive command session. The irregular prompts and responses in the PCAP reflect that outbound, attacker-controlled shell rather than a legitimate client-server protocol.

Why this answer

A reverse shell payload is the correct answer because it establishes an interactive shell session where the target machine connects back to the attacker's machine, allowing the attacker to execute commands. In a PCAP, this appears as a TCP session with irregular command prompts and responses, often with small packet sizes and interactive timing. The traffic may not follow standard protocol patterns, and the commands/responses are human-readable or encoded.

Exam trap

200-201 often tests the ability to distinguish between different types of network traffic, so candidates must recognize that an interactive shell session with command prompts is characteristic of a reverse shell, not a file transfer, port scan, or SQL injection.

How to eliminate wrong answers

Option A is wrong because a file transfer tool would generate traffic with large data transfers and specific protocols like FTP or SMB, not an interactive shell with command prompts. Option B is wrong because a port scanner generates many connection attempts to different ports with SYN packets, not an established interactive session with command/response patterns. Option D is wrong because SQL injection tools typically target web applications over HTTP and would show SQL queries in HTTP requests, not an interactive shell session over TCP.

75
MCQhard

During a PCAP analysis, a security analyst notices an HTTP request with the URI parameter 'id=1 UNION SELECT username,password FROM users--'. What is the most likely attack being attempted?

A.Command injection
B.Cross-site scripting (XSS)
C.Directory traversal
D.SQL injection
AnswerD

The payload 'UNION SELECT username,password FROM users--' appends a second query to the original, harvesting credential columns and commenting out the remainder. This is textbook SQL injection, exploiting unsanitised input in the 'id' parameter to exfiltrate database contents.

Why this answer

The payload 'id=1 UNION SELECT username,password FROM users--' is a classic SQL injection attempt. It uses a UNION operator to combine the original query with a malicious one that extracts sensitive data from the users table, and the double dash comments out the rest of the original query.

Exam trap

The trap is misidentifying the attack as XSS or command injection due to the presence of SQL keywords, especially if the analyst is not familiar with SQL syntax.

How to eliminate wrong answers

Option A is wrong because command injection targets OS commands, not database queries. Option B is wrong because XSS involves injecting client-side scripts, not SQL. Option C is wrong because directory traversal attempts to access files outside the web root, typically using '../' sequences.

Page 1 of 2 · 122 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Network Intrusion Analysis questions.