Courseiva

CCNA Network Intrusion Analysis Questions

47 of 122 questions · Page 2/2 · Network Intrusion Analysis · Answers revealed

76
MCQeasy

In the MITRE ATT&CK framework, TTPs are mapped to:

A.Vulnerability databases
B.Compliance standards
C.Network protocols
D.Real-world threat groups
AnswerD

MITRE ATT&CK maps tactics, techniques and procedures to documented real-world threat groups, satisfying the framework's purpose of describing adversary behaviour rather than isolated indicators. Each group entry links specific techniques to observed campaigns, enabling defenders to prioritise detections against actors actually targeting their sector.

Why this answer

MITRE ATT&CK maps Tactics, Techniques, and Procedures (TTPs) to specific real-world threat groups (also called Advanced Persistent Threats or APTs). Each technique page in ATT&CK lists the known threat actors that have been observed using it, allowing defenders to attribute behaviors and prioritize defenses against groups targeting their industry. This threat-group-centric mapping is what distinguishes ATT&CK from a pure technique catalog.

Exam trap

200-201 often tests the misconception that ATT&CK is a vulnerability or compliance framework, when it is actually a behavioral knowledge base whose TTPs are mapped to real-world threat groups.

How to eliminate wrong answers

Option A is wrong because vulnerability databases (such as CVE/NVD) catalog software flaws, not adversary behaviors — ATT&CK does not map TTPs to CVEs. Option B is wrong because compliance standards (PCI-DSS, HIPAA, ISO 27001) are governance frameworks, not adversary behavior repositories, and ATT&CK mappings to controls are a separate downstream exercise. Option C is wrong because network protocols (TCP, HTTP, SMB) are technical communication standards; ATT&CK techniques may abuse protocols but TTPs are not mapped to protocol specifications.

77
MCQmedium

During an intrusion analysis, an analyst identifies that an attacker used a domain generation algorithm (DGA) to resolve C2 domains. Which of the following traffic patterns is most consistent with DGA?

A.Multiple DNS queries to algorithmically generated domains that result in NXDOMAIN responses
B.Large DNS responses indicating amplification
C.DNS queries to a single domain with high frequency
D.DNS queries with long TTL values
AnswerA

DGA malware rapidly cycles through algorithmically generated domain names, most of which are unregistered, producing bursts of DNS queries answered with NXDOMAIN. This high-volume, high-failure pattern distinguishes DGA activity from normal resolution of legitimate, registered domains.

Why this answer

DGA generates many random-looking domains, many of which will be non-existent (NXDOMAIN) as the attacker cycles through them.

78
MCQhard

An analyst observes a large outbound FTP transfer to an external IP address from a server that normally does not generate such traffic. This is most likely an indicator of:

A.Persistence
B.Lateral movement
C.C2 communication
D.Exfiltration
AnswerD

Anomalous outbound FTP transfers from a server that normally generates no such traffic indicate data being stolen to an external destination. This matches exfiltration, where attackers move collected data out of the environment over file-transfer protocols.

Why this answer

A large outbound FTP transfer to an external IP from a server that normally does not generate such traffic is a classic indicator of data exfiltration — data is being stolen and sent out of the network. The volume, direction (outbound), and anomaly relative to baseline behavior all point to exfiltration rather than other attack phases.

Exam trap

The trap is confusing exfiltration with C2 — candidates see 'external IP' and pick C2, but C2 is low-volume beaconing while exfiltration is bulk outbound data transfer.

How to eliminate wrong answers

Option A is wrong because persistence refers to maintaining access across reboots (e.g., registry run keys, scheduled tasks, cron jobs) — it does not describe bulk outbound data transfer. Option B is wrong because lateral movement is east-west traffic between internal hosts (e.g., SMB, RDP, PsExec), not outbound to an external IP. Option C is wrong because C2 communication is typically low-volume, beaconing traffic to a controller for command and control, not a large one-time FTP transfer of data.

79
MCQmedium

During a SYN scan, an attacker sends a SYN packet to a closed port on a target. What response does the target typically send back?

A.ICMP Port Unreachable
B.RST
C.ACK
D.SYN-ACK
AnswerB

A closed port has no listener, so the target's TCP stack replies to the SYN with a RST packet, immediately refusing the connection. An open port would answer SYN-ACK instead. This RST-versus-SYN-ACK difference is exactly what lets a SYN scan distinguish open from closed ports.

Why this answer

In a SYN scan, a closed port responds with a RST packet to reject the connection attempt.

80
MCQmedium

A SOC analyst is reviewing NetFlow records and notices that a single internal host has initiated connections to 1,024 distinct destination IP addresses on TCP port 445 within a five-minute window. Each connection attempt lasts under one second and transfers fewer than three packets. Which activity does this pattern most strongly indicate?

A.SMB worm propagation scanning the local subnet and adjacent ranges
B.An SMB client resolving a hostname through repeated broadcast name queries
C.A legitimate backup application performing parallel SMB writes to storage nodes
D.A normal NetFlow sampling artifact caused by flow timeout settings
AnswerA

The short-lived, low-packet-count connections to many hosts on TCP 445 in a compressed timeframe match worm-style SMB scanning, where malware enumerates targets looking for writable shares or vulnerable services before moving laterally. A benign file server or backup job would not touch over a thousand distinct hosts in five minutes, and the uniform port reinforces automated propagation rather than user-driven access.

Why this answer

Rapid connections from one internal host to a large number of unique destinations on a single service port, each lasting only a moment and exchanging minimal data, is the signature of automated SMB scanning used for worm propagation. Legitimate SMB workloads target a small, stable set of servers and move meaningful data. NetFlow aggregation does not create destination diversity, and name resolution uses different ports and protocols, so the fan-out reflects real scanning behavior.

Exam trap

The trap here is assuming any burst of SMB traffic is normal file-sharing activity, when the decisive clue is the count of distinct destination hosts rather than the protocol itself.

81
MCQeasy

In the Cyber Kill Chain model, which phase involves delivering the exploit to the target, such as via email attachment or malicious link?

A.Installation
B.Exploitation
C.Weaponization
D.Delivery
AnswerD

Delivery is the phase where the adversary transmits the weaponised payload to the victim, satisfying the stem's requirement for an exploit reaching the target via email attachment or malicious link. It follows Weaponisation and precedes Exploitation, making it the precise Cyber Kill Chain stage described.

Why this answer

The delivery phase is where the weaponized payload is transmitted to the victim, e.g., via phishing email or drive-by download.

82
MCQmedium

An analyst filters PCAP with 'tcp.stream eq 0' and sees an interactive shell session with commands like 'whoami', 'ls -la', 'cd /etc'. The session originated from an HTTP POST to a web shell. Which type of attack is this?

A.Reverse shell
B.DNS tunnelling
C.SQL injection
D.Cross-site scripting
AnswerA

Interactive shell over TCP is a reverse shell.

Why this answer

A web shell allows remote command execution over HTTP, essentially a reverse shell.

83
MCQeasy

An analyst is reviewing a network intrusion alert and sees a large number of ICMP echo requests sent from a single external IP to multiple internal hosts. The ICMP payloads are identical and the requests are sent in rapid succession. Which type of activity does this most likely represent?

A.Smurf attack amplification
B.ICMP flood denial-of-service attack
C.ICMP tunneling for data exfiltration
D.ICMP ping sweep for host discovery
AnswerD

A ping sweep sends ICMP echo requests to multiple IP addresses to identify which hosts are alive. The scenario describes rapid, identical ICMP echo requests to multiple internal hosts, which is characteristic of a ping sweep used for network reconnaissance before a more targeted attack.

Why this answer

The rapid succession of identical ICMP echo requests to multiple internal hosts is a classic ping sweep, used to discover live hosts on a network. Attackers often perform ping sweeps during reconnaissance to map the network before launching further attacks. The identical payloads and multiple targets distinguish it from a denial-of-service flood or tunneling.

Exam trap

The trap here is assuming any high-volume ICMP traffic is a denial-of-service attack, but a ping sweep targets multiple hosts for discovery, not a single host for resource exhaustion.

84
MCQeasy

An intrusion detection system alerts on traffic that appears to be a command and control (C2) beacon. Which of the following characteristics is most typical of beaconing traffic?

A.Large data transfers to a known cloud provider
B.ICMP echo requests to multiple hosts
C.Random intervals with varying packet sizes
D.Periodic connections at regular intervals to an external IP
AnswerD

Beaconing malware checks in with its command and control server on a fixed schedule, producing repeated connections to the same external IP at consistent intervals. This regularity, rather than payload content or port choice, is the defining signature analysts use to distinguish beaconing from normal traffic.

Why this answer

Beaconing is characterized by regular, periodic connections to a C2 server at consistent intervals.

85
MCQmedium

An analyst is monitoring network traffic and observes a host making outbound HTTPS connections to a domain that appears to be generated by a Domain Generation Algorithm (DGA). Which phase of the Cyber Kill Chain best describes this activity?

A.Installation
B.Command and Control (C2)
C.Actions on Objectives
D.Exploitation
AnswerB

DGA-generated domains are contacted by infected hosts to receive instructions from attacker infrastructure, which is the Command and Control phase. The outbound HTTPS beaconing to algorithmically generated domains is the defining C2 characteristic, occurring after exploitation and installation but before actions on objectives.

Why this answer

DGA-generated domains are used by malware to locate its C2 infrastructure, and the periodic HTTPS beaconing to those algorithmically generated domains is the hallmark of the Command and Control phase of the Cyber Kill Chain. The host has already been compromised and is now reaching out to receive instructions or exfiltrate data. This activity occurs after exploitation and installation but before the attacker achieves their final objectives.

Exam trap

The trap is confusing the C2 callback with Installation or Actions on Objectives — candidates see 'malware' and pick Installation, or see 'HTTPS traffic' and pick Actions on Objectives, missing that the defining characteristic is the beaconing to attacker-controlled infrastructure.

How to eliminate wrong answers

Option A is wrong because Installation refers to the malware being placed on the victim system (e.g., dropper execution, persistence), not the outbound beaconing to DGA domains. Option C is wrong because Actions on Objectives is the final phase where the attacker accomplishes their goal (data theft, encryption, lateral movement), which comes after C2 is established. Option D is wrong because Exploitation is the phase where a vulnerability is triggered to gain code execution, which precedes the C2 callback.

86
MCQhard

An analyst examines a PCAP and finds a series of UDP packets sent to multiple ports on a target. The target responds with ICMP 'Destination Unreachable (Port Unreachable)' messages for each port. What type of scan is being performed?

A.UDP scan
B.SYN scan
C.Xmas scan
D.FIN scan
AnswerA

Sending UDP datagrams to successive ports and receiving ICMP Port Unreachable replies for closed ones is the signature of a UDP scan, which maps open UDP services by their silence versus closed ports returning ICMP unreachable messages.

Why this answer

A UDP scan works by sending a UDP packet to a target port. If the port is closed, the target responds with an ICMP Port Unreachable message (Type 3, Code 3). If the port is open, the service may or may not reply, so the absence of an ICMP unreachable is interpreted as 'open|filtered.' The pattern of UDP probes followed by ICMP Port Unreachable responses is the signature of a UDP scan.

Exam trap

The trap is assuming any scan that elicits ICMP responses is a TCP-based stealth scan; candidates must remember that ICMP Port Unreachable is specifically the closed-port response for UDP, not TCP.

How to eliminate wrong answers

Option B is wrong because a SYN scan sends TCP SYN packets and expects SYN-ACK (open) or RST (closed) responses, not ICMP unreachable messages. Option C is wrong because an Xmas scan sets the FIN, PSH, and URG flags in a TCP packet and relies on the absence of a response (open|filtered) or an RST (closed), not ICMP. Option D is wrong because a FIN scan sends a TCP packet with only the FIN flag set and similarly relies on RST or silence, not ICMP Port Unreachable.

87
MCQmedium

Which type of attack is indicated by a series of SMB authentication attempts from one host to multiple other hosts in a short time frame?

A.Lateral movement
B.Port scanning
C.C2 beaconing
D.DNS exfiltration
AnswerA

SMB authentication attempts from one host to many hosts indicate an attacker using harvested credentials to move between systems. This pattern is characteristic of lateral movement, distinguishing it from a single-target brute-force or credential-stuffing attack.

Why this answer

Lateral movement often involves propagating across hosts using SMB for remote access and authentication.

88
MCQhard

An analyst detects a large outbound FTP transfer from a sensitive server to an external IP address not previously seen. The file being transferred is a compressed archive containing database dumps. Which Cyber Kill Chain phase is most directly indicated?

A.Installation
B.C2
C.Exploitation
D.Actions on Objectives
AnswerD

Exfiltration of compressed database dumps to an external IP constitutes the adversary achieving their goal, which defines Actions on Objectives. The earlier phases (delivery, exploitation, installation, command and control) are already complete; this transfer is the mission's payoff, not lateral movement or staging.

Why this answer

Exfiltration of sensitive data is part of 'Actions on Objectives', where the attacker achieves their goal of stealing data.

89
Multi-Selectmedium

An analyst is investigating a suspected TCP session hijacking attempt. The analyst reviews a PCAP and sees duplicate packets with the same sequence numbers but different source IP addresses. Which two TCP characteristics would most likely be manipulated in such an attack? (Choose two.)

Select 2 answers
A.Urgent pointer
B.Window size
C.Acknowledgement numbers
D.Sequence numbers
E.Maximum segment size (MSS)
AnswersC, D

Acknowledgement numbers are used to confirm receipt of data. An attacker may spoof ACKs to keep the session alive or to acknowledge injected data, preventing the legitimate endpoint from detecting the anomaly. Manipulating both sequence and acknowledgement numbers is necessary to maintain the hijacked session.

Why this answer

TCP session hijacking requires the attacker to inject packets that appear to be from the legitimate client. To do this, the attacker must know or predict the current sequence numbers and provide valid acknowledgement numbers. Manipulating these two fields allows the attacker to insert data into the stream without the server rejecting it.

Other TCP fields like window size or urgent pointer are not central to this attack.

Exam trap

The trap here is focusing on TCP flags or options like window size, while the fundamental requirement for hijacking is correct sequence and acknowledgement numbers.

90
MCQhard

An analyst is investigating a host that is making outbound HTTPS connections to multiple random-looking domains, each with a short TTL. The domains are not in any threat intelligence feeds. Which technique is most likely being used?

A.Domain Generation Algorithm (DGA)
B.Beaconing
C.DNS tunneling
D.Fast flux DNS
AnswerA

DGA malware generates large volumes of pseudo-random domains, cycling through them via short TTLs to evade blocklists. Because each domain is algorithmically produced and rapidly rotated, it will not yet appear in threat intelligence feeds, matching the observed HTTPS beaconing pattern.

Why this answer

Domain Generation Algorithms (DGAs) generate many random domain names to evade blocklists. Short TTLs allow fast changes.

91
MCQeasy

During network intrusion analysis, an analyst reviews a PCAP showing a series of TCP packets where the attacker sends an ACK with a sequence number outside the expected window, followed by packets with overlapping sequence ranges. The analyst suspects the attacker is attempting to evade an IDS by confusing its TCP stream reassembly. Which evasion technique is being used?

A.TCP RST injection
B.TCP SYN flood
C.IP fragmentation attack
D.TCP segmentation overlap evasion
AnswerD

TCP segmentation overlap evasion exploits differences in how operating systems and IDS reassemble overlapping segments. By sending out-of-window ACKs and overlapping sequence numbers, the attacker tries to make the IDS reconstruct a benign payload while the target host reconstructs a malicious one, causing the IDS to miss the actual attack.

Why this answer

In TCP segmentation overlap evasion, the attacker deliberately crafts overlapping or out-of-window segments so that an IDS and the destination host disagree on the reassembled byte stream. The IDS may see harmless data while the host processes the malicious version, or vice versa. Normalizing and validating TCP streams is required for reliable detection.

Exam trap

The trap here is confusing Layer 4 sequence-number manipulation with Layer 3 IP fragmentation overlap, even though both are evasion techniques aimed at reassembly ambiguity.

92
MCQhard

An analyst is reviewing a PCAP of an intrusion and observes that the attacker's machine sent a TCP segment with the ACK flag set to a target host, but the target had never received a SYN from the attacker. The target responded with an RST. The analyst wants to determine what the attacker was attempting. Which technique best describes this activity?

A.An ACK scan used to map firewall rules and determine which ports are filtered
B.A TCP SYN scan used to identify open ports on the target
C.A TCP session hijacking attempt using a spoofed sequence number
D.A Christmas tree scan used to identify open ports via illegal flag combinations
AnswerA

An ACK scan sends TCP segments with only the ACK flag set to target ports. Because no prior handshake exists, the target responds with RST regardless of whether the port is open or closed. The key value is that filtered ports often drop the ACK silently while unfiltered ports return RST, allowing the attacker to map firewall rule sets rather than open services.

Why this answer

An ACK scan sends TCP segments with only the ACK flag set to ports where no session exists. Targets respond with RST if the port is reachable and unfiltered, while firewalls that filter the port may drop the packet silently. This allows the attacker to infer firewall rule sets rather than open services, which matches the observed segment and RST response.

Exam trap

The trap here is assuming any TCP scan that elicits RST responses is identifying open ports, when an ACK scan actually maps firewall filtering rather than service availability.

93
MCQhard

An analyst reviews a PCAP and sees a host receive an unsolicited ICMP echo reply containing an embedded payload, followed by the host initiating a TCP connection to an internal server on port 445. The ICMP payload begins with bytes that decode to a URL path. Which analysis conclusion is most defensible?

A.The ICMP payload is a fragmentation artifact and should be ignored
B.The ICMP traffic is a benign network health check and the SMB connection is unrelated
C.The ICMP payload is likely a covert channel delivering a command that triggered the SMB connection
D.The SMB connection indicates the host is acting as a file server for the attacker
AnswerC

Unsolicited ICMP echo replies with embedded URL-like data are a known covert channel for command delivery. The immediate SMB connection to an internal server on port 445 is consistent with the delivered command instructing the host to move laterally or access a share. Correlating the payload content with the follow-on SMB session gives a defensible intrusion narrative, so this conclusion matches the evidence best.

Why this answer

An unsolicited ICMP echo reply carrying a decodable URL path is a hallmark of ICMP-based covert command delivery. Pairing it with a subsequent outbound SMB connection to an internal server suggests the delivered instruction told the host to reach a share for lateral movement or tool retrieval. The direction of the TCP handshake confirms the host is the client, and the payload is coherent, not a fragmentation artifact, so the covert-channel conclusion is the most defensible.

Exam trap

The trap here is treating ICMP as inherently harmless monitoring traffic; unsolicited replies with embedded data are not normal health checks.

94
Multi-Selectmedium

A network analyst is investigating a suspected DNS tunneling attack. Which THREE of the following are indicators of DNS tunneling?

Select 3 answers
A.DNS queries for well-known domains like google.com
B.Unusually high volume of DNS queries to a single domain
C.DNS queries with long subdomain names containing encoded characters
D.Low volume of DNS queries from internal hosts
E.DNS responses with large TXT record sizes
AnswersB, C, E

Tunnelling tools continuously encode and transmit data, producing far more queries to a single domain than legitimate resolution patterns. This sustained query volume to one domain satisfies the stem's requirement for a DNS tunnelling indicator.

Why this answer

DNS tunneling often involves high volumes of DNS queries to a single domain, large payloads in TXT records, and encoded data in subdomains to exfiltrate data.

95
MCQmedium

A security analyst is examining a PCAP and observes a series of TCP packets with the PSH flag set and small payload sizes, sent from an internal host to an external IP. The packets are spaced roughly 30 seconds apart. Which type of malicious activity is MOST likely indicated?

A.A TCP SYN flood attack
B.A TCP port scan using FIN packets
C.A command-and-control (C2) beacon
D.A large file transfer using FTP
AnswerC

C2 beacons often use periodic, small payloads to check in with the attacker. The PSH flag indicates data is being pushed, and the 30-second interval suggests a beaconing pattern. This is typical of malware communicating with a C2 server.

Why this answer

The combination of small payloads, PSH flag, and regular 30-second intervals strongly suggests C2 beaconing. Malware often beacons to its C2 server at set intervals to receive commands or exfiltrate small amounts of data. This pattern is distinct from floods, file transfers, or scans.

Exam trap

The trap here is assuming any TCP packet with PSH is benign interactive traffic, but regular small beacons are a hallmark of C2 communication.

96
MCQmedium

A SOC analyst is investigating a suspected data exfiltration event on a corporate network. The analyst runs a Wireshark display filter on a captured PCAP and sees a large volume of outbound packets from an internal workstation to an external IP address, all with the same destination port and with the TCP PSH flag set on nearly every packet. The payloads are small but consistently sized, and the transfer continues for over 30 minutes. Which statement best explains why this traffic pattern is suspicious in the context of network intrusion analysis?

A.The PSH flag indicates the sender is bypassing TCP flow control, which is a known evasion technique used by rootkits to hide data in the TCP header.
B.The presence of the PSH flag on nearly every packet means the connection is using TCP Fast Open, which is only seen in malicious command-and-control channels.
C.The use of a single destination port for all outbound packets indicates the traffic is encrypted, and encrypted exfiltration cannot be detected by network analysis.
D.The steady, long-duration outbound flow with consistent packet sizes suggests a scripted or automated transfer, which is consistent with data exfiltration rather than normal interactive user activity.
AnswerD

A sustained, uniform outbound flow over 30 minutes with uniform packet sizes and PSH on nearly every packet strongly suggests an automated tool pushing data out, not a human browsing or emailing. Exfiltration tools often chunk data into consistent sizes to optimize throughput. In intrusion analysis, this beaconing-like regularity is a key indicator of malicious data transfer rather than legitimate user traffic.

Why this answer

The correct answer focuses on behavioral indicators: a long, steady, automated-looking outbound flow with uniform packet sizes and the PSH flag set on most packets. This pattern is typical of data exfiltration tools that chunk and push data continuously, unlike bursty interactive user traffic. The other options misattribute meaning to TCP flags or make incorrect claims about detection limits, which would mislead an analyst.

Exam trap

The trap here is assuming that a TCP flag like PSH is inherently malicious or that a single destination port implies encryption, when the real signal is the sustained, automated transfer pattern.

97
MCQhard

A threat hunter identifies a binary that uses a Domain Generation Algorithm (DGA) to create domain names like 'eksdghf23.com', 'mzncxv89.net' each day. The malware contacts these domains over HTTPS. Which phase of the Cyber Kill Chain is most directly associated with this technique?

A.Installation
B.Exploitation
C.Command and Control
D.Actions on Objectives
AnswerC

DGA-generated domains provide resilient command and control infrastructure, letting malware receive instructions and exfiltrate data despite takedown attempts. The HTTPS beaconing to algorithmically generated names is the defining C2 signature, directly satisfying the stem's requirement to identify the Cyber Kill Chain phase for this technique.

Why this answer

The use of a DGA to generate domain names that the malware contacts over HTTPS is the defining characteristic of the Command and Control (C2) phase. The malware is attempting to reach its operator's infrastructure to receive instructions or send data. This occurs after the malware is installed and before the attacker achieves their objectives.

Exam trap

The trap is confusing C2 with Installation or Actions on Objectives — candidates may see 'malware contacts domains' and think Installation, or see 'HTTPS' and think exfiltration (Actions on Objectives), but the key is that DGA beaconing is the C2 channel.

How to eliminate wrong answers

Option A is wrong because Installation refers to the malware being placed on the system (e.g., via a dropper), not the subsequent beaconing to DGA domains. Option B is wrong because Exploitation is the phase where a vulnerability is leveraged to execute code, which happens before C2. Option D is wrong because Actions on Objectives is the final phase where the attacker accomplishes their goal (data theft, destruction), which follows C2 establishment.

98
MCQhard

An analyst is investigating lateral movement and observes SMB authentication attempts from host A to multiple other hosts using NTLM authentication with a hash value instead of a password. Which attack technique is most likely being used?

A.Pass-the-hash attack
B.Brute force attack
C.Kerberos golden ticket attack
D.SMB relay attack
AnswerA

Pass-the-hash exploits NTLM's design, where the password hash itself authenticates without knowing the plaintext. Replaying a captured hash across multiple hosts via SMB produces exactly the observed pattern of lateral authentication attempts, distinguishing it from credential guessing or Kerberos abuse.

Why this answer

Pass-the-hash exploits the NTLM challenge-response protocol by replaying a captured NTLM hash directly to authenticate, without ever needing the plaintext password. The tell-tale sign is SMB authentication where the credential material is a hash rather than a password, especially when one host authenticates to many others in a fan-out pattern typical of lateral movement. Tools like Mimikatz, Impacket's psexec.py, and CrackMapExec perform this by injecting the hash into the NTLM authentication exchange.

Exam trap

200-201 often tests the distinction between pass-the-hash (replaying a stolen hash) and SMB relay (forwarding someone else's authentication) — candidates confuse the two because both involve NTLM and SMB lateral movement.

How to eliminate wrong answers

Option B is wrong because brute force involves repeatedly guessing passwords against an authentication service, producing many failed logon events (4625) rather than successful hash-based authentications. Option C is wrong because a Kerberos golden ticket forges a TGT using the KRBTGT account hash and is validated via Kerberos (port 88), not NTLM over SMB. Option D is wrong because an SMB relay forwards a victim's authentication to a third-party server to impersonate the victim; it does not involve the attacker supplying a hash directly from host A to multiple targets.

99
Multi-Selecteasy

Which TWO of the following are typical indicators of a C2 beaconing communication?

Select 2 answers
A.Regular intervals of communication at consistent times
B.Large outbound data transfers to an external IP
C.Multiple failed login attempts from a single source
D.ICMP echo requests to multiple hosts
E.DNS queries for domains that are rarely visited
AnswersA, E

Beaconing malware contacts its command-and-control server on a fixed schedule, so traffic recurs at predictable intervals rather than randomly. This periodicity, often with consistent packet sizes, distinguishes automated beaconing from bursty human browsing and satisfies the stem's requirement for a typical C2 indicator.

Why this answer

Option A is correct because C2 beaconing is characterized by periodic check-ins from an infected host to its command-and-control server, producing highly regular, consistent communication intervals (often with jitter added to evade detection). Option E is correct because beaconing frequently abuses DNS for command-and-control or data exfiltration, generating queries to unusual, rarely visited, or algorithmically generated (DGA) domains that stand out against normal browsing patterns. Option B is not typical of beaconing itself, since beaconing traffic is usually small and low-volume; large outbound transfers suggest exfiltration rather than the beacon check-in.

Option C describes a brute-force or password-guessing attack, not C2 beaconing. Option D describes ICMP echo requests (ping sweeps) used for host discovery or network reconnaissance, not command-and-control beaconing.

Exam trap

200-201 often tests whether candidates can distinguish C2 beaconing (small, periodic callbacks) from exfiltration (large outbound transfers) — the word 'outbound' in both options is the bait.

100
Multi-Selectmedium

An analyst investigates a suspected data exfiltration event and captures outbound traffic from a compromised host. The traffic uses HTTPS to an unfamiliar external domain and shows consistent large uploads at regular intervals. Which two indicators would most strongly support the conclusion that this is automated exfiltration rather than normal user browsing? (Choose two.)

Select 2 answers
A.The connection uses TLS version 1.2
B.The TLS certificate uses a self-signed issuer
C.The uploads occur at fixed intervals with near-identical byte counts
D.The destination domain was registered recently and has no reputation history
E.The client sends data without any corresponding inbound user-driven requests
AnswersC, E

Automated exfiltration tools typically beacon or upload on a schedule with consistent payload sizes, producing regular intervals and near-identical byte counts. Human browsing is irregular in both timing and volume. This periodicity and uniformity are strong behavioral indicators that a script or malware, not a person, is generating the traffic, making it a reliable discriminator in this scenario.

Why this answer

Automated exfiltration is best identified by behavior: uploads at fixed intervals with near-identical sizes indicate a scheduled tool, and outbound data with no matching user-driven inbound requests shows the transfer is not interactive browsing. Domain age, certificate issuer, and TLS version describe infrastructure or protocol choices that legitimate and malicious traffic share, so they are weaker indicators and do not specifically demonstrate automation.

Exam trap

The trap here is favoring infrastructure clues like new domains or self-signed certificates over behavioral patterns that actually reveal automation.

101
MCQeasy

In the Cyber Kill Chain, which phase involves sending a malicious attachment to a targeted user?

A.Exploitation
B.Delivery
C.Weaponization
D.Reconnaissance
AnswerB

Delivery is the phase where the adversary transmits the weaponised payload — such as a malicious attachment or link — to the target. Exploitation occurs only after the user opens it, so transmission itself sits in Delivery.

Why this answer

In the Lockheed Martin Cyber Kill Chain, Delivery is the phase where the attacker transmits the weaponised payload to the victim — for example, via a phishing email with a malicious attachment, a malicious link, or a USB drop. Sending the malicious attachment to a targeted user is the textbook definition of Delivery. Weaponization (the prior phase) is where the attacker pairs the exploit with the payload, but the actual transmission to the target is Delivery.

Exam trap

200-201 often tests the boundary between Weaponization and Delivery — candidates pick Weaponization because the attachment is 'malicious', but the act of sending it is what defines Delivery.

How to eliminate wrong answers

Option A is wrong because Exploitation is when the delivered payload actually triggers a vulnerability to execute code on the target — it happens after delivery. Option C is wrong because Weaponization is the preparation step where the attacker couples malware with an exploit into a deliverable payload; nothing has been sent to the victim yet. Option D is wrong because Reconnaissance is information gathering (OSINT, scanning) that occurs before any payload is created or sent.

102
MCQeasy

During the Cyber Kill Chain, which phase involves sending a malicious attachment to a target user via email?

A.Exploitation
B.Weaponization
C.Delivery
D.Reconnaissance
AnswerC

Delivery is the phase where the adversary transmits the weaponised payload to the victim, such as a malicious attachment sent by email. Exploitation occurs only after the user opens it, so delivery is the correct phase.

Why this answer

Delivery is the phase where the attacker transmits the weaponized payload to the target, such as via email attachments.

103
MCQhard

An analyst examining a PCAP sees an internal host sending ICMP echo requests where the payload length is consistently 1,100 bytes and the payload bytes change on every packet, while the destination is an external IP that returns echo replies of normal size. The host has no monitoring tool installed and no legitimate reason to send large ICMP. Which technique is most likely being used?

A.A ping flood denial-of-service attack against the external host.
B.Path MTU discovery using oversized ICMP packets to find fragmentation limits.
C.ICMP tunneling used to exfiltrate or relay data inside echo request payloads.
D.A smurf attack reflecting ICMP echo requests off the external host to a broadcast address.
AnswerC

Large, consistently sized ICMP echo requests with payloads that change on every packet indicate data is being carried inside the ICMP payload rather than standard reachability testing. Normal ping payloads are small and static, often a fixed pattern. The external host returning normal-sized replies fits a covert channel where the request carries the data outbound. This is a classic ICMP tunneling signature that warrants payload inspection and host isolation.

Why this answer

Normal ICMP echo traffic uses small, fixed payloads for reachability. Large echo requests whose payload changes on every packet indicate the ICMP payload is being used as a transport for data, a covert channel known as ICMP tunneling. The external endpoint returning ordinary replies supports a request-carries-data-out model.

Flood, MTU discovery, and smurf do not produce varying large payloads from a single internal host.

Exam trap

The trap here is treating any large ICMP packet as a denial-of-service or MTU issue, when varying payload contents inside echo requests reveal a covert data channel instead.

104
MCQmedium

An analyst detects multiple SMB authentication attempts from a single internal host to several other internal hosts using NTLM hashes instead of plaintext passwords. Which technique is most likely being used?

A.Brute force
B.Kerberoasting
C.Golden ticket attack
D.Pass-the-hash
AnswerD

Pass-the-hash reuses captured NTLM password hashes directly for authentication, bypassing plaintext password knowledge entirely. The multiple SMB connections between internal hosts using hashes rather than credentials match this technique's signature, distinguishing it from credential cracking.

Why this answer

Pass-the-hash is the technique where an attacker uses a captured NTLM hash to authenticate to remote systems without knowing the plaintext password. The scenario — one internal host authenticating to many others using NTLM hashes — is the canonical lateral-movement signature of pass-the-hash, typically executed with tools like Mimikatz, CrackMapExec, or Impacket. The fan-out pattern from a single source to multiple targets is a strong indicator of automated credential reuse.

Exam trap

200-201 often tests the distinction between pass-the-hash (replaying a stolen NTLM hash) and Kerberoasting (cracking Kerberos service tickets) — candidates pick Kerberoasting because both involve credential theft, but only pass-the-hash uses NTLM hashes over SMB.

How to eliminate wrong answers

Option A is wrong because brute force generates many failed authentication attempts against a target, not successful hash-based logons across many hosts. Option B is wrong because Kerberoasting targets Kerberos service tickets (TGS-REPs) for offline cracking of service account passwords — it does not involve NTLM hash authentication over SMB. Option C is wrong because a golden ticket forges a Kerberos TGT using the KRBTGT hash and is validated through Kerberos, not NTLM.

105
MCQeasy

A junior analyst is reviewing a packet capture and sees a workstation repeatedly sending ICMPv4 Type 8 packets to an external IP address with varying payload sizes. The analyst wants to confirm whether this activity is a covert channel. Which characteristic of the ICMP traffic would most strongly suggest that the ICMP payload is being used to exfiltrate data?

A.The ICMP payload data changes on every request and contains non-printable, high-entropy bytes.
B.The ICMP echo requests are sent at a fixed interval of exactly one second.
C.The ICMP echo requests contain a consistent sequence number and identifier.
D.The ICMP echo requests receive echo replies from the same external IP address.
AnswerA

Legitimate ping payloads are usually fixed patterns such as alphabetic strings or zeros. When the payload varies on every request and contains high-entropy, non-printable bytes, it suggests data is being encoded into the ICMP data field for exfiltration. This is a classic indicator of an ICMP tunnel or covert channel, especially when combined with a consistent external destination.

Why this answer

Covert ICMP channels hide data inside the payload of echo requests and replies. Benign pings use fixed, printable payload patterns, so a payload that changes on every packet and contains high-entropy, non-printable bytes strongly suggests encoded data is being transmitted. Combined with an external destination, this pattern points to ICMP-based exfiltration rather than routine connectivity testing.

Exam trap

The trap here is focusing on packet timing or reply behaviour, which are normal for ping, instead of inspecting the payload content where covert data actually hides.

106
MCQmedium

During an intrusion analysis, a SOC analyst reviews logs showing an outbound connection from an internal host to an external IP at 03:00 AM every 60 seconds. The traffic is HTTPS to a suspicious domain with a high entropy name. Which phase of the Cyber Kill Chain does this activity represent?

A.Actions on Objectives
B.Delivery
C.Command and Control (C2)
D.Weaponisation
AnswerC

Regular beaconing at fixed 60-second intervals to an external suspicious high-entropy domain over HTTPS indicates an implanted host checking in with its controller. This periodic callback traffic is the hallmark of the Command and Control phase of the Cyber Kill Chain.

Why this answer

Periodic outbound HTTPS connections to a suspicious high-entropy domain at fixed intervals are the classic signature of Command and Control (C2) beaconing, where an implant checks in with its controller for instructions. The regularity (every 60 seconds) and the high-entropy domain name (typical of DGA or attacker-registered infrastructure) are the defining indicators. This activity occurs after exploitation and installation, when the malware establishes its channel back to the attacker.

Exam trap

200-201 often tests whether candidates can distinguish C2 (periodic callbacks to attacker infrastructure) from Delivery (initial payload transmission) — the presence of 'external IP' in the question tempts candidates toward Delivery.

How to eliminate wrong answers

Option A is wrong because Actions on Objectives is the final phase where the attacker achieves their goal (data theft, encryption, destruction) — beaconing is the channel setup, not the objective execution. Option B is wrong because Delivery is the initial transmission of the payload to the victim, which happens before any C2 channel exists. Option D is wrong because Weaponisation is the preparation of the payload with an exploit, occurring before delivery and long before any network callback.

107
Multi-Selectmedium

An analyst is examining network alerts for lateral movement. Which TWO of the following are typical indicators of lateral movement using SMB?

Select 2 answers
A.A single SMB connection to a file server
B.Multiple SMB connection attempts from a single host to many different hosts
C.NTLM authentication using a hash instead of a password
D.DNS queries for internal hostnames
E.HTTP requests to a web server
AnswersB, C

Lateral movement tools such as PsExec and Cobalt Strike's SMB beacon rapidly authenticate to many hosts from one source. A single host initiating SMB sessions to numerous distinct hosts deviates from normal peer-to-peer patterns and indicates propagation.

Why this answer

Option B is correct because lateral movement via SMB typically manifests as one compromised host rapidly initiating SMB (TCP 445) connections to numerous distinct internal hosts, reflecting an attempt to fan out and find accessible targets or admin shares such as C$ or ADMIN$. Option C is correct because pass-the-hash attacks, a hallmark of SMB-based lateral movement, authenticate with an NTLM hash via NTLM challenge-response rather than a cleartext password, which is anomalous and strongly indicative of credential theft and reuse. Option A is not an indicator because a single SMB connection to a file server is normal, benign business activity.

Option D is not specific to SMB lateral movement, since DNS queries for internal hostnames occur routinely during normal name resolution. Option E is unrelated, as HTTP requests to a web server involve the HTTP protocol on ports 80/443, not SMB.

Exam trap

200-201 often tests the confusion between normal SMB traffic and malicious lateral movement, and the misconception that any NTLM authentication is suspicious when only hash-based authentication is a red flag.

108
MCQmedium

A SOC analyst reviewing a packet capture notices that a single internal host has initiated hundreds of short-lived TCP sessions to the same external web server over the past hour, and every session completed a full three-way handshake before being torn down with FIN/ACK. No single session transferred more than a few kilobytes. Which traffic characteristic should the analyst use to classify this activity?

A.Possible beaconing or automated application behavior, because repeated uniform short sessions at regular volume suggest periodic callbacks.
B.A TCP SYN flood, because many connection attempts were made to one destination in a short period.
C.A slowloris-style denial of service, because each session stayed open for a short time.
D.A port scan, because the host contacted the same server repeatedly.
AnswerA

Repeated, uniform, short-lived completed TCP sessions to the same external endpoint are characteristic of beaconing malware or an automated client polling a service on a timer. The consistent small transfer size and full handshake/teardown pattern distinguish it from scanning or flooding. The analyst should baseline the interval and correlate with process and destination reputation to confirm whether it is malicious command-and-control.

Why this answer

Repeated short TCP sessions with complete handshakes and consistent small payloads point to periodic automated communication such as malware beaconing, not resource-exhaustion attacks or scanning. A SYN flood and slowloris both leave connections incomplete by design, while a port scan varies destination ports and usually never completes a session. The distinguishing evidence is the uniform, repeating, fully established flow pattern.

Exam trap

The trap here is assuming that high connection volume to one destination automatically means a denial-of-service flood, when the state of the handshake and teardown reveals the true nature of the traffic.

109
Multi-Selecthard

During an incident response, an analyst finds evidence of lateral movement. Which THREE of the following are common techniques used for lateral movement?

Select 3 answers
A.Remote Desktop Protocol (RDP) connections
B.SMB authentication attempts across multiple hosts
C.DNS tunneling
D.Pass-the-hash attacks
E.ICMP echo requests
AnswersA, B, D

RDP gives an attacker an interactive graphical session on a remote host once valid credentials are obtained, enabling direct control of additional systems. That remote-access mechanism moves the intrusion sideways across the estate, matching the stem's lateral movement evidence.

Why this answer

SMB authentication attempts, pass-the-hash, and RDP are common lateral movement techniques.

110
MCQmedium

An analyst reviews an alert that triggered on a network signature for 'shellcode' in a payload. The payload contains a sequence of NOP sleds followed by executable code. Which type of exploitation technique does this indicate?

A.Return-oriented programming (ROP)
B.Heap spray
C.Buffer overflow with NOP sled
D.Format string attack
AnswerC

A NOP sled preceding executable code is the signature of a buffer overflow exploit, where the sled provides a landing zone for the overwritten return address to jump into. The network signature detecting shellcode in the payload confirms this exploitation technique.

Why this answer

A NOP sled (a long run of no-operation instructions) immediately preceding shellcode is the classic signature of a stack-based buffer overflow exploit. The sled gives the attacker a large landing zone so the overwritten return address only needs to jump somewhere into the sled, which then slides execution into the payload.

Exam trap

200-201 often tests whether candidates can distinguish NOP-sled buffer overflows from heap sprays and ROP, since all three involve shellcode delivery but use different memory structures and bypass techniques.

How to eliminate wrong answers

Option A is wrong because ROP chains together short existing code gadgets ending in return instructions to bypass DEP, and does not rely on a NOP sled. Option B is wrong because heap spray fills heap memory with repeated copies of shellcode (often using NOP-like padding) to increase the odds of a jump landing in the payload, but the described sequence of NOP sled plus executable code in a single payload is the buffer overflow pattern. Option D is wrong because format string attacks abuse printf-style format specifiers like %n to write to memory, not NOP sleds.

111
Multi-Selecthard

During PCAP analysis, a security analyst observes the following pattern: a series of TCP SYN packets to multiple ports on a target, followed by RST packets from the target for closed ports. Which TWO characteristics describe this scan?

Select 2 answers
A.It uses ICMP echo requests
B.It is a SYN scan
C.It is a UDP scan
D.It completes the TCP three-way handshake
E.It is a stealthy scan that may avoid logging
AnswersB, E

Sending SYN packets to multiple ports and interpreting RST replies for closed ports is the defining behaviour of a half-open SYN scan, which never completes the handshake. This matches the packet pattern in the stem, distinguishing it from a full-connect scan that completes the three-way handshake.

Why this answer

The SYN scan sends SYN packets and listens for SYN-ACK (open) or RST (closed). It is a stealthy scan because it doesn't complete the TCP handshake.

112
MCQmedium

An analyst notices that a DNS query for 'www.attacker.com' contains a long subdomain with Base64-encoded data. This activity is observed every 5 minutes. What exfiltration technique is most likely in use?

A.Steganography
B.DNS tunneling
C.HTTP POST exfiltration
D.FTP exfiltration
AnswerB

DNS tunneling uses DNS queries to exfiltrate data.

Why this answer

DNS tunneling encodes data within DNS queries and responses, often using Base64 or hex in subdomains, and is characterized by periodic, high-volume queries to a single domain. The long Base64-encoded subdomain and 5-minute interval are classic indicators of data exfiltration via DNS. Attackers use this because DNS is rarely blocked and often overlooked by security controls.

Exam trap

The trap here is confusing DNS tunneling with other exfiltration methods; candidates may pick HTTP POST because they see 'data exfiltration' but miss the DNS-specific indicators like Base64 subdomains and periodic queries.

How to eliminate wrong answers

Option A is wrong because steganography hides data inside images or other media files, not in DNS query strings. Option C is wrong because HTTP POST exfiltration would show large outbound HTTP payloads to an external server, not encoded subdomains in DNS queries. Option D is wrong because FTP exfiltration involves file transfers over ports 20/21, which would not appear as DNS queries with Base64-encoded subdomains.

113
MCQhard

An analyst inspects a PCAP and finds a TCP stream where the client and server exchange data in alternating small chunks, each packet's payload is roughly 40 to 60 bytes, and the conversation lasts over two hours with consistent inter-packet delays of about ten seconds. The destination port is 443 but the payload is not TLS. Which conclusion is best supported?

A.The traffic is a large file transfer that has been fragmented by the network
B.The traffic is a reverse shell or command-and-control channel using interactive command semantics
C.The traffic is a DNS-over-HTTPS session resolving names for a busy client
D.The traffic is a misconfigured TLS session negotiating an unusually small cipher block
AnswerB

Alternating small payloads, long duration, and steady delays are hallmarks of an interactive remote shell or beacon where each request and response carries a short command or result. A reverse shell keeps the session alive for hours, and the ten-second cadence reflects either human interaction or a beacon interval. The non-TLS payload on port 443 confirms deliberate port masquerading to blend with expected HTTPS traffic.

Why this answer

Long-lived sessions with alternating short payloads and a steady interval are characteristic of interactive command-and-control or reverse shells, where each message carries a command or its output. Bulk transfers, TLS cipher negotiation, and DNS-over-HTTPS all produce different payload sizes, framing, and timing. The use of port 443 without TLS framing strengthens the conclusion that the port is being used to evade egress filtering rather than for legitimate web traffic.

Exam trap

The trap here is treating the destination port as proof of the protocol, when the payload inspection shows no TLS and the timing profile contradicts normal web browsing.

114
Multi-Selectmedium

An analyst is investigating a suspected FTP brute-force attack. The logs show numerous failed login attempts from a single external IP to multiple user accounts on an internal FTP server. Which two additional pieces of evidence would best confirm a brute-force attack? (Choose two.)

Select 2 answers
A.The FTP server is configured to allow anonymous access.
B.A high number of FTP 530 Login incorrect responses within a short time window.
C.The external IP is listed on a threat intelligence feed for credential stuffing.
D.The FTP server uses plaintext authentication.
E.The external IP has a low reputation score but no specific threat intelligence tags.
AnswersB, C

FTP 530 responses indicate failed logins. A high frequency of these within a short period strongly suggests automated brute-force attempts, as legitimate users rarely fail repeatedly in rapid succession. This is a key indicator of brute-force activity.

Why this answer

The correct answers are a high number of FTP 530 Login incorrect responses within a short time window and threat intelligence linking the external IP to credential stuffing. These directly support the brute-force hypothesis: repeated failures indicate automated attempts, and threat intel provides context that the source is malicious.

Exam trap

The trap here is focusing on server configuration weaknesses like anonymous access or plaintext authentication, which are vulnerabilities but do not confirm an ongoing brute-force attack.

115
MCQmedium

A security analyst is reviewing PCAP data and sees a TCP stream with interactive shell commands such as 'whoami', 'ls -la', and 'cat /etc/passwd'. The session appears to be bidirectional with a remote IP. Which type of attack is most likely occurring?

A.Reverse shell
B.DNS tunnelling
C.SQL injection
D.Man-in-the-middle attack
AnswerA

A reverse shell is an outbound connection from the victim to an attacker-controlled listener, carrying interactive commands such as whoami, ls -la and cat /etc/passwd. The bidirectional stream to a remote IP matches this pattern rather than inbound exploitation.

Why this answer

Interactive shell commands over TCP indicate a reverse shell, where the attacker has a command shell on the victim.

116
MCQmedium

Which tool can be used to extract files from a PCAP file for further analysis?

A.Wireshark (Export Objects)
B.Snort
C.tcpdump
D.nmap
AnswerA

Wireshark's Export Objects feature reconstructs files carried over protocols such as HTTP, SMB and TFTP from captured packets and writes them to disk. This directly satisfies the requirement to extract files from a PCAP for further analysis, unlike tools that only inspect headers or statistics.

Why this answer

Wireshark's 'Export Objects' feature allows you to extract files (e.g., HTTP objects, SMB files, or other application-layer payloads) from a PCAP file. This is essential for further analysis of malware or data exfiltration, as it reconstructs the original files from the captured network streams without needing to replay the traffic.

Exam trap

Cisco often tests the distinction between packet capture tools (tcpdump) and protocol analysis tools (Wireshark), leading candidates to mistakenly think tcpdump can extract files because it can read PCAPs, but it only outputs raw packet data without application-layer reconstruction.

How to eliminate wrong answers

Option B (Snort) is wrong because Snort is an intrusion detection/prevention system (IDS/IPS) that analyzes traffic in real-time using rules, but it does not have a built-in feature to extract files from a PCAP for offline analysis. Option C (tcpdump) is wrong because tcpdump is a command-line packet capture tool that can read PCAP files and display packet headers, but it cannot extract application-layer objects like files; it lacks the protocol dissection and reassembly needed for file extraction. Option D (nmap) is wrong because nmap is a network scanning tool used for host discovery and port scanning, not for parsing PCAP files or extracting embedded objects.

117
MCQeasy

A network analyst is reviewing firewall logs and sees repeated inbound connections from a single external IP to TCP port 445 on multiple internal hosts over a short period. The connections are followed by SMB negotiation attempts. Which activity does this most likely represent?

A.A backup server replicating data to internal hosts
B.DNS zone transfer requests to internal DNS servers
C.SMB enumeration or exploitation attempts against internal file-sharing services
D.Normal SMB file access by remote employees using VPN
AnswerC

Repeated inbound connections to TCP 445 across multiple hosts, followed by SMB negotiation, indicate an external actor probing or attacking SMB services. Port 445 is used by SMB for file sharing and is a common target for enumeration and exploitation. The breadth of targets suggests scanning or worm-like behavior rather than a single targeted connection.

Why this answer

Inbound SMB connections to TCP port 445 from one external IP across many internal hosts indicate enumeration or exploitation of file-sharing services. Backup traffic, legitimate VPN-based file access, and DNS zone transfers have different source, port, and pattern characteristics. The sweep across multiple hosts in a short time is the key indicator of malicious SMB activity.

Exam trap

The trap here is treating any SMB traffic as normal file sharing and ignoring that the source is external and the targets are numerous.

118
MCQmedium

An analyst detects traffic from an internal host that periodically sends small DNS queries to a domain with high entropy subdomains (e.g., 'a3k9f2.example.com'). The domain is not on any blocklist, and the query intervals are consistent every 60 seconds. Which technique is most likely being used?

A.DNS tunnelling for C2 communication
B.DNS amplification attack
C.Normal DNS resolution for a dynamic DNS service
D.DNS cache poisoning attempt
AnswerA

High-entropy subdomains carrying small queries at fixed 60-second intervals indicate data encoded into DNS labels and exfiltrated or commanded through recursive resolvers. The absence from blocklists and regular beaconing fit DNS tunnelling used for command-and-control rather than normal resolution.

Why this answer

DNS tunnelling encodes data in subdomain queries, and periodic beaconing is common for C2. High entropy subdomains and regular intervals suggest DNS tunnelling for C2.

119
MCQeasy

A security analyst receives an alert for a known malware signature in an outbound file transfer. After investigation, the file is confirmed as benign software. This alert is classified as:

A.False positive
B.True positive
C.False negative
D.True negative
AnswerA

A false positive occurs when detection logic flags activity that is actually benign, so a confirmed benign file triggering a known-malware signature matches this classification. The alert fired correctly per the signature, but the underlying file is harmless, distinguishing it from a true positive.

Why this answer

A false positive is an alert that fires for benign activity — the detection correctly identified a signature match, but the file was confirmed benign, so the alert is a false positive. In this scenario, the malware signature matched an outbound file transfer, but investigation confirmed the file is legitimate software, making it a false positive.

Exam trap

The 200-201 exam often tests the distinction between false positive and true positive — the trap is confusing 'an alert fired' with 'the alert was correct,' leading candidates to pick true positive when the activity is confirmed benign.

How to eliminate wrong answers

Option B is wrong because a true positive means the alert correctly identified actual malicious activity — here the file is confirmed benign, so the alert is not a true positive. Option C is wrong because a false negative is a missed detection — malicious activity that did not trigger an alert — which is the opposite of this scenario where an alert did fire. Option D is wrong because a true negative is the correct absence of an alert for benign activity — here an alert did fire, so it cannot be a true negative.

120
MCQeasy

An analyst observes an alert triggered by a single SYN packet to a closed port. The packet did not complete a TCP handshake. What type of attack does this most likely indicate?

A.SYN scan
B.TCP connect scan
C.Ping sweep
D.UDP scan
AnswerA

A SYN scan sends a lone SYN packet to probe a port; a closed port replies with RST, and no handshake completes. This matches the stem's single SYN to a closed port, satisfying the constraint that the connection never finished the TCP three-way handshake.

Why this answer

A single SYN packet to a closed port that does not complete the TCP handshake is the signature of a SYN scan (half-open scan). The scanner sends SYN; if the port is closed, the target responds with RST, and the scanner never sends ACK. This is the classic behavior of tools like Nmap's -sS scan.

Exam trap

The trap is confusing SYN scan with TCP connect scan — candidates may pick TCP connect scan because both involve SYN packets, but only SYN scan leaves the handshake incomplete.

How to eliminate wrong answers

Option B is wrong because a TCP connect scan completes the full three-way handshake (SYN, SYN-ACK, ACK) using the OS's connect() call, which would show a completed handshake in logs. Option C is wrong because a ping sweep uses ICMP Echo requests, not TCP SYN packets. Option D is wrong because a UDP scan sends UDP packets, not TCP SYN, and would not trigger a TCP handshake-related alert.

121
MCQmedium

During an incident response, an analyst identifies a PCAP containing an HTTP POST request to a suspicious external IP with a large payload. The response is not typical for web applications. What type of activity is most likely occurring?

A.SQL injection attack
B.Normal web browsing
C.Data exfiltration
D.Command and control beaconing
AnswerC

A large outbound HTTP POST to an untrusted external address, with a response that does not match normal application behaviour, indicates data being uploaded out of the network. Exfiltration over HTTP commonly abuses permitted web traffic to move stolen data past egress controls.

Why this answer

A large HTTP POST to an external IP with an atypical response is the classic signature of data exfiltration — the attacker uses a legitimate-looking outbound channel (HTTP POST) to push stolen data to attacker-controlled infrastructure. The 'large payload' is the stolen data leaving the network, and the unusual response indicates the endpoint is not a real web application but a collection point.

Exam trap

The trap here is confusing any HTTP POST to an external IP with C2 beaconing; candidates must distinguish bulk one-shot egress (exfiltration) from small periodic callbacks (C2).

How to eliminate wrong answers

Option A is wrong because SQL injection is an inbound attack against a web application's database layer, typically seen as malicious GET/POST parameters to a legitimate server, not a large outbound POST to an external suspicious IP. Option B is wrong because normal web browsing produces small, symmetric request/response patterns to known sites, not large one-way payloads to suspicious external IPs. Option D is wrong because C2 beaconing is characterized by small, periodic, low-volume callbacks (often with jitter) to maintain persistence, not a single large POST carrying bulk data.

122
MCQmedium

An analyst is analyzing a PCAP and sees multiple ICMP port unreachable responses from a target host when scanning UDP ports. What does this indicate about the scanned ports?

A.The ports are closed.
B.The scan is a SYN scan.
C.The ports are filtered by a firewall.
D.The ports are open.
AnswerA

An ICMP port unreachable response means the target host received the UDP datagram but no application is listening on that port, which is the definitive indicator that the scanned port is closed rather than filtered.

Why this answer

When a UDP scan sends a packet to a closed port, the target responds with an ICMP port unreachable message.

← PreviousPage 2 of 2 · 122 questions total

Ready to test yourself?

Try a timed practice session using only Network Intrusion Analysis questions.