Courseiva

CCNA Security Concepts Questions

68 of 143 questions · Page 2/2 · Security Concepts · Answers revealed

76
MCQmedium

Which cryptographic technique uses a public and private key pair to provide non-repudiation?

A.Digital signature
B.Symmetric encryption
C.Digital certificate
D.Hashing
AnswerA

A digital signature is generated using the sender's private key, which only they possess, so they cannot later deny creating it. Verification with the corresponding public key provides non-repudiation, the specific property the stem requires.

Why this answer

A digital signature is created by hashing the message and encrypting that hash with the sender's private key. Anyone can verify it using the sender's public key, and because only the sender possesses the private key, the sender cannot later deny having signed it — this is non-repudiation. Symmetric encryption, certificates, and hashing alone do not provide that property.

Exam trap

200-201 often tests the difference between integrity (hashing), confidentiality (encryption), authentication (certificates), and non-repudiation (digital signatures) — candidates confuse digital certificates with digital signatures, but only the signature uses the private key to prove origin.

How to eliminate wrong answers

Option B is wrong because symmetric encryption uses a single shared secret key for both encryption and decryption, so either party could have produced the ciphertext — there is no proof of origin and thus no non-repudiation. Option C is wrong because a digital certificate binds a public key to an identity via a CA's signature; it enables authentication and trust but does not itself sign the message or provide non-repudiation of the message content. Option D is wrong because hashing alone provides integrity (a fixed-length digest) but no key or identity binding — anyone can compute the same hash, so it cannot prove who sent the data.

77
MCQmedium

An attacker intercepts communication between two parties and modifies the data before forwarding it. Which type of attack is this?

A.Man-in-the-middle
B.DNS poisoning
C.Replay attack
D.ARP spoofing
AnswerA

A man-in-the-middle attack places the adversary between two communicating parties, relaying traffic while altering its contents before forwarding, which matches the stem's interception plus modification. The attacker typically achieves this position through ARP spoofing, rogue Wi-Fi access points or DNS poisoning, breaking both confidentiality and integrity.

Why this answer

A man-in-the-middle (MITM) attack occurs when an attacker intercepts and alters communications between two parties without their knowledge. The attacker positions themselves between the sender and receiver, capturing, modifying, and then forwarding the data, which directly matches the scenario described.

Exam trap

Cisco often tests the distinction between the attack type (MITM) and the technique used to achieve it (ARP spoofing), causing candidates to confuse the method with the overarching attack category.

How to eliminate wrong answers

Option B (DNS poisoning) is wrong because it involves corrupting a DNS resolver's cache to redirect traffic to a malicious site, not intercepting and modifying an existing communication stream. Option C (Replay attack) is wrong because it captures valid data and retransmits it later, but does not involve modifying the data before forwarding. Option D (ARP spoofing) is wrong because it is a specific technique used to facilitate MITM attacks by linking the attacker's MAC address to a legitimate IP address, but it is not the attack itself—it is a method to achieve a MITM position.

78
MCQmedium

A company's web server is overwhelmed with traffic from many compromised devices, causing legitimate users to be unable to access the site. What type of attack is this?

A.ARP spoofing
B.DoS
C.DNS poisoning
D.DDoS
AnswerD

A distributed denial-of-service attack floods the web server with traffic from many compromised devices, exhausting its capacity so legitimate users cannot connect. The stem's defining constraint — numerous geographically dispersed sources overwhelming one target — distinguishes DDoS from a single-source DoS, which one host alone generates.

Why this answer

A DDoS (Distributed Denial of Service) attack uses many compromised devices — often a botnet — to flood a target with traffic, overwhelming its resources so legitimate users cannot connect. The key distinguishing factor in the question is 'many compromised devices,' which indicates distribution across multiple sources rather than a single attacking host. This matches the definition of DDoS and differentiates it from a single-source DoS attack.

Exam trap

200-201 often tests the distinction between DoS and DDoS by embedding the word 'many' or 'distributed' in the scenario — candidates who skim may pick DoS because it is the more familiar term, missing the distribution clue.

How to eliminate wrong answers

Option A is wrong because ARP spoofing is a layer-2 attack that poisons ARP caches to intercept or redirect traffic on a local network segment; it does not generate the volumetric flood described. Option B is wrong because DoS (Denial of Service) originates from a single source or a single attack vector, whereas the question explicitly states traffic comes from many compromised devices. Option C is wrong because DNS poisoning corrupts DNS resolver caches to redirect users to malicious sites; it does not overwhelm a web server with traffic.

79
MCQmedium

A user receives an email that appears to be from their bank, asking them to click a link and verify their account details. The email contains a sense of urgency. Which type of attack is this?

A.Pretexting
B.Vishing
C.Spear phishing
D.Phishing
AnswerD

The email spoofs a trusted bank, demands urgent verification and harvests credentials via a link, matching phishing's social-engineering mechanism. It satisfies the stem's constraints: forged sender identity, urgency pressure and a credential-capture link, distinguishing it from technical exploits that need no user interaction.

Why this answer

Phishing is a social engineering attack that uses deceptive emails to trick recipients into revealing sensitive information.

80
MCQmedium

A security analyst is examining a suspicious executable found on a compromised host. Static analysis reveals that the file contains a packer and obfuscated strings. When run in a sandbox, it attempts to connect to an external IP address and modifies registry keys for persistence. Which stage of the cyber kill chain does the registry modification represent?

A.Installation
B.Command and Control
C.Exploitation
D.Delivery
AnswerA

Installation is the stage where the attacker establishes persistence on the victim system. Modifying registry keys to ensure the malware runs on startup is a classic installation technique. The sandbox behavior of modifying registry keys aligns with maintaining access after the initial compromise.

Why this answer

Registry modification for persistence is part of the Installation stage of the cyber kill chain, where the attacker ensures the malware survives reboots. The other stages such as Delivery, Exploitation, and Command and Control occur at different points. The sandbox observation of registry changes indicates the malware is establishing a foothold.

Exam trap

The trap here is associating any external connection with Command and Control, but the registry modification specifically serves persistence, which is Installation.

81
MCQeasy

A security administrator is reviewing the company's incident response plan and wants to ensure that the team understands the difference between a vulnerability, a threat, and a risk. During a tabletop exercise, the administrator presents a scenario: a web server has an unpatched Apache Struts vulnerability, and a known exploit exists publicly. Which term best describes the unpatched Apache Struts vulnerability in this context?

A.Threat
B.Exploit
C.Vulnerability
D.Risk
AnswerC

A vulnerability is a weakness or flaw in a system that can be exploited by a threat. The unpatched Apache Struts vulnerability is a specific software weakness that could allow an attacker to compromise the server. This term accurately describes the condition of the unpatched software.

Why this answer

The unpatched Apache Struts issue is a software flaw that can be leveraged by an attacker, making it a vulnerability. Understanding this distinction is crucial for risk assessment: vulnerabilities are weaknesses, threats are actors or events that can exploit them, and risk is the potential impact. Correctly identifying the vulnerability helps prioritize remediation such as patching.

Exam trap

The trap here is equating a vulnerability with an exploit because a public exploit exists; however, the exploit is the method used to take advantage of the weakness, while the vulnerability is the weakness itself.

82
Multi-Selecthard

An analyst is investigating a malware infection on a workstation. The malware appears to be a trojan that downloads additional payloads and allows remote control. The analyst needs to classify the malware based on its behavior. Which THREE characteristics match this description? (Choose three.)

Select 3 answers
A.It provides unauthorized remote access to the system.
B.It downloads and installs additional malicious software.
C.It requires user interaction to execute.
D.It self-replicates without user interaction.
E.It encrypts files and demands ransom.
AnswersA, B, C

Remote-access trojans install a backdoor that grants the attacker interactive control of the workstation, satisfying the stem's "allows remote control" constraint. This unauthorised access is the defining behavioural characteristic distinguishing a RAT from payloads that merely download or self-replicate, so it matches the classification requirement directly.

Why this answer

The scenario describes a trojan that downloads additional payloads and allows remote control, so the correct characteristics are A, B, and C. Option A is correct because allowing remote control is precisely unauthorized remote access, the defining behavior of a Remote Access Trojan (RAT). Option B is correct because downloading additional payloads is a dropper/downloader behavior, where the initial malware retrieves and installs further malicious software.

Option C is correct because a trojan typically relies on social engineering or user execution (e.g., opening an attachment or running a file) to activate, unlike worms or exploits that can execute without interaction. Option D is incorrect because self-replication without user interaction describes a worm, not a trojan. Option E is incorrect because encrypting files and demanding ransom describes ransomware, which is not stated in this scenario.

Exam trap

Cisco often tests the distinction between trojans and worms by emphasizing that trojans require user interaction to execute, whereas worms self-replicate and spread automatically without user action.

83
MCQmedium

A security analyst is reviewing logs and notices that an attacker has intercepted and modified communications between two devices without their knowledge. Which type of attack is this?

A.ARP spoofing
B.DNS poisoning
C.Denial of Service (DoS)
D.Man-in-the-middle (MitM)
AnswerD

A man-in-the-middle attack satisfies the interception-and-modification constraint: the adversary covertly relays traffic between two endpoints, terminating each side's session so both devices believe they communicate directly. Sitting inline on the path, the attacker can read and alter data in transit undetected, matching the stem's silent modification of communications.

Why this answer

This scenario describes an attacker intercepting and modifying communications between two devices without their knowledge, which is the defining characteristic of a Man-in-the-Middle (MitM) attack. In a MitM attack, the attacker positions themselves between the two communicating parties, allowing them to eavesdrop, capture, and alter data in transit while both endpoints believe they are communicating directly with each other.

Exam trap

The trap here is that Cisco often tests the distinction between the attack technique (e.g., ARP spoofing) and the broader attack category (MitM), leading candidates to confuse a specific method with the overall attack type described in the question.

How to eliminate wrong answers

Option A is wrong because ARP spoofing is a specific technique used to associate an attacker's MAC address with the IP address of a legitimate device on a local network, enabling traffic interception; however, it is a method to facilitate an attack, not the attack itself described in the question. Option B is wrong because DNS poisoning corrupts the DNS resolver cache to redirect users to malicious sites by altering DNS records, but it does not inherently involve intercepting and modifying communications between two specific devices in real time. Option C is wrong because a Denial of Service (DoS) attack aims to overwhelm a target with traffic to disrupt service availability, not to intercept or modify communications between two devices.

84
MCQhard

A company processes credit card payments and must comply with a framework that mandates specific security controls for protecting cardholder data. Which compliance framework applies?

A.ISO 27001
B.PCI DSS
C.GDPR
D.HIPAA
AnswerB

PCI DSS applies because the stem specifies credit card payments and cardholder data protection. It is the payment card industry standard that mandates controls such as encryption, access restriction and network monitoring for any entity storing, processing or transmitting cardholder data, directly satisfying the stated compliance requirement.

Why this answer

PCI DSS (Payment Card Industry Data Security Standard) is the framework specifically mandated for organizations that store, process, or transmit cardholder data. It defines 12 requirement categories covering network security, access control, encryption, monitoring, and policy. Any company processing credit card payments must comply with PCI DSS.

Exam trap

200-201 often tests framework recognition — candidates confuse general security standards (ISO 27001) or privacy regulations (GDPR) with the cardholder-data-specific PCI DSS mandate.

How to eliminate wrong answers

Option A is wrong because ISO 27001 is a general information security management system standard — it is not specific to cardholder data and does not mandate the prescriptive controls PCI DSS requires. Option C is wrong because GDPR governs personal data privacy for EU residents; it addresses data protection rights and consent, not cardholder data security controls. Option D is wrong because HIPAA applies to protected health information in the US healthcare sector, not payment card data.

85
MCQmedium

Which compliance framework is specifically designed to protect the privacy and security of electronic health information in the United States?

A.GDPR
B.ISO 27001
C.HIPAA
D.PCI DSS
AnswerC

HIPAA, the Health Insurance Portability and Accountability Act, sets the US legal requirements for safeguarding protected health information held by covered entities and their business associates. Its Privacy and Security Rules specifically govern electronic health records, matching the scenario's demand for a US health-data framework.

Why this answer

HIPAA (Health Insurance Portability and Accountability Act) is the US federal law that specifically governs the privacy and security of protected health information (PHI) held by covered entities and business associates. It defines the Privacy Rule, Security Rule, and Breach Notification Rule, making it the direct answer for electronic health information in the United States. GDPR, ISO 27001, and PCI DSS address different scopes and jurisdictions.

Exam trap

200-201 often tests the confusion between general data protection regulations (GDPR) and sector-specific US laws (HIPAA), so candidates must anchor on the phrase 'electronic health information in the United States.'

How to eliminate wrong answers

Option A is wrong because GDPR is the European Union's general data protection regulation and, while it covers health data as a special category, it is not a US-specific health information framework. Option B is wrong because ISO 27001 is an international information security management standard, not a health-privacy law, and it is voluntary certification rather than regulation. Option D is wrong because PCI DSS governs payment card data security, not health information, and applies to any organization handling cardholder data regardless of industry.

86
MCQmedium

A company wants to protect its web application from injection attacks by ensuring that user-supplied input is not interpreted as code by the backend database. Which control should be implemented?

A.Web application firewall
B.Output encoding
C.Parameterized queries
D.Input validation
AnswerC

Parameterized queries, also called prepared statements, separate SQL code from data by sending the query structure and parameters separately. The database treats parameters as data, not executable code, which prevents SQL injection even if the input contains malicious characters. This directly meets the requirement.

Why this answer

Parameterized queries ensure that user input is passed as data and never concatenated into the SQL statement, so the database cannot interpret it as code. This is the most effective and fundamental defense against SQL injection, unlike input validation, output encoding, or a WAF.

Exam trap

The trap here is choosing a WAF or input validation as the primary fix, when the root cause is the lack of separation between code and data in the query.

87
MCQmedium

Which type of malware is characterized by self-replication and spreading to other systems without user interaction, often causing network congestion?

A.Ransomware
B.Trojan
C.Worm
D.Virus
AnswerC

A worm self-replicates and propagates across networks autonomously, requiring no user interaction or host file, unlike viruses that need a carrier. This satisfies the stem's constraint of spreading without user action, and its rapid, uncontrolled replication consumes bandwidth, directly causing the network congestion described.

Why this answer

A worm is self-replicating malware that spreads autonomously across networks without requiring a user to open a file or click a link, often consuming bandwidth and causing congestion. Classic examples include WannaCry's worm component and Conficker. Ransomware, Trojans, and viruses all require some form of user action or host file execution to propagate.

Exam trap

200-201 often tests the distinction between worms and viruses, so candidates must remember that the defining trait of a worm is autonomous self-replication without user interaction, not the type of damage it causes.

How to eliminate wrong answers

Option A is wrong because ransomware encrypts files and demands payment; while some ransomware (e.g., WannaCry) uses worm-like propagation, ransomware as a category is defined by its payload, not self-replication. Option B is wrong because a Trojan disguises itself as legitimate software and relies on the user to execute it, so it does not self-replicate. Option D is wrong because a virus requires a host file and typically user action (opening an infected document or running an executable) to spread, unlike a worm that propagates on its own.

88
Multi-Selectmedium

A security analyst is configuring a firewall to block common reconnaissance techniques. Which THREE types of reconnaissance traffic should be blocked to prevent active reconnaissance? (Choose three.)

Select 3 answers
A.Social engineering
B.WHOIS lookups
C.Vulnerability scanning
D.Port scanning
E.Ping sweeps
AnswersC, D, E

Vulnerability scanning actively probes target systems with crafted packets to identify known weaknesses, generating detectable traffic that a firewall can block. This satisfies the stem's requirement to prevent active reconnaissance, since scanning directly interacts with the target rather than gathering data passively from public sources.

Why this answer

Vulnerability scanning (C) is active reconnaissance because the attacker directly sends probes to the target to identify weaknesses, generating traffic the firewall can detect and block. Port scanning (D) is active reconnaissance since tools like Nmap send TCP SYN, FIN, or UDP packets to enumerate open ports on the target hosts. Ping sweeps (E) are active reconnaissance because ICMP Echo Request packets are sent across an address range to discover live hosts.

WHOIS lookups (B) are passive reconnaissance, as they query public registration databases rather than the target's own systems, so a firewall cannot block them. Social engineering (A) is a human-based attack that involves no network traffic to the firewall and is therefore not a reconnaissance traffic type to filter.

Exam trap

The trap here is confusing passive reconnaissance (e.g., WHOIS, social engineering) with active reconnaissance; candidates may incorrectly select social engineering or WHOIS because they are reconnaissance types, but they do not generate blockable network traffic.

89
MCQhard

A security analyst is reviewing a suspicious file recovered from a compromised endpoint. The file contains a macro that, when opened, launches PowerShell to download a second-stage payload from a remote server. The analyst wants to classify this file based on its behavior. Which classification is most accurate?

A.A dropper that delivers a malicious payload onto the system
B.A rootkit because it hides the PowerShell process
C.Fileless malware because it uses a scripting engine
D.A logic bomb because it triggers on a specific event
AnswerA

A dropper is code whose purpose is to install or download malware onto a target. The macro document fits this role: it executes on open and fetches a second-stage payload, establishing the infection. Classifying it as a dropper correctly describes its function in the attack chain rather than the payload it delivers.

Why this answer

The macro document functions as a dropper: its sole purpose is to execute and pull a second-stage payload onto the host. Droppers are common initial-access vehicles, and classifying by function helps the analyst understand the infection chain and prioritize response. The delivered payload may later exhibit other behaviors, but the file in hand is a dropper.

Exam trap

The trap here is labeling the threat fileless merely because PowerShell is involved, even though a macro document on disk is a clear file-based dropper.

90
Multi-Selectmedium

A security analyst is investigating a potential data breach. The analyst identifies that the attacker used a technique to impersonate a legitimate user by spoofing the MAC address and IP address. Which TWO types of network attacks could involve these techniques? (Choose two.)

Select 2 answers
A.ARP spoofing
B.Denial of Service
C.DNS poisoning
D.IP spoofing
E.Phishing
AnswersA, D

ARP spoofing sends forged Address Resolution Protocol replies, binding the attacker's MAC address to a legitimate user's IP address within the victim's cache. This satisfies the stem's requirement for both MAC and IP impersonation, enabling traffic interception or man-in-the-middle positioning on the local subnet.

Why this answer

ARP spoofing (A) is correct because it works by sending forged ARP replies that map the attacker's MAC address to a legitimate user's IP address, effectively spoofing both MAC and IP to impersonate that user on the local subnet. IP spoofing (D) is correct because it involves crafting packets with a forged source IP address (and often a spoofed MAC at layer 2) to make traffic appear to originate from a legitimate host. Denial of Service (B) focuses on exhausting resources or bandwidth rather than impersonating a user via MAC/IP spoofing.

DNS poisoning (C) corrupts DNS resolver cache entries to redirect name resolution, not to impersonate a user's MAC/IP identity. Phishing (E) is a social-engineering attack using deceptive messages or sites, not MAC/IP address spoofing.

Exam trap

Cisco often tests the distinction between IP spoofing (Layer 3) and ARP spoofing (Layer 2), and candidates may incorrectly assume that IP spoofing alone is sufficient for impersonation on a local network, forgetting that ARP resolution is required for actual traffic interception.

91
MCQhard

A security analyst is evaluating risks and calculates that a threat has a likelihood of 0.5 and an impact of $200,000. What is the risk value?

A.$50,000
B.$100,000
C.$400,000
D.$200,000
AnswerB

Multiplying likelihood (0.5) by impact ($200,000) yields $100,000, the quantitative risk value the analyst must report. This satisfies the stem's single-step calculation, giving the expected loss figure that feeds directly into the risk register and subsequent prioritisation decisions.

Why this answer

The risk value is calculated by multiplying the likelihood (0.5) by the impact ($200,000), resulting in $100,000. This is the standard quantitative risk analysis formula used in security assessments to prioritize threats.

Exam trap

Cisco often tests the basic risk calculation formula (Risk = Likelihood × Impact) and the trap here is that candidates may mistakenly use the impact value alone or apply incorrect arithmetic, such as dividing instead of multiplying.

How to eliminate wrong answers

Option A is wrong because $50,000 would result from multiplying 0.25 by $200,000, not 0.5. Option C is wrong because $400,000 would result from multiplying 2.0 by $200,000, which is not a valid probability. Option D is wrong because $200,000 assumes a likelihood of 1.0, ignoring the 0.5 probability factor.

92
MCQmedium

A security analyst is investigating a recent security breach. The analyst discovers that an attacker gained access to the network by exploiting a vulnerability in an unpatched web server. After gaining access, the attacker moved laterally to other systems and exfiltrated sensitive data. The organization wants to improve its security posture to prevent similar incidents. Which security concept best describes the attacker's actions after initial compromise?

A.Reconnaissance
B.Persistence
C.Privilege escalation
D.Lateral movement
AnswerD

Lateral movement refers to the techniques an attacker uses to move through a network after initial compromise, seeking additional access and privileges. In this scenario, the attacker moved from the compromised web server to other systems, which is lateral movement. This phase often involves credential dumping, remote execution, and internal reconnaissance.

Why this answer

After exploiting the web server, the attacker moved to other systems, which is lateral movement. This phase is about expanding access within the network. Privilege escalation, persistence, and reconnaissance are different phases of an attack.

Lateral movement is a key concept in understanding how attackers spread and compromise additional assets.

Exam trap

The trap here is equating any post-compromise activity with privilege escalation; lateral movement specifically involves moving between systems, while privilege escalation is about gaining higher privileges on a single system.

93
MCQmedium

A security analyst is investigating an incident where an attacker gained initial access to a corporate network. The analyst finds that the attacker sent a phishing email with a link to a malicious website that exploited a vulnerability in the user's browser. Which phase of the Cyber Kill Chain does the browser exploitation represent?

A.Weaponization
B.Installation
C.Reconnaissance
D.Exploitation
AnswerD

Exploitation is the phase where the attacker leverages a vulnerability to gain access, such as exploiting a browser flaw when the user visits a malicious site. In this scenario, the malicious website exploits the browser vulnerability, which is the defining action of the Exploitation phase. This occurs after delivery and before installation of persistent malware.

Why this answer

The Cyber Kill Chain phases are Reconnaissance, Weaponization, Delivery, Exploitation, Installation, Command and Control, and Actions on Objectives. When a user visits a malicious website that exploits a browser vulnerability, that action is Exploitation. It follows Delivery (the phishing email with the link) and precedes Installation of any persistent payload.

Exam trap

The trap here is confusing Delivery with Exploitation, but the delivery is the phishing email, while the actual vulnerability exploitation is the browser compromise.

94
MCQeasy

Which security concept describes the potential for a threat to exploit a vulnerability, and is often expressed as a combination of likelihood and impact?

A.Risk
B.Exploit
C.Threat
D.Vulnerability
AnswerA

Risk quantifies the potential for a threat to exploit a vulnerability, combining the likelihood of that exploitation with the resulting business impact. This matches the stem's definition precisely, distinguishing it from a vulnerability or threat in isolation.

Why this answer

Risk is defined as the potential for a threat to exploit a vulnerability, typically calculated as likelihood × impact. It is the overarching concept that combines the probability of a threat event with the resulting business or asset damage. In security frameworks like NIST and ISO 27005, risk = f(threat, vulnerability, impact, likelihood), which matches the question's wording exactly.

Exam trap

The trap here is confusing the four related terms — threat, vulnerability, exploit, and risk — because they are often used interchangeably in casual conversation, but the exam requires recognizing that only risk combines likelihood and impact.

How to eliminate wrong answers

Option B is wrong because an exploit is the specific tool, code, or technique that takes advantage of a vulnerability — it is the mechanism of attack, not the combined likelihood/impact measure. Option C is wrong because a threat is only the potential cause of an unwanted incident (e.g., an attacker or malware), not the composite measure of likelihood and impact. Option D is wrong because a vulnerability is merely a weakness in a system, application, or control — it has no inherent likelihood or impact value until paired with a threat and evaluated as risk.

95
MCQmedium

A security analyst is reviewing a packet capture from the DMZ and sees a host at 203.0.113.45 sending a flood of TCP segments with the SYN flag set to many different destination ports on a single internal web server, all within a few seconds. The source IP never completes the three-way handshake. Which type of attack is this host most likely performing?

A.Cross-site scripting attack
B.SYN flood denial-of-service attack
C.UDP amplification attack
D.ARP spoofing attack
AnswerB

A SYN flood exploits the TCP three-way handshake by sending many SYN packets, often with spoofed sources, without completing the handshake. The server allocates resources for each half-open connection, exhausting its backlog queue. The scenario shows exactly this pattern: many SYNs to multiple ports, no completed handshakes, quickly overwhelming the web server's connection table.

Why this answer

The observed traffic matches a SYN flood: a high volume of TCP SYN segments to many ports from one source, with no completed three-way handshakes. Each half-open connection consumes server resources until the backlog is exhausted, denying service to legitimate clients. This is a classic volumetric denial-of-service technique at Layer 4.

Exam trap

The trap here is assuming any flood of packets is a generic DoS without checking the TCP flags and handshake state, which specifically identify a SYN flood.

96
MCQhard

During an incident, an analyst finds a workstation that is beaconing to an external IP every 60 seconds using DNS TXT queries. The queries contain long, base64-encoded subdomains. The endpoint has no other suspicious network connections. Which technique is most likely being used?

A.Domain generation algorithm for ransomware
B.Fast flux DNS for phishing
C.DNS tunneling for command-and-control
D.DNS cache poisoning for redirection
AnswerC

DNS tunneling encodes data in DNS queries and responses, often using TXT records and long encoded subdomains, to exfiltrate data or receive commands. The regular 60-second beaconing and base64 payloads in TXT queries are hallmarks of DNS-based command-and-control, which blends with legitimate DNS traffic and often bypasses egress filtering.

Why this answer

The combination of regular beaconing, TXT record use, and base64-encoded subdomains strongly indicates DNS tunneling for command-and-control. Attackers use DNS because it is widely allowed through firewalls and rarely inspected deeply. Detecting it requires monitoring for anomalous query volume, unusually long labels, and consistent timing to a single external resolver.

Exam trap

The trap here is treating any suspicious DNS activity as a DGA, when the encoded TXT payloads and steady beaconing point specifically to tunneling.

97
MCQhard

An organization needs to ensure that a document has not been altered and to verify the sender's identity. Which combination of cryptographic techniques should be used?

A.Digital signature and hashing
B.Digital signature and symmetric encryption
C.Symmetric encryption and hashing
D.Asymmetric encryption and hashing
AnswerA

Hashing produces a fixed-length digest that detects any alteration to the document, satisfying the integrity requirement. Signing that hash with the sender's private key lets the recipient verify it using the public key, proving the sender's identity and origin.

Why this answer

A digital signature provides authentication (verifying the sender's identity via their private key) and integrity (proving the document was not altered), while hashing produces the fixed-length digest that the signature signs. Together they satisfy both requirements: the hash detects any modification, and the asymmetric signature binds the document to the sender's private key.

Exam trap

200-201 often tests the pairing of hashing with digital signatures — candidates pick 'asymmetric encryption and hashing' thinking encryption alone authenticates, but only a digital signature binds the sender's identity to the hash.

How to eliminate wrong answers

Option B is wrong because symmetric encryption uses a shared secret key, which cannot prove sender identity (both parties know the key) — it provides confidentiality, not authentication. Option C is wrong because symmetric encryption plus hashing still lacks non-repudiation and sender authentication, since the shared key does not uniquely identify the sender. Option D is wrong because asymmetric encryption alone (without a signature) provides confidentiality but not integrity verification or sender authentication in the sense required — hashing is needed to detect alteration, and the signature is what binds identity to the hash.

98
MCQeasy

A company wants to ensure that only authorized employees can enter the server room. Which type of control is a badge reader at the door?

A.Detective technical control
B.Corrective administrative control
C.Preventive physical control
D.Compensating logical control
AnswerC

A badge reader at the server room door is a preventive physical control because it stops unauthorized individuals from entering before access is granted. It enforces physical access restrictions by requiring a valid credential, thereby reducing the likelihood of unauthorized entry. This aligns with the goal of ensuring only authorized employees can enter, making it a preventive physical control rather than a detective or administrative one.

Why this answer

A badge reader restricts entry to a physical space by requiring valid credentials, so it functions as a preventive physical control. Preventive controls stop incidents before they happen, which matches the goal of allowing only authorized employees into the server room. Detective controls identify events after the fact, corrective controls restore operations, and compensating controls substitute for other measures.

Administrative and logical controls address policies and data rather than physical door access.

Exam trap

The trap here is focusing on the logs a badge reader produces and calling it detective, when its primary purpose is to prevent unauthorized physical entry.

99
MCQmedium

A security analyst is reviewing a vulnerability scan report and sees a finding labeled 'CVE-2021-44228' with a CVSS score of 10.0. The analyst needs to prioritize remediation. Which factor does the CVSS score primarily represent?

A.The likelihood that the vulnerability will be exploited in the wild within the next 30 days
B.The amount of time required to patch the vulnerability
C.The severity of the vulnerability based on its technical impact and exploitability
D.The business impact of the vulnerability specific to the organization's assets
AnswerC

CVSS (Common Vulnerability Scoring System) provides a numerical score reflecting the severity of a vulnerability based on metrics such as attack vector, complexity, privileges required, and impact on confidentiality, integrity, and availability. A score of 10.0 indicates maximum severity. The scenario asks what the CVSS score primarily represents, and it is the severity based on technical impact and exploitability.

Why this answer

CVSS is a standardized framework for rating the severity of security vulnerabilities. The base score, such as 10.0, reflects intrinsic characteristics like exploitability and impact. It does not predict exploitation likelihood, business-specific impact, or remediation time.

Analysts use CVSS alongside other factors to prioritize remediation.

Exam trap

The trap here is assuming CVSS predicts real-world exploitation; it is a severity score, not a threat intelligence metric.

100
MCQhard

During a security assessment, an analyst uses the Shodan search engine to find exposed industrial control systems. Which phase of the attack lifecycle does this activity represent?

A.Command and control
B.Reconnaissance
C.Delivery
D.Exploitation
AnswerB

Shodan passively indexes internet-facing devices, letting the analyst gather intelligence on exposed industrial control systems without directly interacting with them. This satisfies the reconnaissance phase, where adversaries collect target information before exploitation, mapping to the Cyber Kill Chain's first stage and the MITRE ATT&CK discovery tactic.

Why this answer

Using Shodan to search for exposed industrial control systems is a form of passive/active information gathering about the target's internet-facing assets — this is the Reconnaissance phase of the attack lifecycle (also called footprinting or information gathering). The attacker is mapping the attack surface before any exploitation, delivery, or command-and-control activity occurs. Shodan indexes banners from internet-connected devices, making it a classic reconnaissance tool.

Exam trap

The trap is confusing reconnaissance with exploitation because Shodan 'finds vulnerable systems' — candidates assume finding equals exploiting, but Shodan performs no exploitation; it only indexes publicly available banner data, which is pure reconnaissance.

How to eliminate wrong answers

Option A is wrong because Command and Control (C2) refers to the post-compromise channel an attacker uses to communicate with implanted malware — no compromise has occurred during Shodan searching. Option C is wrong because Delivery is the phase where the weaponized payload is transmitted to the victim (e.g., phishing email, malicious USB) — Shodan does not deliver anything. Option D is wrong because Exploitation is the phase where a vulnerability is actually triggered to gain code execution — Shodan only identifies potentially vulnerable systems, it does not exploit them.

101
Multi-Selectmedium

A security analyst is reviewing the cryptographic mechanisms used to protect data in transit and at rest. The organization wants to ensure confidentiality and integrity for sensitive files stored on a server and for data sent over a VPN. Which TWO of the following mechanisms provide both confidentiality and integrity for data? (Choose two.)

Select 2 answers
A.HMAC-SHA256
B.SHA-256 hashing
C.AES-256 in CBC mode with HMAC-SHA256
D.AES-256 in GCM mode
E.RSA-2048 encryption
AnswersC, D

AES-256 in CBC mode provides confidentiality by encrypting data, and combining it with HMAC-SHA256 provides integrity and authenticity through a keyed hash. This combination is a common approach in protocols like IPsec and TLS. Together they ensure both confidentiality and integrity for data in transit and at rest, satisfying the organization's requirements.

Why this answer

AES-256 in GCM mode and AES-256 in CBC mode combined with HMAC-SHA256 both provide confidentiality and integrity. GCM is an authenticated encryption mode that includes an integrity tag, while CBC with HMAC uses separate encryption and authentication. SHA-256 and HMAC-SHA256 alone lack confidentiality, and RSA-2048 encryption alone lacks inherent integrity.

Exam trap

The trap here is assuming that any strong cryptographic algorithm provides both confidentiality and integrity, when hashing and HMAC provide only integrity and encryption alone provides only confidentiality.

102
MCQhard

An analyst is reviewing network traffic and observes a series of DNS queries for long, random-looking subdomains of a single domain, followed by large TXT record responses. The queries occur at regular intervals and the volume is unusually high. Which type of attack is most likely indicated?

A.DNS cache poisoning
B.DNS tunneling
C.DNS amplification
D.Domain generation algorithm
AnswerB

DNS tunneling encodes data within DNS queries and responses, often using long, random-looking subdomains and large TXT records to exfiltrate data or communicate with command-and-control servers. The regular intervals and high volume are typical of automated tunneling tools that bypass network controls by abusing DNS.

Why this answer

The use of long, random-looking subdomains under one domain with large TXT record responses and regular intervals is characteristic of DNS tunneling. Attackers use DNS to exfiltrate data or maintain command-and-control because DNS is often allowed through firewalls. This pattern is not consistent with cache poisoning, amplification, or DGA, which have different traffic profiles.

Exam trap

The trap here is confusing DNS tunneling with DGA because both involve random-looking names, but DGA uses many distinct domains, while tunneling uses subdomains of a single domain for data transfer.

103
MCQmedium

An attacker sends an email that appears to come from the company's IT department, asking the recipient to click a link and reset their password due to a security breach. Which type of social engineering is this?

A.Vishing
B.Phishing
C.Pretexting
D.Spear phishing
AnswerB

Phishing is a social engineering attack that uses fraudulent email impersonating a trusted entity — here the IT department — to trick recipients into clicking links or disclosing credentials. The spoofed sender and urgent password-reset pretext fit phishing exactly, distinguishing it from vishing, smishing or pretexting.

Why this answer

B is correct because the attack uses email as the delivery vector to trick the recipient into clicking a malicious link and divulging credentials. This matches the definition of phishing, which is a broad social engineering technique that employs deceptive electronic communications (typically email) to steal sensitive information. The email impersonates the IT department to create a false sense of urgency, a hallmark of phishing campaigns.

Exam trap

The trap here is that candidates often confuse 'phishing' with 'spear phishing' because both involve email, but the key differentiator is that spear phishing is targeted and personalized, while the question describes a generic, untargeted email sent to a broad audience.

How to eliminate wrong answers

Option A is wrong because vishing (voice phishing) uses telephone calls or voice messages, not email, to deceive victims. Option C is wrong because pretexting involves fabricating a scenario or identity to gain trust and extract information, but it does not necessarily rely on a specific communication channel like email; the question explicitly describes an email-based attack, which is phishing. Option D is wrong because spear phishing is a targeted form of phishing aimed at a specific individual or organization, often using personalized details, whereas the scenario describes a generic email sent to a recipient without any indication of customization or prior reconnaissance.

104
MCQmedium

A security analyst is evaluating the risk of a new web application that will store customer credit card data. The analyst needs to determine the likelihood and impact of a data breach. Which risk analysis approach involves assigning numerical values to assets, threats, and vulnerabilities to calculate an annualized loss expectancy (ALE)?

A.Quantitative risk analysis
B.Qualitative risk analysis
C.Threat modeling
D.Business impact analysis (BIA)
AnswerA

Quantitative risk analysis assigns monetary and numeric values to assets, threat frequency, and vulnerability likelihood to compute metrics like single loss expectancy (SLE) and annualized loss expectancy (ALE). This allows the analyst to justify security spending by comparing expected losses against control costs. For credit card data, the analyst would estimate the value of the data, the probability of a breach, and the potential financial impact.

Why this answer

Quantitative risk analysis uses numerical values for assets, threats, and vulnerabilities to calculate annualized loss expectancy, enabling cost-benefit comparisons for security investments. Qualitative analysis uses descriptive ratings, while BIA and threat modeling serve different purposes. For credit card data, the quantitative approach provides the financial justification for controls.

Exam trap

The trap here is assuming that any risk analysis producing a high/medium/low rating is sufficient, when ALE specifically requires quantitative inputs.

105
MCQeasy

Which element of the CIA triad is primarily concerned with preventing unauthorized access to data?

A.Non-repudiation
B.Integrity
C.Confidentiality
D.Availability
AnswerC

Confidentiality guards data against disclosure to unauthorised parties, directly satisfying the stem's requirement to prevent unauthorised access. It achieves this through encryption, access controls and classification, unlike Integrity, which addresses unauthorised modification, or Availability, which addresses timely, reliable access for legitimate users.

Why this answer

Confidentiality is the CIA triad element that ensures data is accessible only to authorized users. It is primarily enforced through encryption (e.g., AES-256 for data at rest, TLS 1.3 for data in transit) and access control mechanisms (e.g., RBAC, ACLs). Preventing unauthorized access directly aligns with confidentiality's goal of protecting data from disclosure.

Exam trap

Cisco often tests the distinction between confidentiality and integrity, where candidates mistakenly choose integrity because they conflate 'preventing changes' with 'preventing access'.

How to eliminate wrong answers

Option A is wrong because non-repudiation ensures that a party cannot deny an action (e.g., using digital signatures with PKI), not that data is protected from unauthorized access. Option B is wrong because integrity ensures data has not been altered (e.g., via hashing with SHA-256 or checksums), not that it is hidden from unauthorized viewers. Option D is wrong because availability ensures systems and data are accessible when needed (e.g., via redundancy, failover), not that access is restricted.

106
MCQeasy

An organization is implementing a new security control that will verify the integrity of critical system files by comparing their current hash values against known good baseline values. Which security concept does this control primarily address?

A.Non-repudiation
B.Availability
C.Confidentiality
D.Integrity
AnswerD

Integrity ensures that data has not been altered or tampered with. Comparing hash values against a baseline detects any unauthorized changes to critical files, thus verifying integrity. This is a core method for file integrity monitoring (FIM) and directly addresses the integrity pillar of the CIA triad.

Why this answer

Integrity is the security principle that ensures data remains accurate and unaltered. By comparing current hash values to a baseline, the organization can detect unauthorized modifications to critical files. This control directly supports integrity, as any change would produce a different hash.

Confidentiality, availability, and non-repudiation are separate concerns not addressed by hash comparison.

Exam trap

The trap here is assuming that hash comparison provides confidentiality because it uses cryptographic functions, but hashing is for integrity, not secrecy.

107
Multi-Selectmedium

A security analyst is reviewing the organization's incident response plan and wants to ensure it aligns with the NIST incident response lifecycle. Which two phases are part of the NIST incident response lifecycle? (Choose two.)

Select 2 answers
A.Preparation
B.Detection and Analysis
C.Vulnerability Scanning
D.Penetration Testing
E.Risk Assessment
AnswersA, B

Preparation is the first phase of the NIST incident response lifecycle. It involves establishing policies, training staff, acquiring tools, and building communication plans before an incident occurs. This phase ensures the organization is ready to detect and respond effectively, making it a correct component of the lifecycle.

Why this answer

The NIST incident response lifecycle consists of four phases: Preparation; Detection and Analysis; Containment, Eradication, and Recovery; and Post-Incident Activity. Preparation and Detection and Analysis are two of these phases, while vulnerability scanning, risk assessment, and penetration testing are separate security activities.

Exam trap

The trap here is confusing proactive security activities like vulnerability scanning and penetration testing with the defined phases of the incident response lifecycle.

108
MCQeasy

Which phase of the NIST Cybersecurity Framework involves actions to limit the impact of a cybersecurity incident?

A.Respond
B.Protect
C.Identify
D.Detect
AnswerA

Respond covers the actions taken once a cybersecurity incident is detected, containing its spread and limiting impact through response planning, communications, analysis, mitigation and improvements. It follows Detect and precedes Recover, which restores services, so it directly matches the stem's requirement to limit incident impact.

Why this answer

The Respond function of the NIST Cybersecurity Framework (CSF) covers the actions taken once an incident is detected—containment, mitigation, analysis, and communication—to limit the impact and prevent further damage. It is the phase where incident response plans, communications, and mitigation activities are executed. This directly matches the question's wording about limiting the impact of an incident.

Exam trap

The trap is the overlap between Protect and Respond: both mention 'limiting impact,' so candidates pick Protect, but Protect is pre-incident while Respond is the active-incident phase.

How to eliminate wrong answers

Option B is wrong because Protect covers safeguards implemented before an incident (access control, awareness training, data security) to limit or contain the impact of a potential event, not the response to an active incident. Option C is wrong because Identify is about understanding the organization's assets, risks, and governance—it is foundational and pre-incident. Option D is wrong because Detect focuses on discovering and analyzing anomalies and events; it precedes Respond and does not itself limit impact.

109
MCQeasy

A security team is designing a defense-in-depth strategy. They want to add a control that inspects the actual content of network traffic for known attack signatures and can block or alert on malicious payloads in real time. Which technology best meets this requirement?

A.Intrusion prevention system (IPS)
B.Virtual private network (VPN) concentrator
C.Load balancer
D.Host-based firewall
AnswerA

An IPS inspects packet payloads against signatures and behavioral rules and can actively block or drop malicious traffic in real time. It is placed inline in the traffic path, so it can prevent attacks rather than just detect them. For content inspection with blocking capability, an IPS is the appropriate control.

Why this answer

An IPS is designed for inline deep packet inspection, matching traffic against signatures and behavioral rules and taking action to block or alert. Because it sits in the traffic path, it can stop attacks in real time, unlike passive detection or simple filtering controls. This makes it the best fit for content inspection with active response.

Exam trap

The trap here is confusing detection with prevention; an IDS detects but does not block, while an IPS both detects and blocks inline.

110
Multi-Selectmedium

An organization wants to ensure the integrity of software updates downloaded from its vendor's website. The vendor provides a hash value for each update. Which TWO properties of hashing algorithms make them suitable for integrity verification? (Choose two.)

Select 2 answers
A.The same input always produces the same hash.
B.A small change in input results in a significantly different hash.
C.The hash can be reversed to obtain the original data.
D.The hash output is always the same length for a given algorithm.
E.Hashing requires a secret key to generate the hash.
AnswersA, B

Deterministic output lets the administrator recompute the digest from the downloaded file and compare it against the vendor's published value; any alteration to the update, however small, yields a different hash, exposing tampering. This satisfies the integrity-verification requirement without needing the vendor's private key or a shared secret.

Why this answer

Option A is correct because hashing is deterministic: for a given algorithm, the same input always produces the same hash value, so a recipient can recompute the hash of a downloaded update and compare it to the vendor-published hash to verify integrity. Option B is correct because of the avalanche effect, where even a one-bit change in the input produces a drastically different hash, making any tampering with the update immediately detectable. Option C is incorrect because hashing is a one-way function and cannot be reversed to recover the original data.

Option D is incorrect because, while true for a given algorithm, fixed output length is not the property that enables integrity verification of the update content. Option E is incorrect because hashing does not require a secret key; keyed constructions like HMAC use a key, but plain hashing algorithms do not.

Exam trap

The trap here is confusing hashing with encryption or MACs — candidates pick 'reversible' or 'requires a secret key' because they conflate hash functions with symmetric ciphers or HMAC, when hashing is one-way and keyless.

111
MCQmedium

A security analyst is examining a log file and notices that the hash value of a configuration file does not match the expected value. Which security goal has been violated?

A.Integrity
B.Confidentiality
C.Non-repudiation
D.Availability
AnswerA

A mismatched hash directly evidences unauthorised modification of the configuration file, violating integrity. Hashing detects any alteration to data, so comparing the computed digest against the expected baseline value confirms the file's contents changed. Confidentiality and availability remain unaffected, as neither the file's secrecy nor its accessibility is implicated by the discrepancy.

Why this answer

A hash mismatch indicates that the file's contents have been altered from their expected state, which directly violates the integrity security goal. Integrity ensures data has not been modified in an unauthorized or accidental way, and cryptographic hashes are the standard mechanism for verifying it. Confidentiality, non-repudiation, and availability are unrelated to detecting unauthorized modification.

Exam trap

200-201 often tests the confusion between integrity and non-repudiation, tricking candidates into selecting non-repudiation when the scenario involves detecting unauthorized modification via hashes rather than proving who performed an action.

How to eliminate wrong answers

Option B is wrong because confidentiality concerns preventing unauthorized disclosure of data — a hash mismatch does not indicate that data was exposed to unauthorized parties. Option C is wrong because non-repudiation ensures a party cannot deny having performed an action, typically enforced via digital signatures and audit logs, not hash comparisons. Option D is wrong because availability ensures systems and data are accessible when needed — a modified file is still available, so availability is not the violated goal.

112
Multi-Selecteasy

A security analyst is identifying potential vulnerabilities in the network. Which TWO of the following are examples of passive reconnaissance?

Select 2 answers
A.Vulnerability scan
B.Google search for company information
C.WHOIS lookup
D.Ping sweep
E.Port scanning
AnswersB, C

Searching public sources for company information gathers intelligence without touching the target's systems, so no packets reach the organisation and nothing is logged. That absence of direct interaction with the target satisfies the passive reconnaissance constraint in the stem.

Why this answer

Passive reconnaissance gathers information about a target without directly interacting with its systems, so Google searches for company information (B) qualify because they use public search engines and cached data to collect OSINT such as employee names, technologies, and domains without touching the target's infrastructure. WHOIS lookup (C) is also passive because it queries public registration databases to obtain domain ownership, registrar, and contact details without sending any traffic to the target's hosts. By contrast, a vulnerability scan (A) actively probes systems for weaknesses, a ping sweep (D) sends ICMP echo requests to discover live hosts, and port scanning (E) sends TCP/UDP probes to enumerate open ports — all of which are active reconnaissance techniques that directly interact with the target and can be logged or detected.

Exam trap

Cisco often tests the distinction between passive and active reconnaissance by including 'vulnerability scan' as a distractor, because candidates may mistakenly think it is passive since it can be run with minimal privileges, but it always involves direct interaction with the target.

113
MCQmedium

A security analyst discovers that a server's configuration allows users to access files outside of their intended directory. In security terminology, what is this weakness called?

A.Exploit
B.Vulnerability
C.Threat
D.Risk
AnswerB

A vulnerability is a weakness in a system's configuration or design that a threat could exploit. Directory traversal access outside intended directories is exactly such a flaw, so this term precisely describes the weakness the analyst found.

Why this answer

A vulnerability is a weakness or flaw in a system's design, configuration, or code that could be exploited to violate security. The scenario describes a path traversal weakness in the server configuration, which is a classic vulnerability. This is the precise security term for the condition described.

Exam trap

200-201 often tests the distinction between vulnerability, threat, risk, and exploit — candidates pick 'exploit' or 'risk' because the scenario sounds like an active attack, but the question asks for the weakness itself.

How to eliminate wrong answers

Option A is wrong because an exploit is the actual code or technique that takes advantage of a vulnerability, not the weakness itself. Option C is wrong because a threat is any potential cause of harm (e.g., an attacker, malware, or natural disaster), not the configuration flaw. Option D is wrong because risk is the combination of the likelihood and impact of a threat exploiting a vulnerability, not the weakness itself.

114
MCQmedium

A hospital's security team discovers that a network device is silently forwarding copies of all traffic to an internal host that no administrator recognizes. The device is a managed switch that connects the radiology VLAN to the core. Which attack has most likely been implemented against this switch?

A.ARP cache poisoning
B.MAC flooding
C.VLAN hopping via double tagging
D.SPAN port misconfiguration
AnswerD

A Switched Port Analyzer session copies traffic from a source VLAN or interface to a destination port for monitoring. If an attacker with management access creates a SPAN session pointing at their own host, the switch transparently duplicates every frame from the radiology VLAN to that host, matching the observed silent copy of all traffic without disrupting normal forwarding.

Why this answer

A SPAN session on a managed switch replicates traffic from a source interface or VLAN to a destination port. When a rogue administrator or attacker with device access creates such a session aimed at an unknown internal host, every frame on the radiology VLAN is duplicated there while normal forwarding continues unaffected. The other techniques either degrade forwarding, enable cross-VLAN access, or manipulate host caches rather than producing a sustained, targeted copy of one VLAN's traffic.

Exam trap

The trap here is assuming that any traffic duplication on a switch must be an attack on the switch's forwarding tables, when a legitimate built-in monitoring feature can be abused to mirror traffic.

115
MCQmedium

Which of the following is an example of a symmetric encryption algorithm?

A.SHA-256
B.RSA
C.AES
D.ECC
AnswerC

AES is a symmetric block cipher using the same secret key for encryption and decryption, satisfying the stem's requirement for a symmetric algorithm. Operating on 128-bit blocks with key sizes of 128, 192, or 256 bits, it contrasts with asymmetric algorithms such as RSA, which use separate public and private keys.

Why this answer

AES (Advanced Encryption Standard) is a symmetric encryption algorithm, meaning the same secret key is used for both encryption and decryption. It operates on fixed-size blocks (128 bits) with key sizes of 128, 192, or 256 bits and is the current NIST standard for symmetric encryption. Because both parties must share the same key, AES is fast and efficient for bulk data encryption.

Exam trap

The trap here is confusing hashing (SHA) and asymmetric algorithms (RSA, ECC) with symmetric encryption — candidates often assume any 'crypto-sounding' acronym is symmetric, but only AES among these uses a single shared key.

How to eliminate wrong answers

Option A is wrong because SHA-256 is a cryptographic hash function (part of the SHA-2 family), not an encryption algorithm — it produces a one-way 256-bit digest and cannot be decrypted. Option B is wrong because RSA is an asymmetric algorithm that uses a public/private key pair for encryption and digital signatures. Option D is wrong because ECC (Elliptic Curve Cryptography) is also asymmetric, relying on elliptic curve mathematics for key exchange and signatures rather than symmetric encryption.

116
MCQhard

A financial services firm is building a threat model and wants to classify an attacker who is highly skilled, well funded, and focused on stealing intellectual property from a specific set of companies over a long period. Which threat actor category best fits this profile?

A.Script kiddie
B.Hacktivist
C.Insider threat
D.Advanced persistent threat
AnswerD

An advanced persistent threat is a well-resourced actor, often state-sponsored, that conducts prolonged campaigns against specific targets. The combination of high skill, significant funding, focus on a defined set of victims, and long-term intellectual property theft matches the APT profile exactly. APTs prioritize stealth and persistence over quick disruption, which is consistent with the described behavior.

Why this answer

An advanced persistent threat is characterized by significant resources, advanced skills, and sustained, stealthy operations against specific targets, often for espionage or intellectual property theft. The scenario's emphasis on long duration, funding, and a defined victim set aligns with APT behavior. Hacktivists are ideologically driven, script kiddies lack sophistication and resources, and insider threats are authorized users, so none matches the described external, well-funded, persistent actor.

Exam trap

The trap here is focusing on the theft of intellectual property alone, which any actor might attempt, instead of weighing the funding, skill, and long-term persistence that define an advanced persistent threat.

117
MCQhard

An organization wants to ensure that a user cannot deny having sent an email. Which security goal does this address?

A.Non-repudiation
B.Availability
C.Integrity
D.Confidentiality
AnswerA

Non-repudiation provides cryptographic proof of origin through digital signatures, binding the sender's identity to the message so they cannot later deny sending it. This directly satisfies the scenario's requirement that a user cannot deny having sent an email, unlike confidentiality, integrity or availability goals.

Why this answer

Non-repudiation ensures that a party cannot deny having performed a specific action, such as sending an email. This is typically achieved through digital signatures using asymmetric cryptography (e.g., RSA or ECDSA) and public key infrastructure (PKI), where the sender's private key creates a signature that can be verified by anyone with the sender's public key. The goal is to provide irrefutable proof of origin and integrity, preventing the sender from later claiming they did not send the message.

Exam trap

Cisco often tests the distinction between integrity and non-repudiation, where candidates mistakenly choose integrity because they associate hashing with proof of origin, but integrity alone does not link the data to a specific sender.

How to eliminate wrong answers

Option B (Availability) is wrong because availability ensures that systems and data are accessible when needed, often through redundancy and fault tolerance, not by preventing denial of actions. Option C (Integrity) is wrong because integrity guarantees that data has not been altered in transit or storage, typically via hashing (e.g., SHA-256) or checksums, but does not tie an action to a specific user. Option D (Confidentiality) is wrong because confidentiality protects data from unauthorized disclosure using encryption (e.g., AES or TLS), but does not provide proof of origin or prevent repudiation.

118
MCQmedium

A company's security policy requires that sensitive data be encrypted at rest using AES-256. Which type of encryption does AES-256 represent?

A.Hashing algorithm
B.Digital signature
C.Asymmetric encryption
D.Symmetric encryption
AnswerD

AES-256 uses a single shared secret key for both encryption and decryption, making it symmetric. Asymmetric algorithms such as RSA instead use a public-private key pair. The policy's requirement for AES-256 therefore specifies symmetric encryption, not hashing or asymmetric cryptography.

Why this answer

AES-256 is a symmetric encryption algorithm, meaning it uses the same key for both encryption and decryption. It is widely used for data at rest due to its strength and efficiency. The '256' refers to the key size in bits, making it highly resistant to brute-force attacks.

Exam trap

The trap is confusing symmetric and asymmetric encryption. Candidates might think AES is asymmetric because it's strong, but the key characteristic is that it uses a single shared key. Also, hashing is sometimes mistaken for encryption, but it's irreversible.

How to eliminate wrong answers

Option A is wrong because a hashing algorithm (e.g., SHA-256) is a one-way function used for integrity, not encryption; it does not use a key and cannot be decrypted. Option B is wrong because a digital signature uses asymmetric cryptography to provide authenticity and integrity, not symmetric encryption. Option C is wrong because asymmetric encryption (e.g., RSA) uses a key pair (public and private), while AES is symmetric.

119
MCQeasy

A security analyst discovers that a malicious actor is using a technique to gather information about employees by searching social media sites. Which type of attack is being performed?

A.Active reconnaissance
B.Passive reconnaissance
C.Denial of Service
D.Social engineering
AnswerB

Searching social media for employee details involves no direct interaction with the target's systems, so nothing is sent that could trigger detection. That absence of engagement with the target's infrastructure is precisely what makes it passive reconnaissance rather than active scanning.

Why this answer

Passive reconnaissance involves gathering information about a target without directly interacting with its systems, such as searching public social media sites for employee details. Because the attacker only observes publicly available data and does not send packets or queries to the target's infrastructure, it is classified as passive. This contrasts with active reconnaissance, which involves direct interaction (e.g., port scanning).

Exam trap

The trap is confusing passive reconnaissance with social engineering — both involve people, but social engineering requires interaction/deception, while passive reconnaissance only observes public information without contacting the target.

How to eliminate wrong answers

Option A is wrong because active reconnaissance requires direct interaction with the target (e.g., scanning, banner grabbing), which is not occurring when merely browsing social media. Option C is wrong because a Denial of Service attack aims to disrupt availability, not gather employee information. Option D is wrong because social engineering involves manipulating people into divulging information or performing actions, whereas here the attacker is only collecting publicly posted data without deception or interaction.

120
MCQhard

An attacker intercepts communication between a client and a server, allowing the attacker to read, insert, and modify messages in both directions. Which type of network attack is this?

A.Denial of Service
B.ARP spoofing
C.DNS poisoning
D.Man-in-the-middle
AnswerD

A man-in-the-middle attack places the adversary between client and server, relaying traffic while reading, inserting and modifying messages in both directions. This active interception, rather than passive eavesdropping or denial of service, matches the bidirectional read-write-modify capability described in the scenario.

Why this answer

A man-in-the-middle (MITM) attack occurs when an attacker intercepts and relays communication between two parties, allowing them to read, insert, and modify messages. This matches the scenario exactly. The attacker positions themselves between the client and server, often without either party's knowledge.

Exam trap

The trap here is confusing MITM with specific techniques like ARP spoofing or DNS poisoning; the question describes the outcome, not the method.

How to eliminate wrong answers

Option A is wrong because a Denial of Service attack aims to disrupt availability, not intercept and modify communications. Option B is wrong because ARP spoofing is a technique to facilitate MITM on a local network, but it is not the attack type itself; the question describes the broader MITM attack. Option C is wrong because DNS poisoning redirects traffic to malicious sites but does not inherently allow bidirectional message modification.

121
MCQhard

A security analyst is investigating an incident where an employee received an email that appeared to be from the company's IT department, requesting the employee to verify their account by clicking a link and entering their credentials. The employee complied, and later the attacker used those credentials to access the corporate VPN. Which combination of attack types best describes this incident?

A.Pretexting and privilege escalation
B.Phishing and man-in-the-middle
C.Spear phishing and credential theft
D.Vishing and brute force
AnswerC

The email targeted a specific employee while impersonating internal IT, which is spear phishing rather than generic phishing. The captured credentials were then reused to access the corporate VPN, directly constituting credential theft, matching both elements the scenario describes.

Why this answer

The incident involves a targeted email that appears to be from the IT department, requesting credential verification—this is spear phishing because it's tailored to the organization. The employee providing credentials leads to credential theft, which the attacker then uses to access the VPN. Thus, spear phishing and credential theft best describe the attack.

Exam trap

The trap is misclassifying the attack as pretexting or man-in-the-middle. Pretexting is a component of spear phishing but not the primary label; man-in-the-middle requires interception. Candidates might also think privilege escalation occurred because the attacker accessed the VPN, but that's unauthorized access, not escalation.

How to eliminate wrong answers

Option A is wrong because pretexting involves creating a fabricated scenario, but here the primary attack is phishing; privilege escalation did not occur—the attacker used existing credentials, not elevated privileges. Option B is wrong because man-in-the-middle involves intercepting communications, which is not described; the attacker directly used stolen credentials. Option D is wrong because vishing is voice phishing (phone), and brute force involves guessing passwords, neither of which occurred.

122
Multi-Selectmedium

A security operations center is building detection rules for man-in-the-middle attacks on its internal network. The team wants to identify techniques an attacker on the same Layer 2 segment could use to intercept or redirect traffic between two hosts. (Choose two.)

Select 2 answers
A.DNS cache poisoning to redirect a victim to an attacker-controlled server
B.On-path routing manipulation using forged ICMP redirect messages
C.VLAN hopping by double-tagging 802.1Q frames to reach another segment
D.ARP spoofing to associate the attacker's MAC address with the default gateway IP
E.MAC flooding to overflow the switch CAM table and force hub-like flooding
AnswersB, D

Forged ICMP redirects tell a host to send traffic for a destination through a different next hop, which can be the attacker's address. This places the attacker on the path between two hosts and enables interception or alteration. Detection looks for unexpected ICMP redirect messages and hosts accepting redirects when they should not.

Why this answer

ARP spoofing and forged ICMP redirects both manipulate how a host forwards traffic so the attacker becomes an on-path device, enabling interception and modification. ARP spoofing targets the mapping of IP to MAC on the local segment, while ICMP redirect manipulation alters the next-hop decision. Both are detectable through switch features such as dynamic ARP inspection and through monitoring for unexpected redirect messages.

Exam trap

The trap here is treating MAC flooding or VLAN hopping as interception methods, when they expose or redirect traffic without placing the attacker inline between the two communicating hosts.

123
MCQeasy

A security analyst discovers that an attacker used a publicly available tool to scan a company's network for open ports and services. What type of attack is this?

A.Passive reconnaissance
B.Denial of Service
C.Social engineering
D.Active reconnaissance
AnswerD

Active reconnaissance involves directly interacting with target systems, such as port scanning with tools like Nmap, generating traffic the target can detect. This matches the stem's constraint of using a publicly available tool to scan for open ports and services.

Why this answer

Using a publicly available tool to scan a company's network for open ports and services involves directly interacting with the target systems by sending probes (e.g., TCP SYN packets, UDP datagrams) and analyzing responses. This constitutes active reconnaissance, as the attacker's actions generate traffic that can be detected by intrusion detection systems (IDS) or firewall logs, unlike passive methods that only observe existing traffic.

Exam trap

Cisco often tests the distinction between active and passive reconnaissance by presenting a scenario where a tool is used to 'scan' or 'probe' the network, and candidates mistakenly choose passive reconnaissance because they think 'scanning' is non-intrusive, but any direct interaction with the target (sending packets) is active.

How to eliminate wrong answers

Option A is wrong because passive reconnaissance involves gathering information without directly interacting with the target network, such as sniffing traffic or using public records (e.g., WHOIS, DNS lookups), not sending probes to identify open ports. Option B is wrong because a Denial of Service (DoS) attack aims to disrupt or degrade service availability by overwhelming resources (e.g., SYN flood, ICMP flood), not to enumerate open ports and services for later exploitation. Option C is wrong because social engineering exploits human psychology to manipulate individuals into divulging confidential information or performing actions, not technical scanning of network ports and services.

124
MCQhard

A security analyst is reviewing an incident in which an attacker gained initial access to a corporate workstation by exploiting a vulnerability in a browser plugin. After gaining access, the attacker moved laterally to a file server and exfiltrated data. The analyst must map these activities to the cyber kill chain. Which phase of the kill chain does the browser plugin exploitation represent?

A.Command and control, because the attacker established a channel to manage the compromised host.
B.Weaponization, because the attacker prepared an exploit payload for the browser plugin.
C.Reconnaissance, because the attacker gathered information about the target before the attack.
D.Exploitation, because the attacker took advantage of the vulnerability to execute code on the workstation.
AnswerD

Exploitation is the kill chain phase where the attacker leverages a vulnerability to execute code or gain access. Exploiting the browser plugin vulnerability to gain initial access on the workstation is precisely this phase. The subsequent lateral movement and exfiltration are later phases, but the plugin exploitation itself maps to exploitation, making this the correct mapping.

Why this answer

The browser plugin vulnerability was leveraged to gain code execution and initial access on the workstation. In the cyber kill chain, that action is exploitation, which follows reconnaissance and weaponization and precedes actions such as command and control, lateral movement, and exfiltration. The later lateral movement and data theft are separate phases, so the exploitation itself maps to the exploitation phase.

Exam trap

The trap here is confusing weaponization with exploitation, because both involve preparing and using an exploit, but weaponization occurs before delivery while exploitation is the actual triggering of the vulnerability.

125
Multi-Selectmedium

A security analyst is evaluating the security posture of a new web application. The analyst needs to identify which TWO of the following are examples of security controls that fall under the category of technical controls. (Choose two.)

Select 2 answers
A.Intrusion prevention system (IPS)
B.Access control lists (ACLs) on a router
C.Background checks for new hires
D.Security awareness training for employees
E.Security policy document
AnswersA, B

An intrusion prevention system is a technical control because it uses hardware or software to automatically detect and block malicious network traffic. It enforces security policies through technical mechanisms, such as signature matching or anomaly detection. This falls squarely under technical controls, making it a correct choice for this scenario.

Why this answer

Technical controls are security measures implemented through technology, such as hardware, software, or firmware. An intrusion prevention system and router access control lists both use technical mechanisms to enforce security policies. Security awareness training, policy documents, and background checks are administrative controls that rely on human processes rather than technical enforcement.

Exam trap

The trap here is confusing administrative controls like policies and training with technical controls, as both aim to reduce risk but only technical controls are enforced by technology.

126
MCQeasy

An organization implements encryption for all sensitive data at rest and in transit to prevent unauthorized access. Which element of the CIA triad is being primarily addressed?

A.Non-repudiation
B.Integrity
C.Availability
D.Confidentiality
AnswerD

Encryption at rest and in transit renders data unintelligible to anyone lacking the decryption key, directly preventing unauthorised disclosure. This satisfies the stem's constraint of preventing unauthorised access, which maps to confidentiality within the CIA triad. Integrity concerns alteration, and availability concerns uptime, neither of which encryption primarily delivers.

Why this answer

Encryption of data at rest and in transit ensures that only authorized parties can read the data, thus addressing confidentiality. Confidentiality is the element of the CIA triad focused on preventing unauthorized access to information.

Exam trap

200-201 often tests the distinction between confidentiality and integrity; candidates may confuse encryption with hashing, but encryption primarily provides confidentiality.

How to eliminate wrong answers

Option A is wrong because non-repudiation ensures that a party cannot deny having performed an action, often achieved through digital signatures, not encryption alone. Option B is wrong because integrity ensures data is not altered, typically addressed by hashing or checksums, not encryption. Option C is wrong because availability ensures data and systems are accessible when needed, which encryption does not directly address.

127
MCQmedium

A network analyst notices a high volume of traffic from a single external IP address to multiple internal hosts on port 443. The traffic includes incomplete TCP handshakes. Which type of reconnaissance is being performed?

A.Social engineering attack
B.Active reconnaissance via port scanning
C.Denial of Service attack
D.Passive reconnaissance using WHOIS
AnswerB

Incomplete TCP handshakes across many internal hosts on port 443 indicate a SYN scan probing for live services. This is active reconnaissance: the attacker sends packets directly to targets, unlike passive monitoring, and the half-open connections reveal port scanning behaviour.

Why this answer

A high volume of connections to port 443 with incomplete TCP handshakes (SYN sent, no ACK) from one external IP to many internal hosts is the signature of a TCP SYN scan — an active reconnaissance technique used to discover which hosts and ports are open. The incomplete handshakes occur because the scanner does not complete the three-way handshake, either to avoid logging or to speed up the scan.

Exam trap

200-201 often tests the distinction between active reconnaissance (scanning, generates traffic) and passive reconnaissance (WHOIS, DNS, no target traffic) — candidates confuse the two when they see 'reconnaissance' in the question.

How to eliminate wrong answers

Option A is wrong because social engineering targets people (phishing, pretexting), not network ports, and produces no TCP handshake traffic. Option C is wrong because a DoS attack aims to exhaust resources and typically uses complete or spoofed connections at high volume to a single target, not a scan pattern across many hosts. Option D is wrong because passive reconnaissance (WHOIS, DNS lookups) generates no traffic to the target's internal hosts — it queries third-party registries.

128
MCQmedium

A security analyst is reviewing the risk associated with a new cloud service. The service provider stores data in multiple countries, and the data includes personal information of EU citizens. The analyst must ensure compliance with GDPR. Which principle of GDPR is most directly relevant to this scenario?

A.Cross-border data transfer restrictions
B.Data protection impact assessment (DPIA)
C.Data minimization
D.Right to erasure
AnswerA

GDPR imposes strict rules on transferring personal data outside the EU/EEA. The scenario highlights that data is stored in multiple countries, which triggers the need to ensure adequate safeguards such as Standard Contractual Clauses or adequacy decisions. This principle directly addresses the legality of transferring EU citizens' data to other jurisdictions, making it the most relevant GDPR principle in this scenario.

Why this answer

GDPR restricts the transfer of personal data of EU citizens to countries outside the EU/EEA unless adequate protections are in place. The scenario describes data stored in multiple countries, which directly implicates cross-border data transfer restrictions. Data minimization, right to erasure, and DPIA are important but not as directly tied to the geographic storage of data.

Exam trap

The trap here is selecting a well-known GDPR principle like the right to erasure or data minimization simply because it sounds relevant, without focusing on the specific trigger of data being stored in multiple countries.

129
MCQmedium

An attacker sends an email posing as the company's IT department, asking employees to click a link and enter their credentials. Which type of social engineering attack is this?

A.Vishing
B.Phishing
C.Pretexting
D.Spear phishing
AnswerB

Phishing fits because the attacker uses a fraudulent email impersonating the IT department to trick employees into revealing credentials via a deceptive link. This satisfies the scenario's defining constraint: mass, electronic, credential-harvesting deception. Unlike spear phishing, it is not individually researched, and unlike vishing or smishing, the channel is email, matching the stem exactly.

Why this answer

B is correct because the attack uses email as the delivery vector to trick recipients into revealing credentials, which is the classic definition of phishing. Phishing is a broad category of social engineering that employs deceptive electronic communications (typically email) to steal sensitive information.

Exam trap

Cisco often tests the distinction between phishing (mass, untargeted) and spear phishing (targeted), so the trap here is that candidates may confuse the generic email to all employees with a targeted attack, leading them to incorrectly choose spear phishing.

How to eliminate wrong answers

Option A is wrong because vishing (voice phishing) uses telephone calls or voice messages, not email. Option C is wrong because pretexting involves fabricating a scenario or identity to gain trust and extract information, but it does not specifically require an email with a link to harvest credentials. Option D is wrong because spear phishing is a targeted version of phishing aimed at a specific individual or organization, whereas the question describes a generic email sent to all employees, which is a mass phishing campaign.

130
MCQeasy

Which component of the NIST Cybersecurity Framework involves taking action to stop an ongoing attack?

A.Identify
B.Detect
C.Respond
D.Protect
AnswerC

The Respond function covers the actions taken once an incident is detected, containing its impact and stopping the ongoing attack. Identify, Protect, Detect and Recover address other phases, so Respond satisfies the stem's requirement to halt active compromise.

Why this answer

The Respond function includes activities to contain and mitigate incidents.

131
MCQhard

An organization must comply with a regulation that requires protecting the privacy of EU citizens' personal data. Which compliance framework applies?

A.HIPAA
B.ISO 27001
C.PCI DSS
D.GDPR
AnswerD

GDPR directly governs the protection of EU citizens' personal data, satisfying the stem's regulatory privacy requirement. It imposes binding obligations on organisations processing that data, regardless of where the organisation is established, making it the applicable compliance framework rather than a security control or technical standard.

Why this answer

The General Data Protection Regulation (GDPR) is the EU regulation specifically designed to protect the privacy and personal data of EU citizens. It applies to any organization that processes or controls the personal data of individuals in the EU, regardless of where the organization is based. This makes GDPR the correct compliance framework for the scenario described.

Exam trap

Cisco often tests the distinction between data privacy regulations (like GDPR) and data security standards (like PCI DSS or HIPAA), where candidates mistakenly apply a US-centric regulation to an EU privacy requirement.

How to eliminate wrong answers

Option A is wrong because HIPAA (Health Insurance Portability and Accountability Act) applies only to protected health information (PHI) in the United States, not to EU citizens' personal data. Option B is wrong because ISO 27001 is an international standard for information security management systems (ISMS), not a regulation that specifically addresses EU privacy requirements. Option C is wrong because PCI DSS (Payment Card Industry Data Security Standard) governs the security of credit card data, not the privacy of EU citizens' personal data.

132
MCQhard

In a PKI, what is the role of a Certificate Authority (CA)?

A.Generates private keys for users
B.Provides symmetric keys for session encryption
C.Encrypts data for secure transmission
D.Issues and validates digital certificates
AnswerD

The CA is the trusted third party within a PKI that issues digital certificates, binding a public key to a verified identity, and validates those certificates through its registration and revocation processes. This satisfies the stem's requirement for trusted certificate issuance and validation.

Why this answer

A Certificate Authority (CA) is a trusted entity that issues and validates digital certificates. It verifies the identity of certificate applicants and signs the certificates with its private key, thereby binding a public key to an identity. This is the core function of a CA in a PKI.

Exam trap

200-201 often tests the misconception that the CA generates private keys or performs encryption; candidates must remember that the CA only issues and validates certificates.

How to eliminate wrong answers

Option A is wrong because the CA does not generate private keys for users; users generate their own key pairs, and the CA only certifies the public key. Option B is wrong because symmetric keys for session encryption are typically generated by the communicating parties, not the CA. Option C is wrong because the CA does not encrypt data for transmission; it only provides certificates that enable encryption through public key cryptography.

133
MCQmedium

An analyst is investigating an incident and needs to determine the source of a piece of malware. The analyst finds that the malware uses a domain generation algorithm to contact command-and-control servers. Which term best describes this capability?

A.Persistence
B.Command and control
C.Lateral movement
D.Privilege escalation
AnswerB

Command and control (C2) describes the communication channel between malware and its operator. A domain generation algorithm produces many possible domain names that the malware queries to find an active C2 server, making it harder for defenders to block a single domain. The scenario explicitly mentions contacting command-and-control servers, so this capability is best described as command and control. It is the correct term for the malware's remote communication mechanism.

Why this answer

A domain generation algorithm creates a large set of pseudo-random domain names that malware periodically queries to find an active command-and-control server. This technique helps the malware evade static blocklists and takedown attempts, because defenders cannot easily predict or block every possible domain. The scenario states the malware contacts command-and-control servers, so the capability is command and control.

Persistence, privilege escalation, and lateral movement describe different phases or objectives of an intrusion.

Exam trap

The trap here is associating any advanced evasion technique with persistence, when the domain generation algorithm specifically supports locating and communicating with C2 infrastructure.

134
Multi-Selectmedium

Which THREE of the following are common types of malware?

Select 3 answers
A.Patch
B.Virus
C.Ransomware
D.Worm
E.Firewall
AnswersB, C, D

A virus is a self-replicating malware type that attaches to legitimate files or executables, spreading when those hosts run. It satisfies the stem's requirement for a common malware category, distinct from standalone threats such as worms or trojans. Microsoft Entra ID documentation and standard security curricula classify viruses among the core malware families.

Why this answer

Option B (Virus) is correct because a virus is a classic malware category: self-replicating code that attaches to a host file or program and spreads when the host is executed. Option C (Ransomware) is correct because ransomware is a well-known malware type that encrypts or locks victim data and demands payment, often using symmetric keys like AES with an asymmetric-wrapped key. Option D (Worm) is correct because a worm is standalone self-replicating malware that spreads across networks (e.g., via SMB or email) without needing a host file.

Option A (Patch) does not belong because a patch is a legitimate software update that fixes vulnerabilities, not malicious code. Option E (Firewall) does not belong because a firewall is a security control that filters network traffic by rules, not a malware type.

Exam trap

Cisco often tests the distinction between security tools (like patches and firewalls) and actual malware types, leading candidates to mistakenly classify protective measures as malicious software.

135
MCQhard

A security analyst needs to verify that a downloaded software update has not been tampered with. The update's publisher provides a file containing a hash value. Which process should the analyst use to verify integrity?

A.Decrypt the file using the publisher's public key
B.Use a digital signature to sign the file
C.Compute the file's hash and compare it with the provided hash
D.Encrypt the file using the publisher's private key
AnswerC

Hashing is deterministic, so the analyst recomputes the digest of the downloaded file using the same algorithm and compares it against the publisher's supplied value; any mismatch proves the file was altered in transit or storage.

Why this answer

Verifying file integrity involves computing a cryptographic hash (e.g., SHA-256) of the downloaded file and comparing it to the hash provided by the publisher. If the hashes match, the file has not been altered; any tampering would produce a different hash value. This is a standard integrity check, not a confidentiality or authentication mechanism.

Exam trap

Cisco often tests the distinction between integrity (hash comparison) and authenticity (digital signatures), leading candidates to mistakenly choose digital signature verification when the question only asks about integrity.

How to eliminate wrong answers

Option A is wrong because decrypting a file with the publisher's public key would only work if the file were encrypted with the publisher's private key, which is used for confidentiality or non-repudiation, not for integrity verification of a hash. Option B is wrong because signing the file with a digital signature is a process the publisher performs to provide authenticity and integrity, but the analyst does not sign the file; the analyst verifies the signature using the publisher's public key. Option D is wrong because encrypting the file with the publisher's private key is not a standard integrity check; private key encryption is used for digital signatures or to prove origin, and the analyst would not have access to the publisher's private key.

136
MCQeasy

A security analyst at a financial services company is reviewing the organization's security program. The CISO wants to ensure that the confidentiality, integrity, and availability of information assets are protected by administrative, physical, and technical controls. Which security concept is the CISO describing?

A.The AAA framework, which governs authentication, authorization, and accounting for user access.
B.The OSI model, which defines seven layers of network communication used to design secure protocols.
C.The CIA triad, which defines the three core objectives of information security that controls must protect.
D.The principle of least privilege, which restricts users to only the access required to perform their jobs.
AnswerC

The CIA triad is exactly what the CISO describes: confidentiality, integrity, and availability are the three foundational objectives of information security. Administrative, physical, and technical controls are implemented specifically to protect these three properties of information assets. This aligns with the Cisco CyberOps objective of understanding the core security principles that guide the design of a security program.

Why this answer

The scenario names confidentiality, integrity, and availability as the properties controls must protect. These three objectives form the CIA triad, the foundational model of information security. Administrative, physical, and technical controls are all implemented to preserve these properties, so the concept described is the CIA triad rather than an access framework, a network model, or a single control principle.

Exam trap

The trap here is confusing the CIA triad with the AAA framework because both use three-letter acronyms and relate to security, but only the CIA triad describes confidentiality, integrity, and availability.

137
Multi-Selectmedium

A security analyst is investigating a network breach. Which TWO activities are examples of passive reconnaissance? (Choose two.)

Select 2 answers
A.Reviewing LinkedIn profiles of employees
B.Sending ping sweeps to identify live hosts
C.Using a vulnerability scanner to find weaknesses
D.Searching WHOIS records for domain registration details
E.Performing a port scan on the target network
AnswersA, D

Reviewing LinkedIn profiles gathers employee names, roles and technologies without touching the target's systems, so no packets reach the organisation. This indirect, non-intrusive collection satisfies the stem's passive-reconnaissance constraint, unlike scanning or banner grabbing, which generate detectable traffic.

Why this answer

Option A (Reviewing LinkedIn profiles of employees) is correct because it is passive reconnaissance: the analyst gathers publicly available employee information from social media without directly interacting with the target's systems, so no packets are sent to the organization's infrastructure. Option D (Searching WHOIS records for domain registration details) is also correct because WHOIS queries retrieve publicly registered domain ownership, contact, and nameserver data from third-party registries, again without touching the target network. By contrast, option B (ping sweeps) and option E (port scans) are active reconnaissance techniques that send ICMP echo requests or TCP/UDP probes directly to target hosts, and option C (vulnerability scanning) is active because it transmits crafted probes to identify weaknesses on the target systems.

Exam trap

200-201 often tests whether candidates can distinguish passive from active reconnaissance — candidates incorrectly classify WHOIS lookups as active because they involve querying a server, but WHOIS queries go to a third-party registry, not the target.

138
MCQmedium

An organization is required to protect cardholder data. Which compliance framework applies to this requirement?

A.ISO 27001
B.HIPAA
C.GDPR
D.PCI DSS
AnswerD

PCI DSS is the payment card industry standard governing organisations that store, process or transmit cardholder data. Its twelve requirements mandate controls such as encryption, access restriction and network monitoring, directly satisfying the stem's cardholder data protection obligation.

Why this answer

PCI DSS is the Payment Card Industry Data Security Standard, which applies to organizations that handle credit card data.

139
MCQmedium

A security operations center analyst is reviewing a vulnerability scan report for a web server. The report identifies that the server is running an outdated version of Apache HTTP Server with a known remote code execution vulnerability. The analyst needs to classify this finding. Which term best describes this vulnerability?

A.A software misconfiguration, because the server is running an unsupported version.
B.A known software vulnerability, because it is a documented flaw in the Apache code that can be exploited.
C.A social engineering attack, because the attacker could trick users into visiting a malicious site.
D.A zero-day exploit, because the vulnerability allows remote code execution.
AnswerB

A known software vulnerability is a documented weakness in software code that attackers can exploit. The outdated Apache version contains a published remote code execution flaw, which matches this definition. The analyst should classify it as a known vulnerability and prioritize patching or upgrading, consistent with vulnerability management practices in the CyberOps Security Concepts domain.

Why this answer

The scan reveals an outdated Apache version with a published remote code execution flaw. That is a known software vulnerability: a documented weakness in code for which a fix typically exists. It is not a configuration error, an unknown zero-day, or a human-focused social engineering technique, so the appropriate classification is a known software vulnerability requiring patch or upgrade remediation.

Exam trap

The trap here is assuming any remote code execution flaw is a zero-day, when a zero-day specifically requires that no patch or public knowledge exists yet.

140
Multi-Selectmedium

An organization wants to protect sensitive data at rest and in transit. Which THREE cryptographic methods can provide confidentiality? (Choose three.)

Select 3 answers
A.Digital signature
B.Transport Layer Security (TLS)
C.Symmetric encryption
D.Hashing
E.Asymmetric encryption
AnswersB, C, E

TLS encrypts data in transit using symmetric and asymmetric methods.

Why this answer

TLS (B) is correct because it provides confidentiality for data in transit by encrypting the session between client and server using negotiated symmetric ciphers (e.g., AES) after an asymmetric handshake. Symmetric encryption (C) is correct because it uses a shared secret key with algorithms such as AES to encrypt data at rest or in transit, directly providing confidentiality. Asymmetric encryption (E) is correct because it uses public/private key pairs (e.g., RSA, ECC) to encrypt data so that only the holder of the corresponding private key can decrypt it, protecting confidentiality.

Digital signature (A) is not correct because it provides integrity, authentication, and non-repudiation, not confidentiality. Hashing (D) is not correct because it is a one-way function used for integrity verification and cannot encrypt or conceal data.

141
MCQmedium

An attacker sends a fraudulent email that appears to come from the company's IT department, requesting that the recipient click a link and enter their login credentials. Which type of social engineering attack is this?

A.Vishing
B.Phishing
C.Pretexting
D.Spear phishing
AnswerB

Phishing uses fraudulent emails impersonating a trusted entity, such as the IT department, to trick recipients into clicking links and surrendering credentials. This matches the stem's constraint of a spoofed internal email harvesting login details.

Why this answer

This is a phishing attack because the attacker uses a fraudulent email that impersonates a trusted entity (the IT department) to trick the recipient into clicking a malicious link and entering sensitive login credentials. Phishing is a broad category of social engineering that relies on deceptive electronic communications, typically email, to harvest credentials or deliver malware.

Exam trap

Cisco often tests the distinction between generic phishing and spear phishing, where the trap is that candidates confuse a broad phishing email with a targeted one, but the question lacks any indication of personalization or specific targeting, making 'Phishing' the correct choice over 'Spear phishing'.

How to eliminate wrong answers

Option A (Vishing) is wrong because vishing (voice phishing) uses voice calls or VoIP systems, not email, to deceive victims. Option C (Pretexting) is wrong because pretexting involves fabricating a scenario or false identity to obtain information, but it does not necessarily use a fraudulent email with a link to harvest credentials; it often relies on direct interaction or impersonation over phone or in person. Option D (Spear phishing) is wrong because spear phishing is a targeted form of phishing aimed at a specific individual or organization, often using personalized details; the question describes a generic email sent to a recipient without indicating targeting, so it fits the broader phishing category.

142
MCQmedium

Which compliance standard specifically applies to organizations that handle credit card information?

A.HIPAA
B.GDPR
C.ISO 27001
D.PCI DSS
AnswerD

PCI DSS is the Payment Card Industry Data Security Standard, mandated for any organisation that stores, processes or transmits cardholder data. The stem's credit card handling constraint maps directly to this standard, unlike HIPAA (health) or GDPR (personal data).

Why this answer

PCI DSS (Payment Card Industry Data Security Standard) is the compliance standard specifically designed for organizations that handle credit card information. It sets requirements for securing cardholder data, including encryption, access control, and network security, and applies to all entities that store, process, or transmit card data.

Exam trap

200-201 often tests the confusion between general data protection regulations (GDPR, HIPAA) and industry-specific standards (PCI DSS), so candidates must associate credit card data with PCI DSS.

How to eliminate wrong answers

Option A is wrong because HIPAA applies to protected health information in the healthcare sector, not credit card data. Option B is wrong because GDPR is a European data protection regulation that governs personal data privacy, not specifically credit card information. Option C is wrong because ISO 27001 is a general information security management standard, not specific to credit card data.

143
Multi-Selectmedium

A security engineer is analyzing a recent data breach. Which TWO are examples of active reconnaissance techniques? (Select two.)

Select 2 answers
A.Port scanning
B.Ping sweep
C.LinkedIn profiling
D.WHOIS lookup
E.Google dorking
AnswersA, B

Port scanning actively probes target hosts to discover open ports and running services, generating traffic that touches the target directly, which defines active reconnaissance. It contrasts with passive techniques such as searching public records or monitoring traffic, where the attacker never interacts with the target's systems.

Why this answer

Port scanning (A) is an active reconnaissance technique because it sends TCP/UDP probes (e.g., SYN, ACK, or UDP packets via tools like Nmap) directly to target hosts to discover open ports and services, which interacts with the target and can be logged. Ping sweep (B) is also active reconnaissance because it transmits ICMP Echo Request packets (or ARP/TCP probes) across an IP range to identify live hosts, again directly engaging the target network. By contrast, LinkedIn profiling (C), WHOIS lookup (D), and Google dorking (E) are passive reconnaissance techniques, as they gather information from third-party sources or public records without sending traffic to the target's systems.

Exam trap

The trap is misclassifying OSINT techniques like WHOIS, Google dorking, and social media profiling as active — candidates forget that 'active' specifically means sending traffic to the target, not just gathering information about it.

← PreviousPage 2 of 2 · 143 questions total

Ready to test yourself?

Try a timed practice session using only Security Concepts questions.