Courseiva

CCNA Security Monitoring Questions

75 of 159 questions · Page 1/3 · Security Monitoring · Answers revealed

1
MCQmedium

An IDS/IPS alert shows a signature named 'ET POLICY Outgoing HTTP Request with Suspicious User-Agent' with severity high. What is the most likely next step for an analyst?

A.Immediately block the source IP on the firewall
B.Reset the IDS/IPS signature database
C.Investigate the source IP and user-agent for malicious activity
D.Ignore the alert as it is not a critical signature
AnswerC

The signature flags an unusual User-Agent in outbound HTTP, which may indicate malware beaconing or command-and-control traffic. Correlating the source IP with the User-Agent string confirms whether the host is compromised, satisfying the need to validate the alert before escalation.

Why this answer

The 'ET POLICY Outgoing HTTP Request with Suspicious User-Agent' signature indicates a policy violation, not necessarily a confirmed attack. An analyst must first investigate the source IP and user-agent to determine if the traffic is malicious (e.g., command-and-control communication, data exfiltration) or benign (e.g., a legitimate application using a non-standard user-agent). Immediate blocking (Option A) could disrupt legitimate services, while ignoring the alert (Option D) risks missing a real threat.

Exam trap

Cisco often tests the distinction between 'policy' and 'exploit' signatures, where candidates mistakenly treat a policy violation as an immediate threat and jump to blocking, rather than following the proper incident response process of investigation first.

How to eliminate wrong answers

Option A is wrong because immediately blocking the source IP on the firewall is an overly aggressive response without confirming malicious activity; it could cause a denial of service for legitimate users and violates the principle of 'verify before blocking'. Option B is wrong because resetting the IDS/IPS signature database does not address the alert; it would remove all signatures, including legitimate ones, and is not a standard troubleshooting step for a single alert. Option D is wrong because ignoring the alert is negligent; even though it is a policy-based signature, it may indicate reconnaissance, scanning, or malware activity that requires investigation.

2
MCQeasy

A security analyst is monitoring network traffic and notices a large number of TCP SYN packets being sent to a single host on various ports. Which type of attack is most likely occurring?

A.Man-in-the-middle
B.ARP spoofing
C.DNS amplification
D.Port scan
AnswerD

A port scan sends TCP SYN packets to many ports on one host, seeking open services; the half-open responses distinguish it from a SYN flood, which targets a single port. This matches the stem's multiple-ports-to-one-host pattern.

Why this answer

A port scan involves sending packets to multiple ports on a target to discover open ports. The description matches a TCP SYN scan.

3
MCQmedium

A security analyst is analyzing a PCAP file in Wireshark and wants to isolate all HTTPS traffic. Which display filter should the analyst use?

A.tcp.dstport == 443
B.https
C.tcp.port == 443
D.port 443
AnswerC

Filtering on `tcp.port == 443` matches packets where either source or destination TCP port is 443, isolating HTTPS flows regardless of direction. This satisfies the analyst's requirement to display all HTTPS traffic in the PCAP, since HTTPS conventionally runs over TCP port 443.

Why this answer

The display filter `tcp.port == 443` in Wireshark captures all TCP traffic where either the source or destination port is 443, which is the default port for HTTPS. HTTPS traffic is HTTP over TLS/SSL, encapsulated in TCP, so filtering on port 443 effectively isolates all HTTPS sessions. This filter is symmetric, meaning it includes both client-to-server and server-to-client packets, ensuring complete visibility of the HTTPS conversation.

Exam trap

Cisco often tests the distinction between capture filters and display filters, and the trap here is that candidates confuse the simpler capture filter syntax (`port 443`) with the required display filter syntax (`tcp.port == 443`), leading them to choose Option D.

How to eliminate wrong answers

Option A is wrong because `tcp.dstport == 443` only filters packets where the destination port is 443, missing packets where the source port is 443 (e.g., server responses). Option B is wrong because `https` is not a valid Wireshark display filter; Wireshark does not have a built-in protocol name filter for HTTPS since it is encrypted and not directly dissectable as a separate protocol. Option D is wrong because `port 443` is a capture filter syntax (used in tcpdump or Wireshark's capture filter field), not a display filter; display filters require a different syntax (e.g., `tcp.port == 443`).

4
Multi-Selecthard

A SOC analyst is tuning a SIEM correlation rule to detect port scanning. The rule should generate an alert when a single source IP connects to many different destination ports on multiple hosts within a short time. Which THREE conditions should be included in the rule?

Select 3 answers
A.Count of unique destination IPs > threshold
B.Destination port is well-known
C.Single source IP
D.Average packet count per connection is high (e.g., >100)
E.Count of unique destination ports > threshold
AnswersA, C, E

Counting unique destination IPs above a threshold captures the horizontal spread of a scan, where one source probes many hosts. Combined with port and time-window conditions, it satisfies the stem's requirement to detect scanning across multiple hosts rather than a single target.

Why this answer

Option A is correct because a port scan is characterized by one source touching many distinct targets, so counting unique destination IPs above a threshold captures the horizontal spread across multiple hosts required by the rule. Option C is correct because the scenario specifies a single source IP, and grouping or filtering on that single source is what ties the many connections together as one scanning event rather than unrelated traffic. Option E is correct because counting unique destination ports above a threshold detects the vertical sweep of many ports, which is the defining signature of port scanning.

Option B is not required because scans can target any port range, not just well-known ports, so restricting to well-known ports would miss scans of high or ephemeral ports. Option D is not appropriate because port scans typically involve small, often single-packet connections, so a high average packet count per connection would indicate data transfer or a different behavior, not scanning.

5
MCQhard

In Zeek (Bro), which log file would an analyst examine to identify HTTP methods, URIs, and response codes from web traffic?

A.files.log
B.dns.log
C.conn.log
D.http.log
AnswerD

The http.log records HTTP transactions, capturing request methods, URIs, host headers, response status codes and user agents. This directly satisfies the stem's requirement to identify HTTP methods, URIs and response codes from web traffic, whereas conn.log, dns.log and ssl.log lack application-layer HTTP detail.

Why this answer

Zeek's http.log contains detailed HTTP transaction information including methods, URIs, and status codes.

6
MCQhard

An analyst is investigating a potential data exfiltration via DNS. In Zeek DNS logs, the analyst sees many queries for subdomains like 'a1b2c3.malicious.com', 'd4e5f6.malicious.com' etc. from an internal host. Which technique is likely being used?

A.DNS cache poisoning
B.DNS amplification
C.DNS tunneling
D.DNS zone transfer
AnswerC

DNS tunneling uses subdomains to encode data.

Why this answer

The repeated pattern of unique, seemingly random subdomains (e.g., 'a1b2c3.malicious.com') from a single internal host is a classic indicator of DNS tunneling. This technique encodes exfiltrated data into DNS query subdomains, leveraging the fact that DNS traffic is often allowed through firewalls. The malicious server decodes the subdomain strings to reconstruct the stolen data.

Exam trap

Cisco often tests the distinction between DNS tunneling (data exfiltration) and DNS amplification (DDoS), where candidates mistakenly associate any unusual DNS pattern with a volumetric attack rather than a covert channel.

How to eliminate wrong answers

Option A is wrong because DNS cache poisoning (spoofing) corrupts a resolver's cache with forged records to redirect traffic, not to exfiltrate data via subdomain queries. Option B is wrong because DNS amplification is a reflection-based DDoS attack that uses open resolvers to flood a victim with large responses, not a data exfiltration method. Option D is wrong because a DNS zone transfer is a legitimate mechanism for replicating DNS records between authoritative servers, not a technique for encoding data in subdomain queries.

7
MCQhard

An analyst is configuring a Snort rule to detect a known exploit targeting Apache web servers. The exploit sends a malicious HTTP POST request with a long User-Agent string. Which Snort rule header and options are most appropriate?

A.alert icmp any any -> any 80 (content:"POST"; pcre:"/User-Agent:.{200,}/R"; sid:1000001;)
B.alert tcp any any -> any 443 (content:"POST"; pcre:"/User-Agent:.{200,}/R"; sid:1000001;)
C.alert tcp any any -> any 80 (content:"POST"; pcre:"/User-Agent:.{200,}/R"; sid:1000001;)
D.alert udp any any -> any 80 (content:"GET"; pcre:"/User-Agent:.{200,}/R"; sid:1000001;)
AnswerC

The rule alerts on TCP port 80, matching the HTTP POST, and the pcre option detects a User-Agent exceeding 200 characters, which is the exploit's signature. The content match on POST plus the regex satisfies the requirement to detect this Apache-targeting request.

Why this answer

The rule must alert on TCP traffic to port 80 because HTTP POST requests use TCP, and Apache web servers typically listen on port 80 for unencrypted HTTP. The content match for 'POST' and the PCRE regex looking for a User-Agent string of 200 or more characters correctly targets the described exploit. This combination of protocol, port, and payload inspection is the most appropriate Snort rule.

Exam trap

The trap is that candidates focus on the payload content ('POST', User-Agent regex) and overlook the protocol and port in the rule header — a rule with the right content but wrong protocol (ICMP/UDP) or wrong port (443) will never fire on the actual exploit traffic.

How to eliminate wrong answers

Option A is wrong because it uses the `icmp` protocol, but HTTP POST requests are TCP-based, so the rule would never match the exploit traffic. Option B is wrong because it targets port 443 (HTTPS), where traffic is TLS-encrypted and Snort cannot inspect the plaintext HTTP payload without SSL inspection configured. Option D is wrong because it uses UDP (HTTP is TCP) and matches 'GET' instead of 'POST', so it would miss the malicious POST request entirely.

8
MCQhard

A security analyst is examining a PCAP and observes a TCP stream where the client sends a single packet with the PSH, ACK flags set, and the server responds with a single packet with the RST, ACK flags set. The client then sends no further packets. What is the most likely explanation for this behavior?

A.The client is performing a TCP port scan using a half-open scan.
B.The server is terminating the connection abruptly, possibly due to an application error or security policy.
C.The network is experiencing packet loss, causing the server to reset the connection.
D.The server rejected the connection attempt because the destination port is closed.
AnswerB

A PSH, ACK from the client indicates it is sending data to the server. The server's RST, ACK response means it is abruptly resetting the connection, which can occur if the application encounters an error, the server is enforcing a security policy (e.g., IPS blocking), or the service is misconfigured. The client then stops sending, consistent with a reset. This is the most likely explanation for the observed flags.

Why this answer

The sequence of a client sending a PSH, ACK (data) followed by a server RST, ACK indicates that the server is abruptly terminating the connection. This can happen due to application errors, security policies, or misconfigurations. The client then ceases communication, which is typical after a reset.

Other explanations like closed port, port scan, or packet loss do not align with the observed flags.

Exam trap

The trap here is assuming a RST always means a closed port, but in this case the connection was already established, so the RST indicates an abrupt termination after data was sent.

9
MCQeasy

Which protocol and port pair is commonly used for secure web traffic?

A.HTTPS 443
B.FTP 21
C.HTTP 80
D.SSH 22
AnswerA

HTTPS uses TLS over TCP port 443 to encrypt web traffic, satisfying the stem's requirement for a secure web protocol and port pair. Plain HTTP on port 80 provides no transport encryption, so 443 is the standard secure alternative.

Why this answer

HTTPS (HTTP Secure) uses port 443 for encrypted web traffic.

10
MCQeasy

A security analyst is examining a suspicious executable found on a compromised host. The analyst runs the command 'strings malware.exe' and sees the string 'cmd.exe /c net user hacker P@ssw0rd /add'. What is the most likely intent of this command?

A.Add the user 'hacker' to the local administrators group.
B.Create a new user account named 'hacker' with a specified password.
C.Modify the password of an existing user account named 'hacker'.
D.Delete the user account named 'hacker'.
AnswerB

The command 'net user hacker P@ssw0rd /add' is used to create a new local user account named 'hacker' with the password 'P@ssw0rd'. This is a common persistence technique used by attackers to maintain access to a compromised system. The '/add' switch explicitly adds the user, and the syntax matches the Windows net user command. This is the most likely intent based on the string.

Why this answer

The command 'net user hacker P@ssw0rd /add' is a classic Windows command to create a new local user account. The '/add' switch is the key indicator of account creation. This technique is often used by attackers for persistence, allowing them to regain access even if other malware is removed.

The other options describe different actions that would require different syntax or switches.

Exam trap

The trap here is confusing the 'net user' command for account creation with group membership changes, which require 'net localgroup' instead.

11
MCQmedium

A network analyst is examining a packet capture and notices a series of TCP packets where the client sends a SYN, the server responds with SYN-ACK, and the client never sends an ACK. The client repeats this for many destination ports on the same server. Which conclusion is most accurate?

A.The client is using a legitimate application that only requires half-open connections.
B.The server is misconfigured and is dropping all incoming connections.
C.The client is performing a TCP SYN scan to discover open ports on the server.
D.The client is experiencing network congestion causing packet loss of the final ACK.
AnswerC

A SYN scan sends SYN packets and never completes the three-way handshake. The server responds with SYN-ACK for open ports, but the scanner does not send the final ACK, so no full connection is established. This half-open behavior across many ports on one server is characteristic of a port scan.

Why this answer

The pattern of SYN, SYN-ACK, and no ACK repeated across many ports is a TCP SYN scan. This technique, often called half-open scanning, allows an attacker to discover open ports without completing connections, making it harder to log on the target. It is a common reconnaissance method.

Exam trap

The trap here is interpreting the missing ACK as packet loss, when the systematic repetition across many ports indicates deliberate scanning behavior.

12
Multi-Selecthard

An analyst is tuning Snort IDS rules and wants to reduce false positives. Which TWO rule options can be adjusted to decrease sensitivity?

Select 2 answers
A.Change the rule action from 'alert' to 'drop'
B.Add a 'suppress' rule to ignore traffic from known benign IPs
C.Change protocol from TCP to UDP
D.Increase the rule priority from low to high
E.Use the 'detection_filter' to require a certain number of matches within a time window
AnswersB, E

The suppress option tells Snort to ignore traffic matching a specified source or rule, so known benign IPs stop generating alerts. This directly reduces false positives, satisfying the stem's sensitivity-reduction goal, because trusted hosts no longer trigger signatures during routine activity.

Why this answer

Option B is correct because a 'suppress' rule in Snort tells the IDS to ignore alerts generated by a specific rule for a given source or destination IP, which directly eliminates false positives caused by known benign hosts. Option E is correct because 'detection_filter' (or its predecessor 'threshold') requires a specified number of matches within a time interval before an alert fires, raising the bar for triggering and thereby reducing sensitivity to isolated or incidental events. Option A is incorrect because changing the action from 'alert' to 'drop' alters the response mode (inline IPS behavior) rather than decreasing detection sensitivity, and it may even increase impact.

Option C is incorrect because switching the protocol from TCP to UDP changes what traffic the rule inspects, not the sensitivity threshold, and would likely miss the intended traffic. Option D is incorrect because increasing priority from low to high only affects alert ranking and does not reduce the number of false positives generated.

13
MCQeasy

During a security monitoring review, an analyst notices an unusual amount of traffic on port 445. Which protocol is most likely associated with this port?

A.HTTPS
B.SMB
C.DNS
D.HTTP
AnswerB

Port 445 carries SMB (Server Message Block), Microsoft's protocol for file and printer sharing, named pipes and remote administration. Unusual volumes on 445 often indicate ransomware propagation, lateral movement or data exfiltration, making SMB the protocol to investigate.

Why this answer

Port 445 is the default port for Microsoft's implementation of the Server Message Block (SMB) protocol, used for file and printer sharing over a network. An unusual amount of traffic on this port often indicates SMB-related activity, such as legitimate file transfers or potential exploitation attempts like the EternalBlue vulnerability (MS17-010).

Exam trap

Cisco often tests the association of well-known ports with their protocols, and the trap here is that candidates may confuse port 445 with HTTPS (443) or HTTP (80) due to similar numbering, or assume DNS uses a non-standard port.

How to eliminate wrong answers

Option A is wrong because HTTPS uses port 443, not 445, and is secured with TLS/SSL for encrypted web traffic. Option C is wrong because DNS primarily uses UDP port 53 (and TCP port 53 for zone transfers), not port 445. Option D is wrong because HTTP uses port 80 by default, not port 445, and is used for unencrypted web traffic.

14
MCQmedium

A Cisco Stealthwatch analyst notices a host on the internal network is sending periodic DNS queries to a single external domain with subdomains that are long, random-looking strings (e.g., a8f3k2j9d0x1.example.com). The queries occur every 60 seconds, and the responses are consistently NXDOMAIN. Which type of malicious activity does this pattern most strongly indicate?

A.DNS tunneling for data exfiltration
B.A misconfigured DNS resolver causing retry storms
C.Normal DNS prefetching by a web browser
D.DNS beaconing from a command-and-control implant
AnswerD

The periodic, fixed-interval queries with random subdomains to one domain, combined with NXDOMAIN responses, are classic signs of a DNS beacon. The implant generates unique subdomains to check in and receives no response because the C2 domain may not be active yet or the analyst is seeing only the beacon attempts. This pattern is a well-known indicator of compromise.

Why this answer

The combination of periodic timing, random subdomains, and consistent NXDOMAIN responses points to a DNS beacon from malware attempting to contact command-and-control. The implant uses DNS because it is often allowed through firewalls. The fixed interval and single destination domain distinguish this from normal DNS traffic or tunneling, which would carry larger payloads and expect responses.

Exam trap

The trap here is assuming any DNS anomaly is tunneling, but tunneling requires bidirectional data transfer, while beaconing only needs periodic check-ins.

15
MCQhard

A SOC analyst is reviewing firewall logs and sees repeated outbound connections from an internal server to an external IP on TCP port 443, but the traffic is not TLS. Packet capture shows a custom binary protocol with periodic small keepalives. Which type of malicious activity is most consistent with these findings?

A.A misconfigured application using HTTPS on port 443
B.Command-and-control beaconing over a non-standard protocol
C.Data exfiltration over DNS
D.Lateral movement using SMB
AnswerB

Malware often masquerades as HTTPS by using port 443 while speaking a custom binary protocol to evade port-based filtering and TLS inspection. The periodic small keepalives are a hallmark of beaconing, where the implant checks in with its controller at regular intervals. Because the traffic is not actually TLS, signature-based TLS inspection will not flag it, making behavioral analysis essential for detection.

Why this answer

The combination of outbound port 443, absence of TLS, a custom binary protocol, and periodic small keepalives strongly suggests command-and-control beaconing. Attackers commonly use port 443 to blend with normal web traffic while evading TLS inspection by not actually using TLS. The regular check-ins are designed to receive instructions or exfiltrate small amounts of data without drawing attention.

Exam trap

The trap here is assuming port 443 always means TLS and benign web traffic, when attackers frequently abuse it for non-TLS command-and-control.

16
Multi-Selecthard

A SOC analyst is investigating a potential security incident involving a Windows workstation. The analyst has collected network traffic and host logs. Which two artifacts would provide the most direct evidence of a Pass-the-Hash attack? (Choose two.)

Select 2 answers
A.Network traffic showing SMB authentication with NTLMSSP messages containing a username and hash.
B.Windows Security Event ID 4688 showing 'svchost.exe' with parent 'services.exe'.
C.Windows Security Event ID 4624 with Logon Type 3 and NTLM authentication.
D.Windows Security Event ID 4672 indicating special privileges assigned to a new logon.
E.Windows Security Event ID 4768 showing a Kerberos TGT request.
AnswersA, C

Pass-the-Hash attacks often leverage SMB for lateral movement. Capturing network traffic that includes NTLMSSP authentication attempts can reveal the use of NTLM hashes instead of plaintext passwords. Specifically, the NTLMSSP_AUTH message contains the username and the challenge response derived from the hash. If the same hash is used from multiple hosts or in an unusual pattern, it strongly suggests Pass-the-Hash. This artifact provides direct network-level evidence.

Why this answer

Pass-the-Hash is an attack where an adversary uses the NTLM hash of a user's password to authenticate without knowing the plaintext. The most direct evidence comes from authentication events that show NTLM usage, such as Windows Security Event ID 4624 with Logon Type 3 and NTLM, and network captures of SMB NTLMSSP authentication. Other events like process creation or privilege assignment are not specific to this technique.

Exam trap

The trap here is assuming that any NTLM authentication or administrative logon indicates Pass-the-Hash, when in fact NTLM is still used legitimately; the key is the context of hash reuse without plaintext.

17
MCQmedium

A Cisco Firepower analyst inspects an inline intrusion policy event where the packet was dropped but only a partial payload was captured. The analyst wants to confirm whether the attack was successful on the target host. Which data source should be correlated with the Firepower event?

A.NetFlow records exported from the Firepower device
B.Syslog messages generated by the Firepower management center
C.Full packet capture stored on the Firepower device
D.Endpoint security product telemetry from the target host
AnswerD

Endpoint detection and response (EDR) or endpoint protection platform telemetry records process execution, file modification, registry changes, and command-line arguments on the target. Correlating the Firepower intrusion event timestamp and source IP with this endpoint data reveals whether the dropped packet was part of a successful exploit chain or whether the host actually spawned a malicious process. This is the authoritative source for confirming host-level compromise after a partial network capture.

Why this answer

When an intrusion event shows a partial payload capture, the network sensor can confirm the attempt but not the outcome on the host. Endpoint telemetry supplies process, file, and registry evidence that ties the network event to actual execution. Correlating the Firepower timestamp and addresses with endpoint records determines whether the attack succeeded, which is the analyst's stated goal.

Exam trap

The trap here is assuming that more packet capture or flow data from the same Firepower sensor can prove host compromise, when only endpoint telemetry shows process-level execution.

18
Multi-Selecthard

A SOC analyst is reviewing Cisco Firepower and NetFlow records for a suspected lateral movement campaign inside the corporate network. Which TWO monitoring observations most strongly support the hypothesis that an attacker is moving laterally using SMB? (Choose two.)

Select 2 answers
A.Repeated authentication attempts using a service account against multiple servers on port 445
B.An internal host sending large volumes of ICMP echo requests to the default gateway
C.A single host resolving many external DNS names over port 53
D.A workstation downloading operating system updates from an internal WSUS server over HTTP
E.Multiple internal hosts receiving TCP connections on port 445 from a single workstation in a short time window
AnswersA, E

Using one service account to authenticate to many servers over SMB suggests credential reuse for lateral movement, especially if the account is not normally used interactively. Attackers commonly harvest service account credentials and spray them across hosts, so this pattern supports the SMB lateral movement hypothesis.

Why this answer

SMB lateral movement is characterized by one host fanning out to many internal systems on port 445 and by credential reuse, such as a service account authenticating to multiple servers. These two observations together distinguish attacker pivoting from normal file share access, making them the strongest supporting evidence.

Exam trap

The trap here is selecting any internal-to-internal traffic as lateral movement, when the distinguishing factors are the fan-out pattern on port 445 and suspicious credential reuse rather than routine update or DNS traffic.

19
MCQeasy

A SOC analyst is triaging a Cisco Stealthwatch alarm that shows a workstation uploading 4 GB to an external IP address at 02:00, outside normal business hours. The destination has no prior reputation data. Which action should the analyst take first according to the incident response process?

A.Block the external IP address on the perimeter firewall
B.Escalate the alarm directly to the legal department
C.Validate the alarm and identify the internal host and user
D.Disable the user account associated with the workstation
AnswerC

The first step in the incident response process is to validate that the alarm represents a real security event and to identify the affected asset and user. This establishes scope, confirms whether the traffic is expected, and determines whether escalation is warranted. Only after validation and identification can the analyst make informed containment decisions. Jumping to blocking or disabling accounts without this step risks disrupting legitimate business activity and missing related compromised systems.

Why this answer

Incident response follows a defined sequence, and the identification phase requires validating the alarm and determining the affected asset and user before containment. This step confirms whether the activity is malicious, establishes scope, and informs subsequent decisions. Blocking, disabling accounts, or escalating to legal before validation can disrupt legitimate operations and leave related compromised systems undiscovered.

Exam trap

The trap here is equating a large outbound transfer with confirmed exfiltration and skipping validation, when the first response step is always to verify and identify the affected host.

20
MCQmedium

A SOC analyst is tuning IDS signatures and notices that a particular signature triggers frequently on legitimate traffic from a specific internal application. The signature has a high false positive rate. What is the best action to take?

A.Disable the signature entirely.
B.Increase the severity of the signature to get more attention.
C.Create a suppression rule to ignore the specific source IP or application.
D.Change the signature action to 'alert' instead of 'drop'.
AnswerC

Suppression rules let the IDS ignore matching traffic from the specific source IP or application while retaining the signature for all other sources, eliminating the recurring false positives without losing genuine detection coverage. This directly addresses the high false-positive rate constraint.

Why this answer

A suppression rule is the correct tuning action because it preserves the signature's detection capability for all other traffic while filtering out the known-good source IP or application that generates the false positives. This is the standard IDS/IPS tuning practice: narrow the exception rather than removing the detection entirely. It maintains visibility into genuine attacks using the same signature from other sources.

Exam trap

The trap here is confusing 'reduce false positives' with 'disable the noisy rule' — candidates often pick the most drastic action (disable) instead of the surgical one (suppress specific source), missing that the exam tests least-disruptive tuning.

How to eliminate wrong answers

Option A is wrong because disabling the signature entirely removes detection for real attacks that would match it, creating a blind spot — the correct approach is to narrow, not eliminate, coverage. Option B is wrong because raising severity on a noisy signature increases alert fatigue and does nothing to reduce the false positive rate; severity is a prioritization field, not a filtering mechanism. Option D is wrong because changing the action from 'drop' to 'alert' only changes the response mode, not the volume of false positives — the analyst would still receive the same noisy alerts, just without blocking.

21
Multi-Selecthard

During packet analysis in Wireshark, which THREE findings are indicators of potential malicious activity? (Choose THREE.)

Select 3 answers
A.An HTTPS connection to a well-known website.
B.An unusually large ICMP echo request packet (e.g., 65,000 bytes).
C.Unencrypted credentials in an HTTP packet.
D.A normal DNS query for a common domain.
E.A large number of TCP SYN packets to various ports on one host.
AnswersB, C, E

Oversized ICMP echo requests exploit the protocol's normal 64-byte payload ceiling, indicating tunnelling or data exfiltration hidden inside ping traffic. This satisfies the stem's malicious-activity criterion because legitimate diagnostics never require 65,000-byte payloads, and such frames often signal covert channels or ping floods.

Why this answer

Option B is correct because an ICMP echo request of roughly 65,000 bytes is abnormally large for a standard ping (normally 32–64 bytes of payload), indicating possible ICMP tunneling, data exfiltration, or a Ping of Death-style attack. Option C is correct because credentials transmitted in cleartext over HTTP can be captured by anyone sniffing the traffic, which is a clear sign of insecure and potentially malicious credential harvesting or a policy violation. Option E is correct because a flood of TCP SYN packets to multiple ports on a single host is the classic signature of a port scan (e.g., SYN scan), often a precursor to exploitation.

Option A is not an indicator because HTTPS to a well-known website is normal, expected, encrypted traffic. Option D is not an indicator because a routine DNS query for a common domain is ordinary network behavior and not inherently suspicious.

Exam trap

Cisco often tests the distinction between normal traffic patterns and protocol anomalies; the trap here is that candidates may overlook the 'unusually large' qualifier and dismiss ICMP anomalies as benign, or mistake a legitimate HTTPS connection for suspicious activity due to encryption.

22
MCQmedium

A firewall log shows repeated denied packets from IP 10.0.0.5 to destination 192.168.1.10 on port 22. What is the most likely attack?

A.HTTP flood
B.SMB exploit
C.SSH brute force
D.DNS amplification
AnswerC

Repeated denied connections to port 22, the SSH service, from one source indicate automated credential guessing against remote shell access. The firewall's consistent blocking of these attempts confirms brute-force behaviour rather than legitimate administrative traffic, matching the log pattern described in the stem.

Why this answer

Repeated denied packets from a single source IP to a specific destination on port 22 (SSH) indicate a brute-force attack, where an attacker attempts multiple username/password combinations to gain unauthorized access. The firewall logs show the traffic is being blocked, but the pattern of repeated attempts is characteristic of an SSH brute-force attack, not a flood or exploit targeting other services.

Exam trap

Cisco often tests the association between specific port numbers and common attack types, so the trap here is that candidates may confuse port 22 with HTTP (port 80) or SMB (port 445) and pick a wrong answer based on the attack name rather than the port number.

How to eliminate wrong answers

Option A is wrong because an HTTP flood targets port 80 or 443 with a high volume of HTTP requests, not port 22 (SSH). Option B is wrong because an SMB exploit targets port 445 (SMB over TCP) or 139 (NetBIOS), not port 22, and involves exploiting vulnerabilities like EternalBlue, not repeated authentication attempts. Option D is wrong because a DNS amplification attack uses UDP port 53 and involves spoofed source IPs to amplify traffic toward a victim, not repeated TCP connections to port 22.

23
MCQmedium

Which log source would provide the most detailed information about HTTP requests, including URLs and user agents?

A.DNS logs
B.Firewall logs
C.Web server logs
D.System logs
AnswerC

Web server logs record each HTTP transaction, capturing request method, URL path, query strings, status codes and User-Agent headers. This satisfies the requirement for detailed request-level data, unlike firewall logs that show only connection metadata or NetFlow records lacking application-layer detail.

Why this answer

Web server logs capture HTTP requests with details like URL, method, response code, and user-agent. They are the best source for HTTP traffic details.

24
MCQhard

A network baseline shows that a server typically sends 1-2 MB of data per hour to external IPs. Suddenly, the server sends 50 MB of data to an IP in a foreign country within 10 minutes. The traffic is encrypted. Which monitoring tool would best confirm data exfiltration?

A.NetFlow/IPFIX analysis comparing current traffic to baseline
B.Snort IDS with a rule to detect large file transfers
C.Wireshark packet capture with a display filter for the destination IP
D.Windows Event Logs for file access
AnswerA

NetFlow/IPFIX records flow metadata — source, destination, byte counts and timestamps — letting the analyst compare the 50 MB foreign transfer against the 1-2 MB hourly baseline. Encryption hides payload contents, but flow volume and destination still confirm exfiltration.

Why this answer

NetFlow/IPFIX provides flow records with byte counts, enabling detection of unusual data volumes, even with encrypted payloads.

25
Multi-Selectmedium

A security analyst is examining system logs for signs of privilege escalation. Which THREE events are most relevant to detect such activity?

Select 3 answers
A.Execution of commands with sudo
B.Multiple failed login attempts
C.Modification of user group memberships
D.User account creation with administrator privileges
E.Successful SSH login from a remote IP
AnswersA, C, D

Sudo execution records commands run with elevated privileges, making it a direct indicator of privilege escalation attempts. Monitoring these events reveals when a user gains or attempts root-level access, satisfying the requirement to detect escalation activity in system logs.

Why this answer

Option A is correct because execution of commands with sudo directly indicates a user is attempting to run processes with elevated (root) privileges, which is a primary vector for privilege escalation and should be audited via /var/log/auth.log or journalctl. Option C is correct because modification of user group memberships (e.g., adding an account to the sudo or wheel group) grants persistent elevated privileges, a classic privilege-escalation technique detectable through changes to /etc/group or usermod/gpasswd events. Option D is correct because creating a user account with administrator privileges (e.g., UID 0 or membership in an admin group) establishes a new high-privilege identity, which is a strong indicator of malicious persistence or escalation.

Option B is not the best fit because multiple failed login attempts primarily indicate brute-force or password-guessing attempts against authentication, not privilege escalation after access is obtained. Option E is also not the best fit because a successful SSH login from a remote IP only shows initial remote access, without evidence that privileges were elevated on the system.

Exam trap

The trap is that 'failed login attempts' feels security-relevant and candidates select it, but the question specifically asks about privilege escalation — authentication failures are a different attack phase and do not demonstrate elevated access.

26
MCQmedium

A security analyst is reviewing firewall logs and notices a high number of denied outbound connections from an internal workstation to various external IP addresses on port 445 (SMB). What is the most likely explanation for this activity?

A.The user is browsing the web and the firewall is blocking HTTP
B.The workstation is performing a DNS lookup
C.The workstation is infected with malware attempting to spread via SMB
D.The workstation is performing a legitimate file transfer using FTP
AnswerC

SMB on port 445 is used by ransomware and worms such as WannaCry to propagate laterally. Repeated outbound attempts to many external addresses indicate the workstation scanning for reachable SMB shares, consistent with infection rather than legitimate file sharing.

Why this answer

Port 445 is used by SMB (Server Message Block) for file sharing and network communication. A high volume of denied outbound connections from a single workstation to many external IPs on this port is a classic indicator of malware attempting to propagate via SMB vulnerabilities, such as EternalBlue (MS17-010). Legitimate SMB traffic is typically confined to internal networks, not external scanning.

Exam trap

Cisco often tests the association of specific ports with their services (e.g., SMB = 445) and expects candidates to recognize that anomalous outbound scanning on a file-sharing port indicates malware, not a benign application.

How to eliminate wrong answers

Option A is wrong because HTTP traffic uses ports 80 and 443, not port 445, and the firewall would block HTTP on those ports, not SMB. Option B is wrong because DNS lookups use UDP or TCP port 53, not port 445, and would not generate denied outbound connections to multiple external IPs. Option D is wrong because FTP uses ports 20 and 21 for control and data transfer, not port 445, and legitimate file transfers would not exhibit a high volume of denied connections to random external IPs.

27
MCQeasy

A security analyst is examining a Cisco Umbrella Investigate report for a domain that has been flagged as malicious. The report shows a high 'security score' and lists multiple categories including 'Malware' and 'Command and Control'. Which action should the analyst take first?

A.Add the domain to a watchlist and continue monitoring for 24 hours
B.Submit the domain to Cisco Talos for reclassification
C.Block the domain at the DNS layer and investigate any internal hosts that queried it
D.Report the domain to the ISP and wait for their response
AnswerC

When a domain is categorized as malware and command-and-control with a high security score, the immediate priority is to prevent further communication and identify affected hosts. Blocking at DNS via Umbrella stops resolution, and querying logs for internal clients that resolved the domain helps scope the incident. This aligns with containment and investigation best practices.

Why this answer

A domain flagged as malware and command-and-control with a high security score should be blocked immediately to sever communication. The analyst must also identify internal hosts that resolved the domain to determine the scope of compromise. This two-step approach of containment and investigation is the correct first response.

Exam trap

The trap here is treating the report as a suggestion rather than actionable intelligence, leading to delayed containment.

28
MCQeasy

A junior SOC analyst receives an alert indicating that a workstation attempted to resolve a domain associated with a known malware family. The analyst wants to determine whether the workstation actually connected to the malicious domain or if the resolution attempt was blocked. Which data source would most directly answer this question?

A.The organization's password policy configuration
B.The workstation's local hosts file
C.The endpoint's installed application inventory
D.DNS server response logs showing query results and response codes
AnswerD

DNS server response logs record whether a query received a valid answer, an NXDOMAIN, or a blocked response from a protective DNS service. This directly shows if the domain was resolved or denied, answering whether the workstation could have connected. Correlating these responses with firewall or proxy logs then confirms whether an actual connection followed the resolution.

Why this answer

DNS server response logs capture the outcome of each query, including successful answers, NXDOMAIN responses, and blocks from protective DNS filtering. This directly determines whether the workstation received an address for the malicious domain. Following up with firewall or proxy logs confirms whether an outbound connection actually occurred, allowing the analyst to decide whether endpoint containment is required.

Exam trap

The trap here is assuming that an alert for a DNS resolution attempt proves a successful connection, when the response code in DNS logs determines whether the name was actually resolved or blocked.

29
MCQhard

An analyst is reviewing Cisco Firepower intrusion events and sees an alert for a TCP connection to an internal web server on port 80 with the rule message 'SERVER-WEBAPP Apache Struts2 remote code execution attempt'. The packet payload contains the string 'Content-Type: %{(#_='multipart/form-data')'. The server is running Apache Struts2 version 2.3.15. What should the analyst do next?

A.Check the web server logs and file system for signs of compromise, and verify whether the server was patched.
B.Ignore the alert because the server is behind a firewall and the attack is not likely to succeed.
C.Block the source IP address at the firewall and consider the incident resolved.
D.Update the Snort signature to detect the specific payload string and wait for the next alert.
AnswerA

The alert indicates an attempted exploit against a known vulnerable version of Apache Struts2. The analyst must determine if the exploit succeeded by examining web server logs, looking for unusual processes or files, and confirming the patch level. This response aligns with incident handling: validate the alert, assess impact, and contain if necessary.

Why this answer

The alert shows a remote code execution attempt against a known vulnerable Apache Struts2 version. The analyst must verify whether the exploit succeeded by examining server logs, processes, and files. This is critical because the traffic reached the internal server, and the payload matches a known exploit.

Proper incident response requires validation and scoping before containment.

Exam trap

The trap here is focusing on blocking the source IP or updating signatures instead of investigating whether the vulnerable server was actually compromised.

30
MCQeasy

Which OSI layer is responsible for logical addressing and routing, and is commonly targeted by IP spoofing attacks?

A.Application layer
B.Network layer
C.Transport layer
D.Data Link layer
AnswerB

The Network layer (Layer 3) handles logical addressing and routing, satisfying the stem's requirement. IP spoofing attacks forge source addresses within IP packets at this layer, exploiting the lack of authentication in the IP protocol. This makes Layer 3 the precise target, unlike the Transport layer's ports or Data Link layer's MAC addresses.

Why this answer

The Network layer (Layer 3) handles logical addressing (IP addresses) and routing. IP spoofing involves falsifying the source IP address at this layer.

31
MCQmedium

A security analyst is reviewing firewall logs and notices a rule that denies traffic from source IP 10.0.0.5 to destination port 3389. What service is being blocked?

A.RDP
B.SNMP
C.SMTP
D.SSH
AnswerA

Port 3389 is the registered TCP port for Remote Desktop Protocol, so a deny rule targeting it blocks RDP sessions. The stem's constraint — destination port 3389 — maps directly to RDP, Microsoft's protocol for remote graphical access to Windows hosts. No other listed service uses this port.

Why this answer

Port 3389 is the default port for Remote Desktop Protocol (RDP), which is used for remote graphical desktop access to Windows systems. The firewall rule denying traffic from 10.0.0.5 to this port blocks RDP connections, preventing that host from initiating remote desktop sessions.

Exam trap

Cisco often tests the association of default port numbers with common services, and the trap here is that candidates may confuse RDP (3389) with SSH (22) or SMTP (25) due to similar remote access or management functions.

How to eliminate wrong answers

Option B (SNMP) is wrong because SNMP uses UDP ports 161 (queries) and 162 (traps), not TCP 3389. Option C (SMTP) is wrong because SMTP uses TCP port 25 for email relay, with submissions on port 587 or 465, not 3389. Option D (SSH) is wrong because SSH uses TCP port 22 for secure remote shell access, not port 3389.

32
MCQeasy

A SOC analyst receives an alert that a user account successfully authenticated to the VPN from two geographically distant locations within four minutes. Both sessions remain active. The identity team confirms the user is traveling and has only one device. Which monitoring conclusion is most appropriate?

A.This indicates a split-tunnel misconfiguration, since split tunneling causes a user to appear from multiple source networks simultaneously.
B.This is expected behavior because VPN concentrators load-balance sessions and users commonly appear from multiple regions.
C.This is a low-severity event because both sessions authenticated successfully, and successful authentication rules out misuse.
D.This is impossible-travel behavior consistent with credential theft, so the account should be treated as compromised pending verification.
AnswerD

Two simultaneous active VPN sessions from distant geographies within four minutes cannot be produced by one traveler with one device, since physical travel between those points is impossible in that interval. This pattern is a classic indicator of stolen credentials being used in parallel with the legitimate user. Treating the account as compromised and verifying with the user is the correct monitoring response.

Why this answer

Impossible travel detection compares authentication events across time and geography to find sessions that one person could not physically produce. Two concurrent VPN sessions from distant locations, with one confirmed device and one traveling user, indicate a second party using the same credentials. The appropriate action is to treat the account as compromised, verify with the user through an out-of-band channel, and review session activity for data access or lateral movement.

Exam trap

The trap here is treating a successful login as proof of legitimate access, when valid credentials presented by an unauthorized party authenticate just as successfully.

33
MCQmedium

Which component of a SIEM is responsible for converting log data from various sources into a standard format?

A.Aggregation
B.Alerting
C.Correlation
D.Normalization
AnswerD

Normalization standardizes log data.

Why this answer

Normalization is the SIEM component that parses incoming log data from diverse sources (e.g., syslog, Windows Event Log, NetFlow) and maps the fields into a common, standardized schema. This process ensures that fields like source IP, destination IP, and timestamp are consistently named and formatted, enabling effective correlation and analysis across heterogeneous devices.

Exam trap

The trap here is that candidates confuse normalization with aggregation, thinking that simply collecting logs from multiple sources is enough to make them comparable, when in fact normalization is the crucial step that standardizes the data format.

How to eliminate wrong answers

Option A is wrong because aggregation refers to the collection and consolidation of log data from multiple sources into a central repository, not the conversion of that data into a standard format. Option B is wrong because alerting is the function that generates notifications based on predefined rules or thresholds, not the transformation of log formats. Option C is wrong because correlation involves analyzing relationships between events to identify patterns or incidents, which depends on already-normalized data.

34
MCQeasy

A security analyst is examining a suspicious file and calculates its SHA-256 hash. The analyst then queries Cisco Talos Intelligence for the hash. The result shows that the file is known malware with a detection name of 'Trojan.GenericKD.123456'. Which of the following does this result indicate?

A.The file is confirmed malicious and matches a known malware signature in the Talos database.
B.The file is benign but has a similar hash to known malware.
C.The file is suspicious but requires further dynamic analysis to confirm maliciousness.
D.The file has been quarantined by Cisco AMP for Endpoints automatically.
AnswerA

Cisco Talos Intelligence maintains a database of file hashes associated with malware. When a hash query returns a known malware detection name, it means the exact file has been previously identified as malicious. This is a strong indicator that the file is indeed malware, and the analyst should treat it as such, initiating incident response procedures.

Why this answer

Cisco Talos Intelligence provides reputation and threat data for files, IPs, and domains. When a SHA-256 hash is queried and returns a known malware detection, it means the exact file has been previously analyzed and confirmed malicious. This is a reliable indicator, and the analyst should proceed with containment and remediation.

Other options either misinterpret the result or assume actions that are not part of the query process.

Exam trap

The trap here is thinking that a hash match requires further validation or that it only indicates similarity, when in fact it is a definitive identification of the exact file.

35
Multi-Selectmedium

A security analyst is analyzing system logs and notices multiple failed authentication events followed by a successful login from the same user account, and then a privilege escalation event. Which THREE events should be correlated to detect a potential attack?

Select 3 answers
A.Successful authentication event
B.Privilege escalation event
C.Failed authentication events
D.Network share access event
E.Account creation event
AnswersA, B, C

The successful login is the pivot point: after repeated failures, it signals the attacker guessed valid credentials and gained access. Correlating it with the preceding failures and the following privilege escalation confirms a brute-force-to-compromise chain rather than isolated noise.

Why this answer

The scenario describes a classic brute-force-then-compromise pattern, so the three events that must be correlated are C, the failed authentication events, which indicate repeated unsuccessful login attempts against the same account; A, the successful authentication event, which shows the attacker eventually guessed or cracked the credentials and gained access; and B, the privilege escalation event, which reveals that the compromised account was then used to obtain higher-level rights, confirming the attack progressed beyond initial access. Correlating these three in sequence (many failures → one success → escalation) is what distinguishes a real intrusion from benign failed logins. D (network share access) and E (account creation) are not part of the described sequence and, while potentially suspicious in other contexts, are not the events the analyst should correlate here to detect this specific attack chain.

Exam trap

Cisco often tests the concept that a single successful login alone is not suspicious, but when combined with preceding failed attempts and subsequent privilege escalation, it forms a clear attack pattern that candidates must recognize as a three-event correlation.

36
MCQeasy

A security analyst is monitoring network traffic and notices a high volume of TCP SYN packets sent to various ports on a single host. Which type of attack is most likely occurring?

A.DNS amplification
B.Smurf attack
C.Port scan
D.ARP spoofing
AnswerC

A port scan sends TCP SYN packets to many ports on one host, seeking open services. The half-open SYN pattern, with no completed handshake, distinguishes scanning from a SYN flood, which targets a single port. This matches the stem's high-volume SYN traffic to various ports.

Why this answer

A high volume of TCP SYN packets to various ports on a single host is the signature of a port scan, most commonly an SYN (half-open) scan using tools like Nmap with -sS. The scanner sends SYN to many ports and analyzes SYN-ACK (open) versus RST (closed) responses without completing the three-way handshake. This pattern of many SYNs to different ports on one target is the classic reconnaissance footprint.

Exam trap

The trap is that 'high volume of SYN packets' can sound like a SYN flood (DoS), but the key detail is 'to various ports on a single host' — that is reconnaissance (port scan), not a flood, and candidates who fixate on volume alone pick the wrong category.

How to eliminate wrong answers

Option A is wrong because DNS amplification is a reflection/volumetric DDoS attack that floods a victim with large DNS responses, not a stream of SYNs to many ports on one host. Option B is wrong because a Smurf attack uses ICMP echo requests to a broadcast address with a spoofed source, amplifying ICMP replies to the victim — it involves ICMP, not TCP SYN. Option D is wrong because ARP spoofing poisons the ARP cache to redirect Layer 2 traffic; it does not generate TCP SYN packets to many ports and is not detectable by SYN volume.

37
MCQhard

An analyst is investigating a potential security incident and reviews the Cisco ASA firewall logs. The logs show the following entry: 'Deny tcp src outside:203.0.113.5/443 dst inside:10.1.1.10/3389'. Which of the following does this log entry indicate?

A.An external host successfully connected to an internal host on RDP.
B.An internal host attempted to connect to an external host on RDP, but the connection was blocked.
C.An external host attempted to connect to an internal host on RDP, but the connection was blocked by the firewall.
D.An internal host attempted to connect to an external host on HTTPS, but the connection was blocked.
AnswerC

The log shows a denied TCP connection from an external IP (203.0.113.5) on port 443 to an internal IP (10.1.1.10) on port 3389. Port 3389 is used for RDP. The firewall denied the connection, indicating an attempt to access RDP from the outside was blocked. This is a common indicator of scanning or exploitation attempts.

Why this answer

The Cisco ASA log entry shows a denied TCP connection from an external IP address to an internal IP address on port 3389, which is the default port for RDP. The 'Deny' action indicates the firewall blocked the attempt. This is a common scenario where an external host tries to exploit RDP, but the firewall prevents it.

Understanding log format, including source/destination and port numbers, is essential for incident analysis.

Exam trap

The trap here is misreading the direction of the connection or confusing the source port with the destination port, leading to an incorrect interpretation of the log entry.

38
MCQhard

An analyst is reviewing DNS logs and sees repeated queries from an internal workstation to randomly generated subdomains of a single domain, such as a1b2c3.example.com, d4e5f6.example.com, and so on. The responses are consistently NXDOMAIN. Which technique is most consistent with this pattern?

A.Fast flux DNS used to rotate IP addresses for a botnet.
B.DNS cache poisoning attempt against the internal resolver.
C.DNS tunneling used to exfiltrate data through TXT record queries.
D.Domain generation algorithm (DGA) used by malware for command-and-control resolution.
AnswerD

DGAs produce many pseudo-random subdomains that malware queries until one resolves to a C2 server. The NXDOMAIN responses for most queries are expected because only a few generated domains are registered by the attacker. This pattern, with high volumes of random-looking names under one domain, is a classic DGA indicator in DNS logs.

Why this answer

Randomly generated subdomains under a single domain with mostly NXDOMAIN responses are a hallmark of a domain generation algorithm. Malware uses DGAs to evade static blocklists by cycling through many candidate C2 domains, and DNS logs are the primary place to detect this behavior.

Exam trap

The trap here is confusing DGA traffic with DNS tunneling, even though tunneling usually shows successful, data-carrying queries rather than repeated NXDOMAIN responses.

39
Multi-Selecthard

An analyst is correlating telemetry after a suspected Kerberoasting attack against an Active Directory environment. Which two artifacts, when found together, most strongly support that the attack succeeded in obtaining crackable service ticket material? (Choose two.)

Select 2 answers
A.Windows Security event 4769 logged with RC4 encryption type (0x17) for service accounts, generated in a short burst from one workstation.
B.A Group Policy update pushed to all domain-joined computers changing the minimum password length requirement.
C.LDAP search traffic enumerating accounts with a servicePrincipalName attribute set, originating from a workstation rather than a domain controller.
D.A spike in Windows Security event 4625 failed logons against many user accounts from a single source over a brief interval.
E.A sudden increase in SMB file share access to the finance department's documents from a user in the engineering group.
AnswersA, C

Event 4769 records Kerberos service ticket requests. A burst of requests for multiple service principal names using RC4, the weaker encryption type, from a single non-server host matches the Kerberoasting pattern, since the attacker requests tickets and cracks them offline. The volume, encryption downgrade, and unusual requesting host together distinguish this from normal service access.

Why this answer

Kerberoasting requires two observable steps: discovery of accounts with service principal names, and requests for their service tickets using weak encryption that can be cracked offline. A workstation issuing broad LDAP queries for the servicePrincipalName attribute, followed by a burst of event 4769 entries with RC4 encryption for service accounts, together demonstrate both steps. Failed logons or policy changes do not evidence ticket acquisition, and share access belongs to a different attack phase.

Exam trap

The trap here is pairing any credential-related anomaly, such as failed logons, with ticket activity, when Kerberoasting requires no password guessing and produces successful ticket requests instead.

40
MCQmedium

A SOC analyst reviews a firewall log with the following entry: action=deny, source IP=192.168.1.100, destination IP=10.0.0.1, destination port=22. The analyst knows that 10.0.0.1 is an SSH server. What does this log entry indicate?

A.A DNS query resolved to 10.0.0.1
B.An attempted SSH connection that was blocked by the firewall
C.A successful SSH connection from 192.168.1.100 to 10.0.0.1
D.A misconfigured firewall allowing SSH traffic
AnswerB

The deny action combined with destination port 22 shows a connection attempt to the SSH service that the firewall rejected. The source host never established a session, so the entry records blocked traffic rather than a successful login.

Why this answer

The log entry shows 'action=deny', which explicitly indicates the firewall blocked the packet. Since destination port 22 is the default port for SSH, this log entry represents an attempted SSH connection from 192.168.1.100 to 10.0.0.1 that was denied by the firewall. The analyst's knowledge that 10.0.0.1 is an SSH server confirms the nature of the traffic.

Exam trap

Cisco often tests the ability to read a firewall log entry literally—candidates may overlook the 'action=deny' field and incorrectly assume any connection attempt to port 22 is automatically successful or that the firewall is misconfigured.

How to eliminate wrong answers

Option A is wrong because DNS queries use UDP or TCP port 53, not TCP port 22, and the log shows a destination port of 22, which is SSH, not DNS. Option C is wrong because the 'action=deny' field means the connection was blocked, not successful; a successful connection would show 'action=allow' or 'action=permit'. Option D is wrong because the firewall is correctly enforcing a deny rule for SSH traffic to 10.0.0.1, which is the opposite of a misconfiguration allowing SSH traffic.

41
MCQmedium

A SOC analyst is reviewing NetFlow records exported from a border router and notices a single internal host initiating outbound connections to more than 300 distinct external IP addresses on TCP port 443 within a five-minute window, with each flow carrying only a few hundred bytes. Which security monitoring conclusion is best supported by this evidence?

A.The host is likely exfiltrating a large database to a single external cloud storage provider.
B.The host is likely the victim of a reflected DNS amplification attack.
C.The host is likely performing a port scan or host sweep against external targets.
D.The host is likely performing beaconing to a command-and-control server over HTTPS.
AnswerC

Hundreds of distinct destination addresses contacted in a very short window, each with minimal data transferred, is the classic NetFlow signature of a host sweep. Because the flows target port 443, the sweep is aimed at discovering reachable HTTPS services. NetFlow's IP, port, and byte-count fields are sufficient to identify this fan-out behavior without full packet capture.

Why this answer

NetFlow captures metadata rather than payloads, but the metadata here is decisive: one internal host opening connections to hundreds of distinct external addresses on the same port with uniformly tiny byte counts is a host sweep. Beaconing would target few destinations; exfiltration would move large volumes to one destination; amplification would be inbound UDP. The fan-out pattern uniquely supports scanning activity.

Exam trap

The trap here is assuming that any burst of outbound HTTPS traffic is command-and-control beaconing, when the distinguishing factor is the number of distinct destinations and the near-constant small flow size, not the port used.

42
MCQeasy

Which protocol is used by SNMP to send traps from network devices to the management station?

A.TCP port 162
B.TCP port 161
C.UDP port 162
D.UDP port 161
AnswerC

SNMP traps are unsolicited notifications sent from agents to the manager, and they travel over UDP port 162. The manager listens on 162, while queries use UDP 161. This connectionless transport suits one-way alert delivery without acknowledgement overhead.

Why this answer

SNMP traps are sent from agents to managers using UDP port 162. SNMP uses UDP, not TCP.

43
MCQmedium

While analyzing a packet capture in Wireshark, an analyst observes a series of TCP packets with the PSH, ACK flags set and a payload containing the string 'cmd.exe /c whoami'. The destination port is 4444. Which type of activity is most likely indicated?

A.A DNS tunneling session exfiltrating data
B.A web server serving content on a non-standard port
C.A legitimate remote administration session using SSH
D.A reverse shell established by malware
AnswerD

Port 4444 is commonly used by Metasploit and other penetration testing or malware tools for reverse shells. The command 'cmd.exe /c whoami' is a typical reconnaissance command executed through a shell. The combination of a non-standard high port and command execution strongly suggests a reverse shell, where the compromised host connects back to the attacker's listener.

Why this answer

The packet capture shows TCP traffic to port 4444 with a payload containing a Windows command. This is a classic indicator of a reverse shell, where malware on a compromised host connects back to an attacker-controlled listener. SSH would be encrypted and on port 22, web traffic would be HTTP on standard ports, and DNS tunneling would use port 53.

The correct answer is the reverse shell.

Exam trap

The trap here is overlooking the non-standard port and cleartext command, assuming it might be legitimate remote administration, when reverse shells often use high ports like 4444.

44
MCQhard

During incident response, an analyst notices that a compromised host is making outbound SMB connections to several internal servers on TCP port 445 using the same domain user account within minutes. Which activity is most likely occurring?

A.Normal user access to multiple file shares
B.Lateral movement using stolen credentials
C.A backup application scanning file shares
D.A vulnerability scanner enumerating SMB services
AnswerB

Outbound SMB connections to multiple internal servers on port 445 using a single domain account within a short window strongly suggest lateral movement. Attackers who have compromised one host often use stolen credentials to access file shares or administrative shares on other systems, spreading malware or establishing additional footholds. This pattern is a classic indicator that should trigger immediate containment and credential reset.

Why this answer

Rapid outbound SMB connections to multiple internal servers using the same domain account indicate lateral movement with stolen credentials. Attackers use tools like PsExec or built-in SMB to pivot across the network, access shares, and deploy payloads. This behavior should be treated as a high-severity incident, triggering isolation of the source host and a review of the compromised account's activity.

Exam trap

The trap here is dismissing the SMB fan-out as routine file share access, when the speed and account reuse point to credential-based lateral movement.

45
MCQmedium

An analyst finds a YARA rule that matches a file containing the string 'MZ' at offset 0 and includes 'CreateRemoteThread'. This rule likely identifies:

A.A benign PDF
B.A network packet capture
C.A malicious executable
D.A Linux ELF binary
AnswerC

The 'MZ' signature at offset 0 confirms a Windows PE executable, while 'CreateRemoteThread' indicates process injection capability. Together these satisfy the stem's detection criteria for a malicious executable, since legitimate binaries rarely combine a valid PE header with remote thread creation for code injection.

Why this answer

The YARA rule matches a file starting with the 'MZ' magic bytes at offset 0 and containing the string 'CreateRemoteThread', which together identify a Windows Portable Executable (PE) that performs process injection. 'MZ' is the DOS header signature of every Windows executable, and CreateRemoteThread is a Windows API commonly used for DLL injection and process hollowing. This combination strongly indicates a malicious executable.

Exam trap

The trap is that 'MZ' and 'CreateRemoteThread' are individually generic — candidates may overthink and pick a benign file type, but the exam expects recognition that MZ + Windows injection API = malicious Windows PE, not a document or Linux binary.

How to eliminate wrong answers

Option A is wrong because PDF files begin with '%PDF-' magic bytes, not 'MZ', and do not contain Windows API names like CreateRemoteThread. Option B is wrong because a packet capture (pcap) has no 'MZ' header and is a binary stream of network frames, not an executable image. Option D is wrong because Linux ELF binaries begin with the magic bytes 0x7F 0x45 0x4C 0x46 ('\x7fELF'), not 'MZ', and CreateRemoteThread is a Windows-only API not present in ELF binaries.

46
MCQeasy

Which OSI layer is responsible for logical addressing and routing?

A.Application layer
B.Data link layer
C.Network layer
D.Transport layer
AnswerC

The Network layer (layer 3) handles logical addressing through IP addresses and determines path selection via routing protocols, forwarding packets between networks. Layers 2 and 4 handle physical addressing and transport respectively, so neither performs routing.

Why this answer

The Network layer (Layer 3) is responsible for logical addressing (e.g., IPv4/IPv6 addresses) and routing decisions that determine the best path for data packets across interconnected networks. Protocols such as OSPF, BGP, and ICMP operate at this layer to manage routing tables and forward packets between different subnets or autonomous systems.

Exam trap

Cisco often tests the distinction between Layer 2 (Data link) and Layer 3 (Network) by having candidates confuse MAC addressing (physical) with IP addressing (logical), leading them to incorrectly select the Data link layer for routing functions.

How to eliminate wrong answers

Option A is wrong because the Application layer (Layer 7) provides network services to end-user applications (e.g., HTTP, FTP, SMTP) and does not handle logical addressing or routing. Option B is wrong because the Data link layer (Layer 2) is responsible for physical addressing (MAC addresses) and frame delivery on the same local network segment, not for logical addressing or routing across networks. Option D is wrong because the Transport layer (Layer 4) manages end-to-end communication, segmentation, and flow control (e.g., TCP/UDP port numbers), but does not perform logical addressing or routing.

47
Multi-Selecteasy

Which TWO of the following are functions of a SIEM system in security monitoring?

Select 2 answers
A.Packet capture and analysis
B.Correlation rule engine
C.Firewall rule management
D.Log aggregation and normalization
E.Vulnerability scanning
AnswersB, D

A correlation rule engine ingests and normalises logs from disparate sources, then matches event patterns across them to surface multi-stage attacks that isolated alerts would miss. This directly satisfies the stem's requirement for a security monitoring function, since correlation is a core SIEM capability rather than an endpoint or network control.

Why this answer

A SIEM (Security Information and Event Management) system is built around collecting and consolidating log and event data from many sources, so option D, log aggregation and normalization, is correct: the SIEM ingests logs via agents, syslog, or APIs and parses them into a common schema so disparate formats can be searched and analyzed together. Option B, correlation rule engine, is also correct because the SIEM applies correlation rules and logic (e.g., matching multiple events across sources within a time window) to detect patterns, generate alerts, and support incident detection beyond what individual devices report. The other options do not belong: packet capture and analysis (A) is the role of tools such as Wireshark, tcpdump, or NDR/IDS sensors, not the core SIEM function; firewall rule management (C) is performed on firewalls or via firewall management platforms; and vulnerability scanning (E) is done by dedicated scanners like Nessus, Qualys, or OpenVAS, which may feed findings into a SIEM but are not SIEM functions themselves.

48
Multi-Selectmedium

A security analyst is investigating a potential security incident and needs to correlate events across multiple data sources. Which two Cisco CyberOps tools or features would provide network flow data and intrusion event details respectively? (Choose two.)

Select 2 answers
A.Cisco Stealthwatch for network flow analysis
B.Cisco Firepower Management Center for intrusion event details
C.Cisco Identity Services Engine for authentication logs
D.Cisco Umbrella for DNS security
E.Cisco Advanced Malware Protection for endpoint
AnswersA, B

Cisco Stealthwatch collects NetFlow and other flow data to provide network visibility and detect anomalies. It is designed for network flow analysis, helping analysts identify unusual traffic patterns and potential threats. In this scenario, it would supply the network flow data needed to understand communication patterns.

Why this answer

Cisco Stealthwatch is purpose-built for network flow analysis using NetFlow and other telemetry, while Firepower Management Center is the central console for intrusion events from Firepower sensors. Together, they provide the flow and intrusion data needed to correlate a security incident. The other tools focus on DNS, identity, or endpoint, which are not the requested data types.

Exam trap

The trap here is confusing Cisco Umbrella's DNS logs with network flow data, or assuming ISE provides intrusion events, when each tool has a specific telemetry focus.

49
MCQmedium

A SIEM correlation rule triggers when it detects more than 10 failed login attempts from the same source IP within 1 minute. Which type of attack is this rule designed to detect?

A.Port scan
B.DDoS attack
C.Privilege escalation
D.Brute-force attack
AnswerD

Repeated authentication failures from one source within a short window indicate systematic credential guessing, the defining signature of brute-force attacks. The rule's threshold and time constraint detect this volume-based pattern, distinguishing it from single failed logins or distributed password spraying across many accounts.

Why this answer

A brute-force attack involves repeated login attempts using many password guesses against a single account or a set of accounts. The SIEM rule correlates more than 10 failed login attempts from the same source IP within 1 minute, which is a classic signature of an automated password-guessing tool. This threshold-based detection is specifically designed to identify brute-force activity, not other attack types.

Exam trap

Cisco often tests the distinction between a brute-force attack (repeated login attempts) and a DDoS attack (traffic volume), so candidates may confuse the two because both involve high rates of activity from a single source.

How to eliminate wrong answers

Option A is wrong because a port scan typically sends connection requests (SYN packets) to multiple ports on a target, not repeated login attempts; it would be detected by a rule counting connections to different ports, not failed logins. Option B is wrong because a DDoS attack aims to overwhelm a target with traffic volume, not to authenticate; it would be detected by a rule monitoring bandwidth or packet rates, not failed login attempts. Option C is wrong because privilege escalation involves an attacker gaining higher-level access after initial compromise, often using a single exploit or token manipulation, not repeated failed logins; it would be detected by rules monitoring changes in user permissions or unusual process execution.

50
MCQmedium

A SIEM correlation rule is configured to alert when there are 10 failed login attempts from the same source IP within 1 minute. An analyst receives an alert for source IP 10.0.0.5. Which type of attack is most likely being detected?

A.Brute force attack
B.Man-in-the-middle attack
C.DDoS attack
D.SQL injection attempt
AnswerA

Ten failed authentications from one source within a minute indicates repeated credential guessing against an account, the defining pattern of brute force. The rule's threshold and one-minute window directly capture that volume-based signature, distinguishing it from a single failed attempt or a slow, low-rate password spray.

Why this answer

A brute force attack involves repeatedly attempting to guess login credentials, often from a single source IP, which matches the pattern of 10 failed login attempts within 1 minute. This is a classic indicator of a brute force attack, where an attacker tries multiple username/password combinations rapidly.

Exam trap

200-201 often tests the ability to distinguish between different attack types based on log patterns; the trap is that candidates may confuse brute force with other attacks like DDoS, which also involve multiple attempts but from many sources.

How to eliminate wrong answers

Option B is wrong because a man-in-the-middle attack involves intercepting communications between two parties, not generating multiple failed login attempts from a single IP. Option C is wrong because a DDoS attack aims to overwhelm a service with traffic from many sources, not a series of failed logins from one IP. Option D is wrong because a SQL injection attempt involves injecting malicious SQL code into input fields, which would not typically manifest as multiple failed login attempts from the same IP.

51
Multi-Selecthard

An analyst is using Zeek to monitor network traffic. Which THREE types of logs can Zeek generate to provide visibility into application-layer activity?

Select 3 answers
A.conn.log
B.smtp.log
C.weird.log
D.dns.log
E.http.log
AnswersB, D, E

Zeek's SMTP analyser parses email transactions at the application layer, producing smtp.log with fields such as sender, recipient, subject and helo, satisfying the requirement for application-layer visibility. It captures protocol-level mail activity rather than transport metadata, so it directly evidences application-layer behaviour in the monitored traffic.

Why this answer

Zeek generates smtp.log (B) to record SMTP transactions, including sender/recipient envelopes, subjects, and mail server responses, giving application-layer visibility into email traffic. dns.log (D) captures DNS queries and responses at the application layer, logging query names, record types, and answers. http.log (E) records HTTP requests and replies, including methods, URIs, host headers, user agents, and status codes, which is classic application-layer visibility. conn.log (A) is a transport/network-layer connection summary (IPs, ports, protocol, bytes, duration) and does not describe application-layer activity, while weird.log (C) logs protocol anomalies and unexpected behavior rather than normal application-layer transactions.

Exam trap

Cisco often tests the distinction between network-layer logs (conn.log) and application-layer logs (http.log, dns.log, smtp.log), and candidates may incorrectly assume conn.log covers application-layer activity because it includes port numbers.

52
MCQhard

A SOC receives a threat intelligence feed indicating that a specific SHA-256 hash belongs to a trojan. An analyst searches the endpoint telemetry and finds no process with that hash, but the file name appears in several temporary directories. Which explanation best accounts for this result?

A.The malware mutates or is repacked on each execution, so the file content and therefore the hash differ while the name persists.
B.The endpoint agent is not collecting file metadata, so hash matching cannot be performed.
C.The endpoint is using a different hash algorithm, so SHA-256 values cannot be compared.
D.The threat feed is stale and the hash was retired by the vendor before the analyst searched.
AnswerA

Polymorphic and repacked malware changes its bytes between builds or executions, producing a new SHA-256 each time while often retaining a familiar file name. The intelligence feed's hash identifies one specific sample, so the absence of that hash does not mean the malware is absent. This explains why name-based sightings persist without a hash match and why behavioural detection matters.

Why this answer

A SHA-256 value identifies exact file content, so the same malware name appearing with different bytes yields different hashes. Repacking, encryption, or packing layers can change content on every campaign or execution. The analyst should pivot from static hash matching to behavioural and name-based hunting, then capture a live sample to confirm the current variant.

Exam trap

The trap here is treating a threat intelligence hash as a permanent name-based signature, when a hash identifies one exact binary and stops matching the moment the file content changes.

53
MCQmedium

A network security analyst is reviewing traffic logs and notices a series of connections from an internal host to a known command-and-control (C2) server. The connections occur every 5 minutes and are small in size. Which of the following is the MOST likely explanation for this traffic pattern?

A.The host is synchronizing time with an NTP server.
B.The host is running a legitimate software update service that checks for updates every 5 minutes.
C.The host is part of a botnet and is being used to scan other hosts.
D.The host is infected with malware that is beaconing to its C2 server.
AnswerD

Regular, periodic connections to a known C2 server are characteristic of malware beaconing. The interval and small data size suggest the malware is checking in for instructions. This is a common detection for command-and-control activity. The analyst should investigate the host for compromise and block the C2 communication.

Why this answer

Periodic connections to a known C2 server are a strong indicator of malware beaconing. Malware often uses beaconing to maintain communication with its controller, receiving commands and exfiltrating data. The regular interval and small payload size are typical to avoid detection.

Other options describe benign or different malicious activities that do not match the scenario, especially the destination being a known C2 server.

Exam trap

The trap here is dismissing the periodic nature as benign (like updates or NTP) without considering the destination reputation and the context of a known C2 server.

54
Multi-Selectmedium

A security analyst is tuning a SIEM to detect lateral movement. Which THREE log sources would provide the most useful data for this purpose? (Choose THREE.)

Select 3 answers
A.Windows Event Logs showing network connections and process creation.
B.Web server logs for external requests.
C.DNS logs for external domain queries.
D.System logs showing authentication events across hosts.
E.Firewall logs showing connections between internal hosts.
AnswersA, D, E

Windows Event Logs capture process creation (Sysmon Event ID 1) and network connection events (Event ID 3), exposing the parent-child process chains and outbound connections lateral movement tools generate. This directly satisfies the SIEM tuning requirement by supplying host-level telemetry that reveals anomalous execution and remote connection patterns across endpoints.

Why this answer

Option A is correct because Windows Event Logs such as Security Event ID 4688 (process creation) and Sysmon Event ID 3 (network connection) reveal suspicious process-to-network relationships that are hallmarks of lateral movement tools like PsExec or Cobalt Strike. Option D is correct because system logs capturing authentication events (e.g., Windows 4624/4625, Linux sshd and sudo entries) across multiple hosts expose pass-the-hash, credential reuse, and remote logon patterns central to lateral movement. Option E is correct because firewall logs showing internal-to-internal connections (east-west traffic) highlight anomalous host-to-host communication that would otherwise be invisible at the perimeter.

Option B is not appropriate because web server logs for external requests focus on inbound client activity against a service, not host-to-host movement inside the network. Option C is not appropriate because DNS logs for external domain queries are more useful for command-and-control and exfiltration detection than for identifying lateral movement between internal hosts.

55
MCQeasy

An analyst is monitoring network traffic and sees a large number of TCP SYN packets sent to various ports on a single host from the same source IP. Which type of attack is most likely occurring?

A.DNS amplification
B.ARP poisoning
C.Port scan
D.SYN flood
AnswerC

A port scan sends TCP SYN packets to many ports on one host to map which services are listening. Half-open scans exploit the SYN/ACK or RST response to classify each port as open, closed or filtered, matching the stem's single source IP and multiple destination ports.

Why this answer

A port scan involves an attacker sending TCP SYN packets to multiple ports on a target host to determine which ports are open and listening. The key indicator is the single source IP targeting various ports on a single host, which matches the behavior of a SYN scan (half-open scan) used to map services without completing the full TCP three-way handshake.

Exam trap

Cisco often tests the distinction between a port scan (reconnaissance, multiple ports) and a SYN flood (DoS, single port with high volume), so the trap here is confusing the reconnaissance technique of scanning many ports with the denial-of-service technique of overwhelming a single service.

How to eliminate wrong answers

Option A is wrong because DNS amplification uses spoofed source IPs to send small queries to open DNS resolvers, which then send large responses to the victim, not TCP SYN packets to various ports on a single host. Option B is wrong because ARP poisoning involves sending forged ARP replies to associate the attacker's MAC address with the IP of a legitimate host on a local network, not sending TCP SYN packets to multiple ports. Option D is wrong because a SYN flood targets a single port (or a few ports) with a high volume of SYN packets to exhaust the target's connection queue, not a large number of SYN packets sent to various ports as part of reconnaissance.

56
Multi-Selectmedium

A security analyst is correlating network and endpoint telemetry to detect a host infected with malware that is attempting to establish persistence and communicate externally. Which TWO artifacts would best support this investigation? (Choose two.)

Select 2 answers
A.Sysmon Event ID 13 registry value set events for Run key modifications
B.NetFlow records showing periodic outbound connections to an external IP
C.DHCP server logs showing IP address leases for the subnet
D.Antivirus scan reports from the previous quarter
E.Windows Event ID 4688 process creation events for every process on all hosts
AnswersA, B

Sysmon Event ID 13 records registry value set operations, including changes to Run keys, which are a common persistence mechanism. By capturing the process that wrote the value and the exact registry path, analysts can identify which executable will launch at logon. This directly supports the persistence portion of the investigation and links the registry change to a specific process on the infected host.

Why this answer

To confirm both persistence and external communication, the analyst needs an endpoint artifact that shows the persistence mechanism and a network artifact that shows beaconing. Sysmon registry value set events reveal Run key modifications used for persistence, while NetFlow records expose periodic outbound connections to an external IP. Together they link the infected host's persistence to its command-and-control channel.

Exam trap

The trap here is choosing high-volume sources like all process creation events instead of the targeted registry and flow artifacts that directly evidence persistence and beaconing.

57
MCQmedium

A SIEM correlation rule is designed to detect a brute-force attack. The rule triggers when an event includes 10 or more failed logins from the same source IP within 1 minute. An analyst sees an alert for 12 failed logins from IP 10.0.0.1 in 2 minutes. Why did the rule not trigger?

A.The source IP is not in the watch list
B.The time window is too short; the rule requires 10 failures in 1 minute, but this occurred over 2 minutes
C.The rule only counts successful logins
D.The alert severity is too low
AnswerB

The rule's threshold is bound to a one-minute sliding window, so twelve failures spread across two minutes never accumulate ten events inside any single window. The correlation engine evaluates count per interval, not cumulative totals, so the two-minute duration itself prevents the threshold from being met.

Why this answer

The rule requires 10+ failures in 1 minute. In 2 minutes, the rate is 6 per minute, which is below threshold.

58
MCQmedium

A network analyst notices that a host is sending a large volume of traffic to an external IP address on port 443 during non-business hours. The traffic volume is significantly higher than the established baseline. Which type of data exfiltration technique should be suspected?

A.HTTP post
B.HTTPS exfiltration
C.ICMP tunneling
D.DNS tunneling
AnswerB

Sustained high-volume traffic to an external address on port 443 outside business hours indicates data being tunnelled inside encrypted HTTPS sessions, evading content inspection. The volume and timing deviation from baseline satisfy the scenario's exfiltration indicators.

Why this answer

Port 443 is the default port for HTTPS (HTTP over TLS). The large volume of traffic during non-business hours, exceeding the baseline, strongly suggests the attacker is using encrypted HTTPS connections to hide data exfiltration. Unlike plaintext HTTP, HTTPS encryption makes it difficult for network monitoring tools to inspect the payload, allowing the attacker to blend malicious traffic with legitimate encrypted web traffic.

Exam trap

Cisco often tests the association of common protocols with their default ports; the trap here is that candidates might see 'large volume of traffic' and immediately think of HTTP post (option A) without noticing the port number 443, which clearly indicates encrypted HTTPS traffic.

How to eliminate wrong answers

Option A is wrong because HTTP post uses port 80, not port 443, and while it could be used for data exfiltration, the question specifies port 443 which is HTTPS. Option C is wrong because ICMP tunneling uses ICMP echo request/reply packets (typically on the network layer) and does not use TCP port 443; it would also likely show unusual ICMP traffic patterns, not high-volume TCP traffic on port 443. Option D is wrong because DNS tunneling uses UDP port 53 (or TCP port 53 for large queries) to encode data in DNS queries and responses, not TCP port 443.

59
MCQhard

An analyst is examining a YARA rule that contains the condition: 'uint16(0) == 0x5a4d and filesize < 500KB'. What type of file is this rule targeting?

A.Windows executable files
B.PDF files
C.JPEG images
D.Linux ELF files
AnswerA

The uint16(0) == 0x5a4d check reads the MZ magic bytes at offset zero, the DOS header signature unique to Windows PE executables. The filesize constraint simply limits scanning to smaller binaries, confirming the rule targets Windows executable files.

Why this answer

The condition 'uint16(0) == 0x5a4d' checks the first two bytes of a file for the hexadecimal value 0x5a4d, which corresponds to the ASCII characters 'MZ'. This 'MZ' signature is the magic number for DOS/Windows executable files (e.g., .exe, .dll). The additional constraint 'filesize < 500KB' further narrows the rule to small Windows executables.

Therefore, the rule targets Windows executable files.

Exam trap

The trap here is confusing common file magic numbers; candidates might mistakenly associate 'MZ' with other file types or overlook that uint16(0) reads the first two bytes as a little-endian value, leading to incorrect identification of the file type.

How to eliminate wrong answers

Option B is wrong because PDF files begin with the magic number '%PDF' (0x25 0x50 0x44 0x46), not 'MZ'. Option C is wrong because JPEG images start with the magic number 0xFFD8 (0xFF 0xD8), not 'MZ'. Option D is wrong because Linux ELF files begin with the magic number 0x7F454C46 (0x7F 'E' 'L' 'F'), not 'MZ'.

60
MCQhard

During a security assessment, a SOC analyst notices an IDS/IPS alert with a severity of 'High' for a signature named 'ET TROJAN Win32.Vobfus Checkin'. The alert shows source IP 10.0.0.5 and destination IP 203.0.113.50 on port 443. What is the most likely interpretation of this alert?

A.A compromised host attempting to communicate with a command-and-control server over encrypted traffic
B.A false positive due to a web browser accessing a secure site
C.An attacker scanning for open HTTPS ports on the internal network
D.A benign HTTPS connection to a legitimate website
AnswerA

The ET TROJAN signature name indicates known malware, and port 443 traffic to an external address represents beaconing over TLS to evade inspection. Source 10.0.0.5 is therefore a compromised internal host checking in with command-and-control infrastructure, matching the alert's encrypted-channel characteristics.

Why this answer

The signature 'ET TROJAN Win32.Vobfus Checkin' is a known detection rule for the Vobfus trojan family, which typically establishes command-and-control (C2) communications over HTTPS (port 443) to exfiltrate data or receive instructions. The high severity indicates the IDS/IPS has matched traffic patterns or JA3 hashes associated with this malware's C2 beaconing, making it highly likely that the host at 10.0.0.5 is compromised and communicating with a malicious server at 203.0.113.50.

Exam trap

Cisco often tests the distinction between generic HTTPS traffic and signature-specific malware detection, trapping candidates who assume all encrypted traffic is benign or that high-severity alerts are automatically false positives.

How to eliminate wrong answers

Option B is wrong because a false positive from a web browser accessing a secure site would not match a specific trojan signature like 'ET TROJAN Win32.Vobfus Checkin'—that signature is tuned to detect malware-specific behaviors, not generic HTTPS traffic. Option C is wrong because an attacker scanning for open HTTPS ports would generate a different signature (e.g., port scan or brute-force attempt), not a trojan checkin signature that implies established C2 communication. Option D is wrong because a benign HTTPS connection to a legitimate website would not trigger a high-severity trojan signature; the IDS/IPS would only alert on such a signature if the traffic matches known malicious patterns (e.g., specific SNI, certificate fingerprints, or JA3 hashes) associated with Vobfus.

61
MCQmedium

A security analyst is reviewing a packet capture in Wireshark and notices a series of DNS queries for randomly generated domain names such as 'a1b2c3d4e5.com', 'f6g7h8i9j0.net', and 'k1l2m3n4o5.org'. The queries are sent to multiple different DNS servers. Which type of malicious activity does this pattern most likely indicate?

A.DNS tunneling for data exfiltration.
B.Domain Generation Algorithm (DGA) used by malware for C2.
C.Fast flux DNS technique.
D.DNS cache poisoning attack.
AnswerB

DGAs are used by malware to generate a large number of pseudo-random domain names that it can query to find its command and control server. The pattern of many random-looking domains, often with different top-level domains, and queries to various DNS servers, is a classic indicator of DGA activity. This allows the malware to evade domain blacklisting. The analyst should correlate with endpoint logs to identify the infected host.

Why this answer

The pattern of numerous DNS queries for random-looking domain names across different TLDs is characteristic of a Domain Generation Algorithm (DGA). Malware uses DGAs to generate many potential C2 domains, making it difficult for defenders to block them all. The analyst should investigate the host making these queries for signs of infection.

Other options like DNS tunneling, cache poisoning, or fast flux do not match the observed pattern of multiple random domains.

Exam trap

The trap here is confusing DGA with DNS tunneling; DGA generates many random domains, while tunneling encodes data within queries to a single domain.

62
MCQmedium

A network security analyst is reviewing NetFlow records from a Cisco router and notices a large number of flows from a single internal host to many external IP addresses on port 445. The flows are short, with small packet counts, and occur within a few minutes. Which type of activity is most likely occurring?

A.A peer-to-peer file sharing client
B.A worm or scanner attempting to propagate via SMB
C.A legitimate backup process to a cloud storage provider
D.A misconfigured application performing a port scan
AnswerB

Port 445 is used by SMB. A single host connecting to many external IPs on that port in a short time with short flows is characteristic of a worm or scanner trying to find vulnerable SMB services. This pattern is typical of exploits like WannaCry or NotPetya, which scan and propagate. The high fan-out and small packet counts indicate scanning, not normal file sharing.

Why this answer

The combination of a single internal host, many external destinations, port 445, and short flows over a brief period is a hallmark of SMB scanning or worm propagation. This behavior aims to find and infect vulnerable systems. Analysts should isolate the host and investigate for malware, as this fan-out pattern is not normal for legitimate SMB usage.

Exam trap

The trap here is assuming port 445 traffic is always internal file sharing, but external fan-out on that port is a strong indicator of scanning or worm activity.

63
MCQmedium

A Cisco Firepower analyst notices repeated syslog messages from an ASA firewall showing TCP connections to 203.0.113.55:4444 that are reset immediately after the three-way handshake. The source hosts are internal workstations running an outdated browser plugin. Which security monitoring data source would best confirm whether these workstations established a command-and-control channel?

A.Full packet capture from the internal segment, analyzed in Wireshark
B.NetFlow records exported from the ASA to a collector
C.Endpoint process and network connection telemetry from the workstations
D.Proxy web logs recording HTTP CONNECT requests and user agents
AnswerC

Endpoint telemetry correlates process creation, loaded modules, and outbound socket events, so it can tie the browser plugin process to the connection attempts to 203.0.113.55:4444. That directly confirms whether a C2 channel was established by the vulnerable plugin, which network-only sources cannot do. It also captures the reset timing, showing failed versus successful C2 sessions.

Why this answer

Confirming a command-and-control channel requires linking network activity to the responsible process on the host. Endpoint process and socket telemetry provides that link, showing the vulnerable browser plugin initiating connections to the external address. Flow, packet capture, and proxy logs can corroborate network behavior, but they lack process attribution and, for encrypted or direct traffic, may not reveal enough to confirm C2.

Exam trap

The trap here is assuming that flow records or packet captures alone can prove which local process established a command-and-control channel.

64
Multi-Selecthard

A Cisco CyberOps analyst is reviewing a network security monitoring console and must determine which TWO data sources are most useful for detecting lateral movement by an attacker who has already compromised a workstation. (Choose two.)

Select 2 answers
A.Windows Security event logs collected through Cisco SecureX
B.Email gateway logs from Cisco Email Security Appliance
C.Web proxy logs from Cisco Web Security Appliance
D.NetFlow records from Cisco Stealthwatch
E.DNS query logs from Cisco Umbrella
AnswersA, D

Windows Security event logs record authentication events such as logon type 3 network logons, explicit credential use, and privileged logon activity. When an attacker moves laterally using stolen credentials or remote execution tools, these logs capture the source workstation, target host, account, and logon type. Correlating these events across endpoints reveals the path of movement. SecureX or a SIEM can aggregate these logs, making them one of the most direct sources for detecting lateral movement in a Windows environment.

Why this answer

Lateral movement is characterized by internal authentication attempts and internal connection fan-out. Windows Security event logs capture logon types and account usage across hosts, while NetFlow from Stealthwatch exposes the internal connection patterns to administrative ports and multiple targets. Together they correlate identity and network behavior to trace an attacker's path.

External-focused sources such as DNS, email, and web proxy logs are less relevant once the attacker is moving inside the environment.

Exam trap

The trap here is choosing external telemetry such as DNS or web proxy logs, which detect command-and-control or initial infection, instead of the internal authentication and flow data that reveal lateral movement.

65
MCQeasy

Which of the following is an example of an Indicator of Compromise (IoC)?

A.A file hash (SHA-256)
B.A SIEM dashboard
C.A firewall rule
D.A network baseline
AnswerA

A SHA-256 file hash is a concrete, artefact-based IoC: it uniquely identifies known-malicious files, letting analysts search endpoints and logs for that exact value. Unlike behavioural heuristics, the hash is a static forensic indicator satisfying the stem's requirement for an IoC example.

Why this answer

An Indicator of Compromise (IoC) is a piece of forensic data that identifies potentially malicious activity on a system or network. A file hash (SHA-256) is a classic IoC because it provides a unique cryptographic fingerprint of a known malicious file, allowing security tools to detect its presence across endpoints. This is a specific, actionable artifact that directly points to a compromise.

Exam trap

Cisco often tests the distinction between an IoC (a specific artifact like a hash, IP, or domain) and a security tool or process (like a SIEM, firewall rule, or baseline), so candidates mistakenly classify operational components as IoCs.

How to eliminate wrong answers

Option B is wrong because a SIEM dashboard is a visualization tool that aggregates and displays security events, not a specific artifact of compromise. Option C is wrong because a firewall rule is a policy definition for permitting or denying traffic, not an evidence of a past or ongoing intrusion. Option D is wrong because a network baseline is a reference of normal traffic patterns used for anomaly detection, not a direct indicator of a specific malicious event.

66
MCQmedium

A network security analyst reviews a packet capture from a compromised host and sees repeated outbound DNS queries for long, random-looking subdomains such as 'a3f9c2b81e7d4.example-cdn.net', each followed by a small response and no subsequent connection to the returned address. Which interpretation is most accurate?

A.This is normal content delivery network behavior, because CDNs use random subdomains to distribute requests across edge servers.
B.This is DNS tunneling or exfiltration, because encoded data is carried in query names and the returned addresses are never contacted.
C.This is DNS cache poisoning, because the host is querying for records that do not exist and receiving forged responses.
D.This is a domain generation algorithm used for command-and-control, because the host resolves many random domains before receiving instructions.
AnswerB

Long, high-entropy subdomain labels sent repeatedly to one domain, with no follow-on connection to the answers, indicate data being encoded into DNS queries for covert transfer. Legitimate resolution produces a connection or cached result; here the query itself is the payload channel. This pattern lets an attacker move data out through recursive resolvers that most networks permit by default.

Why this answer

DNS tunneling encodes data inside query names so it can leave a network through permitted recursive resolution. High-entropy, variable-length subdomain labels under one parent domain, sent at volume with responses that are never used, match that behavior. A domain generation algorithm instead rotates across many registered domains, and normal CDN activity ends in a connection to the resolved address, so both alternatives conflict with the evidence shown.

Exam trap

The trap here is dismissing the traffic as CDN or DGA behavior because the names look random, when the decisive clues are a single parent domain and responses that are never contacted.

67
MCQmedium

A security analyst is examining web server logs and finds an entry with method 'POST', URL '/login.php', response code '200', and user-agent 'Mozilla/5.0'. The log shows 100 similar entries from the same IP within 5 seconds. What is the most likely activity?

A.A brute-force attack on the login form
B.A SQL injection attempt on the login page
C.A DDoS attack targeting the web server
D.A user repeatedly clicking the login button due to a slow connection
AnswerA

One hundred POST requests to the login endpoint from a single IP within five seconds indicates automated credential guessing against the authentication form. The rapid repetition and uniform user-agent reveal scripted abuse rather than human login behaviour, matching brute-force attack characteristics.

Why this answer

Repeated POST requests to /login.php from a single IP at a rate of 100 in 5 seconds (20 requests/second) with a generic browser user-agent is the classic signature of an automated brute-force attack against a login form. The 200 response code indicates the server processed the requests, consistent with credential guessing rather than a single exploit attempt. High request rate plus authentication endpoint equals brute force.

Exam trap

200-201 often tests whether candidates can distinguish brute force from SQLi and DDoS by volume and pattern; the trap is assuming any POST to login.php is SQL injection, when the high uniform request rate points to brute force.

How to eliminate wrong answers

Option B is wrong because a SQL injection attempt would typically show a small number of crafted requests with suspicious payloads (quotes, UNION, OR 1=1) in the URL or body, not 100 uniform POSTs to the same endpoint in 5 seconds. Option C is wrong because a DDoS attack aims to exhaust resources and would target many endpoints or flood with high volume, often resulting in 5xx/timeout responses rather than 200s on a login page. Option D is wrong because a human clicking a slow login button cannot generate 100 requests in 5 seconds, and the uniform user-agent and timing indicate automation.

68
Multi-Selecthard

An analyst suspects a host is communicating with a command-and-control server using DNS tunneling. Which THREE network traffic patterns would support this hypothesis?

Select 3 answers
A.Frequent use of TXT record type in DNS queries
B.DNS response sizes larger than typical A record responses
C.DNS queries with TTL values greater than 86400
D.DNS queries for multiple well-known domains
E.High volume of DNS queries from a single host to a single domain
AnswersA, B, E

DNS tunnelling exfiltrates data by encoding payloads into DNS queries and responses, and TXT records carry arbitrary text up to 255 characters per string, making them the preferred carrier. Frequent TXT queries to a single domain, especially with high entropy or long labels, satisfy the stem's command-and-control hypothesis.

Why this answer

Option A is correct because DNS tunneling often abuses TXT records, which can carry arbitrary text payloads, to exfiltrate data or receive commands from a C2 server. Option B is correct because tunneling responses frequently contain encoded data, making DNS responses larger than the typical small A-record response. Option E is correct because a single host generating a high volume of DNS queries to one domain is a classic beaconing/tunneling indicator.

Option C is not correct because high TTL values are not characteristic of DNS tunneling; tunneling often uses low or zero TTLs to avoid caching. Option D is not correct because queries to multiple well-known domains are common benign behavior and do not specifically indicate DNS tunneling.

Exam trap

200-201 often tests the ability to distinguish between normal DNS behavior and malicious patterns, where candidates might overlook the significance of TXT records and large response sizes in favor of less specific indicators like TTL values.

69
MCQhard

A security analyst is reviewing Snort IDS alerts and sees the following rule triggered: alert tcp $HOME_NET any -> $EXTERNAL_NET 80 (msg:'Possible SQL Injection'; content:'UNION'; nocase; sid:1000001;). Which action will Snort take when it detects matching traffic?

A.Generate an alert
B.Log the packet only
C.Drop the packet
D.Reject the connection
AnswerA

The rule header specifies alert as its action, so Snort logs the matching packet and generates an alert without dropping or blocking it. This satisfies the stem's requirement, since the rule detects the "UNION" string in outbound port 80 traffic but Snort's default alert action is passive monitoring, not prevention.

Why this answer

The rule uses the Snort 'alert' action, which instructs Snort to generate an alert when the traffic matches the specified conditions (TCP traffic from any port on the home network to port 80 on an external network, with the string 'UNION' present in the payload, case-insensitive). Snort's default behavior for an 'alert' action is to log the packet and generate an alert, but it does not drop or reject the traffic because Snort is an IDS (Intrusion Detection System) by default, not an IPS (Intrusion Prevention System).

Exam trap

Cisco often tests the distinction between Snort's 'alert' action (IDS behavior: alert and log) versus 'drop' or 'reject' actions (IPS behavior: block or reset), and candidates mistakenly assume any triggered rule will block traffic.

How to eliminate wrong answers

Option B is wrong because logging the packet only is the behavior of the 'log' action, not the 'alert' action; the 'alert' action generates an alert in addition to logging. Option C is wrong because dropping the packet requires an IPS mode or a 'drop' rule action (e.g., 'drop tcp ...'), and this rule uses 'alert', which does not drop traffic. Option D is wrong because rejecting the connection (sending a TCP RST) is done by the 'reject' action in Snort, not by the 'alert' action.

70
MCQeasy

An analyst is monitoring network traffic and observes a large number of TCP SYN packets sent to a single host on various ports with no corresponding SYN-ACK replies. This behavior is most indicative of which type of attack?

A.ARP spoofing
B.DNS amplification attack
C.ICMP flood attack
D.SYN flood attack
AnswerD

SYN packets to varied ports with no SYN-ACK replies indicate half-open connections exhausting the target's backlog queue. This matches a SYN flood, a volumetric denial-of-service attack that never completes the TCP handshake, distinguishing it from port scans that typically elicit RST responses.

Why this answer

A large volume of TCP SYN packets to a single host across various ports with no SYN-ACK replies is the classic signature of a SYN flood attack. The attacker sends many SYN packets (often with spoofed source IPs) to exhaust the target's half-open connection table, preventing legitimate connections from completing the TCP three-way handshake.

Exam trap

The trap is confusing SYN flood with other flood attacks — candidates must key on the specific TCP SYN-without-SYN-ACK pattern, which distinguishes it from ICMP floods (ping), DNS amplification (DNS traffic), and ARP spoofing (Layer 2 MAC manipulation).

How to eliminate wrong answers

Option A is wrong because ARP spoofing involves forging ARP replies to associate an attacker's MAC with a legitimate IP, enabling man-in-the-middle — it does not produce a flood of SYN packets. Option B is wrong because a DNS amplification attack sends spoofed DNS queries to open resolvers, which return large responses to the victim — the traffic pattern is DNS, not TCP SYN. Option C is wrong because an ICMP flood sends large volumes of ICMP echo requests (ping), not TCP SYN packets, and does not target TCP ports.

71
MCQmedium

A firewall log shows a connection from internal IP 192.168.1.100 to external IP 203.0.113.5 on port 443 with action 'deny'. What does this indicate?

A.The connection was successfully encrypted.
B.The firewall allowed the connection.
C.The external host attempted to access the internal host.
D.The internal host attempted to access a secure web server but was blocked.
AnswerD

Port 443 indicates HTTPS, so the internal host initiated a connection to a secure web server. The deny action confirms the firewall blocked it, matching the stem exactly. This is outbound filtering, not an inbound attack or a non-web protocol attempt.

Why this answer

The log shows a connection from internal IP 192.168.1.100 to external IP 203.0.113.5 on port 443, with the action 'deny'. Port 443 is the default port for HTTPS (HTTP over TLS), which is used for secure web server access. The 'deny' action indicates the firewall blocked this outbound connection, meaning the internal host attempted to reach a secure web server but was prevented by the firewall policy.

Exam trap

Cisco often tests the distinction between source and destination IPs in firewall logs, where candidates mistakenly assume the external IP is the initiator (Option C) because they focus on the 'deny' action rather than the direction of the connection.

How to eliminate wrong answers

Option A is wrong because the connection was denied, so no encryption handshake (TLS) could occur; a successful encryption would require the firewall to allow the connection first. Option B is wrong because the action 'deny' explicitly means the firewall blocked the connection, not allowed it. Option C is wrong because the source IP is internal (192.168.1.100) and the destination is external (203.0.113.5), indicating the internal host initiated the connection to the external host, not the reverse.

72
MCQmedium

A SOC analyst is reviewing Cisco Firepower Intrusion Event logs and notices a high volume of alerts for the signature 'SERVER-WEBAPP Apache Struts2 remote code execution attempt' coming from a single internal host to external web servers. The analyst needs to determine if this is a true positive or a false positive. Which of the following actions would BEST help make that determination?

A.Correlate the alert with NetFlow records to see if the internal host successfully established a connection and transferred data.
B.Check the reputation of the external web servers using Cisco Talos Intelligence.
C.Review the Snort rule that triggered the alert to understand its detection logic and potential for false positives.
D.Examine the full packet capture associated with the alert to verify if the exploit payload was actually sent and if a response indicating compromise was received.
AnswerD

Examining the full packet capture allows the analyst to see the actual payload and server response. If the payload matches known exploit patterns and the server responds with a shell or unusual behavior, it is a true positive. If the payload is benign or the server rejects it, it may be a false positive. This is the most direct method to validate the alert.

Why this answer

The most reliable way to determine if an intrusion alert is a true positive is to inspect the raw packets that triggered it. By analyzing the packet capture, the analyst can see the exact payload and the server's response, which provides definitive evidence of whether the exploit attempt was successful or benign. Correlating with other logs or checking reputations can provide supporting context but does not directly confirm the nature of the event.

Exam trap

The trap here is assuming that a high volume of alerts automatically indicates a true positive, or that checking the destination reputation is sufficient without examining the actual payload.

73
MCQmedium

An analyst receives an IDS alert with signature name 'ET TROJAN Win32.Zeus Checkin' and severity 'high'. The alert shows source IP 192.168.1.50 and destination IP 198.51.100.20 on port 443. Which action should the analyst take FIRST?

A.Isolate the source host from the network to prevent further communication.
B.Check the host's web browsing history for suspicious websites.
C.Immediately block the destination IP on the firewall.
D.Ignore the alert because the traffic is encrypted over port 443.
AnswerA

The signature indicates an active Zeus trojan check-in from internal host 192.168.1.50 to external infrastructure over port 443, confirming likely compromise and command-and-control beaconing. Isolating that host immediately halts exfiltration and lateral movement, the priority containment step before deeper forensic analysis.

Why this answer

The alert indicates a high-severity Zeus Trojan check-in, which is a known malware communicating with a command-and-control (C2) server. The first priority is to contain the threat by isolating the source host (192.168.1.50) to prevent further data exfiltration or lateral movement. Even though the traffic is encrypted over port 443 (HTTPS), the signature confirms malicious activity, so immediate isolation is the correct initial response per incident response best practices.

Exam trap

Cisco often tests the principle that containment (isolating the host) takes precedence over blocking external IPs or performing forensic analysis, and that encryption does not invalidate IDS alerts because signatures can detect malicious patterns in metadata or handshake characteristics.

How to eliminate wrong answers

Option B is wrong because checking web browsing history is a secondary forensic step that delays containment; the immediate priority is to stop active C2 communication. Option C is wrong because blocking the destination IP on the firewall may disrupt the C2 channel but does not prevent the compromised host from communicating with other C2 servers or spreading within the network; isolation of the host is more comprehensive. Option D is wrong because ignoring the alert due to encryption is a dangerous misconception—the IDS signature is based on behavioral or pattern analysis (e.g., JA3 fingerprint, packet timing) that can detect malware even over TLS; encryption does not make the alert invalid.

74
MCQhard

In a Zeek/Bro log, an analyst observes a connection with 'service' field set to 'dns' and 'query' field containing a long, random-looking subdomain. This could be indicative of which type of activity?

A.DNS tunneling for data exfiltration
B.DNS amplification attack
C.DNS cache poisoning
D.Normal DNS resolution for a legitimate service
AnswerA

DNS tunnelling encodes stolen data within subdomain labels of queries sent to an attacker-controlled authoritative nameserver. Zeek's `service` field identifying DNS, combined with an abnormally long, high-entropy subdomain, satisfies the exfiltration indicator: legitimate DNS labels are short and structured, whereas tunnelled payloads appear random to evade signature matching.

Why this answer

A long, random-looking subdomain in a DNS query is a classic indicator of DNS tunneling, where an attacker encodes exfiltrated data into DNS queries to bypass network security controls. Zeek/Bro logs showing a 'service' of 'dns' with such queries suggest the client is using the DNS protocol to covertly transmit data to an external authoritative server, which decodes and reassembles the payload.

Exam trap

Cisco often tests the distinction between DNS tunneling (exfiltration) and DNS amplification (DDoS), where candidates confuse the long query string of tunneling with the large response size of amplification, but the key is that amplification uses spoofed source IPs and small queries, not random subdomains.

How to eliminate wrong answers

Option B is wrong because a DNS amplification attack relies on sending small queries with a spoofed source IP to open resolvers, causing them to flood the victim with large responses; the 'query' field would typically be a fixed, short string (e.g., 'ANY isc.org'), not a long random subdomain. Option C is wrong because DNS cache poisoning involves corrupting a resolver's cache with forged DNS records, which does not manifest as a long random subdomain in the query itself; it would instead show unexpected IP addresses in the answer section. Option D is wrong because legitimate DNS queries for services like CDNs or load balancers may use long hostnames, but they follow a predictable pattern (e.g., 'cdn123.example.com') and are not random-looking; a truly random subdomain is a strong anomaly.

75
MCQmedium

An analyst is reviewing a web server log and sees the following entry: '192.168.1.1 - - [25/Oct/2023:10:15:30 -0400] "GET /admin/index.php?cmd=id HTTP/1.1" 200 1532 "-" "Mozilla/5.0"'. What potential attack does this log entry suggest?

A.Command injection
B.SQL injection
C.Directory traversal
D.Cross-site scripting (XSS)
AnswerA

The query string passes 'cmd=id' to a PHP script, indicating the attacker is attempting to execute the shell command 'id' via an unsanitised parameter. A 200 response suggests the command injection succeeded, satisfying the log evidence for this attack type.

Why this answer

The presence of 'cmd=id' in the URL suggests an attempt to execute the 'id' command via a web shell or command injection vulnerability. The response code 200 indicates success, which is concerning.

Page 1 of 3 · 159 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Security Monitoring questions.