Courseiva

CCNA Cbrops Security Concepts Questions

75 of 143 questions · Page 1/2 · Cbrops Security Concepts topic · Answers revealed

1
MCQhard

An organization wants to ensure that a received email genuinely came from the claimed sender and has not been altered. Which cryptographic mechanism provides both authentication and integrity?

A.Digital signature
B.Hash function
C.Public key infrastructure (PKI)
D.Symmetric encryption
AnswerA

A digital signature is created with the sender's private key and verified with their public key, so successful verification proves origin and confirms the message was not altered in transit. This delivers both authentication and integrity, matching the stem's requirements.

Why this answer

A digital signature uses the sender's private key to sign the message, and the recipient verifies it with the sender's public key. This process provides authentication (proving the sender's identity) and integrity (detecting any alteration) because any change to the message invalidates the signature. Hash functions alone provide integrity but not authentication, while PKI is the infrastructure that supports digital signatures but is not the mechanism itself.

Exam trap

Cisco often tests the distinction between a mechanism (digital signature) and the supporting infrastructure (PKI), leading candidates to mistakenly select PKI because they associate it with certificates and authentication.

How to eliminate wrong answers

Option B is wrong because a hash function provides integrity by producing a fixed-size digest, but it does not authenticate the sender; an attacker can replace both the message and its hash. Option C is wrong because PKI is a framework of policies, roles, and certificates that enables digital signatures and encryption, but it is not a cryptographic mechanism that directly provides both authentication and integrity. Option D is wrong because symmetric encryption provides confidentiality (secrecy) but does not inherently authenticate the sender or ensure integrity; an attacker with the shared key could modify the ciphertext.

2
Multi-Selectmedium

A healthcare organization must comply with HIPAA. Which THREE security measures are typically required under HIPAA? (Choose three.)

Select 3 answers
A.Regular vulnerability scanning of all internet-facing systems
B.Encryption of electronic protected health information (ePHI)
C.Annual penetration testing by an external firm
D.Implementation of access controls to limit who can view ePHI
E.Audit controls to record and examine access to ePHI
AnswersB, D, E

HIPAA's Security Rule treats encryption of electronic protected health information as an addressable implementation specification, protecting confidentiality and integrity during storage and transmission. It satisfies the stem's ePHI protection constraint, alongside access controls and audit logging required for compliance.

Why this answer

Option B is correct because HIPAA's Security Rule identifies encryption of electronic protected health information (ePHI) as an addressable implementation specification under both transmission security and encryption/decryption safeguards, meaning covered entities must implement it or document an equivalent alternative. Option D is correct because the Security Rule's Access Control standard (45 CFR 164.312(a)(1)) requires technical policies and procedures that limit ePHI access to authorized persons or software programs, such as unique user IDs, role-based access, and emergency access procedures. Option E is correct because the Audit Controls standard (45 CFR 164.312(b)) requires hardware, software, and procedural mechanisms that record and examine activity in information systems containing or using ePHI.

Option A is not a specifically mandated HIPAA requirement; vulnerability scanning supports risk analysis but HIPAA does not prescribe it as a standalone required measure. Option C is likewise not required by HIPAA, which mandates risk analysis and periodic evaluation rather than an annual external penetration test.

Exam trap

200-201 often tests the confusion between HIPAA's actual named requirements and generic best practices like annual pen testing or vulnerability scanning, which are not explicitly mandated by the Security Rule.

3
MCQhard

An organization wants to ensure that data sent over the internet cannot be read if intercepted. Which cryptographic method should be used?

A.Digital signature using RSA
B.Hash-based message authentication code (HMAC)
C.Symmetric encryption with AES
D.Hashing with SHA-256
AnswerC

AES is a symmetric block cipher whose confidentiality guarantee renders intercepted ciphertext unreadable without the shared key, satisfying the stem's interception constraint. Symmetric encryption suits bulk data protection, whereas asymmetric algorithms are typically reserved for key exchange and digital signatures.

Why this answer

Symmetric encryption with AES transforms plaintext into ciphertext using a shared secret key, so an attacker who intercepts the data over the internet cannot read it without the key. AES is the standard, NIST-approved symmetric cipher (FIPS 197) used in TLS, VPNs, and disk encryption. This directly satisfies the requirement that intercepted data cannot be read.

Exam trap

The trap is that candidates equate 'cryptographic method' with 'security' and pick hashing or HMAC because they sound protective, forgetting that only encryption provides confidentiality — hashing and signing do not hide data.

How to eliminate wrong answers

Option A is wrong because a digital signature using RSA provides authenticity, integrity, and non-repudiation — it proves who sent the data and that it was not altered, but it does not hide the content, which remains readable. Option B is wrong because HMAC provides integrity and authenticity via a shared key and hash, but it does not encrypt the message; the plaintext is still exposed. Option D is wrong because SHA-256 is a one-way hash function used for integrity checks; it does not provide confidentiality and cannot be reversed to recover the original data.

4
Multi-Selecthard

A security analyst is reviewing a recent security incident where an attacker gained unauthorized access to a server. The analyst needs to determine which factors contributed to the incident by examining the vulnerability, threat, and risk. Which TWO of the following best describe the relationship between these concepts in this scenario? (Choose two.)

Select 2 answers
A.Risk is the same as vulnerability and can be used interchangeably.
B.A vulnerability is a weakness in the server's software that the attacker exploited.
C.Risk is the potential for loss or damage when a threat exploits a vulnerability.
D.A threat is the potential cause of an incident that exploits a vulnerability.
E.A threat is always a deliberate attack by a human actor.
AnswersB, D

A vulnerability is a flaw or weakness in a system that can be exploited to violate security. In this scenario, the attacker gained access by exploiting a weakness, such as an unpatched service or misconfiguration. This definition correctly describes the role of a vulnerability in the incident.

Why this answer

A vulnerability is a weakness that can be exploited, and a threat is the potential cause that exploits it. Together, they create risk, which is the potential for loss. The correct options define vulnerability and threat accurately in the context of the incident, while the others either misdefine terms or are too narrow.

Exam trap

The trap here is equating risk with vulnerability or assuming all threats are human attackers, which oversimplifies the risk formula and ignores natural or accidental threats.

5
MCQmedium

A security analyst observes repeated failed login attempts from a single external IP address, causing the authentication server to become unresponsive. Which type of attack is occurring?

A.Denial of Service
B.Reconnaissance
C.Brute force attack
D.Man-in-the-middle
AnswerA

Flooding authentication with repeated failed logins from one external IP exhausts server resources until it stops responding, which is the defining effect of a Denial of Service attack. The stem's unresponsive authentication server confirms availability, not confidentiality, is the target.

Why this answer

The scenario describes repeated failed login attempts from a single external IP that render the authentication server unresponsive — this is a Denial of Service (DoS) condition, where the volume of authentication requests exhausts server resources (CPU, connection table, lock contention) and denies service to legitimate users. The defining symptom is availability loss, not credential compromise or information gathering. A brute force attack would aim to guess credentials, but here the observed outcome is service unavailability.

Exam trap

200-201 often tests the confusion between brute force and DoS when both involve failed logins — the discriminator is the attacker's objective: credential compromise (brute force) versus service unavailability (DoS).

How to eliminate wrong answers

Option B is wrong because reconnaissance involves scanning and enumeration to gather information (e.g., port scans, banner grabbing) without necessarily causing resource exhaustion or service outage. Option C is wrong because a brute force attack's objective is to successfully authenticate by trying many password combinations; while it generates failed logins, the question's emphasis on the server becoming unresponsive indicates the attack's effect is denial of service, not credential guessing. Option D is wrong because a man-in-the-middle attack requires the adversary to intercept and relay traffic between two parties, which is not described by a flood of failed logins from a single IP.

6
MCQmedium

An attacker uses a tool to capture keystrokes on a compromised system. What type of malware is most likely in use?

A.Spyware
B.Rootkit
C.Ransomware
D.Keylogger
AnswerD

A keylogger is malware that records every keystroke typed on a compromised host, typically storing or transmitting them to the attacker. Capturing keystrokes is its sole defining capability, so it matches the described tool exactly.

Why this answer

A keylogger is a type of malware specifically designed to capture and record keystrokes on a compromised system. The question directly describes the behavior of capturing keystrokes, which is the primary function of a keylogger, making it the most likely malware in use.

Exam trap

Cisco often tests the distinction between a general category (spyware) and a specific type (keylogger), so the trap here is that candidates may choose spyware because it is a broader term, but the question asks for the most likely malware based on the specific behavior described.

How to eliminate wrong answers

Option A is wrong because spyware is a broader category of malware that focuses on collecting information about a user's activities, such as browsing habits or login credentials, but it does not specifically specialize in capturing keystrokes; a keylogger is a subset of spyware, but the question asks for the most likely type, and keylogger is more precise. Option B is wrong because a rootkit is designed to hide the presence of other malware or provide persistent, stealthy access to a system by modifying operating system kernel or system calls, not to capture keystrokes directly. Option C is wrong because ransomware is malware that encrypts files or locks the system to demand a ransom, and it does not typically include keystroke capture as its primary function.

7
MCQmedium

A security analyst is reviewing logs and notices that an attacker has intercepted and modified communications between two devices on the same network. Which attack technique is being used?

A.Reconnaissance
B.ARP spoofing
C.Man-in-the-Middle
D.DNS poisoning
AnswerC

Man-in-the-Middle attacks satisfy the on-path interception constraint: the adversary inserts themselves between two communicating devices, relaying and altering traffic without either party detecting it. Unlike passive sniffing, which only copies packets, MitM actively modifies data in transit, matching the stem's intercepted and modified communications.

Why this answer

A man-in-the-middle attack is when an attacker intercepts and modifies communications between two parties who believe they are talking directly to each other. The scenario describes interception and modification of traffic between two devices on the same network, which is the defining behavior of a MITM attack. ARP spoofing is often the technique used to enable MITM on a LAN, but the attack technique described is MITM itself.

Exam trap

The trap is that ARP spoofing is the enabling mechanism for a LAN MITM, so candidates pick the technique rather than the attack category the question is asking about.

How to eliminate wrong answers

Option A is wrong because reconnaissance is information gathering (scanning, enumeration) and does not involve intercepting or modifying communications. Option B is wrong because ARP spoofing is a specific Layer 2 technique that poisons ARP caches to redirect traffic; it is a means to an end, not the general attack technique described, and the question asks for the technique being used. Option D is wrong because DNS poisoning corrupts DNS responses to redirect users to malicious sites; it does not describe interception and modification of an ongoing communication between two devices.

8
MCQhard

A security analyst is selecting a symmetric encryption algorithm for encrypting data at rest. Which of the following is a suitable symmetric algorithm?

A.AES
B.ECC
C.RSA
D.SHA-256
AnswerA

AES is the only symmetric block cipher listed, satisfying the data-at-rest requirement. It encrypts and decrypts with one shared key, unlike RSA and ECC, which are asymmetric. AES-256 offers strong resistance to brute-force attacks and is the standard choice for protecting stored data.

Why this answer

AES (Advanced Encryption Standard) is a symmetric block cipher, meaning it uses the same key for both encryption and decryption, making it suitable for encrypting data at rest. It is widely adopted, standardized by NIST, and available in 128-, 192-, and 256-bit key lengths. AES is the de facto standard for symmetric encryption in modern systems.

Exam trap

The trap is that candidates see 'SHA-256' and assume it is an encryption algorithm because it sounds cryptographic — but hashing is one-way and cannot encrypt/decrypt data, and asymmetric algorithms like RSA/ECC are often confused with symmetric ones under exam pressure.

How to eliminate wrong answers

Option B is wrong because ECC (Elliptic Curve Cryptography) is an asymmetric algorithm used for key exchange and digital signatures, not symmetric bulk encryption. Option C is wrong because RSA is also an asymmetric algorithm, typically used for key transport and signatures, and is too slow for bulk data encryption. Option D is wrong because SHA-256 is a cryptographic hash function, not an encryption algorithm — it produces a fixed-size digest and is not reversible, so it cannot be used to encrypt data at rest.

9
MCQmedium

What is the primary difference between symmetric and asymmetric encryption?

A.Asymmetric encryption is used only for hashing
B.Symmetric uses two keys, asymmetric uses one
C.Symmetric is slower than asymmetric
D.Symmetric uses a single shared key; asymmetric uses a key pair
AnswerD

Symmetric encryption relies on one shared secret key for both encryption and decryption, whereas asymmetric encryption uses a mathematically linked key pair: a public key to encrypt and a private key to decrypt. This directly satisfies the stem's request for the primary distinction between the two encryption schemes.

Why this answer

Symmetric encryption uses a single shared key for both encryption and decryption, while asymmetric encryption uses a key pair: a public key for encryption and a private key for decryption. This fundamental difference in key usage is the primary distinction.

Exam trap

200-201 often tests the confusion between key usage and performance characteristics, or the misconception that asymmetric encryption is used only for hashing. Candidates might also mix up which type uses one key versus two.

How to eliminate wrong answers

Option A is wrong because asymmetric encryption is not used only for hashing; hashing is a separate cryptographic operation. Asymmetric encryption is used for encryption/decryption and digital signatures. Option B is wrong because it reverses the key usage: symmetric uses one key, asymmetric uses two.

Option C is wrong because symmetric encryption is generally faster than asymmetric, but this is a performance characteristic, not the primary difference in key management.

10
MCQhard

A security analyst is reviewing a suspicious email reported by a user. The email appears to come from the CEO and requests an urgent wire transfer. The analyst examines the email headers and notices that the 'From' address is spoofed and the 'Reply-To' address is different from the 'From' address. The email also contains a link to a credential-harvesting page. Which type of attack is this?

A.Spear phishing
B.Business email compromise (BEC)
C.Whaling
D.Phishing
AnswerB

BEC is a sophisticated scam where attackers impersonate executives or trusted partners to trick employees into transferring funds or revealing sensitive information. The scenario describes a spoofed CEO email requesting an urgent wire transfer, which is a classic BEC attack. The mismatched Reply-To and credential-harvesting link further support this classification.

Why this answer

The email impersonates the CEO and requests an urgent wire transfer, which is the hallmark of business email compromise (BEC). BEC attacks often involve spoofed sender addresses and may include links to credential-harvesting sites. While it is a form of phishing, BEC specifically targets financial transactions and is a distinct category.

Exam trap

The trap here is labeling any fraudulent email as phishing; BEC is a specific subtype that involves impersonating executives to commit financial fraud, often without malware.

11
MCQeasy

A security analyst is examining a suspicious executable found on a user's workstation. The file appears to be a legitimate PDF document but when opened, it executes code that encrypts the user's files and demands payment. The analyst determines that the file is actually a malicious program disguised as a benign file. Which type of malware is this?

A.Rootkit
B.Trojan
C.Virus
D.Worm
AnswerB

A Trojan is malware that disguises itself as legitimate software or a benign file to trick users into executing it. In this case, the executable appears to be a PDF but actually performs malicious actions like encrypting files. This deception is the defining characteristic of a Trojan, which often delivers ransomware or other payloads.

Why this answer

The key indicator is the file masquerading as a legitimate PDF while actually being a malicious executable that encrypts files. This deception is the hallmark of a Trojan, which often delivers ransomware payloads. Unlike worms or viruses, Trojans rely on user execution and do not self-replicate.

Exam trap

The trap here is assuming any malware that encrypts files is automatically ransomware; however, the delivery method (disguised as a benign file) defines it as a Trojan.

12
MCQmedium

A security analyst is investigating a potential data exfiltration incident. The analyst observes that a large amount of data is being transferred from an internal database server to an external IP address during non-business hours. The transfer is using an encrypted channel that is not typical for the server's normal operations. Which type of threat is this activity most likely associated with?

A.Advanced persistent threat (APT)
B.Phishing
C.Ransomware
D.Distributed denial of service (DDoS)
AnswerA

An advanced persistent threat often involves stealthy, prolonged access to a network to steal data over time. The scenario describes data exfiltration using an encrypted channel during non-business hours, which aligns with APT tactics. APTs aim to maintain persistence and exfiltrate sensitive information without detection, making this the most likely threat type.

Why this answer

An advanced persistent threat is a prolonged and targeted attack where an intruder gains access to a network and remains undetected to steal data. The scenario's characteristics—large data transfer to an external IP, encrypted channel, and non-business hours—are typical of APT exfiltration. DDoS, ransomware, and phishing do not match the observed behavior of stealthy outbound data transfer.

Exam trap

The trap here is assuming that any data transfer is ransomware or DDoS, but the stealthy, encrypted exfiltration during off-hours points to a persistent threat actor.

13
MCQmedium

Which cryptographic method uses the same key for both encryption and decryption, and is typically faster than asymmetric encryption?

A.Digital signature
B.RSA
C.AES
D.SHA-256
AnswerC

AES is a symmetric block cipher, so encryption and decryption share one secret key. This satisfies the stem's same-key requirement, and symmetric ciphers process data far faster than asymmetric algorithms such as RSA, which rely on computationally expensive modular arithmetic.

Why this answer

Symmetric encryption uses a single shared key for both operations.

14
Multi-Selecteasy

Which TWO of the following are examples of malware that rely on user interaction to spread? (Select two.)

Select 2 answers
A.Rootkit
B.Worm
C.Trojan
D.Virus
E.Ransomware
AnswersC, D

A Trojan disguises itself as legitimate software, so the victim must execute or install it before it runs. That dependency on the user launching the file satisfies the stem's user-interaction requirement, unlike worms, which self-propagate across networks without any user action.

Why this answer

Option C (Trojan) is correct because a Trojan horse is malware disguised as legitimate software, and it requires the user to download and execute the file before it can infect the system — the user's action is the trigger for the infection. Option D (Virus) is correct because a virus must attach itself to a host file or program and typically needs the user to run that infected file or share it (e.g., via email attachment or USB drive) for it to propagate. By contrast, Option B (Worm) is incorrect because worms self-replicate and spread across networks automatically without any user interaction.

Option A (Rootkit) is incorrect because it is a stealth tool for maintaining privileged access, not a self-spreading mechanism, and Option E (Ransomware) is incorrect because it is defined by its payload (encrypting data for extortion) rather than by a user-interaction-dependent spreading method.

15
MCQmedium

An analyst is examining a suspicious executable recovered from a compromised host. Static analysis shows it is packed, and dynamic analysis in a sandbox reveals it creates a mutex, modifies registry Run keys, and attempts to connect to a hardcoded IP address on port 443. The file also contains a section with high entropy. Which characteristic most strongly suggests the file is packed or encrypted?

A.A section with high entropy
B.Connection to a hardcoded IP on port 443
C.Modification of registry Run keys
D.Creation of a mutex
AnswerA

High entropy in a file section indicates compressed or encrypted data, which is typical of packed malware. Packers compress or encrypt the original code to evade signature detection, and the unpacking stub restores it at runtime. The high-entropy section is a strong static indicator that the executable is packed or encrypted.

Why this answer

High entropy in a section is a classic static indicator of packing or encryption, because compressed or encrypted data lacks the patterns of normal executable code. Packers use this to hide the original code and evade signature-based detection. The other observed behaviors are runtime actions related to persistence and command-and-control, not structural evidence of packing.

Exam trap

The trap here is focusing on dynamic behaviors like persistence or C2, which are separate from the static structural clue of high entropy that indicates packing.

16
MCQeasy

A security analyst is notified that an employee's laptop was stolen. The laptop contains sensitive customer data. Which type of threat does this incident represent?

A.Exploit
B.Risk
C.Threat
D.Vulnerability
AnswerC

A stolen laptop containing sensitive customer data represents a physical asset loss enabling data exposure, which falls under threat classification in risk models. The threat is the potential actor or event exploiting the missing device's unencrypted data, satisfying the scenario's requirement to categorise the incident as a threat rather than a vulnerability or exploit.

Why this answer

A threat is any potential cause of an unwanted incident that could harm assets; a stolen laptop containing sensitive data is a threat event because it can lead to unauthorized disclosure. The laptop itself is the asset, the sensitive data is what's at risk, and the theft is the threat action. Exploit, risk, and vulnerability describe different concepts in the threat model.

Exam trap

200-201 often tests the threat vs. vulnerability vs. risk vs. exploit distinction — candidates frequently pick 'vulnerability' for a stolen device because it feels like a weakness, but theft is a threat event, not a weakness in the system.

How to eliminate wrong answers

Option A (Exploit) is wrong because an exploit is a technique or code that takes advantage of a vulnerability, not the theft event itself. Option B (Risk) is wrong because risk is the potential for loss or damage when a threat exploits a vulnerability, calculated as likelihood times impact — it is the outcome, not the event. Option D (Vulnerability) is wrong because a vulnerability is a weakness (e.g., missing encryption, unpatched software) that a threat can exploit; the stolen laptop is not itself a weakness.

17
MCQmedium

An organization is reviewing its exposure to attack surface. A security architect notes that employees routinely install browser extensions from unapproved sources, and several internal web applications accept unsanitized input. Which concept do these findings primarily describe?

A.Vulnerabilities that expand the attack surface and may be exploited by threat actors
B.A compliance violation of the Payment Card Industry Data Security Standard
C.A social engineering campaign targeting employees through malicious extensions
D.A denial-of-service condition caused by excessive extension usage
AnswerA

Unsanitized input creates injection vulnerabilities such as cross-site scripting, and unapproved browser extensions add untrusted code to endpoints. Together these weaknesses enlarge the attack surface, giving threat actors more paths to exploit. The architect's findings describe exploitable vulnerabilities rather than a specific attack technique or a compliance gap.

Why this answer

The findings are vulnerabilities that enlarge the attack surface. Unsanitized input enables injection flaws, and unapproved extensions introduce untrusted code with broad browser privileges. Both give threat actors additional entry points and increase the likelihood of compromise.

Reducing the attack surface requires application input validation, extension allowlisting, and endpoint policy enforcement, which directly address the weaknesses identified.

Exam trap

The trap here is focusing on the browser extensions as a social engineering issue, when the combined findings describe exploitable vulnerabilities that widen the attack surface.

18
MCQhard

A security analyst is evaluating the risk of a new vulnerability in a web application. The vulnerability has a CVSS base score of 9.8 and is remotely exploitable without authentication. The application is internet-facing and processes sensitive customer data. Which risk response strategy is MOST appropriate according to risk management principles?

A.Risk transference
B.Risk avoidance
C.Risk acceptance
D.Risk mitigation
AnswerD

Risk mitigation involves applying controls to reduce the likelihood or impact of a vulnerability. Given the high CVSS score and exposure, patching or implementing a web application firewall is necessary. Mitigation is the most appropriate response to protect sensitive data and maintain compliance.

Why this answer

The vulnerability is critical and remotely exploitable, posing a high risk to sensitive data. Mitigating the risk through patching or other controls is the most appropriate response. Risk acceptance, transference, or avoidance are less suitable because they do not directly reduce the technical exposure in a timely manner.

Exam trap

The trap here is choosing risk transference (e.g., cyber insurance) as a quick fix, but it does not address the underlying vulnerability and is not the primary response for high-severity technical risks.

19
MCQhard

During a security audit, it is discovered that an organization’s network is vulnerable to ARP spoofing attacks. Which type of attack could result from exploiting this vulnerability?

A.DNS poisoning
B.Man-in-the-middle
C.Phishing
D.DoS
AnswerB

ARP spoofing lets an attacker send forged ARP replies, poisoning victims' caches so traffic is redirected through the attacker's machine. Positioned between two communicating hosts, the attacker relays traffic while reading or altering it, producing a man-in-the-middle condition.

Why this answer

ARP spoofing allows an attacker to send forged ARP replies that associate the attacker's MAC address with a legitimate IP (e.g., the default gateway), causing victims to send traffic to the attacker instead of the real destination. The attacker then relays traffic between the victim and the gateway, positioning themselves in the path — a classic man-in-the-middle (MITM) attack that enables eavesdropping, session hijacking, and credential theft.

Exam trap

200-201 often tests the distinction between ARP spoofing's direct effect (MITM) and its secondary effects (DoS, DNS poisoning) — candidates must identify the primary, canonical consequence the question is targeting.

How to eliminate wrong answers

Option A is wrong because DNS poisoning involves corrupting DNS resolver caches or responses to redirect name resolution; while ARP spoofing can facilitate DNS poisoning by intercepting DNS queries, the direct and primary consequence of ARP spoofing is MITM, not DNS cache corruption. Option C is wrong because phishing is a social engineering attack delivered via email or fake websites; it does not result from ARP spoofing, though ARP spoofing could redirect a victim to a phishing site as a secondary effect. Option D is wrong because a DoS attack aims to make a service unavailable; ARP spoofing can cause DoS if the attacker blackholes traffic, but the question asks for the attack type that results from the vulnerability, and MITM is the canonical, direct exploitation.

20
Multi-Selectmedium

A security analyst is classifying security controls for a new data center. Which TWO of the following are examples of physical controls? (Choose two.)

Select 2 answers
A.Security awareness training for staff
B.Full-disk encryption on employee laptops
C.Bollards installed at the building entrance
D.Security guards stationed at the lobby
E.Access control lists on the core router
AnswersC, D

Bollards are physical barriers that prevent vehicles from ramming into a building or accessing restricted areas. They are tangible structures designed to deter or block physical threats, which makes them a classic physical control. In a data center, bollards help protect the facility from vehicle-borne attacks and accidental damage. This option is correct because it directly addresses physical access and protection of the premises.

Why this answer

Physical controls are measures that protect tangible assets, facilities, and people. Bollards and security guards both operate in the physical world: bollards block vehicle access, and guards control and monitor entry. Access control lists, full-disk encryption, and awareness training are technical or administrative controls because they address logical access, data protection, or human behavior rather than physical barriers or presence.

Only the two physical measures fit the requested category.

Exam trap

The trap here is treating any security measure as a physical control, when the category depends on whether it protects tangible space and assets rather than data or behavior.

21
Multi-Selectmedium

A security engineer is implementing controls to meet compliance requirements. Which TWO of the following frameworks are specifically designed for protecting personal data?

Select 2 answers
A.HIPAA
B.NIST Cybersecurity Framework
C.GDPR
D.PCI DSS
E.ISO 27001
AnswersA, C

HIPAA safeguards protected health information, a subset of personal data, through its Privacy and Security Rules. It satisfies the compliance constraint by mandating administrative, physical and technical safeguards for individually identifiable health data, making it a framework specifically designed to protect personal information rather than general security controls.

Why this answer

HIPAA (A) is correct because it is a U.S. regulation specifically designed to protect the privacy and security of protected health information (PHI), which is a category of personal data. GDPR (C) is correct because it is an EU regulation explicitly focused on the protection of personal data and the privacy rights of individuals. NIST Cybersecurity Framework (B) is a voluntary framework for managing cybersecurity risk generally, not specifically for personal data protection.

PCI DSS (D) is designed to protect payment card data, which is a narrower and different scope than personal data. ISO 27001 (E) is a general information security management standard, not specifically focused on personal data protection.

Exam trap

Cisco often tests the distinction between frameworks that are specifically designed for personal data protection (like HIPAA and GDPR) versus general cybersecurity or information security frameworks (like NIST CSF, PCI DSS, and ISO 27001) that may include data protection but are not their primary purpose.

22
MCQmedium

A security analyst at a mid-sized company is reviewing a packet capture from the DMZ and notices a series of TCP SYN packets sent to multiple ports on a single internal web server, all originating from the same external IP address within a 3-second window. None of the SYN packets are followed by a completed three-way handshake. The analyst must classify this activity to determine the appropriate response. Which type of attack is most consistent with this traffic pattern?

A.UDP amplification attack
B.SYN flood denial-of-service attack
C.ARP poisoning attack
D.DNS tunneling attack
AnswerB

A SYN flood sends numerous TCP SYN packets to open ports without completing the three-way handshake, exhausting the server's connection backlog. The scenario describes exactly this: multiple SYNs to different ports from one source with no completed handshakes. This matches the classic half-open connection pattern used to deny service to legitimate users.

Why this answer

The traffic pattern of many TCP SYN packets to multiple ports from a single source without completed handshakes is the hallmark of a SYN flood. This attack consumes server resources by leaving connections half-open, preventing legitimate users from establishing sessions. Recognizing this pattern allows the analyst to apply mitigations such as SYN cookies or rate limiting.

Exam trap

The trap here is confusing a SYN flood with a port scan, because both send SYNs to multiple ports; however, a port scan typically completes or resets connections and aims to discover services, while a SYN flood deliberately leaves connections half-open to exhaust resources.

23
MCQeasy

A security team is implementing a defense-in-depth strategy and wants to ensure that even if an attacker compromises a web server, the attacker cannot easily move laterally to the internal database server. Which security principle is being applied when the team segments the network and restricts traffic between the web tier and the database tier?

A.Network segmentation
B.Zero trust
C.Least privilege
D.Defense in depth
AnswerA

Network segmentation divides a network into isolated zones and enforces traffic controls between them. By restricting traffic from the web tier to the database tier, the team limits lateral movement, so a compromised web server cannot freely reach the database. This directly matches the described control and its purpose.

Why this answer

Segmenting the network and restricting traffic between the web and database tiers limits an attacker's ability to move laterally after compromising a web server. This is the principle of network segmentation, which reduces the attack surface and contains breaches within a zone.

Exam trap

The trap here is choosing the umbrella term defense in depth when the scenario describes the specific control of network segmentation.

24
MCQeasy

Which of the following best describes a vulnerability?

A.A weakness in a system that could be exploited
B.The act of taking advantage of a weakness
C.The likelihood that a threat will exploit a weakness
D.A potential event that could cause harm
AnswerA

A vulnerability is precisely a weakness or flaw in a system that an attacker could exploit to violate confidentiality, integrity or availability; this definition distinguishes it from a threat, which is the potential cause of harm.

Why this answer

A vulnerability is a flaw or weakness in a system's design, implementation, or configuration that can be exploited by a threat actor. Option A correctly captures this as a weakness that could be exploited, which aligns with the standard definition in cybersecurity (e.g., NIST SP 800-30). It is not the act of exploitation itself, nor the likelihood of exploitation, nor the potential event causing harm.

Exam trap

The trap here is confusing vulnerability with exploit, risk, or threat, as these terms are often used interchangeably in casual conversation but have distinct meanings in cybersecurity.

How to eliminate wrong answers

Option B is wrong because it describes an exploit (the act of taking advantage of a weakness), not the vulnerability itself. Option C is wrong because it describes risk (the likelihood that a threat will exploit a weakness), which combines threat, vulnerability, and impact. Option D is wrong because it describes a threat (a potential event that could cause harm), not a vulnerability.

25
MCQmedium

An organization experiences a ransomware attack where files are encrypted and a ransom is demanded. Which element of the CIA triad is most directly impacted?

A.Availability
B.Integrity
C.Non-repudiation
D.Confidentiality
AnswerA

Ransomware encryption renders files unreadable, directly denying legitimate access to data and systems. Availability is the CIA element concerned with ensuring authorised users can access resources when required, so encryption that blocks access satisfies the stem's constraint of disrupted data access. Confidentiality and integrity remain intact; the data is neither exposed nor altered.

Why this answer

A ransomware attack encrypts files and demands payment, directly preventing users from accessing their data and systems. This loss of access is a direct impact on Availability, which ensures that information and resources are accessible when needed. The CIA triad's Availability element is most immediately compromised because the organization cannot retrieve or use its encrypted files.

Exam trap

Cisco often tests the distinction between Integrity and Availability by presenting a scenario where data is altered (encryption) but the primary consequence is loss of access, leading candidates to mistakenly choose Integrity because they focus on the modification rather than the resulting denial of service.

How to eliminate wrong answers

Option B is wrong because Integrity is about ensuring data has not been tampered with or altered; while ransomware does modify files by encrypting them, the primary impact is the loss of access, not the verification of data correctness. Option C is wrong because Non-repudiation refers to the ability to prove that an action or transaction occurred, typically through digital signatures or logs, which is not directly relevant to file encryption and ransom demands. Option D is wrong because Confidentiality involves protecting data from unauthorized disclosure; ransomware does not primarily expose data to unauthorized parties (unless exfiltration occurs), but rather locks authorized users out.

26
MCQhard

An organization wants to implement a security framework that includes functions such as Identify, Protect, Detect, Respond, and Recover. Which framework aligns with this structure?

A.NIST Cybersecurity Framework
B.HIPAA Security Rule
C.PCI DSS
D.ISO 27001
AnswerA

The NIST Cybersecurity Framework is structured around the five core functions: Identify, Protect, Detect, Respond, and Recover. No other framework in the stem's list uses this exact function set, so it directly matches the required structure.

Why this answer

The NIST Cybersecurity Framework (CSF) is explicitly organized around five core functions: Identify, Protect, Detect, Respond, and Recover. This structure provides a common language for managing cybersecurity risk and is widely adopted across industries. The framework's functions cover the full lifecycle of cybersecurity activities, from understanding assets and risks to recovering from incidents.

Exam trap

The trap here is confusing a security framework with a regulation or standard; candidates may pick HIPAA or PCI DSS because they are well-known in security, but only the NIST CSF explicitly defines the five functions.

How to eliminate wrong answers

Option B is wrong because the HIPAA Security Rule is a U.S. regulation focused on protecting electronic protected health information (ePHI) and does not define a framework with those five functions; it specifies administrative, physical, and technical safeguards. Option C is wrong because PCI DSS is a payment card industry standard that prescribes specific security controls for cardholder data environments, not a framework with Identify, Protect, Detect, Respond, and Recover functions. Option D is wrong because ISO 27001 is an international standard for information security management systems (ISMS) that requires a risk-based approach but does not use the five-function structure; it focuses on Plan-Do-Check-Act and Annex A controls.

27
MCQhard

During a penetration test, a security engineer uses publicly available information from LinkedIn and Google to gather details about employees and organizational structure. Which type of reconnaissance is being performed?

A.Active reconnaissance
B.Social engineering
C.Passive reconnaissance
D.Internal reconnaissance
AnswerC

Passive reconnaissance relies on publicly available sources without directly interacting with the target's systems, so no packets reach the organisation's infrastructure. LinkedIn and Google searches match this exactly, satisfying the stem's constraint of gathering employee and structural details covertly, leaving no trace in the target's logs.

Why this answer

The security engineer is gathering information from publicly available sources (LinkedIn, Google) without directly interacting with the target's systems. This is the definition of passive reconnaissance, which involves collecting data from open-source intelligence (OSINT) without sending any packets to the target network.

Exam trap

Cisco often tests the distinction between active and passive reconnaissance by describing an activity that uses public sources but might seem 'active' to a novice; the trap here is confusing passive information gathering with active scanning or social engineering.

How to eliminate wrong answers

Option A is wrong because active reconnaissance involves direct interaction with the target, such as sending probes, scans, or packets (e.g., using Nmap or ping sweeps), which is not described here. Option B is wrong because social engineering involves manipulating people to divulge confidential information, not simply collecting publicly available data from websites. Option D is wrong because internal reconnaissance is performed from within the target's network, often after gaining initial access, whereas this activity occurs externally using public sources.

28
Multi-Selectmedium

A security analyst is reviewing the organization's defense-in-depth strategy. The analyst must recommend TWO controls that specifically reduce the risk of successful phishing attacks against employees. Which two controls should the analyst recommend? (Choose two.)

Select 2 answers
A.Implementing email filtering that blocks messages with malicious attachments and links.
B.Configuring network segmentation to isolate the finance department from the rest of the network.
C.Deploying a web application firewall (WAF) to inspect HTTP traffic to the company's public website.
D.Enabling full-disk encryption on all employee laptops.
E.Conducting regular security awareness training that teaches employees to recognize phishing attempts.
AnswersA, E

Email filtering inspects incoming messages and blocks those containing known malicious attachments, URLs, or sender reputations. This directly reduces the volume of phishing emails reaching user inboxes, lowering the chance of a successful attack. It is a preventive control that operates before the user interacts with the message, making it a core component of anti-phishing defense in depth.

Why this answer

Email filtering and security awareness training are both direct anti-phishing controls. Filtering blocks malicious messages before delivery, while training helps users recognize and avoid phishing attempts that bypass filters. Together they form a layered defense.

The other options address different threats such as web application attacks, data-at-rest protection, and lateral movement containment.

Exam trap

The trap here is selecting network segmentation because it sounds like defense in depth, but it mitigates impact rather than preventing phishing success.

29
MCQmedium

A security analyst is investigating a recent security incident and needs to determine the extent of the compromise. The analyst wants to understand which systems were affected and what data may have been accessed. Which phase of the incident response process is the analyst currently performing?

A.Detection and analysis
B.Post-incident activity
C.Preparation
D.Containment, eradication, and recovery
AnswerA

Detection and analysis is the phase where analysts validate whether an incident occurred, determine its scope, and identify affected systems and data. The analyst's goal of understanding which systems were compromised and what data was accessed aligns directly with this phase. This step precedes containment and eradication and is critical for making informed decisions about subsequent response actions.

Why this answer

The detection and analysis phase of incident response involves validating incidents, determining their scope, and identifying affected systems and data. The analyst's investigation into which systems were compromised and what data was accessed is a textbook example of this phase, which must be completed before containment and eradication can be effectively planned.

Exam trap

The trap here is thinking that any investigative activity belongs to containment, when scope determination is specifically part of detection and analysis.

30
Multi-Selectmedium

A security analyst is assessing the risk profile of a new cloud-based collaboration application that employees want to adopt. The analyst must identify which factors contribute to the overall risk of introducing this application into the environment. (Choose two.)

Select 2 answers
A.The likelihood that a threat will exploit a vulnerability in the application or its supporting infrastructure.
B.The marketing team's preferred color scheme for the application's user interface.
C.The number of employees who have requested access to the application for productivity purposes.
D.The vendor's stock price over the past fiscal quarter.
E.The potential impact to the organization if the application's data is compromised or the service becomes unavailable.
AnswersA, E

Risk is a function of likelihood and impact. The probability that a threat actor will exploit a weakness in the application or its cloud infrastructure directly contributes to the overall risk level. Without considering likelihood, the analyst cannot estimate how probable a loss event is. This factor is a core component of risk assessment in the Security Concepts domain.

Why this answer

Risk assessment combines the likelihood that a threat will exploit a vulnerability with the impact that exploitation would have on the organization. These two factors produce the overall risk rating for the collaboration application. User demand, UI color schemes, and vendor stock price do not measure security risk, so likelihood and impact are the two factors the analyst must evaluate.

Exam trap

The trap here is treating business popularity or vendor financial metrics as risk factors, when risk specifically requires assessing both the probability of exploitation and the resulting impact.

31
MCQmedium

A security engineer discovers that an attacker has inserted fake entries into a DNS resolver's cache, redirecting users to a malicious website. Which attack has occurred?

A.DDoS
B.DNS poisoning
C.Man-in-the-middle
D.ARP spoofing
AnswerB

DNS poisoning corrupts a resolver's cache with forged records, so subsequent queries return the attacker's IP address and redirect victims. This matches the stem exactly: fake entries inserted into the cache, sending users to a malicious site.

Why this answer

DNS poisoning, also known as DNS cache poisoning, occurs when an attacker inserts forged DNS resource records into a resolver's cache. This causes the resolver to return a malicious IP address for a legitimate domain, redirecting users to an attacker-controlled site without their knowledge.

Exam trap

Cisco often tests the distinction between DNS poisoning and ARP spoofing by presenting a scenario involving redirection to a malicious site, leading candidates to confuse the Layer 2 ARP attack with the Layer 7 DNS cache corruption.

How to eliminate wrong answers

Option A is wrong because a DDoS (Distributed Denial of Service) attack aims to overwhelm a target with traffic to disrupt service, not to insert fake DNS entries. Option C is wrong because a man-in-the-middle (MITM) attack intercepts and potentially alters communications between two parties in real time, whereas DNS poisoning corrupts the resolver's stored cache records. Option D is wrong because ARP spoofing links an attacker's MAC address to a legitimate IP address on a local network, targeting Layer 2 address resolution, not the DNS resolver's cache.

32
MCQmedium

What is the primary purpose of a digital certificate in a Public Key Infrastructure (PKI)?

A.To encrypt all network traffic
B.To bind a public key to an identity
C.To provide a backup of private keys
D.To prevent malware infections
AnswerB

A digital certificate binds a public key to a verified identity by having a trusted certificate authority digitally sign the certificate, which contains the subject's public key and identifying details. This binding lets relying parties confirm the key genuinely belongs to the claimed entity, preventing impersonation and enabling trusted encryption and authentication.

Why this answer

The primary purpose of a digital certificate in a Public Key Infrastructure (PKI) is to bind a specific public key to a verified identity (such as a person, device, or organization). This binding is achieved through the certificate authority (CA) signing the certificate, which cryptographically asserts that the public key belongs to the named subject. Without this binding, there would be no trusted way to associate a public key with its owner, making secure communications and authentication impossible.

Exam trap

Cisco often tests the misconception that a digital certificate itself encrypts data or contains the private key, when in fact it only binds the public key to an identity and never holds the private key.

How to eliminate wrong answers

Option A is wrong because encrypting all network traffic is not the role of a digital certificate; encryption of traffic is performed by protocols like TLS using the public/private key pair, but the certificate itself only provides the binding and does not perform encryption. Option C is wrong because a digital certificate contains only the public key and identity information, never the private key; backing up private keys is a separate key management task, and exposing the private key in a certificate would break the entire security model. Option D is wrong because preventing malware infections is a function of security controls such as antivirus software, firewalls, and endpoint protection, not of digital certificates or PKI.

33
MCQeasy

Which element of the CIA triad ensures that data cannot be modified by unauthorized parties?

A.Availability
B.Non-repudiation
C.Integrity
D.Confidentiality
AnswerC

Integrity guarantees data remains accurate and unaltered unless changed by authorised parties. Hashing, checksums and digital signatures detect unauthorised modification, directly satisfying the requirement that data cannot be modified by unauthorised parties, unlike confidentiality or availability controls.

Why this answer

Integrity is the CIA triad element that ensures data has not been altered or tampered with by unauthorized parties. It guarantees that information remains accurate, complete, and trustworthy throughout its lifecycle, typically enforced through hashing, checksums, digital signatures, and access controls.

Exam trap

The trap is mixing up confidentiality and integrity — candidates often think 'unauthorized parties' implies confidentiality, but the question specifically says 'cannot be modified,' which is integrity, not secrecy.

How to eliminate wrong answers

Option A is wrong because availability ensures that data and systems are accessible to authorized users when needed, not that data is unmodified. Option B is wrong because non-repudiation ensures that a party cannot deny the authenticity of their signature or the sending of a message — it is related to accountability, not data modification. Option D is wrong because confidentiality ensures that data is only accessible to authorized parties, preventing unauthorized disclosure, but it does not address modification.

34
Multi-Selecteasy

A company needs to comply with regulations that protect personal data of EU citizens. Which TWO compliance frameworks are directly relevant to this requirement? (Choose two.)

Select 1 answer
A.PCI DSS
B.GDPR
C.ISO 27001
D.NIST Cybersecurity Framework
E.HIPAA
AnswersB

GDPR is the EU regulation governing protection of personal data of EU citizens, imposing lawful processing, consent and breach-notification duties. It directly satisfies the stem's requirement for a compliance framework relevant to safeguarding EU citizens' personal data.

Why this answer

GDPR (B) is directly relevant because the General Data Protection Regulation is the EU legal framework that governs the protection of personal data of EU citizens, imposing requirements on data controllers and processors regarding consent, data subject rights, breach notification, and cross-border transfers. ISO 27001 (C) is not correct because it is a voluntary international standard for establishing an Information Security Management System (ISMS), not a regulation that directly protects EU citizens' personal data. PCI DSS (A) is not correct because it applies specifically to organizations that store, process, or transmit cardholder data (payment card information), not to personal data of EU citizens generally.

NIST Cybersecurity Framework (D) is not correct because it is a voluntary US-origin framework for managing cybersecurity risk rather than a data protection regulation aimed at EU personal data. HIPAA (E) is not correct because it governs protected health information in the United States, not the personal data of EU citizens.

Exam trap

200-201 often tests the confusion between general security frameworks and specific regulations; candidates may incorrectly select NIST, PCI DSS, or ISO 27001 when asked about EU personal data protection.

35
MCQmedium

A security analyst is reviewing the organization's incident response plan. The plan currently defines containment, eradication, and recovery but does not include a formal step to determine the root cause of an incident. Which phase of the NIST SP 800-61 incident response lifecycle should the analyst add to address this gap?

A.Post-incident activity
B.Containment, eradication, and recovery
C.Preparation
D.Detection and analysis
AnswerA

Post-incident activity is the final phase of the NIST SP 800-61 lifecycle, where the team reviews what happened, identifies the root cause, documents lessons learned, and updates procedures. Adding this phase directly fills the gap because root cause analysis is a core activity of the post-incident review, not of containment, eradication, or recovery.

Why this answer

The NIST SP 800-61 lifecycle includes preparation; detection and analysis; containment, eradication, and recovery; and post-incident activity. Root cause analysis and lessons learned belong to the post-incident activity phase, which the plan lacks. Adding it ensures the organization systematically identifies why the incident occurred and improves future response.

Exam trap

The trap here is assuming that root cause analysis happens during detection and analysis, when it is formally part of the post-incident activity phase.

36
Multi-Selecteasy

A security analyst is assessing the risks to a company's data. The analyst identifies a vulnerability in the web application that could allow SQL injection. Which TWO terms correctly describe the elements of this risk scenario? (Choose two.)

Select 2 answers
A.The SQL injection flaw in the application is a threat.
B.The combination of the vulnerability and threat is the exploit.
C.The SQL injection flaw in the application is a vulnerability.
D.The possibility of an attacker exploiting the SQL injection is a vulnerability.
E.The possibility of an attacker exploiting the SQL injection is a threat.
AnswersC, E

A vulnerability is a weakness in a system or application that an attacker could exploit. The SQL injection flaw is precisely such a weakness in the web application, making it the vulnerability element of this risk scenario.

Why this answer

Option C is correct because a SQL injection flaw is a weakness in the web application's code that can be leveraged to compromise the system, which is the definition of a vulnerability. Option E is correct because the possibility of an attacker exploiting that flaw represents a potential danger or adversary action, which is the definition of a threat. Option A is incorrect because the flaw itself is a vulnerability, not a threat; a threat is the actor or event that could exploit it.

Option B is incorrect because an exploit is the specific technique or code that takes advantage of the vulnerability, not the combination of vulnerability and threat. Option D is incorrect because the possibility of exploitation describes a threat, not a vulnerability, which is the actual weakness.

Exam trap

The trap is swapping vulnerability and threat — candidates often call the flaw a 'threat' because it sounds dangerous, but the flaw is the weakness (vulnerability) and the attacker's potential action is the threat.

37
MCQmedium

An attacker uses a tool to scan all IP addresses in a range to identify which hosts are online and what services are running. Which type of reconnaissance is this?

A.Active reconnaissance
B.Denial of Service
C.Passive reconnaissance
D.Social engineering
AnswerA

Active reconnaissance involves directly interacting with targets, such as scanning IP ranges to elicit responses revealing live hosts and services. This matches the stem's constraint: the attacker's scanning traffic touches the target, unlike passive reconnaissance, which only observes third-party data.

Why this answer

Active reconnaissance involves directly interacting with the target system to gather information, such as scanning IP addresses to identify live hosts and open services. This type of scanning generates traffic that can be detected by the target, distinguishing it from passive reconnaissance.

Exam trap

200-201 often tests the distinction between active and passive reconnaissance; the trap is that candidates may confuse scanning (active) with monitoring (passive) and select the wrong type.

How to eliminate wrong answers

Option B is wrong because a Denial of Service attack aims to disrupt availability, not gather information about hosts and services. Option C is wrong because passive reconnaissance involves collecting information without directly interacting with the target, such as monitoring network traffic or using public sources, which does not generate scan traffic. Option D is wrong because social engineering involves manipulating people to divulge information, not technical scanning of IP ranges.

38
MCQmedium

Which compliance framework specifically addresses the protection of cardholder data?

A.PCI DSS
B.GDPR
C.ISO 27001
D.HIPAA
AnswerA

PCI DSS is the payment-card industry standard governing storage, transmission and access to cardholder data, so it uniquely satisfies the stem's cardholder-data protection constraint. Other frameworks address health information, financial reporting or general security controls rather than card data specifically.

Why this answer

PCI DSS (Payment Card Industry Data Security Standard) is the compliance framework specifically designed to protect cardholder data — including credit card numbers, expiration dates, and cardholder names — for any organization that stores, processes, or transmits payment card information. It is mandated by the major card brands and enforced through acquirers and payment processors.

Exam trap

The trap is confusing privacy regulations (GDPR) or industry standards (ISO 27001) with the payment-card-specific framework — candidates may pick GDPR because it also deals with data protection, but only PCI DSS is explicitly about cardholder data.

How to eliminate wrong answers

Option B is wrong because GDPR (General Data Protection Regulation) is a European Union regulation focused on personal data privacy and protection for EU residents, not specifically cardholder data. Option C is wrong because ISO 27001 is a generic international standard for information security management systems (ISMS), not a card-specific framework. Option D is wrong because HIPAA (Health Insurance Portability and Accountability Act) governs protected health information (PHI) in the United States, not payment card data.

39
MCQmedium

A security analyst is examining a network capture and observes that an attacker is sending a large volume of SYN packets to a web server with spoofed source IP addresses. The server's connection table is filling up, and legitimate users cannot connect. Which type of attack is the analyst observing?

A.A DNS amplification attack, which uses open resolvers to send large responses to a victim.
B.A man-in-the-middle attack, which intercepts and relays traffic between two parties.
C.A Smurf attack, which uses ICMP echo requests with a spoofed source to amplify traffic.
D.A TCP SYN flood, which exhausts the server's connection table with half-open connections.
AnswerD

A TCP SYN flood sends many SYN packets with spoofed sources. The server allocates resources for each half-open connection and waits for the final ACK that never arrives, exhausting the connection table and denying service to legitimate users. This exactly matches the observed SYN volume, spoofed IPs, and full connection table, making it the correct classification.

Why this answer

The capture shows many SYN packets with spoofed sources, and the server's connection table is exhausted, blocking legitimate users. This is the classic signature of a TCP SYN flood, a denial-of-service attack that abuses the TCP three-way handshake. Smurf uses ICMP, DNS amplification uses resolvers, and man-in-the-middle intercepts traffic, so none match the observed half-open connection exhaustion.

Exam trap

The trap here is grouping all denial-of-service attacks together and overlooking that SYN floods specifically exhaust TCP connection state with spoofed half-open connections.

40
MCQhard

A security analyst is investigating a breach where an attacker gained access to a server by exploiting a vulnerability in a web application. The analyst needs to determine the type of attack that was used. The server logs show that the attacker sent a specially crafted HTTP request that caused the server to execute arbitrary code. Which type of attack is this?

A.SQL injection
B.Cross-site request forgery (CSRF)
C.Cross-site scripting (XSS)
D.Remote code execution (RCE)
AnswerD

Remote code execution occurs when an attacker can execute arbitrary code on a remote server, often by exploiting a vulnerability in a web application. The scenario describes a crafted HTTP request that causes the server to execute arbitrary code, which is the definition of RCE. This is a severe vulnerability that can lead to full system compromise. Thus, RCE is the correct answer.

Why this answer

The attacker exploited a web application vulnerability to execute arbitrary code on the server. This is the definition of remote code execution (RCE). XSS and CSRF are client-side attacks, and SQL injection is a specific type of injection that may not always lead to code execution.

The scenario clearly points to RCE as the attack type.

Exam trap

The trap here is assuming any web attack that involves crafted input is SQL injection, but the key is that the server executed arbitrary code, which is the hallmark of RCE.

41
MCQhard

A security analyst is examining a memory dump from a compromised host and finds a small piece of code that resides only in memory, has no corresponding file on disk, and injects itself into a running legitimate process. The code does not replicate to other systems. Which type of malware best describes this?

A.A fileless malware that operates in memory and injects into processes
B.A worm that spreads across the network
C.A rootkit that hides its presence by modifying the kernel
D.A trojan that disguises itself as legitimate software
AnswerA

Fileless malware resides in memory, often using PowerShell, reflective DLL injection, or process hollowing, and leaves little or no trace on disk. It typically injects into legitimate processes to evade detection. The scenario matches these characteristics: no file on disk, memory-resident, and process injection, without self-replication to other systems.

Why this answer

Fileless malware operates entirely in memory, often by injecting into legitimate processes, and leaves no file on disk. This makes it difficult to detect with traditional file-based antivirus. The absence of a disk file and the process injection behavior are the defining characteristics, distinguishing it from worms, trojans, and rootkits, which typically involve files or kernel modifications.

Exam trap

The trap here is equating any memory-resident code with a rootkit, when the absence of disk files and process injection specifically point to fileless malware.

42
Multi-Selecthard

A company is implementing a security policy to reduce risk. Which THREE activities are examples of risk mitigation? (Choose three.)

Select 3 answers
A.Implementing access controls
B.Accepting the risk without action
C.Encrypting sensitive data
D.Purchasing cyber insurance
E.Patching vulnerabilities
AnswersA, C, E

Implementing access controls directly satisfies the stem's requirement to reduce risk by limiting who can reach systems and data. Authentication, authorisation and least-privilege enforcement, typically via Microsoft Entra ID, shrink the attack surface and block unauthorised actions, lowering both likelihood and impact of a breach.

Why this answer

Implementing access controls (A) is a risk mitigation activity because it enforces authentication and authorization mechanisms (such as RBAC, least privilege, and MFA) that reduce the likelihood of unauthorized access to systems and data. Encrypting sensitive data (C) mitigates risk by protecting confidentiality, so even if data is intercepted or stolen, it remains unreadable without the proper cryptographic keys (e.g., AES-256). Patching vulnerabilities (E) mitigates risk by remediating known weaknesses (e.g., CVEs) that attackers could exploit, thereby reducing the attack surface.

Accepting the risk without action (B) is risk acceptance, not mitigation, since no controls are applied. Purchasing cyber insurance (D) is risk transference, as the financial impact is shifted to an insurer rather than reduced through technical or administrative controls.

43
Multi-Selecthard

Which THREE components are part of a Public Key Infrastructure (PKI)? (Choose three.)

Select 3 answers
A.Registration Authority (RA)
B.Symmetric encryption key
C.Digital certificate
D.Hash function
E.Certificate Authority (CA)
AnswersA, C, E

The Registration Authority verifies subscriber identity and approves or rejects certificate requests before forwarding them to the Certificate Authority for issuance. It is a core PKI component, separating identity vetting from certificate signing so the CA is not exposed to untrusted request traffic.

Why this answer

A Registration Authority (RA) is a correct component because it acts as the intermediary that verifies subscriber identity and processes certificate requests before forwarding them to the CA, offloading identity-proofing duties from the CA. A digital certificate is correct because it is the core PKI artifact—an X.509 structure binding a subject's public key to identity, signed by the CA. A Certificate Authority (CA) is correct because it is the trust anchor that issues, signs, revokes, and manages certificates, and publishes CRLs or OCSP responses.

A symmetric encryption key is not a PKI component; PKI is built on asymmetric key pairs, and symmetric keys are used for bulk data encryption outside the PKI trust framework. A hash function is a cryptographic primitive used within PKI (e.g., for signing and fingerprints) but is not itself a PKI component or role.

Exam trap

Cisco often tests the distinction between PKI components (CA, RA, digital certificate) and cryptographic primitives (hash functions, symmetric keys), so candidates mistakenly select hash functions or symmetric keys because they are associated with security, but they are not structural PKI components.

44
MCQeasy

Which term describes a weakness in a system that could be exploited by a threat?

A.Vulnerability
B.Risk
C.Exploit
D.Threat
AnswerA

A vulnerability is precisely a weakness or flaw in a system, application, or configuration that a threat actor could exploit to compromise confidentiality, integrity, or availability. This directly matches the stem's requirement for a term describing an exploitable weakness, distinguishing it from a threat (the potential attacker) or risk (the likelihood of exploitation).

Why this answer

A vulnerability is a weakness in a system, such as a missing security patch, misconfiguration, or design flaw, that a threat actor could exploit to compromise confidentiality, integrity, or availability. In the context of the 200-201 exam, this aligns with the core security concept that vulnerabilities are the specific gaps that make an asset susceptible to attack.

Exam trap

Cisco often tests the distinction between vulnerability and exploit by describing a scenario where a tool is used to break into a system, leading candidates to mistakenly select 'exploit' when the question asks for the weakness itself.

How to eliminate wrong answers

Option B (Risk) is wrong because risk is the potential for loss or damage when a threat exploits a vulnerability, not the weakness itself. Option C (Exploit) is wrong because an exploit is the actual code, technique, or tool used to take advantage of a vulnerability, not the weakness. Option D (Threat) is wrong because a threat is any potential danger (e.g., a hacker, malware, or natural disaster) that could cause harm, not the system weakness.

45
MCQeasy

A security administrator needs to verify that a downloaded file has not been altered during transit. Which cryptographic technique should be used?

A.Public key encryption
B.Symmetric encryption
C.Hashing
D.Digital signature
AnswerC

Hashing produces a fixed-length digest from file contents; recomputing it and comparing against the published value reveals any alteration, satisfying the stem's integrity-verification constraint. Encryption provides confidentiality and digital signatures provide authenticity, neither directly detecting transit modification.

Why this answer

Hashing produces a fixed-size hash that changes if the file is modified, allowing integrity verification.

46
MCQhard

A security operations center (SOC) analyst is investigating a security incident where an attacker gained initial access to a corporate network. The analyst suspects the attacker used a technique that involves exploiting a vulnerability in a public-facing web server to execute arbitrary code. Which phase of the Cyber Kill Chain does this activity represent?

A.Weaponization
B.Installation
C.Exploitation
D.Reconnaissance
AnswerC

Exploitation is the phase where the attacker leverages a vulnerability to gain access to the target system. In this scenario, the attacker exploits a vulnerability in a public-facing web server to execute arbitrary code, which is a classic example of exploitation. This phase directly follows delivery and precedes installation of persistent access.

Why this answer

The Cyber Kill Chain phase of exploitation involves taking advantage of a vulnerability to execute code on a target system. The scenario describes an attacker exploiting a web server vulnerability to run arbitrary code, which fits the exploitation phase. Reconnaissance and weaponization are preparatory, while installation is a later step for maintaining access.

Exam trap

The trap here is conflating exploitation with installation, as both involve code execution, but exploitation is about gaining initial access, while installation is about maintaining persistence.

47
MCQmedium

Which type of malware is designed to encrypt files on a victim's system and demand payment for the decryption key?

A.Rootkit
B.Worm
C.Trojan horse
D.Ransomware
AnswerD

Ransomware encrypts victim files using symmetric or hybrid cryptography, rendering data inaccessible until a decryption key is supplied. This directly matches the stem's constraint of encryption plus payment demand, distinguishing it from worms, trojans or spyware, which do not extort via cryptographic locking.

Why this answer

Ransomware is the correct answer because it is specifically designed to encrypt files on a victim's system using a symmetric or asymmetric encryption algorithm (e.g., AES-256, RSA-2048) and then demand a ransom payment, typically in cryptocurrency, in exchange for the decryption key. This type of malware directly targets data availability, a core component of the CIA triad, by rendering files inaccessible until the ransom is paid.

Exam trap

Cisco often tests the distinction between ransomware and Trojan horses, where candidates mistakenly choose Trojan horse because they associate it with malicious software that tricks users, but the key differentiator is that ransomware specifically encrypts files for extortion, whereas a Trojan horse may have various payloads like backdoors or keyloggers.

How to eliminate wrong answers

Option A is wrong because a rootkit is designed to hide the presence of other malware or processes by modifying the operating system kernel or system calls, not to encrypt files for ransom. Option B is wrong because a worm is a self-replicating malware that spreads across networks without user interaction, often consuming bandwidth or delivering payloads, but it does not inherently encrypt files for extortion. Option C is wrong because a Trojan horse disguises itself as legitimate software to trick users into installing it, but its primary purpose is to provide unauthorized remote access or steal data, not to encrypt files and demand payment.

48
Multi-Selectmedium

A security analyst is evaluating an endpoint detection and response deployment for a company that must detect fileless attacks. Which TWO techniques should the analyst expect the tool to monitor because they are commonly used by fileless malware? (Choose two.)

Select 2 answers
A.Kerberos ticket-granting service requests
B.WMI event subscription persistence
C.PowerShell script execution using encoded commands
D.Disk encryption of the system volume
E.Scheduled antivirus signature updates
AnswersB, C

Windows Management Instrumentation allows attackers to create permanent event subscriptions that execute code when triggered, without dropping a traditional executable. Because WMI is a legitimate management component, the malicious subscription can blend into normal activity. EDR products monitor WMI activity, including __EventFilter and CommandLineEventConsumer creation, to catch this common fileless persistence mechanism, so the analyst should expect this coverage.

Why this answer

Fileless malware lives in memory and abuses trusted system components instead of dropping executables on disk. PowerShell is a favorite because it is signed and ubiquitous, and encoded command lines hide the payload from casual inspection. WMI event subscriptions provide persistence that survives reboots without a file artifact.

EDR tools therefore focus on process command lines, script block logging, and WMI activity. Disk encryption, antivirus update schedules, and Kerberos TGS requests are not fileless attack techniques and would not be expected monitoring targets for this purpose.

Exam trap

The trap here is equating any suspicious-looking Windows activity, such as Kerberos requests or update tasks, with fileless malware, when the defining trait is in-memory execution through trusted system components.

49
MCQeasy

A security analyst discovers that an employee's computer is infected with malware that encrypts files and demands payment. What type of malware is this?

A.Spyware
B.Worm
C.Ransomware
D.Rootkit
AnswerC

Ransomware encrypts victim files and demands payment for the decryption key, matching the stem's description exactly. Unlike worms, which self-propagate across networks, or trojans, which disguise themselves as legitimate software, ransomware's defining mechanism is cryptographic extortion of data access.

Why this answer

Ransomware is a type of malware that encrypts files on a victim's system and demands payment (often in cryptocurrency) for the decryption key. The scenario explicitly describes file encryption and a payment demand, which are the defining characteristics of ransomware. Unlike other malware types, ransomware's primary goal is extortion through data denial, not stealth or data theft.

Exam trap

The trap here is confusing ransomware with other malware types that also cause damage or steal data, but only ransomware combines file encryption with a payment demand.

How to eliminate wrong answers

Option A is wrong because spyware is designed to secretly monitor user activity and collect information (e.g., keystrokes, browsing habits) without encrypting files or demanding payment. Option B is wrong because a worm is self-replicating malware that spreads across networks automatically, but it does not typically encrypt files or demand ransom; its primary purpose is propagation. Option D is wrong because a rootkit is used to gain and maintain privileged access to a system while hiding its presence, not to encrypt files or extort payment.

50
MCQeasy

Which of the following best describes the relationship between a vulnerability, threat, and risk in cybersecurity?

A.A vulnerability is a potential danger; a threat is a weakness; risk is the impact.
B.A vulnerability is a potential attack; a threat is a weakness.
C.Risk is eliminated when a vulnerability is patched.
D.A threat exploits a vulnerability, resulting in risk.
AnswerD

A vulnerability is a weakness; a threat is the actor or event that exploits it; risk is the resulting potential for loss. This option correctly chains the three, matching the stem's request for their relationship rather than treating them as interchangeable.

Why this answer

In cybersecurity, a threat (e.g., an attacker) exploits a vulnerability (e.g., an unpatched software flaw) to cause harm, and the likelihood and impact of that exploitation constitute risk. This aligns with the NIST SP 800-30 definition: risk is a function of the likelihood of a threat exploiting a vulnerability and the resulting impact. Without the exploitation of a vulnerability by a threat, there is no risk to the asset.

Exam trap

Cisco often tests the precise definitions of vulnerability, threat, and risk, and the trap here is confusing the terms (e.g., thinking a vulnerability is a threat or that risk disappears after patching) rather than recognizing the causal chain where a threat exploits a vulnerability to create risk.

How to eliminate wrong answers

Option A is wrong because it reverses the definitions: a vulnerability is a weakness (e.g., an open port or missing patch), not a potential danger; a threat is a potential danger (e.g., a hacker or malware), not a weakness; and risk is not simply the impact but the combination of likelihood and impact. Option B is wrong because a vulnerability is not a potential attack (an attack is an action), and a threat is not a weakness (a weakness is a vulnerability). Option C is wrong because patching a vulnerability reduces risk but does not eliminate it entirely; residual risk remains due to other vulnerabilities, threats, or incomplete coverage (e.g., a patched system may still be vulnerable to zero-day exploits or misconfigurations).

51
MCQeasy

A security analyst is investigating an alert about a workstation that is repeatedly resolving domain names for known malicious command-and-control servers. The analyst wants to determine whether the workstation is infected with malware that uses DNS for communication. Which type of malware behavior is most likely occurring?

A.DNS tunneling
B.SQL injection
C.Cross-site scripting
D.ARP spoofing
AnswerA

DNS tunneling encapsulates command-and-control traffic within DNS queries and responses, often to domains controlled by an attacker. Repeated resolution of malicious domains is a strong indicator of this behavior. The scenario describes the workstation repeatedly resolving domain names for known malicious C2 servers, which aligns with DNS tunneling used by malware to exfiltrate data or receive instructions.

Why this answer

DNS tunneling is a technique where malware encodes command-and-control or data exfiltration traffic inside DNS queries and responses. Repeated resolutions of known malicious domains from a single workstation strongly suggest this behavior. The other options describe different attack types that do not match the DNS-centric evidence in the scenario.

Exam trap

The trap here is confusing DNS tunneling with other network attacks; the key indicator is repeated DNS resolutions to malicious domains, not ARP or web-based attacks.

52
MCQmedium

A security analyst at a retail company is reviewing DNS logs and notices a workstation repeatedly resolving random-looking subdomains such as a8f3k2.example-bad.com, followed by a long TXT record response containing encoded data. No user reported visiting any website. Which technique is most likely occurring?

A.DNS tunneling used for command-and-control or data exfiltration
B.Cache poisoning of the local resolver to redirect the workstation to a malicious site
C.A domain generation algorithm used only for load balancing legitimate traffic
D.A DNS amplification attack targeting the internal recursive resolver
AnswerA

The high volume of unique, algorithmically generated subdomains combined with large TXT responses is characteristic of DNS tunneling, where an attacker encodes data or commands inside DNS queries and responses to bypass egress filtering. Legitimate DNS rarely produces this pattern, so the analyst should treat this host as compromised and begin containment.

Why this answer

Random subdomains plus oversized TXT replies from a single workstation indicate DNS tunneling, a covert channel that abuses port 53 to move data or commands past egress controls. Because DNS is almost always permitted, attackers use it for command-and-control and exfiltration. The analyst should isolate the host, capture full DNS traffic, and inspect the resolver logs for the encoded payload pattern.

Exam trap

The trap here is assuming any random-looking domain name must be a domain generation algorithm, when the oversized TXT responses reveal a covert tunneling channel rather than simple DGA beaconing.

53
Multi-Selectmedium

A security analyst is evaluating the organization's use of cryptographic algorithms. The analyst must identify which TWO algorithms are symmetric encryption algorithms that can be used for bulk data encryption. (Choose two.)

Select 2 answers
A.ECDSA
B.3DES
C.SHA-256
D.RSA
E.AES
AnswersB, E

3DES (Triple Data Encryption Standard) is a symmetric block cipher that applies DES three times with different keys. It is used for bulk data encryption, though it is slower than AES. It is still considered acceptable in some legacy systems. The scenario asks for symmetric algorithms, and 3DES is symmetric and designed for bulk encryption.

Why this answer

Symmetric encryption algorithms use a single shared key for both encryption and decryption and are efficient for bulk data. AES and 3DES are both symmetric block ciphers suitable for this purpose. RSA and ECDSA are asymmetric, and SHA-256 is a hash function, so they do not meet the criteria.

Exam trap

The trap here is confusing asymmetric algorithms like RSA with symmetric ones; RSA is often used in encryption but not for bulk data.

54
MCQhard

A security analyst is examining a suspicious executable found on a compromised host. The analyst runs the file in a sandbox and observes that it creates a mutex named 'Global\MyMutex123', attempts to connect to an external IP address on port 443, and modifies the registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Run. Which type of analysis is the analyst performing?

A.Static analysis
B.Memory forensics
C.Log analysis
D.Dynamic analysis
AnswerD

Dynamic analysis involves executing malware in a controlled environment, such as a sandbox, and observing its behavior, including process creation, network traffic, and file system changes. The analyst's observations of mutex creation, outbound connections, and registry modification are classic dynamic indicators. This approach reveals runtime actions that static analysis might miss due to obfuscation or packing.

Why this answer

Dynamic analysis is the process of executing malware in a controlled environment and observing its behavior, such as network connections, registry changes, and mutex creation. The analyst's actions in the sandbox directly match this definition. Static analysis, memory forensics, and log analysis do not involve running the sample and monitoring its runtime effects.

Exam trap

The trap here is equating sandbox execution with memory forensics, but memory forensics examines an existing memory image without running the sample.

55
MCQhard

A security analyst is reviewing a packet capture and notices that an attacker is sending a large number of SYN packets to a web server from spoofed source IP addresses. The server's connection table is filling up, and legitimate users cannot connect. Which type of attack is being described?

A.Smurf attack
B.SYN flood
C.Ping of death
D.UDP flood
AnswerB

A SYN flood is a type of denial-of-service attack where the attacker sends many SYN packets with spoofed source IP addresses. The server allocates resources for each half-open connection, eventually exhausting its connection table and preventing legitimate users from connecting. The scenario matches this exactly: spoofed SYNs, full connection table, and denial of service.

Why this answer

A SYN flood exploits the TCP three-way handshake by sending numerous SYN requests with spoofed source addresses. The server allocates resources for each half-open connection, eventually exhausting its backlog queue and denying service to legitimate clients. The scenario's description of spoofed SYNs and a full connection table confirms this attack.

Exam trap

The trap here is assuming any flood is a UDP flood; the distinguishing factor is the use of SYN packets and the TCP connection table exhaustion.

56
MCQhard

A security analyst needs to ensure that a message has not been tampered with during transit and that the sender cannot deny sending it. Which cryptographic method should be used?

A.Digital signature
B.Symmetric encryption
C.Hashing
D.Public key infrastructure (PKI)
AnswerA

A digital signature uses the sender's private key to sign a message hash, letting the recipient verify integrity via the public key and providing non-repudiation, since only the sender could have produced that signature. This satisfies both the tamper-detection and non-deniability requirements.

Why this answer

A digital signature provides both integrity (ensuring the message has not been tampered with) and non-repudiation (preventing the sender from denying they sent it). It works by hashing the message and encrypting that hash with the sender's private key; the recipient verifies the signature using the sender's public key. This cryptographic method uniquely binds the sender to the message, unlike other options that only address one of these requirements.

Exam trap

Cisco often tests the distinction between hashing (which provides integrity only) and digital signatures (which provide both integrity and non-repudiation), leading candidates to mistakenly choose hashing when non-repudiation is required.

How to eliminate wrong answers

Option B (Symmetric encryption) is wrong because it only provides confidentiality (secrecy) and does not provide integrity or non-repudiation; both parties share the same key, so the sender can deny sending the message. Option C (Hashing) is wrong because while it ensures integrity by detecting tampering, it does not provide non-repudiation since there is no key binding the hash to a specific sender. Option D (Public key infrastructure (PKI)) is wrong because PKI is a framework of policies, roles, and procedures for managing digital certificates and keys, not a cryptographic method itself; it enables digital signatures but does not directly provide integrity and non-repudiation.

57
Multi-Selectmedium

A security analyst is investigating a potential data breach. Which two actions are examples of passive reconnaissance? (Choose two.)

Select 2 answers
A.Performing a port scan on the company's web server
B.Searching for employee information on LinkedIn
C.Using a ping sweep to identify live hosts
D.Conducting a WHOIS lookup on the company domain
E.Sending a phishing email to employees
AnswersB, D

Searching LinkedIn for employee information gathers publicly available data without directly touching the target's systems, so no traffic reaches company infrastructure. This indirect, non-intrusive collection is passive reconnaissance, unlike active scanning or enumeration, which would interact with and potentially alert the target.

Why this answer

Option B is correct because searching LinkedIn for employee information is passive reconnaissance: the analyst gathers publicly available OSINT about personnel, roles, and organizational structure without sending any packets to or interacting with the target's systems, so it cannot be detected by the target. Option D is correct because a WHOIS lookup queries public registry databases (via port 43 to the registrar/RIR) for domain registration details such as registrant, admin contacts, name servers, and creation/expiry dates; this information is obtained from third-party records rather than from the target's own infrastructure, making it passive. The unmarked options do not belong: A (port scan) and C (ping sweep) are active reconnaissance techniques that directly probe the target's hosts and services and are detectable in logs or IDS/IPS, while E (phishing email) is an active social-engineering attack that interacts with employees and is not reconnaissance at all.

Exam trap

The trap here is confusing any information-gathering activity as passive; candidates often mistakenly classify ping sweeps or port scans as passive because they seem less intrusive than exploitation, but they are active and detectable.

58
MCQmedium

A company's web server is overwhelmed by traffic from multiple compromised systems, causing it to become unresponsive to legitimate users. Which type of attack is this?

A.MitM
B.DoS
C.Botnet
D.DDoS
AnswerD

A DDoS attack floods the web server with traffic from many compromised hosts, exhausting its resources so legitimate users cannot connect. This matches the scenario's constraint of multiple compromised systems overwhelming one target, distinguishing it from a single-source DoS attack.

Why this answer

(DDoS) because the scenario describes a distributed denial-of-service attack: traffic originates from multiple compromised systems (a botnet) to overwhelm the web server. A DDoS attack is a subtype of DoS that specifically uses multiple sources, making it harder to mitigate than a single-source DoS. The key clue is 'multiple compromised systems,' which directly maps to the distributed nature of a DDoS.

Exam trap

Cisco often tests the distinction between DoS and DDoS by including the phrase 'multiple compromised systems' as the key differentiator, and the trap here is that candidates may confuse the attack type (DDoS) with the infrastructure used to execute it (botnet).

How to eliminate wrong answers

Option A (MitM) is wrong because a man-in-the-middle attack intercepts or alters communication between two parties (e.g., ARP spoofing, SSL stripping), not overwhelming a server with traffic. Option B (DoS) is wrong because while a DoS attack also aims to make a service unavailable, the question explicitly states 'multiple compromised systems,' which distinguishes it as a distributed attack; a standard DoS originates from a single source. Option C (Botnet) is wrong because a botnet is the network of compromised devices used to launch the attack, not the attack itself; the question asks for the type of attack, not the infrastructure.

59
MCQeasy

A security team is reviewing the confidentiality, integrity, and availability (CIA) triad for a new file-sharing service. The service must ensure that data cannot be altered in transit by unauthorized parties. Which security principle is primarily addressed by implementing TLS for all connections?

A.Integrity
B.Confidentiality
C.Non-repudiation
D.Availability
AnswerA

Integrity ensures that data is not modified by unauthorized parties. TLS uses message authentication codes and encryption to detect tampering, thereby preserving integrity of data in transit. The scenario explicitly states the requirement to prevent unauthorized alteration, which directly maps to the integrity principle of the CIA triad.

Why this answer

The requirement to prevent unauthorized alteration of data in transit directly addresses the integrity principle of the CIA triad. TLS provides integrity through message authentication codes, ensuring that any modification is detected. While TLS also offers confidentiality, the scenario's emphasis on preventing alteration makes integrity the primary principle.

Exam trap

The trap here is focusing on the encryption aspect of TLS and selecting confidentiality, while overlooking that the scenario explicitly requires protection against unauthorized modification.

60
Multi-Selectmedium

A security team is analyzing a malware infection. Which two characteristics are typical of a worm? (Choose two.)

Select 2 answers
A.Exploits vulnerabilities to spread without user interaction
B.Requires a host file to propagate
C.Disguises itself as a legitimate program
D.Attaches to an email to spread
E.Self-replicates across networks
AnswersA, E

Exploiting vulnerabilities lets the worm propagate autonomously across networks, satisfying the stem's requirement for self-replication without user interaction. Unlike viruses, which need a host file or user action to execute, worms spread directly between systems, making this a defining characteristic of worm behaviour during malware analysis.

Why this answer

Option A is correct because a worm actively exploits vulnerabilities (for example, unpatched SMB or RDP flaws) to propagate autonomously across systems without requiring any user action such as clicking a link or opening an attachment. Option E is correct because self-replication is the defining trait of a worm: it copies itself from host to host over network connections, often scanning for new targets and consuming bandwidth. Option B is wrong because requiring a host file to propagate describes a virus, which needs to infect an executable or document, not a worm.

Option C is wrong because disguising itself as a legitimate program is characteristic of a Trojan, which relies on deception rather than self-replication. Option D is wrong because attaching to an email to spread is typical of a mass-mailing virus or email-based malware, not the network-propagating worm behavior described here.

Exam trap

The trap is confusing worm traits with virus or Trojan traits — candidates must remember that 'no user interaction' and 'self-replication across networks' are the two defining worm characteristics.

61
MCQmedium

A security analyst needs to verify the authenticity and integrity of a software update. The update is signed with a digital signature. Which key is used to verify the signature?

A.Sender's public key
B.Sender's private key
C.Recipient's public key
D.Recipient's private key
AnswerA

The sender signs with their private key, so verification requires the mathematically paired public key. This satisfies the authenticity and integrity constraint: only the matching public key validates the signature, confirming the update originated from the holder of the private key and was not altered.

Why this answer

A digital signature is created by the sender using their private key, and it is verified by anyone using the sender's public key. The public key mathematically validates that the signature was produced by the corresponding private key and that the message has not been altered. Therefore, the recipient uses the sender's public key to verify authenticity and integrity.

Exam trap

200-201 often tests the confusion between signing and encryption keys — candidates must remember that the sender's private key signs and the sender's public key verifies, while the recipient's keys are used for confidentiality, not signature verification.

How to eliminate wrong answers

Option B is wrong because the sender's private key is used to create (sign) the signature, not to verify it — sharing or using it for verification would destroy the security guarantee. Option C is wrong because the recipient's public key is used to encrypt data intended for the recipient, not to verify a signature made by the sender. Option D is wrong because the recipient's private key is used to decrypt data sent to the recipient or to sign the recipient's own messages, not to verify the sender's signature.

62
MCQmedium

A security analyst is reviewing a packet capture and notices that a host is sending TCP segments with the SYN flag set to a range of ports on a single target, but the source IP address in each segment is spoofed to a different random address. The target replies with SYN-ACK packets to those spoofed addresses, and the host never completes the handshake. Which type of attack is this host performing?

A.Smurf attack
B.UDP flood
C.SYN flood
D.Ping of death
AnswerC

A SYN flood exploits the TCP three-way handshake by sending many SYN packets, often with spoofed source addresses, so the target allocates resources for half-open connections and never receives the final ACK. The scenario describes exactly this: spoofed source IPs, SYN segments to many ports, and no completed handshakes, exhausting the target's connection table.

Why this answer

The traffic pattern shows TCP SYN segments with spoofed source addresses and no completed three-way handshakes. This exhausts the target's half-open connection resources, which is the defining behavior of a SYN flood. UDP floods, Smurf attacks, and ping of death use different protocols and packet structures.

Exam trap

The trap here is assuming any spoofed-source flood is a Smurf attack, when the protocol and packet type determine the actual attack classification.

63
MCQmedium

A security analyst is reviewing a packet capture of traffic entering the corporate network. The analyst notices a large number of TCP SYN packets sent to multiple destination ports on a single internal host, with no corresponding ACK packets. The source IP addresses are spoofed and vary across each packet. Which type of attack is this traffic MOST likely associated with?

A.UDP amplification
B.SYN flood
C.ARP poisoning
D.DNS tunneling
AnswerB

A SYN flood is a denial-of-service attack where the attacker sends many TCP SYN requests with spoofed source IPs, causing the target to allocate resources for half-open connections. The lack of ACKs and use of spoofed sources match this pattern. The goal is to exhaust the target's connection table, preventing legitimate connections.

Why this answer

The traffic pattern of numerous TCP SYN packets from spoofed sources without completing the three-way handshake is characteristic of a SYN flood. This attack exploits the TCP connection setup process to exhaust the target's resources, denying service to legitimate users. The other options involve different protocols or layers and do not match the observed packets.

Exam trap

The trap here is confusing a SYN flood with other denial-of-service attacks that also use spoofed addresses but rely on different protocols or mechanisms.

64
MCQeasy

A security analyst is reviewing a suspicious file found on a user's workstation. The file has a .docx extension but when the analyst inspects its header bytes, the file begins with the magic number for a Windows Portable Executable. The user reports the file arrived as an email attachment. Which type of malware delivery technique does this describe?

A.A file masquerading as a document but actually an executable
B.A rootkit that hides its presence on the system
C.A polymorphic virus that changes its own code to evade detection
D.A macro virus embedded in a legitimate document
AnswerA

The file uses a .docx extension to appear harmless, but its magic number shows it is a Windows Portable Executable. This masquerading technique tricks users into opening what they believe is a document, potentially executing malicious code. The mismatch between the file extension and its actual header is a strong indicator of disguised malware delivered via email attachment.

Why this answer

The file's extension claims it is a Word document, but its header bytes match a Windows Portable Executable. This is a classic masquerading technique where malware is disguised as a benign file type to trick users into executing it. The mismatch between the expected file signature and the actual content is the key indicator, distinguishing it from macro viruses, polymorphic code, or rootkits.

Exam trap

The trap here is focusing on the .docx extension and assuming a macro virus, when the header bytes reveal the file is actually an executable.

65
MCQmedium

Which encryption method uses a single key for both encryption and decryption of data?

A.Asymmetric encryption
B.Symmetric encryption
C.Digital signature
D.Hashing
AnswerB

Symmetric encryption satisfies the single-key constraint by using one shared secret for both encryption and decryption, as with AES. This contrasts with asymmetric algorithms such as RSA, which employ a public key to encrypt and a mathematically related private key to decrypt, requiring two distinct keys.

Why this answer

Symmetric encryption uses a single shared key for both encryption and decryption of data. This is the defining characteristic of symmetric algorithms like AES, DES, and 3DES, where the same secret key must be known to both sender and receiver to protect confidentiality.

Exam trap

Cisco often tests the distinction between symmetric and asymmetric encryption by presenting a scenario where a single key is used, and candidates may confuse 'single key' with the public key in asymmetric encryption, leading them to incorrectly select asymmetric encryption.

How to eliminate wrong answers

Option A is wrong because asymmetric encryption uses a pair of keys (public and private) for encryption and decryption, not a single key. Option C is wrong because a digital signature is a cryptographic mechanism for authentication and non-repudiation, not an encryption method; it uses asymmetric keys to sign and verify, not to encrypt data. Option D is wrong because hashing is a one-way function that produces a fixed-size digest and cannot be reversed to recover the original data, so it does not support both encryption and decryption.

66
Multi-Selectmedium

A security analyst is reviewing logs from a web server and notices a high volume of HTTP requests from a single IP address targeting the same login page within a short time frame. The analyst suspects a brute force attack. Which TWO actions are most appropriate to mitigate this type of attack? (Choose two.)

Select 2 answers
A.Implement rate limiting on the login endpoint.
B.Disable the login page entirely.
C.Block all traffic from the offending IP address permanently.
D.Increase the password complexity requirements.
E.Implement account lockout after a certain number of failed attempts.
AnswersA, E

Rate limiting caps requests per source within a time window, throttling the high-volume login attempts the stem describes. This directly addresses the brute force constraint by slowing credential guessing, making automated attacks impractical without blocking legitimate users.

Why this answer

Option A is correct because rate limiting on the login endpoint directly throttles the high volume of repeated HTTP requests from a single IP address, which is the defining signature of the brute force attack observed in the logs. Option E is correct because account lockout after a certain number of failed attempts stops an attacker from making unlimited password guesses against a given account, complementing rate limiting by protecting the credential itself rather than just the request rate. Option B is not appropriate because disabling the login page entirely would deny legitimate users access and cause a self-inflicted denial of service.

Option C is not the best mitigation because permanently blocking the offending IP address is brittle—attackers can rotate IPs, and legitimate users behind shared or dynamic addresses could be blocked—so it is not a sustainable control. Option D is not appropriate because increasing password complexity requirements is a preventive policy for credential strength and does not stop the ongoing high-volume request pattern of a brute force attack.

Exam trap

The trap here is that candidates may choose permanent IP blocking or disabling the login page as immediate fixes, but these are either too disruptive or easily bypassed; the exam expects understanding of layered, non-disruptive mitigations like rate limiting and account lockout.

67
MCQmedium

Which type of malware is designed to replicate itself and spread to other systems without user intervention?

A.Virus
B.Ransomware
C.Trojan
D.Worm
AnswerD

A worm self-replicates and propagates across networks autonomously, exploiting vulnerabilities or weak credentials without requiring a user to open a file or click a link. This matches the stem's constraint of spreading without user intervention, unlike viruses, which need host execution.

Why this answer

A worm is malware that self-replicates and spreads to other systems automatically, without requiring user interaction or a host program. It typically exploits network vulnerabilities or weak credentials to propagate across networks. This autonomous spreading behavior is the defining characteristic that distinguishes worms from other malware types.

Exam trap

200-201 often tests the distinction between viruses and worms — candidates must remember that worms self-replicate without user intervention, while viruses require a host and user action to spread.

How to eliminate wrong answers

Option A is wrong because a virus requires a host file and some form of user action (such as opening an infected attachment) to execute and spread — it does not self-replicate autonomously. Option B is wrong because ransomware is designed to encrypt data and demand payment; while it may spread via other mechanisms, its defining purpose is extortion, not self-replication. Option C is wrong because a Trojan disguises itself as legitimate software and relies on the user installing and running it — it does not self-replicate or spread on its own.

68
MCQeasy

A security analyst at a mid-sized company is reviewing the organization's risk management strategy. The CIO asks the analyst to describe the primary purpose of a vulnerability assessment. Which statement best describes this purpose?

A.It automatically applies patches to all discovered software flaws without human intervention.
B.It identifies, quantifies, and prioritizes vulnerabilities in a system.
C.It actively exploits vulnerabilities to determine the level of access an attacker could achieve.
D.It provides a real-time dashboard of all security incidents occurring on the network.
AnswerB

A vulnerability assessment systematically scans and evaluates systems to discover weaknesses, then ranks them by severity and potential impact. It does not exploit flaws or simulate an active adversary, but it provides the inventory needed to plan remediation. In this scenario, the analyst would use tools such as vulnerability scanners to produce a prioritized list that helps the CIO allocate patching resources efficiently.

Why this answer

A vulnerability assessment is a systematic review that identifies, quantifies, and prioritizes security weaknesses in an environment. It differs from a penetration test because it does not exploit flaws or simulate an attacker; instead, it produces a list of vulnerabilities ranked by severity so that remediation efforts can be planned. This makes it a foundational risk management activity.

Exam trap

The trap here is confusing a vulnerability assessment with a penetration test, which actively exploits flaws to demonstrate impact.

69
MCQeasy

A security analyst discovers that an attacker is using a vulnerability scanning tool to identify open ports on the company's network. Which type of attack is being performed?

A.Social engineering
B.Passive reconnaissance
C.Active reconnaissance
D.Denial of Service
AnswerC

Active reconnaissance involves directly interacting with the target to gather information, such as port scanning, which generates traffic and can be detected. Vulnerability scanning tools probing open ports are actively engaging the network, distinguishing this from passive reconnaissance.

Why this answer

Active reconnaissance involves directly interacting with the target system to gather information, such as port scanning, vulnerability scanning, or banner grabbing. Using a vulnerability scanning tool to identify open ports sends packets to the target and elicits responses, which is the definition of active reconnaissance. This contrasts with passive reconnaissance, which collects information without direct interaction.

Exam trap

The trap is confusing active vs. passive reconnaissance; candidates often think 'scanning' is passive because it's information gathering, but any direct interaction with the target is active.

How to eliminate wrong answers

Option A is wrong because social engineering manipulates people into revealing information, not technical scanning of ports. Option B is wrong because passive reconnaissance gathers information from public sources (e.g., WHOIS, DNS records, social media) without touching the target's systems. Option D is wrong because a Denial of Service attack aims to disrupt availability, not enumerate open ports.

70
MCQeasy

Which NIST Cybersecurity Framework function involves developing and implementing appropriate safeguards to ensure delivery of critical infrastructure services?

A.Respond
B.Detect
C.Identify
D.Protect
AnswerD

The Protect function covers safeguards that limit or contain the impact of a cybersecurity event, including access control, awareness training, data security and protective technology. Developing and implementing these safeguards to ensure delivery of critical infrastructure services is its stated purpose.

Why this answer

The Protect function of the NIST Cybersecurity Framework involves developing and implementing appropriate safeguards to ensure delivery of critical infrastructure services. It covers access control, awareness training, data security, protective technology, and maintenance. This function limits or contains the impact of a potential cybersecurity event.

Exam trap

200-201 often tests the boundaries between CSF functions — candidates must distinguish Protect (safeguards) from Detect (monitoring) and Identify (asset and risk understanding), since all three sound related but address different phases.

How to eliminate wrong answers

Option A is wrong because Respond involves taking action regarding a detected cybersecurity incident — activities like response planning, communications, analysis, mitigation, and improvements occur after an event. Option B is wrong because Detect involves developing and implementing activities to identify the occurrence of a cybersecurity event, such as continuous monitoring and detection processes. Option C is wrong because Identify involves understanding the cybersecurity risks to systems, people, assets, data, and capabilities — it is about inventory and risk assessment, not safeguards.

71
MCQhard

An attacker intercepts communication between a client and server and modifies the data being transmitted. The client and server are unaware of the modification. Which type of attack is being performed?

A.Man-in-the-Middle
B.ARP spoofing
C.DNS poisoning
D.Replay attack
AnswerA

A man-in-the-middle attack places the adversary inline between client and server, letting them relay and alter transmitted data while both endpoints believe they communicate directly. This interception plus undetected modification is precisely the behaviour described in the scenario.

Why this answer

A Man-in-the-Middle (MITM) attack occurs when an attacker secretly relays and possibly alters the communication between two parties who believe they are directly communicating with each other. In this scenario, the attacker intercepts and modifies the data in transit, and neither the client nor the server detects the modification, which is the hallmark of a MITM attack. MITM is a broad category that encompasses various techniques, including ARP spoofing and DNS poisoning, but the core definition is the active interception and modification of traffic.

Exam trap

200-201 often tests the distinction between broad attack categories and specific techniques, so candidates may incorrectly choose a specific method like ARP spoofing or DNS poisoning when the question describes the general behavior of a MITM attack.

How to eliminate wrong answers

Option B is wrong because ARP spoofing is a specific technique used to enable a MITM attack by poisoning the ARP cache to associate the attacker's MAC address with the IP address of a legitimate host, but it does not inherently include modification of data; it is a means to an end. Option C is wrong because DNS poisoning (or DNS spoofing) involves corrupting DNS records to redirect traffic to a malicious site, but it does not necessarily involve intercepting and modifying data between a client and server; it is a redirection attack. Option D is wrong because a replay attack involves capturing valid data transmission and retransmitting it later to produce an unauthorized effect, but it does not involve modifying the data; the data is simply repeated.

72
MCQmedium

A security analyst is reviewing the access control strategy for a research and development department. The department handles highly sensitive intellectual property, and the organization wants to ensure that employees can only access information strictly necessary for their current project tasks, even if they have previously worked on other projects. Which access control principle is being enforced?

A.Mandatory access control
B.Separation of duties
C.Need to know
D.Least privilege
AnswerC

Need to know restricts access to information only to individuals who require it to perform their specific duties. In this scenario, employees should only access data necessary for their current project tasks, aligning with the need-to-know principle. It ensures that even if an employee had access to other projects previously, that access is revoked when no longer needed.

Why this answer

The need-to-know principle ensures that access to information is granted only to individuals whose current responsibilities require that specific information. In this scenario, the organization wants to restrict access to intellectual property based on project tasks, which directly reflects need-to-know. Least privilege is about minimum permissions, but need-to-know is more granular and focuses on information relevance to the task.

Exam trap

The trap here is confusing need to know with least privilege, as both limit access, but need to know is specifically about information relevance to a task, while least privilege is about minimum permissions for a role.

73
MCQmedium

A security analyst is reviewing a packet capture and observes that a workstation is sending a large volume of TCP SYN packets to many different destination IP addresses on port 445, with no corresponding completed handshakes. The analyst suspects malware is performing reconnaissance. Which type of activity is this workstation most likely performing?

A.A man-in-the-middle attack intercepting SMB traffic
B.TCP port scanning of many hosts on port 445
C.A SYN flood denial-of-service attack against a single target
D.A brute-force attack against SMB credentials
AnswerB

Sending TCP SYN packets to many destination IP addresses on the same port, without completing the three-way handshake, is classic TCP SYN scanning. The goal is to discover which hosts have port 445 (SMB) open. The broad destination range indicates host discovery across a subnet, which matches reconnaissance behavior often performed by worms or scanning malware.

Why this answer

The traffic pattern of many TCP SYN packets to numerous destination addresses on a single port, with no completed handshakes, is the signature of TCP SYN scanning. This is a reconnaissance technique used to identify live hosts and open services, commonly on port 445 for SMB. A SYN flood would focus on one target, and brute-force or man-in-the-middle activity would require established connections.

Exam trap

The trap here is assuming any flood of SYN packets is a SYN flood DoS, when the distinguishing factor is whether the packets target one host or many hosts for discovery.

74
MCQeasy

Which element of the CIA triad is primarily compromised when an attacker successfully intercepts and reads encrypted network traffic without authorization?

A.Non-repudiation
B.Confidentiality
C.Integrity
D.Availability
AnswerB

Confidentiality guarantees data is readable only by authorised parties. Intercepting and reading encrypted traffic without authorisation exposes the plaintext content to an unintended party, so the confidentiality element of the CIA triad is the one primarily compromised.

Why this answer

Confidentiality ensures data is not disclosed to unauthorized parties. When an attacker intercepts and reads encrypted traffic, the confidentiality of that data is breached because the adversary gains access to information they were not authorized to see. Integrity concerns unauthorized modification, and availability concerns disruption of access, neither of which is the primary impact of a read-only interception.

Exam trap

The trap here is conflating confidentiality with integrity when the scenario involves interception; candidates often assume any network attack compromises integrity, but a read-only interception specifically targets confidentiality.

How to eliminate wrong answers

Option A is wrong because non-repudiation is not one of the three CIA triad elements; it is a separate security property ensuring a party cannot deny having performed an action, typically provided by digital signatures. Option C is wrong because integrity refers to protecting data from unauthorized alteration, whereas the scenario describes reading/interception, not modification. Option D is wrong because availability refers to ensuring systems and data are accessible to authorized users when needed, which is not affected by passive interception.

75
MCQmedium

A security analyst is reviewing network traffic and observes a large number of DNS queries for randomly generated domain names, such as 'a1b2c3d4e5f6g7h8.com', from a single internal host. The queries are followed by responses with very short TTL values. The analyst suspects the host is compromised. Which type of malicious activity is most likely occurring?

A.Fast flux DNS used to hide the location of a botnet controller
B.DNS cache poisoning attack against the internal resolver
C.Domain generation algorithm (DGA) used by malware for command-and-control (C2) communication
D.DNS tunneling used to exfiltrate sensitive data
AnswerC

DGA malware generates many pseudo-random domain names to avoid static blocklists and to locate its C2 server. The short TTLs and high volume of unique, random-looking queries from one host strongly indicate DGA activity. The host is likely attempting to resolve one of the domains that the attacker has registered to establish C2.

Why this answer

The high volume of unique, random-looking domain queries with short TTLs from a single host is a classic indicator of a domain generation algorithm. Malware uses DGA to periodically generate many domain names and attempt to resolve them, hoping to find the one registered by the attacker for command and control. This evades static domain blocklists and makes takedown difficult.

Exam trap

The trap here is confusing DGA with DNS tunneling or fast flux; DGA involves many random domains, while tunneling uses one domain with encoded data, and fast flux uses one domain with changing IPs.

Page 1 of 2 · 143 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Cbrops Security Concepts questions.