Courseiva

CCNA Cbrops Security Monitoring Questions

9 of 159 questions · Page 3/3 · Cbrops Security Monitoring topic · Answers revealed

151
MCQeasy

An analyst is reviewing a Windows event log and sees Event ID 4625 repeated many times for the same user account from different source workstations within a short period. Which activity does this most likely indicate?

A.A successful privilege escalation by a domain administrator
B.A brute-force or password-spraying attack against the account
C.A user account lockout due to a stale cached credential
D.Normal user behavior when a password has expired
AnswerB

Event ID 4625 is generated on failed logon attempts. A high volume of these events for one account, especially from multiple source workstations, suggests an attacker is trying many passwords. Password spraying uses a few common passwords across many accounts, but repeated failures for a single account from different hosts also align with brute-force or credential-stuffing activity targeting that account.

Why this answer

Repeated Windows Event ID 4625 entries for one account from multiple source workstations indicate many failed logon attempts, which is the signature of a brute-force or password-spraying attack. Legitimate causes such as expired passwords or stale cached credentials would not produce this volume or diversity of source hosts, so the activity should be investigated as a credential attack.

Exam trap

The trap here is treating all 4625 events as routine user error, when a high volume from multiple hosts signals an active credential attack.

152
MCQmedium

An analyst is reviewing IDS alerts and sees an alert with signature name 'ET POLICY Suspicious inbound to MySQL port 3306'. The source IP is external and destination is an internal database server. What is the best immediate action?

A.Allow the traffic because it is a legitimate database query
B.Ignore the alert as it is a false positive
C.Disable the signature to reduce noise
D.Block the external IP at the firewall
AnswerD

Blocking the external source at the firewall immediately stops further inbound attempts to the MySQL port, containing the threat while investigation proceeds. This satisfies the need for the fastest containment action against a confirmed external probe of an internal database.

Why this answer

An inbound connection from an external IP to a MySQL server (port 3306) is highly suspicious — MySQL is a database service that should never be exposed directly to the internet. The immediate best action is to block the external IP at the firewall to prevent potential exploitation, data exfiltration, or brute-force attacks. This aligns with the principle of least privilege and defense-in-depth, as database servers should only accept connections from trusted internal hosts.

Exam trap

Cisco often tests the misconception that IDS alerts should be analyzed for false positives before taking action, but in this scenario, the immediate risk of an external connection to a database port demands a blocking response first, with analysis to follow.

How to eliminate wrong answers

Option A is wrong because allowing the traffic assumes it is legitimate, but external inbound MySQL traffic is almost always malicious or misconfigured — legitimate database queries should come from internal application servers, not the public internet. Option B is wrong because ignoring the alert as a false positive is premature without investigation; while some alerts may be false positives, an inbound connection to a database port from an external source warrants immediate action due to the high risk. Option C is wrong because disabling the signature reduces visibility and increases risk — the signature is correctly firing on suspicious behavior, and disabling it would allow future attacks to go undetected.

153
MCQmedium

A security engineer is setting up a Snort rule to detect FTP traffic where the source IP is not from the internal network. Which Snort rule header correctly specifies the action, protocol, source, and destination?

A.alert tcp !$HOME_NET any -> any 21
B.alert tcp $HOME_NET any -> any 21
C.alert tcp any any -> any 21
D.alert udp any any -> any 21
AnswerA

The `!$HOME_NET` negation operator matches any source outside the defined internal network, satisfying the "not from the internal network" constraint. `alert tcp` sets the action and protocol, `any` covers all source ports, and `-> any 21` targets FTP destination port 21 on any host.

Why this answer

The rule header alert tcp !$HOME_NET any -> any 21 correctly specifies: action (alert), protocol (tcp), source (!$HOME_NET, i.e., NOT the internal network), source port (any), direction (->), destination (any), and destination port (21, FTP). The ! negation operator inverts the HOME_NET variable, so the rule fires only when the source is external — exactly what the engineer wants.

Exam trap

200-201 often tests Snort header syntax, and candidates forget that ! negates the variable — they pick $HOME_NET thinking it means 'external' when it actually means 'internal,' or they choose UDP for FTP, which is TCP-only.

How to eliminate wrong answers

Option B is wrong because $HOME_NET (without !) matches traffic originating from the internal network, which is the opposite of the requirement. Option C is wrong because 'any any' matches all sources including internal, so it does not restrict to external sources. Option D is wrong because it specifies udp, but FTP uses TCP (control on 21, data on 20 or passive ports), so the rule would never match FTP traffic.

154
Multi-Selectmedium

An analyst is investigating a potential compromise using Indicators of Compromise (IoCs). Which TWO of the following are valid types of IoCs?

Select 2 answers
A.User name
B.IP address
C.Geographic location
D.File hash (MD5)
E.Protocol name
AnswersB, D

An IP address is a network-level IoC, recording the source or destination of malicious traffic such as command-and-control contact. It satisfies the stem's requirement for a valid IoC type because it provides concrete, observable evidence of compromise that analysts can correlate across logs and block at perimeter controls.

Why this answer

Option B (IP address) is a valid IoC because a specific IP address associated with command-and-control (C2) servers, malicious scanning, or exfiltration traffic is a concrete, observable network artifact that analysts can search for in firewall, IDS/IPS, and proxy logs. Option D (File hash (MD5)) is a valid IoC because a cryptographic hash such as an MD5 digest uniquely identifies a known malicious file, allowing endpoint and antivirus tools to detect that exact sample without relying on its filename. By contrast, option A (User name) is generally not an IoC by itself, since usernames are not inherently malicious and are too common to serve as reliable compromise indicators.

Option C (Geographic location) is not a valid IoC type on its own, as geolocation is a derived attribute of an IP address rather than a distinct indicator. Option E (Protocol name) is not a valid IoC, because protocols like HTTP or DNS are legitimate, ubiquitous communication methods and only become suspicious in specific contexts, not as standalone indicators.

Exam trap

Cisco often tests the distinction between an IoC (a specific, observable artifact of compromise) and contextual or behavioral data (like usernames or geographic locations) that may be useful in an investigation but are not valid IoCs themselves.

155
MCQmedium

An analyst sees a Snort alert with the message 'ET POLICY Outbound connection to known malicious IP'. What does this indicate?

A.A malicious IP is connecting to an internal host.
B.The firewall blocked the connection.
C.An internal host is connecting to an IP that is on a threat intelligence blacklist.
D.The connection is encrypted and safe.
AnswerC

The signature name identifies an outbound connection from an internal host to an IP address listed on a threat intelligence blacklist, indicating possible command-and-control or data exfiltration traffic. The rule triggers on the destination reputation, not on payload content, so it flags the connection itself as suspicious.

Why this answer

Snort signature-based IDS alerts on matching rules. This alert indicates a connection from an internal host to a known malicious IP address, likely a command-and-control server.

156
Multi-Selectmedium

A SOC analyst is tuning Cisco Firepower intrusion policies and reviewing alert metadata to prioritize response. Which TWO alert attributes most directly indicate that a detected event represents a successful compromise rather than a blocked attempt? (Choose two.)

Select 2 answers
A.The alert action is recorded as 'Blocked'
B.The rule's signature is classified with a high severity level
C.The event's source is an external IP and the destination is an internal server
D.Subsequent correlated events show the target initiating outbound connections to a known C2 server
E.The alert's impact flag is set to 'Vulnerable'
AnswersD, E

Post-exploitation callback traffic from the target to a known command-and-control address is strong evidence that the earlier exploit succeeded and the host is now under adversary control. Correlation between the initial intrusion event and later outbound C2 activity links cause and effect. This behavioral evidence outweighs static metadata such as severity or direction when assessing compromise.

Why this answer

Successful compromise is indicated by evidence that the target was actually affected, not merely targeted. An impact flag of Vulnerable shows the host matched the exploit's affected configuration, and later outbound connections to known C2 infrastructure demonstrate post-exploitation control. Blocked actions, severity levels, and traffic direction describe the attempt or its potential, but not confirmed success.

Exam trap

The trap here is treating a high-severity signature or a Blocked action as proof of compromise when neither demonstrates that the target host was actually exploited.

157
MCQeasy

An analyst needs to establish a normal traffic pattern baseline for the network. Which activity is most appropriate for this purpose?

A.Capture traffic during a known attack to identify anomalies
B.Use only firewall logs as they are the most reliable
C.Average traffic from multiple different organizations
D.Capture traffic over a period of normal operation, such as a week
AnswerD

Capturing traffic across a representative period such as a week captures diurnal and weekly usage variation, producing a baseline that reflects genuine normal operation. Short captures miss periodic activity, so this duration satisfies the requirement for a reliable traffic-pattern baseline.

Why this answer

Establishing a baseline requires capturing traffic during a period of normal operation, typically over a week, to account for daily and weekly usage patterns. This baseline represents the typical volume, protocol mix, and flow characteristics, enabling the analyst to later detect deviations that may indicate security incidents. Using a representative sample from normal conditions is the foundational step in anomaly-based monitoring.

Exam trap

Cisco often tests the misconception that baselines can be derived from attack traffic or external averages, but the key is that a baseline must be network-specific and captured during normal operations to serve as a valid reference for anomaly detection.

How to eliminate wrong answers

Option A is wrong because capturing traffic during a known attack provides a sample of malicious activity, not a baseline of normal behavior; baselines must reflect benign patterns to identify anomalies. Option B is wrong because firewall logs alone are insufficient for a comprehensive baseline; they lack visibility into internal traffic, application-layer protocols, and non-firewalled segments, and they may miss encrypted or lateral movement traffic. Option C is wrong because averaging traffic from multiple different organizations introduces irrelevant patterns due to differing network architectures, user behaviors, and business operations; a baseline must be specific to the network being monitored.

158
MCQhard

An analyst is triaging a host that antivirus flagged for a file named svchost.exe running from C:\Users\Public\Downloads. The file has a valid digital signature issued to a legitimate software publisher, and the hash matches a known-good installer component. The process is making outbound SMB connections to several internal servers. Which action best reflects sound security monitoring practice?

A.Close the alert as a false positive because the signature and hash both verify as trusted.
B.Escalate for investigation because a signed binary executing from a user-writable path and initiating internal SMB sessions is anomalous.
C.Ignore the alert because the process name matches a legitimate Windows system binary.
D.Immediately delete the file and the user profile, then document the incident as remediated.
AnswerB

The combination of an unexpected path under a world-writable directory, a system-process name, and outbound SMB connections to multiple internal servers is a strong behavioural anomaly regardless of signature validity. Signed binaries are routinely abused for lateral movement, so the analyst should preserve volatile data and investigate parent process, logon session, and network peers before clearing the alert.

Why this answer

Signature validity and hash reputation address integrity, not intent or context. A trusted binary in a user-writable directory that opens SMB sessions to multiple internal servers is a behavioural red flag consistent with abuse for lateral movement, so the analyst should escalate, preserve evidence, and determine scope rather than dismiss or prematurely remediate the alert.

Exam trap

The trap here is equating a valid digital signature with proof of benign behaviour, when signatures only attest to the publisher and file integrity, not to how or why the binary is running.

159
Multi-Selecteasy

A security analyst is creating a network baseline for normal traffic patterns. Which TWO metrics should be included to detect anomalies?

Select 2 answers
A.Average bandwidth usage per hour
B.Geolocation of source IPs
C.Number of connections per host
D.MAC addresses of devices
E.CPU utilization of servers
AnswersA, C

Average bandwidth usage per hour establishes a quantitative norm for traffic volume, so deviations such as sudden spikes or sustained drops become detectable against the baseline. It directly satisfies the stem's requirement for metrics that reveal anomalies in normal traffic patterns, complementing flow-based measures like protocol distribution or connection counts.

Why this answer

Average bandwidth usage per hour (A) is correct because establishing a normal throughput baseline per time interval lets the analyst spot deviations such as traffic spikes, data exfiltration, or denial-of-service conditions that exceed the expected range. Number of connections per host (C) is correct because connection counts per host reveal abnormal session behavior, such as scanning, beaconing, or worm propagation, that would stand out against the established norm. Geolocation of source IPs (B) is useful context for investigating suspicious traffic but is not itself a traffic-pattern metric for a baseline.

MAC addresses of devices (D) are Layer 2 identifiers used for asset inventory or access control, not for measuring normal traffic patterns. CPU utilization of servers (E) is a host performance metric, not a network traffic baseline metric.

Exam trap

Cisco often tests the distinction between network traffic metrics and host/system metrics, so the trap here is confusing server CPU utilization (a host metric) with network baseline metrics, leading candidates to incorrectly select it as a valid network anomaly detection parameter.

← PreviousPage 3 of 3 · 159 questions total

Ready to test yourself?

Try a timed practice session using only Cbrops Security Monitoring questions.