Courseiva

CCNA Security Operations Questions

75 of 164 questions · Page 1/3 · Security Operations · Answers revealed

1
MCQhard

An organization uses an EDR solution and wants to detect ransomware that encrypts files and then deletes volume shadow copies. Which EDR detection technique would be most effective for this behavior?

A.Signature-based detection using file hashes
B.Behavioral detection for mass file modifications and vssadmin.exe execution
C.Allowlisting of trusted applications
D.Network traffic analysis to detect C2 communication
AnswerB

Ransomware's destructive sequence — rapid mass file encryption followed by vssadmin.exe deleting shadow copies — is a behavioural pattern, not a signature. Detecting that combination of mass modification and shadow-copy deletion catches the attack regardless of malware family, satisfying the requirement to detect this specific behaviour.

Why this answer

Behavioral detection monitors runtime behavior like file encryption and shadow copy deletion, which are indicative of ransomware.

2
MCQmedium

A security analyst is reviewing a vulnerability scan report for a web application. The report shows a high-severity finding for a SQL injection vulnerability on a login page. The analyst needs to validate the finding before escalating to the development team. Which of the following actions should the analyst take to safely validate the vulnerability?

A.Run a full vulnerability scan with credentials to confirm the finding.
B.Use an automated SQL injection tool to dump the database schema.
C.Review the application source code for parameterized queries.
D.Manually inject a benign SQL payload that returns a database error, such as a single quote.
AnswerD

Injecting a single quote is a safe, non-destructive way to test for SQL injection. If the application returns a database error, it indicates improper input sanitization and potential SQL injection. This method validates the finding without extracting data or modifying the database, making it suitable for a production environment. It is a standard manual validation technique.

Why this answer

Manual injection of a benign payload like a single quote is a safe and effective way to validate SQL injection. It tests the application's input handling without extracting data or causing damage. If a database error is returned, the vulnerability is confirmed.

This approach is minimally invasive and suitable for production systems, allowing the analyst to escalate with confidence.

Exam trap

The trap here is thinking that exploiting the vulnerability (e.g., dumping the schema) is necessary for validation, when a simple error-based test is sufficient and safer.

3
MCQeasy

A security team is implementing deception technology to detect attackers inside the network. They plan to deploy fake systems that appear vulnerable and attract attackers. Which of the following is an example of a honeytoken?

A.A network segment with multiple decoy systems
B.A fake DNS entry for a non-existent domain
C.A virtual machine running a vulnerable web server
D.A fake database credential file that triggers an alert when opened
AnswerD

A honeytoken is a decoy artefact, not a full system, that alerts on unauthorised access. A planted credential file triggers detection the moment an attacker opens or exfiltrates it, satisfying the requirement for a lure that reveals insider intrusion without exposing real assets.

Why this answer

A honeytoken is a piece of decoy data or a credential artifact — such as a fake database credential file, API key, or document — that has no legitimate use, so any access to it signals malicious activity and triggers an alert. Option D describes exactly this: a fake credential file that fires an alert when opened. The other options describe broader deception constructs (honeynets, honeypots, fake DNS records) rather than a discrete token of data.

Exam trap

The trap is conflating honeytokens with honeypots or honeynets — candidates pick the decoy system or decoy network because they sound similar, but a honeytoken is specifically a discrete data artifact (credential, file, key) whose access triggers an alert.

How to eliminate wrong answers

Option A is wrong because a network segment with multiple decoy systems is a honeynet, not a honeytoken — it is an environment of decoys, not a single data artifact. Option B is wrong because a fake DNS entry is a decoy record used for DNS sinkholing or detection of name-resolution abuse, not a honeytoken, which is data meant to be consumed. Option C is wrong because a VM running a vulnerable web server is a honeypot — an entire decoy host designed to attract exploitation — whereas a honeytoken is a smaller, embedded data object.

4
MCQmedium

A security analyst is investigating a suspected DNS tunneling attack. The analyst observes a high volume of DNS queries to a single domain, with query names that appear to be Base64-encoded strings. Which of the following is the MOST effective way to confirm and analyze this activity?

A.Capture full packet data and decode the query names to look for hidden data
B.Check the reputation of the destination DNS server IP address
C.Monitor for an increase in DNS response time
D.Review firewall logs for allowed outbound DNS traffic
AnswerA

DNS tunneling encodes data in DNS query names or responses. Capturing full packets allows the analyst to extract the query strings, decode them (e.g., Base64), and examine the payload. This confirms tunneling and reveals exfiltrated or command-and-control data. Other methods may indicate tunneling but do not provide the actual content for analysis.

Why this answer

DNS tunneling hides data within DNS queries and responses. To confirm and analyze it, the analyst must capture the actual DNS packets and decode the query names, which often contain Base64 or hex-encoded payloads. This reveals the exfiltrated data or C2 commands.

The other options may provide circumstantial evidence but do not directly analyze the tunneled content.

Exam trap

The trap here is focusing on network-level indicators like IP reputation or response times instead of examining the actual DNS payload for encoded data.

5
Multi-Selecteasy

A penetration tester is planning a test against a web application. The rules of engagement specify that the tester must not disrupt production services. Which TWO reconnaissance techniques are considered passive and would be appropriate for initial information gathering without impacting the target? (Select TWO.)

Select 2 answers
A.Port scanning the target network
B.Vulnerability scanning
C.Social engineering attacks
D.WHOIS lookup on the domain
E.OSINT gathering from public sources
AnswersD, E

A WHOIS lookup queries public registrar databases rather than the target's own infrastructure, so no packets reach the web application and production services remain untouched. This satisfies the rules of engagement constraint prohibiting disruption, making it suitable for initial passive information gathering before any active enumeration begins.

Why this answer

WHOIS lookup on the domain (D) is correct because it queries public registrar databases for registration details such as registrant contacts, name servers, and creation/expiration dates, generating no traffic to the target's own infrastructure and thus causing zero disruption. OSINT gathering from public sources (E) is correct because it collects information from third-party sites, search engines, cached pages, and public records, again without sending packets to the target and therefore remaining passive and non-disruptive. Port scanning (A) is not passive: it sends TCP/UDP probes (e.g., SYN or connect scans) directly to target hosts, which can be logged, rate-limited, or destabilize fragile services.

Vulnerability scanning (B) is also active and intrusive, as it transmits crafted requests and payloads that can crash or overload production systems. Social engineering attacks (C) are neither passive reconnaissance nor non-disruptive, since they involve direct interaction with personnel and can cause operational or security incidents.

Exam trap

The trap here is conflating 'non-intrusive' with 'passive' — candidates often pick vulnerability scanning because it can be run in a low-impact mode, but any technique that sends packets to the target is active by definition.

6
MCQmedium

A security operations center (SOC) analyst receives an alert from the SIEM indicating a user has logged into the corporate VPN from an unusual geographic location at 3 AM, which is outside the user's normal working hours. The user has not previously exhibited this behavior. Which advanced SIEM capability is most likely responsible for generating this alert?

A.User Behavior Analytics (UBA)
B.Correlation rule based on static thresholds
C.Signature-based detection
D.Threat intelligence feed correlation
AnswerA

User Behaviour Analytics baselines each user's normal login patterns — location, time, device — and flags statistically anomalous deviations. The 3 AM foreign VPN login falls outside the established baseline, so UBA generates the alert rather than static correlation rules.

Why this answer

User Behavior Analytics (UBA) uses machine learning to establish a baseline of normal user activity and detect anomalies such as unusual login times and locations. This is a core feature of advanced SIEM platforms.

7
MCQmedium

A security operations center (SOC) is deploying a new endpoint detection and response (EDR) solution across 10,000 endpoints. The team wants to ensure that if the EDR agent is disabled or tampered with, the SOC is immediately alerted and the endpoint can be isolated. Which EDR capability should the team prioritize?

A.Full disk encryption with key escrow
B.Tamper protection with automated response actions
C.Continuous signature updates from the vendor
D.Integration with a SIEM for log forwarding
AnswerB

Tamper protection prevents unauthorized disabling of the EDR agent, and automated response actions such as host isolation can be triggered when tampering is detected. This directly addresses the requirement to alert and isolate. Other features like signature updates or forensic analysis do not provide real-time tamper detection and response.

Why this answer

The requirement is to detect tampering and respond by isolating the endpoint. Tamper protection ensures the EDR agent cannot be easily disabled, and automated response actions can isolate the host. Other options focus on detection updates, logging, or encryption, which do not provide the needed tamper detection and immediate isolation.

Exam trap

The trap here is assuming that SIEM integration alone provides tamper detection and response, when it only forwards logs and does not prevent agent disablement.

8
MCQeasy

An organization wants to share threat intelligence with industry peers using a standardized format. Which of the following formats is specifically designed for representing structured threat information in a machine-readable way?

A.CyboX
B.TAXII
C.STIX
D.OpenIOC
AnswerC

STIX (Structured Threat Information Expression) is purpose-built to represent cyber threat intelligence as structured, machine-readable JSON, covering indicators, campaigns, threat actors and relationships. It satisfies the stem's requirement for a standardised, machine-readable sharing format, unlike document-centric or transport protocols such as TAXII, which merely conveys STIX.

Why this answer

STIX (Structured Threat Information Expression) is a standardized language for representing threat intelligence.

9
MCQmedium

A security analyst is analyzing a memory dump from a compromised host using Volatility. Which Volatility plugin would be most useful to identify a malicious process that is hidden from the standard process listing?

A.pstree
B.malfind
C.psxview
D.pslist
AnswerC

psxview cross-references multiple process-listing sources — such as EPROCESS, PspCidTable and CSRSS handles — and highlights discrepancies where a process appears in some lists but not others. That mismatch exposes processes hidden by rootkits, satisfying the requirement to identify a malicious process absent from the standard listing.

Why this answer

The psxview plugin in Volatility cross-references multiple process listing sources (pslist, psscan, thrdproc, pspcid, csrss, session, deskthrd) to detect processes hidden from the standard listing. It is specifically designed to reveal rootkit-hidden processes by comparing discrepancies between these sources.

Exam trap

CAS-005 often tests the difference between Volatility plugins, so candidates confuse malfind (code injection) with psxview (hidden process detection) or pick pslist for hidden processes.

How to eliminate wrong answers

Option A is wrong because pstree displays processes in a tree hierarchy based on the standard process list, so it will not show hidden processes. Option B is wrong because malfind detects injected code or memory regions with suspicious permissions (e.g., RWX), which is useful for malware analysis but not specifically for finding hidden processes. Option D is wrong because pslist only shows processes from the active process list, which is exactly what rootkits hide from.

10
MCQhard

A security analyst is investigating a potential data exfiltration incident. The analyst has a packet capture (PCAP) file from the network segment where the suspected exfiltration occurred. The analyst wants to extract files that were transferred over HTTP and analyze their contents. Which of the following tools should the analyst use to achieve this?

A.tcpdump
B.Wireshark
C.Nmap
D.Metasploit
AnswerB

Wireshark can open PCAP files, reassemble TCP streams, and export objects from HTTP, SMB, and other protocols. Its 'Export Objects' feature allows the analyst to extract files transferred over HTTP, which can then be analyzed. This directly meets the requirement of extracting files from the PCAP for further inspection.

Why this answer

The analyst needs to extract files from a PCAP, specifically from HTTP transfers. Wireshark's 'Export Objects' feature can reassemble and save files from HTTP, SMB, and other protocols. tcpdump is limited to packet capture and display without file extraction. Nmap and Metasploit are not designed for PCAP analysis.

Thus, Wireshark is the correct tool.

Exam trap

The trap here is confusing packet capture tools like tcpdump with analysis tools like Wireshark, assuming tcpdump can extract files.

11
MCQmedium

A security analyst is using the MITRE ATT&CK framework to categorize adversary behavior observed in recent incidents. The analyst notes that the adversary used spearphishing with a malicious attachment to gain initial access, then executed a PowerShell script to download additional tools. Which ATT&CK tactic is the PowerShell execution associated with?

A.Defense Evasion
B.Execution
C.Initial Access
D.Command and Control
AnswerB

PowerShell running a script to download tools is adversary-controlled code running on the victim host, which maps to the Execution tactic. Initial access was already achieved via spearphishing; the script's purpose is to execute further payloads, satisfying the stem's requirement to categorise this behaviour.

Why this answer

In MITRE ATT&CK, Execution (TA0002) covers techniques that result in adversary-controlled code running on a local or remote system, including T1059 Command and Scripting Interpreter. PowerShell is explicitly documented under T1059.001, so running a PowerShell script to download tools is classified as Execution. Initial Access describes how the adversary got in (the spearphishing), not what they ran afterward.

Exam trap

The trap is conflating the *initial access vector* (spearphishing) with the *post-compromise action* (PowerShell execution) — candidates see 'spearphishing' in the scenario and reflexively choose Initial Access.

How to eliminate wrong answers

Option A is wrong because Defense Evasion (TA0005) covers hiding artifacts, obfuscation, and disabling security tools — merely running PowerShell is not inherently evasive unless paired with techniques like T1027 or T1562. Option C is wrong because Initial Access (TA0001) refers to the entry vector (spearphishing attachment, T1566.001), which already occurred before the PowerShell step. Option D is wrong because Command and Control (TA0011) describes adversary communication with compromised systems (e.g., C2 channels), not local script execution.

12
Multi-Selectmedium

A security analyst is conducting a penetration test for a client. The rules of engagement specify that no social engineering is allowed. Which TWO of the following reconnaissance techniques are permitted under these rules?

Select 2 answers
A.Calling the help desk to obtain credentials
B.Scanning the client's external network for open ports
C.Performing DNS enumeration using public records
D.Sending phishing emails to employees
E.Tailgating into the building
AnswersB, C

Scanning external networks for open ports is a technical reconnaissance activity that does not involve deceiving or manipulating people, so it satisfies the rules of engagement prohibiting social engineering. It maps the attack surface through direct network probing rather than human interaction, making it permissible alongside other non-social techniques.

Why this answer

Option B is correct because scanning the client's external network for open ports is a purely technical reconnaissance activity that does not involve deceiving or manipulating people, so it falls outside the prohibition on social engineering. Option C is correct because DNS enumeration using public records relies on openly available registration and name-resolution data (e.g., WHOIS, zone data, public DNS queries) rather than human interaction or deception. Option A is not permitted because calling the help desk to obtain credentials is a pretexting/social-engineering attack that manipulates a person into disclosing sensitive information.

Option D is not permitted because phishing emails are a classic social-engineering technique that deceives employees into revealing data or executing actions. Option E is not permitted because tailgating is a physical social-engineering method that exploits human trust to gain unauthorized building access.

Exam trap

The trap here is conflating 'reconnaissance' with 'social engineering' — candidates may think any information-gathering technique is off-limits, but the RoE only prohibits social engineering, so technical scanning and public DNS enumeration remain permitted.

13
MCQeasy

An organization needs to ensure that evidence collected during a forensic investigation remains intact and admissible in court. Which process is most critical for maintaining the integrity of digital evidence?

A.Storing evidence in a secure locker
B.Maintaining an unbroken chain of custody
C.Using write-blockers when imaging drives
D.Hashing the evidence with SHA-256
AnswerB

Digital evidence is only admissible if its provenance is provable. An unbroken chain of custody documents every transfer, handler and storage condition from seizure to court, so any tampering or contamination can be ruled out. Hashing proves integrity, but the chain of custody is what satisfies the court's admissibility constraint.

Why this answer

Chain of custody documents every person who handled the evidence, from collection to presentation in court, ensuring that evidence has not been tampered with. This is essential for admissibility.

14
MCQmedium

During a digital forensics investigation of a compromised Linux server, the investigator needs to preserve the evidence in a forensically sound manner. The server is still running. Which of the following should the investigator do first?

A.Pull the power cord to preserve the disk state
B.Create a forensic image of the hard drive using dd over a network connection
C.Run the 'history' command to see recent user commands
D.Capture the contents of RAM using a tool like LiME or fmem
AnswerD

RAM contents are volatile and lost on shutdown, so capturing memory with LiME or fmem first preserves evidence that would otherwise vanish. Order of volatility demands memory acquisition before disk imaging on a live system.

Why this answer

On a live system, volatile data — RAM contents, running processes, network connections, and encryption keys — is lost the moment power is cut or the system is rebooted. Order of volatility (RFC 3227) dictates capturing RAM first using tools like LiME or fmem before touching the disk. This preserves evidence that may never exist on disk, such as in-memory malware or active sessions.

Exam trap

The trap is thinking 'preserve the disk first' — but on a live system, order of volatility means RAM must be captured before anything else, and pulling the plug is the worst possible action.

How to eliminate wrong answers

Option A is wrong because pulling the power cord destroys volatile evidence (RAM, caches, running processes) and can corrupt the filesystem, violating order of volatility. Option B is wrong because imaging the disk over the network before capturing RAM loses volatile data and also alters the system state by running dd. Option C is wrong because running 'history' modifies the shell environment and only shows the current user's shell history — it's not a first-step evidence-preservation action and can overwrite or miss data.

15
Multi-Selectmedium

A security team is implementing a threat intelligence program and wants to consume intelligence from various sources. Which TWO of the following are commonly used threat intelligence feeds or sharing mechanisms? (Select TWO.)

Select 2 answers
A.DNS
B.SMTP
C.HTTP
D.ISACs
E.STIX/TAXII
AnswersD, E

ISACs are sector-specific non-profit bodies through which member organisations share threat indicators, incidents and mitigation guidance. Consuming their feeds satisfies the stem's requirement for a commonly used threat intelligence sharing mechanism, alongside ISAO and CERT channels.

Why this answer

ISACs (Information Sharing and Analysis Centers) are sector-specific organizations that collect, analyze, and share threat intelligence among their members, making them a standard threat intelligence sharing mechanism. STIX/TAXII is also correct: STIX (Structured Threat Information Expression) is a standardized language for describing cyber threat intelligence, and TAXII (Trusted Automated Exchange of Intelligence Information) is the application-layer protocol used to exchange that STIX data over HTTPS. By contrast, DNS, SMTP, and HTTP are general-purpose network protocols used for name resolution, email transport, and web communication respectively; while threat intelligence may traverse them, they are not themselves threat intelligence feeds or sharing mechanisms.

Exam trap

The trap is picking generic protocols (DNS, HTTP, SMTP) because they're used to transport threat intel — but the question asks for sharing mechanisms/feeds, which are ISACs and STIX/TAXII.

16
MCQmedium

A security analyst is reviewing threat intelligence feeds and notices that a known Advanced Persistent Threat (APT) group has been using a specific technique to move laterally within networks. The analyst wants to map this technique to the MITRE ATT&CK framework. Which resource would the analyst use to find the corresponding ATT&CK technique ID?

A.MITRE ATT&CK Navigator or website
B.NIST SP 800-61
C.STIX/TAXII feeds
D.CVE database
AnswerA

The MITRE ATT&CK Navigator and website host the full technique matrix with IDs, letting the analyst map the observed lateral movement technique to its corresponding identifier. It is the authoritative source for ATT&CK technique IDs, satisfying the stem's mapping requirement.

Why this answer

The MITRE ATT&CK Navigator and the official ATT&CK website are the authoritative resources for mapping adversary techniques to ATT&CK technique IDs (e.g., T1021 for Remote Services). The analyst would search the technique name or tactic (Lateral Movement) to find the corresponding ID and details.

Exam trap

The trap is confusing ATT&CK (adversary TTPs) with CVE (vulnerabilities) or NIST SP 800-61 (IR process) — candidates must recognize that technique IDs come only from the ATT&CK framework.

How to eliminate wrong answers

Option B is wrong because NIST SP 800-61 is the incident handling guide — it defines IR lifecycle phases, not ATT&CK technique mappings. Option C is wrong because STIX/TAXII is a transport/format for threat intel, not a mapping database for ATT&CK technique IDs. Option D is wrong because the CVE database catalogs software vulnerabilities, not adversary tactics, techniques, and procedures (TTPs).

17
MCQmedium

A security analyst is investigating a phishing campaign targeting the organization. The threat intelligence team has provided indicators such as email subject lines, sender domains, and attachment hashes. However, the analyst notices that these IOCs change rapidly and are only effective for a short period. Which type of threat intelligence would provide more durable and actionable information for defending against this campaign?

A.STIX/TAXII feeds
B.IoC-based threat intelligence
C.TTP-based threat intelligence
D.Strategic threat intelligence
AnswerC

TTP-based intelligence describes adversary behaviours and tradecraft, which change far more slowly than email subjects, sender domains or attachment hashes. This satisfies the stem's constraint that rapidly shifting IOCs give only short-lived value, providing durable detection for the phishing campaign.

Why this answer

TTP-based threat intelligence focuses on the adversary's tactics, techniques, and procedures — the behavioral patterns behind an attack — rather than volatile artifacts like subject lines or hashes. Because TTPs describe how attackers operate (e.g., MITRE ATT&CK techniques such as spearphishing attachment T1566.001), they remain relevant even when IOCs rotate. This makes them far more durable and actionable for building detections and defenses against an ongoing campaign.

Exam trap

CAS-005 often tests the distinction between volatile indicators (hashes, domains, subject lines) and durable behavioral intelligence (TTPs), so candidates who equate 'threat intelligence' with 'IOC feeds' pick the wrong answer.

How to eliminate wrong answers

Option A is wrong because STIX/TAXII are merely standards and transport protocols for sharing threat intelligence (STIX for structured representation, TAXII for exchange) — they are not a category of intelligence and do not inherently provide durable behavioral insight. Option B is wrong because IoC-based intelligence is exactly what the analyst already has, and by definition it is short-lived and easily evaded by attackers who rotate domains, hashes, and subject lines. Option D is wrong because strategic threat intelligence addresses long-term, high-level trends and risk posture for executives, not the operational detection detail needed to defend against a specific active phishing campaign.

18
MCQeasy

A vulnerability scanner reports a critical vulnerability on a critical server with a CVSS v3.1 base score of 9.8. The server cannot be patched immediately due to vendor constraints. Which of the following should the security team implement as a compensating control?

A.Disable the server until a patch is available
B.Increase monitoring of the server
C.Isolate the server on a separate network segment with strict firewall rules
D.Apply a workaround provided by the vendor
AnswerC

Network isolation with strict firewall rules is a compensating control: it blocks the exploit paths a CVSS 9.8 vulnerability would use, reducing exposure without patching. This satisfies the vendor constraint preventing immediate remediation while the server keeps operating.

Why this answer

When a patch cannot be applied, compensating controls such as network segmentation, firewall rules, or WAF can reduce risk. Network isolation is a common compensating control.

19
Multi-Selecthard

A security analyst is reviewing a malware sample in a sandbox environment. The analyst notes that the malware attempts to check for the presence of a debugger and modifies its behavior if one is detected. Additionally, the malware uses encrypted strings and resolves API calls dynamically. Which THREE analysis techniques would be most effective for understanding this malware's capabilities? (Select THREE.)

Select 3 answers
A.Static analysis using a disassembler like IDA Pro to examine the code for anti-debugging and obfuscation techniques
B.Network analysis using Wireshark to capture packets from the sandbox
C.Hash analysis by submitting the malware to VirusTotal
D.Dynamic analysis in a sandbox to observe the malware's behavior after it detects a debugger
E.Memory analysis using Volatility on the sandbox host to capture the malware's process memory
AnswersA, D, E

Disassembly with IDA Pro reveals anti-debugging checks, encrypted string routines and dynamic API resolution logic in the code itself, without executing the sample. This exposes the obfuscation and evasion mechanisms the malware uses, which behavioural observation alone cannot fully map.

Why this answer

Option A is correct because static analysis with a disassembler such as IDA Pro lets the analyst inspect the binary's code directly, revealing the anti-debugging checks (e.g., IsDebuggerPresent, PEB BeingDebugged flag) and the obfuscation/encrypted-string routines without executing the sample. Option D is correct because dynamic analysis in a sandbox observes the malware's actual runtime behavior, and since the sample alters its behavior when a debugger is detected, running it in an instrumented sandbox (without an attached debugger) exposes the alternate execution path and its true capabilities. Option E is correct because memory analysis with Volatility captures the malware's process memory, allowing recovery of dynamically resolved API addresses, decrypted strings, and unpacked code that never appear on disk.

Option B is not among the correct answers because Wireshark packet capture only shows network traffic and cannot reveal the anti-debugging logic, encrypted strings, or dynamic API resolution central to this sample. Option C is not among the correct answers because VirusTotal hash lookups only provide reputation and prior detection data, not an understanding of the malware's internal capabilities.

Exam trap

CAS-005 often tests the misconception that simple hash or network analysis is sufficient for evasive malware, when in fact obfuscated and anti-debugging malware requires deeper static, dynamic, and memory analysis.

20
MCQmedium

A security analyst receives an alert from the SIEM indicating a possible DNS tunneling attempt. The analyst needs to investigate the incident. Which of the following actions should the analyst take FIRST to validate the alert?

A.Run a vulnerability scan on the suspected host to check for DNS-related exploits.
B.Review DNS logs for unusually long or high-entropy subdomain queries from the same host.
C.Capture full packet data for all DNS queries and analyze the payloads for executable content.
D.Immediately block all outbound DNS traffic from the suspected host.
AnswerB

DNS tunneling often encodes data in subdomains, resulting in long, random-looking strings. Reviewing DNS logs for such patterns from a single host can quickly validate the alert. This is a direct and efficient first step because it uses existing log data without disrupting operations, and it can confirm whether the traffic is anomalous.

Why this answer

The first step should be to review DNS logs for anomalies such as long or high-entropy subdomain queries from the same host. This leverages existing data to validate the alert without disrupting services. Blocking DNS traffic is a containment action, packet capture is more resource-intensive, and vulnerability scanning does not address active tunneling behavior.

Exam trap

The trap here is jumping to containment or advanced analysis before performing a simple log review, which can quickly confirm or dismiss the alert.

21
MCQeasy

A security team is preparing for a penetration test. Which document defines the scope, rules, and restrictions for the test?

A.Rules of Engagement (RoE)
B.Memorandum of Understanding (MOU)
C.Statement of Work (SoW)
D.Service Level Agreement (SLA)
AnswerA

The Rules of Engagement document is the formal agreement that scopes a penetration test, listing authorised targets, permitted techniques, timing windows and prohibited actions. It satisfies the stem's requirement for a document defining scope, rules and restrictions, protecting both tester and client legally.

Why this answer

The Rules of Engagement (RoE) is a formal document that outlines the scope, permissions, and constraints of a penetration test.

22
Multi-Selectmedium

A security team is deploying deception technology to detect lateral movement within the network. They plan to use honeypots configured to mimic critical servers. Which TWO of the following are essential considerations for the honeypot deployment to be effective? (Choose TWO.)

Select 2 answers
A.Configure the honeypots with the same patch level as production systems
B.Use realistic network services and data to attract attackers
C.Isolate the honeypots from production systems to prevent pivoting
D.Ensure the honeypots are in the same broadcast domain as production servers
E.Disable logging on honeypots to avoid detection by attackers
AnswersB, C

Honeypots only detect lateral movement if attackers believe they are genuine targets. Populating them with realistic services, banners, credentials and data sustains attacker engagement long enough to record techniques and tooling, directly satisfying the stem's requirement that the deployment attract and deceive intruders effectively.

Why this answer

Option B is correct because honeypots only generate useful detection telemetry if they present realistic, believable network services, banners, and data that entice an attacker into interacting with them; a bare or obviously fake service will be ignored and yield no lateral-movement indicators. Option C is correct because a honeypot must be isolated (for example, on a separate VLAN or segment with strict firewall/ACL rules) so that an attacker who compromises it cannot pivot into production systems, which would turn a detection asset into an attack platform. Option A is not required: matching production patch levels is not essential to effectiveness, and honeypots are often deliberately left vulnerable to attract attackers.

Option D is not required and can be risky, since placing honeypots in the same broadcast domain as production servers exposes them to unnecessary traffic and increases pivot risk. Option E is wrong because logging and monitoring are fundamental to a honeypot's purpose; disabling logging would defeat detection.

Exam trap

The trap is thinking honeypots should mirror production exactly (patch level, broadcast domain) — but the correct approach is realistic services plus strict isolation, not production parity.

23
MCQmedium

During a penetration test, the tester has obtained a foothold on an internal server. The tester wants to identify other systems on the network and find potential targets for lateral movement. Which type of reconnaissance is MOST appropriate in this scenario?

A.Internal network scanning with Nmap
B.OSINT gathering via Shodan
C.Social engineering attacks on employees
D.Passive sniffing with Wireshark
AnswerA

Nmap scanning from the compromised host enumerates live neighbours, open ports and services across internal subnets, directly satisfying the requirement to find lateral-movement targets. External reconnaissance cannot reach internal-only systems, and passive sniffing reveals only traffic already traversing the segment.

Why this answer

Active reconnaissance on internal networks (e.g., port scanning, OS fingerprinting) is appropriate after gaining a foothold, as it provides detailed information about adjacent systems. Passive reconnaissance (like sniffing) might be stealthier but active scanning is more effective for mapping.

24
MCQhard

A security engineer is implementing a new endpoint detection and response (EDR) solution. The engineer wants to detect process injection techniques where malware writes to the memory of a remote process and then creates a remote thread to execute its payload. Which of the following Windows API call sequences should the EDR monitor to detect this behavior?

A.RegOpenKeyEx, RegSetValueEx, RegCloseKey
B.OpenProcess, VirtualAllocEx, WriteProcessMemory, CreateRemoteThread
C.WSAStartup, socket, connect, send
D.CreateFile, ReadFile, WriteFile, CloseHandle
AnswerB

This sequence is the classic remote process injection pattern: OpenProcess obtains a handle to the target process, VirtualAllocEx allocates memory in its address space, WriteProcessMemory writes the payload, and CreateRemoteThread starts execution. Monitoring these API calls in sequence is a reliable indicator of remote thread injection, commonly used by malware to execute code in another process.

Why this answer

Remote process injection via CreateRemoteThread requires allocating memory in the target process (VirtualAllocEx), writing the payload (WriteProcessMemory), and then creating a thread to execute it (CreateRemoteThread). The OpenProcess call obtains the necessary handle. Monitoring this API sequence helps EDR solutions detect a common malware technique.

The other options describe file, registry, or network operations that are not related to process injection.

Exam trap

The trap here is confusing process injection with other malicious behaviors like file manipulation or registry persistence, which use entirely different API sets.

25
MCQeasy

A security analyst is reviewing firewall logs and notices a large number of outbound connections from an internal server to various external IP addresses on port 443. The connections are occurring at regular intervals and transferring small amounts of data. Which of the following is the MOST likely explanation for this activity?

A.The server is performing legitimate software updates from various vendors.
B.The server is using a peer-to-peer file-sharing application for legitimate business purposes.
C.The server is beaconing to a command-and-control (C2) server as part of a malware infection.
D.The server is experiencing a distributed denial-of-service (DDoS) attack from external sources.
AnswerC

Regular outbound connections to multiple external IPs on port 443 with small data transfers are characteristic of C2 beaconing. Malware often uses HTTPS to blend in with normal traffic. The periodic nature and multiple destinations suggest a compromised host attempting to communicate with its controller, possibly using domain generation algorithms (DGAs) or fast-flux.

Why this answer

The pattern of regular outbound connections to multiple external IPs on port 443 with small data transfers is a classic indicator of C2 beaconing. Malware often uses HTTPS to evade detection and communicates periodically to receive commands or exfiltrate small amounts of data. This behavior warrants further investigation, such as checking the server for malware and analyzing the destinations.

Exam trap

The trap here is assuming that any outbound HTTPS traffic is benign, when in fact attackers commonly use port 443 for C2 to blend in with normal web traffic.

26
MCQmedium

A security administrator is configuring a new VPN concentrator to support remote workers. The organization requires that all remote access use strong authentication and that the VPN concentrator validate the health of connecting devices before granting access. Which technology should the administrator implement?

A.VPN with IKEv2 and certificate-based authentication
B.802.1X with EAP-TLS
C.Network Access Control (NAC) with posture assessment
D.RADIUS with PAP
AnswerC

NAC with posture assessment checks the health of devices, such as ensuring antivirus is up-to-date and patches are installed, before allowing network access. When integrated with VPN, it can enforce health policies for remote workers. This directly meets the requirement for strong authentication and device health validation.

Why this answer

The requirement is for strong authentication and device health validation for remote VPN access. NAC with posture assessment provides exactly that by evaluating endpoint compliance before granting access. While IKEv2 with certificates offers strong authentication, it lacks health checks.

RADIUS with PAP is weak, and 802.1X is not typically used for VPN health validation.

Exam trap

The trap here is assuming that IKEv2 with certificate-based authentication alone satisfies the health validation requirement, when it only provides strong authentication.

27
MCQmedium

A security operations center (SOC) has deployed a SOAR platform to automate phishing response. An analyst wants to ensure that when a phishing email is reported, the platform automatically extracts all URLs from the email body and headers, submits them to a threat intelligence service, and then quarantines the email if any URL is malicious. Which SOAR component should the analyst configure to define this sequence of actions?

A.Playbook
B.Case management system
C.Orchestration engine
D.Runbook
AnswerA

A playbook is a predefined, automated workflow that executes a series of actions based on triggers and conditions. Here, the trigger is a reported phishing email, and the actions include URL extraction, threat intelligence lookup, and conditional quarantine. This directly matches the requirement to define a sequence of automated actions.

Why this answer

The requirement is to define an automated sequence of actions triggered by a phishing report. A playbook in SOAR is exactly this: a workflow that can include conditional logic, integrations with threat intelligence, and actions like quarantine. The other components either support execution, document procedures, or track cases but do not define the automation logic.

Exam trap

The trap here is confusing the orchestration engine (which executes workflows) with the playbook (which defines the workflow logic).

28
MCQeasy

A security analyst is reviewing threat intelligence feeds and notices indicators from a known APT group. Which threat intelligence sharing standard is most commonly used to structure and share such cyber threat information in a machine-readable format?

A.CybOX
B.MITRE ATT&CK
C.STIX/TAXII
D.OpenIOC
AnswerC

STIX provides a structured, machine-readable schema for describing indicators, threat actors and relationships, while TAXII defines the transport protocol for exchanging that content between servers and clients. Together they satisfy the stem's requirement for a standardised, automated format for sharing APT indicators, unlike document-centric or proprietary feed formats.

Why this answer

STIX (Structured Threat Information Expression) and TAXII (Trusted Automated Exchange of Intelligence Information) are the standard protocols for sharing cyber threat intelligence in a structured, machine-readable format. STIX defines the data model, and TAXII defines the transport mechanism.

29
MCQhard

A security operations team has deployed a deception platform consisting of several Windows and Linux honeypots on a dedicated VLAN. After two weeks, the team notices the honeypots generate a high volume of connection attempts originating from internal vulnerability scanners, asset discovery tools, and backup agents, drowning out any genuine adversary activity. Which of the following is the BEST course of action to preserve the fidelity of the deception environment?

A.Place the honeypots behind a firewall rule that permits only traffic from external IP address ranges.
B.Decommission the honeypots and replace them with host-based intrusion detection agents installed on production servers.
C.Move the honeypots to the same VLAN as production servers so that legitimate administrative traffic blends in with adversary activity.
D.Tune the deception platform to suppress alerts for known scanner, discovery, and backup agent signatures and source addresses, while forwarding all other honeypot interactions to the SIEM.
AnswerD

Deception fidelity depends on distinguishing authorized tooling from adversary behavior. By fingerprinting the deterministic traffic patterns and source addresses of sanctioned scanners and backup agents and suppressing only those events, the team removes expected noise without blinding the environment to novel or anomalous connections. All other honeypot interactions remain high-signal indicators worth forwarding to the SIEM for correlation and triage.

Why this answer

Deception environments lose value when benign, authorized traffic overwhelms the alerts they produce. The practical fix is to baseline and suppress the deterministic signatures and source addresses of sanctioned tools such as vulnerability scanners, asset discovery engines, and backup agents, while continuing to forward every other honeypot interaction to the SIEM. This preserves the honeypot's high-fidelity detection role without discarding it or exposing production networks.

Exam trap

The trap here is treating honeypot noise as a reason to abandon or isolate the deception layer, rather than tuning suppression for known benign sources while keeping the environment live.

30
MCQmedium

During an incident response, the team identifies that an attacker gained initial access via a phishing email containing a malicious macro. The macro downloaded a payload from a remote server. Which phase of the incident response lifecycle is currently being executed when the team identifies the phishing email as the attack vector?

A.Containment, eradication, and recovery
B.Preparation
C.Lessons learned
D.Detection and analysis
AnswerD

Identifying the phishing email as the initial access vector is analysis of collected evidence to determine how the intrusion occurred, which falls within detection and analysis. This phase scopes the incident and informs later containment and eradication decisions.

Why this answer

Detection and analysis is the phase where the IR team identifies and validates the incident, determines its scope, and identifies the attack vector (e.g., phishing email with malicious macro). Identifying the phishing email as the initial access vector is a classic detection-and-analysis activity, occurring before containment or eradication.

Exam trap

The trap is assuming that identifying the attack vector is part of containment or eradication — but vector identification is squarely in Detection and Analysis, before any containment actions begin.

How to eliminate wrong answers

Option A is wrong because containment, eradication, and recovery happen after the incident is detected and analyzed — the team is still identifying the vector, not yet containing it. Option B is wrong because preparation is the pre-incident phase (building playbooks, tools, training), not the phase where an active incident's vector is identified. Option C is wrong because lessons learned occurs after recovery, when the team documents what happened and improves processes.

31
MCQeasy

A security analyst is investigating a malware sample found on a workstation. The analyst wants to determine the malware's capabilities without executing it. Which type of malware analysis involves examining the binary's strings, headers, and structure?

A.Static analysis
B.Dynamic analysis
C.Reverse engineering
D.Memory forensics
AnswerA

Static analysis examines the binary's strings, headers and structure without running it, directly satisfying the stem's constraint of determining capabilities without execution. Dynamic or behavioural analysis would require detonating the sample in a sandbox, which the analyst explicitly wants to avoid.

Why this answer

Static analysis involves examining the malware binary without executing it, focusing on its structure, strings, headers, and other static properties. This allows the analyst to extract indicators like embedded URLs, IP addresses, and function calls without risking infection or triggering malicious behavior.

Exam trap

The trap here is confusing static analysis with reverse engineering; while reverse engineering is a subset of static analysis, the question specifically asks about examining strings and headers, which is classic static analysis.

How to eliminate wrong answers

Option B is wrong because dynamic analysis requires executing the malware in a controlled environment to observe its behavior, which contradicts the requirement to avoid execution. Option C is wrong because reverse engineering involves disassembling or decompiling the binary to understand its logic, which is a deeper form of static analysis but not the primary term for examining strings and headers. Option D is wrong because memory forensics analyzes volatile memory (RAM) from a running system, not a static binary file.

32
MCQhard

During a malware analysis, an analyst runs a suspicious binary in a sandbox and observes that it attempts to communicate with a known malicious IP address, modifies registry keys, and creates a service. The analyst then extracts strings from the binary and finds references to a specific C2 server. Which analysis phase does the extraction of strings represent?

A.Dynamic analysis
B.Reverse engineering
C.Static analysis
D.Memory analysis
AnswerC

Extracting strings examines the binary's raw bytes without executing it, revealing embedded artefacts such as the C2 server address. That places it firmly in static analysis, which inspects code and metadata at rest, distinct from the dynamic sandbox observation already performed.

Why this answer

Extracting strings from a binary is a static analysis technique because it examines the file's contents without executing it. The strings command or similar tools reveal embedded text such as URLs, IP addresses, and error messages, which can provide immediate indicators of compromise like the C2 server address.

Exam trap

The trap is mixing up static and dynamic analysis phases; candidates might think that because the malware was run in a sandbox, all subsequent analysis is dynamic, but string extraction is purely static.

How to eliminate wrong answers

Option A is wrong because dynamic analysis involves observing the malware's behavior during execution, such as network traffic and registry changes, not extracting strings from the binary file. Option B is wrong because reverse engineering involves disassembling or decompiling the code to understand its logic, which is more complex than simply extracting strings. Option D is wrong because memory analysis examines volatile memory (RAM) to find artifacts of running processes, not the static binary file.

33
MCQmedium

An organization is unable to patch a critical vulnerability in a legacy application due to vendor limitations. The risk assessment indicates a high likelihood of exploitation. Which compensating control should the organization implement to reduce the risk?

A.Deploy an additional firewall in front of the application
B.Disable the application until a patch is available
C.Increase the frequency of vulnerability scanning
D.Implement network segmentation to isolate the application
AnswerD

Network segmentation places the unpatched legacy application in an isolated segment with restricted inbound and outbound traffic, limiting lateral movement and reducing exploitability. This compensates for the vendor-imposed inability to patch while addressing the high likelihood of exploitation.

Why this answer

Network segmentation isolates the legacy application from critical systems, limiting the blast radius if the vulnerability is exploited. This compensating control reduces risk by preventing lateral movement and restricting access to the vulnerable application, even though the vulnerability remains unpatched.

Exam trap

The trap is selecting a control that only detects or monitors (like scanning) rather than one that actually reduces risk; candidates must distinguish between detection and prevention controls.

How to eliminate wrong answers

Option A is wrong because deploying an additional firewall in front of the application may not address the specific vulnerability and could be bypassed if the attack vector is not network-based; it also adds complexity without guaranteeing isolation. Option B is wrong because disabling the application until a patch is available is a disruptive measure that may not be feasible for business operations and is not a compensating control but rather a full mitigation. Option C is wrong because increasing the frequency of vulnerability scanning only improves detection, not protection; it does not reduce the likelihood or impact of exploitation.

34
MCQmedium

A company's incident response team is conducting a post-incident review. They identify that the intrusion was not detected for 72 hours due to insufficient logging on critical servers. Which phase of the incident response lifecycle should be improved to address this gap?

A.Lessons learned
B.Containment
C.Detection
D.Preparation
AnswerD

Preparation covers establishing logging, monitoring and detection capabilities before incidents occur. Insufficient logging on critical servers is a preparation gap, so strengthening log collection and alerting in this phase directly addresses the 72-hour detection failure identified in the review.

Why this answer

The gap is insufficient logging on critical servers, which is a preparation issue because logging must be configured and enabled before an incident occurs. Detection relies on logs, but if logs are not properly set up during the preparation phase, detection will fail. Therefore, improving preparation by ensuring adequate logging is the correct phase to address.

Exam trap

The trap is selecting 'Detection' because the failure occurred during detection, but the question asks which phase should be improved to address the gap, and the gap is in preparation (logging setup).

How to eliminate wrong answers

Option A is wrong because lessons learned is a post-incident activity where improvements are identified, but the actual implementation of logging improvements falls under preparation. Option B is wrong because containment involves limiting the spread of an incident, not addressing logging deficiencies. Option C is wrong because detection is the phase where the lack of logging manifested, but the root cause is inadequate preparation; improving detection would require better logging, which is a preparation task.

35
Multi-Selecthard

A security analyst is reviewing an incident where an attacker used a compromised service account to perform lateral movement within an Active Directory environment. The analyst wants to identify other systems that the attacker may have accessed using this account. Which two data sources would be most effective for this investigation? (Choose two.)

Select 2 answers
A.Domain controller security logs for Kerberos service ticket requests (Event ID 4769) involving the service account.
B.Windows Security event logs for logon events (e.g., Event ID 4624) filtered by the service account.
C.SIEM alerts for unusual process execution on the service account's original workstation.
D.Antivirus logs on the domain controller.
E.Firewall logs showing outbound connections from the service account's workstation.
AnswersA, B

Event ID 4769 logs Kerberos service ticket requests, showing which services the account accessed. Since service accounts often use Kerberos, this can reveal lateral movement to servers. Correlating with logon events provides a comprehensive view of accessed systems.

Why this answer

To track lateral movement of a service account, the analyst needs authentication records across the domain. Windows Security event logs (4624) show successful logons per system, and domain controller Kerberos service ticket requests (4769) show which services the account requested tickets for. Together, these reveal the systems the attacker accessed.

Other sources lack account-specific authentication details.

Exam trap

The trap here is focusing on network or endpoint logs that do not tie activity to the specific service account, missing the domain-wide authentication trail.

36
Multi-Selectmedium

A SOC analyst is investigating a potential data exfiltration incident. The analyst suspects that an attacker used DNS tunneling to exfiltrate data. Which THREE network traffic indicators would support this hypothesis? (Select THREE.)

Select 3 answers
A.A sudden increase in failed login attempts
B.Large DNS response packets (greater than 512 bytes)
C.Unencrypted HTTP traffic to external IPs
D.DNS queries for domains with long subdomains and random characters
E.An unusually high number of DNS queries from a single host
AnswersB, D, E

DNS tunnelling encodes exfiltrated data into DNS records, inflating responses well beyond the 512-byte UDP limit and often forcing TCP fallback. Large response packets therefore satisfy the stem's requirement for network indicators supporting the DNS tunnelling hypothesis.

Why this answer

Option B is correct because DNS tunneling typically requires encoding data in DNS responses, which pushes packet sizes beyond the standard 512-byte UDP DNS limit and often forces TCP fallback or EDNS0 usage, making large DNS response packets a strong indicator. Option D is correct because tunneling tools encode exfiltrated data into subdomain labels, producing long, high-entropy, randomly generated subdomains that are atypical of legitimate DNS traffic. Option E is correct because DNS tunneling generates a high volume of queries from a single host as data is chunked and sent in many small DNS requests, so an unusual spike in query count from one internal host supports the hypothesis.

Option A does not belong because failed login attempts indicate authentication attacks such as brute forcing, not DNS-based exfiltration. Option C does not belong because unencrypted HTTP to external IPs is a general web traffic observation and is not specific to DNS tunneling, which operates over port 53.

Exam trap

CAS-005 often tests the ability to distinguish DNS tunneling indicators from other attack indicators, causing candidates to select generic exfiltration signs like HTTP traffic or failed logins instead of DNS-specific anomalies.

37
MCQeasy

Which of the following best describes the purpose of the STIX and TAXII standards in threat intelligence sharing?

A.They are tools for analyzing malware behavior in a sandbox environment
B.They are used to automatically patch vulnerabilities based on threat feeds
C.They provide a framework for conducting incident response exercises
D.They standardize the format and exchange of cyber threat intelligence
AnswerD

STIX defines a structured language for describing threat indicators, actors and campaigns, while TAXII specifies the transport protocol for exchanging that content between systems. Together they give vendors and sharing communities a common format and delivery mechanism for cyber threat intelligence.

Why this answer

STIX (Structured Threat Information Expression) is a language for describing threat intelligence, and TAXII (Trusted Automated Exchange of Intelligence Information) is a protocol for exchanging that intelligence. Together they enable automated sharing of threat data.

38
MCQhard

A security analyst is investigating a security incident where an attacker gained unauthorized access to a server. The analyst reviews the server logs and finds the following entries: 'Accepted password for root from 192.168.1.100 port 22 ssh2' followed by 'session opened for user root by (uid=0)'. The analyst suspects the attacker used stolen credentials. Which of the following log sources would provide the MOST direct evidence of the attacker's activities after the initial access?

A.System call auditing logs (e.g., auditd).
B.Network flow data (NetFlow) from the server's switch.
C.Bash history file for the root user.
D.Authentication logs from the SSH service.
AnswerA

System call auditing logs, such as those generated by auditd on Linux, record detailed information about system calls, including process execution, file access, and network activity. They provide a comprehensive and tamper-resistant record of the attacker's actions after initial access. This is the most direct evidence for forensic analysis.

Why this answer

System call auditing logs, such as those from auditd, capture detailed system-level activities including process execution, file access, and network connections. They are tamper-resistant and provide a comprehensive record of the attacker's actions after initial access. Authentication logs only show login events, bash history can be altered, and NetFlow lacks host-based detail.

Exam trap

The trap here is assuming that bash history or authentication logs provide sufficient detail about post-exploitation activities, when in fact system call auditing offers more comprehensive and reliable evidence.

39
MCQmedium

A SOC team is implementing a SOAR platform to automate responses to phishing emails. The team wants to create a playbook that, upon detection of a phishing email, automatically quarantines the email from all mailboxes and blocks the sender's domain. Which type of playbook action is being described?

A.Advisory action
B.Manual action
C.Semi-automated action
D.Automated action
AnswerD

Automated actions execute without analyst intervention, which satisfies the stem's requirement that quarantine and domain blocking occur automatically upon detection. Unlike manual or semi-automated playbooks, this removes human approval from the response path, enabling immediate containment. Microsoft Entra ID and email security controls are invoked programmatically by the SOAR platform.

Why this answer

Automated response actions are executed by the SOAR platform without human intervention, such as quarantining and blocking.

40
Multi-Selecthard

A security operations center (SOC) is evaluating a new EDR solution. Which three capabilities are essential for effective endpoint detection and response? (Select THREE).

Select 3 answers
A.Network firewall management
B.Behavioral analysis to detect anomalies
C.Automated containment of malicious processes
D.Real-time monitoring of endpoint activities
E.Vulnerability scanning of endpoints
AnswersB, C, D

Behavioural analysis continuously baselines normal endpoint activity and flags deviations, catching fileless malware and living-off-the-land techniques that signature matching misses. This satisfies the SOC's need for detection beyond known indicators, enabling EDR to surface novel threats in real time rather than waiting for updated signatures.

Why this answer

Option B is correct because behavioral analysis is the core of EDR: it baselines normal process, file, registry, and network activity and flags deviations (e.g., anomalous parent-child process chains, suspicious PowerShell usage) that signature-based tools miss, enabling detection of unknown or fileless threats. Option C is correct because EDR must not only detect but respond; automated containment capabilities such as isolating the host from the network, terminating or suspending malicious processes, and quarantining files are essential to stop lateral movement and reduce dwell time. Option D is correct because continuous, real-time telemetry collection from endpoints (process creation, command-line arguments, file and registry modifications, network connections) is the foundational data source that feeds both detection analytics and post-incident investigation.

Option A is not correct because network firewall management is a network-perimeter control, not an endpoint detection and response capability, even though EDR may integrate with firewalls for containment. Option E is not correct because vulnerability scanning identifies known weaknesses for patch prioritization and is typically a separate VM tool, not a core EDR detection-and-response function.

Exam trap

The trap is selecting vulnerability scanning or firewall management because they sound security-related, but the exam expects you to distinguish EDR's host-centric detect/respond triad from adjacent network or vulnerability management functions.

41
Multi-Selecthard

During an incident response, a team is prioritizing containment actions. Which THREE of the following actions should be taken to contain the incident effectively?

Select 3 answers
A.Blocking malicious IP addresses at the firewall
B.Notifying law enforcement
C.Collecting forensic images of affected systems
D.Isolating affected systems from the network
E.Disabling compromised user accounts
AnswersA, D, E

Blocking malicious IP addresses at the firewall satisfies the containment constraint by severing the network path attackers use for command-and-control and lateral movement. Perimeter filtering stops inbound exploitation attempts and outbound callbacks immediately, limiting blast radius while forensic investigation continues. This is a standard, reversible containment action that preserves evidence on affected hosts.

Why this answer

Option A is correct because blocking malicious IP addresses at the firewall is a direct, immediate containment action that severs the attacker's command-and-control or exfiltration channel at the network perimeter, preventing further ingress or egress. Option D is correct because isolating affected systems from the network (e.g., VLAN quarantine, disabling switch ports, or pulling the cable) stops lateral movement and prevents the compromised hosts from infecting other assets while preserving their state for later analysis. Option E is correct because disabling compromised user accounts (e.g., resetting credentials and revoking sessions/tokens in Active Directory or the IdP) contains the incident by cutting off the attacker's authenticated access and halting further abuse of those identities.

Option B does not belong because notifying law enforcement is an external communication/coordination step, not a technical containment action, and it typically occurs after containment or per legal guidance. Option C does not belong because collecting forensic images is evidence preservation and investigation work that, while important, is not itself a containment measure and is often performed after systems are isolated.

Exam trap

CAS-005 often tests the distinction between containment and other incident response phases, and candidates frequently select evidence collection or legal notification as containment actions when they are actually part of investigation or communication.

42
MCQmedium

A security analyst is reviewing a suspicious PowerShell script found on a compromised host. The script contains a long string of base64-encoded text and uses the `-EncodedCommand` parameter. The analyst wants to understand the script's functionality without executing it. Which of the following actions should the analyst take FIRST?

A.Run the script in a sandboxed environment to observe its behavior.
B.Submit the script's hash to VirusTotal for threat intelligence.
C.Use a debugger to step through the script line by line.
D.Decode the base64 string using a tool like CyberChef or PowerShell's FromBase64String method.
AnswerD

Decoding the base64 string reveals the actual PowerShell commands, allowing the analyst to understand the script's intent without execution. This is a safe, static analysis step that can quickly expose malicious actions like downloading payloads or establishing persistence. It is the logical first step before any dynamic analysis or containment.

Why this answer

The most efficient and safe first step is to decode the base64-encoded command to reveal the underlying PowerShell code. This static analysis technique requires no execution and often immediately exposes the script's purpose, such as downloading a payload or creating a scheduled task. It allows the analyst to make informed decisions about further investigation or containment without risking the environment.

Exam trap

The trap here is assuming that dynamic analysis or sandboxing is always the best first step, when static decoding can provide immediate insight without any risk.

43
MCQhard

A security analyst is investigating a malware sample that uses the Windows API function NtQueryInformationProcess to detect if it is being debugged. The analyst wants to understand how this anti-debugging technique works and how to bypass it. Which of the following statements accurately describes the technique and a potential bypass?

A.The malware checks the ProcessDebugFlags field, which is zero when a debugger is attached. A bypass is to use a kernel-mode debugger to avoid detection.
B.The malware checks the ProcessDebugPort field, which is non-zero when a debugger is attached. A bypass is to patch the return value of the API call.
C.The malware checks the ProcessBasicInformation field, which contains a pointer to the PEB. A bypass is to modify the PEB directly.
D.The malware checks the ProcessDebugObjectHandle field, which is zero when a debugger is attached. A bypass is to set a breakpoint on the API and modify the handle.
AnswerB

NtQueryInformationProcess with ProcessDebugPort (0x07) returns a non-zero port when a debugger is present. Malware uses this to detect debugging. Bypassing can be done by patching the API to always return zero or using a plugin that hides the debug port. This is a known anti-debugging technique, and the described bypass is effective in many cases.

Why this answer

The correct answer describes the ProcessDebugPort technique. When a debugger is attached, the system creates a debug port, and NtQueryInformationProcess with ProcessDebugPort returns a non-zero value. Malware can check this to detect debugging.

A common bypass is to patch the API function to always return zero for that information class, effectively hiding the debug port. This is a standard anti-anti-debugging approach used in malware analysis.

Exam trap

The trap here is confusing the various ProcessInformationClass values and their return conditions, such as when they indicate a debugger is present.

44
MCQeasy

During a penetration test, the tester has gained initial access to a web server and wants to move laterally to a database server. Which technique is most commonly used for lateral movement in a Windows environment?

A.SQL injection
B.Cross-site scripting (XSS)
C.Pass-the-Hash
D.ARP spoofing
AnswerC

Pass-the-Hash reuses captured NTLM password hashes to authenticate to remote Windows systems without cracking the plaintext password, enabling lateral movement between hosts. This satisfies the scenario's Windows lateral-movement requirement by leveraging credential material already obtained during initial access.

Why this answer

Pass-the-Hash (PtH) is a credential theft technique where an attacker captures NTLM password hashes (e.g., via Mimikatz from LSASS memory) and uses them to authenticate to other Windows systems without cracking the plaintext password. It is one of the most common lateral movement techniques in Windows environments because NTLM authentication accepts the hash directly.

Exam trap

The trap is that SQL injection and XSS are famous attack names, so candidates pick them without checking whether the question asks about lateral movement versus initial access — the key is recognizing that lateral movement in Windows almost always involves credential abuse like Pass-the-Hash.

How to eliminate wrong answers

Option A is wrong because SQL injection is an initial access or data exfiltration technique against web applications, not a lateral movement technique between Windows hosts. Option B is wrong because XSS targets web application users in their browsers and does not facilitate host-to-host movement in a Windows domain. Option D is wrong because ARP spoofing is a man-in-the-middle technique on the local subnet used for traffic interception, not a credential-based lateral movement method across Windows systems.

45
Multi-Selectmedium

A security engineer is configuring a web application firewall (WAF) to protect a public-facing application from common attacks. The engineer wants to ensure the WAF can detect and block SQL injection and cross-site scripting (XSS) attempts. Which TWO of the following WAF capabilities should the engineer enable? (Choose two.)

Select 2 answers
A.IP reputation blocking based on threat intelligence feeds
B.Signature-based detection for known attack patterns
C.SSL/TLS termination for encrypted traffic inspection
D.Rate limiting to prevent brute force attacks
E.Positive security model with whitelisting of allowed parameters
AnswersB, E

Signature-based detection uses predefined patterns to identify known attack payloads for SQL injection and XSS. It is effective for common attacks and is a standard WAF feature. Enabling this helps block well-known malicious requests based on their structure and content.

Why this answer

To detect and block SQL injection and XSS, the WAF should use signature-based detection to recognize known attack patterns and a positive security model to enforce strict input validation. These two capabilities directly address the attack vectors. Rate limiting, SSL termination, and IP reputation are useful but do not specifically target SQL injection or XSS.

Exam trap

The trap here is assuming that SSL/TLS termination alone provides protection against SQL injection and XSS, when it only enables inspection of encrypted traffic.

46
MCQmedium

An organization wants to detect attackers who have already breached the network by deploying decoy credentials and data files. Which type of deception technology should they use?

A.Sandbox
B.Honeypot
C.Honeytoken
D.Honeynet
AnswerC

Honeytokens are decoy credentials, files or records that have no legitimate use, so any access or use signals an attacker already inside the network. This matches the requirement to detect breached attackers, unlike honeypots, which are decoy systems rather than planted data artefacts.

Why this answer

Honeytokens are decoy credentials, API keys, or data files placed in systems that legitimate users would never access. When an attacker uses them, an alert fires, revealing the breach. This matches the requirement to detect attackers already inside the network using decoy credentials and files.

Exam trap

CAS-005 often tests the confusion between honeypots (decoy systems) and honeytokens (decoy credentials/files), causing candidates to pick the broader deception category instead of the precise technique.

How to eliminate wrong answers

Option A (Sandbox) is wrong because a sandbox is an isolated environment for detonating and analyzing suspicious files or code, not for planting decoy credentials to detect intruders. Option B (Honeypot) is wrong because a honeypot is a decoy system or service designed to attract attackers, not a planted credential or file. Option D (Honeynet) is wrong because a honeynet is a network of honeypots, which is broader than the specific decoy-credential technique described.

47
MCQeasy

An organization wants to collect threat intelligence from multiple Information Sharing and Analysis Centers (ISACs) relevant to their industry. Which of the following is a primary benefit of participating in an ISAC?

A.Free penetration testing services
B.Access to proprietary threat intelligence feeds
C.Ability to share sensitive information anonymously
D.Timely and relevant threat data from peers
AnswerD

ISAC membership gives sector-specific sharing between peers facing comparable threats, so members receive timely, relevant threat data — indicators and tactics — far faster than public feeds, directly satisfying the requirement to collect intelligence from multiple industry-relevant centres.

Why this answer

ISACs provide a trusted community for sharing threat intelligence, early warnings, and best practices, helping members defend against sector-specific threats.

48
Multi-Selectmedium

A security operations team is developing a SOAR playbook to automate response to a detected ransomware outbreak. The team wants to ensure the playbook can contain the threat quickly while minimizing business disruption. Which TWO actions should the playbook include as automated responses? (Select TWO.)

Select 2 answers
A.Run a full antivirus scan on all systems
B.Restore all systems from the latest backup automatically
C.Power off all affected servers immediately
D.Block outbound traffic to known malicious IP addresses and domains
E.Isolate the affected endpoints from the network
AnswersD, E

Blocking outbound traffic to known malicious IPs and domains via firewall or DNS sinkhole rules halts command-and-control communication and data exfiltration, directly satisfying the containment requirement while leaving internal business services untouched. This limits ransomware spread without disrupting legitimate user access, unlike broad network isolation.

Why this answer

Option D is correct because blocking outbound traffic to known malicious IP addresses and domains (e.g., via firewall, proxy, or DNS sinkhole rules) severs command-and-control (C2) and exfiltration channels, which is a fast, low-disruption containment action that prevents the ransomware from receiving instructions or leaking data. Option E is correct because isolating affected endpoints from the network (for example, via EDR network containment or switch port/VLAN quarantine) stops lateral movement and further encryption or spread while leaving the hosts powered on for forensic memory capture and recovery. Option A is not appropriate as an automated containment response because a full antivirus scan is slow, resource-intensive, and does not stop an active outbreak.

Option B is not appropriate because automatically restoring all systems from backup can overwrite forensic evidence, reintroduce malware if the backup is compromised, and cause major business disruption before the threat is contained. Option C is not appropriate because powering off affected servers immediately destroys volatile memory evidence, can corrupt encrypted or in-flight data, and may disrupt critical services more than isolation would.

Exam trap

The trap here is confusing containment with eradication or recovery — candidates pick 'run antivirus' or 'restore backups' because those sound like fixing the problem, but the question asks for immediate containment actions that stop spread without destroying evidence or availability.

49
MCQmedium

During a threat hunting exercise, a security analyst hypothesizes that an adversary is using PowerShell to execute malicious scripts. Which approach is the analyst employing?

A.TTP-driven hunting
B.Machine learning-driven hunting
C.IoC-driven hunting
D.Hypothesis-driven hunting
AnswerD

The analyst forms a specific proposition about adversary behaviour, PowerShell execution, then hunts for evidence supporting or refuting it. This structured, hypothesis-first method is hypothesis-driven hunting, matching the stem's constraint of starting from a stated theory rather than an indicator or alert.

Why this answer

Hypothesis-driven hunting starts with a specific assumption about adversary behavior, unlike IoC-driven (based on known indicators) or TTP-driven (focused on tactics, techniques, procedures).

50
MCQhard

A security engineer is configuring a Web Application Firewall (WAF) to protect an e-commerce site against SQL injection attacks. The WAF is deployed in reverse proxy mode. The engineer notices that legitimate search queries containing single quotes are being blocked. Which of the following actions should the engineer take to reduce false positives while maintaining protection?

A.Tune the SQL injection rule to allow single quotes in specific parameter contexts, such as search parameters, while still blocking suspicious patterns.
B.Switch the WAF to detection-only mode so that it logs but does not block SQL injection attempts.
C.Disable the SQL injection rule set entirely to prevent blocking of legitimate traffic.
D.Create a whitelist rule that allows requests containing single quotes from known trusted IP addresses.
AnswerA

Tuning the rule to understand the application's expected input, such as allowing single quotes in search parameters but still detecting SQL injection patterns like ' OR '1'='1', reduces false positives while maintaining protection. This contextual approach is a best practice for WAF tuning, balancing security and usability.

Why this answer

Tuning the SQL injection rule to allow single quotes in specific contexts, such as search parameters, while still blocking malicious patterns is the most effective way to reduce false positives without compromising security. This approach requires understanding the application's normal input and crafting rules that distinguish between benign and malicious use of special characters.

Exam trap

The trap here is thinking that any request with a single quote is malicious, when in fact legitimate queries may contain them, and the solution is contextual tuning rather than blanket blocking.

51
MCQmedium

A security analyst is reviewing a suspicious PowerShell script that was found on a compromised host. The analyst wants to understand the script's functionality without executing it. Which of the following techniques should the analyst use?

A.Network traffic analysis
B.Debugging with PowerShell ISE
C.Static code analysis
D.Dynamic analysis in a sandbox
AnswerC

Static code analysis examines the script's source code without executing it. The analyst can read the PowerShell commands, identify obfuscation, and understand the script's intent. Tools like PowerShell's AST parser or manual review can be used. This directly fulfills the requirement to analyze without execution, making it the correct choice.

Why this answer

The analyst needs to understand the script's functionality without executing it. Static code analysis involves examining the script's code, deobfuscating if necessary, and identifying malicious commands. This avoids the risks of execution.

Dynamic analysis, debugging, and network traffic analysis all require or assume execution, which is not desired here. Therefore, static code analysis is the correct approach.

Exam trap

The trap here is thinking that debugging or sandboxing is a form of static analysis, when they actually involve execution.

52
MCQhard

A security team is implementing a new detection for a fileless malware attack that uses PowerShell to execute a malicious script directly in memory. The team wants to detect this activity using Windows Event Logs. Which of the following event IDs should they monitor to capture the script block content?

A.Event ID 4688
B.Event ID 5156
C.Event ID 4104
D.Event ID 4624
AnswerC

Event ID 4104 is generated when PowerShell logs a script block, capturing the actual code being executed. This is crucial for detecting fileless malware because the malicious script may never touch disk. Monitoring this event allows the team to see the script content and identify malicious patterns, even if the script is obfuscated or executed in memory.

Why this answer

Event ID 4104 is the correct choice because it logs PowerShell script block content, which is essential for detecting fileless malware that executes in memory. Event ID 4688 only shows process creation and command-line arguments, not the script itself. Event IDs 4624 and 5156 are unrelated to script execution and do not provide the needed visibility.

Exam trap

The trap here is confusing process creation logging (Event ID 4688) with script block logging (Event ID 4104), assuming that command-line arguments capture the full script content.

53
MCQhard

An organization has a critical vulnerability in a legacy application that cannot be patched due to vendor end-of-life. The application is required for business operations and is accessible only from the internal network. Which compensating control would best reduce the risk of exploitation while maintaining availability?

A.Deploy a host-based intrusion prevention system (HIPS) on the server
B.Apply a vendor-supplied patch
C.Implement network segmentation and strict ACLs to limit access to the application
D.Uninstall the application
AnswerC

Segmentation with strict ACLs restricts reachability to the vulnerable legacy application, shrinking the attack surface while it stays available to authorised internal users. Since patching is impossible, this compensating control limits lateral movement and exploitation attempts, satisfying the availability constraint better than disabling the service.

Why this answer

Network segmentation with strict ACLs limits who can reach the legacy application, reducing the attack surface while keeping it available to authorized internal users. This is a classic compensating control when patching is impossible — it does not fix the vulnerability but constrains exploitability and blast radius.

Exam trap

The trap is that HIPS sounds like a strong security control, so candidates pick it — but the question asks for the BEST compensating control that maintains availability, and network segmentation with ACLs directly limits exposure while HIPS is a weaker, host-level mitigation.

How to eliminate wrong answers

Option A is wrong because a HIPS is detective/preventive at the host level but does not address the unpatched vulnerability itself and can be bypassed by novel exploits; it is a weaker compensating control than restricting network access. Option B is wrong because the question states the vendor is end-of-life, so no patch exists — this is a distractor that ignores the scenario constraint. Option D is wrong because uninstalling the application would break business operations, violating the requirement to maintain availability.

54
MCQmedium

A SOC team receives an alert from a SOAR platform indicating a potential phishing email. The SOAR playbook automatically quarantines the email, blocks the sender, and opens a ticket. This is an example of which SOAR capability?

A.Response
B.Automation
C.Orchestration
D.Correlation
AnswerB

The playbook executes quarantine, sender blocking and ticket creation without human intervention, which is machine-driven execution of a predefined workflow. That distinguishes automation from orchestration, which coordinates multiple tools, and from case management or threat intelligence enrichment.

Why this answer

Automation in SOAR refers to executing predefined actions without human intervention — here, the playbook automatically quarantines the email, blocks the sender, and opens a ticket. This is the defining characteristic of automation: machine-driven execution of response steps based on a trigger.

Exam trap

The trap is that Orchestration and Automation are often used interchangeably, so candidates pick Orchestration — but the exam distinguishes them: orchestration is coordinating tools, automation is executing actions without human intervention, and the question's 'automatically' keyword points to automation.

How to eliminate wrong answers

Option A is wrong because 'Response' is the broader category of actions taken against a threat, not the specific SOAR capability of executing them automatically; the question asks which capability the automatic execution represents. Option C is wrong because Orchestration refers to coordinating multiple tools and systems (e.g., email gateway, firewall, ticketing system) into a unified workflow — while orchestration is involved, the question emphasizes the automatic execution, which is automation. Option D is wrong because Correlation is the process of linking related alerts or events (e.g., SIEM correlating logs) to identify incidents, not executing response actions.

55
Multi-Selecthard

A security operations center (SOC) is deploying a new endpoint detection and response (EDR) solution. The team wants to ensure that the EDR can detect advanced threats that use fileless techniques and living-off-the-land binaries (LOLBins). Which two data sources should the SOC prioritize collecting from the EDR to effectively detect such threats? (Choose two.)

Select 2 answers
A.User login and logout events from the domain controller
B.Windows Event Logs, specifically Sysmon events for process creation and network connections
C.API call tracing and script block logging from PowerShell
D.Full packet capture (PCAP) of all network traffic
E.Antivirus scan logs showing signature-based detection results
AnswersB, C

Sysmon provides detailed process creation events including command-line arguments, parent process, and hashes, which are critical for detecting suspicious LOLBin execution and fileless techniques. Network connection events from Sysmon also help identify command-and-control traffic. This data source is essential for advanced threat detection because it captures rich context that native Windows event logs may lack.

Why this answer

Detecting fileless threats and LOLBins requires visibility into process execution and script activity. Sysmon events provide detailed process creation and network connection data, while PowerShell script block logging and API tracing capture the actual code and function calls used by attackers. These sources together give the SOC the behavioral context needed to identify advanced techniques that evade traditional file-based detection.

Exam trap

The trap here is assuming that traditional antivirus logs or network packet captures are sufficient for detecting fileless threats, when in fact endpoint process and script-level telemetry is required.

56
MCQhard

During a penetration test, the tester gains access to a web server and wants to escalate privileges to root. The tester discovers that the web application runs with a service account that has the SeImpersonatePrivilege enabled. Which attack is most likely to succeed for privilege escalation?

A.SQL injection
B.Pass-the-hash attack
C.DLL hijacking
D.JuicyPotato attack
AnswerD

JuicyPotato exploits the SeImpersonatePrivilege token by coercing a privileged service into authenticating, then impersonating its token via COM server abuse. Since the stem confirms the service account holds SeImpersonatePrivilege, this satisfies the exact prerequisite, enabling escalation to SYSTEM or root without needing kernel exploits.

Why this answer

SeImpersonatePrivilege allows a process to impersonate a user token. Tools like JuicyPotato exploit this privilege to impersonate SYSTEM by forcing a higher-privileged process to authenticate and then stealing its token. This is a common technique for local privilege escalation on Windows.

57
Multi-Selectmedium

A security architect is designing deception technologies to detect and delay attackers. Which TWO of the following are examples of deception technologies that can be deployed? Select TWO.

Select 2 answers
A.Honeytokens
B.Honeypots
C.Security Information and Event Management (SIEM)
D.Vulnerability scanner
E.Intrusion Prevention System (IPS)
AnswersA, B

Honeytokens are decoy credentials, files or records seeded across systems; any access triggers an alert, since legitimate users have no reason to touch them. This satisfies the stem's detection requirement, giving high-fidelity, low-false-positive signals of attacker reconnaissance or lateral movement without delaying normal business activity.

Why this answer

Honeytokens (A) are deception artifacts such as fake credentials, files, or database records that have no legitimate use, so any access or use of them is a high-fidelity indicator of malicious activity and can trigger alerts while wasting attacker time. Honeypots (B) are decoy systems or services deliberately exposed to attract and observe attackers, allowing defenders to detect intrusions, collect TTPs, and delay or divert adversaries from real assets. SIEM (C) is a log aggregation, correlation, and alerting platform, not a deception mechanism, so it does not itself lure or deceive attackers.

A vulnerability scanner (D) is an assessment tool that identifies weaknesses in systems and does not create decoys or false targets. An IPS (E) is a preventive control that detects and blocks malicious traffic inline, but it is not a deception technology because it does not present fake assets or bait to attackers.

58
MCQmedium

A company uses a SIEM with User Behavior Analytics (UBA). The UBA generates an alert when a user accesses sensitive data at unusual hours. Which type of correlation rule is being applied?

A.Threshold-based correlation
B.Signature-based correlation
C.Anomaly-based correlation
D.Trend-based correlation
AnswerC

Anomaly-based correlation baselines normal behaviour and alerts on statistically significant deviations, rather than matching fixed signatures or thresholds. Accessing sensitive data at unusual hours deviates from the established behavioural baseline, which is precisely what this rule type detects.

Why this answer

Anomaly-based correlation establishes a baseline of normal behavior and alerts when activity deviates from that baseline. Accessing sensitive data at unusual hours is a deviation from the user's typical access pattern, which is exactly what UBA anomaly detection flags. This is distinct from threshold, signature, and trend rules, which rely on fixed counts, known patterns, or long-term statistical drift respectively.

Exam trap

CAS-005 often tests the confusion between anomaly-based and threshold-based correlation, since both can involve 'unusual' activity — the key discriminator is whether a learned baseline or a fixed numeric limit drives the alert.

How to eliminate wrong answers

Option A is wrong because threshold-based correlation triggers when a count exceeds a predefined limit (e.g., more than 10 failed logins in 5 minutes), not when behavior deviates from a learned baseline. Option B is wrong because signature-based correlation matches known indicators such as specific hashes, IPs, or regex patterns, and unusual access timing is not a static signature. Option D is wrong because trend-based correlation analyzes changes over a longer period (e.g., increasing data exfiltration volume week over week), whereas the scenario describes a single deviation from a behavioral baseline.

59
MCQhard

A security analyst is reviewing a Windows event log from a domain controller and notices Event ID 4769 with the ticket encryption type 0x17. The analyst suspects a Kerberoasting attack. Which of the following best explains why this event is suspicious?

A.The encryption type 0x17 indicates that the ticket is encrypted with the KRBTGT account hash, which is only used for TGTs and not service tickets.
B.The encryption type 0x17 indicates AES256-CTS-HMAC-SHA1-96, which is the default for modern Windows systems and should not trigger alerts.
C.Event ID 4769 with encryption type 0x17 indicates a TGT request using DES, which is deprecated and signals an attempt to downgrade encryption.
D.The encryption type 0x17 indicates RC4-HMAC, which is weak and often requested by attackers to crack service account passwords offline.
AnswerD

Event ID 4769 logs a Kerberos service ticket request. The encryption type 0x17 corresponds to RC4-HMAC, which is weaker and faster to crack than AES. Attackers performing Kerberoasting often request RC4-encrypted tickets for service accounts with SPNs, then extract and crack them offline. Thus, seeing RC4 where AES is expected is a strong indicator of Kerberoasting.

Why this answer

Kerberoasting involves requesting service tickets for accounts with SPNs and then cracking them offline. Attackers often request RC4 (0x17) encryption because it is weaker and faster to crack. Event ID 4769 with encryption type 0x17 on a domain controller is a key detection point.

The correct answer identifies RC4-HMAC as the suspicious element, which aligns with known attacker tactics.

Exam trap

The trap here is confusing encryption type 0x17 with AES, or misidentifying the event ID as a TGT request instead of a service ticket request.

60
MCQmedium

A security operations center (SOC) analyst is reviewing a Windows event log after a suspected credential dumping incident. The analyst observes Event ID 4688 (process creation) for a process named 'rundll32.exe' with command-line arguments containing 'comsvcs.dll MiniDump'. Which of the following best describes the attacker's technique?

A.Credential dumping via LSASS memory using a signed Windows binary
B.Pass-the-hash using NTLM authentication against remote systems
C.Kerberoasting by requesting service tickets for SPNs
D.DCSync attack to replicate directory services data
AnswerA

This is correct because comsvcs.dll MiniDump is a known LOLBin technique to dump LSASS memory using rundll32.exe, a signed Microsoft binary. It avoids dropping custom tools and can bypass some application whitelisting. The command-line arguments are a strong indicator of credential dumping, aligning with MITRE ATT&CK T1003.001.

Why this answer

The attacker used rundll32.exe to call the MiniDump export of comsvcs.dll, a built-in Windows DLL, to dump LSASS process memory. This is a living-off-the-land technique for credential dumping (T1003.001) that evades detection by using a signed binary. The other options describe different credential access methods that do not match the observed command line.

Exam trap

The trap here is assuming that credential dumping always requires custom tools like Mimikatz, overlooking built-in Windows utilities that can achieve the same goal.

61
MCQeasy

Which component of the MITRE ATT&CK framework categorizes the 'why' of an adversary's action, such as initial access or credential access?

A.Tactics
B.Mitigations
C.Procedures
D.Techniques
AnswerA

Tactics represent the adversary's tactical goal — the 'why' behind an action — with entries such as Initial Access, Execution and Credential Access. Techniques, by contrast, describe the 'how'. The stem asks which component categorises the 'why', so Tactics is the matching category.

Why this answer

In MITRE ATT&CK, tactics represent the adversary's tactical goal — the 'why' behind an action — such as Initial Access, Execution, Persistence, or Credential Access. Techniques describe the 'how' (specific methods), and procedures describe the specific implementation. The question explicitly asks for the 'why,' which maps to tactics.

Exam trap

CAS-005 often tests the distinction between tactics (the why/goal) and techniques (the how/method), since both terms appear frequently and candidates conflate them under the TTP umbrella.

How to eliminate wrong answers

Option B is wrong because Mitigations are defensive countermeasures mapped to techniques, not adversary goals. Option C is wrong because Procedures (the 'P' in TTP) describe the specific, detailed implementation an adversary uses, not the high-level goal. Option D is wrong because Techniques describe how a tactic is accomplished (e.g., phishing is a technique under Initial Access), not the why.

62
MCQhard

An incident responder is analyzing a malware sample obtained from an infected host. The responder wants to perform dynamic analysis to observe the malware's behavior in a safe environment. Which of the following is the best approach?

A.Check the PE header for imported functions
B.Disassemble the malware using IDA Pro
C.Run strings on the malware binary
D.Execute the malware in a virtual machine with network monitoring tools
AnswerD

Running the sample inside an isolated virtual machine with network monitoring captures real behavioural indicators — process creation, registry writes, file drops and command-and-control traffic — without risking the production host. This satisfies the stem's safe-environment constraint, since the VM can be snapshotted and reverted after execution.

Why this answer

Dynamic analysis requires observing malware behavior during execution, not examining its static properties. Running the sample in an isolated VM with network monitoring (e.g., Wireshark, INetSim, FakeNet-NG) allows the responder to capture real-time process creation, file system changes, registry modifications, and C2 callbacks. This is the only option that actually executes the malware and observes runtime behavior, which is the definition of dynamic analysis.

Exam trap

CAS-005 often tests the distinction between static analysis (PE headers, strings, disassembly) and dynamic analysis (execution in a sandbox/VM), so candidates who equate 'analyzing malware' with 'inspecting the binary' pick A, B, or C instead of the only option that actually executes the sample.

How to eliminate wrong answers

Option A is wrong because inspecting the PE header for imported functions is static analysis — it reveals potential capabilities (e.g., CreateRemoteThread, InternetOpen) but never confirms actual runtime behavior and can be defeated by packing or dynamic API resolution. Option B is wrong because disassembling with IDA Pro is also static analysis; it produces assembly code for human review but does not execute the sample, so it cannot observe live behavior and is heavily hindered by obfuscation, packing, or anti-disassembly tricks. Option C is wrong because running strings extracts printable ASCII/Unicode sequences from the binary — a purely static, low-fidelity technique that may reveal URLs or error messages but provides no behavioral insight and is trivially obfuscated.

63
MCQhard

During a red team exercise, the team gains access to a workstation and needs to maintain persistence. They modify a registry run key to execute a payload. However, the organization uses EDR that monitors registry changes. Which technique could the red team use to avoid detection?

A.Delete the registry key after execution
B.Change the registry key to a less suspicious name
C.Encrypt the registry key value
D.Use a LOLBin to execute the payload via a scheduled task
AnswerD

A LOLBin such as schtasks.exe creates the scheduled task using a signed Microsoft binary, so the registry run key is never touched. This satisfies evading the EDR's registry-change monitoring while still achieving persistence through Task Scheduler.

Why this answer

Using a LOLBin (Living Off the Land Binary) such as schtasks.exe, regsvr32.exe, or mshta.exe to trigger the payload via a scheduled task avoids writing to the classic Run/RunOnce registry keys that EDR products heavily monitor. Scheduled tasks are a native Windows persistence mechanism, and when invoked through signed Microsoft binaries, the activity blends into legitimate administrative behavior. This reduces the registry-change telemetry that would otherwise flag the Run key modification.

Exam trap

CAS-005 often tests the misconception that hiding or obfuscating a monitored artifact (renaming, encrypting, deleting) defeats EDR, when the correct answer is usually to switch to a different, less-monitored persistence mechanism such as a scheduled task or WMI subscription.

How to eliminate wrong answers

Option A is wrong because deleting the Run key after execution removes the persistence mechanism entirely — the payload would not survive a reboot, defeating the purpose of persistence. Option B is wrong because renaming a Run key to something 'less suspicious' does not evade EDR; modern EDR monitors the Run/RunOnce hives by path and value content, not by name reputation, so any write to those keys still generates telemetry. Option C is wrong because encrypting the registry value does not prevent the registry write event from being logged — EDR detects the modification itself, and the encrypted blob would also fail to execute as a valid command.

64
MCQmedium

A security analyst is reviewing a packet capture of suspicious traffic that uses a custom protocol over TCP. The analyst needs to determine the application-layer payload and session flow to identify potential data exfiltration. Which tool is MOST appropriate for this task?

A.Nmap
B.tcpdump
C.Wireshark
D.NetFlow
AnswerC

Wireshark provides deep packet inspection with protocol dissectors, allowing the analyst to view application-layer payloads, reassemble TCP streams, and analyze session flow. It supports custom protocol analysis through user-defined dissectors and is the most appropriate tool for this scenario.

Why this answer

Wireshark is the correct choice because it enables deep packet inspection, protocol dissection, and TCP stream reassembly, which are essential for analyzing custom protocols and identifying data exfiltration. The other tools lack the granular payload analysis and session reconstruction capabilities required for this task.

Exam trap

The trap here is assuming that any packet capture tool can perform deep application-layer analysis, when only Wireshark provides the necessary dissectors and stream reassembly.

65
MCQhard

A security analyst is reviewing logs from a SIEM and notices that a user account has been successfully authenticated from two different geographic locations within a short time span, which is impossible. The SIEM uses user behavior analytics (UBA). What type of anomaly is this most likely to detect?

A.A credential theft and reuse incident
B.A misconfigured VPN that routes traffic through multiple gateways
C.A brute-force attack on the user account
D.A man-in-the-middle attack intercepting the authentication
AnswerA

Impossible travel is the classic UBA signal: the same credentials authenticating from two distant locations faster than physical travel allows. This pattern indicates the account's credentials have been compromised and reused by an attacker, directly matching the impossible-login constraint described in the stem.

Why this answer

The scenario describes a successful authentication from two geographically distant locations within a time span that makes physical travel impossible. This is a classic indicator of credential theft and reuse, where an attacker has obtained valid credentials and is using them from a different location while the legitimate user is also active. UBA detects this as an anomaly because it deviates from the normal access pattern for that user, such as typical login locations and times.

Exam trap

CAS-005 often tests the distinction between anomaly types, and candidates may confuse brute-force attacks (which involve multiple failed logins) with credential theft (successful logins from impossible locations), or they may overlook that the scenario specifies successful authentication, leading them to choose brute-force or MITM.

How to eliminate wrong answers

Option B is wrong because a misconfigured VPN might cause multiple IP addresses or locations to appear, but it would not result in two simultaneous successful authentications from different geographies; VPN misconfigurations typically cause connectivity issues or inconsistent geolocation, not impossible travel. Option C is wrong because a brute-force attack involves repeated failed authentication attempts, not successful logins from two locations; the scenario specifies successful authentication. Option D is wrong because a man-in-the-middle attack intercepts authentication traffic but does not typically result in successful logins from two different locations; it would more likely cause session hijacking or credential interception, but the anomaly of impossible travel points to credential reuse.

66
MCQmedium

An organization is implementing a threat hunting program. The team decides to use a hypothesis-driven approach. Which of the following best describes this methodology?

A.Developing a theory about potential adversary behavior and actively looking for signs
B.Searching for known indicators of compromise from threat feeds
C.Automated scanning of all systems for vulnerabilities
D.Analyzing historical alerts for patterns
AnswerA

Hypothesis-driven hunting starts from an informed theory about attacker tactics, techniques or targets, then queries telemetry for evidence confirming or refuting it. This differs from indicator-led hunting, which searches for known IoCs rather than testing a reasoned proposition about adversary behaviour.

Why this answer

Hypothesis-driven threat hunting starts with an analyst forming a testable theory about how an adversary might operate in the environment — for example, 'attackers may be using PowerShell for lateral movement' — and then proactively searching telemetry for evidence that confirms or refutes that theory. This differs from reactive or feed-driven approaches because the hunt is guided by the analyst's hypothesis rather than by pre-existing alerts or indicators. The goal is to discover threats that have evaded automated detection, not to validate known badness.

Exam trap

CAS-005 often tests the distinction between proactive hypothesis-driven hunting and reactive indicator-based or alert-driven approaches, so candidates must recognize that 'searching for known IOCs' and 'analyzing historical alerts' are not true threat hunting even though they sound security-related.

How to eliminate wrong answers

Option B is wrong because searching for known indicators of compromise from threat feeds is indicator-based hunting, which is reactive and limited to threats already catalogued by third parties; it does not involve forming an original hypothesis about adversary behavior. Option C is wrong because automated vulnerability scanning is a preventive control that identifies misconfigurations and missing patches, not a threat hunting methodology — it does not seek evidence of active adversary activity. Option D is wrong because analyzing historical alerts for patterns is retrospective alert triage or retrospective analysis, which relies on data already flagged by detection tools rather than proactively testing a novel hypothesis about attacker tradecraft.

67
MCQeasy

A security administrator is configuring a new web server and wants to ensure that it is protected against cross-site scripting (XSS) attacks. Which of the following controls should the administrator implement to BEST mitigate XSS?

A.Content Security Policy (CSP)
B.Web application firewall (WAF) in blocking mode
C.Input validation and output encoding
D.HTTPS with HSTS
AnswerC

Input validation ensures that user-supplied data conforms to expected formats, while output encoding (e.g., HTML entity encoding) ensures that any data rendered in the browser is treated as data, not executable code. Together, they prevent XSS by stopping malicious scripts from being injected and executed. This is a fundamental and effective mitigation for XSS.

Why this answer

Cross-site scripting occurs when untrusted data is included in web output without proper handling. Input validation ensures data is safe, and output encoding ensures it is rendered as text, not code. These controls directly address the vulnerability.

A WAF, HTTPS, and CSP are supplementary but do not fix the underlying issue. Thus, input validation and output encoding are the best mitigations.

Exam trap

The trap here is assuming that a WAF or CSP alone can fully prevent XSS, when they are only additional layers and not the root fix.

68
Multi-Selectmedium

A security analyst is reviewing a CVSS score for a vulnerability that affects a critical server. The base score is 7.5, but the analyst needs to adjust for the environment. Which TWO of the following are valid CVSS environmental metrics that can modify the score? (Choose two.)

Select 2 answers
A.Exploit Code Maturity (ECM)
B.Privileges Required (PR)
C.Modified Attack Vector (MAV)
D.Attack Vector (AV)
E.Modified Privileges Required (MPR)
AnswersC, E

Modified Attack Vector (MAV) is a valid CVSS environmental metric that adjusts the base Attack Vector to reflect how the vulnerability is actually exploitable in the organisation's environment, directly satisfying the stem's requirement to tailor the 7.5 base score.

Why this answer

Modified Attack Vector (MAV) is a valid CVSS environmental metric because the Environmental metric group includes Modified versions of the Base exploitability metrics (MAV, MAC, MPR, MUI, MS), allowing the analyst to re-score the Attack Vector based on how the vulnerable server is actually reachable in their environment. Modified Privileges Required (MPR) is likewise a valid environmental metric, since it lets the analyst adjust the privilege level an attacker needs in their specific deployment rather than using the Base PR value. Both MAV and MPR are explicitly part of the CVSS Environmental metric group and therefore can modify the overall score.

By contrast, Exploit Code Maturity (ECM) belongs to the Temporal metric group, not the Environmental group, so it is not an environmental metric. Attack Vector (AV) and Privileges Required (PR) are Base metrics, which describe the intrinsic vulnerability and cannot themselves be used to adjust for the environment.

69
Multi-Selecthard

A security analyst is performing dynamic malware analysis in a sandbox. The analyst observes that the malware sample attempts to connect to a command-and-control (C2) server but fails. The analyst wants to modify the sandbox environment to allow the malware to communicate with the C2 server to observe its behavior. Which TWO of the following changes should the analyst make? (Choose two.)

Select 2 answers
A.Configure the sandbox to use a simulated internet service (INetSim) to respond to network requests.
B.Set up a fake DNS server to resolve the C2 domain to a local listener.
C.Use a VPN to route all sandbox traffic through a different country.
D.Increase the sandbox's CPU and memory resources to prevent timeouts.
E.Disable the sandbox's firewall to allow all outbound traffic to the internet.
AnswersA, B

INetSim simulates common internet services, allowing malware to receive responses as if it were communicating with real servers. This can trick the malware into revealing its C2 behavior, such as HTTP requests or DNS queries. It is a safe way to observe network activity without allowing actual external connections, which is essential in a sandbox environment.

Why this answer

To allow the malware to communicate with its C2 server in a safe manner, the analyst should simulate network services. INetSim provides fake responses to common protocols, and a fake DNS server redirects C2 domains to a local listener. Both techniques enable observation of the malware's network behavior without risking actual external communication.

Disabling the firewall or using a VPN could expose the real C2 and is unsafe. Resource adjustments do not solve the network issue.

Exam trap

The trap here is thinking that simply allowing all outbound traffic or using a VPN will solve the problem, when in fact controlled simulation is the safe and effective approach.

70
Multi-Selectmedium

A company's incident response team is developing a playbook for ransomware incidents. The playbook should cover the preparation phase. Which THREE of the following are appropriate preparation activities? (Choose THREE.)

Select 3 answers
A.Train employees on how to recognize and report phishing attempts
B.Conduct regular backup testing and ensure offline backups are available
C.Isolate infected systems from the network immediately after detection
D.Develop communication procedures, including legal and PR contacts
E.Perform threat hunting in the network to identify potential threats
AnswersA, B, D

Phishing remains the primary initial access vector for ransomware, so training employees to recognise and report suspicious messages directly reduces the likelihood of successful compromise. This satisfies the preparation phase's requirement to build preventive human controls before an incident occurs, complementing technical safeguards such as email filtering and endpoint detection.

Why this answer

Option A is correct because user awareness training on recognizing and reporting phishing is a foundational preparation activity, since phishing is a leading initial access vector for ransomware and trained employees enable earlier detection and response. Option B is correct because regular backup testing and maintaining offline, immutable backups are essential preparation steps that ensure data can be restored without paying a ransom and that backups are not encrypted or deleted by the malware. Option D is correct because establishing communication procedures with legal, PR, and other stakeholders before an incident occurs is a preparation-phase task that supports coordinated, compliant crisis communication during an actual ransomware event.

Option C is not a preparation activity but a containment action performed during the detection/response phase after an infection is identified. Option E is not a preparation activity in this context; threat hunting is an ongoing detection operation conducted during normal security monitoring rather than a preparatory step in a ransomware playbook.

Exam trap

CAS-005 often tests the distinction between preparation and other incident response phases, and candidates may incorrectly classify containment or detection activities as preparation.

71
MCQhard

An organization uses a SIEM to collect logs from multiple sources. The security team wants to identify users who are accessing resources outside of normal business hours and exhibiting unusual data transfer patterns. Which advanced SIEM capability would be most effective?

A.Threat intelligence feed integration
B.User and Entity Behavior Analytics (UEBA)
C.Log normalization and aggregation
D.Correlation rules with threshold-based alerts
AnswerB

UEBA baselines each user's and entity's normal activity, then flags statistical deviations such as logons outside business hours and anomalous data volumes. Unlike static correlation rules, it detects subtle, gradual changes in behaviour, directly satisfying the requirement to identify off-hours access and unusual transfer patterns.

Why this answer

UEBA (User and Entity Behavior Analytics) is designed to baseline normal behavior for users and entities, then detect statistical deviations such as off-hours access and anomalous data transfer volumes. Unlike static rules, UEBA uses machine learning to model each user's typical login times, peer group activity, and data movement patterns, flagging outliers that would otherwise go unnoticed. This makes it the most effective capability for identifying subtle insider-threat or compromised-account behavior described in the scenario.

Exam trap

CAS-005 often tests the distinction between static, rule-based detection (correlation rules, thresholds) and adaptive, behavior-based analytics (UEBA), so candidates must recognize that 'unusual patterns' and 'outside normal business hours' signal a need for baselining rather than predefined thresholds.

How to eliminate wrong answers

Option A is wrong because threat intelligence feeds provide known indicators of compromise (IPs, domains, hashes) and do not baseline individual user behavior or detect off-hours access patterns. Option C is wrong because log normalization and aggregation only parse and store logs in a common format; they enable analysis but do not themselves identify behavioral anomalies. Option D is wrong because threshold-based correlation rules are static and require predefined limits, so they cannot adapt to each user's normal schedule or detect subtle deviations like unusual data transfer patterns without generating excessive false positives.

72
Multi-Selectmedium

A security operations center (SOC) is implementing User Behavior Analytics (UBA) to detect insider threats. Which TWO of the following data sources are most critical for establishing a baseline of normal user behavior?

Select 2 answers
A.Authentication logs from Active Directory
B.Threat intelligence feeds
C.Network traffic logs from firewalls and proxies
D.HR records of employee performance reviews
E.Email content and subject lines
AnswersA, C

Authentication logs from Microsoft Entra ID or Active Directory record who logged on, when, from where and whether attempts failed. These identity events form the core behavioural baseline UBA needs to flag anomalous insider sign-in patterns, such as impossible travel or off-hours access, satisfying the stem's requirement for normal user behaviour data.

Why this answer

Authentication logs from Active Directory (A) are critical because they capture logon events, logon types, source workstations, and failure patterns (e.g., Event IDs 4624/4625), which directly define each user's normal access times, locations, and habits for UBA baselining. Network traffic logs from firewalls and proxies (C) are equally critical because they reveal each user's typical destinations, protocols, ports, data volumes, and timing, enabling detection of deviations such as large uploads or access to unusual external services. Together, identity/authentication data and network activity data form the core behavioral baseline for insider-threat detection.

Threat intelligence feeds (B) describe external adversaries and indicators of compromise, not a given user's normal behavior, so they support threat matching rather than baselining. HR performance reviews (D) are subjective personnel records unrelated to technical behavior patterns. Email content and subject lines (E) are content-level data that raise privacy and legal concerns and are not required to establish behavioral baselines, which rely on metadata and activity patterns.

Exam trap

The trap is selecting data sources that seem security-related but are not behavioral, such as threat intelligence feeds or email content. Candidates might also overlook network traffic logs as a key source for behavioral baselining.

73
MCQhard

A security analyst is investigating a potential breach and needs to determine the timeline of events on a compromised Windows workstation. The analyst has access to the disk image and memory dump. Which artifact should the analyst examine FIRST to establish a timeline of file system activity?

A.Registry hives
B.$MFT (Master File Table)
C.Prefetch files
D.Windows Event Logs
AnswerB

$MFT contains metadata for every file on an NTFS volume, including timestamps for creation, modification, and access. It is a primary source for file system timeline analysis. Other artifacts like prefetch or registry hives provide program execution or configuration data but are not as comprehensive for file system activity timelines.

Why this answer

The $MFT is the central repository for file metadata on NTFS, including timestamps for file creation, modification, and access. It provides a comprehensive record of file system activity, making it the primary artifact for timeline analysis. Other artifacts like Prefetch or Event Logs are useful for specific activities but do not cover the full scope of file system changes.

Exam trap

The trap here is assuming that Prefetch files provide a complete file system timeline, when they only record program execution and limited file references.

74
MCQmedium

A security operations center (SOC) receives a high-severity alert indicating that a domain administrator account was used to authenticate to a workstation at 03:00. The account is normally used only for interactive logons to domain controllers during business hours. The SOC analyst wants to quickly determine whether this is a malicious activity or a false positive. Which of the following is the MOST appropriate next step?

A.Run a vulnerability scan against the workstation to check for missing patches that could have allowed credential theft.
B.Immediately disable the domain administrator account to prevent further unauthorized access.
C.Check the domain controller's security log for Event ID 4768 to see if a Kerberos ticket was issued for the account.
D.Review the Windows Security event log on the workstation for Event ID 4624 and examine the Logon Type and Source Network Address fields.
AnswerD

Event ID 4624 records successful logons and includes the Logon Type and Source Network Address. A Type 3 (network) or Type 10 (RemoteInteractive) logon from an unusual source would confirm suspicious remote access, while a Type 2 (interactive) logon at the console would suggest a different scenario. This directly addresses the anomaly and is the fastest way to validate or dismiss the alert.

Why this answer

The most direct way to investigate an anomalous logon is to examine the successful logon event on the target system. Event ID 4624 includes critical details such as logon type and source address, which can quickly differentiate between a legitimate interactive logon and a suspicious remote or network logon. This evidence-based approach avoids premature containment actions and focuses the investigation on the actual behavior observed.

Exam trap

The trap here is assuming that any out-of-hours domain admin logon is automatically malicious and jumping to disable the account, rather than first verifying the logon type and source to understand the context.

75
MCQeasy

A security administrator is configuring a new wireless network for a small office. The administrator wants to ensure that only authorized devices can connect and that traffic is encrypted. Which of the following should the administrator implement?

A.WPA3-Personal with SAE
B.Open network with a captive portal
C.WPA2-Enterprise with RADIUS
D.WEP with MAC address filtering
AnswerA

WPA3-Personal with Simultaneous Authentication of Equals (SAE) provides strong encryption and resistance to offline dictionary attacks. SAE replaces the pre-shared key handshake in WPA2, offering forward secrecy and protecting against brute-force attempts. This meets the requirements for authorized device access and encrypted traffic, making it the most secure choice for a small office wireless network.

Why this answer

WPA3-Personal with SAE offers robust encryption and authentication without the need for additional infrastructure like a RADIUS server. It is designed for small to medium-sized networks where individual user credentials are not required. SAE prevents offline dictionary attacks, ensuring that only devices with the correct password can connect, and all traffic is encrypted.

Exam trap

The trap here is assuming that WPA2-Enterprise is always better, but for a small office without RADIUS infrastructure, WPA3-Personal with SAE provides superior security with simpler deployment.

Page 1 of 3 · 164 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Security Operations questions.