Courseiva

CCNA Security Operations Questions

14 of 164 questions · Page 3/3 · Security Operations · Answers revealed

151
Multi-Selectmedium

A penetration tester is performing reconnaissance against a target. Which TWO of the following are examples of active reconnaissance? (Select TWO.)

Select 2 answers
A.Banner grabbing
B.Social media profiling
C.Port scanning
D.WHOIS lookup
E.Searching job postings for technology details
AnswersA, C

Banner grabbing sends crafted requests directly to target services and reads their responses, so the tester's traffic reaches the target's systems. That interaction with the target distinguishes active reconnaissance from passive methods such as OSINT or DNS lookups, which never touch the target directly.

Why this answer

Banner grabbing (A) is active reconnaissance because the tester directly connects to target services (e.g., via netcat or telnet to a port) and reads the service's response banner, which generates traffic and can be logged by the target. Port scanning (C) is also active reconnaissance since tools like Nmap send TCP SYN, TCP connect, or UDP probes directly to the target's IP addresses to discover open ports, again interacting with the target's systems. In contrast, social media profiling (B), WHOIS lookup (D), and searching job postings (E) are passive reconnaissance techniques that rely on publicly available third-party information without directly touching the target's infrastructure, so they do not qualify as active reconnaissance.

Exam trap

The trap is confusing passive OSINT techniques (WHOIS, social media) with active probing; candidates may incorrectly select D or E as active.

152
Multi-Selecthard

During an incident response, a forensic examiner is collecting evidence from a compromised Windows workstation. The examiner must follow proper order of volatility to preserve potential evidence. Which THREE of the following items should be collected first, before the others? (Choose THREE.)

Select 3 answers
A.Master File Table (MFT) from the hard drive
B.Event logs from the Security log
C.List of active network connections
D.List of running processes
E.Contents of RAM (memory dump)
AnswersC, D, E

Active network connections reside only in volatile memory and vanish on shutdown or reboot, placing them among the most volatile artefacts. Order of volatility demands capturing them before disk-based evidence such as logs or files.

Why this answer

The order of volatility dictates that the most perishable evidence must be captured first, and E (contents of RAM / memory dump) is the most volatile item because RAM contents are lost the instant the system is powered off or rebooted, so it must be acquired before anything else. C (list of active network connections) is also highly volatile, since TCP/UDP sessions, ephemeral ports, and established connections change or disappear within seconds as processes terminate or time out, making it a top-priority live acquisition. D (list of running processes) is likewise volatile because process tables, PIDs, and in-memory process state change continuously and vanish on shutdown, so it must be captured early alongside memory and network state.

By contrast, A (the Master File Table from the hard drive) is far less volatile because it persists on disk until modified or overwritten, and B (Security event logs) are stored on disk and remain available after collection, so both belong to later, less volatile tiers of the order of volatility.

Exam trap

The trap is confusing less volatile disk artifacts (MFT, event logs) with highly volatile memory and network data; candidates may select A or B incorrectly.

153
MCQeasy

During a threat hunting exercise, a security analyst hypothesizes that adversaries may be using PowerShell to execute commands in memory. Which threat hunting methodology is being employed?

A.Signature-based hunting
B.TTP-driven hunting
C.Hypothesis-driven hunting
D.IoC-driven hunting
AnswerC

Hypothesis-driven hunting begins with a formulated proposition — here, that adversaries execute PowerShell in memory — then tests it against telemetry. It differs from intelligence-driven hunting, which starts from known indicators, and from situational-awareness hunting, which explores anomalies without a stated premise.

Why this answer

Hypothesis-driven hunting starts with a hypothesis about potential adversary behavior, then searches for evidence. IoC-driven uses indicators of compromise, and TTP-driven focuses on tactics, techniques, and procedures.

154
MCQeasy

A security analyst is reviewing a suspicious file. Which static analysis technique would the analyst use to examine the file without executing it?

A.Submit the file to VirusTotal
B.Execute the file in a debugger
C.Run the file in a sandbox
D.Use strings to extract readable text
AnswerD

Running strings extracts embedded ASCII and Unicode sequences from the binary without loading or executing it, satisfying the requirement for non-execution. Readable artefacts such as URLs, file paths, registry keys and command fragments reveal functionality and indicators, making this a core static analysis technique.

Why this answer

Using the 'strings' utility extracts readable ASCII/Unicode text from a binary without executing it, which is a classic static analysis technique for examining suspicious files. It reveals embedded URLs, file paths, error messages, and other indicators of compromise without any runtime risk.

Exam trap

CAS-005 often tests the static vs. dynamic analysis distinction, and the trap is that VirusTotal and sandboxes feel like 'analysis' but both involve execution or external submission, not static inspection.

How to eliminate wrong answers

Option A is wrong because submitting to VirusTotal is dynamic/cloud-based multi-engine scanning, not local static analysis, and it shares the sample externally. Option B is wrong because executing the file in a debugger is dynamic analysis — the code runs, which defeats the purpose of examining it without execution. Option C is wrong because running the file in a sandbox is dynamic analysis by definition, observing behavior during execution.

155
Multi-Selectmedium

A security operations team is implementing deception technology to detect lateral movement. Which TWO of the following are examples of deception technologies? (Select TWO.)

Select 2 answers
A.Honeytoken
B.Intrusion prevention system
C.Endpoint detection and response (EDR)
D.Security information and event management (SIEM)
E.Honeypot
AnswersA, E

Honeytokens are fabricated credentials, files or records seeded across systems; any access or use triggers an alert, since legitimate users have no reason to touch them. This satisfies the stem's lateral-movement detection requirement by catching adversaries probing with stolen credentials, without generating the false positives typical of signature-based monitoring.

Why this answer

Option A (Honeytoken) is correct because a honeytoken is a fake credential, file, or data artifact (such as a dummy AWS key or a planted document) that has no legitimate use; any access or use of it signals unauthorized activity and potential lateral movement, making it a classic deception technology. Option E (Honeypot) is correct because a honeypot is a decoy system or service deliberately exposed to attract attackers, and interactions with it reveal reconnaissance or lateral movement attempts while generating high-fidelity alerts with minimal false positives. Option B (Intrusion prevention system) is not a deception technology; an IPS is a preventive control that inspects traffic inline and blocks malicious activity based on signatures or anomalies.

Option C (Endpoint detection and response, EDR) is not deception either; EDR continuously monitors endpoint telemetry and responds to threats but does not rely on decoys. Option D (Security information and event management, SIEM) is a log aggregation, correlation, and alerting platform, not a deception mechanism, so it does not belong.

Exam trap

CAS-005 often tests the confusion between detection tools (EDR, SIEM, IPS) and deception tools (honeypots, honeytokens) — candidates pick IPS or EDR because they 'detect' attacks, missing that deception requires fake assets.

156
MCQeasy

A security administrator is configuring a new endpoint detection and response (EDR) solution. The administrator wants to ensure that the EDR can detect malicious activities such as process injection and credential dumping. Which of the following capabilities is MOST important for the EDR to have?

A.Full disk encryption
B.Signature-based detection
C.Behavioral monitoring
D.Network segmentation
AnswerC

Behavioral monitoring observes system activities and process behaviors to detect malicious actions like process injection and credential dumping, which may not have known signatures. This capability is essential for identifying advanced threats in real-time, making it the most important for the EDR.

Why this answer

To detect techniques like process injection and credential dumping, the EDR must monitor system behavior rather than rely solely on signatures. Behavioral monitoring allows the EDR to identify suspicious actions such as unexpected process memory modifications or access to LSASS. Other options are security controls but not detection capabilities for these specific threats.

Exam trap

The trap here is equating EDR with signature-based antivirus, when EDR's strength lies in behavioral detection.

157
MCQmedium

A security engineer is designing a network segmentation strategy for a new data center. The engineer wants to ensure that if a web server in the DMZ is compromised, the attacker cannot directly access the internal database servers. Which of the following controls would BEST achieve this objective?

A.Implement a firewall rule that allows all traffic from the DMZ to the internal network.
B.Place the database servers in the same VLAN as the web servers to simplify management.
C.Deploy an intrusion detection system (IDS) between the DMZ and internal network.
D.Configure a firewall to allow only specific, required traffic from the web servers to the database servers.
AnswerD

Configuring a firewall to allow only specific, required traffic (e.g., database port) from the web servers to the database servers enforces least privilege and segmentation. This prevents an attacker on a compromised web server from initiating arbitrary connections to the database servers. It is the most effective control to limit lateral movement.

Why this answer

To prevent direct access from a compromised web server to internal database servers, the engineer should implement a firewall rule that allows only specific, required traffic. This enforces least privilege and segmentation, blocking unauthorized connections. Allowing all traffic, sharing a VLAN, or relying solely on an IDS would not prevent lateral movement.

Exam trap

The trap here is confusing detection (IDS) with prevention (firewall rules), or assuming that VLAN separation alone provides sufficient security without firewall filtering.

158
Multi-Selectmedium

A security analyst is investigating a potential malware infection on a Windows workstation. The analyst wants to perform live response to collect volatile data. Which of the following commands or tools should the analyst use to capture volatile data? (Choose two.)

Select 2 answers
A.Use `netstat -anob` to capture active network connections and associated process IDs.
B.Use `fsutil usn readjournal C:` to read the USN journal for file system changes.
C.Use `wmic process get name,processid,commandline` to list running processes and their command lines.
D.Use `reg export HKLM\Software\Microsoft\Windows\CurrentVersion\Run run.reg` to export autostart entries.
E.Use `dd if=/dev/mem of=memory.dmp` to capture physical memory.
AnswersA, C

`netstat -anob` displays active connections, listening ports, and the executable name and PID for each connection. This is volatile data that can be lost on reboot and is crucial for identifying command-and-control connections. It is a standard live response command for capturing network state on Windows systems.

Why this answer

Volatile data includes information that is lost when the system is powered off, such as active network connections and running processes. The `netstat -anob` command captures network connections with associated process IDs, and `wmic process get name,processid,commandline` captures running processes with command lines. Both are essential for live response on Windows and help identify malicious activity quickly.

The other options involve non-volatile data or are not applicable to Windows.

Exam trap

The trap here is confusing non-volatile registry or file system data with volatile data, or assuming Linux commands work on Windows.

159
MCQmedium

During an incident response engagement, the security team identifies that a compromised host has been communicating with multiple external IP addresses using encrypted channels. The team needs to determine which processes initiated the connections. Which type of evidence collection should be performed first to preserve the most volatile data?

A.Export the Windows event logs related to network activity
B.Execute a network scan from the compromised host to identify active connections
C.Capture a full disk image using FTK Imager
D.Perform a memory capture using a tool like DumpIt or winpmem
AnswerD

RAM holds running processes, open sockets and encryption keys, and is lost on shutdown or reboot. Capturing memory first with DumpIt or winpmem preserves the process-to-connection mapping the team needs, satisfying the requirement to collect the most volatile evidence before disk artefacts.

Why this answer

Memory capture is the correct first step because running processes, active network connections, and encryption keys exist only in volatile memory (RAM) and are lost on shutdown or reboot. Tools like DumpIt or winpmem preserve this state, including the process-to-connection mapping needed to identify which process initiated the encrypted channels. The order of volatility in digital forensics dictates that RAM be collected before disk or logs, since it is the most transient evidence.

Exam trap

CAS-005 often tests the order of volatility, and candidates frequently choose disk imaging or log export because they seem more permanent, forgetting that RAM is the most volatile and must be captured first.

How to eliminate wrong answers

Option A is wrong because Windows event logs are stored on disk and are less volatile than RAM; they may not contain the process-to-connection mapping and can be overwritten or tampered with, so they should be collected after memory. Option B is wrong because executing a network scan alters the system state, generates new network traffic, and does not preserve existing volatile evidence; it is an investigative action, not evidence collection. Option C is wrong because a full disk image captures non-volatile data and misses active processes, open network sockets, and encryption keys in RAM; disk imaging is performed after memory capture in the order of volatility.

160
MCQmedium

A security team is implementing a new detection rule in their SIEM to identify brute-force attacks against a web application. The rule should trigger when there are more than 10 failed login attempts from the same source IP within 5 minutes. Which of the following data sources is MOST critical for this detection?

A.Application authentication logs
B.Intrusion detection system (IDS) alerts
C.Firewall logs
D.Web server access logs
AnswerA

Application authentication logs capture login attempts and their outcomes, including failures. They provide the necessary details such as username, source IP, and timestamp to detect brute-force patterns. This is the most critical source for identifying failed logins within a time window.

Why this answer

To detect brute-force attacks based on failed login attempts, the SIEM needs logs that record authentication failures. Application authentication logs provide this information with sufficient detail (source IP, timestamp, outcome). Other sources either lack authentication context or are derived alerts, making them less suitable for building a precise correlation rule.

Exam trap

The trap here is assuming that firewall or web server logs contain authentication results, when they typically do not.

161
MCQhard

During a threat hunting exercise, a hunter uses the MITRE ATT&CK framework to identify a series of behaviors: an attacker used PowerShell to download a payload, then created a scheduled task for persistence, and finally performed credential dumping via LSASS. Which ATT&CK tactic is associated with the credential dumping technique?

A.Defense Evasion
B.Credential Access
C.Execution
D.Persistence
AnswerB

Credential dumping via LSASS maps to the Credential Access tactic in MITRE ATT&CK, which covers techniques for stealing account credentials such as hashes and plaintext passwords. This directly answers the stem's question about the tactic associated with the LSASS dumping behaviour.

Why this answer

Credential dumping via LSASS (e.g., Mimikatz reading lsass.exe memory) is classified under the Credential Access tactic in MITRE ATT&CK, specifically technique T1003 OS Credential Dumping. The tactic describes the adversary's goal of stealing account names and passwords to use for lateral movement and privilege escalation. LSASS holds cached credentials and Kerberos tickets, making it a prime target for this tactic.

Exam trap

CAS-005 often tests the overlap between tactics — candidates see 'PowerShell' or 'scheduled task' in the scenario and pick Execution or Persistence, ignoring that the question specifically asks about the credential dumping step.

How to eliminate wrong answers

Option A is wrong because Defense Evasion covers techniques like obfuscation, disabling security tools, or process injection to avoid detection — credential dumping may incidentally involve evasion, but its primary goal is obtaining credentials, so it maps to Credential Access. Option C is wrong because Execution covers running adversary-controlled code (e.g., PowerShell, scheduled tasks, WMI) — the PowerShell download in the scenario is Execution, not the LSASS dump. Option D is wrong because Persistence covers maintaining foothold (e.g., scheduled tasks, registry run keys) — the scheduled task in the scenario is Persistence, not credential dumping.

162
Multi-Selecthard

A security team is implementing a new endpoint detection and response (EDR) solution. The team wants to ensure the EDR can detect advanced threats that use fileless malware techniques. Which TWO of the following capabilities are MOST important for detecting fileless malware? (Choose two.)

Select 2 answers
A.Disk encryption of the endpoint's hard drive
B.Monitoring of PowerShell and Windows Management Instrumentation (WMI) activity
C.Regular vulnerability scanning of the endpoint
D.Analysis of in-memory process behavior and API calls
E.Signature-based detection of known malware hashes
AnswersB, D

Fileless malware often uses built-in system tools like PowerShell and WMI to execute malicious code in memory without writing to disk. Monitoring these activities can detect suspicious command lines, encoded scripts, and unusual WMI events. This is critical because traditional file-based detection may miss such threats. EDR solutions that log and analyze PowerShell and WMI behavior can identify malicious patterns and block execution.

Why this answer

Fileless malware executes in memory using legitimate system tools, so detecting it requires monitoring of scripting and management interfaces like PowerShell and WMI, as well as analyzing in-memory process behavior and API calls. These capabilities allow EDR to identify malicious activity without relying on file signatures. The other options are either preventive measures or ineffective against fileless threats.

Exam trap

The trap here is assuming that traditional signature-based detection or vulnerability scanning can catch fileless malware, when in fact they are ineffective because fileless malware leaves no files on disk.

163
Multi-Selectmedium

A penetration tester is conducting a test against a web application. The client has defined rules of engagement that prohibit any denial of service attacks. The tester discovers an endpoint that is vulnerable to command injection. Which THREE of the following actions should the tester take to validate the vulnerability while staying within scope? (Choose THREE.)

Select 3 answers
A.Use the echo command to write a file on the server
B.Run a whoami command to confirm the user context
C.Delete a random system file to observe impact
D.Flood the endpoint with multiple requests to test resilience
E.Execute a ping command to a controlled server to verify code execution
AnswersA, B, E

Writing a file with echo proves command injection executed without launching floods, crashes or resource exhaustion. This validates the vulnerability while honouring the rules of engagement prohibiting denial of service, satisfying the stem's in-scope constraint.

Why this answer

Option A is correct because using the echo command to write a benign file on the server safely demonstrates command injection without causing damage or service disruption, which respects the no-DoS rules of engagement. Option B is correct because running whoami is a non-destructive command that confirms code execution and reveals the privilege context of the injected commands, providing clear validation evidence. Option E is correct because pinging a controlled server (e.g., via the ping command to an IP the tester owns) verifies outbound code execution and network reachability without harming the target or violating the no-DoS constraint.

Option C is not appropriate because deleting a system file is destructive and could cause an outage or data loss, violating the rules of engagement. Option D is not appropriate because flooding the endpoint with multiple requests constitutes a denial-of-service style test, which the client explicitly prohibited.

164
Multi-Selecthard

An incident response team is handling a ransomware incident. The team has successfully contained the threat and is now in the eradication phase. Which THREE actions are appropriate for the eradication phase? (Select THREE.)

Select 3 answers
A.Restore systems from clean backups
B.Apply security patches to the vulnerability that allowed initial access
C.Revoke and reset all compromised user and service accounts
D.Delete all infected files and registry keys associated with the ransomware
E.Conduct a lessons learned meeting
AnswersB, C, D

Patching the exploited vulnerability removes the initial access vector, preventing re-compromise during recovery. Eradication requires eliminating the root cause, so remediation of the flaw that permitted entry is a core action, distinct from containment or recovery tasks.

Why this answer

In the eradication phase, the goal is to remove the threat and close the attack vector, so option B is correct because applying security patches to the vulnerability that allowed initial access eliminates the root cause and prevents reinfection. Option C is correct because revoking and resetting all compromised user and service accounts removes adversary persistence and stops further unauthorized access using stolen credentials. Option D is correct because deleting all infected files and registry keys associated with the ransomware removes malicious artifacts and persistence mechanisms from affected systems.

Option A is not appropriate here because restoring systems from clean backups is a recovery-phase action performed after eradication, and option E is not appropriate because conducting a lessons learned meeting occurs in the post-incident activity phase after recovery is complete.

Exam trap

CAS-005 often tests the confusion between eradication and recovery phases, where candidates incorrectly select recovery actions like restoring from backups as part of eradication.

← PreviousPage 3 of 3 · 164 questions total

Ready to test yourself?

Try a timed practice session using only Security Operations questions.