Courseiva

CCNA Incident Response and Management Questions

75 of 98 questions · Page 1/2 · Incident Response and Management · Answers revealed

1
MCQmedium

When performing digital forensics, which of the following represents the correct order of volatility from most volatile to least volatile?

A.RAM, CPU registers, disk, swap, logs, archived media
B.Swap, RAM, CPU registers, disk, logs, archived media
C.Archived media, logs, disk, swap, RAM, CPU registers
D.CPU registers, RAM, swap, disk, logs, archived media
AnswerD

This is the standard order of volatility used in digital forensics, ranking evidence by how quickly it is lost. CPU registers are the most volatile, holding the CPU's current working values and disappearing in nanoseconds; RAM follows, losing all data when power is removed; swap is a disk-backed file that may persist but is overwritten and purged; then disk, logs (which are written regularly but more durable), and finally archived media, which is deliberately preserved and least volatile. Following this order ensures the most fragile evidence is collected first.

Why this answer

The order of volatility, per RFC 3227, runs from most volatile to least: CPU registers and cache, RAM, swap/pagefile, disk (local), logs (remote), and archived media. Option D follows this sequence exactly. Capturing the most volatile data first preserves evidence that would otherwise be lost when the system powers down or memory is overwritten.

Exam trap

CS0-004 often tests the RAM-vs-CPU-registers and RAM-vs-swap ordering; candidates who memorize 'RAM first' forget that registers and cache are even more volatile.

How to eliminate wrong answers

Option A is wrong because it places RAM before CPU registers — registers and cache are more volatile than RAM since they are overwritten on every instruction cycle. Option B is wrong because it places swap before RAM; swap is disk-backed and persists longer than RAM, so it is less volatile. Option C is wrong because it reverses the entire order, listing archived media (least volatile) first and CPU registers (most volatile) last — the exact inverse of the correct sequence.

2
Multi-Selectmedium

After a phishing incident, the security team wants to improve detection of similar attacks in the future. Which THREE actions should the team take as part of post-incident activity? (Choose THREE.)

Select 3 answers
A.Disabling user accounts that clicked the phishing link
B.Updating email filtering rules and detection signatures
C.Sharing indicators of compromise with other organizations via a threat intelligence platform
D.Conducting a lessons learned meeting to identify process improvements
E.Reimaging all affected workstations
AnswersB, C, D

Updating email filtering rules and detection signatures is a direct, preventive improvement that uses indicators from the phishing campaign (such as sender domain, subject line patterns, and payload hashes) to enhance the email security gateway. This action hardens the environment against similar attacks by proactively blocking malicious emails before they reach users. It is a classic post-incident activity because it closes the specific vulnerability that allowed the phishing email to be delivered, reducing the likelihood of recurrence.

Why this answer

Option B is correct because updating email filtering rules and detection signatures directly operationalizes the lessons from the phishing incident, enabling future similar messages to be blocked or flagged based on the observed sender, subject, URL, or attachment characteristics. Option C is correct because sharing indicators of compromise (IOCs) such as malicious domains, IP addresses, and file hashes through a threat intelligence platform helps other organizations detect the same campaign and can yield reciprocal intelligence that improves the team's own defenses. Option D is correct because a lessons learned meeting is a core post-incident activity that reviews the timeline, root cause, and response effectiveness to identify concrete process, tooling, and training improvements.

Option A is not a post-incident improvement action; disabling accounts is a containment step during the incident, and it does not by itself enhance future detection. Option E is also not a detection improvement; reimaging workstations is an eradication/recovery action for affected hosts and does not build capability to detect similar attacks later.

Exam trap

CS0-004 often tests the confusion between containment/recovery actions (disabling accounts, reimaging hosts) and true post-incident improvement activities (lessons learned, detection tuning, intel sharing).

3
MCQhard

During forensic analysis of a compromised Linux server, an analyst needs to acquire memory evidence. The server is running and the analyst has root access. Which of the following tools should the analyst use to capture the contents of RAM with the least impact on the system?

A.WinPmem
B.FTK Imager
C.dd if=/dev/mem of=mem.dump
D.LiME
AnswerD

LiME (Linux Memory Extractor) is a loadable kernel module purpose-built for forensically sound live acquisition on Linux, capturing physical memory directly into a file or over the network with atomic, kernel-level access that avoids the instability and incompleteness risks of userland tools like dd, making it the appropriate low-impact choice here.

Why this answer

LiME (Linux Memory Extractor) is a loadable kernel module that dumps memory and is designed to minimize footprint. It is commonly used for Linux memory acquisition.

4
MCQeasy

During an incident response engagement, a junior analyst asks the team lead about the purpose of a lessons learned meeting. Which of the following BEST describes the primary objective of this meeting?

A.To determine the exact financial cost of the incident for insurance claims.
B.To assign blame for the incident to the responsible parties.
C.To identify improvements to the incident response process and prevent recurrence.
D.To provide a detailed technical walkthrough of the malware for all attendees.
AnswerC

The primary objective of a lessons learned meeting is to review the incident response and identify what went well and what needs improvement. It aims to enhance future detection, response, and recovery. This meeting often results in actionable recommendations for updating plans, training, and tools. It is a key step in the continuous improvement of the incident response capability. The focus is on process enhancement, not punishment.

Why this answer

The lessons learned meeting is a post-incident review focused on improving the incident response process. It identifies strengths and weaknesses in detection, analysis, containment, eradication, and recovery. The outcome should be actionable recommendations to prevent similar incidents and enhance future response.

Blame, financial calculations, and deep technical dives are not the primary objectives. A blameless, improvement-oriented approach is most effective.

Exam trap

The trap here is assuming that the lessons learned meeting is for assigning blame or calculating costs, when its true purpose is process improvement.

5
MCQmedium

During the detection and analysis phase of the NIST SP 800-61 incident response lifecycle, a security analyst identifies an alert indicating a high volume of outbound traffic from a critical server to an unknown IP address. Which of the following actions should the analyst perform FIRST?

A.Correlate the alert with firewall logs and other security tools.
B.Notify law enforcement immediately.
C.Isolate the server from the network to prevent data exfiltration.
D.Rebuild the server from a known good backup.
AnswerA

During the Detection and Analysis phase of NIST SP 800-61 Rev 2, analysts must validate precursors and indicators to confirm if an actual incident has occurred. Correlating the initial alert with complementary data sources, such as firewall logs, DNS queries, and host-based intrusion detection systems, helps establish the scope, reduce false positives, and build a timeline before taking disruptive actions.

Why this answer

In the NIST SP 800-61 Detection and Analysis phase, the analyst's first priority is to validate and understand the alert before taking disruptive action. Correlating the alert with firewall logs and other security tools confirms whether the outbound traffic is truly malicious, identifies the destination, and establishes scope — this is the analysis step that precedes containment. Acting on an unverified alert risks unnecessary downtime and destroys evidence needed for the investigation.

Exam trap

The trap here is conflating urgency with action — candidates often pick 'isolate the server' because it feels like the safest immediate step, but NIST SP 800-61 explicitly places containment after detection and analysis.

How to eliminate wrong answers

Option B is wrong because notifying law enforcement is premature and typically occurs after internal validation and escalation procedures, not as a first response to an unconfirmed alert. Option C is wrong because isolation is a Containment-phase action that should follow analysis; isolating immediately on an unverified alert can disrupt critical services and destroy volatile evidence. Option D is wrong because rebuilding from backup is a recovery action taken after eradication, and doing so before analysis would eliminate forensic artifacts and potentially reintroduce the compromise.

6
MCQeasy

Which of the following is an example of a behavioral indicator of compromise (IOC) observed during dynamic malware analysis?

A.PE section names
B.File hash
C.Domain name
D.Outbound network connection to a known malicious IP
AnswerD

Watching the sample actually open a socket and beacon out to a known-bad IP during sandbox detonation is a runtime action captured by network monitoring tools like Wireshark or Cuckoo, exemplifying a behavioral IOC because it reflects what the malware does, not just what it is.

Why this answer

Dynamic analysis monitors behavior such as network connections, file system changes, and process creation.

7
MCQmedium

A security analyst is investigating a potential data breach. The analyst needs to preserve evidence before containment. Which of the following actions is MOST appropriate at this stage?

A.Powering off the system
B.Blocking the attacker's IP at the firewall
C.Disabling the user's account
D.Creating a forensic image of the hard drive
AnswerD

Creating a bit-stream forensic image of the hard drive ensures that a mathematically precise copy of the non-volatile storage is preserved for analysis. This process utilizes write-blockers to prevent any modification to the original media, maintaining chain of custody and evidence integrity. It allows investigators to safely analyze deleted files, slack space, and system artifacts without altering the source system.

Why this answer

Creating a forensic image of the hard drive is the most appropriate action to preserve evidence before containment. A forensic image is a bit-for-bit copy of the storage media that captures the system state, including deleted files, memory remnants, and metadata, without altering the original. This preserves the integrity of evidence for later analysis and legal proceedings.

Powering off, blocking IPs, or disabling accounts are containment actions that can destroy volatile evidence and should be done after imaging.

Exam trap

CS0-004 often tests the confusion between containment and evidence preservation, tricking candidates into selecting actions that alter system state or alert the attacker instead of preserving forensic evidence.

How to eliminate wrong answers

Option A is wrong because powering off the system can destroy volatile evidence in memory (RAM), such as running processes, network connections, and encryption keys, and may also trigger anti-forensic mechanisms. Option B is wrong because blocking the attacker's IP at the firewall is a containment action that can alert the attacker and cause them to destroy evidence or pivot, and it does not preserve local evidence. Option C is wrong because disabling the user's account is also a containment action that may tip off the attacker and does not capture the current state of the system for forensic analysis.

8
MCQmedium

During the detection and analysis phase of the NIST SP 800-61 incident response lifecycle, a security analyst identifies suspicious network traffic from an internal host to a known malicious IP address. Which of the following is the most appropriate next step?

A.Notify law enforcement immediately.
B.Immediately isolate the host from the network.
C.Rebuild the host from a known good image.
D.Collect additional logs and perform a deeper analysis to confirm the compromise.
AnswerD

The detection and analysis phase focuses on validating alerts to minimize false positives and accurately scope the potential incident. Gathering supplementary log sources, correlating event data, and conducting deeper forensic analysis are essential steps to confirm that a true compromise has occurred before initiating disruptive containment actions.

Why this answer

After detection, the analyst should collect additional data to confirm the incident and scope the impact before proceeding to containment.

9
Multi-Selecteasy

During a post-incident review, a security analyst identifies that the mean time to detect (MTTD) for incidents is significantly higher than the industry benchmark. Which THREE actions should the analyst recommend to improve detection capabilities?

Select 3 answers
A.Implement additional network monitoring sensors.
B.Enhance SIEM correlation rules based on current threat intelligence.
C.Subscribe to threat intelligence feeds to enrich alerts.
D.Increase the frequency of vulnerability scans.
E.Reduce the retention period for logs.
AnswersA, B, C

Deploying additional network monitoring sensors at segmentation boundaries and critical ingress/egress points eliminates the blind spots that allowed this incident to go undetected. These sensors capture full packet data, NetFlow metadata, or IDS/IPS alerts, enabling analysts to detect lateral movement and command-and-control activity that passive host-based tools might miss. This is a direct corrective action to improve visibility and reduce time-to-detection for future attacks.

Why this answer

Option A is correct because deploying additional network monitoring sensors (e.g., IDS/IPS or network TAP/SPAN-based collectors) increases visibility across network segments, allowing malicious traffic and anomalies to be observed sooner and thereby lowering MTTD. Option B is correct because tuning and expanding SIEM correlation rules with current threat intelligence lets the platform detect multi-event attack patterns and known adversary techniques faster, directly reducing the time between compromise and alerting. Option C is correct because subscribing to threat intelligence feeds enriches alerts with indicators of compromise (IOCs) and contextual data, enabling analysts to recognize and prioritize malicious activity more quickly.

Option D is not appropriate because vulnerability scans identify unpatched weaknesses on a scheduled basis and do not provide real-time detection of active intrusions, so they do not materially improve MTTD. Option E is not appropriate because reducing log retention removes historical evidence needed for correlation and forensic analysis, which would likely degrade detection and investigation capabilities rather than improve them.

Exam trap

CompTIA often tests whether candidates confuse detection improvement with prevention or hygiene activities; vulnerability scanning and log reduction sound security-related but do not reduce MTTD.

10
MCQhard

A CSIRT is following its incident response plan during a confirmed data breach. The team lead needs to ensure that all evidence collected is admissible in a future legal proceeding. Which of the following should the team lead implement FIRST?

A.Notify law enforcement and await their instructions before collecting any evidence.
B.Establish a chain of custody log for all evidence items.
C.Create a full forensic image of every affected system's hard drive.
D.Interview all employees who have access to the affected systems.
AnswerB

A chain of custody log documents every person who handled evidence, when, and why. It is the foundational requirement for evidence integrity and admissibility. Without it, even properly collected evidence can be challenged in court. The log should be started at the beginning of evidence collection and maintained throughout the incident. This is the first step to ensure legal defensibility.

Why this answer

A chain of custody log is the first legal safeguard because it documents the who, what, when, and why of evidence handling. Without it, any forensic image or log can be challenged as tampered or unauthenticated. Other actions like imaging or interviews are important but do not by themselves ensure admissibility.

The team lead should initiate the chain of custody before or during the first evidence collection.

Exam trap

The trap here is confusing the order of operations: collecting evidence without first establishing a chain of custody can render even technically perfect forensic images inadmissible.

11
MCQmedium

During the detection and analysis phase of an incident, an analyst identifies a file with a hash that matches a known malware signature. The analyst wants to enrich this IOC with additional context. Which resource is BEST suited for this enrichment?

A.Shodan
B.WHOIS lookup
C.VirusTotal
D.Passive DNS
AnswerC

VirusTotal is an industry-standard threat intelligence platform that aggregates antivirus engines and website scanners to analyze submitted files, URLs, and cryptographic hashes. During incident detection, analysts query VirusTotal with a file's MD5, SHA-1, or SHA-256 hash to rapidly determine if known malware has been previously identified by the security community.

Why this answer

VirusTotal aggregates antivirus scan results and provides additional context such as file metadata, behavior, and community comments.

12
MCQmedium

A security operations center (SOC) analyst receives an alert about a potential ransomware infection on a critical server. The incident response team needs to contain the threat quickly. Which of the following should be performed FIRST as a short-term containment measure?

A.Disable the user account associated with the alert
B.Run a full antivirus scan on the server
C.Isolate the affected network segment
D.Rebuild the server from a clean backup
AnswerC

Isolating the affected network segment is the most effective short-term containment action to prevent the lateral movement of ransomware to other critical systems. By restricting network traffic at the switch, router, or firewall level, the analyst halts the spread of the infection while preserving the volatile memory of the affected server for subsequent forensic analysis.

Why this answer

Short-term containment focuses on immediate isolation to prevent further damage. Isolating the affected network segment stops the ransomware from spreading to other systems.

13
MCQmedium

After containing a malware outbreak, the incident response team performs static malware analysis on a suspicious executable. Which of the following artifacts would be most helpful in creating a YARA rule to detect variants of the malware?

A.The creation timestamp of the file
B.The file size of the executable
C.The packer used to obfuscate the executable
D.The import table showing API calls like WriteProcessMemory and CreateRemoteThread
AnswerD

Targeting specific Windows API functions within the Portable Executable (PE) import table, such as WriteProcessMemory and CreateRemoteThread, allows YARA rules to identify the underlying functional capabilities of the malware, such as process injection. Because these APIs are essential for the malware's injection mechanism, they serve as robust, behavior-based indicators that remain consistent across different compiled versions and packaging variations.

Why this answer

Import table analysis reveals API calls and DLLs used by the malware, which are often consistent across variants and useful for detection.

14
Multi-Selecthard

During a forensic investigation, an analyst must acquire digital evidence while maintaining forensic soundness. Which THREE practices should the analyst follow? (Choose three.)

Select 3 answers
A.Use the suspect's operating system to copy files
B.Power on the system to capture volatile data first
C.Verify the hash of the image against the original
D.Use a write blocker when imaging the hard drive
E.Document every action taken during the acquisition
AnswersC, D, E

Verifying the hash of the acquired image against the original evidence is a critical step because it provides cryptographic proof that the image is an exact bit-for-bit replica. Using algorithms like SHA-256, any change to even a single bit in the image produces a completely different hash, so the match confirms no data was altered during acquisition. This verification is recorded and matched against the hash of the original, establishing the integrity and authenticity of the evidence for the chain of custody and courtroom admissibility.

Why this answer

Option C is correct because hashing the acquired image (e.g., with MD5 or SHA-256) and comparing it to the hash of the original source proves the copy is a bit-for-bit duplicate and has not been altered, which is essential to forensic soundness and admissibility. Option D is correct because a hardware or software write blocker prevents any write operations from reaching the suspect drive during imaging, preserving the integrity of the original evidence. Option E is correct because maintaining a detailed chain of custody and documenting every action (tools, timestamps, hashes, personnel) ensures the acquisition is reproducible, defensible, and legally admissible.

Option A is not appropriate because using the suspect's operating system can modify file metadata (MAC times) and alter the evidence, violating forensic soundness. Option B is not appropriate as a general acquisition practice because powering on the system can change volatile and non-volatile data; volatile data should only be captured under a documented, justified order of volatility when necessary, not as a blanket first step.

Exam trap

CompTIA often tests the misconception that capturing volatile data by powering on the system is always good practice — candidates must recognise that in dead-box acquisition, powering on destroys forensic soundness.

15
Multi-Selectmedium

A security analyst is responding to a potential data exfiltration incident. As part of the containment strategy, the analyst must preserve evidence. Which TWO actions should the analyst take before containment? (Select two.)

Select 2 answers
A.Capture a forensic image of the affected systems
B.Change passwords for affected accounts
C.Disconnect the system from the network
D.Record current active network connections
E.Kill malicious processes
AnswersA, D

Capturing a forensic image of affected systems is the correct first step because it creates a bit-for-bit copy of the storage media while preserving file slack, unallocated space, and metadata. Using a hardware write-blocker and cryptographic hashing ensures the evidence remains intact and tamper-proof for later analysis. This action is essential for identifying how the data exfiltration occurred, which files were accessed, and what remnants remain, all without altering the original source.

Why this answer

Option A is correct because capturing a forensic image of the affected systems creates a bit-for-bit copy of volatile and non-volatile data (using tools like dd, FTK Imager, or EnCase) that preserves evidence in its original state before any containment actions alter the system. Option D is correct because recording current active network connections (e.g., via netstat, ss, or Get-NetTCPConnection) captures volatile evidence such as established sessions, remote IP addresses, and ports that would be lost once the system is isolated or processes are terminated. Option B is not appropriate because changing passwords modifies system state and can destroy evidence of credential compromise or attacker persistence.

Option C is a containment action itself, not an evidence-preservation step, and would eliminate live network artifacts. Option E is also a containment/remediation action that destroys volatile memory evidence such as running processes and their associated network connections.

Exam trap

CS0-004 often tests the sequence of incident response phases, and candidates confuse containment actions (disconnecting, killing processes, changing passwords) with evidence preservation, picking a containment step that destroys the very evidence the question asks them to save.

16
MCQeasy

During the detection and analysis phase of the NIST SP 800-61 incident response lifecycle, an analyst identifies suspicious network traffic from an internal host to a known malicious IP address. Which step should the analyst perform next to validate the alert?

A.Search for the IP address on VirusTotal and Shodan.
B.Correlate the alert with other logs and endpoint data to confirm malicious activity.
C.Escalate the alert to the incident response team for containment.
D.Contain the host immediately by disconnecting it from the network.
AnswerB

Correlating the network alert with logs and endpoint telemetry confirms whether the internal host is genuinely compromised or the traffic is benign. This validation step distinguishes true malicious activity from false positives before escalating within the detection and analysis phase.

Why this answer

During the detection and analysis phase, the primary goal is to validate the alert by correlating it with additional data sources (e.g., firewall logs, DNS logs, endpoint detection and response (EDR) telemetry) to confirm whether the traffic is truly malicious or a false positive. Simply searching external threat intelligence (Option A) provides context but does not confirm activity on the host; escalation (Option C) and containment (Option D) are premature without validated evidence.

Exam trap

A common pitfall in the CySA+ exam is assuming that external threat intelligence (e.g., VirusTotal, Shodan) alone is sufficient for alert validation. The NIST framework emphasizes correlating internal logs (firewall, DNS, EDR) to confirm malicious activity before proceeding to containment or escalation.

How to eliminate wrong answers

Option A is wrong because searching VirusTotal and Shodan only provides external reputation data and does not validate whether the internal host actually communicated with the IP or if the traffic was benign (e.g., a false positive from a misconfigured proxy). Option C is wrong because escalation to the incident response team should occur only after the alert has been validated through correlation; premature escalation wastes resources and may lead to unnecessary incident handling. Option D is wrong because immediate containment (e.g., disconnecting the host) is a reactive step that should follow validation and a formal incident declaration; acting without confirmation can disrupt legitimate business operations and violate the NIST SP 800-61 containment strategy.

17
Multi-Selecthard

A CSIRT is investigating a ransomware incident that encrypted files on multiple servers. The team needs to determine the initial infection vector. Which THREE pieces of evidence should the team prioritize collecting? (Select three.)

Select 3 answers
A.Email gateway logs for the week prior to the incident
B.Endpoint detection and response (EDR) logs from affected servers
C.Network traffic logs from the perimeter firewall
D.Physical access logs to the data center
E.Firewall configuration backups
AnswersA, B, C

Email gateway logs are the primary source for identifying phishing payloads because ransomware often arrives via malicious attachments or embedded URLs. These logs capture sender metadata, subject lines, message IDs, and any verdicts (e.g., quarantined, spam, clean), so reviewing the week prior to the incident lets investigators trace the exact message that delivered the initial dropper and recover the full email thread for IoC extraction.

Why this answer

Email gateway logs (A) are essential because phishing emails with malicious attachments or links are the most common initial ransomware vector, and reviewing the week prior to the incident can reveal the delivery of the payload. EDR logs from affected servers (B) provide process-level telemetry such as parent-child process relationships, command lines, and file encryption behavior that can pinpoint the execution of the ransomware and its dropper. Network traffic logs from the perimeter firewall (C) can show command-and-control callbacks, exploit kit traffic, or lateral movement that help trace the infection back to its source.

Physical access logs (D) are not relevant to a remote ransomware infection vector and would only matter for insider or physical intrusion scenarios. Firewall configuration backups (E) document rule sets rather than activity, so they do not provide evidence of how the infection occurred.

Exam trap

CS0-004 often tests the tendency to select containment or configuration artifacts (firewall backups, physical access logs) instead of the telemetry sources that actually evidence the infection vector.

18
MCQmedium

A security analyst is conducting static analysis of a suspicious executable. Which of the following tools or techniques is BEST suited for extracting strings and viewing the import table?

A.LiME
B.FTK Imager
C.Cuckoo Sandbox
D.PEview or CFF Explorer
AnswerD

PEview and CFF Explorer are specialized static analysis utilities designed to inspect the internal structure of Portable Executable (PE) files, such as .exe and .dll files, without executing them. These tools allow analysts to examine PE headers, section headers, import/export address tables, and embedded strings to identify suspicious characteristics or indicators of compromise.

Why this answer

Static analysis often involves examining the PE header, imports, and strings. Tools like PEview, CFF Explorer, or simply using 'strings' command can extract readable strings. The import table shows DLLs and functions the executable uses.

19
MCQmedium

After containing a security incident, the incident response team conducts a root cause analysis. Which of the following is the PRIMARY purpose of this activity?

A.To identify the initial attack vector
B.To calculate the financial loss
C.To document the timeline
D.To assign blame to individuals
AnswerA

Identifying the initial attack vector is the primary objective of root cause analysis because it pinpoints the exact vulnerability or entry point exploited by the threat actor. This technical understanding allows security teams to implement targeted remediation controls, such as patching specific software or updating firewall rules, to prevent identical future compromises.

Why this answer

Root cause analysis aims to identify the underlying cause of the incident to prevent recurrence. It is a key part of post-incident activity.

20
MCQmedium

After a DDoS attack, the incident response team wants to improve detection and prevention. Which of the following metrics would be MOST useful for evaluating the effectiveness of the response?

A.Mean Time to Respond (MTTR)
B.Number of false positives
C.Mean Time to Detect (MTTD)
D.Incidents per week
AnswerA

Mean Time to Respond (MTTR) is the definitive metric for evaluating incident response effectiveness because it quantifies the average time taken to contain, mitigate, and resolve a security incident once it has been identified. For a DDoS attack, reducing MTTR directly correlates with minimizing service downtime and financial loss, demonstrating the team's operational efficiency in executing playbooks and deploying countermeasures like rate limiting or BGP blackholing.

Why this answer

Mean Time to Respond (MTTR) measures the average time taken to respond to and resolve an incident after it is detected. In the context of evaluating the effectiveness of the response to a DDoS attack, MTTR directly reflects how quickly the team mitigated the attack and restored normal operations. A lower MTTR indicates a more effective response process, making it the most useful metric among the options.

Exam trap

CS0-004 often tests the distinction between detection metrics (MTTD) and response metrics (MTTR), so candidates must carefully read whether the question asks about detection or response effectiveness.

How to eliminate wrong answers

Option B is wrong because the number of false positives measures detection accuracy, not response effectiveness. Option C is wrong because Mean Time to Detect (MTTD) measures how quickly incidents are identified, which is a detection metric, not a response metric. Option D is wrong because incidents per week is a frequency metric that does not evaluate the effectiveness of the response to a specific incident.

21
MCQmedium

An organization's security team receives an alert about a potential ransomware infection on a critical server. The severity classification is 'high' because the server supports a production database. According to the incident response plan, which containment action should be taken first to minimize data loss?

A.Reboot the server to clear the ransomware from memory.
B.Disconnect the server from the network.
C.Kill the ransomware process using task manager.
D.Create a full disk image of the server before any action.
AnswerB

Disconnecting the server from the network is the most effective immediate containment action because it halts lateral movement to other network segments and prevents the ransomware from communicating with its command-and-control (C2) server. This isolation stops the spread of the infection and prevents the exfiltration of sensitive data while preserving the system's volatile memory for subsequent forensic analysis.

Why this answer

Isolating the network connection prevents lateral movement and further encryption while preserving evidence for forensic analysis.

22
MCQmedium

A security analyst is performing static analysis on a suspicious PE file. Which initial step should the analyst take to understand the file's imports and potential capabilities?

A.Create a YARA rule based on hash characteristics.
B.Run the file in a sandbox and observe behavior.
C.Extract strings from the file.
D.Analyze the PE header and import table.
AnswerD

Examining the Portable Executable (PE) header and its Import Address Table (IAT) is a fundamental static analysis technique that reveals the specific dynamic-link libraries (DLLs) and functions the executable requests from the operating system. This structural analysis allows the analyst to infer the program's intended capabilities, such as network communication or registry modification, without executing the code.

Why this answer

Analyzing the import table reveals which Windows API functions the file uses, providing insight into its functionality (e.g., network, file, or registry operations).

23
Multi-Selecthard

During a forensic investigation, an analyst needs to acquire disk images from multiple suspect drives. Which THREE practices ensure forensic soundness? (Select THREE)

Select 3 answers
A.Documenting the chain of custody for each drive
B.Using the fastest available imaging method without verification
C.Computing and verifying hashes (e.g., SHA-256) of the original and the image
D.Using a hardware write blocker to prevent writes to the source drive
E.Acquiring the image while the system is running (live acquisition)
AnswersA, C, D

Chain of custody documentation is critical because it creates a verifiable, chronological record of every person who handled the evidence, along with the time, purpose, and condition of each transfer. In a forensic investigation, this paper trail ensures legal admissibility; if the chain is unbroken, the court can trust that the evidence has not been tampered with or substituted. Without proper documentation, even a technically perfect disk image could be ruled inadmissible, undermining the entire investigation.

Why this answer

Option A is correct because documenting the chain of custody for each drive creates an auditable record of who handled the evidence, when, and under what conditions, which is essential for the evidence to be admissible and for forensic soundness. Option C is correct because computing and verifying cryptographic hashes such as SHA-256 (or MD5) of both the original drive and the resulting image proves the image is a bit-for-bit duplicate and that no alteration occurred during acquisition. Option D is correct because a hardware write blocker enforces a read-only connection to the source drive at the hardware level, preventing any writes or metadata changes that would taint the original evidence.

Option B is not appropriate because speed without verification sacrifices integrity; forensic imaging must prioritize accuracy and validation over raw throughput. Option E is not appropriate because live acquisition alters the running system's state and memory, introduces volatility and potential contamination, and is generally reserved for situations where a dead-box acquisition is impossible.

Exam trap

CS0-004 often tests the difference between practices that ensure forensic soundness and those that compromise it; candidates may select live acquisition as a best practice when it is actually a last resort.

24
MCQhard

A security analyst is performing dynamic analysis of a suspicious file in a sandbox. Which of the following observations is most indicative of ransomware behavior?

A.The file injects code into a legitimate process
B.The file opens and overwrites documents with a new extension and drops a ransom note
C.The file creates a registry run key
D.The file attempts to connect to multiple external IPs
AnswerB

This behavior represents the definitive, high-fidelity signature of ransomware during dynamic analysis. The rapid opening, cryptographic overwriting of user data, appending of a unique file extension, and subsequent creation of a text or HTML ransom note uniquely identify the payload's destructive intent to extort the victim.

Why this answer

Ransomware typically encrypts files and renames them with a new extension. Dropping a ransom note and leaving encrypted files is characteristic.

25
MCQeasy

An organization is implementing an incident response plan. Which phase of the NIST SP 800-61 lifecycle includes activities such as creating policies, establishing IR teams, and acquiring necessary tools?

A.Containment, Eradication, and Recovery
B.Detection and Analysis
C.Preparation
D.Post-Incident Activity
AnswerC

Preparation is the foundational phase of the NIST incident response lifecycle that occurs before any security event begins. It involves establishing incident response capabilities, drafting playbooks, training personnel, securing communication channels, and deploying defensive tools. Implementing the incident response plan itself is a core component of this proactive readiness phase.

Why this answer

Preparation involves all proactive measures to enable effective incident response, including policy, team, and tool readiness.

26
Multi-Selectmedium

A security analyst is investigating a potential data breach. The analyst needs to collect digital evidence while preserving its integrity. Which TWO actions should the analyst take? (Choose TWO.)

Select 2 answers
A.Run a full antivirus scan on the system.
B.Delete any malicious files found during the investigation.
C.Verify the hash of the acquired image against the original.
D.Use a write blocker when imaging the hard drive.
E.Connect the suspect drive to a forensic workstation without a write blocker.
AnswersC, D

Computing a one-way cryptographic hash (such as SHA-256) of the original drive before acquisition and of the forensic image after, then comparing the two digests, is the definitive test that the image is a bit-for-bit clone with no changes introduced during capture. A matching hash validates the image for court admissibility and provides a baseline for later re-verification as part of the chain of custody.

Why this answer

Option C is correct because verifying the hash (e.g., MD5 or SHA-256) of the acquired forensic image against the original source confirms that the copy is bit-for-bit identical and has not been altered, which is essential for maintaining evidence integrity and admissibility. Option D is correct because using a hardware or software write blocker when imaging the hard drive prevents any write operations to the suspect drive, ensuring the original evidence remains unmodified during acquisition. Option A is incorrect because running a full antivirus scan modifies system state, timestamps, and potentially quarantines or alters files, which contaminates evidence.

Option B is incorrect because deleting malicious files destroys evidence and violates chain-of-custody and preservation principles. Option E is incorrect because connecting a suspect drive without a write blocker allows the forensic workstation's OS to write to the drive, altering metadata and compromising evidentiary integrity.

Exam trap

CS0-004 often tests the misconception that antivirus scanning or deleting malware is part of evidence collection — candidates must recognize that any action that modifies the system destroys evidence integrity.

27
Multi-Selecteasy

An organization's incident response team is classifying an incident based on severity and priority. Which TWO factors should the team consider when determining the priority of an incident? (Select TWO.)

Select 2 answers
A.The number of users reporting the issue.
B.The potential business impact of the incident.
C.The criticality of the affected systems or data.
D.The time of day the incident occurred.
E.The type of threat actor involved.
AnswersB, C

The potential business impact of an incident drives its priority because the goal of incident management is to minimize harm to the organization. Impact includes financial loss, operational disruption, regulatory fines, reputational damage, and customer trust. A high-impact incident, such as a ransomware attack on a core revenue system, necessitates immediate escalation regardless of other factors.

Why this answer

Option B is correct because incident priority is driven primarily by the potential business impact — how severely the incident could disrupt operations, revenue, reputation, or regulatory obligations — which determines how urgently the response must be escalated. Option C is correct because the criticality of the affected systems or data (for example, a domain controller, PII database, or payment processing system) directly shapes priority, since a compromise of high-value assets warrants faster and more aggressive response than one on a low-value endpoint. Together, business impact and asset criticality are the standard inputs for priority scoring in frameworks such as NIST SP 800-61, which separates severity (technical impact) from priority (business-driven urgency).

Option A is not a priority factor per se; the number of users reporting an issue may indicate scope but does not by itself establish business urgency. Option D is not a defining factor, since time of day may affect staffing but not the inherent priority of the incident. Option E is also not a priority determinant; the type of threat actor is relevant to threat intelligence and attribution, not to how urgently the business must respond.

Exam trap

CS0-004 often tests the confusion between severity (technical) and priority (business) — candidates pick volume or threat-actor factors when the question asks for business-impact and asset-criticality drivers.

28
MCQmedium

An analyst is using YARA to create rules for detecting a specific malware strain. Which of the following pieces of information is MOST useful for writing a YARA rule?

A.The malware's file size.
B.The date the malware was first seen.
C.A unique string within the malware.
D.The malware's MD5 hash.
AnswerC

YARA is primarily a pattern-matching tool designed to identify malware families based on textual or hexadecimal patterns. Defining unique strings, such as specific registry keys, user-agent strings, or unique function names within the rule's string section, allows the engine to reliably flag files belonging to that specific malware family.

Why this answer

YARA rules are based on patterns in the file, such as strings and byte sequences. A unique string found in the malware sample can be used to create a rule that identifies the malware.

29
MCQhard

An organization's incident response team is handling a ransomware incident where critical servers have been encrypted. The team has identified the ransomware variant and determined that decryption is not possible. Which of the following is the BEST post-incident activity to prevent recurrence?

A.Increase the frequency of vulnerability scans.
B.Share IOCs with the industry ISAC.
C.Conduct a root cause analysis to determine the initial infection vector.
D.Reimage all affected servers from backups.
AnswerC

Conducting a root cause analysis (RCA) is the critical post-incident activity required to pinpoint the exact initial infection vector, such as a phishing email, compromised credential, or unpatched edge device. Identifying this entry point allows the incident response team to implement targeted, permanent security controls to prevent the same exploit from being used in future attacks.

Why this answer

A root cause analysis identifies how the ransomware actually entered — phishing email, exposed RDP, unpatched VPN, supply chain — which is the only way to close the specific gap that allowed the incident. Without knowing the initial infection vector, any remediation is guesswork and the same attack can recur. Post-incident activities in NIST SP 800-61 and CompTIA's IR lifecycle explicitly call for lessons-learned/root-cause work to drive preventive controls.

Exam trap

CS0-004 often tests the confusion between recovery actions (reimage, restore) and preventive actions (RCA, control changes), tempting candidates to pick the most visible operational step instead of the one that stops recurrence.

How to eliminate wrong answers

Option A is wrong because increasing scan frequency is a generic hardening action that does not address the specific entry path the attacker used; it may not even cover the exploited vector (e.g., a phishing payload). Option B is wrong because sharing IOCs with an ISAC is a threat-intelligence contribution that helps the community but does nothing to prevent recurrence inside this organization. Option D is wrong because reimaging from backups is a recovery action, not a preventive one — it restores service but leaves the original vulnerability in place.

30
MCQmedium

An analyst is examining a disk image acquired from a compromised Linux server. The analyst needs to verify that the image is an exact bit-for-bit copy of the original drive. Which forensic sound procedure should the analyst perform?

A.Compare the hash of the image to the hash of the original drive.
B.Use a write blocker when acquiring the image.
C.Mount the image in read-only mode.
D.Analyze the image with a hex editor.
AnswerA

To verify the integrity of a forensic acquisition, the analyst must calculate a cryptographic hash (such as MD5, SHA-1, or SHA-256) of both the source media and the destination image. Matching hash values mathematically prove that no data was altered, added, or lost during the imaging process, establishing a verifiable chain of custody.

Why this answer

Hash verification ensures the image matches the original by comparing cryptographic hashes (e.g., MD5, SHA-256) generated during acquisition.

31
MCQmedium

During dynamic analysis of a malware sample in a sandbox, the analyst observes that the malware attempts to connect to an IP address 198.51.100.23 and modifies the registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run. Which IOC type is the IP address an example of?

A.Network indicator
B.File hash
C.Email indicator
D.Domain name
AnswerA

During dynamic analysis in a sandbox, observing a malware sample attempt to establish outbound connections to specific external IP addresses provides critical network indicators. These IP addresses serve as network-based indicators of compromise (IOCs) that security analysts can use to configure firewalls, intrusion detection systems, and blocklists to prevent further communication with command-and-control (C2) servers.

Why this answer

IP addresses are a common type of indicator of compromise, representing network-based IOCs that can be used for detection.

32
MCQeasy

Which of the following is the FIRST step in the NIST SP 800-61 incident response lifecycle?

A.Detection and Analysis
B.Post-Incident Activity
C.Preparation
D.Containment, Eradication, and Recovery
AnswerC

Preparation is the first phase in the NIST SP 800-61 incident response lifecycle, and it occurs before any incident actually happens. It entails building an incident response team, establishing communication plans, deploying necessary tooling (such as SIEM and EDR), creating playbooks, and conducting training and tabletop exercises. Without this pre-emptive groundwork, downstream phases like detection and analysis lack the required procedures and resources, making Preparation the non-negotiable starting point.

Why this answer

NIST SP 800-61 Rev. 2 defines the incident response lifecycle as four phases: Preparation; Detection and Analysis; Containment, Eradication, and Recovery; and Post-Incident Activity. Preparation is the first phase because it establishes the CSIRT, tools, communications plans, and playbooks before any incident occurs. Without preparation, later phases cannot be executed effectively.

Exam trap

CS0-004 often tests whether candidates assume Detection is first because incidents 'start' with detection—but the lifecycle begins with Preparation, the phase that makes detection possible.

How to eliminate wrong answers

Option A is wrong because Detection and Analysis is the second phase—it only happens after preparation has built the capability to detect. Option B is wrong because Post-Incident Activity is the final phase, involving lessons learned and evidence retention. Option D is wrong because Containment, Eradication, and Recovery is the third phase, executed only after an incident has been detected and analyzed.

33
MCQmedium

During a post-incident review, the incident response team identifies that the mean time to detect (MTTD) for a recent breach was 14 days, while the mean time to respond (MTTR) was 6 hours. Which metric should the team prioritize to improve in future incidents?

A.Percentage of incidents containing malware
B.Number of incidents per week
C.Mean time to respond (MTTR)
D.Mean time to detect (MTTD)
AnswerD

Mean time to detect (MTTD) measures the duration between the initial security compromise and the moment security analysts identify the threat. Minimizing this metric is crucial because reducing dwell time directly limits an attacker's lateral movement and data exfiltration opportunities. By prioritizing MTTD, the organization can initiate containment protocols much earlier in the attack lifecycle, significantly mitigating overall business impact.

Why this answer

With MTTD at 14 days and MTTR at only 6 hours, detection is clearly the bottleneck — attackers had nearly two weeks of dwell time before anyone noticed. Improving MTTD (via better logging, EDR tuning, threat hunting, or SIEM correlation) will reduce attacker dwell time and blast radius far more than shaving hours off an already-fast response.

Exam trap

CS0-004 often tests whether candidates reflexively pick 'improve MTTR' as the security answer without comparing the relative magnitudes of the two metrics — here 14 days vs. 6 hours makes detection the obvious priority.

How to eliminate wrong answers

Option A is wrong because the percentage of incidents containing malware is a composition metric, not a speed metric, and does not address the 14-day detection gap. Option B is wrong because incident volume per week measures workload, not detection or response efficiency, and does not indicate where the breach lifecycle is failing. Option C is wrong because MTTR is already excellent at 6 hours; optimizing it further yields marginal gains compared to the 14-day detection delay.

34
MCQhard

During a post-incident review, the incident response team identifies that the mean time to detect (MTTD) for incidents is significantly higher than industry benchmarks. Which of the following improvements would most directly reduce MTTD?

A.Increasing the number of forensic analysts on call.
B.Conducting more frequent tabletop exercises.
C.Implementing automated alerting based on threat intelligence.
D.Rotating credentials after each incident.
AnswerC

Automated alerting driven by threat intelligence continuously matches live telemetry against known indicators of compromise and behavioral patterns in near real time, directly closing the gap between when malicious activity occurs and when it is surfaced to an analyst, which is precisely the mechanism that lowers mean time to detect.

Why this answer

Mean time to detect (MTTD) measures how quickly incidents are identified. Implementing automated alerting based on threat intelligence directly improves detection speed by continuously monitoring for known indicators of compromise and generating alerts in real time. This reduces the time between an incident occurring and the team becoming aware of it.

Exam trap

The trap is conflating detection with response; candidates may choose options that improve response (more analysts, tabletop exercises) but the question specifically asks for reducing MTTD, which requires faster detection mechanisms like automated threat intelligence alerting.

How to eliminate wrong answers

Option A is wrong because increasing forensic analysts improves response and investigation after detection, not the speed of detection itself. Option B is wrong because tabletop exercises improve preparedness and response processes but do not directly reduce the time to detect live incidents. Option D is wrong because rotating credentials after incidents is a containment/remediation step and does not affect detection speed.

35
MCQeasy

An organization has identified indicators of compromise (IOCs) from a recent incident. Which data format is specifically designed for sharing threat intelligence in a standardized, machine-readable way?

A.PDF
B.CSV
C.JSON
D.STIX
AnswerD

Structured Threat Information Expression (STIX) is an industry-standard language specifically designed to standardize the representation of cyber threat intelligence. It enables organizations to share structured threat data—including indicators, adversaries, and tactics—in a consistent, machine-readable format that security tools like SIEMs, SOAR platforms, and firewalls can automatically ingest and operationalize.

Why this answer

STIX (Structured Threat Information Expression) is a standardized language and serialization format specifically designed by MITRE and OASIS to represent and share cyber threat intelligence in a machine-readable way. It defines domain objects like Indicator, Malware, ThreatActor, and Relationship, and is typically transported via TAXII. JSON, CSV, and PDF are generic data formats not purpose-built for threat intel semantics.

Exam trap

CS0-004 often tests whether candidates pick a generic serialization format like JSON instead of the domain-specific threat-intelligence standard STIX, so remember STIX is the schema and JSON is merely one possible encoding.

How to eliminate wrong answers

Option A is wrong because PDF is a human-readable document format with no machine-parseable schema for threat intel objects. Option B is wrong because CSV is a flat tabular format that cannot express the graph relationships (e.g., indicator-indicates-malware) central to threat intelligence. Option C is wrong because JSON is only a generic serialization syntax; while STIX can be serialized as JSON, JSON alone carries no threat-intel schema or vocabulary.

36
MCQmedium

During a post-incident review, the CSIRT identifies that the mean time to detect (MTTD) is significantly higher than the industry benchmark. Which initiative would MOST likely reduce MTTD?

A.Conducting more frequent tabletop exercises
B.Rotating credentials for all service accounts
C.Deploying additional endpoint detection and response (EDR) sensors
D.Implementing a new patch management process
AnswerC

Deploying additional EDR sensors directly addresses visibility gaps by expanding host-level monitoring across the enterprise. This allows the security team to collect real-time telemetry, analyze behavioral anomalies, and rapidly detect malicious activities, thereby significantly reducing the mean time to detect (MTTD) future incidents.

Why this answer

Improving detection capabilities through enhanced monitoring and alerting reduces detection time.

37
MCQeasy

An analyst needs to capture the contents of volatile memory from a Windows system suspected of being compromised. Which tool should the analyst use to acquire a memory image?

A.WinPmem
B.LiME
C.FTK Imager
D.dd
AnswerA

WinPmem is an open-source, dedicated physical memory acquisition tool designed specifically for Windows operating systems. It utilizes a kernel driver to safely bypass operating system restrictions and read raw physical memory (RAM), dumping it into standard formats like RAW or ELF for subsequent forensic analysis. This makes it the ideal choice for capturing volatile memory on a Windows host.

Why this answer

WinPmem is a memory acquisition tool for Windows systems, capable of capturing RAM contents for analysis.

38
MCQhard

An analyst runs a YARA rule against a set of files and gets a hit. The rule was written to detect a specific malware family. What is the PRIMARY purpose of using YARA rules in this context?

A.To sandbox the malware for dynamic analysis
B.To identify files that match known malware characteristics
C.To verify the hash of the malware sample
D.To extract strings from the malware
AnswerB

YARA rules define combinations of strings, byte sequences, and boolean logic that describe a malware family's known characteristics, and running a rule against a file set flags any files whose content matches those defined patterns, which is precisely why the analyst got a hit here.

Why this answer

YARA is a pattern-matching tool used to identify and classify malware samples based on textual or binary patterns.

39
MCQhard

During a ransomware incident, the incident response team needs to preserve evidence before containment. Which of the following actions should be performed BEFORE isolating the infected system from the network?

A.Capture the contents of RAM.
B.Run an antivirus scan.
C.Disable the network interface.
D.Capture a forensic image of the hard drive.
AnswerA

Volatile memory contains critical, ephemeral evidence such as active network connections, running processes, decrypted ransomware keys, and unencrypted payloads. According to the Order of Volatility (RFC 3227), RAM must be captured first because any subsequent system interaction or shutdown will permanently destroy or alter this highly perishable data.

Why this answer

The order of volatility requires capturing volatile data like RAM before shutting down or isolating the system, as isolation may alter or lose memory contents.

40
Multi-Selectmedium

A security analyst is investigating a potential malware infection on a Windows workstation. The analyst needs to collect evidence while preserving the order of volatility. Which TWO pieces of data should the analyst collect FIRST? (Select TWO)

Select 2 answers
A.System event logs
B.Contents of the hard drive
C.Registry hives
D.Contents of RAM
E.Running processes and network connections
AnswersD, E

RAM is the most volatile data source because it holds running code, decrypted data, cached credentials, and the current state of the operating system. This information disappears the instant the system loses power or is rebooted, so capturing a memory dump is the highest-priority step. Without it, analysts lose the only copy of in-memory malware behavior and live artifacts.

Why this answer

Options D and E are correct because they represent the most volatile data on a Windows workstation, which must be captured before it is lost on shutdown, reboot, or continued system activity. Contents of RAM (D) hold live memory artifacts such as injected code, encryption keys, and uncommitted malware traces that vanish when power is removed, making it the highest-priority acquisition under the order of volatility. Running processes and network connections (E) are also highly volatile, since process tables, handles, and active TCP/UDP sessions change or disappear rapidly and reveal the malware's execution and command-and-control activity.

By contrast, system event logs (A) and registry hives (C) persist on disk and are less volatile, so they are collected after memory and live-state data, while the contents of the hard drive (B) are the least volatile and typically imaged last.

Exam trap

CS0-004 often tests the order of volatility by presenting disk-based artifacts (logs, registry, hard drive) as attractive options, when RAM and live process/network state must always be collected first.

41
MCQhard

After containing a data breach, the incident response team discovers that an attacker exfiltrated sensitive data over DNS tunneling. Which of the following detection rules would BEST identify similar activity in the future?

A.An SIEM alert for any DNS query exceeding 100 bytes
B.A Snort rule blocking traffic to known malicious IPs
C.A firewall rule that blocks all DNS requests from internal servers
D.A YARA rule that flags DNS queries with high entropy domain names
AnswerD

DNS tunneling utilities typically encode stolen data or command-and-control instructions into the subdomain portion of a query, resulting in highly randomized, high-entropy character strings. Using a YARA rule or similar detection mechanism to analyze DNS logs for high-entropy domains allows security analysts to precisely identify anomalous, machine-generated queries indicative of exfiltration without disrupting legitimate network traffic.

Why this answer

DNS tunneling often involves unusual domain names with high entropy or long subdomains. A YARA rule targeting DNS query patterns can detect such anomalies.

42
MCQeasy

During which phase of the NIST SP 800-61 incident response lifecycle would an organization conduct a lessons learned meeting?

A.Containment, Eradication, and Recovery
B.Detection and Analysis
C.Post-Incident Activity
D.Preparation
AnswerC

NIST SP 800-61 explicitly places the lessons-learned meeting within Post-Incident Activity, where the team reviews the full incident timeline, evaluates response effectiveness, updates playbooks and detection rules, and produces a formal report once containment and recovery are complete.

Why this answer

The post-incident activity phase includes lessons learned, root cause analysis, and improvement actions.

43
MCQmedium

A security analyst detects ransomware on a critical server. Which containment strategy should be implemented FIRST to minimize damage?

A.Run a full antivirus scan on the server
B.Block the ransomware's command-and-control IP at the firewall
C.Rebuild the server from a clean backup
D.Disconnect the server from the network
AnswerD

Disconnecting the server from the network is the primary containment action to halt active ransomware propagation. This immediate physical or logical isolation prevents the malware from encrypting mapped network drives, communicating with its command-and-control server, or spreading to other vulnerable hosts on the segment.

Why this answer

Immediate network isolation (short-term containment) stops lateral spread and limits damage.

44
Multi-Selecthard

A security analyst is investigating a potential data exfiltration incident. The analyst captures memory from a Windows system and finds a process that is injecting code into other processes. Which THREE indicators from the memory analysis would MOST strongly suggest malicious activity? (Select THREE.)

Select 3 answers
A.The process has memory regions with RWX permissions.
B.The process is hidden from the task manager.
C.The process is making calls to WriteProcessMemory and CreateRemoteThread.
D.The process name is a known Windows system process.
E.The process has a valid digital signature.
AnswersA, B, C

RWX (read-write-execute) memory pages in a process are a high-confidence indicator of injected shellcode because modern operating systems enforce W^X (write XOR execute) policies; legitimate code typically resides in read-only executable regions or uses explicit VirtualProtect transitions. While some Just-In-Time (JIT) engines may briefly allocate RWX, persistent regions outside known JIT heaps warrant immediate investigation.

Why this answer

Option A is correct because memory regions marked RWX (read-write-execute) are a strong indicator of code injection, since legitimate code typically resides in RX (read-execute) or read-only pages, and RWX allows an attacker to write and then execute shellcode in the same region. Option B is correct because a process hidden from Task Manager indicates an attempt to evade user and analyst detection, which is characteristic of rootkits or injected/hooked processes used in exfiltration tooling. Option C is correct because WriteProcessMemory followed by CreateRemoteThread is the canonical Windows API sequence for process injection, letting an attacker place code in a remote process and start a thread to run it, which strongly suggests malicious activity.

Option D is not correct on its own because malware frequently masquerades as a known Windows system process (e.g., svchost.exe), so a familiar name alone is not a reliable malicious indicator. Option E is not correct because a valid digital signature generally indicates trusted, unmodified software and argues against malicious tampering, not for it.

Exam trap

CS0-004 often tests whether candidates over-weight superficial indicators like process names or digital signatures, when the strongest malicious indicators are behavioral and memory-permission anomalies.

45
MCQeasy

A security analyst is classifying an incident where an employee's workstation is infected with ransomware that encrypts files and displays a ransom note. Which incident category and severity level best describe this scenario?

A.DDoS, low
B.Malware, moderate
C.Data breach, high
D.Insider threat, high
AnswerB

Ransomware is malware, so the category is straightforward. Moderate severity fits because a single infected workstation is contained, not spreading enterprise-wide, yet file encryption and a ransom demand still disrupt business operations and require remediation.

Why this answer

Ransomware is a specific subtype of malware that encrypts files and demands payment, making 'Malware' the appropriate incident category. The severity is 'moderate' because while the infection impacts a single workstation and causes data loss, it does not immediately compromise the entire network or expose sensitive data at scale, aligning with typical moderate-severity criteria for isolated malware incidents.

Exam trap

In the CompTIA CySA+ exam, a common trap is confusing 'Malware' with 'Data breach' when ransomware is involved. Ransomware typically encrypts files but does not necessarily exfiltrate them; thus classification as 'Malware' is more appropriate than 'Data breach' unless there is evidence of data exfiltration. Additionally, severity is 'moderate' for a single workstation incident, not 'high', which would require broader organizational impact.

How to eliminate wrong answers

Option A is wrong because a DDoS (Distributed Denial of Service) attack involves overwhelming a network or server with traffic to disrupt availability, not encrypting files on a single workstation; ransomware does not cause network-level flooding. Option C is wrong because a data breach requires unauthorized access or exfiltration of sensitive data, whereas ransomware here only encrypts local files without evidence of data theft or exposure. Option D is wrong because an insider threat involves malicious or negligent actions by an authorized user, but the scenario describes an external malware infection (ransomware) with no indication of employee intent or privilege misuse.

46
MCQeasy

A security analyst is reviewing indicators of compromise (IOCs) from a recent phishing campaign. Which of the following is an example of an email-related IOC?

A.Domain name in the URL
B.Suspicious sender email address
C.IP address of the sender's mail server
D.File hash of an attachment
AnswerB

The sender's email address is a primary, direct email indicator of compromise found within the SMTP envelope or mail headers (such as the "From:" field). Analysts use this specific attribute to create mail transport rules, blocklists, and search mailboxes for phishing campaigns targeting the organization.

Why this answer

A suspicious sender email address is an email-header-level artifact — it appears in the From, Reply-To, or Return-Path fields and is directly tied to the phishing email itself. That makes it an email-related IOC, unlike network or file artifacts.

Exam trap

CS0-004 often tests IOC categorization — candidates pick C or D because they are 'from the email,' but the exam distinguishes email-header IOCs from network and file IOCs, and only the sender address lives in the email header.

How to eliminate wrong answers

Option A is wrong because a domain name in a URL is a web/network indicator extracted from the link, not from the email header itself. Option C is wrong because the sender's mail server IP is a network-layer indicator (often found in Received headers or DNS lookups), categorized as a network IOC rather than an email IOC. Option D is wrong because a file hash of an attachment is a host/file indicator used for endpoint detection, not an email-header artifact.

47
MCQmedium

An incident responder needs to collect forensic evidence from a server that was attacked. The evidence includes network connections, running processes, memory contents, and disk data. According to the order of volatility, which piece of evidence should the responder collect FIRST?

A.Memory contents
B.Network connections
C.Running processes
D.Disk data
AnswerB

Active network connections, routing tables, and ARP caches are extremely transient and can terminate or change in milliseconds as sessions close. Capturing these live state metrics first is critical before any local tools are run that might alter the network socket state or terminate active connections.

Why this answer

The order of volatility dictates that the most volatile data (e.g., CPU registers, network connections) should be collected first. Network connections change rapidly.

48
MCQeasy

During the preparation phase of the NIST SP 800-61 incident response lifecycle, a security analyst is tasked with ensuring the team has the necessary tools and resources. Which of the following is the MOST important activity to perform during this phase?

A.Sharing indicators of compromise with threat intel platforms
B.Developing and testing incident response playbooks
C.Conducting root cause analysis of past incidents
D.Analyzing malware samples in a sandbox
AnswerB

Developing, documenting, and testing incident response playbooks through tabletop exercises or simulations is a fundamental task of the Preparation phase. This proactive step ensures that the incident response team has validated, repeatable procedures to follow when an active threat is detected. It establishes the necessary operational readiness before any actual security incident occurs.

Why this answer

In the NIST SP 800-61 preparation phase, the most important activity is establishing the capability to respond before an incident occurs, which centers on developing, documenting, and testing incident response playbooks. Playbooks codify roles, communication paths, and step-by-step procedures so the team can act consistently under pressure. Testing them (tabletop exercises, simulations) validates that tools, contacts, and escalation paths actually work.

Exam trap

CS0-004 often tests phase mapping — candidates see a security activity that sounds important (sharing IOCs, sandboxing malware) and pick it without checking whether it belongs to the preparation phase versus detection, analysis, or post-incident activity.

How to eliminate wrong answers

Option A is wrong because sharing indicators of compromise with threat intel platforms is an information-sharing activity that typically occurs during detection, analysis, or post-incident phases, not as the core preparation deliverable. Option C is wrong because root cause analysis is a post-incident activity performed after an incident is contained and eradicated, not during preparation. Option D is wrong because analyzing malware samples in a sandbox is a detection/analysis-phase task that occurs once a sample is in hand, not a preparation-phase priority.

49
MCQeasy

An organization uses MISP as its threat intelligence platform. After a security incident, the team wants to share IOCs with other trusted organizations. Which standard should they use to package and exchange the threat intelligence?

A.SNMP
B.NetFlow
C.SMTP
D.STIX/TAXII
AnswerD

Structured Threat Information Expression (STIX) provides a standardized XML/JSON schema to represent cyber threat intelligence, while Trusted Automated Exchange of Intelligence Information (TAXII) is the application-layer protocol used to securely route this data. MISP natively supports STIX/TAXII to enable automated, machine-to-machine sharing of indicators of compromise (IoCs) and threat actor profiles across diverse security tools.

Why this answer

STIX (Structured Threat Information Expression) is the standard for describing threat intelligence, and TAXII is the protocol for sharing it.

50
Multi-Selectmedium

An incident response team is conducting post-incident activities after a ransomware attack. The team wants to improve detection and response for future incidents. Which TWO actions are most appropriate for updating detection rules? (Select TWO.)

Select 2 answers
A.Conduct a tabletop exercise for the incident response team.
B.Increase the frequency of vulnerability scans.
C.Create YARA rules to identify the ransomware file hashes and patterns.
D.Share IOCs with external threat intelligence platforms.
E.Update the SIEM correlation rules to detect the TTPs observed.
AnswersC, E

YARA rules are highly effective for endpoint detection of a known ransomware strain because they can match on multiple characteristics beyond simple hashes—such as unique strings, mutex names, byte patterns, PE section anomalies, and file metadata. By creating a rule that evaluates file content and structure, the team can identify the malicious payload regardless of filename or hash mutation (e.g., hash-busting variants), enabling rapid triage on forensic images and live systems. This directly addresses the immediate need to recognize the specific ransomware artifacts that were observed during the incident.

Why this answer

Option C is correct because YARA rules are specifically designed to identify malware based on file hashes, byte patterns, and strings, so creating them from the ransomware samples observed during the incident directly improves future detection of that malware. Option E is correct because updating SIEM correlation rules to detect the observed TTPs (tactics, techniques, and procedures) enables the organization to alert on the attacker's behavior, not just static indicators, which strengthens detection and response for future incidents. Option A is not appropriate here because a tabletop exercise tests response processes and decision-making rather than updating detection rules.

Option B does not belong because increasing vulnerability scan frequency addresses vulnerability management, not detection rule improvement. Option D is also not the best fit because sharing IOCs with external platforms contributes to threat intelligence sharing and community defense, but it does not itself update the organization's detection rules.

Exam trap

The trap is choosing activities that improve overall security posture (tabletop exercises, more scans, IOC sharing) instead of the two actions that specifically update detection rules—YARA and SIEM correlation.

51
MCQhard

An analyst is investigating a possible data exfiltration incident. The analyst has acquired a memory dump from the compromised system. Which of the following would be the BEST approach to extract evidence of exfiltration?

A.Calculating the MD5 hash of the memory dump and comparing it to known good hashes
B.Using a memory analysis framework like Volatility to analyze network connections and process memory
C.Searching the memory dump for strings containing 'password'
D.Rebooting the system and capturing a new memory dump
AnswerB

Utilizing an advanced memory forensics tool like Volatility allows an analyst to reconstruct active network sockets, identify rogue processes, and extract unencrypted payloads from RAM. This deep-dive analysis can reveal active TCP/UDP connections to external command-and-control (C2) servers or identify the specific buffers used to stage exfiltrated data.

Why this answer

Memory analysis tools like Volatility can extract network connections, process memory, and other artifacts that may show exfiltration activity.

52
MCQmedium

During post-incident activities, the security team reviews metrics. Which metric measures the average time taken to detect an incident?

A.MTTR
B.SLA
C.RTO
D.MTTD
AnswerD

Mean Time to Detect is the primary security metric used to calculate the average elapsed time between the initial occurrence of a security compromise and its formal identification by security tools or analysts. Reviewing MTTD during post-incident activities helps organizations evaluate the effectiveness of their monitoring controls, SIEM correlation rules, and threat hunting capabilities.

Why this answer

MTTD (Mean Time to Detect) is the metric that measures the average time between when an incident actually occurs and when it is detected by the security team. It is a core SOC effectiveness metric used in post-incident reviews to evaluate detection capability.

Exam trap

CS0-004 often tests the family of incident metrics (MTTD, MTTA, MTTR, RTO, RPO) — the trap is confusing 'detect' with 'respond' or 'recover', so candidates pick MTTR when the question explicitly says detection.

How to eliminate wrong answers

Option A is wrong because MTTR (Mean Time to Repair/Resolve) measures the average time to remediate an incident after detection, not to detect it. Option B is wrong because SLA (Service Level Agreement) is a contractual commitment, not a detection metric. Option C is wrong because RTO (Recovery Time Objective) is the maximum acceptable downtime defined in business continuity planning, not an average detection time.

53
Multi-Selectmedium

During dynamic analysis of a suspicious file in a sandbox environment, which THREE behaviors are considered indicators of compromise (IOCs) that suggest malicious activity? (Choose THREE.)

Select 3 answers
A.Creating a registry run key to achieve persistence.
B.Outbound network connections to a known malicious IP.
C.The file reading its own content.
D.Dropping an executable file in the startup folder.
E.Opening a text file that was already present.
AnswersA, B, D

A registry Run key (e.g., HKCU\Software\Microsoft\Windows\CurrentVersion\Run) is an autostart extension point that launches a specified executable at user logon. Malware frequently adds entries here to achieve persistence, ensuring the malicious code runs on every subsequent login. Sandbox analysis treats this as high-risk because legitimate programs rarely modify such keys during a single execution, especially with randomly named or masqueraded values.

Why this answer

Option A is correct because creating a registry Run key (e.g., HKCU\Software\Microsoft\Windows\CurrentVersion\Run or HKLM\...\Run) is a classic persistence mechanism that causes malware to execute automatically at user logon or system startup, making it a strong IOC. Option B is correct because outbound network connections to a known malicious IP indicate command-and-control (C2) communication, data exfiltration, or payload retrieval, which are hallmark malicious behaviors observed during sandbox dynamic analysis. Option D is correct because dropping an executable into the Startup folder (e.g., %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup) establishes persistence by launching the file automatically at user logon, another well-known IOC.

Option C is not an IOC because a file reading its own content is common benign behavior (e.g., self-verification, configuration parsing) and does not by itself indicate malicious activity. Option E is not an IOC because opening a pre-existing text file is normal, expected behavior for many legitimate applications and lacks the persistence, network, or payload-dropping characteristics of malicious activity.

Exam trap

The trap is selecting behaviors that seem suspicious but are actually benign, such as a file reading itself; candidates may overestimate the maliciousness of self-referential actions.

54
MCQmedium

During a phishing incident, an analyst extracts a URL from the email body and searches VirusTotal. The URL is associated with a credential harvesting page. Which type of indicator is this URL?

A.Indicator of Compromise (IOC)
B.Indicator of Attack (IOA)
C.Campaign
D.TTP
AnswerA

A malicious URL extracted from a phishing email serves as a classic Indicator of Compromise (IOC). Security analysts use these reactive, static artifacts—such as domain names, IP addresses, and file hashes—to identify systems that have already been breached or targeted. Once identified, IOCs are ingested into security tools like SIEMs and firewalls to block future traffic and scope the extent of the intrusion.

Why this answer

The URL is an observable that indicates malicious activity and can be used to detect and block further phishing attempts, making it an IOC.

55
Multi-Selectmedium

A security analyst is investigating a phishing incident that resulted in credential theft. Which TWO actions should the analyst take as part of short-term containment? (Choose two.)

Select 2 answers
A.Block the phishing domain at the email gateway
B.Rebuild the affected workstations from a clean image
C.Conduct a full vulnerability scan of the network
D.Change all user passwords in the domain
E.Disable the compromised user accounts
AnswersA, E

Blocking the phishing domain at the email gateway is immediate containment because it prevents subsequent emails carrying the same malicious payload from reaching other recipients, thereby reducing the number of users exposed to the lure. This email gateway control is fast, reversible, and can also block outbound traffic if needed, but it does not remediate credentials that have already been stolen.

Why this answer

Option A is correct because blocking the phishing domain at the email gateway is a short-term containment action that immediately prevents additional phishing emails from the same domain from reaching other users and stops further credential harvesting. Option E is correct because disabling the compromised user accounts is a short-term containment step that stops the attacker from using the stolen credentials to access resources, halting ongoing unauthorized activity. Option B is not appropriate here because rebuilding workstations from a clean image is a longer-term eradication and recovery action, and credential theft does not necessarily require reimaging.

Option C is not a containment action; a full vulnerability scan is a broader assessment activity that does not stop the active incident. Option D is not the best short-term containment step because changing all domain user passwords is a broad, disruptive action, whereas disabling the specific compromised accounts is more targeted and immediate.

Exam trap

CS0-004 often tests the distinction between short-term containment and other incident response phases (e.g., eradication, recovery), causing candidates to select remediation actions like rebuilding systems or changing all passwords instead of immediate, targeted containment steps.

56
MCQeasy

During the preparation phase of the NIST SP 800-61 incident response lifecycle, which of the following is the MOST important activity to ensure effective incident response?

A.Using YARA rules to detect malware in the environment
B.Implementing network segmentation to limit lateral movement
C.Conducting a root cause analysis after each incident
D.Creating and training the incident response team
AnswerD

People execute the plan; without a formed, trained team, detection, analysis and containment stall regardless of tooling. Creating and training the incident response team during preparation directly satisfies the stem's requirement for effective response capability before an incident occurs.

Why this answer

The preparation phase of NIST SP 800-61 is about establishing the capability to respond before an incident occurs. The single most critical element is having a trained, organized incident response team with defined roles, responsibilities, and communication channels. Without a competent team, detection tools, segmentation, and post-incident analysis cannot be effectively leveraged.

NIST explicitly lists 'Incident Response Team' as a key preparation component, including team formation, training, and equipping.

Exam trap

CS0-004 often tests the distinction between preparation and other phases, and candidates may confuse preventive controls (like segmentation) or detection tools (like YARA) as preparation activities, when the most critical preparation is the human team and its readiness.

How to eliminate wrong answers

Option A is wrong because YARA rules are a detection mechanism used during detection and analysis, not a preparation activity; they are part of the tooling but not the most important preparatory step. Option B is wrong because network segmentation is a preventive architectural control that supports containment, but it is not the primary preparation activity for incident response; it is a general security measure. Option C is wrong because root cause analysis is performed during post-incident activity (lessons learned), which is the final phase of the lifecycle, not preparation.

57
MCQmedium

After containing a ransomware incident, the incident response team is conducting post-incident activities. Which action is MOST important to prevent a similar attack in the future?

A.Sharing IOCs with other organizations via a threat intelligence platform
B.Reimaging all affected systems
C.Performing a root cause analysis and implementing remediation
D.Updating the incident response plan
AnswerC

Performing a root cause analysis (RCA) allows the incident response team to trace the attack path back to the initial point of entry and understand the vulnerabilities exploited. Implementing targeted remediation based on these findings—such as patching software, disabling unnecessary protocols, or enforcing multi-factor authentication—directly eliminates the security gaps. This is the only action that systematically prevents the same threat actor or campaign from recurring.

Why this answer

Conducting a root cause analysis identifies the underlying vulnerability or weakness that allowed the attack, enabling targeted remediation.

58
Multi-Selecthard

During a forensic investigation, an analyst must preserve evidence in accordance with forensic sound procedures. Which THREE of the following practices should the analyst follow? (Select THREE.)

Select 3 answers
A.Run a full antivirus scan on the target drive
B.Document all actions taken in a chain of custody form
C.Use a write blocker when imaging a hard drive
D.Create a cryptographic hash of the original media before imaging
E.Boot the system to ensure it is operational
AnswersB, C, D

Maintaining a complete chain of custody form is essential because it documents every interaction with the evidence — who collected it, when, where, and how it was handled, transferred, and secured. In court, opposing counsel will attack a gap in this record as evidence tampering or mishandling. A continuous, written log of all actions taken during acquisition and analysis preserves the integrity narrative and is what makes the forensic evidence legally admissible.

Why this answer

Option B is correct because maintaining a chain of custody form that documents every action, transfer, and access of the evidence is essential for forensic soundness and admissibility in court. Option C is correct because a write blocker prevents any modification to the original hard drive during imaging, preserving the integrity of the evidence. Option D is correct because creating a cryptographic hash (e.g., MD5 or SHA-256) of the original media before imaging provides a verifiable baseline to prove the image is an exact copy and that the original was not altered.

Option A is not appropriate because running an antivirus scan modifies the drive (e.g., quarantining or deleting files), which violates forensic soundness. Option E is not appropriate because booting the system can alter the state of the drive (e.g., changing timestamps, creating temporary files), compromising evidence integrity.

Exam trap

The trap is that options A and E sound like reasonable 'verification' steps, but CompTIA expects candidates to recognize that any action altering the original media — including antivirus scans or booting — violates forensic soundness.

59
MCQeasy

A security analyst receives an alert about a possible ransomware outbreak. Which short-term containment action should be performed FIRST to prevent further spread?

A.Disable the user account
B.Rebuild the system
C.Update antivirus signatures
D.Isolate the system from the network
AnswerD

Isolating the affected host from the network is the primary containment step during a ransomware incident. This action immediately halts the propagation of the malware to other network segments, prevents the encryption of mapped network shares, and severs command-and-control (C2) communications required for key exchange.

Why this answer

Network isolation (disconnecting the affected system from the network) is a quick short-term containment step that stops the ransomware from communicating with C2 or spreading laterally.

60
MCQmedium

During the detection and analysis phase of incident response, a security analyst identifies suspicious outbound traffic from a finance workstation to a known malicious IP address at 2:00 AM. The analyst checks the firewall logs and sees a single connection. Which action should the analyst take FIRST according to NIST SP 800-61?

A.Validate the incident by reviewing additional data sources.
B.Run a full antivirus scan on the workstation.
C.Isolate the workstation from the network immediately.
D.Notify law enforcement per the incident response plan.
AnswerA

Validating the incident is the crucial initial step in the detection and analysis phase. This involves corroborating the initial alert by reviewing additional data sources such as logs from firewalls, intrusion detection systems, endpoint detection and response (EDR) tools, and network flow data. This process helps to confirm if the alert represents a true security incident, thereby minimizing false positives and preventing the premature allocation of valuable incident response resources to non-threats.

Why this answer

NIST SP 800-61 emphasizes that during detection and analysis, the first step is to validate the incident as a true positive before escalating or containing. The analyst should confirm the alert is not a false positive by gathering additional evidence.

61
MCQmedium

A security analyst is triaging an alert indicating that a user's workstation has been infected with ransomware. The file server shows signs of encryption. The analyst needs to contain the incident. Which action should the analyst take FIRST to minimize damage?

A.Running a full antivirus scan on the workstation
B.Disabling the user's Active Directory account
C.Rebuilding the workstation from a known good image
D.Disconnecting the workstation from the network
AnswerD

Disconnecting the workstation from the network is the most immediate and effective short-term containment action for an active ransomware infection. This action physically isolates the compromised system, preventing the ransomware from communicating with command-and-control servers, exfiltrating data, or attempting to spread laterally to other network resources, shares, or systems. It buys critical time for incident responders to analyze the threat and plan further remediation steps without risking wider network compromise, thus limiting the overall impact of the incident.

Why this answer

Disconnecting the infected workstation from the network stops the ransomware from spreading to other systems via network shares.

62
MCQmedium

An incident responder is called to a server room where a critical database server is exhibiting signs of compromise. The responder must preserve evidence while preventing further damage. Which of the following is a short-term containment strategy that also preserves evidence?

A.Reboot the server into safe mode.
B.Disconnect the network cable from the server.
C.Power off the server to freeze the system state.
D.Run a memory dump with WinPmem before any action.
AnswerB

Disconnecting the network cable immediately isolates the compromised server from the network, preventing further malicious activity such as data exfiltration, lateral movement, or command-and-control communication. This crucial containment step preserves the current volatile system state for subsequent forensic acquisition without introducing significant changes, allowing for a more accurate investigation.

Why this answer

Disconnecting the network cable (Option B) is the correct short-term containment strategy because it immediately isolates the compromised database server from the network, preventing further lateral movement or data exfiltration, while preserving the volatile system state (memory, running processes, open network connections) for forensic analysis. This action stops active network-based attacks without altering the contents of RAM or disk, which is critical for evidence integrity.

Exam trap

In the CompTIA CySA+ exam, the trap is that candidates may select Option C (power off) thinking it 'freezes' the state, but this destroys volatile evidence and does not contain the incident if the attacker has remote access. Option D (memory dump) is a forensic step, not containment. Option A (reboot) modifies the system.

Only Option B isolates while preserving volatile data.

How to eliminate wrong answers

Option A is wrong because rebooting into safe mode will overwrite volatile memory (RAM) and modify system logs, destroying critical forensic evidence such as active network connections, running malware processes, and encryption keys. Option C is wrong because powering off the server causes a hard shutdown that erases all volatile memory data and may trigger anti-forensic mechanisms (e.g., self-deleting scripts), losing the most time-sensitive evidence. Option D is wrong because running a memory dump with WinPmem before any containment action is a forensic acquisition step, not a containment strategy; it takes time and does not stop ongoing damage or network-based attacks.

63
MCQmedium

During dynamic malware analysis in a sandbox, an analyst observes that the malware attempts to connect to a remote IP address on port 443, modifies the Windows registry under HKCU\Software\Microsoft\Windows\CurrentVersion\Run, and drops a DLL in the system32 folder. Which type of IOC is most indicative of persistence?

A.The registry modification to the Run key
B.The network connection over port 443
C.The remote IP address
D.The dropped DLL file hash
AnswerA

The HKCU\Software\Microsoft\Windows\CurrentVersion\Run key causes the referenced program to execute automatically at user logon, establishing persistence across reboots. The outbound port 443 connection indicates command-and-control, and the dropped system32 DLL is a payload artefact, but only the Run key modification ensures the malware survives restarts.

Why this answer

The registry modification to HKCU\Software\Microsoft\Windows\CurrentVersion\Run is the most indicative of persistence because this specific key is designed to automatically launch programs when a user logs in. By adding a value here, the malware ensures it executes on every system startup, which is the definition of persistence. In contrast, network connections and file drops are common during execution but do not inherently guarantee re-execution after a reboot.

Exam trap

CompTIA CySA+ often tests the distinction between indicators of activity (network connections, file drops) and indicators of persistence (registry Run keys, scheduled tasks, services), and the trap here is that candidates confuse a common malware behavior (like connecting to a C2 server) with a mechanism that ensures the malware runs again after reboot.

How to eliminate wrong answers

Option B is wrong because a network connection over port 443 (HTTPS) indicates command-and-control communication or data exfiltration, not a mechanism to survive a reboot. Option C is wrong because the remote IP address is merely a destination for network activity and provides no information about automatic re-execution. Option D is wrong because the dropped DLL file hash is a file-based indicator of compromise (IOC) that identifies the malware sample, but the file alone does not ensure it will be loaded again after a restart without a persistence mechanism like a Run key or service.

64
MCQmedium

During a forensic investigation, an analyst creates a disk image using dd with a SHA256 hash. Later, the analyst needs to verify the integrity of the image before analysis. Which command should the analyst use to compare the original hash with a newly computed hash?

A.md5sum original.dd
B.dd if=image.dd | sha256sum
C.sha256sum image.dd
D.chksum -a sha256 image.dd
AnswerC

Running sha256sum directly against the image file recomputes its SHA256 digest using the same algorithm and tool convention as the original acquisition hash, producing a value the analyst can directly diff against the recorded original hash to confirm bit-for-bit integrity and an unbroken chain of custody before proceeding with analysis.

Why this answer

The analyst needs to recompute the SHA256 hash of the image file and compare it to the original value. The command 'sha256sum image.dd' computes the SHA256 digest of the file directly, which is the standard Linux utility for this purpose and produces output that can be diffed against the original hash.

Exam trap

CS0-004 often tests command syntax and hash algorithm matching — candidates pick md5sum out of habit or choose a non-existent command like 'chksum -a sha256', forgetting that the hash algorithm must match the original baseline exactly.

How to eliminate wrong answers

Option A is wrong because md5sum computes an MD5 hash, not SHA256, so it cannot verify a SHA256 baseline and MD5 is cryptographically broken for integrity assurance. Option B is wrong because piping 'dd if=image.dd | sha256sum' works but is unnecessarily indirect and error-prone; more importantly, it is not the canonical command and introduces an extra process that could mask read errors — the direct sha256sum is preferred. Option D is wrong because 'chksum -a sha256' is not a valid standard Linux command for computing SHA256 digests; the correct tools are sha256sum or openssl dgst -sha256.

65
MCQmedium

An organization has been experiencing repeated phishing attacks that bypass email filters. The incident response team wants to enhance detection by creating rules based on characteristics of the phishing emails. Which of the following IOCs would be most effective for detecting similar phishing campaigns?

A.Registry keys modified by the payload
B.File hashes of attached malware
C.IP addresses of the phishing servers
D.Email subject lines and sender domain
AnswerD

Email subject lines and sender domains serve as highly effective, static indicators of compromise that can be ingested directly into secure email gateways (SEGs) to block incoming campaigns. By creating transport rules or blocklists based on these specific header elements, security analysts can proactively intercept and neutralize widespread phishing waves before users interact with them.

Why this answer

Email subject lines and sender domains are the most effective IOCs for detecting phishing campaigns that bypass email filters, because these characteristics are directly observable at the email gateway and are commonly reused across a campaign. Attackers often reuse subject line templates and sender domains (or lookalike domains) across many messages, making them reliable detection pivots. Unlike file hashes or registry keys, these IOCs do not require the payload to execute or the attachment to be present, so they catch the phishing attempt at delivery time.

Exam trap

The trap here is confusing host-based IOCs (hashes, registry keys) with network/email-layer IOCs — candidates often pick file hashes because they sound 'technical,' but the question asks about detecting phishing emails at the filter-bypass stage, which requires email-observable indicators.

How to eliminate wrong answers

Option A is wrong because registry keys modified by the payload are host-based IOCs that only appear after the malware has already executed, so they cannot detect phishing emails at the email gateway and are useless for campaigns that bypass filters without executing. Option B is wrong because file hashes of attached malware only detect known, previously seen payloads; phishing campaigns routinely mutate attachments or use unique hashes per recipient, and many phishing emails contain no attachment at all (just links). Option C is wrong because IP addresses of phishing servers are volatile — attackers rotate infrastructure rapidly, use CDNs, and compromise legitimate hosts — so IP-based IOCs have a very short useful lifespan and miss the email-layer characteristics that would catch the campaign earlier.

66
Multi-Selecteasy

A security analyst is reviewing IOCs from a threat intelligence feed. The analyst wants to enrich the IOCs using open-source tools. Which THREE tools are commonly used for IOC enrichment? (Select three.)

Select 3 answers
A.WHOIS
B.Wireshark
C.VirusTotal
D.Shodan
E.Nmap
AnswersA, C, D

WHOIS queries domain registration databases, returning registrar, registrant contact, creation and expiration dates, and nameserver records. For an IOC like a known malicious domain, WHOIS enables analysts to pivot on registration metadata, identify shared infrastructure, or detect typosquatting and recently registered domains. It is a read-only lookup service, not a traffic analysis tool, making it a first-line passive enrichment source.

Why this answer

WHOIS (A) is correct because it enriches domain and IP IOCs with registration data such as registrar, creation/expiration dates, name servers, and registrant contact details, which help attribute infrastructure to threat actors. VirusTotal (C) is correct because it aggregates results from dozens of antivirus engines, URL/domain scanners, and sandboxes to provide reputation, detection ratios, and behavioral context for hashes, URLs, domains, and IPs. Shodan (D) is correct because it enriches IP and service IOCs with internet-facing banner data, open ports, service versions, TLS certificates, and geolocation, revealing exposed infrastructure tied to an indicator.

Wireshark (B) is a packet capture and protocol analysis tool used for live traffic inspection, not for querying external reputation or registration data about IOCs. Nmap (E) is a network scanning and host-discovery utility used to probe systems directly, not an open-source enrichment service that correlates IOCs against third-party intelligence.

Exam trap

CS0-004 often tests whether candidates confuse enrichment tools (reputation, registration, exposure data) with analysis or scanning tools (Wireshark, Nmap), so options that are legitimate security tools but not enrichment sources are the trap.

67
MCQmedium

An organization is experiencing a DDoS attack targeting its web servers. Which of the following is the BEST short-term containment strategy?

A.Rebuild the web servers from backups.
B.Implement rate limiting on the firewall.
C.Reroute traffic through a DDoS mitigation service.
D.Disable the web server accounts.
AnswerC

Rerouting traffic to a cloud-based DDoS mitigation or scrubbing service (via DNS or BGP redirection) is the most effective containment strategy. This allows the provider to filter out malicious traffic at the network edge using global scrubbing centers, ensuring that only clean, legitimate traffic reaches the organization's origin servers.

Why this answer

Short-term containment for DDoS often involves rerouting traffic through a scrubbing center or cloud-based DDoS mitigation service that filters malicious traffic.

68
MCQmedium

A security team is responding to a phishing incident that led to credential compromise. Which of the following is the BEST short-term containment action to prevent further damage?

A.Disable the compromised user account.
B.Rebuild the user's workstation.
C.Block the phishing email's source IP at the firewall.
D.Rotate all domain admin passwords.
AnswerA

Disabling the compromised account is the most immediate and effective containment action to halt active exploitation. It instantly revokes the attacker's access to network resources, cloud services, and email, preventing lateral movement or data exfiltration using those specific credentials. This action buys the incident response team time to investigate the scope of the breach without allowing further unauthorized activity.

Why this answer

Short-term containment aims to stop the attack quickly. Disabling the compromised account prevents the attacker from using the stolen credentials to access resources.

69
Multi-Selectmedium

An incident responder is performing containment of a ransomware incident that has encrypted files on several file servers. Which THREE actions are appropriate for long-term containment and recovery? (Select THREE)

Select 3 answers
A.Blocking the ransomware's command-and-control IP at the firewall
B.Patching the vulnerability exploited by the ransomware
C.Rebuilding affected servers from known-good backups
D.Rotating all service account credentials
E.Isolating the affected network segment
AnswersB, C, D

Patching the specific vulnerability that the ransomware exploited is a definitive eradication measure because it closes the door at the root cause, preventing both the current strain and any similar variations from re-entering through the same path. This step, derived from the incident's root cause analysis, is essential for protecting not only the affected hosts but also all other unpatched systems in the environment. Without this patch, even after rebuilding or credential rotation, the same hole remains, leaving the network vulnerable to immediate reinfection.

Why this answer

Patching the exploited vulnerability (B) is correct because it removes the initial access vector, preventing the ransomware from re-infecting systems during long-term containment and recovery. Rebuilding affected servers from known-good backups (C) is correct because encrypted systems cannot be trusted after compromise; restoring from clean backups ensures integrity and enables recovery. Rotating all service account credentials (D) is correct because ransomware often harvests credentials for lateral movement and persistence, so rotating them invalidates stolen secrets and blocks re-entry.

Blocking the C2 IP (A) and isolating the affected segment (E) are valid immediate/short-term containment measures, but they do not address the root cause or restore operations, so they are not the long-term containment and recovery actions requested.

Exam trap

CS0-004 often tests the distinction between short-term containment actions (e.g., blocking IPs, isolating segments) and long-term containment/recovery actions (e.g., patching, rebuilding, rotating credentials), causing candidates to select immediate but temporary measures instead of permanent remediation steps.

70
MCQmedium

An analyst is investigating a suspected data breach. The analyst needs to identify which files were exfiltrated and preserve evidence. According to the order of volatility, which of the following should the analyst capture FIRST?

A.Contents of the hard drive
B.Network connections and listening ports
C.CPU registers and cache
D.System logs
AnswerC

CPU registers and L1/L2/L3 caches represent the absolute highest tier of volatility in digital forensics. This data changes nanosecond by nanosecond as the processor executes instructions, and it is completely lost the moment any tool is run or the system state changes. Analysts must capture this ultra-transient data first to preserve the immediate execution state of the system.

Why this answer

Order of volatility prioritizes capturing volatile data first. CPU registers and cache are the most volatile, then RAM, swap, disk, etc.

71
MCQmedium

During the detection and analysis phase of incident response, a security analyst identifies suspicious outbound traffic from a workstation to an external IP address known for command and control (C2) activity. Which classification should the analyst assign to this incident?

A.Insider threat
B.Data breach
C.Phishing
D.Malware
AnswerD

Outbound beaconing or persistent connections to a known command-and-control (C2) IP address are primary indicators of compromise (IoCs) associated with malware infections, such as trojans or botnet agents. Identifying this traffic during the detection and analysis phase allows analysts to confirm the presence of malicious software executing on the workstation.

Why this answer

The suspicious outbound traffic to a known C2 IP indicates that the workstation is likely infected with malware that is beaconing to its command and control server. This is a classic indicator of a malware infection, where the compromised host communicates with an external entity for instructions or data exfiltration. Therefore, the incident should be classified as malware.

Exam trap

CS0-004 often tests the ability to distinguish between incident classifications based on observable indicators; candidates might confuse malware with data breach when seeing outbound traffic, but the key is that C2 communication indicates an active malware infection, not necessarily a confirmed data breach.

How to eliminate wrong answers

Option A is wrong because an insider threat involves a trusted internal user misusing access, not external C2 communication. Option B is wrong because a data breach refers to unauthorized data exfiltration, but the scenario only mentions suspicious traffic, not confirmed data theft. Option C is wrong because phishing is an initial attack vector (e.g., deceptive emails), not the post-compromise C2 activity observed.

72
MCQeasy

An incident responder is classifying an incident. The incident involves ransomware encrypting files on multiple workstations, causing significant business disruption. Which severity level should be assigned to this incident?

A.Medium
B.High
C.Informational
D.Low
AnswerB

High-severity incidents involve severe degradation of critical services, widespread compromise, or the encryption of multiple production systems by ransomware. This classification triggers immediate escalation, mobilization of the full incident response team, and containment protocols to prevent catastrophic operational downtime or data loss.

Why this answer

Ransomware affecting multiple workstations causes high impact and likely critical business disruption, so it should be classified as high or critical severity. The highest typical level is 'Critical' (or similar).

73
Multi-Selecthard

A security analyst is investigating a potential insider threat where a user is suspected of exfiltrating sensitive data via USB drives. The analyst needs to gather evidence while preserving the chain of custody. Which THREE actions should the analyst perform? (Choose THREE.)

Select 3 answers
A.Creating a forensic image of the USB drive using a write blocker
B.Disabling the user's network account immediately
C.Interviewing the user about their activities
D.Documenting the chain of custody for the USB drive
E.Computing a hash of the original USB drive and the forensic image
AnswersA, D, E

A write blocker permits read-only access, preventing any modification to the USB drive's original data during acquisition. Imaging captures a bit-for-bit replica for analysis, directly satisfying the chain-of-custody requirement by leaving the source evidence untouched and forensically sound.

Why this answer

Option A is correct because creating a forensic image of the USB drive using a write blocker ensures that the original evidence is not altered during acquisition, preserving its integrity for later analysis and legal admissibility. Option D is correct because documenting the chain of custody for the USB drive records every person who handled, transferred, or accessed the evidence, which is essential for proving that the evidence has not been tampered with. Option E is correct because computing a hash (e.g., MD5 or SHA-256) of both the original USB drive and the forensic image allows the analyst to verify that the image is an exact bit-for-bit copy and that the original has not changed.

Option B does not belong because disabling the user's network account is a containment action that could alert the suspect and is not part of evidence gathering or chain-of-custody preservation. Option C does not belong because interviewing the user is an investigative step that could compromise the case and is not a forensic evidence-handling action.

Exam trap

The trap here is confusing containment actions (disabling accounts, interviewing suspects) with evidence-preservation actions — CS0-004 tests whether candidates know that forensic integrity requires write blockers, hashing, and chain-of-custody documentation, not just securing the suspect.

74
MCQmedium

An analyst is reviewing a suspicious executable using static analysis. Which of the following would provide information about the functions the executable imports from system libraries?

A.Import table analysis
B.PE header analysis
C.String extraction
D.YARA rule creation
AnswerA

Import table analysis allows an analyst to inspect the Import Address Table (IAT) of a Portable Executable (PE) file. This reveals the specific dynamic-link libraries (DLLs) and API functions the binary requests from the operating system at runtime. By identifying these imported functions, such as internet connectivity or registry modification APIs, the analyst can infer the program's intended capabilities without executing it.

Why this answer

The import table (also called the import address table, IAT) lists the functions an executable imports from system libraries (DLLs), such as kernel32.dll or user32.dll. Static analysis of the import table reveals which APIs the malware calls, providing insight into its capabilities (e.g., file I/O, network communication, registry manipulation). This directly answers the question about functions imported from system libraries.

Exam trap

The trap is confusing PE header analysis with import table analysis — the PE header contains overall metadata, while the import table specifically enumerates functions from system libraries.

How to eliminate wrong answers

Option B is wrong because PE header analysis provides metadata like machine type, number of sections, entry point, and timestamps — it does not enumerate imported functions. Option C is wrong because string extraction pulls human-readable strings from the binary, which may hint at functionality but does not systematically list imported functions. Option D is wrong because YARA rule creation is a detection technique for identifying malware based on patterns, not a method for discovering imported functions.

75
MCQmedium

A security analyst receives an alert that a workstation is communicating with a known C2 server over DNS. The analyst wants to quickly isolate the endpoint from the network but keep it powered on for later memory capture. Which of the following actions should the analyst take FIRST?

A.Administratively disable the switch port to which the workstation is connected.
B.Disconnect the workstation's network cable from the switch port.
C.Run a full antivirus scan on the workstation to remove the malware.
D.Shut down the workstation to prevent further data exfiltration.
AnswerA

Administratively disabling the switch port immediately stops all network communication from the endpoint while keeping it powered on for memory capture. This method is reversible, logged, and does not require physical access. It also prevents the malware from communicating with the C2 server without alerting the attacker via a full shutdown. This is the most appropriate first containment step.

Why this answer

Administratively disabling the switch port is the fastest, most controlled way to isolate the endpoint while preserving volatile memory. It stops C2 communication without powering off the system, allowing the analyst to capture RAM and running processes. Physical disconnection or shutdown may lose evidence or be less auditable, and antivirus scanning does not contain the threat.

Containment should always precede eradication.

Exam trap

The trap here is assuming that physically unplugging the network cable is always the best first containment step, when a switch port shutdown is often faster and more auditable.

Page 1 of 2 · 98 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Incident Response and Management questions.