Courseiva

CCNA Security Questions

50 of 125 questions · Page 2/2 · Security topic · Answers revealed

76
MCQmedium

A SOC analyst receives an alert from the SIEM indicating a high volume of outbound traffic from a single workstation to an external IP address on port 22. Upon investigation, the analyst finds the workstation is used by a developer who frequently transfers large files to a remote server via SCP. What is the most appropriate classification for this alert?

A.True positive
B.True negative
C.False positive
D.False negative
AnswerC

A false positive occurs when a security control incorrectly flags benign, authorized activity as malicious. In this case, the SIEM generated an alert for legitimate SCP transfers, meaning the rule triggered on normal administrative behavior rather than an actual security incident.

Why this answer

The alert is triggered by legitimate administrative activity (SCP file transfer), so it is a false positive. The analyst should tune the SIEM to reduce similar alerts.

77
MCQmedium

During a traffic analysis, a security analyst observes repeated outbound connections from an internal workstation to an external IP address on TCP port 53 at irregular intervals. The connections are small and occur every few minutes. Which technique is most likely being used?

A.HTTP smuggling
B.TCP handshake anomaly
C.DNS tunneling
D.Beaconing
AnswerC

DNS tunneling encapsulates non-DNS traffic, such as SSH, HTTP, or proprietary data exfiltration protocols, within DNS queries and responses. While standard DNS queries typically utilize UDP port 53, attackers frequently fall back to or abuse TCP port 53 to bypass standard UDP-based inspection filters and transmit larger payloads or maintain persistent, stateful connection channels.

Why this answer

DNS normally uses UDP, but TCP port 53 can be used for DNS tunneling. The small, irregular connections to a single external IP suggest data exfiltration via DNS tunneling.

78
MCQmedium

A CASB alert indicates that a user downloaded a file containing sensitive data from a cloud app to an unmanaged device. Which action should the analyst take first?

A.Report the incident to law enforcement
B.Reset the user's password
C.Block the user's cloud app access
D.Investigate the alert to confirm the data exfiltration
AnswerD

The first phase of the incident response lifecycle following detection is analysis and validation. Analysts must investigate the CASB alert to rule out false positives, determine the classification of the downloaded file, and verify whether the activity constitutes actual unauthorized data exfiltration before initiating containment or eradication protocols.

Why this answer

The first step is to verify the alert is a true positive by checking the user's activity and the file's sensitivity. Prematurely blocking or reporting may be incorrect if the alert is a false positive.

79
MCQeasy

A security analyst is reviewing a SIEM alert that triggered on a single failed login attempt from an internal IP address to a domain controller at 3:00 AM. The user associated with the account is on vacation. Which classification best describes this alert?

A.False positive
B.False negative
C.True negative
D.True positive
AnswerD

A true positive occurs when a security monitoring tool correctly identifies and alerts on actual malicious or unauthorized activity. In this case, the SIEM alert successfully flagged a genuine security event that requires analyst triage and incident response. Validating true positives is a fundamental step in the incident handling lifecycle before escalating to containment.

Why this answer

The alert is triggered by a real failed login attempt from an internal IP, but the user is on vacation, so it likely indicates a malicious attempt. Since it is a confirmed security incident, it is a true positive.

80
MCQhard

During memory analysis of a compromised host, an analyst finds a process that appears to be 'svchost.exe' but with an unusual parent process (not 'services.exe'). The process also has injected code in its memory. What is the most likely explanation?

A.The process is a legitimate svchost.exe but spawned by a different service
B.The svchost.exe is a hollowed process used for malicious purposes
C.The process is a DLL injection into svchost.exe
D.The svchost.exe process is a false positive due to a known Windows bug
AnswerB

Process hollowing is a defense evasion technique where an adversary spawns a legitimate process like svchost.exe in a suspended state, unmaps its memory, and replaces it with a malicious payload. This allows the malware to masquerade as a trusted system process, hiding its true nature from basic process-monitoring tools while executing unauthorized code.

Why this answer

Svchost.exe should always have services.exe as parent. A different parent suggests process hollowing where an attacker replaced the legitimate process memory.

81
MCQmedium

A cloud security analyst reviews AWS CloudTrail logs and notices multiple 'RunInstances' API calls from a single IAM user creating EC2 instances with public IP addresses in an unusual region. What is the most likely concern?

A.The user's credentials may be compromised and used for cryptomining
B.The user is performing legitimate scaling operations
C.The user is provisioning resources for a new project
D.The user is testing disaster recovery procedures
AnswerA

When threat actors compromise AWS IAM credentials, they frequently target unused geographical regions to evade detection while spinning up high-performance EC2 instances for illicit cryptocurrency mining. This anomalous behavior is flagged in CloudTrail logs by API calls like RunInstances originating from unfamiliar IPs and targeting non-standard regions, which deviates sharply from established baseline activity.

Why this answer

Multiple RunInstances calls from a single IAM user creating public-IP EC2 instances in an unusual region is a textbook indicator of compromised credentials being used for cryptomining. Attackers favor this pattern because it rapidly provisions compute resources for mining, often in regions the victim doesn't normally use to evade detection and quota monitoring.

Exam trap

CS0-004 often tests whether candidates can distinguish a genuine security incident (compromised credentials, cryptomining) from benign operational explanations (scaling, new projects) by focusing on anomalies like unusual region and public IP exposure.

How to eliminate wrong answers

Option B is wrong because legitimate auto-scaling is typically driven by Auto Scaling Groups with service-linked roles, not a single IAM user making manual RunInstances calls in an unusual region. Option C is wrong because new-project provisioning would normally follow change-management processes and occur in the organization's standard regions, not an anomalous one. Option D is wrong because disaster recovery testing is a planned, documented activity that would not present as repeated ad-hoc RunInstances calls with public IPs from one user.

82
MCQmedium

An analyst reviews AWS CloudTrail logs and detects multiple 'CreateNetworkAclEntry' API calls from a user who does not typically perform network administration. What type of activity is this?

A.Cloud misconfiguration
B.Privilege escalation or lateral movement
C.Normal administrative activity
D.Data exfiltration via NACL
AnswerB

When a user account suddenly executes unauthorized API calls to alter network configurations or security groups, it strongly suggests an adversary is attempting privilege escalation or lateral movement. By modifying these boundaries, the attacker aims to establish broader access to sensitive cloud resources or bypass existing security controls.

Why this answer

Creating Network ACL entries is a network administration task. When a user who does not normally perform such actions makes multiple CreateNetworkAclEntry calls, it suggests the user's credentials may have been compromised and are being used to modify network access controls, potentially to enable lateral movement or privilege escalation. This is a classic indicator of compromise in cloud environments.

Exam trap

The trap is labeling suspicious but non-destructive API calls as 'misconfiguration' or 'normal'; candidates must recognize that unusual administrative actions by a non-admin user indicate compromise and potential lateral movement.

How to eliminate wrong answers

Option A is wrong because cloud misconfiguration refers to accidental errors in configuration, not suspicious API calls from an unusual user; the pattern here indicates malicious intent. Option C is wrong because the user does not typically perform network administration, so this is not normal activity for them. Option D is wrong because data exfiltration via NACL is not a standard attack technique; NACLs control traffic, and while they could be used to allow exfiltration, the act of creating entries is more indicative of establishing persistence or lateral movement.

83
MCQmedium

An analyst is creating a YARA rule to detect a specific malware family that uses the string 'evil' in its PE file. Which of the following rule structures is correct?

A.rule detect_malware { strings: $a = "evil" condition: $a }
B.rule detect_malware { strings: "evil" condition: $a }
C.rule detect_malware { condition: $a = "evil" }
D.if "evil" in file then alert
AnswerA

This is the correct YARA rule syntax. It defines a rule named detect_malware, declares a string identifier $a assigned to the literal byte sequence "evil" inside the strings section, and then uses that identifier as the condition. The condition $a evaluates to true if the string 'evil' is found anywhere in the scanned file. YARA requires a dollar-sign prefix for string identifiers, an equals sign to bind the literal value, and a condition that references the identifier without quotes or further assignment. This rule compiles and will trigger a match when the file contains the specified string.

Why this answer

A valid YARA rule requires the structure: rule <name> { strings: $var = "pattern" condition: $var }. Option A correctly declares a string variable $a assigned to 'evil' and then references $a in the condition, which is the canonical YARA syntax.

Exam trap

CS0-004 often tests the exact YARA rule skeleton — candidates pick options that omit the $variable assignment in the strings section or use imperative pseudocode instead of the rule/strings/condition block.

How to eliminate wrong answers

Option B is wrong because it omits the variable assignment ($a =) in the strings section, so the condition references an undefined identifier $a — YARA will fail to compile. Option C is wrong because it places the string assignment inside the condition block and leaves the strings section empty, which is invalid syntax. Option D is wrong because 'if ... then alert' is pseudocode, not YARA syntax — YARA rules use the rule/strings/condition block structure, not imperative if-then statements.

84
Multi-Selectmedium

A security team is tuning a SIEM rule that alerts on all outbound connections to IP addresses classified as 'high risk' by threat intelligence. The rule generates many false positives because some legitimate services use these IPs. Which two actions should the analyst take to reduce false positives? (Select TWO.)

Select 2 answers
A.Ignore the false positives and continue
B.Increase the risk score threshold to only alert on very high risk IPs
C.Expand the rule to include all risky IPs
D.Add known legitimate IP addresses to an exclusion list
E.Disable the rule
AnswersB, D

Raising the risk score threshold means only IPs with very high threat-intelligence risk scores trigger alerts, filtering out lower-scored IPs that legitimate services use. This directly reduces the false positives described in the stem while retaining detection of genuinely high-risk connections.

Why this answer

Option B is correct because raising the risk score threshold so the rule only fires on 'very high risk' IPs narrows the alert set to indicators with stronger threat-intelligence confidence, filtering out lower-confidence 'high risk' entries that frequently match legitimate services. Option D is correct because adding the verified legitimate IP addresses to an exclusion list (allowlist) suppresses alerts for known-good destinations while keeping detection coverage for the remaining high-risk IPs. Option A is wrong because ignoring false positives leaves the rule noisy and risks missing true malicious connections.

Option C is wrong because expanding the rule to include all risky IPs would increase, not reduce, false positives. Option E is wrong because disabling the rule eliminates detection entirely, creating a blind spot rather than tuning the rule.

Exam trap

CS0-004 often tests whether candidates choose the 'do nothing' or 'disable' options as shortcuts, when the correct answer is always a targeted tuning action (threshold adjustment or exclusion) that preserves detection while reducing noise.

85
MCQmedium

During a threat hunting exercise, the hunter creates a hypothesis based on recent threat intelligence about a new ransomware variant that uses scheduled tasks for persistence. Which ATT&CK technique should the hunter focus on?

A.T1566.001 (Spearphishing Attachment)
B.T1059.001 (PowerShell)
C.T1053.005 (Scheduled Task)
D.T1547.001 (Registry Run Keys)
AnswerC

Scheduled Tasks (T1053.005) represent a highly common persistence mechanism where adversaries abuse task scheduling utilities, such as Windows Task Scheduler, to execute malicious binaries at specific intervals or system events. This technique directly aligns with the threat hunter's hypothesis of identifying persistent execution methods that survive reboots and user logoffs.

Why this answer

Scheduled tasks are a persistence technique (T1053.005). The hunter should focus on the persistence tactic and the specific technique for scheduled tasks.

86
MCQhard

An analyst suspects a process hollowing attack on an endpoint. Which of the following EDR telemetry findings would best support this hypothesis?

A.A legitimate process (e.g., svchost.exe) created in a suspended state and later resumed with changed memory contents
B.A process with the same name as a Windows system process but running from a temporary directory
C.A process injecting code into a legitimate running process
D.An unknown process making network connections to multiple internal IPs
AnswerA

Process hollowing specifically involves spawning a legitimate system process (like svchost.exe) in a suspended state using the CREATE_SUSPENDED flag, unmapping its original executable code from memory, writing a malicious payload into that hollowed space, and then resuming the thread. This allows the malware to masquerade as a trusted process while executing arbitrary code under its identity.

Why this answer

Process hollowing involves creating a legitimate process in a suspended state, then replacing its memory with malicious code. This leaves the original path unchanged but the process may exhibit unusual child process behavior.

87
Multi-Selecthard

A security analyst is investigating a potential advanced persistent threat (APT) that uses living off the land binaries (LOLBins). The EDR has flagged several processes. Which THREE process behaviors are most indicative of LOLBin abuse? (Choose THREE.)

Select 3 answers
A.mshta.exe executing JavaScript from a remote URL
B.explorer.exe opening the Start menu
C.notepad.exe opening a .txt file in the user's Documents folder
D.wmic.exe creating a process on a remote system
E.certutil.exe downloading an executable from a remote server
AnswersA, D, E

mshta.exe is a Microsoft HTML Application host that runs .hta files containing VBScript or JavaScript. When invoked with a remote URL, it executes attacker-supplied script directly from the internet, bypassing many application control policies and acting as a living-off-the-land binary (LOLBin). This behavior is highly suspicious because legitimate mshta execution is typically local and user-initiated, not a network fetch of script code.

Why this answer

Option A is correct because mshta.exe is a signed Microsoft LOLBin that normally renders HTML applications, so executing JavaScript from a remote URL is a classic abuse pattern for fileless execution and remote payload retrieval. Option D is correct because wmic.exe is a legitimate WMI command-line utility, and using it to create a process on a remote system (e.g., via /node and process call create) is a well-known lateral movement and remote execution technique. Option E is correct because certutil.exe is a built-in certificate utility whose -urlcache or -split options are frequently abused to download executables from remote servers, making it a hallmark LOLBin download cradle.

Option B is not indicative because explorer.exe opening the Start menu is normal user-interface behavior, and Option C is not indicative because notepad.exe opening a local .txt file in the user's Documents folder is ordinary, expected activity with no remote or execution-abuse characteristics.

Exam trap

CS0-004 often tests whether candidates can distinguish normal signed-binary behavior from anomalous LOLBin abuse — the trap is picking benign actions like opening a text file or Start menu because the binary itself is legitimate.

88
MCQhard

During a threat hunting engagement, an analyst creates a hypothesis based on a recent threat intelligence report about a new APT group using DLL side-loading for persistence. The analyst decides to search for processes that have loaded a known vulnerable DLL. Which framework is most appropriate to map the TTPs?

A.Diamond Model
B.NIST CSF
C.MITRE ATT&CK
D.Cyber Kill Chain
AnswerC

MITRE ATT&CK is a globally accessible knowledge base of adversary tactics and techniques based on real-world observations. It provides threat hunters with a highly structured, granular matrix to map specific behaviors, identify coverage gaps in telemetry, and systematically formulate hypotheses regarding how advanced persistent threats (APTs) might execute actions within an environment.

Why this answer

MITRE ATT&CK is the most comprehensive framework for mapping adversary TTPs, including persistence techniques like DLL side-loading (T1574.002).

89
MCQhard

An analyst is investigating a suspected data exfiltration via HTTP. The analyst examines a PCAP file and finds a series of HTTP POST requests to an external site with varying 'Content-Length' values. The payloads appear to be base64-encoded strings. Which tool would be most effective for extracting and decoding the payloads for analysis?

A.Wireshark
B.Python with scapy
C.tcpdump
D.NetFlow
AnswerB

Python paired with the Scapy library provides a powerful programmatic environment to parse packet capture (PCAP) files. It allows analysts to write custom scripts that target specific layers, extract HTTP payload data, programmatically decode base64-encoded strings, and automate the identification of exfiltrated data at scale.

Why this answer

Python with scapy allows custom scripting to extract and decode payloads from PCAP files.

90
MCQmedium

During a memory analysis of a potentially compromised host, a security analyst finds a process with an executable image that is not present on disk. Which technique is most likely being observed?

A.Reflective DLL injection
B.Process hollowing
C.API hooking
D.DLL injection
AnswerB

Process hollowing involves spawning a legitimate process in a suspended state, unmapping its original executable image from memory, and replacing it with a malicious payload. Because the process's metadata and path point to a legitimate disk-backed executable while the memory contains unauthorized code, it creates a memory-only execution state that evades standard signature-based detection.

Why this answer

Process hollowing (a form of process replacement) involves creating a legitimate process in a suspended state, unmapping its original executable image from memory, and writing malicious code into that address space before resuming it. The result is a running process whose in-memory image does not correspond to any executable on disk — exactly the artifact described. This is a classic malware evasion technique used by families such as TrickBot and Emotet.

Exam trap

The trap is confusing process hollowing with reflective DLL injection — both involve in-memory code, but only hollowing produces a running process whose primary executable image is absent from disk.

How to eliminate wrong answers

Option A is wrong because reflective DLL injection loads a DLL directly into memory via a reflective loader without touching disk, but the host process's own executable image remains intact and present on disk — the anomaly would be an unbacked DLL module, not a missing primary image. Option C is wrong because API hooking intercepts function calls (e.g., via inline patches or IAT hooks) to redirect execution; it does not remove the process's executable image from disk or memory. Option D is wrong because DLL injection writes a DLL into a target process's address space, but the target's original executable image is still mapped and present on disk — the disk/memory mismatch described is specific to process hollowing.

91
MCQmedium

A security analyst is creating a Sigma rule to detect suspicious usage of 'schtasks.exe' to create a scheduled task that runs an encoded PowerShell command. Which log source is most appropriate for this rule?

A.Windows Security Event Log (Event ID 4624)
B.Sysmon Event ID 1 (Process creation)
C.DNS server log
D.Windows PowerShell operational log
AnswerB

Sysmon Event ID 1 provides highly detailed telemetry regarding process creation, including the parent process, command-line arguments, and file hashes. This rich context is essential for Sigma rules designed to detect suspicious command-line flags or anomalous parent-child process relationships.

Why this answer

Sysmon Event ID 1 captures process creation with rich metadata including the full command line, parent process, hashes, and user context — exactly what's needed to detect 'schtasks.exe' spawning with an encoded PowerShell payload. Sigma rules map to log sources that expose these fields, and Sysmon EID 1 is the canonical source for process-creation-based detections. This lets the rule match on Image, CommandLine, and ParentImage to catch the suspicious pattern.

Exam trap

The trap is assuming the PowerShell operational log is the best source because the payload is PowerShell — but the detection target is the schtasks.exe process creation, which only process-creation telemetry captures.

How to eliminate wrong answers

Option A is wrong because Windows Security Event ID 4624 is a logon event, not process creation — it records authentication, not command lines, so it cannot detect schtasks.exe arguments. Option C is wrong because DNS logs only show name resolution queries and would not reveal the process or its encoded PowerShell argument. Option D is wrong because the PowerShell operational log captures PowerShell engine activity (script block logging, module logging) but not the initial schtasks.exe process creation with its command-line arguments — the detection target is the scheduled task creation, not the PowerShell execution itself.

92
MCQmedium

A security analyst is reviewing a SIEM alert indicating a high number of failed authentication attempts from a single IP address against multiple user accounts. The analyst checks the logs and finds the IP belongs to a known vulnerability scanner used by the internal security team. How should the analyst classify this alert?

A.True positive - unauthorized access attempt
B.False positive - authorized activity
C.True positive - lateral movement
D.False negative - missed detection
AnswerB

This is the correct classification because the SIEM generated an alert for behavior that, while anomalous or aggressive in appearance, is actually benign and pre-authorized. Vulnerability scanners frequently trigger brute-force or account-harvesting alerts during routine credentialed checks. Labeling this as a false positive allows analysts to tune the SIEM rules to exclude the scanner's IP address from future alerts.

Why this answer

The alert is triggered by authorized activity from a known internal scanner, so it is a false positive. The SIEM rule should be tuned to exclude this scanner or reduce its severity.

93
MCQeasy

A vulnerability scan report shows a critical vulnerability with a CVSS score of 10.0. The application team states that the affected service is isolated in a DMZ and has no access to sensitive data. What should the analyst consider?

A.Accept the risk based on compensating controls
B.Reclassify the vulnerability as low severity
C.Immediately patch the vulnerability
D.Ignore the finding as a false positive
AnswerA

When a critical vulnerability cannot be immediately patched, security analysts must evaluate the surrounding architecture. Isolating the affected system within a demilitarized zone (DMZ) acts as a compensating control that significantly reduces the threat vector and likelihood of exploitation. Consequently, formally accepting the residual risk is a valid temporary or permanent business decision when these alternative safeguards are active.

Why this answer

Compensating controls like network isolation can reduce the risk even if the vulnerability itself is critical.

94
MCQmedium

A security analyst is creating a correlation rule in the SIEM to detect DGA (Domain Generation Algorithm) activity. Which of the following data points would be most useful to include in the rule?

A.High number of DNS queries to domains with high entropy and frequent NXDOMAIN responses
B.Multiple successful connections to a single external IP
C.Large data transfers over HTTPS
D.Unusual parent-child process relationships
AnswerA

Correct. DGA malware generates hundreds or thousands of pseudo-random candidate domains per day to locate its command-and-control server, so a rule watching for high-entropy hostnames paired with a burst of NXDOMAIN responses (since most generated domains are never registered) is the defining behavioral fingerprint of DGA activity.

Why this answer

DGA malware generates large volumes of pseudo-random domain names (e.g., 'aj3kf9x2qz.com') to locate its C2 server, and the vast majority of these domains are unregistered, producing NXDOMAIN responses. Correlating a high rate of DNS queries with high-entropy domain strings and a high NXDOMAIN ratio is the classic SIEM detection pattern for DGA beaconing. The other options describe behaviors that are either normal or unrelated to domain-generation activity.

Exam trap

CS0-004 often tests whether candidates confuse network-layer DGA indicators (high-entropy DNS + NXDOMAIN) with host-layer injection indicators (parent-child process anomalies), so pick the answer tied to DNS behavior, not endpoint process trees.

How to eliminate wrong answers

Option B is wrong because multiple successful connections to a single external IP describes normal client-server communication or C2 beaconing to a fixed address, not the algorithmically generated, constantly changing domains that define DGA. Option C is wrong because large HTTPS data transfers indicate exfiltration or bulk download activity, which is a data-loss concern rather than a DNS-based DGA signature. Option D is wrong because unusual parent-child process relationships are a host-based EDR detection for process injection or spawning abuse, not a network/DNS indicator of domain generation.

95
MCQeasy

Which analysis technique involves examining the parent-child relationships of processes to identify potentially malicious activity?

A.Network analysis
B.Memory analysis
C.Registry analysis
D.Process analysis
AnswerD

Process analysis specifically evaluates the execution lifecycle, metadata, and hierarchical relationships of running programs. By examining process trees, analysts can identify anomalous parent-child relationships, such as a web server spawning a command shell, which is a classic indicator of compromise.

Why this answer

Process analysis involves examining running processes, their attributes, and especially their parent-child relationships to detect anomalies such as a suspicious process spawned by an unexpected parent (e.g., a word processor spawning cmd.exe). This technique is fundamental in endpoint detection and response (EDR) and forensic investigations to identify malicious activity like process injection or lateral movement.

Exam trap

CS0-004 often tests the confusion between different analysis techniques, where candidates might choose memory analysis for process relationships because processes reside in memory, but the specific focus on parent-child relationships is unique to process analysis.

How to eliminate wrong answers

Option A is wrong because network analysis focuses on network traffic, protocols, and connections, not on process hierarchies. Option B is wrong because memory analysis examines volatile memory for artifacts like injected code or credentials, but does not specifically focus on parent-child process relationships. Option C is wrong because registry analysis involves examining Windows Registry keys and values for configuration changes or persistence mechanisms, not process relationships.

96
MCQhard

An analyst examines a memory dump from a compromised host and finds that 'svchost.exe' is executing code from a memory region that is not backed by any executable file. What technique is most likely being used?

A.Reflective DLL injection
B.API hooking
C.Process hollowing
D.DLL injection
AnswerC

Process hollowing involves spawning a legitimate system process in a suspended state, unmapping its original executable memory using APIs like NtUnmapViewOfSection, and writing malicious code into the hollowed-out space. Because the malicious payload is written directly into the allocated memory of the victim process without being loaded from a corresponding file on disk, memory analysis reveals executable regions that lack proper file backing. This allows the malware to masquerade as a trusted system process.

Why this answer

Process hollowing involves creating a legitimate process (often svchost.exe) in a suspended state, unmapping its original executable image from memory, and replacing it with malicious code. The result is a process whose in-memory code is not backed by any executable file on disk, which is exactly what the memory dump shows. Reflective DLL injection and classic DLL injection leave the host image intact and load a DLL into it.

Exam trap

CS0-004 often tests whether candidates can distinguish process hollowing (original image unmapped, unbacked executable region) from DLL injection (host image intact, extra DLL loaded) — the phrase 'not backed by any executable file' is the tell for hollowing.

How to eliminate wrong answers

Option A is wrong because reflective DLL injection loads a DLL directly into memory via a reflective loader, but the host process's original executable image remains mapped and file-backed, so the 'not backed by any executable file' signature does not match. Option B is wrong because API hooking redirects function calls within a process (e.g., via IAT or inline hooks) and does not replace the process image or create unbacked executable regions. Option D is wrong because classic DLL injection uses LoadLibrary or manual mapping to add a DLL to a running process, but the primary executable image is still file-backed, so the specific indicator described points to hollowing.

97
MCQeasy

During a vulnerability scan of an internal web server, the scanner reports a critical vulnerability with a CVSS score of 9.8. The analyst reviews the finding and determines that the vulnerability is mitigated by a Web Application Firewall (WAF) deployed in front of the server. What should the analyst do with this finding?

A.Mark the finding as a false positive and close it.
B.Immediately patch the server to remove the vulnerability.
C.Document the compensating control and track the finding until patched.
D.Increase the scan frequency to detect if the vulnerability changes.
AnswerC

This is the correct approach because it maintains accurate risk visibility while acknowledging the temporary protection provided by the Web Application Firewall (WAF). Documenting the WAF as a compensating control justifies delaying immediate patching, but the vulnerability must still be tracked in the risk register. This ensures the flaw is eventually remediated permanently during scheduled maintenance, preventing exposure if the WAF is misconfigured or bypassed.

Why this answer

The vulnerability is effectively mitigated by the compensating control (WAF), so it should be documented as such and tracked until the patch is applied.

98
MCQmedium

During a network traffic analysis, a security analyst observes repeated TCP SYN packets sent to a host that responds with SYN-ACK, but the connection never completes. What type of anomaly is this?

A.DNS amplification
B.SYN flood
C.ARP spoofing
D.Port scan
AnswerB

A SYN flood is a classic denial-of-service attack that exploits the TCP three-way handshake. The attacker floods the target with SYN packets using spoofed source IP addresses, forcing the victim to allocate resources and respond with SYN-ACKs, but never completes the connection with a final ACK. This rapidly exhausts the target's connection queue, preventing legitimate users from establishing connections.

Why this answer

A half-open TCP handshake (SYN flood) is a common DoS technique where the attacker sends many SYN packets without completing the handshake, exhausting server resources.

99
MCQeasy

A security analyst is reviewing logs from multiple sources to investigate a potential intrusion. Which log source would provide the most reliable evidence of successful authentication from an unusual location?

A.Endpoint detection and response (EDR) logs
B.Firewall logs
C.Authentication logs
D.DNS logs
AnswerC

Authentication logs, such as those generated by Active Directory, Kerberos, or RADIUS servers, explicitly record identity verification events, including usernames, source IPs, timestamps, and explicit success or failure codes. These logs are the definitive source for tracking credential usage, identifying brute-force attacks, and verifying successful access to systems. Analyzing these events allows security analysts to correlate login patterns with potential unauthorized access.

Why this answer

Authentication logs record login events including source IP, timestamp, and success/failure status, making them the best source for identifying successful authentication from unusual locations.

100
Multi-Selectmedium

A security analyst is investigating a potential data exfiltration incident. The analyst observes the following network traffic from an internal host: Outbound connections to an external IP on port 22, large data transfers during off-hours, and the use of SCP. Which two indicators of compromise (IOCs) are most relevant? (Select TWO.)

Select 2 answers
A.Frequent DNS queries
B.HTTP POST requests
C.Large outbound data transfers during off-hours
D.Use of SCP on port 22
E.ICMP echo requests
AnswersC, D

Large outbound transfers during off-hours deviate from the host's normal baseline, indicating possible automated exfiltration rather than legitimate business activity. Volume combined with unusual timing is the behavioural anomaly that distinguishes data theft from routine traffic in this scenario.

Why this answer

Option C is correct because the scenario explicitly describes large data transfers occurring during off-hours, which is a classic exfiltration IOC indicating data is being moved out of the network when normal business activity and monitoring are minimal. Option D is correct because SCP operates over SSH on TCP port 22, and using SCP to an external IP is a concrete IOC showing a file-transfer protocol being abused to move data outbound, matching the observed port 22 traffic. The other options do not fit: frequent DNS queries (A) could suggest DNS tunneling but no such activity is described, HTTP POST requests (B) would indicate web-based exfiltration over ports 80/443 rather than SCP/22, and ICMP echo requests (E) are ordinary ping traffic and not consistent with the SCP-over-port-22 behavior observed.

Exam trap

CS0-004 often tests the ability to distinguish between common network activities and specific IOCs of data exfiltration, such as SCP and off-hours large transfers.

101
MCQeasy

A security analyst is reviewing NetFlow data and notices a significant amount of traffic from an internal host to a known malicious IP address on port 443. What tool would be most effective for further analyzing the payload of this traffic?

A.Nikto
B.Wireshark
C.Nmap
D.tcpdump
AnswerB

Wireshark captures and decodes packets in real time or from a saved capture file, reassembling TCP streams and, where the session is unencrypted or keys are available, rendering application-layer payload content, protocol fields, and TLS handshake metadata needed to determine what data is actually being exchanged with the malicious IP.

Why this answer

Wireshark captures and analyzes packet payloads, which is necessary for examining the content of encrypted or unencrypted traffic.

102
MCQeasy

Which of the following is the primary purpose of log normalisation in a SIEM?

A.Encrypt logs to protect confidentiality
B.Reduce storage space by compressing log data
C.Remove false positives from log entries
D.Convert logs into a standardised format for correlation and analysis
AnswerD

The primary objective of log normalization is to ingest disparate log formats from various vendors—such as firewalls, operating systems, and databases—and map them to a common schema, such as mapping "src_ip", "source", and "src" all to "source_ip". This standardization is essential for SIEM correlation engines to accurately analyze cross-platform events and detect complex attack patterns.

Why this answer

Log normalisation converts logs from different sources into a common, structured format so that the SIEM can correlate and analyse them uniformly.

103
MCQhard

A security analyst uses Wireshark to capture traffic and notices an unusually high number of DNS queries for random-looking subdomains under a single domain, such as 'a1b2c3.malicious.com'. The TTL values are very low. The analyst suspects DNS tunneling. Which of the following additional indicators would most strongly support this hypothesis?

A.Large number of NXDOMAIN responses
B.DNS queries with unusually large TXT record response sizes
C.High number of A record queries
D.Queries originating from a DNS server
AnswerB

DNS tunneling protocols frequently abuse TXT records because they can carry arbitrary, unstructured text payloads up to 65,535 bytes in size. When an analyst observes unusually large TXT record responses, it strongly indicates that an external server is sending encapsulated payload data or command-and-control instructions back to a compromised internal host.

Why this answer

DNS tunneling often uses TXT records to encode data, and the packet sizes can be larger than normal DNS queries.

104
Multi-Selecthard

A security analyst is reviewing an alert from Azure Sentinel that indicates a possible privilege escalation attempt. The alert is based on a correlation rule that detects unusual usage of the 'Add-AzKeyVaultKey' cmdlet by a user who has never used it before. The analyst needs to validate the alert and determine if the activity is malicious. Which THREE actions should the analyst take?

Select 3 answers
A.Check the user's role assignments and permissions
B.Run a vulnerability scan on the user's workstation
C.Review the Key Vault's diagnostic logs for any key retrieval after the cmdlet
D.Disable the user account immediately
E.Verify the user's identity by checking Azure AD sign-in logs
AnswersA, C, E

Checking the user's RBAC role assignments against Key Vault establishes whether Add-AzKeyVaultKey was actually within that person's authorized scope of duties, since a first-time use of a cmdlet by someone who legitimately holds a Key Vault Contributor or Crypto Officer role is far less suspicious than the same call from an account with no assigned Key Vault permissions.

Why this answer

Checking Azure AD logs for the authentication context, reviewing the user's recent activity history, and examining the Key Vault audit logs for any subsequent access are all relevant steps.

105
MCQmedium

A threat hunter is creating a hypothesis based on the MITRE ATT&CK framework. The hunter wants to detect adversaries using PowerShell to download files from remote servers. Which ATT&CK technique should the hunter focus on?

A.T1078 (Valid Accounts)
B.T1053.005 (Scheduled Task)
C.T1047 (WMI)
D.T1059.001 (PowerShell)
AnswerD

PowerShell (T1059.001) is a sub-technique under Command and Scripting Interpreter that allows adversaries to execute commands, run scripts, and interact directly with the operating system. Threat hunters look for PowerShell commands utilizing cmdlets like 'Invoke-WebRequest' or 'Start-BitsTransfer' because they are commonly abused to download and execute malicious payloads directly into memory.

Why this answer

T1059.001 is PowerShell, which is commonly used for file downloads. The hunter should create detection rules for PowerShell download cradles.

106
MCQhard

A threat hunter is creating a Sigma rule to detect a specific TTP where an attacker uses reg.exe to create a Run key for persistence. Which of the following Sigma rule event selectors would best detect this activity?

A.EventID: 4688 (Process Creation) AND ParentImage: '*reg.exe*'
B.EventID: 13 (Registry Value Set) AND TargetObject: '*\CurrentVersion\Run*'
C.EventID: 4657 (Registry modification) AND ObjectName: '*\RunOnce*'
D.EventID: 1 (Process Creation) AND CommandLine: '*reg.exe*'
AnswerB

Sysmon Event ID 13 specifically monitors registry value modifications, making it highly effective for tracking persistence mechanisms. By targeting the \\CurrentVersion\\Run key path within the TargetObject field, this rule directly alerts on attempts to establish autostart execution points, regardless of the process initiating the change.

Why this answer

Registry persistence via Run keys is commonly achieved by modifying HKCU\Software\Microsoft\Windows\CurrentVersion\Run. Sigma rules targeting registry add/modify events with that path will detect it.

107
MCQmedium

An analyst receives an alert that a user's workstation contacted a known command-and-control (C2) IP address. The analyst checks the EDR logs and finds that the process 'svchost.exe' initiated the connection. What should the analyst do next to determine if this is a true positive?

A.Check the parent process of svchost.exe
B.Verify the IP address with threat intelligence feeds
C.Search for other workstations contacting the same IP
D.Isolate the workstation from the network immediately
AnswerA

In a legitimate Windows environment, svchost.exe (Service Host) is always spawned by the Services Control Manager (services.exe). If the parent process is anything else, such as a web browser, user-space application, or command shell, it strongly indicates process hollowing, DLL injection, or malicious Living off the Land (LotL) activity. Verifying this lineage is the most effective way to confirm whether the process has been hijacked to establish the outbound C2 connection.

Why this answer

Checking the parent process of svchost.exe helps identify if it was spawned by a malicious process like a service or scheduled task, indicating compromise.

108
MCQeasy

A security analyst is reviewing a SIEM alert that triggered on a single failed login attempt from a known internal IP address to a file server. The user authenticated successfully on the next attempt. Which classification best describes this alert?

A.True negative
B.True positive
C.False negative
D.False positive
AnswerD

This is a false positive because the alert fired on a single failed login from a known, trusted internal IP that was immediately followed by successful authentication, a pattern far more consistent with a routine typo than malicious activity; the detection rule's threshold for triggering on just one failed attempt is overly sensitive and should likely be tuned to require multiple failures before alerting.

Why this answer

The alert is a false positive because a single failed login followed by success is normal user behavior and not indicative of malicious activity.

109
MCQeasy

A security analyst is reviewing a SIEM alert that triggered on a known malicious IP address communicating with an internal server. The analyst checks the threat intelligence feed and confirms the IP is associated with a command-and-control server. What type of alert is this?

A.False negative
B.True positive
C.False positive
D.True negative
AnswerB

A true positive represents a successful detection where the SIEM security analytics engine correctly flags actual malicious behavior or policy violations. When an analyst validates that the triggered alert corresponds to genuine adversary activity, such as an active brute-force attack or unauthorized data exfiltration, it confirms a true positive state. This validation initiates the incident response lifecycle.

Why this answer

A true positive means the alert correctly identified a real malicious event. Here the SIEM flagged communication with a known C2 IP, threat intel confirmed the IP is malicious, and the internal server is genuinely talking to it — so the detection is accurate and the incident is real. This is the textbook definition of a true positive in alert triage.

Exam trap

The trap is overthinking the classification — candidates sometimes pick 'false positive' because they assume any alert needs further validation, but confirmed malicious activity with a fired alert is unambiguously a true positive.

How to eliminate wrong answers

Option A is wrong because a false negative is a missed detection — malicious activity that occurred but produced no alert, which is the opposite of what happened here. Option C is wrong because a false positive is an alert on benign activity that was incorrectly flagged; here the activity is confirmed malicious, so it's not benign. Option D is wrong because a true negative is the correct absence of an alert on benign activity — no alert fired and nothing malicious occurred, which doesn't match a triggered alert on confirmed C2 traffic.

110
MCQmedium

A SOC analyst is triaging a SIEM alert for a registry modification on a workstation. The alert indicates a new Run key was added under HKCU\Software\Microsoft\Windows\CurrentVersion\Run. Which of the following is the most likely purpose of this modification?

A.To change the desktop wallpaper
B.To establish persistence
C.To disable Windows Defender
D.To update the system time
AnswerB

Threat actors frequently target registry Run and RunOnce keys located within HKLM or HKCU to ensure their malicious payloads execute automatically upon system boot or user logon. This mechanism allows the malware to survive system reboots and maintain a continuous presence within the compromised environment. Consequently, detecting unauthorized modifications to these specific registry paths is a high-fidelity indicator of a persistence establishment attempt.

Why this answer

Run keys are a common persistence mechanism used by malware to ensure execution at user logon.

111
MCQeasy

Which of the following is the best data source for detecting DNS tunneling activity?

A.Firewall logs
B.DNS logs
C.EDR telemetry
D.NetFlow data
AnswerB

DNS logs capture the complete transaction details, including the requested domain names, query types (such as TXT, MX, or CNAME), and the corresponding server responses. This granular payload visibility is essential for identifying the high-frequency, anomalously long, or encoded subdomains characteristic of DNS tunneling and data exfiltration techniques.

Why this answer

DNS logs contain the queries and responses; analyzing them for unusual domain patterns, large query volumes, or odd record types can reveal tunneling.

112
MCQmedium

A security analyst is tuning a SIEM correlation rule that generates alerts when a single user logs into more than 10 workstations within 5 minutes. The rule is producing excessive false positives due to service accounts performing automated tasks. Which of the following is the best tuning approach to reduce false positives while still detecting potential lateral movement?

A.Change the time window to 10 minutes
B.Increase the threshold to 20 workstations
C.Add an exception for known service account names
D.Disable the rule and rely on manual log review
AnswerC

Creating a whitelist or exception within the SIEM correlation rule for validated, non-interactive service accounts is the most effective tuning strategy. This approach eliminates high-volume false positives generated by legitimate automated processes while maintaining strict, low-threshold monitoring for standard user accounts. It ensures that any anomalous lateral movement by human adversaries remains highly visible to the security operations center.

Why this answer

Excluding known service accounts from the rule reduces false positives while still detecting lateral movement by user accounts.

113
MCQhard

An analyst is reviewing a memory dump of a compromised system and notices that the memory of a legitimate process (e.g., notepad.exe) contains a PE header and executable code that is not part of the original binary. Which technique is most likely being used?

A.A reflective DLL loader
B.Process hollowing
C.DLL injection
D.API hooking
AnswerB

Process hollowing launches a legitimate process in a suspended state, unmaps its original executable image from memory, and writes malicious code and a new PE header into that same memory space before resuming execution, which is exactly why memory forensics reveals a legitimate process name like notepad.exe containing a PE header and code that does not match its original binary on disk.

Why this answer

Process hollowing involves replacing the legitimate code of a running process with malicious code, but the PE header and executable code in memory indicate code injection, specifically hollowing.

114
MCQmedium

During a network traffic analysis, a security analyst notices a host communicating with an external IP address over TCP port 443 using a self-signed certificate. The traffic flows are consistent in size and occur every 60 seconds. The external IP is not on any threat intelligence feeds. What does this pattern most likely indicate?

A.Lateral movement attempt
B.Data exfiltration via DNS tunneling
C.Command and control beaconing
D.Normal web browsing
AnswerC

Command and control (C2) beaconing is characterized by compromised internal hosts making periodic, highly consistent outbound connections to external malicious infrastructure to check for instructions. These regular intervals, often referred to as heartbeat signals, are designed to maintain persistence and bypass standard firewalls by masquerading as legitimate outbound HTTPS traffic.

Why this answer

Regular, periodic connections of consistent size to an external host over HTTPS suggest beaconing, often used by malware for command and control.

115
MCQmedium

A security analyst is triaging an alert from the EDR that shows the process 'powershell.exe' with a parent process of 'winword.exe'. The user recently opened a document from an email. What is the most likely explanation?

A.The user double-clicked a PowerShell script attached to the email
B.The document contains a malicious macro that spawned PowerShell to execute commands
C.A scheduled task started PowerShell that initiated Word
D.The user is running a legitimate PowerShell script from within a Word document
AnswerB

Malicious VBA macros embedded in Office documents commonly use the Shell function or WScript.Shell object to launch powershell.exe directly as a child process of winword.exe, often passing obfuscated, base64-encoded, or download-cradle commands as arguments to retrieve a second-stage payload, which produces exactly the winword.exe-to-powershell.exe parent-child relationship seen in this alert and matches the well-documented email-delivered macro attack pattern.

Why this answer

When winword.exe (Microsoft Word) is the parent of powershell.exe, it almost always indicates a malicious macro in the document spawned a shell to execute commands. This parent-child relationship is a classic indicator of macro-based malware delivery, especially when the document arrived via email and the user opened it. Legitimate Word documents rarely spawn PowerShell directly.

Exam trap

CS0-004 often tests parent-child process lineage — candidates pick the 'user double-clicked a script' option, missing that the parent process would be explorer.exe, not winword.exe, which is the key forensic clue.

How to eliminate wrong answers

Option A is wrong because double-clicking a PowerShell script attachment would make explorer.exe or the mail client the parent process, not winword.exe. Option C is wrong because a scheduled task starting PowerShell would show taskeng.exe or svchost.exe as the parent, and it would not explain Word being the parent. Option D is wrong because legitimate PowerShell execution from within Word is extremely rare and would still be unusual; the email-delivered document context strongly points to malicious macro activity rather than a benign script.

116
MCQeasy

What is the primary purpose of performing credentialed vulnerability scans?

A.Eliminate the need for patch management
B.Reduce network bandwidth usage
C.Avoid detection by the target system
D.Provide deeper insight into the system configuration
AnswerD

By authenticating to the target, the scanner can query installed software versions, registry settings, running services, and local configuration files directly from the operating system, producing far more accurate and complete vulnerability data than an external, unauthenticated scan could infer from network responses alone.

Why this answer

Credentialed scans authenticate to the target system, allowing deeper inspection (e.g., registry, installed software) for a more accurate assessment.

117
MCQeasy

A security analyst reviews a SIEM alert that fired when a user successfully logged into a server from a remote IP address at 3 AM. The user is a system administrator who often works late. What is the most appropriate initial classification of this alert?

A.False positive
B.True positive
C.True negative
D.False negative
AnswerA

This scenario represents a false positive because the SIEM's correlation rules triggered an alert on benign, authorized user activity. The system incorrectly classified a legitimate login attempt as a security threat, requiring the analyst to investigate and potentially tune the rule to prevent future noise.

Why this answer

The alert is a false positive because the SIEM rule triggered on a legitimate login that matches the pattern of an authorized after-hours admin session. The user is a system administrator who often works late, so the activity is expected and benign. A true positive would require the login to be malicious or unauthorized, which is not the case here.

Since the alert fired but the underlying activity is not a security incident, it is correctly classified as a false positive.

Exam trap

CS0-004 often tests the distinction between alert classification terms, and the trap is confusing 'false positive' with 'true positive' by assuming any alert that fires is a true positive, or misinterpreting 'true negative' as a correct non-alert.

How to eliminate wrong answers

Option B is wrong because a true positive means the alert correctly identified malicious or unauthorized activity, but the login was legitimate. Option C is wrong because a true negative refers to no alert firing when no malicious activity occurs, which is not the scenario here since an alert did fire. Option D is wrong because a false negative means malicious activity occurred but no alert was generated, whereas here an alert was generated for benign activity.

118
MCQmedium

A security analyst is configuring a vulnerability scanner for internal network scanning. The analyst wants to ensure the scanner can identify missing patches and software configurations that require administrative privileges to read. Which scan type should the analyst configure?

A.Non-credentialed scan
B.Credentialed scan
C.External scan
D.Passive scan
AnswerB

A credentialed scan utilizes provided administrative or user credentials to log directly into the target operating system. This allows the scanner to perform deep local inspections, such as querying the registry, checking package manager databases, and auditing configuration files. Consequently, it provides a highly accurate assessment of missing patches and misconfigurations with minimal false positives.

Why this answer

Credentialed scans use administrative credentials to access systems and retrieve detailed configuration information, including missing patches.

119
Multi-Selectmedium

A security analyst is reviewing network traffic and suspects a host is infected with malware that uses a domain generation algorithm (DGA) for C2 communication. Which two of the following indicators are most consistent with DGA activity?

Select 2 answers
A.All DNS queries are to internal DNS servers
B.Frequent DNS queries to domains with random-looking, long subdomains
C.DNS queries to domains with a high Alexa ranking
D.High volume of DNS queries resulting in NXDOMAIN responses
E.Consistent DNS query intervals to a single IP
AnswersB, D

Frequent queries to domains with random-looking, long subdomains are a hallmark of Domain Generation Algorithms (DGAs). Malware uses DGAs to generate pseudorandom domain names as rendezvous points with command-and-control (C2) servers, often producing long, alphanumeric subdomains that appear nonsensical. The high query rate to such domains is a strong indicator of compromise because legitimate users rarely make repeated queries to random subdomains.

Why this answer

Option B is correct because DGA malware generates large numbers of pseudo-random domain names (often long, high-entropy subdomains) and the infected host repeatedly queries them while attempting to locate its C2 server. Option D is correct because most algorithmically generated domains are unregistered, so the resolver typically returns NXDOMAIN for the vast majority of these queries, producing a distinctive high-volume NXDOMAIN pattern. Option A is not indicative of DGA activity, since using internal DNS resolvers is normal enterprise behavior and says nothing about the queried domain names.

Option C is not indicative because DGA domains are newly generated and unregistered, so they would not have a high Alexa ranking. Option E is not indicative because consistent intervals to a single IP suggest beaconing to a fixed C2, whereas DGA relies on constantly changing domain names.

Exam trap

CS0-004 often tests the confusion between DGA indicators (random domains, NXDOMAIN floods) and fixed-C2 beaconing (consistent intervals to one IP), so candidates pick the beaconing pattern as DGA.

120
Multi-Selectmedium

A SOC analyst is investigating an alert from Azure Sentinel indicating a user account logged in from an unfamiliar location. The analyst wants to determine if this is a true positive. Which TWO additional log sources should the analyst correlate to make an informed decision?

Select 2 answers
A.Azure Security Center alerts
B.Azure Network Watcher flow logs
C.Azure Activity Logs
D.Azure Key Vault logs
E.Azure AD sign-in logs
AnswersC, E

Correct. Activity Logs record subscription-level control-plane operations performed by the account after authentication, so correlating them reveals whether the session was used to create, modify, or delete resources, which is a strong indicator of malicious intent versus benign access.

Why this answer

Azure AD sign-in logs provide authentication details, and Azure Activity Logs provide management plane activity. Correlating these can reveal if the sign-in was part of administrative actions or other anomalies.

121
Multi-Selecteasy

An analyst is configuring correlation rules in a SIEM. Which TWO data sources are essential for detecting lateral movement using pass-the-hash attacks?

Select 2 answers
A.Firewall logs
B.Authentication logs (e.g., Windows Event ID 4624)
C.DNS logs
D.Endpoint process creation logs (e.g., Event ID 4688)
E.Vulnerability scan results
AnswersB, D

Authentication logs, specifically Windows Event ID 4624, are central to detecting pass-the-hash because they record successful and failed logon events, including the logon type, authentication package (e.g., NTLM), source workstation, and target account. In a PtH attack, an attacker uses an NTLM hash as if it were a password; the logon event will typically show a network logon (Type 3) using NTLM, often from a non-domain host or in conjunction with suspicious source IP addresses. Correlating these 4624 events with known user activity patterns can reveal an attacker authenticating with a hash from an unauthorized source.

Why this answer

Authentication logs such as Windows Event ID 4624 are essential because they record logon events, including the logon type (e.g., Type 3 network logon) and authentication package (NTLM), which reveal the credential reuse characteristic of pass-the-hash lateral movement. Endpoint process creation logs such as Event ID 4688 are also essential because they capture the execution of tools and commands (e.g., cmd.exe, PsExec, net use) spawned after the attacker authenticates with the stolen hash, providing the behavioral evidence of movement on the target host. Firewall logs only show network connections and cannot confirm authentication or credential reuse, so they are insufficient on their own.

DNS logs may reveal resolution of internal hosts but do not show authentication or process execution tied to pass-the-hash. Vulnerability scan results identify missing patches or misconfigurations but do not record the runtime authentication and process activity needed to detect an active pass-the-hash attack.

Exam trap

CS0-004 often tests the misconception that network or vulnerability data detects credential-based lateral movement, when pass-the-hash is only visible through authentication and process creation telemetry correlated together.

122
MCQmedium

A threat hunter is reviewing osquery data from endpoints and notices that the Windows Registry key 'HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run' contains an entry for 'C:\Users\Public\svchost.exe'. Which of the following best describes the significance of this finding?

A.Confirms a false positive because svchost.exe is always legitimate
B.Indicates a scheduled task has been created
C.Suggests persistence via a malicious binary masquerading as svchost.exe
D.Indicates a legitimate application installed for all users
AnswerC

This is correct because the registry Run key is a classic persistence mechanism used to ensure malware executes automatically when a user logs in. Furthermore, legitimate "svchost.exe" binaries must execute exclusively from the System32 directory; finding an executable with this name in a user-writable directory like the Public folder strongly indicates a masquerading technique.

Why this answer

The Run key is a common persistence location in the Windows Registry. The entry points to 'C:\Users\Public\svchost.exe', which is suspicious because legitimate svchost.exe resides in C:\Windows\System32 and is never in the Users\Public folder. This strongly suggests a malicious binary masquerading as a legitimate system process to maintain persistence and evade detection.

Exam trap

CS0-004 often tests the misconception that any file named svchost.exe is legitimate, but the path is the key indicator; candidates might overlook the non-standard location.

How to eliminate wrong answers

Option A is wrong because while svchost.exe is a legitimate Windows process, its presence in a non-standard path like C:\Users\Public is highly anomalous and indicates compromise, not a false positive. Option B is wrong because scheduled tasks are stored in the Task Scheduler library, not in the Run key; the Run key indicates autostart via registry. Option D is wrong because legitimate applications rarely install to C:\Users\Public and use the name svchost.exe, which is a system process; this is a classic malware tactic.

123
MCQeasy

A security analyst is reviewing a SIEM alert for a single failed login attempt from an internal IP address to a file server. The analyst determines this is a false positive. Which step should the analyst take next?

A.Escalate to a senior analyst
B.Disable the SIEM alert permanently
C.Tune the alert to suppress similar events
D.Create a correlation rule to link with other events
AnswerC

Tuning the alert is the industry-standard method for managing false positives because it refines the detection logic to exclude benign, repetitive behavior. By adding specific exclusions, such as a trusted IP address or a known service account, the analyst reduces noise and alert fatigue without compromising the SIEM's ability to identify actual threats.

Why this answer

After confirming a false positive, the analyst should tune the alert to reduce noise. This may involve adjusting thresholds or whitelisting the source.

124
Multi-Selecthard

A security analyst is conducting a proactive threat hunt for lateral movement techniques. The analyst examines EDR data for unusual parent-child process relationships. Which three process chains are indicative of lateral movement? (Select THREE.)

Select 3 answers
A.svchost.exe spawning schtasks.exe
B.explorer.exe spawning cmd.exe
C.services.exe spawning cmd.exe
D.wmiprvse.exe spawning cmd.exe
E.rundll32.exe spawning powershell.exe
AnswersA, C, D

svchost.exe normally hosts service DLLs and does not spawn schtasks.exe. This parent-child pairing indicates a service being abused to create a scheduled task, a common lateral movement and persistence technique for executing code on a remote host.

Why this answer

Option A is correct because svchost.exe normally hosts Windows services and should not directly spawn schtasks.exe; this parent-child chain indicates a service abusing the Task Scheduler to create or run a remote task for lateral movement. Option C is correct because services.exe is the Service Control Manager and spawning cmd.exe directly is anomalous, often reflecting a malicious service or PsExec-style remote service creation used to execute commands on a target host. Option D is correct because wmiprvse.exe is the WMI provider host, and a WMI provider spawning cmd.exe is a classic sign of remote WMI execution (for example, wmic /node: process call create) used for lateral movement.

Option B is not indicative by itself because explorer.exe spawning cmd.exe is a common, legitimate user action such as opening a command prompt. Option E is not a reliable lateral-movement indicator because rundll32.exe spawning powershell.exe, while suspicious in some contexts, is a generic execution chain that can occur from local scripts or malware and does not specifically demonstrate lateral movement.

Exam trap

CS0-004 often tests the ability to distinguish between benign and malicious process chains, and candidates may incorrectly select explorer.exe spawning cmd.exe (a common user action) or rundll32.exe spawning powershell.exe (more associated with execution than lateral movement) as indicators of lateral movement.

125
MCQeasy

Which tool would best allow a security analyst to capture and analyze packets in real time to investigate a network anomaly?

A.Metasploit
B.Wireshark
C.Nmap
D.Nikto
AnswerB

Wireshark is a premier open-source packet analyzer that intercepts and decodes network traffic in real time. It allows security analysts to capture raw frames from a network interface card in promiscuous mode, filter traffic using display filters, and perform deep packet inspection to troubleshoot anomalies or detect malicious payloads.

Why this answer

Wireshark is a network protocol analyzer that captures and inspects packets in real time, making it ideal for real-time traffic analysis.

← PreviousPage 2 of 2 · 125 questions total

Ready to test yourself?

Try a timed practice session using only Security questions.