into a page, what happens?","url":"https://courseiva.com/questions/giac/giac-gcih/refer-to-the-exhibit-if-an-attacker-successfully-injects-s-imgc3"},{"@type":"ListItem","position":257,"name":"An incident handler is using a locally hosted LLM to summarize a 200-page intrusion report and extract indicators of com…","url":"https://courseiva.com/questions/giac/giac-gcih/an-incident-handler-is-using-a-locally-hosted-llm-to-summari-mh3mi"},{"@type":"ListItem","position":258,"name":"During a malware investigation, you discover that the adversary is using an AI model to generate domain names for its co…","url":"https://courseiva.com/questions/giac/giac-gcih/during-a-malware-investigation-you-discover-that-the-adversa-xeypd"},{"@type":"ListItem","position":259,"name":"An incident handler is analyzing a web application that uses a NoSQL database. The application constructs queries by dir…","url":"https://courseiva.com/questions/giac/giac-gcih/an-incident-handler-is-analyzing-a-web-application-that-uses-jeche"},{"@type":"ListItem","position":260,"name":"A security analyst is reviewing password hashes extracted from an older Linux system. The hashes are stored in /etc/shad…","url":"https://courseiva.com/questions/giac/giac-gcih/a-security-analyst-is-reviewing-password-hashes-extracted-fr-6h7p9"},{"@type":"ListItem","position":261,"name":"When performing a password audit, you identify the use of 'PBKDF2-HMAC-SHA256' for credential storage. What makes this a…","url":"https://courseiva.com/questions/giac/giac-gcih/when-performing-a-password-audit-you-identify-the-use-of-p-x0ahx"},{"@type":"ListItem","position":262,"name":"When auditing an application for Insecure Direct Object References, why is it recommended to perform tests using two dis…","url":"https://courseiva.com/questions/giac/giac-gcih/when-auditing-an-application-for-insecure-direct-object-refe-gnti6"},{"@type":"ListItem","position":263,"name":"An analyst uses an AI assistant to summarize a malware report and generate response steps. Before executing any recommen…","url":"https://courseiva.com/questions/giac/giac-gcih/an-analyst-uses-an-ai-assistant-to-summarize-a-malware-repor-w1fgj"},{"@type":"ListItem","position":264,"name":"What is the primary risk associated with using 'aggressive' scan timing templates (like T4 or T5) in an environment with…","url":"https://courseiva.com/questions/giac/giac-gcih/what-is-the-primary-risk-associated-with-using-aggressive-vtnnq"},{"@type":"ListItem","position":265,"name":"Which of the following is a classic example of an 'adversarial' attack against an AI-powered detection engine?","url":"https://courseiva.com/questions/giac/giac-gcih/which-of-the-following-is-a-classic-example-of-an-adversari-cfvei"},{"@type":"ListItem","position":266,"name":"Which of the following best describes the purpose of 'flow data' (like NetFlow) during an incident investigation?","url":"https://courseiva.com/questions/giac/giac-gcih/which-of-the-following-best-describes-the-purpose-of-flow-d-ae7vs"},{"@type":"ListItem","position":267,"name":"What is the primary function of the 'Token Manipulation' technique in Windows pivoting?","url":"https://courseiva.com/questions/giac/giac-gcih/what-is-the-primary-function-of-the-token-manipulation-tec-ezpjl"},{"@type":"ListItem","position":268,"name":"An attacker discovers an API endpoint /api/v1/user/details?id=123 that returns JSON data. They modify the parameter to /…","url":"https://courseiva.com/questions/giac/giac-gcih/an-attacker-discovers-an-api-endpoint-api-v1-user-details-i-5360b"},{"@type":"ListItem","position":269,"name":"An incident responder is investigating a suspected SMB relay attack on a corporate network. The attacker has compromised…","url":"https://courseiva.com/questions/giac/giac-gcih/an-incident-responder-is-investigating-a-suspected-smb-relay-ioo2s"},{"@type":"ListItem","position":270,"name":"A compromised Windows 10 workstation has an active Meterpreter session. The responder observes that the attacker used th…","url":"https://courseiva.com/questions/giac/giac-gcih/a-compromised-windows-10-workstation-has-an-active-meterpret-nkdhz"},{"@type":"ListItem","position":271,"name":"An incident responder is investigating a Windows endpoint where an attacker used the Windows Management Instrumentation …","url":"https://courseiva.com/questions/giac/giac-gcih/an-incident-responder-is-investigating-a-windows-endpoint-wh-nbl8c"},{"@type":"ListItem","position":272,"name":"A GCIH analyst is investigating a web application that uses Java deserialization to process user-supplied session object…","url":"https://courseiva.com/questions/giac/giac-gcih/a-gcih-analyst-is-investigating-a-web-application-that-uses--9st79"},{"@type":"ListItem","position":273,"name":"A penetration tester discovers that a web application uses a predictable numeric parameter `user_id` in the URL to retri…","url":"https://courseiva.com/questions/giac/giac-gcih/a-penetration-tester-discovers-that-a-web-application-uses-a-14ld3"},{"@type":"ListItem","position":274,"name":"An analyst is reviewing logs and finds multiple failed logins followed by a single successful login from a different IP …","url":"https://courseiva.com/questions/giac/giac-gcih/an-analyst-is-reviewing-logs-and-finds-multiple-failed-login-6ale6"},{"@type":"ListItem","position":275,"name":"A GCIH analyst is examining a web application that uses GraphQL. The analyst notices that an attacker sent a deeply nest…","url":"https://courseiva.com/questions/giac/giac-gcih/a-gcih-analyst-is-examining-a-web-application-that-uses-grap-nl5xi"},{"@type":"ListItem","position":276,"name":"An attacker is using WMI (Windows Management Instrumentation) to move laterally. Which WMI class and method combination …","url":"https://courseiva.com/questions/giac/giac-gcih/an-attacker-is-using-wmi-windows-management-instrumentation-68hcd"},{"@type":"ListItem","position":277,"name":"An incident handler is triaging a suspected beaconing implant on a Windows workstation. NetFlow records show a repeating…","url":"https://courseiva.com/questions/giac/giac-gcih/an-incident-handler-is-triaging-a-suspected-beaconing-implan-njb5j"},{"@type":"ListItem","position":278,"name":"An incident handler is analyzing a packet capture and notices a high volume of TCP SYN packets sent to multiple ports on…","url":"https://courseiva.com/questions/giac/giac-gcih/an-incident-handler-is-analyzing-a-packet-capture-and-notice-7gxp4"},{"@type":"ListItem","position":279,"name":"When evaluating potential SQL injection in an application, what is the most significant indicator that an application is…","url":"https://courseiva.com/questions/giac/giac-gcih/when-evaluating-potential-sql-injection-in-an-application-w-kc7sv"},{"@type":"ListItem","position":280,"name":"Which of the following describes the 'Confused Deputy' problem in the context of cloud IAM roles?","url":"https://courseiva.com/questions/giac/giac-gcih/which-of-the-following-describes-the-confused-deputy-probl-ofon7"},{"@type":"ListItem","position":281,"name":"A penetration tester is performing a password attack against an Active Directory environment. The tester has obtained a …","url":"https://courseiva.com/questions/giac/giac-gcih/a-penetration-tester-is-performing-a-password-attack-against-jed4o"},{"@type":"ListItem","position":282,"name":"An attacker uses living-off-the-land binaries (LotLbins) to execute a malicious PowerShell script. Which detection strat…","url":"https://courseiva.com/questions/giac/giac-gcih/an-attacker-uses-living-off-the-land-binaries-lotlbins-to-7kju7"},{"@type":"ListItem","position":283,"name":"Why are GPUs highly effective at cracking password hashes compared to traditional CPUs?","url":"https://courseiva.com/questions/giac/giac-gcih/why-are-gpus-highly-effective-at-cracking-password-hashes-co-3xpc5"},{"@type":"ListItem","position":284,"name":"An adversary is using reflective DLL injection to evade detection. Which TWO indicators would most reliably suggest this…","url":"https://courseiva.com/questions/giac/giac-gcih/an-adversary-is-using-reflective-dll-injection-to-evade-dete-tk0rn"},{"@type":"ListItem","position":285,"name":"Which of the following is the primary risk associated with using unvetted AI models for malware signature generation?","url":"https://courseiva.com/questions/giac/giac-gcih/which-of-the-following-is-the-primary-risk-associated-with-u-z6491"},{"@type":"ListItem","position":286,"name":"During an authorized incident response engagement, you need to determine whether a specific suspicious host at 10.20.30.…","url":"https://courseiva.com/questions/giac/giac-gcih/during-an-authorized-incident-response-engagement-you-need-t-l3wv2"},{"@type":"ListItem","position":287,"name":"An incident handler is investigating a web application that allows users to upload profile pictures. The application sto…","url":"https://courseiva.com/questions/giac/giac-gcih/an-incident-handler-is-investigating-a-web-application-that--ui9a3"},{"@type":"ListItem","position":288,"name":"A security analyst is investigating a suspected local file inclusion (LFI) attack against a PHP web application. The web…","url":"https://courseiva.com/questions/giac/giac-gcih/a-security-analyst-is-investigating-a-suspected-local-file-i-llm1m"},{"@type":"ListItem","position":289,"name":"Refer to the exhibit. An AI-based EDR identifies a suspicious process chain. Based on the provided JSON output, what is …","url":"https://courseiva.com/questions/giac/giac-gcih/refer-to-the-exhibit-an-ai-based-edr-identifies-a-suspiciou-e60ma"},{"@type":"ListItem","position":290,"name":"An analyst is investigating a suspected compromise on a Windows 10 endpoint. Network telemetry shows periodic outbound H…","url":"https://courseiva.com/questions/giac/giac-gcih/an-analyst-is-investigating-a-suspected-compromise-on-a-wind-w6b9h"},{"@type":"ListItem","position":291,"name":"Which of the following describes a 'credential stuffing' attack?","url":"https://courseiva.com/questions/giac/giac-gcih/which-of-the-following-describes-a-credential-stuffing-att-in0l3"},{"@type":"ListItem","position":292,"name":"An incident responder investigates a web application breach where an attacker successfully extracted sensitive user data…","url":"https://courseiva.com/questions/giac/giac-gcih/an-incident-responder-investigates-a-web-application-breach-zond0"},{"@type":"ListItem","position":293,"name":"An incident responder is analyzing a compromised Linux server. The responder notices that the file /etc/ld.so.preload co…","url":"https://courseiva.com/questions/giac/giac-gcih/an-incident-responder-is-analyzing-a-compromised-linux-serve-daggd"},{"@type":"ListItem","position":294,"name":"A security analyst is reviewing logs from a Linux web server and notices that the 'last' command output shows a login by…","url":"https://courseiva.com/questions/giac/giac-gcih/a-security-analyst-is-reviewing-logs-from-a-linux-web-server-ukq3h"},{"@type":"ListItem","position":295,"name":"An incident responder is investigating a suspected compromise on a Windows endpoint and wants to identify evidence of la…","url":"https://courseiva.com/questions/giac/giac-gcih/an-incident-responder-is-investigating-a-suspected-compromis-dgujc"},{"@type":"ListItem","position":296,"name":"Refer to the exhibit. Given the provided log entry, which attack is likely occurring, and what does the sub-status code …","url":"https://courseiva.com/questions/giac/giac-gcih/refer-to-the-exhibit-given-the-provided-log-entry-which-at-g53nj"},{"@type":"ListItem","position":297,"name":"A GCIH incident responder is investigating a suspected API attack where an attacker manipulated a JSON Web Token (JWT) t…","url":"https://courseiva.com/questions/giac/giac-gcih/a-gcih-incident-responder-is-investigating-a-suspected-api-a-msjdn"},{"@type":"ListItem","position":298,"name":"Which technique involves an attacker injecting code into a legitimate, running process to perform malicious activity whi…","url":"https://courseiva.com/questions/giac/giac-gcih/which-technique-involves-an-attacker-injecting-code-into-a-l-04t6w"},{"@type":"ListItem","position":299,"name":"During a forensic analysis of a compromised developer workstation, an incident handler discovers scripts showing an atta…","url":"https://courseiva.com/questions/giac/giac-gcih/during-a-forensic-analysis-of-a-compromised-developer-workst-grj6m"},{"@type":"ListItem","position":300,"name":"Which TWO of the following are considered best practices for password hashing to mitigate offline cracking?","url":"https://courseiva.com/questions/giac/giac-gcih/which-two-of-the-following-are-considered-best-practices-for-t5i3a"}]}
Refer to the exhibit. An analyst deploys this policy to detect threats. Why is the 'parent_process' condition specifically targeting 'w3wp.exe'?
A.To detect unauthorized software installations performed by administrative users.
B.To identify potential web shell execution or exploit payloads triggered via IIS.
C.To prevent the web server from being used as a staging ground for brute force.
D.To ensure that all PowerShell scripts are signed and authorized by the organization.
AnswerB
IIS worker processes (w3wp.exe) should rarely spawn PowerShell. When they do, it is a high-confidence indicator of a web application compromise, such as a web shell executing commands. This detection is tailored to catch the specific behavior of attackers attempting to pivot from a web exploit to system-level execution.
Why this answer
The 'w3wp.exe' process is the IIS worker process. Attackers often exploit web vulnerabilities to spawn child processes, such as PowerShell, to execute malicious scripts directly from memory. By flagging PowerShell child processes of an IIS worker, the analyst is specifically monitoring for web shell activity or remote code execution, which are common vectors for initial access and persistence in web-facing server environments.
Exam trap
Candidates often assume the rule is looking for the 'w3wp.exe' process itself as the threat, missing that the goal is to detect suspicious child processes spawned by a legitimate web server process.
Refer to the exhibit. An analyst identifies these entries on a critical server. What should the analyst conclude regarding the process associated with PID 4?
A.The server is likely compromised by a kernel-mode rootkit acting as a listener.
B.The process is a legitimate Windows kernel operation for SMB file sharing.
C.A remote adversary is using the SMB protocol to exfiltrate data from the system.
D.The system is currently scanning the network for vulnerabilities using SMB exploits.
AnswerB
PID 4 is the System process, which handles network traffic for the Server service, including SMB (TCP 445). This traffic is typical for a server responding to legitimate client requests. An analyst should differentiate between standard operating system network behavior and suspicious outbound connections to unauthorized external IP addresses.
Why this answer
In Windows environments, PID 4 is reserved for the System process. In the context of port 445 (SMB), this is standard behavior for the Server service and kernel-level file sharing. Recognizing legitimate OS behavior is critical to avoid false positives.
If the source IPs were unknown or the connection volume was anomalous, further investigation into kernel-mode drivers or rootkits would be required, but this output represents standard file sharing functionality.
Exam trap
Test-takers frequently panic upon seeing PID 4 involved in network listening ports, incorrectly assuming it represents malicious kernel-level rootkits or compromise.
An incident responder is investigating a RESTful API breach where an authenticated low-privileged user accessed administrative records by modifying an integer identifier in the resource path from /api/v1/users/104 to /api/v1/users/1. Which type of vulnerability has been exploited?
A.Broken Function Level Authorization
B.Cross-Site Request Forgery
C.Insecure Direct Object Reference
D.Server-Side Request Forgery
AnswerC
The API trusted the client-supplied identifier without verifying that the authenticated user owned or was authorised for that record. Changing /users/104 to /users/1 returned another user's administrative data, which is the defining pattern of Insecure Direct Object Reference.
Why this answer
This scenario describes an Insecure Direct Object Reference vulnerability, commonly classified under Broken Object Level Authorization in modern API security taxonomies. The application fails to validate whether the requesting user possesses authorization to access the specific resource identifier requested in the URL path. Attackers systematically enumerate these predictable identifiers to harvest unauthorized sensitive data across multi-tenant API endpoints during security assessments and active breaches.
Exam trap
Candidates frequently confuse Broken Object Level Authorization with Broken Function Level Authorization because both involve access control failures, but function authorization restricts administrative URLs rather than specific data record identifiers.
An attacker has obtained a set of NTLM hashes from a compromised workstation and now wants to use them to authenticate to other systems in the domain without cracking them. Which two of the following conditions are necessary for a successful Pass-the-Hash attack? (Choose two.)
Select 2 answers
A.The target systems must be domain controllers.
B.The target systems must accept NTLM authentication.
C.The attacker must know the plaintext password associated with the hash.
D.The NTLM hash must correspond to a user account with logon rights on the target systems.
E.The attacker must have administrative privileges on the target systems.
AnswersB, D
Pass-the-Hash relies on the NTLM authentication protocol. If target systems are configured to only accept Kerberos authentication, the attack will fail. Therefore, NTLM must be enabled and permitted on the target systems for the hash to be used directly for authentication. This is a fundamental requirement for the attack to succeed.
Why this answer
Pass-the-Hash requires that the target systems accept NTLM authentication and that the compromised hash belongs to an account with logon rights on those systems. Without these, the attack cannot proceed. Administrative privileges, plaintext passwords, and domain controller status are not necessary conditions, making them incorrect choices.
Exam trap
The trap here is thinking Pass-the-Hash requires administrative rights or the plaintext password, but it only requires a valid hash and NTLM-enabled target.
An incident responder is reviewing a compromised Linux host and notices that the attacker modified the /etc/ld.so.preload file to include a path to a shared object file. Shortly after, the responder observes that common commands like 'ls' and 'ps' are returning incomplete or manipulated output. Which post-exploitation technique has the attacker most likely employed?
A.Cron job persistence to maintain access
B.SUID binary exploitation to escalate privileges
C.Kernel module rootkit loaded via insmod
D.Userland rootkit using LD_PRELOAD to hook library calls
AnswerD
Modifying /etc/ld.so.preload to load a malicious shared object causes the dynamic linker to preload that library into every process. The library can hook functions like readdir and open to hide files and processes, producing manipulated output from commands like ls and ps. This is a classic userland rootkit technique on Linux that does not require kernel modifications.
Why this answer
The modification of /etc/ld.so.preload to load a malicious shared object is a hallmark of a userland rootkit. The dynamic linker preloads the library into every process, allowing it to hook system calls like readdir and open, which hides files and processes and manipulates command output. This technique is stealthy because it operates in userland without kernel modifications.
Exam trap
The trap here is assuming any rootkit requires kernel module loading, when userland rootkits using LD_PRELOAD are simpler to deploy and leave different, file-based artifacts.
Refer to the exhibit. An attacker attempts to establish persistence by creating a new service. Why did the command fail?
A.The service has already been deleted by the system.
B.The 'sc' command does not support the 'binPath' argument.
C.The command syntax is incorrect for creating a service.
D.The user lacks sufficient privileges to query services.
AnswerC
The 'sc query' command is designed to retrieve the status of a registered service, not to define a new one. To register a service, the attacker must use 'sc create [ServiceName] binPath=...'. The provided command failed because it was querying for an object that was never defined.
Why this answer
The 'sc query' command is used to inspect existing services, not to register new ones. The attacker attempted to use the query syntax rather than the 'create' command to define the service. Understanding the proper syntax for service manipulation is critical for incident handlers to identify how attackers attempt to achieve persistence via Windows Service Control Manager or other system-level configuration methods.
Exam trap
Candidates often confuse the 'sc query' command with 'sc create'. They assume that because 'query' is used to view services, it is the primary command for all service-related administrative tasks in Windows.
An incident responder is analyzing a packet capture and observes a Windows workstation sending an SMB2 NEGOTIATE request listing only the SMB 2.0.2 dialect, followed by a SESSION_SETUP request containing an NTLMSSP Type 3 message. The server responds with STATUS_SUCCESS. The workstation normally communicates with this file server using SMB 3.1.1. What is the most likely explanation for this behavior?
A.The workstation's SMB client is misconfigured to use only SMB 2.0.2 due to a missing registry key.
B.An attacker performed an SMB downgrade attack by intercepting the negotiation and stripping higher dialect offers.
C.The file server is configured to only accept SMB 2.0.2 connections, forcing the client to downgrade.
D.The capture shows normal fallback behavior because the client and server could not agree on SMB 3.1.1 encryption.
AnswerB
The workstation normally uses SMB 3.1.1, but the capture shows only SMB 2.0.2 offered and NTLMSSP authentication instead of Kerberos, indicating a man-in-the-middle stripped higher dialects and forced weaker authentication. This aligns with an SMB downgrade attack, where the attacker manipulates negotiation to weaken security and capture or relay credentials.
Why this answer
The correct answer is the scenario where an attacker intercepts SMB negotiation and strips higher dialect offers, forcing the client to use SMB 2.0.2 and NTLMSSP authentication. This is a classic SMB downgrade attack aimed at capturing or relaying credentials. The other options describe misconfigurations or benign fallbacks that do not match the sudden change from SMB 3.1.1 with Kerberos to SMB 2.0.2 with NTLMSSP.
Exam trap
The trap here is assuming that any SMB dialect mismatch is a configuration error, when a sudden downgrade combined with NTLMSSP authentication can indicate an active man-in-the-middle attack.
A penetration testing team is integrating a locally hosted LLM into its post-exploitation tooling to help draft PowerShell and Bash commands from natural-language objectives. Before deployment, the team lead must identify controls that limit the blast radius if the model is manipulated through crafted input. (Choose two.)
Select 2 answers
A.Fine-tune the model on the team's historical engagement reports to improve command accuracy and reduce manipulation risk.
B.Execute all model-generated commands inside a disposable, network-isolated sandbox until they are reviewed and approved.
C.Require human review and explicit approval of each generated command before it is executed against any target.
D.Enable verbose logging of the model's internal attention weights so operators can detect manipulated prompts.
E.Grant the LLM service account standing administrative credentials on the engagement jump host to avoid execution failures.
AnswersB, C
Running generated commands in a disposable, isolated sandbox contains any destructive or unintended action the model produces, including commands induced by crafted input. Because the environment is ephemeral and lacks network reach into production or client systems, manipulation cannot translate into real-world impact. Review and approval before promotion to live systems adds a human gate, directly limiting blast radius as required by the scenario.
Why this answer
Limiting blast radius requires containment and human control over what actually executes. Running generated commands in a disposable, network-isolated sandbox ensures any manipulated output is harmless, and requiring explicit human approval before execution against targets prevents harmful commands from ever running. Attention-weight logging offers no containment, standing admin credentials amplify impact, and fine-tuning improves quality without creating any security boundary.
Exam trap
The trap here is treating output-quality improvements such as fine-tuning or interpretability logging as security controls, when blast-radius reduction actually requires isolation and human approval before execution.
An organization is migrating to AWS and needs to ensure that IAM users do not possess long-term credentials. Which approach provides the most secure mechanism for programmatic access?
A.Generate unique access keys for every developer stored in an encrypted S3 bucket.
B.Rotate IAM user access keys every 90 days via an automated script.
C.Implement IAM roles that grant temporary security credentials via STS.
D.Use an IAM group policy to enforce Multi-Factor Authentication on all API requests.
AnswerC
IAM roles provide temporary security credentials that expire automatically, effectively mitigating the risk of credential theft. By leveraging AWS Security Token Service (STS), developers can assume roles only when needed. This approach eliminates the need for managing static keys, significantly reducing the attack surface for programmatic cloud access.
Why this answer
Utilizing IAM roles with temporary security credentials is the best practice for cloud security. By assuming roles, you eliminate the risks associated with static access keys, which are frequently leaked or stolen. This approach aligns with the principle of least privilege, as temporary tokens expire automatically, reducing the window of opportunity for an attacker to exploit compromised credentials, thereby enhancing the overall security posture of the cloud environment.
Exam trap
Candidates frequently select long-term access keys configured with multi-factor authentication, forgetting that programmatic access requires automated temporary credentials.
During a security incident, a GCIH analyst discovers that an attacker used PowerShell to download and execute a malicious script from a remote server. The analyst wants to determine the full command line and parent process of the PowerShell execution to understand the attack vector. Which Windows artifact should the analyst examine to retrieve this information?
A.PowerShell operational log, event ID 4104
B.Windows System event log, event ID 7045
C.Windows Security event log, event ID 4688
D.Sysmon event ID 1 (Process Create)
AnswerD
Sysmon event ID 1 logs process creation and includes rich details such as the full command line, parent process ID, user account, and hashes. This directly answers the analyst's need to see the exact PowerShell command line and its parent process, enabling reconstruction of the attack chain. Sysmon is commonly used in incident response for this level of detail.
Why this answer
Sysmon event ID 1 provides comprehensive process creation data, including the full command line and parent process, which are critical for understanding how PowerShell was invoked and what it executed. Other logs either lack command-line detail (Security 4688 by default) or focus on script content (PowerShell 4104) rather than process lineage. Thus, Sysmon is the most appropriate artifact to retrieve the required information.
Exam trap
The trap here is assuming that PowerShell script block logging captures the command line and parent process, when it only captures script content.
An incident handler is reviewing SMB traffic and notices multiple 'Tree Connect' requests to the IPC$ share. What does this activity typically signify in an attack scenario?
A.A standard user is accessing their home directory.
B.An attacker is likely performing reconnaissance or lateral movement.
C.The workstation is simply performing routine backups.
D.The SMB server is correctly enforcing message signing.
AnswerB
The IPC$ share is a primary target for attackers during the reconnaissance phase. It allows them to interact with the system's administrative features without needing a standard file share. Frequent connections to IPC$ are a hallmark of an attacker mapping the network or attempting to execute remote commands via SMB.
Why this answer
The IPC$ (Inter-Process Communication) share is a special share used by Windows for communication between network devices, often for administrative functions. Attackers frequently connect to IPC$ to perform null sessions or to interact with the service control manager to remotely execute code. Identifying frequent, unauthorized connections to IPC$ is a strong indicator of reconnaissance or lateral movement, as it is a common starting point for an attacker to enumerate the system.
Exam trap
Students often dismiss IPC$ share connections as normal background operating system noise, failing to recognize that repeated null sessions indicate active attacker reconnaissance.
A company stores sensitive data in an Amazon S3 bucket. The security team wants to ensure that all data is encrypted at rest using keys managed by AWS Key Management Service (KMS) and that the encryption is enforced automatically for all new objects. Which configuration should they implement?
A.Use AWS Certificate Manager (ACM) to provision SSL/TLS certificates for the S3 bucket.
B.Create a bucket policy that denies unencrypted PutObject requests.
C.Enable default encryption on the S3 bucket using SSE-S3 (AES-256).
D.Enable default encryption on the S3 bucket using SSE-KMS with a customer managed key.
AnswerD
SSE-KMS with a customer managed key uses AWS KMS to manage the encryption keys, providing centralized control, audit trails via CloudTrail, and the ability to rotate keys. Enabling default encryption ensures all new objects are encrypted automatically without relying on users to specify encryption headers. This directly satisfies the requirement for KMS-managed keys and enforced encryption.
Why this answer
Enabling default encryption with SSE-KMS and a customer managed key ensures that all new objects are encrypted using KMS-managed keys, meeting both the encryption at rest and key management requirements. It also provides auditability and control over the keys. Other options either use non-KMS keys, only enforce encryption without specifying key type, or address transit encryption instead of at rest.
Exam trap
The trap here is confusing encryption in transit with encryption at rest, or assuming that SSE-S3 satisfies a requirement for KMS-managed keys when it uses S3-managed keys instead.
An incident responder is analyzing an API access log and notices a user with ID 104 is able to modify account settings for user ID 105 by simply changing the integer value in the URI endpoint from /api/v1/users/104/settings to /api/v1/users/105/settings without any additional token validation or role checks. Which specific OWASP API Security Top 10 vulnerability class does this scenario represent?
A.Broken Authentication due to weak session token generation algorithms allowing session hijacking across user accounts.
B.Broken Object Level Authorization resulting from missing access control validation checks on resource identifiers embedded directly within API request paths.
C.Mass Assignment vulnerability caused by automatically binding incoming HTTP request parameters to internal backend database object properties.
D.Improper Assets Management stemming from exposed documentation and forgotten non-production API endpoints lacking proper security controls.
AnswerB
Missing authorization checks on resource identifiers allow authenticated users to access or modify objects by altering parameters like user IDs in the URI. This represents a classic failure of object-level access controls within modern RESTful API architectures.
Why this answer
This scenario describes Broken Object Level Authorization, where an API endpoint fails to verify whether the authenticated user possesses the appropriate permissions to access or modify a specific object identifier within the URI. Attackers exploit this design flaw to systematically harvest or alter sensitive data across multiple accounts. Recognizing this architectural failure is vital for incident handlers performing root-cause analysis during data breach investigations involving web applications and modern API microservices.
Exam trap
Candidates frequently confuse this with Broken Authentication because the attack involves user identifiers, but the core issue is the complete lack of authorization checks once the user is already authenticated.
During an authorized discovery scan of a DMZ, an incident responder needs Nmap to report the reason each port is classified as open, closed, or filtered so the team can distinguish a firewall drop from a host reset. Which Nmap option should the responder add to the command line?
A.-d
B.-v
C.--packet-trace
D.--reason
AnswerD
The --reason option makes Nmap display the reason code for each port state, such as syn-ack, resets, or no-response, directly in the output. This lets the responder differentiate a closed port that returned a TCP RST from a filtered port that produced no reply, which is exactly what the DMZ analysis requires.
Why this answer
Adding --reason to an Nmap scan causes each port entry to include the reason Nmap assigned the state, such as syn-ack for open, reset for closed, or no-response for filtered. This distinction is critical in a DMZ where a drop and a reset imply very different firewall or host behaviors, and it gives the responder defensible evidence for the report.
Exam trap
The trap here is confusing verbosity options like -v or --packet-trace with the specific --reason flag that annotates each port state with its cause.
An incident handler is examining a web server's access logs after a suspected SQL injection attempt. The log shows a request with a long URL containing multiple single quotes and 'UNION SELECT' statements. Which log field is most critical to correlate this request with other events to determine if the attack succeeded?
A.The HTTP status code
B.The source IP address and timestamp
C.The User-Agent string
D.The requested URL path
AnswerB
The source IP address and timestamp provide a unique combination that can be used to correlate the web request with other log sources, such as database logs, firewall logs, or authentication logs. This allows the incident handler to trace the attacker's actions across multiple systems and determine if the SQL injection led to further compromise.
Why this answer
Correlating events across disparate logs requires a common identifier such as source IP and timestamp. These fields allow the incident handler to pivot from the web server log to database logs, firewall logs, or IDS alerts to see if the SQL injection resulted in data extraction, error messages, or additional requests. Other fields like User-Agent or status code may provide context but lack the uniqueness needed for reliable correlation.
Exam trap
The trap here is assuming that the HTTP status code alone can indicate a successful attack, but many SQL injection attempts return 200 OK even when they fail, and status codes are not unique enough for correlation.
Which THREE of the following are essential components of an effective AI-assisted malware hunting strategy?
Select 3 answers
A.Continuous ingestion of high-quality, normalized telemetry data.
B.A feedback loop where analyst findings refine future AI model detection.
C.Eliminating all manual review to maximize the hunting speed.
D.Focusing exclusively on known malware signatures for speed.
E.Regular testing of the model against adversarial evasion attempts.
AnswersA, B, E
AI models are only as good as the data they process. High-quality, normalized telemetry from across the environment is essential for the AI to identify meaningful patterns. Inconsistent or poor-quality logs lead to missed detections and high false-positive rates, rendering even the most sophisticated AI models ineffective for malware hunting efforts.
Why this answer
Effective malware hunting requires a combination of strong data hygiene, human intuition, and robust analytical loops. AI provides the speed and pattern recognition necessary to handle large volumes of data, but it requires carefully curated inputs and human oversight to remain effective. These components are essential because they ensure that hunting efforts are scalable, reproducible, and aligned with the actual behavioral patterns observed during the adversary's lifecycle within the enterprise environment.
Exam trap
Many test-takers focus exclusively on the AI model's internal capabilities while neglecting the critical importance of data hygiene and the human-in-the-loop feedback mechanisms required for long-term hunting success.
Refer to the exhibit. An attacker bypasses this policy. Why did this control fail?
A.PowerShell was not fully patched to the latest version.
B.The policy only filters for one specific argument variation.
C.The system was not rebooted after the policy was applied.
D.The policy only blocks 'powershell.exe' and not 'pwsh.exe'.
AnswerB
The policy is flawed because it only looks for the '-enc' string. PowerShell accepts various abbreviations for encoded commands, such as '-encoded', '-e', and '-en'. By using a different variation, the attacker effectively circumvents the filter, demonstrating the weakness of signature-based argument blocking.
Why this answer
The policy specifically blocks -enc, but PowerShell supports multiple aliases and variations like -encodedcommand, -e, and -en. Security controls that rely on string matching for specific command-line arguments are brittle because attackers can easily use different syntax or encoding to achieve the same result. Effective detection must look for the behavior of encoded execution regardless of the specific argument shorthand used in the command line.
Which THREE items are essential components of an API security documentation strategy for incident responders?
A.Up-to-date OpenAPI/Swagger specifications
B.Complete inventory of all exposed API endpoints
C.Detailed API rate-limiting and throttling policies
D.Hardcoded database credentials for internal services
E.Customer personal identifiable information (PII) logs
AnswerA, B, C
OpenAPI documents provide a ground truth of the API's intended design, including expected input formats, authentication methods, and endpoint definitions. Responders use this to detect anomalies by comparing actual request structures against the documented schema to identify malicious variations or unexpected inputs.
Why this answer
Effective incident response for APIs requires comprehensive documentation. API specifications (like OpenAPI/Swagger) provide the baseline for expected behavior and valid endpoints. Inventory documentation ensures all endpoints are known and monitored.
Finally, security headers and rate-limiting policies document the defense-in-depth posture. Without these, responders cannot differentiate between legitimate traffic patterns and malicious exploitation attempts during an active security event or during post-incident forensic analysis.
Exam trap
Candidates often select 'API keys' or 'authentication logs' as essential components. While useful, they are not structural documentation strategies required for incident responders to understand API behavior and baseline traffic patterns during an active event.
An analyst is investigating a suspected Pass-the-Hash attack within an Active Directory environment. Which TWO Windows Security Event Log IDs should the analyst examine to detect the use of stolen NTLM credential material for lateral movement? (Choose TWO)
Select 2 answers
A.Event ID 4624 (An account was successfully logged on)
B.Event ID 4625 (An account failed to log on)
C.Event ID 4672 (Special privileges assigned to new logon)
D.Event ID 4720 (A user account was created)
E.Event ID 1102 (The audit log was cleared)
AnswersA, C
Event ID 4624 is critical because Pass-the-Hash attacks result in successful authentication sessions without requiring plaintext passwords. Analysts examine the logon type and authentication package fields within this event to identify anomalous network logons utilizing NTLM.
Why this answer
Event ID 4624 records successful logons, and specifying Logon Type 3 (Network) combined with NTLM authentication indicates a potential Pass-the-Hash event when originating from an unusual source. Event ID 4672 details special privileges assigned to new logins, helping verify if the compromised security context obtained administrative privileges across the domain.
Exam trap
Candidates frequently select Event ID 4625, confusing failed logon attempts with the successful authentication events characteristic of valid stolen hash utilization.
An application uses a Base64 encoded string as a parameter for object references. An attacker decodes the string, modifies the ID, re-encodes it, and successfully accesses unauthorized data. Why did the security control fail?
A.Base64 encoding is inherently reversible
B.The server failed to enforce HTTPS
C.The session token was not included in the payload
D.The application used an insecure hashing algorithm
AnswerA
Base64 is a reversible encoding scheme, not an encryption method. Attackers can easily decode and modify the payload before re-encoding it. The security failure stems from the reliance on this 'obfuscation' instead of implementing robust server-side authorization checks to verify if the user is permitted to access the modified ID.
Why this answer
The failure occurred because the application relied on encoding (Base64) as a security control instead of proper authorization logic. Encoding is a data representation technique, not a security mechanism. Because the server failed to perform access control checks on the decoded identifier, it allowed the attacker to bypass the intended security model.
This highlights the importance of never confusing data format obfuscation with actual authorization or identity management.
Exam trap
Candidates frequently mistake encoding (like Base64) for encryption or a security control, failing to realize that reversible data formats provide zero protection against unauthorized access if authorization checks are missing.
Which THREE actions are recommended to secure SMB against credential relay and man-in-the-middle attacks?
Select 3 answers
A.Enforce SMB message signing
B.Force the use of SMBv1 exclusively
C.Implement SMB encryption
D.Disable the SMBv1 protocol
E.Use cleartext passwords for SMB shares
AnswersA, C, D
SMB signing adds a cryptographic signature to each packet, ensuring that the traffic has not been modified in transit. This is a primary defense against man-in-the-middle attacks, as an attacker cannot forge or alter packets without the server detecting the invalid signature, effectively neutralizing the relay attack vector.
Why this answer
Securing SMB requires a layered approach focusing on authentication integrity and protocol restrictions. Enabling SMB signing ensures that packets are not modified in transit, while SMB encryption provides confidentiality. Furthermore, disabling legacy protocols like SMBv1 eliminates the weakest links that are often targeted for relaying.
These steps are fundamental for hardening Windows environments against attackers aiming to steal or reuse credentials within the network, significantly hindering lateral movement and privilege escalation attempts.
Exam trap
Candidates frequently choose 'disabling SMB' as a whole. Disabling the entire protocol is usually not feasible in production; the correct approach is hardening it by disabling legacy versions and enforcing security flags.
During an authorized red team engagement, an operator uses a locally hosted LLM to draft a novel payload that evades the client's endpoint detection. Before delivering the payload to the target, the operator must validate the model's output. Which two practices best support safe, accountable use of the generated payload? (Choose two.)
Select 2 answers
A.Trust the payload because the LLM was fine-tuned on a corpus of validated offensive security code.
B.Ask the same LLM to review its own payload and confirm that it is safe to run against the target.
C.Execute the generated payload first in an isolated lab replica of the target environment and confirm its behavior matches the engagement's rules of engagement.
D.Record the prompt, model version, and a hash of the generated payload in the engagement log for later reconstruction.
E.Publish the generated payload to a public repository so peers can review it before the engagement proceeds.
AnswersC, D
Model output can contain unintended functionality that exceeds the authorized scope. Running it in an isolated replica lets the operator observe actual behavior, confirm no destructive or out-of-scope actions occur, and verify the payload does what the engagement intends. This directly enforces the rules of engagement before any live delivery and is a core validation step for AI-assisted offensive tooling.
Why this answer
AI-assisted payload generation shifts the operator's job from writing code to validating it. Isolated execution against a lab replica confirms the artifact behaves within the authorized scope, and logging the prompt, model version, and payload hash preserves reproducibility and accountability for the client debrief and any later forensic review. Self-review, public disclosure, and blind trust in fine-tuning all substitute assumption for evidence.
Exam trap
The trap here is treating the model's own confidence or its fine-tuning pedigree as validation, when only observed behavior and documented provenance demonstrate that a generated payload stays inside the rules of engagement.
A web application allows users to download files by specifying a filename in the URL, such as `download?file=report.pdf`. An attacker changes the parameter to `download?file=../../../../etc/passwd` and successfully retrieves the system's password file. Which of the following best describes this attack?
A.Remote File Inclusion (RFI)
B.Insecure Direct Object Reference (IDOR)
C.Cross-Site Scripting (XSS)
D.Path Traversal
AnswerD
The attacker uses `../` sequences to navigate outside the intended directory and access a system file. This is the definition of Path Traversal, also known as directory traversal. The application fails to sanitize the file path, allowing access to files outside the web root. The success of retrieving `/etc/passwd` confirms the vulnerability.
Why this answer
The attacker manipulates the `file` parameter with `../` sequences to escape the intended directory and read a system file. This is a classic Path Traversal attack. The application fails to validate or sanitize the user-supplied path, allowing access to files outside the web root.
The successful retrieval of `/etc/passwd` demonstrates the vulnerability.
Exam trap
The trap here is confusing Path Traversal with IDOR, but IDOR involves accessing objects by reference, not navigating the file system with directory traversal sequences.
Which TWO of the following are common indicators that a password database has been compromised?
Select 2 answers
A.A high volume of account takeover reports
B.Increased server CPU usage during off-hours
C.Sudden, massive spikes in credential stuffing logs
D.A change in the local system time on the server
E.An increase in valid user password reset requests
AnswersA, C
When a large number of users suddenly report account takeovers, it is a strong indicator that their credentials have been exfiltrated and are being actively used by an attacker. This is often the first real-world sign that a database has been breached and the hashes cracked offline.
Why this answer
Detecting a password database compromise often involves monitoring for unusual database activity or indicators of downstream misuse. A sudden spike in failed login attempts across many accounts (credential stuffing) or an influx of reports from users about account takeovers on unrelated services are classic red flags. These events suggest that the attacker is leveraging stolen hashes to gain unauthorized access elsewhere, making these observations critical for triggering incident response procedures for a potential database breach.
Exam trap
Candidates often look for direct evidence of database access (like SQL logs). However, in many scenarios, the first indication of a database compromise is the downstream impact, such as credential stuffing.
An incident handler is analyzing a severe Cross-Site Scripting (XSS) incident where malicious JavaScript stole administrator session cookies. Which TWO of the following defensive configurations and practices effectively mitigate session theft risks via XSS?
Select 2 answers
A.Set the HttpOnly flag on all sensitive authentication and session cookies.
B.Require strict TLS 1.3 encryption for all incoming and outgoing web traffic sessions.
D.Store user session tokens inside local storage rather than standard browser cookies.
E.Encode all dynamic output using generic HTML entity encoding routines on the server side.
AnswersA, C
Enabling the HttpOnly attribute instructs browsers to restrict cookie access exclusively to the HTTP protocol. Consequently, malicious JavaScript running inside an exploited browser session cannot read or exfiltrate the session identifier via document.cookie properties during an XSS attack.
Why this answer
Applying the HttpOnly flag prevents client-side scripts from accessing sensitive cookies via document.cookie, stopping direct session hijacking even if XSS exists. Combining this with a strong Content Security Policy restricts where scripts load and execute, providing defense-in-depth against malicious script injection attempts.
Exam trap
Many test-takers select encryption mechanisms or HTTPS enforcement thinking they protect session cookies from XSS, forgetting that encryption only secures data in transit.
An incident response team wants its LLM assistant to triage endpoint telemetry and recommend containment actions, but leadership is concerned that a manipulated model could recommend disabling critical production services. Which design choice best mitigates that concern?
A.Configure the model to output recommendations only, with all containment actions requiring explicit analyst authorization through the existing ticketing workflow.
B.Grant the model direct containment authority but require it to log every action to the SIEM after execution.
C.Fine-tune the model on historical containment decisions so it learns to avoid disabling services that are critical.
D.Allow the model to invoke containment APIs directly but limit it to disabling services that are not tagged as critical.
AnswerA
Restricting the model to advisory output means no containment action occurs without an analyst deliberately authorizing it, so a manipulated recommendation cannot disable production services on its own. Routing approvals through the existing ticketing workflow preserves accountability and gives responders context to judge each suggestion. This design directly addresses leadership's concern by ensuring the model never holds execution authority over critical systems.
Why this answer
The strongest mitigation is to keep the model in an advisory role, where every containment action requires explicit analyst authorization through an established workflow. This removes the model's ability to disable production services regardless of manipulation, and the ticketing process preserves human judgment and accountability. Direct execution with tag limits, post-hoc logging, or fine-tuning all leave an execution path or rely on controls that cannot guarantee protection of critical services.
Exam trap
The trap here is accepting logging, tagging, or fine-tuning as safeguards when the model still retains the authority to execute containment actions directly.
A GCIH analyst is reviewing web server logs and sees repeated requests to /search?q=... where the q parameter contains strings like ../../../etc/passwd and ....//....//etc/shadow. The responses include root:x:0:0 entries. The application is a Java servlet that concatenates a user-supplied filename onto a base directory before calling new File(baseDir + userInput). Which vulnerability class best describes this incident?
A.XML External Entity (XXE) injection
B.Local File Inclusion (LFI)
C.Server-Side Request Forgery (SSRF)
D.Path Traversal
AnswerD
The attacker is using ../ sequences to escape the intended base directory and read files outside it, which is classic Path Traversal. The Java code concatenates user input directly onto a base path without canonicalization or a whitelist, so the servlet opens /etc/passwd instead of a permitted file. The presence of root:x:0:0 in responses confirms successful traversal, making Path Traversal the accurate classification.
Why this answer
The attacker manipulates a filename parameter to escape the intended directory using ../ sequences and reads /etc/passwd, which is the defining behavior of Path Traversal. The vulnerable Java code concatenates user input onto a base path without canonicalization or validation, allowing the traversal. SSRF, LFI, and XXE each involve different mechanisms and would not produce this specific log pattern.
Exam trap
The trap here is confusing Path Traversal with Local File Inclusion, when the servlet directly reads a file rather than including it as executable code.
Which of the following describes the core difference between Path Traversal and IDOR?
A.Path Traversal is an OS-level vulnerability, while IDOR is an application-level flaw
B.IDOR is only applicable to RESTful APIs
C.Path Traversal is only possible on Windows systems
D.IDOR is a subtype of Path Traversal
AnswerA
Path traversal directly affects the server's file system, making it an OS-level concern. IDOR is a logic flaw within the application's authorization implementation, where the application fails to distinguish between users when accessing data objects in its database. This structural difference dictates how each must be tested and remediated.
Why this answer
Path Traversal targets the file system by manipulating paths to access arbitrary files, whereas IDOR targets application data by manipulating identifiers to access unauthorized database objects. While both involve parameter tampering, they operate at different layers: Path Traversal interacts with the underlying OS file structure, while IDOR interacts with the application's data model. Understanding this distinction is key to selecting the appropriate remediation strategy for each specific vulnerability.
Exam trap
Candidates often confuse the operating system layer of file paths with the database application layer of object identifiers, assuming both vulnerabilities operate identically.
During an incident response engagement on a Linux server, you discover an attacker has established covert command and control using a custom backdoor communicating over raw ICMP sockets. Which network analysis method provides the most reliable detection mechanism for this specific covert channel regardless of packet payload obfuscation?
A.Scanning all active network interfaces for unauthorized listening TCP ports bound to high-numbered ports.
B.Analyzing ICMP packet frequency, inter-arrival timing anomalies, and payload size distributions across network flows.
C.Reviewing traditional stateful firewall drop logs for blocked SYN packets originating from internal server zones.
D.Inspecting standard application layer web server access logs for anomalous HTTP POST request parameter values.
AnswerB
Raw ICMP tunnelling hides commands inside payloads, so signature or content inspection fails once obfuscated. Statistical analysis of packet frequency, inter-arrival timing and payload size distributions exposes the anomalous traffic pattern inherent to the covert channel, regardless of payload encoding.
Why this answer
Monitoring packet frequency and timing anomalies identifies ICMP tunneling because legitimate diagnostic tools like ping operate at steady, predictable intervals. Attackers forcing high-volume data transmissions create irregular burst patterns and anomalous payload sizes that standard baseline monitoring quickly highlights as suspicious behavior.
Effective incident handlers must look beyond simple signature detection when analyzing sophisticated tunneling techniques. Understanding foundational network protocols allows analysts to spot statistical deviations even when cryptographic encryption completely obscures the underlying application layer payload contents.
Exam trap
Candidates often assume that deep packet inspection or payload signatures are required to detect ICMP covert channels, completely overlooking statistical traffic profiling and timing anomaly detection methods.
A SOC analyst triages an alert showing that a mobile banking API responded to a request for /api/accounts/8842/transactions with HTTP 200 and another customer's transaction list. The requesting user was authenticated normally with a valid session token, but the account number in the URL belonged to a different customer. The API returned data without checking whether the authenticated user owned that account. Which vulnerability does this represent?
A.Broken object level authorization on the account resource
B.Cross-site request forgery against the transactions endpoint
C.Server-side request forgery through the account identifier parameter
D.Insecure direct object reference in the session token generation
AnswerA
The API authenticated the caller but never verified that the caller owned account 8842 before returning its transactions, which is the defining characteristic of broken object level authorization. Access control must be enforced per object on every request using the authenticated identity, not merely by requiring a valid session. This is why a legitimate user can read another customer's financial records simply by changing the identifier.
Why this answer
The caller was properly authenticated, but the API failed to confirm that the authenticated identity owned the account referenced in the URL. Authorization must be evaluated per object on every request, comparing the resource's owner against the caller's identity. Relying on a valid session alone creates exactly this exposure, where changing an identifier yields another customer's data.
Exam trap
The trap here is treating a valid authenticated session as sufficient authorization, when the missing ownership check on the object is the actual flaw.
Refer to the exhibit. If an attacker successfully injects <script>alert(1)</script> into a page, what happens?
A.The script executes successfully.
B.The browser blocks the script and logs a violation.
C.The browser executes the script only if the user is an admin.
D.The browser automatically strips the script tags.
AnswerB
The policy strictly restricts scripts to the origin and a specific CDN. Inline scripts are not allowed by the policy, so the browser identifies the violation, stops the script from running, and sends a report to the configured CSP reporting endpoint. This protects users from the malicious script execution.
Why this answer
The CSP policy explicitly permits only scripts from the application's own origin ('self') and from the trusted CDN. Because the injected inline script does not match these sources, the browser will block its execution. This is a crucial security control because it forces the developer to rely on external files, rendering traditional inline XSS payloads useless.
It effectively mitigates the risk by ensuring only scripts from trusted, verified locations can run.
Exam trap
Candidates often assume the script executes because they focus on the injection attempt itself rather than the active CSP policy that explicitly prevents such execution in the browser.
An incident handler is using a locally hosted LLM to summarize a 200-page intrusion report and extract indicators of compromise for a threat intel feed. The model returns a concise summary but omits several IP addresses present in the source document. What is the most likely explanation for this behavior?
A.The IP addresses were encrypted in the source document and the model cannot decrypt them.
B.The model's context window is too small to process the entire document in a single prompt, causing content truncation.
C.The LLM is deliberately suppressing IP addresses as part of a safety alignment policy.
D.The model is hallucinating the summary and never actually read the document.
AnswerB
When a document exceeds the model's context window, the input is truncated, and content beyond the limit is never processed, so indicators in later sections are silently dropped. A 200-page report easily exceeds typical context limits. Chunking the document or using a retrieval pipeline ensures all content is seen before summarization.
Why this answer
A 200-page report almost certainly exceeds the model's context window, so the input is truncated before inference and content beyond the limit is never seen. The result is a faithful but incomplete summary missing indicators from later sections. Chunking, retrieval-augmented approaches, or a model with a larger context window resolves the issue.
Safety alignment, encryption, and hallucination do not match the observed accurate-but-incomplete behavior.
Exam trap
The trap here is attributing missing content to hallucination or safety filters when the simpler and more likely cause is silent truncation at the context window boundary.
During a malware investigation, you discover that the adversary is using an AI model to generate domain names for its command-and-control (C2) infrastructure. The domains appear legitimate and are registered in bulk. Your AI-assisted threat hunting platform uses domain generation algorithm (DGA) detection but is missing these domains. Which of the following is the MOST likely reason for the detection failure?
A.The DGA detection model was trained on older DGA families and cannot recognize AI-generated patterns.
B.The AI model generates domains that are too short to be analyzed by the DGA detection.
C.The C2 traffic is encrypted, preventing the DGA detection from analyzing the domain names.
D.The domains are registered with legitimate registrars, so they are automatically whitelisted.
AnswerA
AI-generated domains may follow different statistical patterns than traditional DGAs. If the detection model was trained primarily on known DGA families, it may not generalize to novel AI-generated domains. This is a common limitation of machine learning models when faced with evolving threats, requiring retraining with new data.
Why this answer
AI-generated domains may not match the patterns learned by a DGA detection model trained on traditional algorithms. The model's inability to recognize novel AI-generated patterns is the most likely cause. Other factors like registration, encryption, or length are less relevant to DGA detection.
Exam trap
The trap here is assuming that DGA detection can automatically adapt to AI-generated domains, when in fact it requires retraining on new data to recognize evolving patterns.
An incident handler is analyzing a web application that uses a NoSQL database. The application constructs queries by directly embedding user input into JSON objects. An attacker submits a payload that includes `$ne` and `$gt` operators to bypass authentication. Which TWO of the following statements accurately describe this attack or its mitigation? (Choose two.)
Select 2 answers
A.The attack is only possible if the application uses MongoDB; other NoSQL databases are immune.
B.The attack is a NoSQL injection that exploits the lack of input sanitization in query operators.
C.The attack can be mitigated by enabling strict mode in the NoSQL database, which blocks all operator usage.
D.The attack is a form of SQL injection because NoSQL databases use SQL-like syntax.
E.The attack can be prevented by using parameterized queries or an ORM that safely handles user input.
AnswersB, E
NoSQL injection occurs when user input is not properly sanitized before being included in a NoSQL query. Operators like `$ne` (not equal) and `$gt` (greater than) can alter query logic. For example, injecting `{"$ne": null}` into a password field can bypass authentication by matching any non-null value. This statement correctly identifies the attack type and its root cause.
Why this answer
NoSQL injection exploits unsanitized input that is interpreted as query operators, allowing authentication bypass or data manipulation. Effective mitigation includes using parameterized queries or ORMs, and sanitizing input to remove special operators. Incident handlers should review application code for direct concatenation of user input into NoSQL queries and check database logs for unusual operator usage.
Exam trap
The trap here is assuming NoSQL databases are immune to injection because they do not use SQL, when in fact they have their own injection vectors via query operators.
A security analyst is reviewing password hashes extracted from an older Linux system. The hashes are stored in /etc/shadow and begin with the prefix $1$. The analyst wants to determine the hashing algorithm used so they can choose the correct cracking mode. Which algorithm is indicated by the $1$ prefix?
A.SHA-512 crypt
B.SHA-256 crypt
C.bcrypt
D.MD5 crypt
AnswerD
In Linux shadow files, the $1$ prefix denotes MD5 crypt, a legacy hashing scheme that is fast and therefore weak against modern cracking. Recognizing this prefix is important because it tells the analyst to select the corresponding mode in cracking tools and to recommend migration to a stronger algorithm such as yescrypt or SHA-512 crypt.
Why this answer
Linux shadow file prefixes identify the hashing algorithm: $1$ is MD5 crypt, $5$ is SHA-256 crypt, $6$ is SHA-512 crypt, and $2a$/$2b$/$2y$ is bcrypt. MD5 crypt is a legacy scheme that is fast to compute and therefore easily cracked with modern hardware. Analysts should recognize these prefixes to select the correct cracking mode and to advise upgrading to stronger algorithms.
Exam trap
The trap here is assuming that any dollar-sign prefix indicates a strong modern hash, when the low $1$ value actually signals the weak legacy MD5 crypt scheme.
When performing a password audit, you identify the use of 'PBKDF2-HMAC-SHA256' for credential storage. What makes this a strong choice compared to basic salted hashes, and how does it specifically hinder offline attacks?
A.It uses hardware-specific instructions to prevent GPU cracking
B.It stretches the password, making individual guesses slow
C.It encrypts the hash so it cannot be decrypted
D.It requires a secret key that is stored on a HSM
AnswerB
Key stretching algorithms like PBKDF2 force the hashing operation to run thousands of times. This dramatically increases the computational cost of testing a single password candidate, which slows down offline cracking attacks by orders of magnitude compared to un-stretched hash functions.
Why this answer
PBKDF2 (Password-Based Key Derivation Function 2) is a key stretching algorithm that applies a pseudorandom function repeatedly to the input password and salt. This 'stretching' makes the process intentionally slow. By increasing the iteration count, defenders force the attacker to expend significantly more CPU time for each guess, making brute-force or dictionary attacks prohibitively slow compared to standard hashing methods.
Exam trap
Candidates often confuse key stretching with simple encryption or salting. They fail to identify that the primary purpose is specifically increasing the computational cost to make brute-force attacks slower.
When auditing an application for Insecure Direct Object References, why is it recommended to perform tests using two distinct user accounts?
A.To verify if the server is load balanced
B.To ensure that session cookies are not reused
C.To confirm that the application does not validate object ownership
D.To test the strength of the password hashing
AnswerC
By logging in as User A and attempting to access an object owned by User B, the auditor confirms if the application performs authorization checks. If the request succeeds, it proves the system only validates the session, not the ownership of the referenced object, confirming the IDOR flaw.
Why this answer
Testing with two accounts allows the auditor to verify if User A can access User B's resources using the same identifiers. This 'cross-account' test is the gold standard for confirming an IDOR vulnerability. It isolates the logic flaw by demonstrating that the application fails to validate ownership, proving that access control is tied only to authentication rather than granular authorization, which is a critical finding for secure development.
Exam trap
Candidates frequently assume testing requires guessing complex passwords or bypassing authentication mechanisms entirely, missing the specific utility of multi-account cross-referencing.
An analyst uses an AI assistant to summarize a malware report and generate response steps. Before executing any recommended commands on production systems, what is the most important action?
A.Ask the AI to confirm that its own recommendations are correct.
B.Execute the commands immediately to contain the threat before it spreads.
C.Save the AI output as the official incident record without modification.
D.Verify the commands against authoritative documentation and test them in a non-production environment.
AnswerD
AI assistants can produce plausible but incorrect commands or outdated syntax. Verifying against authoritative vendor documentation and testing in a lab or non-production system prevents accidental disruption of production services. This validation step is essential before executing any AI-recommended action, especially commands that modify system state or delete data.
Why this answer
AI-generated response steps must be treated as suggestions, not instructions. Verifying commands against authoritative documentation and testing them in a non-production environment prevents accidental outages and data loss. This practice preserves production stability and evidence integrity while still allowing the analyst to benefit from AI-assisted summarization and drafting.
Exam trap
The trap here is trusting AI-generated commands as authoritative and executing them on production systems without independent verification.
What is the primary risk associated with using 'aggressive' scan timing templates (like T4 or T5) in an environment with high network latency?
A.The scan will consume excessive bandwidth.
B.The scan will yield inaccurate results due to premature timeouts.
C.The scan will trigger an automated shutdown of the network.
D.The scan will crash the Nmap engine.
AnswerB
High-latency networks require longer wait times for packet responses. Aggressive timing templates use very short timeouts, meaning probes are marked as 'filtered' before a reply can return. This results in an inaccurate scan that reports services as unavailable when they are actually operational, which is a major failure for any assessment.
Why this answer
Aggressive timing templates rely on short timeouts, expecting quick responses from targets. In high-latency networks, these short timeouts lead to false negatives, where Nmap incorrectly labels a port as 'filtered' simply because the response did not arrive before the aggressive timer expired. This leads to inaccurate mapping and missed vulnerabilities, directly undermining the goals of the incident investigation.
Exam trap
Candidates assume aggressive timing templates are always better because they finish faster, ignoring how high latency causes premature timeouts and false negatives.
Which of the following is a classic example of an 'adversarial' attack against an AI-powered detection engine?
A.A distributed denial-of-service attack against the AI server.
B.Adding 'dead' code blocks to hide the malicious payload's intent.
C.Applying minimal, non-functional perturbations to code to cause misclassification.
D.Using stolen credentials to access the AI administration console.
AnswerC
This describes an adversarial perturbation. Attackers use these to exploit the mathematical weaknesses in the way AI models process features. Because the change is minimal and non-functional, the malware continues to behave normally while the AI model incorrectly tags it as legitimate, demonstrating the core mechanism of adversarial machine learning attacks.
Why this answer
Adversarial attacks aim to manipulate the input to an AI model to cause a misclassification. By adding carefully crafted, minimal noise—sometimes called an 'adversarial perturbation'—an attacker can make malicious code appear benign to the model. Recognizing these attacks is vital for incident handlers because it explains why an otherwise robust system might miss a clearly malicious payload that an analyst can easily see with the naked eye.
Exam trap
Students frequently confuse adversarial perturbations designed to evade AI classifiers with traditional network-layer evasion techniques or classic application vulnerabilities like SQL injection.
Which of the following best describes the purpose of 'flow data' (like NetFlow) during an incident investigation?
A.To capture the full payload content of every packet.
B.To provide a record of who accessed which specific file.
C.To analyze the volume, source, and destination of network traffic.
D.To perform real-time decryption of SSL/TLS traffic.
AnswerC
Flow data is specifically designed to provide summary information about network traffic. This includes the source IP, destination IP, ports, protocol, and the volume of data transferred, which is essential for identifying anomalous communication patterns during a post-incident forensic investigation.
Why this answer
Flow data provides a high-level summary of network communications, including source, destination, ports, and duration. Unlike full packet capture, which is resource-intensive, flow data is lightweight and allows for long-term retention. It is invaluable for reconstructing an attacker's movement across the network and identifying patterns of communication, such as beaconing to C2 servers, even when specific payload contents are not available.
Exam trap
Candidates often confuse flow data with full packet capture (FPC). They incorrectly assume flow data contains the actual payload contents of packets, which it does not; it only provides metadata summary information.
What is the primary function of the 'Token Manipulation' technique in Windows pivoting?
A.To hide files in a hidden directory.
B.To bypass user authentication prompts.
C.To impersonate another user's security context.
D.To encrypt the memory of a running process.
AnswerC
Impersonation is the core goal of token manipulation. By taking the security token of a higher-privileged process, the attacker can execute commands with those elevated permissions. This is a common and powerful technique used during lateral movement to gain control over critical system components and administrative resources.
Why this answer
Token manipulation involves stealing an access token from a process running as a different user (e.g., SYSTEM or an Administrator) and using it to spawn a new process. This allows the attacker to elevate their privileges or move laterally as a different user. Understanding this technique is vital for incident handlers because it explains how attackers maintain high-level access without knowing user passwords.
Exam trap
Candidates confuse token manipulation with password dumping. They assume the attacker must crack a password to impersonate a user, rather than realizing the token already exists in memory for legitimate use.
An attacker discovers an API endpoint /api/v1/user/details?id=123 that returns JSON data. They modify the parameter to /api/v1/user/details?id=124. This vulnerability indicates a failure in which security control?
A.Broken Authentication
B.Insecure Direct Object Reference
C.Cross-Site Scripting
D.Insufficient Logging and Monitoring
AnswerB
IDOR occurs when an application provides direct access to objects based on user-supplied input. By manipulating the ID parameter, the attacker accesses unauthorized data records. APIs are particularly susceptible to this when they rely on sequential IDs for object retrieval without verifying user permissions.
Why this answer
This scenario describes Insecure Direct Object Reference (IDOR). The application fails to verify if the authenticated user has authorization to access the object associated with the ID parameter. In API security, this is a critical flaw because APIs often expose backend database keys directly.
Proper mitigation requires server-side access control checks on every request, ensuring the requester owns the resource before returning sensitive data.
Exam trap
Candidates sometimes misidentify this as a broken authentication issue or API parameter tampering, missing that direct reference to database keys via predictable parameters defines IDOR.
An incident responder is investigating a suspected SMB relay attack on a corporate network. The attacker has compromised a workstation and is attempting to relay authentication to a domain controller. Which TWO of the following conditions are necessary for a successful SMB relay attack? (Choose two.)
Select 2 answers
A.SMB signing must be disabled or not required on the target server.
B.The target server must be running SMB 1.0.
C.The attacker must have valid domain credentials for the target server.
D.The attacker must have physical access to the victim's workstation.
E.The victim's NTLM authentication must be relayed to a server that accepts NTLM authentication.
AnswersA, E
SMB signing ensures the integrity and authenticity of SMB communications. If signing is disabled or not required, an attacker can modify and relay authentication messages without detection. This is a critical condition for SMB relay, as signing would prevent the relay by invalidating the tampered authentication.
Why this answer
The correct answers are that SMB signing must be disabled or not required on the target server, and the victim's NTLM authentication must be relayed to a server that accepts NTLM. These conditions allow the attacker to forward authentication without detection. The other options are not necessary: valid credentials are not needed, physical access is not required, and SMB 1.0 is not a prerequisite.
Exam trap
The trap here is thinking that SMB relay requires the attacker to have credentials; in reality, the attacker relays the victim's authentication, so no credentials are needed.
A compromised Windows 10 workstation has an active Meterpreter session. The responder observes that the attacker used the `portfwd` command to redirect traffic from the victim's TCP port 8080 to an internal HR server's TCP port 3389. The internal HR server is not directly reachable from the responder's analysis host. Which mechanism is the attacker leveraging to pivot into the HR server?
A.A reverse TCP shell bound to the HR server's port 3389.
B.An SSH tunnel using the compromised workstation as a jump host.
C.A TCP relay created by the Meterpreter `portfwd` command.
D.A SOCKS proxy established via the Meterpreter `socks` command.
AnswerC
The `portfwd` command in Meterpreter creates a TCP relay that listens on a specified port on the compromised host and forwards all incoming connections to a target IP and port. Here, it listens on TCP 8080 on the victim and relays to the HR server's TCP 3389, effectively pivoting into the internal network segment.
Why this answer
The `portfwd` command in Meterpreter creates a TCP relay on the compromised host, forwarding traffic from a local port to a specified remote address and port. This allows the attacker to reach internal services that are not directly accessible from their own machine, effectively using the victim as a pivot point. The other options describe different pivoting techniques that do not match the observed command.
Exam trap
The trap here is confusing port forwarding with a reverse shell or SOCKS proxy, which serve different purposes and require different configurations.
An incident responder is investigating a Windows endpoint where an attacker used the Windows Management Instrumentation (WMI) event subscription mechanism to establish persistence. The responder wants to identify the specific WMI components created by the attacker. Which two of the following WMI artifacts should the responder examine to find the malicious event subscription? (Choose two.)
Select 2 answers
A.__EventFilter instances in the root\subscription namespace
B.__EventConsumer instances in the root\subscription namespace
C.Win32_Service instances in the root\cimv2 namespace
D.MSFT_ScheduledTask instances in the root\Microsoft\Windows\TaskScheduler namespace
E.Win32_StartupCommand instances in the root\cimv2 namespace
AnswersA, B
__EventFilter instances define the events that trigger a WMI event subscription. In a malicious persistence setup, the attacker creates an event filter to specify a trigger, such as a system uptime or user logon. Examining the root\subscription namespace for __EventFilter instances will reveal the filter name, query, and other details, which can be used to identify the malicious subscription and its trigger condition.
Why this answer
WMI event subscription persistence consists of three components: __EventFilter, __EventConsumer, and __FilterToConsumerBinding. The filter defines the trigger, and the consumer defines the action. Examining __EventFilter and __EventConsumer instances in the root\subscription namespace will reveal the malicious subscription's details, including the trigger query and the payload executed.
The other options represent different persistence mechanisms.
Exam trap
The trap here is assuming that any WMI class related to system configuration will reveal the subscription, when in fact only the __EventFilter, __EventConsumer, and binding classes in the root\subscription namespace are relevant.
A GCIH analyst is investigating a web application that uses Java deserialization to process user-supplied session objects. The analyst suspects an attacker exploited an insecure deserialization vulnerability to achieve remote code execution. Which two indicators are most likely to confirm this type of attack? (Choose two.)
Select 2 answers
A.HTTP requests containing serialized Java objects with the magic bytes AC ED 00 05 in the body.
B.The presence of a new administrator account created in the application's user database.
D.Unexpected outbound network connections from the application server to an external IP address shortly after a suspicious request.
E.A sudden increase in the number of 404 errors for static image files.
AnswersA, D
Java serialization streams begin with the magic bytes AC ED 00 05. Their presence in HTTP request bodies indicates that the application is accepting serialized Java objects from the client. When combined with other suspicious behavior, this is a strong indicator of an insecure deserialization attack attempt, as attackers must deliver a serialized payload to the vulnerable endpoint.
Why this answer
Insecure deserialization attacks require delivering a serialized payload, which for Java begins with the AC ED 00 05 magic bytes. Successful exploitation often results in remote code execution, frequently followed by outbound connections for command-and-control or exfiltration. These two indicators together confirm both the delivery and the impact, whereas the other options are either unrelated or nonspecific.
Exam trap
The trap here is selecting generic compromise indicators like a new admin account, which can result from many attacks and do not specifically confirm deserialization exploitation.
A penetration tester discovers that a web application uses a predictable numeric parameter `user_id` in the URL to retrieve user profiles. While authenticated as user 1001, the tester changes the parameter to 1002 and successfully views another user's profile. The application does not perform any additional authorization checks beyond verifying the session. Which of the following best describes the vulnerability and its immediate impact?
A.Vertical privilege escalation due to missing role-based access control
B.SQL injection because the user_id parameter is likely used in a database query
D.Insecure Direct Object Reference (IDOR) allowing horizontal privilege escalation
AnswerD
Changing `user_id` from 1001 to 1002 accesses another user's profile at the same privilege level, which is horizontal privilege escalation. The application fails to verify that the authenticated user owns the requested object, which is the definition of IDOR. This is the correct characterization because the attacker is not elevating to an admin role but accessing peer data.
Why this answer
The application trusts the client-supplied `user_id` without verifying that the authenticated user is authorized to access that object. By changing the identifier to another user's ID, the attacker accesses data belonging to a peer, which is horizontal privilege escalation. This is a classic IDOR because the reference to the object is direct and predictable, and the application lacks an access control check on the object level.
Exam trap
The trap here is assuming that because the parameter is numeric and predictable, the vulnerability must be SQL injection, when the real issue is missing object-level authorization.
An analyst is reviewing logs and finds multiple failed logins followed by a single successful login from a different IP address, which then executes 'whoami' and 'net user'. What is the most likely scenario?
A.A user struggling to remember their password.
B.Credential stuffing followed by automated reconnaissance.
The combination of multiple failed logins and immediate post-exploitation commands is a high-confidence indicator of account compromise. The attacker is mapping the environment to plan further movement. Detecting this progression allows the responder to isolate the compromised account before the adversary can escalate privileges or deploy additional malicious tools.
Why this answer
This sequence is a classic indicator of credential stuffing or password spraying followed by immediate reconnaissance. The shift from multiple failures (guessing) to a successful login (success) and then immediate discovery commands (post-exploitation) strongly suggests a compromised account being used by an adversary. This pattern is vital to detect early in the kill chain before the attacker moves laterally or achieves persistence within the network environment.
Exam trap
Candidates frequently misidentify the event as a simple brute force attack, missing the critical transition from authentication failures to immediate post-exploitation commands, which characterizes a successful account takeover.
A GCIH analyst is examining a web application that uses GraphQL. The analyst notices that an attacker sent a deeply nested query that caused the server to consume excessive resources, leading to a denial of service. Which GraphQL-specific vulnerability is being exploited?
A.GraphQL query depth attack
B.GraphQL alias overloading
C.GraphQL batching attack
D.GraphQL introspection abuse
AnswerA
GraphQL allows clients to request nested fields, and without depth limiting, an attacker can craft a query with many levels of nesting. This can cause exponential resource consumption as the server resolves each level, leading to denial of service. This is known as a query depth attack.
Why this answer
GraphQL's flexible query language allows clients to specify nested fields. Without proper limits, an attacker can send a query with excessive depth, causing the server to recursively resolve many levels and exhaust CPU or memory. This is a query depth attack, a common GraphQL-specific denial-of-service vector.
Exam trap
The trap here is assuming that any resource exhaustion in GraphQL is due to batching or aliases, when the specific indicator—deep nesting—points to a query depth attack.
An attacker is using WMI (Windows Management Instrumentation) to move laterally. Which WMI class and method combination is frequently abused for remote process execution?
A.Win32_Service, StartService
B.Win32_Process, Create
C.Win32_StartupCommand, Create
D.Win32_ScheduledJob, Create
AnswerB
The Win32_Process Create method is a standard technique used by attackers to execute commands on remote systems via WMI. It is favored because it does not require a persistent installation, allowing for stealthy lateral movement that is easily integrated into automated post-exploitation scripts and tools.
Why this answer
The Win32_Process class, specifically the Create method, allows for the execution of arbitrary commands on remote systems. Incident responders often look for WMI-based process creation events in logs to detect lateral movement. Because WMI is a legitimate administrative tool, distinguishing between normal management traffic and malicious movement is a key challenge for detection and response teams.
Exam trap
Candidates often guess generic WMI classes like 'Win32_Service' because they associate WMI with persistence. They overlook that 'Win32_Process' is the specific class required for direct, remote command execution.
An incident handler is triaging a suspected beaconing implant on a Windows workstation. NetFlow records show a repeating outbound connection to the same external IP address every 60 seconds, but the packets are only 200 bytes each, so no payload is captured. The handler wants to confirm the beacon's timing jitter and any command-and-control content without deploying a new agent to the endpoint. Which investigative approach BEST accomplishes this?
A.Export the NetFlow records to a collector and generate a histogram of flow start times to measure the beacon interval precisely.
B.Pull Windows Security event logs for logon type 3 events and correlate their timestamps with the observed outbound connections.
C.Enable full packet capture on the perimeter sensor and filter the traffic by the destination IP address, then analyze inter-arrival times and payload content.
D.Run a port scan against the external IP address from the workstation to identify the listening service and infer the implant family.
AnswerC
Full packet capture at the perimeter preserves both the timing of each connection and the payload bytes, allowing the handler to calculate beacon jitter and inspect command-and-control content. Filtering by the known destination IP keeps the capture volume manageable. Because no endpoint agent is installed, this satisfies the requirement without touching the host.
Why this answer
Perimeter full packet capture retains both timing and payload, which are exactly the two data points needed to characterize the beacon. Flow records and host logs provide timing or authentication context but never the command-and-control content. Scanning the adversary infrastructure is intrusive and yields no information about the local implant's behavior, so it does not meet the investigative requirement.
Exam trap
The trap here is assuming that flow records contain enough detail to characterize beaconing, when they actually omit payload and sub-second precision.
An incident handler is analyzing a packet capture and notices a high volume of TCP SYN packets sent to multiple ports on a single target host, with no corresponding SYN-ACK responses. The source IP is spoofed. What type of activity does this indicate?
A.Port scanning
B.ARP spoofing
C.UDP fragmentation attack
D.TCP SYN flood
AnswerD
A TCP SYN flood is a denial-of-service attack where the attacker sends numerous SYN packets, often with spoofed source IPs, to exhaust the target's connection table. The lack of SYN-ACK responses is typical because the target is either overwhelmed or the spoofed IPs do not complete the handshake. This matches the scenario exactly.
Why this answer
The combination of numerous TCP SYN packets, spoofed source IP, and absence of SYN-ACK responses is a hallmark of a SYN flood attack. This type of denial-of-service attempts to exhaust the target's resources by leaving half-open connections. Recognizing this pattern helps responders mitigate by enabling SYN cookies or rate limiting.
Exam trap
The trap here is confusing a SYN flood with a port scan; both use SYN packets, but a flood uses spoofed IPs and no responses, while a scan seeks responses to map services.
When evaluating potential SQL injection in an application, what is the most significant indicator that an application is vulnerable?
A.The application uses a relational database management system.
B.User input is directly concatenated into a query string.
C.The database contains sensitive user data.
D.The application is written in an interpreted language.
AnswerB
String concatenation allows attackers to inject SQL syntax directly into the final command sent to the database. By using quotes and operators, an attacker can escape the data field and alter the query logic. This is the root cause of most SQL injection vulnerabilities in legacy and poorly written applications.
Why this answer
The most definitive indicator is the presence of dynamic SQL construction using unsanitized user input. When developers concatenate strings to build queries, the database cannot distinguish between data and command intent. Identifying code patterns where user parameters are directly appended to a SQL string is a critical step in security assessments.
This practice allows attackers to manipulate the query structure, leading to unauthorized data exposure, bypasses, or administrative actions within the database management system.
Exam trap
Candidates often look for 'lack of error handling' or 'verbose logs'. These are indicators of existing vulnerabilities, but direct string concatenation is the actual root cause of SQL injection.
Which of the following describes the 'Confused Deputy' problem in the context of cloud IAM roles?
A.A user is assigned two different roles with conflicting permissions.
B.A malicious user triggers a service to use its privileges against a resource.
C.Two cloud administrators inadvertently delete each other's work.
D.A service fails to refresh its temporary tokens, causing a lockout.
AnswerB
This occurs when an attacker convinces a service that has sufficient permissions to act on their behalf. Without checks like External IDs, the service might unknowingly perform actions, such as reading private data, because it trusts the requester. This is a major security concern in multi-tenant cloud environments.
Why this answer
The Confused Deputy problem occurs when a privileged service is coerced into performing an action on behalf of a user who lacks the permissions to perform that action directly. By utilizing 'External IDs' or 'Condition keys' like 'aws:SourceArn', developers can prevent this by ensuring that the service only assumes the role when the request originates from an authorized context, preventing unauthorized cross-account access and privilege escalation.
Exam trap
Candidates often confuse the Confused Deputy problem with simple privilege escalation or credential theft. They fail to recognize the specific nuance where a legitimate service is coerced into misusing its own authority.
A penetration tester is performing a password attack against an Active Directory environment. The tester has obtained a list of valid domain usernames and wants to identify accounts with weak passwords without locking out accounts. The domain account lockout policy is set to lock accounts after five failed attempts within 30 minutes. Which two of the following techniques would allow the tester to test passwords while minimizing the risk of account lockout? (Choose two.)
Select 2 answers
A.Using a pass-the-hash attack with captured NTLM hashes
B.Using a tool that performs a single authentication attempt per account per lockout window
C.Brute-forcing each account with a large dictionary until a valid password is found
D.Password spraying with a single common password against all accounts, waiting between attempts
E.Performing a credential stuffing attack using passwords from previous breaches
AnswersB, D
Limiting each account to one failed attempt per lockout window ensures the account never reaches the lockout threshold. Tools like Spray or custom scripts can enforce this by tracking attempts and waiting the requisite time. This approach allows the tester to test one password per account per window, gradually building a list of valid credentials without locking accounts.
Why this answer
Password spraying and single-attempt-per-window techniques are both designed to test passwords while staying under lockout thresholds. Spraying uses one password across many accounts, and single-attempt-per-window limits each account to one guess per lockout period. Both avoid triggering the five-failure lockout, unlike brute-forcing or credential stuffing, which can rapidly exceed the threshold.
Exam trap
The trap here is assuming that any password attack can be made lockout-safe with delays, when in fact only techniques that limit attempts per account per lockout window truly avoid lockouts.
An attacker uses living-off-the-land binaries (LotLbins) to execute a malicious PowerShell script. Which detection strategy best identifies this activity while minimizing false positives from administrative scripts?
A.Block all PowerShell execution via Group Policy Objects.
B.Flag any process execution involving native Windows binaries.
C.Monitor process lineage for common utilities launching suspicious child processes.
D.Implement static file hash signatures for all known LotLbins.
AnswerC
Analyzing parent-child relationships allows security teams to identify anomalies such as a web server process spawning cmd.exe or a utility like certutil.exe initiating an outbound connection. This behavioral pattern is a hallmark of post-exploitation activity, providing high-fidelity signals that distinguish administrative use cases from malicious abuse of trusted binaries.
Why this answer
Detecting LotLbins requires focusing on process lineage and behavioral context rather than just the binary name. By correlating parent-child process relationships—specifically looking for common utilities like certutil.exe or mshta.exe spawning suspicious network connections or child shells—defenders can distinguish malicious intent from standard management tasks. This approach is critical in modern environments where native tools are frequently abused to bypass static signature-based detection mechanisms used by legacy EDR solutions.
Exam trap
Candidates often suggest blacklisting specific binary names, which is ineffective against LotLbins because legitimate administrative tools will always be present in a production environment.
Why are GPUs highly effective at cracking password hashes compared to traditional CPUs?
A.GPUs have higher clock speeds than CPUs
B.GPUs perform massively parallel operations
C.GPUs access system RAM faster than CPUs
D.GPUs use a different instruction set than CPUs
AnswerB
The architecture of a GPU allows it to perform thousands of concurrent calculations. Because each hash attempt is independent of the others, this parallel architecture allows for immense throughput. This turns what would take years on a CPU into a task that takes hours or days on a GPU.
Why this answer
GPUs excel at parallel processing, containing thousands of small cores designed to perform simple mathematical operations simultaneously. Password hashing, particularly MD5 or SHA-1, involves repetitive, independent calculations, which is the perfect workload for a GPU. While a CPU might handle a few operations at once, a GPU can calculate millions of hashes per second.
This speed advantage drastically reduces the time required for brute-force attacks against databases using weak, unsalted, or fast hashing algorithms.
Exam trap
Candidates often assume GPUs are just 'faster CPUs'. The key distinction is that GPUs are designed for massive parallelization, allowing them to perform millions of simple hashing operations simultaneously.
An adversary is using reflective DLL injection to evade detection. Which TWO indicators would most reliably suggest this activity is occurring?
Select 2 answers
A.Presence of a new file with an unusual extension in the system directory.
B.Memory regions with Read/Write/Execute (RWX) permissions within a process.
C.Increased usage of CPU by background system services.
D.Loaded modules lacking a corresponding file path on the disk.
E.An increase in the number of network connections to unknown IPs.
AnswersB, D
Memory regions marked as RWX are highly unusual in normal applications. Attackers use these permissions to write their malicious code into memory and then execute it immediately. Detecting these memory segments is a primary indicator of injected code or shellcode running within the address space of a legitimate process.
Why this answer
Reflective DLL injection works by loading a library from memory rather than the disk, bypassing standard file-based monitoring. Detecting this requires looking for memory-related anomalies such as memory regions with suspicious permissions (e.g., Read/Write/Execute) and the absence of a corresponding file backer for loaded modules in a process. These indicators are crucial because traditional antivirus solutions scanning the disk will miss the payload entirely as it never touches the physical storage layer.
Exam trap
Candidates frequently select traditional indicators like disk-based executable signatures or standard network connection ports, ignoring memory-specific anomalies such as RWX regions and unbacked modules.
Which of the following is the primary risk associated with using unvetted AI models for malware signature generation?
A.The model will always generate signatures that are too complex to implement.
B.The model may produce signatures that trigger on benign system binaries.
C.The model will consume excessive processing power on the endpoint.
D.The model will force the malware to evolve into a polymorphic variant.
AnswerB
AI models trained on insufficient or biased data often fail to distinguish between malicious and legitimate system activity. This leads to the generation of false-positive signatures that flag critical OS files. Deploying such signatures in a production environment causes significant operational disruption, effectively creating a self-inflicted denial-of-service attack for the organization.
Why this answer
Using unvetted AI models for signature generation risks creating false signatures that could lead to widespread system instability or denial of service if deployed to endpoint protection platforms. In the context of malware investigation, these tools must be calibrated against known-good and known-bad datasets. Failing to vet the model results in a high false-positive rate, which ultimately undermines the efficacy of the incident response team and wastes valuable time during critical security incidents.
Exam trap
Candidates often identify 'AI model theft' or 'slow processing' as the primary risk, overlooking the operational disaster of a false-positive signature that disables critical business services and system binaries.
During an authorized incident response engagement, you need to determine whether a specific suspicious host at 10.20.30.40 is alive before launching a full port scan. You want a lightweight check that does not complete a TCP three-way handshake and works even when ICMP is blocked. Which Nmap command best accomplishes this initial liveness check?
A.nmap -sn 10.20.30.40
B.nmap -sS 10.20.30.40
C.nmap -Pn 10.20.30.40
D.nmap -O 10.20.30.40
AnswerA
The -sn flag performs a ping scan (host discovery) only, without port scanning. Nmap sends ICMP echo, TCP SYN to port 443, TCP ACK to port 80, and an ARP request on local networks. Because it uses multiple probe types, it can detect liveness even when ICMP is filtered, making it ideal for a quick, low-noise check.
Why this answer
The -sn ping scan performs host discovery without port scanning and uses multiple probe types, including TCP SYN to port 443 and TCP ACK to port 80, so it can identify live hosts even when ICMP is blocked. This makes it the correct lightweight liveness check before committing to a full port scan. The other options either skip discovery, perform a port scan, or perform OS fingerprinting, all of which are heavier or not designed for simple liveness detection.
Exam trap
The trap here is assuming that host discovery requires a full port scan, when Nmap's -sn flag performs liveness checks using multiple protocols without scanning any ports.
An incident handler is investigating a web application that allows users to upload profile pictures. The application stores uploaded files in a directory accessible via the web and uses the original filename without sanitization. An attacker uploads a file named `shell.php.jpg` containing PHP code. The server executes the file when accessed via its URL. Which vulnerability has been exploited?
A.Directory Traversal
B.Local File Inclusion (LFI)
C.Remote File Inclusion (RFI)
D.Unrestricted File Upload
AnswerD
The application fails to validate the file type and allows a file with a double extension to be stored and executed. The attacker bypasses a naive check for `.jpg` by including `.php` before it. This is a classic Unrestricted File Upload vulnerability, leading to remote code execution. Incident handlers should treat this as a critical finding and review upload validation logic.
Why this answer
The application allows an attacker to upload a file with a double extension and then executes it, resulting in remote code execution. This is an Unrestricted File Upload vulnerability. Mitigations include validating file types by content, not just extension, storing uploads outside the web root, and disabling script execution in upload directories.
Incident responders should inspect upload logs and file system for malicious files.
Exam trap
The trap here is focusing on the double extension as a bypass of a specific filter, when the root issue is the lack of proper file type validation and execution prevention.
A security analyst is investigating a suspected local file inclusion (LFI) attack against a PHP web application. The web server logs show the following request: `GET /download.php?file=php://filter/convert.base64-encode/resource=index.php`. The analyst needs to determine the attacker's objective and the potential impact. (Choose two.)
Select 2 answers
A.The attacker is attempting to read the source code of `index.php` by encoding it in Base64 to bypass PHP execution.
B.The attacker is attempting to retrieve the contents of a sensitive file, such as `/etc/passwd`, by including it directly.
C.The attacker is attempting to perform a cross-site request forgery (CSRF) attack against the web application.
D.The attacker is attempting to execute arbitrary commands on the server via the `file` parameter.
E.The attacker is exploiting a vulnerability that could lead to disclosure of application source code, potentially revealing database credentials.
AnswersA, E
The `php://filter` wrapper with `convert.base64-encode` is a known technique to read PHP source code. Normally, including a PHP file would execute it, but by Base64-encoding the output, the attacker can view the raw source, which may contain sensitive logic or credentials. This is a direct objective of the attack.
Why this answer
The payload uses the `php://filter` wrapper with Base64 encoding to read the source code of `index.php`. This technique bypasses PHP execution, allowing the attacker to view the raw code, which may contain sensitive information like database credentials. The other options misidentify the objective, such as command execution or CSRF, which are not supported by the specific payload.
Exam trap
The trap here is assuming that any file inclusion attack aims to read `/etc/passwd`, when the use of `php://filter` specifically targets PHP source code.
Refer to the exhibit. An AI-based EDR identifies a suspicious process chain. Based on the provided JSON output, what is the most appropriate next step for an incident handler?
A.Assume the alert is a false positive due to the common nature of svchost.
B.Immediately isolate the host from the network based on the 0.98 AI score.
C.Examine process memory and network artifacts to confirm malicious injection.
D.Restart the svchost service to terminate the suspicious connection.
AnswerC
Verification is mandatory. By analyzing the memory of the svchost instance and the network connection patterns, the responder confirms whether the process is indeed acting maliciously. This technical validation bridges the gap between an automated alert and actionable intelligence, allowing for a decisive and informed response to the identified threat.
Why this answer
The exhibit shows a clear anomaly where a parent-child relationship (PowerShell spawning svchost) is highly suspicious, especially when associated with an external connection. While the AI score is high, it is a heuristic indicator. The handler must verify this via manual inspection of the process memory and network artifacts to confirm if this is a legitimate system injection or a malicious beacon, ensuring that response actions are based on verified facts.
Exam trap
Candidates often rely purely on high-score AI heuristic alerts or automated verdicts, failing to perform the necessary manual verification of process memory and artifacts.
An analyst is investigating a suspected compromise on a Windows 10 endpoint. Network telemetry shows periodic outbound HTTPS traffic to a domain that resolves to a legitimate cloud CDN IP, but the SNI in the TLS ClientHello does not match the destination domain. The endpoint has no browser activity at those times. Which technique best explains this traffic pattern?
A.Domain fronting through a CDN to hide the true command-and-control destination
B.Fast flux DNS rotating A records to evade blocklists
C.DNS tunneling using TXT records to exfiltrate data
D.Beaconing over a covert channel using ICMP echo payloads
AnswerA
Domain fronting places a benign SNI in the TLS handshake while the HTTP Host header points to the attacker's fronted domain on the same CDN. The mismatch between SNI and the actual destination, combined with non-browser beaconing, is a strong indicator. This technique abuses CDN routing to blend C2 with legitimate traffic.
Why this answer
Domain fronting exploits CDN behavior where the TLS SNI and the HTTP Host header can differ, allowing traffic to appear destined for a benign domain while actually reaching attacker infrastructure. The combination of periodic non-browser HTTPS, a legitimate CDN IP, and an SNI that does not match the destination domain is characteristic. DNS tunneling, ICMP covert channels, and fast flux produce different network signatures and would not generate this specific mismatch.
Exam trap
The trap here is treating any traffic to a reputable CDN IP as inherently trustworthy rather than inspecting the SNI and Host header for inconsistencies.
Which of the following describes a 'credential stuffing' attack?
A.Exploiting a buffer overflow to bypass login
B.Using valid credentials from one site to access another
C.Brute-forcing a password using a dictionary file
D.Intercepting credentials via a phishing email
AnswerB
This is the definition of credential stuffing. Because users often reuse passwords, attackers leverage large databases of leaked username/password pairs to gain unauthorized access to accounts on other services, assuming that the credentials will be valid in multiple locations due to human password reuse habits.
Why this answer
Credential stuffing is an automated attack where threat actors use lists of compromised credentials from one breach to attempt logins on unrelated websites. It relies on the common human tendency to reuse passwords across multiple services. Understanding this is vital for incident handlers, as it explains why security alerts for one platform may indicate an account compromise elsewhere.
Mitigation requires enforcing unique passwords and using multi-factor authentication (MFA) to invalidate stolen password utility.
Exam trap
Candidates often confuse credential stuffing with brute-forcing. Brute-forcing guesses a password for one account; credential stuffing uses a list of known credentials to access many different accounts.
An incident responder investigates a web application breach where an attacker successfully extracted sensitive user data by appending UNION SELECT statements to a numeric product ID parameter. Which backend remediation approach directly eliminates this vulnerability class while preserving application functionality?
A.Implement client-side JavaScript regex validation to strip SQL keywords from input parameters before transmission.
B.Wrap all user inputs inside custom string-escaping functions designed to neutralize single quotes and semicolons.
C.Refactor database queries to use prepared statements with bound parameters via the application data access layer.
D.Deploy a traditional network firewall configured with signature rules to block incoming HTTP GET requests containing UNION.
AnswerC
Prepared statements separate code and data completely at the database driver level. When parameters are bound correctly, any user-supplied string like a UNION query is treated strictly as literal literal data values, neutralizing injection attempts and protecting backend data assets permanently.
Why this answer
Parameterized queries decouple user-supplied input from the SQL command structure, ensuring the database engine treats input exclusively as data rather than executable code. Implementing parameterized queries globally stops SQL injection by neutralizing untrusted input regardless of characters appended by attackers, making it the definitive defense for database interaction security in incident response hardening.
Exam trap
Candidates often confuse input sanitization or escaping with parameterized queries, assuming that stripping dangerous characters like quotes provides complete protection against advanced SQL injection variants.
An incident responder is analyzing a compromised Linux server. The responder notices that the file /etc/ld.so.preload contains the path /lib/libprocess.so, which is not a standard library. The responder suspects an attacker is using this for persistence and privilege escalation. Which post-exploitation technique is being employed?
A.Cron job persistence
B.Kernel module rootkit insertion
C.LD_PRELOAD environment variable hijacking
D.Dynamic linker preloading via /etc/ld.so.preload
AnswerD
The /etc/ld.so.preload file specifies shared libraries to be loaded by the dynamic linker before any others for all executables. Attackers can place a malicious library there to intercept function calls, log keystrokes, or escalate privileges. This is a stealthy persistence mechanism because it affects all dynamically linked programs and is not obvious in process lists.
Why this answer
The /etc/ld.so.preload file is used by the dynamic linker to load specified shared libraries before any others for all dynamically linked executables. An attacker can place a malicious library there to intercept function calls, escalate privileges, or maintain persistence. This technique is stealthy because it affects all programs and is not easily detected by process monitoring.
Exam trap
The trap here is confusing LD_PRELOAD environment variable hijacking with system-wide preloading via /etc/ld.so.preload; the latter is more persistent and affects all users and processes, not just those with the environment variable set.
A security analyst is reviewing logs from a Linux web server and notices that the 'last' command output shows a login by user 'root' from an IP address that is not part of the company's network. The login occurred at 03:00 AM, and the analyst also finds that the file /root/.ssh/authorized_keys was modified at the same time. Which post-exploitation technique has the attacker most likely used?
A.LD_PRELOAD hijacking
B.Cron job persistence
C.SSH key persistence
D.Kernel module rootkit
AnswerC
Modifying /root/.ssh/authorized_keys to add an attacker-controlled public key allows passwordless SSH access. The suspicious root login from an external IP at an unusual time, combined with the file modification, strongly indicates that the attacker added a key for persistence. This is a common technique to maintain access even if passwords are changed.
Why this answer
The modification of /root/.ssh/authorized_keys to include an attacker's public key is a classic SSH key persistence technique. The suspicious root login from an external IP at an odd hour corroborates this. Attackers use this to maintain access without needing a password, even if credentials are changed.
Exam trap
The trap here is assuming that any root login from an external IP indicates a password compromise, but the simultaneous modification of authorized_keys points specifically to SSH key persistence.
An incident responder is investigating a suspected compromise on a Windows endpoint and wants to identify evidence of lateral movement. Which TWO artifacts should the responder examine? (Choose two.)
Select 2 answers
A.The system's pagefile size configuration
B.The contents of the Recycle Bin
C.The list of installed Windows updates
D.Remote Desktop Services operational log entries for successful connections
E.Security event log entries for network logon type 3
AnswersD, E
The Remote Desktop Services operational log records successful and failed RDP connections, including the source and target. Attackers commonly use RDP for lateral movement, so entries showing connections from unusual hosts or at odd times are strong indicators. This artifact directly evidences remote access between systems.
Why this answer
Lateral movement leaves traces in authentication and remote access logs. Network logon type 3 entries show cross-host authentication, and Remote Desktop Services operational logs show RDP connections. Together they reveal an attacker moving from one system to another.
The other artifacts do not record the connection and logon events needed to trace lateral movement.
Exam trap
The trap here is selecting general system artifacts like update history or Recycle Bin contents because they are easy to collect, when lateral movement is evidenced by logon and remote session logs.
Refer to the exhibit. Given the provided log entry, which attack is likely occurring, and what does the sub-status code indicate?
A.Pass-the-Hash; 0xC000006A means the hash is expired
B.Brute-force/Dictionary attack; 0xC000006A means bad password
C.Account lockout; 0xC000006A means account is disabled
D.Kerberoasting; 0xC000006A means SPN not found
AnswerB
Repeated failed logins for an account, especially an administrator account, using NTLM indicate a brute-force or dictionary attack. The sub-status code 0xC000006A is the standard Windows error for an incorrect password provided during the authentication process.
Why this answer
Event ID 4625 with sub-status 0xC000006A indicates a failed logon due to a bad password. When this appears repeatedly from a single source for an administrative account, it strongly suggests a brute-force or dictionary attack. The NTLM authentication process indicates that the attacker is attempting to authenticate using the legacy NTLM protocol, which is a common indicator of targeted attacks against Windows environments.
Exam trap
Candidates often misinterpret Event ID 4625 sub-statuses. They may guess account lockout when the code specifically points to a bad password, indicating an active guessing attempt.
A GCIH incident responder is investigating a suspected API attack where an attacker manipulated a JSON Web Token (JWT) to gain unauthorized access. The responder needs to identify which two conditions would allow a JWT 'kid' (Key ID) header injection attack to succeed. (Choose two.)
Select 2 answers
A.The application uses a symmetric signing algorithm and the secret is weak or guessable.
B.The application allows the 'kid' header to specify an absolute path or URL that the server will fetch to obtain the key.
C.The application uses the 'kid' value to construct a file path for retrieving the verification key without proper sanitization.
D.The JWT is transmitted over an unencrypted HTTP connection, allowing token interception.
E.The application supports the 'none' algorithm and accepts unsigned tokens.
AnswersB, C
If the server fetches the key from a location specified by the 'kid' header, an attacker can point it to a malicious server hosting a key they control, or to a local file. This allows the attacker to sign tokens with a key the server will trust, bypassing authentication.
Why this answer
JWT 'kid' injection succeeds when the application uses the 'kid' header to determine the verification key without validating its content. If the 'kid' is used to build a file path or fetch a remote key, an attacker can manipulate it to use a key they control, forging valid tokens. The other conditions describe different JWT weaknesses.
Exam trap
The trap here is conflating 'kid' injection with other JWT attacks like 'none' algorithm or weak secret, which require different conditions and do not involve the 'kid' header.
Which technique involves an attacker injecting code into a legitimate, running process to perform malicious activity while avoiding the detection of file-based scanning?
A.Code signing
B.Process Injection
C.Data Execution Prevention (DEP)
D.Memory Forensics
AnswerB
Process injection is the act of inserting code into the address space of a separate, live process. This allows the attacker to execute their code with the permissions of the host process, effectively masking the malicious activity from security tools that scan files on the disk.
Why this answer
Process injection is a broad category of techniques where malicious code is forced into the memory space of another, healthy process. This is dangerous because the malicious activity appears to originate from the trusted process, potentially bypassing security controls. Responders must look for inter-process memory manipulation, such as calls to WriteProcessMemory or CreateRemoteThread, to identify when an adversary is attempting to hide their execution within a legitimate container.
Exam trap
Test-takers often confuse process injection with process hollowing or standard DLL sideloading, missing the broader definition of forcing code into an active, running process memory space.
During a forensic analysis of a compromised developer workstation, an incident handler discovers scripts showing an attacker utilized an LLM to automate reconnaissance tasks. Which TWO capabilities are typically enhanced when integrating LLMs into modern offensive enumeration workflows? (Choose two)
Select 2 answers
A.Synthesizing unstructured banner-grabbing outputs into structured asset inventories
B.Direct physical manipulation of smart-city IoT gateway switches via radio frequency
C.Autonomously generating custom multi-threaded port scanner binaries in compiled C
D.Translating natural language directives into complex, context-specific command pipelines
E.Bypassing hardware-enforced memory encryption mechanisms on remote hypervisors
AnswersA, D
Large Language Models excel at parsing messy, inconsistent service banner strings and raw network scan outputs into neatly organized JSON inventories. This capability drastically reduces the manual analysis overhead typically required during the initial reconnaissance and asset discovery phases.
Why this answer
Integrating Large Language Models into offensive reconnaissance enhances operations by parsing unstructured network data and generating complex scripting logic on the fly. Incident responders must recognize these patterns during host artifact analysis to map out how attackers accelerated their initial target discovery phases.
Exam trap
Candidates focus on the LLM generating malicious code. They overlook that the primary force-multiplier is the LLM’s ability to parse messy, unstructured data into actionable intelligence for the attacker.
Which TWO of the following are considered best practices for password hashing to mitigate offline cracking?
Select 2 answers
A.Use a unique, random salt for every user
B.Use a global static pepper appended to all hashes
C.Employ a high-cost key derivation function
D.Truncate passwords to 8 characters to save space
E.Store hashes in plain text for performance
AnswersA, C
A unique salt ensures that two users with the same password have different hash outputs. This effectively neutralizes precomputed rainbow table attacks because the attacker would need to generate a new table for every unique salt value, which is computationally impossible for large user databases.
Why this answer
Modern password storage must prioritize computational cost and uniqueness. Using a per-user salt ensures that even identical passwords result in different hashes, preventing rainbow table attacks. Increasing the computational work factor (e.g., iterations) forces attackers to spend more CPU time per guess, making massive brute-force efforts prohibitively expensive.
These controls are foundational to defense-in-depth, protecting user data integrity even when the authentication database is successfully exfiltrated by a threat actor.
Exam trap
Candidates often include 'using a strong encryption algorithm' like AES, which is irrelevant for hashing, as hashing is a one-way function, not encryption, and does not provide protection against offline cracking.