Courseiva

CCNA Incident Response and Cyber Investigation Questions

23 questions · Incident Response and Cyber Investigation · All types, answers revealed

1
MCQmedium

During an investigation, you observe an attacker using 'living-off-the-land' (LotL) techniques. Why is it difficult to detect this activity using traditional signature-based antivirus?

A.These binaries are encrypted on the disk, preventing antivirus from scanning them.
B.The tools operate entirely in volatile memory and never touch the disk.
C.The tools are trusted binaries and the malicious intent is in the parameters.
D.Antivirus software is only capable of detecting malware written in assembly language.
AnswerC

LotL techniques leverage legitimate tools that are signed and trusted by the OS. Antivirus signatures are designed to identify known malicious code; because the binaries themselves are benign, the AV ignores them. Detection must focus on the suspicious flags and command-line arguments, which AV does not typically inspect.

Why this answer

Living-off-the-land attacks use legitimate, signed system binaries (like PowerShell, wmic, or certutil) to perform malicious actions. Since the tools themselves are trusted components of the operating system, antivirus software rarely flags them as malicious. Detecting LotL requires behavioral analysis, command-line logging, and monitoring for anomalous execution patterns rather than relying on file signatures, which are ineffective against tools that are inherently part of the system's baseline.

Exam trap

Candidates often assume that because the binary is 'trusted' or 'signed,' it cannot be used for malicious purposes, leading them to overlook the malicious intent hidden within the command-line arguments.

2
MCQmedium

During a digital investigation, an incident responder is asked to preserve memory from a compromised Linux server. Which tool is most appropriate for a forensically sound memory acquisition?

A.The 'dd' command to copy /dev/mem directly to a remote storage server.
B.LiME (Linux Memory Extractor) to generate an image file for offline analysis.
C.The 'cat' command to pipe the contents of /proc/kcore into a file.
D.Installing a commercial agent to automate the imaging process via a GUI.
AnswerB

LiME is the industry-standard tool for Linux memory acquisition because it is specifically designed to handle the complexities of kernel memory. It minimizes system impact and can be used to stream the memory image over the network, ensuring that the evidence is captured with high fidelity and integrity.

Why this answer

Forensic acquisition requires tools that do not alter the target system's state or metadata significantly. In Linux, LiME (Linux Memory Extractor) is the standard for generating a memory image while minimizing interference. Understanding tool limitations is critical, as improper collection can destroy volatile data, overwrite evidence, or lead to kernel panics, which would invalidate the integrity of the collected memory dump for subsequent analysis and courtroom admissibility.

Exam trap

Candidates often suggest using standard system tools like 'dd' or 'cat' on /dev/mem, which are not forensically sound and can corrupt the memory state or produce inconsistent results.

3
MCQeasy

An incident responder is preparing to acquire a forensic image of a compromised Windows server. The server is still running, and the responder needs to capture volatile data first. Which of the following should be collected FIRST according to the order of volatility?

A.Network configuration and ARP cache.
B.Windows Event Logs.
C.Temporary files on the system drive.
D.Contents of physical memory (RAM).
AnswerD

Physical memory is the most volatile and contains running processes, network connections, and encryption keys. It is lost when the system is powered off. According to the order of volatility, RAM should be captured before any disk or less volatile data to preserve critical evidence that may not exist elsewhere.

Why this answer

According to the order of volatility, physical memory is the most volatile and should be captured first. It contains running processes, network connections, and potentially malicious code that exists only in RAM. Temporary files, network configuration, and event logs are less volatile and can be collected afterward.

Capturing memory first ensures that critical evidence is preserved before it is lost.

Exam trap

The trap here is focusing on disk-based artifacts like event logs or temporary files because they are familiar, while overlooking that RAM is the most volatile and must be captured first.

4
MCQhard

Refer to the exhibit. Why might an investigator use the output of 'vssadmin' during a cyber investigation?

A.To identify hidden partitions created by rootkits for persistence.
B.To recover previous versions of system files and registry hives for analysis.
C.To check for unauthorized changes to the system's BIOS/UEFI firmware.
D.To list all currently active network sockets on the host.
AnswerB

Shadow copies provide a point-in-time snapshot of the system. Investigators often use them to compare the current state of the system against a known-clean state or to recover deleted malicious files and modified configuration files that an attacker attempted to hide by overwriting them on the live disk.

Why this answer

Volume Shadow Copies are an essential artifact in Windows forensics. They allow an investigator to access older versions of files, including logs, registry hives, and malware binaries that the attacker might have modified or deleted to cover their tracks. By mounting these shadows, an investigator can perform 'time-travel' analysis, recovering evidence that is otherwise invisible on the live file system.

Exam trap

Students often think vssadmin is used exclusively for deleting backup files to prevent ransomware recovery, forgetting its critical forensic value for investigators.

5
MCQeasy

A GCIH incident responder is conducting a forensic investigation of a compromised Windows system. The responder needs to determine which user accounts were used to log on to the system and whether any unauthorized access occurred. Which Windows event log should the responder examine to find successful and failed logon attempts?

A.Application log
B.Setup log
C.Security log
D.System log
AnswerC

The Security log records security-related events, including successful and failed logon attempts (event IDs 4624 and 4625), account management, and privilege use. This is the primary log for auditing authentication activity. By examining it, the responder can identify which accounts were used and whether unauthorized access occurred, directly addressing the investigation goal.

Why this answer

The Security log is the authoritative source for authentication events on Windows. It records successful logons (event ID 4624) and failed logons (event ID 4625), along with details such as the user account, logon type, and source workstation. By analyzing this log, the responder can determine which accounts were used and identify any unauthorized access attempts, fulfilling the investigation requirement.

Exam trap

The trap here is assuming that the System log contains logon events because it sounds like it would, but authentication is exclusively in the Security log.

6
MCQeasy

An incident responder is reviewing an IDS alert and needs to determine whether a suspicious executable that ran on a Windows workstation has been seen in other attacks. Which framework should the responder consult to map the observed adversary behavior to known tactics, techniques, and procedures?

A.NIST SP 800-61
B.The Diamond Model of Intrusion Analysis
C.MITRE ATT&CK
D.The Cyber Kill Chain
AnswerC

MITRE ATT&CK is a globally accessible knowledge base of adversary tactics and techniques based on real-world observations. It lets the responder map the executable's behavior to specific techniques, understand which threat groups use them, and prioritize detection and response actions. This directly answers the need to contextualize the suspicious binary against known TTPs.

Why this answer

MITRE ATT&CK is designed specifically to catalog adversary tactics, techniques, and procedures from real-world observations. Mapping the suspicious executable to ATT&CK techniques allows the responder to understand what the binary is doing in terms of known behaviors and which threat actors employ those methods. This supports faster triage, prioritization, and detection engineering.

Exam trap

The trap here is confusing a lifecycle or analytical model with a technique knowledge base, since all four frameworks are commonly referenced in incident response.

7
MCQhard

During an incident response engagement, the team suspects that an attacker is using DNS tunneling to exfiltrate data. The team captures network traffic and wants to confirm the exfiltration. Which of the following DNS traffic characteristics would MOST strongly indicate DNS tunneling?

A.DNS queries that use TCP instead of UDP on port 53.
B.DNS responses that contain only A records and have a short TTL.
C.A high volume of DNS queries for a single domain with long, random-looking subdomains.
D.Frequent DNS queries to multiple known legitimate domains like google.com and microsoft.com.
AnswerC

DNS tunneling often involves encoding data in subdomains, resulting in long, random-looking labels. A high volume of queries to a single domain can indicate a covert channel. This pattern is characteristic of tools like iodine or dnscat2, which use DNS to transfer data. The randomness and length are key indicators.

Why this answer

The strongest indicator of DNS tunneling is a high volume of DNS queries to a single domain with long, random-looking subdomains. This pattern suggests data is being encoded in the subdomain labels and sent to an attacker-controlled authoritative DNS server. Other options, such as queries to legitimate domains or TCP usage, are not specific to tunneling and can occur in normal traffic.

Exam trap

The trap here is assuming any unusual DNS behavior, like TCP usage or short TTLs, indicates tunneling, when the hallmark is the encoded data in subdomains and high query volume to one domain.

8
MCQmedium

A SOC analyst receives a report that a workstation is beaconing to an unknown external IP every 60 seconds. The analyst runs netstat -anob and identifies the process responsible. The process is svchost.exe, but the parent process is not services.exe. Which of the following should the analyst do FIRST to determine if this is a malicious injection?

A.Terminate the svchost.exe process immediately to stop the beaconing.
B.Run a full antivirus scan on the workstation to detect and remove the malware.
C.Capture a memory dump of the svchost.exe process and examine its loaded modules.
D.Check the Windows Event Log for service creation events around the same time.
AnswerC

A memory dump preserves the injected code, strings, and network artifacts, allowing the analyst to confirm process hollowing or injection. Examining loaded modules can reveal unsigned or suspicious DLLs. This is the least disruptive first step that gathers crucial evidence before any containment action.

Why this answer

The correct first step is to capture a memory dump of the suspicious svchost.exe process. This preserves volatile evidence like injected code and network connections, allowing the analyst to confirm malicious activity before taking disruptive actions. Terminating the process or running an AV scan may destroy evidence or miss fileless malware, while event logs alone may not show the injection.

Exam trap

The trap here is assuming that any svchost.exe with an unusual parent is automatically malicious and should be terminated immediately, without gathering volatile evidence first.

9
Multi-Selectmedium

A GCIH incident handler is investigating a suspected compromise on a Windows 10 workstation. The user reported unusual outbound network connections and sluggish performance. To determine the scope and impact of the incident, the handler must collect volatile evidence first. Which TWO artifacts should the handler prioritize to capture active network connections and running processes before memory is altered or lost? (Choose two.)

Select 2 answers
A.List of scheduled tasks from the Task Scheduler library
B.Contents of the Windows Security event log
C.Contents of the `C:\Windows\Prefetch` directory
D.Output of the `netstat -anob` command
E.Output of the `tasklist /v` command
AnswersD, E

The `netstat -anob` command displays all active network connections, listening ports, and the associated executable names (with the -b switch) and process IDs (with the -o switch). This provides an immediate snapshot of which processes are communicating over the network, directly addressing the need to capture active connections and running processes. It is a core volatile data collection step in incident response.

Why this answer

In incident response, volatile data such as active network connections and running processes must be collected first because they are lost when the system is shut down or memory is altered. The `netstat -anob` command provides a snapshot of network connections and associated processes, while `tasklist /v` lists running processes with details. Together, they offer a current view of system activity, enabling the handler to identify malicious processes and their network communications.

Exam trap

The trap here is confusing non-volatile artifacts like event logs or scheduled tasks with volatile data that must be captured immediately.

10
MCQmedium

During an investigation of a compromised Linux web server, an incident responder needs to identify which user account was used to establish an outbound SSH session to an external IP address. Which artifact should the responder examine first?

A.The system's cron job definitions under /etc/cron.d
B.The bash command history file for each user under /home
C.The kernel ring buffer output from the dmesg command
D.The system authentication log, such as /var/log/auth.log or /var/log/secure
AnswerD

The authentication log records SSH session events, including the user account and the source and destination of connections. On most Linux distributions, sshd writes session open and close entries with the username and remote address, allowing the responder to correlate the outbound connection to a specific account. This directly answers which user initiated the session.

Why this answer

SSH session events are logged by the sshd daemon to the system authentication log, which includes the account name and connection endpoints. Examining /var/log/auth.log on Debian-based systems or /var/log/secure on Red Hat-based systems gives the responder the user attribution and timing needed. Other artifacts lack the necessary account-to-connection correlation.

Exam trap

The trap here is assuming shell history or process listings reliably attribute network connections to a user account, when only the authentication log records the SSH session owner.

11
Multi-Selecthard

Which TWO steps are critical during the 'Preparation' phase of the incident response lifecycle to ensure effective forensic investigation during a future security breach?

Select 2 answers
A.Establishing a centralized logging architecture with immutable storage.
B.Drafting an incident communication plan for notifying public regulatory bodies.
C.Defining forensic acquisition procedures and chain of custody documentation.
D.Conducting a comprehensive risk assessment of all internal business applications.
E.Purchasing cybersecurity insurance to cover potential ransomware payout costs.
AnswersA, C

Centralized logs are essential because they prevent attackers from tampering with local event logs after gaining administrative access. By ensuring storage is immutable, the organization guarantees that forensic investigators have an untampered historical record of attacker activity, which is crucial for building a reliable timeline of the intrusion.

Why this answer

Preparation is the foundation of incident response. By establishing logging infrastructure and legal protocols in advance, an organization ensures that forensic evidence is available and admissible when an incident occurs. Failing to prepare these elements often results in fragmented logs or delayed response actions, which hinders the team's ability to reconstruct the attack timeline accurately and perform root cause analysis after the threat is contained.

Exam trap

Candidates often select active response or containment steps rather than focusing strictly on proactive measures that must happen during the 'Preparation' phase before an incident starts.

12
MCQmedium

Which phase of the incident response process is most likely to involve the creation of a 'lessons learned' report to improve future security posture?

A.Detection and Analysis
B.Containment, Eradication, and Recovery
C.Post-Incident Activity
D.Preparation
AnswerC

The Post-Incident Activity phase is designed specifically for conducting a formal review of the incident response process. By documenting successes and failures, the organization can implement systemic changes to security controls, training, and response procedures, effectively closing the loop on the incident and enhancing future resilience.

Why this answer

Post-Incident Activity, often referred to as the 'Lessons Learned' phase, is the final stage of the IR lifecycle. It is essential for organizational growth, allowing the team to reflect on the effectiveness of their response, identify gaps in detection or containment, and update playbooks. This continuous improvement cycle is what differentiates a maturing security program from one that repeats the same mistakes during recurring security incidents.

Exam trap

Candidates often select containment or eradication phases when looking for long-term organizational improvement and post-incident reporting processes.

13
MCQmedium

An incident responder discovers an attacker has established persistence using a Windows 'Run' key. What is the most important first step after identifying the malicious registry entry?

A.Immediately delete the registry key to stop the persistence mechanism.
B.Capture the registry state and the associated binary file for analysis.
C.Reimage the affected workstation to ensure total eradication of the malware.
D.Change all user and service account passwords on the local system.
AnswerB

Capturing the state and the binary allows for thorough forensic analysis, such as identifying the malware's capabilities and its command-and-control infrastructure. This information is vital for scoping the incident, checking for other infected systems, and ensuring that the removal process is successful and leaves no residual malicious components behind.

Why this answer

Identifying the persistence mechanism is only the first step. Before removal, the responder must ensure that evidence is captured, as registry keys can provide valuable data about the attacker's tools and techniques. After imaging the state, the responder must safely remove the entry and then investigate how the attacker initially gained the access required to modify the registry in the first place.

Exam trap

Candidates often immediately delete the registry key to stop the persistence. This destroys forensic evidence, preventing the responder from understanding the attacker's origin and full extent of the compromise.

14
MCQmedium

You are performing a live response and encounter a suspicious process. Which action should you take FIRST to gather the most intelligence without alerting the adversary or crashing the system?

A.Take a forensic image of the hard drive using a hardware write-blocker.
B.Capture volatile data, including process listings, open handles, and network connections.
C.Power down the system immediately to preserve the current state.
D.Run an antivirus scan to identify and delete the malicious process.
AnswerB

Capturing volatile data is the priority because it is the most ephemeral evidence. By using memory acquisition tools, you can identify what the attacker is doing in real-time, such as open network sockets or injected threads, which are essential for understanding the scope of the current incident.

Why this answer

In live response, the principle of 'least intrusive first' is paramount. Collecting volatile data (like process lists and network connections) should always precede disk-based forensic imaging. By capturing the state of the system first, you ensure that you obtain the memory-resident artifacts that would be lost upon a reboot or power-down, providing the best foundation for a successful analysis.

Exam trap

Candidates often jump to disk imaging or memory dumps. They fail to prioritize volatile data like network connections and process lists, which are easily lost and provide immediate, low-impact context.

15
MCQmedium

An incident responder is preparing to collect volatile evidence from a compromised Windows server that is still running. Which order of collection best preserves the most perishable data?

A.Event logs, then memory, then disk
B.Registry hives, then disk image, then memory
C.Memory, then network connections and process state, then disk
D.Disk image first, then memory, then network connections
AnswerC

Memory contains the most perishable evidence, including running processes, network connections, and cryptographic material. Capturing memory first, followed by live network and process state, then the disk, follows the order of volatility. This preserves data that would be lost or altered if the system were imaged or shut down first.

Why this answer

The order of volatility dictates that the most transient data be captured first. Memory holds active processes, network connections, and keys that vanish on shutdown. Capturing memory, then live network and process state, and finally the disk preserves the evidence most likely to be lost.

This sequence reflects standard incident response practice for live systems.

Exam trap

The trap here is prioritizing disk or log artifacts because they are familiar, when the order of volatility requires memory and active network state to be captured before persistent storage.

16
MCQmedium

An organization is responding to an Advanced Persistent Threat (APT). During the 'Eradication' phase, why is it critical to go beyond just removing identified malware?

A.Because malware is often just a dropper for a secondary, more complex backdoor.
B.Because antivirus signatures are always outdated and will miss the actual threat.
C.Because the attacker will likely sue the organization if any artifacts remain.
D.Because the cleanup process must generate new forensic evidence for police.
AnswerA

APT actors use multiple persistence points to guarantee they can regain access if their primary tool is discovered. A thorough eradication process involves identifying and removing all these secondary backdoors and persistence mechanisms; otherwise, the attacker will simply leverage their secondary access to re-infect the system.

Why this answer

APT actors are methodical and typically establish multiple persistence mechanisms and backdoors to ensure continued access. If a responder only removes the single piece of malware they found, the attacker can easily pivot back into the network. Eradication must involve comprehensive cleaning, including resetting compromised credentials, closing open vulnerabilities, and auditing the environment to ensure no hidden persistence points remain.

Exam trap

Candidates often believe that deleting the primary malware is sufficient for remediation, ignoring that APTs prioritize persistence and will likely have multiple hidden backdoors ready for re-entry.

17
Multi-Selecthard

An organization detects a web-based attack and wants to perform a thorough investigation. Which THREE artifacts should the team collect to analyze the adversary's entry point and activity?

Select 3 answers
A.HTTP access and error logs from the web server.
B.System event logs for all workstations in the local network.
C.Application-level logs and database transaction logs.
D.Email gateway logs showing internal-to-external communication patterns.
E.Network perimeter firewall and WAF traffic logs.
AnswersA, C, E

Web server logs are the primary source for identifying the attacker's source IP, the requests made, and the server's response codes. Error logs often reveal failed exploitation attempts or crashes caused by malicious payloads, providing critical context for how the attacker attempted to compromise the application layer.

Why this answer

Analyzing a web-based attack requires a multi-layered approach. By correlating web server logs, application-level logs, and firewall traffic, investigators can reconstruct the full attack chain from the initial exploit attempt to post-exploitation activity. This holistic view is necessary to verify the entry point, understand the impact, and ensure all malicious persistence mechanisms are identified and removed during the remediation process, preventing the attacker from regaining unauthorized access to the environment.

Exam trap

Test-takers often overlook application-level and database logs, focusing solely on network firewalls and perimeter devices when investigating application-layer web attacks.

18
MCQhard

An incident responder is analyzing a Windows memory image and wants to identify a malicious process that has no corresponding file on disk. Which memory analysis artifact is most useful for this purpose?

A.The registry hives extracted from the memory image
B.The Windows event log for process creation, such as Event ID 4688
C.The process list with associated memory sections
D.The list of loaded kernel drivers
AnswerC

Enumerating processes and their memory sections reveals executable regions that may not map to a file on disk. Tools such as Volatility can list process memory maps and identify sections with no backing file, which is characteristic of injected or fileless code. This directly surfaces a process whose code exists only in memory, answering the scenario's need.

Why this answer

Memory section analysis maps each process's virtual memory regions and flags those without a corresponding file on disk. Injected or reflective-loading code appears as executable pages with no file path, which is the hallmark of a fileless process. This is the most direct way to identify a running process that never touched disk.

Exam trap

The trap here is assuming process creation logs or registry artifacts prove fileless execution, when only memory section mapping reveals code without an on-disk backing file.

19
MCQhard

Refer to the exhibit. An analyst deploys this policy to detect threats. Why is the 'parent_process' condition specifically targeting 'w3wp.exe'?

A.To detect unauthorized software installations performed by administrative users.
B.To identify potential web shell execution or exploit payloads triggered via IIS.
C.To prevent the web server from being used as a staging ground for brute force.
D.To ensure that all PowerShell scripts are signed and authorized by the organization.
AnswerB

IIS worker processes (w3wp.exe) should rarely spawn PowerShell. When they do, it is a high-confidence indicator of a web application compromise, such as a web shell executing commands. This detection is tailored to catch the specific behavior of attackers attempting to pivot from a web exploit to system-level execution.

Why this answer

The 'w3wp.exe' process is the IIS worker process. Attackers often exploit web vulnerabilities to spawn child processes, such as PowerShell, to execute malicious scripts directly from memory. By flagging PowerShell child processes of an IIS worker, the analyst is specifically monitoring for web shell activity or remote code execution, which are common vectors for initial access and persistence in web-facing server environments.

Exam trap

Candidates often assume the rule is looking for the 'w3wp.exe' process itself as the threat, missing that the goal is to detect suspicious child processes spawned by a legitimate web server process.

20
MCQmedium

Refer to the exhibit. An analyst identifies these entries on a critical server. What should the analyst conclude regarding the process associated with PID 4?

A.The server is likely compromised by a kernel-mode rootkit acting as a listener.
B.The process is a legitimate Windows kernel operation for SMB file sharing.
C.A remote adversary is using the SMB protocol to exfiltrate data from the system.
D.The system is currently scanning the network for vulnerabilities using SMB exploits.
AnswerB

PID 4 is the System process, which handles network traffic for the Server service, including SMB (TCP 445). This traffic is typical for a server responding to legitimate client requests. An analyst should differentiate between standard operating system network behavior and suspicious outbound connections to unauthorized external IP addresses.

Why this answer

In Windows environments, PID 4 is reserved for the System process. In the context of port 445 (SMB), this is standard behavior for the Server service and kernel-level file sharing. Recognizing legitimate OS behavior is critical to avoid false positives.

If the source IPs were unknown or the connection volume was anomalous, further investigation into kernel-mode drivers or rootkits would be required, but this output represents standard file sharing functionality.

Exam trap

Test-takers frequently panic upon seeing PID 4 involved in network listening ports, incorrectly assuming it represents malicious kernel-level rootkits or compromise.

21
MCQhard

During a security incident, a GCIH analyst discovers that an attacker used PowerShell to download and execute a malicious script from a remote server. The analyst wants to determine the full command line and parent process of the PowerShell execution to understand the attack vector. Which Windows artifact should the analyst examine to retrieve this information?

A.PowerShell operational log, event ID 4104
B.Windows System event log, event ID 7045
C.Windows Security event log, event ID 4688
D.Sysmon event ID 1 (Process Create)
AnswerD

Sysmon event ID 1 logs process creation and includes rich details such as the full command line, parent process ID, user account, and hashes. This directly answers the analyst's need to see the exact PowerShell command line and its parent process, enabling reconstruction of the attack chain. Sysmon is commonly used in incident response for this level of detail.

Why this answer

Sysmon event ID 1 provides comprehensive process creation data, including the full command line and parent process, which are critical for understanding how PowerShell was invoked and what it executed. Other logs either lack command-line detail (Security 4688 by default) or focus on script content (PowerShell 4104) rather than process lineage. Thus, Sysmon is the most appropriate artifact to retrieve the required information.

Exam trap

The trap here is assuming that PowerShell script block logging captures the command line and parent process, when it only captures script content.

22
Multi-Selecthard

An incident responder is investigating a suspected compromise on a Windows endpoint and wants to identify evidence of lateral movement. Which TWO artifacts should the responder examine? (Choose two.)

Select 2 answers
A.The system's pagefile size configuration
B.The contents of the Recycle Bin
C.The list of installed Windows updates
D.Remote Desktop Services operational log entries for successful connections
E.Security event log entries for network logon type 3
AnswersD, E

The Remote Desktop Services operational log records successful and failed RDP connections, including the source and target. Attackers commonly use RDP for lateral movement, so entries showing connections from unusual hosts or at odd times are strong indicators. This artifact directly evidences remote access between systems.

Why this answer

Lateral movement leaves traces in authentication and remote access logs. Network logon type 3 entries show cross-host authentication, and Remote Desktop Services operational logs show RDP connections. Together they reveal an attacker moving from one system to another.

The other artifacts do not record the connection and logon events needed to trace lateral movement.

Exam trap

The trap here is selecting general system artifacts like update history or Recycle Bin contents because they are easy to collect, when lateral movement is evidenced by logon and remote session logs.

23
Multi-Selectmedium

An incident responder is analyzing a compromised Linux server. The attacker gained access via SSH and escalated privileges. The responder wants to identify persistence mechanisms. Which TWO of the following locations should the responder examine? (Choose two.)

Select 2 answers
A.User's ~/.ssh/authorized_keys file
B./etc/hosts
C./etc/passwd
D./etc/crontab and /etc/cron.* directories
E./var/log/auth.log
AnswersA, D

The authorized_keys file contains public keys that are allowed to log in without a password. Attackers often add their own public key to maintain SSH access. Checking this file for unauthorized keys is a critical step in identifying persistence on a compromised Linux system.

Why this answer

The two most common Linux persistence mechanisms are cron jobs and SSH authorized_keys. Cron jobs allow scheduled execution of malicious code, while authorized_keys enables passwordless SSH access. Both are frequently used by attackers to maintain a foothold.

The auth.log, /etc/hosts, and /etc/passwd are not persistence mechanisms; they serve other purposes and may be modified for different attack goals.

Exam trap

The trap here is confusing log files or common configuration files like /etc/passwd with actual persistence mechanisms, when persistence requires a mechanism that automatically re-establishes access.

Ready to test yourself?

Try a timed practice session using only Incident Response and Cyber Investigation questions.

CCNA Incident Response and Cyber Investigation Questions | Courseiva