Courseiva

CCNA Cc Security Operations Questions

75 questions · Cc Security Operations topic · All types, answers revealed

1
MCQhard

An organization has a legacy system that cannot be patched due to vendor end-of-life. The system is critical for operations. Which compensating control is most appropriate to reduce the risk of exploitation?

A.Isolate the system on a separate network segment with strict access controls
B.Increase logging and monitoring without any network changes
C.Apply a virtual patch using a web application firewall
D.Remove the system from the network entirely
AnswerA

Network isolation on a separate segment with strict access controls limits lateral movement and reachability, compensating for the unpatched vulnerabilities that cannot be remediated. This contains exposure without relying on vendor fixes that are no longer available for the end-of-life system.

Why this answer

Isolating the legacy system on a separate network segment with strict access controls (firewalls, ACLs, micro-segmentation) is a compensating control that reduces the attack surface and limits lateral movement even though the system itself cannot be patched. It directly addresses the risk of exploitation by containing the system.

Exam trap

CC often tests compensating controls, and candidates pick monitoring or WAF options because they sound security-focused; the trap is confusing detection (logging) or narrow protection (WAF) with actual risk reduction through containment.

How to eliminate wrong answers

Option B is wrong because increasing logging and monitoring only improves detection and forensics; it does not reduce the likelihood or impact of exploitation. Option C is wrong because a virtual patch via WAF only protects web application traffic and does not address vulnerabilities in other protocols or services the legacy system may expose. Option D is wrong because removing the system from the network entirely would break the critical operations it supports, which is not acceptable given the scenario.

2
MCQhard

A configuration management tool detects that a critical server's security settings have changed from the approved baseline. What is the first action the security team should take?

A.Investigate the root cause of the configuration change
B.Isolate the server from the network
C.Automatically revert the settings to the baseline
D.Update the baseline to match the current configuration
AnswerA

Investigating the root cause first establishes what changed, who or what changed it, and whether it was malicious or accidental, before remediation. Restoring the baseline blindly could destroy forensic evidence or mask an ongoing compromise, so investigation precedes corrective action.

Why this answer

The first action should be to investigate the root cause of the configuration change. This is because a configuration drift could be caused by a legitimate change (e.g., an approved patch) or a malicious act. Understanding the cause informs the appropriate response, whether to revert, isolate, or update the baseline.

Isolating or reverting without investigation could disrupt business operations or destroy evidence.

Exam trap

The trap is assuming immediate containment or remediation is always best; in reality, investigation must precede action to avoid disrupting business or destroying evidence.

How to eliminate wrong answers

Option B is wrong because isolating the server is a containment step that may be premature; without knowing the cause, you might isolate a server that had a legitimate change, causing unnecessary downtime. Option C is wrong because automatically reverting could undo a necessary change (e.g., a security patch) and may not address the root cause, leading to recurrence. Option D is wrong because updating the baseline to match the current configuration would accept a potentially unauthorized or risky change, undermining the purpose of configuration management.

3
MCQmedium

A security administrator is configuring a new Windows server and wants to ensure that only necessary services and ports are enabled. After installation, the administrator runs a port scan and finds that port 3389 is open. Which action should the administrator take FIRST to reduce the attack surface?

A.Enable Network Level Authentication for RDP connections
B.Configure the firewall to allow RDP only from specific IP addresses
C.Change the RDP listening port to a non-standard number
D.Disable the Remote Desktop Protocol service if it is not required for administration
AnswerD

Port 3389 is used by Remote Desktop Protocol (RDP). If RDP is not needed, disabling the service closes the port and eliminates a common attack vector. This is the most direct and effective step to reduce the attack surface, as it removes the service entirely rather than just restricting access.

Why this answer

The first step in reducing attack surface is to remove unnecessary services. Since port 3389 is open due to RDP, and if RDP is not required, disabling it eliminates the exposure entirely. Other measures like firewall restrictions or authentication enhancements are useful but secondary to removing the service.

Exam trap

The trap here is opting for a mitigation like firewall rules or port changes instead of eliminating the unnecessary service, which is the most effective way to reduce attack surface.

4
MCQhard

A SOC analyst reviews a SIEM alert indicating a high volume of outbound traffic from a server to an external IP address known for command-and-control activity. The analyst has confirmed the alert is not a false positive. What is the most appropriate next step?

A.Escalate the alert to Tier 3 for advanced analysis.
B.Conduct a deeper investigation to identify affected systems and data.
C.Block the external IP address at the firewall immediately.
D.Reboot the server to terminate any malicious processes.
AnswerB

With the alert confirmed genuine, the analyst must scope the compromise: identify which systems communicated with the command-and-control infrastructure and what data was accessed. Containment decisions depend on that evidence, so deeper investigation precedes remediation.

Why this answer

After confirming a SIEM alert is not a false positive, the most appropriate next step is to conduct a deeper investigation to identify affected systems and data. This aligns with the incident response process, where containment and eradication should be based on a thorough understanding of the scope and impact. Immediate blocking or rebooting without investigation could destroy evidence or disrupt business operations.

Exam trap

CC often tests the order of incident response steps, and candidates may jump to containment (blocking) before investigation, which can be counterproductive.

How to eliminate wrong answers

Option A is wrong because escalating to Tier 3 without initial investigation may be premature; Tier 1 or 2 should first gather more context. Option C is wrong because blocking the IP immediately, while a containment step, should be done after understanding the scope to avoid disrupting legitimate traffic or tipping off attackers. Option D is wrong because rebooting the server could destroy volatile evidence and may not remove the root cause, allowing reinfection.

5
MCQmedium

An employee receives an email from the CEO asking for an urgent wire transfer to a new vendor. The email address is slightly misspelled. What type of attack is this?

A.Shoulder surfing
B.USB drop attack
C.Tailgating
D.Phishing
AnswerD

The misspelled sender address signals a spoofed identity, the defining trait of phishing: fraudulent email crafted to impersonate a trusted executive and trigger urgent action. Business email compromise is the specific subtype, but phishing correctly names the broader attack category the stem describes.

Why this answer

Phishing is a social engineering attack where an attacker impersonates a trusted entity (here, the CEO) via email to trick the recipient into performing a harmful action, such as transferring funds. The slightly misspelled email address is a classic phishing indicator — attackers register look-alike domains to deceive recipients. This specific CEO-impersonation variant is often called Business Email Compromise (BEC), a form of phishing.

Exam trap

The trap here is that candidates may overthink the scenario and pick a more 'technical' attack like shoulder surfing or tailgating, when the defining characteristic — deceptive email impersonation — clearly maps to phishing.

How to eliminate wrong answers

Option A is wrong because shoulder surfing involves physically observing someone's screen or keyboard to steal credentials or PINs — it has nothing to do with email impersonation. Option B is wrong because a USB drop attack relies on leaving infected USB drives for victims to plug in, exploiting curiosity or carelessness — no USB is involved here. Option C is wrong because tailgating is a physical security breach where an unauthorized person follows an authorized person through a secured door — it is unrelated to email-based deception.

6
MCQmedium

A security administrator is configuring a firewall to protect an internal network. The administrator needs to allow only HTTP and HTTPS traffic from the internal network to the internet, while blocking all other outbound traffic. Which of the following should the administrator implement?

A.A deny rule for all traffic except HTTP and HTTPS
B.An implicit deny rule at the end of the rule set
C.Explicit allow rules for HTTP and HTTPS, followed by an implicit deny
D.A stateful inspection rule that allows all outbound traffic
AnswerC

To allow only HTTP and HTTPS while blocking all other outbound traffic, the administrator must create explicit allow rules for TCP ports 80 and 443 from the internal network to the internet. These rules should be placed before a final implicit deny rule. This ensures that only the desired traffic is permitted and all other traffic is blocked.

Why this answer

Firewall rule sets are processed in order. To allow only HTTP and HTTPS outbound, explicit allow rules for TCP 80 and 443 must be created first. Then, a final rule (often implicit) denies all other traffic.

This ensures that only the desired traffic is permitted and everything else is blocked, meeting the requirement.

Exam trap

The trap here is assuming that an implicit deny alone is sufficient, when in fact explicit allow rules for the desired traffic must be placed before the deny to permit HTTP and HTTPS.

7
MCQeasy

An organization's security policy requires that all employees use unique, complex passwords for their domain accounts. A security analyst is reviewing a list of common password mistakes. Which of the following best describes a practice that undermines this policy?

A.Enabling multi-factor authentication on all domain accounts.
B.Using a password manager to generate and store unique passwords for each account.
C.Reusing the same password across multiple systems and services.
D.Changing passwords only when prompted by the system at 90-day intervals.
AnswerC

Reusing the same password across multiple systems means that if one system is breached, the attacker can access other systems using the same credentials. This directly violates the requirement for unique passwords and significantly increases risk. It is a common and dangerous practice that undermines the security policy, making it the correct choice.

Why this answer

The policy requires unique, complex passwords. Reusing the same password across multiple systems violates the uniqueness requirement and creates a cascading risk: compromise of one account can lead to compromise of others. This practice is a well-known security weakness.

The other options either support the policy or are neutral, so password reuse is the clear answer.

Exam trap

The trap here is confusing practices that support password security, such as using a password manager or enabling MFA, with those that undermine it, like reusing passwords.

8
MCQeasy

A security analyst at a Security Operations Centre (SOC) receives an alert from the SIEM indicating multiple failed login attempts for a user account followed by a successful login from an unusual geographic location. According to SOC tier responsibilities, which tier should perform the initial triage of this alert?

A.Tier 1 analyst
B.IT support team
C.Tier 2 analyst
D.Tier 3 analyst
AnswerA

Tier 1 analysts handle initial alert triage, validating whether the failed logins followed by an anomalous successful login represent a genuine incident before escalation. This monitoring and classification duty sits squarely within Tier 1 responsibilities, with Tier 2 and Tier 3 engaged only after triage confirms escalation is warranted.

Why this answer

Tier 1 analysts are responsible for initial alert triage — monitoring the SIEM queue, validating alerts, gathering basic context, and escalating confirmed incidents to Tier 2. The scenario describes a standard alert requiring first-level review, which falls squarely within Tier 1 duties. Escalation to higher tiers occurs only after Tier 1 confirms the incident or determines it requires deeper investigation.

Exam trap

The trap is assuming that because the alert looks serious (unusual geography, successful login), it should go straight to Tier 2 or Tier 3 — but all alerts enter through Tier 1 triage first.

How to eliminate wrong answers

Option B is wrong because IT support handles user account issues and endpoint troubleshooting, not security alert triage in a SOC. Option C is wrong because Tier 2 performs deeper investigation and incident response after Tier 1 escalation — they do not handle initial triage. Option D is wrong because Tier 3 is reserved for advanced threat hunting, malware analysis, and complex incident response, not first-line alert review.

9
MCQmedium

An organization must retain authentication logs for compliance with PCI DSS. What is the minimum retention period and the requirement for immediate availability?

A.6 months retention with 1 month immediately available
B.24 months retention with 12 months immediately available
C.18 months retention with 6 months immediately available
D.12 months retention with 3 months immediately available
AnswerD

PCI DSS mandates retaining audit trail history for at least twelve months, with the most recent three months immediately available for analysis. This satisfies both constraints in the stem: the minimum retention period and the immediate-availability requirement for authentication logs.

Why this answer

PCI DSS Requirement 10.7 mandates retaining audit logs for at least 12 months, with a minimum of the most recent 3 months immediately available for analysis. This ensures organizations can investigate recent incidents quickly while still preserving a full year of history for forensic and compliance review.

Exam trap

The trap is that candidates may recall a different retention figure (e.g., HIPAA's 6 years or SOX's 7 years) or confuse the retention period with the immediately-available window, leading them to pick an option that swaps or inflates the numbers.

How to eliminate wrong answers

Option A is wrong because 6 months retention with 1 month available falls short of the 12-month/3-month PCI DSS requirement. Option B is wrong because 24 months with 12 months available exceeds the PCI DSS minimum — while longer retention is permitted, it is not the specified requirement, making it an incorrect answer to 'what is the minimum.' Option C is wrong because 18 months with 6 months available also exceeds the PCI DSS baseline and misstates the required figures.

10
MCQeasy

To protect the integrity of log files, which of the following is a best practice?

A.Use write-once storage or a separate log server
B.Store logs on the same server as the application
C.Allow administrators to edit logs for accuracy
D.Encrypt logs but store them locally
AnswerA

Write-once storage or a separate log server prevents tampering because the logging host holds no credentials to modify or delete entries, and write-once media makes overwriting impossible. This directly satisfies the integrity constraint by ensuring captured records remain unaltered even if a compromised system is erased.

Why this answer

Using write-once storage (WORM) or a separate log server protects log integrity by preventing modification or deletion of log files. Write-once storage ensures logs cannot be altered after being written, and a separate log server isolates logs from the source system, reducing the risk of tampering by compromised hosts.

Exam trap

CC often tests the misconception that encryption alone ensures log integrity, when integrity requires preventing modification, not just confidentiality.

How to eliminate wrong answers

Option B is wrong because storing logs on the same server as the application makes them vulnerable to modification or deletion if the server is compromised. Option C is wrong because allowing administrators to edit logs compromises integrity and violates the principle of least privilege. Option D is wrong because encrypting logs but storing them locally does not prevent tampering or deletion; encryption protects confidentiality, not integrity.

11
MCQeasy

Which of the following is an indicator of a phishing email?

A.The email has a professional signature with contact information
B.The email includes a link that directs to a website with a domain similar to, but not exactly, the company's official domain
C.The email comes from a known colleague and contains a file attachment they mentioned earlier
D.The email is sent during regular business hours
AnswerB

Lookalike domains use typosquatting or homoglyph characters to imitate a legitimate domain, so the link appears trustworthy while directing victims to attacker-controlled infrastructure. This domain mismatch is a reliable phishing indicator, unlike generic greetings or marketing footers.

Why this answer

A link pointing to a domain that closely resembles—but is not exactly—the company's official domain is a classic phishing indicator (typosquatting or homoglyph attack). Attackers register lookalike domains to deceive users into entering credentials or downloading malware.

Exam trap

The trap is selecting options that seem 'unprofessional' (like off-hours sending) as phishing indicators, when the strongest technical signal is domain impersonation—candidates must focus on verifiable technical red flags, not subjective ones.

How to eliminate wrong answers

Option A is wrong because a professional signature with contact information is common in legitimate emails and can be easily spoofed by attackers, so it is not a reliable indicator. Option C is wrong because an email from a known colleague with a previously mentioned attachment is typically legitimate context, not a phishing sign. Option D is wrong because the time of day an email is sent is not a meaningful phishing indicator; attackers send at all hours.

12
MCQmedium

An employee receives an email that appears to be from the CEO requesting an urgent wire transfer to a new vendor. The email contains several grammatical errors and the sender's address is slightly misspelled. What type of security incident is this?

A.USB drop attack
B.Tailgating incident
C.Password attack
D.Phishing attack
AnswerD

The spoofed sender address, urgency, and grammatical errors are hallmarks of phishing, a social-engineering attack using fraudulent email to induce action. The wire-transfer pretext targets the employee directly, confirming phishing rather than malware, DoS, or insider threat.

Why this answer

The email impersonates the CEO, uses a spoofed/misspelled sender address, contains grammatical errors, and pressures the recipient into an urgent wire transfer — all classic hallmarks of a phishing attack, specifically a business email compromise (BEC) variant. Phishing is a social-engineering attack that uses fraudulent communications to trick users into revealing information or performing actions like transferring funds.

Exam trap

The trap is confusing phishing with other social-engineering or physical attacks — candidates must recognize that email-based deception requesting action is phishing, while USB and tailgating are physical vectors.

How to eliminate wrong answers

Option A is wrong because a USB drop attack involves leaving infected USB drives in a physical location hoping someone plugs them in — there is no physical media involved here. Option B is wrong because tailgating is a physical security incident where an unauthorized person follows an authorized person through a secured door, unrelated to email. Option C is wrong because a password attack involves brute force, credential stuffing, or password spraying against authentication systems, not a deceptive email requesting a wire transfer.

13
MCQhard

A security analyst is reviewing network flow logs and sees periodic outbound connections from an internal server to an external IP address on TCP port 443 every 30 minutes. The connections transfer small amounts of data and the external IP resolves to a newly registered domain. The server has no business need for internet access. Which type of malicious activity is most consistent with this pattern?

A.A beaconing implant maintaining command-and-control communication over HTTPS.
B.A denial-of-service attack launched from the server against the external address.
C.An internal vulnerability scan probing an external host for open ports.
D.A misconfigured software update service contacting its vendor repository.
AnswerA

Regular, evenly spaced connections to a newly registered external domain on port 443, with small data transfers, match the profile of malware beaconing to command-and-control infrastructure. The use of HTTPS blends with normal web traffic and evades content inspection. A server with no business internet need makes the pattern even more suspicious, so the host should be isolated and investigated.

Why this answer

Evenly spaced, low-volume outbound sessions to a newly registered external domain on an encrypted port are a textbook beaconing pattern. Malware uses this to check in for instructions while blending with ordinary TLS traffic. Because the server has no legitimate internet requirement, the activity cannot be dismissed as normal business traffic.

The right next step is to isolate the host, capture volatile data, and hunt for the implant and its persistence mechanism.

Exam trap

The trap here is dismissing encrypted outbound traffic to port 443 as automatically benign, when the timing, destination age, and lack of business need reveal beaconing.

14
MCQhard

A security operations center receives an alert that a workstation is communicating with a known command-and-control IP address over HTTPS on port 443. The endpoint agent shows no malware signature match. Which containment action should the analyst take first to limit damage while preserving the ability to investigate?

A.Isolate the workstation from the network using the endpoint agent's network containment feature.
B.Immediately power off the workstation to stop any malicious activity.
C.Block the destination IP address at the perimeter firewall and continue monitoring the workstation.
D.Delete the suspicious files identified by the endpoint agent and run a full antivirus scan.
AnswerA

Network isolation via the endpoint agent stops the command-and-control communication and prevents lateral movement while keeping the host powered on and its memory intact. This preserves volatile evidence such as running processes and network connections for forensic analysis. It is the fastest containment step that balances damage limitation with investigative value.

Why this answer

When an endpoint shows beaconing to known command-and-control infrastructure but no signature match, the priority is to sever the attacker's channel without destroying evidence. Endpoint network containment isolates the host while keeping memory and running processes available for forensic capture. Powering off, deleting files, or blocking a single external IP either destroys evidence or leaves the compromised host free to communicate and move laterally.

Exam trap

The trap here is treating any confirmed compromise as a reason to power off the machine immediately, when doing so destroys volatile memory that investigators rely on.

15
MCQmedium

A security analyst is reviewing endpoint logs and sees repeated entries showing that a process attempted to modify the Windows registry key HKLM\SYSTEM\CurrentControlSet\Control\Lsa and then attempted to read the SAM database file. The process is not a known administrative tool and was launched from a user's temporary folder. Which type of activity is MOST likely occurring?

A.Routine operating system patch installation
B.Privilege escalation and credential dumping attempts
C.Normal user profile creation by the operating system
D.Antivirus signature update process
AnswerB

Modifying the LSA registry key and reading the SAM database are classic actions associated with extracting password hashes and elevating privileges on Windows. The process running from a user temp folder and not being a known admin tool strongly indicates malicious credential access behavior, which is a key indicator of compromise in security operations.

Why this answer

The combination of modifying the LSA registry key and reading the SAM database from an unknown process in a user temp folder is a strong indicator of credential dumping and privilege escalation. These actions are commonly performed by tools like Mimikatz or custom malware to extract password hashes. Recognizing this pattern helps analysts quickly identify a potential compromise.

Exam trap

The trap here is assuming that any registry modification or SAM access is benign administrative activity, when the context of an unknown process in a temp folder makes it highly suspicious.

16
MCQmedium

An organization wants to ensure that all workstations are configured according to a hardened baseline. Which process detects when a workstation deviates from this baseline?

A.Patch management
B.Change control
C.Security awareness training
D.Automated configuration scanning
AnswerD

Automated configuration scanning continuously compares workstation settings against the defined hardened baseline and flags deviations. This satisfies the stem's requirement to detect when a workstation drifts from the baseline, rather than merely enforcing or remediating it.

Why this answer

Automated configuration scanning continuously compares each workstation's settings against a defined hardened baseline and flags deviations. It is the only option that provides ongoing detection of drift from the security configuration standard.

Exam trap

The trap here is confusing preventive controls like patch management or change control with detective controls like automated configuration scanning, leading candidates to choose a process that does not actually detect drift.

How to eliminate wrong answers

Option A is wrong because patch management addresses missing software updates, not configuration settings that deviate from a baseline. Option B is wrong because change control is a governance process for approving modifications, not a technical detection mechanism for baseline drift. Option C is wrong because security awareness training educates users and does not inspect or detect workstation configuration state.

17
MCQeasy

An employee reports that their laptop suddenly displays a message demanding payment in cryptocurrency to restore access to files, and the files now have an unfamiliar extension. The employee has not clicked any links recently. Which type of malware is MOST likely responsible?

A.A logic bomb
B.A keylogger
C.A rootkit
D.Ransomware
AnswerD

Ransomware encrypts files, often appends unfamiliar extensions, and displays a ransom demand for decryption keys, which matches every symptom described. The cryptocurrency payment demand is a hallmark of this malware class. Even without a recent link click, delivery can occur through exploits, malicious documents, or compromised remote services, making ransomware the most likely culprit.

Why this answer

The combination of encrypted files, altered extensions, and a cryptocurrency ransom demand is the classic signature of ransomware. Delivery does not require a recent link click, since exploits, malicious attachments, and exposed services are common vectors. Recognizing these indicators lets responders isolate the host quickly, preserve evidence, and avoid paying, while restoring from offline backups if available.

Exam trap

The trap here is assuming ransomware always requires a recent link click, which overlooks exploit-based and service-based delivery methods.

18
MCQmedium

A security analyst reviewing web server logs sees repeated requests containing strings such as '../../etc/passwd' and '..%2f..%2fwindows%2fsystem32'. The requests originate from a single external address and target a file-download endpoint. Which type of attack is most likely occurring?

A.Cross-site request forgery
B.Cross-site scripting
C.Directory traversal
D.SQL injection
AnswerC

Directory traversal uses sequences like '../' to escape the intended directory and read files elsewhere on the host. The encoded and literal dot-dot-slash patterns targeting passwd and system32 files are classic traversal attempts against a file-download endpoint. The attacker is trying to make the application return files it should never expose, which matches this attack exactly.

Why this answer

The dot-dot-slash sequences, including the URL-encoded form, are attempts to climb out of the intended directory and read sensitive files such as the password file or Windows system binaries. This is textbook directory traversal against a file-download function. The attacker is not injecting script, SQL, or forging a session request, but manipulating the path the application resolves.

Exam trap

The trap here is treating any encoded or unusual input as SQL injection, when the specific dot-dot-slash and system-file targets clearly point to filesystem path manipulation.

19
MCQmedium

An organization needs to retain authentication logs for compliance with PCI DSS. What is the minimum retention period required, and how long must the logs be immediately available?

A.18 months retention, 6 months immediately available
B.12 months retention, 3 months immediately available
C.6 months retention, 1 month immediately available
D.24 months retention, 12 months immediately available
AnswerB

PCI DSS requires audit logs to be retained for at least 12 months, with the most recent three months immediately available for analysis. This satisfies both the retention and availability constraints stated in the scenario.

Why this answer

PCI DSS Requirement 10.7 mandates retaining audit logs for at least 12 months, with a minimum of the most recent 3 months immediately available for analysis. This ensures organizations can investigate recent incidents quickly while still having historical data for forensic and compliance reviews.

Exam trap

CC often tests the exact PCI DSS retention numbers — candidates confuse the 12-month total retention with the 3-month immediate availability requirement, or pick a larger number thinking 'more is safer.'

How to eliminate wrong answers

Option A is wrong because 18 months retention with 6 months immediately available exceeds the PCI DSS minimum and is not the specified requirement. Option C is wrong because 6 months retention with 1 month available is below the PCI DSS minimum. Option D is wrong because 24 months retention with 12 months available is a stricter internal policy, not the PCI DSS baseline.

20
Multi-Selecthard

A security operations center (SOC) is reviewing its incident response plan and wants to improve detection of data exfiltration over encrypted channels. Which TWO monitoring approaches would BEST help identify potential exfiltration in this scenario? (Choose two.)

Select 2 answers
A.Analyzing network flow records for unusual volumes of outbound traffic to external IP addresses
B.Enabling full packet capture and storing all network traffic for later analysis
C.Reviewing DNS query logs for lookups of known malicious domains
D.Monitoring endpoint logs for processes that compress and archive large numbers of files
E.Deploying SSL/TLS inspection to decrypt and examine all outbound web traffic
AnswersA, D

Network flow records, such as NetFlow or IPFIX, provide metadata about connections without payload inspection. Large or anomalous outbound data transfers to external IPs can indicate exfiltration even when traffic is encrypted. This approach is effective because it focuses on behavior and volume rather than content, making it suitable for detecting encrypted exfiltration.

Why this answer

Detecting encrypted exfiltration requires focusing on behavior and metadata rather than payload content. Network flow analysis identifies anomalous outbound volumes, while endpoint monitoring detects staging activities like archiving. Together, they provide complementary visibility without relying on decryption, making them effective for this scenario.

Exam trap

The trap here is assuming that decrypting all traffic is necessary or always feasible, when in fact behavioral and metadata analysis often provide better detection for encrypted exfiltration.

21
Multi-Selectmedium

An organization is planning to implement a security awareness program. Which TWO topics should be included to address common social engineering attacks?

Select 2 answers
A.Recognizing phishing emails
B.Awareness of tailgating and piggybacking
C.Understanding encryption algorithms
D.Configuring firewall rules
E.Proper password management using a password manager
AnswersA, B

Phishing recognition teaches staff to spot fraudulent emails, the most common social-engineering vector, satisfying the stem's requirement to address common attacks. It covers spoofed senders, urgent lures, and malicious links, reducing credential theft and payload execution.

Why this answer

Option A (Recognizing phishing emails) is correct because phishing is one of the most common social engineering attacks, and training users to identify suspicious senders, spoofed domains, urgent language, and malicious links or attachments directly reduces the risk of credential theft and malware infection. Option B (Awareness of tailgating and piggybacking) is correct because these are physical social engineering techniques in which an attacker follows an authorized person into a restricted area, so awareness training helps employees enforce badge checks and challenge unknown individuals. Option C is not a social engineering topic; understanding encryption algorithms is a technical cryptographic concept rather than a human-focused attack vector.

Option D is also technical rather than social engineering, since configuring firewall rules is an administrative network security task performed by IT staff. Option E, while valuable for overall security, addresses credential hygiene rather than the manipulation tactics that define social engineering attacks.

Exam trap

The trap is selecting technical topics (encryption, firewall rules) because they sound security-related, but the question specifically asks for social engineering topics—candidates must distinguish between technical controls and human-focused awareness.

22
MCQmedium

An organization must comply with PCI DSS log retention requirements. What is the minimum retention period for logs, and how long must they be immediately available for analysis?

A.24 months retention, 12 months immediately available
B.6 months retention, 1 month immediately available
C.12 months retention, 3 months immediately available
D.12 months retention, 6 months immediately available
AnswerC

PCI DSS requires audit logs retained for at least 12 months, with the most recent 3 months immediately available for analysis. This satisfies the stem's two-part constraint, balancing forensic history against the cost of keeping older logs readily searchable.

Why this answer

PCI DSS requires logs to be retained for at least 12 months, with the most recent 3 months immediately available for review.

23
MCQhard

A security analyst receives an alert that a user account successfully authenticated to the corporate VPN from two geographically distant countries within a five-minute window. The user is currently traveling and confirms only one login. Which conclusion is MOST appropriate for the analyst to draw at this stage?

A.The VPN concentrator has failed and the logs are unreliable, so the account is safe
B.The alert is a false positive caused by NTP drift and should be closed immediately
C.The account is likely compromised and the impossible-travel indicator warrants immediate investigation
D.The user must be sharing credentials with a colleague and should only be reminded of policy
AnswerC

Simultaneous successful authentications from geographically distant locations within an impossibly short window strongly suggest the credentials were used by someone other than the legitimate user, especially since the user confirms only one session. Treating impossible travel as a compromise indicator prompts containment steps such as session termination, password reset, and review of accessed resources, which is the appropriate response.

Why this answer

Successful authentications from two distant countries within five minutes, combined with the user confirming a single session, form a classic impossible-travel indicator of credential compromise. The analyst should treat the account as potentially compromised and act quickly to contain it, rather than dismissing the alert, assuming benign credential sharing, or blaming infrastructure. Prompt investigation limits any attacker's access.

Exam trap

The trap here is rationalizing the anomaly as clock drift, credential sharing, or device failure instead of recognizing impossible travel as a likely compromise indicator.

24
Multi-Selecthard

An organization is implementing a security baseline for new servers. Which THREE components are typically included in a hardened baseline configuration? (Choose three.)

Select 3 answers
A.Allowing remote desktop access from any IP address.
B.Disabling unnecessary services and ports.
C.Enabling automatic login for administrators.
D.Enforcing strong password policies.
E.Installing all available security patches.
AnswersB, D, E

Disabling unnecessary services and ports shrinks the attack surface by removing listening daemons and open sockets that are not required for the server's role. This is a core hardening step, directly satisfying the baseline requirement to minimise exploitable entry points on new servers.

Why this answer

Option B is correct because a hardened baseline minimizes the attack surface by disabling unnecessary services and closing unused ports, reducing the number of exploitable entry points on a new server. Option D is correct because enforcing strong password policies (for example, minimum length, complexity, and expiration requirements) strengthens authentication and mitigates brute-force and credential-guessing attacks. Option E is correct because installing all available security patches ensures known vulnerabilities in the OS and applications are remediated before the server is placed into production.

Option A does not belong because allowing RDP from any IP address exposes the server to unauthorized remote access and should instead be restricted to trusted management networks. Option C does not belong because automatic login for administrators bypasses authentication entirely, directly undermining the purpose of a security baseline.

Exam trap

The trap is selecting convenience features like automatic login or unrestricted RDP because they seem efficient, but hardening always prioritizes security over convenience—candidates must recognize that these are anti-patterns.

25
MCQmedium

A SOC analyst detects a pattern of outbound traffic from an internal server to a known malicious IP address. Which SOC tier should this alert be escalated to for a deeper investigation?

A.Tier 3
B.Tier 2
C.Tier 1
D.Incident Response Team
AnswerB

Tier 2 analysts handle deeper investigation, correlating the malicious-IP indicator against threat intelligence, historical logs and endpoint telemetry. Tier 1 performs initial triage only, so escalation to Tier 2 satisfies the requirement for a deeper investigation of confirmed malicious outbound traffic.

Why this answer

Tier 2 analysts handle escalated alerts that require deeper investigation, correlation across data sources, and threat hunting beyond the initial triage performed by Tier 1. An outbound connection to a known malicious IP is a confirmed suspicious indicator that exceeds Tier 1's scope of basic validation and false-positive filtering, so it escalates to Tier 2. Tier 3 is reserved for advanced threat hunting, malware reverse engineering, and major incidents.

Exam trap

The trap is assuming any malicious-IP alert is automatically an incident requiring the IR team, when the correct answer is the tier that performs deeper investigation, not the team that handles confirmed incidents.

How to eliminate wrong answers

Option A is wrong because Tier 3 is for the most complex, advanced investigations such as reverse engineering or APT hunting, which is beyond a single malicious-IP alert. Option C is wrong because Tier 1 performs initial triage and alert validation; escalating to Tier 1 would be a downgrade, not an escalation. Option D is wrong because the Incident Response Team is engaged for confirmed incidents requiring containment and recovery, not for the initial deeper investigation of a suspicious alert.

26
MCQmedium

During an incident investigation, an analyst needs to determine which user account created a specific file on a shared drive at a particular time. The organization enables auditing on the file server. Which Windows event log should the analyst review?

A.The Security log, because object access auditing records file creation events there.
B.The Application log, because file operations are generated by applications writing to disk.
C.The Setup log, because it tracks changes to files installed by administrators.
D.The System log, because it records all file system changes performed by services and users.
AnswerA

When object access auditing is enabled, file creation and access events are written to the Windows Security log with event IDs such as 4663 and 4656, including the account name and object path. This makes the Security log the authoritative source for attribution of file operations. Reviewing it requires the appropriate audit policy and sufficient log retention.

Why this answer

Attribution of file activity requires object access auditing, which writes events to the Security log when enabled through audit policy. Those events include the account, object name, and access type, which directly answers who created the file and when. The System, Application, and Setup logs serve other purposes and do not capture user file operations, so they cannot provide the needed evidence.

Exam trap

The trap here is assuming that the System or Application log tracks all activity on the machine, when file-level attribution depends on object access auditing in the Security log.

27
MCQeasy

What is the primary purpose of a Security Information and Event Management (SIEM) system?

A.Encrypt sensitive data at rest
B.Manage user passwords and access controls
C.Aggregate and correlate logs to generate alerts
D.Block malicious network traffic in real time
AnswerC

A SIEM collects log and event data from across the estate, then correlates it to detect patterns indicating incidents and raises alerts. This aggregation and correlation capability is its primary purpose, satisfying the stem's requirement.

Why this answer

A SIEM's core function is to aggregate log and event data from many sources, normalize it, and correlate events across systems to detect and alert on security incidents. Correlation is what distinguishes a SIEM from simple log collection — it identifies patterns spanning multiple events that individually look benign.

Exam trap

The trap here is confusing SIEM (detect and alert via correlation) with tools that block or encrypt — candidates pick 'block malicious traffic' because they conflate SIEM with IPS/firewall.

How to eliminate wrong answers

Option A is wrong because encryption of data at rest is handled by disk encryption, key management, or database encryption features — not by a SIEM. Option B is wrong because password and access control management is the domain of IAM, PAM, or directory services, not SIEM. Option D is wrong because blocking malicious traffic in real time is the function of firewalls, IPS, or EDR — a SIEM detects and alerts, it does not sit inline to block traffic.

28
Multi-Selectmedium

A SOC analyst is investigating a potential data exfiltration incident. Which TWO log sources would be most useful for identifying outbound data transfers? (Select TWO)

Select 2 answers
A.Firewall logs
B.Patch management logs
C.Proxy logs
D.System logs
E.Authentication logs
AnswersA, C

Firewall logs capture allowed and denied connections with source and destination IP addresses, ports and byte counts, revealing large or anomalous outbound flows to external hosts. This satisfies the exfiltration scenario by exposing volume and destination of egress traffic crossing the network perimeter.

Why this answer

Firewall logs (A) are correct because they record allowed and denied connections with source/destination IP addresses, ports, and byte/packet counts, letting the analyst spot large or anomalous outbound transfers to external hosts. Proxy logs (C) are correct because they capture HTTP/HTTPS requests, URLs, user agents, and often the volume of data uploaded or downloaded, which is essential for identifying web-based exfiltration channels. Patch management logs (B) only track software update deployment and compliance, so they reveal nothing about network data flows.

System logs (D) contain OS, service, and application events but generally lack the destination and transfer-volume detail needed to confirm outbound exfiltration. Authentication logs (E) show logon, logoff, and failed-access events, which help with account compromise analysis but not with tracing data leaving the network.

Exam trap

The trap here is confusing 'system logs' or 'authentication logs' with network visibility — candidates pick them because they sound security-relevant, but only firewall and proxy logs actually show outbound data flows.

29
Multi-Selectmedium

A security team is implementing a Security Information and Event Management (SIEM) system. Which TWO log sources are most critical for detecting unauthorized access attempts on a Linux server? (Choose two.)

Select 2 answers
A./var/log/kern.log
B./var/log/syslog
C./var/log/secure
D./var/log/auth.log
E./var/log/dpkg.log
AnswersC, D

On Red Hat-based Linux distributions, /var/log/secure serves the same purpose as /var/log/auth.log on Debian-based systems. It records authentication and security-related events, including failed logins and sudo usage. Monitoring this file is critical for detecting unauthorized access attempts on those systems. It is a primary source for security auditing.

Why this answer

On Linux systems, authentication events are logged in /var/log/auth.log (Debian-based) or /var/log/secure (Red Hat-based). These files record failed and successful login attempts, sudo usage, and SSH access, making them critical for detecting unauthorized access. Other logs like syslog, kern.log, or dpkg.log serve different purposes and are less directly relevant to access attempts.

Exam trap

The trap here is assuming that syslog contains all security events, but authentication logs are specifically separated into auth.log or secure depending on the distribution.

30
MCQmedium

A security analyst is reviewing email gateway logs and notices a message that passed authentication checks but contains a URL pointing to a look-alike domain registered three days ago. The message appears to come from the organization's CEO and requests an urgent wire transfer. Which type of attack is MOST likely being attempted?

A.Cross-site scripting (XSS)
B.SQL injection
C.Business email compromise (BEC)
D.Distributed denial-of-service (DDoS) attack
AnswerC

The scenario describes a spoofed executive identity, an urgent financial request, and a newly registered look-alike domain. These are hallmarks of business email compromise, where attackers impersonate executives to trick employees into transferring funds or revealing sensitive data. The message passing authentication checks suggests the attacker may have compromised a legitimate account or used a carefully crafted domain that bypasses some filters.

Why this answer

Business email compromise (BEC) is a social engineering attack where cybercriminals impersonate executives or trusted partners to trick employees into transferring funds or sharing sensitive information. The combination of an urgent wire transfer request, a spoofed CEO identity, and a newly registered look-alike domain strongly indicates BEC. Other attack types do not align with the described email-based deception and financial motive.

Exam trap

The trap here is confusing BEC with generic phishing, but BEC specifically targets financial transactions through executive impersonation, often without malicious attachments or links to credential-harvesting sites.

31
MCQmedium

A security team wants to detect when an attacker is using a compromised account to move laterally between servers inside the network. Which monitoring approach would best surface this activity?

A.Tracking the number of failed disk backups on storage systems
B.Monitoring outbound email volume for spikes in messages sent by users
C.Reviewing only the perimeter firewall's inbound connection logs
D.Analyzing internal authentication and remote-access logs for unusual source-destination pairs
AnswerD

Lateral movement typically appears as a compromised account authenticating to systems it does not normally touch, often across unusual host pairs or at odd times. Correlating internal authentication and remote-access logs exposes these deviations, such as one workstation account logging into many servers. This internal visibility is exactly what detects an attacker pivoting through the environment using stolen credentials.

Why this answer

Lateral movement uses stolen credentials to reach systems the account would not normally access, so the strongest signal is internal authentication and remote-access activity showing unusual source-destination pairs, off-hours logins, or one account touching many hosts. Perimeter, email, and backup monitoring address different threats and would not reveal an attacker pivoting inside the network.

Exam trap

The trap here is focusing on external-facing logs, when lateral movement occurs internally and is best revealed by internal authentication and remote-access patterns.

32
Multi-Selectmedium

A security analyst is reviewing network logs to detect potential intrusions. Which TWO of the following are examples of network-based indicators of compromise? (Choose two.)

Select 2 answers
A.Multiple connections to a command-and-control server
B.A file with a suspicious hash value found in a user's download folder
C.Unusual outbound traffic to a known malicious IP address
D.A new local administrator account created on a workstation
E.A sudden increase in failed login attempts on a user account
AnswersA, C

Multiple connections to a command-and-control server are a clear network-based indicator of compromise. This behavior often indicates that compromised hosts are receiving instructions or sending data to an attacker-controlled server. It is typically detected through network traffic analysis and is a strong sign of an active intrusion.

Why this answer

Network-based indicators of compromise are observable in network traffic, such as unusual outbound connections to malicious IPs or multiple connections to command-and-control servers. These suggest active communication with attacker infrastructure. Host-based indicators, like failed logins or new accounts, are found on individual systems and are not network-based.

Exam trap

The trap here is conflating host-based indicators, such as failed logins or new accounts, with network-based indicators, which specifically involve traffic and communications.

33
Multi-Selectmedium

An organization is implementing a security awareness program. Which THREE topics should be included to address common social engineering attacks? (Select THREE)

Select 3 answers
A.Tailgating awareness
B.Secure coding practices
C.USB drop attack risks
D.Recognizing phishing emails
E.Password complexity requirements
AnswersA, C, D

Tailgating exploits politeness and trust: an attacker follows an authorised person through a controlled door without presenting credentials. Awareness training teaches staff to challenge unfamiliar individuals and enforce badge checks, mitigating this physical social-engineering technique that bypasses electronic access controls.

Why this answer

Tailgating awareness (A) is correct because tailgating is a physical social engineering attack where an unauthorized person follows an authorized individual through a secure door, so awareness training must teach employees to challenge strangers and enforce badge/access controls. USB drop attack risks (C) are correct because attackers leave infected USB drives in parking lots or common areas hoping victims plug them in, and awareness training should instruct users never to connect found media. Recognizing phishing emails (D) is correct because phishing is the most common social engineering vector, and training should cover suspicious senders, urgent language, mismatched URLs, and malicious attachments/links.

Secure coding practices (B) are not a social engineering topic; they belong to developer security training such as OWASP Top 10 and input validation. Password complexity requirements (E) are a technical authentication control, not a social engineering awareness topic, since social engineering targets human trust rather than password strength rules.

Exam trap

The trap is selecting technical controls (secure coding, password complexity) instead of human-focused social engineering topics — CC tests whether you can distinguish awareness training content from technical policy.

34
MCQmedium

A company's SIEM solution aggregates logs from various sources and generates an alert when multiple failed logins occur within a short timeframe. Which log source is most likely to provide the data for this alert?

A.System logs
B.Firewall logs
C.Application logs
D.Authentication logs
AnswerD

Authentication logs record each login attempt with success or failure and the originating account or source, so repeated failures within a short window are detectable. This directly satisfies the SIEM correlation rule for multiple failed logins.

Why this answer

Authentication logs record login attempts, including failures, and are the primary source for detecting brute-force attacks.

35
MCQhard

During an incident, a responder needs to capture the contents of volatile memory on a running Linux server before shutting it down, because encryption keys and running processes may only exist in RAM. Which action BEST preserves this volatile evidence?

A.Pull the power cord immediately, then remove and image the hard drive
B.Restart the server and enable verbose logging for future collection
C.Capture a memory image using a tool such as LiME or AVML before any shutdown
D.Run the dd command to image the primary disk to an external drive
AnswerC

Memory acquisition tools like LiME and AVML dump RAM contents to a file or network location while the system runs, preserving encryption keys, network connections, and running processes that vanish on shutdown. Order of volatility principles require capturing memory before less volatile sources. Performing this first ensures the most perishable evidence is secured before power-off or disk imaging.

Why this answer

Order of volatility requires collecting the most perishable evidence first, and RAM contents disappear the moment a system loses power or restarts. Memory acquisition tools such as LiME or AVML capture encryption keys, active network connections, and running processes that disk images cannot recover. Capturing memory before shutdown or disk imaging preserves the ephemeral evidence needed to understand attacker activity and credentials in use.

Exam trap

The trap here is treating the disk image as the priority, when memory is more volatile and must be captured before shutdown or power loss.

36
MCQhard

During an incident, an analyst needs to determine whether a compromised account was used to access a sensitive file share. The file server runs Windows and the organization uses centralized authentication. Which log source should the analyst review first to identify the account's access to the share?

A.Antivirus console logs showing scan results on the file server.
B.Windows Security event logs on the file server, filtered for object access auditing events.
C.Domain controller Security logs filtered for Kerberos ticket-granting service events.
D.Firewall logs showing SMB traffic between the workstation and the file server.
AnswerB

When object access auditing is enabled, the file server's Security log records events such as 4663 for attempts to access an object, including the account name, object path, and access type. This directly answers whether the compromised account touched the sensitive share. It is the most specific and authoritative source for file share access on Windows.

Why this answer

To establish whether a specific account accessed a sensitive file share on Windows, the file server's Security log with object access auditing enabled is the authoritative source. Event 4663 and related object access events capture the account, object path, and access type. Domain controller Kerberos events, firewall SMB logs, and antivirus logs provide authentication or network context but cannot prove file-level access by the compromised account.

Exam trap

The trap here is assuming domain controller authentication logs are sufficient to prove file access, when they only show that a logon or ticket was issued, not which files were opened.

37
MCQmedium

A security administrator is reviewing firewall logs and notices repeated inbound connection attempts to TCP port 3389 from multiple external IP addresses. Which type of attack is MOST likely occurring?

A.Denial-of-service (DoS) attack
B.SQL injection
C.Remote Desktop Protocol (RDP) brute force
D.Ransomware encryption
AnswerC

TCP port 3389 is used by Remote Desktop Protocol (RDP). Repeated inbound connection attempts from multiple external IP addresses suggest a brute-force attack attempting to guess credentials for RDP access. This is a common attack vector for gaining unauthorized remote access to Windows systems. Monitoring and blocking such attempts is critical to prevent compromise.

Why this answer

TCP port 3389 is the default port for Remote Desktop Protocol (RDP). Repeated inbound connection attempts from multiple external IP addresses indicate an RDP brute-force attack, where attackers try to guess credentials to gain remote access. This is a common and dangerous attack, as successful compromise can lead to full system control.

Other attack types do not match the described network behavior.

Exam trap

The trap here is assuming that any repeated connection attempts constitute a DoS attack, but the specific targeting of port 3389 points to RDP brute force rather than volumetric flooding.

38
Multi-Selectmedium

A security administrator is hardening a new Linux web server before it is placed into production. Which TWO practices reduce the attack surface of the operating system itself? (Choose two.)

Select 2 answers
A.Install a host-based intrusion prevention system and configure it to alert only.
B.Enable full-disk encryption on the server's data volumes.
C.Enforce least privilege by removing unnecessary administrative rights and using dedicated service accounts with minimal permissions.
D.Remove or disable unnecessary services, daemons, and open ports that are not required for the server's role.
E.Schedule weekly full backups of the server to a remote location.
AnswersC, D

Limiting administrative rights and running services under dedicated low-privilege accounts constrains what an attacker can do after gaining a foothold. It reduces the number of accounts and processes capable of modifying the system or escalating privileges. This directly shrinks the exploitable surface and limits blast radius, making it a core hardening practice.

Why this answer

Reducing the operating system's attack surface means removing or disabling anything not required for the server's role and limiting the privileges available to users and services. Eliminating unnecessary daemons and ports removes entry points, while least privilege and dedicated service accounts constrain what an attacker can do if one is reached. Encryption, alert-only intrusion prevention, and backups address confidentiality, detection, or recovery rather than shrinking the exploitable surface.

Exam trap

The trap here is equating any security control, such as encryption or backups, with attack-surface reduction, when only removing exposed functionality and limiting privileges actually shrink what an attacker can target.

39
MCQhard

During an incident, an analyst collects a forensic image of a compromised server's disk. The organization's policy requires preserving evidence for potential legal proceedings. Which action best maintains the integrity of the collected evidence?

A.Analyze the original disk in place to avoid copying errors.
B.Delete non-relevant files from the image to reduce size before storage.
C.Compress the image with a password to prevent tampering.
D.Compute and document a cryptographic hash of the image immediately after acquisition.
AnswerD

Hashing the forensic image at acquisition creates a verifiable fingerprint. If the hash is recomputed later and matches, it demonstrates the image has not been altered. This supports admissibility and chain-of-custody requirements because any change would produce a different value. Documenting the hash alongside acquisition details lets independent examiners confirm the copy is a faithful representation of the original media.

Why this answer

Cryptographic hashing at the time of acquisition establishes a verifiable baseline for the forensic image. Any later modification changes the hash, so a match confirms integrity. This practice, combined with documented chain of custody, supports the reliability of evidence in legal contexts.

Working from a verified copy rather than the original also protects the source media, and preserving the full image without deletions ensures nothing is lost.

Exam trap

The trap here is assuming that encryption or access restrictions equal integrity, when only a hash comparison can demonstrate the evidence has not changed.

40
MCQhard

A security operations center (SOC) receives an alert about a possible insider threat. An employee in the finance department has been accessing large amounts of sensitive data outside of normal working hours and emailing it to a personal external email address. The SOC manager asks the analyst to preserve evidence for a potential legal case. Which of the following should the analyst do FIRST to ensure the evidence is admissible?

A.Document the chain of custody for all evidence collected.
B.Create a forensic image of the employee's workstation hard drive.
C.Confront the employee and ask for an explanation.
D.Disable the employee's network access immediately.
AnswerA

Documenting the chain of custody is essential for evidence admissibility. It records who handled the evidence, when, and how, ensuring integrity. This should be done from the moment evidence is identified and collected. It is the first step to ensure that any evidence gathered later can be traced and trusted in legal proceedings.

Why this answer

For evidence to be admissible in a legal case, a proper chain of custody must be established and documented from the outset. This ensures that the evidence has not been tampered with and can be traced from collection to presentation. While imaging and containment are important, they come after initiating the chain of custody to maintain integrity.

Exam trap

The trap here is focusing on technical steps like imaging or containment, which are important, but overlooking that legal admissibility hinges first on a documented chain of custody.

41
Multi-Selectmedium

A company is building an incident response capability and wants to ensure the containment phase is effective. Which TWO activities are appropriate during containment? (Choose two.)

Select 2 answers
A.Applying temporary firewall or access-control rules to block the attacker's known infrastructure
B.Deleting all logs from affected systems to prevent the attacker from covering their tracks
C.Isolating affected hosts from the network while preserving evidence
D.Closing the incident ticket and notifying customers that service has resumed
E.Rebuilding every server in the data center from scratch immediately
AnswersA, C

Blocking confirmed malicious addresses, domains, or ports at perimeter and internal controls is a standard containment measure. It raises the attacker's cost and cuts off command-and-control or exfiltration paths while the team investigates. Because these rules are temporary and reversible, they limit disruption. This directly reduces ongoing impact and is appropriate during containment rather than waiting for full eradication.

Why this answer

Containment stops the spread and limits damage while keeping evidence intact for analysis. Isolating affected hosts and blocking the attacker's known infrastructure both reduce ongoing impact and are reversible, temporary measures. Rebuilding everything, closing the incident, or deleting logs are recovery or destructive actions that either destroy evidence or prematurely end the response, so they do not belong in containment.

Exam trap

The trap here is confusing containment with recovery, so drastic actions like rebuilding all systems or closing the incident get chosen when the goal is only to stop the spread and preserve evidence.

42
MCQmedium

A security administrator is configuring a Linux web server and wants to ensure that only encrypted administrative sessions are allowed, while also preventing direct root logins over the network. Which of the following should the administrator implement?

A.Enable Telnet with strong password policies and disable the root account.
B.Implement a VPN for all server traffic and allow root logins only from the local console.
C.Configure a host-based firewall to allow only HTTP and HTTPS traffic and disable SSH.
D.Enable SSH with PermitRootLogin set to no and restrict access to the management subnet.
AnswerD

SSH provides encrypted administrative sessions, and setting PermitRootLogin to no prevents direct root logins over the network. Restricting access to the management subnet further reduces the attack surface. This combination directly addresses the requirements of encrypted management and no direct root access, making it the correct choice for securing the Linux web server.

Why this answer

The requirement is to allow only encrypted administrative sessions and prevent direct root logins. SSH is the standard encrypted remote administration protocol on Linux. Setting PermitRootLogin to no blocks direct root access over SSH, and restricting access to a management subnet adds defense in depth.

Together, these measures meet both conditions without disrupting necessary administration.

Exam trap

The trap here is assuming that any remote access method with strong passwords is sufficient, while overlooking that Telnet is unencrypted and thus fails the encryption requirement.

43
MCQeasy

A security administrator is configuring a firewall rule to allow only HTTP and HTTPS traffic from the internal network to the internet. Which port numbers should be permitted?

A.TCP 53 and UDP 53
B.TCP 80 and TCP 443
C.TCP 21 and TCP 22
D.TCP 25 and TCP 110
AnswerB

HTTP uses TCP port 80, and HTTPS uses TCP port 443. Allowing these ports enables standard web browsing and secure web traffic. This is a common firewall configuration to permit outbound web access while blocking other potentially risky ports. The administrator should also consider application-layer filtering for additional security, but the correct port numbers are 80 and 443.

Why this answer

HTTP operates on TCP port 80, and HTTPS operates on TCP port 443. To allow only web traffic, the firewall must permit these ports. Other ports correspond to different services such as FTP, SSH, SMTP, POP3, or DNS, which are not required for web browsing.

Therefore, the correct ports are 80 and 443.

Exam trap

The trap here is selecting ports for common internet services like DNS or email, but the question specifically asks for HTTP and HTTPS, which are exclusively port 80 and 443.

44
MCQmedium

A critical zero-day vulnerability is actively being exploited in the wild, affecting an organization's internet-facing application. Which patching approach should be taken?

A.Isolate the application from the network and wait for a vendor patch.
B.Deploy an emergency patch without testing.
C.Implement a web application firewall (WAF) as a permanent solution.
D.Follow the standard patch lifecycle with testing.
AnswerB

Deploying an emergency patch without testing is the appropriate response due to the immediate and severe threat posed by a critical zero-day vulnerability actively being exploited in the wild. The paramount concern is to halt active exploitation and prevent further compromise as quickly as possible. While rigorous testing is normally crucial, the urgency of stopping an ongoing attack outweighs the risks associated with an untested deployment, directly addressing the constraint of mitigating an active, critical threat.

Why this answer

When a zero-day vulnerability is actively exploited in the wild against an internet-facing application, the risk of waiting for full testing outweighs the risk of deploying an untested emergency patch. An emergency patch (or vendor hotfix) is deployed immediately with expedited change approval, because the active exploitation represents an imminent, ongoing threat that standard change-management timelines cannot accommodate.

Exam trap

CC often tests whether candidates default to 'always test before deploying' — but when a zero-day is actively exploited, the correct answer is the emergency patch without full testing, because the standard lifecycle's delay is itself the greater risk.

How to eliminate wrong answers

Option A is wrong because isolating the application from the network may break business functionality and does not remediate the vulnerability — it only reduces exposure while leaving the system unpatched. Option C is wrong because a WAF is a compensating control, not a permanent fix; it can be bypassed and does not address the underlying code flaw, so it cannot replace patching. Option D is wrong because following the standard patch lifecycle with full testing introduces unacceptable delay when the vulnerability is being actively exploited — the standard lifecycle is for routine patches, not emergency zero-days.

45
MCQeasy

An organization wants to ensure that only authorized devices can connect to its corporate Wi-Fi network. The security team decides to implement a solution that requires devices to authenticate before being granted network access. Which technology should they use?

A.MAC address filtering
B.WPA3-SAE with a shared password
C.WPA2-Personal with a pre-shared key
D.802.1X with a RADIUS server
AnswerD

802.1X is an IEEE standard for port-based network access control that requires devices to authenticate via a RADIUS server before gaining network access. It supports per-device credentials, certificates, or other methods, ensuring only authorized devices connect. This is the appropriate solution for corporate Wi-Fi networks requiring strong authentication.

Why this answer

802.1X with a RADIUS server provides port-based network access control, requiring each device to authenticate before being granted access. It supports various authentication methods such as certificates or credentials, making it ideal for ensuring only authorized devices connect to corporate Wi-Fi. Other options like pre-shared keys or MAC filtering are weaker and not scalable for enterprise use.

Exam trap

The trap here is confusing WPA3-SAE, which is a strong encryption protocol, with network access control; it still uses a shared password and does not authenticate individual devices.

46
MCQmedium

An attacker used stolen credentials from a phishing campaign to authenticate to a cloud email account. The organization's incident response team wants to immediately stop the attacker from continuing to access the mailbox while preserving evidence for investigation. Which action best meets both goals?

A.Disable the account in the identity provider, then export the mailbox audit log and sign-in logs to a secure evidence repository.
B.Delete the mailbox and recreate it for the legitimate user, then reset the user's password.
C.Change the user's password and enable self-service password reset so the user can regain access quickly.
D.Add the attacker's IP address to the firewall block list and continue monitoring the mailbox for suspicious activity.
AnswerA

Disabling the account in the identity provider immediately revokes the attacker's ability to authenticate while leaving the mailbox and logs intact for forensic review. Exporting audit and sign-in logs to a secure repository preserves volatile evidence before it ages out or is altered. This combination contains the threat without destroying data needed to determine scope.

Why this answer

The most effective containment combines immediate revocation of access with preservation of forensic data. Disabling the account in the identity provider stops the attacker from authenticating again, while exporting audit and sign-in logs captures evidence before it rotates or is lost. Destructive actions like deleting the mailbox, or partial measures like a password change or IP block, either harm the investigation or fail to reliably stop the attacker.

Exam trap

The trap here is assuming that changing the user's password immediately terminates all active sessions and tokens, when many identity platforms allow existing sessions to persist until explicitly revoked.

47
MCQmedium

Which of the following is the most effective way to prevent tailgating in a secured facility?

A.Training employees to not hold doors open for unknown individuals.
B.Installing security cameras at all entrances.
C.Using keycard access for all doors.
D.Hiring security guards to monitor entrances.
AnswerA

Tailgating exploits social courtesy, so training employees to challenge or refuse entry to unfamiliar individuals removes the human behaviour attackers rely on. This directly addresses the unauthorised-follow-in vector, which locks and turnstiles alone cannot prevent.

Why this answer

Tailgating exploits social trust — an attacker follows an authorized person through a door. Training employees to challenge and not hold doors for unknown individuals directly addresses the human behavior that enables tailgating, making it the most effective preventive control. Technical controls alone cannot stop a person who is willingly allowed through.

Exam trap

The trap is choosing a technical control (cameras, keycards, guards) when the question asks for the 'most effective' prevention of a human-behavior attack — CC exams emphasize that training addresses the root cause.

How to eliminate wrong answers

Option B is wrong because cameras are detective, not preventive — they record the event but do not stop the tailgater, and footage is reviewed after the fact. Option C is wrong because keycard access controls who can open a door but does nothing to stop a second person from walking through behind an authorized user. Option D is wrong because security guards are effective only if they are physically positioned at every entrance and actively challenge people, which is costly and inconsistent; training scales better and addresses the root cause.

48
MCQeasy

An employee receives an email from an unknown sender claiming to be from the IT department, asking for their password to perform an urgent system update. What type of social engineering attack is this?

A.Phishing
B.Tailgating
C.USB drop attack
D.Piggybacking
AnswerA

The message impersonates the IT department and pressures the recipient to disclose credentials urgently, which is phishing: fraudulent email harvesting sensitive data. It satisfies the stem's description, distinguishing it from vishing or pretexting conducted by other channels.

Why this answer

Phishing is a social engineering attack where an attacker sends a fraudulent email, often impersonating a trusted entity like the IT department, to trick the recipient into revealing sensitive information such as passwords. The scenario describes an email from an unknown sender claiming to be from IT and requesting a password, which is a classic phishing attempt. The other options involve physical or direct access tactics.

Exam trap

The trap is confusing phishing with other social engineering methods like tailgating or USB drops; candidates may pick tailgating if they focus on 'unknown sender' but miss that the attack vector is email.

How to eliminate wrong answers

Option B is wrong because tailgating involves an unauthorized person following an authorized individual into a secure physical area, not an email-based attack. Option C is wrong because a USB drop attack relies on leaving infected USB drives for victims to plug in, not email deception. Option D is wrong because piggybacking is similar to tailgating, where someone gains physical access by following an authorized person, often with their consent, but still not an email attack.

49
MCQmedium

A security analyst is reviewing access logs and notices that a former employee's account was used to access a sensitive file share three days after the employee's termination. The account should have been disabled on the termination date. Which of the following is the MOST likely explanation for this security gap?

A.The file share permissions were not updated to remove the former employee's access.
B.The account was not disabled in the directory service after termination.
C.The file share was configured to allow anonymous access.
D.The former employee's password was not changed before termination.
AnswerB

If the account was not disabled in the directory service, it remains active and can be used to authenticate and access resources. This directly explains how the former employee's account could access the file share after termination. The most likely explanation is a failure in the account deprovisioning process.

Why this answer

The access logs show the former employee's account was used after termination. The most direct explanation is that the account was not disabled in the directory service, allowing authentication. While file share permissions and password changes are part of offboarding, the failure to disable the account is the root cause that enabled the access.

Exam trap

The trap here is focusing on file share permissions or password changes, while overlooking that an active account is the prerequisite for any authenticated access.

50
MCQmedium

What is the primary purpose of using security baselines derived from CIS Benchmarks?

A.To ensure all systems have the same software versions
B.To monitor network traffic for anomalies
C.To automate patch deployment
D.To establish a secure starting point for system configuration
AnswerD

CIS Benchmarks encode consensus hardening settings, so applying them yields a documented, secure starting configuration rather than a bespoke one. This satisfies the stem's aim of a repeatable baseline against which drift and deviations can be measured and remediated.

Why this answer

CIS Benchmarks provide consensus-based, prescriptive hardening guidance for operating systems, applications, and cloud platforms. Applying them establishes a known-secure baseline configuration from which deviations can be detected and remediated, reducing the attack surface before systems go into production. The baseline is a starting point, not a version-control or monitoring mechanism.

Exam trap

The trap here is confusing 'baseline' with 'standardization' — candidates pick the software-version answer because it sounds like consistency, but a security baseline is about configuration hardening, not version parity.

How to eliminate wrong answers

Option A is wrong because CIS Benchmarks do not enforce identical software versions across systems — that is a configuration management or golden-image concern, and version uniformity is neither the goal nor a requirement of benchmarking. Option B is wrong because traffic anomaly monitoring is the role of IDS/IPS or SIEM tooling, not configuration baselines. Option C is wrong because patch deployment is handled by patch management systems (WSUS, SCCM, Ansible); CIS Benchmarks define secure settings, not patch orchestration.

51
MCQhard

A security analyst is reviewing logs from a Linux web server and notices the following entries: multiple failed SSH login attempts for user 'root' from various IP addresses, followed by a successful login from an IP address in a different country. Shortly after, a new user account 'backup' is created and added to the sudoers file. Which type of attack is MOST likely represented?

A.Distributed denial of service (DDoS)
B.SQL injection
C.Brute force attack leading to privilege escalation
D.Cross-site scripting (XSS)
AnswerC

The multiple failed SSH logins for root from various IPs indicate a brute force attempt. The subsequent successful login from a foreign IP and creation of a new sudo-enabled account show that the attacker gained access and escalated privileges. This pattern is classic for a brute force attack followed by persistence establishment.

Why this answer

The sequence of multiple failed SSH logins followed by a successful login from a foreign IP and the creation of a sudo-enabled account strongly indicates a brute force attack that succeeded, leading to privilege escalation. This is a common attack chain where initial access is gained through weak credentials, and persistence is established via a new privileged user.

Exam trap

The trap here is focusing on the failed logins alone and missing the subsequent successful login and account creation, which together reveal a successful brute force and privilege escalation.

52
MCQmedium

A company wants to reduce the risk of malware spreading from employee workstations to critical servers. The security team proposes placing firewalls between network segments and restricting traffic to only required ports and protocols. Which security control category does this approach primarily represent?

A.Administrative control
B.Physical control
C.Technical control
D.Compensating control
AnswerC

Technical controls are implemented through systems and devices, such as firewalls, intrusion prevention systems, and access control lists. Placing firewalls between segments and permitting only necessary ports and protocols is a technical enforcement mechanism. It limits lateral movement automatically based on configured rules, which is characteristic of a technical rather than administrative or physical safeguard, and it directly reduces the blast radius of an infected workstation.

Why this answer

Network segmentation enforced by firewalls and port restrictions is implemented through technology, making it a technical control. It limits how malware can move laterally from workstations to critical servers by permitting only required traffic. Unlike administrative controls that depend on policies and training, or physical controls that restrict access to facilities, this approach enforces boundaries automatically.

Segmenting systems and minimizing allowed protocols reduces the attack surface and contains incidents.

Exam trap

The trap here is assuming segmentation is administrative because a policy may mandate it, when the actual enforcement mechanism is a technical device applying rules to traffic.

53
MCQeasy

A junior administrator at a healthcare company receives a call from someone claiming to be from the IT help desk. The caller says there is a critical server issue and asks the administrator to read back the six-digit code just sent to their phone. The administrator has not requested any password reset or MFA challenge. Which social engineering principle is the caller most likely exploiting?

A.Reciprocity, because the caller previously helped the administrator with a ticket and now expects a favor in return.
B.Consensus, because the caller claims that other administrators have already shared their codes to fix the same problem.
C.Authority combined with urgency, because the caller impersonates support staff and pressures the administrator to act immediately.
D.Scarcity, because the caller implies that only a limited number of support slots are available for the server repair.
AnswerC

The caller claims to be help desk staff and invents a critical server issue to create time pressure. This is a classic pretext that leverages authority and urgency so the victim bypasses normal verification. Because the administrator did not initiate the MFA challenge, sharing the code would hand over a second factor and allow account takeover. Recognizing unsolicited authority claims is a core security operations skill.

Why this answer

The caller fabricates a critical server problem while posing as help desk personnel, which combines impersonated authority with manufactured urgency. Because the administrator never initiated an MFA challenge, no legitimate support process would require the code to be read aloud. The correct response is to refuse, hang up, and verify through a known internal channel.

This scenario tests recognition of pretexting and MFA code theft.

Exam trap

The trap here is treating any request for an MFA code as routine support activity instead of recognizing that unsolicited code requests are a hallmark of social engineering.

54
MCQmedium

A security operations center receives an alert that a workstation is communicating with a known command-and-control (C2) IP address every 60 seconds at consistent intervals. The endpoint detection and response (EDR) agent has not flagged any malicious files on the host. Which type of malware behavior BEST describes this activity?

A.Ransomware encryption
B.Privilege escalation
C.Beaconing
D.SQL injection
AnswerC

Beaconing is periodic, regular communication with a C2 server, exactly matching the 60-second intervals observed here. Malware uses this heartbeat to receive commands and exfiltrate data while blending into normal traffic. Because no malicious file was flagged, the network pattern is the strongest indicator, making beaconing the correct characterization of this activity.

Why this answer

Regular, fixed-interval outbound connections to a known malicious address indicate beaconing, the heartbeat malware uses to maintain C2 communications. Because EDR found no malicious files, the network timing pattern becomes the key detection signal. Recognizing beaconing helps analysts identify stealthy implants that have evaded file-based detection and initiate containment before data theft or lateral movement occurs.

Exam trap

The trap here is assuming that because the EDR agent found no malicious files, no malware is present, overlooking the network-level beaconing pattern.

55
MCQhard

An organization implements a security baseline using CIS Benchmarks for all new servers. After a routine scan, a server is found to have a configuration that deviates from the baseline. The deviation was introduced by a system administrator to resolve a performance issue. What is the best course of action?

A.Ignore the deviation since it was done for a valid reason
B.Revert the change immediately without discussion
C.Update the baseline to match the new configuration
D.Document the change and submit it through the change control process
AnswerD

The deviation was a deliberate, justified performance fix, so reverting it blindly risks reintroducing the issue. Documenting the change and routing it through change control preserves the audit trail while allowing the baseline exception to be formally reviewed and approved.

Why this answer

The correct answer is D. When a deviation from a security baseline is introduced for a legitimate operational reason, the proper governance response is to document the change and route it through the change control process. This preserves the integrity of the baseline while allowing a formally reviewed and approved exception, ensuring the deviation is tracked, justified, and periodically reassessed rather than silently accepted or blindly reverted.

Exam trap

The trap here is the temptation to treat a 'valid reason' as sufficient justification to either ignore the deviation or update the baseline, when the exam expects recognition that any deviation must go through formal change control.

How to eliminate wrong answers

Option A is wrong because ignoring the deviation leaves an undocumented, unapproved configuration change in place, undermining the baseline's authority and auditability. Option B is wrong because reverting immediately without discussion ignores the valid performance justification and may reintroduce the original performance issue without proper review. Option C is wrong because updating the baseline to match a single server's ad-hoc change bypasses change control and could weaken the security posture for all systems if the change is not appropriate as a standard.

56
MCQeasy

Which tier in a Security Operations Center (SOC) is primarily responsible for triaging alerts and determining whether to escalate?

A.SOC Manager
B.Tier 3
C.Tier 2
D.Tier 1
AnswerD

Tier 1 analysts perform initial alert triage, validating whether an alert is a true positive and deciding escalation to Tier 2. This matches the stem's requirement for the tier that triages and determines escalation, distinguishing it from Tier 2 investigation and Tier 3 threat hunting.

Why this answer

Tier 1 analysts are the first line of defense in a SOC, responsible for monitoring incoming alerts, performing initial triage, and deciding whether to escalate to Tier 2. They follow predefined playbooks to filter false positives and validate true positives. This role is explicitly designed for rapid alert assessment, not deep investigation or management.

Exam trap

The trap here is confusing the roles of different SOC tiers, especially assuming that higher tiers (Tier 2 or 3) handle initial triage because they are more skilled, when in fact Tier 1 is specifically designed for that first-line responsibility.

How to eliminate wrong answers

Option A is wrong because the SOC Manager oversees the entire SOC, including staffing, processes, and reporting, but does not perform hands-on alert triage. Option B is wrong because Tier 3 analysts are the most advanced, focusing on threat hunting, malware analysis, and complex incident response, not initial triage. Option C is wrong because Tier 2 analysts handle escalated incidents requiring deeper investigation, not the first-pass triage of raw alerts.

57
Multi-Selecthard

A security operations center (SOC) analyst is reviewing network traffic logs and notices a series of connections to an unfamiliar external IP address on port 443. The analyst suspects a command-and-control (C2) channel. Which TWO characteristics would most likely indicate that this traffic is malicious C2 activity? (Choose two.)

Select 2 answers
A.The traffic uses domain fronting to hide the true destination.
B.The connections are initiated by a server process running as a system service.
C.The traffic is encrypted and uses a self-signed certificate.
D.The traffic occurs at regular intervals with consistent packet sizes.
E.The external IP address is associated with a known cloud service provider.
AnswersA, D

Domain fronting is a technique where the SNI and HTTP Host header differ, allowing traffic to appear as if it is destined for a legitimate domain while actually communicating with a different server. This is commonly used by malware to evade detection. Its presence is a strong indicator of malicious C2 activity, making this a correct characteristic.

Why this answer

Beaconing behavior, such as regular intervals with consistent packet sizes, is a hallmark of automated C2 communication. Domain fronting, which disguises the true destination by manipulating SNI and Host headers, is another technique frequently used by malware to evade network defenses. Both are strong indicators of malicious C2 activity, whereas cloud-hosted IPs, service-initiated connections, and self-signed certificates can also be legitimate.

Exam trap

The trap here is assuming that any encrypted traffic to an unfamiliar IP is malicious, when encryption and self-signed certificates are also common in legitimate internal and cloud services.

58
MCQeasy

Which of the following is a key function of a Security Information and Event Management (SIEM) system?

A.Blocking malicious network traffic
B.Correlating log data from multiple sources to identify security incidents
C.Enforcing password complexity requirements
D.Patching vulnerabilities in operating systems
AnswerB

SIEM platforms aggregate and normalise logs from disparate sources, then apply correlation rules to link related events across systems. This cross-source correlation is what surfaces incidents that isolated log review would miss, satisfying the question's requirement for a key SIEM function.

Why this answer

SIEM aggregates and correlates logs from various sources to detect patterns and generate alerts.

59
Multi-Selectmedium

A security awareness trainer is developing material on USB drop attacks. Which TWO messages should be included in the training? (Choose two.)

Select 2 answers
A.Use the USB drive only on a non-networked computer.
B.Never plug in a USB drive that you found lying around.
C.Always scan a found USB drive with antivirus before using.
D.Report any discovered USB drives to the security team.
E.Format the USB drive before using it.
AnswersB, D

Refusing to plug in found drives removes the attack vector entirely, since the malicious payload executes only on connection. This satisfies the stem's training-message requirement by targeting the physical action the USB drop attack depends upon, before any autorun or HID emulation can trigger.

Why this answer

Option B is correct because the core defense against USB drop attacks (such as BadUSB or HID-spoofing devices that emulate keyboards) is simply never inserting an unknown drive into any system, since malicious firmware can execute before any OS-level controls apply. Option D is correct because reporting found drives to the security team allows them to be safely collected and analyzed as potential threat indicators, and it removes the drive from the environment so others are not tempted to plug it in. Options A, C, and E do not belong: using the drive on a non-networked computer still exposes that host to malicious firmware or autorun payloads, antivirus scanning cannot detect firmware-level or HID-emulation attacks and may itself trigger the payload, and formatting a drive does not neutralize malicious controller firmware and requires plugging it in first.

Exam trap

CC often tests the misconception that scanning or formatting a found USB drive makes it safe; candidates may choose these options because they seem like reasonable precautions, but the only safe action is to not plug it in and report it.

60
Multi-Selecthard

A security engineer is designing a patch management process. Which TWO steps are part of the standard patch lifecycle? (Select TWO)

Select 2 answers
A.Vulnerability disclosure by researcher
B.Decommissioning the vulnerable system
C.Testing the patch in a staging environment
D.Deploying the patch to production systems after approval
E.Immediately deploying patches to all systems
AnswersC, D

Staging validation installs the patch in a non-production environment to confirm it remediates the vulnerability without breaking applications. This is a recognised patch lifecycle step, satisfying the stem's requirement for a standard lifecycle activity performed before production deployment.

Why this answer

Option C (Testing the patch in a staging environment) is correct because the standard patch lifecycle includes a validation phase where patches are applied to a representative non-production environment to verify functionality, compatibility, and absence of regressions before wide deployment. Option D (Deploying the patch to production systems after approval) is correct because the lifecycle's deployment phase requires formal change approval and controlled rollout to production, often staged in rings or waves to limit blast radius. Option A is not part of the patch lifecycle itself; vulnerability disclosure is an input from the vulnerability management/research process that may trigger patching but is not a lifecycle step.

Option B is incorrect because decommissioning a system is a risk remediation alternative, not a patch lifecycle step. Option E is incorrect because immediately deploying patches to all systems bypasses testing and approval, violating change management and increasing the risk of outages or failed patches.

Exam trap

CC often tests the patch lifecycle steps, and candidates may incorrectly include vulnerability disclosure or immediate deployment as steps; the trap is confusing triggers or emergency actions with standard lifecycle phases.

61
MCQhard

A security administrator must configure a system so that users prove their identity with something they have plus something they know, without deploying smart cards or hardware tokens. Which authentication approach best meets this requirement?

A.A fingerprint scan used alone to unlock the workstation
B.A password combined with a security question about the user's first pet
C.A password combined with a one-time code generated by a soft token app on the user's phone
D.A username and a strong password used together
AnswerC

A password is something the user knows, and a one-time code produced by an app on their enrolled phone is something the user possesses. Because the app runs on a device rather than dedicated hardware, this meets the two-factor requirement without smart cards or physical tokens. The two factors come from different categories, which is precisely what the scenario demands.

Why this answer

Two-factor authentication requires factors from different categories. A password supplies the knowledge factor, and a one-time code from an app on the user's enrolled phone supplies the possession factor. Because the app is software rather than dedicated hardware, no smart card or physical token is needed, which satisfies the constraint while still delivering genuine two-factor protection.

Exam trap

The trap here is counting two prompts as two factors, when a password plus a security question or two passwords are both knowledge-based and count as only one factor category.

62
MCQeasy

An employee receives an email that appears to be from the IT department asking them to click a link and verify their password because of a mailbox upgrade. The link points to a domain that is misspelled but closely resembles the company's real domain. The employee reports it to the security team. What type of attack is this?

A.Phishing
B.Vishing
C.Spear phishing
D.Whaling
AnswerA

This is a classic phishing attempt: a fraudulent email impersonating IT, using a look-alike domain to trick the recipient into revealing credentials. The generic nature and the urgency of a mailbox upgrade are common phishing tactics. Phishing is the broad category that accurately describes this untargeted credential-harvesting attack.

Why this answer

The email impersonates IT, uses a deceptive domain, and requests credential verification, which are hallmarks of phishing. It is not targeted enough to be spear phishing or whaling, and it does not use voice communication. Phishing remains the most accurate classification for this generic credential-harvesting attempt.

Exam trap

The trap here is overcomplicating the classification by focusing on the employee recipient, when the attack lacks the personalization of spear phishing and is simply a generic phishing email.

63
Multi-Selectmedium

A security operations center wants to improve detection of malicious activity on endpoints. Which TWO data sources provide the most direct endpoint-level evidence for identifying suspicious process execution? (Choose two.)

Select 2 answers
A.Endpoint detection and response (EDR) telemetry
B.Firewall deny logs
C.NetFlow records
D.DHCP lease logs
E.Operating system process accounting or audit logs
AnswersA, E

EDR collects process creation, command-line arguments, parent-child relationships, file and registry changes, and network connections from the endpoint. This telemetry directly shows what executed and how, making it the strongest source for spotting suspicious process behavior such as an office document spawning a scripting interpreter. It also supports historical hunting, so analysts can trace the full execution chain rather than only a single alert.

Why this answer

Detecting suspicious process execution requires host-based visibility into what actually ran. EDR telemetry provides rich process-level detail including command lines and parent-child relationships, while OS process accounting or audit logs offer a lighter but still direct record of executions. Network-oriented sources such as NetFlow, firewall deny logs, and DHCP lease logs describe traffic or addressing, not the processes on the endpoint, so they serve as supporting context rather than primary execution evidence.

Exam trap

The trap here is treating network metadata as equivalent to host telemetry; only sources that record executions on the endpoint directly answer what process ran.

64
Multi-Selecteasy

Which TWO of the following are common indicators of a phishing email?

Select 2 answers
A.Professional formatting with correct grammar
B.Presence of a file attachment
C.Use of the recipient's full name in the greeting
D.Unexpected sender or email address
E.Urgent language requesting immediate action
AnswersD, E

A sender address that does not match the purported organisation, or arrives unexpectedly, indicates spoofing or domain impersonation. This satisfies the stem's indicator criterion because legitimate correspondence normally originates from a recognisable, expected address, making the mismatch a reliable phishing signal.

Why this answer

Option D is correct because phishing emails frequently originate from spoofed or look-alike domains that the recipient does not recognize, so an unexpected sender or mismatched email address is a classic red flag. Option E is correct because attackers rely on social engineering that creates urgency—phrases like "act now" or "your account will be closed"—to pressure victims into clicking links or disclosing credentials before they scrutinize the message. In contrast, option A is not an indicator since professional formatting and correct grammar are typical of legitimate email and, if anything, poor grammar is the more common phishing clue.

Option B is not reliable because legitimate business email routinely carries attachments, so an attachment alone proves nothing. Option C is likewise not an indicator, as using the recipient's full name is normal, personalized behavior in genuine correspondence and does not by itself signal phishing.

Exam trap

The trap is selecting options that seem 'suspicious' in general (like attachments or full-name greetings) without recognizing that phishing indicators must be specific anomalies — attachments and personalization are common in legitimate email, so only the unexpected sender and urgency are reliable indicators.

65
MCQmedium

A security analyst notices repeated failed login attempts from an internal IP address to a domain controller, followed by a successful login. Which log type is most likely to provide detailed evidence of this activity?

A.Application logs
B.Firewall logs
C.System logs
D.Authentication logs
AnswerD

Authentication logs capture the granular Kerberos and NTLM events on the domain controller, recording each failed attempt (Event ID 4625) and the subsequent successful logon (Event ID 4624) with source IP, account name and logon type. This directly satisfies the stem's requirement for detailed evidence of the brute-force pattern.

Why this answer

Authentication logs record login attempts, successes, failures, source IP addresses, timestamps, and account names, making them the definitive source for investigating repeated failed logins followed by a successful login. Domain controllers log authentication events (e.g., Windows Security Event ID 4625 for failed logon and 4624 for successful logon) that directly capture this pattern. This is the primary evidence source for credential-based attacks like brute force or password spraying.

Exam trap

The trap is assuming firewall logs capture login activity because they show IP addresses and connection attempts — candidates must recognize that only authentication logs record the success/failure outcome of credential-based logon events.

How to eliminate wrong answers

Option A is wrong because application logs record events within a specific application (errors, transactions, user actions) and would not typically capture domain controller authentication events across the network. Option B is wrong because firewall logs record network traffic flows (allowed/blocked connections, ports, IPs) but do not show whether a login succeeded or failed at the authentication layer. Option C is wrong because system logs record OS-level events like service starts, driver loads, and hardware errors — not user authentication activity, which is captured in security/authentication logs.

66
Multi-Selectmedium

An organization is building a log management capability so its security team can detect and investigate incidents across many systems. Which TWO practices BEST support effective centralized log collection and analysis? (Choose two.)

Select 2 answers
A.Forward logs to a central repository with integrity protection and controlled access
B.Disable logging on high-traffic servers to reduce storage costs
C.Store all logs only on the local systems that generate them
D.Synchronize clocks across all systems using a consistent time source such as NTP
E.Allow every administrator to modify log settings without change control
AnswersA, D

Centralizing logs with integrity protection and restricted access preserves evidence and enables cross-system correlation. If a source host is compromised, its forwarded records remain intact elsewhere. Access controls prevent tampering or unauthorized viewing. This combination directly supports detection and investigation, making it a core practice for effective centralized log collection and analysis across a diverse environment.

Why this answer

Effective centralized logging depends on trustworthy, correlated data. Synchronized clocks make cross-source timelines reliable, while forwarding logs to a protected central repository preserves evidence even if a source host is compromised. Together these practices enable detection and investigation.

Local-only storage, disabled logging, and ungoverned configuration changes all create blind spots or permit tampering, defeating the purpose of centralization.

Exam trap

The trap here is focusing on storage cost or convenience and overlooking that clock synchronization and tamper-resistant central storage are what make logs usable as evidence.

67
MCQeasy

A new employee reports receiving an email that appears to come from the CEO, urgently requesting gift card purchases for a client. The email domain looks almost identical to the company's domain but uses a different top-level domain. Which type of social engineering attack is this?

A.Business email compromise (BEC) using a look-alike domain
B.Vishing using caller ID spoofing
C.Watering hole attack
D.Spear phishing with a malicious attachment
AnswerA

The scenario describes an attacker impersonating an executive and using a deceptively similar domain to pressure the recipient into an unauthorized financial action. This matches business email compromise, which often relies on spoofed or look-alike domains and urgency to bypass scrutiny. The gift card request is a classic BEC cash-out method rather than a technical exploitation technique.

Why this answer

The message impersonates an executive, uses a domain that closely resembles the real one, and pressures the recipient into an urgent financial action. That combination is the hallmark of business email compromise, specifically using a look-alike domain. Spear phishing, watering hole, and vishing describe different delivery methods or objectives and do not capture the executive impersonation and fraudulent payment request.

Exam trap

The trap here is labeling any targeted email as spear phishing and overlooking the executive impersonation and look-alike domain that specifically define business email compromise.

68
Multi-Selectmedium

A security analyst is reviewing firewall logs and notices an unusually high number of blocked outbound connections to a single external IP address. Which TWO actions should the analyst take to investigate this potential security incident? (Choose two.)

Select 2 answers
A.Check threat intelligence feeds for the external IP address.
B.Increase logging for all traffic to that IP.
C.Disable the firewall rule that is blocking the connections.
D.Block all outbound traffic from the source system.
E.Identify the internal system generating the connections.
AnswersA, E

Querying threat intelligence feeds establishes whether the external IP is a known command-and-control server, malware host or scanner. This reputation data satisfies the stem's need to determine malicious intent before escalating, letting the analyst prioritise the blocked outbound connections correctly.

Why this answer

Investigating the source system helps determine if it is compromised; checking threat intelligence can reveal if the IP is known malicious.

69
MCQhard

A security administrator is implementing measures to protect log integrity. Which of the following is the most effective method to prevent tampering with logs after they are generated?

A.Rotating logs daily
B.Encrypting logs with a symmetric key
C.Storing logs on the local system drive
D.Using write-once storage
AnswerD

Write-once storage enforces immutability at the media or object layer, so once a log entry is committed it cannot be altered or deleted, even by privileged accounts. This directly satisfies the requirement to prevent post-generation tampering rather than merely detecting it.

Why this answer

Write-once storage (WORM—write once, read many) prevents any modification or deletion of log data after it is written, which directly addresses tampering by making alteration physically or logically impossible. This is the strongest control because it enforces immutability at the storage layer rather than relying on cryptographic or procedural safeguards that can be bypassed if keys or access are compromised.

Exam trap

The trap is conflating confidentiality with integrity—candidates pick encryption because it sounds like a strong security control, but the question asks specifically about preventing tampering, which only immutability (write-once) guarantees.

How to eliminate wrong answers

Option A is wrong because rotating logs daily only manages file size and retention; it does not prevent an attacker with write access from modifying or deleting the current or archived log files. Option B is wrong because encrypting logs with a symmetric key protects confidentiality in transit or at rest, but anyone holding the key—or an attacker who compromises the host—can still decrypt, alter, and re-encrypt the logs, so integrity is not guaranteed. Option C is wrong because storing logs on the local system drive is the opposite of a protective measure; it makes logs vulnerable to local tampering, disk failure, and attacker deletion, which is why logs should be shipped to a remote, hardened log server.

70
MCQhard

A security analyst needs to ensure that log data cannot be altered after it is written. Which of the following is the most effective method to protect log integrity?

A.Storing logs on the same server as the application
B.Using a separate log server with read-only access
C.Implementing write-once storage for log files
D.Encrypting logs with a symmetric key
AnswerC

Write-once storage enforces immutability at the media or object layer, so once log data is written it cannot be modified or overwritten, even by compromised accounts. This directly satisfies the stem's requirement that log data cannot be altered after being written.

Why this answer

Write-once storage (WORM) physically prevents modification or deletion of log data after it is written, which is the strongest guarantee of log integrity. Because the media enforces immutability at the storage layer, even a compromised application or administrator cannot alter historical records.

Exam trap

The trap is equating encryption or read-only access with integrity; only write-once/immutable storage actually prevents post-write modification.

How to eliminate wrong answers

Option A is wrong because storing logs on the same server as the application means an attacker who compromises the host can modify or delete the logs. Option B is wrong because read-only access controls who can read but does not prevent an administrator or attacker with write privileges from altering the files. Option D is wrong because symmetric encryption protects confidentiality in transit or at rest but does not prevent someone with the key from decrypting, modifying, and re-encrypting the logs.

71
MCQmedium

A security administrator discovers that a former employee's user account still exists and remains enabled three weeks after their termination. The account has valid credentials and no recent logins. Which access control principle has been violated?

A.Separation of duties
B.Account lifecycle management
C.Defense in depth
D.Least privilege
AnswerB

Account lifecycle management covers provisioning, periodic review, and timely deprovisioning of accounts. When an employee is terminated, their account must be disabled or removed promptly. Leaving it enabled for weeks creates an unauthorized access path. The violation is specifically that the deprovisioning step of the lifecycle failed, leaving a live credential set for someone who no longer works there.

Why this answer

Proper account lifecycle management ensures accounts are created, reviewed, and removed in step with a person's employment status. A terminated employee retaining an enabled account violates the deprovisioning requirement. Even though the account shows no recent logins, the credential remains a live risk because it could be used by the former employee or anyone who obtained the password.

Timely disablement closes that exposure.

Exam trap

The trap here is assuming that because there were no recent logins the account is harmless, when the real issue is that an active credential for a non-employee should not exist at all.

72
Multi-Selecthard

After a security incident, an investigator needs to analyze logs to determine the timeline of events. Which TWO types of logs are most likely to provide evidence of lateral movement within the network?

Select 2 answers
A.DNS logs
B.Authentication logs
C.Firewall logs
D.System logs
E.Application logs
AnswersB, C

Authentication logs record sign-in events, credential use and directory queries, capturing the account and timestamp of each hop between systems. Microsoft Entra ID sign-in and audit logs therefore satisfy the timeline constraint directly, revealing when compromised credentials were reused against other hosts during lateral movement.

Why this answer

Authentication logs (B) are correct because they record logon events such as successful and failed authentications, Kerberos ticket requests, and remote logon types (e.g., Type 3 network logons in Windows Security event 4624), which directly reveal an attacker moving from one host to another using compromised credentials. Firewall logs (C) are correct because they capture allowed and denied connections between internal hosts and across network segments, letting an investigator trace internal-to-internal traffic and identify the source and destination of lateral movement. DNS logs (A) can show name resolution but do not by themselves prove a session or movement between hosts.

System logs (D) and application logs (E) may contain related events, but they are less directly indicative of network-based lateral movement than authentication and firewall records.

Exam trap

The trap is selecting DNS or system logs because they are commonly monitored; candidates must recognize that lateral movement is proven by authentication events plus internal network connections, not by name resolution or local OS events.

73
MCQeasy

An employee receives a call from someone claiming to be from the IT help desk. The caller says there is a problem with the employee's email and asks for the employee's password to fix it. The employee refuses and reports the call. Which social engineering technique was attempted?

A.Smishing
B.Tailgating
C.Vishing
D.Whaling
AnswerC

Vishing is voice phishing conducted over the telephone. The attacker impersonated IT support and tried to extract a password through a phone call. Because the attempt occurred by voice rather than email or text, vishing is the precise term. The employee correctly recognized that help desk staff never need a password and reported the call instead of complying.

Why this answer

Vishing uses voice communication, typically a phone call, to manipulate a target into revealing sensitive information or performing an action. The attacker posed as IT support and requested a password, which legitimate help desk personnel should never do. Recognizing the pretext and refusing to provide credentials is the correct response.

Reporting the call also helps security teams warn others about the active campaign.

Exam trap

The trap here is confusing the delivery channel, since the caller pretends to be IT support; the defining characteristic is that the request came by voice, not that the impersonation occurred.

74
MCQmedium

A security administrator receives an alert that a user's laptop has been infected with ransomware. The user reports that all files on the laptop are encrypted and a ransom note is displayed. The administrator immediately disconnects the laptop from the network. Which of the following should be the NEXT step in the incident response process?

A.Restore the encrypted files from the most recent backup.
B.Pay the ransom to obtain the decryption key and recover the files quickly.
C.Rebuild the laptop from scratch and return it to the user.
D.Identify the scope of the incident and preserve evidence.
AnswerD

After isolating the infected system, the next step is to determine how many other systems are affected and to preserve volatile evidence such as memory and logs. This aligns with the containment, eradication, and recovery phases of incident response. Identifying scope prevents further spread and informs subsequent eradication and recovery actions.

Why this answer

Once an infected system is isolated, the next critical step is to determine the full scope of the compromise and preserve evidence. This allows the organization to understand how the ransomware entered, what else may be affected, and how to eradicate it properly. Recovery actions such as restoring backups or rebuilding systems should come after containment and scoping are complete.

Exam trap

The trap here is assuming that recovery or eradication should happen immediately after isolation, when in fact the next step is to identify scope and preserve evidence to avoid incomplete containment.

75
MCQeasy

An organization wants to ensure that only authorized software can execute on its endpoints. A security administrator is evaluating application control methods. Which of the following is the BEST approach to meet this requirement?

A.Enable full disk encryption on all endpoints.
B.Deploy antivirus software with signature-based detection.
C.Use a blacklist of known malicious applications and allow all others.
D.Implement a whitelist of approved applications and block all others.
AnswerD

A whitelist (allowlist) explicitly permits only approved applications to run, blocking all others by default. This directly enforces the requirement that only authorized software executes. It is the most effective method for application control because it takes a deny-by-default stance, reducing the attack surface from unauthorized or malicious software.

Why this answer

The requirement is to allow only authorized software to execute. An application whitelist (allowlist) enforces this by permitting only explicitly approved applications and blocking all others. This deny-by-default approach is the most effective way to prevent unauthorized or malicious software from running, unlike blacklisting or antivirus, which rely on known signatures.

Exam trap

The trap here is confusing antivirus or blacklisting with application control; those methods do not ensure only authorized software runs, as they allow unknown or new software.

Ready to test yourself?

Try a timed practice session using only Cc Security Operations questions.