A security analyst notices multiple attempts of the same exploit being made on the perimeter network. The behavioral patterns indicate that a TCP SYN flood attack has been initiated, followed by a port scan of the company's public IP range. No other attacks are being performed from the actor's source IP address. All of the SYN flood attempts were thwarted by the firewall's stateful packet inspection engine. Which of the following is the most likely type of threat actor in this scenario?
A. Nation-state
B. Script kiddie
C. Advanced persistent threat
D. Organized crime
Show Answer
Correct Answer: B
Explanation: The described activity is a basic, noisy sequence consisting of a TCP SYN flood followed by a port scan from a single source IP, with no evidence of stealth, persistence, sophisticated exploitation, or financial motivation. Nation-state and APT actors typically use more targeted and evasive techniques, while organized crime is generally associated with financially motivated campaigns beyond simple reconnaissance and unsuccessful flooding. This pattern is most consistent with a script kiddie using readily available tools.
Question 52
Which of the following documents should link to the recovery point objectives and recovery time objectives on critical services?
A. Disaster recovery plan
B. Business impact analysis
C. Playbook
D. Backup plan
Show Answer
Correct Answer: B
Explanation: A Business Impact Analysis (BIA) identifies critical business services/processes and establishes or documents their recovery requirements, including Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs). The Disaster Recovery Plan uses those objectives to define recovery procedures, while playbooks and backup plans support execution rather than serving as the primary document linking critical services to RTO/RPO.
Question 53
A security analyst reviews a SIEM alert related to a suspicious email and wants to verify the authenticity of the message:
SPF = PASS -
DKIM = FAIL -
DMARC = FAIL -
Which of the following did the analyst most likely discover?
A. An insider threat altered email security records to mask suspicious DNS resolution traffic.
B. The message was sent from an authorized mail server but was not signed.
C. Log normalization corrupted the data as it was brought into the central repository.
D. The email security software did not process all of the records correctly.
Show Answer
Correct Answer: B
Explanation: SPF PASS indicates the sending server is authorized by the domain's SPF record. DKIM FAIL indicates the DKIM signature is missing, invalid, or does not verify. Because DMARC relies on SPF and/or DKIM alignment, a DKIM failure and lack of DMARC pass indicate the message did not satisfy DMARC. The best match is that the message came from an authorized mail server but was not properly DKIM-signed.
Question 54
After several tabletop exercises, the cybersecurity team is underperforming against MTTR and MTTD. Which of the following would help the team achieve improved performance?
A. Alert volume
B. Impact analysis
C. Lessons learned
D. Compensating controls
Show Answer
Correct Answer: C
Explanation: MTTD (Mean Time to Detect) and MTTR (Mean Time to Respond/Recover) improve through continuous process improvement. After tabletop exercises, conducting lessons learned (a post-incident review) identifies gaps in detection, communication, escalation, and response procedures so the team can refine playbooks and improve future performance. Alert volume is a metric rather than a direct improvement method, impact analysis helps assess business effects, and compensating controls reduce risk but do not directly improve team detection and response performance.
Question 55
A security analyst reviews the following output:
Which of the following malicious activities is occurring?
A. ARP poisoning
B. MAC flooding
C. ARP spoofing
D. ARP scanning
Show Answer
Correct Answer: D
Explanation: Based on the available information, the activity that matches repeated ARP "who has" requests used to discover live hosts on a subnet is ARP scanning. The referenced output is missing, so this answer is conditional on the output showing sequential ARP requests probing multiple IP addresses.
Question 56
During an internal code review, software called “ACE” was discovered to have a vulnerability that allows the execution of arbitrary code. The vulnerability is in a legacy, third-party vendor resource that is used by the ACE software. ACE is used worldwide and is essential for many businesses in this industry. Developers informed the Chief Information Security Officer that removal of the vulnerability will take time. Which of the following is the first action to take?
A. Look for potential IoCs in the company.
B. Inform customers of the vulnerability.
C. Remove the affected vendor resource from the ACE software.
D. Develop a compensating control until the issue can be fixed permanently.
Show Answer
Correct Answer: D
Explanation: Because permanent remediation will take time, the immediate priority is to reduce exploitation risk by implementing compensating controls. Informing customers may be necessary later, removing the third-party component may not be immediately feasible for a business-critical application, and hunting for IoCs is valuable but does not mitigate the newly identified exposure.
Question 57
A security analyst identifies a device on which different malware was detected multiple times even after the systems were scanned and cleaned several times. Which of the following actions would be most effective to ensure the device does not have residual malware?
A. Update the device and scan offline in safe mode.
B. Replace the hard drive and reimage the device.
C. Upgrade the device to the latest OS version.
D. Download a secondary scanner and rescan the device.
Show Answer
Correct Answer: B
Explanation: If malware repeatedly reappears after multiple scans and cleanups, the system likely has a persistent compromise such as a bootkit, rootkit, or other mechanism that standard remediation has not removed. Replacing the hard drive and reimaging the device provides the most effective way to eliminate residual malware from the storage device. The other options may help detect or remove some malware but do not provide the same level of assurance after repeated failed cleanups.
Question 58
As part of an incident investigation, an analyst creates a detailed document that describes all activities, timelines, root causes, and mitigation actions. Which of the following reports is the analyst creating?
A. Lessons learned
B. Business impact analysis
C. Tabletop exercise
D. Change control
Show Answer
Correct Answer: A
Explanation: A lessons learned report is produced after an incident and documents the incident timeline, activities performed, root cause analysis, mitigation actions, and recommendations for improving future response. The other options do not describe a post-incident investigation report: a business impact analysis assesses business consequences, a tabletop exercise is a discussion-based drill, and change control manages system changes.
Question 59
A systems administrator receives several reports about emails containing phishing links. The hosting domain is always different, but the URL follows a specific pattern of characters.
Which of the following is the best way for the administrator to find more messages that were not reported?
A. Search email logs for a regular expression.
B. Open a support ticket with the email hosting provider.
C. Send a memo to all staff asking them to report suspicious emails.
D. Query firewall logs for any traffic with a suspicious website.
Show Answer
Correct Answer: A
Explanation: A regular expression search against email logs is the best way to identify additional phishing emails when the hosting domain changes but the URL follows a consistent character pattern. Regex can match the invariant URL structure across different domains, making it effective for finding unreported messages. The other options are reactive or search the wrong data source.
Question 60
A security analyst reviews a packet capture and identifies the following output as anomalous:
Which of the following activities explains the output?
A. Nmap Xmas scan
B. Nikto’s web scan
C. Socat’s proxying traffic using the urgent flag
D. Angry IP Scanner output
Show Answer
Correct Answer: A
Explanation: An Nmap Xmas scan sends TCP packets with the FIN, PSH, and URG flags set simultaneously. A packet capture showing this unusual flag combination is characteristic of an Xmas scan. Nikto performs HTTP application-layer requests, Socat proxying is not identified by setting the urgent flag in this pattern, and Angry IP Scanner primarily performs host discovery rather than generating this distinctive TCP flag combination.
$19
Get all 534 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.