During the triage of a SIEM alarm, a security analyst identifies the following activity on a .bash_history file:
Which of the following actions should the analyst take?
A. Declare an incident and look for data exfiltration.
B. Declare an incident and look for lateral movements.
C. Declare a false positive and close the alarm.
D. Declare an incident and look for malware in the affected machine.
Show Answer
Correct Answer: A
Explanation: The observed .bash_history activity shows a script that collects data from files or URLs and transmits it to an external IP address. This behavior is a strong indicator of data exfiltration already occurring, which warrants declaring an incident and immediately focusing on identifying what data was accessed and exfiltrated, the scope of impact, and any external destinations involved.
Question 36
A security analyst reviews the following output:
Which of the following malicious activities is occurring?
A. ARP poisoning
B. MAC flooding
C. ARP spoofing
D. ARP scanning
Show Answer
Correct Answer: D
Explanation: ARP scanning involves sending ARP "who-has" requests across a subnet to identify active hosts by observing which IP addresses respond. This behavior matches the described activity, rather than ARP poisoning/spoofing (which manipulates ARP mappings) or MAC flooding (which overwhelms a switch’s CAM table).
Question 37
Which of the following is the practice of controlling how evidence is handled to ensure its integrity during an investigation?
A. Chain of custody
B. Root cause analysis
C. Incident response
D. Evidence collection
Show Answer
Correct Answer: A
Explanation: Chain of custody refers to the documented process that tracks the handling, transfer, and storage of evidence to preserve its integrity and admissibility during an investigation. The other options describe broader processes or different activities, not the control of evidence handling.
Question 37
During an internal code review, software called “ACE” was discovered to have a vulnerability that allows the execution of arbitrary code. The vulnerability is in a legacy, third-party vendor resource that is used by the ACE software. ACE is used worldwide and is essential for many businesses in this industry. Developers informed the Chief Information Security Officer that removal of the vulnerability will take time. Which of the following is the first action to take?
A. Look for potential IoCs in the company.
B. Inform customers of the vulnerability.
C. Remove the affected vendor resource from the ACE software.
D. Develop a compensating control until the issue can be fixed permanently.
Show Answer
Correct Answer: D
Explanation: The vulnerability allows arbitrary code execution in a critical, widely used product, and a permanent fix will take time. The first priority is to reduce risk immediately. Implementing a compensating control (such as additional monitoring, input validation, sandboxing, network restrictions, or disabling exposed functionality) mitigates exploitation while remediation is developed. Removing the component may not be immediately feasible, and notifying customers or hunting IoCs are important but secondary to containing risk.
Question 38
A company’s policy is to follow NIST standards and use strong encryption to avoid disclosure of sensitive information in transit between any systems. An analyst reviews a lab web server and receives the following outputs:
Which of the following should the analyst identify as the most concerning?
A. TLS 1.0 is enabled.
B. The certificate is self-signed.
C. SSLv3 is disabled.
D. TLS 1.3 is not widely supported.
E. TLS compression is disabled.
Show Answer
Correct Answer: A
Explanation: TLS 1.0 being enabled is the most concerning because it is deprecated and prohibited by NIST SP 800-52 Rev. 2 due to known weaknesses and lack of support for modern cryptography, enabling downgrade and weak-cipher attacks. The other options are either acceptable (self-signed certs in labs), positive security configurations (SSLv3 and compression disabled), or not required for compliance (TLS 1.3 not mandatory if TLS 1.2 is used).
Question 38
A security analyst identifies a device on which different malware was detected multiple times even after the systems were scanned and cleaned several times. Which of the following actions would be most effective to ensure the device does not have residual malware?
A. Update the device and scan offline in safe mode.
B. Replace the hard drive and reimage the device.
C. Upgrade the device to the latest OS version.
D. Download a secondary scanner and rescan the device.
Show Answer
Correct Answer: B
Explanation: Repeated malware detections after multiple scans and cleanups indicate a persistent infection (e.g., rootkits, bootkits, or hidden components) that standard tools cannot fully remove. Replacing the hard drive and reimaging the device ensures complete eradication of any residual malware, making it the most effective option.
Question 39
Which of the following is the appropriate phase in the incident response process to perform a vulnerability scan to determine the effectiveness of corrective actions?
A. Lessons learned
B. Reporting
C. Recovery
D. Root cause analysis
Show Answer
Correct Answer: C
Explanation: A vulnerability scan to verify that corrective actions (patches, configuration changes, mitigations) were effective is performed during the Recovery phase. Recovery focuses on restoring systems to normal operation and validating that they are secure before returning them to production. Lessons learned, reporting, and root cause analysis occur after recovery or focus on documentation and analysis rather than technical validation.
Question 39
As part of an incident investigation, an analyst creates a detailed document that describes all activities, timelines, root causes, and mitigation actions. Which of the following reports is the analyst creating?
A. Lessons learned
B. Business impact analysis
C. Tabletop exercise
D. Change control
Show Answer
Correct Answer: A
Explanation: The document described—covering incident activities, timelines, root cause analysis, and mitigation actions—is a lessons learned (post-incident) report. This report is produced after incident response to capture what happened, why it happened, how it was handled, and what improvements are needed. The other options do not focus on post-incident documentation of response activities.
Question 40
An organization adds an MSSP to supplement its security monitoring operations during weekends and holidays. Which of the following would best demonstrate procurement value to the Chief Information Security Officer?
A. Stakeholder validation metrics
B. Mean time to respond
C. Alert volume
D. Number of escalations per week
Show Answer
Correct Answer: B
Explanation: The CISO is focused on risk reduction and operational effectiveness. Mean time to respond (MTTR) directly demonstrates how quickly the MSSP helps detect and contain incidents during off-hours, showing tangible improvement in security outcomes. Alert volume and escalation counts measure activity, not value, and stakeholder validation metrics are indirect and subjective compared to response performance.
Question 40
A security analyst reviews a packet capture and identifies the following output as anomalous:
Which of the following activities explains the output?
A. Nmap Xmas scan
B. Nikto’s web scan
C. Socat’s proxying traffic using the urgent flag
D. Angry IP Scanner output
Show Answer
Correct Answer: A
Explanation: An Nmap Xmas scan (-sX) sends TCP packets with the FIN, PSH, and URG flags set simultaneously. This unusual flag combination stands out in packet captures as anomalous and is characteristic of Xmas scans used for stealthy port discovery, matching the described output.
$19
Get all 528 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.