Operations and Incident Response
Implementation
Architecture and Design
Attacks, Threats, and Vulnerabilities
100

If you are unable to ping a target because you are receiving no response or a response that states the destination is unreachable, then ICMP may be disabled on the remote end. If you wanted to try to elicit a response from a host using TCP, what tool would you use?

- Traceroute

- TCP ping

- Broadcast ping

- Hping

Hping

100

Which of the following would NOT be included in a company's password policy?

  • Password history
  • Password style
  • Password complexity requirements
  • Password age

Password style

100

 Nicole's organization does not have the budget or staff to conduct 24/7 security monitoring of their network. To supplement her team, she contracts with a managed SOC service. Which of the following services or providers would be best suited for this role?

  • IaaS
  • MSSP
  • SaaS
  • PaaS

MSSP

100

What is the utilization of insights gained from threat research and threat modeling to proactively discover evidence of adversarial TTPs within a network or system called?

  • Penetration testing
  • Threat hunting
  • Information assurance
  • Incident response

Threat hunting

200

During which phase of the incident response process does an organization assemble an incident response toolkit?

  • Detection and analysis
  • Containment, eradication, and recovery
  • Preparation
  • Post-incident activity

Preparation

200

Which of the following is the LEAST secure wireless security and encryption protocol?

  • WEP
  • WPA2
  • AES
  • WPA

Wired Equivalent Privacy (WEP)

200

Karen lives in an area that is prone to hurricanes and other extreme weather conditions. She asks you to recommend an electrical conditioning device that will prevent her files from being corrupted if the power to the building is unstable or lost. Additionally, she would like the computer to maintain power for up to an hour of uptime to allow for a graceful shutdown of her programs and computer. Which of the following should you recommend?

  • Surge protector
  • Power distribution unit
  • Line conditioner
  • Uninterruptible power supply

Uninterruptible power supply

200

An employee contacts the service desk because they are unable to open an attachment they receive in their email. The service desk agent conducts a screen sharing session with the user and investigates the issue. The agent notices that the attached file is named Invoice1043.pdf, and a black pop-up window appears and then disappears quickly when the attachment was double-clicked. Which of the following is most likely causing this issue?

  • The user doesn't have a PDF reader installed on their computer
  • The attachment is using a double file extension to mask its identity
  • The file contains an embedded link to a malicious website
  • The email is a form of spam and should be deleted

The attachment is using a double file extension to mask its identity

300

What role does the red team perform during a tabletop exercise (TTX)?

  • Adversary
  • Network defender
  • Cybersecurity analyst
  • System administrator

Adversary

300

You have been asked to install a computer in a public workspace. The computer should only be used by an authorized user. Which of the following security requirements should you implement to prevent unauthorized users from accessing the network with this computer?

  • Remove the guest account from the administrator group
  • Require authentication on wake-up
  • Disable single sign-on
  • Issue the same strong and complex password for all users

Require authentication on wake-up

300

Chris just downloaded a new third-party email client for his smartphone. When Chris attempts to log in to his email with his username and password, the email client generates an error messaging stating that "Invalid credentials" were entered. Chris assumes he must have forgotten his password, so he resets his email's username and password and then reenters them into the email client. Again, Chris receives an "Invalid credentials" error. What is MOST likely causing the "Invalid credentials" error in regard to Chris's email client?

  • His email account is locked out
  • His smartphone has full device encryption enabled
  • His email account requires a strong password to be used
  • His email account requires multifactor authentication

His email account requires multifactor authentication

300

A cybersecurity analyst is reviewing the logs of a proxy server and saw the following URL, http://test.diontraining.com/../../../../etc/shadow. What type of attack has likely occurred?

  • XML injection
  • Buffer overflow
  • Directory traversal
  • SQL injection

Directory traversal

400

An analyst just completed a port scan and received the following results of open ports: -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- TCP: 80 TCP: 110 TCP: 443 TCP: 1433 TCP: 3306 TCP: 3389 -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- Based on these scan results, which of the following services are NOT currently operating?

  • Web
  • RDP
  • SSH
  • Database

SSH

400

Which type of monitoring would utilize a network tap?

  • Router-based
  • Passive
  • Active
  • SNMP

Passive

400

Keith wants to validate the application file that he downloaded from the vendor of the application. Which of the following should he compare against the file to verify the integrity of the downloaded application?

  • MD5 or SHA1 hash digest of the file
  • File size and file creation date
  • Private key of the file
  • Public key of the file

MD5 or SHA1 hash digest of the file

400

As a cybersecurity analyst conducting vulnerability scans, you have just completed your first scan of an enterprise network comprising over 10,000 workstations. As you examine your findings, you note that you have less than 1 critical finding per 100 workstations. Which of the following statement does BEST explain these results?

  • The network has an exceptionally strong security posture
  • The scanner failed to connect with the majority of workstations
  • An uncredentialed scan of the network was performed
  • The scanner was not compatible with the devices on your network

An uncredentialed scan of the network was performed