01. When correlating DHCP server logs with alerts, an analyst wants the message in the DORA exchange with which the server confirms the lease to the client.
Which message is it?
a) DHCPACK
b) DHCPDISCOVER
c) DHCPREQUEST
d) DHCPOFFER
02. At a law firm, an attacker copied a legitimate command-line file-sync tool to a laptop and renamed it before using it to upload files. A rule that matches the tool's standard executable name raised nothing.
Which attribute should the rule match on instead?
a) The account and session that launched it
b) The name of its parent process
c) Its hash or the original file name stored in its version information
d) The image name recorded at process start
03. Before a budget review, a university's security committee asks the SOC to sort its controls into preventive, detective and corrective. The SOC lead drafts the detective list first.
Which two of the following belong on that list?
(Choose two.)
a) An IPS policy that drops inbound exploit attempts against the student portal
b) Multi-factor authentication enforced on the VPN and staff email
c) An IDS sensor on the campus uplink that alerts on known exploit signatures
d) File integrity monitoring that alerts on changes to web server content
e) Restoring research file shares from backup after an incident
04. Over ten minutes, thousands of documents on a city government's planning share are renamed with a new extension. The file server's EDR shows no unusual process running on the server itself, and dozens of clients legitimately move large volumes of data to that server every day. The analyst must name the client address and account behind the renamed files.
Which evidence answers that?
a) Process creation events on the server (event 4688), which record the program and account behind each launch
b) Detailed file share auditing on the server (event 5145), which records the source address and account for each file accessed
c) Service installation events on the server (event 7045), which record new services
d) NetFlow records from the core switch, which show which hosts sent SMB traffic to the server
05. When ranking an alert on a compromised service account, an analyst estimates how many systems the account can reach and how much harm its misuse could cause.
What is this extent of potential damage commonly called?
a) Attack surface
b) Defense in depth
c) Kill chain stage
d) Blast radius
06. Inside an isolated analysis VM, a logistics company's analyst runs a PDF keyword scanner over a suspicious invoice.pdf and gets:
/JS 1 | /JavaScript 1 | /OpenAction 1 | /Launch 0 | /EmbeddedFile 0
The case needs every URL the script contains, including fallback addresses it would try only if the first one fails.
What is the appropriate next step?
a) Open it in a PDF reader in the VM and capture its network traffic
b) Treat the file as benign, because /Launch 0 shows it cannot start any program
c) Rename it to invoice.txt and read the script in a text editor
d) Extract and decode the JavaScript object with a PDF parser, then read it for every URL
07. Under an approved credit-union policy, a playbook disabled a branch manager's account after a malware alert and a suspicious sign-in on that account. The action was correct. The next day, auditors asked which alert data triggered it and whether anyone approved it. The case record said only "account disabled".
Which improvement BEST answers the auditors' concern?
a) Require a manager's approval before the playbook disables any account
b) Have the playbook write each action, the alert data that triggered it and any approval into the case record
c) Limit the playbook to accounts outside management roles
d) Email the owner, their manager and the help desk when the playbook disables an account
08. Ransomware at a hospital network encrypted the file servers after the attacker used a domain administrator account to delete Volume Shadow Copies and to encrypt the backup share on a domain-joined backup server. The rebuilt design must assume a future attacker will again hold domain administrator rights.
Which backup design would still leave a recoverable copy?
a) Hourly shadow copy snapshots on every file server
b) Nightly backups to a share on a second domain-joined server
c) Offline or immutable backup copies
d) Continuous replication of each file server to a second site
09. Several workstations on a regional bank's branch subnet begin sending traffic for the payments network to 10.60.3.25, an ordinary workstation, instead of the branch router. Their DHCP-assigned default gateway is unchanged, and their ARP caches map the router's address to its real MAC. Their route tables now hold host routes to the payments network, learned from ICMP type 5 messages sent by 10.60.3.25.
Which control addresses this weakness?
a) Enabling DHCP snooping so only the uplink port may send DHCP offers
b) Dynamic ARP inspection on the access switches
c) Blocking ICMP echo at the branch firewall
d) Configuring every workstation to ignore ICMP redirect messages
10. A school district's SOC has hired three tier-1 analysts who have never investigated an intrusion with a SIEM or EDR. Before they work alerts alone, they need hands-on practice with those tools on realistic cases.
Which activities build that skill?
(Choose two.)
a) A reading assignment covering the SOC's escalation and data-handling policies
b) Investigating replayed attacks in a lab SIEM and EDR on a cyber range
c) Paired shifts in which each works live alerts with a senior analyst reviewing every decision
d) Solo handling of the overnight queue so they learn quickly from real incidents
e) A tabletop exercise where they discuss the district's ransomware response plan