Incident Response and Management
CS0-004 · 72 questions
- An analyst reviews an incident where a phishing email delivered an attachment, then PowerShell ran on the endpoint. The CISO wants a model that clearly separates the email delivery phase from the endpoint execution phase, with pre-compromise versus post-compromise activity. Which framework should the analyst use?
- In a hybrid SOC, EDR telemetry shows a process opening lsass.exe and reading its memory to extract credentials. You need classify this observed behavior in MITRE ATT&CK for an incident report. Which classification best describes what you observed?
- An EDR alert shows a suspicious process opening lsass.exe with PROCESSVMREAD rights and extracting authentication material. Which MITRE ATT&CK technique best maps this observed credential-access behavior?
- A CS0-004 analyst sees an account use valid credentials to access ADMIN$ on a file server, then a service named SysUpdate is created and started on that server. Which event is best classified as persistence rather than lateral movement in an ATT&CK timeline?
- An SOC analyst is reviewing MITRE ATT&CK guidance for scheduled-task persistence. A control recommendation states: 'Monitor task scheduler logs and alert on unusual task creation, modification, or deletion.' Which category does this guidance represent?
- An IR analyst opens an ATT&CK Navigator layer mapped to MITRE ATT&CK techniques. Each technique is shaded by detection coverage: dark red means no telemetry, amber means partial, green means full. During a ransomware tabletop, the analyst wants to know where to improve logging first. Which finding should the analyst prioritize?
- An analyst sees an attacker replaying a stolen SaaS OAuth token to list storage buckets via API, with no OS process or password logon. Which ATT&CK technique category should guide the mapping?
- An analyst reviews a mobile phishing alert: a user tapped a link to a fake company portal, then a prompt installed a malicious device configuration profile that enabled remote access. In MITRE ATT&CK, which tactic best describes the user action that first compromised the mobile device?
- A SOC alert shows powershell.exe -enc running a download cradle that retrieves and runs a remote file. The same process then sends small HTTP requests to that URL every 30 seconds. Which ATT&CK tactic pair best describes the initial retrieval and the periodic callbacks?
- A SOC analyst receives a threat report describing an attacker building a malicious loader, embedding it in a macro-enabled document, and signing the file before emailing it to users. Which Cyber Kill Chain phase occurs immediately before the delivery phase?
- A SOC analyst is mapping an insider data-theft case to the Cyber Kill Chain. The user already had valid credentials and access, so no phishing, malware, or perimeter breach was observed. Why does the framework underrepresent this activity?
- During a phishing incident, a SOC analyst has a malware sample, an attacker C2 server, a compromised employee account, and an infected workstation. Using the Diamond Model, which mapping is correct?
- A SOC analyst reviews three incidents over 30 days: a compromised workstation, a VPN jump host, and a backup server. EDR and SIEM logs show each host beaconing to the same external IP. Using Diamond Model infrastructure reasoning, what is the most defensible conclusion?
- Your SOC enforces a policy that blocks unsigned executables and allows only approved applications on analyst endpoints. An alert shows an attempt to run a new binary is prevented by the policy. Which D3FEND-style defensive technique best describes this control?
- A SOC analyst correlates EDR telemetry showing LSASS access, scheduled-task persistence, and SMB lateral movement. Threat intel reports a named group uses similar TTPs, but another group shares them. To enrich the incident with likely technique families, which approach is most reliable?
- A SOC analyst compares two incidents from last week. Incident A shows an EDR alert for a new scheduled task running a PowerShell command from %APPDATA%. Incident B shows proxy logs with periodic HTTPS beaconing to a newly registered domain. Which finding provides the strongest evidence that both incidents belong to the same adversary campaign?
- A Sigma rule fires when schtasks /create is used to add a task that launches a script at system startup. In MITRE ATT&CK, which persistence technique does this detection most directly map to?
- A SOC is mapping ATT&CK T1059 command and scripting interpreter coverage across Windows hosts. Alerts can show file access, DNS queries, and interactive logons, but analysts cannot reconstruct what command a suspicious process ran. Which telemetry gap most directly blocks detection of this execution technique?
- An EDR alert shows a signed Windows process launching from a user’s Downloads folder, using mshta to execute remote JavaScript and later rundll32 to load a DLL. The binaries are legitimate but signed. Which ATT&CK technique best explains this living-off-the-land execution behavior?
- A SOC analyst reviews EDR telemetry showing a newly created scheduled task that launches a PowerShell script at system startup and runs as SYSTEM. The script was added after a user opened a malicious document. Which ATT&CK tactic does this behavior most directly represent?
- A SOC analyst sees an endpoint transfer 18 GB over HTTPS to a rarely contacted external file-sharing host over 12 hours. DNS shows the same domain, but EDR finds no persistence, beaconing, or command responses. Which MITRE ATT&CK tactic best describes this activity?
- During triage, an EDR alert shows a suspicious process enumerating user documents, overwriting them with encrypted contents, renaming files with a new extension, and dropping a ransom note in each folder. The same process did not exploit a service, add a scheduled task, or disable logging. Which MITRE ATT&CK tactic best describes this observed behavior?
- An EDR alert shows encoded PowerShell execution on a host. A scanner later flags an unrelated app with CVSS 9.8. When prioritizing detection and response actions for the active incident, which source should guide the analyst?
- A phishing email delivers a malicious attachment to a finance user. The user opens the attachment, and a PowerShell script immediately runs and connects outbound to a C2 server. Which ATT&CK tactic describes the first successful adversary action?
- A SOC analyst has confirmed a malware infection, isolated the affected server, and blocked command-and-control traffic. The containment step is complete, and no evidence preservation issues remain. What should happen next in the incident response process?
- A high-severity alert suggests ransomware is spreading across file shares. The triage analyst confirms malicious activity and recommends isolating affected hosts. Who should authorize containment before the response team acts?
- An EDR/SIEM alert fires after 18 failed logon attempts to a service account from a maintenance host. The host is known to run a scheduled backup job, and no successful logon or lateral movement appears. Before deciding whether this is a reportable incident, what should the analyst do first?
- A SOC prepares for ransomware across hybrid endpoints. During a live alert, analysts struggle to identify the first malicious process because endpoint visibility is inconsistent. Which preparation activity most improves incident identification?
- Your SOC suspects an insider exfiltrated customer data from a file server that is also causing production outages. The team wants to reimage the server and clear old logs. What must happen before those logs are deleted?
- An EDR alert flags suspicious PowerShell on a laptop used by a finance user. You need to decide whether this is an incident or a benign admin task. Which identification step should you take first?
- An analyst finds a workstation infected with a commodity infostealer. EDR shows the host held customer PII, but no malware family known to be highly destructive is present. The business owner says this data supports regulated customer onboarding. What should primarily drive incident severity classification?
- A SOC analyst confirms an internal workstation is beaconing to a known C2 server. Management wants immediate containment while preserving volatile memory for later analysis. Which action best meets both goals?
- After initial isolation of a compromised workstation, an analyst rotates service credentials, segments affected VLANs, and enables enhanced monitoring while forensic imaging continues. Which incident response phase is being performed?
- A SOC alert shows multiple servers and workstations beaconing to a newly observed C2 domain. Some affected servers support a customer portal and cannot be isolated. The domain is not used by legitimate applications. Which containment point gives the best balance of coverage and business impact?
- An analyst confirms a Windows scheduled task is malicious persistence. During eradication, what action best confirms the mechanism has been removed?
- A jump host in a hybrid SOC is quarantined after EDR detects malware execution. Forensics show the malware arrived through an unpatched remote access application exposed to the internet. The analyst must recommend remediation that fixes the root cause rather than only the symptom. Which action best meets that requirement?
- After eradicating malware from a file server, the team plans to restore from backup. Which action best validates the backup is clean before restoration?
- After a ransomware incident, systems were wiped and restored from clean images. The IR lead needs recovery validation that confirms the adversary cannot immediately regain access. Which action best supports this validation?
- During an incident, an analyst isolated a critical file server because a host alert matched a containment playbook, causing an outage. The containment was later judged incorrect. After restoring service, the team prepares a lessons-learned review. What should be the review’s primary focus?
- During a ransomware containment event, your EDR analyst needed to isolate a compromised server but could not find an approved containment approver, delaying response. The post-incident review identified the missing approval path. What should the team do next?
- An analyst reviews EDR, email gateway, and firewall logs for a suspected intrusion: email delivery to user at 09:02, macro-enabled attachment executed at 09:15, outbound TLS beacon to rare domain at 09:21, SMB admin shares accessed from workstation at 09:36. Which sequence best supports identification and scoping?
- A SOC analyst reviews a ransomware incident. The SIEM shows only four alerts, but the affected file server stores regulated employee records, supports payroll processing, and two additional servers show encryption indicators. The severity matrix weighs data sensitivity, business downtime, and scope. What severity assignment is most appropriate?
- A SOC confirms EDR shows a ransomware note and unusual outbound HTTPS from a customer database server. The incident commander asks when to notify legal, communications, and system owners. Which communication path is appropriate?
- A ransomware alert shows encrypted file shares and a ransom note on a critical file server. The incident manager asks whether to begin payment negotiations. What should the SOC analyst verify first?
- A SOC analyst sees an EDR alert for anomalous mailbox forwarding on a finance user's account. A vendor reports receiving an invoice with new bank details and asks whether to process a $250,000 payment. The analyst must act before containment or eradication. What should the analyst do first?
- During a supply-chain credential compromise, your SOC confirms an attacker reused a service-account credential from a SaaS vendor to access hybrid workloads. The SaaS tenant is outside your direct administrative control. What is the required incident response process step?
- Your SOC detects repeated anomalous API calls from a cloud IAM user tied to a compromised workstation. The team wants to contain the cloud access before investigating the API logs. Which action best balances immediate containment with forensic visibility?
- A SOAR playbook receives an EDR alert that a critical application server may be compromised. The playbook pauses and requests analyst approval before isolating the server from the network. Which action should the analyst take?
- An EDR alert shows PowerShell spawning from an unusual path with no file on disk, and the endpoint is suspected of fileless malware. The analyst must collect evidence before containment could destroy volatile state. What should be captured first?
- A SOC analyst sees an EDR alert showing a Windows server beaconing to an unknown external IP every 30 seconds. The host is suspected compromised, but the analyst needs to keep EDR agent management and remote forensic access while blocking adversary network traffic. Which containment action best meets these requirements?
- A SOC analyst reviews NetFlow for a workstation. For the past six hours, the host has opened a TCP session to the same external IP every 300 seconds, sending about 120 bytes and receiving about 100 bytes, with no corresponding user activity. Which behavior is most strongly indicated?
- A SOC analyst notices a workstation repeatedly querying short, random-looking domains whose lookups often return NXDOMAIN before occasionally resolving. You need to confirm whether the activity is consistent with DGA-based command and control before containment. Which telemetry source should you query first?
- Proxy logs show an analyst workstation sending 18 GB over HTTPS to a personal file-sharing site at 02:15. The user says it is a scheduled cloud backup. Which next step best confirms whether this is exfiltration rather than normal backup activity?
- During lateral movement, a server logs Event ID 7045 seconds after a remote SMB session. The analyst must identify the Windows event source that confirms the service was installed on that endpoint. Which event source should be selected?
- During a Linux incident, auditd shows one execve record for /usr/bin/curl, but you need the full parent-to-child command lineage across a containerized host. Which telemetry should you request to reconstruct the execution chain?
- After a malware incident, the SOC wants to tune a Sigma rule to detect persistence created by scheduled tasks. The rule should identify new scheduled tasks whose command line launches an executable from a user-writable path. Which detection logic best implements this?
- After ransomware-like activity, a SOC analyst has forensic disk images from several workstations and a known malware string from a sample. The analyst needs to locate every file containing that string across all images before deciding containment. Which incident response technique should be used first?
- An EDR alert fires for a malware sample using PowerShell to create a scheduled task and beacon to a new C2. The SOC blocks the file hash and destination IP. Two days later, the same campaign appears with a different hash but similar command-line arguments and persistence. Which response is most durable?
- During containment of a phishing incident, EDR confirms a suspicious executable ran on one workstation. You obtain its SHA-256 hash. To quickly identify every other endpoint that executed the same sample, which action should you take?
- An analyst prepares to transfer a forensic image of a compromised workstation to legal review. The image has been acquired and verified. Which action best preserves admissibility during transfer?
- A suspected compromised workstation contains evidence that may be needed in a legal review. The analyst must acquire the disk while preventing any writes to the original media. Which acquisition technique best protects the original evidence?
- A compromised workstation has no malicious files on disk, but EDR shows a signed system process with an unexpected executable thread and RWX memory. You need to find injected code that disk scanning missed. Which IR technique should you use?
- An EDR process tree for a compromised workstation shows OUTLOOK.EXE launching POWERSHELL.EXE, which then launches MSHTA.EXE to download a payload. The analyst must identify the initial execution vector for the incident report. Which relationship best explains how the malicious activity began?
- Your SIEM rule alerts when one account authenticates successfully to multiple servers within 10 minutes. Daily admin patching triggers many alerts, but you must keep visibility into true lateral movement. Which rule change best improves precision?
- Your SOC receives an EDR alert showing a compromised user account using credentials from an unfamiliar country. A tested SOAR playbook can disable the AD account and open an incident ticket. You need rapid containment plus an integrated audit trail. Which action best meets both goals?
- An EDR alert shows a workstation making a single 30-second beacon to an unfamiliar external IP. NetFlow confirms the connection, but the payload is not available. You query a threat-intel platform for the IP's reputation, ASN, and recent malware associations. What is the best use of that enrichment when deciding containment?
- A SOC analyst investigates suspicious activity from a service account and suspects scheduled-task persistence. Which hunting query best maps to ATT&CK T1053.005?
- A SOC analyst sees repeated access to a restricted finance share, but file integrity logs show no changes. The team suspects an account may be opening or copying files without modifying them. Which technique best provides high-confidence telemetry for this behavior?
- An EDR alert shows an unusual RDP session from a workstation to a server using a valid domain service account. The SOC wants to confirm whether stolen credentials are being reused for lateral movement without exposing production accounts to risk. Which action best supports that goal?
- A SOC analyst sees EDR telemetry showing PowerShell executing encoded commands on a Windows host, with no new file created on disk. To preserve evidence most likely to contain the active malicious code, which artifact should be collected first?
- After eradicating malware from a compromised server, the SOC has confirmed IOCs such as C2 domains, file hashes, and mutexes. Which action best verifies eradication?
- An EDR alert shows a suspicious service spawning PowerShell and beaconing to a new C2. The endpoint is still responsive and telemetry is streaming. Which action best contains and eradicates the threat while preserving evidence?