An analyst receives a report stating that the infection chain starts with a phishing email containing a malicious download link. When the victim downloads the malicious RAR file, the archive requires a specific password for extraction, revealing a fake PDF executable malware file and an image printing file. After the malware is decrypted and the fake PDF executable is run, the embedded LummaC2 or Rhadamanthys information stealer executes automatically, collects the victim’s credentials and data, and sends them to the C2 server.
Which conclusion should the analyst make about the threat actor?
AThe threat actor is focused on stealing sensitive information and may also aim to disrupt operations as a secondary objective after achieving the first one.
BThe threat actor is likely engaged in opportunistic attacks without a clear target profile, focusing on broad-based phishing tactics to maximize reach.
CThe threat actor is using a multi-stage attack to bypass security measures and exfiltrate sensitive information as the main objective of the operation.
DThe threat actor is employing sophisticated techniques to gain initial access and uses malware to move laterally and maintain persistence across network.
A security analyst receives an alert that host A, with the IP address 192.168.5.39, has had a new browser extension installed. While investigating SIEM tool logs, the analyst finds that host A made continuous TCP connections to 1.25.241.8 over TCP port 80. The IP address 1.25.241.8 is categorized as a C2 server.
Which action should the analyst take to mitigate similar connections going forward?
AUse antivirus software to quarantine suspicious files automatically.
BUse Deep Packet Inspection to block malicious domains.
CUse IDS to detect and avoid similar connections.
DConfigure a browser extension deny list.
Refer to the exhibit.
A company was recently breached and decided to strengthen its security posture going forward. A security assessment was commissioned specifically to test the weaknesses exploited during the breach. A security analyst reviews server logs to identify activity related to that security assessment.
Which entry indicates a delivery method associated with an authorized assessment?
AExploitation via “ExploitTest/2.0” using a shutdown command.
BScan via “WebCrawler/1.0” to gather public-facing information.
CLogin test at scale using “AuthCheck/4.1” and leaked credentials.
DUsing “SecurityScan/2.5” to access all /admin endpoints.
A cybersecurity team discovers an increase in DNS amplification attacks. The team wants to prevent an attack and reviews the current configurations. The company has a load balancer to manage network traffic and a DMZ containing important assets. Source IP verification for DNS requests is configured on the servers.
Which additional action should the team take to mitigate similar attacks?
AConfigure the load balancer to handle DNS requests.
BPlace the company’s DNS servers behind the DMZ.
CBlock all IP addresses related to the attack at the firewall.
DDisable recursion on the authoritative name servers.
QuestionQ8
Threat Hunting Techniques
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ9
Threat Actor Attribution Techniques
QuestionQ10
Threat Hunting Techniques
QuestionQ11
Threat Hunting Techniques
QuestionQ12
Threat Hunting Fundamentals
QuestionQ13
Threat Hunting Techniques
QuestionQ14
Threat Hunting Techniques
QuestionQ15
Threat Hunting Techniques
QuestionQ16
Threat Hunting Fundamentals
QuestionQ17
Threat Hunting Outcomes
QuestionQ18
Threat Hunting Techniques
QuestionQ19
Threat Hunting Outcomes
QuestionQ20
Threat Hunting Techniques
QuestionQ21
Threat Hunting Processes
QuestionQ22
Threat Hunting Techniques
QuestionQ23
Threat Hunting Techniques
QuestionQ24
Threat Hunting Outcomes
QuestionQ25
Threat Hunting Techniques
QuestionQ26
Threat Hunting Techniques
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Ad
Want a break from the ads?
Go ad-free and unlock Learn Mode, Exam Mode, AstroTutor AI and every premium tool — everything you need to walk in prepared, and confident.
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Refer to the exhibit.
A company's cybersecurity team detects an active attack against the web server hosting the company website. After analyzing web application firewall logs, the team finds several Base64-encoded HTTP requests. The team decodes the payloads and obtains the HTTP requests.
What did the attackers use to exploit the server?
Aunicode encoding
Bcross-site scripting (XSS)
Cdirectory traversal
DSQL injection
A threat-hunting team is attempting to classify IoT malware families from anomalous activity patterns.
Which IoT malware-family classification method is being described?
Arandom forest
Bdecision tree learning
Crandom number generator
Dgradient boosting
A SOC team must prepare for a new phishing campaign that deceives users into clicking a malicious URL to download a file. When that file runs, it creates a Windows process that harvests user credentials. The team must configure the SIEM tool to generate an alert when a suspicious process is detected.
Which two rules must the team create in the SIEM tool?
Choose two
Arule that detects processes created by the users
Brule that detects changes in process ownership
Crule that detects common processes that have modified names
Drule that detects processes in nonstandard file paths
Erule that detects changes in process startup time
Refer to the exhibit.
An analyst is evaluating artifacts and logs collected from a recent breach. In the logs, ATP established malware persistence by placing a path to the executable in a specific registry entry.
What distinguishes the ATP’s approach from using HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run instead?
AThis key is meant for system settings and not for storing startup program entries.
BThe key is available only on older versions of Windows and is not supported in newer ones.
CEntries in this key are automatically removed after a system restart, which prevents persistence.
DModifying this key requires administrative privileges, which the malware might not have.
What should be taken into account when employing machine learning for data analysis in a SOC?
AMore professionals are needed to maintain the system.
BSecurity gaps can occur during the early stages of development.
CMachine learning is unsuited for small organizations.
DConstant tuning is required for data analysis to be effective.
Refer to the exhibit.
The SOC lead received the scope for a penetration test performed against the company's assets during the last 4 hours. The documentation does not appear to include an authorized IP address range, and the testing company may perform only a surface-level scan and database probing. While SOC analysts review server logs to determine whether recent activity indicates an authorized penetration test or a possible attack, the team discovers several suspicious entries.
Which two log entries indicate a potentially successful unauthorized attack?
Choose two
Ainstance of “Haxxilla/5.0” user agent
Bevent with SQLDestroyer/6.0 user agent
Cuser agent “M Delta Security Services”
Dpresence of “NetworkScanner/3.0” user agent
Eoccurrence of SQLMap user agent
A task has been assigned to strengthen defenses against APT actors in a mid-sized technology company. The adversaries conduct sophisticated, long-running attacks and employ varied tactics to infiltrate and remain within target networks. The company is concentrating on the tactics used by these adversaries to substantially improve its overall security posture. A review of the Pyramid of Pain model has been completed, emphasizing the different levels of threat indicators, from simple hash values to complex TTPs. The goal is to improve detection capabilities.
Which approach should be used to detect APT activity at the Tactics level of the Pyramid of Pain?
Amonitoring all available network logs for specific IPs linked to known APT activities
Bblocking newly registered domains that have not been accessed before by company personnel
Canalyzing logs to identify patterns of behavior matching APT tactics from MITRE ATT&CK
Dusing hash values to identify known malware files used in previous APT campaigns
Refer to the exhibit.
A company has undergone several rounds of restructuring, and the former security team was let go. A new engineer joins and rediscovers all the tools left behind by the prior team. One tool is a Bash script for monitoring AWS accounts for threats.
What is the script's purpose?
Aautomating connection to AWS accounts
Bmonitoring failed AWS console login attempts
Carchiving records from the ConsoleLogin source
Dmonitoring for AWS instance errors
What is one characteristic of a memory-resident attack?
AThe attack is file independent.
BThe execution continues after a system restart.
CPrograms must be closed to be infected.
DMalware is installed in the virtual memory.
A SOC team receives a cloud indicator-of-compromise alert through Cisco Secure Endpoint. The alert shows that Microsoft Word tried to launch PowerShell by executing a VBA macro on a user workstation. After further investigation, the team determines that the PowerShell launch was blocked because of the company’s group policies.
Which action must the team take next to mitigate the issue?
ARun a full scan on the workstation.
BSubmit Word for sandboxing.
CInvestigate the Word file path.
DReview the group policies.
Refer to the exhibit.
After receiving an alert that a Windows host authenticated over the network to another host using a local administrator account, the security team examines the host. The team finds a process-creation event in that host's Sysmon logs.
Which action did the host carry out?
Arootkit installation
Bnetwork host discovery
Clateral movement
Dvertical privilege escalation
Refer to the exhibit.
The Security Operations team is reviewing firewall logs and decrypts this HTTP request from one of the finance team members’ endpoints.
Which Cyber Kill Chain stage does this evidence indicate?
ACommand and Control: establishing persistent C2 channels
BInstallation: installing malware on endpoints
CExfiltration: transferring data to remote server
DDelivery: transmitting malicious payload to target
Refer to the exhibit.
A security engineer observes that a Windows Batch script contains calls to suspicious APIs. How will the script affect the system when executed?
AThe internet connection is disabled.
BThe host is put in sleep mode.
CThe host version is retrieved.
DFiles are encrypted.
The SOC team receives an alert for a user sign-in from an unusual country. After reviewing the SIEM logs, the team confirms that the user never signed in from that country. The incident is reported to the IT administrator, who resets the user’s password.
Which threat-hunting phase was used initially?
Aresponse and resolution
Bhypothesis
Ccollect and process intelligence and data
DPost-incident review
Refer to the exhibit.
Code analysis is performed using the Semgrep tool. The tool reports that a security issue occurred while connecting to the database.
Which security vulnerability does the tool flag?
Adenial of service attack
Bunauthorized login
Cprivilege escalation
DSQL injection
The SOC team receives threat intelligence about a new ransomware variant spreading across businesses. After validating existing suspicious-email use cases, the team creates a new use case using known indicators of compromise for that specific ransomware variant. The focus is on detecting the ransomware attack during its execution phase.
What should be monitored?
Asudden increase in outbound traffic
Bchanges in My Documents file directory
Clarge numbers of file modifications
Dsuspicious DNS requests with no replies
Refer to the exhibit.
The SOC team observes an increase in company traffic. After investigating the spike, it concludes that the increase results from ongoing scanning activity. Further analysis shows that an adversary used Nmap for OS fingerprinting.
Which type of indicator used by the adversary is highest on the Pyramid of Pain?
AUDPs
Bnetwork/host artifacts
CIP addresses
Dport probes
Refer to the exhibit.
A SOC team is investigating an endpoint after observing suspicious communications with a malicious IP address. During the investigation, the team reviews the host's running processes.
On which element should the team focus next to continue the investigation?
AID of the running processes
Bcalc.exe process executed from svchost.exe
Carguments of svchost.exe
Dtaskhostw.exe reference key
A security analyst suspects, based on the telemetry observed so far, that the latest attack on a company machine is memory-resident.
Which action must the analyst take next to confirm this suspicion?
AReboot the server to clear any malicious processes from memory and then run a comprehensive malware scan.
BAnalyze network traffic logs for any suspicious activity and perform packet capture to decrypt unknown communication.
CPerform a full disk scan using antivirus software to identify and install an EDR product to observe how the system behaves.
DCapture a memory dump of the affected system and analyze it using forensic tools to identify malicious processes.
Community Discussion