212-82: Certified Cybersecurity Technician Practice Exam — Free
QuestionQ1
Incident and Risk Management
Save question
Shawn, a forensic officer, has been assigned to investigate a crime scene at a coffee shop. As part of the investigation, Shawn collected the victim’s mobile device, which may contain potential evidence that could identify the culprits.
Which of the following points must Shawn follow when preserving the digital evidence?
ANever record the screen display of the device
BTurn the device ON if it is OFF
CDo not leave the device as it is if it is ON
DMake sure that the device is charged
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ2
Network Monitoring and Analysis
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ3
Application Security and Cloud Computing
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ4
Network Monitoring and Analysis
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ5
Data Security
0
Community Discussion
No comments yet. Be the first to start the discussion!
It's free
100% of the questions are free for all users. No strings attached.
Information Security Threats and AttacksNetwork SecurityNetwork Security ControlsApplication Security and Cloud ComputingWireless Device SecurityData SecurityNetwork Monitoring and AnalysisIncident and Risk Management
As the senior network analyst for a leading fintech organization, you are responsible for ensuring seamless communication among the firm’s global offices. Your network was designed with redundancy in mind, using multiple service providers and a mix of MPLS and public internet connections.
One week after deploying a state-of-the-art Network Performance Monitoring & Diagnostics (NPMD) tool, you observe unusual traffic patterns originating from the European data center and directed to the corporate headquarters in New York. The traffic spikes at intervals, heavily consuming the MPLS link and at times saturating the public internet connection, causing significant data-packet loss and application failures. Your task is to identify the root cause of these traffic anomalies and ensure optimal network performance for all critical business operations. Given this scenario, what might be the primary cause of these traffic spikes, and what should your immediate course of action be?
AFaulty Network Hardware – The network hardware in the European data center, such as routers or switches, might be malfunctioning, causing inconsistent traffic bursts. Diagnosing the hardware, checking for faults, and replacing the faulty equipment should be the immediate action.
BMPLS Link Flapping – The MPLS link might be experiencing flapping, leading to inconsistent traffic flow. It is crucial to liaise with the MPLS service provider to inspect the link stability and consider a backup link or an alternate route to reroute the traffic.
CUnauthorized Application Usage – The European data center staff might be using unauthorized applications or services that are consuming massive bandwidth. You should enforce strict Application and Network Access Control policies, and scrutinize the application traffic to restrict non-business-critical applications.
DData Backup and Replication – The European data center might be running data backup or replication processes during peak business hours. You should liaise with the data center team to reschedule backup operations to non-peak hours and ensure that backup processes are bandwidth-aware.
TechTrendz, a leading technology company, is approaching the final stages of building a new cloud-based web application for real-time processing of financial transactions.
Given the critical nature of the data and the anticipated high user volume, TechTrendz’s security team wants to apply rigorous application-security testing techniques. The team plans to run tests using tools that most closely simulate possible real-world attacks against the application.
The team’s primary concern is identifying system vulnerabilities, including those caused by configuration mistakes, software defects, and faulty APIs. The security specialists have shortlisted four testing tools and techniques. Which of the following would be the MOST comprehensive method for a thorough assessment of the application’s security?
AConducting a manual penetration test focusing only on the user interface and transaction modules.
BImplementing a tool that combines both SAST and DAST features for a more holistic security overview.
CUtilizing static application security testing (SAST) tools to scan the source code for vulnerabilities.
DEmploying dynamic application security testing (DAST) tools that analyze running applications in real-time.
TechTonic, a leading software-solution provider, is implementing stringent cybersecurity measures for its Windows-based server farm. It recently observed a series of unauthorized activities in its systems but could not trace their origins. The company wants to strengthen its monitoring capabilities through comprehensive analysis of Windows system logs. Which strategy should TechTonic prioritize for insightful, effective Windows log analysis aimed at tracing potential intrusions?
ASet up monitoring only for Windows Event Log IDs commonly associated with security breaches.
BRoutinely back up logs every week and conduct a monthly manual review to detect anomalies.
CImplement a centralized logging server and analyze logs using pattern-detection algorithms.
DFocus solely on logs from critical servers, assuming other logs are less consequential.
In an advanced cybersecurity research laboratory, a team is developing a new cryptographic protocol to protect highly sensitive communication. Its objective is to create a protocol resilient to quantum-computing attacks, which could potentially compromise many current encryption methods. During the research, the team focuses on using hash functions in the protocol. They test various hash functions to provide the highest level of security. Considering the quantum-computing threat, which of the following hash functions is the most appropriate choice for the protocol?
AMD5, for its speed and efficiency in generating hash values
BHMAC, for its ability to provide data integrity and authentication
CSHA-3, as it is designed to be resistant against quantum computing attacks
DSHA-256, due to its widespread use and proven security track record
QuestionQ6
Information Security Threats and Attacks
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ7
Incident and Risk Management
QuestionQ8
Information Security Threats and Attacks
QuestionQ9
Wireless Device Security
QuestionQ10
Application Security and Cloud Computing
QuestionQ11
Information Security Threats and Attacks
QuestionQ12
Network Monitoring and Analysis
QuestionQ13
Information Security Threats and Attacks
QuestionQ14
Application Security and Cloud Computing
QuestionQ15
Network Security
QuestionQ16
Network Monitoring and Analysis
QuestionQ17
Application Security and Cloud Computing
QuestionQ18
Incident and Risk Management
QuestionQ19
Network Security
QuestionQ20
Wireless Device Security
QuestionQ21
Application Security and Cloud Computing
QuestionQ22
Information Security Threats and Attacks
QuestionQ23
Network Monitoring and Analysis
QuestionQ26
Network Monitoring and Analysis
QuestionQ27
Network Security Controls
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Ad
Want a break from the ads?
Go ad-free and unlock Learn Mode, Exam Mode, AstroTutor AI and every premium tool — everything you need to walk in prepared, and confident.
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
A disgruntled employee transferred highly confidential tender data for upcoming projects as encoded text. You are assigned to decode the snitch.txt file in the Downloads folder of Attacker Machine-1 and determine the dollar value of the greenfarm project.
Hint 1: All cryptography tools are located at Z:\CCT-Tools\CCT Module 14 Cryptography.
Hint 2: If needed, use sniffer@123 as the password to decode the file. (Practical Question)
A75000
B95000
C36000
D80000
A global financial-services firm is updating its cybersecurity policies to comply with a diverse set of international regulatory frameworks and laws. The firm operates on multiple continents, each with separate legal requirements for data protection, privacy, and cybersecurity. As part of its compliance strategy, it is assessing different regulatory frameworks to identify those most critical to its operations. Given the firm’s international reach and the nature of its services, which of the following regulatory frameworks should be prioritized for compliance?
AGeneral Data Protection Regulation (GDPR) - European Union
BNIST Cybersecurity Framework
CISO 27002 Code of Practice for information security controls
DISO 27001 Information Security Management System
An organization hired a network operations center (NOC) team to safeguard its IT infrastructure against external attacks. The organization used a type of threat intelligence to defend its resources from evolving threats. This intelligence enabled the NOC team to understand how attackers would likely conduct an attack against the organization, identify information leakage, and determine the attackers’ goals and attack vectors.
Identify the type of threat intelligence the organization consumed in this scenario.
AOperational threat intelligence
BStrategic threat intelligence
CTechnical threat intelligence
DTactical threat intelligence
GlobalTech, a multinational corporation with more than 10,000 employees, has experienced a rise in workforce mobile-device use. The IT department must deploy a robust mobile security management solution that protects data, allows flexibility in device selection, and keeps administrative overhead low. Which of the following is the best solution for GlobalTech?
AUnified Endpoint Management (UEM)
BContainerization Solutions
CMobile Device Management (MDM)
DMobile Application Management (MAM)
You are the cybersecurity lead for an international financial institution. Your organization provides online banking services to millions of customers worldwide and has recently migrated its core banking system to a hybrid cloud environment to improve scalability and cost efficiency.
One evening, following a routine system patch, your web application firewall (WAF) reports a surge in server-side request forgery (SSRF) alerts. At the same time, your intrusion detection system (IDS) identifies possible attempts from the application layer to access cloud metadata services, potentially exposing sensitive cloud configuration details and API keys. This clearly suggests that attackers may be attempting to exploit the SSRF vulnerability to compromise your cloud infrastructure. Given the critical nature of your services and the high stakes involved, how should you address this imminent threat while minimizing disruption for banking customers?
ANotify all banking customers about the potential security incident, urging them to change their passwords and monitor their accounts for any unauthorized activity.
BIsolate the affected cloud servers and redirect traffic to backup servers, ensuring continuous service while initiating a deep-dive analysis of the suspicious activities using cloud-native security tools.
CEngage with a third-party cybersecurity firm specializing in cloud security to conduct an emergency audit, relying on its expertise to identify the root cause and potential breaches.
DRollback the recent patch immediately and inform the cloud service provider about potential unauthorized access to gauge the extent of vulnerability and coordinate a joint response.
A John-the-Ripper hash dump containing an FTP server’s login credentials is saved as “target-file” on the Desktop of Attacker Machine-2. Crack the password hashes in the file to recover the FTP server login credentials. The FTP root directory contains an exploit file. Read that file and submit the exploit author’s name as the answer. Hint: Not every credential will provide FTP access. (Practical Question)
AByteDefender
Bnullsecur1ty
CCodeGuard
DCipherShield
Tenda, a network specialist at an organization, examined logged data in Windows Event Viewer to identify attempted or successful unauthorized activities. The logs reviewed by Tenda include Windows security-related events, specifically logon/logoff activities, resource access, and information based on the Windows system's audit policies.
Identify the type of event logs that Tenda analyzed in this scenario.
AApplication event log
BSetup event log
CSecurity event log
DSystem event log
An attacker employed the ping-of-death (PoD) technique to crash a target Android device. The SOC team captured the network traffic and provided it to you for detailed analysis. Analyze the android.pcapng file in the Documents folder of Attacker machine-2 and determine the length, in bytes, of the PoD packets. (Practical Question)
A58
B54
C56
D52
A web application, www.moviescope.com, was discovered to be susceptible to SQL injection attacks. You are tasked with exploiting the web application to retrieve user data. Identify the contact number (Contact) for a user, steve, in the moviescope database. Note: You already have an account on the web application, with credentials sam/test. (Practical Question)
A1-202-509-7432
B1-202-509-7316
C1-202-509-8421
D1-202-509-7364
Jaden, a network administrator at an organization, used the ping command to verify the status of a system connected to the organization's network. He received an ICMP error message indicating that the IP header field contains invalid information. After examining the ICMP packet, Jaden determined that it is an IP parameter problem.
Identify the type of ICMP error message Jaden received in this scenario.
AType =12
BType = 8
CType = 5
DType = 3
An IoT device placed in a hospital as a safety measure has sent an alert command to the server. The network traffic was captured and stored in the Documents folder of Attacker Machine-1. Analyze the loTdeviceTraffic.pcapng file and select the appropriate command that the IoT device sent over the network.
ATempe_Low
BLow_Tempe
CTemp_High
DHigh_Tempe
Miguel, a professional hacker, targeted an organization to obtain illegitimate access to its critical information. He discovered a flaw in endpoint communication that could reveal the target application’s data.
Which secure application design principle was not satisfied by the application in this scenario?
ASecure the weakest link
BDo not trust user input
CException handling
DFault tolerance
Kasen, a cybersecurity specialist at an organization, was working with the business continuity and disaster recovery team. The team initiated various business continuity and discovery activities within the organization. During this process, Kasen established a program to restore both the disaster site and the damaged materials to their pre-disaster levels during an incident.
Which business continuity and disaster recovery activity did Kasen perform in this scenario?
APrevention
BResumption
CResponse
DRecovery
An MNC hired Brandon, a network defender, to set up secure VPN communication between the company’s remote offices. For this purpose, Brandon used a VPN topology in which every remote office communicates with the corporate office, but communication between remote offices is denied.
Identify the VPN topology Brandon used in this scenario.
APoint-to-Point VPN topology
BStar topology
CHub-and-Spoke VPN topology
DFull-mesh VPN topology
A renowned research institute with a high-security wireless network recently suffered an advanced cyberattack. Traditional security measures did not detect the attack, and it resulted in significant data exfiltration. The wireless network used WPA3 encryption, MAC address filtering, and disabled SSID broadcasting. Notably, the attack occurred without any apparent disruption or change in network performance. After exhaustive forensic analysis, the cybersecurity team identified the attack method. Which of the following wireless-network-specific attacks was most likely used?
AKRACK (Key Reinstallation Attack), exploiting vulnerabilities in the WPA2 protocol
BEvil Twin Attack, where a rogue access point mimics a legitimate one to capture network traffic
CJamming Attack, disrupting network communications with interference signals
DBluesnarfing, exploiting Bluetooth connections to access network data
A software company is developing a new software product while following secure application-development best practices. Dawson, a software analyst, is evaluating the application's performance on the client's network to determine whether end users experience any issues accessing the application.
Which tier of a secure application development lifecycle involves checking the application's performance?
ADevelopment
BTesting
CQuality assurance (QA)
DStaging
A threat-intelligence feed data file has been obtained and saved in the Documents folder on Attacker Machine-1 (File Name: Threatfeed.txt). You are a cybersecurity technician for an ABC organization. Your organization has tasked you with analyzing the data and submitting a report on the threat landscape. Select the IP address associated with http://securityabc.s21sec.com.
A5.9.200.200
B5.9.200.150
C5.9.110.120
D5.9.188.148
An attacker acting maliciously used a SYN-flooding technique to disrupt the network and gain an advantage over it to bypass the Firewall. You are working with a security architect to develop security standards and plans for your organization. The SOC team captured the network traffic and provided it to you for detailed analysis. Examine the Synflood.pcapng file and determine the source IP address.
Note: The Synflood.pcapng file is located in the Documents folder of the Attacker-1 machine.
A20.20.10.180
B20.20.10.19
C20.20.10.60
D20.20.10.59
As a network security analyst for a video game development company, you are responsible for monitoring traffic patterns on the development server used by programmers.
During business hours, you observe a steady stream of data packets between the server and internal programmer workstations. Most of this traffic uses TCP connections on port 22 (SSH) and port 5900 (VNC).
Based on this scenario, what does this describe?
ATraffic seems normal - SSH and VNC are commonly used by programmers for secure remote access and collaboration.
BThe situation is inconclusive - Further investigation is necessary to determine the nature of the traffic.
CTraffic is because of malware infection - Frequently used SSH & VNC Ports could indicate malware spreading through the Network.
DTraffic appears suspicious - The presence of encrypted connections might indicate attempts to conceal malicious activities.
Malachi, a security professional, implemented a firewall in his organization to trace inbound and outbound traffic. He deployed a firewall that operates at the session layer of the OSI model and monitors the TCP handshake between hosts to determine whether a requested session is legitimate.
Identify the firewall technology Malachi implemented in this scenario.
Community Discussion