Logical Operations CyberSec First Responder - CFR-210 FREE EXAM DUMPS QUESTIONS & ANSWERS
A system administrator is informed that a user received an email containing a suspicious attachment.
Which of the following methods is the FASTEST way to determine whether the file is suspicious or not?
Which of the following methods is the FASTEST way to determine whether the file is suspicious or not?
Correct Answer: D
Vote an answer
During a malware outbreak, a security analyst has been asked to capture network traffic in hourly
increments for analysis by the incident response team . Which of the following tcpdump commands would
generate hourly pcap files?
increments for analysis by the incident response team . Which of the following tcpdump commands would
generate hourly pcap files?
Correct Answer: A
Vote an answer
A security analyst discovers a zero-day vulnerability affecting Windows, which has not been publicly
identified. The security analyst assumes this vulnerability is present on millions of computer system and
feels an obligation to share this information with other security professionals. Which of the following would
be the MOST adverse consequences of the analyst sharing this information?
identified. The security analyst assumes this vulnerability is present on millions of computer system and
feels an obligation to share this information with other security professionals. Which of the following would
be the MOST adverse consequences of the analyst sharing this information?
Correct Answer: A
Vote an answer
During the course of an investigation, an incident responder discovers illegal material on a user's hard
drive. Which of the following is the incident responder's MOST important next step?
drive. Which of the following is the incident responder's MOST important next step?
Correct Answer: D
Vote an answer
Which of the following is the BEST way to capture all network traffic between hosts on a segmented
network?
network?
Correct Answer: C
Vote an answer
A malware analyst has been assigned the task of reverse engineering malicious code. To conduct the
analysis safely, which of the following could the analyst implement?
analysis safely, which of the following could the analyst implement?
Correct Answer: B
Vote an answer
A malicious attacker has compromised a database by implementing a Python-based script that will automatically establish an SSH connection daily between the hours of 2:00am and 5:00am.
Which of the following is the MOST common motive for the attack vector that was used?
Which of the following is the MOST common motive for the attack vector that was used?
Correct Answer: B
Vote an answer
During an annual penetration test, several rootkit-enabled systems are found to be exfiltrating data.
The penetration test team and the internal incident response team work to begin cleanup. The company's
operations team offers a new emails server to use for communications during the incident. As cleanup
continues, the attackers seem to know exactly what the incident response plan is. Which of the following
will prevent the attackers from compromising cleanup activities?
The penetration test team and the internal incident response team work to begin cleanup. The company's
operations team offers a new emails server to use for communications during the incident. As cleanup
continues, the attackers seem to know exactly what the incident response plan is. Which of the following
will prevent the attackers from compromising cleanup activities?
Correct Answer: D
Vote an answer
An organization needs to determine of any systems on its network (10.0.25.0/24) have web services
running on port 80 or 443. Which of the following is the BEST command to do this?
running on port 80 or 443. Which of the following is the BEST command to do this?
Correct Answer: A
Vote an answer
A system administrator needs to analyze a PCAP file on a Linux workstation where the use of GUI based
applications is restricted . Which of the following command line tools can the administrator use to analyze
the PCAP?
applications is restricted . Which of the following command line tools can the administrator use to analyze
the PCAP?
Correct Answer: B
Vote an answer