Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free CertNexus CyberSec First Responder CFR-410 Exam Questions

Page: 1 / 12 Total 180 questions

Want more questions? Get Premium Access.

Question 1

Which of the following plans helps IT security staff detect, respond to, and recover from a cyber attack?

Correct Answer: B. Incident Response Plan
Explanation:

An Incident Response Plan (IRP) helps IT security staff detect, respond to, and recover from a cyber attack. It outlines procedures for identifying and managing security incidents, minimizing damage, and restoring systems to normal operations. This plan is essential for an organization's ability to effectively handle cybersecurity threats.


Question 2

What is baseline security?

Correct Answer: C. An organization's secure starting point after fixing any security issues.
Explanation:

Baseline security refers to the established set of security measures and configurations that an organization considers to be the minimum level of security for its systems. This baseline is used as a reference point to ensure systems remain secure and to identify when changes or vulnerabilities occur.


Question 3

If an organization suspects criminal activity during the response to an incident, when should they notify law enforcement authorities?

Correct Answer: C. As soon as criminal activity is suspected.
Explanation:

An organization should notify law enforcement authorities as soon as criminal activity is suspected. Early involvement of law enforcement ensures that they can begin their investigation promptly, preserve evidence, and follow the appropriate legal processes, which may be essential for a successful prosecution.


Question 4

An incident responder has collected network capture logs in a text file, separated by five or more data fields.

Which of the following is the BEST command to use if the responder would like to print the file (to terminal/ screen) in numerical order?

Correct Answer: C. sort --n

Question 5

A suspicious script was found on a sensitive research system. Subsequent analysis determined that proprietary data would have been deleted from both the local server and backup media immediately following a specific administrator's removal from an employee list that is refreshed each evening. Which of the following BEST describes this scenario?

Correct Answer: A. Backdoor

Question 6

A secretary receives an email from a friend with a picture of a kitten in it. The secretary forwards it to the

~COMPANYWIDE mailing list and, shortly thereafter, users across the company receive the following message:

''You seem tense. Take a deep breath and relax!''

The incident response team is activated and opens the picture in a virtual machine to test it. After a short analysis, the following code is found in C:

\Temp\chill.exe:Powershell.exe --Command ''do {(for /L %i in (2,1,254) do shutdown /r /m Error! Hyperlink reference not valid.> /f /t / 0 (/c ''You seem tense. Take a deep breath and relax!'');Start-Sleep --s 900) } while(1)''

Which of the following BEST represents what the attacker was trying to accomplish?

Correct Answer: B. Taunt the user and then trigger a reboot every 15 minutes.

Question 7

An unauthorized network scan may be detected by parsing network sniffer data for:

Correct Answer: C. IP traffic from multiple IP addresses to a single IP address.

Question 8

During an incident, the following actions have been taken:

- Executing the malware in a sandbox environment

- Reverse engineering the malware

- Conducting a behavior analysis

Based on the steps presented, which of the following incident handling processes has been taken?

Correct Answer: A. Containment
Explanation:

The ''Containment, eradication and recovery'' phase is the period in which incident response team tries to contain the incident and, if necessary, recover from it (restore any affected resources, data and/or processes).


Question 9

Which of the following are part of the hardening phase of the vulnerability assessment process? (Choose two.)

Correct Answer: A. Installing patches; B. Updating configurations

Question 10

An incident responder was asked to analyze malicious traffic. Which of the following tools would be BEST for this?

Correct Answer: C. Wireshark

Question 11

A government organization responsible for critical infrastructure is being attacked and files on the server been deleted. Which of the following are the most immediate communications that should be made regarding the incident? (Choose two.)

Correct Answer: C. Notifying a national compute emergency response team (CERT) or cybersecurity incident response team (CSIRT); E. Notifying a mitigation expert

Question 12

Which of the following is considered a weakness or gap in a security program that can be exploited to gain unauthorized access?

Correct Answer: D. Vulnerability
Explanation:

A vulnerability is a weakness or gap in a security program, system, or application that can be exploited by attackers to gain unauthorized access. Identifying and mitigating vulnerabilities is a key part of any security program.


Question 13

When tracing an attack to the point of origin, which of the following items is critical data to map layer 2 switching?

Correct Answer: B. ARP cache
Explanation:

The host that owns the IP address sends an ARP reply message with its physical address. Each host machine maintains a table, called ARP cache, used to convert MAC addresses to IP addresses. Since ARP is a stateless protocol, every time a host gets an ARP reply from another host, even though it has not sent an ARP request for that reply, it accepts that ARP entry and updates its ARP cache. The process of updating a target host's ARP cache with a forged entry is referred to as poisoning.


Question 14

A security professional discovers a new ransomware strain that disables antivirus on the endpoint during an

infection. Which location would be the BEST place for the security professional to find technical information about this malware?

Correct Answer: A. Threat intelligence feeds

Question 15

Nmap is a tool most commonly used to:

Correct Answer: C. Perform network and port scanning