Logical Operations CyberSec First Responder - CFR-210 Exam Practice Test

As part of an incident response effort, data has been collected and analyzed, and a malware infection has
been contained . Which of the following is the NEXT step the incident response team should take within
the incident response process?
Correct Answer: B
Which of the following commands should be used to print out ONLY the second column of items in the
following file?
Source_File,txt
Alpha Whiskey
Bravo Tango
Charlie Foxtrot
Echo Oscar
Delta Roger
Correct Answer: B
A high-level government official uses anonymous bank accounts to transfer a requested amount of funds
to individuals in another country. These individuals are known for defacing government websites and
exfiltrating sensitive data. Which of the following BEST describes the involved threat actors?
Correct Answer: B
During an investigation on Windows 10 system, a system administrator needs to analyze Windows event
logs related to CD/DVD-burning activities. In which of the following paths will the system administrator find
these logs?
Correct Answer: A
A user reports a pop-up error when starting a Windows machine. The error states that the machine has
been infected with a virus and instructs the user to download a new antivirus client. In which of the
following locations should the incident responder check to find what is generating the error message?
(Choose two.)
Correct Answer: C,E
A security professional has been tasked with the protection of a specific set of information essential to a
corporation's livelihood, the exposure of which could cost the company billions of dollars in long-term
revenue. The professional is interested in obtaining advice for preventing the theft of this type of
information. Which of the following is the BEST resource for finding this material?
Correct Answer: D
DRAG DROP
Drag and drop the following steps to perform a successful social engineering attack in the correct order,
from first (1) to last (6).
Correct Answer:
During a network-based attack, which of the following data sources will provide the BEST data to quickly
determine the attacker's point of origin? (Choose two.)
Correct Answer: D,E
A DMZ web server has been compromised. During the log review, the incident responder wants to parse all common internal Class A addresses from the log.
Which of the following commands should the responder use to accomplish this?
Correct Answer: B
Organizations should exercise their Incident Response (IR) plan following initial creation. The primary
objective for this first I R plan exercise is to identify:
Correct Answer: A
0
0
0
0