CertNexus CyberSec First Responder - CFR-410 Exam Practice Test
A cybersecurity expert assigned to be the IT manager of a middle-sized company discovers that there is little endpoint security implementation on the company's systems. Which of the following could be included in an endpoint security solution? (Choose two.)
Correct Answer: C,E
A security engineer is setting up security information and event management (SIEM). Which of the following log sources should the engineer include that will contain indicators of a possible web server compromise?
(Choose two.)
(Choose two.)
Correct Answer: B,E
Which of the following can increase an attack surface?
Correct Answer: A
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
An incident response team is concerned with verifying the integrity of security information and event management (SIEM) events after being written to disk. Which of the following represents the BEST option for addressing this concern?
Correct Answer: D
According to company policy, all accounts with administrator privileges should have suffix _ja. While reviewing Windows workstation configurations, a security administrator discovers an account without the suffix in the administrator's group. Which of the following actions should the security administrator take?
Correct Answer: C
When reviewing log files from a recent incident, the response team discovers that most of the network-based indicators are IP-based. It would be helpful to the response team if they could resolve those IP-based indicators to hostnames. Which of the following is BEST suited for this task?
Correct Answer: C
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
Which of the following are well-known methods that are used to protect evidence during the forensics process? (Choose three.)
Correct Answer: B,C,D
When performing an investigation, a security analyst needs to extract information from text files in a Windows operating system. Which of the following commands should the security analyst use?
Correct Answer: D
Which of the following, when exposed together, constitutes PII? (Choose two.)
Correct Answer: A,B
During the forensic analysis of a compromised computer image, the investigator found that critical files are missing, caches have been cleared, and the history and event log files are empty. According to this scenario, which of the following techniques is the suspect using?
Correct Answer: A
What is the BEST process to identify the vendors that will ensure protection and compliance with security and privacy laws?
Correct Answer: C
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
Which two mitigation strategies can prevent an attack delivered via malware? (Choose two.)
Correct Answer: A,E
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
Which two options represent the most basic methods for designing a DMZ network firewall? (Choose two.)
Correct Answer: B,C
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).