Step2Study
IT & Technology200-201100% Free

Cisco CyberOps Associate (CBROPS) 200-201

Practice bank
239 Qs
Real exam
90 Qs
Time limit
120 min
Passing
Variable, based on difficulty of questions

Exam blueprint

Security Concepts
20%
Security Monitoring
20%
Host-Based Analysis
15%
Network Intrusion Analysis
20%
Security Policies and Procedures
15%
Vulnerability Management
10%

Practice

Untimed · instant feedback · 4 practice tests of 90 questions

Questions per test

Custom practice

Flashcard on every question Mental map when you miss

Exam simulation

4 timed tests · 90 questions each · 120 min · pass 80% · 239 questions in the bank

+50 XP per test · +100 XP for a pass

Random simulation (weighted by domain)

Everything is open to everyone. Create a free account to save scores, XP, badges and get progress emails.

Free study resources

All resources →

Study with friends

Challenge a friend to beat your score.

Cisco CyberOps Associate (CBROPS) 200-201 practice test questions

Sample questions from the 239-question bank, with answers and explanations.

All questions
  1. 1. An organization is migrating its on-premises applications to a public cloud environment. The security team is concerned about ensuring that the cloud resources (virtual machines, databases, storage accounts) are configured securely according to industry best practices and compliance requirements before they are deployed. Which security program element is most relevant to this proactive approach?

    Security Concepts

    • A. Vulnerability Management
    • B. Incident Response Planning
    • C. Security Architecture and Design
    • D. Security Operations Center (SOC)
    Show answer

    C. Security Architecture and Design

    Security Architecture and Design is a proactive security program element that focuses on integrating security considerations into the initial planning, design, and implementation phases of systems and applications. Ensuring cloud resources are securely configured *before* deployment falls directly under this domain, aiming to build security in from the start.

  2. 2. A company is implementing a new data classification policy. Sensitive customer data, if compromised, would result in severe financial penalties and reputational damage. According to common security principles, which classification level should this data receive?

    Security Concepts

    • A. Confidential
    • B. Internal
    • C. Public
    • D. Restricted
    Show answer

    D. Restricted

    Data classified as 'Restricted' typically represents the highest level of sensitivity, where unauthorized disclosure would lead to severe consequences, such as legal penalties, significant financial loss, or severe reputational damage. Customer data with high impact fits this category.

  3. 3. A security team is implementing a vulnerability management program and needs to establish a systematic approach to identify and categorize vulnerabilities. They decide to use a publicly available, standardized system for naming and identifying vulnerabilities. Which system are they most likely to adopt?

    Vulnerability Management

    • A. CVSS (Common Vulnerability Scoring System)
    • B. NIST SP 800-53
    • C. OWASP Top 10
    • D. CVE (Common Vulnerabilities and Exposures)
    Show answer

    D. CVE (Common Vulnerabilities and Exposures)

    CVE (Common Vulnerabilities and Exposures) provides a standard naming system for publicly known cybersecurity vulnerabilities. It assigns a unique identifier (e.g., CVE-2023-XXXX) to each vulnerability, allowing security teams to consistently track and reference specific flaws across different tools and reports.

  4. 4. A security architect is designing a system that requires ensuring data not only remains confidential but also that its origin can be verified and that the sender cannot later deny having sent it. Which cryptographic primitive is essential for achieving both data origin authentication and non-repudiation?

    Security Concepts

    • A. Hashing
    • B. Key Exchange
    • C. Digital Signatures
    • D. Symmetric Encryption
    Show answer

    C. Digital Signatures

    Digital signatures use asymmetric cryptography to provide data integrity, data origin authentication, and non-repudiation. The sender uses their private key to sign a hash of the message, and the recipient uses the sender's public key to verify the signature, proving the sender's identity and that the message hasn't been altered.

  5. 5. A security analyst is performing a black-box penetration test against a client's external web application. During the reconnaissance phase, the analyst discovers several subdomains and public-facing IP addresses, but no direct access to source code or internal network diagrams. Which of the following best describes the perspective and information available to the analyst at this stage?

    Vulnerability Management

    • A. They have an insider's view, similar to a malicious employee.
    • B. They have partial knowledge, similar to a privileged user.
    • C. They are operating with full system knowledge and access.
    • D. They are simulating an external, unauthenticated attacker.
    Show answer

    D. They are simulating an external, unauthenticated attacker.

    A black-box penetration test explicitly simulates an external, unauthenticated attacker with no prior knowledge of the internal system. Discovering public-facing information like subdomains and IPs aligns with the reconnaissance phase of such a test.

  6. 6. A security analyst is reviewing system logs on a Linux server and notices repetitive failed login attempts for a root user account originating from various external IP addresses within a short timeframe. Which type of attack is most likely underway?

    Security Monitoring

    • A. Brute-force Attack
    • B. Denial-of-Service (DoS)
    • C. Privilege Escalation
    • D. Cross-Site Scripting (XSS)
    Show answer

    A. Brute-force Attack

    Repetitive failed login attempts for a specific account, especially from multiple external IPs, are a classic indicator of a brute-force attack where an attacker tries many password combinations to gain unauthorized access.

  7. 7. A large enterprise uses a centralized logging system to collect security events from all network devices and servers. A security analyst frequently reviews these logs to identify anomalies and potential threats. This practice is a core component of which security program element?

    Security Concepts

    • A. Security Monitoring
    • B. Security Awareness Training
    • C. Vulnerability Management
    • D. Disaster Recovery Planning
    Show answer

    A. Security Monitoring

    Security monitoring involves continuously observing and analyzing activity to detect security events, anomalies, and potential threats. Centralized logging and analyst review of logs are fundamental activities within a security monitoring program.

  8. 8. A security team is analyzing network traffic logs and observes a significant increase in connection attempts to a web server from a single source IP address, occurring rapidly over a short period. The connection attempts are incomplete, with the attacker sending only the initial SYN packet but never completing the three-way handshake. What type of Denial of Service (DoS) attack is this?

    Security Concepts

    • A. UDP Flood
    • B. SYN Flood
    • C. HTTP Flood
    • D. ICMP Flood
    Show answer

    B. SYN Flood

    A SYN flood is a type of DoS attack that exploits the TCP three-way handshake. The attacker sends a large number of SYN requests to a server but never completes the handshake by sending the final ACK. This leaves the server's connection tables full of half-open connections, exhausting resources and preventing legitimate users from connecting.

  9. 9. A security operations center (SOC) analyst is investigating an alert from an Intrusion Prevention System (IPS) indicating a potential buffer overflow attack. The IPS has successfully blocked the traffic. The analyst needs to determine if the attack attempt was indeed a buffer overflow and identify its source and target. What type of security monitoring concept is the IPS primarily demonstrating in this scenario?

    Security Concepts

    • A. Network Intrusion Detection/Prevention
    • B. Log Management
    • C. Endpoint Detection and Response (EDR)
    • D. Security Information and Event Management (SIEM)
    Show answer

    A. Network Intrusion Detection/Prevention

    An IPS (Intrusion Prevention System) actively monitors network traffic for malicious activity and can automatically block or prevent detected threats, such as a buffer overflow attack. This falls under the category of network intrusion detection and prevention, which focuses on analyzing network traffic for attacks.

  10. 10. A security analyst is investigating a series of alerts from a host-based intrusion detection system (HIDS) indicating 'Registry Key Modification: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'. The alerts show that a new entry has been added pointing to an executable in the C:\Users\Public\ directory. What is the most likely purpose of this registry modification?

    Security Monitoring

    • A. To elevate user privileges
    • B. To disable system services
    • C. To establish persistence
    • D. To delete critical system files
    Show answer

    C. To establish persistence

    The 'HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run' registry key is a well-known location where programs can register themselves to automatically start when Windows boots up or a user logs in. Adding an entry here is a common technique used by malware to ensure it restarts and maintains its presence on the system after a reboot, which is known as establishing persistence.

  11. 11. An organization is considering implementing a continuous vulnerability management program. Which of the following is a primary benefit of integrating threat intelligence feeds into their vulnerability management process?

    Vulnerability Management

    • A. It automates the patching of all identified vulnerabilities.
    • B. It eliminates the need for regular vulnerability scanning.
    • C. It guarantees 100% protection against zero-day attacks.
    • D. It provides context on active exploits and attacker methodologies, aiding prioritization.
    Show answer

    D. It provides context on active exploits and attacker methodologies, aiding prioritization.

    Threat intelligence provides crucial context by detailing current threats, active exploits, and attacker tactics, techniques, and procedures (TTPs). This information helps security teams prioritize which vulnerabilities to address first based on the actual likelihood and impact of exploitation.

  12. 12. A security engineer is configuring a new Intrusion Detection System (IDS) to monitor network traffic for malicious activity. The engineer decides to implement a rule that triggers an alert whenever a specific, known malicious payload signature is detected within any network packet. This approach is an example of which type of security monitoring concept?

    Security Concepts

    • A. Behavioral-based detection
    • B. Anomaly-based detection
    • C. Signature-based detection
    • D. Heuristic-based detection
    Show answer

    C. Signature-based detection

    Signature-based detection relies on a database of known attack patterns or 'signatures'. When the IDS detects traffic that matches one of these predefined signatures, it triggers an alert. The scenario explicitly mentions detecting a 'specific, known malicious payload signature', which is the hallmark of signature-based detection.

  13. 13. A security analyst is investigating a potential data exfiltration incident. Network traffic analysis reveals large volumes of encrypted data being sent from an internal server to an external IP address over an unusual port (TCP 53000). The internal server's legitimate function does not involve outbound connections of this nature. Which network intrusion analysis technique is most critical for determining the content of the exfiltrated data?

    Security Monitoring

    • A. Packet capture and decryption (if possible) to inspect payload.
    • B. NetFlow analysis to identify source and destination IPs.
    • C. Firewall log review to confirm blocked connections.
    • D. DNS query analysis to detect command and control (C2) channels.
    Show answer

    A. Packet capture and decryption (if possible) to inspect payload.

    To determine the *content* of exfiltrated data, direct inspection of the data itself is required. Since the data is encrypted, the most critical step is to obtain a packet capture and then attempt decryption using available keys or certificates. Other options identify traffic but don't reveal content.

  14. 14. A security analyst is investigating a suspicious process on a Linux server. The process is running as 'nobody' (a low-privilege user) but is observed making outbound connections to various external IP addresses on high-numbered, ephemeral ports. There is no legitimate application configured to run as 'nobody' with this network behavior. Which type of malware is most likely responsible?

    Security Monitoring

    • A. Rootkit
    • B. Botnet (bot)
    • C. File Infector
    • D. Logic Bomb
    Show answer

    B. Botnet (bot)

    A process running as a low-privilege user ('nobody') and making 'outbound connections to various external IP addresses on high-numbered, ephemeral ports' without a legitimate reason is highly indicative of a botnet agent (bot). Bots are typically designed to communicate with a command and control (C2) server, often using random high ports to evade simple firewall rules, and often run with minimal privileges to avoid detection or reduce impact if discovered.

  15. 15. A security analyst is investigating a series of alerts indicating that multiple internal hosts are attempting to connect to various external IP addresses on non-standard ports. The traffic patterns are sporadic and do not align with known business operations. Further investigation reveals that these internal hosts are also communicating with each other over unusual ports. What type of attack framework is most likely indicated by these observations?

    Security Concepts

    • A. SQL Injection
    • B. Phishing Campaign
    • C. Command and Control (C2)
    • D. Denial of Service (DoS)
    Show answer

    C. Command and Control (C2)

    The observed behavior of internal hosts communicating with external IP addresses on non-standard ports, coupled with internal host-to-host communication over unusual ports, is characteristic of a Command and Control (C2) framework. This framework allows attackers to maintain persistent access and control over compromised systems within a network.

  16. 16. A financial institution is developing a new mobile banking application. The security team insists that all sensitive data stored on the mobile device must be protected even if the device is lost or stolen. Which endpoint security concept is critical to implement for this requirement?

    Security Concepts

    • A. Network Access Control (NAC)
    • B. Full Disk Encryption (FDE)
    • C. Endpoint Detection and Response (EDR)
    • D. Application Whitelisting
    Show answer

    B. Full Disk Encryption (FDE)

    Full Disk Encryption (FDE) protects all data on a device at rest by encrypting the entire storage volume. If the device is lost or stolen, the data remains unreadable without the correct decryption key, directly addressing the requirement to protect sensitive data on a lost or stolen device.

  17. 17. A security operations center (SOC) analyst observes a series of suspicious events originating from an internal server: multiple failed login attempts to an external SSH server, followed by a successful connection, and then a large outbound data transfer to an unknown IP address. The analyst suspects command and control (C2) communication. Which port is most commonly associated with SSH, and thus a strong indicator in this C2 scenario?

    Security Concepts

    • A. Port 23
    • B. Port 22
    • C. Port 21
    • D. Port 80
    Show answer

    B. Port 22

    SSH (Secure Shell) typically operates on TCP port 22. In a C2 scenario, attackers often use SSH for encrypted communication and remote control of compromised systems, making traffic on port 22 to an external unknown IP highly suspicious, especially after failed logins.

  18. 18. A security analyst is configuring a SIEM to ingest logs from various network devices. The analyst needs to ensure that the SIEM can accurately parse and normalize logs from a new Cisco ASA firewall, which uses syslog for event reporting. Which of the following is the most critical step to ensure effective security monitoring from this new log source?

    Security Monitoring

    • A. Configure the ASA to send logs to a non-standard UDP port.
    • B. Ensure the SIEM has the correct parsing rules (parsers) for Cisco ASA syslog format.
    • C. Disable timestamping on the ASA logs to reduce data volume.
    • D. Only ingest critical alerts (severity 0-2) from the ASA.
    Show answer

    B. Ensure the SIEM has the correct parsing rules (parsers) for Cisco ASA syslog format.

    For a SIEM to effectively analyze and correlate logs, it must first be able to understand their format. Different devices and vendors use varying log formats. Having the correct parsing rules (often called parsers or connectors) ensures that the SIEM can correctly extract fields like source IP, destination IP, event type, and severity, which is crucial for normalization, correlation, and effective security monitoring.

  19. 19. A security architect is designing a system that requires ensuring data not only remains confidential and its integrity is preserved, but also that the sender of the data cannot later deny having sent it. Which cryptographic principle is specifically addressed by the requirement that the sender cannot deny sending the data?

    Security Concepts

    • A. Confidentiality
    • B. Non-repudiation
    • C. Integrity
    • D. Availability
    Show answer

    B. Non-repudiation

    Non-repudiation is the cryptographic principle that ensures that a party cannot successfully deny the authenticity of their signature on a document or the sending of a message that they originated. This is typically achieved through digital signatures.

  20. 20. A security analyst is investigating a series of anomalies on a web server. The server logs show numerous HTTP POST requests to a login page with varying usernames and passwords, originating from a single IP address over a short period. Many of these attempts are failing due to incorrect credentials. Which common attack vector is most likely being observed?

    Security Concepts

    • A. Denial of Service (DoS)
    • B. SQL Injection
    • C. Cross-Site Scripting (XSS)
    • D. Credential Stuffing
    Show answer

    D. Credential Stuffing

    Credential stuffing involves using compromised username/password pairs obtained from a data breach on one service to attempt to gain unauthorized access to accounts on other, unrelated services. The scenario describes repeated login attempts with varying credentials, which aligns with this attack vector.

  21. 21. A cybersecurity firm is developing a new intrusion detection system (IDS) that uses a database of known attack patterns to identify malicious network traffic. This IDS is designed to flag traffic only when it precisely matches an entry in its database. Which detection method is primarily being employed?

    Security Concepts

    • A. Heuristic Detection
    • B. Behavioral Detection
    • C. Anomaly-based Detection
    • D. Signature-based Detection
    Show answer

    D. Signature-based Detection

    Signature-based detection systems rely on a database of known attack patterns or signatures. They flag traffic only when it exactly matches one of these pre-defined patterns. This method is effective against known threats but struggles with novel or zero-day attacks.

  22. 22. A security operations center (SOC) analyst is reviewing alerts from the SIEM. One alert indicates 'Multiple failed attempts to access a critical database using SQL queries containing 'UNION SELECT' and 'pg_sleep()'. The source IP is from an external, untrusted network. Which vulnerability is the attacker most likely attempting to exploit?

    Security Monitoring

    • A. SQL Injection
    • B. Buffer Overflow
    • C. Cross-Site Request Forgery (CSRF)
    • D. Directory Traversal
    Show answer

    A. SQL Injection

    The presence of 'UNION SELECT' and 'pg_sleep()' within SQL queries is a classic signature of SQL injection attempts. 'UNION SELECT' is used to extract data, and 'pg_sleep()' is often used for time-based blind SQL injection.

  23. 23. A security team is implementing a new access control system. The policy dictates that users should only have the minimum necessary access rights to perform their job functions, and these rights should be revoked automatically when their role changes or they leave the company. Which security principle is being enforced by this policy?

    Security Concepts

    • A. Separation of Duties
    • B. Defense in Depth
    • C. Least Privilege
    • D. Implicit Deny
    Show answer

    C. Least Privilege

    The principle of least privilege dictates that users, programs, or processes should be granted only the minimum access necessary to perform their legitimate functions. Revoking access when roles change or employment ends further reinforces this principle by ensuring privileges are always kept to the absolute minimum required.

  24. 24. A security auditor is reviewing an organization's access control policies. The auditor notes that a database administrator has full read and write access to all customer data, including highly sensitive financial records, even though their daily tasks only require access to a subset of non-financial customer data. Which security principle is being violated?

    Security Concepts

    • A. Least Privilege
    • B. Separation of Duties
    • C. Defense in Depth
    • D. Need-to-Know
    Show answer

    A. Least Privilege

    The Principle of Least Privilege dictates that users, programs, or processes should be granted only the minimum necessary authorizations to perform their legitimate tasks. The database administrator having full access when only a subset is needed is a direct violation of this principle.

  25. 25. A security analyst is investigating a series of alerts indicating unusual outbound network connections from several internal workstations to an external IP address known for hosting C2 (Command and Control) infrastructure. The connections are occurring over TCP port 443, but the traffic does not appear to be legitimate HTTPS. What technique is the attacker most likely employing?

    Security Monitoring

    • A. SMB Relay Attack
    • B. Protocol Mismatching
    • C. DNS Tunneling
    • D. ICMP Exfiltration
    Show answer

    B. Protocol Mismatching

    Protocol mismatching, also known as protocol evasion or port masquerading, involves using a standard port (like 443 for HTTPS) for non-standard or malicious traffic to bypass firewall rules that typically allow outbound traffic on common ports. The key indicator is that traffic on port 443 'does not appear to be legitimate HTTPS'.

Cisco CyberOps Associate (CBROPS) 200-201 flashcards

Tap a card to flip it. 179 flashcards in the full deck.

  • Security Architecture & Design

    Flip card

    A proactive security program element focused on integrating security considerations into the initial planning, design, and implementation phases of systems, applications, and infrastructure.

    • Aims to build security in from the ground up ('Secure by Design').
    • Involves defining security requirements, choosing appropriate controls, and creating secure blueprints.
    • Reduces the cost and effort of fixing security vulnerabilities later.
    Study this card →
  • Data Classification

    Flip card

    The process of organizing data into categories based on its sensitivity and impact if compromised, to apply appropriate security controls.

    • Helps determine necessary security measures.
    • Typically includes categories like Public, Internal, Confidential, Restricted.
    • Impact assessment is crucial for classification.
    Study this card →
  • CVE (Common Vulnerabilities and Exposures)

    Flip card

    A list of publicly disclosed cybersecurity vulnerabilities, each assigned a unique identifier (CVE ID) to facilitate data sharing and enable automation.

    • Standardizes vulnerability identification.
    • Maintained by MITRE Corporation.
    • Used by security vendors and researchers worldwide.
    Study this card →
  • Digital Signature

    Flip card

    A mathematical scheme for demonstrating the authenticity of digital messages or documents. A valid digital signature gives a recipient reason to believe that the message was created by a known sender (authentication), that the sender cannot deny having sent the message (non-repudiation), and that the message was not altered in transit (integrity).

    • Uses asymmetric cryptography (public/private key pairs).
    • Provides data integrity, data origin authentication, and non-repudiation.
    • Often involves hashing the message first, then encrypting the hash with the sender's private key.
    Study this card →
  • Black-Box Penetration Test

    Flip card

    A type of penetration test where the tester has no prior knowledge of the target system's internal structure or source code, simulating an external attacker.

    • Mimics a real-world external attacker.
    • Focuses on identifying vulnerabilities visible from the outside.
    • Requires extensive reconnaissance by the tester.
    Study this card →
  • Brute-force Attack

    Flip card

    A brute-force attack is a trial-and-error method used to obtain information such as a user password or personal identification number (PIN). It involves systematically checking all possible passwords until the correct one is found.

    • Characterized by numerous failed login attempts.
    • Can target various services (SSH, RDP, web logins).
    • Often originates from multiple IPs to evade rate limiting.
    Study this card →
  • Security Monitoring

    Flip card

    The continuous process of collecting, analyzing, and reviewing data from various sources (e.g., logs, network traffic) to detect and respond to security incidents and anomalies.

    • Proactive and reactive threat detection.
    • Utilizes tools like SIEM, IDS/IPS, EDR.
    • Essential for maintaining situational awareness.
    Study this card →
  • SYN Flood Attack

    Flip card

    A type of Denial of Service (DoS) attack that exploits the TCP three-way handshake. The attacker sends a high volume of SYN requests to a target server but does not respond to the server's SYN-ACKs, leaving many half-open connections that exhaust the server's resources and prevent legitimate connections.

    • Targets TCP services.
    • Exploits the three-way handshake.
    • Sends SYN, never ACK.
    Study this card →
  • Network Intrusion Prevention System (IPS)

    Flip card

    A network security appliance that monitors network traffic for malicious activity, logs information about it, attempts to block it, and reports it.

    • Active prevention of network attacks.
    • Operates in-line with network traffic.
    • Can block known attack signatures and anomalies.
    Study this card →
  • Persistence Mechanisms

    Flip card

    Techniques used by attackers to maintain access to a compromised system across reboots, loss of network connectivity, or credential changes.

    • Ensures malware or attacker tools restart automatically.
    • Common methods include registry run keys, startup folders, scheduled tasks, and services.
    • Crucial for long-term compromise and covert operations.
    Study this card →
  • Threat Intelligence Integration

    Flip card

    The practice of incorporating actionable information about current and emerging cyber threats into an organization's security operations, including vulnerability management, to make more informed decisions.

    • Provides context on attacker TTPs.
    • Aids in prioritizing vulnerabilities based on real-world risk.
    • Enhances proactive defense strategies.
    Study this card →
  • Signature-based Detection

    Flip card

    A method of detecting threats by comparing observed data (e.g., network traffic, file content) against a database of known malicious patterns or signatures.

    • Effective against known threats.
    • Requires frequent updates to the signature database.
    • Ineffective against zero-day attacks or polymorphic malware.
    Study this card →
  • Packet Capture & Decryption

    Flip card

    The process of intercepting and recording network traffic (packet capture) and subsequently converting encrypted traffic back into readable plaintext (decryption) to analyze its contents.

    • Essential for deep inspection of network payload data.
    • Requires access to encryption keys/certificates for encrypted traffic.
    • Tools like Wireshark are used for capture and analysis.
    Study this card →
  • Botnet (Bot) Characteristics

    Flip card

    A botnet is a network of compromised computers (bots) controlled by a threat actor (bot-herder) via a command and control (C2) server. Bots often run with low privileges and communicate covertly with the C2.

    • Performs C2 communication (often via HTTP, DNS, or custom protocols).
    • Often runs as a low-privilege user.
    • Used for DDoS, spam, data theft, and other malicious activities.
    Study this card →
  • Command and Control (C2)

    Flip card

    A communication channel used by attackers to control compromised systems (bots or agents) within a target network. It enables attackers to issue commands, exfiltrate data, and maintain persistent access.

    • Establishes persistent communication with compromised hosts.
    • Uses various protocols and ports, often non-standard ones, to evade detection.
    • Allows attackers to remotely manage and direct malicious activities.
    Study this card →
  • Full Disk Encryption (FDE)

    Flip card

    A security feature that encrypts all data on a hard drive or storage device, protecting it from unauthorized access if the device is lost, stolen, or accessed by an unauthorized party.

    • Encrypts the entire storage volume, including operating system and user data.
    • Data is unreadable without the correct decryption key or password.
    • Protects 'data at rest'.
    Study this card →
  • SSH (Secure Shell)

    Flip card

    A cryptographic network protocol for operating network services securely over an unsecured network. It is typically used for remote command-line login and remote command execution, but also supports tunneling, port forwarding, and file transfers.

    • Uses TCP port 22 by default.
    • Provides strong authentication and encrypted communication.
    • Commonly used for remote administration.
    Study this card →
  • Log Parsing and Normalization

    Flip card

    The process by which a SIEM system extracts relevant data fields from raw, unstructured log messages and transforms them into a standardized, structured format for easier analysis and correlation.

    • Essential for making heterogeneous log data usable.
    • Involves identifying timestamps, source/destination IPs, event types, etc.
    • Enables cross-source correlation and consistent querying.
    Study this card →
  • Non-repudiation

    Flip card

    A security principle that guarantees that the sender of a message or the performer of an action cannot later deny having sent the message or performed the action.

    • Often achieved using digital signatures and cryptographic hashing.
    • Provides proof of origin and integrity.
    • Crucial in legal and financial transactions.
    Study this card →
  • Credential Stuffing

    Flip card

    An attack where an attacker takes a list of compromised username-password pairs, often obtained from a data breach on one service, and attempts to use them to log into a large number of other, unrelated online services.

    • Relies on users reusing passwords across multiple sites.
    • Automated using bots.
    • Often follows a large data breach.
    Study this card →
  • SQL Injection Signatures

    Flip card

    SQL injection signatures are specific keywords, functions, or patterns found within attacker-crafted SQL queries that indicate an attempt to exploit database vulnerabilities.

    • Common keywords: 'UNION SELECT', 'OR 1=1', 'DROP TABLE'.
    • Functions for enumeration: '@@version', 'user()', 'database()'.
    • Functions for timing attacks: 'SLEEP()', 'pg_sleep()'.
    Study this card →
  • Principle of Least Privilege

    Flip card

    A security principle requiring that a user or process be given only the minimum necessary authorization to perform its function.

    • Reduces the attack surface.
    • Limits the damage from compromised accounts.
    • Requires regular review of access rights.
    Study this card →
  • Principle of Least Privilege (PoLP)

    Flip card

    A security principle requiring that users, programs, or processes be granted only the essential access rights or permissions needed to perform their assigned functions, and no more. This minimizes the potential damage from errors, compromises, or malicious actions.

    • Grants minimum necessary access.
    • Reduces attack surface and impact of compromise.
    • Applies to users, applications, and systems.
    Study this card →
  • Protocol Mismatching/Port Masquerading

    Flip card

    A technique where attackers use a well-known port (e.g., 80, 443) for a protocol other than its standard, often to bypass firewall rules and network monitoring.

    • Leverages trust in common ports to hide malicious traffic.
    • Requires deep packet inspection (DPI) to detect.
    • Often used for C2 communication or data exfiltration.
    Study this card →

Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.