1. A web application firewall log shows the following request against a public e-commerce site:
`192.168.1.15 - - [10/Mar/2024:14:22:07 +0000] "GET /products.php?id=1' UNION SELECT username,password FROM users-- HTTP/1.1" 200 1523`
Which type of attack does this log entry MOST likely indicate?
Security Operations
A.Command injection
B.Directory traversal
C.SQL injection
D.Cross-site scripting (XSS)
Show answerAnswer
C. SQL injection
The request injects a `UNION SELECT` statement into the `id` parameter, attempting to append a second query that pulls usernames and passwords from the `users` table — a textbook SQL injection technique. The trailing `--` comments out the rest of the original query to keep the syntax valid.
2. An incident responder is using the Diamond Model of Intrusion Analysis to document an attack. The team identifies the malicious IP address 203.0.113.55 that hosted the phishing page and later received stolen credentials. Within the Diamond Model, which core feature does this IP address represent?
Vulnerability Management
A.Capability
B.Infrastructure
C.Victim
D.Adversary
Show answerAnswer
B. Infrastructure
In the Diamond Model, Infrastructure refers to the physical or logical resources the adversary uses to deliver a capability or maintain communication, such as IP addresses, domains, and servers — exactly what the phishing-hosting IP represents.
3. A security analyst is reviewing a vulnerability scan report for a fleet of Windows servers. The report flags several servers as missing critical security updates for the operating system and various installed applications. The organization needs a method to automate the deployment of these patches across all affected servers while minimizing manual effort. Which solution is best suited for this task?
Vulnerability Management
A.Patch Management System
B.Security Information and Event Management (SIEM)
C.Data Loss Prevention (DLP)
D.Vulnerability Management System (VMS)
Show answerAnswer
A. Patch Management System
A Patch Management System is specifically designed to automate the process of identifying, downloading, testing, and deploying patches and updates across an organization's IT infrastructure, directly addressing the requirement to automate patch deployment for missing security updates.
4. An incident responder documents an attack using the Diamond Model of Intrusion Analysis. In the report, they record the C2 domain name, the hosting provider's IP address, and the compromised relay server used to route traffic to the attacker. Which core feature (vertex) of the Diamond Model does this information populate?
Vulnerability Management
A.Victim
B.Capability
C.Adversary
D.Infrastructure
Show answerAnswer
D. Infrastructure
The Diamond Model's Infrastructure vertex captures the physical or logical communication structures the adversary uses to deliver capabilities and maintain control, such as domains, IP addresses, and relay/proxy servers. Adversary refers to the threat actor, Capability to the tools/malware/techniques used, and Victim to the targeted organization or asset.
5. During an incident, an analyst identifies that an attacker used a phishing email for initial access, then leveraged a scheduled task for persistence, and finally used PsExec to move laterally to a file server. The analyst wants to document this behavior using a standardized adversary behavior framework for the incident report. Which framework should be used?
Security Operations
A.NIST Cybersecurity Framework (CSF)
B.CVSS scoring framework
C.MITRE ATT&CK
D.Diamond Model of Intrusion Analysis
Show answerAnswer
C. MITRE ATT&CK
MITRE ATT&CK is a knowledge base of adversary tactics and techniques (e.g., Initial Access, Persistence, Lateral Movement) used to categorize observed behaviors like phishing, scheduled tasks, and PsExec usage into standardized TTPs.
6. A development team is building a new mobile application that will handle sensitive customer data. They want to identify security vulnerabilities such as hardcoded credentials, insecure configuration, and potential injection flaws early in the development lifecycle, without actually running the application. Which testing methodology is best suited for this purpose?
Vulnerability Management
A.Dynamic Application Security Testing (DAST)
B.Static Application Security Testing (SAST)
C.Interactive Application Security Testing (IAST)
D.Software Composition Analysis (SCA)
Show answerAnswer
B. Static Application Security Testing (SAST)
Static Application Security Testing (SAST) analyzes an application's source code, bytecode, or binary code without executing it. This allows for the identification of vulnerabilities such as hardcoded credentials, insecure configurations, and injection flaws early in the SDLC, aligning perfectly with the requirement to find flaws 'without actually running the application'.
7. A cyber incident response team has successfully contained a sophisticated persistent threat (APT) from their network. They are now in the post-incident activity phase. Which of the following activities is MOST crucial for improving the organization's future security posture based on this incident?
Incident Response and Management
A.Update the incident response plan to reflect new procedures.
B.Archive all incident logs and forensic images for future reference.
C.Train all employees on advanced phishing detection techniques.
D.Conduct a lessons learned meeting with all involved stakeholders.
Show answerAnswer
D. Conduct a lessons learned meeting with all involved stakeholders.
A 'lessons learned' meeting is the most crucial activity as it facilitates a comprehensive review of the entire incident, identifies what worked and what didn't, and gathers insights from all stakeholders to drive actionable improvements across processes, technologies, and training.
8. A cloud security architect wants to prevent lateral movement between application workloads that reside on the same subnet by enforcing granular, workload-level firewall policies instead of relying solely on VLAN boundaries. Which architectural concept BEST describes this approach?
Security Operations
A.Air-gapped network
B.Network address translation (NAT)
C.Demilitarized zone (DMZ)
D.Microsegmentation
Show answerAnswer
D. Microsegmentation
Microsegmentation applies fine-grained, identity- or workload-based security policies down to the individual host or application level, restricting east-west traffic even within the same subnet or VLAN. A DMZ isolates public-facing services from the internal network, an air gap physically isolates a network entirely, and NAT translates addresses rather than enforcing segmentation policy.
9. A security analyst discovers a critical vulnerability in a production web application that has a CVSSv3 base score of 9.8. The vulnerability allows unauthenticated remote code execution. The development team is currently focused on a major feature release. Which stakeholder group should be immediately informed, emphasizing the potential for data breach and service unavailability, to ensure prompt prioritization and resource allocation for remediation?
Reporting and Communication
A.Human Resources department
B.Legal department
C.Executive leadership and application owners
D.End-users of the web application
Show answerAnswer
C. Executive leadership and application owners
Executive leadership and application owners have the authority to re-prioritize development efforts and allocate resources. They need to understand the critical business impact (data breach, service unavailability) to make informed decisions.
10. A vulnerability management team must choose which finding to remediate first this week. Vulnerability A has a CVSS Base Score of 7.5, appears on the CISA Known Exploited Vulnerabilities (KEV) catalog, and affects an internet-facing VPN appliance. Vulnerability B has a CVSS Base Score of 9.1 but affects an internal file server with no known exploitation activity. Which vulnerability should be prioritized first, and why?
Vulnerability Management
A.Both should be scheduled with equal priority since their CVSS scores are within two points of each other
B.Vulnerability B, because a higher CVSS score always takes precedence regardless of other factors
C.Vulnerability A, because active in-the-wild exploitation and internet exposure increase real-world risk despite the lower base score
D.Vulnerability B, because internal systems must always be patched before external systems
Show answerAnswer
C. Vulnerability A, because active in-the-wild exploitation and internet exposure increase real-world risk despite the lower base score
Risk-based prioritization considers exploitability in the wild (KEV listing) and exposure (internet-facing) alongside CVSS severity; a lower-scored but actively exploited, externally reachable vulnerability typically represents greater real-world risk than a higher-scored but unexploited internal one.
11. Employees on a corporate segment suddenly lose network connectivity. An analyst captures traffic and sees that for a single DHCPDISCOVER broadcast, two DHCPOFFER messages are returned from two different MAC addresses, one of which is not on the approved switch port list, and clients receiving that offer are assigned an incorrect default gateway. Which activity does this indicate?
Security Operations
A.DNS spoofing
B.ARP spoofing
C.DHCP starvation attack
D.Rogue DHCP server
Show answerAnswer
D. Rogue DHCP server
An unauthorized device answering DHCP requests with its own configuration (often pointing clients to a malicious gateway) is a rogue DHCP server, typically used to enable man-in-the-middle attacks. DHCP starvation floods the legitimate server with fake requests to exhaust its address pool rather than issuing false offers itself, and ARP/DNS spoofing operate on different protocols.
12. An analyst reviewing authentication logs from a public-facing web application finds the following pattern from a single source IP over 10 minutes:
5,000 login attempts against 3,200 distinct usernames, with each username attempted only one or two times using a unique password, followed by 12 successful logins to different accounts.
Which attack technique does this pattern indicate?
Security Operations
A.Password spraying
B.Credential stuffing
C.Brute-force attack
D.Kerberoasting
Show answerAnswer
B. Credential stuffing
Credential stuffing uses large lists of previously breached username:password pairs, so each unique username is tried with only one or two specific (not common) passwords rather than many passwords against one account (brute force) or one common password against many accounts (password spraying); the resulting successes reflect users who reused breached credentials. Kerberoasting targets Kerberos service ticket hashes and would not appear as web login attempts.
13. A threat intelligence team wants to automatically share and receive structured indicators of compromise (IOCs) with an information sharing and analysis center (ISAC) using a standardized, machine-readable format transported over a defined exchange protocol. Which pair of standards should the team implement?
Security Operations
A.OpenIOC over FTP
B.CVSS over HTTP
C.YARA rules over SMTP
D.STIX over TAXII
Show answerAnswer
D. STIX over TAXII
STIX (Structured Threat Information eXpression) defines the standardized, machine-readable format for describing threat intelligence, while TAXII (Trusted Automated eXchange of Indicator Information) defines the protocol for transporting that data between organizations—together the industry standard for automated sharing.
14. A security analyst is drafting an incident report for a successful ransomware attack that encrypted several critical file servers. The incident response team managed to recover all data from backups and restore services within 24 hours. The report needs to highlight the effectiveness of the incident response plan and the team's performance. Which of the following KPIs would be MOST appropriate to demonstrate this success to management?
Reporting and Communication
A.Number of security awareness training sessions conducted.
B.Total number of ransomware variants detected.
C.Mean Time To Recover (MTTR) for critical services.
D.Percentage of endpoint detection and response (EDR) agents deployed.
Show answerAnswer
C. Mean Time To Recover (MTTR) for critical services.
Mean Time To Recover (MTTR) directly measures how quickly an organization can restore services after an incident. A MTTR of 24 hours for a ransomware attack demonstrates highly effective incident response and recovery capabilities.
15. During a monthly security review, a security analyst notes a consistent increase in the number of successful brute-force attacks against SSH services, despite existing lockout policies. The analyst needs to communicate this trend to the network operations team to prompt a configuration change. Which of the following communication methods is MOST effective for conveying technical details and facilitating immediate action?
Reporting and Communication
A.An email to the network operations team manager summarizing the trend.
B.A presentation during the quarterly CISO briefing highlighting the risk.
C.A casual mention in a team chat with a link to a dashboard.
D.A formal incident report submitted through the ticketing system with detailed logs.
Show answerAnswer
D. A formal incident report submitted through the ticketing system with detailed logs.
A formal incident report submitted through a ticketing system provides a structured way to convey technical details, attach relevant logs, assign ownership, and track remediation, which is crucial for facilitating immediate and documented action by the network operations team.
16. A network administrator runs an Nmap SYN scan across the 10.1.5.0/24 subnet, sending probe packets directly to each address to identify live hosts, open ports, and service versions for an updated asset inventory. Which asset discovery technique does this describe?
Vulnerability Management
A.Active discovery
B.Passive discovery
C.NetFlow analysis
D.Agent-based discovery
Show answerAnswer
A. Active discovery
Active discovery involves sending probe packets (pings, SYN packets, port scans) directly to hosts to enumerate devices and services, unlike passive discovery which only observes existing traffic.
17. A security analyst is reviewing a custom web application's access logs and identifies the following requests originating from a single IP address (10.10.10.5):
```
GET /api/v1/users?search=admin%27%20OR%20%271%27%3D%271 HTTP/1.1
GET /api/v1/products?category=electronics%27%3B%20WAITFOR%20DELAY%20%270%3A0%3A5%27--%20 HTTP/1.1
GET /api/v1/orders?id=123%20AND%20SUBSTRING%28version%28%29%2C1%2C1%29%3D%275%27 HTTP/1.1
```
Which type of attack is being attempted, and what specific variant is indicated by the second and third entries?
Security Operations
A.Command Injection; OS Command Injection
B.Cross-Site Scripting (XSS); Reflected XSS
C.XML External Entity (XXE); Out-of-band XXE
D.SQL Injection; Time-based Blind SQL Injection
Show answerAnswer
D. SQL Injection; Time-based Blind SQL Injection
The requests show classic SQL injection payloads: `admin' OR '1'='1` (boolean-based), `WAITFOR DELAY` (time-based), and `SUBSTRING(version(),1,1)='5'` (error/boolean-based). Specifically, the `WAITFOR DELAY` command indicates a time-based blind SQL injection, where the attacker infers information based on the server's response time. The `SUBSTRING` query combined with a conditional check also suggests a blind SQL injection variant.
18. A security analyst discovers a critical misconfiguration on a production web server that exposes sensitive customer data. The analyst needs to communicate this finding to the server owner and management. Which of the following elements is MOST crucial to include in the initial communication to ensure the issue is understood and prioritized correctly?
Reporting and Communication
A.The potential business impact (e.g., data breach, regulatory fines) and severity rating.
B.The specific steps to reproduce the misconfiguration and proof of concept (PoC) code.
C.A detailed history of the server's patching schedule for the last year.
D.A list of all previous misconfigurations found on other servers.
Show answerAnswer
A. The potential business impact (e.g., data breach, regulatory fines) and severity rating.
For management and server owners, understanding the potential business impact (financial, reputational, legal) and the severity rating (e.g., CVSS score or internal rating) is paramount. This information directly influences their prioritization and resource allocation for remediation, rather than technical reproduction steps or historical data.
19. A security analyst is investigating a suspected insider threat. The analyst needs to collect volatile data from a running Windows server without altering the system state unnecessarily. Which of the following data types should be collected FIRST due to its ephemeral nature?
Incident Response and Management
A.Hard drive contents (full disk image)
B.System memory (RAM dump)
C.Network traffic captures (PCAPs)
D.Registry hives and configuration files
Show answerAnswer
B. System memory (RAM dump)
System memory (RAM) is the most volatile data and contains crucial information about running processes, network connections, and open files that would be lost immediately if the system were shut down or rebooted. Therefore, it should be collected first.
20. A malware analyst detonates a sample in an automated sandbox but observes no malicious behavior in the report. Manual analysis of the binary reveals a call to GetTickCount followed by a conditional branch that terminates the process if execution time appears too short. Which sandbox evasion technique is being used?
Security Operations
A.API hammering to overwhelm the analysis engine
B.Environment fingerprinting via registry key checks
C.Timing-based evasion to detect accelerated or short-lived sandbox execution
D.Process hollowing to hide the payload inside a legitimate process
Show answerAnswer
C. Timing-based evasion to detect accelerated or short-lived sandbox execution
Checking elapsed time (via GetTickCount) and terminating if execution appears too fast is a timing-based evasion technique; malware assumes sandboxes have limited analysis windows or accelerated clocks, so it stalls or exits to avoid revealing behavior.
21. A threat intelligence analyst rates an external feed source as 'B2' when logging a new indicator, meaning the source is usually reliable and the information is probably true. Which evaluation system is being used to grade the source and the information?
Security Operations
A.MITRE ATT&CK Navigator
B.STIX confidence levels
C.Traffic Light Protocol (TLP)
D.Admiralty Code
Show answerAnswer
D. Admiralty Code
The Admiralty Code (also called the NATO System) grades intelligence using a letter (A-F) for source reliability and a number (1-6) for information credibility, so 'B2' means a usually reliable source providing probably true information. STIX confidence levels are numeric scores in threat intel objects, MITRE ATT&CK Navigator visualizes adversary techniques, and TLP governs how information may be shared rather than its reliability.
22. A security analyst is investigating a suspected data exfiltration incident. Reviewing proxy logs, the analyst observes a large volume of outbound traffic from an internal host (10.10.10.50) to an external IP address (203.0.113.10) on a non-standard port, but the traffic appears to be legitimate HTTP/S. Further inspection of the traffic reveals highly obfuscated data within the HTTP User-Agent and Accept-Language headers. What type of exfiltration technique is most likely being employed?
Security Operations
A.DNS Tunneling
B.SMB Relay
C.ICMP Tunneling
D.HTTP/HTTPS Tunneling
Show answerAnswer
D. HTTP/HTTPS Tunneling
HTTP/HTTPS tunneling involves encapsulating other protocols or data within HTTP/HTTPS traffic to bypass firewalls and proxy servers. The use of non-standard ports and obfuscated data within HTTP headers are strong indicators of this technique.
23. A security analyst is preparing a quarterly report on the organization's security posture for the Board of Directors. The board is primarily interested in high-level trends and the overall effectiveness of security investments. Which of the following Key Performance Indicators (KPIs) would be MOST appropriate to include in this report?
Reporting and Communication
A.Percentage of security patches applied within 48 hours for critical systems.
B.Average time to detect (MTTD) and contain (MTTC) critical incidents.
C.Count of daily blocked intrusion attempts by the Web Application Firewall (WAF).
D.Number of successful phishing emails reported by employees.
Show answerAnswer
B. Average time to detect (MTTD) and contain (MTTC) critical incidents.
The Board of Directors needs strategic insights into overall security program effectiveness. MTTD and MTTC for critical incidents provide a holistic view of the organization's ability to respond to significant threats, directly reflecting the return on security investments in a way that is understandable at a high level. Other options are too granular or focused on specific operational aspects.
24. A security analyst is investigating a suspected data exfiltration incident. The attacker used a compromised user account to log into a critical server and then attempted to transfer a large file to an external IP address. The analyst has identified the compromised account and the external IP. Which of the following actions represents the BEST long-term containment strategy for this specific threat?
Incident Response and Management
A.Force a password reset for all user accounts.
B.Implement a Data Loss Prevention (DLP) solution.
C.Disable the compromised user account immediately.
D.Block the external IP address at the perimeter firewall.
Show answerAnswer
B. Implement a Data Loss Prevention (DLP) solution.
While disabling the account and blocking the IP are immediate containment, a DLP solution offers long-term containment by actively monitoring and preventing unauthorized data transfers, regardless of which account is compromised or which external IP is used, addressing the root problem of data exfiltration attempts.
25. An analyst reviewing endpoint logs finds the following PowerShell command executed by a non-administrative user:
powershell.exe -NoP -NonI -W Hidden -Enc SQBFAFgAIAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQAUwB0AHIAaQBuAGcAKAAn...
Which characteristic of this command is the STRONGEST indicator of malicious intent?
Security Operations
A.The Base64-encoded command combined with hidden window and download activity
B.The .exe file extension present in the process name
C.The command was run by a non-administrative user account
D.The use of the -NoP (NoProfile) flag to speed up execution
Show answerAnswer
A. The Base64-encoded command combined with hidden window and download activity
Base64-encoded PowerShell (-Enc) combined with a hidden window (-W Hidden) is a common obfuscation and living-off-the-land technique used to conceal a downloader/execution payload, strongly indicating malicious intent versus benign scripting.
A Patch Management System is a software solution that automates the process of managing and deploying software updates and security patches across an organization's network.
Streamlines the patching process from discovery to deployment.
Helps ensure systems are up-to-date with the latest security fixes.
Often includes features for scheduling, testing, and reporting on patch status.
One of the four core Diamond Model features, representing the physical/logical communication resources (domains, IPs, servers) an adversary uses to deliver capabilities.
Four core features: Adversary, Capability, Infrastructure, Victim
Infrastructure includes C2 domains, IPs, and relay/proxy servers
Connects Adversary to Victim in the intrusion event
A globally accessible knowledge base of adversary tactics and techniques based on real-world observations, used to categorize and communicate attacker behavior (TTPs).
Organized into tactics (the 'why') and techniques (the 'how')
Covers Initial Access, Execution, Persistence, Lateral Movement, etc.
Widely used for threat hunting, detection engineering, and reporting
SAST is a white-box testing methodology that analyzes an application's source code, bytecode, or binary code for vulnerabilities without executing the application.
Identifies flaws early in the Software Development Lifecycle (SDLC).
Can find issues like injection flaws, hardcoded credentials, and insecure configurations.
Does not require a running application, making it suitable for developers.
A security architecture technique that isolates individual workloads or applications with granular policies to limit lateral movement, even within the same network segment.
Goes beyond VLAN/subnet-level isolation
Commonly implemented via software-defined networking (SDN)
The process of informing and engaging senior management and business owners about cybersecurity risks, incidents, and remediation efforts, focusing on business impact and strategic decisions.
Prioritizes business context over technical jargon.
Aims to secure resources and approval for security initiatives.
Essential for managing high-impact risks effectively.
Remediation prioritization approach that factors in real-world exploitation evidence (e.g., CISA KEV catalog) and asset exposure, not just CVSS severity.
CISA KEV lists vulnerabilities confirmed to be exploited in the wild
Internet-facing assets carry higher exposure risk than internal-only assets
Combines exploitability, exposure, and asset value with CVSS for prioritization
An unauthorized device on the network that responds to DHCP requests with its own lease information, often redirecting victims' default gateway or DNS server to attacker-controlled infrastructure.
Detected by seeing multiple DHCPOFFER from unexpected MAC/switch ports
An attack that uses large sets of previously breached username:password pairs against a login portal, relying on password reuse across sites to gain unauthorized access.
Each username is typically tried with its known specific password, not many guesses
High volume of distinct accounts attempted, low attempts per account
Mitigated with MFA, breach password screening, and rate limiting
STIX is a standardized language for representing cyber threat intelligence; TAXII is the protocol used to exchange STIX data between organizations automatically.
The process of conveying complex security details, findings, or recommendations to technical stakeholders to enable informed decision-making and action.
Requires precision and supporting evidence.
Should facilitate clear understanding and actionable steps.
Often uses ticketing systems or formal reports for tracking.
Blind SQL Injection (SQLi) is a type of SQL injection where the attacker cannot see the results of their malicious query directly within the application's response. Instead, they infer information by observing the application's behavior (e.g., response times, error messages, or subtle differences in content) to determine if a condition is true or false.
No direct data retrieval in the response.
Relies on server behavior (time delays, error messages, boolean logic).
Includes Boolean-based, Error-based, and Time-based variants.
Translating technical security findings into understandable business risks and consequences for non-technical stakeholders, enabling informed decision-making.
Focus on financial, reputational, and legal implications.
Use clear, concise language.
Tie findings to organizational goals and regulatory compliance.
A technique where malware measures elapsed execution time (e.g., via GetTickCount or sleep calls) and withholds malicious behavior if the runtime appears too short, suspecting an automated sandbox.
Sandboxes often have limited analysis windows (seconds to minutes)
Malware may sleep or check timers to outlast automated analysis
Extended/dynamic sandbox timeouts help counter this evasion
A two-part rating system used to evaluate intelligence: a letter (A-F) rates source reliability, and a number (1-6) rates the credibility of the information itself.
A=Completely reliable through F=Reliability cannot be judged
1=Confirmed through 6=Cannot be judged
Widely used in military and cyber threat intelligence to grade feeds
Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.