Free CertNexus Certification CFR-410 Ultimate Study Guide (Updated 100 Questions) [Q21-Q40]

Rate this post

Free CertNexus Certification CFR-410 Ultimate Study Guide (Updated 100 Questions)

Get to the Top with CFR-410 Practice Exam Questions

Q21. A security professional discovers a new ransomware strain that disables antivirus on the endpoint during an infection. Which location would be the BEST place for the security professional to find technical information about this malware?

 
 
 
 

Q22. After a hacker obtained a shell on a Linux box, the hacker then sends the exfiltrated data via Domain Name System (DNS). This is an example of which type of data exfiltration?

 
 
 
 

Q23. According to Payment Card Industry Data Security Standard (PCI DSS) compliance requirements, an organization must retain logs for what length of time?

 
 
 
 

Q24. During a security investigation, a suspicious Linux laptop is found in the server room. The laptop is processing information and indicating network activity. The investigator is preparing to launch an investigation to determine what is happening with this laptop. Which of the following is the MOST appropriate set of Linux commands that should be executed to conduct the investigation?

 
 
 
 

Q25. An administrator believes that a system on VLAN 12 is Address Resolution Protocol (ARP) poisoning clients on the network. The administrator attaches a system to VLAN 12 and uses Wireshark to capture traffic. After reviewing the capture file, the administrator finds no evidence of ARP poisoning. Which of the following actions should the administrator take next?

 
 
 
 

Q26. A network security analyst has noticed a flood of Simple Mail Transfer Protocol (SMTP) traffic to internal clients. SMTP traffic should only be allowed to email servers. Which of the following commands would stop this attack? (Choose two.)

 
 
 
 
 

Q27. Which common source of vulnerability should be addressed to BEST mitigate against URL redirection attacks?

 
 
 
 

Q28. Which of the following, when exposed together, constitutes PII? (Choose two.)

 
 
 
 
 

Q29. Which of the following enables security personnel to have the BEST security incident recovery practices?

 
 
 
 

Q30. Which of the following methods are used by attackers to find new ransomware victims? (Choose two.)

 
 
 
 
 

Q31. An incident responder discovers that the CEO logged in from their New York City office and then logged in from a location in Beijing an hour later. The incident responder suspects that the CEO’s account has been compromised. Which of the following anomalies MOST likely contributed to the incident responder’s suspicion?

 
 
 
 

Q32. A security operations center (SOC) analyst observed an unusually high number of login failures on a particular database server. The analyst wants to gather supporting evidence before escalating the observation to management. Which of the following expressions will provide login failure data for 11/24/2015?

 
 
 
 

Q33. A security administrator is investigating a compromised host. Which of the following commands could the investigator use to display executing processes in real time?

 
 
 
 

Q34. Which of the following is the FIRST step taken to maintain the chain of custody in a forensic investigation?

 
 
 
 

Q35. Which of the following are well-known methods that are used to protect evidence during the forensics process? (Choose three.)

 
 
 
 
 
 

Q36. A company help desk is flooded with calls regarding systems experiencing slow performance and certain Internet sites taking a long time to load or not loading at all. The security operations center (SOC) analysts who receive these calls take the following actions:
– Running antivirus scans on the affected user machines
– Checking department membership of affected users
– Checking the host-based intrusion prevention system (HIPS) console for affected user machine alerts
– Checking network monitoring tools for anomalous activities
Which of the following phases of the incident response process match the actions taken?

 
 
 
 

Q37. It was recently discovered that many of an organization’s servers were running unauthorized cryptocurrency mining software. Which of the following assets were being targeted in this attack? (Choose two.)

 
 
 
 
 

Q38. After a security breach, a security consultant is hired to perform a vulnerability assessment for a company’s web application. Which of the following tools would the consultant use?

 
 
 
 

Q39. Organizations considered “covered entities” are required to adhere to which compliance requirement?

 
 
 
 

Q40. A common formula used to calculate risk is: + Threats + Vulnerabilities = Risk. Which of the following represents the missing factor in this formula?

 
 
 
 

CertNexus CFR-410 Exam Syllabus Topics:

Topic Details
Topic 1
  • Identify applicable compliance, standards, frameworks, and best practices for security
  • Execute the incident response process
Topic 2
  • Analyze common indicators of potential compromise, anomalies, and patterns
  • Review forensic images and other data sources for recovery of potentially relevant information
Topic 3
  • Provide advice and input for disaster recovery, contingency
  • Implement specific cybersecurity countermeasures for systems and applications
Topic 4
  • Protect identity management and access control within the organization
  • Employ approved defense-in-depth principles and practices
Topic 5
  • Develop and implement cybersecurity independent audit processes
  • Analyze and report system security posture trends

 

Pass CertNexus CFR-410 exam – questions – convert Tets Engine to PDF: https://www.it-tests.com/CFR-410.html

         

Related Links: myportal.utt.edu.tt myportal.utt.edu.tt www.stes.tyc.edu.tw myportal.utt.edu.tt myportal.utt.edu.tt www.stes.tyc.edu.tw