Exit demo CFR-410 CyberSec First Responder (CFR) PDF format · free preview

CertNexus CFR-410 - Questions & Answers

Free preview · every answer includes a full explanation

Product page: https://prepkeys.com/cfr-410.html

Question 1
Single choice

The NIST framework 800-137 breaks down the concept of continuous monitoring into which system of tiers?

A.

Tier 1 is information systems, Tier 2 is mission/business processes, and Tier 3 is the organization.

B.

Tier 1 is the organization, Tier 2 is mission/business processes, and Tier 3 is information systems.

C.

Tier 1 is information systems, Tier 2 is the organization, and Tier 3 is mission/business processes.

D.

Tier 1 is the organization, Tier 2 is information systems, and Tier 3 is mission/business processes.

Question 2
Multiple choice

What are the two most appropriate binary analysis techniques to use in digital forensics analysis? (Choose two.)

A.

Injection Analysis

B.

Forensic Analysis

C.

Static Analysis

D.

Dynamic Analysis

Question 3
Single choice

Which approach to cybersecurity involves a series of defensive mechanisms that are layered to protect valuable data and information?

A.

Network segmentation

B.

Defense in depth

C.

Tiered security

D.

Endpoint detection and response

Question 4
Single choice

An administrator investigating intermittent network communication problems has identified an excessive amount of traffic from an external-facing host to an unknown location on the Internet.

Which of the following BEST describes what is occurring?

A.

The network is experiencing a denial of service (DoS) attack.

B.

A malicious user is exporting sensitive data.

C.

Rogue hardware has been installed.

D.

An administrator has misconfigured a web proxy.

Question 5
Single choice

Which of the following can increase an attack surface?

A.

Old or unused code

B.

Vulnerability scanning

C.

Mapping of an attack surface

D.

Penetration scanning

Question 6
Single choice

During an incident, the following actions have been taken:

1. Executing the malware in a sandbox environment
2. Reverse engineering the malware
3. Conducting a behavior analysis

Based on the steps presented, which of the following incident handling processes has been taken?

A.

Containment

B.

Eradication

C.

Recovery

D.

Identification

Question 7
Multiple choice

Which of the following, when exposed together, constitutes PII? (Choose two.)

A.

Full name

B.

Birth date

C.

Account balance

D.

Marital status

E.

Employment status

Question 8
Single choice

Which of the following types of attackers would be MOST likely to use multiple zero-day exploits executed against high-value, well-defended targets for the purposes of espionage and sabotage?

A.

Cybercriminals

B.

Hacktivists

C.

State-sponsored hackers

D.

Cyberterrorist

Question 9
Single choice

Which of the following tools can help to detect suspicious or unauthorized changes to critical system configuration files?

A.

Tripwire

B.

Logstash

C.

Nessus

D.

Netcat

E.

Ifconfig

Question 10
Single choice

Which of the following are components of Security Content Automation Protocol (SCAP)?

A.

CVM, NVD, and OSVDB

B.

CVE, CVSS, and OSVDB

C.

CVE, CVSS, and OVAL

D.

CWE, CWSS, and OVAL

Showing 10 of 180 questions · Unlock the full set