Security Operations Flashcards
7 cards from real CySA+ Test practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security Operations flashcards as text
A SOC detects outbound DNS requests with unusually long subdomains containing random-looking character strings. What attack technique does this suggest?
Answer: DNS tunneling for data exfiltration
Long encoded subdomains in DNS queries are characteristic of DNS tunneling, where data is exfiltrated by embedding it in DNS request subdomains.
Which containment strategy isolates a compromised host while preserving network visibility for ongoing investigation?
Answer: Placing the host in a quarantine VLAN with restricted outbound access
A quarantine VLAN blocks malicious outbound communication while maintaining the host's network connectivity for remote forensic investigation and monitoring.
An analyst discovers a scheduled task running every 30 minutes that executes a script from a hidden directory. What MITRE ATT&CK tactic does this represent?
Answer: Persistence
Scheduled tasks that execute attacker-controlled code at regular intervals are a classic persistence mechanism, ensuring code survives reboots and user logoffs.
During log analysis, an analyst notices a user account authenticating successfully from two geographically distant locations within 15 minutes. What is this called?
Answer: Impossible travel anomaly
Impossible travel occurs when authentication events appear from locations too far apart to be physically possible in the elapsed time, indicating credential compromise.
A security analyst wants to determine whether a suspicious file is malicious without executing it in production. What analysis method should be used FIRST?
Answer: Static analysis of the file's hash, strings, and metadata
Static analysis examines a file's properties without executing it, providing initial triage information quickly with no risk of detonating the payload.
Which log source is MOST useful for detecting process injection attacks on Windows systems?
Answer: Sysmon logs with process creation and CreateRemoteThread events
Sysmon captures detailed process-level telemetry including CreateRemoteThread calls and memory allocation events that are hallmarks of process injection techniques.
A threat intelligence feed reports a new vulnerability being actively exploited in the wild. What is the FIRST action a SOC should take?
Answer: Determine if affected software exists in the environment and assess exposure
Scoping the vulnerability's presence in your environment determines actual risk exposure before committing resources to patching or other defensive actions.