CertNexus CFR-410 Dumps - 100% Cover Real Exam Questions (Updated 100 Questions) [Q50-Q68]

Share

CertNexus CFR-410 Dumps - 100% Cover Real Exam Questions (Updated 100 Questions)

Real CFR-410 dumps - Real CertNexus dumps PDF

NEW QUESTION 50
A company has noticed a trend of attackers gaining access to corporate mailboxes. Which of the following would be the BEST action to take to plan for this kind of attack in the future?

  • A. Scanning email server for vulnerabilities
  • B. Hardening the Microsoft Exchange Server
  • C. Conducting security awareness training
  • D. Auditing account password complexity

Answer: A

 

NEW QUESTION 51
During an incident, the following actions have been taken:
- Executing the malware in a sandbox environment
- Reverse engineering the malware
- Conducting a behavior analysis
Based on the steps presented, which of the following incident handling processes has been taken?

  • A. Identification
  • B. Eradication
  • C. Containment
  • D. Recovery

Answer: C

Explanation:
The "Containment, eradication and recovery" phase is the period in which incident response team tries to contain the incident and, if necessary, recover from it (restore any affected resources, data and/or processes).

 

NEW QUESTION 52
A cybersecurity expert assigned to be the IT manager of a middle-sized company discovers that there is little endpoint security implementation on the company's systems. Which of the following could be included in an endpoint security solution? (Choose two.)

  • A. Anti-malware
  • B. Network Address Translation (NAT)
  • C. Web proxy
  • D. Network monitoring system
  • E. Data loss prevention (DLP)

Answer: C,D

 

NEW QUESTION 53
During which of the following attack phases might a request sent to port 1433 over a whole company network be seen within a log?

  • A. Reconnaissance
  • B. Scanning
  • C. Persistence
  • D. Gaining access

Answer: B

 

NEW QUESTION 54
A security engineer is setting up security information and event management (SIEM). Which of the following log sources should the engineer include that will contain indicators of a possible web server compromise? (Choose two.)

  • A. Web server logs
  • B. Domain controller logs
  • C. Proxy logs
  • D. NetFlow logs
  • E. FTP logs

Answer: A,B

 

NEW QUESTION 55
After a hacker obtained a shell on a Linux box, the hacker then sends the exfiltrated data via Domain Name System (DNS). This is an example of which type of data exfiltration?

  • A. Rogue service
  • B. Steganography
  • C. Covert channels
  • D. File sharing services

Answer: C

 

NEW QUESTION 56
During a malware-driven distributed denial of service attack, a security researcher found excessive requests to a name server referring to the same domain name and host name encoded in hexadecimal. The malware author used which type of command and control?

  • A. File Transfer Protocol (FTP)
  • B. Custom channel
  • C. Internet Relay Chat (IRC)
  • D. Dnscat2

Answer: A

 

NEW QUESTION 57
If a hacker is attempting to alter or delete system audit logs, in which of the following attack phases is the hacker involved?

  • A. Performing reconnaissance
  • B. Covering tracks
  • C. Gaining persistence
  • D. Expanding access

Answer: B

 

NEW QUESTION 58
Various logs are collected for a data leakage case to make a forensic analysis. Which of the following are MOST important for log integrity? (Choose two.)

  • A. Time stamp
  • B. Modified date/time
  • C. Hash value
  • D. Log type
  • E. Log path

Answer: A,C

 

NEW QUESTION 59
To minimize vulnerability, which steps should an organization take before deploying a new Internet of Things (IoT) device? (Choose two.)

  • A. Setting up new users
  • B. Changing the default password
  • C. Updating the device firmware
  • D. Disabling IPv6
  • E. Enabling the firewall

Answer: C,E

 

NEW QUESTION 60
An incident responder discovers that the CEO logged in from their New York City office and then logged in from a location in Beijing an hour later. The incident responder suspects that the CEO's account has been compromised. Which of the following anomalies MOST likely contributed to the incident responder's suspicion?

  • A. Geovelocity
  • B. False positive
  • C. Advanced persistent threat (APT) activity
  • D. Geolocation

Answer: A

 

NEW QUESTION 61
A Linux system administrator found suspicious activity on host IP 192.168.10.121. This host is also establishing a connection to IP 88.143.12.123. Which of the following commands should the administrator use to capture only the traffic between the two hosts?

  • A. # tcpdump -i eth0 host 88.143.12.123
  • B. # tcpdump -i eth0 src 88.143.12.123
  • C. # tcpdump -i eth0 dst 88.143.12.123
  • D. # tcpdump -i eth0 host 192.168.10.121

Answer: C

 

NEW QUESTION 62
Which common source of vulnerability should be addressed to BEST mitigate against URL redirection attacks?

  • A. Users
  • B. Application
  • C. Network infrastructure
  • D. Configuration files

Answer: B

 

NEW QUESTION 63
A Linux administrator is trying to determine the character count on many log files. Which of the following command and flag combinations should the administrator use?

  • A. uniq -c
  • B. wc -m
  • C. tr -d
  • D. grep -c

Answer: B

 

NEW QUESTION 64
A security operations center (SOC) analyst observed an unusually high number of login failures on a particular database server. The analyst wants to gather supporting evidence before escalating the observation to management. Which of the following expressions will provide login failure data for 11/24/2015?

  • A. grep 20151124 security_log | grep "login"
  • B. grep 20150124 security_log | grep "login_failure"
  • C. grep 20151124 security_log | grep -c "login"
  • D. grep 20151124 security_log | grep -c "login failure"

Answer: A

 

NEW QUESTION 65
A government organization responsible for critical infrastructure is being attacked and files on the server been deleted. Which of the following are the most immediate communications that should be made regarding the incident? (Choose two.)

  • A. Notifying law enforcement
  • B. Notifying a national compute emergency response team (CERT) or cybersecurity incident response team (CSIRT)
  • C. Notifying the relevant vendor
  • D. Notifying a mitigation expert
  • E. Notifying the media

Answer: B,D

 

NEW QUESTION 66
In which of the following attack phases would an attacker use Shodan?

  • A. Reconnaissance
  • B. Scanning
  • C. Persistence
  • D. Gaining access

Answer: B

 

NEW QUESTION 67
Which of the following is a method of reconnaissance in which a ping is sent to a target with the expectation of receiving a response?

  • A. Passive scanning
  • B. Network enumeration
  • C. Application enumeration
  • D. Active scanning

Answer: B

 

NEW QUESTION 68
......


CertNexus CFR-410 Exam Syllabus Topics:

TopicDetails
Topic 1
  • Identify and conduct vulnerability assessment processes
  • Identify applicable compliance, standards, frameworks, and best practices for privacy
Topic 2
  • Determine the extent of threats and recommend courses of action or countermeasures to mitigate risks
  • Correlate incident data and create reports
Topic 3
  • Implement system security measures in accordance with established procedures
  • Determine tactics, techniques, and procedures (TTPs) of intrusion sets
Topic 4
  • Perform analysis of log files from various sources to identify possible threats to network security
  • Protect organizational resources through security updates
Topic 5
  • Protect identity management and access control within the organization
  • Employ approved defense-in-depth principles and practices

 

Realistic Exam4Tests CFR-410 Dumps PDF - 100% Passing Guarantee: https://braindumps.exam4tests.com/CFR-410-pdf-braindumps.html