CFR-410 Cybersec First Responder Practice Questions
Prepare for CFR-410 with more than an answer.
- Exam fee
- $395 USD
- Level
- Professional
- Valid for
- 3 years
Domains covered on the exam 5
- Identify22%
- Protect24%
- Detect18%
- Respond19%
- Recover17%
- 1
A cybersecurity analyst is performing threat hunting within a corporate network. The analyst wants to identify systems that may be communicating with known malicious domains or IP addresses. Which of the following actions should the analyst perform? (Select TWO).
Show answer details
Correct answer: A, C
This is a direct and effective method. By comparing the destination IPs in the firewall logs with a list of known malicious IPs, the analyst can quickly identify compromised hosts that are communicating with C2 servers, malware distribution sites, or other malicious infrastructure.
Malware often uses domain names for C2 communication. Analyzing DNS logs allows the hunter to find hosts that are trying to resolve malicious domains, even if the subsequent connection is blocked or uses a non-standard protocol. This is a crucial data source for threat hunting.
- 2
An incident response team is investigating a security breach at a cloud-hosted application. The team needs to collect evidence from the cloud environment, but they do not have direct physical access to the hardware. According to cloud forensic best practices and the principle of evidence volatility, what should be the team's FIRST action?
Show answer details
Correct answer: B
In a cloud environment, the most volatile evidence (RAM) is often lost if the instance is stopped. The most immediate and critical action is to preserve the state of the storage. Creating a disk snapshot via the provider's API is the standard, non-intrusive first step to preserve the disk evidence. Subsequent actions can then be taken on a clone made from this snapshot, preserving the original evidence.
- 3
Case Study:
Company Background: Global Logistics Inc. (GLI) is a large shipping and logistics company that operates a complex, hybrid IT environment. Their critical shipment tracking application runs on-premises, but they utilize a public cloud provider for data analytics and customer-facing web portals. GLI is subject to various international data privacy regulations, including GDPR.
The Incident: At 02:00 UTC, the Security Operations Center (SOC) receives a high-severity alert from their Data Loss Prevention (DLP) system. The alert indicates a large volume of compressed files containing customer PII and shipment data is being transferred from an on-premises database server to an external IP address located in a country where GLI has no business operations. Simultaneously, the network monitoring tool reports a significant spike in outbound traffic, bypassing the standard proxy server. The on-call incident responder confirms the database server is compromised.
Initial Response: The responder immediately applies a firewall rule to block the malicious external IP address. However, the attacker appears to be using a domain generation algorithm (DGA), and the exfiltration attempts resume, targeting new IP addresses. The database server is critical for operations and cannot be taken offline without significant business impact.
Challenge: The Head of Incident Response needs a containment strategy that stops the data exfiltration without causing a complete outage of the shipment tracking application. The strategy must also preserve evidence for a forensic investigation and meet regulatory reporting timelines.
Which containment and response strategy BEST meets all of GLI's requirements?
Show answer details
Correct answer: C
This strategy is the most effective. Isolating the server (segmentation) immediately stops all outbound exfiltration attempts, regardless of the attacker's use of DGA. By specifically allowing only the necessary inbound application traffic, it minimizes business disruption, meeting a key requirement. This containment method also keeps the system live, preserving volatile evidence (like RAM and running processes) for forensic analysis. This balanced approach addresses containment, business continuity, and evidence preservation simultaneously.
- 4
A security auditor is reviewing an organization's identity and access management controls. The auditor finds that developers have standing, persistent administrative access to production servers. This practice violates which fundamental security principle?
Show answer details
Correct answer: C
The principle of least privilege dictates that users and processes should be granted only the permissions necessary to perform their assigned tasks. Developers typically do not need persistent, standing administrative access to production environments. This excessive permission creates a significant security risk. Access should be granted on a temporary, as-needed basis (Just-In-Time access).
- 5
A company is designing a secure multi-tier web application architecture. The design includes a Demilitarized Zone (DMZ) to separate the web servers from the internal network where application and database servers reside. Based on the provided diagram, which firewall rule is essential for this architecture to function securely?
graph TD subgraph Internet User[External User] end subgraph DMZ WebServer[Web Server] end subgraph InternalNetwork["Internal Network"] AppServer[Application Server] Database[(Database)] end User -- HTTP/S --> ExternalFirewall[FW1] ExternalFirewall -- HTTP/S --> WebServer WebServer -- App Traffic --> InternalFirewall[FW2] InternalFirewall -- App Traffic --> AppServer AppServer -- DB Traffic --> DatabaseShow answer details
Correct answer: C
The core principle of a DMZ is to prevent direct traffic from the Internet to the internal network. In this multi-tier architecture, the Web Server in the DMZ must communicate with the Application Server in the internal network. Therefore, the internal firewall (FW2) must have a specific rule that allows the Web Server to initiate connections to the Application Server, but only on the required application port(s), enforcing the principle of least privilege.
- 6
True or False: When collecting digital evidence from a mobile device, creating a logical acquisition is always preferable to a physical acquisition because it is faster and captures all user-generated data like messages and call logs.
Show answer details
Correct answer: B
This statement is false. A physical acquisition, which creates a bit-for-bit copy of the entire flash memory, is forensically superior because it captures all data, including deleted files, file fragments, and unallocated space. A logical acquisition only captures the file system view, similar to a user backup, and misses this crucial deleted or hidden data. While a logical acquisition can be faster, a physical acquisition is preferred for a complete forensic investigation.
- 7
An incident response team is investigating anomalous outbound traffic from a workstation. They need to analyze the executable files that have been recently run by the user to identify any suspicious programs. On a Windows 10 system, which forensic artifact would provide the most direct evidence of program execution, including the execution time and run count?
Show answer details
Correct answer: D
Prefetch files (
.pf) are specifically created by Windows to speed up application loading. Forensically, they are invaluable as they contain the executable name, a hash of its path, a run count, and the timestamp of the last execution. This makes them the most direct and detailed artifact for proving a specific program was run. LNK files indicate a file was accessed, but not necessarily executed. The Security Event Log requires process creation auditing to be enabled, which is often not on by default. Shellbags track folder browsing, not program execution. - 8
Following a major data breach, an organization's legal counsel requests a report from the CSIRT to prepare for potential litigation. To ensure the report's findings are defensible in court, which document is most critical for demonstrating the integrity and handling of all collected digital evidence?
Show answer details
Correct answer: C
The Chain of Custody form is a legal document that provides a detailed chronological record of every person who handled a piece of evidence, the dates and times it was handled, and the purpose for the handling. This meticulous record-keeping is essential to prove that the evidence has not been tampered with or altered, ensuring its admissibility and integrity in legal proceedings.
- 9
During an incident, the response team determines that an attacker used PowerShell-based malware that executes entirely in memory, leaving minimal traces on the hard disk. Which forensic tool is essential for analyzing this type of attack?
Show answer details
Correct answer: D
The Volatility Framework is an open-source memory forensics tool specifically designed to analyze RAM dumps. For fileless or in-memory malware, the primary evidence (such as running processes, injected code, and network connections) exists only in volatile memory. Volatility allows an investigator to extract these artifacts from a memory image, which is essential when disk-based evidence is minimal or nonexistent. FTK Imager and Autopsy are primarily for disk forensics, and Wireshark is for network traffic analysis.
- 10
During a forensic investigation, an analyst must create a bit-for-bit copy of a suspect's hard drive. To ensure the integrity of the original evidence is maintained, which of the following tools or techniques is essential?
Show answer details
Correct answer: A
A write-blocker is a device or software that prevents any write operations to a storage device. This is absolutely critical in digital forensics to ensure that the process of connecting and imaging the source drive does not alter it in any way (e.g., by updating timestamps or writing temporary files). Using a write-blocker is a fundamental step in creating a forensically sound duplicate.
