10 free sample questions from a bank of 535, with the correct answers and explanations. No signup required — start practising right now.
1Which event is user interaction?
gaining root access
executing remote code
reading and writing file permission
opening a malicious file
Answer: D
The short version
D — Opening a malicious file requires the victim to act. That user interaction triggers download, macro, or exploit chains.
Key concepts in this question
User interaction: an action like opening an attachment or clicking a link.
Exploit prerequisites: many CVEs need the victim to open crafted content first.
Impact versus vector: root access and code execution are results, not the interaction.
Why D is correct
Security advisories distinguish vulnerabilities needing user interaction from remotely wormable ones. Opening a malicious document, archive, or installer is the classic required click that lets the payload run, so it is the only listed event that is itself a user interaction.
Why the others are wrong
A. Gaining root access is the attacker's resulting privilege level, not the victim's action.
B. Executing remote code is the exploit outcome the attacker achieves after interaction.
C. Reading and writing file permissions describes an access-control operation, not victim interaction.
200-201 exam tip
Interaction means the victim clicks: opening files or links is the giveaway phrase.
2An analyst is investigating an incident in a SOC environment. Which method is used to identify a session from a group of logs?
sequence numbers
IP identifier
5-tuple
timestamps
Answer: C
The short version
C — The 5-tuple identifies a session across logs. Source and destination IPs and ports plus protocol uniquely define the flow.
Session correlation: joining firewall, IDS, and NetFlow records by the same flow key.
Log fields: sequence numbers and timestamps order packets but do not identify flows.
Why C is correct
SOC analysts pivot between log sources by the flow's identity, and that identity is the 5-tuple. Filtering all records to one tuple reconstructs the session's packets and events even when they are scattered across sensors and time windows.
Why the others are wrong
A. TCP sequence numbers track byte order within a connection, not which session a log belongs to.
B. The IP identifier aids fragment reassembly, not session correlation.
D. Timestamps order events but are shared by millions of unrelated sessions.
200-201 exam tip
Session identity is five fields: two IPs, two ports, one protocol.
3Which system monitors local system operation and local network access for violations of a security policy?
host-based intrusion detection
systems-based sandboxing
host-based firewall
antivirus
Answer: A
The short version
A — Host-based intrusion detection watches the local system. It checks host activity and local network access against policy.
Key concepts in this question
HIDS: monitors OS logs, file integrity, and host network behavior.
Local scope: sees what network sensors cannot, such as encrypted-payload effects on the endpoint.
Policy violations: alerts when local actions breach the security baseline.
Why A is correct
A host-based intrusion detection system runs on the endpoint and inspects local operations plus the host's network access for policy violations and attack signs. That local-system-plus-local-access wording matches the HIDS definition directly.
Why the others are wrong
B. Sandboxing detonates suspicious files in isolation; it does not monitor live host policy.
C. A host firewall permits or blocks traffic but does not generally analyze behavior for violations.
D. Antivirus focuses on malware signatures and behavior, a narrower job than full policy monitoring.
200-201 exam tip
Host in the name, host on the box: HIDS monitors the endpoint itself.
4An analyst received an alert on their desktop computer showing that an attack was successful on the host. After investigating, the analyst discovered that no mitigation action occurred during the attack. What is the reason for this discrepancy?
The computer has a HIPS installed on it.
The computer has a NIPS installed on it.
The computer has a HIDS installed on it.
The computer has a NIDS installed on it.
Answer: C
The short version
C — A HIDS only detects; it cannot block. The alert fired but no mitigation ran because detection lacks prevention.
Key concepts in this question
IDS versus IPS: IDS alerts, IPS (HIPS/NIPS) also drops or resets attacks.
Host versus network: HIDS/NIDS detect in their scope; HIPS/NIPS prevent there.
The discrepancy is an alert with no blocking action, which is exactly how a detection-only sensor behaves. A host IDS on the desktop saw the successful attack and raised the alert but, having no prevention engine, took no mitigation step.
Why the others are wrong
A. A HIPS would have attempted to block or kill the malicious activity inline.
B. A NIPS protects network segments inline and would have tried to stop the traffic.
D. A NIDS is network-scoped detection, not the desktop sensor, and still would not prevent anyway.
200-201 exam tip
D in IDS means detect only: alerts without action always point to IDS, not IPS.
5Refer to the exhibit. What is the potential threat identified in this Stealthwatch dashboard?
A policy violation is active for host 10.10.101.24.
A host on the network is sending a DDoS attack to another inside host.
There are three active data exfiltration alerts.
A policy violation is active for host 10.201.3.149.
Answer: C
The short version
C — The dashboard shows three active exfiltration alarms. The top Exfiltration counter reads 3 alongside data-hoarding indicators.
Key concepts in this question
Stealthwatch alarming hosts: top counters summarize active alarm categories.
Exfiltration: unauthorized outbound movement of sensitive data.
Supporting signals: data-hoarding and high-concern-index hosts corroborate theft staging.
Why C is correct
The exhibit's top alarm ribbon lists Exfiltration with a count of 3, and the Top Alarming Hosts table plus Today's Alarms pie show data-hoarding and suspect-hoarding activity consistent with staged exfiltration. Three active exfiltration alerts is therefore the directly readable threat.
Why the others are wrong
A. Host 10.10.101.24 does not appear among the top alarming hosts or policy-violation entries shown.
B. The DDoS Source counter is 0 and no DDoS-to-inside-host pattern is evidenced.
D. Host 10.201.3.149 is absent from the visible host list; policy-violation alarms total 3 but attach elsewhere.
200-201 exam tip
Read the ribbon first: Stealthwatch top counters state each active alarm type directly.
6What is a difference between tampered and untampered disk images?
Tampered images have the same stored and computed hash.
Untampered images are deliberately altered to preserve as evidence.
Tampered images are used as evidence.
Untampered images are used for forensic investigations.
Answer: D
The short version
D — Untampered images preserve evidence-grade integrity. Their stored and computed hashes match, so courts trust them.
Key concepts in this question
Disk image hashing: a hash at acquisition proves later copies are unchanged.
Tampered versus untampered: mismatch means alteration; match means pristine.
Chain of custody: only verifiable images support forensic conclusions.
Why D is correct
Forensic practice requires working from bit-for-bit copies whose integrity is proven by equal stored and computed hashes. Such untampered images are the ones analysts examine and present, because any alteration would destroy evidentiary value.
Why the others are wrong
A. Matching hashes prove an image is untampered; tampered images show mismatched hashes.
B. Untampered images are preserved unchanged; deliberate alteration defines tampering.
C. Tampered images are disqualified as evidence precisely because integrity failed.
200-201 exam tip
Hashes must match: equal hashes mean evidence, mismatch means tampered.
7What is a sandbox interprocess communication service?
A collection of rules within the sandbox that prevent the communication between sandboxes.
A collection of network services that are activated on an interface, allowing for inter-port communication.
A collection of interfaces that allow for coordination of activities among processes.
A collection of host services that allow for communication between sandboxes.
Answer: C
The short version
C — Sandbox IPC is the interface set for process coordination. It lets analyzed processes signal and synchronize under observation.
Key concepts in this question
Interprocess communication: channels by which processes exchange data and events.
Sandbox role: controlled detonation environment that still allows normal OS coordination.
Interfaces: APIs, pipes, and shared-memory abstractions processes call.
Why C is correct
Within a sandbox, monitored malware and system processes still need standard coordination primitives. The IPC service is therefore the collection of interfaces permitting activities among processes to be coordinated, which the banked key states verbatim.
Why the others are wrong
A. Sandboxes isolate sandboxes from each other; IPC connects processes rather than blocking sandboxes.
B. Network services on interfaces describe connectivity, not process-to-process coordination.
D. Host services bridging sandboxes would break isolation rather than coordinate processes inside one.
200-201 exam tip
IPC always means processes talking: pick the answer about coordinating activities among processes.
8An analyst is investigating a host in the network that appears to be communicating to a command and control server on the Internet. After collecting this packet capture, the analyst cannot determine the technique and payload used for the communication. Which obfuscation technique is the attacker using?
Base64 encoding
transport layer security encryption
SHA-256 hashing
ROT13 encryption
Answer: B
The short version
B — The traffic is TLS-encrypted, hiding payload and technique. The capture shows only TLS Application Data and Encrypted Alerts.
Key concepts in this question
TLS encryption: session keys render application bytes opaque to sniffers.
Capture evidence: TLSv1.2 Application Data and Encrypted Alert messages prove encryption.
Analysis limit: headers and metadata remain, but payload content is unreadable.
Why B is correct
The packet list shows repeated TLSv1.2 Application Data exchanges plus Encrypted Alert messages between the host and the external server. Because TLS encrypts everything above the record layer, the analyst sees endpoints and timing but cannot determine the C2 technique or payload, which is the obfuscation at work.
Why the others are wrong
A. Base64 merely encodes visibly; the capture would still show decodable text, not TLS records.
C. SHA-256 is a one-way hash for integrity, not a channel-hiding mechanism.
D. ROT13 is trivial substitution whose output stays readable in captures, unlike TLS ciphertext.
200-201 exam tip
Application Data plus Encrypted Alert in a capture always means TLS is hiding the payload.
9During which phase of the forensic process is data that is related to a specific event labeled and recorded to preserve its integrity?
examination
investigation
collection
reporting
Answer: C
The short version
C — Collection labels and preserves event data. Tagging and recording evidence there protects its integrity.
Key concepts in this question
Collection phase: identifying, labeling, and acquiring relevant data first.
Integrity: hashing, documentation, and chain of custody start at collection.
Later phases: examination analyzes copies; reporting presents findings.
Why C is correct
Forensic models place preservation duties in collection: responders label each item, record its source and handling, and secure it so integrity survives scrutiny. The stem's labeled-and-recorded-to-preserve-integrity language is the collection definition.
Why the others are wrong
A. Examination analyzes already-collected data for relevance and content.
B. Investigation is the generic inquiry, not the named phase with preservation duties.
D. Reporting documents methods and conclusions after analysis is complete.
200-201 exam tip
First touch is collection: label, bag, hash, and log before any analysis.
10Which step in the incident response process researches an attacking host through logs in a SIEM?
detection and analysis
preparation
eradication
containment
Answer: A
The short version
A — Researching attacker logs in the SIEM is detection and analysis. That phase triages alerts and scopes the incident.
Key concepts in this question
NIST incident response: preparation, detection and analysis, containment, eradication, recovery.
SIEM research: querying logs to confirm, characterize, and attribute activity.
Studying an attacking host through SIEM logs means confirming the event, understanding its technique and blast radius, which is precisely the detection-and-analysis function. Preparation sets up tools beforehand; hands-on log investigation happens once detection triggers analysis.
Why the others are wrong
B. Preparation builds playbooks, tools, and training before any alert exists.
C. Eradication removes the cause (malware, accounts) after analysis is done.
D. Containment isolates affected systems, a step driven by but distinct from log research.
200-201 exam tip
SIEM sleuthing equals detection and analysis: research first, contain second.