CFR-410 Sample Questions & Answers
Applying protective security policies carries the top weight, from spotting assets and threat actors to catching indicators of compromise in log data, running the incident-response process and gathering evidence, and recovery planning with forensic review.
Launch the full CFR-410 simulator →Showing 10 of 20 free samples.
- Question 1Intermediate
Recover · Implement specific cybersecurity countermeasures for systems and applications.
During a post-incident review of a data exfiltration event, an analyst discovers that the attacker pivoted from a compromised web server to an internal database using credentials stored in a plaintext configuration file. The organization's policy mandates credential rotation every 90 days, but this had not been enforced. Which of the following countermeasures would be MOST effective in preventing a similar incident in the future?
Show answer & explanation
Correct answer: B
While enforcing credential rotation is a good practice, the root cause was storing credentials in plaintext. A secrets management vault (like HashiCorp Vault or AWS Secrets Manager) is the most effective countermeasure as it eliminates plaintext credentials, provides secure storage, manages access control, and often includes features for automated rotation, addressing the root cause more comprehensively.
- Question 2Intermediate
Respond · Execute the incident response process.
An incident responder is analyzing a compromised Linux host. The attacker has attempted to cover their tracks. The responder needs to determine if the attacker modified critical system binaries like
/bin/lsor/bin/ps. Which command should the responder use to verify the integrity of these files against a known-good database?Show answer & explanation
Correct answer: C
On RPM-based systems (like CentOS, RHEL, Fedora), the
rpm -Vcommand verifies the integrity of files belonging to a package against the RPM database. This check includes size, MD5 sum, permissions, and other metadata. Since/bin/lsis part of thecoreutilspackage, this command is the correct way to detect modifications. Thestatandlscommands can be trojanized by the attacker, making them unreliable. - Question 3Advanced
Identify · Identify and conduct vulnerability assessment processes.
A manufacturing company is conducting a vulnerability assessment of its Industrial Control Systems (ICS) network. The assessment must identify vulnerabilities without disrupting the sensitive, real-time operations of the Programmable Logic Controllers (PLCs). Which scanning approach is MOST appropriate for this environment?
Show answer & explanation
Correct answer: C
ICS and SCADA environments are extremely sensitive to active network probes, which can cause PLCs and other devices to fail or behave unpredictably, leading to operational downtime or safety risks. A passive scanning approach, which analyzes network traffic without sending any packets to the devices, is the most appropriate method. This allows the analyst to identify assets, protocols, and potential vulnerabilities without risking disruption.
- Question 4IntermediateSelect 2
Protect · Employ approved defense-in-depth principles and practices.
A security team is implementing a defense-in-depth strategy for their Active Directory environment to mitigate risks from compromised credentials. Which of the following controls should be implemented? (Select TWO).
Show answer & explanation
Correct answers: A, C
A tiered access model (Tier 0 for domain controllers, Tier 1 for servers, Tier 2 for workstations) prevents high-privilege credentials from being exposed on lower-trust systems, effectively containing the impact of a compromise.
PAWs are hardened, dedicated machines used only for sensitive administrative tasks. This practice isolates administrative credentials from the higher-risk environment of daily-use workstations (email, web browsing), significantly reducing the attack surface.
- Question 5Intermediate
Respond · Collect and seize documentary or physical evidence and create a forensically sound duplicate...
True or False: In the context of evidence collection, a snapshot of a running virtual machine is considered a forensically sound duplicate of the live system's memory and disk.
Show answer & explanation
Correct answer: B
False. While a VM snapshot captures the state of the disk and optionally the memory, the process of creating the snapshot can alter the state of the live system, modifying file timestamps and memory contents. It is not a bit-for-bit copy and does not typically come with the cryptographic hashing and chain-of-custody documentation required for it to be considered a 'forensically sound' duplicate in a legal context. Dedicated forensic imaging tools should be used instead.
- Question 6Intermediate
Recover · Implement recovery planning processes and procedures to restore systems and assets affected by cybersecurity incidents.
An e-commerce company has experienced a security incident where customer PII was exposed. The After Action Report (AAR) identified a lack of timely detection as a key failure. The company's SIEM currently collects logs from firewalls and web servers but lacks endpoint context. To improve detection capabilities and address the AAR's findings, which log source should be integrated into the SIEM with the HIGHEST priority?
Show answer & explanation
Correct answer: D
The key failure was a lack of timely detection, and the current SIEM lacks endpoint context. EDR logs provide the most granular detail about what is happening on endpoints, including process execution, file modifications, registry changes, and network connections. Integrating this data allows the SIEM to correlate network events (which they already have) with specific endpoint behaviors, enabling much faster and more accurate detection of compromises.
- Question 7Beginner
Respond · Collect and seize documentary or physical evidence...
A first responder arrives at the scene of a suspected insider threat incident. An employee's workstation is powered on and logged in. The responder needs to preserve volatile memory for later analysis. What is the command-line tool of choice for capturing a full memory image on a live Windows system?
Show answer & explanation
Correct answer: A
FTK Imager is a widely used, free tool in digital forensics that can capture live memory (RAM) and create a forensic image of it. It is designed to be run on a live system from an external drive to minimize its footprint and is a standard tool for first responders. While other tools exist, FTK Imager is a primary choice for this specific task.
- Question 8Intermediate
Detect · Determine the extent of threats and recommend courses of action or countermeasures to mitigate risks.
An analyst is reviewing SIEM alerts and notices a pattern of activity from an internal server. The server is making outbound connections on TCP port 53 to a non-standard DNS server IP address. Packet captures reveal that the payloads are encrypted and do not conform to normal DNS traffic. This activity is indicative of which post-exploitation technique?
Show answer & explanation
Correct answer: C
Using DNS protocol (port 53) to carry non-DNS traffic is a classic example of DNS tunneling. Attackers use this technique to establish a covert Command and Control (C2) channel or exfiltrate data, as DNS traffic is often less scrutinized and frequently allowed through firewalls. The encrypted payload and use of a non-standard DNS server are strong indicators of this technique.
- Question 9Advanced
Identify · Identify applicable compliance, standards, frameworks, and best practices for privacy.
A financial institution is required to comply with the Gramm-Leach-Bliley Act (GLBA). As part of their incident response plan, which specific component of GLBA dictates the requirements for protecting customer information and notifying them in case of a breach?
Show answer & explanation
Correct answer: C
The GLBA Safeguards Rule requires financial institutions to have measures in place to keep customer information secure. A key part of this rule is the requirement to develop, implement, and maintain a comprehensive written information security program which includes an incident response plan to handle breaches and notify affected customers.
- Question 10Intermediate
Protect · Ensure that plans of action are in place for vulnerabilities identified during risk assessments, audits, and inspections.
An organization's security policy requires a Plan of Action and Milestones (POA&M) to be created for all high-risk vulnerabilities found during quarterly scans. An administrator discovers a critical remote code execution vulnerability in a legacy production application that cannot be patched. Which of the following would be the MOST appropriate entry in the POA&M for this finding?
Show answer & explanation
Correct answer: C
A POA&M's purpose is to track the remediation of vulnerabilities. When a direct patch cannot be applied, the correct procedure is to implement compensating controls to mitigate the risk. A WAF with virtual patching can block exploit attempts targeting the vulnerability. This action, along with documenting the accepted residual risk, is the proper entry for a POA&M.
Ready for the real thing?
The full CFR-410 simulator has every exam-style question, timed mode, and instant scoring.