A.A public collection of ordinary search engine results
B.A private folder stored on a local computer
C.A wireless network protected by a password
D.A hidden part of the internet requiring special software
Correct Answer: A hidden part of the internet requiring special software
Explanation:
The dark web consists of intentionally hidden online services that generally require special software or configurations to access.
Incorrect! Try again.
2Which software is commonly used to access websites on the Tor dark web?
Dark Web
Easy
A.Tor Browser
B.Media Player
C.Text Editor
D.File Explorer
Correct Answer: Tor Browser
Explanation:
Tor Browser routes traffic through the Tor network and can access dark web services.
Incorrect! Try again.
3Which statement correctly distinguishes the dark web from the deep web?
Dark Web
Easy
A.The dark web is an intentionally hidden part of the deep web
B.The deep web contains only illegal online marketplaces
C.The deep web can be accessed only through Tor Browser
D.The dark web includes every password-protected web page
Correct Answer: The dark web is an intentionally hidden part of the deep web
Explanation:
The deep web includes content not indexed by search engines, while the dark web is a deliberately hidden portion of it.
Incorrect! Try again.
4Which email field identifies the main recipient of a message?
Email Basics
Easy
A.From
B.Subject
C.To
D.Date
Correct Answer: To
Explanation:
The To field contains the address of the primary recipient.
Incorrect! Try again.
5Which protocol is commonly used to send email messages?
Email Basics
Easy
A.SMTP
B.SSH
C.FTP
D.DNS
Correct Answer: SMTP
Explanation:
SMTP stands for Simple Mail Transfer Protocol and is used to send email.
Incorrect! Try again.
6What is an email attachment?
Email Basics
Easy
A.A password used to open an inbox
B.A server that delivers email messages
C.A folder that stores deleted messages
D.A file sent with an email message
Correct Answer: A file sent with an email message
Explanation:
An attachment is a file, such as an image or document, included with an email.
Incorrect! Try again.
7What should an investigator do first with a potentially important email?
Email Crime Investigation and Its Steps
Easy
A.Preserve it without altering its contents
B.Forward it to several personal accounts
C.Delete it after taking a screenshot
D.Edit its subject to describe the case
Correct Answer: Preserve it without altering its contents
Explanation:
Potential email evidence should be preserved in its original form to maintain integrity.
Incorrect! Try again.
8Which part of an email can show the servers through which the message traveled?
Email Crime Investigation and Its Steps
Easy
A.Email subject
B.Email header
C.Email greeting
D.Email signature
Correct Answer: Email header
Explanation:
Email headers contain routing information, timestamps, server details, and related metadata.
Incorrect! Try again.
9Why is a hash value calculated for collected email evidence?
Email Crime Investigation and Its Steps
Easy
A.To verify that the evidence remains unchanged
B.To remove unwanted messages from the inbox
C.To deliver the message to another recipient
D.To translate the message into another language
Correct Answer: To verify that the evidence remains unchanged
Explanation:
A matching hash helps demonstrate that the evidence has not been modified after collection.
Incorrect! Try again.
10What is the primary purpose of an Intrusion Detection System (IDS)?
Intrusion Detection System
Easy
A.To design web pages and database tables
B.To create user accounts and email addresses
C.To detect suspicious activity and generate alerts
D.To compress files and reduce storage use
Correct Answer: To detect suspicious activity and generate alerts
Explanation:
An IDS monitors activity for possible attacks or policy violations and alerts administrators.
Incorrect! Try again.
11What does a network-based IDS mainly monitor?
Intrusion Detection System
Easy
A.Documents stored in an office cabinet
B.Traffic moving across a computer network
C.Images displayed on a computer screen
D.Passwords written in a paper notebook
Correct Answer: Traffic moving across a computer network
Explanation:
A network-based IDS examines network traffic for suspicious patterns or known attacks.
Incorrect! Try again.
12What does an IDS commonly produce when it identifies suspicious behavior?
Intrusion Detection System
Easy
A.A user profile
B.A software license
C.A security alert
D.A backup archive
Correct Answer: A security alert
Explanation:
An IDS normally generates an alert so security personnel can investigate the activity.
Incorrect! Try again.
13What is the main purpose of an Intrusion Prevention System (IPS)?
Intrusion Prevention System
Easy
A.To detect and block malicious network activity
B.To improve the quality of digital images
C.To organize and rename personal documents
D.To create and format spreadsheet reports
Correct Answer: To detect and block malicious network activity
Explanation:
An IPS monitors traffic and can automatically block activity identified as malicious.
Incorrect! Try again.
14What is a basic difference between an IDS and an IPS?
Intrusion Prevention System
Easy
A.An IDS blocks attacks, while an IPS stores passwords
B.An IDS encrypts files, while an IPS deletes backups
C.An IPS can block attacks, while an IDS mainly alerts
D.An IPS sends email, while an IDS hosts websites
Correct Answer: An IPS can block attacks, while an IDS mainly alerts
Explanation:
An IDS primarily detects and reports threats, whereas an IPS can actively prevent or block them.
Incorrect! Try again.
15Why is an IPS commonly placed inline with network traffic?
Intrusion Prevention System
Easy
A.So it can inspect and block traffic directly
B.So it can create employee email accounts
C.So it can increase the size of stored files
D.So it can print incident reports automatically
Correct Answer: So it can inspect and block traffic directly
Explanation:
Inline placement allows an IPS to examine passing traffic and stop malicious connections.
Incorrect! Try again.
16What does a Web Application Firewall (WAF) primarily protect?
Web Application Firewall
Easy
A.Mobile batteries from excessive power use
B.Web applications from malicious web requests
C.Printed documents from physical damage
D.Desktop files from accidental name changes
Correct Answer: Web applications from malicious web requests
Explanation:
A WAF filters web traffic to protect web applications from common attacks.
Incorrect! Try again.
17Which type of traffic is commonly inspected by a WAF?
Web Application Firewall
Easy
A.Keyboard lighting signals
B.Bluetooth audio traffic
C.Printer cartridge data
D.HTTP and HTTPS traffic
Correct Answer: HTTP and HTTPS traffic
Explanation:
A WAF examines HTTP and HTTPS requests and responses associated with web applications.
Incorrect! Try again.
18Which web attack attempts to insert malicious database commands into an input field?
Attacks on Web Applications
Easy
A.Password hashing
B.SQL injection
C.Data compression
D.Digital signing
Correct Answer: SQL injection
Explanation:
SQL injection places malicious SQL commands into application input to manipulate a database.
Incorrect! Try again.
19Which attack injects malicious scripts into web pages viewed by other users?
Attacks on Web Applications
Easy
A.Port forwarding
B.Disk fragmentation
C.Cross-site scripting
D.File compression
Correct Answer: Cross-site scripting
Explanation:
Cross-site scripting (XSS) injects scripts that may run in another user's web browser.
Incorrect! Try again.
20What does a Cross-Site Request Forgery (CSRF) attack attempt to do?
Attacks on Web Applications
Easy
A.Trick a logged-in user into sending an unwanted request
B.Insert a harmful script into a displayed web page
C.Flood a server with a large amount of traffic
D.Guess a database password through repeated login attempts
Correct Answer: Trick a logged-in user into sending an unwanted request
Explanation:
CSRF abuses a user's authenticated session to make the web application perform an unintended action.
Incorrect! Try again.
21A dark-web vendor consistently signs marketplace announcements with the same PGP key. Which artifact found on a suspect's seized laptop would most strongly link the suspect to that vendor identity?
Dark Web
Medium
A.A text file containing the marketplace's onion address
B.A browser bookmark pointing to the vendor's marketplace profile
C.The private PGP key corresponding to the vendor's public key
D.A screenshot showing the vendor's public PGP key
Correct Answer: The private PGP key corresponding to the vendor's public key
Explanation:
The corresponding private key indicates control of the cryptographic identity used to sign the vendor's announcements.
Incorrect! Try again.
22An investigator must preserve a dark-web listing that may soon disappear. Which approach provides the strongest evidentiary record?
Dark Web
Medium
A.Take screenshots, rename them by date, and place them in a case folder
B.Bookmark the page, record its title, and revisit it after obtaining approval
C.Copy the listing text, translate it, and paste it into an investigation report
D.Capture page source and assets, record UTC time, and hash the files
Correct Answer: Capture page source and assets, record UTC time, and hash the files
Explanation:
Preserving the underlying content, collection time, and cryptographic hashes supports later verification of integrity and context.
Incorrect! Try again.
23When examining an email's Received headers, how should an investigator usually identify the earliest documented mail server in the route?
Email Basics
Medium
A.Select the entry with the newest local timestamp
B.Select the entry containing the visible sender address
C.Read the trusted Received entries from top to bottom
D.Read the trusted Received entries from bottom to top
Correct Answer: Read the trusted Received entries from bottom to top
Explanation:
Mail servers prepend Received headers, so the earliest trusted hop normally appears near the bottom. Untrusted entries may still have been forged.
Incorrect! Try again.
24A recipient received an email through Bcc, but their address does not appear in the message headers. Which source is most likely to confirm that the server delivered the message to that address?
Email Basics
Medium
A.The SMTP transaction logs
B.The message's subject header
C.The email client's signature block
D.The sender's display-name field
Correct Answer: The SMTP transaction logs
Explanation:
SMTP logs can record envelope recipients, including Bcc recipients that are not listed in the message's visible headers.
Incorrect! Try again.
25An email has a valid DKIM result for news.example. What does this result establish most directly?
Email Basics
Medium
A.The recipient personally knows the human author
B.The message was delivered without passing through relays
C.The signed content remained intact after domain signing
D.The sending computer was free of malicious software
Correct Answer: The signed content remained intact after domain signing
Explanation:
A valid DKIM signature shows that the signed headers and body were not altered and that the signature verifies for the signing domain.
Incorrect! Try again.
26An investigator receives a suspicious email as an .eml file. What should be done before opening attachments or modifying the evidence?
Email Crime Investigation and Its Steps
Medium
A.Remove duplicate headers to simplify later examination
B.Rename each attachment according to its apparent type
C.Calculate and record a hash of the original file
D.Forward the message to a personal analysis account
Correct Answer: Calculate and record a hash of the original file
Explanation:
Hashing the original email before analysis establishes a baseline for proving that the evidence has not changed.
Incorrect! Try again.
27An email displays From: security@bank.example, but SPF passes only for bounce.attacker.example, and no DKIM signature is present. What is the best interpretation?
Email Crime Investigation and Its Steps
Medium
A.SPF passed, but the visible sender domain is not aligned
B.SPF proves that bank.example authorized the visible sender
C.SPF validates the attachment but not the sender's domain
D.SPF confirms that both domains use the same mail provider
Correct Answer: SPF passed, but the visible sender domain is not aligned
Explanation:
SPF normally validates the envelope-sender domain. Without alignment to the visible From domain, the result does not authenticate bank.example for DMARC purposes.
Incorrect! Try again.
28A suspicious email contains a password-protected document. Which initial examination method best reduces risk while preserving useful evidence?
Email Crime Investigation and Its Steps
Medium
A.Open the document directly on the investigator's workstation
B.Upload the original document to a public conversion website
C.Analyze a verified copy in an isolated forensic sandbox
D.Remove the password and overwrite the original attachment
Correct Answer: Analyze a verified copy in an isolated forensic sandbox
Explanation:
An isolated sandbox limits exposure while allowing behavior to be observed. The original should remain preserved and unchanged.
Incorrect! Try again.
29Email headers, firewall logs, and authentication logs use different time zones. What should an investigator do before correlating the events?
Email Crime Investigation and Its Steps
Medium
A.Remove timestamps that include daylight-saving-time information
B.Sort the events alphabetically by the systems that recorded them
C.Use only the timestamps recorded by the recipient's email client
D.Convert all timestamps to a common time standard such as UTC
Correct Answer: Convert all timestamps to a common time standard such as UTC
Explanation:
Normalizing timestamps to UTC allows events from different systems and time zones to be placed on a consistent timeline.
Incorrect! Try again.
30A network IDS detects command-and-control traffic and generates an alert, but the connection continues. Which characteristic best explains this behavior?
Intrusion Detection System
Medium
A.The IDS can inspect traffic only after the connection is closed
B.The IDS records attacks but cannot generate real-time notifications
C.The IDS monitors traffic passively rather than blocking it inline
D.The IDS blocks traffic only when a firewall is completely disabled
Correct Answer: The IDS monitors traffic passively rather than blocking it inline
Explanation:
A traditional IDS observes traffic and alerts analysts but is not positioned inline to stop the connection automatically.
Incorrect! Try again.
31An anomaly-based IDS begins alerting on a newly deployed backup service because the service transfers unusually large amounts of data at night. What is the most appropriate response?
Intrusion Detection System
Medium
A.Replace anomaly detection with packet capture only
B.Update the behavioral baseline for the authorized service
C.Classify every large transfer as confirmed data theft
D.Disable all nighttime monitoring for the affected network
Correct Answer: Update the behavioral baseline for the authorized service
Explanation:
The authorized service changed normal network behavior. Updating or tuning the baseline reduces false positives while retaining anomaly detection.
Incorrect! Try again.
32Network traffic to a server is encrypted with TLS, limiting a network IDS's visibility. Which deployment would provide better evidence of malicious activity after decryption?
Intrusion Detection System
Medium
A.A DNS resolver placed on an isolated management segment
B.A network IDS placed upstream of the internet router
C.A passive hub connected outside the network perimeter
D.A host-based IDS installed on the destination server
Correct Answer: A host-based IDS installed on the destination server
Explanation:
A host-based IDS can monitor processes, files, and events on the server after encrypted traffic has been decrypted by the application.
Incorrect! Try again.
33Where should an IPS be positioned if it must automatically stop malicious packets before they reach an internal web server?
Intrusion Prevention System
Medium
A.On a passive mirror port beside the web server
B.Inside an offline forensic analysis workstation
C.Inline along the traffic path to the web server
D.Behind the server on a disconnected monitoring segment
Correct Answer: Inline along the traffic path to the web server
Explanation:
An IPS must operate inline so that it can inspect and drop malicious traffic before the traffic reaches its destination.
Incorrect! Try again.
34A new IPS signature may block a legitimate business application. Which rollout strategy best balances protection and availability?
Intrusion Prevention System
Medium
A.Enable blocking immediately and suppress all resulting logs
B.Disable the business application until the signature becomes outdated
C.Run the signature in alert mode, validate it, then enable blocking
D.Apply the signature only after removing all existing IPS policies
Correct Answer: Run the signature in alert mode, validate it, then enable blocking
Explanation:
Testing in alert mode reveals false positives and allows tuning before the signature is permitted to block production traffic.
Incorrect! Try again.
35A WAF is placed in front of an HTTPS application, but TLS terminates only on the application server. Why might the WAF fail to detect SQL injection in request bodies?
Web Application Firewall
Medium
A.The WAF ignores every request containing standard HTTP headers
B.The WAF cannot inspect application data that remains encrypted
C.The WAF requires the application to use UDP instead of TCP
D.The WAF can inspect only responses returned by database servers
Correct Answer: The WAF cannot inspect application data that remains encrypted
Explanation:
If the WAF cannot decrypt TLS traffic, it cannot examine HTTP paths, parameters, or bodies for application-layer attack patterns.
Incorrect! Try again.
36A critical web framework vulnerability has been disclosed, but the application cannot be patched until the next maintenance window. What can a WAF provide temporarily?
Web Application Firewall
Medium
A.A database backup that removes the vulnerable application component
B.A replacement certificate that permanently corrects the software defect
C.A source-code patch automatically inserted into the vulnerable framework
D.A virtual patch that blocks requests matching the exploit pattern
Correct Answer: A virtual patch that blocks requests matching the exploit pattern
Explanation:
A virtual patch uses WAF rules to block known exploit requests while the underlying application remains awaiting a permanent software fix.
Incorrect! Try again.
37A login query is constructed by concatenating user input into SELECT * FROM users WHERE name='...'. Which change most directly prevents SQL injection?
Attacks on Web Applications
Medium
A.Store the database on the same host as the application
B.Use parameterized queries with separately bound input values
C.Rename the login fields to values that attackers cannot predict
D.Encode the database response before displaying it to users
Correct Answer: Use parameterized queries with separately bound input values
Explanation:
Parameterized queries keep user input separate from SQL syntax, preventing the input from being interpreted as executable query code.
Incorrect! Try again.
38A forum stores a malicious script in a comment. The script executes whenever another user views the discussion. Which attack occurred?
Attacks on Web Applications
Medium
A.Server-side request forgery
B.Stored cross-site scripting
C.Cross-site request forgery
D.Reflected cross-site scripting
Correct Answer: Stored cross-site scripting
Explanation:
Stored XSS occurs when malicious script content is saved by the application and later delivered to multiple users.
Incorrect! Try again.
39A logged-in user visits a malicious page that silently submits a request to change the user's email address on another site. Which control most directly prevents this attack?
Attacks on Web Applications
Medium
A.A database index created for the user-account table
B.An output-encoding function applied to every displayed email address
C.A unique anti-CSRF token validated with each state-changing request
D.A longer TLS certificate installed on the destination server
Correct Answer: A unique anti-CSRF token validated with each state-changing request
Explanation:
An anti-CSRF token proves that the state-changing request originated from a legitimate application workflow rather than an external malicious page.
Incorrect! Try again.
40A web application fetches images from URLs supplied by users. An attacker submits http://169.254.169.254/latest/meta-data/ and obtains cloud credentials. Which vulnerability was exploited?
Attacks on Web Applications
Medium
A.Cross-site request forgery
B.Directory path traversal
C.Server-side request forgery
D.Reflected cross-site scripting
Correct Answer: Server-side request forgery
Explanation:
SSRF causes the server to request an attacker-chosen URL, potentially exposing internal services such as a cloud instance metadata endpoint.
Incorrect! Try again.
41Investigators suspect that two Tor onion marketplaces are operated by the same person. Which evidence most strongly supports this attribution while still requiring corroboration?
Dark Web
Hard
A.Both sites are reachable through Tor and accept privacy-focused cryptocurrency
B.Both sites use dark themes and experience downtime during similar periods
C.Both sites reuse a unique PGP key and announce synchronized changes signed by it
D.Both sites sell similar prohibited products and use comparable category names
Correct Answer: Both sites reuse a unique PGP key and announce synchronized changes signed by it
Explanation:
Reuse of a unique cryptographic identity across synchronized activity strongly links the sites. It does not conclusively identify a person because the private key could be shared, transferred, or compromised.
Incorrect! Try again.
42A live server hosting an onion service is seized under valid legal authority. Which acquisition strategy best preserves evidence that may disappear when the system is powered off?
Dark Web
Hard
A.Browse the service from the console, export its pages, and then copy database files
B.Disconnect power immediately, image each disk, and reconstruct memory from swap files
C.Restart into trusted media, acquire the disks, and inspect active network connections
D.Document the system, capture volatile memory, and then create verified forensic images
Correct Answer: Document the system, capture volatile memory, and then create verified forensic images
Explanation:
RAM may contain encryption keys, processes, sessions, and network state that disappear at shutdown. After documenting the live system, investigators should capture volatile data before producing hashed forensic images.
Incorrect! Try again.
43A cryptocurrency withdrawal from a dark-web market enters a CoinJoin transaction and later reaches a regulated exchange. What is the most defensible forensic conclusion?
Dark Web
Hard
A.The market operator directly controlled the output deposited at the regulated exchange
B.The transaction creates an investigative lead whose attribution needs independent evidence
C.The CoinJoin mathematically proves that the deposited funds originated outside the market
D.The exchange account owns every input that participated in the CoinJoin transaction
Correct Answer: The transaction creates an investigative lead whose attribution needs independent evidence
Explanation:
CoinJoin deliberately weakens input-output linkage. Timing, amount, exchange records, device evidence, and other artifacts may support attribution, but the blockchain path alone is not conclusive.
Incorrect! Try again.
44An email is forwarded by a conventional mailing list. SPF fails because the forwarding server is not authorized by the original envelope sender, but an aligned DKIM signature remains valid. Under ordinary DMARC evaluation, what is the expected result?
Email Basics
Hard
A.DMARC passes because one aligned authentication mechanism passes
B.DMARC passes only if both SPF and DKIM produce aligned results
C.DMARC fails because SPF failure overrides every valid DKIM result
D.DMARC fails because forwarding necessarily invalidates identifier alignment
Correct Answer: DMARC passes because one aligned authentication mechanism passes
Explanation:
DMARC requires an aligned pass from either SPF or DKIM. An intact DKIM signature aligned with the visible From: domain can therefore produce a DMARC pass despite forwarded SPF failure.
Incorrect! Try again.
45A suspicious message contains five Received: fields, including two attacker-supplied fields below the entry added by the recipient's secure email gateway. Which method best identifies the earliest trustworthy transport hop?
Email Basics
Hard
A.Select the lowest Received: field because headers are always appended at the bottom
B.Average timestamps from all Received: fields and choose the host nearest that time
C.Select the highest Received: field because it necessarily records the original sender
D.Start at the gateway-added field and validate downward only to the established trust boundary
Correct Answer: Start at the gateway-added field and validate downward only to the established trust boundary
Explanation:
SMTP servers prepend Received: fields, but a sender can forge fields before entering trusted infrastructure. Analysis should begin with a header verified as gateway-generated and correlate it with independent gateway logs.
Incorrect! Try again.
46A message is signed using DKIM with relaxed header and relaxed body canonicalization. Which modification is most likely to preserve signature validity?
Email Basics
Hard
A.Changing a signed subject word while retaining the original header length
B.Rewrapping body text by inserting line breaks at different character positions
C.Compressing header whitespace and removing trailing whitespace from body lines
D.Replacing an attachment while preserving its MIME type and original filename
Correct Answer: Compressing header whitespace and removing trailing whitespace from body lines
Explanation:
Relaxed canonicalization normalizes certain whitespace in signed headers and body lines. Semantic header changes, inserted body line breaks, or modified attachment bytes change the canonicalized content and invalidate the signature.
Incorrect! Try again.
47Investigators obtain a running laptop and a provider-hosted mailbox in an email-extortion case. Which sequence best supports forensic integrity and completeness?
Email Crime Investigation and Its Steps
Hard
A.Open messages, print relevant threads, reset credentials, and image the laptop afterward
B.Shut down the laptop, forward messages to investigators, and analyze them in personal mailboxes
A defensible process establishes authority, records the initial state, preserves volatile evidence when appropriate, acquires native data, verifies it cryptographically, and confines examination to authenticated working copies.
Incorrect! Try again.
48A business email compromise used a malicious OAuth application rather than a stolen password. Which evidence set is most likely to establish the access mechanism and subsequent mailbox activity?
Email Crime Investigation and Its Steps
Hard
A.Email screenshots, local browser history, public DNS records, and attachment filenames
B.SPF records, DKIM public keys, message themes, and the recipient's contact directory
OAuth abuse is best reconstructed from application consent, token and identity logs, mailbox auditing, and configuration changes. A normal password-login history does not exclude access through delegated tokens.
Incorrect! Try again.
49An email's Date: field shows 09:15 with a -0500 offset, the receiving gateway logs 14:17 UTC, and the suspect computer clock was seven minutes fast. What is the soundest timeline practice?
Email Crime Investigation and Its Steps
Hard
A.Subtract seven minutes from every server timestamp in the entire investigation
B.Discard the email timestamp because a two-minute transport delay proves manipulation
C.Normalize timestamps to UTC and document each source's offset, drift, and trust level
D.Treat 09:15 as authoritative because the sender creates the Date: field
Correct Answer: Normalize timestamps to UTC and document each source's offset, drift, and trust level
Explanation:
Timelines should normalize times while retaining original values and documenting clock drift and source reliability. The sender-controlled Date: field is less authoritative than independently maintained gateway logs.
Incorrect! Try again.
50A MIME attachment's Base64 text has one hash, while the decoded executable has another. Which reporting approach is forensically correct?
Email Crime Investigation and Its Steps
Hard
A.Record both hashes and document the deterministic decoding process connecting the artifacts
B.Record only the executable hash because transfer-encoded bytes have no evidentiary value
C.Record only the Base64 hash because decoded content is necessarily derivative evidence
D.Replace the original MIME section with decoded bytes so all tools calculate one hash
Correct Answer: Record both hashes and document the deterministic decoding process connecting the artifacts
Explanation:
The raw MIME representation and decoded payload are distinct byte sequences. Hashing both and recording the decoding method preserves the original evidence while supporting malware and file-based comparisons.
Incorrect! Try again.
51An IDS examines events of which are truly malicious. Its true-positive rate is , and its false-positive rate is . Approximately what proportion of alerts represent real attacks?
Intrusion Detection System
Hard
A.
B.
C.
D.
Correct Answer:
Explanation:
The positive predictive value is The low base rate means false positives dominate even though sensitivity is high.
Incorrect! Try again.
52TLS inspection is unavailable, but defenders must detect possible command-and-control traffic in encrypted sessions. Which IDS strategy is most appropriate?
Intrusion Detection System
Hard
A.Correlate flow timing, destination reputation, certificate metadata, and endpoint telemetry
B.Match plaintext command strings directly inside every encrypted application record
C.Disable network monitoring and rely exclusively on server-side application error logs
D.Treat all long-lived TLS sessions as confirmed command-and-control communications
Without decryption, an IDS can still analyze observable metadata and correlate it with endpoint evidence. Such indicators are probabilistic, so multiple signals are preferable to a single heuristic.
Incorrect! Try again.
53An attacker sends overlapping IP fragments that the IDS and protected server reassemble differently. Which defense most directly addresses this evasion technique?
Intrusion Detection System
Hard
A.Reduce alert retention so duplicate fragment events cannot overwhelm the analyst queue
B.Increase signature length so every fragment contains the complete malicious pattern
C.Normalize or reject ambiguous fragments before applying detection to reassembled traffic
D.Move detection behind DNS resolution so fragments can be associated with hostnames
Correct Answer: Normalize or reject ambiguous fragments before applying detection to reassembled traffic
Explanation:
Inconsistent reassembly lets an IDS inspect bytes different from those accepted by the endpoint. Traffic normalization or rejection of ambiguous overlaps ensures detection sees a consistent byte stream.
Incorrect! Try again.
54An inline IPS is configured to fail open if its inspection engine crashes. Which statement most accurately describes the resulting risk trade-off?
Intrusion Prevention System
Hard
A.Detection accuracy increases, but encrypted traffic is automatically converted to plaintext
B.Evidence integrity improves, but packet timing is permanently removed from all captures
C.Availability is preserved, but malicious traffic may bypass inspection during failure
D.Confidentiality is preserved, but legitimate traffic is blocked until inspection resumes
Correct Answer: Availability is preserved, but malicious traffic may bypass inspection during failure
Explanation:
Fail-open behavior keeps traffic flowing when the IPS fails, favoring availability. The cost is a period in which attacks may pass without inspection or prevention.
Incorrect! Try again.
55A critical exploit is active, but a new IPS signature may block legitimate requests sharing similar byte patterns. Which deployment plan best balances rapid protection and operational safety?
Intrusion Prevention System
Hard
A.Disable all related signatures until the vulnerable application receives its next upgrade
B.Enable blocking globally without logging so attackers cannot infer the signature's behavior
C.Block every connection to the application and treat resulting outages as false positives
D.Test in detection mode, scope the rule, validate traffic, and then enable monitored blocking
Correct Answer: Test in detection mode, scope the rule, validate traffic, and then enable monitored blocking
Explanation:
Staging reveals false positives, while scoping and validation reduce collateral impact. Monitored enforcement can then provide a temporary virtual patch without applying an untested rule globally.
Incorrect! Try again.
56A reverse proxy decodes a URL once, the WAF inspects that result, and the application decodes it again. An attacker exploits double encoding to bypass a traversal rule. Which remediation is strongest?
Web Application Firewall
Hard
A.Canonicalize consistently, reject ambiguous encodings, and align inspection with application parsing
B.Decode repeatedly until the value stops changing and permit every resulting normalized path
C.Add signatures for several known encoded traversal strings and retain both decoding stages
D.Inspect only the undecoded URL because transformations always destroy reliable attack indicators
Correct Answer: Canonicalize consistently, reject ambiguous encodings, and align inspection with application parsing
Explanation:
A WAF must evaluate the same effective representation the application uses. Consistent canonicalization and rejection of ambiguous or multiply encoded inputs prevent parser differentials from enabling bypasses.
Incorrect! Try again.
57A retail API validates each purchase request, but attackers send concurrent requests that collectively buy more limited-stock items than exist. Why is a WAF alone unlikely to solve the defect?
Web Application Firewall
Hard
A.The attack relies on invalid TLS certificates that only endpoint antivirus can evaluate
B.The attack abuses transaction-level business logic requiring atomic application-side controls
C.The attack modifies DNS responses after the WAF has completed signature verification
D.The attack requires fragmented packets that every reverse proxy automatically discards
Correct Answer: The attack abuses transaction-level business logic requiring atomic application-side controls
Explanation:
Each individual request may be syntactically valid, so ordinary WAF rules cannot reliably infer the inventory invariant. Atomic database operations, locking, or equivalent concurrency controls are required.
Incorrect! Try again.
58An application uses prepared statements for values but concatenates a user-controlled sort parameter into an SQL ORDER BY clause. What is the safest correction?
Attacks on Web Applications
Hard
A.Bind the column identifier as a normal string parameter in the prepared statement
B.Map accepted parameter values to a server-side allowlist of fixed column expressions
C.Escape quotation marks in the parameter and concatenate the resulting identifier
D.Encode the parameter with Base64 before appending it to the SQL statement
Correct Answer: Map accepted parameter values to a server-side allowlist of fixed column expressions
Explanation:
Prepared-statement placeholders generally bind data values, not SQL identifiers or keywords. A server-side mapping from permitted choices to fixed expressions prevents injection into structural query elements.
Incorrect! Try again.
59A front-end proxy honors Content-Length, while a back-end server prioritizes Transfer-Encoding: chunked. What attack can arise from this parser disagreement, and what is the best primary mitigation?
Attacks on Web Applications
Hard
A.Cross-site request forgery; rotate session cookies and disable all persistent HTTP connections
B.HTTP request smuggling; enforce consistent framing and reject ambiguous requests at every hop
C.XML external entity injection; remove document type declarations from JSON request bodies
Correct Answer: HTTP request smuggling; enforce consistent framing and reject ambiguous requests at every hop
Explanation:
Conflicting message-length interpretations can cause one component to treat hidden bytes as a second request. Consistent HTTP parsing and rejection of requests containing ambiguous framing prevent desynchronization.
Incorrect! Try again.
60A server-side URL fetcher blocks literal private IP addresses but follows redirects and performs fresh DNS lookups. Which control set best mitigates SSRF, including DNS rebinding?
Attacks on Web Applications
Hard
A.Validate only the submitted hostname and trust all addresses returned during later connections
B.Resolve and validate each destination, restrict egress, and recheck every redirect and connection
C.Block uncommon URL extensions and allow redirects whenever the first response uses HTTPS
D.Require Base64-encoded URLs and reject requests whose original strings contain decimal digits
Correct Answer: Resolve and validate each destination, restrict egress, and recheck every redirect and connection
Explanation:
DNS answers and redirect targets can change after initial validation. Revalidating actual destinations, restricting outbound access, and blocking internal or metadata ranges address both ordinary SSRF and rebinding techniques.
Incorrect! Try again.
Did this save you a night before the exam?
LPU Notes is free, and it stays free. Ads cover part of the server bill.
The rest comes out of a student's own pocket: the domain, the storage,
and keeping the site up through the weeks everyone needs it at once.
The payment button didn't load. An ad blocker or a filtered network is the usual reason.
to try again.
Nothing here is ever locked, and nothing unlocks. Chip in only if it was worth it.
What it pays for →