Free Cisco Certified CyberOps Associate practice — 6 questions on Network Intrusion Analysis, with explanations. No sign-up.
Full 12-question mixed test →
Question 1 of 6 · Network Intrusion Analysis
A SOC analyst discovers that a data exfiltration event went undetected for three weeks because no IDS signature matched the encrypted C2 channel, and malicious traffic was actively leaving the network the entire time. How should this event be classified?
Malicious activity actually occurred (impact) but no alert was generated to detect it, which is the definition of a false negative - the most dangerous classification because the security tooling failed silently.
Question 2 of 6 · Network Intrusion Analysis
During packet capture analysis of a suspected lateral movement incident, an analyst needs to isolate all traffic associated with a single infected host communicating with an internal file server on a non-standard port. Which combination of fields constitutes the 5-tuple needed to uniquely identify this conversation?
The 5-tuple used to uniquely identify a network conversation consists of source IP, destination IP, source port, destination port, and protocol - this is exactly what's needed to isolate one host's session to the file server regardless of the port used.
Question 3 of 6 · Network Intrusion Analysis
A firewall administrator configures a device that tracks the state of TCP connections in a session table, automatically permitting return traffic for established sessions, but does not inspect the application-layer payload for protocol conformance or malicious content. Which firewall operation type does this describe?
A stateful firewall maintains a connection/session table and uses that state to automatically permit return traffic for established sessions, but it operates at Layer 3/4 and does not inspect the actual application payload content.
Question 4 of 6 · Network Intrusion Analysis
An analyst needs to determine the exact URI path and User-Agent string requested by an internal workstation before it downloaded a malicious payload from an external website over HTTP. NetFlow records only show source/destination IP, ports, and byte counts. Which log source should the analyst pivot to in order to obtain this level of detail?
Web proxy logs capture full HTTP transaction details including the requested URI, host header, User-Agent string, and response codes, giving the analyst the granularity needed that flow-based sources cannot provide.
Question 5 of 6 · Network Intrusion Analysis
While investigating a phishing email, an analyst examines the message headers and finds multiple 'Received:' lines showing the mail hopped through several relays, along with a failed SPF result (softfail) and a DKIM signature that did not validate. Which of the following BEST describes what this artifact evidence indicates?
SPF softfail indicates the sending IP is not fully authorized by the domain's SPF policy, and a failed DKIM signature means the message content/headers cannot be cryptographically verified as unaltered - together these strongly suggest spoofing or a compromised relay.
Question 6 of 6 · Network Intrusion Analysis
An analyst reviewing a packet capture notices a host sending an unusually high volume of DNS queries for TXT records to a single external authoritative domain, with query name labels containing long strings of seemingly random alphanumeric characters. Which technique is most likely being used, and what should the analyst check to confirm?
High-volume TXT queries to one domain with long randomized/encoded subdomain labels is a classic DNS tunneling indicator; confirming involves inspecting the TXT answer payloads for base32/base64-style encoded data being smuggled through legitimate-looking DNS traffic.
Ready for the real thing?
The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.