TechNuggets Academy

Security Operations

Free CompTIA Cybersecurity Analyst (CySA+) practice — 6 questions on Security Operations, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Security Operations
During a proactive threat hunt, an analyst suspects an adversary is using the Windows Management Instrumentation (WMI) service to execute commands remotely and evade traditional process-creation logging. Which MITRE ATT&CK technique ID should the analyst use to scope the hunt and identify relevant data sources?
T1047 specifically covers adversary use of WMI for both local and remote execution, and the ATT&CK page lists relevant data sources such as WMI-Activity logs and process command-line auditing, which directly guide the hunt.
Question 2 of 6 · Security Operations
An analyst notices an internal workstation issuing hundreds of DNS queries per minute for domains with random-looking strings (e.g., xk4j9fh2q.net), most of which return NXDOMAIN. Which technique is BEST suited to confirm this is DGA-based C2 activity rather than benign CDN or ad-network traffic?
Passive DNS analysis, when combined with entropy scoring (measuring randomness of the domain string) and checking how recently the domain was registered, is a standard technique for distinguishing algorithmically generated domains used by malware from legitimate high-volume DNS traffic.
Question 3 of 6 · Security Operations
A SOAR playbook automatically isolates any endpoint generating an alert that matches a known-malware hash from the threat intel feed. After deployment, several legitimate administrative tools were quarantined because their hashes matched stale entries in the feed. Which playbook modification BEST resolves this without eliminating automation?
Adding an allowlist check and multi-source confidence enrichment before the isolation action addresses false positives from stale feed data while preserving the speed benefit of automation - this is the intended design pattern for SOAR playbooks per CySA+ process-improvement objectives.
Question 4 of 6 · Security Operations
While reviewing a packet capture, an analyst identifies a TLS ClientHello whose JA3 fingerprint matches known Cobalt Strike beacon tooling, even though the destination IP address has a good reputation score in threat intel platforms. What is the analyst's BEST next step?
JA3 fingerprints identify client-side TLS negotiation characteristics of specific tooling and are largely independent of the destination IP's reputation; attackers frequently use compromised or newly-provisioned infrastructure with clean reputation. A JA3 match to known C2 tooling should be escalated for endpoint-level investigation regardless of IP reputation.
Question 5 of 6 · Security Operations
Which statement correctly distinguishes tokenization from encryption as data protection methods relevant to SOC data handling practices?
Tokenization substitutes sensitive values with a randomly generated, non-mathematically-related token, with the original value stored separately in a secure vault - there is no key that mathematically derives the original from the token. Encryption instead uses a key-based algorithm that can mathematically reverse the ciphertext back to plaintext.
Question 6 of 6 · Security Operations
A user reports a phishing email appearing to come from the company CEO. Header analysis shows: Return-Path resolves to a free public webmail domain, SPF = fail, DKIM = none, but the friendly "From" display name correctly shows the CEO's full name. What does this combination BEST indicate?
Attackers commonly set the visible display name to match a trusted executive while the actual Return-Path/envelope sender is an unrelated free webmail domain that fails SPF and lacks DKIM signing - a hallmark of display-name spoofing used in BEC attacks, since most mail clients show only the friendly name by default.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →