Cybersec First Responder Free Sample Questions

20 free sample questions212 in the full practice test

Try simulator

CFR-410 Sample Questions

  1. Question 1

    True or False: When collecting digital evidence from a mobile device, creating a logical acquisition is always preferable to a physical acquisition because it is faster and captures all user-generated data like messages and call logs.

    Answer and explanation

    Correct answer: B

    This statement is false. A physical acquisition, which creates a bit-for-bit copy of the entire flash memory, is forensically superior because it captures all data, including deleted files, file fragments, and unallocated space. A logical acquisition only captures the file system view, similar to a user backup, and misses this crucial deleted or hidden data. While a logical acquisition can be faster, a physical acquisition is preferred for a complete forensic investigation.

  2. Question 2

    An incident response team is investigating anomalous outbound traffic from a workstation. They need to analyze the executable files that have been recently run by the user to identify any suspicious programs. On a Windows 10 system, which forensic artifact would provide the most direct evidence of program execution, including the execution time and run count?

    Answer and explanation

    Correct answer: D

    Prefetch files (.pf) are specifically created by Windows to speed up application loading. Forensically, they are invaluable as they contain the executable name, a hash of its path, a run count, and the timestamp of the last execution. This makes them the most direct and detailed artifact for proving a specific program was run. LNK files indicate a file was accessed, but not necessarily executed. The Security Event Log requires process creation auditing to be enabled, which is often not on by default. Shellbags track folder browsing, not program execution.

  3. Question 3

    Following a major data breach, an organization's legal counsel requests a report from the CSIRT to prepare for potential litigation. To ensure the report's findings are defensible in court, which document is most critical for demonstrating the integrity and handling of all collected digital evidence?

    Answer and explanation

    Correct answer: C

    The Chain of Custody form is a legal document that provides a detailed chronological record of every person who handled a piece of evidence, the dates and times it was handled, and the purpose for the handling. This meticulous record-keeping is essential to prove that the evidence has not been tampered with or altered, ensuring its admissibility and integrity in legal proceedings.

  4. Question 4

    During an incident, the response team determines that an attacker used PowerShell-based malware that executes entirely in memory, leaving minimal traces on the hard disk. Which forensic tool is essential for analyzing this type of attack?

    Answer and explanation

    Correct answer: D

    The Volatility Framework is an open-source memory forensics tool specifically designed to analyze RAM dumps. For fileless or in-memory malware, the primary evidence (such as running processes, injected code, and network connections) exists only in volatile memory. Volatility allows an investigator to extract these artifacts from a memory image, which is essential when disk-based evidence is minimal or nonexistent. FTK Imager and Autopsy are primarily for disk forensics, and Wireshark is for network traffic analysis.

  5. Question 5

    During a forensic investigation, an analyst must create a bit-for-bit copy of a suspect's hard drive. To ensure the integrity of the original evidence is maintained, which of the following tools or techniques is essential?

    Answer and explanation

    Correct answer: A

    A write-blocker is a device or software that prevents any write operations to a storage device. This is absolutely critical in digital forensics to ensure that the process of connecting and imaging the source drive does not alter it in any way (e.g., by updating timestamps or writing temporary files). Using a write-blocker is a fundamental step in creating a forensically sound duplicate.

  6. Question 6

    During a post-incident review of a data exfiltration event, an analyst discovers that the attacker pivoted from a compromised web server to an internal database using credentials stored in a plaintext configuration file. The organization's policy mandates credential rotation every 90 days, but this had not been enforced. Which of the following countermeasures would be MOST effective in preventing a similar incident in the future?

    Answer and explanation

    Correct answer: B

    While enforcing credential rotation is a good practice, the root cause was storing credentials in plaintext. A secrets management vault (like HashiCorp Vault or AWS Secrets Manager) is the most effective countermeasure as it eliminates plaintext credentials, provides secure storage, manages access control, and often includes features for automated rotation, addressing the root cause more comprehensively.

  7. Question 7

    An incident responder is analyzing a compromised Linux host. The attacker has attempted to cover their tracks. The responder needs to determine if the attacker modified critical system binaries like /bin/ls or /bin/ps. Which command should the responder use to verify the integrity of these files against a known-good database?

    Answer and explanation

    Correct answer: C

    On RPM-based systems (like CentOS, RHEL, Fedora), the rpm -V command verifies the integrity of files belonging to a package against the RPM database. This check includes size, MD5 sum, permissions, and other metadata. Since /bin/ls is part of the coreutils package, this command is the correct way to detect modifications. The stat and ls commands can be trojanized by the attacker, making them unreliable.

  8. Question 8

    A manufacturing company is conducting a vulnerability assessment of its Industrial Control Systems (ICS) network. The assessment must identify vulnerabilities without disrupting the sensitive, real-time operations of the Programmable Logic Controllers (PLCs). Which scanning approach is MOST appropriate for this environment?

    Answer and explanation

    Correct answer: C

    ICS and SCADA environments are extremely sensitive to active network probes, which can cause PLCs and other devices to fail or behave unpredictably, leading to operational downtime or safety risks. A passive scanning approach, which analyzes network traffic without sending any packets to the devices, is the most appropriate method. This allows the analyst to identify assets, protocols, and potential vulnerabilities without risking disruption.

  9. Question 9

    Multiple answers

    A security team is implementing a defense-in-depth strategy for their Active Directory environment to mitigate risks from compromised credentials. Which of the following controls should be implemented? (Select TWO).

    Answer and explanation

    Correct answers: A, C

    A tiered access model (Tier 0 for domain controllers, Tier 1 for servers, Tier 2 for workstations) prevents high-privilege credentials from being exposed on lower-trust systems, effectively containing the impact of a compromise.

    PAWs are hardened, dedicated machines used only for sensitive administrative tasks. This practice isolates administrative credentials from the higher-risk environment of daily-use workstations (email, web browsing), significantly reducing the attack surface.

  10. Question 10

    True or False: In the context of evidence collection, a snapshot of a running virtual machine is considered a forensically sound duplicate of the live system's memory and disk.

    Answer and explanation

    Correct answer: B

    False. While a VM snapshot captures the state of the disk and optionally the memory, the process of creating the snapshot can alter the state of the live system, modifying file timestamps and memory contents. It is not a bit-for-bit copy and does not typically come with the cryptographic hashing and chain-of-custody documentation required for it to be considered a 'forensically sound' duplicate in a legal context. Dedicated forensic imaging tools should be used instead.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 212 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon