
CertNexus CyberSec First Responder (CFR) - CFR-310 Exam Questions
QUESTION NO: 1
In which of the following attack phases would an attacker use Shodan?
In which of the following attack phases would an attacker use Shodan?
Correct Answer: C
QUESTION NO: 2
During a security investigation, a suspicious Linux laptop is found in the server room. The laptop is processing information and indicating network activity. The investigator is preparing to launch an investigation to determine what is happening with this laptop. Which of the following is the MOST appropriate set of Linux commands that should be executed to conduct the investigation?
During a security investigation, a suspicious Linux laptop is found in the server room. The laptop is processing information and indicating network activity. The investigator is preparing to launch an investigation to determine what is happening with this laptop. Which of the following is the MOST appropriate set of Linux commands that should be executed to conduct the investigation?
Correct Answer: D
QUESTION NO: 3
When performing an investigation, a security analyst needs to extract information from text files in a Windows operating system. Which of the following commands should the security analyst use?
When performing an investigation, a security analyst needs to extract information from text files in a Windows operating system. Which of the following commands should the security analyst use?
Correct Answer: B
QUESTION NO: 4
Which of the following enables security personnel to have the BEST security incident recovery practices?
Which of the following enables security personnel to have the BEST security incident recovery practices?
Correct Answer: D
QUESTION NO: 5
As part of an organization's regular maintenance activities, a security engineer visits the Internet Storm Center advisory page to obtain the latest list of blacklisted host/network addresses. The security engineer does this to perform which of the following activities?
As part of an organization's regular maintenance activities, a security engineer visits the Internet Storm Center advisory page to obtain the latest list of blacklisted host/network addresses. The security engineer does this to perform which of the following activities?
Correct Answer: A
QUESTION NO: 6
A company that maintains a public city infrastructure was breached and information about future city projects was leaked. After the post-incident phase of the process has been completed, which of the following would be PRIMARY focus of the incident response team?
A company that maintains a public city infrastructure was breached and information about future city projects was leaked. After the post-incident phase of the process has been completed, which of the following would be PRIMARY focus of the incident response team?
Correct Answer: B
QUESTION NO: 7
A Linux administrator is trying to determine the character count on many log files. Which of the following command and flag combinations should the administrator use?
A Linux administrator is trying to determine the character count on many log files. Which of the following command and flag combinations should the administrator use?
Correct Answer: B
QUESTION NO: 8
Which of the following data sources could provide indication of a system compromise involving the exfiltration of data to an unauthorized destination?
Which of the following data sources could provide indication of a system compromise involving the exfiltration of data to an unauthorized destination?
Correct Answer: C
QUESTION NO: 9
A security administrator needs to review events from different systems located worldwide. Which of the following is MOST important to ensure that logs can be effectively correlated?
A security administrator needs to review events from different systems located worldwide. Which of the following is MOST important to ensure that logs can be effectively correlated?
Correct Answer: B
Explanation: Only visible for Pass4Test members. You can sign-up / login (it's free).
QUESTION NO: 10
It was recently discovered that many of an organization's servers were running unauthorized cryptocurrency mining software. Which of the following assets were being targeted in this attack? (Choose two.)
It was recently discovered that many of an organization's servers were running unauthorized cryptocurrency mining software. Which of the following assets were being targeted in this attack? (Choose two.)
Correct Answer: A,B




