Use CFR-310 Exam Dumps (2022 PDF Dumps) To Have Reliable CFR-310 Test Engine [Q26-Q47]

Share

Use CFR-310 Exam Dumps (2022 PDF Dumps) To Have Reliable CFR-310 Test Engine

CFR-310 PDF Recently Updated Questions Dumps to Improve Exam Score

NEW QUESTION 26
The Key Reinstallation Attack (KRACK) vulnerability is specific to which types of devices? (Choose two.)

  • A. Hub
  • B. Switch
  • C. Firewall
  • D. Access point
  • E. Wireless router

Answer: A,E

Explanation:
Explanation
Explanation/Reference: https://www.kaspersky.com/blog/krackattack/19798/

 

NEW QUESTION 27
Which of the following are well-known methods that are used to protect evidence during the forensics process?
(Choose three.)

  • A. Evidence bags
  • B. Secure rooms
  • C. Faraday boxes
  • D. Lock box
  • E. Security envelope
  • F. Caution tape

Answer: A,E,F

 

NEW QUESTION 28
During which phase of a vulnerability assessment would a security consultant need to document a requirement to retain a legacy device that is no longer supported and cannot be taken offline?

  • A. Performing a vulnerability scan
  • B. Determining scope
  • C. Conducting post-assessment tasks
  • D. Identifying critical assets

Answer: D

 

NEW QUESTION 29
A suspicious script was found on a sensitive research system. Subsequent analysis determined that proprietary data would have been deleted from both the local server and backup media immediately following a specific administrator's removal from an employee list that is refreshed each evening. Which of the following BEST describes this scenario?

  • A. Backdoor
  • B. Login bomb
  • C. Time bomb
  • D. Rootkit

Answer: A

 

NEW QUESTION 30
If a hacker is attempting to alter or delete system audit logs, in which of the following attack phases is the hacker involved?

  • A. Covering tracks
  • B. Gaining persistence
  • C. Performing reconnaissance
  • D. Expanding access

Answer: A

Explanation:
Explanation/Reference: https://resources.infosecinstitute.com/category/certifications-training/ethical-hacking/covering- tracks/log-tampering-101/#gref

 

NEW QUESTION 31
Various logs are collected for a data leakage case to make a forensic analysis. Which of the following are MOST important for log integrity? (Choose two.)

  • A. Modified date/time
  • B. Log path
  • C. Time stamp
  • D. Hash value
  • E. Log type

Answer: C,D

 

NEW QUESTION 32
Recently, a cybersecurity research lab discovered that there is a hacking group focused on hacking into the computers of financial executives in Company A to sell the exfiltrated information to Company B.
Which of the following threat motives does this MOST likely represent?

  • A. Association/affiliation
  • B. Desire for financial gain
  • C. Desire for power
  • D. Reputation/recognition

Answer: B

 

NEW QUESTION 33
When tracing an attack to the point of origin, which of the following items is critical data to map layer 2 switching?

  • A. CAM table
  • B. DNS cache
  • C. NAT table
  • D. ARP cache

Answer: D

Explanation:
Explanation
The host that owns the IP address sends an ARP reply message with its physical address. Each host machine maintains a table, called ARP cache, used to convert MAC addresses to IP addresses. Since ARP is a stateless protocol, every time a host gets an ARP reply from another host, even though it has not sent an ARP request for that reply, it accepts that ARP entry and updates its ARP cache. The process of updating a target host's ARP cache with a forged entry is referred to as poisoning.

 

NEW QUESTION 34
Which of the following technologies would reduce the risk of a successful SQL injection attack?

  • A. Reverse proxy
  • B. Stateful firewall
  • C. Web application firewall
  • D. Web content filtering

Answer: C

 

NEW QUESTION 35
During an incident, the following actions have been taken:
-Executing the malware in a sandbox environment
-Reverse engineering the malware
-Conducting a behavior analysis
Based on the steps presented, which of the following incident handling processes has been taken?

  • A. Recovery
  • B. Identification
  • C. Eradication
  • D. Containment

Answer: D

Explanation:
Explanation
The "Containment, eradication and recovery" phase is the period in which incident response team tries to contain the incident and, if necessary, recover from it (restore any affected resources, data and/or processes).

 

NEW QUESTION 36
Which of the following could be useful to an organization that wants to test its incident response procedures without risking any system downtime?

  • A. Red team exercise
  • B. Tabletop exercise
  • C. Blue team exercise
  • D. Business continuity exercise

Answer: D

 

NEW QUESTION 37
After a hacker obtained a shell on a Linux box, the hacker then sends the exfiltrated data via Domain Name System (DNS). This is an example of which type of data exfiltration?

  • A. File sharing services
  • B. Covert channels
  • C. Steganography
  • D. Rogue service

Answer: B

 

NEW QUESTION 38
A Windows system administrator has received notification from a security analyst regarding new malware that executes under the process name of "armageddon.exe" along with a request to audit all department workstations for its presence. In the absence of GUI-based tools, what command could the administrator execute to complete this task?

  • A. top | grep armageddon
  • B. wmic process list brief | find "armageddon.exe"
  • C. ps -ef | grep armageddon
  • D. wmic startup list full | find "armageddon.exe"

Answer: B

Explanation:
Explanation/Reference: https://www.andreafortuna.org/2017/08/09/windows-command-line-cheatsheet-part-2-wmic/

 

NEW QUESTION 39
Organizations considered "covered entities" are required to adhere to which compliance requirement?

  • A. Sarbanes-Oxley Act (SOX)
  • B. International Organization for Standardization (ISO) 27001
  • C. Payment Card Industry Data Security Standard (PCI DSS)
  • D. Health Insurance Portability and Accountability Act of 1996 (HIPAA)

Answer: D

Explanation:
Explanation/Reference: https://www.hhs.gov/hipaa/for-professionals/faq/190/who-must-comply-with-hipaa-privacy- standards/index.html

 

NEW QUESTION 40
A security engineer is setting up security information and event management (SIEM). Which of the following log sources should the engineer include that will contain indicators of a possible web server compromise?
(Choose two.)

  • A. Web server logs
  • B. NetFlow logs
  • C. Proxy logs
  • D. Domain controller logs
  • E. FTP logs

Answer: A,D

 

NEW QUESTION 41
During a security investigation, a suspicious Linux laptop is found in the server room. The laptop is processing information and indicating network activity. The investigator is preparing to launch an investigation to determine what is happening with this laptop. Which of the following is the MOST appropriate set of Linux commands that should be executed to conduct the investigation?

  • A. iperf, traceroute, whois, ls, chown, cat
  • B. lsof, ifconfig, who, ps, ls, tcpdump
  • C. lsof, chmod, nano, whois, chown, ls
  • D. iperf, wget, traceroute, dc3dd, ls, whois

Answer: D

 

NEW QUESTION 42
To minimize vulnerability, which steps should an organization take before deploying a new Internet of Things (IoT) device? (Choose two.)

  • A. Disabling IPv6
  • B. Enabling the firewall
  • C. Changing the default password
  • D. Updating the device firmware
  • E. Setting up new users

Answer: B,D

 

NEW QUESTION 43
Which common source of vulnerability should be addressed to BEST mitigate against URL redirection attacks?

  • A. Users
  • B. Configuration files
  • C. Application
  • D. Network infrastructure

Answer: C

 

NEW QUESTION 44
Which of the following are part of the hardening phase of the vulnerability assessment process? (Choose two.)

  • A. Conducting audits
  • B. Updating configurations
  • C. Generating reports
  • D. Documenting exceptions
  • E. Installing patches

Answer: B,E

 

NEW QUESTION 45
A security professional discovers a new ransomware strain that disables antivirus on the endpoint during an infection. Which location would be the BEST place for the security professional to find technical information about this malware?

  • A. Social network sites
  • B. Threat intelligence feeds
  • C. Vulnerability databases
  • D. Computer emergency response team (CERT) press releases

Answer: B

 

NEW QUESTION 46
An unauthorized network scan may be detected by parsing network sniffer data for:

  • A. IP traffic from multiple IP addresses to a single IP address.
  • B. IP traffic from a single IP address to multiple IP addresses.
  • C. IP traffic from a single IP address to a single IP address.
  • D. IP traffic from multiple IP addresses to other networks.

Answer: A

 

NEW QUESTION 47
......

CFR-310 Dumps Full Questions with Free PDF Questions to Pass: https://www.briandumpsprep.com/CFR-310-prep-exam-braindumps.html