Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CertNexus logo

CertNexusCyberSec First Responder (CFR)

Domain 2Objective 1

Objective 2.1 Analyze Logs for Signs of Attack. CYBERSEC-FIRST-RESPONDER Practice Questions (Page 8)

Part of the 2.0 Analyze Attacks on Computing Environments domain, which accounts for 20% of the CYBERSEC-FIRST-RESPONDER exam.

38questions here
8free pages
10concepts
20%of the exam

Questions 36–38

  1. 36application · medium

    A small company needs a log analysis platform that is free and open-source, with the ability to ingest logs from multiple sources and provide a web interface for searching. Which platform would best meet these requirements?

    Select an answer first
  2. 37application · medium

    An analyst sees an alert for a single failed login on a domain controller. The alert severity is low. However, the analyst notices that the username is 'admin' and the source IP is from a foreign country. Which action should the analyst take first?

    Select an answer first
  3. 38expert · hard

    A SOC analyst is triaging alerts. Alert A is a single failed login for a standard user. Alert B is a successful login for a domain admin from a new IP address. Alert C is a port scan from an internal IP. Which alert should be prioritized first?

    Select an answer first
Finished these 3 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CertNexus. “CYBERSEC-FIRST-RESPONDER” is a trademark of its owner, used for identification only.