
CertNexusCyberSec First Responder (CFR)
Domain 2Objective 2
Objective 2.2 Detect Attacks Using Active Monitoring Systems. CYBERSEC-FIRST-RESPONDER Practice Questions (Page 4)
Part of the 2.0 Analyze Attacks on Computing Environments domain, which accounts for 20% of the CYBERSEC-FIRST-RESPONDER exam.
60questions here
12free pages
22concepts
20%of the exam
Questions 16–20
- 16
How does FIM typically notify administrators of file changes?
Select an answer first - 17
A security analyst needs to monitor network traffic to understand the behavior of applications and users, including file transfers, DNS queries, and HTTP requests. The analyst wants a tool that generates detailed logs of network activity for later analysis. Which tool should the analyst use?
Select an answer first - 18
A security team is evaluating network monitoring tools and needs one that can perform deep packet inspection, handle high-throughput traffic, and support multi-threading for performance. Which tool is best suited for this requirement?
Select an answer first - 19
A security analyst is investigating a suspected ARP spoofing attack on the corporate network. The analyst wants to confirm the attack and identify the source. Which approach would be most effective?
Select an answer first - 20
A network administrator notices that a server is sending small, periodic outbound connections to an IP address in a foreign country every 10 minutes, regardless of user activity. The administrator suspects the server may be compromised and communicating with a command-and-control (C2) server. Which detection method would best confirm this suspicion?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CertNexus. “CYBERSEC-FIRST-RESPONDER” is a trademark of its owner, used for identification only.