
CertNexusCyberSec First Responder (CFR)
Domain 1Objective 3
Objective 1.3 Exploit Vulnerabilities in Software. CYBERSEC-FIRST-RESPONDER Practice Questions (Page 4)
Part of the 1.0 Attack Computing Environments to Test Cybersecurity domain, which accounts for 52% of the CYBERSEC-FIRST-RESPONDER exam.
39questions here
8free pages
12concepts
52%of the exam
Questions 16–20
- 16
What is pivoting in the context of network attacks?
Select an answer first - 17
During an assessment, a tester obtains a file containing hashed passwords from a Linux server. The tester knows the organization enforces a policy requiring all passwords to be at least 12 characters, but a quick analysis shows that several hashes correspond to short, common words. The tester has a limited time window and wants to recover as many passwords as possible quickly. Which approach is most efficient for this situation?
Select an answer first - 18
Why are unpatched or outdated software systems often targeted by attackers?
Select an answer first - 19
An attacker has compromised a workstation and needs to exfiltrate a small database file containing proprietary source code. The organization has strict egress filtering that blocks all outbound traffic except DNS queries to the corporate DNS server. The attacker wants to avoid detection by the network security team. Which method is most appropriate for covertly transferring the data?
Select an answer first - 20
A security analyst is investigating a malware infection on a user's laptop. The user reports that they received an email from an unknown sender with an attachment named 'Invoice_Q3.zip'. The user opened the attachment, and shortly after, the laptop began exhibiting suspicious behavior. The analyst wants to identify the initial infection vector. Which action by the user is the most likely cause of the infection?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CertNexus. “CYBERSEC-FIRST-RESPONDER” is a trademark of its owner, used for identification only.