Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CertNexus logo

CertNexusCyberSec First Responder (CFR)

Domain 1Objective 3

Objective 1.3 Exploit Vulnerabilities in Software. CYBERSEC-FIRST-RESPONDER Practice Questions (Page 5)

Part of the 1.0 Attack Computing Environments to Test Cybersecurity domain, which accounts for 52% of the CYBERSEC-FIRST-RESPONDER exam.

39questions here
8free pages
12concepts
52%of the exam

Questions 21–25

  1. 21foundation · easy

    Which of the following is an example of a common vulnerability found in unpatched or outdated software?

    Select an answer first
  2. 22application · medium

    An attacker has compromised a web server in a DMZ. The attacker wants to reach internal database servers that are not directly accessible from the internet. The attacker uses the compromised web server as a relay to send traffic to the internal database network. Which technique is the attacker using?

    Select an answer first
  3. 23expert · hard

    An attacker has compromised a server in a segmented network. The attacker wants to move laterally to a database server in a different subnet. The attacker has captured a set of credentials for a service account that has administrative privileges on the database server. The attacker also has a C&C channel to the compromised server. Which sequence of actions is most appropriate for lateral movement?

    Select an answer first
  4. 24expert · hard

    A security team is responding to a breach. They discover that an attacker gained initial access via a phishing email, then used a local privilege escalation exploit to gain SYSTEM-level access on a single workstation. Over the next six months, the attacker slowly moved laterally to other systems, using legitimate administrative tools and credentials, and exfiltrated small amounts of data periodically. The attacker's activity was only discovered after a routine audit. Which characteristic of this attack most strongly indicates an Advanced Persistent Threat (APT)?

    Select an answer first
  5. 25foundation · easy

    An attacker uses malware to record every keystroke a user types, including usernames and passwords. Which credential harvesting technique is being used?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CertNexus. “CYBERSEC-FIRST-RESPONDER” is a trademark of its owner, used for identification only.