Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CertNexus logo

CertNexusCyberSec First Responder (CFR)

Domain 1Objective 3

Objective 1.3 Exploit Vulnerabilities in Software. CYBERSEC-FIRST-RESPONDER Practice Questions (Page 7)

Part of the 1.0 Attack Computing Environments to Test Cybersecurity domain, which accounts for 52% of the CYBERSEC-FIRST-RESPONDER exam.

39questions here
8free pages
12concepts
52%of the exam

Questions 31–35

  1. 31application · medium

    A penetration tester is assessing a company that uses a web-based email portal. The tester sends a crafted email to an employee that appears to be from the IT department, urging the employee to click a link and 'verify' their mailbox credentials. The link leads to a realistic fake login page that captures the username and password. After the employee submits the credentials, the tester immediately uses them to log into the real email portal and searches for sensitive documents. Which attack technique is the tester primarily demonstrating?

    Select an answer first
  2. 32foundation · easy

    Which technique involves an attacker sending fraudulent emails that appear to come from a trusted source to trick users into revealing their login credentials?

    Select an answer first
  3. 33foundation · easy

    Which password cracking method uses a precomputed table of hashes to quickly reverse a password hash?

    Select an answer first
  4. 34application · medium

    A threat actor has compromised a server in a corporate network. The actor wants to maintain persistent access and issue commands to the compromised host without being detected by the security operations center (SOC). The SOC monitors for unusual outbound connections to known malicious IP addresses. Which command and control (C&C) mechanism is most likely to evade this type of detection?

    Select an answer first
  5. 35application · medium

    A penetration tester has gained initial access to a Windows workstation as a standard user. The tester runs a script that checks for services running with SYSTEM privileges that have weak file permissions, allowing the binary or configuration to be replaced. The tester replaces a service binary with a malicious executable and restarts the service, gaining SYSTEM-level access. Which privilege escalation technique is the tester using?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CertNexus. “CYBERSEC-FIRST-RESPONDER” is a trademark of its owner, used for identification only.