210-255 Sample Questions & Answers
Correlating events and analyzing specialized logs is weighted heaviest, alongside packet-level intrusion analysis, kill-chain and VERIS-based incident handling, building and running response teams, and forensic analysis of endpoint threats.
Launch the full 210-255 simulator →Showing 8 of 17 free samples.
- Question 1Intermediate
Endpoint Threat Analysis and Computer Forensics · Risk Analysis and CVSS
A security analyst is reviewing a vulnerability assessment report. One critical vulnerability has a CVSS v3.0 base score of 9.8. The vector string is: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Which of the following best describes the characteristics of this vulnerability based on the vector?
Show answer & explanation
Correct answer: B
The vector components decode as follows: AV:N (Attack Vector: Network), AC:L (Attack Complexity: Low), PR:N (Privileges Required: None), UI:N (User Interaction: None). This indicates a remotely exploitable vulnerability that requires no authentication or user action, making it critical.
- Question 2AdvancedSelect 2
Endpoint Threat Analysis and Computer Forensics · Windows Forensics
During a forensic investigation of a compromised Windows workstation, an analyst suspects the attacker established persistence using the Registry. Which TWO Registry keys are most commonly modified to execute malware automatically upon user login? (Select TWO)
Show answer & explanation
Correct answers: A, C
The 'RunOnce' key is another mechanism for persistence, allowing a program to run the next time the system boots or a user logs on, often used by malware to complete installation or re-infect.
The 'Run' keys in both HKCU (Current User) and HKLM (Local Machine) are standard locations for auto-start entries. Malware often adds values here to ensure execution when a user logs in.
- Question 3Beginner
Endpoint Threat Analysis and Computer Forensics · Evidence Collection and Handling
True or False: In the context of digital forensics, the 'Order of Volatility' dictates that you should capture data from a hard disk drive before capturing data from the CPU cache and registers.
Show answer & explanation
Correct answer: B
False. The Order of Volatility states that you must capture the most volatile data first. CPU cache and registers are the most volatile, followed by RAM, then temporary file systems, and finally non-volatile storage like hard disks.
- Question 4Advanced
Endpoint Threat Analysis and Computer Forensics · Linux Forensics
A SOC analyst is analyzing a Linux server that was compromised. The attacker attempted to delete log files to cover their tracks. Which feature of the Ext4 file system might allow the analyst to recover or reconstruct the timeline of file operations even after deletion?
Show answer & explanation
Correct answer: C
Ext4 is a journaling file system. The journal keeps a log of changes that are about to be made to the main file system. Even if files are deleted, the journal entries may persist for a time, allowing forensic analysts to recover metadata or file contents and reconstruct the timeline.
- Question 5Intermediate
Endpoint Threat Analysis and Computer Forensics · Threat Analysis
While performing threat modeling for a new banking application, the team identifies a risk where a user could potentially deny performing a transaction after it has been completed. Which aspect of the STRIDE model does this scenario represent?
Show answer & explanation
Correct answer: A
Repudiation refers to the ability of a user to deny having performed an action. Non-repudiation controls (like audit logs and digital signatures) are implemented to prevent this.
- Question 6Intermediate
Endpoint Threat Analysis and Computer Forensics · Evidence Collection and Handling
An incident responder arrives at a desk where a desktop computer is powered on and suspected of containing active malware. The screen is locked. To preserve the most volatile evidence, what should be the responder's FIRST action?
Show answer & explanation
Correct answer: D
The most volatile evidence is in RAM (system memory). Shutting down the system would destroy this evidence. The first action should be to perform a live memory capture to secure running processes, network connections, and encryption keys.
- Question 7Beginner
Endpoint Threat Analysis and Computer Forensics · Malware Analysis
A security analyst is performing malware analysis. They execute the malware specimen in a secure, isolated sandbox environment to observe its behavior, network connections, and file system modifications. This approach is known as:
Show answer & explanation
Correct answer: C
Dynamic analysis involves running the malware in a controlled environment to observe its behavior. Static analysis involves examining the code without running it.
- Question 8Intermediate
Network Intrusion Analysis · Packet Analysis
Case Study: You are investigating a network breach. You have a PCAP file from the DMZ. You observe the following sequence of packets:
- External IP sends a TCP SYN to Internal Web Server Port 80.
- Web Server sends TCP SYN/ACK to External IP.
- External IP sends TCP ACK to Web Server.
- External IP immediately sends a TCP FIN packet.
What type of activity does this traffic pattern most likely represent?
Show answer & explanation
Correct answer: B
This sequence shows a full TCP 3-way handshake (SYN, SYN/ACK, ACK) followed immediately by a teardown (FIN). This is characteristic of a TCP Connect scan where the scanner completes the connection to verify the port is open and then immediately closes it.
sequenceDiagram participant Attacker participant Server Attacker->>Server: SYN (Port 80) Server-->>Attacker: SYN/ACK Attacker->>Server: ACK Note over Attacker,Server: Connection Established Attacker->>Server: FIN Note over Attacker,Server: Scan Complete
Ready for the real thing?
The full 210-255 simulator has every exam-style question, timed mode, and instant scoring.