Question 1
A SIEM alert shows a user account logged in from London at 10:00 AM and from Tokyo at 10:15 AM on the same day. This is BEST described as:
Show answer & explanation
Correct answer: C - A geo-velocity anomaly
10 free, exam-style CyberSec First Responder (CFR) practice questions with answers and explanations. No signup required. Work through them below, then take the full free CFR practice test to study every exam domain.
A SIEM alert shows a user account logged in from London at 10:00 AM and from Tokyo at 10:15 AM on the same day. This is BEST described as:
Correct answer: C - A geo-velocity anomaly
A company discovers malware on a workstation that encrypts all local files and network shares, then displays a ransom demand. The FIRST containment action should be to:
Correct answer: A - Disconnect the workstation from the network
Implementing both a network firewall AND a host-based firewall is an example of:
Correct answer: D - Defense-in-depth strategy
An analyst needs to collect evidence from a compromised laptop. The laptop is currently running. Which is the correct order of collection from MOST to LEAST volatile?
Correct answer: A - RAM → Swap files → Disk → Remote logs
To count the number of unique source IP addresses in an Apache access log, an analyst would MOST likely use which combination of commands?
Correct answer: C - awk '{print $1}' access.log | sort | uniq
An attacker sends a spear-phishing email with a malicious attachment (Initial Access), the user opens it and a macro executes PowerShell (Execution), which downloads and installs a RAT (Persistence). Mapping these to ATT&CK involves:
Correct answer: B - Identifying tactics and techniques for each step
A security analyst investigates a compromised Windows system and finds Event IDs 4720 (account created) and 4732 (added to admin group) for an unknown account at 3:00 AM. This indicates:
Correct answer: D - Backdoor admin account creation
A forensic analyst uses Volatility and finds that pslist shows 45 processes but psscan shows 48. The 3 additional processes found by psscan are MOST likely:
Correct answer: A - Hidden or terminated processes
An organization performs a full backup on Sunday and incremental backups Monday through Saturday. If the system fails on Thursday, restoration requires:
Correct answer: B - Sunday's full backup plus Monday through Wednesday incrementals
An organization receives a threat intelligence report indicating a new vulnerability (CVSS 9.8) affects their web server software. What should be the FIRST action?
Correct answer: C - Assess which systems are affected
Practice hundreds more CFR questions with instant scoring, weak-area drills, and full exam simulations.