Free CFR-210 Practice Test Questions and Answers (2026) | Cert Empire Practice Questions

Free preview: 20 questions.

Already purchased? Log in

Logical Operations CFR 210

View Mode
Q: 1
A security analyst would like to parse through several SQL logs for indicators of compromise. The analyst is aware that none of the fields should contain a string of text longer than 30 characters; however, the analyst is unaware if there are any implemented controls to prevent such an overflow. Which of the following BEST describes the regular expression the analyst should use to find any alphanumeric character string?
Options
Q: 2
During review of a company’s web server logs, the following items are discovered: 2015-03-01 03:32:11 www.example.com/index.asp?id=-999 or 1=convert(int,@@version)— 2015-03-01 03:35:33 www.example.com/index.asp?id=-999 or 1=convert(int,db_name())— 2015-03-01 03:38:25 www.example.com/index.asp?id=-999 or 1=convert(int,user_name())— Which of the following is depicted in the log example above?
Options
Q: 3
Which of the following describes pivoting?
Options
Q: 4
An attack was performed on a company’s web server, disabling the company’s website. The incident response team’s investigation produced the following: 1. Presence of malicious code installed on employees’ workstations. 2. Excessive UDP datagrams sent to a single address. 3. Web server received excessive UDP datagrams from multiple internal hosts. 4. Network experienced high traffic after 3:00 pm. 5. Employee workstations sent large traffic bursts when employees accessed the internal timecard application. Which of the following BEST describes the attack tool used to perform the attack?
Options
Q: 5
Which of the following could an attacker use to perpetrate a social engineering attack? (Choose two.)
Options
Q: 6
A hacker’s end goal is to target the Chief Financial Officer (CFO) of a bank. Which of the following describes this social engineering tactic?
Options
Q: 7
A Windows system user reports seeing a command prompt window pop up briefly during each login. In which of the following locations would an incident responder check to explain this activity?
Options
Q: 8
A computer attacker has compromised a system by implanting a script that will send 10B packages over port 150. This port is also used for sending heartbeat messages to a central monitoring server. Which of the following BEST describes the tactic used to execute this attack?
Options
Q: 9
An alert has been triggered identifying a new application running on a Windows server. Which of the following tools can be used to identify the application? (Choose two.)
Options
Q: 10
When investigating a wireless attack, which of the following can be obtained from the DHCP server?
Options
Q: 11
An unauthorized network scan may be detected by parsing network sniffer data for:
Options
Q: 12
A security analyst for a financial services firm is monitoring blogs and reads about a zero-day vulnerability being exploited by a little-known group of hackers. The analyst wishes to independently validate and corroborate the blog’s posting. Whichof the following sources of information will provide the MOST credible supporting threat intelligence in this situation?
Options
Q: 13
Malicious code that can replicate itself using various techniques is referred to as a:
Options
Q: 14
A system administrator is informed that a user received an email containing a suspicious attachment. Which of the following methods is the FASTEST way to determine whether the file is suspicious or not?
Options
Q: 15
Which of the following technologies is used as mitigation to XSS attacks?
Options
Q: 16
During the identification phase, it is discovered that port 23 is being used maliciously. Which of the following system hardening techniques should be used to remediate the issue?
Options
Q: 17
An incident responder needs to quickly locate specific data in a large data repository. Which of the following Linux tool should be used?
Options
Q: 18
A DMZ web server has been compromised. During the log review, the incident responder wants to parse all common internal Class A addresses from the log. Which of the following commands should the responder use to accomplish this?
Options
Q: 19

DRAG DROP Logical Operations CFR 210 question Drag and drop the following steps in the correct order from first (1) to last (7) that a forensic expert would follow based on data analysis in a Windows system.

Drag & Drop
Q: 20

DRAG DROP Drag and drop the following steps to perform a successful social engineering attack in the correct order, from first (1) to last (6). Logical Operations CFR 210 question

Drag & Drop
Question 1 of 20

Premium Access Includes

  • Quiz Simulator
  • Exam Mode
  • Progress Tracking
  • Question Saving
  • Flash Cards
  • Drag & Drops
  • 3 Months Access
  • PDF Downloads
Get Premium Access
Scroll to Top

FLASH OFFER

Days
Hours
Minutes
Seconds

avail 10% DISCOUNT on YOUR PURCHASE