Browse all practice questions for the Security Blue Team Level 1 Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

Security Blue Team Level 1 Practice Test course image
More practice questions

These questions are part of the practice quiz. Start practicing

  • In the Threat Intelligence Lifecycle, which stage captures the needs of consuming teams to refine priorities?
  • Business Email Compromise (BEC) is best described as a phishing attack that impersonates a known source to obtain what?
  • What is a security baseline and how is it used to assess risk?
  • What are Precursors?
  • Which Windows file stores RAM contents on disk when physical memory is full?
  • What information is typically stored in the /etc/passwd file on a Unix-like system?
  • Which phase of the Incident Response Plan includes reviewing the incident to improve future response?
  • How should incident containment actions be documented?
  • What is the circular disk on which magnetic data is stored in a hard disk drive called?
  • Which phase requires proven techniques and methodology to be reproducible by other forensic examiners?
  • SIEM is described as a combination of which two components?
  • What are the two types of Jump List destination files?
  • What is the term for making the sending address in an email appear legitimate to the recipient?
  • Where are Jump List data stored for AutomaticDestinations and CustomDestinations?
  • Which item is listed as an Email Artifact?
  • Which phase focuses on identifying potential sources of relevant evidence, custodians, and data locations?
  • Which statement best describes Sigma's rule format?
  • What is the MITRE ATT&CK framework used for in blue team activities?
  • Which item is a File Artifact?
  • In a dual-firewall DMZ, what is the frontend firewall configured to do?
  • Which group is typically motivated by political or social causes rather than financial gain?
  • What term refers to impersonating a brand or domain by misspelling it?
  • What is Vishing?
  • What is a data loss prevention (DLP) concept and where is it applied?
  • What is CASB and why is it used?
  • According to the order of volatility, which sequence correctly lists components from most volatile to least volatile?
  • What is the Linux swap file used for?
  • In the NIST incident response lifecycle, the primary objective of containment is to
  • Which statement best describes SIEM?
  • OSINT stands for which type of intelligence?
  • Which statement accurately contrasts Strategic Threat Intelligence and Operational Threat Intelligence?
  • Which data is stored in the /etc/shadow file on Unix-like systems?
  • What is the role of automation and playbooks in SOC operations?
  • What is the role of backup and disaster recovery planning in cyber resilience?
  • Which attack exploits visually similar characters due to Unicode encoding, making it hard for users to spot?
  • Which tool can view Jump List destination files?
  • Which item is used to ground the handler to prevent static discharge during handling of electronic evidence?
  • Prefetch files are stored in which directory?
  • Which statement best describes Precursors?
  • How do firewalls and IDS/IPS differ in function
  • In security operations, which statement best describes alerting?
  • Which option best reflects the typical use of Strategic Threat Intelligence?
  • Which ACPO principle requires an audit trail or other record of all processes applied to computer-based electronic evidence to be created and preserved, with an independent third party able to examine those processes?
  • Which phishing category presents a real-looking login portal after a click?
  • What is MFA and why does it improve security?
  • Spam Emails are defined as?
  • How do you measure SOC performance? What are common KPIs?
  • During collection, which activity may be involved when acquiring a device's content?
  • Which approach best helps detect and prevent social engineering?
  • Why is time synchronization important in security monitoring?
  • SIGNT in intelligence terminology refers to which type of intelligence?
  • What is data encryption at rest vs in transit? Provide examples
  • What are common misconfigurations in cloud storage and how to mitigate them?
  • Which intelligence discipline relies on information gathered from human sources, such as in-person meetings and debriefings?
  • What is zero-trust security and its core principle?
  • What is a VPN and what security considerations apply?
  • In security operations, which statement best describes monitoring?
  • Which incident response phase focuses on stopping the spread and impact of an incident?
  • Which phase focuses on protecting the crime or incident scene, preserving evidence, and documenting how it was acquired?
  • Which stage is described as determining whether to investigate a potential threat?
  • Threat Exposure Check involves using multiple tools to look for indicators of compromise retrieved from which sources?
  • Digital Forensics Process.
  • What is the purpose of computing and comparing hashes in digital forensics?
  • Which phase involves an in-depth systematic search of evidence relating to the incident being investigated?
  • Where is the Windows Recycle Bin stored?
  • What describes Hosted Malware?
  • Which Event ID represents a Successful Logon?
  • What is threat hunting and how does it differ from traditional monitoring?
  • Credential Harvesters are described as...
  • Which Windows command computes the SHA-256 hash of a file?
  • What is a golden image in endpoint security and why does baselining matter?
  • Which statement accurately reflects common authentication methods and their security implications?
  • Which tool is used for file carving in forensic imaging?
  • Which is the correct order of steps in the logging lifecycle?
  • What defense is suggested against social engineering, smishing, and vishing?
  • What is STIX?
  • Which action is a typical step in incident response runbook?
  • Subdivisions of a track on a disk that store a fixed amount of user data are called?
  • Why is log normalization important in a SIEM system?
  • Why is correlating traffic patterns with baselines important in detecting anomalies?
  • Sysmon provides detailed information about which of the following?
  • Which log file contains system authentication information including user logins?
  • In the Threat Intelligence Lifecycle, which stage turns processed information into actionable intelligence used to decide whether to investigate threats?
  • Which item is used to block cellular or radio signals during evidence collection?
  • What is a DDoS attack and how can a blue team mitigate it at a high level
  • Hacktivists are typically motivated by social or political issues.
  • SHA256 Hash Value is a what type of artifact?
  • What do RPO and RTO stand for in disaster recovery planning?
  • Which logs benefit most from synchronized clocks?
  • In the NIST incident response lifecycle, what phase follows Detection & Analysis?
  • What is the primary purpose of wear leveling in flash memory?
  • In a DMZ with a single firewall architecture, how many network interfaces are typically involved?
  • Which of the following is NOT listed as an Actor Motivation?
  • What is Sigma in the context of security monitoring?
  • What are the key components of a cybersecurity incident report?
  • Which component stores magnetic data on a hard drive?
  • In digital forensics, Slack Space refers to leftover storage that exists when a file does not need all the space allocated by the operating system.
  • Which of the following is least likely to be a primary blue team logging source?
  • What indicators help identify phishing and spear-phishing in email logs?
  • What is the purpose of reconnaissance emails?
  • Which log records requests made to the Apache web server?
  • Tactical Threat Intelligence is technical and shared as indicators of compromise such as URLs, domains, email addresses, file hashes, and IP addresses.
  • Which statement best describes STIX and TAXII relationship?
  • What is a baseline configuration and how is it used in security operations?
  • What are common indicators of compromise (IOCs) you might look for in logs?
  • Which statement best describes Malicious Attachments in phishing campaigns?
  • What best describes malware sandboxing?
  • Which term refers to monitoring network traffic to detect malicious activity and optionally block it?
  • What is file carving in digital forensics?
  • What is the purpose of an incident response playbook?
  • In gathering metadata for a file on Windows, which method is commonly used?
  • What defense is suggested for highly targeted phishing (whaling)?
  • Which log file contains information about failed login attempts?
  • Threat Intelligence Platforms (TIPs) purpose.
  • Which statement best describes symmetric cryptography?
  • What is the correct order of the six phases in the Incident Response Plan?
  • Chain of Custody is described as which of the following?
  • LNK shortcuts are commonly found in which Windows directory?
  • Which stage involves setting goals and stakeholders for the intelligence project?
  • Which statement best describes detection in security operations?
  • LNK files are used by Windows OS to link one file to another and work as what?
  • What is cryptographic hashing and why is it used in integrity checks?
  • What is a typical feature of malicious attachments?
  • In Linux, which command provides detailed metadata about a file (size, inode, timestamps, etc.)?
  • What is the difference between vulnerability scanning and penetration testing?
  • Which item is NOT provided by Windows Prefetch files?
  • What differentiates hot backups from other backup types?
  • Sending Server IP & Reverse DNS is part of which artifact category?
  • What does malware sandboxing enable security teams to collect?
  • Which of the following signals would you examine in basic network traffic analysis to detect anomalous activity?
  • What defines network segmentation?
  • Which ACPO principle requires that personnel accessing original data must be competent to do so and able to explain their actions and the implications of those actions on the digital evidence to a court?
  • Full URLs are categorized as which type of artifact?
  • Which TI lifecycle stage follows Processing?
  • What is the primary purpose of SOC KPIs like mean time to detect and mean time to respond?
  • Explain the concept of defense in depth with an example
  • In the Threat Intelligence Lifecycle, which stage involves collecting all needed data for the end goal?
  • Which Windows component remains resident across reboots to monitor and log system activity?
  • During collection, which action may be involved in acquiring content from a device located at the scene?
  • What type of data does the .bash_history file store?
  • What is Smishing?
  • Which practice enforces retention and tamper-evident storage of logs?
  • What does TAXII define?
  • What is the Windows hibernation file used for?
  • Which is NOT a core function of SIEM in a SOC environment?
  • In a typical cloud shared responsibility model, which party is primarily responsible for the security of the cloud's physical infrastructure?
  • What is the primary purpose of the /var/lib directory in Linux?
  • Which method is a hydraulic device used to destroy physical media?
  • Geosint uses which type of data to monitor activities such as tracking individuals of interest and military movements?
  • What is a rogue device and which approach helps detect it on a network?
  • In the Threat Intelligence Lifecycle, which stage transforms data into a readable format for analysts?
  • In incident response, what is the primary goal of containment actions?
  • During incident containment, which step should occur first?
  • Which stage focuses on understanding intelligence priorities and consumer requirements?
  • What is log tampering and how can you detect it?
  • What is Whaling?
  • Cyber Criminals are a group that includes hackers and crackers looking to make money from malicious activity such as cyber-attacks, ransomware, and phishing.
  • What is a key security difference between single-firewall and dual-firewall DMZ architectures?
  • Operational Threat Intelligence focuses on threat actors to gain information about who they are, their motivations, and their TTPs.
  • In the Threat Intelligence Lifecycle, which stage defines the scope of the project?
  • Which term describes information gathered from human sources, often through in-person meetings and debriefings?
  • Which tactic disguises malicious URLs by using a shortened link?
  • Date & Time is part of which artifact category?
  • Which Linux commands are commonly used to compute file hashes such as SHA-256, MD5, and SHA-1?
  • Which sequence correctly lists the stages of the cyber kill chain from reconnaissance to actions on objectives?
  • Geosint is defined as the use of satellite imaging to monitor activities such as tracking individuals of interest, structural reconnaissance, and military movement.
  • Public Exposure Check: Which statement describes it?
  • Which of the following is the first phase in the NIST incident response lifecycle?
  • Describe the purpose of a runbook in incident response and give an example of a step.
  • Which concept is defined as exploiting a human rather than a technical system?
  • What is defense-in-depth, in terms of network and host security?
  • Which term describes a platform to manage CTI including actors, campaigns, etc?
  • What is log normalization?
  • Which stage ensures that the procedures used to recover data can be reproduced by other forensic examiners?
  • Which statement about security baselines is accurate?
  • Which tool is used to view Prefetch files?
  • What is the difference between risk, threat, and vulnerability?
  • Nation-States/APTs are hackers or hacking teams that work for governments around the world and have a very high level of technical sophistication as well as resources.
  • Which term best describes a security tool that provides visibility and protection for cloud usage, including data and threat protection?
  • What is the principle of least privilege and why is it important?
  • Which outcome directly results from effective patch management?
  • Which ACPO principle states that no action should change data held on a computer or storage media which may subsequently be relied upon in court?
  • Which of the following is an example of data encryption at rest?
  • What is the difference between a security alert and a ticket?
  • Among Digital Forensics Equipment, which item prevents modifying evidence on a storage device?
  • Which statement best captures the primary purpose of DLP in networks and endpoints?
  • What is a network access control (NAC) and how does it help detect rogue devices?
  • Which algorithm is an example of symmetric cryptography?
  • Which Event ID indicates a failed logon?
  • What is patch management and why is it critical in security operations
  • What is Attribution?
  • Which term is used to describe attackers tricking a target into thinking they are someone they know, increasing likelihood of interaction with a phishing email?
  • What term describes the automatic reclamation of memory that is no longer referenced by programs?
  • What are the stages of the cyber kill chain?
  • What is the purpose of ISACs?
  • Which stage is about distributing intelligence to SOC, analysts, and executives?
  • Which term describes leftover storage that exists on a hard disk when a file does not need all space allocated?
  • In the Threat Intelligence Lifecycle, which stage disseminates finished intelligence to the places it needs to go?
  • In zero-trust security, which concept helps minimize the risk by isolating workloads?
  • Traffic Light Protocol colors.
  • Traffic Light Protocol. What is it?
  • What is the best defense against social engineering?
  • Which is an example of Tactical Threat Intelligence data?
  • Insider Threat refers to individuals who have intentionally or unintentionally abused their power and knowledge of the organization.
  • Define SIEM and its core functions in a SOC environment.
  • Which term describes a group of sectors within a disk that the filesystem uses to organize files?
  • False Positives are...
  • What is the purpose of time synchronization in log management?
  • In cloud environments, what are shared responsibility models and why are they important?
  • What does SIM stand for in security monitoring?
  • What is the primary function of TRIM in solid-state drives (SSDs)?
  • What is alert triage and why is it important?
  • In forensic workflows, what is the main purpose of a write-blocker?
  • Which term describes the grouping of sectors within a disk by which files are organized?
  • Which ACPO principle states that the lead investigator has the overall responsibility to ensure that the ACPO principles are followed throughout the investigation?
  • What is the correct logical order of Active Directory GPO application from first to last?
  • ISAC. They primarily facilitate sharing of actionable intelligence among which groups?
  • Which term describes when a malicious actor spends time gathering information about their target before a phishing attack?
  • What distinguishes SEM from SIM in security software?
  • Attachment Name belongs to which artifact category?
  • Describe the general approach to containment during an incident.
  • Which phishing category involves impersonating a known source to obtain financial advantage?
  • What are common logging sources in a blue team environment and why are they important?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy