Key details for this exam, checked against the published exam outline
Each question shows the correct answer and an explanation of why it is right
A government organization responsible for critical infrastructure is being attacked and files on the server been deleted. Which of the following are the most immediate communications that should be made regarding the incident? (Choose two.)
What allows a company to restore normal business operations in a matter of minutes or seconds?
A hot site is a fully equipped, operational backup site that allows a company to restore normal business operations in a matter of minutes or seconds. It has up-to-date copies of critical data and systems, ensuring minimal downtime in the event of a disaster.
Traditional SIEM systems provide:
Traditional SIEM (Security Information and Event Management) systems are designed to provide aggregation, normalization, correlation, and alerting of log and event data from various sources within an organization's network. These functions help identify potential security incidents, providing security teams with the necessary information to investigate and respond to threats effectively.
A Linux system administrator found suspicious activity on host IP 192.168.10.121. This host is also establishing a connection to IP 88.143.12.123. Which of the following commands should the administrator use to capture only the traffic between the two hosts?
ABC Company uses technical compliance tests to verify that its IT systems are configured according to organizational information security policies, standards, and guidelines. Which two tools and controls can ABC Company use to verify that its IT systems are configured accordingly? (Choose two.)
Performing Vulnerability Assessments and Penetration Testing: These tools are used to identify weaknesses in the system configurations and test whether the IT systems are vulnerable to various security threats, which helps verify compliance with security policies.
Implementing Baseline Configuration Security Controls: Baseline configuration controls ensure that IT systems are set up according to predefined, secure configurations, which helps ensure compliance with organizational security policies and standards.
What are the two most appropriate binary analysis techniques to use in digital forensics analysis? (Choose two.)
Static Analysis: Involves examining the binary code without executing it, helping to identify potentially malicious code, vulnerabilities, or patterns in the file's structure.
Dynamic Analysis: Involves executing the binary in a controlled environment to observe its behavior, interactions, and effects, which is useful for identifying how the binary functions in real time.
Exam domains verified against: Official CertNexus CFR-410 exam guide, last checked September 2026.
Identify assets across your infrastructure including applications, workstations, and operating systems. Map your network topology, data flows, and vulnerable ports using passive and active scanning tools like Nmap and Nessus. Evaluate threats by reviewing relevant policies, analyzing asset risks, and monitoring CVE and CVSS data against your critical infrastructure.
Sample question from this domain above: Q5
Analyze security posture trends using logs and vulnerability databases to prioritize remediation steps. Apply security policies and hardening techniques against common attack methods including footprinting, scanning, malware, and social engineering. Implement defense-in-depth with IDS/IPS, firewalls, network segmentation, and endpoint detection tools. Conduct independent audits and ensure patch management plans protect against identified vulnerabilities.
Analyze indicators of compromise in security logs and SIEM systems to spot anomalies like unusual bandwidth usage, suspicious files, and unauthorized accounts. Perform log analysis using tools like grep and Event Viewer, enriching data with IP resolution and threat feeds. Distinguish malicious activity from benign behavior and alert incident response teams with documented evidence of confirmed threats and misuse.
Sample question from this domain above: Q6
Execute incident response plans including containment through network segmentation, firewall rules, and web filtering. Collect and preserve digital evidence with proper chain of custody using forensic tools like EnCase and Volatility. Correlate logs and forensic data to identify root causes and determine attacker tactics, techniques, and procedures. Escalate and communicate findings to internal teams and external stakeholders following established procedures.
Conduct post-incident root cause analysis and lessons learned sessions to document recovery activities. Implement countermeasures for systems affected by incidents, addressing security requirements and prevention strategies. Review forensic images and memory dumps for evidence recovery using Volatility and bit stream imaging techniques. Advise on disaster recovery and business continuity plans that strengthen resilience against future attacks.
Common questions about the exam itself