CertNexus CyberSec First Responder CFR-410 Dumps in PDF

Free CertNexus CFR-410 Real Questions (page: 1)

A network security analyst has noticed a flood of Simple Mail Transfer Protocol (SMTP) traffic to internal clients. SMTP traffic should only be allowed to email servers.
Which of the following commands would stop this attack? (Choose two.)

  1. iptables -A INPUT -p tcp ­dport 25 -d x.x.x.x -j ACCEPT
  2. iptables -A INPUT -p tcp ­sport 25 -d x.x.x.x -j ACCEPT
  3. iptables -A INPUT -p tcp ­dport 25 -j DROP
  4. iptables -A INPUT -p tcp ­destination-port 21 -j DROP
  5. iptables -A FORWARD -p tcp ­dport 6881:6889 -j DROP

Answer(s): A,C



A secretary receives an email from a friend with a picture of a kitten in it. The secretary forwards it to the
~COMPANYWIDE mailing list and, shortly thereafter, users across the company receive the following message:

"You seem tense. Take a deep breath and relax!"

The incident response team is activated and opens the picture in a virtual machine to test it. After a short analysis, the following code is found in C:

\Temp\chill.exe:Powershell.exe ­Command "do {(for /L %i in (2,1,254) do shutdown /r /m Error! Hyperlink reference not valid.> /f /t / 0 (/c "You seem tense. Take a deep breath and relax!");Start- Sleep ­s 900) } while(1)"

Which of the following BEST represents what the attacker was trying to accomplish?

  1. Taunt the user and then trigger a shutdown every 15 minutes.
  2. Taunt the user and then trigger a reboot every 15 minutes.
  3. Taunt the user and then trigger a shutdown every 900 minutes.
  4. Taunt the user and then trigger a reboot every 900 minutes.

Answer(s): B



A Linux system administrator found suspicious activity on host IP 192.168.10.121. This host is also establishing a connection to IP 88.143.12.123.
Which of the following commands should the administrator use to capture only the traffic between the two hosts?

  1. # tcpdump -i eth0 host 88.143.12.123
  2. # tcpdump -i eth0 dst 88.143.12.123
  3. # tcpdump -i eth0 host 192.168.10.121
  4. # tcpdump -i eth0 src 88.143.12.123

Answer(s): B



After imaging a disk as part of an investigation, a forensics analyst wants to hash the image using a tool that supports piecewise hashing.
Which of the following tools should the analyst use?

  1. md5sum
  2. sha256sum
  3. md5deep
  4. hashdeep

Answer(s): A



Which of the following is a cybersecurity solution for insider threats to strengthen information protection?

  1. Web proxy
  2. Data loss prevention (DLP)
  3. Anti-malware
  4. Intrusion detection system (IDS)

Answer(s): B


Reference:

https://www.techrepublic.com/article/how-to-protect-your-organization-against-insider- threats/



Share your comments for CertNexus CFR-410 exam with other users:

A
akminocha
9/28/2023 10:36:00 AM

please help us with 1z0-1107-2 dumps

J
Jefi
9/4/2023 8:15:00 AM

please upload the practice questions

T
Thembelani
5/30/2023 2:45:00 AM

need this dumps

A
Abduraimov
4/19/2023 12:43:00 AM

preparing for this exam is overwhelming. you cannot pass without the help of these exam dumps.

P
Puneeth
10/5/2023 2:06:00 AM

new to this site but i feel it is good

A
Ashok Kumar
1/2/2024 6:53:00 AM

the correct answer to q8 is b. explanation since the mule app has a dependency, it is necessary to include project modules and dependencies to make sure the app will run successfully on the runtime on any other machine. source code of the component that the mule app is dependent of does not need to be included in the exported jar file, because the source code is not being used while executing an app. compiled code is being used instead.

M
Merry
7/30/2023 6:57:00 AM

good questions

V
VoiceofMidnight
12/17/2023 4:07:00 PM

Delayed the exam until December 29th.

U
Umar Ali
8/29/2023 2:59:00 PM

A and D are True

V
vel
8/28/2023 9:17:09 AM

good one with explanation

G
Gurdeep
1/18/2024 4:00:15 PM

This is one of the most useful study guides I have ever used.

AI Tutor 👋 I’m here to help!