Browse all practice questions for the ReliaQuest Security Analyst / Greymatter Specialist Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

ReliaQuest Security Analyst / Greymatter Specialist Practice Test course image
All questions

These questions are part of the practice quiz. Start practicing

  • Which phase of the incident lifecycle focuses on post-incident analysis and updating detections?
  • In incident metric terminology, what does detection coverage refer to?
  • What is the recommended approach to perform a post-incident root-cause analysis and which artifacts should be collected?
  • SQL is used for what?
  • What is the role of EDR and NDR telemetry in detecting advanced threats?
  • What is an appropriate initial response when a user clicks a phishing link?
  • Differentiate between IOCs and TTPs and how Greymatter uses them in detections.
  • How should a phishing simulation program be approached to align with Greymatter playbooks?
  • Which statement correctly describes a DMZ in network architecture?
  • Which network device directs traffic between different networks using IP routing tables?
  • Which statement best describes how detections map to the Kill Chain stages?
  • Which artifact is most useful for detecting lateral movement?
  • Which defense best counters reconnaissance and network scanning by an attacker?
  • Which statement best describes the value of threat modeling in a security operations program?
  • What are some best practices for secure on-boarding of new analysts in the Greymatter environment?
  • Which of the following is a web-based injection attack?
  • Which Linux command displays active network connections and listening ports?
  • Which statement best describes how Greymatter uses data correlation to detect suspicious activity?
  • Which type of malware self-replicates and can spread rapidly across networks without requiring user interaction?
  • What is the primary objective of compiling a timeline in a security investigation case?
  • Which HTTP status code range corresponds to informational responses?
  • If China was port scanning and you have no relations to China what do you do?
  • How is a DMZ typically deployed in a network, and what services would it commonly include?
  • Which protocol/port combination is commonly abused for remote desktop access and potential ransomware deployment?
  • What is the role of threat intel in breach investigations?
  • What is a SIM/SIEM?
  • Which tool is primarily used for exploitation in penetration testing?
  • How would you go about identifying malicious activity?
  • Which port is commonly exploited for anonymous access and data exfiltration?
  • Which initial access vector is commonly detected by authentication failures and abnormal login patterns?
  • During a port scan, which log entries are typically generated?
  • What kind of traffic could resemble port scanning?
  • In the incident response lifecycle, what step comes after Detection?
  • Which telemetry would you rely on to detect credential dumping attempts?
  • Describe how to perform cross-correlation between endpoint, network, and cloud logs to detect complex attacks.
  • Which of the following is considered an offensive security technique?
  • What does a port scan typically look like?
  • Syslog is a standardized protocol used to collect, store, and transmit logs. What is its primary purpose?
  • Which layer manages physical transmission via Ethernet, Wi-Fi, or other link-layer technologies?
  • What is the last rule commonly placed on a firewall?
  • Which statement best describes suppression by entity in Greymatter?
  • Describe the TCP handshake.
  • What is Wireshark primarily used for?
  • Which memory forensics artifacts are most useful for identifying in-memory malware on Windows?
  • Which of the following is NOT listed among the OWASP Top 10 vulnerabilities?
  • Which description best explains port numbers in networking?
  • Which of the following is a defensive security technique?
  • If you see a large ICMP file being sent to an AWS server, what is the recommended first step?
  • What is Wireless Application Protocol (WAP)?
  • Which statement best describes the security implications of IP addresses?
  • When triaging incidents, which set of factors should guide prioritization?
  • Which service uses port 22?
  • What is threat modeling in the context of Greymatter and why is it important?
  • Which incident metrics are commonly used to evaluate performance, and how should their trends be interpreted?
  • Which of the following is a commonly used OSINT tool?
  • Which of the following is a sign of intrusion?
  • What artifacts are typically collected to support a post-incident root-cause analysis and remediation planning?
  • What are ports used for?
  • How would you assess and communicate incident risk to executive stakeholders after containment?
  • Which HTTP security feature helps prevent client-side script access to cookies?
  • What is cross-site scripting (XSS) and how can it be prevented?
  • Which statement correctly describes the difference between GET and POST in HTTP?
  • Which cloud log sources are essential to detect misconfig or abuse in cloud environments and how should they be ingested?
  • After gaining access to a network, which actions are commonly performed?
  • How does malware achieve persistence?
  • What is the primary purpose of DNS in a network?
  • Which set represents the core components of ReliaQuest Greymatter architecture and their typical data flow during alert processing?
  • Which TCP/IP layer ensures reliable data transmission (TCP) or fast transmission (UDP)?
  • Why does Greymatter normalize data from diverse sources?
  • Which layer routes data packets using IP addresses?
  • In Greymatter, what does data normalization do and why are consistent schemas important?
  • Which tool is used for vulnerability scanning in penetration testing?
  • What is a runbook, and which steps are appropriate when crafting one for ransomware containment?
  • What distinguishes stateful packet filtering from stateless filtering?
  • What is SQL injection (SQLi) and how can it be prevented?
  • What is a proxy server and what is its primary function?
  • Describe botnets.
  • What are the four phases of the end-to-end incident response lifecycle in Greymatter practice?
  • Which cloud-native security services complement Greymatter in a multi-cloud environment?
  • Outline the steps to onboard a new data source into Greymatter and ensure effective detections.
  • What data pattern indicates exfiltration in Greymatter?
  • In the Cyber Kill Chain, which phase involves developing or acquiring the malicious payload (malware) that will exploit vulnerabilities?
  • Which statement about the TCP handshake is true?
  • Which is the correct sequence of the Lockheed Martin Cyber Kill Chain stages?
  • Which statement best describes the TCP/IP suite?
  • Which statement best describes the Gateway device?
  • Which description accurately summarizes how DNS resolves a domain name to an IP address?
  • If an attacker gained access to a system and could do anything, which of the following best reflects typical attacker objectives?
  • Describe the difference between a router and a switch.
  • What regulatory considerations should be considered when storing security logs in a multi-region environment?
  • Which component is primarily responsible for turning correlated signals into actionable alerts in Greymatter?
  • Which input pattern is commonly associated with SQL injection attempts?
  • Which artifact is not typically considered a memory forensics artifact when identifying in-memory malware on a Windows host?
  • Which vulnerability allows unauthorized access to files or user accounts by modifying request parameters?
  • Which phase of penetration testing comes after Vulnerability Assessment?
  • Threat intelligence enrichment in a security operations workflow primarily provides which of the following?
  • What is the first thing malware does when executed?
  • Which tool is used for exploitation in penetration testing?
  • In the TCP/IP model, which layer handles user interactions and application protocols such as HTTP and DNS?
  • Which statement correctly describes a reverse proxy?
  • Rootkits are designed to do which of the following?
  • What is the role of playbooks in Greymatter?
  • If you found out that your computer had a virus, walk me through how you would diagnose the problem.
  • Which port is used by DNS?
  • Which proxy sits in front of a web server to distribute requests and improve reliability?
  • What do MTTR and MTTA stand for, and how are they calculated in incident response?
  • Which network topology is characterized by a central hub connecting all devices?
  • Which defense best mitigates SQL Injection?
  • What would you do with a botnet?
  • Which of the following is NOT listed as an attacker entry method?
  • What is the purpose of lock-out and account gating controls in threat detection and response?
  • Differentiate horizontal escalation from vertical escalation in SOC operations and provide an example of each.
  • Which practice supports privacy-preserving logging in Greymatter?
  • In a Greymatter incident case, why is an immutable case history important?
  • What is case management in Greymatter?
  • What are some ways to mitigate against an attacker once they've reached an internal machine?
  • During ransomware containment, why is preserving evidence important?
  • Which web attack involves exploiting a server-side function to make unauthorized requests to internal resources?
  • Which approach is recommended to reduce false positives and tune detections in Greymatter?
  • Which of the following best mitigates man-in-the-middle attacks in a network?
  • What are typical incident severities and the criteria used to assign them in Greymatter practice?
  • Which HTTP status code range represents successful responses?
  • Before deploying a new detector rule to production, which validation steps are recommended?
  • Which action is most effective to mitigate after an attacker has reached an internal machine?
  • What best describes an Intrusion Detection System (IDS)?
  • Which behavior is a common early sign of malware on a device?
  • Which statement is true about TCP and UDP?
  • Which statement best describes routing and switching in a network?
  • In the incident response process, which activity best describes the Preparation phase?
  • How would you design a Greymatter-based alerting strategy to minimize alert fatigue?
  • Which of the following best describes a port scan?
  • What are typical log retention guidelines for an enterprise SOC and how does Greymatter help manage this?
  • Which data source is NOT typically ingested by Greymatter?
  • Which data categories are major sources Greymatter ingests and how are they normalized?
  • Which statement correctly describes a forward proxy?
  • Which web attack is characterized by injecting malicious scripts into web pages to steal user data or manipulate content?
  • What is data enrichment and which examples are commonly used in alert investigations?
  • Which Linux command retrieves domain registration and IP information?
  • Which network troubleshooting tool is commonly used to diagnose connectivity and routing issues by displaying the path to a host?
  • What is the recommended action upon detecting a phishing email?
  • What best describes an Intrusion Prevention System (IPS)?
  • Which Kill Chain stage is primarily associated with Command & Control activity?
  • Which type of malware encrypts a victim's files until a ransom is paid?
  • Which statement about vulnerability scanning tools is true?
  • What is reverse DNS and when is it used?
  • What is a DMZ and why is it used?
  • What is a firewall and which of the following describes its typical types?
  • Lateral movement detection refers to what, and which signals are typical indicators?
  • Describe a sample query concept to detect anomalous login times (off-hours) for a user.
  • In detector-rule validation, what does a high false positive rate imply?
  • What approach best enables detection of coordinated attacks across endpoint, network, and cloud domains?
  • Which statement describes the distinction between SIM and SIEM?
  • If you suspected malware on one of three computers, which indicators would you check?
  • What is a typical threat hunting workflow within a modern security operations practice?
  • To confirm a breach when multiple alerts are present, which approach is most effective?
  • What is zero trust in a security operations center and how would Greymatter support it?
  • Which proxy type protects internal servers by filtering threats and managing traffic?
  • A detection rule concept for PowerShell activity should include which components?
  • What is the best practice for validating a new data source before relying on its detections?
  • Which measure mitigates Insecure Direct Object References (IDOR) vulnerabilities?
  • Which term describes a proxy that handles client requests to external resources?
  • Which attack involves stealing or manipulating session tokens to impersonate a user?
  • What is the purpose of an SSL handshake?
  • Which ATT&CK mapping best reflects detections for spearphishing attachments, spearphishing links, PowerShell, and Web Protocols?
  • Which activity is an appropriate first step to investigate lateral movement using Greymatter data?
  • Which is the final phase of the Cyber Kill Chain, where the attacker achieves their ultimate objective?
  • How do you handle data privacy regulations when logging in Greymatter?
  • What is a primary benefit provided by a reverse proxy?
  • Which defense best mitigates CSRF attacks?
  • Which log sources are typically ingested by a SIEM for threat detection?
  • Which cloud log sources are essential to detect misconfig or abuse, and how should Greymatter ingest them?
  • Which tool is commonly used for penetration testing and post-exploitation activities?
  • In incident response workflows, which statement best describes the relationship among an event, an alert, and a case?
  • Which description correctly identifies the function of the OSI Presentation layer?
  • Which is commonly one of the first actions a hacker takes after gaining access to an internal system?
  • Which component is NOT typically part of a detection rule concept?
  • What is a wireless access point (WAP)?
  • Which statement best describes TCP?
  • What is baselining in security analytics and how is it used?
  • Which security technique involves using leaked credentials to automate login attempts?
  • How would you map a set of alerts to MITRE ATT&CK techniques to assess coverage?
  • What is the primary goal of mapping detections to Kill Chain stages?
  • Which defense mitigates Server-Side Request Forgery (SSRF)?
  • Explain how to maintain evidence integrity in incident investigations in Greymatter.
  • What is the primary purpose of a playbook in Greymatter and what are its typical components?
  • Which HTTP status code range corresponds to client errors?
  • Which statement about the OSI Model is accurate regarding the Transport layer?
  • How would you design spearphishing link vs attachment detection and strategies?
  • Which tool is NOT primarily used for exploitation?
  • Which HTTP status code range covers server errors?
  • Which signals are best captured by network detection and response (NDR) telemetry?
  • Which indicators signal an SQL injection attack?
  • Which statement correctly describes the Session layer in the OSI model?
  • The Cyber Kill Chain framework is part of which defense model?
  • Which practice is essential for secure on-boarding of new analysts in Greymatter?
Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy