Hard 200-201 practice questions
Challenge — multi-step scenarios, trade-offs, and subtle distinctions. 2 hard questions available — no sign-up, always free.
While analyzing a suspicious PCAP, an analyst notices multiple IPv4 packets from a single source that each carry the More Fragments (MF) flag set and non-zero Fragment Offset values, but the reassembled payloads produce overlapping byte ranges. Based on interpreting these IPv4 header fields, what is the most likely purpose of this traffic?
A SOC analyst investigating a suspected endpoint compromise pulls the following data types from their monitoring platform: NetFlow records, firewall logs, and full packet capture from the network segment. The malware is confirmed to run entirely in memory on the host, injects into a legitimate signed process, and communicates only over TLS 1.3 to a domain that later resolves to a known-good CDN. Which additional data source would most directly reveal the malicious activity that the network-based sources are missing?