Official Bank 0/100

Logical Operations CyberSec First Responder (CFR-210) - Logical Operation Exam Questions

Last updated on June 20, 2026

97% Exam Compliance
100 Total Questions
1
Question
An attacker has sent malicious macro-enabled Office files. Which of the following regular expressions will return a list of macro-enabled files?
Options
A ^.*(?:xls|ppt|doc)m.*
B ^.*?\.(?:xls|ppt|doc)m
C ^.*(?:xls|ppt|doc)m
D ^.*?\.(?:xls|ppt|doc)m$
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question
A SOC analyst reviews vendor security bulletins and security blog articles against the company’s deployed system and software base. Based on current attack patterns, three vulnerabilities, including a zero-day vulnerability, have been upgraded to high priority. Which of the following should the SOC analyst recommend? (Choose two.)
Select 2
Options
A Implement DNS filtering
B Reboot affected servers
C Patch affected systems
D Update IPS rules
E Implement application whitelisting
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question
When investigating a wireless attack, which of the following can be obtained from the DHCP server?
Options
A Operating system of the attacker
B MAC address of the attacker
C Effectiveness of the VLAN terminator
D IP traffic between the attacker and victim
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question
As part of an incident response effort, data has been collected and analyzed, and a malware infection has been contained. Which of the following is the NEXT step the incident response team should take within the incident response process?
Options
A Ensure every instance of the malware has been removed across the organization.
B Begin recovering all infected systems to return the organization to normal operations as soon as possible.
C Start writing the report to ensure a quality product is delivered by the end of the project.
D Discuss lessons learned before proceeding with other steps.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question
An alert on user account activity outside of normal business hours returns Windows even IDs 540 and 4624. In which of the following locations will these events be found?
Options
A System event log
B Application event log
C Security event log
D Setup event log
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.