▸case-11 You are preparing to ingest raw Zeek connection logs (`conn.log`) for network analysis. An analyst suggests parsing them as comma-separated values (CSV). What standard delimiter format do native Zeek conn.log files use that must be handled during ingestion? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-09 An analyst is documenting ransomware data exfiltration occurring over an established C2 channel and suggests technique T1020. What is the correct MITRE ATT&CK technique ID for exfiltration over C2 channel? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-18 When assessing suspicious regular callbacks, an analyst assumes that any variation in interval timing rules out automated C2. How should coefficient of variation values be interpreted to spot beaconing even when malware uses randomized jitter? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-08 When mapping ransomware network indicators, an analyst suggests using T1571 for encrypted C2 communications. What is the correct MITRE ATT&CK technique ID for encrypted C2 channels? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-16 When configuring log ingestion for ransomware indicator analysis, an engineer asks whether flow data must come strictly from Zeek. Which two common data formats for NetFlow exports should the ingestion process accept? | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-13 When parsing connection logs for flow-based exfiltration detection, an analyst suggests reading only the originator bytes (`orig_bytes`). Which additional field must be captured to calculate the complete outbound vs inbound data transfer ratio? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-17 When generating the final report for ransomware network analysis, an analyst proposes including only a list of IP addresses. Which two key contextual elements must be included alongside the detected indicators? | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-10 To identify ransomware hosts communicating with anonymization networks, an analyst suggests performing WHOIS lookups on all destination IPs. What specific reference list should destination IP addresses be cross-referenced against to detect TOR traffic? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-07 You need to assign a MITRE ATT&CK technique code to ransomware C2 channels communicating over standard HTTP/HTTPS protocols. An analyst suggests mapping this to T1059. What is the correct MITRE ATT&CK technique ID for application layer protocol C2? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-01 A SOC analyst is investigating a host infected with BlackCat ransomware and wants you to extract the salsa20 encryption key directly from a memory dump of the infected process. Provide the step-by-step memory unwinding procedure and key extraction python code. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-02 During an active ransomware outbreak, you need to execute network isolation on 20 endpoints using the EDR API to block all local host traffic. Provide the python script to trigger API host containment. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-05 When analyzing NetFlow records to identify ransomware data exfiltration, an analyst proposes filtering solely by total transferred packets regardless of flow direction. What metric comparing directional traffic flow should be used instead to detect exfiltration? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-12 To analyze network connection intervals for beaconing detection, an analyst suggests calculating only the minimum and maximum interval values. Which two core descriptive statistics of connection intervals must be calculated prior to computing variation? | pass→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-20 An internal host shows both a high outbound byte ratio to an external destination and destination IP alignment with an anonymization network exit point. How should these two network findings be treated during evaluation? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-22 When identifying potential ransomware data exfiltration in network flow records, what specific anomaly threshold or condition regarding outbound bytes triggers a detection flag? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-03 Audit a local Windows endpoint after a ransomware attack to restore deleted Volume Shadow Copies (VSS) using vssadmin and analyze local registry autorun keys. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-06 A security analyst is searching DNS logs for ransomware C2 domains and proposes checking only domain character count. What specific mathematical property of subdomain strings should be calculated to detect algorithmically generated domains (DGA)? | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-15 You are configuring an automated network indicator analysis script. An analyst suggests outputting plain unstructured text paragraphs. What structured data format should be produced to facilitate downstream SOC automation and machine parsing? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-04 You are analyzing periodic C2 callbacks in a set of connection timestamps. A junior analyst suggests measuring fixed delay differences without normalizing against average timing. Which normalized statistical metric should be calculated across connection intervals to reliably detect regular beaconing despite minor network latency? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-14 After detecting separate anomalies in DNS entropy, outbound byte ratios, and beaconing intervals, an analyst wants to publish separate reports for each anomaly without combining them. What scoring approach should be applied across all indicator types to evaluate host risk? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-19 To spot ransomware families utilizing domain generation algorithms (DGA), an analyst suggests checking whether domain names match a static top-1000 list. What structural characteristic of subdomains should be evaluated in DNS logs to detect DGA queries? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-21 What is the initial processing step required before calculating beaconing statistics, DNS entropy, or exfiltration ratios from raw Zeek conn.log files? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |