1 | Page
Sophos Firewall v20.0 Real Exam High
Yield Practice Questions and Verified
Answers Graded A+ Pass Guaranteed
Just Released
This practice exam covers the key technical domains of the Sophos
Firewall v20.0 certification, including the Attack Kill Chain,
Security Features, Deployment and Configuration, High Availability
and Routing, Authentication and VPN, Zero Trust Network Access,
and Troubleshooting.
1: THE ATTACK KILL CHAIN AND SECURITY FUNDAMENTALS
Question 1
What are the phases of the Attack Kill Chain as defined in Sophos
security concepts?
A) Reconnaissance, Weaponization, Delivery, Exploitation, Installation,
Command and Control, Behaviour
B) Scanning, Phishing, Payload Delivery, Execution, Persistence,
Exfiltration, Destruction
C) Reconnaissance, Intrusion, Propagation, Execution, Obfuscation,
Control, Damage
,2 | Page
D) Discovery, Weaponization, Distribution, Trigger, Installation,
Communication, Action
Verified Answer: A
Rationale: The Attack Kill Chain consists of seven phases:
Reconnaissance (passive information gathering), Weaponization
(preparing the exploit), Delivery (sending the payload), Exploitation
(executing code on the victim machine), Installation (establishing
persistence), Command and Control (connecting to remote servers), and
Behaviour (executing the final objective).
Question 2
What happens during the Delivery phase of the Attack Kill Chain?
A) The attacker gathers email addresses and company information
through passive reconnaissance
B) The attacker uses a vulnerability to execute code on the victim's
machine
C) The attacker accesses the estate to deliver the malicious payload via
email or social engineering
D) The attacker installs malware that establishes persistence on the
infected machine
Verified Answer: C
Rationale: The Delivery phase involves the attacker delivering the
malicious payload to the target, often through methods such as email
attachments or social engineering to direct the victim to a malicious site.
,3 | Page
Question 3
What happens in the Reconnaissance and Weaponization phases of the
Attack Kill Chain?
A) The attacker creates the malware to exploit a known vulnerability
B) The attacker will passively harvest email addresses and company
information, before actively scanning the target environment using tools
like port scanners
C) The attacker delivers the malicious payload via email or social
engineering
D) The attacker establishes a connection to a remote command and
control centre
Verified Answer: B
Rationale: In the Reconnaissance phase, the attacker passively harvests
information such as email addresses and company details, then actively
scans the target environment using tools like port scanners during
Weaponization.
Question 4
What happens during the Command and Control phase of the Attack Kill
Chain?
A) The installed malware makes a connection to a remote command and
control centre for remote manipulation
B) The attacker gathers information about the target environment
C) The attacker delivers the malicious payload to the victim
, 4 | Page
D) The attacker exploits a vulnerability to execute code on the victim
machine
Verified Answer: A
Rationale: In the Command and Control phase, the installed malware
establishes a connection to a remote command and control centre,
allowing the attacker to remotely manipulate the infected machine.
Question 5
What happens in the Behaviour phase of the Attack Kill Chain?
A) The attacker delivers the malicious payload via email
B) The attacker installs malware on the victim machine
C) The malware behaviour varies, including encrypting files for ransom
or stealing information such as passwords or payment details
D) The attacker passively gathers information about the target
organization
Verified Answer: C
Rationale: In the Behaviour phase, the malware executes its final
objective. This can include encrypting files for ransom, stealing and
downloading passwords, or exfiltrating payment information.
Question 6
What is ATP in Sophos Firewall terminology?
A) Advanced Threat Protocol
Sophos Firewall v20.0 Real Exam High
Yield Practice Questions and Verified
Answers Graded A+ Pass Guaranteed
Just Released
This practice exam covers the key technical domains of the Sophos
Firewall v20.0 certification, including the Attack Kill Chain,
Security Features, Deployment and Configuration, High Availability
and Routing, Authentication and VPN, Zero Trust Network Access,
and Troubleshooting.
1: THE ATTACK KILL CHAIN AND SECURITY FUNDAMENTALS
Question 1
What are the phases of the Attack Kill Chain as defined in Sophos
security concepts?
A) Reconnaissance, Weaponization, Delivery, Exploitation, Installation,
Command and Control, Behaviour
B) Scanning, Phishing, Payload Delivery, Execution, Persistence,
Exfiltration, Destruction
C) Reconnaissance, Intrusion, Propagation, Execution, Obfuscation,
Control, Damage
,2 | Page
D) Discovery, Weaponization, Distribution, Trigger, Installation,
Communication, Action
Verified Answer: A
Rationale: The Attack Kill Chain consists of seven phases:
Reconnaissance (passive information gathering), Weaponization
(preparing the exploit), Delivery (sending the payload), Exploitation
(executing code on the victim machine), Installation (establishing
persistence), Command and Control (connecting to remote servers), and
Behaviour (executing the final objective).
Question 2
What happens during the Delivery phase of the Attack Kill Chain?
A) The attacker gathers email addresses and company information
through passive reconnaissance
B) The attacker uses a vulnerability to execute code on the victim's
machine
C) The attacker accesses the estate to deliver the malicious payload via
email or social engineering
D) The attacker installs malware that establishes persistence on the
infected machine
Verified Answer: C
Rationale: The Delivery phase involves the attacker delivering the
malicious payload to the target, often through methods such as email
attachments or social engineering to direct the victim to a malicious site.
,3 | Page
Question 3
What happens in the Reconnaissance and Weaponization phases of the
Attack Kill Chain?
A) The attacker creates the malware to exploit a known vulnerability
B) The attacker will passively harvest email addresses and company
information, before actively scanning the target environment using tools
like port scanners
C) The attacker delivers the malicious payload via email or social
engineering
D) The attacker establishes a connection to a remote command and
control centre
Verified Answer: B
Rationale: In the Reconnaissance phase, the attacker passively harvests
information such as email addresses and company details, then actively
scans the target environment using tools like port scanners during
Weaponization.
Question 4
What happens during the Command and Control phase of the Attack Kill
Chain?
A) The installed malware makes a connection to a remote command and
control centre for remote manipulation
B) The attacker gathers information about the target environment
C) The attacker delivers the malicious payload to the victim
, 4 | Page
D) The attacker exploits a vulnerability to execute code on the victim
machine
Verified Answer: A
Rationale: In the Command and Control phase, the installed malware
establishes a connection to a remote command and control centre,
allowing the attacker to remotely manipulate the infected machine.
Question 5
What happens in the Behaviour phase of the Attack Kill Chain?
A) The attacker delivers the malicious payload via email
B) The attacker installs malware on the victim machine
C) The malware behaviour varies, including encrypting files for ransom
or stealing information such as passwords or payment details
D) The attacker passively gathers information about the target
organization
Verified Answer: C
Rationale: In the Behaviour phase, the malware executes its final
objective. This can include encrypting files for ransom, stealing and
downloading passwords, or exfiltrating payment information.
Question 6
What is ATP in Sophos Firewall terminology?
A) Advanced Threat Protocol