Security Blue Team Level 1 Exam
Practice Questions & Verified Answers with
Rationale
The Security Blue Team Level 1 Certification Exam is designed for
individuals seeking to validate their foundational skills in cybersecurity
defense and blue team operations. This comprehensive exam evaluates
candidates' knowledge across multiple domains including email security,
phishing analysis, social engineering detection, network defense, incident
response, and security operations.
This practice question bank contains 250 questions aligned with the exam
content areas, covering reconnaissance emails, credential harvesting,
social engineering techniques, smishing, vishing, whaling, malicious
attachments, hosted malware, spam detection, false positives, spear
phishing, impersonation, typosquatting, homographs, sender spoofing, URL
shorteners, Business Email Compromise (BEC), email artifacts, and other
critical blue team concepts. Each question includes the correct answer and
a brief rationale to support your exam preparation.
SECTION 1: EMAIL SECURITY AND PHISHING ANALYSIS (Questions 1-50)
1. Reconnaissance emails (recon emails)
Answer: Used to check if the destination mailbox is in use so that it can
be targeted in future phishing attack. Can be spam, social engineering or
tracking pixels.
2. Credential Harvesters
Answer: Most common phishing emails targeting human weaknesses to attempt
to retrieve valid credentials. Email will tell the recipient to click a
button or URL, where they will typically be presented with a real-looking
login portal.
,3. Social Engineering
Answer: The practice of exploiting a human as opposed to a system.
Malicious actors can convince employees that they are someone they know,
or even someone in a higher position that has more power than them.
4. Smishing
Answer: Kind of phishing attack, where the attack vector is through a
text message or SMS. Best way to defend is user security awareness
training and education.
5. Vishing
Answer: Kind of phishing attack, where the attack vector is through a
phone call. Best way to defend is user security awareness training and
education.
6. Whaling
Answer: Highly-targeted phishing attack that looks to target individuals
within management positions in an organization. Best way to defend is
implementing DLP, marking external emails, train individuals to detect
phishing emails.
7. Malicious Attachments
Answer: Malicious actors will send you Microsoft Office documents to
bypass email scanners and to seem less suspicious. Include malicious
macros, series of command and instructions, that download malware to the
system.
8. Hosted Malware
Answer: Method of hosting malware on websites and convincing users to
click on a hyperlink, download a file, and then run it. Actor can create
a malicious domain or compromise a legitimate site then host the malware.
,9. Spam Emails
Answer: Messages that are unsolicited, unwanted, or unexpected but are
not necessarily malicious in nature. Should not be confused with
malicious spam emails.
10. False Positives
Answer: Messages that have not been sent by a malicious actor and are
instead legitimate emails that have been incorrectly reported as
malicious.
11. Spear Phishing
Answer: When a malicious actor spends time before the phishing attack to
gather information about their specific target. Makes it more convincing,
increases the chances of the recipient clicking on the email and entering
their credentials, or opening an attachment.
12. Impersonation
Answer: Used by malicious actors to trick their target into thinking
they are someone they know. Makes them more likely to open and interact
with a phishing email.
13. Typosquatting
Answer: The act of impersonating a brand or domain name by misspelling
it, such as missing letters or including additional ones.
14. Homographs
Answer: This attack exploits the fact that many different characters look
exactly alike. The problem is with how the characters are encoded using
Unicode. Virtually impossible for users to spot.
15. Sender Spoofing
Answer: The process of making the sending address in an email look the
same as a legitimate email to make the recipients believe it is coming
, from a genuine sender.
16. URL Shorteners
Answer: A tactic for disguising malicious URLs, short versions that
simply redirect to the full URL. Example: bit.ly/2yyvczQ
17. Business Email Compromise (BEC)
Answer: A type of phishing attack where a threat actor impersonates a
known source to obtain financial advantage.
18. Email Artifacts
Answer: - Sending Email Address
- Sending IP Address
- Reply-to Address
- Subject Line
- Attachments
- Body Content
- Headers (SPF, DKIM, DMARC)
19. What is the primary purpose of a reconnaissance email?
A. To immediately infect the recipient's system
B. To check if the destination mailbox is in use for future targeting
C. To steal credentials directly
D. To send spam messages
Answer: B
Reconnaissance emails are used to verify that an email address is active
and monitored, allowing attackers to target it in future phishing
campaigns.
20. Which of the following is a common indicator of a credential harvester
phishing email?
A. A request to verify account details by clicking a link
B. A simple greeting without any call to action