Free PBQ Demo · Advanced

Topology · Malware Containment

CompTIA CertMaster-style PBQ — click any host in a live network diagram to isolate an infected workstation, block its C2 traffic at the perimeter firewall, and revoke its file-server access.

Tests: Incident response, network segmentation, ACL configuration under time pressure — the exact PBQ format on Security+, CySA+, and CCNA exams.

~10 minNo signup needed

Scenario

Your SIEM has flagged WS-A (Marketing) for ransomware-like behaviour — outbound C2 traffic, suspicious file encryption, and lateral SMB scanning toward the file server. You're the on-call analyst.

Contain WS-A, block its C2 channel at the perimeter firewall, and revoke its access to the file server. Leave clean hosts untouched.

Network Topology — Live View

monitoring
WANtrunk10.0.20.0/2410.0.10.0/24Internet0.0.0.0/0Perimeter FWfw-edge-01Core Switchsw-core-01FS-0110.0.20.10 · PayrollWS-A10.0.10.21 · MarketingWS-B10.0.10.22 · MarketingWS-C10.0.10.23 · Sales
InfectedAlertConfiguredclick any hostto configure

Perimeter FW

fw-edge-01

Alert

Outbound Block Rules

C2 traffic to 185.207.x.x detected from WS-A. Block the bad host.

Block outbound traffic from:

Pick the host(s) to deny outbound at this firewall.

Capture enough detail for the post-incident report.

Tip: never block outbound for hosts you haven't confirmed as compromised — you'll lock out clean users.

Tasks

  • Quarantine the infected workstation (WS-A) and capture forensic evidence first.
  • Block WS-A's outbound traffic at the perimeter firewall + enable IDS.
  • Revoke WS-A's SMB access to the file server and snapshot /payroll.
  • Verify WS-B and WS-C — same VLAN risk for B, different VLAN for C.

0 settings configured

Liked this PBQ? There are 80+ more inside.

Sign up free to take full timed exams with mixed MCQs and all 6 PBQ types — across 10 CompTIA and Cisco certifications.