Cisco 300-220 Practice Test Questions and Exam Dumps Part6 Q101-120

View Full Cisco 300-220 Exam Dumps and Practice Test Dumps

 

Question 101.

Which activity can help detect unusual service account behavior?

  1. Monitor configuration changes
  2. Review account activity
  3. Inspect display adapters
  4. Measure disk temperature

Correct Answer: 2

Explanation:

Reviewing account activity can help identify unusual behavior involving service accounts. Hunters can examine authentication times, source systems, accessed resources, privilege usage, and command execution associated with these accounts. Service accounts often have predictable operational patterns, so unexpected interactive logins or activity from unfamiliar systems can warrant investigation. Monitor configuration changes and hardware measurements provide different types of information and may not directly explain account behavior. Establishing normal service-account usage makes it easier to recognize deviations and correlate suspicious authentication with endpoint or network activity.

Question 102.

What can DNS query frequency reveal during a hunt?

  1. CPU architecture
  2. Repeated resolution behavior
  3. File ownership
  4. Memory capacity

Correct Answer: 4

Explanation:

DNS query frequency can reveal repeated resolution behavior that may be unusual for a particular host or application. Regularly repeated queries to the same domain can sometimes indicate automated communication, while unusually high query volumes may warrant additional investigation. DNS frequency alone does not prove malicious activity because legitimate applications can also generate recurring requests. CPU architecture, file ownership, and memory capacity are unrelated to DNS query behavior. Hunters should correlate query frequency with destination reputation, timestamps, process information, and network connections to determine whether the observed pattern is consistent with expected activity.

Question 103.

Which endpoint evidence can expose newly created persistence mechanisms?

  1. Persistence-related artifacts
  2. Monitor brightness logs
  3. Keyboard layout files
  4. Printer alignment records

Correct Answer: 1

Explanation:

Persistence-related artifacts can reveal mechanisms that allow software or commands to execute automatically after a system event, startup, login, or scheduled condition. Depending on the operating system, these artifacts may include startup entries, scheduled tasks, services, or other autorun mechanisms. Hunters can compare newly created entries with known baseline configurations and investigate unusual paths, commands, or accounts. Monitor brightness, keyboard layout, and printer alignment information do not normally provide persistence visibility. Examining persistence artifacts is particularly useful when investigating malware that attempts to maintain access after an initial compromise.

Question 104.

Why can rare-event analysis support threat hunting?

  1. It removes all benign activity
  2. It guarantees malicious attribution
  3. It highlights unusual behavior
  4. It disables common processes

Correct Answer: 3

Explanation:

Rare-event analysis identifies activities that occur infrequently within an environment. Unusual events can be useful hunting signals because attackers may generate behaviors that differ from established operational patterns. For example, an uncommon administrative connection, rarely observed executable, or unusual authentication source may deserve closer examination. Rare does not automatically mean malicious, since legitimate administrative or business activities can also be uncommon. The value comes from combining rarity with context, asset importance, user behavior, timing, and other evidence. Rare-event analysis therefore helps hunters prioritize unusual activity for deeper investigation.

Question 105.

Which information helps associate network activity with an executing program?

  1. Process-network correlation
  2. Screen dimensions
  3. BIOS vendor name
  4. Keyboard polling rate

Correct Answer: 4

Explanation:

Process-network correlation connects network communications with the processes responsible for generating them. This can help hunters determine whether a suspicious executable established an external connection, contacted an unusual destination, or communicated at unexpected intervals. Such correlation can provide stronger evidence than reviewing network traffic or process activity separately. Screen dimensions, BIOS vendor information, and keyboard polling rates do not establish a relationship between programs and network connections. Combining endpoint process telemetry with network observations can therefore improve visibility into command-and-control activity, unauthorized communication, and other suspicious behaviors.

Question 106.

What is a useful purpose of threat-intelligence enrichment?

  1. Add contextual information
  2. Replace endpoint visibility
  3. Disable network collection
  4. Remove historical records

Correct Answer: 1

Explanation:

Threat-intelligence enrichment adds contextual information to observed indicators or events. This may include reputation information, known associations, infrastructure details, related techniques, or historical observations. Enrichment helps hunters determine whether an observed domain, address, file, or behavior warrants additional investigation. It does not replace endpoint visibility, disable network collection, or remove historical records. Intelligence should be treated as supporting evidence rather than automatic proof of malicious activity. Combining external intelligence with internal telemetry provides stronger investigative context and helps analysts evaluate indicators according to the environment in which they were observed.

Question 107.

Which pattern may suggest an account is being used from an unusual location?

  1. Stable hostname naming
  2. Consistent application versions
  3. Authentication from unexpected geography
  4. Normal backup completion

Correct Answer: 3

Explanation:

Authentication from an unexpected geographic location can be a useful signal when investigating potentially compromised credentials. Hunters can compare the source location with the user’s established access patterns, expected travel, corporate network ranges, and other authentication evidence. Geographic anomalies do not automatically prove account compromise because VPNs, proxies, cloud services, and legitimate travel can affect apparent locations. Stable hostnames, application versions, and successful backups do not directly indicate geographic authentication behavior. Combining location information with timestamps, device identity, authentication method, and account history can produce stronger investigative context.

Question 108.

Which technique helps discover activity not matching established baselines?

  1. Anomaly detection
  2. Cable certification
  3. Asset disposal
  4. Screen replacement

Correct Answer: 1

Explanation:

Anomaly detection identifies activity that differs significantly from established patterns or expected behavior. In threat hunting, anomalies can involve authentication frequency, process execution, network communication, resource usage, or other observable characteristics. An anomaly is not automatically malicious because legitimate operational changes can also create unusual activity. Cable certification, asset disposal, and screen replacement address unrelated operational tasks. Effective anomaly detection relies on appropriate baselines and contextual information so that analysts can distinguish meaningful deviations from harmless variation. Hunters often use anomaly findings as starting points for deeper investigation.

Question 109.

What can authentication failure patterns help identify?

  1. Display configuration changes
  2. Possible credential attacks
  3. Hardware inventory gaps
  4. Application licensing issues

Correct Answer: 4

Explanation:

Authentication failure patterns can provide evidence of possible credential attacks. Hunters may examine repeated failures, affected accounts, source systems, timing, and authentication methods to identify patterns such as password guessing or credential spraying. A single failed login is usually insufficient to establish malicious activity, so the surrounding pattern is important. Display configuration, hardware inventory, and application licensing do not normally explain authentication failures. Correlating authentication failures with successful logins and network-source information can help determine whether an observed pattern represents normal user behavior or potentially suspicious account activity.

Question 110.

Which artifact can help determine when a process started?

  1. Process creation timestamp
  2. Monitor serial number
  3. Network cable type
  4. Printer queue size

Correct Answer: 2

Explanation:

A process creation timestamp records when a process began execution and can be valuable during timeline reconstruction. Hunters can compare process start times with authentication events, file activity, network connections, and other telemetry to understand the sequence of events. This information can help identify whether a suspicious process appeared before or after another relevant activity. Monitor serial numbers, network cable types, and printer queue sizes do not provide process execution timing. Accurate timestamps and synchronized system clocks are important when building reliable timelines across multiple endpoints and security data sources.

Question 111.

What does asset criticality add to hunting analysis?

  1. Context for prioritization
  2. Encryption of telemetry
  3. Automatic malware removal
  4. Password generation

Correct Answer: 1

Explanation:

Asset criticality provides context that helps hunters prioritize findings according to the importance of affected systems. Suspicious behavior involving a critical server, identity system, or sensitive application may require different attention than similar activity on a low-impact test machine. Criticality does not encrypt telemetry, remove malware automatically, or generate passwords. Combining asset importance with behavioral evidence can help security teams determine which findings deserve immediate investigation. Asset context should be maintained accurately because outdated classifications can lead to inappropriate prioritization and may cause significant activity to receive insufficient attention.

Question 112.

Which method can identify previously unseen executable behavior?

  1. Reviewing wallpaper files
  2. Behavioral analysis
  3. Checking monitor cables
  4. Inspecting printer drivers

Correct Answer: 4

Explanation:

Behavioral analysis can identify suspicious executable activity even when the specific file or hash has not been previously observed. Instead of relying exclusively on known indicators, behavioral analysis examines characteristics such as process relationships, file operations, network connections, persistence attempts, and command execution. This approach can therefore help uncover previously unseen or modified malware. Wallpaper files, monitor cables, and printer drivers do not normally provide meaningful visibility into executable behavior. Behavioral analysis is especially useful when attackers alter filenames or binaries to evade simple signature-based detection.

Question 113.

Why should hunters compare suspicious activity with historical behavior?

  1. To establish behavioral context
  2. To remove all old logs
  3. To change account passwords automatically
  4. To increase disk capacity

Correct Answer: 3

Explanation:

Historical behavior provides context for determining whether an observed event represents a meaningful deviation from normal activity. Comparing current behavior with previous patterns can reveal changes in user access, process execution, network destinations, or system activity. Historical comparison does not automatically remove logs, change passwords, or increase disk capacity. The goal is to understand whether an observed event is consistent with established behavior or represents a significant change. This contextual approach can reduce false positives and help hunters focus investigative attention on deviations that warrant further examination.

Question 114.

Which network detail is useful when investigating suspicious connections?

  1. Destination port
  2. Keyboard type
  3. Screen orientation
  4. Battery percentage

Correct Answer: 1

Explanation:

The destination port is an important network detail because it identifies the service endpoint targeted by a connection. Hunters can examine destination ports alongside source and destination addresses, protocols, timestamps, and process information to determine whether communication is expected. Unusual ports or unexpected services may provide useful investigative clues, although port numbers alone do not prove malicious activity. Keyboard type, screen orientation, and battery percentage are generally unrelated to network communication analysis. Reviewing port information as part of broader network telemetry can help identify suspicious services and communication patterns.

Question 115.

What can command-line obfuscation make more difficult?

  1. Hardware replacement
  2. Behavioral baselining
  3. Human-readable analysis
  4. Network segmentation

Correct Answer: 4

Explanation:

Command-line obfuscation can make human-readable analysis more difficult by disguising the actual commands, arguments, or execution intent. Attackers may use encoded strings, unusual syntax, variable manipulation, or other techniques to make commands harder to interpret. Hunters can address this by examining decoded content, process ancestry, execution context, and related telemetry. Hardware replacement, behavioral baselining, and network segmentation are separate security or operational concepts. Obfuscation does not necessarily prevent detection, but it can increase the analytical effort required to understand what a process actually attempted to execute.

Question 116.

Which evidence can support identifying a compromised host?

  1. Unexpected malicious behavior
  2. Standard system uptime
  3. Normal wallpaper settings
  4. Approved software inventory

Correct Answer: 2

Explanation:

Unexpected malicious behavior can provide evidence that a host may be compromised. Relevant examples can include suspicious process execution, unauthorized persistence, unusual authentication activity, unexpected network connections, or known malicious artifacts. Normal system uptime, standard wallpaper settings, and an approved software inventory do not by themselves demonstrate compromise. Hunters should combine multiple observations and validate suspicious findings before concluding that a host is affected. A strong investigation considers the behavior, timing, affected account, network relationships, and available intelligence to determine whether the evidence supports further response.

Question 117.

Which process relationship may warrant additional investigation?

  1. Browser launching its normal helper
  2. System service starting routinely
  3. Document reader launching a shell
  4. Backup agent starting on schedule

Correct Answer: 3

Explanation:

A document reader launching a command shell can represent an unusual process relationship and may warrant additional investigation. Certain attack techniques abuse applications to launch scripting engines or command interpreters after a user opens a crafted document. The relationship is not automatically malicious, but it can be a valuable hunting signal when combined with unusual command-line parameters, downloaded files, or network activity. Routine browser helpers, system services, and scheduled backup agents may represent expected behavior. Process ancestry helps hunters distinguish ordinary execution chains from relationships that require closer analysis.

Question 118.

What can network timing patterns reveal?

  1. Screen calibration status
  2. Periodic communications
  3. CPU manufacturer
  4. File extension preferences

Correct Answer: 1

Explanation:

Network timing patterns can reveal periodic communications between systems. Regular intervals between connections may indicate automated applications, scheduled services, monitoring systems, or potentially command-and-control beaconing. Timing patterns should therefore be evaluated with destination information, process context, connection volume, and expected application behavior. Screen calibration, CPU manufacturer, and file-extension preferences do not provide meaningful network timing information. Periodic communication is a useful hunting signal, but it is not independently conclusive because many legitimate applications communicate according to predictable schedules.

Question 119.

Which action improves the quality of a hunting hypothesis?

  1. Making it broader and untestable
  2. Removing all contextual assumptions
  3. Defining observable evidence
  4. Ignoring available telemetry

Correct Answer: 4

Explanation:

Defining observable evidence makes a hunting hypothesis more precise and testable. A useful hypothesis should describe a specific behavior or condition that can be evaluated using available telemetry. For example, a hunter might hypothesize that a particular technique produces an identifiable process or network pattern. Broad, untestable assumptions make investigations difficult to evaluate, while ignoring telemetry removes the evidence needed for validation. Clearly defining expected observations allows hunters to build targeted queries, interpret results consistently, and refine the hypothesis when the collected evidence does not support the initial assumption.

Question 120.

What should hunters do after validating a new malicious pattern?

  1. Preserve the finding and improve detection
  2. Delete supporting telemetry
  3. Ignore similar future activity
  4. Disable security monitoring

Correct Answer: 2

Explanation:

After validating a new malicious pattern, hunters should preserve the evidence and consider how the discovery can improve defensive monitoring. The validated behavior may support a new detection rule, updated hunting query, analytic, playbook, or intelligence record. Preserving the finding also allows other analysts to understand and reproduce the investigation. Deleting telemetry, ignoring future activity, or disabling monitoring would reduce defensive visibility. Operationalizing validated hunting discoveries helps organizations move from one-time investigation toward repeatable monitoring and improves their ability to identify similar activity in future investigations.