View Full Cisco 300-220 Exam Dumps and Practice Test Dumps
Question 121.
Which telemetry can expose unusual remote administration activity?
- Remote session logs
- Display brightness records
- Battery charging cycles
- Audio device settings
Correct Answer: 1
Explanation:
Remote session logs can provide valuable evidence when investigating unusual administrative access. They may identify the account used, source system, destination host, connection time, authentication method, and session details. Hunters can compare these observations with expected administrative patterns to identify access that appears unusual. Display brightness, battery charging, and audio settings do not normally provide visibility into remote administration. Remote access activity should also be correlated with process execution and network telemetry because legitimate administrators may use the same tools and protocols that attackers abuse after obtaining valid credentials.
Question 122.
What can user-behavior profiling help identify?
- Hardware failures
- Deviations from normal user activity
- Printer configuration errors
- Display driver problems
Correct Answer: 2
Explanation:
User-behavior profiling establishes patterns associated with normal account activity and can help identify significant deviations. Relevant characteristics may include typical login times, accessed systems, authentication locations, applications used, and resource-access patterns. A sudden change can provide a useful signal for investigation, although legitimate travel, role changes, or operational requirements can also cause behavioral differences. Hardware failures, printer configuration errors, and display driver problems are unrelated to user-behavior profiling. Hunters should combine behavioral deviations with authentication, endpoint, and network evidence before determining whether an activity is suspicious.
Question 123.
Which artifact can reveal modifications to startup configuration?
- DNS records
- Network routes
- Autorun entries
- Authentication tokens
Correct Answer: 3
Explanation:
Autorun entries can reveal programs configured to execute automatically during system startup, login, or other triggering events. Attackers may modify these locations to establish persistence after gaining access to a host. Hunters can inspect newly created or modified entries, associated executable paths, account context, and timestamps to determine whether the configuration is expected. DNS records describe name resolution, network routes describe traffic paths, and authentication tokens relate to identity and authorization. Autorun analysis is therefore useful when investigating persistence techniques involving startup or automatic application execution.
Question 124.
Why is time synchronization important for threat hunting?
- It improves display quality
- It increases storage capacity
- It changes encryption settings
- It supports accurate event correlation
Correct Answer: 4
Explanation:
Time synchronization helps ensure that timestamps from different systems can be accurately compared. Threat hunters frequently reconstruct sequences involving authentication, process creation, file access, and network communication. If system clocks differ significantly, events may appear in the wrong order and lead to incorrect conclusions. Time synchronization does not improve display quality, increase storage capacity, or change encryption settings. Consistent timestamps allow analysts to correlate events across endpoints, servers, network devices, and security platforms, making timelines more reliable and improving the accuracy of investigative conclusions.
Question 125.
Which signal may indicate unusual use of administrative privileges?
- Unexpected elevated process
- Normal desktop wallpaper
- Standard keyboard input
- Routine screen locking
Correct Answer: 1
Explanation:
An unexpected elevated process can indicate unusual use of administrative privileges and may warrant investigation. Hunters can examine which account launched the process, its parent process, command-line arguments, execution path, and associated activity. Legitimate administrative tools may also generate elevated processes, so context is essential before determining whether the behavior is suspicious. Desktop wallpaper, keyboard input, and screen-locking activity generally provide little information about privilege use. Combining privilege-related process evidence with authentication and asset information can help determine whether elevated activity matches expected administrative operations.
Question 126.
What does command-line frequency analysis help identify?
- Monitor failures
- Repeated execution patterns
- Disk partition types
- Printer status changes
Correct Answer: 2
Explanation:
Command-line frequency analysis examines how often particular commands or command patterns are executed. Repeated execution can reveal automated tasks, recurring administrative activity, scripts, or potentially malicious behavior. Hunters can compare frequency across users, systems, and time periods to identify unusual concentrations or deviations from established patterns. Monitor failures, disk partition types, and printer status changes do not relate directly to command execution frequency. Frequency analysis becomes more useful when combined with process ancestry, user identity, timestamps, and command parameters, allowing analysts to distinguish normal automation from suspicious repetition.
Question 127.
Which observation may indicate unauthorized software execution?
- Approved application launch
- Normal system update
- Unrecognized executable activity
- Scheduled backup process
Correct Answer: 3
Explanation:
Unrecognized executable activity can indicate potentially unauthorized software execution and should be investigated in context. Hunters can examine the executable’s location, hash, signer, parent process, user account, execution time, and network behavior. An unfamiliar executable is not automatically malicious because newly deployed or specialized business software may not yet be included in established inventories. Approved applications, system updates, and scheduled backup processes commonly represent legitimate activity. Combining executable observations with software inventories and endpoint telemetry can help determine whether the observed program is expected or requires further investigation.
Question 128.
Which data can help identify abnormal outbound traffic volume?
- Local user profiles
- System boot records
- Application icons
- Network flow statistics
Correct Answer: 4
Explanation:
Network flow statistics can reveal unusual outbound traffic volume by showing communication quantities, destinations, timing, and connection characteristics. Hunters can compare current traffic against historical patterns or expected behavior for specific systems and applications. An unexpected increase in outbound traffic may warrant investigation for possible data transfer, software updates, backups, or other activity. Local user profiles, boot records, and application icons do not provide comparable network-volume visibility. Traffic volume should always be interpreted with business context because legitimate operations can also produce large or unusual outbound transfers.
Question 129.
What can a process hash comparison help establish?
- Whether binaries match known samples
- Whether a port is reachable
- Whether a user is online
- Whether DNS is configured
Correct Answer: 1
Explanation:
Process or executable hash comparison can help determine whether a collected binary matches another file with the same cryptographic hash. Hunters may compare hashes against known malicious samples, trusted software, or previously observed files. A matching hash can provide useful evidence, although it should be interpreted with other information such as file location, signer, execution context, and source. Hash comparison does not determine whether a network port is reachable, whether a user is online, or whether DNS is configured. It is primarily useful for identifying identical file content.
Question 130.
Which behavior can indicate possible discovery activity?
- Routine backup completion
- Host and service enumeration
- Normal screen locking
- Approved software installation
Correct Answer: 4
Explanation:
Host and service enumeration can indicate discovery activity because attackers may gather information about available systems, services, or network resources after obtaining access. Hunters can examine commands, network connections, process activity, and timing associated with enumeration behavior. Legitimate administrators and security tools can also perform similar activities, so context is important. Routine backups, screen locking, and approved software installation generally do not represent discovery by themselves. Correlating enumeration activity with account identity, source host, and subsequent actions can help determine whether the behavior is consistent with expected administrative operations.
Question 131.
What does a network baseline primarily describe?
- Expected communication patterns
- User password complexity
- Hardware replacement schedules
- Application licensing terms
Correct Answer: 3
Explanation:
A network baseline describes expected communication patterns within an environment. It may include typical traffic volumes, common destinations, frequently used protocols, normal connection intervals, and expected relationships between systems. Establishing this baseline allows hunters to identify deviations that may deserve further investigation. Password complexity, hardware replacement schedules, and application licensing terms address different operational areas. A network baseline should reflect legitimate business activity and be updated when infrastructure or applications change. Without an accurate baseline, analysts may generate excessive false positives or overlook meaningful changes in communication behavior.
Question 132.
Which evidence can help identify suspicious file creation?
- Monitor resolution
- File creation events
- Keyboard layout
- Power settings
Correct Answer: 2
Explanation:
File creation events can show when files were created, where they appeared, and sometimes which process or account created them. Hunters can use this information to investigate unexpected executables, scripts, configuration files, or temporary artifacts. Correlating file creation with process execution and network activity can reveal how a file entered the system and whether it was subsequently executed. Monitor resolution, keyboard layout, and power settings do not provide equivalent file-creation visibility. File events become particularly useful when investigating malware delivery, staging activity, or unauthorized software deployment.
Question 133.
Which activity may indicate attempts to enumerate user accounts?
- Listing account information
- Changing desktop themes
- Updating printer firmware
- Adjusting screen scaling
Correct Answer: 4
Explanation:
Listing account information can indicate account-discovery activity because attackers may enumerate available users before attempting further actions. Hunters can examine command execution, identity-related queries, process ancestry, and the account performing the enumeration. Similar activity can also be performed legitimately by administrators and security tools, so the context and frequency are important. Desktop themes, printer firmware, and screen scaling do not normally indicate account enumeration. When account discovery occurs alongside other reconnaissance behavior, it can provide useful evidence about the sequence of activity occurring on a potentially compromised host.
Question 134.
What is the value of correlating identity and endpoint telemetry?
- Measuring screen performance
- Connecting users to host activity
- Tracking printer supplies
- Calculating storage capacity
Correct Answer: 1
Explanation:
Correlating identity and endpoint telemetry helps connect a specific user or account with activity observed on a host. This can provide important context for process execution, file access, authentication, and network communication. For example, investigators can determine which account was active when a suspicious process started and whether the activity matches the user’s normal behavior. Screen performance, printer supplies, and storage capacity are unrelated objectives. Identity-to-endpoint correlation is particularly valuable when investigating compromised credentials because it helps connect account activity with the systems and processes involved.
Question 135.
Which condition can make an authentication event more suspicious?
- Known corporate source
- Expected business hours
- Familiar managed device
- Unusual source and timing
Correct Answer: 2
Explanation:
An authentication event occurring from an unusual source at an unexpected time can provide a useful signal for investigation. Hunters can compare the event with historical account behavior, known corporate networks, device identity, geographic information, and business schedules. Such anomalies are not automatically malicious because legitimate travel, remote access, or emergency administration can produce unusual authentication patterns. Known corporate sources, expected business hours, and familiar managed devices may instead align with established behavior. Authentication anomalies become more meaningful when multiple independent indicators point toward the same suspicious activity.
Question 136.
Which technique can uncover malicious activity without relying on known signatures?
- Signature-only matching
- Behavioral hunting
- Static inventory review
- Warranty validation
Correct Answer: 3
Explanation:
Behavioral hunting can identify suspicious activity based on what a program or user does rather than requiring a previously known signature. Hunters may examine process relationships, persistence attempts, network communication, credential access, or other behaviors associated with attack techniques. This approach can help uncover modified or previously unseen malware that does not match known hashes or signatures. Static inventory review and warranty validation serve different purposes, while signature-only matching depends on previously identified indicators. Behavioral analysis therefore provides an important complementary approach for detecting novel or altered malicious activity.
Question 137.
What can an unusually long process command line suggest?
- Potentially complex execution
- Guaranteed malware infection
- Hardware incompatibility
- Network cable failure
Correct Answer: 4
Explanation:
An unusually long process command line can suggest complex execution and may warrant further investigation. Long commands can occur legitimately in automation, deployment, scripting, or administrative tools, but attackers may also use extensive parameters, encoded content, or chained commands. The length alone does not prove malware infection. Hardware incompatibility and network cable failures are unrelated to command-line length. Hunters should inspect the command contents, parent process, user, execution path, and associated network activity to determine whether the command represents legitimate automation or potentially suspicious behavior.
Question 138.
Which network artifact can reveal repeated connections to the same destination?
- Asset tags
- Flow records
- BIOS settings
- User profile pictures
Correct Answer: 2
Explanation:
Network flow records can reveal repeated connections between specific sources and destinations. They commonly provide source and destination addresses, ports, protocols, timestamps, and traffic volumes. Hunters can analyze these fields to identify recurring communication patterns that may represent normal application behavior or potentially automated command-and-control traffic. Asset tags, BIOS settings, and profile pictures do not provide network communication visibility. Repeated connections should be evaluated alongside timing intervals, destination reputation, process information, and application context before determining whether the observed behavior requires investigation.
Question 139.
Why should hunting queries be tested against known benign activity?
- To increase false positives
- To eliminate all telemetry
- To evaluate detection quality
- To disable alerting
Correct Answer: 3
Explanation:
Testing hunting queries against known benign activity helps determine whether the logic generates excessive false positives. A useful query should identify the intended behavior while avoiding large volumes of legitimate activity. Analysts can use representative benign examples to refine conditions, thresholds, exclusions, and contextual filters. Increasing false positives, eliminating telemetry, or disabling alerting would undermine the purpose of query validation. Testing against both suspicious and benign examples improves confidence that the resulting hunting logic is practical and can potentially be converted into reliable detection content.
Question 140.
What should a hunter record when closing an investigation?
- Only the analyst’s name
- Unrelated system settings
- Temporary browser data
- Findings and supporting evidence
Correct Answer: 4
Explanation:
A completed hunting investigation should document the findings and the evidence supporting them. Useful documentation can include the original hypothesis, data sources, queries, relevant observations, affected assets, validation steps, and final conclusions. Recording only an analyst’s name or unrelated system settings provides little value for future investigations. Temporary browser data is also not an appropriate substitute for structured investigative evidence. Clear documentation allows other analysts to understand what was investigated, reproduce important steps, and use successful findings to improve detections, playbooks, and future threat-hunting activities.