Cisco 300-220 Practice Test Questions and Exam Dumps Part11 Q201-220

View Full Cisco 300-220 Exam Dumps and Practice Test Dumps

 

Question 201.

Which endpoint artifact can expose changes to executable permissions?

  1. DNS query records
  2. User session duration
  3. File permission events
  4. Network latency

Correct Answer: 3

Explanation:

File permission events can reveal changes affecting who may execute, modify, or access files. Unexpected permission changes can be relevant during investigations involving privilege abuse, persistence, or unauthorized modification. Analysts should examine which file was affected, the previous and new permissions, the account responsible, and the time of the change. DNS queries, session duration, and network latency provide different types of information and do not directly establish executable permission changes. Permission telemetry becomes more valuable when correlated with process activity, account events, and file creation records. Analysts should also consider legitimate administrative changes and software installation activity before interpreting a permission modification as suspicious.

Question 202.

Why compare authentication behavior against historical account activity?

  1. To identify behavioral deviations
  2. To increase disk capacity
  3. To modify account passwords
  4. To remove login records

Correct Answer: 1

Explanation:

Historical authentication behavior provides a baseline for understanding how an account normally accesses systems. Comparing current activity with that baseline can reveal deviations involving unusual sources, timing, systems, or access patterns. Such deviations do not automatically indicate compromise because legitimate travel, remote access, administrative duties, and organizational changes can alter normal behavior. Disk capacity, password modification, and removal of login records are unrelated to behavioral comparison. Analysts should examine the account’s role, expected access locations, authentication methods, and related endpoint activity. Historical comparison is most useful when combined with contextual evidence rather than treated as proof based solely on an unusual login.

Question 203.

Which network evidence can expose an unexpected connection to a management interface?

  1. File size statistics
  2. Destination service details
  3. Screen-lock events
  4. Local font settings

Correct Answer: 2

Explanation:

Destination service details can reveal whether a host is unexpectedly connecting to a management interface or administrative service. Analysts can examine destination addresses, ports, protocols, and service characteristics to determine whether the communication fits the system’s expected role. An endpoint connecting to an administrative interface may be legitimate for administrators but suspicious when performed by an unrelated workstation or process. File sizes, screen-lock events, and font settings do not directly describe network services. Reviewing destination context alongside user identity, initiating process, asset role, and connection timing can help determine whether the observed communication represents normal administration or requires further investigation.

Question 204.

What is a useful indicator of abnormal process ancestry?

  1. Normal parent-child relationships
  2. Standard startup services
  3. Approved application launches
  4. Unexpected parent executable

Correct Answer: 4

Explanation:

An unexpected parent executable can indicate abnormal process ancestry when a child process is launched by a program that does not normally create it. Process ancestry is useful because many applications have predictable parent-child relationships during normal operation. A surprising relationship can provide an investigative lead, particularly when combined with unusual command-line arguments, user context, file access, or network activity. Normal startup services and approved application launches may represent expected behavior. Analysts should validate the anomaly against known software functionality and environmental baselines because legitimate applications can sometimes create unusual child processes during updates, diagnostics, or specialized workflows.

Question 205.

Which record can help identify unauthorized changes to local user accounts?

  1. Account-management events
  2. DNS cache entries
  3. Network packet size
  4. Display driver logs

Correct Answer: 1

Explanation:

Account-management events can record activities such as creating users, deleting accounts, modifying memberships, or changing account attributes. These events are valuable when investigating unauthorized privilege changes or persistence mechanisms. Analysts should examine the initiating account, affected account, timestamp, action performed, and whether the change was expected. DNS cache entries and packet sizes provide network-related information, while display driver logs concern endpoint hardware or graphics functionality. Account-management telemetry should be correlated with authentication records and administrative activity to determine whether a change was legitimate. Unexpected modifications to privileged or sensitive accounts deserve particular attention because they can alter access within the environment.

Question 206.

Why examine command-line arguments during process investigations?

  1. To measure monitor resolution
  2. To understand executed behavior
  3. To determine cable length
  4. To inspect printer toner

Correct Answer: 2

Explanation:

Command-line arguments provide important context about how a process was executed. Two executions of the same executable can have very different security implications depending on the supplied arguments. Analysts can use command-line information to identify unusual parameters, encoded content, suspicious paths, administrative actions, or unexpected commands. Monitor resolution, cable length, and printer toner have no meaningful relationship to process behavior. Command-line telemetry becomes more valuable when combined with the parent process, account, execution time, and destination network activity. Because legitimate administrators and applications may also use complex commands, analysts should evaluate the complete execution context rather than treating unusual syntax as automatically malicious.

Question 207.

Which observation may indicate unauthorized remote administration?

  1. Local wallpaper changes
  2. Routine file indexing
  3. Unexpected remote session activity
  4. Normal battery charging

Correct Answer: 3

Explanation:

Unexpected remote session activity may indicate unauthorized remote administration, particularly when the source account, originating host, timing, or accessed system differs from established administrative patterns. Remote administration can be completely legitimate, so analysts should investigate the surrounding context rather than treating every remote session as malicious. Wallpaper changes, file indexing, and battery charging do not directly indicate remote access. Useful evidence includes authentication records, remote-session telemetry, process execution, source addresses, destination systems, and account privileges. Correlating these sources can help determine whether the session was initiated by an authorized administrator, a support process, or potentially an unauthorized actor.

Question 208.

What helps reduce noise when hunting for rare process behavior?

  1. Ignoring asset context
  2. Removing process telemetry
  3. Expanding every search
  4. Applying environmental baselines

Correct Answer: 4

Explanation:

Environmental baselines help reduce noise by establishing what process behavior is normally observed across specific systems or user groups. A process that is rare globally may be completely normal on a specialized server. Conversely, behavior that is common on ordinary workstations may be unusual on a sensitive infrastructure host. Applying appropriate baselines allows analysts to focus on deviations that are meaningful for the particular environment. Ignoring asset context, removing telemetry, or expanding every search without filtering can increase investigative noise. Baselines should be periodically reviewed because legitimate software deployments, configuration changes, and business processes can alter normal process behavior over time.

Question 209.

Which evidence can connect a downloaded file to its initiating process?

  1. File and process correlation
  2. Display configuration records
  3. Printer inventory
  4. Keyboard settings

Correct Answer: 3

Explanation:

File and process correlation can connect a downloaded file with the process responsible for creating or retrieving it. This relationship helps analysts understand whether a browser, scripting engine, document application, or another executable initiated the file transfer. It can also provide useful context when investigating suspicious downloads or malware delivery. Display configuration, printer inventory, and keyboard settings do not directly establish the relationship between a downloaded file and its initiating process. Analysts should correlate timestamps, file paths, process identifiers, command-line arguments, network destinations, and user identity. This combined evidence can help reconstruct the sequence from network retrieval to local file creation and execution.

Question 210.

What should analysts inspect when a system suddenly contacts many new destinations?

  1. Screen resolution
  2. Process-to-network relationships
  3. Keyboard shortcuts
  4. Printer driver versions

Correct Answer: 1

Explanation:

Process-to-network relationships can help identify which local processes are responsible for contacting newly observed destinations. A sudden increase in destination diversity may result from legitimate software updates, cloud services, application changes, or potentially suspicious activity. Examining the initiating processes provides an important way to distinguish these possibilities. Screen resolution, keyboard shortcuts, and printer driver versions do not explain network destination behavior. Analysts should also consider destination ownership, ports, timing, connection frequency, and asset role. Reviewing historical behavior can reveal whether the destinations are genuinely new or simply uncommon observations that were not previously captured by existing monitoring.

Question 211.

Which artifact is useful for identifying recently modified startup behavior?

  1. Network throughput
  2. Service or autorun records
  3. Mouse sensitivity
  4. Display orientation

Correct Answer: 4

Explanation:

Service or autorun records can reveal mechanisms configured to execute automatically when a system starts or a user session begins. Changes to these mechanisms can be relevant when investigating persistence. Analysts should examine newly created entries, modified configurations, executable paths, associated accounts, and timestamps. Network throughput, mouse sensitivity, and display orientation do not directly expose startup execution mechanisms. Legitimate software installations and updates can also create or modify autorun entries, so analysts should correlate the change with software deployment records and process activity. Comparing current startup configuration with an established baseline can help identify unexpected modifications that warrant further examination.

Question 212.

Which network pattern may suggest automated scanning behavior?

  1. One stable application connection
  2. Repeated sequential destinations
  3. A single DNS lookup
  4. Normal gateway traffic

Correct Answer: 2

Explanation:

Repeated sequential connections to multiple destinations can indicate automated scanning behavior, particularly when the destinations follow a systematic pattern. An automated process may probe addresses, ports, or services to discover reachable systems. However, legitimate monitoring and management tools can generate similar patterns, so the activity requires contextual validation. A single DNS lookup or stable application connection generally provides less evidence of scanning. Analysts should examine connection frequency, destination ranges, ports, initiating process, account, and asset role. Correlating the pattern with known administrative tools and historical behavior can help distinguish authorized discovery activity from suspicious reconnaissance.

Question 213.

What can reveal whether a suspicious process accessed sensitive files?

  1. File-access telemetry
  2. Monitor refresh data
  3. Printer supply levels
  4. Browser appearance

Correct Answer: 1

Explanation:

File-access telemetry can reveal which files or directories were accessed by processes and accounts. This information can be valuable when investigating suspicious processes that may have interacted with sensitive information. Analysts can examine the accessing process, user identity, file path, operation type, and timestamp. Monitor refresh data, printer supplies, and browser appearance do not directly provide file-access evidence. Sensitive file access should be interpreted within the context of normal application behavior because legitimate applications may routinely access large numbers of files. Correlating file-access events with process execution and network transfers can provide additional evidence when investigating possible collection or unauthorized access.

Question 214.

Why map observed activity to a known attack technique?

  1. To change system hardware
  2. To reduce event timestamps
  3. To provide behavioral context
  4. To remove investigation scope

Correct Answer: 3

Explanation:

Mapping observed activity to a known attack technique provides behavioral context and helps analysts understand how individual events may relate to a broader adversary behavior. Technique mapping can also improve communication between security teams and support consistent investigation and detection development. Changing hardware, reducing timestamps, or removing investigation scope does not provide this benefit. A technique mapping should be based on observed evidence rather than assumptions. Analysts can use process activity, authentication behavior, network communication, or persistence artifacts to support the mapping. The resulting context can help determine whether additional related behaviors should be searched for across the environment.

Question 215.

Which evidence can help distinguish legitimate software updates from suspicious downloads?

  1. Screen brightness
  2. File ownership and signer information
  3. Keyboard layout
  4. Speaker volume

Correct Answer: 4

Explanation:

File ownership and signer information can provide useful context when distinguishing legitimate software updates from suspicious downloads. Trusted publishers, expected installation paths, appropriate ownership, and valid digital signatures may support the legitimacy of an update. These indicators are not absolute proof, because attackers can abuse trusted software or exploit compromised signing infrastructure. Screen brightness, keyboard layout, and speaker volume do not directly validate downloaded software. Analysts should also review the download source, initiating process, timestamp, network destination, and expected software-management mechanisms. Combining multiple independent observations provides stronger validation than relying on a single file property.

Question 216.

What is a useful response when a hunting query produces excessive benign results?

  1. Refine contextual filters
  2. Delete the query
  3. Disable endpoint logging
  4. Ignore the results

Correct Answer: 1

Explanation:

Refining contextual filters can reduce excessive benign results while preserving useful investigative coverage. Analysts can narrow searches by asset type, process relationship, account role, destination category, time window, or known administrative behavior. Simply deleting the query or disabling endpoint logging removes visibility without addressing the underlying problem. Ignoring the results also prevents the analyst from learning why the query is noisy. Query refinement should be tested against representative benign and suspicious examples to ensure that important activity is not accidentally excluded. Documenting the reason for each filter can make the hunting logic easier to maintain and review later.

Question 217.

Which event may expose modification of a privileged group membership?

  1. DNS registration
  2. Account-group change
  3. File compression
  4. Network interface reset

Correct Answer: 2

Explanation:

Account-group change events can reveal modifications to membership in privileged or security-sensitive groups. Such changes may grant additional permissions and therefore deserve investigation when they occur unexpectedly. Analysts should identify the initiating account, affected user, target group, timestamp, and authorization context. DNS registration, file compression, and network interface resets do not directly document group membership changes. Privileged group modifications can be legitimate during onboarding, role changes, or administrative maintenance, so the event should be compared with change-management records and expected administrative activity. Correlating the modification with subsequent authentication or endpoint behavior can provide additional investigative context.

Question 218.

Which network detail is useful for identifying unusual encrypted service usage?

  1. Destination port and protocol
  2. Desktop wallpaper
  3. File icon style
  4. Keyboard repeat rate

Correct Answer: 4

Explanation:

Destination port and protocol information can help analysts identify unusual service usage, including unexpected encrypted communications. While encryption may prevent inspection of application content, metadata such as destination, port, protocol, timing, and connection frequency can still provide useful investigative evidence. Desktop wallpaper, file icon style, and keyboard repeat rate are unrelated to network service identification. Analysts should compare the observed communication with the expected role of the initiating host and application. A nonstandard encrypted connection may be legitimate, so destination ownership, process identity, historical behavior, and organizational context should be evaluated before reaching a conclusion.

Question 219.

What strengthens confidence when multiple telemetry sources show the same event?

  1. Removing duplicate evidence
  2. Ignoring timestamps
  3. Cross-source correlation
  4. Narrowing all searches

Correct Answer: 3

Explanation:

Cross-source correlation strengthens confidence by showing that independent telemetry sources support the same observation. For example, endpoint process data, authentication records, and network telemetry may collectively establish that a particular account launched a process that communicated with a specific destination. Agreement between sources reduces reliance on a single potentially incomplete record. Removing duplicate evidence or ignoring timestamps can weaken the investigation, while narrowing every search may exclude useful corroborating information. Analysts should ensure that correlated events align logically in time and context. Strong correlation can help validate a hunting hypothesis and provide a more defensible basis for subsequent investigation or detection development.

Question 220.

Which practice helps preserve the reproducibility of a threat hunt?

  1. Deleting search criteria
  2. Documenting queries and assumptions
  3. Removing event timestamps
  4. Avoiding result validation

Correct Answer: 2

Explanation:

Documenting queries and assumptions helps another analyst understand how a threat hunt was conducted and reproduce the investigation. Useful documentation can include the hypothesis, data sources, search logic, time range, filters, assumptions, notable findings, and validation steps. Deleting search criteria or removing timestamps eliminates important investigative context. Avoiding result validation can make conclusions difficult to trust or reproduce. A documented hunting process also supports future refinement when new telemetry becomes available. Reproducibility is valuable because successful and unsuccessful hunts can both provide lessons for improving detection coverage, reducing false positives, and developing stronger investigative methods.