Cisco 300-220 Practice Test Questions and Exam Dumps Part16 Q301-320

View Full Cisco 300-220 Exam Dumps and Practice Test Dumps

 

Question 301.

Which evidence helps identify abnormal data transfer destinations?

  1. Local group membership
  2. File creation time
  3. External destination context
  4. Screen saver settings

Correct Answer: 3

Explanation:

External destination context helps determine whether data transfers are occurring toward expected or suspicious systems. A hunter can examine destination ownership, reputation, geographic context, domain relationships, previous organizational communications, and known infrastructure associations. This information becomes particularly useful when a host sends an unusual amount of data to an unfamiliar external destination. File creation times and group membership may provide supporting context but do not directly characterize the remote destination. Screen saver settings are unrelated. Destination context should be combined with transfer volume, initiating process, account information, and timing to determine whether the observed communication warrants deeper investigation.

Question 302.

What is a useful indicator of unusual local privilege activity?

  1. Unexpected privilege transition
  2. Normal DNS resolution
  3. Routine software update
  4. Standard logoff event

Correct Answer: 1

Explanation:

An unexpected privilege transition can indicate suspicious local activity, particularly when a process or user suddenly operates with elevated permissions outside normal administrative workflows. Hunters can investigate which account initiated the transition, the originating process, the target process, timing, and associated authentication events. Legitimate software updates can also create elevated processes, so the surrounding context is important before determining whether the behavior is suspicious. Normal DNS resolution and standard logoff events do not directly demonstrate privilege changes. Examining privilege transitions alongside process lineage and identity telemetry can help establish whether elevation was expected or potentially associated with unauthorized activity.

Question 303.

Which analysis can reveal rare software execution within a department?

  1. Firewall rule inspection
  2. Peer-based execution frequency
  3. Password complexity review
  4. DHCP scope modification

Correct Answer: 2

Explanation:

Peer-based execution frequency can reveal software that executes rarely within a defined group of comparable systems. A hunter can establish how often an executable appears across endpoints performing similar business functions and then investigate unusual outliers. Rare execution does not automatically indicate malicious behavior because specialized administrative or business applications may legitimately run on only a small number of systems. Additional context such as file reputation, signer information, execution path, and user identity can improve the analysis. Firewall rules, password policies, and DHCP configuration do not directly measure application execution frequency across comparable endpoints.

Question 304.

Why investigate the first-seen time of an unfamiliar artifact?

  1. To calculate CPU temperature
  2. To establish introduction timing
  3. To measure network bandwidth
  4. To determine monitor settings

Correct Answer: 2

Explanation:

The first-seen time helps establish when an unfamiliar artifact was initially observed within the monitored environment. This temporal information can be correlated with software deployments, user activity, security alerts, authentication events, and network communications. If the artifact appeared shortly before suspicious behavior began, its introduction time may provide an important investigative lead. First-seen timing does not prove maliciousness because legitimate software can also be newly introduced. CPU temperature, bandwidth measurement, and monitor settings address unrelated areas. Establishing when an artifact first appeared allows hunters to build a more accurate timeline and identify potentially related events surrounding its introduction.

Question 305.

Which behavior can indicate unauthorized security-control modification?

  1. Reading a public webpage
  2. Updating a calendar
  3. Changing endpoint protection settings
  4. Opening a standard document

Correct Answer: 3

Explanation:

Changes to endpoint protection settings can indicate attempts to weaken or bypass security controls, particularly when they occur unexpectedly or outside approved administrative procedures. Hunters can examine which account made the modification, what configuration changed, when the change occurred, and which process performed it. Legitimate maintenance may also modify security settings, so the activity should be compared against authorized change records and administrative baselines. Opening documents, reading webpages, and updating calendars are common user activities and do not directly indicate security-control tampering. Configuration-change telemetry can therefore provide valuable evidence when investigating attempts to reduce endpoint protection visibility.

Question 306.

What can a host inventory comparison reveal during threat hunting?

  1. Missing display drivers
  2. Unusual software presence
  3. Keyboard preferences
  4. Wallpaper differences

Correct Answer: 2

Explanation:

Comparing host inventories can reveal software or components that appear unexpectedly on one endpoint or a small subset of systems. Such differences may identify unauthorized tools, newly installed applications, unusual services, or software that does not match the approved environment. Inventory differences should be interpreted according to the endpoint’s business role because specialized systems can legitimately contain unique software. Display drivers, keyboard preferences, and wallpaper differences generally provide little security value in this context. Host inventory comparison becomes more useful when combined with installation timestamps, executable paths, digital signatures, and process activity to determine whether an unusual software presence deserves investigation.

Question 307.

Which event can expose unauthorized changes to account privileges?

  1. Account authorization records
  2. Browser cache entries
  3. DNS response timing
  4. Printer connection logs

Correct Answer: 1

Explanation:

Account authorization records can reveal changes affecting permissions, roles, or privileges assigned to users and groups. These records can help hunters identify unexpected privilege additions, membership changes, or modifications performed outside approved administrative procedures. Investigators can correlate the change with the responsible account, source system, timestamp, and subsequent activity. Browser cache data and DNS timing do not directly document authorization changes, while printer connection logs generally provide unrelated endpoint activity. Reviewing authorization records is therefore useful when investigating possible privilege escalation or unauthorized administrative access. Additional identity and endpoint telemetry can help determine whether the changed privilege was subsequently used.

Question 308.

What does comparing authentication sources help identify?

  1. Storage fragmentation
  2. Application licensing
  3. Endpoint screen settings
  4. Unusual access origins

Correct Answer: 4

Explanation:

Comparing authentication sources helps identify unusual origins for account activity. A hunter can examine source hosts, addresses, geographic context, access methods, and normal login patterns to determine whether a particular authentication event differs from established behavior. An unexpected source does not automatically mean an account was compromised because users may legitimately access systems remotely or from changing locations. However, unusual source information becomes more significant when combined with unfamiliar devices, abnormal timing, privilege use, or concurrent endpoint activity. Storage fragmentation, software licensing, and screen settings do not provide meaningful authentication-origin context. Source comparison therefore supports identity-focused behavioral analysis.

Question 309.

Which telemetry can expose unusual application-to-application communication?

  1. Process relationship data
  2. Disk cleanup history
  3. Printer queue status
  4. Display configuration

Correct Answer: 1

Explanation:

Process relationship data can expose unusual communication or interaction between applications by showing process lineage and related execution behavior. Hunters can identify applications that launch unexpected child processes, interact with uncommon components, or establish relationships that differ from the normal endpoint baseline. Such relationships can provide leads for investigating scripting abuse, application exploitation, or unauthorized execution chains. Disk cleanup history, printer queues, and display configuration generally do not reveal process relationships. Process telemetry becomes particularly valuable when correlated with command-line parameters, user identity, file paths, and network activity, allowing investigators to understand the broader context around an unusual application interaction.

Question 310.

Which characteristic can distinguish automated activity from normal user actions?

  1. Repeated uniform timing
  2. Random wallpaper changes
  3. Variable screen resolution
  4. Occasional document printing

Correct Answer: 1

Explanation:

Repeated uniform timing can be a useful characteristic when distinguishing automated activity from ordinary human-driven actions. Scripts, scheduled jobs, and malicious automated processes may perform actions at highly consistent intervals. Hunters can analyze event timestamps and compare intervals across multiple occurrences to identify regular patterns. However, timing alone is not sufficient to establish malicious automation because legitimate monitoring systems, scheduled maintenance, and applications can behave similarly. Other characteristics such as initiating process, destination, account context, and activity type should be considered. Wallpaper changes, screen resolution, and occasional printing generally do not provide comparable evidence of automated execution.

Question 311.

What should be compared when assessing whether a new service is legitimate?

  1. Approved service inventory
  2. Mouse sensitivity settings
  3. Browser font selection
  4. Desktop shortcut order

Correct Answer: 1

Explanation:

An approved service inventory provides an important baseline for determining whether a newly observed service is expected. Hunters can compare the service name, executable path, configuration, startup behavior, and owning application against approved organizational records. A service that differs from the established baseline may warrant additional examination, especially if it appeared without a documented deployment or change request. A difference alone does not establish malicious activity because legitimate software updates can introduce new services. Mouse settings, browser fonts, and shortcut ordering do not provide meaningful service-validation context. Combining inventory comparison with installation and process telemetry can improve confidence in the assessment.

Question 312.

Which network pattern may indicate unusual internal discovery?

  1. One routine web request
  2. Broad host probing
  3. A successful backup
  4. A scheduled patch

Correct Answer: 2

Explanation:

Broad host probing can indicate internal discovery because a system may attempt connections to numerous hosts while identifying available systems or services. Hunters can examine destination counts, targeted ports, connection timing, source process, and whether the activity differs from the endpoint’s normal communication profile. Administrative tools and security scanners can legitimately generate similar patterns, so the activity must be evaluated against approved operational processes. A routine web request, successful backup, or scheduled patch does not by itself indicate broad internal discovery. Network flow and connection telemetry can provide the necessary evidence to identify and investigate unusual probing behavior.

Question 313.

Which evidence helps determine whether a suspicious command was interactive?

  1. File compression level
  2. DNS record age
  3. Session context
  4. Disk partition size

Correct Answer: 3

Explanation:

Session context can help determine whether a suspicious command occurred during an interactive user session or through an automated mechanism. Relevant information may include the account, session type, originating endpoint, logon event, remote-access method, and timing relationship between authentication and command execution. This context can distinguish expected administrative activity from commands launched through scheduled tasks, services, or potentially compromised sessions. File compression, DNS record age, and disk partition size do not establish command interactivity. Session information should be correlated with process execution and identity telemetry to develop a more complete understanding of how the command was initiated.

Question 314.

Which artifact can show when a system component was installed?

  1. Installation records
  2. DNS cache entries
  3. Network packet size
  4. Screen-lock events

Correct Answer: 1

Explanation:

Installation records can provide timestamps and other details associated with the introduction of software or system components. Hunters can use this information to establish when an unfamiliar application, service, driver, or package appeared on an endpoint. Installation timing can then be compared with suspicious process execution, configuration changes, authentication events, or network activity. DNS cache entries and packet size describe network behavior, while screen-lock events describe user activity. Installation records therefore provide valuable temporal evidence when investigating newly introduced software. The evidence should be checked against approved deployment records because legitimate software updates can also create newly observed components.

Question 315.

Why correlate file and network timestamps?

  1. To establish possible activity sequence
  2. To change file permissions
  3. To increase storage capacity
  4. To modify DNS configuration

Correct Answer: 1

Explanation:

Correlating file and network timestamps can help establish a possible sequence of events. For example, a newly created file followed shortly by an outbound connection may provide a useful investigative lead, particularly when the same process is associated with both events. Timestamp relationships do not prove causation, because system clocks, delayed processing, and unrelated activity can affect observed ordering. Nevertheless, temporal correlation helps hunters construct an evidence-based timeline. File permissions, storage capacity, and DNS configuration are separate concerns. Combining timestamps from multiple telemetry sources can reveal relationships that are difficult to recognize when each data source is examined independently.

Question 316.

Which observation can strengthen a hypothesis about unauthorized software deployment?

  1. Matching approved inventory
  2. Documented maintenance window
  3. Unapproved installation event
  4. Normal application startup

Correct Answer: 3

Explanation:

An unapproved installation event can strengthen a hypothesis that software was deployed without authorization. The hunter should examine the installer, account, endpoint, installation timestamp, source location, and resulting files or services. Evidence becomes stronger when the installation cannot be matched to approved change records or expected software-management activity. Matching approved inventory and documented maintenance windows instead provide explanations for legitimate changes, while normal application startup does not establish how software was introduced. Installation telemetry should be correlated with endpoint configuration, process execution, and identity records to determine whether the observed software deployment was expected or potentially unauthorized.

Question 317.

What is useful for identifying abnormal command execution frequency?

  1. Process execution baseline
  2. Wallpaper history
  3. Printer toner levels
  4. Monitor power state

Correct Answer: 1

Explanation:

A process execution baseline helps identify commands or applications that execute more frequently than expected. Hunters can establish normal execution patterns for particular users, hosts, applications, or business roles and then investigate significant deviations. An unusually high execution frequency may result from legitimate automation, software updates, or administrative activity, so frequency should be evaluated alongside process identity, command-line content, account context, and timing. Wallpaper history, printer toner levels, and monitor power state are unrelated to command execution frequency. Establishing a reliable baseline enables the hunter to distinguish unusual execution behavior from normal recurring activity.

Question 318.

Which information helps validate an external indicator before escalation?

  1. Monitor manufacturer
  2. Threat-intelligence context
  3. Keyboard shortcut list
  4. Desktop icon order

Correct Answer: 2

Explanation:

Threat-intelligence context can help validate an external indicator before escalation. Hunters can examine the indicator’s reputation, associated infrastructure, historical observations, confidence level, related domains or addresses, and known campaign or malware relationships. External intelligence should not be treated as definitive proof because indicators can become outdated, be shared by legitimate services, or be misclassified. Local telemetry should therefore be used to confirm whether the indicator actually appears in suspicious activity. Monitor manufacturers, keyboard shortcuts, and desktop icon ordering do not provide meaningful validation context. Combining intelligence with local evidence provides a stronger basis for deciding whether an indicator requires escalation.

Question 319.

Which event can reveal modification of a local security policy?

  1. Browser bookmark creation
  2. File download completion
  3. Policy configuration change
  4. Screen brightness adjustment

Correct Answer: 3

Explanation:

Policy configuration changes can reveal modifications to local security settings. Hunters can examine which policy was changed, the previous and new values, the responsible account or process, and the timestamp. Unexpected modifications may indicate attempts to weaken protections, enable unauthorized functionality, or alter endpoint behavior. However, legitimate administrators and management systems may also make policy changes, so the event should be compared against approved configuration baselines and change records. Browser bookmarks, file downloads, and screen brightness adjustments do not directly indicate security-policy modification. Configuration-change telemetry therefore provides an important source for investigating unexpected endpoint security changes.

Question 320.

What should a hunter preserve after confirming a significant finding?

  1. Only unrelated events
  2. Supporting investigative evidence
  3. Temporary screen settings
  4. Personal desktop themes

Correct Answer: 2

Explanation:

Supporting investigative evidence should be preserved after confirming a significant finding. Useful evidence may include relevant process records, network events, authentication data, timestamps, file information, query results, and contextual observations that support the conclusion. Preserving this material allows other analysts to validate the finding, reconstruct the activity, and improve future detection logic. Evidence should be handled according to organizational retention and investigation procedures. Unrelated events, screen settings, and desktop themes generally provide little value for documenting the finding. A well-preserved evidence set also makes it easier to communicate the investigation’s reasoning and support subsequent response activities.