Cisco 300-220 Practice Test Questions and Exam Dumps Part18 Q341-360

View Full Cisco 300-220 Exam Dumps and Practice Test Dumps

 

Question 341.

Which telemetry can expose unexpected changes to endpoint exclusions?

  1. Browser history
  2. DNS cache
  3. Printer events
  4. Security configuration records

Correct Answer: 4

Explanation:

Security configuration records can reveal changes to endpoint protection exclusions and related security settings. Hunters can examine which exclusion was added or modified, when the change occurred, which account performed it, and whether the modification was associated with an approved administrative action. Unexpected exclusions can reduce visibility or allow selected files, directories, or processes to bypass security controls. Browser history, DNS cache, and printer events do not directly document endpoint protection configuration changes. Configuration telemetry should be correlated with identity and process records to determine whether the modification was legitimate maintenance or potentially suspicious activity.

Question 342.

What helps establish whether a process belongs to approved software?

  1. Digital signature information
  2. Screen resolution
  3. Keyboard preferences
  4. Printer configuration

Correct Answer: 1

Explanation:

Digital signature information can help establish the publisher associated with an executable and whether the file carries a valid signature. Hunters can compare signer details with approved software records and investigate unsigned or unexpectedly signed binaries. Signature validation alone does not prove that software is safe because legitimate software may be unsigned and malicious files can sometimes abuse trusted certificates. Additional evidence such as file hashes, installation source, path, prevalence, and execution behavior should also be considered. Screen resolution, keyboard preferences, and printer configuration do not provide meaningful information about software authenticity or publisher identity.

Question 343.

Which pattern can indicate suspicious account enumeration?

  1. One successful application login
  2. Repeated queries for many accounts
  3. Normal password expiration
  4. Routine service startup

Correct Answer: 2

Explanation:

Repeated queries involving many user accounts can indicate account enumeration activity. A hunter can examine which process generated the requests, how many accounts were queried, the timing of requests, and whether the activity originated from a system that normally performs directory or identity administration. Legitimate identity-management tools may also query many accounts, so the observed pattern must be compared with approved workflows. A single successful login, normal password expiration, and routine service startup do not directly indicate enumeration. Account-related telemetry combined with process and network context can help determine whether broad account discovery is expected or suspicious.

Question 344.

Which evidence can reveal an executable launched from an unusual directory?

  1. Authentication metadata
  2. Process path telemetry
  3. Network latency
  4. DNS response time

Correct Answer: 2

Explanation:

Process path telemetry can reveal the directory from which an executable was launched. Unusual paths, such as temporary folders, user-writable locations, or unexpected system directories, may provide valuable investigative leads. Hunters should compare the observed path with approved software locations and known deployment practices. The path alone does not establish maliciousness because legitimate applications may execute from nonstandard directories. Authentication metadata, network latency, and DNS response time provide different contextual information but do not directly identify the executable’s launch directory. Combining process path data with file provenance, signer information, and command-line telemetry can strengthen the investigation.

Question 345.

Why examine command-line arguments during threat hunting?

  1. To measure disk capacity
  2. To identify monitor models
  3. To understand execution intent
  4. To calculate network latency

Correct Answer: 3

Explanation:

Command-line arguments can reveal how an executable was instructed to operate. They may expose selected files, destinations, scripts, administrative actions, encoded parameters, or other details that are not visible from the process name alone. This information can help distinguish ordinary application use from suspicious execution. Command-line data should be interpreted within context because legitimate administrative tools can also contain complex parameters. Disk capacity, monitor models, and network latency do not explain process execution intent. Correlating command-line arguments with the parent process, user identity, file path, and network activity can provide a much clearer picture of what a process was attempting to accomplish.

Question 346.

Which source can identify unexpected changes to firewall rules?

  1. Endpoint firewall configuration logs
  2. Browser download history
  3. File extension statistics
  4. User wallpaper records

Correct Answer: 1

Explanation:

Endpoint firewall configuration logs can identify modifications to local firewall rules and settings. Hunters can examine which rule changed, its previous and new configuration, the responsible account or process, and the time of modification. Unexpected rule changes may affect network exposure or allow specific applications to communicate where they previously could not. Legitimate software installations and administrative maintenance can also modify firewall settings, so findings should be compared against approved change records. Browser history, file-extension statistics, and wallpaper records do not directly document firewall configuration. Configuration logs therefore provide the most relevant evidence for investigating unexpected firewall modifications.

Question 347.

What can reveal whether an unusual process is common across similar hosts?

  1. Password history
  2. Peer endpoint prevalence
  3. Screen-lock duration
  4. Printer queue size

Correct Answer: 2

Explanation:

Peer endpoint prevalence shows how frequently a process or executable appears across comparable systems. If a process is common among hosts with the same business role, it may represent expected software. Conversely, a process appearing on only one endpoint can become a useful hunting lead, particularly when other suspicious characteristics are present. Prevalence must be interpreted carefully because specialized applications can legitimately have limited distribution. Password history, screen-lock duration, and printer queue size do not provide meaningful software prevalence information. Comparing similar endpoints therefore helps hunters distinguish environmental norms from isolated process activity.

Question 348.

Which network evidence can identify communication with an unusual port?

  1. File ownership data
  2. Flow records
  3. Account profile settings
  4. Software license records

Correct Answer: 2

Explanation:

Flow records can reveal source and destination addresses, ports, protocols, timestamps, direction, and traffic volume. These details allow hunters to identify connections involving ports that differ from the normal communication profile of a host or service. An unusual port does not automatically indicate malicious activity because legitimate applications can use nonstandard ports. Investigators should compare the observed communication with service inventories, firewall policies, process ownership, and historical traffic patterns. File ownership, account profile settings, and software licensing do not directly describe network ports. Flow telemetry therefore provides an important foundation for unusual-port investigations.

Question 349.

Which evidence can indicate a process was launched by a service?

  1. Parent-process lineage
  2. Browser bookmarks
  3. DHCP lease duration
  4. Screen brightness

Correct Answer: 1

Explanation:

Parent-process lineage can help reveal how a process was initiated and whether a service or service-management component was responsible. Understanding the parent process is important when investigating unexpected execution because service-launched processes may behave differently from processes started interactively by users. Hunters can examine the parent executable, command line, service configuration, account context, and timestamps to establish the execution chain. Browser bookmarks, DHCP lease duration, and screen brightness do not provide process ancestry information. Lineage should be combined with service configuration records to determine whether the observed process was launched through an expected service mechanism.

Question 350.

What can repeated outbound transfers from one host suggest?

  1. Normal display activity
  2. Potential data movement
  3. Standard password rotation
  4. Routine screen locking

Correct Answer: 2

Explanation:

Repeated outbound transfers from a single host can suggest potential data movement, especially when the volume, destination, timing, or initiating process differs from the host’s normal behavior. Hunters should investigate what data was accessed, which process generated the transfer, which account initiated the activity, and whether the destination is approved. Repeated transfers can also result from legitimate backups, synchronization tools, or business applications, so volume alone does not establish malicious activity. Display activity, password rotation, and screen locking do not explain network data transfers. Correlating network and endpoint telemetry helps determine whether the observed movement requires further investigation.

Question 351.

Which artifact helps identify newly modified system services?

  1. Service configuration records
  2. Browser cache
  3. DNS resolver history
  4. Printer preferences

Correct Answer: 1

Explanation:

Service configuration records can reveal when system services are created, modified, enabled, disabled, or assigned different executable paths. Hunters can compare these changes with approved software deployments and administrative records. Suspicious service modifications may indicate persistence, unauthorized software installation, or attempts to execute programs automatically. Legitimate updates can also alter service configurations, so the account, process, timing, and affected executable should be reviewed. Browser cache, DNS resolver history, and printer preferences do not directly document service configuration changes. Service records are therefore an important source when investigating unexpected persistent or automatically launched processes.

Question 352.

Which activity may indicate discovery of internal services?

  1. Changing file permissions
  2. Opening a local document
  3. Probing multiple service ports
  4. Updating a browser

Correct Answer: 3

Explanation:

Probing multiple service ports can indicate attempts to discover available services on internal systems. Hunters can examine the source host, number of destinations, targeted ports, connection frequency, and initiating process. Such behavior can be generated by legitimate vulnerability scanners, network-management tools, or administrative software, so approved scanning activity should be excluded before treating the pattern as suspicious. File-permission changes, local document access, and browser updates do not directly demonstrate service discovery. Network-flow records combined with endpoint process telemetry can help identify the source of the probing and determine whether the behavior fits an expected operational purpose.

Question 353.

What should be compared when investigating an unusual remote login?

  1. Desktop theme
  2. Authentication baseline
  3. Printer inventory
  4. File icon style

Correct Answer: 2

Explanation:

An authentication baseline provides the normal patterns against which an unusual remote login can be evaluated. Relevant baseline characteristics may include source systems, login times, authentication methods, target hosts, and account usage. A deviation can provide a useful investigative lead, particularly when combined with unfamiliar devices, privilege changes, or suspicious processes. However, legitimate remote work and administrative operations can create exceptions, so the baseline should not be treated as definitive proof. Desktop themes, printer inventories, and file icon styles do not provide meaningful authentication context. Comparing the event with historical identity behavior helps determine whether further investigation is warranted.

Question 354.

Which telemetry can reveal modifications to startup entries?

  1. Startup configuration events
  2. Network bandwidth reports
  3. Printer connection records
  4. Browser font settings

Correct Answer: 1

Explanation:

Startup configuration events can reveal changes to entries that cause applications or scripts to launch automatically during system startup or user sign-in. Hunters can examine newly created entries, executable paths, command parameters, responsible accounts, and timestamps. Unexpected startup modifications may indicate persistence or unauthorized configuration changes, although legitimate software installations can create similar artifacts. Network bandwidth, printer connections, and browser font settings do not directly expose startup configuration. Correlating startup events with subsequent process execution can help determine whether the modified entry actually executed and whether its behavior matched the expected software baseline.

Question 355.

Why correlate file creation with process execution?

  1. To identify related activity
  2. To change file ownership
  3. To measure CPU temperature
  4. To update DNS servers

Correct Answer: 1

Explanation:

Correlating file creation with process execution can help determine whether a newly created file was subsequently executed or used by a particular process. This relationship can be valuable when investigating downloaded executables, dropped scripts, temporary payloads, or newly generated tools. Hunters can compare timestamps, file paths, hashes, parent processes, and user accounts to establish a coherent sequence of activity. File creation alone does not prove that a file was executed, while process telemetry provides execution context. File ownership changes, CPU temperature, and DNS configuration are unrelated to this analytical relationship. Combining file and process telemetry can therefore strengthen evidence around suspicious artifacts.

Question 356.

Which information helps identify a process running under an unexpected account?

  1. Process identity context
  2. Network packet size
  3. Monitor refresh rate
  4. Browser cache age

Correct Answer: 1

Explanation:

Process identity context identifies the account under which a process executes. This information can help hunters detect applications running under privileged, service, or user accounts that do not normally operate them. An unexpected identity becomes more significant when paired with unusual process lineage, command-line activity, or network communication. Network packet size, monitor refresh rate, and browser cache age do not establish process ownership. Identity context should be compared with expected application behavior and account responsibilities rather than treated as proof of compromise. Correlation with authentication records can also help determine how the account became active before the process was launched.

Question 357.

Which observation may support a hypothesis of credential misuse?

  1. Expected local update
  2. Routine DNS query
  3. Unusual account activity
  4. Standard application launch

Correct Answer: 3

Explanation:

Unusual account activity can support a hypothesis of credential misuse when it differs significantly from the account’s established behavior. Examples may include access from unfamiliar systems, unexpected times, unusual destinations, or activity inconsistent with the account’s normal role. Such observations do not prove credential compromise because legitimate operational changes can produce similar anomalies. Hunters should correlate authentication sources, session details, process execution, privilege use, and network activity to determine whether the account was potentially misused. Routine updates, ordinary DNS queries, and standard application launches generally provide less direct evidence of credential misuse without additional suspicious context.

Question 358.

What can help determine whether a suspicious destination was contacted previously?

  1. Historical network telemetry
  2. Screen-lock records
  3. Printer settings
  4. Desktop shortcut data

Correct Answer: 1

Explanation:

Historical network telemetry can show whether an endpoint or other systems previously communicated with a suspicious destination. Reviewing historical connections helps determine whether the destination is newly observed or part of an established communication pattern. Hunters can compare timestamps, affected hosts, ports, protocols, processes, and traffic volumes to identify changes in behavior. Previous communication does not automatically make a destination legitimate because malicious infrastructure can remain active for extended periods. Screen-lock records, printer settings, and desktop shortcuts do not provide useful communication history. Historical network analysis therefore adds valuable context when assessing an unfamiliar external or internal destination.

Question 359.

Which signal can strengthen a hypothesis involving process persistence?

  1. Normal application closure
  2. Routine DNS lookup
  3. Repeated automatic execution
  4. Standard user logoff

Correct Answer: 3

Explanation:

Repeated automatic execution can strengthen a hypothesis involving process persistence because persistence mechanisms are designed to cause programs or scripts to launch again without requiring the same manual action each time. Hunters can examine startup entries, scheduled tasks, services, login triggers, execution paths, and responsible accounts to identify the mechanism involved. Repeated execution alone does not prove malicious persistence because legitimate applications commonly start automatically. Normal application closure, routine DNS lookups, and standard logoffs provide little direct evidence of persistence. Correlating repeated execution with configuration changes and process lineage can provide stronger investigative support.

Question 360.

What is an appropriate outcome after a hunt disproves its hypothesis?

  1. Preserve the conclusion and refine future searches
  2. Delete all collected telemetry
  3. Ignore the observed evidence
  4. Disable related monitoring

Correct Answer: 1

Explanation:

When a hunt disproves its hypothesis, the conclusion should be documented and used to refine future searches. Recording which observations contradicted the hypothesis helps prevent the same assumptions from producing repeated false positives. The hunter can adjust query conditions, identify missing telemetry, narrow the scope, or develop a different hypothesis based on the available evidence. Discarding telemetry or disabling monitoring would reduce future visibility and remove potentially useful investigative context. Ignoring evidence also prevents learning from the investigation. A disproven hypothesis is therefore still valuable because it can improve hunting methodology and make subsequent investigations more precise.