View Full Cisco CCNP CyberSecurity 300-215 Exam Dumps and Practice Test Dumps
Question 21.
A security analyst receives an alert showing a user account authenticating successfully from two geographically distant locations within a very short period. Which activity should the analyst investigate first?
- Potential credential compromise
2. Disk fragmentation
3. DNS zone transfer
4. Printer spooler failure
Correct Answer: 1
Explanation:
Successful authentication from geographically distant locations within an impossible or highly unlikely travel window can indicate compromised credentials. The analyst should review authentication logs, source IP addresses, VPN activity, device information, MFA events, timestamps, and the user’s normal behavior. Cloud identity and endpoint telemetry can help determine whether one login is legitimate and the other suspicious. Disk fragmentation and printer services are unrelated to authentication anomalies. A DNS zone transfer could be security-relevant in another scenario but does not directly explain the unusual login pattern. The analyst should avoid assuming compromise solely from geolocation because VPNs, mobile carriers, proxies, and cloud services can affect apparent location. Context and corroborating evidence are required before containment actions are taken.
Question 22.
Which security technology is primarily designed to aggregate logs from many systems, correlate events, and generate security alerts?
- Network address translation
2. SIEM
3. RAID
4. DHCP
Correct Answer: 2
Explanation:
A Security Information and Event Management system, or SIEM, collects and analyzes logs from sources such as firewalls, endpoints, identity systems, servers, network devices, applications, and cloud platforms. It can normalize data, correlate related events, execute detection rules, produce dashboards, and generate alerts for analysts. NAT translates IP addresses, RAID provides storage resiliency, and DHCP dynamically assigns network configuration. A SIEM does not automatically guarantee accurate detection; its value depends on telemetry quality, parsing, detection logic, tuning, and analyst workflows. Mature security operations teams also enrich SIEM events with threat intelligence, asset criticality, user context, and endpoint data so high-risk activity can be prioritized and investigated more efficiently.
Question 23.
A security analyst observes a Windows process spawning cmd.exe, which then launches an encoded PowerShell command. Which data source provides the best visibility into this process relationship?
- Physical access logs
2. DHCP logs only
3. EDR process telemetry
4. Printer logs
Correct Answer: 3
Explanation:
Endpoint detection and response telemetry can provide detailed process trees showing parent and child processes, command-line arguments, executable paths, hashes, users, timestamps, and associated network activity. This makes EDR especially useful for analyzing suspicious chains such as one process launching cmd.exe, followed by encoded PowerShell execution. DHCP logs may help map an IP address to a host but do not explain process relationships. Physical access and printer logs are similarly unrelated. Analysts should examine the parent process, PowerShell command, resulting child processes, downloaded files, persistence actions, and outbound connections. A suspicious process chain can indicate script-based malware, exploitation, or legitimate administration, so the analyst should validate context before classifying the activity.
Question 24.
An analyst identifies a malicious executable on a compromised host. Which artifact would be most useful for searching other endpoints for an exact copy of the same file?
- User’s monitor resolution
2. DHCP lease duration
3. Keyboard layout
4. Cryptographic file hash
Correct Answer: 4
Explanation:
A cryptographic hash provides a reproducible identifier based on file content and can be used to search endpoint telemetry, malware repositories, threat-intelligence platforms, or file inventories for identical copies. Hashes are useful indicators of compromise, particularly during incident scoping. However, attackers can modify even a small part of a file to produce a completely different hash, so analysts should not rely on hash matching alone. Behavioral indicators, file paths, certificates, process relationships, network connections, and other attributes should also be examined. Monitor resolution, keyboard layout, and DHCP lease duration do not identify the malicious executable. Hash values are also useful for forensic integrity verification when analysts need to demonstrate that collected evidence has not changed.
Question 25.
Which network artifact can help an analyst determine which internal host was assigned a specific dynamically allocated IP address at the time of an incident?
- DHCP logs
2. Browser bookmarks
3. BIOS configuration
4. Screen-lock policy
Correct Answer: 1
Explanation:
DHCP logs can record which IP addresses were leased to particular client identifiers or MAC addresses and at what times. This is extremely important in forensic and incident-response investigations because an IP address may be assigned to different systems at different points in time. The analyst should correlate the incident timestamp with the correct lease period rather than assume that the device currently using an address also used it during the event. Browser bookmarks, BIOS settings, and screen-lock policies do not provide dynamic address attribution. DHCP evidence can be combined with switch logs, wireless controller data, endpoint inventory, authentication records, and EDR telemetry to establish stronger host attribution.
Question 26.
A network intrusion alert identifies communication from an internal workstation to a known command-and-control IP address. Which step best helps determine whether the connection was actually initiated by malware?
- Replace the workstation immediately without investigation
2. Correlate network data with endpoint process telemetry
3. Delete the firewall logs
4. Reset all employee passwords before validating the alert
Correct Answer: 2
Explanation:
Correlating network activity with endpoint process telemetry can reveal which executable initiated the connection, which user context it ran under, how the process started, and whether related suspicious activity occurred. This helps distinguish malicious command-and-control traffic from a false positive or legitimate connection. Replacing the system immediately could destroy evidence and may not address the root cause. Deleting logs removes valuable investigative data, while resetting every password before establishing scope may be unnecessarily disruptive. Analysts should build a timeline using firewall, proxy, DNS, EDR, and authentication telemetry. If malware is confirmed, containment and credential-reset decisions should then be made according to the incident-response plan and observed compromise scope.
Question 27.
Which term describes information about observable malicious artifacts such as IP addresses, domains, hashes, and file names associated with a compromise?
- Indicators of compromise
2. Recovery objectives
3. Service-level agreements
4. Asset depreciation records
Correct Answer: 1
Explanation:
Indicators of compromise, or IOCs, are observable technical artifacts that may indicate malicious activity or a compromised system. Examples include known malicious IP addresses, domains, file hashes, registry paths, filenames, mutexes, or email addresses. IOCs are useful for detection, threat hunting, incident scoping, and retrospective searches. However, they often have limited lifespan because attackers can change infrastructure or modify malware easily. Analysts should therefore combine static IOCs with behavioral detections that focus on adversary techniques, process relationships, authentication anomalies, and other harder-to-change patterns. Recovery objectives, SLAs, and asset depreciation are important operational concepts but do not describe malicious technical artifacts.
Question 28.
An analyst observes a compromised host repeatedly connecting to an external server at nearly identical time intervals. What malicious behavior could this pattern indicate?
- Normal ARP resolution
2. Routine local file access
3. DHCP address conflict
4. Command-and-control beaconing
Correct Answer: 4
Explanation:
Regular outbound connections at predictable intervals can indicate command-and-control beaconing. Malware often contacts attacker-controlled infrastructure periodically to receive instructions, report host status, or transfer information. Analysts should review destination reputation, timing patterns, packet sizes, protocols, DNS activity, process telemetry, and whether multiple hosts show similar behavior. Legitimate software such as monitoring agents, cloud applications, and update services can also generate regular traffic, so periodicity alone does not prove maliciousness. ARP and DHCP behaviors have different characteristics and generally involve local network functions. If beaconing is confirmed, the analyst should identify the responsible process, isolate affected hosts when appropriate, and hunt for the same pattern elsewhere in the environment.
Question 29.
A threat hunter wants to search for systems where Microsoft Office applications unexpectedly launch command shells. Which type of detection is being used?
- Behavioral detection
2. Physical access detection
3. Hardware inventory matching
4. Static IP assignment
Correct Answer: 1
Explanation:
Searching for unusual process relationships, such as a document application spawning cmd.exe or PowerShell, is a behavioral detection strategy. It focuses on attacker techniques and anomalous execution patterns rather than matching a single file hash or IP address. Behavioral detections can remain effective even when adversaries change malware files or infrastructure. Office applications sometimes legitimately launch helper processes, so the analyst must consider command-line arguments, parent-child context, user behavior, file origin, and resulting network activity. Physical access records, hardware inventory, and static IP assignments do not identify this type of execution chain. Behavioral analytics are valuable for threat hunting because they can surface previously unknown malware using recognizable attacker methods.
Question 30.
Which artifact would best help determine whether a malicious domain was accessed through a corporate web proxy?
- RAM module serial number
2. Proxy logs
3. BIOS password configuration
4. Monitor inventory
Correct Answer: 2
Explanation:
Web proxy logs can record client IP addresses, usernames, requested URLs, domains, timestamps, HTTP methods, response codes, user-agent information, and sometimes transferred byte counts. These records can help determine which users or systems accessed a malicious domain and when. Proxy logs are therefore valuable for incident scoping and timeline construction. Hardware serial numbers and BIOS settings provide inventory or configuration information but do not show web requests. Analysts should correlate proxy data with DNS, endpoint, authentication, and firewall telemetry because a proxy record can show that a request occurred but may not by itself establish which local process generated it. The combination of network and endpoint evidence provides stronger attribution.
Question 31.
A SOC analyst needs to determine whether a newly identified malicious IP address appeared anywhere in historical firewall data during the previous 30 days. Which activity is most appropriate?
- Retrospective search
2. Disk formatting
3. Physical inventory
4. Password expiration
Correct Answer: 1
Explanation:
A retrospective search involves querying historical telemetry for an indicator or behavior that has only recently become known to be suspicious. After receiving a new malicious IP address from threat intelligence, analysts can search previous firewall, proxy, DNS, or endpoint logs to determine whether internal systems communicated with it before the IOC was identified. This can reveal previously undetected compromise and expand incident scope. Historical searches depend on sufficient log retention and good data quality. Disk formatting, physical inventory, and password expiration do not provide this capability. Analysts should also consider that IP addresses can change ownership, so timestamps and contextual threat intelligence are important when determining whether historical communication was malicious at the time.
Question 32.
During forensic analysis, why is time synchronization across systems important?
- It increases available storage capacity
2. It makes malware unable to execute
3. It simplifies antivirus licensing
4. It helps accurately correlate events across multiple data sources
Correct Answer: 4
Explanation:
Accurate and synchronized timestamps are essential for building reliable incident timelines. If endpoints, firewalls, servers, identity platforms, and network devices use different times, events may appear in the wrong order and lead investigators to incorrect conclusions about cause and effect. Network Time Protocol or another centralized time source helps maintain consistency. Analysts should also understand time zones and whether log sources record local time or UTC. Time synchronization does not increase storage or prevent malware execution. When investigating an event, analysts may need to account for clock drift or logging delays if systems were not properly synchronized. Reliable timestamps make correlation, evidence review, and incident reporting substantially more accurate.
Question 33.
An analyst captures the volatile memory of a compromised system. Which artifact is most likely to be recovered from RAM but lost after shutdown?
- Active process and network-connection information
2. Computer chassis serial number
3. Printed security policy
4. Monitor model number
Correct Answer: 1
Explanation:
RAM can contain volatile information such as active processes, loaded modules, active network connections, decrypted content, command history, encryption keys, injected code, and other transient artifacts. Much of this information can disappear when the computer is powered off, which is why memory acquisition may be prioritized during some investigations. Hardware serial numbers and printed documentation are persistent and do not depend on system power. Analysts should follow approved forensic procedures when acquiring memory because the collection process itself changes the system state to some degree. The resulting memory image should be hashed, documented, and protected according to chain-of-custody requirements when forensic integrity matters.
Question 34.
Which forensic practice helps demonstrate that an acquired evidence file has not changed since collection?
- Renaming the file
2. Calculating and verifying a cryptographic hash
3. Compressing the file repeatedly
4. Moving it between folders
Correct Answer: 2
Explanation:
Calculating a cryptographic hash at the time of acquisition and comparing it with later hash values helps demonstrate that evidence has remained unchanged. If the hashes match, investigators gain confidence that the file analyzed later is identical to the collected evidence. Renaming, moving, or compressing evidence does not provide the same integrity assurance and may alter metadata or representations. Hashing should be combined with chain-of-custody documentation, restricted evidence storage, and approved forensic procedures. Analysts typically avoid working directly on original evidence and instead analyze validated copies. Any unexpected change in the hash value should be investigated and documented because it may indicate modification or corruption.
Question 35.
A security analyst finds evidence that an attacker created a scheduled task to launch malware every time a user logs in. Which adversary objective does this most directly support?
- Persistence
2. Reconnaissance only
3. Data classification
4. Asset management
Correct Answer: 1
Explanation:
Creating a scheduled task that repeatedly launches malware is a persistence technique because it allows malicious code to regain execution after reboot, logout, or other interruptions. Attackers commonly use scheduled tasks, services, startup entries, registry locations, or compromised accounts to maintain access. Reconnaissance focuses on gathering information, while data classification and asset management are defensive administrative activities. During eradication, analysts must identify and remove persistence mechanisms in addition to deleting the primary malicious executable. If persistence remains, the attacker may regain control after the system appears to have been cleaned. Analysts should also hunt for similar scheduled tasks on other hosts to determine whether the technique was deployed more broadly.
Question 36.
Which incident-response action is intended to limit the spread or impact of an active compromise before complete eradication is performed?
- Lessons learned
2. Preparation
3. Recovery validation
4. Containment
Correct Answer: 4
Explanation:
Containment aims to limit damage, prevent lateral movement, stop data exfiltration, and reduce additional compromise while the incident is being investigated and eradicated. Examples can include isolating endpoints, blocking malicious domains, disabling compromised accounts, segmenting systems, or restricting network communication. The exact method should preserve necessary evidence and avoid unnecessary business disruption. Preparation occurs before incidents, lessons learned occurs afterward, and recovery validation confirms restored systems are functioning safely. Analysts must balance speed with evidence preservation because an overly aggressive containment action can destroy volatile evidence or alert the attacker. The incident-response plan should define approved containment methods and decision authority.
Question 37.
After malware is removed from a compromised workstation, which action is most important before returning the system to production?
- Verify that persistence is removed, vulnerabilities are addressed, and the host is clean
2. Delete all security logs
3. Disable endpoint monitoring
4. Restore the malicious file for comparison
Correct Answer: 1
Explanation:
Before a compromised system is returned to production, analysts should verify that malicious files and persistence mechanisms are gone, exploited vulnerabilities or misconfigurations have been addressed, compromised credentials have been handled, and security controls are functioning. The system should also be monitored for signs of recurrence. Deleting security logs or disabling monitoring would reduce visibility at the point when continued observation is particularly important. Restoring malicious files would reintroduce risk. Depending on the severity and trustworthiness of the system, complete reimaging from a known-good source may be preferred over attempting to clean it. Recovery is not complete simply because the original alert stops; confidence must be established that the attacker no longer retains access.
Question 38.
Which classification applies when malicious activity occurs but the security monitoring system fails to generate an alert?
- True positive
2. False negative
3. False positive
4. True negative
Correct Answer: 2
Explanation:
A false negative occurs when malicious activity is present but the security control fails to detect or alert on it. False negatives are particularly dangerous because the organization may believe the environment is safe while an attack continues unnoticed. A true positive correctly detects malicious activity. A false positive generates an alert for benign activity, while a true negative correctly produces no alert for legitimate behavior. Detection engineering attempts to reduce both false positives and false negatives, although perfect detection is unrealistic. Threat hunting, retrospective analysis, purple-team exercises, and incident reviews can reveal missed behaviors and help improve detection coverage. Analysts should carefully determine why the control missed the activity before modifying rules.
Question 39.
An analyst confirms that an alert correctly identified malicious credential dumping on an endpoint. How should the alert be classified?
- True positive
2. False positive
3. True negative
4. False negative
Correct Answer: 1
Explanation:
A true positive occurs when a security control generates an alert and investigation confirms that the detected activity is genuinely malicious. In this scenario, the endpoint alert accurately identified credential dumping, so the detection behaved as intended. A false positive would mean the activity was legitimate, a false negative would mean malicious behavior occurred without being detected, and a true negative would mean benign activity correctly produced no alert. Confirmed true positives should still be reviewed for detection quality, response speed, and incident scope. Analysts may use the confirmed behavior to search other endpoints, identify persistence or lateral movement, and improve automated response or enrichment for future occurrences.
Question 40.
After completing an incident investigation, the team identifies that existing monitoring failed to detect the attacker’s initial execution technique. What is the best post-incident action?
- Delete the incident data to reduce storage use
2. Disable the affected security control
3. Document the detection gap and develop improved monitoring or detection logic
4. Ignore the gap because the incident has already ended
Correct Answer: 3
Explanation:
A post-incident review should identify detection gaps and convert lessons from the incident into measurable security improvements. If the initial execution technique was not detected, the team should document the gap, determine which telemetry is required, create or tune detection logic, test the new detection, and update response procedures when necessary. Deleting incident data or disabling controls would reduce future visibility. Ignoring the weakness leaves the organization vulnerable to the same technique. Effective lessons-learned processes often result in new SIEM rules, EDR detections, threat-hunting queries, logging improvements, network controls, user training, or architectural changes. The objective is to improve resilience so future attacks using similar behavior are detected earlier and handled more effectively.