Cisco CCNP CyberSecurity 300-215 Practice Test Questions and Exam Dumps Part4 Q61-80

View Full Cisco CCNP CyberSecurity 300-215 Exam Dumps and Practice Test Dumps

Question 61.

A SOC analyst observes repeated failed authentication attempts against a privileged account from several internal hosts, followed by one successful login. What should the analyst investigate first?

  1. Possible credential compromise and lateral movement
    2. Printer configuration errors
    3. Disk fragmentation
    4. DHCP lease expiration

Correct Answer: 1

Explanation:

Repeated authentication failures from multiple internal systems followed by a successful login to a privileged account can indicate credential compromise, password spraying, or lateral movement. The analyst should determine which systems generated the attempts, whether the successful login is consistent with the account owner’s normal behavior, and what activity followed authentication. Domain controller logs, EDR telemetry, VPN records, and identity-provider data can provide valuable context. Because the account is privileged, the event should generally receive higher priority than similar activity involving a low-impact account. Printer configuration and disk fragmentation are unrelated. Analysts should also check whether the source systems themselves are compromised and whether the account authenticated to additional hosts afterward.

Question 62.

Which information would be most useful for determining whether authentication activity represents normal administrator behavior or malicious lateral movement?

  1. Monitor model information
    2. Historical user and host behavior baselines
    3. Laptop battery health
    4. Printer toner levels

Correct Answer: 2

Explanation:

Historical behavior baselines help analysts understand what is normal for a specific account and system. An administrator who routinely authenticates to dozens of servers may generate activity that would be highly suspicious for a standard office user. Baselines can include commonly accessed systems, normal working hours, source devices, authentication methods, network locations, and typical administrative tools. They should not be treated as absolute truth because legitimate behavior can change, but they provide useful investigative context. Hardware inventory and printer information do not explain authentication patterns. Analysts should combine baseline deviations with asset criticality, privilege level, authentication telemetry, process activity, and threat intelligence before determining whether lateral movement is occurring.

Question 63.

A security analyst identifies a suspicious domain in DNS logs. Which pivot would provide the most useful next step for scoping the incident?

  1. Search for all internal hosts that queried or connected to the domain
    2. Replace every DNS server
    3. Delete the DNS logs
    4. Disable all name resolution

Correct Answer: 1

Explanation:

Once a suspicious domain is identified, searching across historical DNS, proxy, firewall, and endpoint telemetry for all hosts that interacted with it helps establish incident scope. The analyst can determine whether the activity is limited to one endpoint or appears across many systems. Additional pivots can include associated IP addresses, downloaded files, process names, user accounts, and timestamps. Replacing DNS infrastructure or disabling name resolution would be disruptive and would not necessarily address the underlying compromise. Deleting logs would destroy valuable evidence. Effective investigations often begin with one indicator and expand through related artifacts until analysts understand the affected systems, users, and attack sequence.

Question 64.

Which network behavior is most consistent with data exfiltration from a compromised endpoint?

  1. Normal ARP requests to the default gateway
    2. A routine DHCP renewal
    3. Standard NTP synchronization
    4. An unusual large outbound transfer to an external destination

Correct Answer: 4

Explanation:

A large outbound transfer to an unusual external destination can be an indicator of data exfiltration, particularly when the destination is rare, newly registered, or associated with malicious infrastructure. Analysts should review transfer volume, protocol, destination reputation, user context, endpoint process information, data classification, and whether similar communication has occurred previously. A large transfer alone does not prove compromise because legitimate cloud backup, file sharing, software distribution, or business workflows can generate substantial outbound traffic. ARP, DHCP, and NTP normally involve smaller, predictable infrastructure-related exchanges. Correlating network telemetry with endpoint and user activity helps determine whether the transfer represents legitimate business use or unauthorized data movement.

Question 65.

Which technique would help an analyst identify potentially encoded command-and-control traffic hidden within DNS queries?

  1. Analyze query length, entropy, frequency, and subdomain patterns
    2. Check monitor resolution
    3. Review printer queues
    4. Replace the endpoint hard drive

Correct Answer: 1

Explanation:

DNS tunneling often produces unusual query characteristics such as very long subdomains, high-entropy strings, repetitive request patterns, or unusually high query volumes to a small set of domains. Analysts can compare these characteristics with normal DNS behavior to identify potential covert communication. The responsible process on the endpoint should also be identified, and the domain’s reputation, registration age, and passive DNS history should be reviewed. Legitimate content-delivery, telemetry, or security products may also generate unusual DNS names, so statistical anomalies should be validated with context. Display settings, printer queues, and hard-drive replacement have no direct relevance to DNS tunneling analysis.

Question 66.

A security team wants to reduce alert fatigue caused by a SIEM rule that frequently triggers on legitimate administrative activity. What should be done?

  1. Disable all security logging
    2. Tune the rule using contextual conditions while preserving meaningful detection coverage
    3. Ignore every future alert from the rule
    4. Delete historical events

Correct Answer: 2

Explanation:

Detection tuning should reduce unnecessary false positives without creating a significant detection gap. Analysts can refine the rule by incorporating approved administrator accounts, known management systems, normal execution paths, expected time windows, command-line characteristics, or other contextual factors. The goal is not simply to reduce the number of alerts but to improve signal quality. Disabling logging or ignoring every alert would remove useful visibility, while deleting historical data prevents retrospective analysis. After tuning, the rule should be tested against known malicious patterns to verify that important behavior is still detected. Detection engineering is an iterative process informed by incidents, threat hunting, baselines, and analyst feedback.

Question 67.

Which term describes an alert that correctly identifies actual malicious activity?

  1. True positive
    2. False positive
    3. True negative
    4. False negative

Correct Answer: 1

Explanation:

A true positive occurs when a detection mechanism generates an alert and investigation confirms that the underlying activity is genuinely malicious. For example, an endpoint alert that identifies actual credential dumping would be a true positive. A false positive is an alert for legitimate activity, while a false negative occurs when malicious activity happens but is not detected. A true negative represents benign activity that correctly produces no alert. Tracking these classifications helps security teams measure detection quality, tune rules, and identify gaps. True positives should also be used as opportunities to hunt for similar behavior elsewhere and to assess whether containment, response, and escalation procedures worked effectively.

Question 68.

Which term describes malicious activity that occurs without generating the expected security alert?

  1. True positive
    2. True negative
    3. False positive
    4. False negative

Correct Answer: 4

Explanation:

A false negative occurs when malicious behavior takes place but the security control fails to generate an alert. False negatives are particularly dangerous because they can allow an attacker to remain undetected while defenders believe monitoring is functioning correctly. They may result from missing telemetry, poor parsing, overly narrow detection logic, disabled sensors, or new attacker techniques. True positives correctly identify malicious activity, false positives alert on legitimate behavior, and true negatives correctly remain silent for benign activity. Post-incident reviews, threat hunting, adversary simulation, and retrospective searches can reveal false negatives and help security teams improve detection coverage.

Question 69.

An analyst finds that a user clicked a phishing link and shortly afterward an Office application spawned PowerShell. What should the analyst investigate next?

  1. PowerShell command-line activity and subsequent network connections
    2. The monitor’s refresh rate
    3. Printer driver versions
    4. UPS battery condition

Correct Answer: 1

Explanation:

Office applications spawning PowerShell shortly after a phishing event can indicate malicious code execution. The analyst should inspect the complete PowerShell command line, script-block logging when available, parent-child process relationships, downloaded files, persistence actions, and outbound connections. The investigation should also determine whether credentials were accessed or whether additional hosts were targeted. Endpoint telemetry, email security logs, proxy records, DNS data, and authentication events can help reconstruct the attack chain. Hardware display and power information are not relevant. The analyst should also search the environment for similar process chains to determine whether other users received or executed the same malicious content.

Question 70.

Which source is most useful for determining how a suspicious attachment entered the organization and which recipients received it?

  1. DHCP logs
    2. Email security gateway logs
    3. ARP cache entries
    4. Switch port counters

Correct Answer: 2

Explanation:

Email security gateway logs can provide message sender information, recipients, timestamps, subject lines, attachment metadata, message IDs, URLs, and delivery actions. This makes them highly valuable for phishing investigations. Analysts can determine whether the message reached one or many users and then correlate recipient information with endpoint telemetry to identify who opened the attachment or clicked a link. DHCP and ARP data provide network information but do not describe email delivery. Switch counters likewise cannot identify message recipients. Email investigation should also include header analysis, sender reputation, domain intelligence, and related messages so the SOC can quickly scope and contain a campaign.

Question 71.

Which activity most directly supports identifying additional hosts affected by a newly discovered malicious file hash?

  1. Retrospective endpoint search
    2. Hardware replacement
    3. Printer inventory
    4. Password expiration review

Correct Answer: 1

Explanation:

A retrospective endpoint search allows analysts to query historical telemetry for a newly identified malicious hash. This can reveal systems that downloaded, stored, or executed the file before the indicator was known to be malicious. Analysts should not stop at exact hash matching because attackers can change file contents to generate different hashes. Related filenames, paths, certificates, parent processes, domains, and behaviors should also be examined. Retrospective searches depend on adequate telemetry retention, so organizations should maintain data long enough to support investigations. Hardware replacement and printer inventory do not help determine whether the malicious file existed elsewhere in the environment.

Question 72.

Which security practice helps ensure that forensic evidence can be shown to have remained unchanged after collection?

  1. Rename the evidence file
    2. Move it repeatedly between folders
    3. Calculate a cryptographic hash and verify it later
    4. Change the file extension

Correct Answer: 3

Explanation:

A cryptographic hash provides a content-based value that can be recalculated later and compared with the original. Matching values provide evidence that the forensic image or file has not changed. This supports forensic integrity and complements chain-of-custody documentation. Renaming, moving, or changing the extension does not prove integrity and may change metadata. Analysts should preserve original evidence when possible and perform analysis on validated copies. The acquisition process, tools, timestamps, storage location, and personnel involved should also be documented. If the hash unexpectedly changes, the difference must be investigated because the evidence may have been modified or corrupted.

Question 73.

Why is chain of custody important during a security investigation?

  1. It documents who handled evidence and when
    2. It increases processor performance
    3. It automatically removes malware
    4. It replaces encryption

Correct Answer: 1

Explanation:

Chain of custody documents the collection, transfer, storage, analysis, and access history of evidence. It helps show that evidence was handled consistently and was not improperly modified, lost, or substituted. This becomes especially important when an investigation may support legal, regulatory, disciplinary, or law-enforcement action. A chain-of-custody record may include evidence identifiers, dates and times, signatures, storage details, and every transfer between individuals. It does not improve system performance, remove malware, or replace cryptographic protection. Evidence handling should also include integrity verification, access controls, and approved forensic procedures so investigative findings remain defensible and reproducible.

Question 74.

Which data should generally receive high priority for collection because it may disappear when a compromised computer is powered off?

  1. Printed asset tags
    2. Volatile memory
    3. Purchase invoices
    4. Rack diagrams

Correct Answer: 2

Explanation:

Volatile memory can contain active processes, network connections, injected code, command history, encryption material, credentials, and other artifacts that may disappear when power is removed. Therefore, memory acquisition may be prioritized when volatile evidence is relevant and collection is permitted by organizational procedures. The exact order of volatility depends on the investigation and should be balanced against containment needs. Printed records and physical diagrams are persistent and do not disappear when the system is shut down. Memory acquisition should be performed using approved forensic methods, with collection actions documented and resulting evidence protected through hashes and chain-of-custody procedures where appropriate.

Question 75.

An attacker creates a new service that launches malicious code every time Windows starts. Which security objective does this behavior most directly support?

  1. Impact
    2. Discovery
    3. Persistence
    4. Exfiltration

Correct Answer: 3

Explanation:

Creating a service that automatically launches malicious code at startup is a persistence technique because it allows the attacker to regain execution after a reboot. Persistence mechanisms can include services, scheduled tasks, startup items, registry entries, modified authentication components, or newly created accounts. Discovery focuses on learning about the environment, Exfiltration involves stealing data, and Impact concerns disruption or destruction. During eradication, analysts must remove persistence mechanisms as well as visible malware files. Otherwise, the malicious payload may simply return after restart. The SOC should also hunt for similar service creation on other systems to determine whether the attacker established persistence more broadly.

Question 76.

Which action best represents containment during incident response?

  1. Writing a lessons-learned report
    2. Updating annual training material
    3. Purchasing replacement hardware
    4. Isolating a compromised endpoint from the network

Correct Answer: 4

Explanation:

Containment aims to limit the scope, spread, and impact of an active compromise. Isolating an infected endpoint can prevent additional command-and-control communication, lateral movement, malware propagation, or data exfiltration while analysts continue investigating. Containment methods may include EDR network isolation, firewall blocks, account disabling, segmentation, or physical disconnection depending on the incident. Lessons learned occurs after the incident, while training and procurement are broader operational activities. Containment decisions should consider evidence preservation and business impact. In some cases, analysts may first need to capture volatile evidence if doing so does not create unacceptable risk.

Question 77.

Which activity belongs primarily to the eradication phase of incident response?

  1. Removing malware and persistence mechanisms
    2. Establishing the SOC staffing plan
    3. Creating asset purchase orders
    4. Writing employee vacation schedules

Correct Answer: 1

Explanation:

Eradication focuses on removing the root causes and malicious components associated with an incident. This can include deleting malware, removing scheduled tasks or services used for persistence, patching exploited vulnerabilities, closing unauthorized accounts, and resetting compromised credentials. Containment limits the immediate spread, while recovery restores normal operation after the threat has been removed. Simply deleting one malicious executable may be insufficient if persistence or stolen credentials remain. Analysts should understand the attack path and confirm that all known footholds have been addressed. Depending on incident severity, rebuilding systems from trusted images may provide greater confidence than attempting to clean them manually.

Question 78.

Which action belongs primarily to the recovery phase of incident response?

  1. Developing the incident-response plan
    2. Restoring systems to production and monitoring for recurrence
    3. Collecting threat intelligence before an incident
    4. Creating employee badges

Correct Answer: 2

Explanation:

Recovery focuses on safely returning systems and services to normal operation after the threat has been contained and eradicated. Activities can include restoring data, rebuilding endpoints, validating security controls, reconnecting systems to the network, and closely monitoring for signs that the attacker has returned. Recovery should not begin until analysts have reasonable confidence that persistence and root causes have been addressed. Preparation activities such as creating response plans occur before incidents, while threat intelligence collection can support several phases. Post-recovery monitoring is essential because recurrence may indicate incomplete eradication, compromised credentials, or an unrecognized access path.

Question 79.

A post-incident review finds that a compromised endpoint had no process command-line logging, preventing analysts from understanding the attacker’s commands. What improvement should be prioritized?

  1. Enable appropriate command-line and endpoint telemetry collection
    2. Remove all endpoint sensors
    3. Reduce log retention
    4. Disable script logging

Correct Answer: 1

Explanation:

The missing command-line telemetry represents a visibility gap that directly limited the investigation. Enabling appropriate endpoint, process, PowerShell, and command-line logging can provide richer evidence for future incidents and improve detection engineering. The organization should balance logging depth with storage, privacy, and performance requirements, but reducing or disabling telemetry would worsen the problem. The post-incident review should document the gap, assign ownership for remediation, test the new logging configuration, and ensure the data reaches the SIEM or EDR platform correctly. Lessons learned are most valuable when they produce concrete, measurable improvements rather than remaining only as written observations.

Question 80.

After an incident is fully resolved, which action provides the greatest long-term defensive value?

  1. Delete the investigation records immediately
    2. Disable the detections that generated alerts
    3. Document lessons learned and improve detections, procedures, and controls
    4. Ignore the incident because systems are operational again

Correct Answer: 3

Explanation:

A structured lessons-learned process converts an incident into improvements for future defense. The team should review what happened, how quickly the attack was identified, which controls worked, where visibility or process gaps existed, and how containment and recovery were handled. Useful outcomes can include new detection rules, updated threat-hunting queries, improved logging, stronger access controls, revised incident-response playbooks, better automation, or additional training. Deleting records or ignoring the event wastes valuable knowledge, while disabling detections could create new gaps. Incident response should therefore be treated as a continuous improvement cycle in which each confirmed event strengthens prevention, detection, investigation, and response capabilities.