Cisco CCNP CyberSecurity 300-215 Practice Test Questions and Exam Dumps Part5 Q81-100

View Full Cisco CCNP CyberSecurity 300-215 Exam Dumps and Practice Test Dumps

 

Question 81.

A security analyst observes a user account successfully authenticating from an internal workstation and then accessing several servers the user has never contacted before. Which activity should the analyst investigate first?

  1. Potential lateral movement using compromised credentials
    2. Routine DHCP renewal
    3. Normal DNS recursion
    4. Scheduled endpoint inventory

Correct Answer: 1

Explanation:

A sudden change in authentication behavior, especially when an account begins accessing multiple unfamiliar systems, can indicate lateral movement with compromised credentials. The analyst should review the originating host, authentication type, timestamps, destination systems, privilege level, and any processes launched after each login. EDR telemetry may reveal remote administration tools, PowerShell, service creation, or other activity associated with lateral movement. Historical baselines are also valuable because some administrators legitimately access many systems while ordinary users usually do not. DHCP and DNS activity would not directly explain the unusual authentication pattern. If compromise is confirmed, containment may include isolating the originating endpoint, restricting the affected account, and searching for the same behavior across additional systems.

Question 82.

Which log source is most valuable when investigating whether a compromised account was used to authenticate to multiple Windows systems?

  1. Printer logs
    2. Windows authentication and domain controller security logs
    3. Monitor inventory
    4. UPS logs

Correct Answer: 2

Explanation:

Windows authentication events and domain controller security logs can provide important information about successful and failed logins, account names, source systems, destination systems, logon types, and authentication protocols. These events are central to investigating credential abuse and lateral movement. Analysts should correlate authentication logs with endpoint telemetry to identify what happened immediately after each login, because successful authentication alone does not prove malicious activity. For example, process creation, remote service execution, PowerShell, or unusual file access may strengthen the case. Printer, display, and UPS logs generally do not provide useful identity context. Accurate timestamps are especially important because the analyst may need to reconstruct the sequence of logins across many hosts.

Question 83.

A user account generates hundreds of login failures against a single server using many different passwords. Which attack pattern is most consistent with this behavior?

  1. Password spraying
    2. DNS tunneling
    3. Brute-force password attack
    4. ARP poisoning

Correct Answer: 3

Explanation:

A brute-force password attack typically involves attempting many different passwords against one account or one target until a valid credential is discovered. Password spraying usually takes the opposite approach by trying one or a few commonly used passwords against many different accounts to reduce the chance of triggering per-account lockout thresholds. DNS tunneling and ARP poisoning are unrelated to password guessing. The analyst should examine the source IP address, authentication method, account lockout events, timing, and whether any attempt eventually succeeded. If a login was successful, subsequent account activity becomes particularly important. Defensive controls can include MFA, appropriate lockout policies, rate limiting, monitoring, and strong password practices.

Question 84.

An analyst observes one commonly used password being attempted against hundreds of different accounts. Which attack should be suspected?

  1. Credential stuffing only
    2. ARP spoofing
    3. SQL injection
    4. Password spraying

Correct Answer: 4

Explanation:

Password spraying involves testing one or a small number of common passwords across many accounts. This strategy can help attackers avoid triggering traditional account lockout controls that focus on repeated failures against a single user. Analysts should search identity logs for the same source IP, repeated failure patterns, targeted usernames, and any successful authentication that follows. They should also review MFA events and determine whether the source is associated with known malicious infrastructure. Credential stuffing instead typically uses previously stolen username-and-password pairs. If a password-spraying attempt succeeds, incident scope should expand to the affected account, the source device, and any resources accessed after authentication.

Question 85.

A SOC receives a threat-intelligence report containing a malicious domain first observed yesterday. What is the most useful initial action?

  1. Search historical DNS, proxy, firewall, and endpoint data for the domain
    2. Reimage every endpoint
    3. Delete all DNS caches across the enterprise without investigation
    4. Disable internet access permanently

Correct Answer: 1

Explanation:

A retrospective search across historical telemetry can reveal whether internal systems interacted with the malicious domain before the organization knew it was suspicious. DNS data can show which hosts resolved it, proxy logs can identify web requests, firewall records can show network connections, and endpoint telemetry can reveal which processes generated those connections. This approach helps determine incident scope while preserving evidence. Reimaging every endpoint would be unnecessarily disruptive, and broad changes without confirming exposure may obscure useful investigative context. Analysts should also review the age and confidence of the intelligence because domains can change ownership or purpose. If affected systems are identified, the investigation can pivot to related files, processes, users, IP addresses, and persistence mechanisms.

Question 86.

Which characteristic of threat intelligence is most important before automatically blocking an IP address across the enterprise?

  1. The indicator contains only numbers
    2. Confidence, freshness, and context
    3. The source uses a colorful dashboard
    4. The IP address responds to ping

Correct Answer: 2

Explanation:

Before automatically blocking infrastructure, the SOC should consider the confidence of the source, how recently malicious activity was observed, and the context associated with the indicator. IP addresses can be reassigned, shared by many services, or belong to cloud infrastructure hosting both legitimate and malicious workloads. A stale or low-confidence indicator can therefore create false positives and disrupt business traffic. Ping responsiveness does not determine maliciousness, and presentation quality has no bearing on intelligence reliability. Mature security programs assign confidence, severity, timestamps, and source information to indicators and may use different response actions based on those attributes. High-confidence active command-and-control infrastructure may justify blocking, while lower-confidence data may be more appropriate for alert enrichment.

Question 87.

A threat hunter is looking for abnormal parent-child process relationships such as winword.exe spawning powershell.exe. What type of detection approach is this?

  1. Behavioral detection
    2. File-hash-only detection
    3. Hardware inventory detection
    4. Physical access detection

Correct Answer: 1

Explanation:

Behavioral detection focuses on what processes and users are doing rather than relying solely on static indicators such as hashes or IP addresses. An Office application spawning PowerShell can be suspicious because document-based attacks frequently abuse scripting interpreters to execute additional payloads. However, the relationship is not automatically malicious, so analysts should examine the document source, command-line arguments, PowerShell logging, child processes, and network connections. Behavioral detections can remain useful when attackers modify malware files or infrastructure because the underlying techniques may remain similar. Static indicators still provide value, but combining them with process behavior creates stronger and more durable detection coverage.

Question 88.

A security rule alerts every time PowerShell runs, creating thousands of benign alerts. Which tuning approach best preserves useful detection coverage?

  1. Disable PowerShell telemetry completely
    2. Ignore every PowerShell event
    3. Alert only when PowerShell executes during business hours
    4. Add suspicious context such as encoded commands, unusual parents, or network behavior

Correct Answer: 4

Explanation:

PowerShell is widely used for legitimate administration, so alerting on every execution creates excessive noise. A stronger rule looks for contextual factors associated with malicious use, such as encoded commands, execution from unusual parent processes, hidden windows, downloads, suspicious script blocks, unusual users, or unexpected outbound connections. This improves precision without removing visibility entirely. Disabling PowerShell telemetry or ignoring all events would create a major detection gap. Restricting alerts based only on time is also weak because attackers can operate during normal business hours. Detection tuning should be tested against known malicious examples to ensure that reducing false positives does not create unacceptable false negatives.

Question 89.

Which situation represents a false positive?

  1. A legitimate administrative script triggers a malware-style PowerShell alert
    2. Malware runs but no alert is generated
    3. Malware runs and the SOC correctly alerts
    4. Benign activity occurs and no alert is generated

Correct Answer: 1

Explanation:

A false positive occurs when a security control generates an alert for activity that investigation determines is legitimate. In this example, the detection mechanism correctly observed suspicious-looking PowerShell behavior but misclassified approved administrative activity as malicious. A false negative occurs when malware runs without generating an alert. A true positive occurs when malicious behavior is correctly detected, while a true negative is benign activity that correctly produces no alert. SOC teams should track false-positive patterns because excessive noise can create analyst fatigue and slow response to genuine threats. However, tuning must be performed carefully so that legitimate exceptions do not become broad exclusions that attackers can exploit.

Question 90.

Which situation represents a false negative?

  1. A harmless administrative command triggers an alert
    2. Malicious credential dumping occurs but no alert is generated
    3. A malicious file triggers a correct endpoint alert
    4. Legitimate activity produces no alert

Correct Answer: 2

Explanation:

A false negative occurs when malicious activity happens but the detection system fails to identify it. In this case, credential dumping took place without an alert, leaving the organization unaware of a potentially serious compromise. False negatives can result from missing telemetry, disabled sensors, poor parsing, overly narrow detection rules, or attacker techniques that have not yet been covered. A post-incident review should determine why the activity was missed and what telemetry or detection logic is needed to close the gap. Threat hunting, adversary simulation, and retrospective searches can also reveal similar undetected activity. False negatives are especially dangerous because they create a false sense of security.

Question 91.

A host sends a small HTTPS request to the same external destination approximately every sixty seconds. What additional evidence would most help distinguish malware beaconing from a legitimate management agent?

  1. The process responsible for each network connection
    2. The monitor’s refresh rate
    3. The user’s keyboard layout
    4. The workstation’s asset color

Correct Answer: 1

Explanation:

Process attribution is critical when evaluating periodic network activity. If the connection originates from a known and properly signed management agent communicating with its expected vendor infrastructure, the behavior may be legitimate. If it comes from an unsigned executable in a temporary directory or from an unusual script interpreter, the same traffic pattern becomes far more suspicious. The analyst should also consider destination reputation, TLS certificate details, timing regularity, data volume, domain age, and whether similar traffic appears on other managed systems. Hardware display characteristics provide no meaningful network context. Correlating endpoint and network telemetry is one of the most effective methods for separating malicious beaconing from legitimate automated communications.

Question 92.

Which telemetry would be most useful for identifying the internal systems that resolved a suspicious command-and-control domain?

  1. Asset purchase records
    2. DNS query logs
    3. Printer maintenance logs
    4. Video surveillance records

Correct Answer: 2

Explanation:

DNS query logs can show which clients requested resolution for a particular domain and when those queries occurred. This makes them valuable for incident scoping after a malicious or command-and-control domain is discovered. Analysts can search for all clients that queried the domain, then pivot into endpoint and network telemetry for each host. DNS activity does not necessarily prove that a successful connection occurred, so firewall or proxy data should be used to confirm actual communication when possible. Analysts should also review DNS response data, caching behavior, and timestamps. Purchase, printer, and physical-security records do not provide the required name-resolution visibility.

Question 93.

A SOC analyst wants to determine whether sensitive information was transmitted through DNS. Which network pattern would be most suspicious?

  1. Occasional requests for common corporate domains
    2. Standard reverse DNS lookups
    3. Repeated long, high-entropy subdomain queries carrying varying encoded data
    4. Normal DNS server health checks

Correct Answer: 3

Explanation:

DNS tunneling can encode information into subdomains or DNS responses, producing unusually long, high-entropy labels and repeated requests to a small set of domains. When the encoded portion changes frequently, it may represent data being transferred through DNS. Analysts should evaluate query length, frequency, entropy, record types, destination domain reputation, and endpoint process information. Legitimate cloud and security services can also produce complex DNS names, so the pattern must be validated before it is considered malicious. If tunneling is suspected, the analyst should identify the responsible process, examine the domain’s history, and determine whether the endpoint contains other signs of compromise.

Question 94.

Which information is most important when reconstructing a multi-system incident timeline from different log sources?

  1. Screen resolution
    2. Consistent timestamps and time-zone awareness
    3. Monitor serial numbers
    4. Laptop battery capacity

Correct Answer: 2

Explanation:

Accurate timestamps are essential for correlating events from endpoints, firewalls, identity platforms, email systems, cloud services, and other sources. Systems should ideally use synchronized time services, and analysts need to know whether each platform records timestamps in UTC or local time. Clock drift can make actions appear in the wrong order and lead to incorrect conclusions about cause and effect. The analyst should normalize time values before creating a timeline and document any known time discrepancies. Hardware display and battery information do not contribute to chronological reconstruction. Reliable timestamps are particularly important when tracing phishing delivery, execution, credential theft, lateral movement, and exfiltration across multiple systems.

Question 95.

An analyst is preparing to collect forensic evidence from an active compromised endpoint. Which evidence is generally considered the most volatile?

  1. System memory
    2. Files stored on an offline backup
    3. Printed network diagrams
    4. Archived asset records

Correct Answer: 1

Explanation:

System memory is highly volatile because its contents can disappear when the host loses power or is restarted. RAM may contain active processes, injected code, network connections, decrypted data, authentication artifacts, encryption keys, and other information that is difficult or impossible to recover later. For this reason, memory acquisition may be prioritized when forensic procedures and incident conditions permit. Stored files and printed records are much less volatile. Analysts must still balance evidence collection with containment because delaying isolation could allow additional malicious activity. The collection method, tool, operator, timestamp, and resulting hash should be documented when forensic integrity is important.

Question 96.

Which control is most directly used to demonstrate that a forensic image has not changed since it was collected?

  1. Changing the filename
    2. Compressing the image
    3. Storing it in a new directory
    4. Verifying a cryptographic hash

Correct Answer: 4

Explanation:

A cryptographic hash produces a deterministic value based on the evidence contents. By calculating a hash at acquisition and comparing it with a later value, investigators can demonstrate that the forensic image has remained unchanged. This supports evidence integrity and complements chain-of-custody documentation. Renaming, moving, or compressing evidence does not provide the same assurance. Analysts should generally preserve original evidence and conduct analysis on verified working copies. If a hash value differs unexpectedly, the discrepancy should be investigated and documented because the evidence may have changed or become corrupted. Strong evidence handling is especially important when findings may be used for regulatory, disciplinary, or legal purposes.

Question 97.

A compromised endpoint contains a scheduled task, a newly created service, and a registry startup entry, all launching the same payload. Which adversary goal do these artifacts primarily support?

  1. Persistence
    2. Discovery
    3. Exfiltration
    4. Reconnaissance

Correct Answer: 1

Explanation:

Scheduled tasks, services, and startup registry entries are common persistence mechanisms because they allow malicious code to execute again after reboot, logon, or interruption. Multiple persistence techniques on one endpoint may indicate that the attacker wanted redundant methods for maintaining access. Discovery is used to learn about systems and accounts, exfiltration involves removing data, and reconnaissance generally concerns information gathering. During eradication, analysts must remove all persistence mechanisms rather than deleting only the primary payload. The SOC should also search other systems for equivalent scheduled tasks, services, registry changes, and filenames because the attacker may have deployed the same persistence strategy throughout the environment.

Question 98.

Which incident-response action should normally occur after containment but before normal business operations are restored?

  1. Ignore remaining persistence because the host is isolated
    2. Eradicate malware, persistence, and the underlying cause
    3. Delete investigation records
    4. Disable monitoring

Correct Answer: 2

Explanation:

After containment limits the immediate spread or impact of an incident, the team should eradicate the malicious components and underlying causes. Eradication may include removing malware, persistence mechanisms, unauthorized accounts, malicious scheduled tasks, or compromised credentials and patching exploited vulnerabilities. Simply isolating a host is not sufficient because reconnecting it without eliminating the attacker’s foothold could immediately reintroduce the threat. Investigation records and monitoring should be preserved, not removed. Depending on the severity of compromise, rebuilding from a known-good image may provide greater assurance than manually cleaning the system. Recovery should begin only after the team has sufficient confidence that the threat has been removed.

Question 99.

Which activity belongs primarily to the recovery phase of incident response?

  1. Restoring cleaned or rebuilt systems to production and monitoring them closely
    2. Creating the incident-response plan for the first time
    3. Gathering pre-incident threat intelligence only
    4. Purchasing employee laptops

Correct Answer: 1

Explanation:

Recovery focuses on safely returning systems and services to normal operation after containment and eradication have addressed the active threat. Activities may include restoring data, rebuilding systems, validating security controls, reconnecting hosts to production networks, and closely monitoring for recurrence. A system should not simply be reconnected because malware files were deleted; the organization needs confidence that persistence, compromised credentials, and exploited weaknesses were addressed. Preparation occurs before an incident, while threat intelligence can support multiple phases. Careful post-recovery monitoring is essential because renewed command-and-control traffic or suspicious authentication may reveal that eradication was incomplete.

Question 100.

After a major incident, the SOC determines that several important log sources were unavailable during the investigation. What should be the highest-priority post-incident improvement?

  1. Reduce log collection further to save storage
    2. Delete existing incident evidence
    3. Improve telemetry coverage, retention, and monitoring for the missing sources
    4. Disable correlation rules until the next incident

Correct Answer: 3

Explanation:

Missing telemetry is a significant detection and investigation gap. The post-incident review should identify which logs were unavailable, why they were missing, and what changes are needed to ensure future collection and retention. This could involve enabling endpoint process telemetry, improving identity logging, sending firewall or proxy events to the SIEM, increasing retention, fixing parsing, or monitoring ingestion health. The organization should also verify that timestamps are synchronized and that important fields are normalized correctly. Reducing logging or deleting evidence would make future investigations more difficult. Lessons learned are most valuable when they result in measurable defensive improvements, such as stronger telemetry, updated detection rules, improved playbooks, and clearer ownership for monitoring failures.