Cisco CCNP CyberSecurity 300-215 Practice Test Questions and Exam Dumps Part6 Q101-120

View Full Cisco CCNP CyberSecurity 300-215 Exam Dumps and Practice Test Dumps

 

Question 101.

A SOC analyst sees an endpoint making repeated outbound connections to an unfamiliar external IP address every 90 seconds. Which next step provides the best evidence for determining whether the traffic is malicious?

  1. Correlate the connections with the endpoint process responsible for generating them
    2. Replace the workstation network adapter
    3. Clear the user’s browser history
    4. Reset every account in the organization

Correct Answer: 1

Explanation:

Correlating the network connections with endpoint process telemetry provides critical context. The analyst can determine which executable initiated the connection, its parent process, command-line arguments, user context, file path, hash, and potentially associated file or registry activity. Regular outbound connections can represent command-and-control beaconing, but legitimate monitoring, backup, update, or management software can behave in a similar way. Process attribution helps distinguish these possibilities. Replacing hardware or clearing browser history does not address the evidence needed to classify the communication. Broad account resets are also premature without confirming credential compromise. Strong investigations correlate endpoint, firewall, DNS, proxy, and threat-intelligence data before deciding on containment or remediation.

Question 102.

Which security data source would be most useful for determining whether a suspicious executable created a new registry persistence entry on a Windows endpoint?

  1. DHCP server logs
    2. Endpoint detection and response telemetry
    3. Physical access badge logs
    4. Wireless controller channel statistics

Correct Answer: 2

Explanation:

Endpoint detection and response telemetry can often record process execution, registry modifications, file changes, persistence activity, user context, and parent-child relationships. This allows an analyst to connect a suspicious executable directly to the creation of a registry startup entry. DHCP logs are useful for associating dynamically assigned IP addresses with hosts at particular times but do not normally provide registry visibility. Badge logs provide physical access information, while wireless channel statistics relate to radio performance. Registry-based persistence should also be correlated with process creation and subsequent execution events so analysts can determine whether the entry successfully relaunched malicious code and whether the same technique appears on other systems.

Question 103.

An analyst identifies a domain used for command-and-control activity. Which action is most appropriate for determining the full scope of affected hosts?

  1. Search DNS, proxy, firewall, and endpoint telemetry for the domain and related infrastructure
    2. Disable DNS across the organization
    3. Delete all historical DNS logs
    4. Reimage every server immediately

Correct Answer: 1

Explanation:

Searching multiple telemetry sources for the malicious domain and related infrastructure helps establish incident scope. DNS logs can identify hosts that resolved the domain, proxy records can show web requests, firewall logs can reveal direct network connections, and endpoint telemetry can identify the processes responsible. Analysts should also pivot to associated IP addresses, certificates, file hashes, URLs, and similar domains if threat intelligence provides them. Disabling DNS would severely disrupt operations and would not identify historical exposure. Deleting logs destroys evidence, while reimaging every server before scoping the incident is unnecessarily disruptive. Effective incident analysis expands systematically from known indicators to related hosts, accounts, files, and behaviors.

Question 104.

A suspicious host communicates with an external service using TLS. The payload is encrypted, preventing direct content inspection. Which evidence remains useful for analysis?

  1. Only the plaintext payload
    2. Nothing can be analyzed when TLS is used
    3. The user’s monitor resolution
    4. Connection metadata such as destination, certificate information, timing, volume, and initiating process

Correct Answer: 4

Explanation:

Encrypted traffic still provides significant metadata that can support security analysis. Analysts can examine destination IP addresses, domain names, TLS certificates, connection frequency, session duration, byte counts, timing patterns, and the endpoint process responsible for the traffic. Certificate reuse, rare destinations, newly registered domains, and periodic connections can all strengthen a malicious hypothesis. Endpoint telemetry may also reveal the executable generating the encrypted session. TLS prevents straightforward inspection of application content unless appropriate decryption capabilities exist, but it does not make the communication invisible. Analysts should combine metadata with DNS, EDR, proxy, identity, and threat-intelligence evidence rather than assume encrypted traffic cannot be investigated.

Question 105.

Which activity most directly helps identify whether multiple alerts involving the same username, endpoint, and external IP address belong to one coordinated incident?

  1. Event correlation
    2. Disk defragmentation
    3. Network cabling replacement
    4. Software licensing review

Correct Answer: 1

Explanation:

Event correlation connects related security events based on attributes such as usernames, IP addresses, hostnames, processes, timestamps, domains, and alert identifiers. Multiple alerts may appear unrelated when viewed individually but can form a coherent attack sequence when correlated. For example, a phishing event could be followed by suspicious process execution, outbound command-and-control traffic, and unusual authentication activity from the same endpoint. Correlation can be performed manually by an analyst or automatically by a SIEM or analytics platform. Hardware maintenance and licensing reviews do not establish relationships between security events. Effective correlation helps reduce fragmented investigation and allows analysts to understand attack progression and incident scope.

Question 106.

A SIEM rule generates a high-severity alert because a privileged account logged in from a new country. Which factor should the analyst evaluate before declaring the account compromised?

  1. The user’s monitor size
    2. VPN usage, source IP reputation, MFA events, and normal travel behavior
    3. Printer queue length
    4. Disk partition layout

Correct Answer: 2

Explanation:

Geolocation anomalies can indicate credential compromise, but they require contextual validation. VPNs, mobile carriers, cloud services, and corporate proxies can cause authentication to appear from unexpected locations. The analyst should review source IP reputation, device identity, MFA activity, impossible-travel timing, user behavior, and whether the account performed unusual actions after authentication. A privileged account deserves elevated scrutiny because compromise could have significant impact, but geolocation alone is not definitive evidence. Hardware and printer information are unrelated. Security analysis should combine multiple independent signals before containment actions are taken, especially when those actions could disrupt legitimate administrators.

Question 107.

Which evidence would best support the conclusion that a phishing attachment resulted in malicious code execution?

  1. An Office application spawning a script interpreter or command shell shortly after the attachment was opened
    2. The user’s workstation has a large SSD
    3. The email contained an attachment name ending in .docx
    4. The user is assigned to a particular office floor

Correct Answer: 1

Explanation:

A process chain showing an Office application spawning PowerShell, cmd.exe, a script interpreter, or another unusual child process shortly after an attachment was opened provides strong evidence of code execution. Analysts should inspect the full command line, file origin, child processes, network activity, persistence changes, and downloaded payloads. The attachment extension alone does not prove execution because many legitimate documents use standard formats. Hardware characteristics and office location are also unrelated. Email gateway data, endpoint process telemetry, and proxy or DNS records can be combined to reconstruct the sequence from message delivery to code execution and subsequent attacker activity.

Question 108.

An analyst finds a suspicious executable with a valid digital signature. What is the correct interpretation?

  1. The file must be safe
    2. The file cannot communicate externally
    3. The endpoint must be reimaged immediately without further analysis
    4. The signature is useful context but does not prove the file is benign

Correct Answer: 4

Explanation:

A valid digital signature can indicate that a file was signed by a particular certificate and has not been modified since signing, but it does not guarantee that the software is trustworthy. Attackers may steal code-signing certificates, compromise legitimate vendors, abuse signed utilities, or use legitimate signed applications for malicious purposes. The analyst should still examine reputation, certificate status, execution path, parent process, command line, network behavior, and other telemetry. Conversely, unsigned software is not automatically malicious either. Digital signatures are one contextual signal among many. Security conclusions should be based on combined behavioral, reputational, and environmental evidence rather than a single property.

Question 109.

Which process would be most useful for identifying whether a newly discovered malicious technique occurred before a detection rule was created?

  1. Retrospective hunting
    2. Asset disposal
    3. Password expiration
    4. Network rack labeling

Correct Answer: 1

Explanation:

Retrospective hunting uses historical telemetry to search for indicators or behaviors that were not recognized as malicious when they originally occurred. Once analysts discover a new technique, process pattern, domain, file characteristic, or command line, they can search retained endpoint, SIEM, DNS, proxy, or firewall data for earlier occurrences. This can reveal previously undetected compromise and help establish the true timeline and scope of an incident. The effectiveness of retrospective hunting depends heavily on telemetry quality and retention periods. Asset disposal, password expiration, and physical labeling do not provide historical behavioral analysis. Lessons from retrospective searches can also be converted into new detection logic.

Question 110.

A threat hunter wants to test the hypothesis that attackers are using remote service creation for lateral movement. Which telemetry would be most useful?

  1. Screen-lock events only
    2. Service creation, authentication, and process execution events across endpoints
    3. Laptop battery statistics
    4. Printer supply records

Correct Answer: 2

Explanation:

Remote service creation used for lateral movement often leaves a combination of identity and endpoint artifacts. Authentication logs can show the source account and remote logon, service creation events can reveal newly installed services, and process telemetry can show which executable or command was launched. Correlating these events across source and destination hosts provides stronger evidence than examining any one source in isolation. Threat hunting should begin with a defined hypothesis and measurable telemetry. Battery statistics and printer records provide no useful insight into remote execution. If suspicious service creation is confirmed, analysts should investigate the credential used, source host, persistence, and whether the same technique affected additional endpoints.

Question 111.

Which MITRE ATT&CK tactic most closely describes an adversary attempting to move from one compromised host to another system in the environment?

  1. Lateral Movement
    2. Collection
    3. Reconnaissance
    4. Impact

Correct Answer: 1

Explanation:

The Lateral Movement tactic describes techniques adversaries use to access and control additional systems after gaining an initial foothold. Examples can include remote services, stolen credentials, administrative shares, remote desktop tools, and other methods that allow attackers to expand access. Collection focuses on gathering target data, Reconnaissance involves learning about a target or environment, and Impact covers actions intended to disrupt availability or integrity. Mapping observed behavior to ATT&CK can help analysts describe incidents consistently, identify detection gaps, and design hunts for related techniques. Detecting lateral movement early is important because it can indicate that an attacker is expanding beyond the initial compromised endpoint.

Question 112.

Which MITRE ATT&CK tactic is most closely associated with an adversary gathering files or information before exfiltration?

  1. Persistence
    2. Collection
    3. Initial Access
    4. Defense Evasion

Correct Answer: 2

Explanation:

Collection covers adversary techniques used to gather information of interest before it is transferred or otherwise used. Attackers may collect documents, browser data, email, database content, screenshots, or files from network shares. Persistence focuses on maintaining access, Initial Access concerns obtaining the first foothold, and Defense Evasion covers avoiding detection or security controls. Collection activity may generate indicators such as unusual archive creation, bulk file access, temporary staging directories, or large numbers of file reads. Analysts should correlate collection behavior with subsequent outbound transfers because staging and exfiltration often occur as related phases of an intrusion.

Question 113.

An analyst observes an attacker creating a large password-protected archive containing sensitive files shortly before an unusual outbound transfer. Which hypothesis is most reasonable?

  1. Routine operating-system patching
    2. Normal DHCP activity
    3. Data staging for exfiltration
    4. ARP resolution

Correct Answer: 3

Explanation:

Creating a large archive containing sensitive data shortly before an unusual outbound transfer is consistent with data staging and potential exfiltration. Attackers frequently compress or archive information before transfer to reduce the number of files, simplify transport, or obscure content. Encryption or password protection can further complicate inspection. The analyst should identify which process created the archive, which files were included, the account involved, where the archive was stored, and which network connection transferred it. Legitimate backup or business workflows can produce similar patterns, so context remains important. DHCP and ARP do not explain archive creation or bulk outbound transfer.

Question 114.

Which source would best help determine whether a user uploaded a sensitive archive to an external cloud-storage service?

  1. Physical badge logs
    2. Proxy or secure web gateway logs
    3. BIOS settings
    4. Keyboard layout

Correct Answer: 2

Explanation:

Proxy or secure web gateway logs can reveal access to cloud-storage domains, upload requests, transferred byte counts, usernames, URLs, and timestamps depending on the platform and encryption visibility. This makes them valuable for investigating suspected data exfiltration through web applications. Analysts should correlate the web activity with endpoint telemetry showing archive creation or file access and with identity data confirming the user account. Physical and firmware information does not establish web upload behavior. If TLS inspection is unavailable, connection metadata may still provide useful context, while endpoint telemetry can help identify the process that initiated the transfer.

Question 115.

Which forensic practice is most important when copying a disk for analysis while preserving the original evidence?

  1. Create a forensic image and verify its integrity with cryptographic hashes
    2. Open files directly on the original disk whenever possible
    3. Modify timestamps to simplify analysis
    4. Delete irrelevant files before imaging

Correct Answer: 1

Explanation:

A forensic image creates a bit-for-bit or otherwise forensically appropriate copy of storage so analysis can occur without modifying the original evidence. Cryptographic hashes help verify that the image matches the acquired source and remains unchanged during handling. Investigators generally avoid directly analyzing original evidence because normal operating-system access can alter metadata or other contents. Deleting files or changing timestamps before imaging would compromise evidence integrity. The acquisition process should be documented, and chain of custody should record who collected, transferred, stored, and analyzed the evidence. Working from verified copies protects the original and allows analysis to be repeated if required.

Question 116.

Why might an investigator use a write blocker when acquiring evidence from a storage device?

  1. To increase disk performance
    2. To remove malware automatically
    3. To encrypt the evidence
    4. To prevent writes that could modify the original evidence

Correct Answer: 4

Explanation:

A write blocker prevents the forensic workstation or acquisition software from writing data back to the original storage device. This helps preserve evidence integrity by reducing the risk that timestamps, file-system metadata, or other information will be changed during acquisition. It does not automatically remove malware, increase disk speed, or encrypt evidence. Hardware or validated software write-blocking approaches may be used depending on investigative requirements and available tools. The analyst should still document the acquisition process, calculate hashes, and maintain chain of custody. Evidence preservation is essential when findings may support legal, regulatory, disciplinary, or formal incident-response decisions.

Question 117.

A compromised endpoint is still actively communicating with command-and-control infrastructure. Which response action is normally appropriate once required volatile evidence is preserved?

  1. Isolate the endpoint from the network
    2. Allow the user to continue normal activity indefinitely
    3. Delete all logs
    4. Disable security monitoring

Correct Answer: 1

Explanation:

Once necessary volatile evidence is preserved, isolating the endpoint is a common containment action because it can prevent additional command-and-control communication, lateral movement, malware propagation, or data exfiltration. The isolation method may use EDR network containment, switch or firewall controls, or physical disconnection depending on organizational procedure. Allowing unrestricted activity can increase damage, while deleting logs or disabling monitoring destroys visibility. Incident-response teams must balance containment speed with evidence preservation, especially when active memory contains valuable information. After isolation, analysts can continue scoping the incident, identifying persistence, determining credential exposure, and planning eradication.

Question 118.

During eradication, analysts remove the malicious executable but leave the attacker’s stolen administrator credentials active. What is the primary risk?

  1. The operating system will automatically become corrupted
    2. The attacker may regain access using the compromised credentials
    3. DNS will stop functioning
    4. Every endpoint will lose its IP address

Correct Answer: 2

Explanation:

Removing malware alone is insufficient if the attacker still possesses valid credentials. Stolen administrator credentials may allow re-entry through remote services, VPN, cloud applications, management tools, or other authentication paths. Eradication therefore requires addressing all known attacker footholds, including malicious files, persistence mechanisms, exploited vulnerabilities, and compromised accounts or tokens. Credentials may need to be reset, sessions revoked, keys rotated, or access policies changed depending on scope. Analysts should also search logs for other systems accessed with the same credentials. Recovery should not proceed until the organization has reasonable confidence that the attacker no longer has a valid method of returning.

Question 119.

Which activity is most appropriate during the lessons-learned phase after a security incident?

  1. Identify detection gaps, response problems, and control improvements
    2. Delete evidence immediately
    3. Disable all monitoring to reduce noise
    4. Ignore actions that failed during the response

Correct Answer: 1

Explanation:

The lessons-learned phase should examine what happened, which controls worked, where detections failed, how efficiently the team communicated, and what changes are needed to improve future response. Useful outcomes can include new SIEM rules, updated EDR detections, improved logging, revised playbooks, stronger authentication, network segmentation, or better analyst training. The process should be evidence-based and focused on improvement rather than blame. Deleting evidence, disabling monitoring, or ignoring failures wastes the opportunity to strengthen defenses. Action items should have owners and measurable completion criteria so the review produces concrete changes rather than only a written summary.

Question 120.

A post-incident review finds that the SOC detected lateral movement only after several servers had already been compromised. Which improvement would most directly reduce detection time during a similar future attack?

  1. Remove authentication logs to reduce storage requirements
    2. Stop collecting endpoint process data
    3. Develop correlation and behavioral detections for anomalous remote authentication and execution
    4. Disable alerts involving administrative tools

Correct Answer: 3

Explanation:

Behavioral detections that correlate unusual authentication, remote execution, service creation, process activity, and deviations from normal user behavior can identify lateral movement earlier. For example, a rule might highlight a standard user authenticating to many servers followed by remote service creation or suspicious PowerShell execution. Removing identity or endpoint telemetry would make such detection harder, while ignoring administrative tools could allow attackers to hide within legitimate management mechanisms. The SOC should use the incident to identify specific missed behaviors, develop detection logic, test it against historical data, and update response procedures. Earlier detection can reduce attacker dwell time, limit the number of compromised systems, and make containment substantially easier.