View Full Cisco CCNP CyberSecurity 300-215 Exam Dumps and Practice Test Dumps
Question 141.
A SOC analyst receives an alert that an endpoint contacted a domain associated with a malware campaign. Which action should the analyst perform first to determine whether the alert represents a true compromise?
- Correlate the domain access with endpoint process, DNS, proxy, and user activity
2. Reimage the endpoint immediately
3. Disable all DNS services
4. Delete the alert after blocking the domain
Correct Answer: 1
Explanation:
The analyst should first correlate the domain access with additional telemetry to determine what generated the communication and whether malicious activity actually occurred. DNS logs can show name resolution, proxy or firewall logs can confirm connections, and EDR telemetry can reveal the initiating process, command line, user context, and related file activity. A known malicious domain is a strong indicator, but false positives are still possible because infrastructure may change ownership or be accessed indirectly through security tools. Reimaging before investigation can destroy useful evidence. Blocking the domain may be appropriate as containment, but analysts should still establish scope, identify affected hosts, and determine whether the endpoint executed malware or merely attempted communication.
Question 142.
Which telemetry source is most useful for identifying whether a suspicious process injected code into another process on an endpoint?
- DHCP logs
2. Endpoint detection and response telemetry
3. Printer spooler records
4. Physical access logs
Correct Answer: 2
Explanation:
Endpoint detection and response telemetry can provide visibility into process creation, memory-related behavior, process injection indicators, parent-child relationships, file access, registry changes, and network connections. These details are essential when investigating whether one process manipulated another process to hide malicious execution. DHCP logs provide IP-address assignment history but do not reveal process-level activity. Printer and physical access records are similarly unrelated. Process injection is often used for defense evasion or privilege-related activity, so analysts should investigate the source process, destination process, user context, loaded modules, network behavior, and any persistence mechanisms. Correlating these artifacts helps determine whether the behavior is malicious or the result of legitimate security or administrative software.
Question 143.
An analyst observes one endpoint attempting SMB connections to dozens of internal hosts within a few minutes. Which activity is most likely?
- Routine DNS resolution
2. Local file indexing
3. Lateral movement or internal discovery
4. NTP synchronization
Correct Answer: 3
Explanation:
Rapid SMB connections to many internal systems can indicate lateral movement, share enumeration, or internal discovery. Attackers often use SMB to identify accessible shares, authenticate to remote systems, or move tools and payloads between hosts. Legitimate management or vulnerability-scanning systems may also generate broad SMB activity, so context matters. The analyst should review the source endpoint role, user account, authentication events, process telemetry, destination systems, and whether remote service creation or file transfers followed the connection attempts. DNS and NTP have different network patterns, while local indexing does not explain wide-ranging SMB communication. Behavioral baselines can help distinguish authorized administrative activity from compromise.
Question 144.
Which evidence would most strongly support the conclusion that SMB activity represents malicious lateral movement rather than authorized administration?
- The source host runs Windows
2. The destination systems are in the same subnet
3. The source user has an Active Directory account
4. A previously compromised workstation authenticates to many servers and creates remote services immediately afterward
Correct Answer: 4
Explanation:
The combination of prior compromise, unusual authentication to many servers, and remote service creation provides strong evidence of lateral movement. Any single behavior may have a legitimate explanation, but together they form a suspicious sequence commonly associated with remote execution techniques. Simply running Windows, being in the same subnet, or using Active Directory is normal in enterprise environments. Analysts should inspect the account used, source process, service names, executable paths, timestamps, and whether the same service or payload appears on multiple systems. The incident should also be scoped for additional affected hosts because lateral movement usually indicates the attacker is expanding beyond the original endpoint.
Question 145.
A threat hunter wants to identify endpoints where a scripting interpreter was launched from an unusual parent process. Which approach is most effective?
- Search EDR process-tree data for anomalous parent-child relationships
2. Review monitor inventory records
3. Search only DHCP logs
4. Disable script logging
Correct Answer: 1
Explanation:
EDR process-tree data is well suited to identifying unusual parent-child relationships such as Office applications, browsers, or archive utilities unexpectedly launching PowerShell, command shells, or other scripting interpreters. Such behavior can indicate phishing execution, exploitation, or malware staging. Analysts should consider command-line arguments, user context, file origin, signature status, network activity, and whether the behavior deviates from the endpoint’s normal baseline. DHCP data cannot show process relationships, and disabling script logging would reduce visibility. Behavioral hunting is valuable because attackers can easily change file hashes but may still rely on similar execution techniques across different malware variants.
Question 146.
Which security concept describes converting raw log data from different vendors into a consistent set of fields before correlation?
- Tokenization
2. Normalization
3. Sandboxing
4. Encapsulation
Correct Answer: 2
Explanation:
Normalization converts logs from multiple vendors and platforms into a common structure so fields such as source IP, destination IP, username, hostname, process, and timestamp can be queried consistently. This is important in SIEM environments because each product may use different naming conventions and formats. Normalization improves correlation, dashboards, alert logic, and automated enrichment. It does not by itself determine whether activity is malicious; it simply makes heterogeneous telemetry easier to analyze. Analysts should still preserve access to raw events because some vendor-specific details may not map cleanly into the normalized schema and may be required during deeper investigation.
Question 147.
A SOC rule correlates a phishing email, suspicious PowerShell execution, and an outbound connection to a rare domain within ten minutes. What advantage does this provide over separate alerts?
- It guarantees zero false positives
2. It eliminates the need for endpoint telemetry
3. It provides attack-chain context and can increase confidence and priority
4. It prevents all malware execution
Correct Answer: 3
Explanation:
Correlating related events creates a more complete view of the attack chain. A phishing email alone may be suspicious, PowerShell execution may be legitimate, and a rare outbound domain may also have a benign explanation. When these events occur on the same endpoint within a short time window, the combined context significantly increases confidence that malicious activity may be occurring. Correlation can improve prioritization and reduce fragmented investigations, but it does not guarantee zero false positives or prevent execution by itself. Good correlation depends on accurate timestamps, consistent identifiers, normalized data, and reliable telemetry across email, endpoint, identity, and network systems.
Question 148.
Which type of analysis compares current behavior with previously established normal patterns for a user, host, or application?
- Static signature matching
2. File carving
3. Packet fragmentation
4. Behavioral baselining
Correct Answer: 4
Explanation:
Behavioral baselining establishes what normal activity looks like for users, systems, applications, or networks and then helps identify meaningful deviations. Examples include a user logging in from unusual locations, a workstation suddenly accessing many servers, or an application making connections to destinations it has never contacted before. Baselining does not automatically mean that every deviation is malicious because legitimate business behavior changes over time. It provides investigative context that can increase or reduce alert priority. Static signatures are useful for known patterns, but behavioral baselines are often more effective for detecting account misuse and attacker activity that uses legitimate tools.
Question 149.
A security analyst sees a user account authenticate at 3:00 AM from a system the user has never used before. Which factor would most increase the alert’s severity?
- The account has privileged access to critical servers
2. The user’s monitor is old
3. The endpoint uses DHCP
4. The login occurs over TCP
Correct Answer: 1
Explanation:
Privileged access significantly increases the potential impact of account compromise. An unusual login time and unfamiliar source host are already suspicious, but if the account can administer critical systems, the risk becomes much greater. Analysts should review MFA events, source IP reputation, device identity, the user’s normal behavior, authentication type, and subsequent actions. The account may need temporary restriction if compromise is likely. DHCP use and TCP transport are normal and do not meaningfully increase severity. Prioritization should consider both likelihood and business impact, including privilege level, asset sensitivity, and evidence of follow-on activity.
Question 150.
Which threat-intelligence characteristic describes how recently an indicator was observed in malicious activity?
- Scope
2. Freshness
3. Availability
4. Persistence
Correct Answer: 2
Explanation:
Freshness refers to how recent the intelligence is. It matters because domains, IP addresses, and hosting infrastructure can change quickly. An IP address associated with malware six months ago may now host a legitimate service, while an IP observed in active command-and-control traffic yesterday may be far more actionable. Analysts should therefore consider freshness together with confidence, source reliability, context, and severity. Older intelligence can still be valuable for historical searches or campaign analysis, but it may be less appropriate for automatic blocking. Mature threat-intelligence processes attach timestamps and confidence information to indicators so security systems can make more informed decisions.
Question 151.
An analyst wants to understand whether a suspicious IP address has historically hosted several malicious domains. Which intelligence source is particularly useful?
- Passive DNS data
2. Monitor inventory
3. Printer queue logs
4. BIOS settings
Correct Answer: 1
Explanation:
Passive DNS data records historical relationships between domain names and IP addresses. It can show which domains resolved to an IP over time and which IP addresses a domain previously used. This helps analysts identify infrastructure relationships, discover additional campaign indicators, and assess whether an IP has repeatedly hosted suspicious domains. Passive DNS should be combined with registration information, certificate data, reputation, and timestamps because shared hosting can place many unrelated domains on the same IP. Hardware and printer information do not provide infrastructure history. Analysts can use these relationships to expand hunts beyond the original indicator and uncover related malicious infrastructure.
Question 152.
Which pattern most strongly suggests DNS-based command-and-control activity?
- One DNS query to a well-known corporate service
2. A workstation repeatedly querying long, high-entropy subdomains under one rare domain
3. A DHCP server renewing leases
4. An endpoint querying its configured DNS server
Correct Answer: 2
Explanation:
Repeated long, high-entropy subdomain queries to a rare domain can indicate DNS tunneling or DNS-based command-and-control activity. Attackers may encode identifiers, commands, or data into DNS labels because DNS traffic is often permitted through network controls. Analysts should examine query frequency, domain age, entropy, record types, response patterns, and the endpoint process responsible. Legitimate services can generate complex subdomains, so the pattern requires validation rather than immediate classification as malicious. Baseline comparison is useful because unusual query lengths or frequency may stand out when compared with typical enterprise DNS behavior.
Question 153.
Which type of network telemetry provides metadata about communications without necessarily storing complete packet payloads?
- Full packet capture
2. Disk image
3. NetFlow
4. Memory dump
Correct Answer: 3
Explanation:
NetFlow and similar flow technologies provide communication metadata such as source IP, destination IP, ports, protocol, timestamps, duration, and byte or packet counts. This makes them valuable for identifying unusual communication patterns, large transfers, scanning, or command-and-control activity across large environments. Unlike full packet capture, flow telemetry generally does not contain complete application payloads. This makes it more storage-efficient but less suitable when investigators need exact transmitted content. Disk images and memory dumps provide host forensic information rather than network-flow metadata. Analysts often combine NetFlow with DNS, firewall, proxy, and endpoint telemetry to build a complete picture of an incident.
Question 154.
What is the primary investigative advantage of full packet capture over NetFlow?
- It always requires less storage
2. It contains packet-level content and protocol details that flow records may not retain
3. It automatically identifies every attacker
4. It eliminates the need for endpoint logs
Correct Answer: 2
Explanation:
Full packet capture preserves packet-level information and, when traffic is not encrypted, may include actual application content, headers, commands, transferred files, and protocol details. NetFlow is more compact and scalable but primarily provides metadata. Packet capture can therefore support deeper protocol and payload analysis. The trade-off is substantially higher storage requirements and potential privacy considerations. Encrypted traffic may still limit payload visibility even in packet capture, although metadata remains useful. Packet capture does not automatically identify attackers and cannot replace endpoint or identity telemetry. The strongest investigations combine multiple sources because each provides different types of evidence.
Question 155.
An investigator acquires a forensic image of a storage device. Which action best supports evidence integrity?
- Calculate and record a cryptographic hash of the acquired image
2. Rename the evidence repeatedly
3. Modify suspicious files before analysis
4. Delete unrelated directories
Correct Answer: 1
Explanation:
A cryptographic hash creates a reproducible value based on the content of the forensic image. Recording the hash at acquisition and verifying it later helps demonstrate that the image has not changed during storage, transfer, or analysis. This is a foundational forensic integrity practice and complements chain-of-custody documentation. Renaming evidence provides no meaningful integrity assurance, while modifying or deleting files before analysis would compromise the evidence. Investigators typically preserve the original media and analyze validated copies. The acquisition tool, operator, date and time, evidence identifier, hash values, and storage location should be documented according to organizational procedures.
Question 156.
Which forensic device helps prevent accidental writes to an original storage drive during evidence acquisition?
- Network tap
2. Packet broker
3. Load balancer
4. Write blocker
Correct Answer: 4
Explanation:
A write blocker prevents the forensic workstation from modifying the original storage device while evidence is being acquired. This helps preserve timestamps, metadata, and file-system contents so the source remains as unchanged as possible. Hardware or validated software write-blocking mechanisms may be used depending on the investigation. Network taps and packet brokers are used for network visibility, while load balancers distribute traffic across systems. A write blocker does not eliminate the need for hashing or chain-of-custody documentation. Investigators should still validate the acquisition and ensure evidence is stored securely with controlled access.
Question 157.
Which incident-response action is most appropriate when an endpoint is confirmed to be actively exfiltrating sensitive information?
- Contain or isolate the endpoint according to the incident-response plan
2. Allow the transfer to continue indefinitely
3. Delete all logs before isolation
4. Disable security monitoring
Correct Answer: 1
Explanation:
Active data exfiltration requires timely containment to limit further loss. Depending on organizational procedures, containment may involve EDR network isolation, firewall blocking, account restrictions, switch controls, or physical disconnection. The response team should still consider evidence preservation, especially volatile data that may be lost during shutdown. Allowing the transfer to continue creates additional risk, while deleting logs or disabling monitoring removes valuable visibility. After containment, analysts should determine what data was accessed, how the attacker obtained access, which credentials were compromised, and whether other systems are involved. Eradication and recovery should address the underlying cause rather than only stopping the immediate transfer.
Question 158.
Which incident-response phase includes removing malicious persistence, resetting compromised credentials, and patching the exploited vulnerability?
- Preparation
2. Eradication
3. Detection only
4. Lessons learned
Correct Answer: 2
Explanation:
Eradication focuses on removing the attacker and addressing the mechanisms that allowed compromise to persist. This can include deleting malware, removing scheduled tasks or malicious services, resetting compromised accounts, revoking tokens, patching vulnerabilities, and removing unauthorized tools. Preparation occurs before incidents, while lessons learned follows recovery. Detection and analysis establish what happened but do not by themselves eliminate the threat. Eradication must be thorough because leaving behind a single persistence method or valid stolen credential may allow the attacker to regain access. Depending on the severity of compromise, rebuilding systems from trusted images may provide greater confidence than manually cleaning them.
Question 159.
During recovery, why should a previously compromised system be monitored more closely after it is returned to production?
- To detect signs that eradication was incomplete or the attacker regained access
2. To reduce the amount of available telemetry
3. To prevent administrators from logging in
4. To eliminate the need for patching
Correct Answer: 1
Explanation:
A system that has recently been compromised deserves enhanced monitoring because recurrence may indicate an overlooked persistence mechanism, an unrevoked credential, or an unaddressed vulnerability. Recovery includes validating that the system is functioning securely, reconnecting it to normal operations, and watching for command-and-control activity, suspicious authentication, unusual processes, or other indicators associated with the original incident. Monitoring does not replace patching or remediation; it verifies that those actions were effective. Analysts should define an appropriate observation period based on the incident’s severity and may also continue hunting for related behavior across the broader environment.
Question 160.
A post-incident review shows that analysts discovered the attack only because a user reported unusual behavior. Which improvement should receive the highest priority?
- Reduce endpoint logging to save storage
2. Disable behavioral detections
3. Develop and validate detections for the observed attack techniques using available telemetry
4. Stop conducting threat hunts
Correct Answer: 3
Explanation:
If user reporting was the only reason the attack was discovered, the organization likely has a detection gap. The post-incident review should identify the specific techniques used by the attacker, determine which telemetry contains evidence of those behaviors, and develop or improve automated detection logic. This might involve EDR process rules, identity analytics, SIEM correlations, DNS detections, or behavioral baselines. The new detections should be tested against historical and simulated data to ensure they identify meaningful activity without creating excessive noise. Reducing logging or disabling hunting would worsen visibility. Lessons learned are most valuable when they result in concrete improvements that shorten detection and response time during future incidents.