Cisco CCNP CyberSecurity 300-215 Practice Test Questions and Exam Dumps Part16 Q301-320

View Full Cisco CCNP CyberSecurity 300-215 Exam Dumps and Practice Test Dumps

 

Question 301.

A SOC analyst observes a service account authenticating interactively to several workstations even though the account is normally used only by a backend application. What is the most appropriate interpretation?

  1. The activity may indicate credential misuse and should be investigated
    2. The behavior is normal for every service account
    3. The event is caused by routine DNS resolution
    4. The workstations should be ignored because they are not servers

Correct Answer: 1

Explanation:

Service accounts usually have predictable usage patterns and are often restricted to specific applications or systems. Interactive logins from a service account can therefore be suspicious, especially when they occur on multiple endpoints. The analyst should review the source systems, authentication types, privilege level, timing, and processes launched after each login. The account may have been compromised and used for lateral movement. Historical baselines and identity logs can help determine whether the activity represents a legitimate administrative exception or abuse. DNS activity does not explain interactive authentication. If misuse is confirmed, the account should be contained according to incident-response procedures and its credentials rotated.

Question 302.

Which telemetry source would best show whether the service account executed commands after logging in to a workstation?

  1. DHCP logs
    2. Endpoint process telemetry
    3. Printer queue records
    4. Building access logs

Correct Answer: 2

Explanation:

Endpoint process telemetry can show the executables launched under the service account, command-line arguments, parent-child relationships, file paths, hashes, and network activity. This is the most direct way to determine what occurred after authentication. DHCP logs may help associate an IP address with a device but do not show executed commands. Printer and physical-access records are unrelated. Analysts should correlate process telemetry with login timestamps and identity data so they can reconstruct the sequence accurately. Unexpected script interpreters, remote administration tools, or credential-access utilities following a service-account login would significantly increase suspicion.

Question 303.

An analyst detects powershell.exe launching with an encoded command from a scheduled task created minutes earlier. Which attacker behavior is most likely?

  1. Routine patch management
    2. Normal DNS administration
    3. Persistence using a scheduled task
    4. Physical access control

Correct Answer: 3

Explanation:

A newly created scheduled task that launches encoded PowerShell is consistent with persistence, especially when the task appears immediately before or after other suspicious activity. Scheduled tasks are commonly used legitimately, so the analyst should review who created the task, its trigger, command line, parent process, execution account, and related network activity. Encoded PowerShell can also be legitimate, but attackers frequently use encoding to obscure malicious commands. The combination of a new task and suspicious script execution is more meaningful than either event alone. Analysts should also hunt for similar task names or command patterns across other systems.

Question 304.

Which detection strategy would best identify suspicious scheduled-task persistence across many endpoints?

  1. Search only for one known task name
    2. Ignore all administrator-created tasks
    3. Alert on every scheduled task without context
    4. Correlate unusual task creation with command lines, users, parent processes, and execution behavior

Correct Answer: 4

Explanation:

Scheduled tasks are widely used for legitimate administration and software operations, so an alert on every task would produce excessive noise. A stronger strategy evaluates context such as unusual task names, encoded commands, suspicious executables, unexpected user accounts, abnormal parent processes, or task creation shortly after malware activity. Searching only for one known name is too narrow because attackers can easily rename tasks. Ignoring administrator-created tasks is also dangerous because compromised privileged credentials are often abused. Behavioral correlation provides broader and more durable coverage.

Question 305.

A host starts communicating with a rare external domain immediately after a new scheduled task executes. Which next step provides the best investigative value?

  1. Correlate the task execution with the process responsible for the external connection
    2. Replace the endpoint monitor
    3. Disable DHCP for the host
    4. Delete the task before collecting evidence

Correct Answer: 1

Explanation:

The analyst should determine whether the scheduled task launched the process responsible for the external communication. EDR telemetry can show the task-triggered process tree, command-line arguments, user context, and network connection. DNS, proxy, or firewall logs can add destination details and confirm whether the communication succeeded. Replacing hardware or changing DHCP does not address the suspected compromise. Deleting the task immediately may remove valuable evidence before the attack chain is understood. Correlation between persistence and command-and-control activity can significantly increase confidence in the incident.

Question 306.

Which threat-intelligence property is most important when deciding whether an indicator should trigger an alert or an automatic block?

  1. The indicator’s character length
    2. Confidence and operational context
    3. The analyst’s preferred dashboard
    4. Whether the IP address responds to ping

Correct Answer: 2

Explanation:

Confidence and operational context help determine how aggressively an indicator should be handled. A high-confidence, recently observed command-and-control domain may justify an automatic block, while a lower-confidence or older indicator may be better used for alerting and enrichment. Infrastructure can change ownership or be shared by legitimate and malicious services, so blindly blocking every indicator can disrupt business activity. Ping response and formatting provide little useful information. Mature threat-intelligence workflows consider source reliability, freshness, confidence, campaign context, and possible business impact before selecting an automated action.

Question 307.

Which source would best help an analyst discover other domains associated with the same TLS certificate used by a suspicious website?

  1. Certificate transparency or threat-intelligence data
    2. Local printer logs
    3. DHCP reservations
    4. Endpoint wallpaper settings

Correct Answer: 1

Explanation:

Certificate transparency and threat-intelligence platforms can reveal certificates, subject names, issuers, serial numbers, and other domains associated with the same certificate or related infrastructure. This can help analysts expand an investigation beyond the original domain and identify additional campaign infrastructure. However, certificate reuse can also occur legitimately, especially with shared hosting and cloud services, so findings should be validated with passive DNS, domain registration data, hosting context, and observed activity. Printer, DHCP, and desktop settings do not provide certificate relationships.

Question 308.

Which pattern most strongly suggests a malicious domain is being used for command-and-control rather than ordinary browsing?

  1. One request from a browser during normal work
    2. A recurring low-volume connection from the same unusual process to the domain
    3. The domain supports HTTPS
    4. The domain has a valid certificate

Correct Answer: 2

Explanation:

Recurring low-volume communication from the same unusual process is more consistent with automated command-and-control behavior than ordinary interactive browsing. Analysts should examine periodicity, destination rarity, process identity, domain age, certificate details, byte counts, and whether the same pattern exists on other systems. HTTPS and valid certificates do not prove legitimacy because attackers regularly use encrypted protocols and publicly trusted certificates. Likewise, a single browser request may be entirely benign. Correlating endpoint process telemetry with network behavior provides the strongest context.

Question 309.

An analyst sees a host sending DNS queries with long, high-entropy subdomains every few seconds. Which threat technique should be considered?

  1. DNS tunneling
    2. ARP inspection
    3. DHCP snooping
    4. Static routing

Correct Answer: 1

Explanation:

Long, high-entropy subdomains generated repeatedly can indicate DNS tunneling, where data or command-and-control messages are encoded within DNS queries and responses. The analyst should review query length, frequency, domain reputation, record types, response behavior, and the process responsible for generating the traffic. Some legitimate applications also create complex DNS names, so anomaly detection must be combined with context. DNS tunneling can be used for covert communication or exfiltration because DNS is often broadly permitted. Endpoint and DNS telemetry together provide the best basis for validation.

Question 310.

Which data source would best help identify the endpoint process generating suspicious DNS requests?

  1. Physical access control logs
    2. Endpoint telemetry with process-to-DNS or process-to-network visibility
    3. Printer server logs
    4. UPS monitoring data

Correct Answer: 2

Explanation:

Endpoint telemetry that associates DNS or network events with processes can show exactly which executable generated suspicious requests. This is especially valuable when multiple applications use DNS at the same time. Analysts can review the process path, hash, parent process, command line, user context, and related file or persistence activity. DNS server logs show which client issued a query but typically do not identify the local initiating process. Physical access, printer, and power records do not provide relevant process-level information.

Question 311.

A compromised endpoint starts scanning internal hosts and shares after receiving a command from an external server. Which MITRE ATT&CK tactic best describes the scanning behavior?

  1. Discovery
    2. Collection
    3. Persistence
    4. Impact

Correct Answer: 1

Explanation:

Discovery includes techniques used to learn about the compromised environment, such as enumerating hosts, services, users, shares, and network configuration. Attackers often perform discovery before selecting lateral-movement targets or valuable data sources. Collection refers to gathering target data, Persistence maintains access, and Impact relates to disruption. When discovery occurs immediately after command-and-control communication, it can strongly indicate active attacker direction. Analysts should identify the process and commands responsible and then determine whether authentication or remote execution followed.

Question 312.

Which MITRE ATT&CK tactic best describes an attacker using stolen credentials to access additional systems?

  1. Initial Access
    2. Lateral Movement
    3. Reconnaissance
    4. Impact

Correct Answer: 2

Explanation:

Lateral Movement covers techniques used to move from one compromised system to other systems in the environment. Stolen credentials are frequently used with remote services, administrative shares, or remote management tools to expand access. Initial Access refers to the first foothold, Reconnaissance is information gathering, and Impact concerns disruption or destruction. Analysts should correlate authentication events with source and destination hosts, process execution, privilege levels, and subsequent activity. Mapping the activity to ATT&CK helps defenders understand the attacker’s progression and identify detection gaps.

Question 313.

An analyst observes a privileged account authenticating to a file server followed by bulk access to sensitive documents. Which additional event would most strongly indicate exfiltration preparation?

  1. Creation of a large compressed archive containing the accessed files
    2. A DHCP lease renewal
    3. An internal DNS query
    4. A routine NTP synchronization

Correct Answer: 1

Explanation:

Bulk access followed by archive creation is strongly consistent with data staging. Attackers often gather files and compress them before exfiltration because a single archive is easier to transfer and may reduce visibility. The analyst should identify the process that created the archive, where it was stored, whether it was encrypted, and whether an outbound transfer followed. Legitimate backup or archival tools can produce similar behavior, so user role and business context are important. DHCP, DNS, and NTP activity do not meaningfully support the staging hypothesis.

Question 314.

Which telemetry would best confirm whether a staged archive was transferred through an external cloud-storage service?

  1. BIOS logs
    2. Secure web gateway, proxy, or cloud-access telemetry
    3. Printer spooler logs
    4. Monitor inventory

Correct Answer: 2

Explanation:

Secure web gateway, proxy, or cloud-access telemetry can reveal the destination application or service, source user or endpoint, timestamps, transfer size, URLs, and sometimes upload actions. If TLS inspection or application-aware controls are available, even more detail may be visible. Analysts should correlate the network session with the archive creation time and the process responsible for the upload. BIOS and printer records do not provide this visibility. Combining host and network evidence is the best way to confirm whether staged data actually left the organization.

Question 315.

During live-response collection, which evidence should generally be prioritized because it may disappear when the system is shut down?

  1. Volatile memory
    2. Printed incident documentation
    3. Archived asset records
    4. Purchase invoices

Correct Answer: 1

Explanation:

Volatile memory can contain running processes, network connections, injected code, credentials, encryption keys, and other transient information that disappears when power is removed. If the investigation requires these artifacts and organizational procedures permit collection, memory should be captured before shutdown. Responders must still balance forensic value with containment because a live compromised system may continue causing damage. Persistent records can be collected later. The memory image should be documented, hashed, and protected appropriately if it will be used as formal evidence.

Question 316.

Which forensic control best helps prevent changes to an original storage device while it is being imaged?

  1. SIEM correlation rule
    2. Firewall policy
    3. VPN tunnel
    4. Write blocker

Correct Answer: 4

Explanation:

A write blocker prevents the acquisition workstation from writing data to the original storage media. This helps preserve metadata, timestamps, deleted-file structures, and other evidence. It is commonly used when creating forensic images. A write blocker should be combined with cryptographic hashing, chain-of-custody documentation, secure storage, and analysis on verified copies. SIEM rules, firewall policies, and VPNs have unrelated functions. Preserving the original evidence is fundamental to a reliable and defensible forensic investigation.

Question 317.

A compromised workstation is actively attempting remote logins to multiple servers. Which response action should be prioritized once necessary volatile evidence is collected?

  1. Isolate the workstation to limit lateral movement
    2. Perform the final lessons-learned meeting
    3. Delete all authentication logs
    4. Disable endpoint monitoring

Correct Answer: 1

Explanation:

Active remote-login attempts from a compromised workstation create immediate risk of lateral movement. Once required volatile evidence is preserved, isolating the host can stop further authentication attempts, command-and-control communication, or malware spread. Containment methods may include EDR isolation, firewall controls, switch changes, or physical disconnection. Deleting logs or disabling monitoring would reduce visibility. After containment, analysts should identify accounts used, affected servers, persistence mechanisms, and any systems already compromised.

Question 318.

Which action belongs primarily to eradication after a compromised host has been isolated?

  1. Reconnecting the system immediately
    2. Removing malware, persistence, stolen credentials, and exploited weaknesses
    3. Performing annual security awareness training
    4. Writing the initial incident-response policy

Correct Answer: 2

Explanation:

Eradication removes the attacker’s footholds and addresses the root cause. This can include deleting malware, removing scheduled tasks or malicious services, resetting compromised credentials, revoking sessions, and patching exploited vulnerabilities. Isolation is containment and only limits ongoing activity. Training and policy creation are preparation-related tasks. Recovery should not begin until the response team has reasonable confidence that malicious access has been eliminated. In severe cases, rebuilding the system from a trusted image may be safer than manual cleanup.

Question 319.

Which action belongs primarily to recovery after eradication has been completed successfully?

  1. Restore validated systems to production and monitor for recurrence
    2. Disable security logging
    3. Restore compromised credentials unchanged
    4. Recreate malicious scheduled tasks

Correct Answer: 1

Explanation:

Recovery focuses on returning systems and services to normal operation safely. Systems should be validated, patched, protected, and monitored closely after reconnection. Compromised credentials should already have been addressed, and security controls should remain enabled. Enhanced monitoring is particularly important because renewed beaconing or suspicious authentication may indicate incomplete eradication. Recovery balances business restoration with assurance that the attacker no longer retains access.

Question 320.

A post-incident review finds that the SOC identified suspicious behavior quickly but containment was delayed because analysts were unsure who was authorized to isolate production systems. Which improvement is most appropriate?

  1. Reduce alert severity levels
    2. Disable automatic enrichment
    3. Define clear containment authority, escalation paths, and response playbooks
    4. Shorten log retention

Correct Answer: 3

Explanation:

Technical detection is only useful if the organization can act quickly. Clear containment authority and escalation paths ensure analysts know who can approve actions such as endpoint isolation, account disabling, firewall blocking, or production-service interruption. Playbooks should define thresholds, required evidence, communication steps, and emergency exceptions. Regular exercises can validate that personnel understand their roles. Reducing alert severity or telemetry retention would not solve the decision-making delay. Post-incident reviews should convert operational uncertainty into explicit procedures so future response actions occur faster and more consistently.