Cisco CCNP CyberSecurity 300-215 Practice Test Questions and Exam Dumps Part18 Q341-360

View Full Cisco CCNP CyberSecurity 300-215 Exam Dumps and Practice Test Dumps

 

Question 341.

A SOC analyst notices that an account belonging to a departed employee successfully authenticated to an internal application. What should the analyst investigate first?

  1. Whether the account should have been disabled and whether its credentials were misused
    2. Whether the application server has enough storage
    3. Whether DHCP renewed the server lease
    4. Whether the user’s old workstation is still under warranty

Correct Answer: 1

Explanation:

An account associated with a departed employee should normally be disabled or otherwise removed from active use according to the organization’s offboarding process. A successful authentication therefore raises the possibility of an access-control failure or credential misuse. The analyst should review the account status, source IP, device, MFA activity, authentication method, resources accessed, and any actions performed after login. The event should also prompt a review of offboarding controls to determine whether other former-employee accounts remain active. Storage, DHCP, and warranty information do not explain the unauthorized authentication. If compromise is confirmed, active sessions should be revoked and the incident scoped for additional activity.

Question 342.

Which security control would most directly reduce the risk of former employees retaining access to enterprise systems?

  1. Disk encryption
    2. A formal identity deprovisioning and offboarding process
    3. Network time synchronization
    4. Printer auditing

Correct Answer: 2

Explanation:

A formal identity deprovisioning process ensures that accounts, tokens, application access, remote-access privileges, and other credentials are disabled or removed when a user leaves the organization. Offboarding should also include device return, ownership reassignment, shared-secret changes where appropriate, and validation that access has actually been revoked. Disk encryption protects stored data but does not terminate identity access. Time synchronization and printer auditing serve other purposes. Weak offboarding creates a long-lived attack surface because forgotten accounts can be abused without immediately attracting attention. Organizations should automate deprovisioning where possible and periodically audit inactive accounts.

Question 343.

A security analyst sees a user account continue to access cloud applications after its primary password has been reset. Which explanation should be considered?

  1. DNS tunneling
    2. DHCP spoofing
    3. An existing session token or refresh token may still be valid
    4. ARP poisoning

Correct Answer: 3

Explanation:

Modern cloud authentication often uses session tokens or refresh tokens after the initial login. Resetting a password may not always terminate every active session immediately, depending on the identity platform and application. If an attacker possesses a valid token, access may continue even after the password changes. Analysts should review identity-provider logs, active sessions, token issuance, device information, and application access. Containment may require revoking sessions and refresh tokens in addition to changing credentials. DNS, DHCP, and ARP attacks do not explain continued cloud access after a password reset. This scenario demonstrates why credential remediation must consider tokens and sessions, not only passwords.

Question 344.

Which response action is most appropriate when an identity compromise includes stolen session tokens?

  1. Only change the user’s display name
    2. Wait for the tokens to expire naturally
    3. Disable endpoint logging
    4. Revoke active sessions and tokens in addition to resetting credentials

Correct Answer: 4

Explanation:

If session or refresh tokens may have been stolen, password reset alone may not terminate attacker access. The response team should revoke active sessions and tokens using the capabilities of the relevant identity platform, then reset affected credentials and investigate how the tokens were obtained. The account’s recent authentication history and application activity should also be reviewed for unauthorized access. Waiting for expiration can leave the attacker active for an unacceptable period. Changing a display name has no security value, while disabling logging would remove important visibility. Identity containment should address every authentication mechanism that may have been compromised.

Question 345.

A SIEM alert shows a privileged user granting an unfamiliar account membership in a highly privileged group. What should the analyst investigate first?

  1. The legitimacy of the group membership change and the account that initiated it
    2. The destination server’s monitor resolution
    3. The DHCP lease duration
    4. The user’s printer settings

Correct Answer: 1

Explanation:

Unexpected membership changes involving highly privileged groups can indicate privilege escalation, persistence, or administrative account misuse. The analyst should determine which account initiated the change, from which system, whether the action was authorized, and what the newly privileged account did afterward. Identity logs, directory-service events, endpoint telemetry, change tickets, and administrator activity should be correlated. If the account was added without authorization, the change may need to be reversed quickly according to incident-response procedures. Monitor, DHCP, and printer information do not address the security significance of the privilege modification.

Question 346.

Which MITRE ATT&CK tactic best describes an attacker adding a compromised account to an administrative group to gain higher privileges?

  1. Collection
    2. Privilege Escalation
    3. Reconnaissance
    4. Exfiltration

Correct Answer: 2

Explanation:

Adding an account to a privileged group is directly associated with Privilege Escalation because the attacker is increasing the permissions available to that identity. Depending on the environment, the same action can also support persistence if the attacker intends to retain administrative access over time. Collection focuses on gathering data, Reconnaissance on learning about targets, and Exfiltration on transferring data out. Analysts should review who made the group change, whether the account was previously compromised, and what privileged actions followed. Privilege modifications should be monitored closely because they can dramatically increase attacker capability.

Question 347.

A security team wants to detect unauthorized changes to privileged group membership more quickly. Which approach is most effective?

  1. Disable directory auditing
    2. Monitor only password failures
    3. Alert on privileged group modifications and enrich the alert with user, host, and change context
    4. Ignore changes made by administrator accounts

Correct Answer: 3

Explanation:

Privileged group membership changes are high-value security events. Monitoring them and automatically enriching alerts with the initiating user, target account, source host, timestamp, ticket or approval context, and subsequent activity gives analysts the information needed for fast triage. Ignoring administrator activity would be dangerous because compromised administrative credentials are often used for privilege escalation. Password failures alone do not capture privilege changes, and disabling auditing would remove critical visibility. The best detection approach combines directory events with endpoint and identity context so authorized administration can be distinguished from suspicious modification.

Question 348.

A SOC analyst sees a privileged account create a new local administrator account on multiple servers. Which attacker objective does this most likely support?

  1. DNS resolution
    2. Network availability
    3. Data compression
    4. Persistence

Correct Answer: 4

Explanation:

Creating new local administrator accounts can provide persistent access even if the original compromised account is later disabled. Attackers may create redundant privileged accounts on multiple systems to preserve control and make eradication more difficult. Analysts should determine which account performed the creation, which hosts were affected, whether the accounts were used, and whether similar changes occurred elsewhere. Legitimate automation can also create accounts, so change-management context matters. If malicious, the accounts should be contained and removed according to response procedures, and the original credential compromise should be investigated.

Question 349.

Which telemetry would best help determine whether a newly created administrator account was later used for remote access?

  1. Authentication logs correlated with endpoint and remote-access events
    2. Printer spooler data
    3. BIOS inventory
    4. Monitor serial numbers

Correct Answer: 1

Explanation:

Authentication and remote-access logs can show whether the newly created account successfully logged in, from which source host, to which destination, and using what authentication mechanism. Endpoint telemetry can then reveal the commands and processes executed after authentication. This correlation is important because account creation alone indicates possible persistence, while subsequent use demonstrates that the account actually became part of attacker activity. Printer, BIOS, and monitor information provide no useful identity context. Analysts should also determine whether the account was used across multiple systems and whether it created further persistence or accessed sensitive resources.

Question 350.

A compromised account accesses a cloud application from a new device and immediately downloads thousands of files. Which factor most increases the alert priority?

  1. The user’s account name is long
    2. The files contain sensitive business data and the behavior deviates sharply from the user’s baseline
    3. The application uses HTTPS
    4. The device receives a private IP address

Correct Answer: 2

Explanation:

Alert priority should consider both likelihood and potential impact. A new device, abnormal bulk downloading, and access to sensitive data create a high-risk combination, especially if the user has no history of performing such activity. Analysts should review authentication factors, source location, device identity, session history, file types, download volume, and whether the account showed other signs of compromise. HTTPS and private IP addressing are normal and do not meaningfully reduce risk. Behavioral baselines and data sensitivity are valuable contextual signals for prioritizing identity-related incidents.

Question 351.

Which security capability is most useful for identifying anomalous cloud-user behavior such as unusual download volume or access from unfamiliar devices?

  1. User and entity behavior analytics
    2. File-system defragmentation
    3. VLAN pruning
    4. Hardware inventory

Correct Answer: 1

Explanation:

User and entity behavior analytics can identify deviations in login locations, device usage, download volume, application access, and other patterns associated with users and systems. This is particularly useful in cloud environments where attackers may use valid credentials and never deploy malware. UEBA can highlight behavior that differs significantly from the user’s historical baseline, but anomalies still require investigation because legitimate changes can occur. The strongest analysis combines UEBA with identity-provider logs, cloud application telemetry, endpoint data, and asset context. Network and hardware maintenance functions do not provide comparable behavioral insight.

Question 352.

Which evidence would best help determine whether a large cloud download was followed by local data staging?

  1. Badge-reader logs
    2. Endpoint file and process telemetry showing archive creation
    3. Printer supply information
    4. DHCP scope utilization

Correct Answer: 2

Explanation:

Endpoint file and process telemetry can reveal whether downloaded files were grouped, compressed, encrypted, or moved into a staging directory after arriving on the device. Archive creation shortly after a large cloud download may indicate preparation for further exfiltration or transfer. Analysts should identify the process responsible, archive size, contents, user account, and any subsequent outbound network activity. Physical and DHCP telemetry do not provide this file-level context. Correlating cloud activity with endpoint behavior helps determine whether the download represents legitimate work or part of a broader data-theft sequence.

Question 353.

A workstation creates a large archive containing confidential files and then begins an outbound connection to a rare destination. Which next step provides the strongest confirmation of exfiltration?

  1. Correlate archive size and creation time with outbound transfer volume and destination telemetry
    2. Check whether the workstation has an SSD
    3. Verify the screen-lock policy
    4. Review the keyboard layout

Correct Answer: 1

Explanation:

The strongest evidence comes from correlating endpoint and network events. If a large archive containing confidential files is created and shortly afterward a transfer of similar size occurs to a rare external destination, the sequence strongly supports an exfiltration hypothesis. Analysts should identify the uploading process, protocol, destination reputation, account context, and whether the transfer completed successfully. Storage type and workstation configuration do not establish exfiltration. Correlation of file staging and network transfer provides a more defensible conclusion than either event alone.

Question 354.

Which telemetry source is best for measuring outbound byte volume when complete packet payloads are not retained?

  1. BIOS event logs
    2. NetFlow or equivalent flow telemetry
    3. Printer logs
    4. Physical security logs

Correct Answer: 2

Explanation:

NetFlow and similar flow technologies record metadata such as source and destination IP addresses, ports, protocols, session duration, packet counts, and byte counts. This makes them useful for measuring outbound traffic volume and identifying anomalous transfers without storing complete packet contents. Flow records can help analysts spot data exfiltration, command-and-control patterns, or scanning across large environments. They do not reveal exact file contents, so endpoint, DLP, proxy, or packet data may be needed for deeper analysis. Hardware and physical-access sources do not provide network transfer metrics.

Question 355.

A forensic investigator is examining a live compromised host. Which evidence should generally be collected before shutdown when active sessions and encryption keys may be important?

  1. Volatile memory
    2. Asset purchase records
    3. Archived invoices
    4. Printed rack diagrams

Correct Answer: 1

Explanation:

Volatile memory may contain active sessions, network connections, process information, credentials, encryption keys, injected code, and other artifacts that can disappear when the system is powered off. If these artifacts are relevant and organizational procedures permit collection, memory should be acquired before shutdown. Responders still need to balance evidence collection with containment risk, particularly if the system is actively causing harm. The collected memory image should be documented, hashed, and securely stored. Business records and printed diagrams are persistent and do not require the same immediate priority.

Question 356.

Which forensic principle determines that volatile memory should usually be collected before persistent disk data?

  1. Least privilege
    2. Segmentation
    3. Data normalization
    4. Order of volatility

Correct Answer: 4

Explanation:

Order of volatility prioritizes evidence based on how quickly it can change or disappear. RAM, active network connections, running processes, and similar live-system information are generally more volatile than files stored on disk. Investigators use this concept to plan collection while considering the operational need to contain an active threat. The exact collection sequence can vary with the incident, but volatile artifacts typically receive earlier attention. Least privilege, segmentation, and normalization are important security concepts but do not determine forensic evidence collection priority.

Question 357.

A compromised host is actively using stolen credentials to access additional servers. Which response action should be prioritized once critical volatile evidence is collected?

  1. Isolate the source host and restrict the compromised credentials
    2. Wait until the next monthly maintenance window
    3. Delete identity logs
    4. Disable endpoint monitoring

Correct Answer: 1

Explanation:

When an attacker is actively moving laterally, containment should address both the compromised endpoint and the abused identity. Isolating the host can stop further network activity, while disabling or restricting the account and revoking active sessions can prevent the attacker from continuing to authenticate elsewhere. The exact action should follow organizational incident-response procedures and account for business impact. Waiting unnecessarily increases risk. Deleting logs or disabling monitoring would hinder investigation. After containment, the team should scope affected systems and proceed with eradication.

Question 358.

Which activity belongs primarily to the eradication phase after a compromised identity has been contained?

  1. Conducting the final post-incident review
    2. Resetting compromised credentials, removing malicious persistence, and patching exploited weaknesses
    3. Reconnecting all systems immediately
    4. Disabling security controls

Correct Answer: 2

Explanation:

Eradication addresses the attacker’s remaining access and the underlying causes of compromise. This can include credential resets, token revocation, removal of malicious services or scheduled tasks, deletion of unauthorized accounts, patching vulnerabilities, and rebuilding systems when necessary. Containment limits immediate activity but does not remove every foothold. Recovery should not begin until the team has reasonable confidence that attacker access has been eliminated. The final review occurs after recovery, while disabling controls would make the environment less secure.

Question 359.

Which task belongs primarily to recovery after identity and endpoint compromise have been eradicated?

  1. Restore validated systems and accounts to service while monitoring closely for recurrence
    2. Reuse the original compromised passwords
    3. Disable identity auditing
    4. Delete all incident evidence

Correct Answer: 1

Explanation:

Recovery restores business operations in a controlled manner after the threat has been removed. Systems should be validated, patched, protected, and reconnected carefully. Accounts should have new credentials or tokens where appropriate, and security controls should remain active. Enhanced monitoring should continue for signs of renewed authentication anomalies, beaconing, or persistence. Reusing compromised passwords or disabling identity auditing would undermine the response. Evidence and incident documentation should be retained according to organizational requirements for review, compliance, and lessons learned.

Question 360.

A post-incident review reveals that an old employee account remained active for months and was later abused by an attacker. Which improvement would most directly prevent recurrence?

  1. Reduce log retention
    2. Disable behavioral analytics
    3. Automate joiner-mover-leaver identity lifecycle controls and regularly audit inactive accounts
    4. Allow former employees to retain limited access indefinitely

Correct Answer: 3

Explanation:

Strong identity lifecycle management ensures that accounts are provisioned, modified, and deprovisioned promptly as employment status and job roles change. Automating joiner-mover-leaver workflows reduces dependence on manual action and helps prevent orphaned accounts. Regular audits can detect inactive, stale, excessive, or incorrectly privileged identities that automation may have missed. Leaving former-employee accounts active creates unnecessary attack surface, while reducing monitoring would make abuse harder to detect. Post-incident lessons should address both the immediate compromise and the process weakness that allowed the unused account to remain exploitable.