View Full Cisco 300-220 Exam Dumps and Practice Test Dumps Question 281. Which telemetry helps identify suspicious DNS query construction? DHCP lease records DNS query logs File ownership data Printer status events Correct Answer: 2 Explanation: DNS query logs provide detailed visibility into domain lookups performed by hosts. A threat hunter can examine queried […]
View Full Cisco 300-220 Exam Dumps and Practice Test Dumps Question 261. Which evidence can identify a process that modified another process? DNS response data Screen activity Process-access telemetry Printer status Correct Answer: 3 Explanation: Process-access telemetry can provide visibility into interactions between processes, including situations where one process accesses another process’s memory or […]
View Full Cisco 300-220 Exam Dumps and Practice Test Dumps Question 241. Which evidence can reveal unauthorized changes to endpoint security exclusions? DNS resolver status Monitor power state Keyboard activity Security configuration events Correct Answer: 4 Explanation: Security configuration events can reveal changes to exclusions, protection settings, scanning policies, or other endpoint security controls. […]
View Full Cisco 300-220 Exam Dumps and Practice Test Dumps Question 221. Which evidence can reveal suspicious changes to a Windows service binary path? DHCP allocation data Browser cache records Audio device events Service configuration telemetry Correct Answer: 4 Explanation: Service configuration telemetry can reveal changes to executable paths, startup settings, service accounts, and […]
View Full Cisco 300-220 Exam Dumps and Practice Test Dumps Question 201. Which endpoint artifact can expose changes to executable permissions? DNS query records User session duration File permission events Network latency Correct Answer: 3 Explanation: File permission events can reveal changes affecting who may execute, modify, or access files. Unexpected permission changes can […]
View Full Cisco 300-220 Exam Dumps and Practice Test Dumps Question 181. Which telemetry best reveals abnormal use of a legitimate administrative utility? Disk capacity Command execution logs Screen brightness Printer status Correct Answer: 2 Explanation: Command execution logs can reveal how administrative utilities are being used on an endpoint. Attackers often abuse legitimate […]
View Full Cisco 300-220 Exam Dumps and Practice Test Dumps Question 161. Which artifact can reveal recently mounted removable storage? Browser history DNS cache Display profiles Device connection records Correct Answer: 4 Explanation: Device connection records can reveal when removable storage devices were connected to an endpoint. This information can support investigations involving unauthorized […]
View Full Cisco 300-220 Exam Dumps and Practice Test Dumps Question 141. Which telemetry can reveal unusual registry modifications? DNS response data Registry change events Network route tables Printer queue records Correct Answer: 2 Explanation: Registry change events can help hunters identify modifications to operating-system configuration and application settings. Attackers may alter registry locations […]
View Full Cisco 300-220 Exam Dumps and Practice Test Dumps Question 121. Which telemetry can expose unusual remote administration activity? Remote session logs Display brightness records Battery charging cycles Audio device settings Correct Answer: 1 Explanation: Remote session logs can provide valuable evidence when investigating unusual administrative access. They may identify the account used, […]
View Full Cisco 300-220 Exam Dumps and Practice Test Dumps Question 101. Which activity can help detect unusual service account behavior? Monitor configuration changes Review account activity Inspect display adapters Measure disk temperature Correct Answer: 2 Explanation: Reviewing account activity can help identify unusual behavior involving service accounts. Hunters can examine authentication times, source […]
View Full Cisco 300-220 Exam Dumps and Practice Test Dumps Question 81. Which method can uncover abnormal lateral movement between hosts? User-interface review Software licensing checks East-west traffic analysis Screen resolution testing Correct Answer: 3 Explanation: East-west traffic analysis examines communication between systems within an environment. This visibility can help identify unusual host-to-host connections […]
View Full Cisco 300-220 Exam Dumps and Practice Test Dumps Question 61. Which telemetry is most useful for identifying unusual parent-child process relationships? DNS query logs Process creation events Firewall rule sets Certificate inventories Correct Answer: 2 Explanation: Process creation events record which executable launched another process, creating a parent-child relationship. Threat hunters can […]
View Full Cisco 300-220 Exam Dumps and Practice Test Dumps Question 41. Which security control helps detect unauthorized changes to critical files? Network segmentation File integrity monitoring Load balancing Address translation Correct Answer: 2 Explanation: File integrity monitoring detects changes to monitored files, directories, or configuration objects. It can identify modifications, creations, deletions, or other […]
View Full Cisco 300-220 Exam Dumps and Practice Test Dumps Question 21. Which technique helps hunters investigate suspicious PowerShell activity? Disk defragmentation Screen calibration Cable mapping Command-line analysis Correct Answer: 4 Explanation: Command-line analysis is valuable when investigating PowerShell activity because it can reveal the commands, parameters, scripts, and execution context used by a […]
View Full Cisco 300-220 Exam Dumps and Practice Test Dumps Question 1. What does the Pyramid of Pain primarily measure in threat intelligence? Attacker difficulty Network bandwidth Malware size Log retention Correct Answer: 1 Explanation: The Pyramid of Pain represents the relative difficulty an adversary experiences when defenders detect and disrupt different types of […]