Cisco 300-220 Practice Test Questions and Exam Dumps Part19 Q361-380

View Full Cisco 300-220 Exam Dumps and Practice Test Dumps

 

Question 361.

Which telemetry can reveal suspicious changes to application configuration?

  1. Printer inventory
  2. Configuration change events
  3. Keyboard preferences
  4. Screen resolution

Correct Answer: 2

Explanation:

Configuration change events can reveal modifications to application settings that may affect security or system behavior. Hunters can examine which setting changed, the previous and new values, the responsible account or process, and the exact modification time. Unexpected configuration changes may indicate unauthorized activity, attempts to alter security controls, or changes associated with newly installed software. Legitimate application updates can also modify configuration, so findings should be compared with approved baselines and change records. Printer inventory, keyboard preferences, and screen resolution provide little relevant evidence for application configuration investigations.

Question 362.

What can identify whether an endpoint contacted a rare destination?

  1. Historical connection frequency
  2. Desktop theme data
  3. File icon metadata
  4. Monitor power events

Correct Answer: 1

Explanation:

Historical connection frequency can help determine whether a destination is commonly or rarely contacted by an endpoint or peer group. A newly observed destination may deserve additional investigation when it falls outside the host’s established communication pattern. Hunters can examine destination addresses, ports, processes, timestamps, and traffic volume to add context. Rarity alone does not establish malicious behavior because legitimate services may be accessed infrequently. Desktop themes, file icons, and monitor power events do not provide useful network-frequency information. Historical communication analysis is therefore a valuable method for identifying unusual destinations while preserving appropriate environmental context.

Question 363.

Which evidence helps identify unauthorized changes to endpoint certificates?

  1. Browser bookmarks
  2. Printer connection history
  3. Certificate-store events
  4. Screen-lock duration

Correct Answer: 3

Explanation:

Certificate-store events can reveal additions, removals, or modifications involving certificates installed on an endpoint. Hunters can investigate certificate subjects, issuers, thumbprints, installation times, responsible accounts, and associated processes. Unexpected certificate changes may affect trust relationships or enable unauthorized authentication behavior, although legitimate enterprise management systems also distribute certificates. Browser bookmarks, printer connections, and screen-lock duration do not directly document certificate-store activity. Certificate events should be correlated with endpoint configuration and identity telemetry to determine whether the modification was expected. Comparing the observed certificate with approved organizational trust stores can provide additional validation.

Question 364.

Which behavior may indicate automated credential testing?

  1. One successful login
  2. Regular password change
  3. Multiple rapid authentication attempts
  4. Routine account logout

Correct Answer: 3

Explanation:

Multiple rapid authentication attempts can indicate automated credential testing, especially when numerous usernames or systems are targeted within a short period. Hunters should examine the source, targeted accounts, authentication protocol, timing, and whether successful logins occurred after repeated failures. Legitimate applications can also generate authentication failures because of configuration problems or expired credentials, so the pattern requires contextual analysis. A single successful login, scheduled password change, or routine logout does not provide comparable evidence of automated credential testing. Combining identity telemetry with source-host and process information can help determine whether the activity represents an attack pattern or an operational issue.

Question 365.

What can help distinguish a legitimate management agent from an unknown executable?

  1. Approved deployment records
  2. Desktop icon placement
  3. Monitor brightness
  4. Browser zoom level

Correct Answer: 1

Explanation:

Approved deployment records can help determine whether a management agent was intentionally installed and distributed. Hunters can compare the executable’s host prevalence, installation time, version, publisher, path, and associated deployment record with expected enterprise software. An executable that matches an authorized deployment is more readily explained than one appearing without corresponding management activity. This does not eliminate the need for verification because legitimate software can be modified or abused. Desktop icons, monitor brightness, and browser zoom settings do not establish deployment legitimacy. Installation records combined with software inventory and digital-signature information provide stronger validation.

Question 366.

Which network characteristic can reveal asymmetric communication behavior?

  1. File ownership
  2. Upload-to-download ratio
  3. Account age
  4. Process priority

Correct Answer: 2

Explanation:

The upload-to-download ratio can reveal whether a host sends substantially more data than it receives. An unusual outbound-heavy pattern may provide a lead when investigating possible data transfer or exfiltration, particularly if the destination and initiating process are unexpected. However, many legitimate services naturally generate asymmetric traffic, such as backups or cloud synchronization. Therefore, the ratio should be evaluated alongside destination reputation, asset role, timing, and application context. File ownership, account age, and process priority do not directly describe network traffic direction or volume. Traffic asymmetry is best treated as contextual evidence rather than standalone proof.

Question 367.

Which artifact can expose unexpected changes to group membership?

  1. Account-group audit events
  2. DNS response records
  3. Network packet counts
  4. Browser session data

Correct Answer: 1

Explanation:

Account-group audit events can reveal when users are added to or removed from security groups. Unexpected membership changes can affect authorization and may support investigations involving privilege escalation or unauthorized access. Hunters should examine the affected account, modified group, responsible administrator, timestamp, source system, and subsequent use of the granted privileges. Legitimate administrative operations and onboarding processes can also change group membership, so organizational change records should be consulted. DNS responses, packet counts, and browser session data do not directly document authorization-group modifications. Group auditing is therefore an important source for investigating unexpected privilege-related changes.

Question 368.

What helps determine whether a new process matches an endpoint role?

  1. Peer-role behavior
  2. Screen resolution
  3. Printer model
  4. Browser language

Correct Answer: 1

Explanation:

Peer-role behavior provides a useful baseline for determining whether a new process is consistent with an endpoint’s function. Servers, developer systems, workstations, and specialized appliances often have different expected software and process profiles. A process that appears routinely across similar endpoints may be expected, while an isolated process on a system where it normally does not belong can become an investigation lead. Role-based comparison should account for legitimate exceptions and recent deployments. Screen resolution, printer model, and browser language do not meaningfully describe whether process activity fits an endpoint’s operational role.

Question 369.

Which evidence can show that a suspicious file changed after creation?

  1. File modification metadata
  2. DHCP lease information
  3. Authentication source data
  4. Network route tables

Correct Answer: 1

Explanation:

File modification metadata can show when a file was changed after its initial creation. Hunters can compare creation and modification times, hashes, file size, ownership, and associated process activity to determine whether the artifact was altered. A modification timestamp alone does not establish malicious behavior because normal applications frequently update files. However, unexpected changes shortly before execution or network communication may provide a useful investigative lead. DHCP leases, authentication sources, and route tables offer different types of system context but do not directly show file modification. File metadata becomes stronger evidence when correlated with process and user activity.

Question 370.

Which pattern can reveal unusual service-account behavior?

  1. Expected scheduled execution
  2. Normal application startup
  3. Interactive administrative login
  4. Standard backup activity

Correct Answer: 3

Explanation:

An interactive administrative login using a service account can represent unusual behavior because service accounts are often intended for automated application or system functions rather than direct user sessions. Such activity should be evaluated against organizational policy and known exceptions. Hunters can examine the source endpoint, authentication method, time, commands executed, and privileges used after the login. Scheduled execution, normal application startup, and standard backups may represent expected service-account activity. An interactive login therefore provides a potentially valuable anomaly signal, but additional evidence is necessary before concluding that the account was misused.

Question 371.

What can reveal whether a suspicious process accessed sensitive files?

  1. File-access telemetry
  2. Monitor configuration
  3. Browser font settings
  4. Printer preferences

Correct Answer: 1

Explanation:

File-access telemetry can show which processes or accounts interacted with particular files. This information is valuable when investigating suspicious processes on systems containing sensitive information. Hunters can examine the accessed paths, timestamps, account context, process identity, access type, and whether the activity differs from normal behavior. File access alone does not establish malicious intent because legitimate applications routinely access sensitive resources. Monitor configuration, browser fonts, and printer preferences do not provide comparable evidence. Correlating file-access events with process execution and network transfers can help determine whether sensitive data was potentially staged or moved.

Question 372.

Which observation may indicate an endpoint is performing unusual discovery?

  1. Accessing many system-management interfaces
  2. Changing a desktop background
  3. Opening a local calendar
  4. Printing a routine report

Correct Answer: 1

Explanation:

Accessing many system-management interfaces can indicate discovery activity when the behavior differs from the endpoint’s normal role. Hunters can examine which interfaces were accessed, the number of systems queried, the initiating process, account privileges, and timing. Administrative tools and management software can legitimately perform broad discovery, so approved operational activity should be considered before escalation. Desktop changes, calendar access, and routine printing generally do not provide comparable evidence of system discovery. Correlating management-interface access with process and network telemetry can help establish whether the behavior represents normal administration or potentially suspicious reconnaissance.

Question 373.

Which information helps validate a suspicious file hash?

  1. Related software context
  2. Monitor serial number
  3. Printer paper size
  4. Keyboard shortcuts

Correct Answer: 1

Explanation:

Related software context helps determine whether a suspicious file hash belongs to an expected application or component. Hunters can examine the file’s path, publisher, version, installation source, prevalence, associated software, and execution behavior. A hash can identify a specific file version, but its meaning depends on how and where the file is observed. A legitimate file can appear suspicious when located outside its normal deployment path, while a known malicious hash can provide a stronger lead. Monitor serial numbers, printer paper size, and keyboard shortcuts do not contribute meaningful file-validation context.

Question 374.

What can indicate that an executable is newly introduced to the environment?

  1. First-observed prevalence data
  2. Screen-lock frequency
  3. Browser tab count
  4. Printer queue length

Correct Answer: 1

Explanation:

First-observed prevalence data can help identify when an executable begins appearing in the monitored environment and how widely it spreads afterward. A sudden appearance on a small number of endpoints may warrant investigation, particularly if the file lacks an approved deployment record. Hunters can compare first-seen information with software-management events, file provenance, digital signatures, and process execution. A new file is not automatically malicious because legitimate updates and deployments also create newly observed executables. Screen locks, browser tabs, and printer queues do not provide meaningful evidence about software introduction. Prevalence and timing together provide useful investigative context.

Question 375.

Which network clue can support investigation of possible tunneling?

  1. Unusual query encoding
  2. Normal webpage access
  3. Routine DHCP renewal
  4. Standard email synchronization

Correct Answer: 1

Explanation:

Unusual query encoding can support an investigation into possible tunneling, particularly when observed in DNS or another protocol capable of carrying structured data. Hunters can examine query length, character patterns, frequency, domain structure, entropy, and recurring communication intervals. These characteristics can also appear in legitimate applications, so encoding alone does not establish tunneling. Normal webpage access, DHCP renewal, and routine email synchronization generally provide different types of network behavior. Query analysis should be correlated with the initiating process, destination infrastructure, response patterns, and host role to determine whether the observed communication warrants deeper investigation.

Question 376.

Which evidence can connect a suspicious action to a remote session?

  1. Session-linked process records
  2. Browser theme settings
  3. Printer driver versions
  4. Monitor orientation

Correct Answer: 1

Explanation:

Session-linked process records can connect processes and commands to a particular remote session. This allows hunters to determine which account, source system, and session context were associated with actions performed after remote access. Such correlation is useful when investigating unauthorized administration, lateral movement, or suspicious use of privileged accounts. Browser themes, printer drivers, and monitor orientation do not establish session relationships. Investigators should compare session timestamps with process creation, command-line arguments, authentication records, and network connections. This broader correlation can help reconstruct what occurred after a remote session was established and whether the activity matched expected administrative behavior.

Question 377.

What should be checked when a security alert conflicts with baseline behavior?

  1. Alert context and telemetry
  2. Desktop wallpaper
  3. Printer preferences
  4. Browser font size

Correct Answer: 1

Explanation:

Alert context and supporting telemetry should be reviewed when an alert appears inconsistent with established baseline behavior. A baseline can provide valuable context, but it may not capture recent changes, specialized systems, or newly introduced threats. Hunters should examine the triggering condition, process details, identity, network activity, asset role, and relevant historical events before deciding how to interpret the alert. Desktop wallpaper, printer preferences, and browser font size generally provide no meaningful security context. Comparing the alert against multiple evidence sources helps determine whether the discrepancy represents a false positive, an environmental change, or genuinely unusual activity.

Question 378.

Which evidence can identify repeated execution from the same unusual path?

  1. Process path frequency
  2. Network interface color
  3. Printer page count
  4. Browser bookmark order

Correct Answer: 1

Explanation:

Process path frequency can reveal repeated execution from an unusual directory or location. Hunters can identify how often a particular executable path appears, which accounts use it, which hosts execute it, and whether the activity follows a consistent pattern. Repeated execution from a user-writable or temporary directory may deserve investigation, although legitimate applications can also operate from such locations. Network-interface color, printer page counts, and bookmark order are unrelated to process execution paths. Combining path frequency with file hashes, process ancestry, and installation records can help determine whether the recurring execution is expected.

Question 379.

Which action improves a hunt after identifying a reliable behavioral pattern?

  1. Convert the pattern into detection logic
  2. Remove historical telemetry
  3. Ignore related observations
  4. Disable the hunting query

Correct Answer: 1

Explanation:

A reliable behavioral pattern can be converted into detection logic to provide ongoing monitoring beyond the original hunt. Hunters should identify the observable conditions that distinguish suspicious activity from normal behavior and then develop appropriate detection rules or analytics. The resulting logic should be tested against historical data and tuned to reduce unnecessary alerts. Removing telemetry would reduce visibility, ignoring related observations would discard useful context, and disabling the query would prevent future investigations. Converting validated hunting knowledge into durable detection allows the organization to continuously identify similar behavior instead of relying solely on periodic manual hunts.

Question 380.

What should be documented when closing a completed hunt?

  1. Findings and investigative rationale
  2. Screen brightness
  3. Printer wallpaper
  4. Keyboard color scheme

Correct Answer: 1

Explanation:

Findings and investigative rationale should be documented when closing a completed hunt. The record should explain the original hypothesis, relevant data sources, observed evidence, conclusions, limitations, and any resulting detection or response recommendations. Documenting both successful and unsuccessful investigations improves repeatability and helps other analysts understand how the conclusion was reached. It also preserves useful knowledge for future hunting activities and detection engineering. Screen brightness, printer wallpaper, and keyboard color schemes do not contribute meaningful investigative context. A clear hunt record ensures that important reasoning and evidence are retained after the investigation is completed.