Cisco CCNP CyberSecurity 300-215 Practice Test Questions and Exam Dumps Part10 Q181-200

View Full Cisco CCNP CyberSecurity 300-215 Exam Dumps and Practice Test Dumps

 

Question 181.

A SOC analyst notices that a user account successfully authenticated to a critical server from a host that has never previously accessed that server. Which factor would most strongly increase the likelihood of compromise?

  1. The source host was previously associated with malware activity
    2. The destination server uses a static IP address
    3. The user has logged in during business hours
    4. The server is located in the same data center

Correct Answer: 1

Explanation:

A source host already associated with malware activity significantly increases the likelihood that the authentication represents credential abuse or lateral movement. The analyst should correlate the login with endpoint telemetry from the source host, review the account’s privilege level, determine whether MFA was used, and inspect activity on the destination server immediately after authentication. A static IP address, normal working hours, or physical proximity between systems does not meaningfully reduce or increase the malicious hypothesis. Context matters because a valid login alone is not proof of compromise. Strong investigations combine identity, endpoint, network, and historical baseline data before determining whether containment is required.

Question 182.

Which telemetry source is most useful for determining whether a user downloaded a malicious file through a corporate web gateway?

  1. Power-supply logs
    2. Proxy or secure web gateway logs
    3. Monitor configuration
    4. BIOS settings

Correct Answer: 2

Explanation:

Proxy and secure web gateway logs can provide requested URLs, domains, usernames, source IP addresses, timestamps, response codes, user agents, and sometimes file or byte-transfer information. This makes them highly useful for identifying web-based malware delivery and determining which user or endpoint initiated the download. Analysts should correlate the web request with endpoint telemetry to confirm whether the file was saved, executed, or blocked. Hardware configuration sources do not provide this application-layer visibility. If the connection was encrypted and the organization does not perform TLS inspection, metadata may still help establish timing and destination context, while EDR can provide the process-level evidence needed to complete the investigation.

Question 183.

A SOC rule identifies a user visiting a domain that has never before been seen in the environment and was registered two days ago. Which additional factor would most increase suspicion?

  1. The endpoint has a large amount of RAM
    2. The domain uses HTTPS
    3. The domain is contacted immediately after a suspicious PowerShell process launches
    4. The workstation uses DHCP

Correct Answer: 3

Explanation:

A newly registered and previously unseen domain becomes more suspicious when the connection occurs immediately after a suspicious process launches. This temporal relationship may indicate malware delivery or command-and-control activity. The analyst should inspect the PowerShell command line, parent process, destination reputation, certificate information, DNS history, and any files or registry changes created around the same time. HTTPS alone is common and does not imply maliciousness, while RAM capacity and DHCP use are irrelevant. Correlating rare-destination behavior with endpoint execution context substantially improves confidence compared with relying only on domain age or reputation.

Question 184.

Which threat-hunting technique focuses on identifying unusual behavior even when no known malicious indicator is available?

  1. Hash-only matching
    2. Static blacklist comparison
    3. Signature validation only
    4. Behavioral hypothesis-driven hunting

Correct Answer: 4

Explanation:

Behavioral hypothesis-driven hunting begins with an assumption about how an attacker might behave and searches telemetry for evidence supporting that hypothesis. For example, a hunter might search for Office applications spawning script interpreters, unusual remote service creation, or abnormal use of privileged accounts. This approach can detect previously unknown threats that do not yet have known hashes, domains, or IP addresses. Static indicators remain useful, but they are easier for attackers to change. Behavioral hunting depends on quality telemetry, strong knowledge of normal activity, and careful validation because legitimate administrative behavior can resemble attacker techniques.

Question 185.

Which security control is most useful for identifying the specific executable responsible for a suspicious outbound connection?

  1. Endpoint detection and response
    2. DHCP reservation
    3. Network address translation
    4. VLAN trunking

Correct Answer: 1

Explanation:

Endpoint detection and response platforms can associate network connections with the exact process, file path, hash, command line, user account, and parent process that generated them. This allows analysts to distinguish between legitimate application traffic and malware communication. DHCP, NAT, and VLAN information may help with network attribution but generally cannot identify the local process responsible for a connection. EDR data is especially valuable when paired with firewall, proxy, or NetFlow telemetry. Together, these sources show both what communicated externally and which process initiated the communication, enabling more confident analysis and faster containment decisions.

Question 186.

An analyst observes repeated outbound connections to the same external destination, but the intervals vary randomly between 30 and 90 seconds. Why might an attacker use this behavior?

  1. To improve DNS resolution
    2. To make beaconing patterns harder to detect
    3. To speed up DHCP renewal
    4. To reduce file-system fragmentation

Correct Answer: 2

Explanation:

Attackers may introduce timing variation, often called jitter, into command-and-control beaconing so that connections do not occur at perfectly predictable intervals. Fixed periodicity can be easier for statistical or behavioral detections to identify. Randomizing the interval helps malicious traffic blend into ordinary network activity. Analysts can still detect jittered beaconing by examining destination rarity, process identity, long-term connection patterns, byte counts, and historical baselines. Legitimate software can also use variable retry intervals, so timing alone is not enough. Combining endpoint and network context is critical for distinguishing malicious beaconing from normal automated traffic.

Question 187.

Which type of log would best help determine whether a malicious user successfully elevated privileges on a Windows system?

  1. Windows security and endpoint telemetry
    2. Printer queue history
    3. UPS battery logs
    4. Monitor firmware information

Correct Answer: 1

Explanation:

Windows security logs and endpoint telemetry can provide evidence of privilege changes, privileged logons, token use, process execution, service creation, and other actions associated with privilege escalation. Analysts should examine the account involved, parent and child processes, command-line arguments, resulting security context, and whether suspicious activity followed the elevation. Printer and hardware logs do not provide relevant security context. Privilege escalation is especially important because it can allow an attacker to disable controls, access credentials, modify system settings, and move laterally. Analysts should also determine whether escalation exploited a vulnerability, misconfiguration, or stolen administrative credential.

Question 188.

Which MITRE ATT&CK tactic is most closely associated with an attacker attempting to gain higher-level permissions after initial compromise?

  1. Collection
    2. Reconnaissance
    3. Exfiltration
    4. Privilege Escalation

Correct Answer: 4

Explanation:

Privilege Escalation covers techniques adversaries use to obtain higher levels of permission, such as moving from a standard user context to administrator or SYSTEM privileges. This may involve exploiting vulnerabilities, abusing services, misconfigurations, token manipulation, or stolen credentials. Collection focuses on gathering data, Reconnaissance concerns information gathering, and Exfiltration covers data removal. Successful privilege escalation can significantly increase attacker capability because higher privileges may enable security control tampering, credential theft, persistence, and lateral movement. Mapping activity to ATT&CK helps analysts understand the attacker’s progression and identify where defensive controls may need improvement.

Question 189.

A SOC analyst detects a newly created local administrator account on a workstation shortly after suspicious PowerShell execution. Which attacker objective does this most directly support?

  1. Persistence or privilege retention
    2. DNS resolution
    3. Network availability
    4. Data compression

Correct Answer: 1

Explanation:

Creating a new local administrator account can provide persistence and privileged access even if the original compromise path is removed. The analyst should determine which process created the account, whether it has logged in, whether similar accounts exist on other hosts, and whether group membership or remote-access permissions were changed. Legitimate administrators can create accounts for valid reasons, so the timing and process context are important. If the account is malicious, incident response should include disabling or removing it, investigating the source credentials, and searching for related account-creation activity across the environment.

Question 190.

Which network behavior most strongly suggests internal reconnaissance?

  1. One host contacting its configured DNS server
    2. One endpoint probing many internal hosts and ports in a short time
    3. A server performing its scheduled backup
    4. A workstation synchronizing time with an NTP server

Correct Answer: 2

Explanation:

Probing many internal hosts and ports in a short period is characteristic of network reconnaissance or scanning. Attackers often perform this activity after compromising a system to identify reachable services, administrative interfaces, databases, and potential lateral-movement targets. Legitimate vulnerability scanners and management systems may generate similar traffic, so analysts should identify the source process, user, device role, and expected scanning schedule. DNS and NTP activity are normal infrastructure functions, while a scheduled backup typically follows established communication patterns. NetFlow, firewall logs, EDR telemetry, and asset context can help distinguish malicious scanning from authorized activity.

Question 191.

Which security source is best suited to identifying large-scale port-scanning behavior across many network segments?

  1. NetFlow or network analytics telemetry
    2. Office document metadata
    3. BIOS configuration
    4. Email signature settings

Correct Answer: 1

Explanation:

NetFlow and network analytics platforms provide broad visibility into source and destination addresses, ports, connection counts, protocols, and timing. These characteristics make them well suited to identifying scanning activity across multiple network segments. Analysts can look for one host generating a high number of short connections to many destinations or ports. Endpoint telemetry can then reveal which process generated the scan. Office metadata and firmware settings do not provide useful network behavior data. Broad network telemetry is especially valuable when the scanning system is not fully managed by endpoint security or when analysts need to understand activity across a large environment.

Question 192.

An analyst sees a process reading thousands of documents from multiple network shares and then creating one large archive. Which MITRE ATT&CK tactic is most closely represented by the first part of this behavior?

  1. Persistence
    2. Collection
    3. Initial Access
    4. Defense Evasion

Correct Answer: 2

Explanation:

Reading large numbers of documents from multiple network shares is consistent with Collection because the attacker appears to be gathering information of interest before further processing or transfer. Creating an archive may represent staging and preparation for exfiltration. Persistence focuses on maintaining access, Initial Access concerns gaining the initial foothold, and Defense Evasion involves avoiding detection. Analysts should inspect the user account, source process, file-access patterns, archive location, and any subsequent network transfer. Legitimate backup or indexing software can produce similar behavior, so baseline and application context are essential for accurate classification.

Question 193.

Which evidence would best confirm that a suspicious archive was actually transferred outside the organization?

  1. Outbound proxy, firewall, or flow records showing a matching transfer at the same time
    2. The archive’s filename
    3. The user’s desktop background
    4. The destination workstation’s monitor type

Correct Answer: 1

Explanation:

Outbound network telemetry can confirm that a transfer occurred and provide destination, timing, byte count, protocol, and source information. If the size and timing of the outbound session closely match the creation of a suspicious archive, the evidence becomes stronger. Proxy or secure web gateway logs may also reveal the specific cloud service or URL used. Endpoint telemetry can identify the process responsible for the upload. A filename alone does not prove that data left the organization. Correlating host and network evidence is the most reliable way to confirm whether staged data was actually exfiltrated.

Question 194.

Which evidence-preservation practice is most appropriate when a potentially compromised system may be needed for forensic investigation?

  1. Delete suspicious files before collection
    2. Reboot the system repeatedly
    3. Document actions and preserve evidence according to established procedures
    4. Allow unrestricted user activity to continue

Correct Answer: 3

Explanation:

Evidence preservation requires careful documentation and minimizing unnecessary changes to the system. Depending on the incident, investigators may capture volatile memory, collect logs, image storage, record hashes, and maintain chain of custody. Deleting files or repeatedly rebooting can destroy valuable evidence, while unrestricted user activity may alter system state or allow the compromise to continue. The exact collection order should follow organizational policy and consider the balance between containment and forensic value. Good evidence handling makes later conclusions more reliable and supports legal, regulatory, or disciplinary processes when necessary.

Question 195.

Which action best demonstrates that a forensic image remains unchanged during an investigation?

  1. Recalculate and compare its cryptographic hash
    2. Rename the image file
    3. Store it on a different desktop
    4. Compress it using another utility

Correct Answer: 1

Explanation:

A cryptographic hash provides a content-based integrity value. If the hash calculated later matches the value recorded when the forensic image was acquired, investigators have strong evidence that the image has not changed. Renaming or moving a file does not validate integrity, while changing its representation through compression may produce a different file structure. Hash verification should be combined with controlled storage and chain-of-custody documentation. Investigators generally analyze validated copies while preserving original evidence. Any unexpected mismatch should be investigated because it may indicate alteration, corruption, or an acquisition problem.

Question 196.

Which forensic control helps prevent an acquisition workstation from modifying the original storage device?

  1. Network IDS
    2. VPN concentrator
    3. Proxy server
    4. Write blocker

Correct Answer: 4

Explanation:

A write blocker prevents writes to the source media during forensic acquisition. This protects file-system metadata, timestamps, and other evidence from accidental modification by the analyst’s operating system or forensic tools. Hardware write blockers are common, although validated software-based approaches can also be used. Network IDS, VPN concentrators, and proxies serve different security functions and do not protect storage evidence from writes. Using a write blocker should be part of a broader forensic process that includes hashing, chain-of-custody documentation, secure storage, and analysis on verified copies rather than the original device.

Question 197.

A compromised endpoint is actively communicating with multiple internal hosts and a known malicious server. What should the incident-response team do first after obtaining any immediately required volatile evidence?

  1. Contain and isolate the endpoint
    2. Wait until the next scheduled maintenance window
    3. Delete all investigation logs
    4. Disable the SIEM

Correct Answer: 1

Explanation:

Once immediately required volatile evidence has been collected, containment should occur quickly to reduce further command-and-control communication, lateral movement, or data exfiltration. Isolation may be performed through EDR network containment, firewall controls, switch changes, or physical disconnection depending on policy. Waiting unnecessarily increases risk, while deleting logs or disabling monitoring removes essential visibility. After containment, analysts can continue scoping affected systems, investigating persistence, identifying compromised credentials, and preparing eradication. The response should be documented so actions and timing are clear for later review.

Question 198.

Which action is most appropriate during eradication after malicious activity has been contained?

  1. Reconnect affected systems immediately
    2. Remove malware, persistence, compromised credentials, and exploited weaknesses
    3. Disable monitoring to reduce noise
    4. Delete the incident ticket

Correct Answer: 2

Explanation:

Eradication removes the attacker’s remaining footholds and addresses the root cause of compromise. This can include removing malicious files, deleting persistence mechanisms, resetting compromised credentials, revoking tokens, patching vulnerabilities, and removing unauthorized tools. A system should not return to production simply because network isolation stopped the immediate threat. If the environment is heavily compromised, rebuilding from trusted images may provide stronger assurance than manual cleanup. Monitoring should remain active because it can help verify whether eradication was complete. Incident records should also be preserved so the organization can learn from the response.

Question 199.

Which action best represents recovery after eradication is complete?

  1. Restore systems to production in a controlled manner and monitor closely for recurrence
    2. Disable endpoint protection
    3. Remove all security logs
    4. Ignore compromised accounts because malware was deleted

Correct Answer: 1

Explanation:

Recovery returns systems and services to normal operation after the active threat and root cause have been addressed. Systems should be validated, patched, protected, and restored from trusted sources when required. Compromised accounts and credentials must also be handled before reconnection. Once systems return to production, enhanced monitoring should continue for a period so recurrence can be detected quickly. Disabling protection or deleting logs would weaken the environment. Recovery is not merely technical restoration; it is a controlled process that balances business continuity with confidence that attacker access has been removed.

Question 200.

A post-incident review finds that analysts had sufficient telemetry but lacked a consistent way to correlate identity, endpoint, and network activity. Which improvement would provide the greatest benefit?

  1. Reduce the number of collected log sources
    2. Stop retaining historical data
    3. Build and test correlation rules and investigation playbooks across the available telemetry
    4. Disable behavioral analytics

Correct Answer: 3

Explanation:

If the necessary telemetry already exists, the next improvement should focus on using it more effectively. Correlation rules can connect suspicious identity events, endpoint processes, DNS activity, and network communication into a coherent attack sequence. Investigation playbooks can then guide analysts through enrichment, validation, scoping, containment, and escalation steps. Reducing telemetry or disabling behavioral analytics would make detection weaker. The organization should test new correlations against historical incidents and representative benign activity to balance detection coverage with false-positive control. Strong correlation and repeatable workflows can significantly reduce detection and response time.