View Full Cisco CCNP CyberSecurity 300-215 Exam Dumps and Practice Test Dumps
Question 201.
A SOC analyst receives an alert showing that a standard user account executed a remote administration tool on several servers. Which factor would most strongly increase the likelihood that the activity is malicious?
- The account normally has no administrative responsibilities and has never accessed those servers
2. The servers use static IP addresses
3. The connections occurred over TCP
4. The servers are located in the same data center
Correct Answer: 1
Explanation:
The strongest indicator is that the account’s activity significantly deviates from its established baseline. A standard user who does not normally administer systems suddenly using remote-management software against several servers may indicate stolen credentials, lateral movement, or attacker abuse of legitimate tools. The analyst should review the originating endpoint, authentication events, remote process execution, command lines, privilege changes, and subsequent server activity. Static IP addressing, TCP communication, and common physical location are normal infrastructure characteristics and do not meaningfully establish malicious intent. Behavioral context is especially useful when attackers use legitimate administrative tools because those utilities may not generate traditional malware signatures.
Question 202.
Which source would best help an analyst determine whether the remote administration activity in the previous scenario was initiated from a compromised workstation?
- Printer logs
2. Endpoint process and network telemetry from the source workstation
3. Power distribution unit logs
4. Monitor inventory
Correct Answer: 2
Explanation:
Endpoint telemetry from the originating workstation can show which process launched the remote administration tool, the user context, parent process, command-line arguments, file path, network connections, and associated suspicious activity. This can help determine whether the tool was intentionally launched by the user, spawned by malware, or executed through another compromised process. Printer, monitor, and power infrastructure records do not provide relevant process-level visibility. Analysts should correlate source endpoint data with authentication and destination-host telemetry so they can reconstruct the full sequence from initial execution through remote access and any actions performed after connection.
Question 203.
An analyst sees a legitimate Windows utility being used to download a payload from an external server. Which security concept best describes this attacker behavior?
- Hardware failure
2. Asset discovery only
3. Living off the land
4. Physical intrusion
Correct Answer: 3
Explanation:
Living-off-the-land techniques involve abusing legitimate tools, interpreters, and operating-system utilities to perform malicious actions. Attackers may use trusted binaries, scripting engines, administrative tools, or built-in network utilities to download payloads, execute commands, move laterally, or evade simplistic application controls. Because the executable itself may be trusted and digitally signed, detections should focus on unusual command lines, parent-child relationships, destinations, user context, and resulting behavior. The presence of a legitimate utility does not make the activity benign. Behavioral detection is particularly important for identifying this type of abuse because static malware signatures may not apply.
Question 204.
Which detection strategy is most effective for identifying living-off-the-land activity?
- Block every signed Windows binary
2. Ignore trusted system utilities
3. Search only for known malware hashes
4. Monitor unusual command lines, process relationships, and network behavior involving trusted utilities
Correct Answer: 4
Explanation:
Living-off-the-land activity often uses legitimate signed tools, so simply allowing trusted binaries or searching for malicious hashes is insufficient. Analysts should detect unusual use patterns such as suspicious command-line parameters, unexpected parent processes, execution from unusual users, remote downloads, credential access, or uncommon network destinations. Context matters because many of these tools are also used legitimately by administrators. Blocking all system utilities would disrupt normal operations, while ignoring them would create major blind spots. Effective behavioral detections focus on how and where trusted tools are used rather than treating the executable name alone as evidence of maliciousness.
Question 205.
A workstation begins making outbound connections to an IP address that has never been contacted by any other corporate device. Which additional evidence would most increase concern?
- The connection is initiated by an unsigned executable running from a temporary directory
2. The workstation uses DHCP
3. The destination responds to ICMP
4. The user has a corporate email account
Correct Answer: 1
Explanation:
A rare external destination becomes substantially more suspicious when the connection originates from an unsigned executable in a temporary directory. This combination of destination rarity, unusual execution location, and weak software trust signals may indicate malware or command-and-control activity. Analysts should inspect the file hash, creation time, parent process, command line, digital signature, persistence mechanisms, and associated DNS activity. DHCP use and corporate email access are ordinary enterprise characteristics. ICMP responsiveness also does not establish legitimacy or maliciousness. Strong conclusions come from combining network rarity with endpoint behavior and threat-intelligence context.
Question 206.
Which type of analytics is most useful for identifying destinations that are rarely contacted by the organization?
- File carving
2. Network behavioral analytics
3. Disk imaging
4. Physical access auditing
Correct Answer: 2
Explanation:
Network behavioral analytics can identify rare destinations, unusual protocols, unexpected traffic volumes, and deviations from historical communication patterns. A domain or IP contacted by only one host may warrant additional investigation, particularly when combined with suspicious endpoint activity. Rarity alone does not prove maliciousness because legitimate users may access new business services or vendor infrastructure. Analysts should correlate network anomalies with process identity, user behavior, threat intelligence, domain age, TLS certificate data, and asset role. Disk imaging and physical access auditing serve different investigative purposes and do not provide the same network-behavior context.
Question 207.
A SOC analyst observes DNS queries to a domain that changes resolved IP addresses frequently across multiple countries. Which threat technique could this behavior indicate?
- Local ARP resolution
2. Static addressing
3. Fast-flux infrastructure
4. DHCP reservation
Correct Answer: 3
Explanation:
Fast-flux infrastructure uses rapidly changing DNS mappings to make malicious services more resilient and difficult to block or take down. A domain may resolve to many IP addresses over short time periods, often distributed across different networks or geographic regions. This technique has been associated with botnets, phishing, malware distribution, and command-and-control infrastructure. However, legitimate content-delivery networks also use dynamic addressing, so analysts should consider domain reputation, registration age, autonomous system information, TTL values, certificate data, and endpoint context. The DNS pattern itself is an investigative clue rather than definitive proof of malicious activity.
Question 208.
Which intelligence source would best help an analyst examine historical relationships between a suspicious domain and previously used IP addresses?
- Endpoint asset inventory
2. Windows Event Viewer only
3. DHCP lease data only
4. Passive DNS intelligence
Correct Answer: 4
Explanation:
Passive DNS intelligence records historical mappings between domains and IP addresses, helping analysts understand how infrastructure has changed over time. It can reveal previously associated addresses, related domains, hosting providers, and infrastructure reuse. This is valuable for expanding threat hunts and identifying additional indicators related to a malicious campaign. DHCP data is useful for internal host attribution but does not provide internet-wide historical domain relationships. Endpoint inventory and local event logs also cannot replace passive DNS. Analysts should still interpret passive DNS carefully because shared hosting and cloud environments can associate many unrelated domains with the same address.
Question 209.
An analyst sees a suspicious executable spawn a command shell, create a scheduled task, and contact an external server. Which approach best helps reconstruct the attack sequence?
- Build a timeline from endpoint, network, and authentication telemetry
2. Review only the file hash
3. Check printer status
4. Reboot the endpoint repeatedly
Correct Answer: 1
Explanation:
A timeline allows the analyst to place related events in chronological order and understand causality. Endpoint process telemetry can show executable and command-shell activity, task creation events can reveal persistence, and network records can identify command-and-control communication. Authentication data may reveal which user context was involved and whether lateral movement followed. Looking only at a hash provides limited insight into sequence and behavior. Repeated rebooting can alter evidence and may remove volatile information. Accurate timestamps, time-zone normalization, and consistent host identifiers are essential when building a reliable incident timeline across multiple sources.
Question 210.
Why is accurate time synchronization important in a multi-system security investigation?
- It increases available bandwidth
2. It allows events from different systems to be placed in the correct chronological order
3. It prevents malware execution
4. It eliminates the need for logs
Correct Answer: 2
Explanation:
Accurate time synchronization allows analysts to correlate activity across endpoints, firewalls, identity systems, proxies, email gateways, and cloud services. If systems have significant clock drift or use inconsistent time zones, events can appear to occur in the wrong order, making it difficult to determine whether one action caused another. Analysts should know whether each source records UTC or local time and should normalize timestamps during investigation. Time synchronization does not prevent malware or replace logging. Reliable chronology is critical when reconstructing attack stages such as phishing delivery, code execution, credential theft, lateral movement, persistence, and exfiltration.
Question 211.
Which MITRE ATT&CK tactic best describes an adversary attempting to identify local users, domain groups, and available network shares?
- Discovery
2. Impact
3. Exfiltration
4. Persistence
Correct Answer: 1
Explanation:
Discovery includes techniques used by adversaries to learn about the compromised environment. Enumerating users, groups, systems, network shares, security products, and domain information helps attackers understand where valuable resources exist and which accounts or systems may support further movement. Impact concerns disruption, Exfiltration involves removing information, and Persistence focuses on maintaining access. Discovery can resemble legitimate administrative activity, so analysts should evaluate who performed it, which process was used, the volume and timing of queries, and whether the activity followed suspicious execution or authentication. ATT&CK mapping helps defenders communicate these behaviors consistently and build targeted detection coverage.
Question 212.
Which MITRE ATT&CK tactic best describes an adversary compressing stolen documents into an archive before transferring them externally?
- Initial Access
2. Collection
3. Credential Access
4. Reconnaissance
Correct Answer: 2
Explanation:
Compressing gathered documents into an archive is typically associated with Collection and staging activities. Attackers often consolidate files before exfiltration because one archive is easier to transfer and may reduce the visibility of individual documents. Encryption or password protection can further obscure the contents. Analysts should correlate archive creation with bulk file access, user context, process activity, and subsequent outbound network transfers. Initial Access concerns gaining the first foothold, Credential Access focuses on authentication material, and Reconnaissance generally occurs before or around targeting. A suspicious archive should be analyzed within the broader attack timeline rather than treated as an isolated artifact.
Question 213.
A user account reads thousands of files from a sensitive share and then uploads several gigabytes to an external service. Which evidence would best help determine whether the activity was authorized?
- Historical user behavior and business role context
2. Monitor model
3. Server rack position
4. DHCP scope name
Correct Answer: 1
Explanation:
Historical behavior and business context are critical for determining whether high-volume file access and external transfer are normal for the account. A backup operator or approved data-transfer service may legitimately handle large volumes, while the same behavior from an ordinary user could be highly suspicious. Analysts should also review destination approval status, endpoint process information, authentication events, data classification, and any relevant change tickets or business workflows. Hardware and addressing details do not explain authorization. Security analytics should combine technical anomalies with user and asset context to avoid both false positives and missed insider or credential-abuse incidents.
Question 214.
An analyst needs to determine whether an endpoint attempted to communicate directly with a known malicious IP address, even though no proxy was used. Which log source is most appropriate?
- Physical badge logs
2. Firewall connection logs
3. Printer spooler logs
4. Hardware warranty records
Correct Answer: 2
Explanation:
Firewall logs can show direct network connections between an internal endpoint and an external IP address, including source and destination addresses, ports, protocols, timestamps, actions, and sometimes transferred byte counts. This is especially useful when traffic does not traverse an application proxy. Analysts should correlate the firewall event with EDR telemetry to identify which process initiated the connection. DNS logs can also help if the IP was reached through domain resolution. Physical and hardware records do not provide network communication evidence. Firewall telemetry is often one of the primary sources used to scope external communications during incident response.
Question 215.
Which forensic practice best preserves the original storage device while allowing detailed examination?
- Acquire a forensic image and analyze a verified copy
2. Browse the original drive interactively
3. Delete unrelated files before acquisition
4. Modify file permissions to simplify access
Correct Answer: 1
Explanation:
Creating a forensic image and analyzing a verified copy helps preserve the original evidence. The image should be acquired using approved procedures, ideally with controls that prevent writes to the source, and validated using cryptographic hashes. Investigators can then perform detailed analysis on working copies while retaining the original media in a protected state. Interactively browsing or modifying the original drive can alter metadata, timestamps, or file-system structures. Deleting files before acquisition would compromise evidence. Proper forensic handling also requires documentation, secure storage, and chain-of-custody records when the investigation may have legal or regulatory significance.
Question 216.
What is the purpose of a write blocker during forensic acquisition?
- To accelerate network traffic
2. To remove malicious files
3. To calculate threat reputation
4. To prevent the acquisition system from modifying the source media
Correct Answer: 4
Explanation:
A write blocker prevents writes from the forensic workstation to the original storage device. This helps preserve file-system metadata, timestamps, deleted-file structures, and other evidence in its original state. Hardware write blockers are commonly used, although validated software mechanisms may also be appropriate in some workflows. A write blocker does not remove malware, calculate threat reputation, or improve network performance. It should be used together with forensic imaging, cryptographic hashing, chain-of-custody documentation, and secure evidence storage. Preserving the original media makes later analysis more reliable and defensible.
Question 217.
An endpoint is confirmed to be actively spreading malware through the internal network. Which response action should receive the highest priority?
- Contain the endpoint to stop further propagation
2. Perform the lessons-learned meeting
3. Delete all evidence
4. Wait for users to report additional infections
Correct Answer: 1
Explanation:
When malware is actively propagating, rapid containment is essential to limit the number of affected systems and reduce business impact. Isolation may be performed through EDR network containment, firewall rules, segmentation, switch controls, or physical disconnection depending on organizational procedures. If critical volatile evidence can be collected safely and quickly, responders may preserve it before full isolation, but stopping active spread remains a priority. Lessons learned occurs later, and deleting evidence would hinder investigation. Once contained, analysts can scope the environment, identify the initial vector, remove persistence, address compromised credentials, and proceed with eradication.
Question 218.
Which activity belongs primarily to the eradication phase of incident response?
- Creating the initial incident-response policy
2. Removing malware, persistence mechanisms, and compromised credentials
3. Monitoring a restored system for recurrence
4. Conducting annual security awareness training
Correct Answer: 2
Explanation:
Eradication focuses on removing the attacker’s presence and addressing the conditions that enabled compromise. This may include deleting malware, removing malicious services or scheduled tasks, patching exploited vulnerabilities, resetting compromised credentials, revoking access tokens, and eliminating unauthorized accounts. Creating policies is a preparation activity, monitoring restored systems belongs primarily to recovery, and awareness training is a broader preventive control. Eradication must address the root cause rather than only visible symptoms. If the response team removes one payload but leaves stolen credentials or persistence intact, the attacker may quickly regain access.
Question 219.
Which action is most appropriate during the recovery phase after eradication is complete?
- Restore systems to normal operations while validating security and monitoring for recurrence
2. Disable security controls before reconnecting systems
3. Delete the incident record
4. Restore known malicious scheduled tasks
Correct Answer: 1
Explanation:
Recovery returns systems and services to normal operations in a controlled manner. Before reconnection, teams should verify patch levels, security controls, credentials, configurations, and the absence of known malicious artifacts. Restored or rebuilt systems should then be monitored closely for recurrence because renewed command-and-control, suspicious authentication, or persistence activity may indicate incomplete eradication. Disabling protection or restoring malicious artifacts would undermine the response. Incident records should remain available for reporting and lessons learned. Recovery balances business restoration with confidence that the environment is no longer under attacker control.
Question 220.
A post-incident review reveals that analysts repeatedly missed suspicious activity because important endpoint and identity events were stored in separate tools and never correlated. Which improvement is most appropriate?
- Stop collecting identity data
2. Shorten all log retention periods
3. Integrate and correlate endpoint and identity telemetry within the SOC workflow
4. Disable detections that use multiple data sources
Correct Answer: 3
Explanation:
Integrating endpoint and identity telemetry allows analysts to connect suspicious process execution with account activity, remote logins, privilege changes, and lateral movement. A single event may appear benign when viewed in isolation, while correlated data can expose a complete attack sequence. The SOC should normalize important fields, establish consistent timestamps, build correlation rules, and update investigation playbooks so analysts can pivot efficiently between users, endpoints, and network activity. Reducing telemetry or retention would make future investigations harder. Post-incident improvements should convert identified visibility gaps into practical changes that shorten detection time and improve analyst confidence.