Cisco CCNP CyberSecurity 300-215 Practice Test Questions and Exam Dumps Part12 Q221-240

View Full Cisco CCNP CyberSecurity 300-215 Exam Dumps and Practice Test Dumps

 

Question 221.

A SOC analyst notices a user account authenticating successfully from a workstation that has recently generated malware alerts. What should the analyst investigate first?

  1. Whether the account credentials may have been stolen and used from the compromised host
    2. Whether the workstation monitor is connected properly
    3. Whether DHCP assigned the expected lease time
    4. Whether the printer queue is empty

Correct Answer: 1

Explanation:

A successful authentication originating from an endpoint already associated with malware activity raises the possibility that the attacker has stolen and is using valid credentials. The analyst should review the account’s normal behavior, authentication type, privilege level, destination systems, MFA activity, and subsequent actions. Endpoint telemetry from the source host can help identify credential-access tools or suspicious processes. Hardware display, DHCP lease duration, and printer status are unrelated. If credential compromise is confirmed, the incident may extend beyond the infected workstation because the attacker could use the account for lateral movement or persistence. Containment may therefore require both host isolation and account-level action.

Question 222.

Which telemetry source is most useful for determining what process executed immediately after a suspicious user logged on to a Windows server?

  1. DNS cache only
    2. Endpoint process telemetry
    3. Badge reader logs
    4. UPS logs

Correct Answer: 2

Explanation:

Endpoint process telemetry can show which executables launched after authentication, the parent process, command-line arguments, user context, hashes, and associated network activity. This is especially useful when determining whether a legitimate-looking login was followed by malicious remote execution, credential theft, or persistence creation. DNS data may provide network context but does not reveal full process execution details. Physical access and power logs are also not suitable. Analysts should correlate the login event and process timeline carefully so they can establish whether suspicious execution actually followed the authentication and whether the same pattern appears on other hosts.

Question 223.

An analyst detects rundll32.exe executing with an unusual external URL in its command line. Why should this be investigated?

  1. rundll32.exe can never access the network
    2. Every use of rundll32.exe is malicious
    3. A legitimate Windows binary may be abused for living-off-the-land execution
    4. Windows does not include rundll32.exe

Correct Answer: 3

Explanation:

rundll32.exe is a legitimate Windows binary, but attackers may abuse trusted system utilities to execute malicious code or perform actions that blend into normal operating-system activity. This is an example of living-off-the-land behavior. The analyst should review the full command line, parent process, user context, referenced DLL or URL, digital signatures, network connections, and resulting child processes. The presence of a Microsoft-signed executable does not automatically make the behavior safe. Detection should therefore focus on how trusted tools are used rather than blocking all execution of common system utilities.

Question 224.

Which strategy is most effective for detecting abuse of trusted administrative tools by attackers?

  1. Ignore signed utilities
    2. Block every administrative utility
    3. Search only for file hashes
    4. Monitor unusual command-line arguments, parent processes, users, and destinations

Correct Answer: 4

Explanation:

Attackers frequently abuse legitimate administrative tools because these utilities are already present and often trusted. Behavioral context such as unusual command-line parameters, unexpected parent-child relationships, rare network destinations, odd user accounts, or execution from unusual systems can reveal malicious use. Blocking all administrative tools would disrupt legitimate operations, while ignoring signed utilities creates major visibility gaps. File hashes are also insufficient because the abused executable may be completely legitimate. Behavioral analytics combined with user and asset context provide stronger coverage for living-off-the-land techniques and similar abuse of trusted software.

Question 225.

Which condition most strongly suggests that a PowerShell command may be malicious?

  1. It contains encoded content, launches from an unusual parent, and contacts a rare external domain
    2. It is executed on a Windows system
    3. It runs during business hours
    4. It is launched by an administrator

Correct Answer: 1

Explanation:

The combination of encoded PowerShell, an unusual parent process, and communication with a rare external destination is significantly more suspicious than any single characteristic alone. Encoded content can be legitimate, but attackers frequently use encoding to obscure commands. An unusual parent, such as an Office application, may indicate document-based execution, while a rare destination can indicate malware delivery or command-and-control. Windows usage and administrator execution are common in enterprise environments and do not establish maliciousness by themselves. Correlation across process, network, and user context allows analysts to distinguish suspicious activity from legitimate administration.

Question 226.

Which source provides the strongest evidence that a suspicious PowerShell process downloaded and executed another file?

  1. Printer audit logs
    2. PowerShell logging and endpoint file/process telemetry
    3. Building access logs
    4. Network switch temperature

Correct Answer: 2

Explanation:

PowerShell logging can reveal the commands or script content involved, while endpoint telemetry can show file creation, process launches, hashes, and execution relationships. Together, these sources can establish whether PowerShell downloaded a file, where it was written, and whether the file subsequently executed. Network logs can add useful confirmation of the external connection, but endpoint and script telemetry provide the strongest process-level evidence. Physical access and infrastructure temperature data do not explain this activity. The analyst should also determine whether the downloaded file created persistence or communicated with additional external systems.

Question 227.

A SOC observes a user account authenticating to many servers using valid credentials, but no malware files are detected. Which security approach is most useful for identifying whether this is malicious?

  1. Behavioral analysis of authentication patterns
    2. Monitor replacement
    3. File compression
    4. DHCP reservation review

Correct Answer: 1

Explanation:

Valid credentials and legitimate tools can allow attackers to move through an environment without dropping obvious malware. Behavioral analysis can reveal deviations such as an ordinary user suddenly authenticating to many servers, logging in at unusual times, or accessing systems outside their normal role. Analysts should compare current activity with historical baselines and examine the source endpoint, authentication method, privilege level, and actions following login. Hardware and DHCP configuration do not address account behavior. This scenario highlights why identity telemetry is critical for detecting attacks that rely on stolen credentials rather than custom malware.

Question 228.

Which pattern is most characteristic of credential stuffing?

  1. One password attempted against hundreds of accounts
    2. A single account trying thousands of random passwords
    3. Previously stolen username-and-password pairs tested against another service
    4. A user creating a long password

Correct Answer: 3

Explanation:

Credential stuffing uses previously compromised username-and-password combinations against other services, relying on password reuse across platforms. This differs from password spraying, where one or a few common passwords are attempted across many accounts, and brute force, where many password guesses are made against a target. Analysts should review source addresses, user-agent patterns, login frequency, geographic context, and whether successful authentications occur. MFA can significantly reduce the effectiveness of credential stuffing. Organizations should also monitor for known compromised credentials and encourage unique passwords or password managers to reduce reuse.

Question 229.

Which response is most appropriate after confirming that a privileged account was successfully compromised?

  1. Restrict or disable the account as appropriate, revoke active sessions, and investigate its activity
    2. Delete authentication logs
    3. Ignore the account if malware is not detected
    4. Wait until the password naturally expires

Correct Answer: 1

Explanation:

A confirmed compromise of a privileged account requires prompt containment because the attacker may be able to access critical systems, alter controls, or establish persistence. Appropriate actions can include disabling or restricting the account, revoking active sessions or tokens, resetting credentials, and reviewing all recent activity associated with the identity. The exact response should follow organizational procedures and consider business impact. Deleting logs would destroy valuable evidence, and waiting for password expiration leaves the attacker with continued access. Analysts should also determine how the account was compromised and whether other credentials or systems were affected.

Question 230.

Which security technology is most useful for analyzing authentication behavior across many users and identifying unusual identity patterns?

  1. Disk imaging
    2. User and entity behavior analytics
    3. Packet fragmentation
    4. RAID

Correct Answer: 2

Explanation:

User and entity behavior analytics, often called UEBA, applies behavioral analysis to users, devices, and other entities to identify anomalies such as unusual login times, impossible travel, abnormal resource access, or sudden privilege use. UEBA can help detect attacks involving valid credentials that may not trigger traditional malware signatures. It is not a replacement for SIEM, EDR, or identity logs; rather, it relies on those data sources for context. Disk imaging and RAID serve different purposes, while packet fragmentation is a networking behavior. Effective UEBA depends on accurate baselines and careful tuning because legitimate changes in user behavior can produce anomalies.

Question 231.

A workstation begins querying many internal hostnames, user accounts, and shares immediately after an exploit. Which attacker objective is most likely?

  1. Discovery
    2. Impact
    3. Exfiltration
    4. Resource Development

Correct Answer: 1

Explanation:

Discovery includes techniques used to learn about the victim environment after access has been obtained. Querying internal hostnames, users, groups, and network shares helps the attacker identify valuable systems, accounts, and potential lateral-movement paths. The analyst should determine which process performed the enumeration, which account was used, and whether authentication or remote execution followed. Impact concerns disruption, Exfiltration involves removing data, and Resource Development generally involves preparing attack resources. Discovery events are especially meaningful when they occur immediately after suspicious execution or exploitation because the sequence suggests an active intrusion.

Question 232.

Which evidence would most strongly suggest that network discovery was followed by lateral movement?

  1. The endpoint resolves its DNS server
    2. The same host authenticates to several newly discovered servers and launches remote processes
    3. The workstation receives a DHCP lease
    4. An NTP synchronization occurs

Correct Answer: 2

Explanation:

The sequence of discovery followed by authentication and remote process execution on multiple systems strongly supports lateral movement. Attackers often enumerate hosts and services first, then use stolen credentials or remote administration methods to expand access. Analysts should review which account was used, remote logon types, process creation, service creation, file transfers, and whether additional persistence was established. DNS, DHCP, and NTP activity are common network functions and do not indicate lateral movement on their own. Sequence and context are critical when reconstructing attacker behavior.

Question 233.

Which network behavior is most suspicious for possible command-and-control communication?

  1. Repeated low-volume connections from one process to the same rare external destination over long periods
    2. A workstation querying an internal DNS server
    3. Routine software updates from an approved vendor
    4. A normal DHCP renewal

Correct Answer: 1

Explanation:

Repeated low-volume connections to the same rare external destination can indicate command-and-control beaconing, especially when they originate from an unusual or unsigned process. Attackers may use long intervals or timing jitter to blend into background traffic. Analysts should evaluate destination reputation, domain age, TLS certificate data, byte counts, frequency, process identity, and whether similar behavior appears elsewhere. Legitimate monitoring or update applications can also generate periodic traffic, so the activity must be validated. DNS and DHCP are expected infrastructure functions, while approved vendor updates usually have known patterns and destinations.

Question 234.

Which network data would best help an analyst identify the periodicity of suspected command-and-control beaconing?

  1. Asset purchase records
    2. NetFlow or firewall session timestamps
    3. Monitor serial numbers
    4. Keyboard settings

Correct Answer: 2

Explanation:

Flow or firewall session data can provide timestamps, destinations, protocols, durations, and byte counts for repeated network connections. Analysts can use this information to identify periodic or near-periodic communication patterns that may indicate command-and-control beaconing. Even when traffic is encrypted, timing and volume remain useful. Endpoint telemetry can add the process responsible, while DNS and threat intelligence can provide destination context. Hardware inventory does not reveal communication periodicity. Long observation windows may be needed when malware uses low-frequency beaconing or jitter to avoid simple pattern detection.

Question 235.

Which evidence most strongly supports the hypothesis that an attacker staged data before exfiltration?

  1. A large archive appears shortly after bulk access to sensitive files
    2. A workstation renews its DHCP lease
    3. The user changes the desktop wallpaper
    4. An endpoint performs normal NTP synchronization

Correct Answer: 1

Explanation:

Bulk access to sensitive files followed by creation of a large archive is consistent with data staging. Attackers often collect files from multiple locations and compress them before transfer to simplify exfiltration and reduce the number of individual file operations. Analysts should examine archive contents, file access logs, user context, archive process, location, encryption, and subsequent outbound traffic. Backup software can produce similar behavior, so business context is important. DHCP and NTP events are unrelated. If the archive is later transferred to an unusual external destination, confidence in an exfiltration hypothesis increases significantly.

Question 236.

Which source would best help identify whether a suspicious archive was uploaded through HTTPS to an external service?

  1. Printer configuration
    2. Badge access records
    3. BIOS logs
    4. Secure web gateway or proxy telemetry

Correct Answer: 4

Explanation:

Secure web gateway or proxy telemetry can reveal web destinations, users, source systems, timestamps, URLs, request types, and transferred byte counts. Depending on the organization’s TLS inspection capabilities, it may also provide detailed application or file information. Even without full decryption, connection metadata can help correlate an outbound transfer with the time an archive was created. Endpoint telemetry should be reviewed to identify which process performed the upload. Physical and firmware records do not provide application-layer web visibility. Correlating host and network evidence is essential for confirming suspected exfiltration.

Question 237.

Which forensic step best preserves the integrity of a storage device that may contain evidence?

  1. Acquire a forensic image using approved methods and verify it with cryptographic hashes
    2. Open suspicious files directly from the original device
    3. Modify permissions to simplify access
    4. Delete irrelevant files before acquisition

Correct Answer: 1

Explanation:

A forensic image allows investigators to preserve the original storage device while conducting analysis on a copy. Approved acquisition methods, often combined with write blocking, reduce the chance of altering original evidence. Cryptographic hashes verify that the acquired image accurately represents the evidence and remains unchanged during subsequent handling. Opening or modifying the original media can alter metadata or file-system structures, while deleting files destroys evidence. Investigators should document the acquisition method, tool, timestamps, operator, hashes, and storage location in accordance with chain-of-custody requirements.

Question 238.

Which forensic concept identifies the order in which evidence should be collected based on how quickly it may disappear?

  1. Data normalization
    2. Order of volatility
    3. Network segmentation
    4. Least privilege

Correct Answer: 2

Explanation:

Order of volatility prioritizes evidence according to how quickly it can change or disappear. Highly volatile information such as CPU state, active network connections, running processes, and memory may be lost when the system is powered off, while disk data and archival records are generally more persistent. Investigators use this concept to determine collection priorities while balancing the need for containment. The exact collection order depends on organizational procedure and incident circumstances. Data normalization, segmentation, and least privilege are important security concepts but do not define forensic evidence-collection priority.

Question 239.

A compromised host is isolated, but the response team discovers that the attacker created several persistent services and stole domain credentials. Which phase should address these issues before recovery?

  1. Eradication
    2. Preparation
    3. Lessons learned
    4. Identification only

Correct Answer: 1

Explanation:

Eradication removes the attacker’s remaining footholds and addresses the root causes of compromise. In this scenario, the response team should remove malicious services and other persistence mechanisms, reset or revoke compromised credentials, patch exploited vulnerabilities, and eliminate unauthorized tools. Isolation is containment and limits ongoing damage, but it does not remove the attacker from the system. Recovery should not begin until the team has reasonable confidence that these footholds have been eliminated. If the system cannot be trusted, rebuilding from a known-good image may be more appropriate than manual cleanup.

Question 240.

A post-incident review reveals that analysts had good detections but spent too much time manually collecting identical context for each alert. Which improvement would most directly help?

  1. Disable the alerts
    2. Reduce telemetry retention
    3. Automate repeatable enrichment steps while retaining analyst control over high-impact decisions
    4. Remove asset and user context from investigations

Correct Answer: 3

Explanation:

Automating repetitive enrichment can substantially improve SOC efficiency. A workflow can automatically retrieve asset criticality, user role, recent authentication activity, domain reputation, endpoint status, and related alerts before an analyst begins investigation. This reduces manual effort and improves consistency. High-impact actions such as disabling privileged accounts or isolating critical production systems may still require human approval depending on organizational policy. Disabling detections or removing context would reduce security effectiveness. Well-designed automation allows analysts to spend more time on judgment, scoping, and complex response tasks rather than repeatedly gathering the same basic information.