View Full Cisco CCNP CyberSecurity 300-215 Exam Dumps and Practice Test Dumps
Question 241.
A SOC analyst observes a compromised endpoint attempting authentication to multiple internal servers using the same account. Which activity should be investigated first?
- Potential lateral movement using stolen credentials
2. Printer spooler status
3. DHCP lease renewal
4. Monitor firmware version
Correct Answer: 1
Explanation:
Repeated authentication from a known compromised endpoint to multiple internal servers strongly suggests possible lateral movement. The analyst should review the account used, destination systems, authentication methods, logon types, privilege level, timestamps, and activity that followed each successful login. Endpoint telemetry from the source host can help determine whether malware, a remote administration tool, or a script initiated the connections. Authentication behavior should also be compared with historical baselines to distinguish legitimate administration from compromise. Printer, DHCP, and display information are unrelated to the security question. If the account is confirmed compromised, containment may require host isolation, session revocation, credential reset, and broader scoping for additional affected systems.
Question 242.
Which log source is most useful for identifying whether a remote Windows login was followed by suspicious process execution on the destination host?
- Badge access records
2. Endpoint process telemetry on the destination system
3. Printer queue history
4. UPS event logs
Correct Answer: 2
Explanation:
Endpoint process telemetry on the destination host can reveal what executed immediately after a remote login, including process names, parent-child relationships, command-line arguments, user context, file paths, and network connections. This helps determine whether the login was followed by legitimate administration or suspicious remote execution. Authentication logs provide important identity context, but process telemetry shows what the account actually did after access was established. Physical access, printer, and UPS logs do not provide this visibility. Analysts should correlate source and destination telemetry to reconstruct the sequence and determine whether the same behavior occurred elsewhere in the environment.
Question 243.
An analyst notices that wmic.exe is being used remotely from a workstation that has never performed administrative tasks before. Which concept best describes the potential attacker behavior?
- Data staging
2. Physical intrusion
3. Living off the land
4. Backup validation
Correct Answer: 3
Explanation:
Living-off-the-land behavior involves abusing legitimate, built-in tools for malicious purposes. Utilities such as WMI-related tools can be used by administrators for legitimate management, but attackers may also use them for remote execution, discovery, or lateral movement because they are trusted and already present. The analyst should review command-line arguments, user context, source and destination hosts, authentication events, and any child processes or network activity that followed. The fact that the source workstation normally performs no administrative activity increases suspicion. Behavioral context is essential because the tool itself is not inherently malicious.
Question 244.
Which detection approach is most effective for identifying malicious use of built-in system utilities such as PowerShell, WMI, or command shells?
- Block all signed binaries
2. Ignore built-in tools because they are trusted
3. Search only for malware hashes
4. Analyze command lines, parent processes, user context, and resulting behavior
Correct Answer: 4
Explanation:
Trusted system utilities are frequently used legitimately, so neither blanket blocking nor unconditional trust is appropriate. Behavioral analysis is more effective because it examines how the tool is being used. Suspicious command-line arguments, unusual parent-child relationships, unexpected users, rare destinations, encoded content, or abnormal remote execution patterns can reveal abuse. Hash-based detection alone is inadequate because the tool may be a legitimate operating-system binary. The strongest detections combine process behavior with endpoint, identity, and network telemetry. This approach helps identify attacker use of legitimate tools while reducing false positives from normal administration.
Question 245.
A workstation begins contacting a newly registered domain immediately after a suspicious script executes. Which additional artifact would provide the strongest evidence that the script initiated the connection?
- EDR process-to-network telemetry
2. DHCP lease duration
3. Printer audit logs
4. Monitor inventory
Correct Answer: 1
Explanation:
EDR process-to-network telemetry can directly associate an outbound connection with the process that generated it. This allows the analyst to determine whether the suspicious script interpreter or a child process contacted the newly registered domain. The analyst can also review the process path, command line, hash, parent process, user context, and related file activity. DHCP information may help map an IP address to a device but does not identify the initiating process. Printer and display data are unrelated. Correlating process and network activity is especially valuable when investigating command-and-control or malware-delivery behavior.
Question 246.
Which threat-intelligence attribute should an analyst consider when deciding whether to block a newly reported malicious domain automatically?
- The domain name length only
2. Confidence, freshness, and source reliability
3. Whether the domain contains numbers
4. Whether the domain resolves quickly
Correct Answer: 2
Explanation:
Threat-intelligence indicators vary in quality and lifespan. Before automatically blocking a domain, analysts should evaluate how recently malicious activity was observed, how reliable the source is, and the confidence assigned to the indicator. Domains can change ownership, infrastructure can be repurposed, and low-confidence intelligence can create false positives. Domain length, use of numbers, and DNS response speed do not determine maliciousness. High-confidence, fresh indicators tied to active campaigns may justify immediate blocking, while lower-confidence intelligence may be more appropriate for alert enrichment or investigation. Context should always guide automation decisions.
Question 247.
A security analyst wants to identify whether a suspicious domain shares infrastructure with other known malicious domains. Which source would be most useful?
- Passive DNS intelligence
2. BIOS inventory
3. Printer logs
4. File-system permissions
Correct Answer: 1
Explanation:
Passive DNS intelligence can reveal historical relationships between domains and IP addresses, making it useful for infrastructure analysis. If several suspicious domains resolved to the same IP addresses or shared similar hosting patterns, analysts may identify broader malicious infrastructure or campaign relationships. Passive DNS should be interpreted carefully because shared hosting and cloud platforms can place unrelated domains on the same infrastructure. Additional context such as registration data, certificate information, threat reputation, and timestamps improves confidence. BIOS, printer, and file-permission data do not provide external DNS infrastructure relationships.
Question 248.
Which network pattern would most strongly suggest command-and-control beaconing rather than ordinary interactive browsing?
- One large web download from an approved vendor
2. Repeated small connections at similar intervals to a rare external destination
3. A user opening several internal web pages
4. A routine software update
Correct Answer: 2
Explanation:
Command-and-control malware often sends periodic small connections to check in with attacker infrastructure, receive commands, or report host status. Repeated communication to a rare external destination with similar timing and small payloads can therefore indicate beaconing. Legitimate software can behave similarly, so analysts should also review the responsible process, domain reputation, certificate data, timing jitter, byte counts, and whether other hosts show the same pattern. Interactive browsing is typically more irregular and user-driven. Correlating network periodicity with endpoint process data is one of the best ways to distinguish malicious beaconing from legitimate automated traffic.
Question 249.
An analyst sees beacon-like traffic with intervals that vary randomly between 5 and 10 minutes. Why might malware use this pattern?
- To make periodic communication less obvious to simple detections
2. To improve DHCP reliability
3. To increase DNS cache lifetime
4. To speed up disk access
Correct Answer: 1
Explanation:
Malware may use jitter, or randomized timing variation, to avoid detections that look for perfectly regular periodic connections. Instead of contacting command-and-control infrastructure exactly every five minutes, the malware may choose a random delay within a range. This makes the pattern blend more naturally into ordinary network traffic. Analysts can still detect this behavior by examining long-term destination rarity, process identity, repeated connections, similar byte counts, and statistical timing characteristics. DHCP, DNS cache behavior, and disk performance are unrelated to beacon timing. Strong behavioral analytics are needed to detect attackers who intentionally reduce obvious periodicity.
Question 250.
Which source would be most useful for determining the total amount of data transferred from an internal system to an external IP address over a period of several hours?
- Physical badge logs
2. NetFlow or firewall traffic records
3. BIOS event logs
4. Printer queue data
Correct Answer: 2
Explanation:
NetFlow and firewall traffic records can provide byte counts, packet counts, source and destination addresses, protocols, ports, session duration, and timestamps. This makes them useful for measuring outbound data volume and identifying possible exfiltration. Analysts can compare the observed transfer volume with historical baselines and the host’s normal role. A large transfer is not automatically malicious because backups, cloud synchronization, and software distribution can be legitimate. Additional context from endpoint telemetry, proxy data, and data-classification systems may be required. Physical, BIOS, and printer information do not provide network transfer volume.
Question 251.
An endpoint accesses thousands of sensitive files in a short time and then creates a compressed archive. Which attacker activity is most likely occurring?
- Data collection and staging
2. DNS resolution
3. DHCP discovery
4. Network time synchronization
Correct Answer: 1
Explanation:
Bulk access to sensitive files followed by creation of a compressed archive is consistent with collection and staging. Attackers often gather documents from multiple locations and package them into a single archive before exfiltration. This reduces the number of files that must be transferred and may make the operation less obvious. Analysts should examine the process that created the archive, the account involved, file types, archive location, encryption settings, and any subsequent outbound network activity. Legitimate backup or archival software can produce similar behavior, so business context is important. DNS, DHCP, and NTP do not explain this sequence.
Question 252.
Which MITRE ATT&CK tactic best describes gathering sensitive files from multiple systems before transferring them externally?
- Persistence
2. Collection
3. Defense Evasion
4. Resource Development
Correct Answer: 2
Explanation:
Collection describes adversary techniques used to gather information of interest before it is transferred, analyzed, or otherwise used. Attackers may collect documents, browser data, email, screenshots, database information, or files from shared storage. This activity often precedes staging and exfiltration. Persistence focuses on maintaining access, Defense Evasion is about avoiding detection, and Resource Development relates to preparing infrastructure and capabilities. Analysts should look for bulk file access, unusual archive creation, temporary staging directories, and outbound transfers. ATT&CK mapping helps organize observations into a broader understanding of the attack lifecycle.
Question 253.
Which evidence would most strongly indicate that collected data was actually exfiltrated?
- A matching outbound transfer to an unusual external destination shortly after archive creation
2. The archive has a .zip extension
3. The user has write permissions to the folder
4. The endpoint is connected to Ethernet
Correct Answer: 1
Explanation:
Archive creation suggests staging, but it does not prove the data left the organization. A large outbound transfer to an unusual destination shortly afterward provides much stronger evidence of exfiltration. Analysts should correlate transfer size, timing, process identity, destination reputation, protocol, and user context. If possible, secure web gateway, firewall, or DLP data may show the specific service or file involved. A .zip extension or folder permissions do not establish that data was transmitted externally. Ethernet connectivity is normal and irrelevant. The strongest conclusions come from correlating host and network evidence into a clear sequence.
Question 254.
Which telemetry would best help determine whether an archive was uploaded to a cloud-storage service through a web browser?
- Network switch fan speed
2. Secure web gateway or proxy logs
3. BIOS configuration
4. DHCP reservation details
Correct Answer: 2
Explanation:
Secure web gateway or proxy logs can provide destination URLs, domains, usernames, client IP addresses, timestamps, request types, and byte counts. Depending on inspection capabilities, they may also identify upload actions or file-related details. Analysts should correlate the web activity with browser process telemetry and the time the archive was created. If TLS inspection is unavailable, metadata can still be useful in confirming a large session to a cloud-storage service. Switch, BIOS, and DHCP information do not reveal application-layer upload behavior. Endpoint and network evidence should be combined to establish whether the transfer was authorized.
Question 255.
Which forensic evidence should generally be acquired before shutting down a live compromised system when memory artifacts are important to the investigation?
- Volatile memory
2. Printed network diagrams
3. Asset purchase records
4. Hardware warranty information
Correct Answer: 1
Explanation:
Volatile memory can contain running processes, injected code, active network connections, encryption keys, command history, credentials, and other artifacts that may disappear when power is removed. If the investigation requires this information and organizational procedures permit it, memory should be collected before shutdown. The response team must still balance evidence preservation with containment because a live compromised host may continue causing damage. Persistent documents and administrative records can be collected later. The memory image should be documented, hashed, and protected according to evidence-handling procedures when forensic integrity is required.
Question 256.
Which forensic tool helps protect an original storage device from modification during imaging?
- SIEM connector
2. VPN gateway
3. Proxy server
4. Write blocker
Correct Answer: 4
Explanation:
A write blocker prevents writes to the source storage device during forensic acquisition. This helps preserve file-system metadata, timestamps, deleted-file structures, and other evidence. Hardware write blockers are commonly used, though validated software mechanisms may also be appropriate. A write blocker does not replace forensic imaging, cryptographic hashing, or chain-of-custody documentation; it simply reduces the risk of accidental modification. SIEM connectors, VPN gateways, and proxy servers have unrelated functions. Evidence should generally be analyzed from verified forensic copies while the original media is securely preserved.
Question 257.
A system is actively communicating with known command-and-control infrastructure. Which incident-response phase should focus on stopping that communication quickly?
- Containment
2. Lessons learned
3. Recovery
4. Preparation
Correct Answer: 1
Explanation:
Containment aims to limit the immediate impact of an incident and prevent additional attacker activity. Stopping command-and-control communication may involve isolating the endpoint, blocking malicious infrastructure, restricting compromised accounts, or segmenting affected systems. The exact method should follow organizational procedures and balance containment with evidence preservation. Recovery happens after eradication, lessons learned follows incident resolution, and preparation occurs before an incident. Quick containment can reduce data loss, lateral movement, and malware propagation, but it should be followed by thorough scoping and eradication rather than treated as the final solution.
Question 258.
Which action belongs primarily to the eradication phase?
- Monitoring for recurrence after restoration
2. Removing malware, persistence, and compromised credentials
3. Writing the initial incident-response policy
4. Conducting routine security awareness training
Correct Answer: 2
Explanation:
Eradication removes the attacker’s footholds and addresses the root cause of compromise. This can include deleting malware, removing malicious services or scheduled tasks, resetting compromised credentials, revoking tokens, patching exploited vulnerabilities, and removing unauthorized accounts. Monitoring for recurrence is mainly associated with recovery, while policy creation and awareness training belong to preparation or general security operations. Eradication must be comprehensive. If only the visible malware is removed while stolen credentials or persistence remain active, the attacker may regain access. In severe cases, rebuilding systems from trusted images may provide stronger assurance.
Question 259.
Which action is most appropriate during recovery after eradication has been completed?
- Return validated systems to service and monitor closely for recurrence
2. Disable endpoint protection
3. Delete all investigation records
4. Restore known malicious files for comparison
Correct Answer: 1
Explanation:
Recovery returns systems and services to normal operations after the active threat and its root causes have been addressed. Before reconnection, teams should verify patches, security controls, credentials, system configuration, and the absence of known malicious artifacts. Restored systems should be monitored closely because renewed command-and-control traffic or suspicious authentication may indicate incomplete eradication. Disabling security controls or restoring malware would undermine the response. Investigation records should remain available for audit, lessons learned, and future detection improvement. Recovery should balance business continuity with confidence that the environment is safe.
Question 260.
A post-incident review shows that analysts repeatedly had to perform the same manual searches across EDR, SIEM, DNS, and threat-intelligence systems. Which improvement would most directly reduce response time?
- Reduce telemetry sources
2. Shorten retention periods
3. Automate common enrichment and pivoting steps within the investigation workflow
4. Disable correlations involving multiple platforms
Correct Answer: 3
Explanation:
Automating common enrichment and pivoting tasks can significantly reduce analyst workload and response time. A workflow can automatically collect endpoint details, user information, DNS history, domain reputation, related alerts, asset criticality, and recent authentication activity when an alert arrives. Analysts can then focus on judgment, scoping, and containment instead of repeatedly gathering the same context. High-impact actions can remain subject to human approval. Reducing telemetry or disabling cross-platform correlation would weaken visibility. Post-incident reviews should identify repetitive manual processes and convert them into tested, documented automation where doing so improves consistency without sacrificing control.