Cisco CCNP CyberSecurity 300-215 Practice Test Questions and Exam Dumps Part15 Q281-300

View Full Cisco CCNP CyberSecurity 300-215 Exam Dumps and Practice Test Dumps

 

Question 281.

A SOC analyst sees a privileged account authenticate to several servers from a workstation that is normally used only for email and web browsing. Which interpretation is most appropriate?

  1. The activity may indicate credential misuse or lateral movement and should be investigated
    2. The behavior is automatically legitimate because the account is privileged
    3. The workstation should be ignored because it is not a server
    4. The event is caused by normal DHCP activity

Correct Answer: 1

Explanation:

A privileged account authenticating from a workstation that does not normally perform administrative activity is a meaningful behavioral anomaly. The analyst should review the source endpoint, account owner, MFA events, logon types, destination systems, and processes launched after authentication. Endpoint telemetry may reveal whether malware, PowerShell, a remote administration utility, or another process initiated the activity. Privileged status does not make unusual behavior inherently legitimate. In fact, privilege increases potential impact if credentials are compromised. Historical baselines, user role information, and source-device reputation should all contribute to prioritization and response decisions.

Question 282.

Which data source would best help determine whether the privileged account in the previous scenario launched remote commands after authentication?

  1. Printer server logs
    2. Endpoint process telemetry from the destination systems
    3. Wireless channel utilization
    4. Badge-reader battery status

Correct Answer: 2

Explanation:

Endpoint process telemetry on the destination systems can show what executed after the remote authentication, including process names, parent-child relationships, command lines, user context, file paths, and network behavior. This helps determine whether the activity was legitimate administration or unauthorized remote execution. Authentication logs provide identity context, but process telemetry explains what happened after access was granted. Printer, wireless channel, and badge-reader information do not provide relevant execution evidence. Analysts should correlate destination events with the source workstation timeline to reconstruct the complete sequence accurately.

Question 283.

An analyst observes mshta.exe launching a script retrieved from an external location. Which security concept best describes the potential attacker technique?

  1. Hardware inventory
    2. Physical access abuse
    3. Living off the land
    4. Data deduplication

Correct Answer: 3

Explanation:

Living-off-the-land techniques abuse legitimate system utilities and trusted binaries to perform malicious actions. mshta.exe is a legitimate Windows component, but attackers may misuse it to execute remote or local script content. Because the binary itself may be signed and trusted, static reputation alone may not identify malicious use. Analysts should inspect the command line, external URL, parent process, user context, subsequent child processes, file activity, and outbound connections. Behavioral detection is especially valuable for this class of activity because the distinction between legitimate and malicious use depends heavily on execution context.

Question 284.

Which strategy is most effective for detecting malicious use of mshta.exe, PowerShell, or other trusted Windows utilities?

  1. Trust all digitally signed executables automatically
    2. Disable all Windows administrative tools
    3. Search only for known malicious file hashes
    4. Detect suspicious command lines, execution chains, users, and network destinations

Correct Answer: 4

Explanation:

Trusted Windows tools are frequently used for legitimate administration, but they can also be abused by attackers. Effective detection therefore focuses on context: suspicious command-line parameters, unusual parent processes, encoded scripts, unexpected users, rare destinations, or abnormal child processes. Trusting all signed binaries would create major blind spots, while disabling every administrative tool would disrupt normal operations. File-hash detection is also insufficient because the underlying utility may be a legitimate Microsoft binary. Behavioral analytics combined with identity and network context provide much stronger coverage.

Question 285.

A workstation contacts an unfamiliar external domain immediately after an Office application launches a script interpreter. Which investigative action provides the strongest next step?

  1. Correlate the process tree with DNS, proxy, and network connection telemetry
    2. Replace the user’s keyboard
    3. Disable DHCP
    4. Delete the user’s browsing history

Correct Answer: 1

Explanation:

The combination of an Office application launching a script interpreter and subsequent communication with an unfamiliar domain may indicate malicious document execution. Correlating the process tree with DNS, proxy, firewall, and endpoint network telemetry can establish whether the script or a child process generated the connection. The analyst should also inspect command-line arguments, downloaded files, persistence changes, and email-delivery context. Hardware replacement or DHCP changes do not address the incident. Deleting browsing history could also destroy useful evidence. Cross-source correlation helps turn isolated suspicious events into a coherent attack sequence.

Question 286.

Which threat-intelligence attribute is most important when deciding whether an IP address observed in a six-month-old report should still be blocked today?

  1. The number of digits in the address
    2. Freshness and current context
    3. Whether it responds to ping
    4. Whether it belongs to a private range

Correct Answer: 2

Explanation:

Threat-intelligence indicators can become stale. An IP address associated with malicious activity six months ago may have since been reassigned to a legitimate user or cloud workload. Analysts should therefore evaluate freshness, current reputation, source reliability, observed timestamps, and campaign context before using an old indicator for automatic blocking. Ping responsiveness does not establish maliciousness, and address formatting is irrelevant. Freshness is particularly important for IP intelligence because hosting providers, cloud systems, and dynamic infrastructure can change ownership quickly.

Question 287.

Which intelligence source would be most useful for discovering domains that historically resolved to the same suspicious IP address?

  1. Passive DNS intelligence
    2. Endpoint registry data
    3. Printer audit logs
    4. BIOS event history

Correct Answer: 1

Explanation:

Passive DNS intelligence records historical mappings between domains and IP addresses. This can help analysts identify related infrastructure, discover additional domains used by the same campaign, and understand how malicious hosting changed over time. Shared hosting and cloud infrastructure can create benign relationships, so analysts should combine passive DNS with registration data, certificate information, timestamps, reputation, and campaign context. Endpoint registry and printer information cannot provide this external infrastructure history. Passive DNS is especially useful for pivoting from a single indicator to a broader set of potentially related assets.

Question 288.

A domain resolves to dozens of rapidly changing IP addresses with very short TTL values. Which malicious infrastructure technique could this indicate?

  1. Static routing
    2. Local ARP poisoning
    3. DHCP starvation
    4. Fast-flux DNS

Correct Answer: 4

Explanation:

Fast-flux DNS frequently changes the IP addresses associated with a domain, often using low TTL values and a distributed set of compromised or rented systems. Attackers can use this technique to make phishing, malware distribution, or command-and-control infrastructure harder to block or take down. Legitimate content-delivery networks can also use dynamic DNS behavior, so the pattern is not conclusive by itself. Analysts should examine domain age, registration data, infrastructure reputation, certificate information, autonomous systems, and endpoint behavior before classifying the activity.

Question 289.

Which pattern is most characteristic of command-and-control beaconing?

  1. Repeated communication from the same endpoint process to a rare destination over time
    2. A workstation obtaining a DHCP lease
    3. A user browsing several approved internal sites
    4. A server performing its scheduled backup

Correct Answer: 1

Explanation:

Command-and-control beaconing commonly involves repeated outbound connections from an infected endpoint to attacker-controlled infrastructure. Analysts should examine timing, destination rarity, process identity, connection duration, byte counts, TLS metadata, and whether the pattern occurs across multiple hosts. Fixed intervals may be obvious, but sophisticated malware can add jitter or use low-frequency callbacks. Legitimate management and monitoring tools may also create regular traffic, so the initiating process and destination reputation are crucial for distinguishing benign automation from malicious beaconing.

Question 290.

Which security telemetry is best suited to measuring the amount of data transferred between an internal host and an external destination when payload inspection is unavailable?

  1. Badge access logs
    2. NetFlow or equivalent flow telemetry
    3. Printer usage logs
    4. BIOS configuration records

Correct Answer: 2

Explanation:

NetFlow and similar flow technologies provide metadata such as source and destination IP addresses, ports, protocols, timestamps, durations, byte counts, and packet counts. This allows analysts to identify large or unusual transfers even when application payloads are unavailable or encrypted. Flow records are especially useful for broad network visibility because they are more storage-efficient than full packet capture. Analysts should compare observed traffic with historical baselines and use endpoint, proxy, or DLP telemetry for additional context. Hardware and physical records do not provide useful data-transfer measurements.

Question 291.

A server suddenly sends several gigabytes of data to a cloud service that it has never contacted before. Which additional evidence would most strongly support an exfiltration hypothesis?

  1. Sensitive files were accessed and archived shortly before the transfer
    2. The server uses TCP/IP
    3. The transfer occurred during business hours
    4. The server has redundant power supplies

Correct Answer: 1

Explanation:

Bulk access to sensitive data followed by archive creation and a large transfer to a previously unseen external service forms a suspicious sequence consistent with staging and exfiltration. The analyst should inspect the responsible user and process, archive contents, transfer destination, authentication events, and whether the cloud service is approved. TCP/IP and business-hours activity are common and do not meaningfully prove or disprove exfiltration. Strong conclusions come from correlating endpoint file activity with network transfer data and business context.

Question 292.

Which MITRE ATT&CK tactic best describes an attacker preparing gathered data for external transfer?

  1. Discovery
    2. Collection
    3. Initial Access
    4. Persistence

Correct Answer: 2

Explanation:

Collection includes techniques used to gather and stage information before exfiltration. Attackers may combine documents into archives, copy data into staging directories, capture screenshots, collect email, or gather database information. These actions often precede outbound transfer. Discovery focuses on learning about the environment, Initial Access concerns gaining the first foothold, and Persistence focuses on maintaining access. Analysts should examine whether collection behavior is followed by archive creation, encryption, unusual network activity, or access to external storage services.

Question 293.

Which source would best help determine whether a large archive was uploaded to an external SaaS platform using HTTPS?

  1. Secure web gateway or proxy telemetry
    2. Server fan-speed data
    3. DHCP scope configuration
    4. Badge reader logs

Correct Answer: 1

Explanation:

Secure web gateway and proxy logs can reveal web destinations, users, source systems, request methods, timestamps, URLs, and transferred byte counts. With application identification or TLS inspection, they may also identify cloud services, upload operations, or specific files. Even without decryption, metadata can help correlate a large outbound HTTPS session with the time an archive was created. Endpoint telemetry can identify the browser or process that initiated the upload. Hardware and physical access data do not provide application-layer network visibility.

Question 294.

A security analyst wants to determine whether a suspicious process established persistence through a Windows service. Which evidence would be most useful?

  1. Physical asset inventory
    2. Windows service creation events and endpoint telemetry
    3. Printer configuration
    4. Monitor model information

Correct Answer: 2

Explanation:

Windows service creation events and endpoint telemetry can reveal when a new service was installed, which executable it launches, which user created it, and what process initiated the action. Attackers frequently abuse services to establish persistence or execute code with elevated privileges. Analysts should inspect service names, executable paths, start types, digital signatures, hashes, and subsequent execution. Legitimate software installations can also create services, so the timing and context matter. Physical inventory and printer or monitor data do not provide evidence about service-based persistence.

Question 295.

Which forensic artifact should generally be collected before a system is powered off because it is highly volatile?

  1. System memory
    2. Printed incident forms
    3. Archived configuration documentation
    4. Asset purchase receipts

Correct Answer: 1

Explanation:

System memory contains volatile information that can disappear immediately when power is removed. This may include running processes, active network sessions, injected code, command history, encryption keys, credentials, and other transient artifacts. If organizational procedures allow and the evidence is relevant, memory acquisition should occur before shutdown. Responders must still consider active risk; a system that is spreading malware or exfiltrating data may require rapid containment. The memory image should be documented, hashed, and protected appropriately. Paperwork and archived records are persistent and can be collected later.

Question 296.

Which forensic principle helps determine whether RAM, network connections, disk data, or archived records should be collected first?

  1. Data normalization
    2. Least privilege
    3. Network segmentation
    4. Order of volatility

Correct Answer: 4

Explanation:

Order of volatility prioritizes evidence based on how quickly it may change or disappear. RAM, running processes, and active connections are generally more volatile than disk data, while archived records are comparatively persistent. Investigators use this principle to plan evidence collection while balancing operational risk and containment needs. The exact order may vary based on the incident and organizational procedures. Data normalization, least privilege, and segmentation are important security concepts but do not define evidence-collection priority.

Question 297.

A compromised host is actively scanning internal systems and attempting remote authentication. Which incident-response action should be prioritized?

  1. Contain or isolate the host to limit further lateral movement
    2. Perform the final lessons-learned meeting
    3. Delete all authentication logs
    4. Disable the SIEM

Correct Answer: 1

Explanation:

When a compromised host is actively scanning and attempting to move laterally, containment should occur quickly to limit additional compromise. Depending on organizational procedures, the host may be isolated through EDR, firewall rules, switch controls, segmentation, or physical disconnection. Any critical volatile evidence should be preserved when practical, but response teams must balance forensic value with ongoing risk. Deleting logs or disabling monitoring would reduce visibility. After containment, analysts should scope affected systems and proceed with eradication.

Question 298.

Which task belongs primarily to the eradication phase of incident response?

  1. Monitoring a restored system for recurrence
    2. Removing malicious services, resetting compromised credentials, and patching the exploited vulnerability
    3. Developing the incident-response plan
    4. Conducting annual security awareness training

Correct Answer: 2

Explanation:

Eradication removes malicious components and addresses the underlying causes of compromise. This includes deleting malware, removing malicious services and scheduled tasks, resetting stolen credentials, revoking sessions, and patching exploited vulnerabilities. Monitoring after restoration is primarily part of recovery, while planning and awareness activities belong to preparation or general security operations. Eradication must be complete because leaving behind credentials or persistence can allow the attacker to return even after the main payload is removed.

Question 299.

Which task belongs primarily to the recovery phase?

  1. Restore validated systems to production and monitor for renewed malicious activity
    2. Create the first incident-response policy
    3. Disable security controls during reconnection
    4. Reuse compromised accounts without changing credentials

Correct Answer: 1

Explanation:

Recovery focuses on safely returning remediated systems and services to normal operation. Before restoration, teams should verify that systems are patched, security controls are active, compromised credentials have been addressed, and known persistence mechanisms are absent. Once reconnected, systems should be monitored for signs of recurrence. Disabling controls or reusing compromised credentials would undermine the response. Recovery balances business restoration with confidence that the attacker no longer maintains access.

Question 300.

A post-incident review finds that analysts could not quickly connect suspicious user activity to the associated endpoint and network events. Which improvement would provide the greatest benefit?

  1. Reduce identity logging
    2. Delete old endpoint telemetry
    3. Improve correlation using common user, host, IP, and timestamp fields across security data sources
    4. Disable behavioral analytics

Correct Answer: 3

Explanation:

Correlation depends on consistent identifiers that allow analysts to connect identity, endpoint, and network activity into one timeline. Common fields such as username, hostname, IP address, process ID, device identifier, and timestamp enable SIEM rules and investigators to pivot between data sources efficiently. Normalization and accurate time synchronization further improve this process. Reducing logging or deleting historical telemetry would make investigations harder. Post-incident improvement should focus on integrating and correlating existing data so analysts can recognize attack chains more quickly and respond with greater confidence.