Cisco CCNP CyberSecurity 300-215 Practice Test Questions and Exam Dumps Part17 Q321-340

View Full Cisco CCNP CyberSecurity 300-215 Exam Dumps and Practice Test Dumps

 

Question 321.

A SOC analyst observes a domain administrator account authenticating to several endpoints from a workstation that is normally assigned to a standard business user. Which action should the analyst take first?

  1. Investigate the source workstation and account activity for possible credential compromise
    2. Assume the activity is legitimate because the account is privileged
    3. Replace the destination endpoints
    4. Disable DNS on the source workstation

Correct Answer: 1

Explanation:

A domain administrator account being used from an unexpected workstation is a high-risk anomaly because privileged credentials can provide broad access across an environment. The analyst should determine whether the account owner intentionally used the workstation, review MFA and authentication events, and examine endpoint telemetry from the source host for credential theft, remote administration, or suspicious process execution. The analyst should also review what occurred on destination systems after authentication. Privileged status does not make unusual activity automatically legitimate. If compromise is confirmed, containment may require restricting the account, revoking active sessions, rotating credentials, and isolating the source host while the wider scope is investigated.

Question 322.

Which data source would best help determine whether the source workstation in the previous scenario executed a credential-dumping tool before the privileged logins occurred?

  1. Printer server logs
    2. Endpoint detection and response telemetry
    3. DHCP scope utilization
    4. Badge-reader events

Correct Answer: 2

Explanation:

Endpoint detection and response telemetry provides process-level visibility that can reveal suspicious executable launches, memory-access behavior, command-line activity, file creation, and parent-child process relationships. This makes it highly useful when investigating whether credentials were stolen before privileged authentication occurred. Authentication logs show how the account was used but generally do not reveal the process responsible for obtaining credentials. DHCP data can help identify host addressing at a particular time, while printer and physical access records do not provide relevant process telemetry. Analysts should correlate endpoint events with authentication timestamps to establish whether credential access preceded the suspicious logins.

Question 323.

An analyst detects a process attempting to access authentication material from LSASS memory. Which attacker objective is most likely?

  1. Network discovery
    2. Data exfiltration
    3. Credential Access
    4. Resource Development

Correct Answer: 3

Explanation:

Accessing LSASS memory is commonly associated with attempts to obtain passwords, password hashes, tokens, or other authentication material. In MITRE ATT&CK terminology, this aligns with Credential Access. Attackers may use stolen credentials to escalate privileges, move laterally, access sensitive resources, or establish additional persistence. Not every process interacting with LSASS is malicious because legitimate security software can also inspect sensitive processes, so analysts should examine the executable, signature, process ancestry, user context, and surrounding activity. When suspicious LSASS access is observed alongside unusual authentication, it should generally receive high investigative priority.

Question 324.

Which detection strategy is most effective for identifying credential dumping when an attacker uses a legitimate or renamed utility?

  1. Search only for one known filename
    2. Block every administrative tool
    3. Ignore signed executables
    4. Detect suspicious access to credential-related processes and associated behavior

Correct Answer: 4

Explanation:

Attackers can rename tools, modify binaries, or abuse legitimate utilities, making filename-only detection fragile. Behavioral detection that focuses on suspicious interaction with credential-related processes, memory access patterns, process relationships, privilege changes, and subsequent authentication activity is more resilient. Blocking all administrative software would disrupt legitimate operations, while ignoring signed binaries creates dangerous blind spots. Analysts should combine endpoint behavior with identity telemetry and threat intelligence. If suspicious credential access is confirmed, the response should include investigation of accounts that may have been exposed and review of subsequent logins across the environment.

Question 325.

A workstation begins authenticating to many servers shortly after a suspicious process accessed credential material. What is the most likely interpretation?

  1. Stolen credentials may be being used for lateral movement
    2. A routine DHCP renewal is occurring
    3. The host is performing normal NTP synchronization
    4. The user is changing local display settings

Correct Answer: 1

Explanation:

Credential-access activity followed by authentication to multiple systems is a suspicious sequence consistent with credential theft and lateral movement. The analyst should review the accounts used, destination systems, authentication protocols, successful and failed logins, and any remote process execution that followed. Endpoint telemetry from the source host can reveal which process initiated the connections, while destination telemetry can show what the attacker did after login. DHCP and NTP activity do not explain the authentication pattern. If lateral movement is confirmed, analysts should assume the incident may extend beyond the original workstation and scope additional systems and identities accordingly.

Question 326.

Which identity-related pattern is most useful for detecting an account being used from a new endpoint and accessing an unusual set of systems?

  1. Hardware inventory matching
    2. User and entity behavior analytics
    3. File carving
    4. Packet fragmentation analysis

Correct Answer: 2

Explanation:

User and entity behavior analytics can identify deviations from normal account and device behavior, such as authentication from new endpoints, abnormal resource access, unusual login times, or rapid access to many systems. These anomalies are especially useful when attackers use valid credentials and do not deploy obvious malware. UEBA depends on sufficient historical data and accurate identity context, and anomalies must still be investigated because legitimate business changes can also produce deviations. File carving and packet fragmentation analysis serve different purposes. Behavioral identity analytics are most valuable when combined with endpoint and network telemetry.

Question 327.

An analyst sees a user account authenticate successfully from Pakistan and then five minutes later from a distant country with no corporate VPN involved. Which alert type is most applicable?

  1. Impossible-travel anomaly
    2. DNS tunneling
    3. ARP spoofing
    4. Port scanning

Correct Answer: 1

Explanation:

Impossible-travel analytics identify authentication events that occur from geographically distant locations within a timeframe that makes legitimate physical travel implausible. This can indicate stolen credentials or token compromise. The analyst should still validate the event because proxies, cloud services, mobile networks, and VPNs can affect geolocation. Device identity, MFA events, source IP reputation, user-agent data, session activity, and the user’s normal access pattern should all be reviewed. DNS tunneling, ARP spoofing, and port scanning describe different technical behaviors unrelated to geographically inconsistent authentication.

Question 328.

Which factor should an analyst evaluate before treating an impossible-travel alert as confirmed compromise?

  1. Whether the account has a long username
    2. Whether one of the sessions used a corporate VPN or proxy
    3. Whether the user owns a laptop
    4. Whether the destination application uses HTTPS

Correct Answer: 2

Explanation:

VPNs, proxies, cloud gateways, and mobile carriers can make legitimate authentication appear to originate from different geographic locations. Analysts should therefore determine whether a corporate VPN or other routing service explains the apparent travel anomaly. They should also review device identifiers, authentication factors, user behavior, and source IP reputation. A long username, laptop ownership, or HTTPS use does not explain the geography. Impossible-travel detections are useful prioritization signals, but they should be validated with additional identity and network context before high-impact containment actions are taken.

Question 329.

A SOC observes an endpoint repeatedly connecting to a rare domain over HTTPS, but the connection intervals vary by several minutes. Which additional telemetry would best help determine whether this is malicious beaconing?

  1. The process responsible for the connections
    2. The user’s desktop theme
    3. Printer toner levels
    4. Hardware warranty status

Correct Answer: 1

Explanation:

Process attribution is one of the most useful ways to determine whether periodic network activity is malicious. If the communication originates from a trusted management agent connecting to its normal vendor infrastructure, the pattern may be legitimate. If it comes from an unsigned executable in a temporary directory or a suspicious script process, the same network behavior becomes much more concerning. Analysts should also examine domain age, destination reputation, TLS certificate information, data volumes, and timing characteristics. Variable intervals may indicate jitter, but jitter alone is not proof of malware.

Question 330.

What is the primary purpose of jitter in command-and-control communication?

  1. To improve endpoint storage performance
    2. To make periodic beaconing less predictable and harder to detect
    3. To increase DNS TTL values
    4. To accelerate DHCP lease renewal

Correct Answer: 2

Explanation:

Jitter introduces random variation into the timing of command-and-control callbacks. Instead of connecting at an exact fixed interval, malware may vary delays so periodic behavior is less obvious to simple threshold or timing-based detections. Security analysts can still identify jittered beaconing by examining longer-term patterns, destination rarity, process identity, byte counts, and relationships between multiple hosts. Jitter does not make communication invisible; it simply reduces regularity. Storage performance, DNS TTL values, and DHCP renewal have no direct relationship to this command-and-control technique.

Question 331.

A compromised endpoint creates an encrypted archive containing files copied from multiple internal servers. Which MITRE ATT&CK tactic most directly describes the gathering of those files?

  1. Collection
    2. Persistence
    3. Defense Evasion
    4. Initial Access

Correct Answer: 1

Explanation:

Gathering files from multiple systems aligns with the Collection tactic because the adversary is acquiring information of interest before using or exfiltrating it. Creating an encrypted archive may also represent data staging in preparation for transfer. Analysts should identify the account used to access the files, the process responsible for collection, the archive location, and any outbound network activity that followed. Persistence maintains access, Defense Evasion avoids detection, and Initial Access concerns the original foothold. Mapping the behavior to ATT&CK helps structure the investigation and identify additional techniques that may occur next.

Question 332.

Which telemetry would best identify whether the encrypted archive from the previous scenario was transferred outside the organization?

  1. Monitor inventory
    2. Proxy, firewall, NetFlow, or cloud-access telemetry
    3. Printer spooler logs
    4. BIOS settings

Correct Answer: 2

Explanation:

Network and cloud-access telemetry can show whether a large outbound transfer occurred after the archive was created. Proxy and secure web gateway logs may identify URLs, cloud applications, usernames, and byte counts. Firewall and flow telemetry can provide source, destination, protocol, session duration, and data volume. Analysts should correlate transfer size and timing with archive creation and endpoint process telemetry. Hardware and printer information do not provide outbound transfer evidence. Correlation is essential because archive creation alone proves staging, not successful exfiltration.

Question 333.

A host uploads several gigabytes to a cloud service that is approved for business use. Which factor would most increase suspicion that the transfer is malicious?

  1. The upload is performed by an unusual process shortly after bulk access to sensitive files
    2. The cloud service supports HTTPS
    3. The endpoint uses Ethernet
    4. The user has a corporate account

Correct Answer: 1

Explanation:

Attackers may abuse legitimate cloud services for exfiltration, so the fact that a destination is approved does not automatically make every transfer safe. Bulk access to sensitive files followed by an upload from an unusual process is highly relevant context. The analyst should review the account, process, file access, transfer size, destination tenant or account, and whether the user has a legitimate business reason for the activity. HTTPS, Ethernet, and corporate authentication are common and provide little evidence either way. Context and sequence matter more than simple destination reputation.

Question 334.

Which control would most help detect unauthorized upload of sensitive data to sanctioned cloud applications?

  1. Printer auditing
    2. CASB or cloud-access security monitoring
    3. BIOS password configuration
    4. DHCP reservations

Correct Answer: 2

Explanation:

A Cloud Access Security Broker or comparable cloud-access security monitoring capability can provide visibility into sanctioned and unsanctioned cloud applications, users, file transfers, access patterns, and policy violations. This can help detect sensitive data being uploaded to legitimate cloud platforms in ways that violate organizational policy. Secure web gateways, DLP systems, and endpoint telemetry may provide complementary evidence. BIOS and DHCP controls do not monitor cloud application usage. Because legitimate cloud services can be abused by insiders or compromised accounts, cloud-aware monitoring is an important component of modern incident detection.

Question 335.

Which forensic evidence should generally be collected before powering off a live compromised host if the investigation requires active network-connection information?

  1. Volatile memory and current connection data
    2. Archived invoices
    3. Printed floor plans
    4. Hardware purchase receipts

Correct Answer: 1

Explanation:

Active network connections and memory-resident information are volatile and may disappear when a system is shut down. Depending on the incident and organizational procedures, investigators may capture RAM, connection tables, running processes, logged-in users, and related live-response information before powering down the system. The need to preserve volatile evidence must be balanced against containment risk because a live host may continue communicating with an attacker. Persistent business documents can be collected later. Investigators should document all actions because live-response collection itself changes the system state.

Question 336.

Which forensic practice is most important for showing that a disk image remained unchanged after acquisition?

  1. Change its filename periodically
    2. Compress it several times
    3. Store it in multiple folders
    4. Calculate and later verify a cryptographic hash

Correct Answer: 4

Explanation:

A cryptographic hash provides a reproducible integrity value based on the contents of the forensic image. If a later hash matches the value recorded at acquisition, investigators gain confidence that the evidence has not been modified. Renaming, compressing, or relocating the file does not provide equivalent integrity assurance and can sometimes alter its representation. Hashing should be combined with chain-of-custody records, secure storage, restricted access, and analysis on verified working copies. Evidence integrity is especially important when findings may be reviewed by legal, regulatory, or disciplinary authorities.

Question 337.

A compromised workstation is actively attempting to authenticate to many internal systems. Which incident-response action should be prioritized after any immediately required volatile evidence is collected?

  1. Isolate the workstation from the network
    2. Conduct the lessons-learned meeting
    3. Delete all authentication logs
    4. Disable endpoint monitoring

Correct Answer: 1

Explanation:

Active authentication attempts from a compromised host create an immediate risk of lateral movement. Network isolation can stop further connection attempts, command-and-control communication, and malware propagation while preserving the system for deeper investigation. Depending on organizational procedures, isolation may be performed through EDR controls, firewall rules, segmentation, switch configuration, or physical disconnection. Lessons learned occurs later, while deleting logs or disabling monitoring would reduce visibility. After containment, analysts should determine which accounts were used and whether any additional systems were already compromised.

Question 338.

Which action belongs primarily to eradication rather than containment?

  1. Blocking a malicious IP temporarily
    2. Removing persistence, resetting compromised credentials, and patching the exploited vulnerability
    3. Isolating an endpoint
    4. Restricting an account during investigation

Correct Answer: 2

Explanation:

Eradication removes the attacker’s footholds and addresses the conditions that enabled compromise. Removing persistence, resetting stolen credentials, revoking active sessions, and patching vulnerabilities are all eradication activities. Temporary network blocks, endpoint isolation, and account restrictions are generally containment measures because they limit immediate risk while the investigation continues. Recovery should not begin until the response team has sufficient confidence that malicious access has been removed. In severely compromised environments, rebuilding from trusted images may provide greater assurance than manual cleaning.

Question 339.

Which action is most appropriate during recovery after systems have been rebuilt and malicious persistence removed?

  1. Restore systems in a controlled manner and monitor closely for recurrence
    2. Disable security telemetry
    3. Reuse compromised passwords
    4. Delete all incident evidence immediately

Correct Answer: 1

Explanation:

Recovery returns systems to normal operation after containment and eradication have addressed the threat. Before reconnecting systems, responders should validate patching, security controls, credentials, configuration, and application functionality. Once production access is restored, enhanced monitoring should continue for a period to detect renewed command-and-control communication, suspicious authentication, or persistence behavior. Security telemetry should remain enabled, and compromised credentials should not be reused. Incident evidence should be retained according to organizational requirements so lessons can be learned and any formal review can be supported.

Question 340.

A post-incident review finds that a compromised service account had excessive privileges on many servers, significantly increasing the attacker’s reach. Which improvement should be prioritized?

  1. Reduce log retention
    2. Disable identity monitoring
    3. Apply least privilege and review service-account permissions and usage regularly
    4. Allow service accounts to log in interactively everywhere

Correct Answer: 3

Explanation:

Service accounts should receive only the permissions required for their intended applications and should generally be restricted from unnecessary interactive use. Excessive privileges increase the impact of credential compromise because attackers can use one account to access many systems. The organization should review service-account privileges, restrict login locations and methods, rotate credentials appropriately, monitor usage, and consider managed service-account technologies where suitable. Reducing logging or expanding access would worsen the risk. Post-incident reviews should address structural weaknesses such as excessive privileges so the same type of compromise has a smaller impact in the future.