Cisco CCNP CyberSecurity 300-215 Practice Test Questions and Exam Dumps Part19 Q361-380

View Full Cisco CCNP CyberSecurity 300-215 Exam Dumps and Practice Test Dumps

 

Question 361.

A SOC analyst discovers that a newly created privileged account authenticated to several critical servers within minutes of being created. What is the most appropriate first action?

  1. Investigate whether the account creation and subsequent use were authorized
    2. Assume the account is legitimate because it has administrative privileges
    3. Reboot all affected servers
    4. Delete historical authentication logs

Correct Answer: 1

Explanation:

A newly created privileged account that immediately accesses critical systems is a high-risk event because attackers may create administrative identities for persistence or privilege escalation. The analyst should determine who created the account, from which host, whether the change was approved, and what actions occurred after login. Directory-service logs, authentication records, endpoint telemetry, and change-management data are useful for validation. Privileged status does not prove legitimacy. Rebooting systems without understanding the incident can destroy volatile evidence, while deleting logs would eliminate valuable investigative data.

Question 362.

Which data source would best identify the system and process responsible for creating the privileged account?

  1. Printer server logs
    2. Directory-service auditing and endpoint telemetry
    3. DHCP lease utilization statistics
    4. Monitor inventory

Correct Answer: 2

Explanation:

Directory-service auditing can show when an account was created, which administrator or process initiated the action, and what group memberships were assigned. Endpoint telemetry can provide additional context such as the executable, command line, source workstation, and user session associated with the change. Together, these sources can distinguish legitimate administrative activity from malicious account creation. DHCP information may help identify a host address at a particular time, but it does not show identity-management operations. Printer and monitor records are unrelated.

Question 363.

An analyst finds that a suspicious administrator account was added to multiple privileged groups. Which MITRE ATT&CK tactic is most directly represented?

  1. Discovery
    2. Collection
    3. Privilege Escalation
    4. Exfiltration

Correct Answer: 3

Explanation:

Adding an account to privileged groups directly increases its authorization level and therefore aligns with Privilege Escalation. Depending on the attacker’s intent, the same modification may also support persistence because it preserves powerful access for later use. Discovery involves learning about the environment, Collection involves gathering data, and Exfiltration concerns transferring data externally. Analysts should examine who performed the group changes, whether the account was already compromised, and what privileged actions followed. High-value directory changes should be monitored and correlated with endpoint and identity telemetry.

Question 364.

Which detection strategy is most effective for identifying unauthorized privileged group changes?

  1. Ignore changes performed by administrators
    2. Alert only on failed logins
    3. Monitor only endpoint malware hashes
    4. Alert on privileged group modifications and enrich them with source, user, and approval context

Correct Answer: 4

Explanation:

Privileged group changes are important identity events that should be monitored directly. The most useful alert includes the initiating account, target identity, source system, timestamp, affected group, and any change ticket or approval information. This context allows the SOC to distinguish legitimate administration from attacker-driven privilege escalation. Ignoring administrator actions is dangerous because attackers often compromise privileged accounts. Failed logins and malware hashes do not capture directory privilege changes. Correlating identity events with endpoint activity provides the strongest investigative context.

Question 365.

A user account begins downloading thousands of files from a cloud application shortly after an unfamiliar device successfully authenticates. Which factor should receive the most investigative attention?

  1. Whether the authentication and bulk download deviate from the user’s normal behavior
    2. Whether the endpoint uses Wi-Fi
    3. Whether the application is hosted in the cloud
    4. Whether the user’s password is longer than eight characters

Correct Answer: 1

Explanation:

The combination of an unfamiliar device and abnormal bulk download behavior may indicate account compromise. Analysts should compare the event with the user’s normal device history, working patterns, typical download volume, geographic location, MFA events, and business role. Cloud applications are normal business tools, and Wi-Fi use by itself is not suspicious. Password length is important for account security but does not explain the current event. Behavioral baselines help prioritize unusual identity activity that could otherwise appear technically valid because the attacker is using real credentials.

Question 366.

Which security capability is best suited to detecting a user suddenly downloading much more data than usual from a cloud service?

  1. Packet fragmentation analysis
    2. User and entity behavior analytics
    3. Hardware asset inventory
    4. Disk imaging

Correct Answer: 2

Explanation:

User and entity behavior analytics can establish normal patterns for users and devices and identify significant deviations such as unusually large downloads, new devices, odd login times, or access to unfamiliar applications. UEBA is particularly useful when attackers use valid credentials and traditional malware indicators are absent. An anomaly is not automatically malicious, so analysts still need identity, cloud, and endpoint context. Hardware inventory and disk imaging serve different purposes, while packet fragmentation analysis is not appropriate for this behavioral scenario.

Question 367.

An analyst sees a cloud account authenticate successfully without an MFA challenge even though MFA is normally required. What should be investigated first?

  1. Whether an existing session or trusted token bypassed a fresh authentication challenge
    2. Whether the user changed the screen brightness
    3. Whether DHCP issued a new lease
    4. Whether the browser supports HTTPS

Correct Answer: 1

Explanation:

Modern cloud environments often maintain sessions or refresh tokens that allow continued access without a new MFA prompt. If an attacker steals a valid session token, the account may appear authenticated even after password changes or without a fresh MFA challenge. Analysts should review session issuance, device identifiers, token activity, authentication logs, and whether the session was created from a legitimate device. DHCP and browser protocol support do not explain the absence of MFA. Token theft should be considered whenever account activity persists despite expected authentication controls.

Question 368.

Which response is most appropriate when a stolen cloud session token is suspected?

  1. Change only the user’s display name
    2. Wait for the session to expire naturally
    3. Reset the password but leave active sessions intact
    4. Revoke active sessions and tokens, then reset affected credentials

Correct Answer: 4

Explanation:

Revoking active sessions and refresh tokens is necessary when token theft is suspected because changing a password alone may not invalidate all existing authentication material. The account’s credentials should also be reset, and identity logs should be reviewed for unauthorized access and suspicious application activity. Waiting for the session to expire can leave the attacker active for hours or days depending on token lifetime. Changing a display name has no security value. Effective identity containment addresses passwords, tokens, sessions, and any associated device trust.

Question 369.

A security analyst observes an endpoint making DNS requests for a domain with hundreds of unique, high-entropy subdomains. Which activity is most likely?

  1. DNS tunneling or covert DNS communication
    2. Normal ARP resolution
    3. Standard DHCP renewal
    4. Routine printer discovery

Correct Answer: 1

Explanation:

Large numbers of unique, high-entropy subdomains can indicate DNS tunneling, where information is encoded into DNS queries or responses. Attackers may use DNS for command-and-control or data transfer because the protocol is widely permitted. Analysts should examine query frequency, length, entropy, domain age, record types, response behavior, and the endpoint process generating the requests. Legitimate applications can also produce complex names, so the pattern must be validated with additional context. ARP and DHCP have different network behaviors, while printer discovery does not normally produce encoded-looking DNS queries.

Question 370.

Which source would best help identify the process generating suspicious DNS tunneling traffic on an endpoint?

  1. Badge-access records
    2. EDR process-to-network telemetry
    3. Printer queue logs
    4. Asset purchase documentation

Correct Answer: 2

Explanation:

EDR telemetry can associate DNS or network connections with a specific process, executable path, hash, user, command line, and parent process. This provides the local context needed to determine whether the suspicious DNS traffic originates from malware or a legitimate application. DNS server logs can identify the client host but usually do not identify the exact process responsible. Physical access, printer, and purchasing records do not provide process-level network visibility. Correlating DNS and endpoint telemetry significantly strengthens the investigation.

Question 371.

A compromised endpoint begins enumerating user accounts, shares, and systems before attempting remote logins. Which MITRE ATT&CK tactic best describes the enumeration phase?

  1. Discovery
    2. Exfiltration
    3. Impact
    4. Persistence

Correct Answer: 1

Explanation:

Enumeration of users, shares, systems, and services fits the Discovery tactic. Attackers use discovery techniques to understand the environment before selecting privilege-escalation, lateral-movement, or collection targets. When discovery is followed by remote authentication attempts, the sequence can indicate that the attacker is actively expanding access. Analysts should identify the process responsible, user context, commands executed, and subsequent destination hosts. Exfiltration, Impact, and Persistence describe different objectives later or elsewhere in an attack chain.

Question 372.

Which evidence would most strongly indicate that discovery activity progressed into lateral movement?

  1. The endpoint queried its DNS server
    2. The same host authenticated to discovered systems and launched remote processes
    3. A DHCP lease was renewed
    4. The workstation synchronized its clock

Correct Answer: 2

Explanation:

Discovery followed by authentication to newly identified systems and remote process execution is a strong sequence indicating lateral movement. The analyst should review the credentials used, logon types, remote service creation, file transfers, PowerShell or administrative tools, and actions taken on the destination hosts. DNS, DHCP, and NTP are routine network functions and do not provide meaningful evidence of lateral movement. Attack-chain context is important because a single discovery event may be legitimate, while discovery followed by remote execution is much more suspicious.

Question 373.

A workstation accesses thousands of confidential files and then creates a large encrypted archive. Which behavior is most likely occurring?

  1. Data collection and staging
    2. Network time synchronization
    3. DHCP discovery
    4. ARP inspection

Correct Answer: 1

Explanation:

Bulk access to confidential data followed by creation of a large encrypted archive is consistent with collection and staging. Attackers may aggregate files into archives to simplify transport, reduce the number of transfers, or obscure individual content. Analysts should identify the process that created the archive, the user account involved, file sources, archive location, encryption method, and whether outbound transfer followed. Legitimate backup software can produce similar patterns, so operational context remains important. Network time, DHCP, and ARP activity do not explain the sequence.

Question 374.

Which telemetry would best help determine whether the staged archive was transferred through an external web application?

  1. BIOS logs
    2. Secure web gateway or proxy telemetry
    3. Printer audit records
    4. Monitor inventory

Correct Answer: 2

Explanation:

Secure web gateway and proxy telemetry can reveal external applications, URLs, usernames, source hosts, request types, timestamps, and transferred byte counts. Depending on inspection capabilities, they may also identify specific uploads or file names. Analysts should correlate the web session with the time the archive was created and the process responsible for the transfer. If the traffic is encrypted and not decrypted, metadata can still provide important confirmation. BIOS, printer, and monitor data do not provide web-transfer evidence.

Question 375.

A forensic investigator needs to preserve information about active processes and network sessions before shutting down a compromised system. What should be collected first?

  1. Volatile memory and live-response data
    2. Archived asset reports
    3. Printed documentation
    4. Hardware purchase receipts

Correct Answer: 1

Explanation:

Volatile memory and live-response data can contain running processes, network connections, logged-in users, credentials, encryption keys, injected code, and other transient information that may disappear after shutdown. If these artifacts are relevant and collection is permitted, they should be acquired before power is removed. Responders must balance forensic value with containment because an active system may continue causing harm. The collection process should be documented, and acquired evidence should be hashed and protected appropriately. Persistent records can be collected later.

Question 376.

Which forensic principle determines the priority for collecting RAM before less volatile disk or archival evidence?

  1. Data normalization
    2. Network segmentation
    3. Least privilege
    4. Order of volatility

Correct Answer: 4

Explanation:

Order of volatility prioritizes evidence based on how quickly it may change or disappear. RAM and active network information are highly volatile and can be lost immediately when power is removed, while disk files and archived records are more persistent. Investigators use this principle to plan evidence acquisition while considering containment and operational risk. Data normalization, segmentation, and least privilege are important security practices but do not define forensic collection priority. Applying order of volatility helps preserve information that may otherwise be unrecoverable.

Question 377.

A compromised endpoint is actively attempting to move laterally using a privileged account. Which containment action is most appropriate?

  1. Isolate the endpoint and restrict the compromised account according to response procedures
    2. Wait for the next scheduled maintenance window
    3. Delete authentication logs
    4. Disable endpoint monitoring

Correct Answer: 1

Explanation:

Both the compromised host and identity should be contained when active lateral movement is occurring. Isolating the endpoint can stop remote access attempts and command-and-control traffic, while restricting or disabling the affected account and revoking sessions can prevent further use of stolen credentials. The exact response should follow organizational policy and consider business impact. Waiting increases risk, while deleting logs or disabling monitoring removes important evidence. Once contained, analysts should identify which systems were already accessed and proceed with eradication.

Question 378.

Which activity belongs primarily to eradication after the lateral-movement activity has been contained?

  1. Writing the final lessons-learned report
    2. Removing persistence, resetting compromised credentials, and patching exploited vulnerabilities
    3. Reconnecting systems immediately
    4. Disabling security controls

Correct Answer: 2

Explanation:

Eradication removes the attacker’s footholds and addresses the causes that enabled compromise. This includes removing malware and persistence mechanisms, resetting or rotating compromised credentials, revoking tokens, patching vulnerabilities, and eliminating unauthorized accounts or tools. Containment only limits immediate activity. Recovery should begin only after the response team has sufficient confidence that malicious access has been eliminated. Lessons learned occurs later, while disabling security controls would weaken the environment.

Question 379.

Which activity belongs primarily to recovery after compromised systems have been rebuilt and credentials secured?

  1. Restore systems to service gradually and monitor closely for recurrence
    2. Disable all identity logging
    3. Restore compromised passwords
    4. Delete incident evidence immediately

Correct Answer: 1

Explanation:

Recovery returns systems and services to normal operation in a controlled manner after eradication is complete. Before restoration, responders should verify patching, security controls, authentication changes, and the absence of known malicious artifacts. Once systems are reconnected, enhanced monitoring should continue for signs of renewed command-and-control traffic, suspicious logins, or persistence. Logging should remain enabled, and compromised credentials should never be reused. Incident evidence should be retained according to organizational and legal requirements.

Question 380.

A post-incident review determines that several privileged accounts were used from systems where they should never have been allowed to authenticate. Which improvement would most directly reduce this risk?

  1. Reduce endpoint telemetry
    2. Disable behavioral monitoring
    3. Restrict privileged account logon locations and enforce tiered administrative access
    4. Allow administrators to use privileged accounts from any workstation

Correct Answer: 3

Explanation:

Restricting where privileged accounts can authenticate reduces the opportunity for credential theft and lateral movement. Tiered administrative access separates high-value administrative identities from ordinary user workstations and limits those accounts to dedicated management systems or approved administrative paths. This reduces the impact of compromised endpoints and makes abnormal privileged authentication easier to detect. Allowing privileged credentials everywhere expands the attack surface, while reducing telemetry would make misuse harder to identify. Post-incident improvements should combine least privilege, logon restrictions, MFA, dedicated administrative endpoints, and continuous monitoring.