View Full Cisco CCNP CyberSecurity 300-215 Exam Dumps and Practice Test Dumps
Question 381.
A SOC analyst observes an account successfully authenticating to a critical server from a host that was recently isolated for malware activity. What should the analyst do first?
- Investigate whether the credentials were compromised and whether the session is still active
2. Assume the login is legitimate because authentication succeeded
3. Delete the endpoint telemetry
4. Reboot the critical server immediately
Correct Answer: 1
Explanation:
A successful login from a host already associated with malware is highly suspicious because the attacker may have stolen credentials before the system was isolated. The analyst should review authentication events, session information, privilege level, destination activity, MFA results, and whether additional systems were accessed. Endpoint telemetry from the compromised source host may reveal credential theft, remote-access tools, or commands that preceded the authentication. Rebooting the server without understanding the event could destroy volatile evidence, while deleting telemetry would remove valuable context. If compromise is confirmed, the account may need to be restricted, sessions revoked, credentials rotated, and related authentication activity hunted across the environment.
Question 382.
Which source would best help determine whether the suspicious login in the previous scenario was followed by remote command execution?
- Printer logs
2. Endpoint process telemetry on the destination server
3. DHCP scope utilization
4. Badge-reader events
Correct Answer: 2
Explanation:
Endpoint process telemetry on the destination server can show which executables launched after the authentication, along with command lines, parent-child relationships, user context, file paths, and network activity. This allows the analyst to determine whether the session involved legitimate access or remote command execution. Authentication logs identify that access occurred but may not reveal what happened afterward. DHCP and physical-access records do not provide process-level evidence. Analysts should align timestamps from authentication and endpoint data to reconstruct the sequence accurately and identify any lateral movement, privilege escalation, or persistence established after login.
Question 383.
An analyst sees psexec-like remote service execution from a compromised workstation to multiple servers. Which attacker behavior is most likely?
- Collection
2. Reconnaissance only
3. Lateral Movement
4. Exfiltration
Correct Answer: 3
Explanation:
Remote service execution from a compromised workstation to multiple servers is strongly associated with Lateral Movement. Attackers often use valid credentials and remote execution mechanisms to expand access after compromising one endpoint. The analyst should examine the source account, destination systems, service creation events, process telemetry, transferred binaries, and whether the same technique appears elsewhere. Collection involves gathering data, Reconnaissance focuses on target information gathering, and Exfiltration concerns transferring data externally. Lateral movement should generally trigger broader incident scoping because compromise may no longer be limited to the original workstation.
Question 384.
Which detection approach is most effective for identifying suspicious remote service execution without alerting on every legitimate administrative action?
- Block every remote service operation
2. Alert only on one known executable name
3. Ignore activity performed by administrators
4. Correlate remote service creation with unusual users, source hosts, binaries, and process behavior
Correct Answer: 4
Explanation:
Remote service creation can be legitimate in enterprise administration, so context is essential. A stronger detection looks for unexpected source hosts, unusual accounts, unknown executables, suspicious service names, uncommon paths, or service creation immediately after anomalous authentication. Blocking all remote service operations would disrupt normal management, while relying on one filename is too narrow because attackers can rename tools. Ignoring administrator activity is also dangerous because privileged credentials are often compromised. Behavioral correlation provides broader coverage while reducing false positives.
Question 385.
A workstation launches a script interpreter that downloads a file and then contacts a rare external domain. Which investigative method best helps establish whether these events are related?
- Build a correlated process and network timeline
2. Review only the file extension
3. Replace the network cable
4. Delete the script after execution
Correct Answer: 1
Explanation:
A correlated timeline can show whether the script interpreter downloaded the file, whether that file executed, and whether the resulting process contacted the rare domain. Endpoint telemetry, DNS, proxy, firewall, and file events should be aligned using accurate timestamps. Looking only at a file extension provides very limited evidence. Replacing hardware does not address the suspected attack chain, and deleting the script immediately may remove useful evidence. Timeline analysis is one of the most effective ways to understand causality and sequence across multiple telemetry sources.
Question 386.
Which threat-intelligence attribute should be reviewed before treating a domain indicator from an old report as currently malicious?
- Domain length
2. Freshness and current reputation
3. Number of vowels in the domain name
4. Whether the domain supports IPv6
Correct Answer: 2
Explanation:
Threat-intelligence indicators can become stale because domains and infrastructure change ownership or usage over time. An indicator that was malicious months ago may no longer represent an active threat. Analysts should evaluate freshness, current reputation, source confidence, registration details, passive DNS history, and recent observations before taking action. Domain length and IPv6 support are not meaningful measures of maliciousness. Old indicators can still be useful for retrospective searches, but automatic blocking should generally depend on current context and confidence.
Question 387.
Which intelligence source is most useful for identifying historical IP addresses associated with a suspicious domain?
- Passive DNS
2. Printer audit logs
3. BIOS configuration
4. Local group policy
Correct Answer: 1
Explanation:
Passive DNS records historical domain-to-IP relationships, making it useful for understanding how suspicious infrastructure has changed over time. Analysts can identify previous hosting addresses, related domains, and possible campaign infrastructure. This can support threat hunting and incident scoping. Because cloud and shared hosting environments can create benign associations, passive DNS should be combined with timestamps, certificate information, registration records, and reputation data. Printer, BIOS, and local policy data do not provide external DNS history.
Question 388.
An endpoint repeatedly sends small HTTPS connections to the same destination every few minutes, but with variable timing. Which technique may the malware be using?
- DHCP renewal
2. ARP inspection
3. Jittered beaconing
4. VLAN hopping
Correct Answer: 3
Explanation:
Jittered beaconing introduces random variation into command-and-control callback intervals. Instead of communicating at perfectly fixed times, malware may vary the delay to make the traffic less obvious to periodicity-based detections. Analysts should still examine destination rarity, process identity, TLS metadata, byte counts, and long-term patterns. Legitimate management agents can also use variable polling intervals, so the responsible process and business context are essential. DHCP, ARP inspection, and VLAN hopping are unrelated to this recurring outbound behavior.
Question 389.
Which source would best determine which process is responsible for suspected jittered beaconing?
- Endpoint process-to-network telemetry
2. Badge-reader logs
3. Printer spooler records
4. Hardware inventory
Correct Answer: 1
Explanation:
Endpoint process-to-network telemetry can associate each connection with a specific executable, user, parent process, command line, and file path. This is critical for distinguishing malware from legitimate automated software. If the process is an unsigned binary in a temporary directory, suspicion increases; if it is a known management agent communicating with approved infrastructure, the traffic may be benign. Network telemetry alone can show timing and destination but may not reveal the responsible process. Combining endpoint and network evidence provides the strongest analysis.
Question 390.
A security analyst sees repeated DNS requests containing long encoded-looking subdomains. Which behavior is most likely?
- Normal DHCP activity
2. DNS tunneling
3. ARP resolution
4. Standard NTP synchronization
Correct Answer: 2
Explanation:
DNS tunneling often encodes data into DNS queries or responses, producing unusually long or high-entropy subdomains. This can be used for command-and-control or data exfiltration because DNS is commonly permitted through network controls. Analysts should inspect query length, frequency, entropy, domain reputation, record types, and the endpoint process generating the traffic. Legitimate services can also create complex DNS names, so the behavior should be validated with context. DHCP, ARP, and NTP have different communication patterns and would not normally generate this type of encoded DNS activity.
Question 391.
Which combination of evidence most strongly supports a DNS tunneling hypothesis?
- High-entropy queries, high query volume, a rare domain, and a suspicious initiating process
2. One ordinary lookup to a popular domain
3. A normal reverse lookup
4. A workstation using an internal DNS server
Correct Answer: 1
Explanation:
Multiple reinforcing indicators provide much stronger evidence than any single DNS anomaly. High-entropy subdomains, repeated queries to a rare domain, abnormal query volume, and a suspicious endpoint process together create a strong tunneling hypothesis. Analysts should still examine whether the application has a legitimate business function that could explain the traffic. Looking at only one ordinary lookup provides little evidence. DNS investigations are most effective when server-side query data is correlated with endpoint process telemetry and threat intelligence.
Question 392.
Which MITRE ATT&CK tactic best describes an attacker enumerating domain users, groups, and network shares after initial compromise?
- Impact
2. Discovery
3. Exfiltration
4. Persistence
Correct Answer: 2
Explanation:
Discovery covers techniques used to learn about the victim environment after access has been obtained. Enumerating domain users, groups, systems, shares, and services helps attackers identify valuable targets and paths for privilege escalation or lateral movement. Impact concerns disruption, Exfiltration concerns data removal, and Persistence concerns maintaining access. Analysts should determine which process performed the enumeration and what actions followed. Discovery immediately followed by remote authentication or service creation is especially suspicious because it may indicate progression into lateral movement.
Question 393.
Which event most strongly indicates that discovery activity progressed into lateral movement?
- The source host authenticates to newly discovered servers and launches remote processes
2. A DNS cache entry is created
3. An NTP request is sent
4. A DHCP lease is renewed
Correct Answer: 1
Explanation:
Authentication to newly identified hosts followed by remote process execution strongly indicates lateral movement. The sequence suggests that discovery was used to select targets and that valid credentials or remote services were then used to expand access. Analysts should review the accounts used, logon types, destination processes, service creation, and any payload transfers. DNS, NTP, and DHCP are normal infrastructure activities and do not demonstrate lateral movement. Sequence and correlation are crucial for understanding attacker progression.
Question 394.
An analyst observes bulk access to confidential files followed by creation of a large encrypted archive. Which attacker activity is most likely occurring?
- Persistence
2. Defense Evasion only
3. Discovery
4. Collection and staging
Correct Answer: 4
Explanation:
Bulk access to confidential files followed by archive creation is consistent with Collection and staging. Attackers frequently consolidate gathered data into archives before transferring it externally because this simplifies transport and may obscure individual files. Analysts should identify the process responsible, user account, archive location, file types, and subsequent network activity. Legitimate backup or archival systems may show similar behavior, so business context matters. If the archive is later uploaded to an unusual external destination, confidence in an exfiltration hypothesis increases substantially.
Question 395.
Which network telemetry would best help determine whether the archive in the previous scenario was transferred externally?
- NetFlow, firewall, proxy, or cloud-access telemetry
2. BIOS logs
3. Monitor settings
4. Printer queue records
Correct Answer: 1
Explanation:
Flow, firewall, proxy, and cloud-access logs can provide evidence of outbound transfer, including destination, timing, protocol, session duration, and byte counts. Analysts can correlate the transfer with the archive’s creation time and approximate size. Proxy or cloud telemetry may provide additional information about the specific service used. Endpoint telemetry can identify which process initiated the upload. BIOS and printer information are unrelated. Host and network correlation is the best way to establish whether staged data actually left the organization.
Question 396.
Which forensic concept should guide whether RAM is collected before disk data?
- Least privilege
2. Segmentation
3. Normalization
4. Order of volatility
Correct Answer: 4
Explanation:
Order of volatility prioritizes evidence based on how quickly it can change or disappear. RAM and active network state are highly volatile and may vanish immediately when a system is powered off, while disk data is more persistent. Investigators use this principle to decide what to collect first, while still considering the urgency of containment. Least privilege, segmentation, and normalization are important security concepts but do not define forensic collection priority. Proper application of order of volatility helps preserve evidence that might otherwise be permanently lost.
Question 397.
Which forensic control helps ensure that original storage media is not altered during evidence acquisition?
- Write blocker
2. SIEM rule
3. Proxy server
4. Load balancer
Correct Answer: 1
Explanation:
A write blocker prevents the acquisition workstation from writing data back to the original storage device. This helps preserve timestamps, metadata, file-system structures, and deleted-file artifacts. It is commonly used during forensic imaging and should be combined with cryptographic hashing, secure evidence storage, and chain-of-custody documentation. SIEM rules, proxies, and load balancers perform unrelated functions. Investigators should normally analyze verified copies rather than original evidence so the source remains preserved.
Question 398.
A compromised endpoint is actively using a stolen privileged account to access additional servers. What should the response team prioritize?
- Wait until the next maintenance window
2. Contain the endpoint and restrict the compromised identity
3. Delete all identity logs
4. Disable endpoint telemetry
Correct Answer: 2
Explanation:
When active lateral movement is occurring, containment should address both the compromised system and the stolen identity. Isolating the endpoint can stop further network activity, while restricting or disabling the account and revoking active sessions can prevent continued authentication. The exact actions should follow organizational procedures and consider business impact. Waiting allows the attacker more time to expand access, while deleting logs or disabling telemetry removes visibility. After containment, analysts should determine which systems were already accessed and proceed with eradication.
Question 399.
Which task belongs primarily to the eradication phase after the active compromise has been contained?
- Removing malware, persistence, compromised credentials, and exploited weaknesses
2. Conducting the final lessons-learned meeting
3. Reconnecting affected systems immediately
4. Disabling security monitoring
Correct Answer: 1
Explanation:
Eradication removes attacker footholds and addresses root causes. This includes removing malicious files and services, deleting unauthorized accounts or scheduled tasks, resetting compromised credentials, revoking tokens, and patching exploited vulnerabilities. Containment only limits immediate activity; it does not eliminate the threat. Recovery should begin only after the organization has reasonable confidence that malicious access has been removed. Lessons learned occurs later, and disabling monitoring would undermine the response.
Question 400.
A post-incident review finds that analysts identified the attack quickly but took too long to connect endpoint alerts with identity events and network activity. Which improvement would provide the most value?
- Reduce log retention
2. Disable cross-platform detections
3. Improve normalization, correlation, and automated enrichment across endpoint, identity, and network telemetry
4. Remove user context from alerts
Correct Answer: 3
Explanation:
When telemetry already exists but analysts struggle to connect it quickly, improved normalization and correlation can substantially reduce investigation time. Common fields such as username, hostname, IP address, process ID, timestamps, and device identifiers make it easier to link identity events with endpoint and network activity. Automated enrichment can add asset criticality, reputation, account privilege, recent alerts, and related sessions before an analyst begins manual investigation. Reducing retention or removing user context would make response slower and less accurate. Post-incident improvements should focus on turning fragmented telemetry into a coherent and repeatable investigation workflow.