View Full Cisco CCNP CyberSecurity 300-215 Exam Dumps and Practice Test Dumps
Question 41.
A SOC analyst notices that several endpoints queried the same rare domain shortly before downloading executable content. Which investigative approach is most appropriate?
- Pivot on the domain across DNS, proxy, and endpoint telemetry
2. Reimage every workstation immediately
3. Ignore the domain because DNS traffic is always benign
4. Delete historical logs to reduce noise
Correct Answer: 1
Explanation:
Pivoting on the suspicious domain across multiple telemetry sources helps the analyst determine scope and context. DNS logs can identify which systems resolved the domain, proxy logs can show HTTP or HTTPS requests, and endpoint telemetry can identify which processes initiated the connections or created downloaded files. This allows the analyst to distinguish isolated activity from a broader compromise. Immediately reimaging every system would be disruptive before scope is established, while ignoring DNS activity could miss command-and-control or malware delivery. Historical logs should be preserved because they may reveal earlier communication. Good investigation techniques repeatedly pivot from one artifact to related hosts, users, processes, domains, hashes, and timestamps.
Question 42.
Which data source is most useful for determining which internal user downloaded a suspicious file through an authenticated corporate web proxy?
- BIOS logs
2. Proxy logs
3. Physical inventory records
4. UPS event logs
Correct Answer: 2
Explanation:
Authenticated proxy logs can often associate web requests with usernames, client IP addresses, requested URLs, timestamps, response codes, and transferred data. This makes them valuable when determining which user accessed a malicious site or downloaded a suspicious file. The analyst can correlate the username and client IP with endpoint telemetry to identify the responsible process and determine whether the download was intentional or malicious. BIOS, inventory, and UPS logs do not provide web-access attribution. Proxy data should still be interpreted carefully because shared systems, service accounts, or credential misuse can complicate attribution. Stronger conclusions come from combining proxy records with identity, DNS, firewall, and endpoint evidence.
Question 43.
A security analyst observes a host making HTTPS connections to a newly registered domain every five minutes with nearly identical byte counts. Which hypothesis should be investigated first?
- Printer discovery
2. DHCP renewal
3. Command-and-control beaconing
4. Normal ARP activity
Correct Answer: 3
Explanation:
Regular outbound connections to a rare or newly registered domain at nearly fixed intervals and with similar byte sizes can indicate command-and-control beaconing. Malware often checks in periodically to report status, receive tasks, or transfer small amounts of information. The analyst should examine the destination’s reputation, certificate data, DNS history, associated processes, user context, timing jitter, and whether other systems exhibit the same pattern. Legitimate management agents can also behave periodically, so regularity alone is not proof of compromise. DHCP and ARP are local networking functions with different traffic patterns. Correlating network observations with endpoint process telemetry is especially important for confirming whether the connection is malicious.
Question 44.
Which technique best helps an analyst determine whether suspicious outbound traffic is associated with a browser, an approved application, or malware?
- Review the monitor serial number
2. Check only the destination country
3. Replace the network cable
4. Correlate the connection with endpoint process telemetry
Correct Answer: 4
Explanation:
Endpoint process telemetry can associate network connections with the executable, process ID, parent process, user, file path, hash, and command line responsible for the communication. This provides far more reliable context than destination geography alone. For example, communication to an unusual country may still be legitimate if it originates from an approved cloud application, while communication to a common cloud provider can still be malicious if initiated by an unexpected process. Replacing cables or examining hardware inventory does not answer the attribution question. Security analysis is strongest when endpoint and network evidence are correlated so the analyst can understand not just where traffic went, but what generated it and why.
Question 45.
A threat-intelligence report provides a list of newly identified malicious file hashes. What is the best way for a SOC analyst to use this information?
- Search historical and current endpoint telemetry for the hashes
2. Delete every file with a similar filename
3. Block all executable files across the organization
4. Ignore the hashes because they are not behavioral indicators
Correct Answer: 1
Explanation:
Searching current and historical endpoint telemetry for malicious hashes can reveal whether any systems contain or executed the known files. This retrospective approach is useful when intelligence becomes available after the original compromise may have occurred. Analysts should also consider related filenames, file paths, parent processes, network indicators, and behaviors because attackers can modify malware slightly and generate a different hash. Deleting files solely based on a similar filename is unreliable, and blocking all executables would be operationally impractical. Hashes are valuable indicators of compromise, but they should be combined with broader behavioral and contextual analysis to improve detection resilience and avoid missing modified variants.
Question 46.
Which characteristic generally makes a behavioral detection more resilient than a static hash-based detection?
- It depends on the exact byte content of one file
2. It focuses on attacker actions or process relationships that may persist across malware variants
3. It requires no telemetry
4. It can never generate false positives
Correct Answer: 2
Explanation:
Behavioral detections focus on actions such as suspicious process relationships, credential access, persistence creation, unusual scripting, or lateral movement. These techniques may remain consistent even when an attacker recompiles malware, changes domains, or modifies file hashes. Static hashes are precise but fragile because any file modification can create a new value. Behavioral analytics still require quality telemetry and can produce false positives when legitimate tools behave similarly to attackers. For this reason, analysts should combine behavior, context, asset criticality, user information, and threat intelligence. Detection engineering is generally strongest when it uses both high-confidence indicators and more durable behavioral patterns rather than relying exclusively on one approach.
Question 47.
A detection rule alerts whenever powershell.exe runs. The SOC receives thousands of alerts from legitimate administrators. Which improvement would best reduce false positives without eliminating useful coverage?
- Disable PowerShell logging
2. Ignore all PowerShell activity permanently
3. Add contextual conditions such as unusual parent processes, encoded commands, or suspicious network activity
4. Block every administrator account
Correct Answer: 3
Explanation:
A rule that alerts on every PowerShell execution is too broad because PowerShell is widely used for legitimate administration. Better detection logic incorporates suspicious context such as encoded command arguments, execution from unusual parent processes, downloads from external locations, hidden windows, unexpected user accounts, or associated network connections. This reduces alert volume while preserving coverage for behavior more consistent with malicious use. Disabling logging or ignoring all PowerShell activity would create major visibility gaps. Blocking administrators is not an appropriate substitute for detection tuning. Effective security analytics should distinguish normal administrative behavior from suspicious deviations using multiple fields rather than relying on a single executable name.
Question 48.
A security analyst sees a process named svchost.exe running from a user’s Downloads directory. Why should this be considered suspicious?
- All instances of svchost.exe are malicious
2. Downloads directories cannot contain executables
3. Windows never uses processes with that name
4. The execution path is inconsistent with the normal location of the legitimate Windows binary
Correct Answer: 4
Explanation:
Attackers frequently use filenames that resemble legitimate system processes to make malicious files less noticeable. The legitimate Windows svchost.exe is expected to run from trusted system locations, so a file with the same name executing from a user’s Downloads folder is suspicious. The analyst should verify the full path, digital signature, file hash, parent process, command line, creation time, and network activity before classifying it. Not every file named svchost.exe is malicious, and executable files can exist in Downloads directories, but the location mismatch is an important anomaly. File path validation is therefore a valuable complement to simple process-name monitoring.
Question 49.
Which type of threat-intelligence information provides the most immediate operational value when blocking known malicious infrastructure?
- IP addresses and domains associated with active malicious activity
2. Annual budget forecasts
3. Hardware warranty information
4. Employee vacation schedules
Correct Answer: 1
Explanation:
Current malicious IP addresses and domains can provide direct operational value because they can be searched in telemetry, added to blocklists, or used in detection rules when appropriate. Analysts should consider the age, confidence, and context of the intelligence because infrastructure can change ownership or be reused. A stale IP indicator may generate false positives if it later belongs to a legitimate service. Threat intelligence is most useful when enriched with timestamps, confidence, associated campaigns, malware families, and observed behaviors. Budget forecasts, warranties, and vacation schedules may matter operationally but do not directly support blocking malicious infrastructure during an active security investigation.
Question 50.
A security team wants to assign confidence and severity to threat-intelligence indicators before automatically blocking them. Why is this important?
- Every threat feed is guaranteed to be accurate
2. Indicators can become stale, context-dependent, or falsely associated with malicious activity
3. Automatic blocking never affects legitimate traffic
4. Threat intelligence should never influence detection
Correct Answer: 2
Explanation:
Threat-intelligence indicators are not equally reliable. Some may come from highly trusted sources with recent direct observations, while others may be old, weakly attributed, or context dependent. IP addresses, domains, and cloud infrastructure can also change ownership, creating false-positive risk if old intelligence is blocked indefinitely. Assigning confidence, severity, age, and source information allows automation to treat indicators appropriately. High-confidence malicious infrastructure may justify immediate blocking, while lower-confidence indicators may be better suited for alerting or enrichment. Mature security operations therefore evaluate intelligence quality rather than assuming every external feed is correct or equally actionable.
Question 51.
Which security operation is most useful for determining whether a suspicious behavior seen on one compromised endpoint also exists elsewhere in the environment?
- Threat hunting
2. Hardware disposal
3. Software procurement
4. Printer maintenance
Correct Answer: 1
Explanation:
Threat hunting allows analysts to proactively search for similar behavior across the environment after discovering a suspicious technique on one endpoint. For example, if an attacker created a scheduled task with an unusual command line, analysts can search endpoint telemetry for comparable task creation events on other hosts. Hunting helps determine whether the incident is isolated or part of a wider compromise. It can also reveal detection gaps and provide material for new detection rules. Hardware disposal, procurement, and printer maintenance are unrelated. A useful hunt begins with a clear hypothesis and uses available telemetry to test whether the same technique, artifact, or behavioral pattern appears elsewhere.
Question 52.
An analyst finds an executable that makes outbound connections but has no known malicious hash and is not detected by antivirus. Which next step would provide the most useful context?
- Delete all logs before executing it again
2. Assume the file is safe because the hash is unknown
3. Disable endpoint monitoring
4. Analyze its behavior, process relationships, network destinations, and file activity
Correct Answer: 4
Explanation:
Absence of a known malicious hash or antivirus detection does not prove a file is benign. New or customized malware may not yet appear in reputation databases. Behavioral analysis can reveal whether the executable creates persistence, spawns suspicious processes, modifies sensitive locations, injects code, or communicates with unusual infrastructure. Analysts should use controlled procedures and, when appropriate, an isolated analysis environment rather than executing suspicious files casually on production systems. Static properties such as signatures, strings, and metadata can also add context. Strong security analysis combines reputation with actual behavior rather than assuming that unknown means safe.
Question 53.
Which log source is most useful for investigating whether a user opened a phishing attachment that launched a suspicious child process?
- Endpoint process telemetry
2. UPS logs
3. Physical access records only
4. Printer configuration
Correct Answer: 1
Explanation:
Endpoint process telemetry can reveal the relationship between the application that opened the attachment and any child process launched afterward. For example, an analyst might see a word-processing application spawning a command shell or script interpreter. This process chain can strongly support the conclusion that the attachment triggered code execution. Email gateway logs can provide additional evidence about the message and attachment, while proxy and DNS telemetry may reveal subsequent network activity. Physical access or printer configuration does not show process creation. Investigators should reconstruct the sequence from message delivery through attachment execution, persistence, network communication, and any subsequent lateral movement.
Question 54.
A suspicious process terminates shortly before memory acquisition. Which source could still provide historical evidence that the process previously executed?
- Monitor EDID data
2. EDR historical telemetry
3. Keyboard settings
4. Power-strip logs
Correct Answer: 2
Explanation:
EDR platforms often retain historical process execution data even after the process has terminated. This can include executable paths, hashes, parent-child relationships, command lines, users, timestamps, and related network connections. Memory acquisition is valuable for active volatile artifacts, but a process that has already exited may no longer be present in RAM. Historical endpoint telemetry can therefore fill important gaps. Analysts should also consider Windows event logs, prefetch artifacts, script logs, and other forensic sources depending on the environment. No single source is guaranteed to contain every artifact, so investigations benefit from overlapping telemetry and retention policies that preserve useful historical evidence.
Question 55.
An analyst suspects that an attacker used stolen credentials to move from one workstation to another. Which evidence would best support lateral-movement analysis?
- Authentication events correlated with source and destination host activity
2. Display brightness settings
3. Printer toner levels
4. Laptop battery health
Correct Answer: 1
Explanation:
Lateral movement analysis often relies on authentication events correlated with endpoint and network activity. Analysts should examine which account authenticated, the source host, destination host, logon type, protocol, timestamp, and subsequent processes or remote-service activity. This can reveal whether a compromised credential was used to access additional systems. Endpoint telemetry can show remote execution tools, newly created services, PowerShell activity, or other behaviors following authentication. Display, printer, and battery data do not contribute meaningfully to this investigation. Analysts should compare observed behavior with the user’s normal access patterns and determine whether the account itself or the originating host was compromised.
Question 56.
Which MITRE ATT&CK tactic is most closely associated with an attacker attempting to obtain usernames, passwords, or authentication material?
- Discovery
2. Impact
3. Credential Access
4. Collection
Correct Answer: 3
Explanation:
Credential Access is the MITRE ATT&CK tactic covering techniques adversaries use to obtain account names, passwords, hashes, tokens, tickets, or other authentication material. Credential theft can enable privilege escalation, lateral movement, persistence, and access to cloud or remote services. Discovery focuses on learning about the environment, Collection involves gathering targeted data, and Impact includes actions intended to disrupt availability or integrity. Mapping incident behavior to ATT&CK helps analysts describe the attack consistently, identify detection gaps, and understand which defensive controls should be reviewed. A single technique can support multiple attacker goals, so analysts should consider the broader sequence rather than examining each event in isolation.
Question 57.
Which MITRE ATT&CK tactic describes an adversary attempting to keep access to a compromised environment across restarts or credential changes?
- Persistence
2. Reconnaissance
3. Resource Development
4. Exfiltration
Correct Answer: 1
Explanation:
Persistence describes techniques used by adversaries to maintain access to compromised systems despite restarts, logoffs, remediation attempts, or other interruptions. Examples can include scheduled tasks, services, startup items, account creation, modified authentication mechanisms, and other methods that relaunch malicious code or preserve access. Reconnaissance occurs before or during targeting to gather information, Resource Development involves preparing infrastructure or capabilities, and Exfiltration focuses on removing data. Identifying persistence mechanisms is critical during eradication because deleting the visible malware file without removing persistence can allow the attacker to regain control. Analysts should hunt for the same persistence technique across related systems.
Question 58.
A SOC alert identifies a user account authenticating to twenty servers within two minutes, even though the user normally accesses only one application server. Which factor most increases the alert’s priority?
- The user has a long display name
2. The behavior deviates significantly from the established baseline and affects many systems
3. The servers are all in the same rack
4. The user’s workstation has a large hard drive
Correct Answer: 2
Explanation:
Rapid authentication to many servers is more concerning when it strongly differs from the user’s normal behavior and potentially represents lateral movement or automated credential use. Baseline deviation, number of affected assets, privilege level, asset criticality, and surrounding endpoint behavior all help determine alert priority. Physical rack location and disk size have little relevance. The analyst should investigate the source host, authentication type, successful versus failed logins, subsequent process activity, and whether the account has been compromised. Behavioral baselines are especially valuable because an action that is normal for one administrative account may be highly unusual for an ordinary business user.
Question 59.
Which action best preserves investigative value when an analyst discovers an endpoint that may be involved in a serious compromise?
- Follow evidence-preservation procedures and document all actions taken
2. Immediately delete suspicious files without recording them
3. Reboot repeatedly until the alerts stop
4. Allow unrestricted user activity during the investigation
Correct Answer: 1
Explanation:
Evidence preservation requires analysts to follow established procedures, minimize unnecessary changes, and document actions taken during an investigation. Depending on the incident, the analyst may need to capture volatile data, isolate the host, create forensic images, calculate hashes, or maintain chain-of-custody records. Deleting files or repeatedly rebooting can destroy valuable evidence. Allowing unrestricted activity can permit further compromise or alter system state. The exact collection order depends on organizational policy, legal requirements, and the nature of the incident. Investigators should balance containment with preservation so that they both reduce ongoing risk and retain enough evidence to determine what happened.
Question 60.
After an incident is resolved, the SOC determines that analysts spent excessive time manually enriching alerts with reputation and asset information. What improvement would most directly increase future efficiency?
- Remove all threat-intelligence sources
2. Stop collecting asset information
3. Automate enrichment and update the incident-response workflow
4. Disable SIEM correlation rules
Correct Answer: 3
Explanation:
Automating enrichment can add threat-intelligence reputation, asset criticality, user details, geolocation, vulnerability context, and other information to alerts before analysts begin investigation. This reduces repetitive manual work and allows analysts to spend more time on reasoning, scoping, and response. Updating the incident-response workflow ensures that the automation becomes part of a consistent process rather than an isolated technical improvement. Removing intelligence or asset data would reduce useful context, while disabling correlation would decrease detection capability. Post-incident reviews should identify recurring inefficiencies and convert them into concrete improvements such as automated enrichment, better playbooks, stronger telemetry, or refined detection rules.