Cisco CCNP CyberSecurity 300-215 Practice Test Questions and Exam Dumps Part7 Q121-140

View Full Cisco CCNP CyberSecurity 300-215 Exam Dumps and Practice Test Dumps

 

Question 121.

An analyst needs to determine whether a suspicious endpoint communicated with other internal hosts before it was isolated. Which source would provide the most useful network-level evidence?

  1. Printer configuration history
    2. Building access records
    3. NetFlow or network telemetry
    4. BIOS inventory information

Correct Answer: 3

Explanation:

NetFlow and similar network telemetry can reveal communication relationships between endpoints by recording information such as source and destination IP addresses, ports, protocols, timestamps, and traffic volumes. This is particularly useful when analysts need to identify internal systems contacted by a potentially compromised host before containment. Unlike full packet capture, flow records generally do not contain payload content, but they provide efficient visibility over large networks and can support retrospective analysis. Printer, physical access, and BIOS records do not provide meaningful network-communication evidence. Analysts should correlate flow data with DNS, firewall, authentication, and endpoint telemetry to determine whether the observed connections represent normal business activity, lateral movement, scanning, or command-and-control behavior.

Question 122.

Which forensic principle should an investigator follow to reduce the risk of unintentionally modifying original digital evidence during analysis?

  1. Analyze a verified forensic copy rather than the original evidence
    2. Open every file directly from the original disk
    3. Disable hashing to improve acquisition speed
    4. Change timestamps before examination

Correct Answer: 1

Explanation:

Investigators should preserve original evidence whenever possible and perform analysis on a verified forensic copy. This reduces the risk of changing file metadata, timestamps, file-system structures, or other artifacts on the original device. A forensic image should be acquired using approved procedures and validated with cryptographic hashes so investigators can demonstrate that the copy accurately represents the source. Directly opening files from original evidence can alter access times or other metadata, while changing timestamps would compromise forensic integrity. Hashing should not be removed merely for speed because integrity verification is fundamental to defensible forensic work. Proper evidence handling should also include chain-of-custody documentation, controlled access, and secure evidence storage.

Question 123.

An endpoint alert shows powershell.exe launching from a Microsoft Word process after a document was opened. Which artifact should the analyst review next to determine what PowerShell actually attempted to do?

  1. DHCP lease duration
    2. Monitor serial number
    3. Physical access logs
    4. PowerShell command-line and script-block telemetry

Correct Answer: 4

Explanation:

PowerShell command-line and script-block telemetry can reveal the actual commands, parameters, encoded content, download locations, and execution behavior associated with suspicious PowerShell activity. When Word launches PowerShell shortly after a document is opened, the process relationship itself is suspicious, but analysts need the command details to understand whether the activity downloaded malware, created persistence, accessed credentials, or performed another action. DHCP information may help identify a host at a certain time, but it does not explain script execution. Physical and hardware inventory data are similarly unrelated. Analysts should also correlate PowerShell activity with resulting child processes, file writes, registry changes, DNS queries, and outbound network connections.

Question 124.

A SOC observes one endpoint attempting connections to hundreds of internal TCP ports and systems over a short period. Which behavior is most likely being observed?

  1. Data compression
    2. Network discovery or scanning
    3. Normal DHCP activity
    4. Disk imaging

Correct Answer: 2

Explanation:

Connections to many internal systems and ports over a short time can indicate network discovery or scanning. Attackers often perform this activity after gaining an initial foothold to identify reachable hosts, services, databases, administrative interfaces, and potential lateral-movement targets. Legitimate vulnerability scanners and management tools can produce similar patterns, so analysts should identify the originating process, source host role, authorized scanning schedules, and account context before classifying the behavior as malicious. DHCP does not normally produce wide-ranging TCP connection attempts, and disk imaging or data compression does not explain the observed network behavior. Network flow telemetry, firewall logs, EDR data, and asset inventory can help distinguish authorized scanning from attacker reconnaissance.

Question 125.

Which Cisco security technology is designed to provide endpoint visibility, malware detection, and response capabilities on protected systems?

  1. Cisco Secure Endpoint
    2. Cisco IOS routing only
    3. Cisco IP SLA
    4. Cisco Discovery Protocol

Correct Answer: 1

Explanation:

Cisco Secure Endpoint is designed to provide endpoint-oriented security capabilities such as malware detection, file and process visibility, retrospective analysis, and response support. Endpoint telemetry is particularly useful during incident investigations because analysts can review process relationships, file activity, network connections, and other behavior associated with a suspected compromise. Cisco IOS routing, IP SLA, and CDP have important networking functions but are not endpoint detection and response platforms. Analysts should combine endpoint findings with broader telemetry such as firewall, DNS, identity, email, and flow information. No single security product provides complete incident visibility, so correlation across multiple sources remains important when scoping and responding to a compromise.

Question 126.

An analyst receives an alert that a known malicious file was observed on an endpoint three weeks ago, before threat intelligence classified the file as malicious. Which capability is most useful in this scenario?

  1. Physical access review
    2. Retrospective analysis
    3. Manual IP addressing
    4. Disk defragmentation

Correct Answer: 2

Explanation:

Retrospective analysis allows analysts to search historical telemetry for files, indicators, or behaviors that were not known to be malicious when originally observed. Once new intelligence identifies a file hash or other artifact as malicious, security teams can search endpoint and network history to determine whether the indicator appeared previously. This can uncover infections that were missed at the time and can significantly expand the known incident timeline. Physical access review and disk maintenance are unrelated. Retrospective analysis depends on sufficient telemetry retention, accurate timestamps, and searchable historical data. Analysts should also pivot beyond the exact file hash to associated processes, network destinations, persistence mechanisms, and related hosts because attackers may have used modified variants.

Question 127.

Which data source would best help identify whether a compromised endpoint transferred an unusually large amount of data to an external system?

  1. User wallpaper configuration
    2. Printer logs
    3. NetFlow or firewall traffic records
    4. BIOS password status

Correct Answer: 3

Explanation:

NetFlow and firewall traffic records can reveal traffic volume, source and destination addresses, ports, protocols, and session timing. This makes them useful for identifying unusual outbound transfers that may indicate data exfiltration. Analysts should compare current activity with historical baselines and the normal role of the host. A workstation sending several gigabytes to a rare external destination may warrant investigation, while similar traffic from an approved backup server may be expected. Flow records may not reveal the transferred content, so endpoint telemetry, proxy data, data-loss prevention systems, or packet capture may be needed for additional context. Hardware and printer information do not provide relevant traffic-volume evidence.

Question 128.

Which condition would most strongly increase confidence that a large outbound data transfer represents exfiltration rather than legitimate business traffic?

  1. The transfer occurs during normal business hours
    2. The destination uses TCP
    3. The workstation has an SSD
    4. A sensitive archive was created immediately before the transfer to a rare external destination

Correct Answer: 4

Explanation:

The combination of suspicious file staging and unusual outbound transfer behavior provides stronger evidence of potential exfiltration than either signal alone. If an endpoint creates a large archive containing sensitive documents and then sends a similar amount of data to a destination rarely contacted by the organization, the sequence is particularly concerning. Analysts should inspect the archive contents, responsible process, user account, destination reputation, protocol, and whether encryption or cloud storage was used. Business applications can legitimately compress and transfer data, so context remains important. Time of day and use of TCP are weak indicators by themselves. Correlating endpoint and network evidence improves confidence while reducing false positives.

Question 129.

A compromised workstation queries many internal hostnames and Active Directory objects immediately after initial execution. Which MITRE ATT&CK tactic best describes this activity?

  1. Discovery
    2. Exfiltration
    3. Impact
    4. Persistence

Correct Answer: 1

Explanation:

Discovery describes adversary activities intended to learn about the victim environment after access has been obtained. Attackers may enumerate hosts, users, groups, domains, network configuration, security software, shares, or other resources before choosing lateral-movement or privilege-escalation targets. Querying many internal hostnames and directory objects fits this objective. Exfiltration concerns removing data, Persistence focuses on maintaining access, and Impact relates to disrupting systems or data. Discovery behavior can resemble legitimate administrative activity, so analysts should consider the account, process, endpoint role, frequency, and timing. Mapping activity to MITRE ATT&CK can help defenders communicate findings consistently and identify opportunities for improved detections.

Question 130.

Which MITRE ATT&CK tactic is most closely associated with an attacker attempting to disable endpoint security software or clear logs?

  1. Collection
    2. Defense Evasion
    3. Reconnaissance
    4. Resource Development

Correct Answer: 2

Explanation:

Defense Evasion includes techniques adversaries use to avoid detection, bypass controls, hide artifacts, or interfere with security mechanisms. Disabling endpoint protection, clearing event logs, changing security settings, and disguising malicious files can all support this objective. Collection concerns gathering target data, Reconnaissance relates to gathering information about a target, and Resource Development generally concerns preparing infrastructure or capabilities before or during operations. Attempts to disable security products should receive high investigative priority because they may indicate that an attacker is actively attempting to reduce visibility before continuing with credential theft, lateral movement, or data theft. Analysts should preserve available telemetry and determine whether other hosts show similar defensive-control tampering.

Question 131.

An analyst finds a Windows event log was cleared shortly after a suspicious administrator login. Why is this significant?

  1. It may indicate an attempt to remove evidence or evade detection
    2. Clearing logs automatically patches Windows
    3. It proves the administrator account owner is malicious
    4. It increases network throughput

Correct Answer: 1

Explanation:

Clearing security or system logs after suspicious activity can indicate an attempt to remove evidence and evade detection. However, it does not prove that the legitimate owner of the administrator account performed the action; the credentials may have been compromised. Analysts should correlate the log-clearing event with authentication records, endpoint process telemetry, remote access activity, and other centralized logs that may remain available even when local logs are removed. If logs are forwarded to a SIEM or centralized collector, attackers may be unable to erase those copies. The event should also prompt investigation for other defense-evasion behavior. Centralized, immutable, or otherwise protected logging substantially improves incident resilience when local systems are compromised.

Question 132.

Which practice best protects security logs from being destroyed by an attacker who gains local administrator access to an endpoint?

  1. Store all logs only on the endpoint
    2. Forward logs to a centralized protected logging platform
    3. Disable logging after successful authentication
    4. Allow every user to modify logs

Correct Answer: 2

Explanation:

Forwarding logs to a centralized and appropriately protected platform reduces dependence on the compromised endpoint. Even if an attacker clears local event logs, copies already transmitted to a SIEM or logging platform may remain available for investigation. Centralized logging also enables correlation across systems and helps identify attacks that span multiple endpoints. Log repositories should use access controls, appropriate retention, time synchronization, and monitoring for ingestion failures. Keeping the only copy locally allows an administrator-level attacker to remove critical evidence. Disabling or broadly exposing logs would further weaken security. Analysts should also monitor for sudden gaps in log transmission because attackers may attempt to stop forwarding before performing malicious actions.

Question 133.

A security analyst notices that a workstation stopped sending endpoint telemetry five minutes before suspicious authentication activity began. What should the analyst consider?

  1. The endpoint sensor may have been disabled or disrupted as part of the attack
    2. The event proves the workstation was powered off
    3. Missing telemetry is always a network maintenance issue
    4. The incident can be closed because there is insufficient data

Correct Answer: 1

Explanation:

A sudden loss of security telemetry immediately before suspicious activity can indicate sensor tampering, service termination, network disruption, or another defense-evasion technique. Analysts should not automatically assume malicious intent, because software failures or connectivity problems can also cause telemetry gaps. The event should be correlated with endpoint service logs, network records, security alerts, system uptime, and administrative activity. If an attacker disabled the EDR agent before using stolen credentials, that sequence may significantly increase incident severity. Missing data should itself be treated as an investigative clue rather than a reason to close the case. Monitoring sensor health and alerting on unexpected telemetry loss improves security visibility.

Question 134.

Which source is most useful for determining whether a suspicious user account was used to establish a remote desktop session to a Windows server?

  1. Printer audit records
    2. Windows authentication and Remote Desktop-related logs
    3. DHCP scope size
    4. Asset purchase receipts

Correct Answer: 2

Explanation:

Windows authentication and Remote Desktop-related event logs can provide details about successful or failed remote sessions, usernames, source addresses, logon types, and session activity. These records can help analysts determine whether a compromised account was used for lateral movement through RDP. Endpoint telemetry on both source and destination hosts can add process and command context after login. DHCP logs may assist with associating a source IP with a device at the relevant timestamp, but they are not the primary evidence for the RDP session itself. Investigators should compare the login with the user’s normal behavior and determine what actions occurred once the remote session was established.

Question 135.

Which incident-response decision should generally be made before reconnecting a rebuilt system to production?

  1. Confirm that the system is patched, security controls are operational, and compromise indicators are absent
    2. Disable all monitoring
    3. Restore the attacker’s persistence mechanism for testing
    4. Delete every investigation record

Correct Answer: 1

Explanation:

Before a rebuilt or remediated system is returned to production, the response team should verify that the operating system and applications are patched, required security controls are active, compromised credentials have been addressed, and known malicious artifacts are absent. The system should also be monitored closely after reconnection for signs of recurrence. Recovery should not be rushed merely because business pressure exists, because reconnecting an incompletely remediated system can reintroduce the attacker to the environment. Disabling monitoring or restoring persistence would directly increase risk. Investigation records should be retained according to organizational policy so the incident can be reviewed and lessons can be incorporated into future defenses.

Question 136.

During an investigation, an analyst finds that malware communicates with its controller only once every eight hours. Why can this technique complicate detection?

  1. It causes every firewall to stop logging
    2. It prevents endpoint telemetry from working
    3. It automatically encrypts all traffic
    4. Low-frequency beaconing can blend into normal background network activity

Correct Answer: 4

Explanation:

Low-frequency beaconing reduces the number of observable network events and can make malicious communication harder to distinguish from ordinary background traffic. A connection every several hours may not trigger simple rules designed to identify highly regular or frequent command-and-control traffic. Analysts may need longer observation windows, historical flow data, rare-destination analysis, endpoint process context, and threat intelligence to identify such behavior. Low frequency does not automatically disable logging or encrypt traffic. Attackers may also add timing variation, called jitter, to make patterns less obvious. Behavioral analysis that combines rarity, destination reputation, process identity, and historical baselines can improve detection of slow command-and-control activity.

Question 137.

An analyst identifies command-and-control traffic from one endpoint. Which hunting strategy is most likely to reveal additional compromised systems using the same malware family?

  1. Search for related domains, IPs, certificates, process patterns, and beaconing behavior across the environment
    2. Examine only the affected user’s wallpaper
    3. Replace network switches
    4. Disable DNS logging

Correct Answer: 1

Explanation:

A broad hunt should use both static indicators and behavioral characteristics. Related domains, IP addresses, TLS certificates, file hashes, process relationships, command lines, persistence artifacts, and similar beaconing patterns can all help identify additional compromised hosts. Relying on only one hash or domain can miss variants because attackers frequently change infrastructure and malware files. Disabling logging would remove useful visibility, while hardware replacement is unwarranted without evidence of device failure. Hunting across multiple telemetry sources allows analysts to determine whether the initial compromise was isolated or part of a wider campaign. Confirmed findings can then be converted into improved detection rules and response playbooks.

Question 138.

Which evidence would most strongly indicate that a malicious actor used a compromised account to access a file server and collect sensitive documents?

  1. The user owns a laptop
    2. Authentication to the file server followed by unusual bulk file access from the same account
    3. The file server uses NTFS
    4. The user has a corporate email address

Correct Answer: 2

Explanation:

Authentication followed immediately by unusual bulk access to sensitive files provides a meaningful sequence supporting the hypothesis that the account was used for collection. Analysts should examine the source host, authentication method, accessed directories, file types, volume of data read, historical user behavior, and whether archive creation or exfiltration followed. Simply having an account or using a common file system provides little evidence. The account owner may also be a victim rather than the attacker, so conclusions should focus on the activity and supporting telemetry rather than assuming insider intent. Identity, file-access auditing, EDR, and network data together can help reconstruct the attack sequence.

Question 139.

A SOC determines that a detection failed because a critical log source was not being parsed correctly by the SIEM. What should be done after correcting the parser?

  1. Test ingestion and detection logic using representative events and search historical data if available
    2. Assume the issue is fixed without validation
    3. Disable the log source
    4. Shorten retention to one hour

Correct Answer: 1

Explanation:

After correcting a parsing problem, the SOC should validate that events are being ingested, normalized, and mapped to expected fields correctly. Detection rules relying on those fields should then be tested with representative data. If raw historical logs remain available, analysts should consider retrospective searches to determine whether earlier malicious events were missed during the parsing failure. Simply changing the parser without validation could leave the same visibility gap in place. Disabling the source or drastically shortening retention would worsen the problem. Monitoring data-pipeline health, parser failures, and source-volume changes is an important operational control because detection logic cannot function reliably when underlying telemetry is incomplete or malformed.

Question 140.

A post-incident review shows that analysts repeatedly performed the same manual containment and enrichment steps. Which improvement is most appropriate?

  1. Remove the incident-response playbook
    2. Stop collecting contextual data
    3. Automate suitable repeatable tasks while preserving analyst approval for high-impact actions
    4. Disable alerts that require investigation

Correct Answer: 3

Explanation:

Repeatable enrichment and low-risk response steps are strong candidates for automation. Automated workflows can gather asset criticality, user information, threat-intelligence reputation, recent authentication events, endpoint details, and other context before an analyst begins investigation. Certain containment actions may also be automated or semi-automated when organizational policy permits, but high-impact actions such as disabling critical accounts or isolating production systems may still require analyst approval. Automation should increase consistency and speed without removing necessary judgment. Eliminating contextual data or suppressing alerts would reduce security effectiveness. Post-incident reviews should identify repetitive work and convert it into tested, documented workflows that shorten response time while maintaining appropriate controls.