View Full Cisco CCNP CyberSecurity 300-215 Exam Dumps and Practice Test Dumps
Question 161.
A security analyst discovers that a compromised endpoint resolved several suspicious domains before contacting an external IP address. Which investigative step provides the best way to expand the scope of the incident?
- Search DNS, proxy, firewall, and endpoint telemetry for the domains and related IP addresses
2. Replace the endpoint network adapter
3. Delete all DNS logs after blocking the domain
4. Disable name resolution across the enterprise
Correct Answer: 1
Explanation:
Searching across multiple telemetry sources allows the analyst to determine whether the same malicious infrastructure was contacted by other systems. DNS logs can show which endpoints resolved the domains, proxy logs can reveal web requests, firewall records can confirm outbound network connections, and endpoint telemetry can identify which processes initiated those communications. Related IP addresses, file hashes, certificates, and URLs can provide additional pivots. Replacing hardware or disabling DNS would be disruptive without helping reconstruct historical activity. Deleting logs would destroy important evidence. Incident scoping is strongest when analysts pivot systematically from known indicators to associated hosts, users, processes, and timestamps rather than investigating one artifact in isolation.
Question 162.
Which security capability is most appropriate for discovering whether a newly identified malicious behavior occurred on endpoints before a formal detection rule existed?
- Asset depreciation analysis
2. Retrospective threat hunting
3. Printer maintenance review
4. Static IP assignment
Correct Answer: 2
Explanation:
Retrospective threat hunting uses historical telemetry to search for behavior that was not previously recognized as malicious. Once analysts learn that attackers use a specific process chain, command pattern, domain, persistence mechanism, or network behavior, they can search retained EDR, SIEM, DNS, proxy, and firewall data for earlier occurrences. This may reveal previously undetected compromise and help establish the true beginning of an incident. The usefulness of retrospective analysis depends heavily on telemetry quality and retention. Asset depreciation, printer maintenance, and addressing configuration do not provide historical attack visibility. Findings from retrospective hunts can also be converted into new detections so future instances generate alerts automatically.
Question 163.
A user account that normally accesses one application server suddenly authenticates to twelve servers in three minutes. Which security concept is most useful for recognizing this behavior as unusual?
- Data deduplication
2. Signature validation
3. Behavioral baselining
4. Disk imaging
Correct Answer: 3
Explanation:
Behavioral baselining establishes what normal activity looks like for a particular user, host, or application. If a user typically accesses one server but suddenly authenticates to twelve systems in rapid succession, the deviation may indicate lateral movement, credential misuse, or automated malicious activity. The analyst should correlate authentication events with source-device telemetry, privilege level, remote execution activity, and subsequent access. A deviation is not automatically malicious because legitimate responsibilities can change, but it provides strong context for prioritization. Signature validation and disk imaging serve different purposes, while deduplication is unrelated. Behavioral baselines are especially valuable when attackers use valid credentials and legitimate administration tools.
Question 164.
Which event would most strongly indicate malicious lateral movement after a successful remote authentication?
- The remote server responds to ping
2. The user opens an approved intranet page
3. The destination host performs a normal scheduled backup
4. A new remote service is created and executes an unfamiliar binary
Correct Answer: 4
Explanation:
Remote service creation followed by execution of an unfamiliar binary is strongly associated with lateral movement and remote code execution techniques. If this occurs immediately after unusual authentication, the combined sequence significantly increases confidence that the account or originating host is compromised. Analysts should review the service name, executable path, file hash, user context, source host, destination host, and whether the same behavior appears elsewhere. A ping response or routine backup provides little evidence of compromise. Once lateral movement is confirmed, the incident should be scoped broadly because additional credentials or systems may already be affected. Containment may require isolating multiple hosts and restricting compromised accounts.
Question 165.
A SOC analyst sees a process named lsass.exe running from a user’s temporary directory. Why is this suspicious?
- The legitimate process is normally expected to run from a trusted Windows system location
2. Windows never uses a process named lsass.exe
3. Temporary directories cannot contain executable files
4. All processes in temporary directories are automatically malware
Correct Answer: 1
Explanation:
Attackers often use filenames that imitate trusted Windows processes to make malicious software appear legitimate. The legitimate lsass.exe normally executes from a protected Windows system location, so an identically named executable running from a user temporary directory is a strong anomaly. Analysts should verify the file path, digital signature, hash, parent process, command line, file creation time, and network behavior. The filename alone does not prove maliciousness because a benign file could theoretically use the same name, but the location mismatch raises suspicion. Path-aware detection is often more effective than process-name-only detection because adversaries can easily choose familiar filenames.
Question 166.
Which data source would best help determine whether a suspicious process created a scheduled task for persistence?
- Network switch temperature logs
2. Endpoint telemetry and Windows task creation events
3. Badge access records
4. Printer queue history
Correct Answer: 2
Explanation:
Endpoint telemetry and Windows task creation events can reveal when scheduled tasks are created, modified, or executed. These records may include the task name, command being run, user account, creation time, and process responsible for the change. Scheduled tasks are frequently used for legitimate administration, but they can also provide persistence or recurring execution for malware. Analysts should evaluate whether the task path, executable, account, and schedule are consistent with normal behavior. Badge and printer records cannot provide this process-level information. If malicious persistence is confirmed, the SOC should search other hosts for the same task name, command, or related binary to determine whether the attacker deployed it more broadly.
Question 167.
Which MITRE ATT&CK tactic is most closely associated with the use of scheduled tasks, startup items, or services to maintain access after reboot?
- Persistence
2. Reconnaissance
3. Collection
4. Impact
Correct Answer: 1
Explanation:
Persistence covers techniques adversaries use to maintain access to systems despite reboots, logoffs, credential changes, or other interruptions. Scheduled tasks, malicious services, registry startup entries, startup folders, and unauthorized accounts are common examples. Reconnaissance involves gathering information about targets, Collection involves gathering data for later use, and Impact concerns disrupting systems or data. Persistence artifacts are especially important during eradication because removing the visible malware payload without eliminating persistence may allow the attacker to regain execution. Analysts should also search for multiple redundant persistence methods because sophisticated intrusions may establish more than one foothold on the same host.
Question 168.
A security analyst observes a large encrypted archive being created from sensitive documents and then uploaded to a cloud-storage domain rarely used by the organization. Which activity is most likely?
- Routine DHCP renewal
2. Normal endpoint patching
3. DNS recursion
4. Data staging and exfiltration
Correct Answer: 4
Explanation:
The sequence of collecting sensitive documents, packaging them into a large encrypted archive, and transferring that archive to an unusual cloud-storage destination is highly consistent with data staging and exfiltration. Analysts should determine which process created the archive, which files were included, the user account involved, destination reputation, transfer size, and whether the cloud service is approved. Legitimate backup or business workflows can produce similar behavior, so context remains necessary. DHCP, DNS, and patching do not explain the combined archive-and-upload sequence. If exfiltration is confirmed, containment should focus on stopping further transfer while preserving evidence and identifying all affected data and systems.
Question 169.
Which network telemetry is most useful for identifying unusually large outbound transfers when packet payloads are not available?
- NetFlow or similar flow records
2. Monitor EDID information
3. BIOS configuration
4. Keyboard layout
Correct Answer: 1
Explanation:
NetFlow and similar flow technologies record metadata such as source and destination addresses, ports, protocols, timestamps, duration, and byte or packet counts. This allows analysts to identify large outbound transfers even when the actual payload is not captured. Flow records are particularly useful for broad enterprise visibility because they require significantly less storage than full packet capture. Analysts can compare traffic volumes against historical baselines and investigate rare destinations, unusual ports, and affected endpoint roles. NetFlow cannot reveal exact file contents, so endpoint, DLP, proxy, or packet data may be required for deeper analysis. Hardware and keyboard information are unrelated to network transfer volume.
Question 170.
What is the primary advantage of full packet capture over flow telemetry during a network investigation?
- It always requires less storage
2. It can provide packet-level protocol details and payload content when traffic is not encrypted
3. It automatically identifies the attacker
4. It removes the need for endpoint telemetry
Correct Answer: 2
Explanation:
Full packet capture records packet-level information and can provide protocol headers, transaction details, transferred content, commands, and other evidence that flow telemetry does not retain. This makes packet capture especially useful when analysts need to reconstruct a session or inspect application behavior. The trade-off is higher storage requirements and potentially greater privacy considerations. Encrypted protocols may still prevent payload inspection unless appropriate decryption capabilities exist. Packet capture also does not replace identity or endpoint telemetry because it may show what communication occurred without identifying the local process or user responsible. Strong investigations therefore combine network packets with endpoint, identity, DNS, and application logs.
Question 171.
A security analyst finds that several hosts stopped forwarding logs shortly before suspicious activity occurred. What should be investigated first?
- Whether logging agents or services were disabled as part of defense evasion
2. Monitor brightness configuration
3. Printer toner levels
4. DHCP scope naming conventions
Correct Answer: 1
Explanation:
A sudden loss of logging from multiple hosts immediately before suspicious activity can indicate tampering with log agents, endpoint sensors, services, or network paths. Attackers may disable security tooling or log forwarding to reduce visibility before performing credential theft, lateral movement, or data exfiltration. Analysts should check agent health, service status, process termination events, administrative activity, network connectivity, and centralized monitoring alerts. Operational failures are also possible, so the event must be validated rather than assumed malicious. Logging gaps themselves are important evidence and should not be ignored. Monitoring telemetry health is a critical defensive capability because detections cannot work properly when log sources silently disappear.
Question 172.
Which practice best protects investigation data if an attacker gains administrative control of an endpoint and clears local logs?
- Keep the only copy of logs on the endpoint
2. Disable log forwarding
3. Forward logs to a centralized protected repository
4. Allow all users to modify log files
Correct Answer: 3
Explanation:
Centralized logging helps preserve evidence even if the local endpoint is compromised. Events that have already been transmitted to a SIEM or protected log platform may remain available after an attacker clears local logs. Centralized collection also supports cross-system correlation and longer retention. The repository itself should have strict access controls, reliable time synchronization, monitored ingestion, and protections against unauthorized modification. Keeping the only copy locally gives an attacker with administrative rights an easy way to destroy evidence. Security teams should also alert on unexpected reductions in event volume or agent health because attackers may try to stop forwarding before clearing local data.
Question 173.
Which forensic artifact should generally be collected early because it may disappear when a system loses power?
- Volatile memory
2. Asset purchase documentation
3. Printed rack diagram
4. Hardware warranty information
Correct Answer: 1
Explanation:
Volatile memory can contain active processes, injected code, network connections, credentials, encryption keys, command history, and other transient artifacts that may disappear after shutdown. When organizational procedures permit, memory acquisition may therefore occur before powering off a compromised system. Analysts must balance evidence preservation against containment because leaving a system connected while collecting memory could allow ongoing malicious activity. The resulting image should be documented, hashed, and protected appropriately. Physical paperwork and warranty data are persistent and do not require urgent collection. Order of volatility is an important forensic concept because some evidence sources are far more time-sensitive than others.
Question 174.
Which forensic control documents every transfer and person who handled evidence during an investigation?
- File compression
2. Chain of custody
3. Network segmentation
4. Data normalization
Correct Answer: 2
Explanation:
Chain of custody documents who collected, possessed, transferred, stored, and analyzed evidence throughout an investigation. It helps demonstrate that the evidence was handled properly and was not substituted, lost, or modified without authorization. A typical record includes evidence identifiers, dates, times, handlers, transfer details, and storage locations. File compression does not document handling, while network segmentation and normalization serve unrelated technical purposes. Chain of custody is particularly important when evidence may support legal, disciplinary, regulatory, or law-enforcement actions. It should be combined with cryptographic hashes, secure storage, restricted access, and repeatable forensic procedures to preserve integrity and defensibility.
Question 175.
Why should a cryptographic hash be calculated after creating a forensic disk image?
- To verify the integrity of the acquired evidence
2. To increase the image storage capacity
3. To remove malware automatically
4. To improve network bandwidth
Correct Answer: 1
Explanation:
A cryptographic hash produces a reproducible value based on the evidence content. By recording the hash immediately after acquisition and comparing it later, investigators can verify that the forensic image has remained unchanged. This provides integrity assurance and supports chain-of-custody documentation. Hashing does not increase capacity, remove malware, or improve network performance. Investigators generally preserve the original evidence and perform analysis on verified working copies. If the hash changes unexpectedly, the discrepancy should be investigated because it may indicate modification, corruption, or a problem with the acquisition process. Evidence integrity is essential for reliable forensic conclusions and for any investigation that may face formal review.
Question 176.
Which device is commonly used during forensic disk acquisition to prevent modifications to the original storage media?
- IDS sensor
2. Network tap
3. Load balancer
4. Write blocker
Correct Answer: 4
Explanation:
A write blocker prevents the forensic workstation from writing data to the original storage media during acquisition. This helps preserve metadata, timestamps, file-system structures, and other evidence. Hardware write blockers are common, although validated software approaches can also be used depending on procedures. Network taps and IDS sensors support network monitoring, while load balancers distribute traffic. A write blocker does not replace hashing, documentation, or chain of custody; it is one component of proper evidence handling. Investigators should still validate the forensic image and document the tools, operator, date, time, and storage location associated with acquisition.
Question 177.
A compromised system is actively spreading malware to other hosts. Which incident-response action should receive immediate priority?
- Contain the affected system to limit propagation
2. Write the final lessons-learned report
3. Purchase replacement hardware
4. Delete every event log
Correct Answer: 1
Explanation:
Containment should receive immediate priority when a system is actively spreading malware because continued connectivity can increase the number of affected hosts and expand business impact. Containment may involve EDR isolation, firewall rules, switch controls, account restrictions, or physical network disconnection depending on organizational procedures. Evidence preservation still matters, so the response team should balance rapid containment with the need to capture volatile data when feasible. Lessons learned occurs after recovery, and deleting logs would destroy valuable evidence. Once propagation is stopped, analysts can continue scoping the incident and move into eradication by removing malware, persistence, compromised credentials, and the original infection vector.
Question 178.
Which action belongs primarily to the eradication phase rather than containment?
- Isolating a workstation from the network
2. Removing malware, persistence mechanisms, and exploited weaknesses
3. Blocking an external IP temporarily
4. Restricting a compromised account while investigation continues
Correct Answer: 2
Explanation:
Eradication addresses the underlying malicious components and root causes after immediate spread has been limited. This includes removing malware, deleting malicious services or scheduled tasks, resetting compromised credentials, patching exploited vulnerabilities, and removing unauthorized tools. Isolation, temporary IP blocking, and account restrictions are commonly containment actions because they reduce immediate risk while investigation continues. Eradication must be thorough because leaving a persistence mechanism or stolen credential in place can allow the attacker to return. In heavily compromised systems, rebuilding from a trusted image may be safer than attempting manual cleanup. Recovery should begin only after the response team has reasonable confidence that attacker access has been eliminated.
Question 179.
Which activity belongs primarily to the recovery phase of incident response?
- Safely restoring systems to production and monitoring for recurrence
2. Creating the incident-response plan for the first time
3. Developing threat intelligence before any event occurs
4. Establishing hardware procurement contracts
Correct Answer: 1
Explanation:
Recovery focuses on returning remediated systems and services to normal operation in a controlled manner. The team should verify that systems are patched, security controls are enabled, compromised credentials have been addressed, data has been restored as necessary, and malicious indicators are absent. Systems are then reconnected and monitored closely for recurrence. Preparation activities such as creating plans occur before incidents. Threat intelligence can support many stages but is not itself recovery. Enhanced monitoring after restoration is important because renewed beaconing, persistence execution, or suspicious authentication may reveal incomplete eradication. Recovery should prioritize both business continuity and confidence that the environment is safe.
Question 180.
A post-incident review determines that several detections existed but analysts did not know which alerts should be escalated quickly. Which improvement would most directly address the problem?
- Reduce log retention
2. Disable high-severity alerts
3. Develop clearer triage criteria, playbooks, and escalation procedures
4. Stop collecting contextual information
Correct Answer: 3
Explanation:
Clear triage criteria and escalation procedures help analysts consistently determine which alerts require immediate action. Playbooks can define what evidence to collect, how to evaluate severity, which assets or accounts increase risk, when to contain systems, and when incidents should be escalated to senior responders or management. Detection alone is not enough if analysts lack a consistent process for interpreting and prioritizing alerts. Reducing telemetry or disabling high-severity alerts would worsen the problem. Mature SOC operations combine strong detections with asset context, user privilege information, threat intelligence, documented workflows, and periodic exercises. Post-incident lessons should result in practical changes that reduce future detection-to-response time.