{"id":22724,"date":"2026-09-26T07:31:06","date_gmt":"2026-09-26T07:31:06","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=22724"},"modified":"2026-09-26T07:31:06","modified_gmt":"2026-09-26T07:31:06","slug":"cisco-300-220-practice-test-questions-and-exam-dumps-part5-q81-100","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cisco-300-220-practice-test-questions-and-exam-dumps-part5-q81-100\/","title":{"rendered":"Cisco 300-220 Practice Test Questions and Exam Dumps Part5 Q81-100"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/300-220-exam-dumps\"><b>Cisco 300-220 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 81.<\/b><\/h3>\n<p><b>Which method can uncover abnormal lateral movement between hosts?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">User-interface review<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Software licensing checks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">East-west traffic analysis<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Screen resolution testing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">East-west traffic analysis examines communication between systems within an environment. This visibility can help identify unusual host-to-host connections that may indicate lateral movement. Hunters can investigate unexpected administrative protocols, repeated connections between systems, unusual source-destination relationships, and activity involving sensitive servers. User-interface reviews and screen-resolution testing do not provide meaningful network movement visibility, while software licensing checks address application compliance. Internal traffic analysis becomes particularly valuable when an attacker has already gained access to one system and begins attempting to reach additional systems within the same environment.<\/span><\/p>\n<h3><b>Question 82.<\/b><\/h3>\n<p><b>What can command-line telemetry reveal during a hunt?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Executed command parameters<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Monitor refresh rate<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cable length<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Printer toner level<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Command-line telemetry can reveal the commands and parameters used during process execution. This information can provide important evidence about administrative actions, scripting activity, reconnaissance, configuration changes, or potentially malicious execution. For example, unusual parameters may expose suspicious tools or techniques that are not obvious from the process name alone. Monitor refresh rates, cable lengths, and printer toner levels are unrelated to command execution analysis. Command-line evidence should be interpreted alongside process ancestry, user identity, timestamps, and other telemetry to determine whether observed activity is expected or potentially suspicious.<\/span><\/p>\n<h3><b>Question 83.<\/b><\/h3>\n<p><b>Which artifact can help identify persistence through scheduled execution?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS response codes<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Scheduled task records<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network cable statistics<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Display driver versions<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Scheduled task records can help hunters identify programs configured to execute automatically according to a schedule or system event. Attackers may abuse scheduled execution mechanisms to maintain persistence or repeatedly launch malicious processes. Hunters can examine task names, commands, execution paths, creation times, and associated accounts to identify unusual configurations. DNS response codes provide domain-resolution information, network cable statistics describe connectivity characteristics, and display driver versions concern hardware support. Scheduled task telemetry is therefore a useful endpoint artifact when investigating persistence mechanisms based on recurring or event-triggered execution.<\/span><\/p>\n<h3><b>Question 84.<\/b><\/h3>\n<p><b>Why should hunters correlate endpoint and network telemetry?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To increase screen brightness<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To eliminate authentication logs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To reduce storage capacity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To connect host behavior with communications<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Correlating endpoint and network telemetry allows hunters to connect what happened on a host with the communications generated by that host. For example, a suspicious process can be associated with outbound connections, DNS lookups, or repeated contact with an external destination. This combined context can make an investigation more meaningful than examining either source independently. Screen brightness, storage capacity, and authentication-log removal are unrelated objectives. Cross-source correlation is particularly valuable because malicious activity often produces multiple observable traces across endpoint and network layers.<\/span><\/p>\n<h3><b>Question 85.<\/b><\/h3>\n<p><b>Which characteristic can make an indicator more valuable during hunting?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Strong contextual relevance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Random formatting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unknown ownership<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Missing timestamps<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Strong contextual relevance increases the usefulness of an indicator during threat hunting. An indicator becomes more meaningful when its relationship to the suspected activity, affected asset, timeframe, or threat behavior is understood. For example, a domain observed during suspicious process execution may provide more investigative value than the same domain viewed without context. Random formatting does not improve indicator quality, while unknown ownership and missing timestamps can make interpretation more difficult. Hunters should evaluate indicators together with surrounding evidence rather than treating every observable artifact as independently conclusive.<\/span><\/p>\n<h3><b>Question 86.<\/b><\/h3>\n<p><b>What does baseline analysis help identify?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Encryption key length<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Deviations from normal activity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Keyboard layout<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hardware warranty status<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Baseline analysis establishes an understanding of normal activity and helps identify deviations that may deserve investigation. Baselines can cover authentication patterns, network traffic, process behavior, resource usage, or application activity. Once normal behavior is understood, unusual changes can become useful hunting signals. Encryption key length, keyboard layout, and hardware warranty status do not represent the primary purpose of behavioral baseline analysis. A baseline should be based on relevant historical or expected activity and should be periodically reviewed because legitimate environmental changes can alter what is considered normal.<\/span><\/p>\n<h3><b>Question 87.<\/b><\/h3>\n<p><b>Which evidence can help identify unusual privilege use?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Wallpaper metadata<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Audio volume settings<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Privileged account activity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Monitor color profiles<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Privileged account activity can reveal unusual use of elevated permissions. Hunters can examine administrative logins, privilege assignments, privileged command execution, access to sensitive resources, and unexpected use of service or administrator accounts. Such activity may indicate misuse of legitimate privileges or an attacker attempting to expand control within an environment. Wallpaper metadata, audio settings, and monitor profiles generally provide no meaningful visibility into privilege use. Privileged activity should be evaluated in context, including the identity involved, source system, timing, accessed resources, and whether the behavior matches established administrative practices.<\/span><\/p>\n<h3><b>Question 88.<\/b><\/h3>\n<p><b>What is a useful reason to preserve original hunting evidence?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It supports later validation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It increases processor speed<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It changes file ownership<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It disables event collection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Preserving original hunting evidence allows analysts to validate findings later and revisit the investigation when new information becomes available. Original logs, timestamps, artifacts, and query results can help confirm observations, reproduce analytical steps, and support incident investigations. Preserving evidence does not increase processor speed, change file ownership, or disable event collection. Maintaining reliable evidence is especially important when findings may lead to additional response activities or detection development. Proper preservation also helps prevent investigators from relying solely on memory or manually summarized observations.<\/span><\/p>\n<h3><b>Question 89.<\/b><\/h3>\n<p><b>Which pattern may indicate credential spraying activity?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">One successful local login<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Many accounts targeted with few attempts<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Repeated file compression<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Frequent display changes<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Credential spraying typically involves attempting a small number of commonly used or compromised passwords across many different accounts rather than repeatedly attacking a single account. This pattern can help attackers avoid account-lockout thresholds. Hunters can examine authentication telemetry for numerous accounts receiving similar failed-login attempts from the same source or related sources. A single successful local login does not establish spraying behavior, while file compression and display changes are unrelated. Authentication patterns should be analyzed alongside source addresses, timing, account populations, and successful or failed outcomes.<\/span><\/p>\n<h3><b>Question 90.<\/b><\/h3>\n<p><b>Which analysis can reveal unexpected connections to internal services?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network relationship mapping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Font installation review<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Battery health testing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Audio driver inspection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network relationship mapping can show which systems communicate with particular internal services and can expose relationships that differ from expected architecture. Hunters may identify unusual source hosts, unexpected administrative connections, or communication paths involving sensitive systems. Such analysis can be especially useful when investigating lateral movement or compromised credentials. Font installations, battery health, and audio drivers do not provide useful visibility into host-to-host communication relationships. Mapping network relationships against known architecture and asset roles can help distinguish legitimate operational traffic from connections that require additional investigation.<\/span><\/p>\n<h3><b>Question 91.<\/b><\/h3>\n<p><b>What should be examined when investigating suspicious PowerShell activity?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Monitor brightness<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Command content and parent process<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Keyboard manufacturer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Printer paper size<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Suspicious PowerShell activity should be examined together with its command content, execution context, parent process, user, and timing. Command-line details can reveal encoded commands, unusual parameters, downloaded content, or administrative actions. The parent process can also show whether PowerShell was launched by an expected administrative tool or an unusual application. Monitor brightness, keyboard manufacturer, and printer paper size provide no meaningful context for PowerShell investigation. Combining execution details with network and identity telemetry can help determine whether PowerShell activity represents routine administration or potentially malicious behavior.<\/span><\/p>\n<h3><b>Question 92.<\/b><\/h3>\n<p><b>Which result can help establish the timeline of an intrusion?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Event timestamps<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Screen dimensions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Keyboard language<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Printer model<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Event timestamps are fundamental when reconstructing the sequence of activities associated with a potential intrusion. By comparing timestamps from authentication, process execution, network connections, file activity, and other telemetry, hunters can establish relationships between events and identify possible attack stages. Screen dimensions, keyboard language, and printer models do not normally establish event chronology. Accurate time synchronization across systems is also important because inconsistent clocks can make correlated events appear out of order. A reliable timeline can help investigators understand how activity progressed and identify important transitions during an incident.<\/span><\/p>\n<h3><b>Question 93.<\/b><\/h3>\n<p><b>Which hunting technique compares observed behavior against known attack patterns?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Asset depreciation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hardware benchmarking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Technique-based analysis<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Display calibration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Technique-based analysis compares observed activity with known adversary techniques and behaviors. Frameworks such as MITRE ATT&amp;CK can provide structured descriptions of techniques that defenders may use to organize investigations. A hunter can examine telemetry for behaviors associated with credential access, execution, persistence, discovery, lateral movement, or other attack activities. Asset depreciation and hardware benchmarking address unrelated operational concerns, while display calibration concerns visual configuration. Technique-based analysis helps hunters move beyond isolated indicators and investigate activity according to recognizable behavioral patterns.<\/span><\/p>\n<h3><b>Question 94.<\/b><\/h3>\n<p><b>What can file-hash comparison help determine?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Whether files share identical content<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Whether users changed passwords<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Whether DNS is available<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Whether a port is open<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">File-hash comparison can determine whether files produce the same cryptographic hash value, providing a useful way to identify identical content under the same hashing method. Hunters can compare observed files against known malicious samples, trusted versions, or previously collected artifacts. Hashes do not directly determine whether a user changed a password, whether DNS is available, or whether a network port is open. Although hash matches can be valuable indicators, they should still be interpreted within context because a hash identifies content rather than explaining how or why the file appeared on a system.<\/span><\/p>\n<h3><b>Question 95.<\/b><\/h3>\n<p><b>Which observation may indicate abnormal data transfer?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Consistent login naming<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Large outbound transfer to an unusual destination<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Standard system startup<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Routine screen locking<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A large outbound data transfer to an unusual destination may indicate potential data exfiltration and therefore deserves investigation. Hunters can examine transfer volume, destination, protocol, timing, originating process, user account, and asset sensitivity to determine whether the activity is legitimate. A consistent login naming convention, standard startup behavior, or routine screen locking generally does not indicate abnormal data movement. Large transfers can also have legitimate causes, such as backups or software distribution, so hunters should correlate network activity with business context and endpoint evidence before drawing conclusions.<\/span><\/p>\n<h3><b>Question 96.<\/b><\/h3>\n<p><b>Which practice improves reproducibility of a hunting investigation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Documenting queries and assumptions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Removing search history<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Changing timestamps manually<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Avoiding evidence notes<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Documenting queries, assumptions, data sources, time ranges, and investigative decisions improves the reproducibility of a threat-hunting investigation. Another analyst can use the documented methodology to understand how the result was produced and potentially repeat the investigation with updated telemetry. Removing search history, manually changing timestamps, or avoiding evidence notes makes investigations harder to validate. Reproducibility is important because threat hunting often evolves through multiple analytical steps. Good documentation also makes successful hunting logic easier to transform into detection rules, playbooks, or future investigative procedures.<\/span><\/p>\n<h3><b>Question 97.<\/b><\/h3>\n<p><b>Which telemetry can reveal unusual access to sensitive files?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File-access events<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Monitor temperature<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BIOS splash screens<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mouse sensitivity settings<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">File-access events can reveal which users or processes accessed particular files and when those accesses occurred. This information can help hunters investigate unusual access to sensitive documents, unexpected bulk reads, or activity involving protected directories. Analysts can correlate file-access records with user identities, process information, network activity, and asset roles to determine whether the behavior appears legitimate. Monitor temperature, BIOS splash screens, and mouse sensitivity settings do not provide meaningful visibility into file access. File telemetry is particularly useful when hunting for unauthorized data access or potential collection activity.<\/span><\/p>\n<h3><b>Question 98.<\/b><\/h3>\n<p><b>What can a detection gap identified during hunting indicate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">An opportunity to improve monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Guaranteed attacker attribution<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Complete absence of risk<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Automatic evidence destruction<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A detection gap indicates that existing monitoring or detection capabilities may not adequately identify a behavior that a hunt has uncovered. This creates an opportunity to improve telemetry collection, detection logic, alerting, or investigative procedures. A detection gap does not provide guaranteed attribution, demonstrate that an environment has no risk, or imply automatic evidence destruction. Hunters can use these findings to collaborate with detection engineers and security operations teams. Turning identified gaps into improved monitoring helps organizations reduce the likelihood that similar activity will remain invisible during future investigations.<\/span><\/p>\n<h3><b>Question 99.<\/b><\/h3>\n<p><b>Which factor can reduce false positives in behavioral hunting?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Removing all telemetry<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ignoring normal activity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Establishing contextual thresholds<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabling alert correlation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Contextual thresholds can reduce false positives by distinguishing expected behavior from activity that is genuinely unusual. A threshold can consider factors such as asset role, user identity, frequency, destination, time of day, or historical behavior. Removing telemetry, ignoring normal activity, or disabling correlation generally reduces visibility rather than improving analytical accuracy. Effective behavioral hunting requires understanding the environment well enough to identify meaningful deviations. Thresholds should also be reviewed periodically because legitimate operational changes can alter normal patterns and otherwise cause previously accurate detection logic to become noisy.<\/span><\/p>\n<h3><b>Question 100.<\/b><\/h3>\n<p><b>What should follow the discovery of credible malicious activity?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ignore the finding<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Preserve evidence and escalate appropriately<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Delete related logs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disable all endpoints<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When credible malicious activity is discovered, the finding should be documented, relevant evidence preserved, and escalated through the organization&#8217;s established incident-response process. Preserving evidence helps maintain investigative context and supports subsequent validation or response actions. Escalation allows appropriate security personnel to determine containment, eradication, and recovery requirements based on the available evidence. Ignoring the finding or deleting logs can remove valuable information, while disabling every endpoint may cause unnecessary operational disruption. A structured response ensures that hunting discoveries are transferred effectively into the organization&#8217;s broader security workflow.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cisco 300-220 Exam Dumps and Practice Test Dumps &nbsp; Question 81. Which method can uncover abnormal lateral movement between hosts? User-interface review Software licensing checks East-west traffic analysis Screen resolution testing Correct Answer: 3 Explanation: East-west traffic analysis examines communication between systems within an environment. This visibility can help identify unusual host-to-host connections [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22724"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=22724"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22724\/revisions"}],"predecessor-version":[{"id":22725,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22724\/revisions\/22725"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=22724"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=22724"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=22724"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}