{"id":22730,"date":"2026-09-26T07:32:09","date_gmt":"2026-09-26T07:32:09","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=22730"},"modified":"2026-09-26T07:32:09","modified_gmt":"2026-09-26T07:32:09","slug":"cisco-300-220-practice-test-questions-and-exam-dumps-part8-q141-160","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cisco-300-220-practice-test-questions-and-exam-dumps-part8-q141-160\/","title":{"rendered":"Cisco 300-220 Practice Test Questions and Exam Dumps Part8 Q141-160"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/300-220-exam-dumps\"><b>Cisco 300-220 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 141.<\/b><\/h3>\n<p><b>Which telemetry can reveal unusual registry modifications?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS response data<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Registry change events<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network route tables<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Printer queue records<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Registry change events can help hunters identify modifications to operating-system configuration and application settings. Attackers may alter registry locations to establish persistence, modify security settings, or influence application behavior. Hunters can examine which key changed, what value was modified, when the change occurred, and which process or account was responsible. DNS responses and route tables provide network information, while printer queues concern printing operations. Registry telemetry becomes more useful when correlated with process execution, user identity, and other endpoint evidence to determine whether a modification was expected or potentially suspicious.<\/span><\/p>\n<h3><b>Question 142.<\/b><\/h3>\n<p><b>What can unusual DNS record types help a hunter identify?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hardware inventory<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Potential tunneling behavior<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Display configuration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Local printer usage<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Unusual DNS record types or patterns can sometimes provide clues about DNS tunneling or other uncommon communication techniques. Hunters may examine query types, frequency, domain structure, response sizes, and requesting hosts to determine whether the activity differs from normal DNS usage. However, unusual DNS behavior does not automatically indicate malicious activity because legitimate applications may use uncommon records. Hardware inventory, display configuration, and printer usage are unrelated to DNS analysis. DNS telemetry becomes more informative when correlated with endpoint processes and network connections associated with the requesting system.<\/span><\/p>\n<h3><b>Question 143.<\/b><\/h3>\n<p><b>Which approach can identify changes from an established endpoint baseline?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Configuration comparison<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cable testing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Printer monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Battery analysis<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Configuration comparison evaluates an endpoint against a known baseline to identify changes. Hunters can compare installed services, startup entries, security settings, applications, scheduled tasks, or other configuration elements with previously established expectations. Unexpected modifications may warrant investigation, particularly when they occur near other suspicious activity. Cable testing, printer monitoring, and battery analysis do not provide comparable endpoint-configuration visibility. Baseline comparison is most effective when the reference configuration is accurate and current. Legitimate software updates and administrative changes should also be considered before treating a difference as malicious.<\/span><\/p>\n<h3><b>Question 144.<\/b><\/h3>\n<p><b>What can process integrity information help determine?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Screen quality<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network bandwidth<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Whether execution context is unusual<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Printer availability<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Process integrity information can help determine whether a process is running under an expected security context or privilege level. Unexpected elevated execution can be an important hunting signal, particularly when associated with unusual applications or user accounts. Analysts can compare process integrity with the executable, parent process, account, command line, and host role. Screen quality, network bandwidth, and printer availability address unrelated operational concerns. Integrity information should not be considered independently; legitimate administrative software can also operate with elevated privileges, so surrounding context is necessary for accurate interpretation.<\/span><\/p>\n<h3><b>Question 145.<\/b><\/h3>\n<p><b>Which activity may indicate remote service execution?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Routine screen locking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Standard file indexing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unexpected service-based process launch<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Normal time synchronization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An unexpected service-based process launch may indicate remote service execution and can warrant investigation. Attackers can abuse legitimate service mechanisms to execute commands on another host after obtaining appropriate access. Hunters can examine the service name, executable path, account context, creation time, source system, and related network activity. Screen locking, file indexing, and time synchronization are generally normal system activities. Service execution should be evaluated against administrative baselines because legitimate management platforms may also create or start services remotely.<\/span><\/p>\n<h3><b>Question 146.<\/b><\/h3>\n<p><b>What does lateral movement analysis primarily examine?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Host-to-host access patterns<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Monitor specifications<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Software license counts<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Battery discharge rates<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Lateral movement analysis examines how activity moves between systems within an environment. Hunters may analyze remote logins, administrative protocols, service execution, authentication relationships, and host-to-host network connections. The goal is to identify access patterns that could indicate an attacker moving from an initially compromised system toward additional resources. Monitor specifications, software license counts, and battery discharge rates are unrelated to lateral movement. Internal network visibility combined with identity and endpoint telemetry can provide stronger evidence about whether observed host-to-host activity is expected administrative behavior or potentially suspicious movement.<\/span><\/p>\n<h3><b>Question 147.<\/b><\/h3>\n<p><b>Which indicator can help identify a suspicious executable across systems?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File hash<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Monitor model<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Keyboard layout<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Screen resolution<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A file hash can provide a consistent identifier for a particular file&#8217;s content. Hunters can search endpoint telemetry for the same hash to determine whether an executable appears on multiple systems. Hashes are useful for identifying known files, comparing collected samples, and finding recurring artifacts. They are not sufficient by themselves to explain whether a file is malicious because legitimate software can share known hashes and attackers can modify files. Monitor models, keyboard layouts, and screen resolutions do not provide comparable executable identification capabilities.<\/span><\/p>\n<h3><b>Question 148.<\/b><\/h3>\n<p><b>Why can parent-process analysis be valuable?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It measures disk capacity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It reveals execution origin<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It changes network routes<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It validates printer drivers<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Parent-process analysis helps determine what process initiated another process. This execution origin can reveal suspicious relationships that may not be obvious from the child process alone. For example, a scripting interpreter launched by an unexpected application can provide an important hunting signal. Hunters can combine parent-child relationships with command-line parameters, user identity, timestamps, and network activity. Disk capacity, network routes, and printer drivers do not explain process origin. Understanding execution lineage is therefore an important part of endpoint investigations involving potentially malicious process activity.<\/span><\/p>\n<h3><b>Question 149.<\/b><\/h3>\n<p><b>Which observation can strengthen a suspected command-and-control finding?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Matching screen settings<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Normal keyboard activity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Correlated beacon-like network timing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Standard printer configuration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Correlated beacon-like network timing can strengthen a suspected command-and-control finding when repeated connections occur at unusual intervals and are associated with suspicious endpoint activity. Hunters can examine connection periodicity, destination infrastructure, process ownership, and related DNS requests. Timing alone does not establish malicious command-and-control because legitimate applications can also communicate periodically. Screen settings, keyboard activity, and printer configuration generally provide little evidence about network command channels. Combining network timing with endpoint and intelligence data creates stronger investigative context and helps distinguish suspicious automation from normal application behavior.<\/span><\/p>\n<h3><b>Question 150.<\/b><\/h3>\n<p><b>What can endpoint process trees help investigators reconstruct?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network cable paths<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Execution sequences<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Printer maintenance history<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Display calibration events<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Endpoint process trees help investigators reconstruct execution sequences by showing relationships between parent and child processes. This can reveal how an application started another program, whether a scripting engine was launched unexpectedly, or whether multiple processes formed a suspicious chain. Network cable paths, printer maintenance, and display calibration do not involve process lineage. Process trees are particularly valuable during malware investigations because they provide temporal and structural context around execution. Analysts can combine process-tree evidence with command lines, user accounts, file paths, and network connections to build a more complete picture.<\/span><\/p>\n<h3><b>Question 151.<\/b><\/h3>\n<p><b>Which log source is most relevant to investigating failed privilege escalation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Authentication and authorization logs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Display configuration logs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Printer status records<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Audio device events<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Authentication and authorization logs are highly relevant when investigating failed privilege escalation because they can record access attempts, account identities, privilege-related events, and authorization outcomes. Hunters can correlate these records with process execution and endpoint activity to determine whether a user or process attempted to obtain higher privileges. Display, printer, and audio logs generally provide unrelated information. Privilege escalation investigations benefit from combining identity telemetry with endpoint evidence because the sequence of authentication, process execution, and authorization events can reveal how an attempted escalation occurred.<\/span><\/p>\n<h3><b>Question 152.<\/b><\/h3>\n<p><b>What does infrastructure pivoting allow a hunter to do?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Change firewall hardware<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Replace endpoint software<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Expand investigation through related indicators<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Reconfigure display settings<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Infrastructure pivoting allows a hunter to expand an investigation from one known indicator to related infrastructure or artifacts. For example, an identified domain may lead investigators to examine associated addresses, certificates, hosting relationships, or other infrastructure characteristics. This approach can uncover additional indicators that were not initially known. Firewall hardware, endpoint software, and display settings are unrelated to investigative pivoting. Infrastructure relationships should be validated carefully because shared hosting and common services can create legitimate associations that do not necessarily indicate malicious coordination.<\/span><\/p>\n<h3><b>Question 153.<\/b><\/h3>\n<p><b>Which artifact can reveal recent changes to Windows services?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service configuration records<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS cache entries<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Screen saver settings<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Browser bookmarks<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Service configuration records can reveal changes involving Windows services, including newly created services, modified executable paths, startup behavior, and associated accounts. Attackers may abuse services for persistence or execution, making unexpected service changes useful hunting signals. DNS cache entries provide name-resolution information, while screen saver settings and browser bookmarks address unrelated endpoint functions. Service evidence should be correlated with timestamps, process activity, account context, and file paths to determine whether the modification was part of legitimate administration or potentially unauthorized activity.<\/span><\/p>\n<h3><b>Question 154.<\/b><\/h3>\n<p><b>What can unusual parent-child relationships indicate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unexpected execution behavior<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Increased monitor brightness<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Printer paper shortages<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Lower battery capacity<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Unusual parent-child process relationships can indicate unexpected execution behavior. For instance, an office application launching a command interpreter or a system utility spawning an unfamiliar executable may deserve closer examination. Such relationships do not automatically prove malicious activity because legitimate software can create unusual process chains. Hunters should investigate the executable, command line, user, timing, file location, and related network connections. Monitor brightness, printer supplies, and battery capacity do not provide useful process-lineage information. Process relationships are particularly valuable because they expose how execution originated and progressed on an endpoint.<\/span><\/p>\n<h3><b>Question 155.<\/b><\/h3>\n<p><b>Which network attribute helps distinguish communication services?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Screen orientation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Destination port<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Keyboard language<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disk manufacturer<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Destination ports help identify the network service associated with a connection. Hunters can examine destination ports together with protocols, addresses, timestamps, and process information to determine whether communications match expected application behavior. A port number alone does not prove which application is responsible or whether the connection is malicious because services can use nonstandard ports. Screen orientation, keyboard language, and disk manufacturer do not provide equivalent network-service information. Port analysis becomes more useful when combined with flow records and endpoint telemetry to establish the context of suspicious communications.<\/span><\/p>\n<h3><b>Question 156.<\/b><\/h3>\n<p><b>Which practice helps reduce noise in a behavioral hunt?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Removing all contextual data<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ignoring historical activity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Applying environment-specific filters<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabling telemetry collection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Environment-specific filters can reduce noise by excluding activity that is known to be legitimate within a particular organization. For example, approved administrative tools, trusted management servers, or expected automated processes may be excluded when appropriate. Removing contextual data, ignoring historical behavior, or disabling telemetry would generally make investigations less accurate. Filters should be carefully documented and periodically reviewed because legitimate infrastructure changes can make previously safe exclusions inappropriate. Proper tuning helps hunters focus on meaningful deviations while maintaining sufficient visibility for discovering genuinely suspicious behavior.<\/span><\/p>\n<h3><b>Question 157.<\/b><\/h3>\n<p><b>What can endpoint isolation help accomplish during an active investigation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Limit potential host communication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Increase monitor resolution<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Repair printer hardware<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Expand disk capacity<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Endpoint isolation can limit a potentially compromised host&#8217;s network communication while allowing investigators to continue examining the system. This can help reduce the opportunity for an attacker or malicious process to communicate with external infrastructure or other internal systems. Isolation should follow established incident-response procedures because completely disconnecting a system may affect evidence collection or business operations. Monitor resolution, printer hardware, and disk capacity are unrelated objectives. Endpoint isolation is a containment measure rather than a hunting technique itself, but hunting findings may provide evidence supporting its use during incident response.<\/span><\/p>\n<h3><b>Question 158.<\/b><\/h3>\n<p><b>Which source can reveal commands executed by an authenticated user?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Process command-line telemetry<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Display event logs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Printer usage records<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Power-management events<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Process command-line telemetry can reveal commands executed by processes associated with an authenticated user. This evidence can help investigators understand administrative actions, scripting activity, discovery commands, or potentially malicious execution. Hunters should examine command-line information alongside the user identity, parent process, executable path, timestamps, and related network activity. Display events, printer usage, and power-management records do not normally expose command execution. Command-line telemetry can be especially valuable when investigating activity performed through legitimate interpreters or administrative utilities that attackers may also abuse.<\/span><\/p>\n<h3><b>Question 159.<\/b><\/h3>\n<p><b>What does threat-intelligence confidence help an analyst assess?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Monitor compatibility<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Printer reliability<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Indicator reliability<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disk performance<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Threat-intelligence confidence helps analysts assess how reliable an intelligence item or indicator is based on its source, supporting evidence, validation, and historical accuracy. Confidence can help hunters decide how much investigative weight to assign to an indicator. A high-confidence indicator may justify more immediate investigation, while lower-confidence information may require additional validation. Monitor compatibility, printer reliability, and disk performance are unrelated concepts. Intelligence confidence should still be considered alongside internal telemetry because an externally reported indicator may have different relevance within a specific environment.<\/span><\/p>\n<h3><b>Question 160.<\/b><\/h3>\n<p><b>Which outcome shows that a hunting hypothesis was successfully validated?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The query returned no data<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Evidence matched the expected behavior<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">All logs were deleted<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Monitoring was disabled<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A hunting hypothesis is successfully validated when collected evidence supports the expected behavior described by the hypothesis. The evidence should be sufficiently relevant and reliable to demonstrate that the investigated activity actually occurred. A query returning no data may disprove the hypothesis or indicate insufficient telemetry, while deleting logs or disabling monitoring removes useful evidence. Successful validation should also include appropriate documentation and, where applicable, additional corroborating evidence. Once validated, the finding can potentially support detection development, incident response, threat intelligence, or additional targeted hunting.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cisco 300-220 Exam Dumps and Practice Test Dumps &nbsp; Question 141. Which telemetry can reveal unusual registry modifications? DNS response data Registry change events Network route tables Printer queue records Correct Answer: 2 Explanation: Registry change events can help hunters identify modifications to operating-system configuration and application settings. Attackers may alter registry locations [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22730"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=22730"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22730\/revisions"}],"predecessor-version":[{"id":22731,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22730\/revisions\/22731"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=22730"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=22730"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=22730"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}