{"id":22746,"date":"2026-09-26T07:35:17","date_gmt":"2026-09-26T07:35:17","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=22746"},"modified":"2026-09-26T07:35:17","modified_gmt":"2026-09-26T07:35:17","slug":"cisco-300-220-practice-test-questions-and-exam-dumps-part16-q301-320","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cisco-300-220-practice-test-questions-and-exam-dumps-part16-q301-320\/","title":{"rendered":"Cisco 300-220 Practice Test Questions and Exam Dumps Part16 Q301-320"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/300-220-exam-dumps\"><b>Cisco 300-220 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 301.<\/b><\/h3>\n<p><b>Which evidence helps identify abnormal data transfer destinations?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Local group membership<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File creation time<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">External destination context<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Screen saver settings<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">External destination context helps determine whether data transfers are occurring toward expected or suspicious systems. A hunter can examine destination ownership, reputation, geographic context, domain relationships, previous organizational communications, and known infrastructure associations. This information becomes particularly useful when a host sends an unusual amount of data to an unfamiliar external destination. File creation times and group membership may provide supporting context but do not directly characterize the remote destination. Screen saver settings are unrelated. Destination context should be combined with transfer volume, initiating process, account information, and timing to determine whether the observed communication warrants deeper investigation.<\/span><\/p>\n<h3><b>Question 302.<\/b><\/h3>\n<p><b>What is a useful indicator of unusual local privilege activity?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unexpected privilege transition<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Normal DNS resolution<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Routine software update<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Standard logoff event<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An unexpected privilege transition can indicate suspicious local activity, particularly when a process or user suddenly operates with elevated permissions outside normal administrative workflows. Hunters can investigate which account initiated the transition, the originating process, the target process, timing, and associated authentication events. Legitimate software updates can also create elevated processes, so the surrounding context is important before determining whether the behavior is suspicious. Normal DNS resolution and standard logoff events do not directly demonstrate privilege changes. Examining privilege transitions alongside process lineage and identity telemetry can help establish whether elevation was expected or potentially associated with unauthorized activity.<\/span><\/p>\n<h3><b>Question 303.<\/b><\/h3>\n<p><b>Which analysis can reveal rare software execution within a department?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Firewall rule inspection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Peer-based execution frequency<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password complexity review<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP scope modification<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Peer-based execution frequency can reveal software that executes rarely within a defined group of comparable systems. A hunter can establish how often an executable appears across endpoints performing similar business functions and then investigate unusual outliers. Rare execution does not automatically indicate malicious behavior because specialized administrative or business applications may legitimately run on only a small number of systems. Additional context such as file reputation, signer information, execution path, and user identity can improve the analysis. Firewall rules, password policies, and DHCP configuration do not directly measure application execution frequency across comparable endpoints.<\/span><\/p>\n<h3><b>Question 304.<\/b><\/h3>\n<p><b>Why investigate the first-seen time of an unfamiliar artifact?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To calculate CPU temperature<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To establish introduction timing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To measure network bandwidth<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To determine monitor settings<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The first-seen time helps establish when an unfamiliar artifact was initially observed within the monitored environment. This temporal information can be correlated with software deployments, user activity, security alerts, authentication events, and network communications. If the artifact appeared shortly before suspicious behavior began, its introduction time may provide an important investigative lead. First-seen timing does not prove maliciousness because legitimate software can also be newly introduced. CPU temperature, bandwidth measurement, and monitor settings address unrelated areas. Establishing when an artifact first appeared allows hunters to build a more accurate timeline and identify potentially related events surrounding its introduction.<\/span><\/p>\n<h3><b>Question 305.<\/b><\/h3>\n<p><b>Which behavior can indicate unauthorized security-control modification?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Reading a public webpage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Updating a calendar<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Changing endpoint protection settings<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Opening a standard document<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Changes to endpoint protection settings can indicate attempts to weaken or bypass security controls, particularly when they occur unexpectedly or outside approved administrative procedures. Hunters can examine which account made the modification, what configuration changed, when the change occurred, and which process performed it. Legitimate maintenance may also modify security settings, so the activity should be compared against authorized change records and administrative baselines. Opening documents, reading webpages, and updating calendars are common user activities and do not directly indicate security-control tampering. Configuration-change telemetry can therefore provide valuable evidence when investigating attempts to reduce endpoint protection visibility.<\/span><\/p>\n<h3><b>Question 306.<\/b><\/h3>\n<p><b>What can a host inventory comparison reveal during threat hunting?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Missing display drivers<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unusual software presence<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Keyboard preferences<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Wallpaper differences<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Comparing host inventories can reveal software or components that appear unexpectedly on one endpoint or a small subset of systems. Such differences may identify unauthorized tools, newly installed applications, unusual services, or software that does not match the approved environment. Inventory differences should be interpreted according to the endpoint&#8217;s business role because specialized systems can legitimately contain unique software. Display drivers, keyboard preferences, and wallpaper differences generally provide little security value in this context. Host inventory comparison becomes more useful when combined with installation timestamps, executable paths, digital signatures, and process activity to determine whether an unusual software presence deserves investigation.<\/span><\/p>\n<h3><b>Question 307.<\/b><\/h3>\n<p><b>Which event can expose unauthorized changes to account privileges?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Account authorization records<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Browser cache entries<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS response timing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Printer connection logs<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Account authorization records can reveal changes affecting permissions, roles, or privileges assigned to users and groups. These records can help hunters identify unexpected privilege additions, membership changes, or modifications performed outside approved administrative procedures. Investigators can correlate the change with the responsible account, source system, timestamp, and subsequent activity. Browser cache data and DNS timing do not directly document authorization changes, while printer connection logs generally provide unrelated endpoint activity. Reviewing authorization records is therefore useful when investigating possible privilege escalation or unauthorized administrative access. Additional identity and endpoint telemetry can help determine whether the changed privilege was subsequently used.<\/span><\/p>\n<h3><b>Question 308.<\/b><\/h3>\n<p><b>What does comparing authentication sources help identify?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storage fragmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application licensing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Endpoint screen settings<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unusual access origins<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Comparing authentication sources helps identify unusual origins for account activity. A hunter can examine source hosts, addresses, geographic context, access methods, and normal login patterns to determine whether a particular authentication event differs from established behavior. An unexpected source does not automatically mean an account was compromised because users may legitimately access systems remotely or from changing locations. However, unusual source information becomes more significant when combined with unfamiliar devices, abnormal timing, privilege use, or concurrent endpoint activity. Storage fragmentation, software licensing, and screen settings do not provide meaningful authentication-origin context. Source comparison therefore supports identity-focused behavioral analysis.<\/span><\/p>\n<h3><b>Question 309.<\/b><\/h3>\n<p><b>Which telemetry can expose unusual application-to-application communication?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Process relationship data<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disk cleanup history<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Printer queue status<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Display configuration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Process relationship data can expose unusual communication or interaction between applications by showing process lineage and related execution behavior. Hunters can identify applications that launch unexpected child processes, interact with uncommon components, or establish relationships that differ from the normal endpoint baseline. Such relationships can provide leads for investigating scripting abuse, application exploitation, or unauthorized execution chains. Disk cleanup history, printer queues, and display configuration generally do not reveal process relationships. Process telemetry becomes particularly valuable when correlated with command-line parameters, user identity, file paths, and network activity, allowing investigators to understand the broader context around an unusual application interaction.<\/span><\/p>\n<h3><b>Question 310.<\/b><\/h3>\n<p><b>Which characteristic can distinguish automated activity from normal user actions?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Repeated uniform timing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Random wallpaper changes<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Variable screen resolution<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Occasional document printing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Repeated uniform timing can be a useful characteristic when distinguishing automated activity from ordinary human-driven actions. Scripts, scheduled jobs, and malicious automated processes may perform actions at highly consistent intervals. Hunters can analyze event timestamps and compare intervals across multiple occurrences to identify regular patterns. However, timing alone is not sufficient to establish malicious automation because legitimate monitoring systems, scheduled maintenance, and applications can behave similarly. Other characteristics such as initiating process, destination, account context, and activity type should be considered. Wallpaper changes, screen resolution, and occasional printing generally do not provide comparable evidence of automated execution.<\/span><\/p>\n<h3><b>Question 311.<\/b><\/h3>\n<p><b>What should be compared when assessing whether a new service is legitimate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Approved service inventory<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mouse sensitivity settings<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Browser font selection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Desktop shortcut order<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An approved service inventory provides an important baseline for determining whether a newly observed service is expected. Hunters can compare the service name, executable path, configuration, startup behavior, and owning application against approved organizational records. A service that differs from the established baseline may warrant additional examination, especially if it appeared without a documented deployment or change request. A difference alone does not establish malicious activity because legitimate software updates can introduce new services. Mouse settings, browser fonts, and shortcut ordering do not provide meaningful service-validation context. Combining inventory comparison with installation and process telemetry can improve confidence in the assessment.<\/span><\/p>\n<h3><b>Question 312.<\/b><\/h3>\n<p><b>Which network pattern may indicate unusual internal discovery?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">One routine web request<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Broad host probing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A successful backup<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A scheduled patch<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Broad host probing can indicate internal discovery because a system may attempt connections to numerous hosts while identifying available systems or services. Hunters can examine destination counts, targeted ports, connection timing, source process, and whether the activity differs from the endpoint&#8217;s normal communication profile. Administrative tools and security scanners can legitimately generate similar patterns, so the activity must be evaluated against approved operational processes. A routine web request, successful backup, or scheduled patch does not by itself indicate broad internal discovery. Network flow and connection telemetry can provide the necessary evidence to identify and investigate unusual probing behavior.<\/span><\/p>\n<h3><b>Question 313.<\/b><\/h3>\n<p><b>Which evidence helps determine whether a suspicious command was interactive?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File compression level<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS record age<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Session context<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disk partition size<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Session context can help determine whether a suspicious command occurred during an interactive user session or through an automated mechanism. Relevant information may include the account, session type, originating endpoint, logon event, remote-access method, and timing relationship between authentication and command execution. This context can distinguish expected administrative activity from commands launched through scheduled tasks, services, or potentially compromised sessions. File compression, DNS record age, and disk partition size do not establish command interactivity. Session information should be correlated with process execution and identity telemetry to develop a more complete understanding of how the command was initiated.<\/span><\/p>\n<h3><b>Question 314.<\/b><\/h3>\n<p><b>Which artifact can show when a system component was installed?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Installation records<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS cache entries<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network packet size<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Screen-lock events<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Installation records can provide timestamps and other details associated with the introduction of software or system components. Hunters can use this information to establish when an unfamiliar application, service, driver, or package appeared on an endpoint. Installation timing can then be compared with suspicious process execution, configuration changes, authentication events, or network activity. DNS cache entries and packet size describe network behavior, while screen-lock events describe user activity. Installation records therefore provide valuable temporal evidence when investigating newly introduced software. The evidence should be checked against approved deployment records because legitimate software updates can also create newly observed components.<\/span><\/p>\n<h3><b>Question 315.<\/b><\/h3>\n<p><b>Why correlate file and network timestamps?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To establish possible activity sequence<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To change file permissions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To increase storage capacity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To modify DNS configuration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Correlating file and network timestamps can help establish a possible sequence of events. For example, a newly created file followed shortly by an outbound connection may provide a useful investigative lead, particularly when the same process is associated with both events. Timestamp relationships do not prove causation, because system clocks, delayed processing, and unrelated activity can affect observed ordering. Nevertheless, temporal correlation helps hunters construct an evidence-based timeline. File permissions, storage capacity, and DNS configuration are separate concerns. Combining timestamps from multiple telemetry sources can reveal relationships that are difficult to recognize when each data source is examined independently.<\/span><\/p>\n<h3><b>Question 316.<\/b><\/h3>\n<p><b>Which observation can strengthen a hypothesis about unauthorized software deployment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Matching approved inventory<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Documented maintenance window<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unapproved installation event<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Normal application startup<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An unapproved installation event can strengthen a hypothesis that software was deployed without authorization. The hunter should examine the installer, account, endpoint, installation timestamp, source location, and resulting files or services. Evidence becomes stronger when the installation cannot be matched to approved change records or expected software-management activity. Matching approved inventory and documented maintenance windows instead provide explanations for legitimate changes, while normal application startup does not establish how software was introduced. Installation telemetry should be correlated with endpoint configuration, process execution, and identity records to determine whether the observed software deployment was expected or potentially unauthorized.<\/span><\/p>\n<h3><b>Question 317.<\/b><\/h3>\n<p><b>What is useful for identifying abnormal command execution frequency?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Process execution baseline<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Wallpaper history<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Printer toner levels<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Monitor power state<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A process execution baseline helps identify commands or applications that execute more frequently than expected. Hunters can establish normal execution patterns for particular users, hosts, applications, or business roles and then investigate significant deviations. An unusually high execution frequency may result from legitimate automation, software updates, or administrative activity, so frequency should be evaluated alongside process identity, command-line content, account context, and timing. Wallpaper history, printer toner levels, and monitor power state are unrelated to command execution frequency. Establishing a reliable baseline enables the hunter to distinguish unusual execution behavior from normal recurring activity.<\/span><\/p>\n<h3><b>Question 318.<\/b><\/h3>\n<p><b>Which information helps validate an external indicator before escalation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Monitor manufacturer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Threat-intelligence context<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Keyboard shortcut list<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Desktop icon order<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Threat-intelligence context can help validate an external indicator before escalation. Hunters can examine the indicator&#8217;s reputation, associated infrastructure, historical observations, confidence level, related domains or addresses, and known campaign or malware relationships. External intelligence should not be treated as definitive proof because indicators can become outdated, be shared by legitimate services, or be misclassified. Local telemetry should therefore be used to confirm whether the indicator actually appears in suspicious activity. Monitor manufacturers, keyboard shortcuts, and desktop icon ordering do not provide meaningful validation context. Combining intelligence with local evidence provides a stronger basis for deciding whether an indicator requires escalation.<\/span><\/p>\n<h3><b>Question 319.<\/b><\/h3>\n<p><b>Which event can reveal modification of a local security policy?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Browser bookmark creation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File download completion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Policy configuration change<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Screen brightness adjustment<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Policy configuration changes can reveal modifications to local security settings. Hunters can examine which policy was changed, the previous and new values, the responsible account or process, and the timestamp. Unexpected modifications may indicate attempts to weaken protections, enable unauthorized functionality, or alter endpoint behavior. However, legitimate administrators and management systems may also make policy changes, so the event should be compared against approved configuration baselines and change records. Browser bookmarks, file downloads, and screen brightness adjustments do not directly indicate security-policy modification. Configuration-change telemetry therefore provides an important source for investigating unexpected endpoint security changes.<\/span><\/p>\n<h3><b>Question 320.<\/b><\/h3>\n<p><b>What should a hunter preserve after confirming a significant finding?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Only unrelated events<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Supporting investigative evidence<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Temporary screen settings<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Personal desktop themes<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Supporting investigative evidence should be preserved after confirming a significant finding. Useful evidence may include relevant process records, network events, authentication data, timestamps, file information, query results, and contextual observations that support the conclusion. Preserving this material allows other analysts to validate the finding, reconstruct the activity, and improve future detection logic. Evidence should be handled according to organizational retention and investigation procedures. Unrelated events, screen settings, and desktop themes generally provide little value for documenting the finding. A well-preserved evidence set also makes it easier to communicate the investigation&#8217;s reasoning and support subsequent response activities.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cisco 300-220 Exam Dumps and Practice Test Dumps &nbsp; Question 301. Which evidence helps identify abnormal data transfer destinations? Local group membership File creation time External destination context Screen saver settings Correct Answer: 3 Explanation: External destination context helps determine whether data transfers are occurring toward expected or suspicious systems. A hunter can [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22746"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=22746"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22746\/revisions"}],"predecessor-version":[{"id":22747,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22746\/revisions\/22747"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=22746"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=22746"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=22746"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}